[Tue Aug 18 12:53:06.355869 2026] [lsapi:notice] [pid 119994:tid 119994] mod_lsapi: version 1.1-92
[Tue Aug 18 12:53:06.363935 2026] [:notice] [pid 66590:tid 66590] [host root@srv254.prodns.com.br] mod_lsapi: Selfstarter 66590 started
[Tue Aug 18 12:53:06.399358 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ledline.net.br.ledline.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.450563 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: nardyefeitozaadvogados.adv.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.457583 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: cp36-imobibrasil.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.459176 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: tenaxengenharia.com.br.solutiengenharia.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.480222 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: avalleimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.495174 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: cp37-imobibrasil.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.505641 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ciaobus.com.br.imgm.giordaniturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.506562 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: taniimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.516405 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: tenazprotecaoveicular.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.562833 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: osorioimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.567196 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: cariaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.569073 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: belmais.com.br.construbelmais.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.577766 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: lucenaassessoria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.588707 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: dominiocontroledepragas.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.689639 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: smcasanova.silplan.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.692142 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: smconstrutoraeengenharia.com.br.silplan.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.702768 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: loja.portalsatfiscal.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.711132 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: limapolimentos.com.br.riopolimento.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.720312 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: r3telhas.r3metais.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.732200 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: aagroup.com.br.pontadaareiaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.739347 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: pisogranitina.com.br.pisodegranitina.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.807885 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: msinspecoes.com.br.msengnr13.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.826866 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: lagenzia.testedemesa.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.830368 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: skyorionn.testedemesa.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.834751 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: skyorion.tec.testedemesa.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.849595 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: centroassistencialpaz.testedemesa.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.851344 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: mconteccontabil.com.br.testedemesa.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.852119 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: gramadoboutiqueeventos.testedemesa.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.852848 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: seuferrazzabarbearia.com.br.testedemesa.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.853984 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ktcproducoeseeventos.com.br.testedemesa.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.854691 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: lojasmemo.memo.ind.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.858483 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: cervejeirasmemo.memo.ind.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.898184 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: shopping.impactodivisoria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.899036 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: impactodivisorias.com.br.impactodivisoria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.937090 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: holldyperfuracoes.grupoaquifero.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.937855 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: americapocosartesianos.grupoaquifero.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.972180 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: maosaobramt.com.br.ferrazegomes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.974616 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: website.fbenevides.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:06.988207 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: cargaedescargatiofe.com.br.expressotiofe.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.000830 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: drthiagocollares.drthiagocollares.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.001642 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: azelarcontroledepragas.com.br.dominiocontroledepragas.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.019146 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: construtoradetoni.detoniconstrutora.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.051161 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: capecodcleaningsvc.com.capecodcleaningservice.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.061777 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: seaconsultoriaambiental.bigcat.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.068520 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: belmaisbomfim.belmaisold.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.072715 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: requintelimp.com.br.automasantos.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.130133 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: rodolfoveras.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.130936 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: portobeloimoveismg.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.131614 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: novosares.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.134612 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: lacazaconstrutora.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.136204 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: soimoveistatuape.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.136931 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: zavaloni.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.137675 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: sulhaus.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.138397 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: inlarimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.139123 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: imparavelimob.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.139872 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: perescoelho.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.140589 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: voxconsultoriaimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.141385 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: comercialimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.143781 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: localimoveisaraguari.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.144506 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: 3xpay.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.145228 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: santosimoveis.imb.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.145960 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: angelaflats.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.147432 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: imobiliariaparanhos.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.148204 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: priorimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.170228 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: wrsteel.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.173803 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: oniimoveis.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.174541 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: igarataimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.178280 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: rlcorretores.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.179112 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: vprimesolucoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.179905 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: vp3.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.198321 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: lplnegocios.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.213935 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: rilleyerick.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.214663 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: finanimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.215428 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: regentnegociosimobiliarios.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.219949 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: uniquemultimarcas.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.223523 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: underr.co:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.226615 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: brunocunhaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.227323 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: domusimoveisaracaju.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.228193 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: intuitoimobiliario.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.229729 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: quadradoimob.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.231177 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: fhcorretores.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.245728 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ccrimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.263588 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: alessandrawagner.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.264342 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: beachhouseimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.265088 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: privatebroker.online:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.267413 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: vanessasantosimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.275690 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: equipeaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.282101 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: sportvel.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.282932 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: lusoimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.310403 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: sfcacessorios.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.338914 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: meimoveisnapraia.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.339580 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: analustosaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.348800 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: noventaempreendimentos.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.354896 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: grservicos.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.373952 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: reidasbateriasbarra.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.386943 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: hdpinturas.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.388427 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: roselifroesimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.391638 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: jeosafaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.395408 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: gfsnegociosimobiliarios.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.396124 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: arteembambu.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.396940 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: imobi1.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.412111 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: bahiabrokers.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.426048 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: wmtransporterj.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.436887 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: slobimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.437604 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: pandaimoveispraia.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.442172 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: pasys.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.442897 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: passopreto.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.452292 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: sdtechelevadores.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.453052 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ivofilhoimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.470671 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: octoaipro.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.472243 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: rayssamoutranconsultora.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.473542 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: imobiliariaborille.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.474280 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: duarteemouraoadvogados.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.474961 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: vicentegomesimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.477913 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: minattoimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.478639 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: vidamoimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.486798 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: andrehkarrimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.491739 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: bcostim.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.492400 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: abensimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.497553 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: iconeimoveisrs.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.498303 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: fabioporfiro.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.499621 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: inovalleimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.509911 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: mogipallets.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.513438 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: mmachado.imb.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.524369 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: receptivaimoveis.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.559275 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: maracanaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.571195 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: pusch.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.572661 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: deucertoimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.576608 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: luxsociety.club:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.578326 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: luvdesign.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.584188 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: dealencastroconyvidal.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.591030 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: lojainspirada.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.593248 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: alconstrutora.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.599184 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: fserranodosreisimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.600252 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: desimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.606850 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: planetimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.607633 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: brazriosimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.608385 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: azevedofernandes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.696631 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: imobiliariacenterville.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.697413 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: yurilisboaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.698256 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: homego.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.699010 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: bolzonelloimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.700603 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ofimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.704153 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: mendesestrutura.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.704982 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: imob.adm.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.705839 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: detalhesimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.706853 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: positivoimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.707980 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: casaverdeeamarelamogi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.712320 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: corretorafaroldabarra.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.713007 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: singularimovel.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.719455 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: moralesemenezesadvocacia.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.759932 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: imperiodosquadros.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.776418 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: investincorporacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.778631 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: marciacristiane.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.784615 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: aragoniimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.794715 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: casafacilprudente.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.812553 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: rmi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.820066 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: gavino.imb.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.820831 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: corretoresdeimoveis.cim.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.828479 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: amaadvocacia.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.829210 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ponto4imoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.834670 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: palaceteimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.835373 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: novolarlimeira.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.836087 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: beneville.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.853609 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: beckcentral.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.855946 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ferrazegomes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.859956 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: feitech.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.868166 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: braunaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.871833 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: re9nove.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.886924 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: rmautomoveisitajai.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.896801 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: dayaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.905800 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: reiximoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.906483 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: diegorobertoimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.910458 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: dryulocesare.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.915657 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: fernandooliveiracorretor.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.924487 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: diveramkt.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.933600 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: destaquemultimarcas.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.941254 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: vigaimoveistc.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.944171 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ingalar.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.955212 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: credprimevc.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.957417 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: cp39-imobibrasil.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.958208 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: cp38-imobibrasil.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.959547 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: corretorjoaofilho.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.967645 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: conquistamaquinas.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.990385 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: claraconecta.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:07.991160 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: openhouses.net.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.032800 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: alocaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.033520 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: imobiliariasafra.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.039737 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: brsplit.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.049417 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: bondtintas.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.052605 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: a2ai.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.063950 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: raposoimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.082193 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: lopesreis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.095986 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: atendeprime.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.102613 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: arsegfire.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.105885 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: arautosveiculos.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.106712 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: rastroimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.107479 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: advfreire.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.110069 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: eliaquimimoveis.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.113185 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ipimoveisjatai.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.164554 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: acertdecor.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.165340 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: aceleradigital.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.167587 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: n5negocios.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.171467 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Tue Aug 18 12:53:08.194906 2026] [qos:notice] [pid 119994:tid 119994] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Tue Aug 18 12:53:08.565879 2026] [http2:info] [pid 119994:tid 119994] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.70.0), initializing...
[Tue Aug 18 12:53:08.572849 2026] [mpm_event:notice] [pid 119994:tid 119994] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Tue Aug 18 12:53:08.572863 2026] [core:notice] [pid 119994:tid 119994] AH00094: Command line: '/usr/sbin/httpd'
[Tue Aug 18 12:53:09.651444 2026] [http2:info] [pid 66623:tid 66623] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Aug 18 12:53:09.680852 2026] [security2:error] [pid 66623:tid 66791] [client 68.155.154.236:65211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoR_5dO5rbWdOArH04J1owAAASM"]
[Tue Aug 18 12:53:09.681678 2026] [security2:error] [pid 66623:tid 66795] [client 20.104.100.201:56859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoR_5dO5rbWdOArH04J1pQAAASc"]
[Tue Aug 18 12:53:09.682589 2026] [security2:error] [pid 66623:tid 66799] [client 172.182.200.96:14106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/qfvqu.php"] [unique_id "aoR_5dO5rbWdOArH04J1pwAAASs"]
[Tue Aug 18 12:53:09.682759 2026] [security2:error] [pid 66623:tid 66801] [client 20.48.236.86:10801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/av.php"] [unique_id "aoR_5dO5rbWdOArH04J1qAAAAS0"]
[Tue Aug 18 12:53:09.683632 2026] [security2:error] [pid 66623:tid 66805] [client 20.151.109.219:20929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/ut.php"] [unique_id "aoR_5dO5rbWdOArH04J1qgAAATE"]
[Tue Aug 18 12:53:09.684253 2026] [security2:error] [pid 66623:tid 66807] [client 172.202.39.151:11074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/k.php"] [unique_id "aoR_5dO5rbWdOArH04J1qwAAATM"]
[Tue Aug 18 12:53:09.685521 2026] [security2:error] [pid 66623:tid 66813] [client 172.202.39.151:28527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-content.php.php"] [unique_id "aoR_5dO5rbWdOArH04J1rgAAATk"]
[Tue Aug 18 12:53:09.685937 2026] [security2:error] [pid 66623:tid 66777] [client 20.104.100.201:54054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-asudo.php"] [unique_id "aoR_5dO5rbWdOArH04J1mwAAARU"]
[Tue Aug 18 12:53:09.685966 2026] [security2:error] [pid 66623:tid 66787] [client 104.209.144.33:31255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoR_5dO5rbWdOArH04J1ogAAAR8"]
[Tue Aug 18 12:53:09.686001 2026] [security2:error] [pid 66623:tid 66785] [client 20.171.51.14:16762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ij.php"] [unique_id "aoR_5dO5rbWdOArH04J1ngAAAR0"]
[Tue Aug 18 12:53:09.686032 2026] [security2:error] [pid 66623:tid 66773] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wap.php"] [unique_id "aoR_5dO5rbWdOArH04J1mQAAARE"]
[Tue Aug 18 12:53:09.686051 2026] [security2:error] [pid 66623:tid 66779] [client 20.250.27.191:7370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/kir.php"] [unique_id "aoR_5dO5rbWdOArH04J1nQAAARc"]
[Tue Aug 18 12:53:09.686095 2026] [security2:error] [pid 66623:tid 66768] [client 20.65.69.59:54595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/47.php"] [unique_id "aoR_5dO5rbWdOArH04J1lgAAAQw"]
[Tue Aug 18 12:53:09.686145 2026] [security2:error] [pid 66623:tid 66766] [client 68.221.73.131:4231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/xiugai.php"] [unique_id "aoR_5dO5rbWdOArH04J1lQAAAQo"]
[Tue Aug 18 12:53:09.686180 2026] [security2:error] [pid 66623:tid 66772] [client 132.196.61.152:38372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/xiugai.php"] [unique_id "aoR_5dO5rbWdOArH04J1mgAAARA"]
[Tue Aug 18 12:53:09.686204 2026] [security2:error] [pid 66623:tid 66767] [client 20.42.19.40:2227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/chosen.php"] [unique_id "aoR_5dO5rbWdOArH04J1lwAAAQs"]
[Tue Aug 18 12:53:09.686261 2026] [security2:error] [pid 66623:tid 66781] [client 52.173.121.69:6087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoR_5dO5rbWdOArH04J1oAAAARk"]
[Tue Aug 18 12:53:09.686288 2026] [security2:error] [pid 66623:tid 66783] [client 20.171.51.14:15784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/pu.php"] [unique_id "aoR_5dO5rbWdOArH04J1nwAAARs"]
[Tue Aug 18 12:53:09.686331 2026] [security2:error] [pid 66623:tid 66815] [client 52.238.210.254:10189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_5dO5rbWdOArH04J1rwAAATs"]
[Tue Aug 18 12:53:09.686361 2026] [security2:error] [pid 66623:tid 66789] [client 4.223.164.152:7071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoR_5dO5rbWdOArH04J1oQAAASE"]
[Tue Aug 18 12:53:09.688032 2026] [security2:error] [pid 66623:tid 66823] [client 74.249.206.207:58233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_5dO5rbWdOArH04J1sQAAAUM"]
[Tue Aug 18 12:53:09.688347 2026] [security2:error] [pid 66623:tid 66825] [client 74.248.136.165:60573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/xqq.php"] [unique_id "aoR_5dO5rbWdOArH04J1sgAAAUU"]
[Tue Aug 18 12:53:09.690324 2026] [security2:error] [pid 66623:tid 66833] [client 52.238.210.254:42081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/goods.php"] [unique_id "aoR_5dO5rbWdOArH04J1tgAAAU0"]
[Tue Aug 18 12:53:09.690868 2026] [security2:error] [pid 66623:tid 66835] [client 104.209.144.33:24839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoR_5dO5rbWdOArH04J1twAAAU8"]
[Tue Aug 18 12:53:09.703261 2026] [autoindex:error] [pid 66623:tid 66811] [client 52.139.47.57:0] AH01276: Cannot serve directory /home4/spilwf01/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:09.741038 2026] [security2:error] [pid 66623:tid 66825] [client 192.141.172.134:49714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5dO5rbWdOArH04J1uQAAAUU"]
[Tue Aug 18 12:53:09.741186 2026] [security2:error] [pid 66623:tid 66825] [client 192.141.172.134:49714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5dO5rbWdOArH04J1uQAAAUU"]
[Tue Aug 18 12:53:09.747352 2026] [autoindex:error] [pid 66623:tid 66793] [client 4.223.164.152:46149] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:09.804764 2026] [security2:error] [pid 66623:tid 66810] [client 20.119.58.187:15357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/admin-post.php"] [unique_id "aoR_5dO5rbWdOArH04J1vQAAATY"]
[Tue Aug 18 12:53:09.811965 2026] [security2:error] [pid 66623:tid 66641] [remote 57.141.22.92:45366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_5dO5rbWdOArH04J1wAABhgQ"]
[Tue Aug 18 12:53:09.818782 2026] [authz_core:error] [pid 66623:tid 66843] [client 192.178.4.133:64201] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:09.819032 2026] [authz_core:error] [pid 66623:tid 66843] [client 192.178.4.133:64201] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:09.856107 2026] [security2:error] [pid 66623:tid 66649] [remote 57.141.22.18:25404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_5dO5rbWdOArH04J10AABHww"]
[Tue Aug 18 12:53:09.856527 2026] [security2:error] [pid 66623:tid 66663] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_5dO5rbWdOArH04J11gABFho"]
[Tue Aug 18 12:53:09.866978 2026] [authz_core:error] [pid 66623:tid 66652] [remote 216.73.216.206:18307] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:09.867513 2026] [authz_core:error] [pid 66623:tid 66652] [remote 216.73.216.206:18307] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:09.871467 2026] [authz_core:error] [pid 66623:tid 66661] [remote 216.73.216.206:18307] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:09.871980 2026] [authz_core:error] [pid 66623:tid 66661] [remote 216.73.216.206:18307] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:09.895835 2026] [security2:error] [pid 66623:tid 66800] [client 158.158.74.177:13803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoR_5dO5rbWdOArH04J15wAAASw"]
[Tue Aug 18 12:53:09.903755 2026] [security2:error] [pid 66623:tid 66677] [remote 57.141.22.7:26564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_5dO5rbWdOArH04J16QABaSg"]
[Tue Aug 18 12:53:09.955785 2026] [autoindex:error] [pid 66623:tid 66869] [client 20.91.215.254:12614] AH01276: Cannot serve directory /home3/aceunai/public_html/abraceocomerciodeunai.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:09.973232 2026] [security2:error] [pid 66623:tid 66679] [remote 159.69.192.98:33246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.192.69.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.capecodcleaningservice.com"] [uri "/wp-login.php"] [unique_id "aoR_5dO5rbWdOArH04J18AABbSo"]
[Tue Aug 18 12:53:09.984271 2026] [security2:error] [pid 66623:tid 66779] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_5dO5rbWdOArH04J18wAAARc"]
[Tue Aug 18 12:53:10.021323 2026] [security2:error] [pid 66623:tid 66690] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_5tO5rbWdOArH04J1-wABWTU"]
[Tue Aug 18 12:53:10.028561 2026] [security2:error] [pid 66623:tid 66841] [client 213.35.127.232:62460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoR_5tO5rbWdOArH04J1_wAAAVU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:10.033780 2026] [security2:error] [pid 66623:tid 66838] [client 20.42.19.40:2212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/simple.php"] [unique_id "aoR_5tO5rbWdOArH04J2AgAAAVI"]
[Tue Aug 18 12:53:10.035857 2026] [security2:error] [pid 66623:tid 66845] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoR_5tO5rbWdOArH04J2AwAAAVk"]
[Tue Aug 18 12:53:10.043016 2026] [security2:error] [pid 66623:tid 66830] [client 52.139.47.57:39517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/pwnd/as.php"] [unique_id "aoR_5tO5rbWdOArH04J2BAAAAUo"]
[Tue Aug 18 12:53:10.069551 2026] [security2:error] [pid 66623:tid 66845] [client 132.196.61.152:54757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/adminner.php"] [unique_id "aoR_5tO5rbWdOArH04J2CQAAAVk"]
[Tue Aug 18 12:53:10.108596 2026] [security2:error] [pid 66623:tid 66830] [client 192.141.172.134:50021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2DgAAAUo"]
[Tue Aug 18 12:53:10.108902 2026] [security2:error] [pid 66623:tid 66830] [client 192.141.172.134:50021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2DgAAAUo"]
[Tue Aug 18 12:53:10.117368 2026] [security2:error] [pid 66623:tid 66787] [client 68.221.73.131:4308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/adminner.php"] [unique_id "aoR_5tO5rbWdOArH04J2DwAAAR8"]
[Tue Aug 18 12:53:10.127756 2026] [security2:error] [pid 66623:tid 66702] [remote 66.102.134.13:49070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.134.102.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stremma.com.br"] [uri "/wp-login.php"] [unique_id "aoR_5tO5rbWdOArH04J2EAABdkE"]
[Tue Aug 18 12:53:10.130507 2026] [security2:error] [pid 66623:tid 66790] [client 20.250.27.191:7406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/nofile.php"] [unique_id "aoR_5tO5rbWdOArH04J2EQAAASI"]
[Tue Aug 18 12:53:10.152511 2026] [security2:error] [pid 66623:tid 66703] [remote 72.167.40.62:53450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.40.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "i-databi.com.br"] [uri "/wp-login.php"] [unique_id "aoR_5tO5rbWdOArH04J2EgABH0I"]
[Tue Aug 18 12:53:10.156510 2026] [security2:error] [pid 66623:tid 66774] [client 20.100.169.31:33702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-good.php"] [unique_id "aoR_5tO5rbWdOArH04J2FAAAARI"]
[Tue Aug 18 12:53:10.160502 2026] [security2:error] [pid 66623:tid 66890] [client 20.65.69.59:15210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/payout.php"] [unique_id "aoR_5tO5rbWdOArH04J2FQAAAYY"]
[Tue Aug 18 12:53:10.182887 2026] [security2:error] [pid 66623:tid 66709] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/media.php"] [unique_id "aoR_5tO5rbWdOArH04J2GgABdkg"]
[Tue Aug 18 12:53:10.188660 2026] [security2:error] [pid 66623:tid 66710] [remote 74.220.219.216:47970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.219.220.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ondaparaty.com"] [uri "/wp-login.php"] [unique_id "aoR_5tO5rbWdOArH04J2GwABfEk"]
[Tue Aug 18 12:53:10.189507 2026] [security2:error] [pid 66623:tid 66844] [client 20.91.215.254:22530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/mah/function.php"] [unique_id "aoR_5tO5rbWdOArH04J2HgAAAVg"]
[Tue Aug 18 12:53:10.192673 2026] [security2:error] [pid 66623:tid 66712] [remote 46.62.208.238:53350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.208.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amp.adv.br"] [uri "/wp-login.php"] [unique_id "aoR_5tO5rbWdOArH04J2HQABg0s"]
[Tue Aug 18 12:53:10.212391 2026] [security2:error] [pid 66623:tid 66852] [client 4.223.164.152:6893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wp-blog.php"] [unique_id "aoR_5tO5rbWdOArH04J2JAAAAWA"]
[Tue Aug 18 12:53:10.219913 2026] [security2:error] [pid 66623:tid 66788] [client 74.7.244.15:45094] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.jx2.com.br.jx2sitesprofissionais.com"] [uri "/index.php"] [unique_id "aoR_5dO5rbWdOArH04J14AABIB8"]
[Tue Aug 18 12:53:10.221510 2026] [authz_core:error] [pid 66623:tid 66715] [remote 57.141.22.51:27560] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:10.221932 2026] [authz_core:error] [pid 66623:tid 66715] [remote 57.141.22.51:27560] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:10.223800 2026] [security2:error] [pid 66623:tid 66875] [client 149.34.210.141:56234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2KAAAAXc"]
[Tue Aug 18 12:53:10.232474 2026] [security2:error] [pid 66623:tid 66877] [client 45.92.229.104:21259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.229.92.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-login.php"] [unique_id "aoR_5tO5rbWdOArH04J2JwAAAXk"], referer: https://ozzyfernandesoficial.com.br/wp-login.php
[Tue Aug 18 12:53:10.252772 2026] [security2:error] [pid 66623:tid 66882] [client 74.248.18.37:27708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ethosconsult.com.br"] [uri "/fone1.php"] [unique_id "aoR_5tO5rbWdOArH04J2LAAAAX4"]
[Tue Aug 18 12:53:10.340155 2026] [security2:error] [pid 66623:tid 66799] [client 20.119.58.187:15315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/maint/maint/ajax-actions.php"] [unique_id "aoR_5tO5rbWdOArH04J2RAAAASs"]
[Tue Aug 18 12:53:10.347687 2026] [security2:error] [pid 66623:tid 66745] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/admin.php"] [unique_id "aoR_5tO5rbWdOArH04J2RwABemw"]
[Tue Aug 18 12:53:10.362540 2026] [security2:error] [pid 66623:tid 66790] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_5tO5rbWdOArH04J2TgAAASI"]
[Tue Aug 18 12:53:10.373451 2026] [security2:error] [pid 66623:tid 66770] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/bgymj.php"] [unique_id "aoR_5tO5rbWdOArH04J2XgAAAQ4"]
[Tue Aug 18 12:53:10.376971 2026] [security2:error] [pid 66623:tid 66790] [client 172.182.200.96:14200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/oivcl.php"] [unique_id "aoR_5tO5rbWdOArH04J2XwAAASI"]
[Tue Aug 18 12:53:10.386018 2026] [security2:error] [pid 66623:tid 66781] [client 213.232.122.14:64853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "acpecasebaterias.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J1_QAAARk"]
[Tue Aug 18 12:53:10.403090 2026] [security2:error] [pid 66623:tid 66798] [client 4.223.164.152:37272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/pucci.php"] [unique_id "aoR_5tO5rbWdOArH04J2YQAAASo"]
[Tue Aug 18 12:53:10.406765 2026] [lsapi:error] [pid 66623:tid 66823] [client 192.178.4.5:61914] [host csleducacional.com.br] Backend fatal error: PHP Fatal error: Uncaught TypeError: implode(): Argument #2 ($array) must be of type ?array, string given in /home3/csleduca/public_html/wp-content/plugins/wp-rocket/vendor/matthiasmullie/minify/src/CSS.php:528\nStack trace:\n#0 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/vendor/matthiasmullie/minify/src/CSS.php(528): implode(Array, '|')\n#1 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/vendor/matthiasmullie/minify/src/CSS.php(314): MatthiasMullie\\Minify\\CSS->shortenColors('.elementor-kit-...')\n#2 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/vendor/matthiasmullie/minify/src/Minify.php(111): MatthiasMullie\\Minify\\CSS->execute(NULL)\n#3 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/inc/classes/optimization/CSS/class-minify.php(175): MatthiasMullie\\Minify\\Minify->minify()\n#4 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/inc/classes/optimization/CSS/class-minify.php(128): WP_Rocket\\Optimization\\CSS\\Minify->minify('/home3/csleduca...', '/home3/csleduca...')\n#5 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/inc/classes/optimization/CSS/class-minify.php(66): WP_Rocket\\Optimization\\CSS\\Minify->replace_url('https://csleduc...')\n#6 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/inc/classes/subscriber/Optimization/class-abstract-minify-subscriber.php(85): WP_Rocket\\Optimization\\CSS\\Minify->optimize('...')\n#7 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/inc/classes/subscriber/Optimization/class-minify-css-subscriber.php(44): WP_Rocket\\Subscriber\\Optimization\\Minify_Subscriber->optimize('...')\n#8 /home3/csleduca/public_html/wp-includes/class-wp-hook.php(341): WP_Rocket\\Subscriber\\Optimization\\Minify_CSS_Subscriber->process('...')\n#9 /home3/csleduca/public_html/wp-includes/plugin.php(205): WP_Hook->apply_filters('...', Array)\n#10 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/inc/classes/Buffer/class-optimization.php(104): apply_filters('rocket_buffer', '...')\n#11 [internal function]: WP_Rocket\\Buffer\\Optimization->maybe_process_buffer('...', 9)\n#12 /home3/csleduca/public_html/wp-includes/functions.php(5493): ob_end_flush()\n#13 /home3/csleduca/public_html/wp-includes/class-wp-hook.php(341): wp_ob_end_flush_all('')\n#14 /home3/csleduca/public_html/wp-includes/class-wp-hook.php(365): WP_Hook->apply_filters(NULL, Array)\n#15 /home3/csleduca/public_html/wp-includes/plugin.php(522): WP_Hook->do_action(Array)\n#16 /home3/csleduca/public_html/wp-includes/load.php(1308): do_action('shutdown')\n#17 [internal function]: shutdown_action_hook()\n#18 {main}\n thrown in /home3/csleduca/public_html/wp-content/plugins/wp-rocket/vendor/matthiasmullie/minify/src/CSS.php on line 528\n
[Tue Aug 18 12:53:10.425524 2026] [security2:error] [pid 66623:tid 66883] [client 160.120.140.123:51051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2YgAAAX8"]
[Tue Aug 18 12:53:10.425744 2026] [security2:error] [pid 66623:tid 66883] [client 160.120.140.123:51051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2YgAAAX8"]
[Tue Aug 18 12:53:10.461444 2026] [security2:error] [pid 66623:tid 66879] [client 178.153.171.161:64444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2ZAAAAXs"]
[Tue Aug 18 12:53:10.461632 2026] [security2:error] [pid 66623:tid 66879] [client 178.153.171.161:64444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2ZAAAAXs"]
[Tue Aug 18 12:53:10.478546 2026] [security2:error] [pid 66623:tid 66852] [client 20.171.51.14:29246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ry.php"] [unique_id "aoR_5tO5rbWdOArH04J2ZgAAAWA"]
[Tue Aug 18 12:53:10.491126 2026] [security2:error] [pid 66623:tid 66800] [client 20.65.69.59:60126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/bh.php"] [unique_id "aoR_5tO5rbWdOArH04J2aAAAASw"]
[Tue Aug 18 12:53:10.491426 2026] [security2:error] [pid 66623:tid 66875] [client 149.34.210.141:56234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2KAAAAXc"]
[Tue Aug 18 12:53:10.518786 2026] [security2:error] [pid 66623:tid 66799] [client 20.104.100.201:53830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/az.php"] [unique_id "aoR_5tO5rbWdOArH04J2agAAASs"]
[Tue Aug 18 12:53:10.519307 2026] [security2:error] [pid 66623:tid 66674] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/mac.php"] [unique_id "aoR_5tO5rbWdOArH04J2aQABIyU"]
[Tue Aug 18 12:53:10.543190 2026] [security2:error] [pid 66623:tid 66838] [client 132.196.61.152:54746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/file1221.php"] [unique_id "aoR_5tO5rbWdOArH04J2awAAAVI"]
[Tue Aug 18 12:53:10.556727 2026] [security2:error] [pid 66623:tid 66883] [client 68.221.73.131:4313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/file1221.php"] [unique_id "aoR_5tO5rbWdOArH04J2bAAAAX8"]
[Tue Aug 18 12:53:10.585175 2026] [security2:error] [pid 66623:tid 66869] [client 158.158.74.177:13804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoR_5tO5rbWdOArH04J2cgAAAXE"]
[Tue Aug 18 12:53:10.609200 2026] [security2:error] [pid 66623:tid 66794] [client 20.250.27.191:7889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/fling.php"] [unique_id "aoR_5tO5rbWdOArH04J2dQAAASY"]
[Tue Aug 18 12:53:10.635149 2026] [security2:error] [pid 66623:tid 66788] [client 52.173.121.69:17923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoR_5tO5rbWdOArH04J2dwAAASA"]
[Tue Aug 18 12:53:10.692652 2026] [http2:info] [pid 67073:tid 67073] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Aug 18 12:53:10.695349 2026] [security2:error] [pid 66623:tid 66885] [client 74.248.18.37:26681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp.php"] [unique_id "aoR_5tO5rbWdOArH04J2fgAAAYE"]
[Tue Aug 18 12:53:10.701140 2026] [security2:error] [pid 66623:tid 66796] [client 20.119.58.187:14838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/dropdown.php"] [unique_id "aoR_5tO5rbWdOArH04J2gAAAASg"]
[Tue Aug 18 12:53:10.704198 2026] [security2:error] [pid 66623:tid 66791] [client 68.155.154.236:63931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoR_5tO5rbWdOArH04J2gQAAASM"]
[Tue Aug 18 12:53:10.708493 2026] [security2:error] [pid 66623:tid 66792] [client 47.128.54.59:51252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aesexaustores.com.br"] [uri "/robots.txt"] [unique_id "aoR_5tO5rbWdOArH04J2ggAAASQ"]
[Tue Aug 18 12:53:10.717259 2026] [security2:error] [pid 66623:tid 66694] [remote 20.250.27.191:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "paypix.co"] [uri "/1.php"] [unique_id "aoR_5tO5rbWdOArH04J2gwABeTk"]
[Tue Aug 18 12:53:10.717405 2026] [security2:error] [pid 66623:tid 66694] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/1.php"] [unique_id "aoR_5tO5rbWdOArH04J2gwABeTk"]
[Tue Aug 18 12:53:10.718251 2026] [security2:error] [pid 66623:tid 66694] [remote 72.167.40.62:42624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.40.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maxhost.com.br"] [uri "/wp-login.php"] [unique_id "aoR_5tO5rbWdOArH04J2hAABEjk"]
[Tue Aug 18 12:53:10.720572 2026] [security2:error] [pid 66623:tid 66779] [client 85.154.68.202:56134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2hQAAARc"]
[Tue Aug 18 12:53:10.720846 2026] [security2:error] [pid 66623:tid 66779] [client 85.154.68.202:56134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2hQAAARc"]
[Tue Aug 18 12:53:10.728253 2026] [security2:error] [pid 66623:tid 66783] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoR_5tO5rbWdOArH04J2hwAAARs"]
[Tue Aug 18 12:53:10.828807 2026] [security2:error] [pid 66623:tid 66814] [client 74.248.18.37:62822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/lock360.php"] [unique_id "aoR_5tO5rbWdOArH04J2lAAAATo"]
[Tue Aug 18 12:53:10.831340 2026] [security2:error] [pid 66623:tid 66889] [client 34.178.149.167:45784] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.blueorbit.com.br"] [uri "/database.sql"] [unique_id "aoR_5tO5rbWdOArH04J2lgAAAYU"]
[Tue Aug 18 12:53:10.832330 2026] [security2:error] [pid 66623:tid 66846] [client 157.51.166.53:49178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2lQAAAVo"]
[Tue Aug 18 12:53:10.832463 2026] [security2:error] [pid 67073:tid 67208] [client 132.196.61.152:54762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/inx.php"] [unique_id "aoR_5vcmepr5_nHgLbMpXAAAAhc"]
[Tue Aug 18 12:53:10.832481 2026] [security2:error] [pid 66623:tid 66846] [client 157.51.166.53:49178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2lQAAAVo"]
[Tue Aug 18 12:53:10.836580 2026] [security2:error] [pid 67073:tid 67206] [client 20.42.19.40:2713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/ioxi-o.php"] [unique_id "aoR_5vcmepr5_nHgLbMpXQAAAhU"]
[Tue Aug 18 12:53:10.848162 2026] [security2:error] [pid 66623:tid 66860] [client 34.178.149.167:45782] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.blueorbit.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "aoR_5tO5rbWdOArH04J2mQAAAWg"]
[Tue Aug 18 12:53:10.850319 2026] [security2:error] [pid 66623:tid 66772] [client 34.178.149.167:45778] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.blueorbit.com.br"] [uri "/telescope/requests"] [unique_id "aoR_5tO5rbWdOArH04J2nAAAARA"]
[Tue Aug 18 12:53:10.852348 2026] [security2:error] [pid 66623:tid 66837] [client 168.62.48.100:16376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_5tO5rbWdOArH04J2ngAAAVE"]
[Tue Aug 18 12:53:10.854752 2026] [security2:error] [pid 66623:tid 66785] [client 34.178.149.167:45748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.blueorbit.com.br"] [uri "/dump.sql"] [unique_id "aoR_5tO5rbWdOArH04J2mgAAAR0"]
[Tue Aug 18 12:53:10.857779 2026] [security2:error] [pid 66623:tid 66789] [client 34.178.149.167:45722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.blueorbit.com.br"] [uri "/backup.sql"] [unique_id "aoR_5tO5rbWdOArH04J2oAAAASE"]
[Tue Aug 18 12:53:10.877489 2026] [security2:error] [pid 66623:tid 66848] [client 34.178.149.167:45840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.149.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blueorbit.com.br"] [uri "/info.php"] [unique_id "aoR_5tO5rbWdOArH04J2pgAAAVw"]
[Tue Aug 18 12:53:10.878806 2026] [security2:error] [pid 66623:tid 66704] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/coffee.php"] [unique_id "aoR_5tO5rbWdOArH04J2pwABcUM"]
[Tue Aug 18 12:53:10.887874 2026] [security2:error] [pid 66623:tid 66787] [client 20.65.69.59:36362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/ct.php"] [unique_id "aoR_5tO5rbWdOArH04J2qAAAAR8"]
[Tue Aug 18 12:53:10.894717 2026] [autoindex:error] [pid 66623:tid 66847] [client 4.223.164.152:37301] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:10.899902 2026] [security2:error] [pid 66623:tid 66873] [client 37.40.227.74:56893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2qgAAAXU"]
[Tue Aug 18 12:53:10.900056 2026] [security2:error] [pid 66623:tid 66873] [client 37.40.227.74:56893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2qgAAAXU"]
[Tue Aug 18 12:53:10.959603 2026] [security2:error] [pid 66623:tid 66770] [client 34.178.149.167:45846] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.blueorbit.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoR_5tO5rbWdOArH04J2rwAAAQ4"]
[Tue Aug 18 12:53:10.980620 2026] [security2:error] [pid 66623:tid 66852] [client 68.221.73.131:4800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/inx.php"] [unique_id "aoR_5tO5rbWdOArH04J2sQAAAWA"]
[Tue Aug 18 12:53:11.004383 2026] [security2:error] [pid 67073:tid 67218] [client 20.48.236.86:65088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/media.php"] [unique_id "aoR_5_cmepr5_nHgLbMpYQAAAiE"]
[Tue Aug 18 12:53:11.018086 2026] [security2:error] [pid 66623:tid 66836] [client 74.248.18.37:41349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ethosconsult.com.br"] [uri "/ncx.php"] [unique_id "aoR_59O5rbWdOArH04J2vAAAAVA"]
[Tue Aug 18 12:53:11.049048 2026] [security2:error] [pid 66623:tid 66676] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/classwithtostring.php"] [unique_id "aoR_59O5rbWdOArH04J2wAABKyc"]
[Tue Aug 18 12:53:11.068461 2026] [security2:error] [pid 66623:tid 66866] [client 20.250.27.191:7934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/zoo1.php"] [unique_id "aoR_59O5rbWdOArH04J21gAAAW4"]
[Tue Aug 18 12:53:11.072039 2026] [security2:error] [pid 67073:tid 67205] [client 213.35.127.232:64398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoR_5_cmepr5_nHgLbMpYwAAAhQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:11.076736 2026] [security2:error] [pid 66623:tid 66778] [client 20.119.58.187:15323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/css/index.php"] [unique_id "aoR_59O5rbWdOArH04J25QAAARY"]
[Tue Aug 18 12:53:11.089553 2026] [security2:error] [pid 67073:tid 67220] [client 168.62.48.100:16318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_5_cmepr5_nHgLbMpZAAAAiM"]
[Tue Aug 18 12:53:11.130040 2026] [security2:error] [pid 67073:tid 67221] [client 4.223.164.152:6613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/adminfuns.php"] [unique_id "aoR_5_cmepr5_nHgLbMpZQAAAiQ"]
[Tue Aug 18 12:53:11.172731 2026] [security2:error] [pid 66623:tid 66808] [client 132.196.61.152:23817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/reviall.php"] [unique_id "aoR_59O5rbWdOArH04J2-wAAATQ"]
[Tue Aug 18 12:53:11.223516 2026] [security2:error] [pid 66623:tid 66692] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/wp-ws68.php"] [unique_id "aoR_59O5rbWdOArH04J3BQABXzc"]
[Tue Aug 18 12:53:11.238679 2026] [security2:error] [pid 66623:tid 66819] [client 20.171.51.14:29193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/pm.php"] [unique_id "aoR_59O5rbWdOArH04J3BwAAAT8"]
[Tue Aug 18 12:53:11.240284 2026] [security2:error] [pid 67073:tid 67227] [client 20.65.69.59:40378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/gy.php"] [unique_id "aoR_5_cmepr5_nHgLbMpZgAAAio"]
[Tue Aug 18 12:53:11.264672 2026] [security2:error] [pid 66623:tid 66885] [client 158.158.74.177:14258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/lite.php"] [unique_id "aoR_59O5rbWdOArH04J3CQAAAYE"]
[Tue Aug 18 12:53:11.277928 2026] [security2:error] [pid 67073:tid 67211] [client 52.139.47.57:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/rk2.php"] [unique_id "aoR_5_cmepr5_nHgLbMpZwAAAho"]
[Tue Aug 18 12:53:11.282064 2026] [security2:error] [pid 67073:tid 67228] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoR_5_cmepr5_nHgLbMpaAAAAis"]
[Tue Aug 18 12:53:11.318530 2026] [security2:error] [pid 67073:tid 67230] [client 20.151.109.219:20716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/eh.php"] [unique_id "aoR_5_cmepr5_nHgLbMpaQAAAi0"]
[Tue Aug 18 12:53:11.325691 2026] [security2:error] [pid 67073:tid 67229] [client 168.62.48.100:14828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/weozh.php"] [unique_id "aoR_5_cmepr5_nHgLbMpagAAAiw"]
[Tue Aug 18 12:53:11.328590 2026] [security2:error] [pid 66623:tid 66767] [client 20.91.215.254:20262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/filter.php"] [unique_id "aoR_59O5rbWdOArH04J3GQAAAQs"]
[Tue Aug 18 12:53:11.332738 2026] [autoindex:error] [pid 66623:tid 66882] [client 4.223.164.152:37301] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:11.340513 2026] [security2:error] [pid 66623:tid 66704] [remote 115.146.125.52:38466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tivinalili.com.br"] [uri "/wp-login.php"] [unique_id "aoR_59O5rbWdOArH04J3GgABcEM"]
[Tue Aug 18 12:53:11.341762 2026] [security2:error] [pid 66623:tid 66873] [client 52.238.210.254:10113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_59O5rbWdOArH04J3GwAAAXU"]
[Tue Aug 18 12:53:11.397084 2026] [security2:error] [pid 67073:tid 67209] [client 34.178.149.167:45876] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.blueorbit.com.br"] [uri "/trace.axd"] [unique_id "aoR_5_cmepr5_nHgLbMpawAAAhg"]
[Tue Aug 18 12:53:11.404687 2026] [security2:error] [pid 66623:tid 66668] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/yj09.php"] [unique_id "aoR_59O5rbWdOArH04J3JAABDh8"]
[Tue Aug 18 12:53:11.422794 2026] [security2:error] [pid 66623:tid 66852] [client 68.221.73.131:4828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/reviall.php"] [unique_id "aoR_59O5rbWdOArH04J3KAAAAWA"]
[Tue Aug 18 12:53:11.423463 2026] [security2:error] [pid 66623:tid 66705] [remote 162.43.94.44:53218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.94.43.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michelepamela.com.br"] [uri "/wp-login.php"] [unique_id "aoR_59O5rbWdOArH04J3JwABNUQ"]
[Tue Aug 18 12:53:11.426626 2026] [security2:error] [pid 67073:tid 67235] [client 20.104.100.201:40261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/thoms.php"] [unique_id "aoR_5_cmepr5_nHgLbMpbAAAAjI"]
[Tue Aug 18 12:53:11.432497 2026] [security2:error] [pid 66623:tid 66769] [client 20.119.58.187:14814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/about.php7"] [unique_id "aoR_59O5rbWdOArH04J3KQAAAQ0"]
[Tue Aug 18 12:53:11.458500 2026] [security2:error] [pid 66623:tid 66820] [client 74.248.18.37:62382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/log.php"] [unique_id "aoR_59O5rbWdOArH04J3LAAAAUA"]
[Tue Aug 18 12:53:11.458681 2026] [security2:error] [pid 67073:tid 67233] [client 20.42.19.40:2211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/av.php"] [unique_id "aoR_5_cmepr5_nHgLbMpbgAAAjA"]
[Tue Aug 18 12:53:11.464847 2026] [security2:error] [pid 67073:tid 67240] [client 52.173.121.69:17952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoR_5_cmepr5_nHgLbMpbwAAAjc"]
[Tue Aug 18 12:53:11.489805 2026] [security2:error] [pid 66623:tid 66840] [client 74.7.175.149:42912] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "caiosousamendes.adv.br"] [uri "/index.php"] [unique_id "aoR_5dO5rbWdOArH04J1zwABVBU"]
[Tue Aug 18 12:53:11.517246 2026] [security2:error] [pid 67073:tid 67244] [client 20.250.27.191:7397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/zoo2.php"] [unique_id "aoR_5_cmepr5_nHgLbMpcAAAAjs"]
[Tue Aug 18 12:53:11.522841 2026] [security2:error] [pid 67073:tid 67246] [client 172.182.200.96:14093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/zugvi.php"] [unique_id "aoR_5_cmepr5_nHgLbMpcQAAAj0"]
[Tue Aug 18 12:53:11.527243 2026] [security2:error] [pid 67073:tid 67247] [client 132.196.61.152:25695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/11.php"] [unique_id "aoR_5_cmepr5_nHgLbMpcgAAAj4"]
[Tue Aug 18 12:53:11.533911 2026] [security2:error] [pid 66623:tid 66856] [client 20.104.100.201:54070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/z43agz.php"] [unique_id "aoR_59O5rbWdOArH04J3QQAAAWQ"]
[Tue Aug 18 12:53:11.542198 2026] [security2:error] [pid 66623:tid 66804] [client 4.223.164.152:37301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-temp.php"] [unique_id "aoR_59O5rbWdOArH04J3QgAAATA"]
[Tue Aug 18 12:53:11.563639 2026] [security2:error] [pid 67073:tid 67248] [client 158.23.17.4:58412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/vd.php"] [unique_id "aoR_5_cmepr5_nHgLbMpcwAAAj8"]
[Tue Aug 18 12:53:11.564112 2026] [deflate:error] [pid 66623:tid 66821] (104)Connection reset by peer: [client 213.232.122.14:64419] AH10298: failed reading from PIPE bucket
[Tue Aug 18 12:53:11.582092 2026] [security2:error] [pid 66623:tid 66729] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/scxy.php"] [unique_id "aoR_59O5rbWdOArH04J3RwABKlw"]
[Tue Aug 18 12:53:11.609008 2026] [security2:error] [pid 67073:tid 67252] [client 168.62.48.100:14806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/rymmm.php"] [unique_id "aoR_5_cmepr5_nHgLbMpdAAAAkM"]
[Tue Aug 18 12:53:11.613879 2026] [security2:error] [pid 67073:tid 67255] [client 20.171.51.14:29210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ud.php"] [unique_id "aoR_5_cmepr5_nHgLbMpdQAAAkY"]
[Tue Aug 18 12:53:11.625057 2026] [security2:error] [pid 67073:tid 67256] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/xx.php"] [unique_id "aoR_5_cmepr5_nHgLbMpdgAAAkc"]
[Tue Aug 18 12:53:11.664706 2026] [security2:error] [pid 67073:tid 67257] [client 20.65.69.59:58416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/tt.php"] [unique_id "aoR_5_cmepr5_nHgLbMpdwAAAkg"]
[Tue Aug 18 12:53:11.676186 2026] [security2:error] [pid 67073:tid 67203] [remote 57.141.22.86:30824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_5_cmepr5_nHgLbMpeAACQX8"]
[Tue Aug 18 12:53:11.738770 2026] [security2:error] [pid 66623:tid 66753] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoR_59O5rbWdOArH04J3VQABg3Q"]
[Tue Aug 18 12:53:11.743661 2026] [security2:error] [pid 67073:tid 67268] [client 111.225.149.166:42678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gustavofrison.com.br"] [uri "/wp-content/uploads/2018/04/Bianca-Pereira-e-Marcos-Nascimento-400x284.jpg"] [unique_id "aoR_5_cmepr5_nHgLbMpegAAAlM"]
[Tue Aug 18 12:53:11.745439 2026] [security2:error] [pid 67073:tid 67269] [client 4.223.164.152:6891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/ms-edit.php"] [unique_id "aoR_5_cmepr5_nHgLbMpewAAAlQ"]
[Tue Aug 18 12:53:11.768001 2026] [security2:error] [pid 67073:tid 67077] [remote 108.167.161.133:41210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.161.167.108.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "m2mit.cloud"] [uri "/wp-login.php"] [unique_id "aoR_5_cmepr5_nHgLbMpfQACVgE"]
[Tue Aug 18 12:53:11.789330 2026] [security2:error] [pid 66623:tid 66825] [client 20.119.58.187:15339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/adminfuns.php7"] [unique_id "aoR_59O5rbWdOArH04J3WwAAAUU"]
[Tue Aug 18 12:53:11.825117 2026] [security2:error] [pid 67073:tid 67278] [client 132.196.61.152:25677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/File.php"] [unique_id "aoR_5_cmepr5_nHgLbMpfwAAAl0"]
[Tue Aug 18 12:53:11.837584 2026] [security2:error] [pid 66623:tid 66851] [client 68.155.154.236:65157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoR_59O5rbWdOArH04J3YQAAAV8"]
[Tue Aug 18 12:53:11.842132 2026] [security2:error] [pid 67073:tid 67280] [client 68.221.73.131:4367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/11.php"] [unique_id "aoR_5_cmepr5_nHgLbMpgAAAAl8"]
[Tue Aug 18 12:53:11.845766 2026] [security2:error] [pid 67073:tid 67281] [client 168.62.48.100:14784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/lddxs.php"] [unique_id "aoR_5_cmepr5_nHgLbMpgQAAAmA"]
[Tue Aug 18 12:53:11.894875 2026] [security2:error] [pid 66623:tid 66854] [client 34.178.149.167:45860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "www.blueorbit.com.br"] [uri "/.bash_history"] [unique_id "aoR_59O5rbWdOArH04J3ZAAAAWI"]
[Tue Aug 18 12:53:11.921312 2026] [security2:error] [pid 66623:tid 66682] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoR_59O5rbWdOArH04J3aAABIS0"]
[Tue Aug 18 12:53:11.925582 2026] [security2:error] [pid 67073:tid 67261] [client 158.158.74.177:13823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoR_5_cmepr5_nHgLbMphAAAAkw"]
[Tue Aug 18 12:53:11.928017 2026] [security2:error] [pid 66623:tid 66787] [client 20.48.236.86:65144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/images.php"] [unique_id "aoR_59O5rbWdOArH04J3aQAAAR8"]
[Tue Aug 18 12:53:11.967556 2026] [security2:error] [pid 66623:tid 66847] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/av.php"] [unique_id "aoR_59O5rbWdOArH04J3cQAAAVs"]
[Tue Aug 18 12:53:11.982493 2026] [security2:error] [pid 66623:tid 66882] [client 172.182.200.96:14207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wsrer.php"] [unique_id "aoR_59O5rbWdOArH04J3cwAAAX4"]
[Tue Aug 18 12:53:11.983290 2026] [security2:error] [pid 66623:tid 66868] [client 4.223.164.152:64698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoR_59O5rbWdOArH04J3dAAAAXA"]
[Tue Aug 18 12:53:11.993562 2026] [security2:error] [pid 67073:tid 67290] [client 20.250.27.191:7401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/org.php"] [unique_id "aoR_5_cmepr5_nHgLbMphQAAAmk"]
[Tue Aug 18 12:53:11.997147 2026] [security2:error] [pid 66623:tid 66824] [client 20.65.69.59:33319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/mq.php"] [unique_id "aoR_59O5rbWdOArH04J3dQAAAUQ"]
[Tue Aug 18 12:53:12.020731 2026] [security2:error] [pid 66623:tid 66781] [client 74.248.18.37:27654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ethosconsult.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoR_6NO5rbWdOArH04J3eQAAARk"]
[Tue Aug 18 12:53:12.032015 2026] [security2:error] [pid 66623:tid 66672] [remote 57.141.22.115:63770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_6NO5rbWdOArH04J3egABcSM"]
[Tue Aug 18 12:53:12.035055 2026] [security2:error] [pid 67073:tid 67080] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6Pcmepr5_nHgLbMphwACUQQ"]
[Tue Aug 18 12:53:12.035311 2026] [security2:error] [pid 67073:tid 67266] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6Pcmepr5_nHgLbMphwACUQQ"]
[Tue Aug 18 12:53:12.082899 2026] [security2:error] [pid 66623:tid 66679] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/blurbs.php"] [unique_id "aoR_6NO5rbWdOArH04J3ewABDio"]
[Tue Aug 18 12:53:12.091212 2026] [security2:error] [pid 67073:tid 67298] [client 168.62.48.100:14786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/zjggu.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpiwAAAnE"]
[Tue Aug 18 12:53:12.091711 2026] [security2:error] [pid 67073:tid 67270] [client 213.35.127.232:64631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpjAAAAlU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:12.097221 2026] [security2:error] [pid 66623:tid 66802] [client 74.248.18.37:62818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/lv.php"] [unique_id "aoR_6NO5rbWdOArH04J3fgAAAS4"]
[Tue Aug 18 12:53:12.099125 2026] [authz_core:error] [pid 66623:tid 66699] [remote 216.73.216.206:54798] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:12.099574 2026] [authz_core:error] [pid 66623:tid 66699] [remote 216.73.216.206:54798] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:12.099591 2026] [authz_core:error] [pid 66623:tid 66713] [remote 216.73.216.206:54798] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:12.100046 2026] [authz_core:error] [pid 66623:tid 66713] [remote 216.73.216.206:54798] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:12.144345 2026] [security2:error] [pid 66623:tid 66788] [client 132.196.61.152:38384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/fi22.php"] [unique_id "aoR_6NO5rbWdOArH04J3gAAAASA"]
[Tue Aug 18 12:53:12.154703 2026] [security2:error] [pid 67073:tid 67292] [client 20.119.58.187:15124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/ebs.php7"] [unique_id "aoR_6Pcmepr5_nHgLbMpjQAAAms"]
[Tue Aug 18 12:53:12.196916 2026] [security2:error] [pid 66623:tid 66873] [client 20.91.215.254:16666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/input.php"] [unique_id "aoR_6NO5rbWdOArH04J3gwAAAXU"]
[Tue Aug 18 12:53:12.235381 2026] [security2:error] [pid 66623:tid 66780] [client 20.100.169.31:15100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/atex1.php"] [unique_id "aoR_6NO5rbWdOArH04J3hQAAARg"]
[Tue Aug 18 12:53:12.243017 2026] [security2:error] [pid 67073:tid 67309] [client 4.223.164.152:6604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/222.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpjgAAAnw"]
[Tue Aug 18 12:53:12.264667 2026] [security2:error] [pid 66623:tid 66815] [client 4.232.151.198:20969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/666.php"] [unique_id "aoR_6NO5rbWdOArH04J3hwAAATs"]
[Tue Aug 18 12:53:12.272448 2026] [security2:error] [pid 67073:tid 67311] [client 172.202.39.151:46890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/01.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpjwAAAn4"]
[Tue Aug 18 12:53:12.275524 2026] [security2:error] [pid 66623:tid 66714] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/bajah.php"] [unique_id "aoR_6NO5rbWdOArH04J3iAABck0"]
[Tue Aug 18 12:53:12.291388 2026] [authz_core:error] [pid 66623:tid 66670] [remote 216.73.216.206:54798] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:12.291831 2026] [authz_core:error] [pid 66623:tid 66670] [remote 216.73.216.206:54798] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:12.295676 2026] [security2:error] [pid 66623:tid 66799] [client 68.221.73.131:4843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/File.php"] [unique_id "aoR_6NO5rbWdOArH04J3jQAAASs"]
[Tue Aug 18 12:53:12.300285 2026] [security2:error] [pid 66623:tid 66796] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/media.php"] [unique_id "aoR_6NO5rbWdOArH04J3jgAAASg"]
[Tue Aug 18 12:53:12.324850 2026] [security2:error] [pid 66623:tid 66891] [client 168.62.48.100:14787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/dlvqo.php"] [unique_id "aoR_6NO5rbWdOArH04J3kAAAAYc"]
[Tue Aug 18 12:53:12.402007 2026] [security2:error] [pid 66623:tid 66774] [client 20.250.27.191:7928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/imageskir.php"] [unique_id "aoR_6NO5rbWdOArH04J3lgAAARI"]
[Tue Aug 18 12:53:12.411049 2026] [security2:error] [pid 66623:tid 66877] [client 20.65.69.59:37102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/13.php"] [unique_id "aoR_6NO5rbWdOArH04J3mAAAAXk"]
[Tue Aug 18 12:53:12.422055 2026] [security2:error] [pid 67073:tid 67234] [client 20.100.169.31:12612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/simple.php"] [unique_id "aoR_6Pcmepr5_nHgLbMplQAAAjE"]
[Tue Aug 18 12:53:12.458057 2026] [security2:error] [pid 66623:tid 66861] [client 149.34.210.157:63776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_6NO5rbWdOArH04J3pAAAAWk"]
[Tue Aug 18 12:53:12.478006 2026] [security2:error] [pid 66623:tid 66709] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/domvf.php"] [unique_id "aoR_6NO5rbWdOArH04J3rAABhEg"]
[Tue Aug 18 12:53:12.508746 2026] [security2:error] [pid 67073:tid 67318] [client 20.119.58.187:15358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/ws.php7"] [unique_id "aoR_6Pcmepr5_nHgLbMplgAAAoU"]
[Tue Aug 18 12:53:12.512743 2026] [security2:error] [pid 67073:tid 67325] [client 20.104.100.201:53863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/3.php"] [unique_id "aoR_6Pcmepr5_nHgLbMplwAAAow"]
[Tue Aug 18 12:53:12.545402 2026] [security2:error] [pid 66623:tid 66833] [client 20.171.51.14:58839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ip.php"] [unique_id "aoR_6NO5rbWdOArH04J3swAAAU0"]
[Tue Aug 18 12:53:12.549771 2026] [security2:error] [pid 66623:tid 66812] [client 34.178.149.167:45924] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.blueorbit.com.br"] [uri "/.openclaw/openclaw.json"] [unique_id "aoR_6NO5rbWdOArH04J3tAAAATg"]
[Tue Aug 18 12:53:12.561620 2026] [security2:error] [pid 66623:tid 66801] [client 74.248.136.165:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/06.php"] [unique_id "aoR_6NO5rbWdOArH04J3uAAAAS0"]
[Tue Aug 18 12:53:12.564474 2026] [security2:error] [pid 67073:tid 67326] [client 4.223.164.152:37263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/puc.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpmAAAAo0"]
[Tue Aug 18 12:53:12.565931 2026] [security2:error] [pid 67073:tid 67327] [client 168.62.48.100:14799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/pkmoj.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpmQAAAo4"]
[Tue Aug 18 12:53:12.579670 2026] [security2:error] [pid 66623:tid 66803] [client 74.7.175.149:42924] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.caiosousamendes.adv.br"] [uri "/index.php"] [unique_id "aoR_6NO5rbWdOArH04J3rQABLxI"], referer: https://caiosousamendes.adv.br/robots.txt
[Tue Aug 18 12:53:12.580215 2026] [security2:error] [pid 66623:tid 66854] [client 132.196.61.152:7868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoR_6NO5rbWdOArH04J3vAAAAWI"]
[Tue Aug 18 12:53:12.624434 2026] [security2:error] [pid 67073:tid 67315] [client 158.158.74.177:13771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpnAAAAoI"]
[Tue Aug 18 12:53:12.636682 2026] [security2:error] [pid 66623:tid 66658] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/fpwch.php"] [unique_id "aoR_6NO5rbWdOArH04J3vwABWxU"]
[Tue Aug 18 12:53:12.644375 2026] [security2:error] [pid 67073:tid 67332] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/images.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpnQAAApM"]
[Tue Aug 18 12:53:12.659576 2026] [security2:error] [pid 67073:tid 67300] [client 74.249.206.207:58178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpngAAAnM"]
[Tue Aug 18 12:53:12.665636 2026] [security2:error] [pid 66623:tid 66845] [client 213.232.122.14:39897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "acpecasebaterias.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6NO5rbWdOArH04J3wwAAAVk"]
[Tue Aug 18 12:53:12.668533 2026] [security2:error] [pid 67073:tid 67301] [client 68.155.154.236:64448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpnwAAAnQ"]
[Tue Aug 18 12:53:12.670482 2026] [security2:error] [pid 66623:tid 66824] [client 172.182.200.96:14163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/ucpfr.php"] [unique_id "aoR_6NO5rbWdOArH04J3xQAAAUQ"]
[Tue Aug 18 12:53:12.687146 2026] [security2:error] [pid 67073:tid 67212] [client 4.223.164.152:6628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/cgi-bin/index.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpoAAAAhs"]
[Tue Aug 18 12:53:12.720341 2026] [security2:error] [pid 66623:tid 66841] [client 20.151.109.219:33502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/ad.php"] [unique_id "aoR_6NO5rbWdOArH04J3yAAAAVU"]
[Tue Aug 18 12:53:12.725349 2026] [security2:error] [pid 66623:tid 66861] [client 149.34.210.157:63776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_6NO5rbWdOArH04J3pAAAAWk"]
[Tue Aug 18 12:53:12.728830 2026] [security2:error] [pid 66623:tid 66776] [client 74.248.18.37:62355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/mah/function.php"] [unique_id "aoR_6NO5rbWdOArH04J3ygAAARQ"]
[Tue Aug 18 12:53:12.763341 2026] [security2:error] [pid 66623:tid 66793] [client 68.221.73.131:4379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/fi22.php"] [unique_id "aoR_6NO5rbWdOArH04J3zAAAASU"]
[Tue Aug 18 12:53:12.804043 2026] [security2:error] [pid 67073:tid 67207] [client 168.62.48.100:16268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/kopyw.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpoQAAAhY"]
[Tue Aug 18 12:53:12.831891 2026] [security2:error] [pid 67073:tid 67222] [client 20.250.27.191:58979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/indexo.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpogAAAiU"]
[Tue Aug 18 12:53:12.840200 2026] [security2:error] [pid 67073:tid 67223] [client 52.238.210.254:43656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/php8.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpowAAAiY"]
[Tue Aug 18 12:53:12.871124 2026] [security2:error] [pid 66623:tid 66878] [client 20.119.58.187:14599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/alfanew2.php7"] [unique_id "aoR_6NO5rbWdOArH04J30gAAAXo"]
[Tue Aug 18 12:53:12.884841 2026] [security2:error] [pid 66623:tid 66755] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/adminner.php"] [unique_id "aoR_6NO5rbWdOArH04J30wABgnY"]
[Tue Aug 18 12:53:12.912285 2026] [security2:error] [pid 67073:tid 67228] [client 20.104.100.201:56844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoR_6Pcmepr5_nHgLbMppAAAAis"]
[Tue Aug 18 12:53:12.943303 2026] [security2:error] [pid 66623:tid 66873] [client 132.196.61.152:38353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoR_6NO5rbWdOArH04J31QAAAXU"]
[Tue Aug 18 12:53:12.974634 2026] [security2:error] [pid 67073:tid 67209] [client 20.171.51.14:16744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/dr.php"] [unique_id "aoR_6Pcmepr5_nHgLbMppgAAAhg"]
[Tue Aug 18 12:53:12.983931 2026] [security2:error] [pid 67073:tid 67231] [client 20.48.236.86:65130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/admin.php"] [unique_id "aoR_6Pcmepr5_nHgLbMppwAAAi4"]
[Tue Aug 18 12:53:12.984871 2026] [security2:error] [pid 67073:tid 67232] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/mac.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpqAAAAi8"]
[Tue Aug 18 12:53:13.016920 2026] [security2:error] [pid 66623:tid 66809] [client 5.253.205.188:60996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/error_reportinstallmysql.sql"] [unique_id "aoR_6dO5rbWdOArH04J31wAAATU"], referer: https://medihub.com.br/error_reportinstallmysql.sql
[Tue Aug 18 12:53:13.038595 2026] [security2:error] [pid 67073:tid 67233] [client 168.62.48.100:16346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/zznmg.php"] [unique_id "aoR_6fcmepr5_nHgLbMpqgAAAjA"]
[Tue Aug 18 12:53:13.054660 2026] [autoindex:error] [pid 67073:tid 67240] [client 4.223.164.152:37271] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:13.060016 2026] [security2:error] [pid 66623:tid 66749] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/abcd.php"] [unique_id "aoR_6dO5rbWdOArH04J32QABMHA"]
[Tue Aug 18 12:53:13.087496 2026] [security2:error] [pid 67073:tid 67246] [client 104.209.144.33:32675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoR_6fcmepr5_nHgLbMprgAAAj0"]
[Tue Aug 18 12:53:13.104156 2026] [security2:error] [pid 66623:tid 66798] [client 20.171.51.14:58387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/99.php"] [unique_id "aoR_6dO5rbWdOArH04J32gAAASo"]
[Tue Aug 18 12:53:13.109984 2026] [security2:error] [pid 66623:tid 66802] [client 213.35.127.232:64854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoR_6dO5rbWdOArH04J32wAAAS4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:13.141808 2026] [security2:error] [pid 67073:tid 67254] [client 52.173.121.69:17972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoR_6fcmepr5_nHgLbMprwAAAkU"]
[Tue Aug 18 12:53:13.177916 2026] [security2:error] [pid 66623:tid 66836] [client 20.91.215.254:16676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/jquery.php"] [unique_id "aoR_6dO5rbWdOArH04J33gAAAVA"]
[Tue Aug 18 12:53:13.224380 2026] [security2:error] [pid 67073:tid 67262] [client 68.221.73.131:4844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoR_6fcmepr5_nHgLbMpswAAAk0"]
[Tue Aug 18 12:53:13.226418 2026] [security2:error] [pid 67073:tid 67247] [client 20.119.58.187:14604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/alfa-rex2.php7"] [unique_id "aoR_6fcmepr5_nHgLbMptAAAAj4"]
[Tue Aug 18 12:53:13.239489 2026] [security2:error] [pid 67073:tid 67267] [client 172.202.39.151:30180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/403.php"] [unique_id "aoR_6fcmepr5_nHgLbMpugAAAlI"]
[Tue Aug 18 12:53:13.239985 2026] [security2:error] [pid 67073:tid 67265] [client 132.196.61.152:38385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoR_6fcmepr5_nHgLbMpuwAAAlA"]
[Tue Aug 18 12:53:13.241499 2026] [security2:error] [pid 67073:tid 67268] [client 20.250.27.191:58995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoR_6fcmepr5_nHgLbMpvAAAAlM"]
[Tue Aug 18 12:53:13.241730 2026] [security2:error] [pid 67073:tid 67239] [client 158.158.74.177:13820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoR_6fcmepr5_nHgLbMpvQAAAjY"]
[Tue Aug 18 12:53:13.242127 2026] [security2:error] [pid 66623:tid 66729] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/simple.php"] [unique_id "aoR_6dO5rbWdOArH04J34AABblw"]
[Tue Aug 18 12:53:13.246772 2026] [security2:error] [pid 66623:tid 66805] [client 68.155.154.236:65196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoR_6dO5rbWdOArH04J34QAAATE"]
[Tue Aug 18 12:53:13.260958 2026] [security2:error] [pid 66623:tid 66774] [client 172.182.200.96:7642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/yxijx.php"] [unique_id "aoR_6dO5rbWdOArH04J34gAAARI"]
[Tue Aug 18 12:53:13.276096 2026] [security2:error] [pid 66623:tid 66814] [client 168.62.48.100:16365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/bhfnd.php"] [unique_id "aoR_6dO5rbWdOArH04J34wAAATo"]
[Tue Aug 18 12:53:13.299250 2026] [security2:error] [pid 67073:tid 67271] [client 20.65.69.59:59570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/so.php"] [unique_id "aoR_6fcmepr5_nHgLbMpvgAAAlY"]
[Tue Aug 18 12:53:13.322547 2026] [security2:error] [pid 66623:tid 66834] [client 34.178.149.167:45968] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.blueorbit.com.br"] [uri "/debug/default/view"] [unique_id "aoR_6dO5rbWdOArH04J36gAAAU4"]
[Tue Aug 18 12:53:13.330663 2026] [security2:error] [pid 66623:tid 66781] [client 196.12.128.158:52379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoR_6dO5rbWdOArH04J37AAAARk"]
[Tue Aug 18 12:53:13.330810 2026] [security2:error] [pid 66623:tid 66781] [client 196.12.128.158:52379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoR_6dO5rbWdOArH04J37AAAARk"]
[Tue Aug 18 12:53:13.330968 2026] [security2:error] [pid 67073:tid 67274] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/ops.php"] [unique_id "aoR_6fcmepr5_nHgLbMpvwAAAlk"]
[Tue Aug 18 12:53:13.342971 2026] [security2:error] [pid 67073:tid 67275] [client 4.223.164.152:6876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/BDKR28WP.php"] [unique_id "aoR_6fcmepr5_nHgLbMpwAAAAlo"]
[Tue Aug 18 12:53:13.392154 2026] [security2:error] [pid 67073:tid 67256] [client 74.248.18.37:62387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/makeasmtp.php"] [unique_id "aoR_6fcmepr5_nHgLbMpwQAAAkc"]
[Tue Aug 18 12:53:13.398900 2026] [security2:error] [pid 66623:tid 66764] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/wp-manager.php"] [unique_id "aoR_6dO5rbWdOArH04J37wABG38"]
[Tue Aug 18 12:53:13.441539 2026] [security2:error] [pid 67073:tid 67279] [client 20.104.100.201:53852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/log.php"] [unique_id "aoR_6fcmepr5_nHgLbMpwgAAAl4"]
[Tue Aug 18 12:53:13.489567 2026] [authz_core:error] [pid 66623:tid 66842] [client 34.178.149.167:45952] AH01630: client denied by server configuration: /home1/blueorbit/public_html/error_log
[Tue Aug 18 12:53:13.515161 2026] [security2:error] [pid 66623:tid 66888] [client 168.62.48.100:14792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/qfvqu.php"] [unique_id "aoR_6dO5rbWdOArH04J38wAAAYQ"]
[Tue Aug 18 12:53:13.516419 2026] [security2:error] [pid 67073:tid 67293] [client 4.223.164.152:37271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/8.php"] [unique_id "aoR_6fcmepr5_nHgLbMpwwAAAmw"]
[Tue Aug 18 12:53:13.534996 2026] [security2:error] [pid 66623:tid 66851] [client 104.209.144.33:25289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoR_6dO5rbWdOArH04J39wAAAV8"]
[Tue Aug 18 12:53:13.558326 2026] [security2:error] [pid 67073:tid 67270] [client 132.196.61.152:23808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoR_6fcmepr5_nHgLbMpxAAAAlU"]
[Tue Aug 18 12:53:13.581170 2026] [security2:error] [pid 67073:tid 67285] [client 20.119.58.187:15147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "aoR_6fcmepr5_nHgLbMpxQAAAmQ"]
[Tue Aug 18 12:53:13.604873 2026] [security2:error] [pid 66623:tid 66739] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/xiugai.php"] [unique_id "aoR_6dO5rbWdOArH04J3-QABNGY"]
[Tue Aug 18 12:53:13.631128 2026] [security2:error] [pid 67073:tid 67292] [client 20.171.51.14:33675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/er.php"] [unique_id "aoR_6fcmepr5_nHgLbMpxwAAAms"]
[Tue Aug 18 12:53:13.662076 2026] [security2:error] [pid 66623:tid 66885] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/coffexium.php"] [unique_id "aoR_6dO5rbWdOArH04J3-wAAAYE"]
[Tue Aug 18 12:53:13.663671 2026] [security2:error] [pid 67073:tid 67305] [client 68.221.73.131:4387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoR_6fcmepr5_nHgLbMpyQAAAng"]
[Tue Aug 18 12:53:13.674806 2026] [security2:error] [pid 67073:tid 67307] [client 172.182.200.96:14172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/zwlsv.php"] [unique_id "aoR_6fcmepr5_nHgLbMpywAAAno"]
[Tue Aug 18 12:53:13.678870 2026] [security2:error] [pid 67073:tid 67309] [client 20.250.27.191:8002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/8pyceeo.php"] [unique_id "aoR_6fcmepr5_nHgLbMpzAAAAnw"]
[Tue Aug 18 12:53:13.680637 2026] [security2:error] [pid 67073:tid 67295] [client 104.209.144.33:25297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/.cache/x.php"] [unique_id "aoR_6fcmepr5_nHgLbMpzQAAAm4"]
[Tue Aug 18 12:53:13.760704 2026] [security2:error] [pid 66623:tid 66639] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/wp-load.php"] [unique_id "aoR_6dO5rbWdOArH04J3_wABLwI"]
[Tue Aug 18 12:53:13.767896 2026] [deflate:error] [pid 66623:tid 66859] (104)Connection reset by peer: [client 213.232.122.14:15047] AH10298: failed reading from PIPE bucket
[Tue Aug 18 12:53:13.767907 2026] [security2:error] [pid 66623:tid 66854] [client 20.65.69.59:54607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/10.php"] [unique_id "aoR_6dO5rbWdOArH04J4AAAAAWI"]
[Tue Aug 18 12:53:13.768832 2026] [security2:error] [pid 66623:tid 66815] [client 20.100.169.31:16150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/edit-tags.php"] [unique_id "aoR_6dO5rbWdOArH04J4AQAAATs"]
[Tue Aug 18 12:53:13.776192 2026] [security2:error] [pid 67073:tid 67312] [client 168.62.48.100:16344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/oivcl.php"] [unique_id "aoR_6fcmepr5_nHgLbMpzwAAAn8"]
[Tue Aug 18 12:53:13.856992 2026] [security2:error] [pid 67073:tid 67316] [client 20.104.100.201:17386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/ohct.php"] [unique_id "aoR_6fcmepr5_nHgLbMp0QAAAoM"]
[Tue Aug 18 12:53:13.858691 2026] [security2:error] [pid 67073:tid 67304] [client 20.91.215.254:23681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/media-new.php"] [unique_id "aoR_6fcmepr5_nHgLbMp0gAAAnc"]
[Tue Aug 18 12:53:13.937754 2026] [security2:error] [pid 67073:tid 67306] [client 158.158.74.177:13752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/xmrlpc.php"] [unique_id "aoR_6fcmepr5_nHgLbMp1QAAAnk"]
[Tue Aug 18 12:53:13.943641 2026] [security2:error] [pid 67073:tid 67100] [remote 57.141.22.94:57546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_6fcmepr5_nHgLbMp1gACgRg"]
[Tue Aug 18 12:53:13.944183 2026] [security2:error] [pid 66623:tid 66789] [client 20.119.58.187:15135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "aoR_6dO5rbWdOArH04J4CgAAASE"]
[Tue Aug 18 12:53:13.952599 2026] [security2:error] [pid 66623:tid 66737] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/155.php"] [unique_id "aoR_6dO5rbWdOArH04J4CwABW2Q"]
[Tue Aug 18 12:53:14.006658 2026] [security2:error] [pid 67073:tid 67331] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoR_6vcmepr5_nHgLbMp1wAAApI"]
[Tue Aug 18 12:53:14.007994 2026] [security2:error] [pid 67073:tid 67332] [client 20.48.236.86:10797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/222.php"] [unique_id "aoR_6vcmepr5_nHgLbMp2QAAApM"]
[Tue Aug 18 12:53:14.022906 2026] [security2:error] [pid 67073:tid 67216] [client 168.62.48.100:16308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/zugvi.php"] [unique_id "aoR_6vcmepr5_nHgLbMp3AAAAh8"]
[Tue Aug 18 12:53:14.024307 2026] [security2:error] [pid 67073:tid 67300] [client 4.223.164.152:37281] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "veloxxprodutos.com.br"] [uri "/1.php"] [unique_id "aoR_6vcmepr5_nHgLbMp3QAAAnM"]
[Tue Aug 18 12:53:14.024981 2026] [security2:error] [pid 67073:tid 67300] [client 4.223.164.152:37281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/1.php"] [unique_id "aoR_6vcmepr5_nHgLbMp3QAAAnM"]
[Tue Aug 18 12:53:14.039709 2026] [security2:error] [pid 66623:tid 66786] [client 34.178.149.167:45824] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "www.blueorbit.com.br"] [uri "/server-info"] [unique_id "aoR_6tO5rbWdOArH04J4EAAAAR4"]
[Tue Aug 18 12:53:14.043087 2026] [security2:error] [pid 67073:tid 67313] [client 74.248.18.37:62376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/mass.php"] [unique_id "aoR_6vcmepr5_nHgLbMp3gAAAoA"]
[Tue Aug 18 12:53:14.062050 2026] [security2:error] [pid 67073:tid 67206] [client 4.232.151.198:28736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/ws54.php"] [unique_id "aoR_6vcmepr5_nHgLbMp3wAAAhU"]
[Tue Aug 18 12:53:14.083799 2026] [security2:error] [pid 66623:tid 66827] [client 20.171.51.14:29211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/qk.php"] [unique_id "aoR_6tO5rbWdOArH04J4FAAAAUc"]
[Tue Aug 18 12:53:14.094174 2026] [security2:error] [pid 66623:tid 66795] [client 20.250.27.191:8037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/.admin.php"] [unique_id "aoR_6tO5rbWdOArH04J4FQAAASc"]
[Tue Aug 18 12:53:14.103612 2026] [security2:error] [pid 66623:tid 66881] [client 34.178.149.167:45976] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.blueorbit.com.br"] [uri "/secrets.yml"] [unique_id "aoR_6tO5rbWdOArH04J4FgAAAX0"]
[Tue Aug 18 12:53:14.111187 2026] [security2:error] [pid 67073:tid 67214] [client 4.223.164.152:6868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wp.php"] [unique_id "aoR_6vcmepr5_nHgLbMp4AAAAh0"]
[Tue Aug 18 12:53:14.112696 2026] [security2:error] [pid 67073:tid 67217] [client 54.39.89.227:19642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "eccellenzaconsultoria.com.br"] [uri "/robots.txt"] [unique_id "aoR_6vcmepr5_nHgLbMp4QAAAiA"]
[Tue Aug 18 12:53:14.112794 2026] [security2:error] [pid 67073:tid 67217] [client 54.39.89.227:19642] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "eccellenzaconsultoria.com.br"] [uri "/robots.txt"] [unique_id "aoR_6vcmepr5_nHgLbMp4QAAAiA"]
[Tue Aug 18 12:53:14.118971 2026] [security2:error] [pid 67073:tid 67213] [client 132.196.61.152:45168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoR_6vcmepr5_nHgLbMp4gAAAhw"]
[Tue Aug 18 12:53:14.119497 2026] [security2:error] [pid 66623:tid 66793] [client 104.209.144.33:25286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoR_6tO5rbWdOArH04J4GAAAASU"]
[Tue Aug 18 12:53:14.127478 2026] [security2:error] [pid 66623:tid 66823] [client 213.35.127.232:65062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoR_6tO5rbWdOArH04J4GQAAAUM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:14.128756 2026] [security2:error] [pid 66623:tid 66770] [client 68.221.73.131:4853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoR_6tO5rbWdOArH04J4GgAAAQ4"]
[Tue Aug 18 12:53:14.130934 2026] [security2:error] [pid 67073:tid 67218] [client 20.151.109.219:36688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/vd.php"] [unique_id "aoR_6vcmepr5_nHgLbMp4wAAAiE"]
[Tue Aug 18 12:53:14.137580 2026] [security2:error] [pid 66623:tid 66830] [client 68.155.154.236:63912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoR_6tO5rbWdOArH04J4GwAAAUo"]
[Tue Aug 18 12:53:14.155522 2026] [security2:error] [pid 66623:tid 66682] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/index.php"] [unique_id "aoR_6tO5rbWdOArH04J4HQABhS0"]
[Tue Aug 18 12:53:14.178370 2026] [security2:error] [pid 67073:tid 67259] [client 74.248.18.37:50640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/155.php"] [unique_id "aoR_6vcmepr5_nHgLbMp5QAAAko"]
[Tue Aug 18 12:53:14.194154 2026] [security2:error] [pid 67073:tid 67211] [client 104.209.144.33:31276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoR_6vcmepr5_nHgLbMp5gAAAho"]
[Tue Aug 18 12:53:14.199088 2026] [security2:error] [pid 67073:tid 67228] [client 20.104.100.201:54025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/ot.php"] [unique_id "aoR_6vcmepr5_nHgLbMp5wAAAis"]
[Tue Aug 18 12:53:14.204916 2026] [security2:error] [pid 67073:tid 67328] [client 85.208.96.208:39408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1751683201/1753920000/"] [unique_id "aoR_6vcmepr5_nHgLbMp6AAAAo8"]
[Tue Aug 18 12:53:14.205098 2026] [security2:error] [pid 67073:tid 67328] [client 85.208.96.208:39408] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1751683201/1753920000/"] [unique_id "aoR_6vcmepr5_nHgLbMp6AAAAo8"]
[Tue Aug 18 12:53:14.211362 2026] [security2:error] [pid 67073:tid 67223] [client 192.141.172.134:50276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6vcmepr5_nHgLbMp6QAAAiY"]
[Tue Aug 18 12:53:14.211476 2026] [security2:error] [pid 67073:tid 67223] [client 192.141.172.134:50276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6vcmepr5_nHgLbMp6QAAAiY"]
[Tue Aug 18 12:53:14.233807 2026] [security2:error] [pid 67073:tid 67297] [client 197.184.64.235:41353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6vcmepr5_nHgLbMp6gAAAnA"]
[Tue Aug 18 12:53:14.233935 2026] [security2:error] [pid 67073:tid 67297] [client 197.184.64.235:41353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6vcmepr5_nHgLbMp6gAAAnA"]
[Tue Aug 18 12:53:14.259626 2026] [security2:error] [pid 67073:tid 67237] [client 168.62.48.100:16309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wsrer.php"] [unique_id "aoR_6vcmepr5_nHgLbMp6wAAAjQ"]
[Tue Aug 18 12:53:14.270935 2026] [security2:error] [pid 67073:tid 67236] [client 172.202.39.151:44479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/404.php"] [unique_id "aoR_6vcmepr5_nHgLbMp7AAAAjM"]
[Tue Aug 18 12:53:14.305223 2026] [security2:error] [pid 67073:tid 67225] [client 20.119.58.187:14644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/plugins/linkpreview/db.php"] [unique_id "aoR_6vcmepr5_nHgLbMp7QAAAig"]
[Tue Aug 18 12:53:14.321302 2026] [security2:error] [pid 66623:tid 66674] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/aaa.php"] [unique_id "aoR_6tO5rbWdOArH04J4IAABHSU"]
[Tue Aug 18 12:53:14.322073 2026] [security2:error] [pid 67073:tid 67241] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/aa.php"] [unique_id "aoR_6vcmepr5_nHgLbMp7gAAAjg"]
[Tue Aug 18 12:53:14.339389 2026] [security2:error] [pid 66623:tid 66840] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/sf.php"] [unique_id "aoR_6tO5rbWdOArH04J4IQAAAVQ"]
[Tue Aug 18 12:53:14.345563 2026] [security2:error] [pid 67073:tid 67249] [client 172.182.200.96:14188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/jrpga.php"] [unique_id "aoR_6vcmepr5_nHgLbMp7wAAAkA"]
[Tue Aug 18 12:53:14.348991 2026] [security2:error] [pid 66623:tid 66819] [client 20.100.169.31:28458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/class-t.api.php"] [unique_id "aoR_6tO5rbWdOArH04J4IgAAAT8"]
[Tue Aug 18 12:53:14.406759 2026] [security2:error] [pid 66623:tid 66798] [client 52.238.210.254:10151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/admin.php"] [unique_id "aoR_6tO5rbWdOArH04J4JAAAASo"]
[Tue Aug 18 12:53:14.419291 2026] [security2:error] [pid 67073:tid 67255] [client 132.196.61.152:38378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoR_6vcmepr5_nHgLbMp8AAAAkY"]
[Tue Aug 18 12:53:14.453682 2026] [security2:error] [pid 67073:tid 67258] [client 4.223.164.152:37250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/about.php"] [unique_id "aoR_6vcmepr5_nHgLbMp8QAAAkk"]
[Tue Aug 18 12:53:14.457809 2026] [security2:error] [pid 66623:tid 66791] [client 52.238.210.254:15921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/info.php"] [unique_id "aoR_6tO5rbWdOArH04J4JgAAASM"]
[Tue Aug 18 12:53:14.477635 2026] [security2:error] [pid 66623:tid 66654] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/FWAZ.php"] [unique_id "aoR_6tO5rbWdOArH04J4KAABNxE"]
[Tue Aug 18 12:53:14.500716 2026] [security2:error] [pid 66623:tid 66893] [client 52.139.47.57:18339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/storage/rip.php"] [unique_id "aoR_6tO5rbWdOArH04J4LQAAAYk"]
[Tue Aug 18 12:53:14.501631 2026] [security2:error] [pid 66623:tid 66805] [client 168.62.48.100:16294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/ucpfr.php"] [unique_id "aoR_6tO5rbWdOArH04J4LgAAATE"]
[Tue Aug 18 12:53:14.504104 2026] [security2:error] [pid 66623:tid 66792] [client 20.250.27.191:7386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/wsomini.php"] [unique_id "aoR_6tO5rbWdOArH04J4LwAAASQ"]
[Tue Aug 18 12:53:14.556362 2026] [security2:error] [pid 66623:tid 66884] [client 114.5.214.109:49791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6tO5rbWdOArH04J4MwAAAYA"]
[Tue Aug 18 12:53:14.556482 2026] [security2:error] [pid 66623:tid 66884] [client 114.5.214.109:49791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6tO5rbWdOArH04J4MwAAAYA"]
[Tue Aug 18 12:53:14.581797 2026] [security2:error] [pid 67073:tid 67239] [client 68.221.73.131:4316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoR_6vcmepr5_nHgLbMp8gAAAjY"]
[Tue Aug 18 12:53:14.585398 2026] [security2:error] [pid 67073:tid 67251] [client 158.158.74.177:13793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoR_6vcmepr5_nHgLbMp8wAAAkI"]
[Tue Aug 18 12:53:14.623625 2026] [security2:error] [pid 67073:tid 67222] [client 86.120.159.145:61122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6vcmepr5_nHgLbMp9AAAAiU"]
[Tue Aug 18 12:53:14.623807 2026] [security2:error] [pid 67073:tid 67222] [client 86.120.159.145:61122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6vcmepr5_nHgLbMp9AAAAiU"]
[Tue Aug 18 12:53:14.631361 2026] [access_compat:error] [pid 66623:tid 66883] [client 34.178.149.167:46052] AH01797: client denied by server configuration: /home1/blueorbit/public_html/server-status
[Tue Aug 18 12:53:14.659647 2026] [security2:error] [pid 66623:tid 66678] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/site.php"] [unique_id "aoR_6tO5rbWdOArH04J4NQABgSk"]
[Tue Aug 18 12:53:14.660839 2026] [security2:error] [pid 66623:tid 66826] [client 20.119.58.187:15352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoR_6tO5rbWdOArH04J4NgAAAUY"]
[Tue Aug 18 12:53:14.672841 2026] [security2:error] [pid 67073:tid 67256] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/k.php"] [unique_id "aoR_6vcmepr5_nHgLbMp9QAAAkc"]
[Tue Aug 18 12:53:14.687574 2026] [security2:error] [pid 67073:tid 67277] [client 20.104.100.201:57312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/root.php"] [unique_id "aoR_6vcmepr5_nHgLbMp9gAAAlw"]
[Tue Aug 18 12:53:14.695485 2026] [security2:error] [pid 66623:tid 66836] [client 74.248.18.37:62364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/memberfuns.php"] [unique_id "aoR_6tO5rbWdOArH04J4OAAAAVA"]
[Tue Aug 18 12:53:14.719260 2026] [security2:error] [pid 67073:tid 67288] [client 20.171.51.14:59279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/fraie1p4.php"] [unique_id "aoR_6vcmepr5_nHgLbMp-QAAAmc"]
[Tue Aug 18 12:53:14.720826 2026] [security2:error] [pid 67073:tid 67293] [client 20.104.100.201:17345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/v5.php"] [unique_id "aoR_6vcmepr5_nHgLbMp-gAAAmw"]
[Tue Aug 18 12:53:14.743337 2026] [security2:error] [pid 66623:tid 66815] [client 104.209.144.33:31291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/index.php"] [unique_id "aoR_6tO5rbWdOArH04J4OQAAATs"]
[Tue Aug 18 12:53:14.743988 2026] [security2:error] [pid 66623:tid 66800] [client 104.209.144.33:32684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoR_6tO5rbWdOArH04J4OgAAASw"]
[Tue Aug 18 12:53:14.747801 2026] [security2:error] [pid 66623:tid 66787] [client 168.62.48.100:14749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/yxijx.php"] [unique_id "aoR_6tO5rbWdOArH04J4OwAAAR8"]
[Tue Aug 18 12:53:14.792180 2026] [security2:error] [pid 66623:tid 66849] [client 4.223.164.152:6896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/i.php"] [unique_id "aoR_6tO5rbWdOArH04J4PgAAAV0"]
[Tue Aug 18 12:53:14.802686 2026] [security2:error] [pid 67073:tid 67302] [client 132.196.61.152:38375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/media.php"] [unique_id "aoR_6vcmepr5_nHgLbMp_AAAAnU"]
[Tue Aug 18 12:53:14.836247 2026] [security2:error] [pid 66623:tid 66837] [client 68.155.154.236:63920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoR_6tO5rbWdOArH04J4QAAAAVE"]
[Tue Aug 18 12:53:14.843010 2026] [security2:error] [pid 66623:tid 66708] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/ccc.php"] [unique_id "aoR_6tO5rbWdOArH04J4QQABR0c"]
[Tue Aug 18 12:53:14.875065 2026] [security2:error] [pid 66623:tid 66861] [client 20.42.19.40:2198] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-admin"] [unique_id "aoR_6tO5rbWdOArH04J4RAAAAWk"]
[Tue Aug 18 12:53:14.877966 2026] [security2:error] [pid 67073:tid 67276] [client 20.91.215.254:16652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoR_6vcmepr5_nHgLbMp_gAAAls"]
[Tue Aug 18 12:53:14.887305 2026] [security2:error] [pid 67073:tid 67267] [client 213.232.122.14:39363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "acpecasebaterias.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6vcmepr5_nHgLbMp_wAAAlI"]
[Tue Aug 18 12:53:14.903731 2026] [security2:error] [pid 67073:tid 67209] [client 5.31.227.224:7869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6vcmepr5_nHgLbMqAAAAAhg"]
[Tue Aug 18 12:53:14.912368 2026] [security2:error] [pid 66623:tid 66793] [client 20.250.27.191:58973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/vr.php"] [unique_id "aoR_6tO5rbWdOArH04J4RQAAASU"]
[Tue Aug 18 12:53:14.916567 2026] [security2:error] [pid 67073:tid 67209] [client 5.31.227.224:7869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6vcmepr5_nHgLbMqAAAAAhg"]
[Tue Aug 18 12:53:14.918741 2026] [security2:error] [pid 67073:tid 67278] [client 20.100.169.31:28477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/u.php"] [unique_id "aoR_6vcmepr5_nHgLbMqAgAAAl0"]
[Tue Aug 18 12:53:14.942856 2026] [security2:error] [pid 67073:tid 67283] [client 4.223.164.152:37265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/admin.php"] [unique_id "aoR_6vcmepr5_nHgLbMqAwAAAmI"]
[Tue Aug 18 12:53:14.943170 2026] [security2:error] [pid 67073:tid 67294] [client 52.173.121.69:16448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/first.php"] [unique_id "aoR_6vcmepr5_nHgLbMqBAAAAm0"]
[Tue Aug 18 12:53:14.984234 2026] [security2:error] [pid 67073:tid 67289] [client 168.62.48.100:14734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/zwlsv.php"] [unique_id "aoR_6vcmepr5_nHgLbMqBgAAAmg"]
[Tue Aug 18 12:53:15.011879 2026] [security2:error] [pid 67073:tid 67321] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/82.php"] [unique_id "aoR_6_cmepr5_nHgLbMqCAAAAog"]
[Tue Aug 18 12:53:15.014059 2026] [security2:error] [pid 66623:tid 66881] [client 20.119.58.187:14611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/plugins/seoplugins/db.php"] [unique_id "aoR_69O5rbWdOArH04J4SQAAAX0"]
[Tue Aug 18 12:53:15.022033 2026] [security2:error] [pid 67073:tid 67322] [client 20.48.236.86:65103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/mac.php"] [unique_id "aoR_6_cmepr5_nHgLbMqCQAAAok"]
[Tue Aug 18 12:53:15.082305 2026] [security2:error] [pid 66623:tid 66809] [client 68.221.73.131:4315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoR_69O5rbWdOArH04J4TAAAATU"]
[Tue Aug 18 12:53:15.087304 2026] [security2:error] [pid 67073:tid 67325] [client 20.104.100.201:53865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoR_6_cmepr5_nHgLbMqCgAAAow"]
[Tue Aug 18 12:53:15.115912 2026] [security2:error] [pid 66623:tid 66656] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/admin.php"] [unique_id "aoR_69O5rbWdOArH04J4TQABKxM"]
[Tue Aug 18 12:53:15.117047 2026] [security2:error] [pid 66623:tid 66852] [client 138.36.100.162:42749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_69O5rbWdOArH04J4TgAAAWA"]
[Tue Aug 18 12:53:15.117185 2026] [security2:error] [pid 66623:tid 66852] [client 138.36.100.162:42749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_69O5rbWdOArH04J4TgAAAWA"]
[Tue Aug 18 12:53:15.145585 2026] [security2:error] [pid 67073:tid 67292] [client 213.35.127.232:65281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoR_6_cmepr5_nHgLbMqDAAAAms"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:15.195435 2026] [security2:error] [pid 66623:tid 66794] [client 20.42.19.40:2207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp.php"] [unique_id "aoR_69O5rbWdOArH04J4VQAAASY"]
[Tue Aug 18 12:53:15.218825 2026] [security2:error] [pid 67073:tid 67281] [client 4.232.151.198:16328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/deepseek_d.php"] [unique_id "aoR_6_cmepr5_nHgLbMqDgAAAmA"]
[Tue Aug 18 12:53:15.222233 2026] [security2:error] [pid 67073:tid 67300] [client 168.62.48.100:14823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/jrpga.php"] [unique_id "aoR_6_cmepr5_nHgLbMqDwAAAnM"]
[Tue Aug 18 12:53:15.248055 2026] [security2:error] [pid 66623:tid 66844] [client 135.136.0.233:62982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.0.136.135.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoR_69O5rbWdOArH04J4WAAAAVg"]
[Tue Aug 18 12:53:15.248255 2026] [security2:error] [pid 66623:tid 66844] [client 135.136.0.233:62982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoR_69O5rbWdOArH04J4WAAAAVg"]
[Tue Aug 18 12:53:15.300843 2026] [security2:error] [pid 67073:tid 67206] [client 132.196.61.152:38379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/inso.php"] [unique_id "aoR_6_cmepr5_nHgLbMqEAAAAhU"]
[Tue Aug 18 12:53:15.318253 2026] [autoindex:error] [pid 67073:tid 67331] [client 205.210.31.41:57612] AH01276: Cannot serve directory /home4/ejsserralheriasp/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:15.320201 2026] [security2:error] [pid 66623:tid 66649] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/reviall.php"] [unique_id "aoR_69O5rbWdOArH04J4XQABVgw"]
[Tue Aug 18 12:53:15.328102 2026] [security2:error] [pid 67073:tid 67314] [client 74.248.18.37:62386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/meta.php"] [unique_id "aoR_6_cmepr5_nHgLbMqEgAAAoE"]
[Tue Aug 18 12:53:15.350076 2026] [security2:error] [pid 66623:tid 66880] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/dex.php"] [unique_id "aoR_69O5rbWdOArH04J4XgAAAXw"]
[Tue Aug 18 12:53:15.358827 2026] [security2:error] [pid 66623:tid 66890] [client 68.155.154.236:64542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/rezor.php"] [unique_id "aoR_69O5rbWdOArH04J4XwAAAYY"]
[Tue Aug 18 12:53:15.369544 2026] [security2:error] [pid 66623:tid 66878] [client 20.119.58.187:15303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/plugins/seoplugins/mar.php"] [unique_id "aoR_69O5rbWdOArH04J4YAAAAXo"]
[Tue Aug 18 12:53:15.425082 2026] [security2:error] [pid 67073:tid 67218] [client 4.223.164.152:37294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/edit.php"] [unique_id "aoR_6_cmepr5_nHgLbMqFAAAAiE"]
[Tue Aug 18 12:53:15.442207 2026] [security2:error] [pid 66623:tid 66812] [client 74.249.206.207:29676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoR_69O5rbWdOArH04J4YgAAATg"]
[Tue Aug 18 12:53:15.454125 2026] [security2:error] [pid 66623:tid 66801] [client 20.104.100.201:53828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoR_69O5rbWdOArH04J4YwAAAS0"]
[Tue Aug 18 12:53:15.456890 2026] [security2:error] [pid 67073:tid 67226] [client 168.62.48.100:16367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/museu/yhweq.php"] [unique_id "aoR_6_cmepr5_nHgLbMqFQAAAik"]
[Tue Aug 18 12:53:15.471021 2026] [security2:error] [pid 66623:tid 66846] [client 20.171.51.14:62520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ts.php"] [unique_id "aoR_69O5rbWdOArH04J4ZAAAAVo"]
[Tue Aug 18 12:53:15.478666 2026] [security2:error] [pid 66623:tid 66719] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/nope.php"] [unique_id "aoR_69O5rbWdOArH04J4ZQABblI"]
[Tue Aug 18 12:53:15.513305 2026] [security2:error] [pid 66623:tid 66854] [client 68.221.73.131:4826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoR_69O5rbWdOArH04J4aAAAAWI"]
[Tue Aug 18 12:53:15.520231 2026] [security2:error] [pid 66623:tid 66800] [client 158.158.74.177:14225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/ku.php"] [unique_id "aoR_69O5rbWdOArH04J4aQAAASw"]
[Tue Aug 18 12:53:15.559371 2026] [security2:error] [pid 67073:tid 67217] [client 20.91.215.254:22949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-admin/images/moon.php"] [unique_id "aoR_6_cmepr5_nHgLbMqFwAAAiA"]
[Tue Aug 18 12:53:15.573430 2026] [security2:error] [pid 67073:tid 67216] [client 74.248.18.37:47496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/96i.php"] [unique_id "aoR_6_cmepr5_nHgLbMqGAAAAh8"]
[Tue Aug 18 12:53:15.575877 2026] [security2:error] [pid 67073:tid 67230] [client 20.104.100.201:56889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/fpwch.php"] [unique_id "aoR_6_cmepr5_nHgLbMqGQAAAi0"]
[Tue Aug 18 12:53:15.587138 2026] [security2:error] [pid 67073:tid 67297] [client 51.222.168.251:61932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "eccellenzaconsultoria.com.br"] [uri "/"] [unique_id "aoR_6_cmepr5_nHgLbMqGgAAAnA"]
[Tue Aug 18 12:53:15.587258 2026] [security2:error] [pid 67073:tid 67297] [client 51.222.168.251:61932] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "eccellenzaconsultoria.com.br"] [uri "/"] [unique_id "aoR_6_cmepr5_nHgLbMqGgAAAnA"]
[Tue Aug 18 12:53:15.588812 2026] [security2:error] [pid 66623:tid 66849] [client 40.85.222.29:29235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/Cachex.php"] [unique_id "aoR_69O5rbWdOArH04J4bgAAAV0"]
[Tue Aug 18 12:53:15.595947 2026] [security2:error] [pid 67073:tid 67303] [client 4.223.164.152:7041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/abcd.php"] [unique_id "aoR_6_cmepr5_nHgLbMqGwAAAnY"]
[Tue Aug 18 12:53:15.640937 2026] [security2:error] [pid 66623:tid 66660] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/nope.php"] [unique_id "aoR_69O5rbWdOArH04J4cQABJxc"]
[Tue Aug 18 12:53:15.661279 2026] [security2:error] [pid 66623:tid 66861] [client 132.196.61.152:25679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/shiny.php"] [unique_id "aoR_69O5rbWdOArH04J4cgAAAWk"]
[Tue Aug 18 12:53:15.692424 2026] [security2:error] [pid 66623:tid 66823] [client 168.62.48.100:14839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/nwwha.php"] [unique_id "aoR_69O5rbWdOArH04J4dAAAAUM"]
[Tue Aug 18 12:53:15.717266 2026] [security2:error] [pid 66623:tid 66830] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/puc.php"] [unique_id "aoR_69O5rbWdOArH04J4dQAAAUo"]
[Tue Aug 18 12:53:15.725828 2026] [security2:error] [pid 66623:tid 66786] [client 20.119.58.187:15298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoR_69O5rbWdOArH04J4dgAAAR4"]
[Tue Aug 18 12:53:15.764052 2026] [security2:error] [pid 67073:tid 67238] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-mail.php"] [unique_id "aoR_6_cmepr5_nHgLbMqHAAAAjU"]
[Tue Aug 18 12:53:15.771157 2026] [security2:error] [pid 67073:tid 67233] [client 20.171.51.14:28837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/fs.php"] [unique_id "aoR_6_cmepr5_nHgLbMqHQAAAjA"]
[Tue Aug 18 12:53:15.780982 2026] [authz_core:error] [pid 66623:tid 66684] [remote 57.141.22.30:36034] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:15.781440 2026] [authz_core:error] [pid 66623:tid 66684] [remote 57.141.22.30:36034] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:15.808552 2026] [security2:error] [pid 66623:tid 66667] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/new.php"] [unique_id "aoR_69O5rbWdOArH04J4eQABHR4"]
[Tue Aug 18 12:53:15.886050 2026] [security2:error] [pid 67073:tid 67112] [remote 57.141.22.21:50242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_6_cmepr5_nHgLbMqHwACMyQ"]
[Tue Aug 18 12:53:15.910564 2026] [security2:error] [pid 67073:tid 67244] [client 20.48.236.86:10662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/ops.php"] [unique_id "aoR_6_cmepr5_nHgLbMqIAAAAjs"]
[Tue Aug 18 12:53:15.944043 2026] [security2:error] [pid 67073:tid 67257] [client 4.223.164.152:37252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoR_6_cmepr5_nHgLbMqIQAAAkg"]
[Tue Aug 18 12:53:15.948911 2026] [security2:error] [pid 66623:tid 66852] [client 168.62.48.100:16283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/opsqt.php"] [unique_id "aoR_69O5rbWdOArH04J4fQAAAWA"]
[Tue Aug 18 12:53:15.961290 2026] [security2:error] [pid 66623:tid 66821] [client 20.171.51.14:58856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/53.php"] [unique_id "aoR_69O5rbWdOArH04J4fgAAAUE"]
[Tue Aug 18 12:53:15.964409 2026] [security2:error] [pid 67073:tid 67224] [client 74.248.18.37:62795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/mini.php"] [unique_id "aoR_6_cmepr5_nHgLbMqIgAAAic"]
[Tue Aug 18 12:53:15.969160 2026] [security2:error] [pid 67073:tid 67258] [client 20.42.19.40:2226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/file2.php"] [unique_id "aoR_6_cmepr5_nHgLbMqIwAAAkk"]
[Tue Aug 18 12:53:15.983482 2026] [security2:error] [pid 66623:tid 66734] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/new.php"] [unique_id "aoR_69O5rbWdOArH04J4gQABh2E"]
[Tue Aug 18 12:53:15.989691 2026] [security2:error] [pid 66623:tid 66856] [client 132.196.61.152:44447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/403dd.php"] [unique_id "aoR_69O5rbWdOArH04J4ggAAAWQ"]
[Tue Aug 18 12:53:16.014692 2026] [security2:error] [pid 67073:tid 67247] [client 68.221.73.131:4339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/media.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqJQAAAj4"]
[Tue Aug 18 12:53:16.021730 2026] [security2:error] [pid 66623:tid 66790] [client 103.184.169.37:40949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_7NO5rbWdOArH04J4gwAAASI"]
[Tue Aug 18 12:53:16.021891 2026] [security2:error] [pid 66623:tid 66790] [client 103.184.169.37:40949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_7NO5rbWdOArH04J4gwAAASI"]
[Tue Aug 18 12:53:16.023684 2026] [security2:error] [pid 66623:tid 66767] [client 68.155.154.236:65099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoR_7NO5rbWdOArH04J4hAAAAQs"]
[Tue Aug 18 12:53:16.042864 2026] [security2:error] [pid 67073:tid 67265] [client 104.209.144.33:25307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqJwAAAlA"]
[Tue Aug 18 12:53:16.048328 2026] [deflate:error] [pid 66623:tid 66841] (104)Connection reset by peer: [client 213.232.122.14:19397] AH10298: failed reading from PIPE bucket
[Tue Aug 18 12:53:16.058584 2026] [security2:error] [pid 66623:tid 66773] [client 104.209.144.33:24884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoR_7NO5rbWdOArH04J4hwAAARE"]
[Tue Aug 18 12:53:16.060631 2026] [security2:error] [pid 66623:tid 66794] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/inso.php"] [unique_id "aoR_7NO5rbWdOArH04J4iAAAASY"]
[Tue Aug 18 12:53:16.090499 2026] [security2:error] [pid 67073:tid 67250] [client 20.119.58.187:15356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/.well-known/acme-challenge/xmrlpc.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqKAAAAkE"]
[Tue Aug 18 12:53:16.136681 2026] [security2:error] [pid 66623:tid 66877] [client 52.238.210.254:10125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/edit.php"] [unique_id "aoR_7NO5rbWdOArH04J4iwAAAXk"]
[Tue Aug 18 12:53:16.140068 2026] [security2:error] [pid 66623:tid 66814] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/bolt.php"] [unique_id "aoR_7NO5rbWdOArH04J4jAAAATo"]
[Tue Aug 18 12:53:16.142439 2026] [security2:error] [pid 66623:tid 66754] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/apreset.php"] [unique_id "aoR_7NO5rbWdOArH04J4jQABGXU"]
[Tue Aug 18 12:53:16.154059 2026] [security2:error] [pid 67073:tid 67242] [client 20.104.100.201:58402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/mg.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqKQAAAjk"]
[Tue Aug 18 12:53:16.159672 2026] [security2:error] [pid 67073:tid 67249] [client 213.35.127.232:65488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqKgAAAkA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:16.186375 2026] [security2:error] [pid 67073:tid 67275] [client 168.62.48.100:16301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/jvcpa.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqKwAAAlo"]
[Tue Aug 18 12:53:16.186702 2026] [security2:error] [pid 66623:tid 66829] [client 20.104.100.201:17373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/dk.php"] [unique_id "aoR_7NO5rbWdOArH04J4jwAAAUk"]
[Tue Aug 18 12:53:16.196139 2026] [security2:error] [pid 66623:tid 66888] [client 20.100.169.31:28447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/w.php"] [unique_id "aoR_7NO5rbWdOArH04J4kQAAAYQ"]
[Tue Aug 18 12:53:16.244658 2026] [security2:error] [pid 66623:tid 66784] [client 4.223.164.152:6866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wp-manager.php"] [unique_id "aoR_7NO5rbWdOArH04J4kwAAARw"]
[Tue Aug 18 12:53:16.250637 2026] [security2:error] [pid 67073:tid 67110] [remote 47.86.33.52:10068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wrtech.com.br"] [uri "/wp-login.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqLQACjyI"]
[Tue Aug 18 12:53:16.266511 2026] [security2:error] [pid 66623:tid 66839] [client 74.248.136.165:1908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/166.php"] [unique_id "aoR_7NO5rbWdOArH04J4lgAAAVM"]
[Tue Aug 18 12:53:16.273979 2026] [security2:error] [pid 67073:tid 67268] [client 132.196.61.152:7343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/baba.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqLgAAAlM"]
[Tue Aug 18 12:53:16.299956 2026] [security2:error] [pid 66623:tid 66745] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/1mage.php"] [unique_id "aoR_7NO5rbWdOArH04J4lwABd2w"]
[Tue Aug 18 12:53:16.346465 2026] [security2:error] [pid 66623:tid 66778] [client 20.91.215.254:23683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-admin/import.php"] [unique_id "aoR_7NO5rbWdOArH04J4nQAAARY"]
[Tue Aug 18 12:53:16.364974 2026] [security2:error] [pid 67073:tid 67271] [client 4.223.164.152:37300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/inputs.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqLwAAAlY"]
[Tue Aug 18 12:53:16.407560 2026] [security2:error] [pid 66623:tid 66846] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/aa.php"] [unique_id "aoR_7NO5rbWdOArH04J4nwAAAVo"]
[Tue Aug 18 12:53:16.412188 2026] [security2:error] [pid 67073:tid 67309] [client 158.158.74.177:14213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/chosen.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqMAAAAnw"]
[Tue Aug 18 12:53:16.419955 2026] [security2:error] [pid 67073:tid 67267] [client 20.171.51.14:59285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/rb.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqMQAAAlI"]
[Tue Aug 18 12:53:16.432926 2026] [security2:error] [pid 67073:tid 67209] [client 168.62.48.100:16298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqMgAAAhg"]
[Tue Aug 18 12:53:16.440221 2026] [security2:error] [pid 67073:tid 67111] [remote 46.62.208.238:39104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.208.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/wp-login.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqMwACWSM"]
[Tue Aug 18 12:53:16.443064 2026] [security2:error] [pid 67073:tid 67278] [client 68.221.73.131:4842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/inso.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqNAAAAl0"]
[Tue Aug 18 12:53:16.449541 2026] [security2:error] [pid 67073:tid 67264] [client 20.119.58.187:15133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqNgAAAk8"]
[Tue Aug 18 12:53:16.476863 2026] [security2:error] [pid 66623:tid 66677] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/imsc.php"] [unique_id "aoR_7NO5rbWdOArH04J4oQABLyg"]
[Tue Aug 18 12:53:16.512582 2026] [security2:error] [pid 67073:tid 67312] [client 20.171.51.14:62476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/lq.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqOAAAAn8"]
[Tue Aug 18 12:53:16.527960 2026] [security2:error] [pid 66623:tid 66865] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/bthil.php"] [unique_id "aoR_7NO5rbWdOArH04J4owAAAW0"]
[Tue Aug 18 12:53:16.561276 2026] [security2:error] [pid 67073:tid 67234] [client 132.196.61.152:44440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/site.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqOgAAAjE"]
[Tue Aug 18 12:53:16.565075 2026] [security2:error] [pid 66623:tid 66847] [client 172.202.39.151:28096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/gecko.php"] [unique_id "aoR_7NO5rbWdOArH04J4pAAAAVs"]
[Tue Aug 18 12:53:16.569174 2026] [security2:error] [pid 66623:tid 66783] [client 74.248.18.37:43387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/as.php"] [unique_id "aoR_7NO5rbWdOArH04J4pQAAARs"]
[Tue Aug 18 12:53:16.629786 2026] [security2:error] [pid 67073:tid 67276] [client 74.248.18.37:62845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/mm.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqOwAAAls"]
[Tue Aug 18 12:53:16.636638 2026] [security2:error] [pid 67073:tid 67292] [client 74.249.206.207:59602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqPAAAAms"]
[Tue Aug 18 12:53:16.657366 2026] [security2:error] [pid 67073:tid 67254] [client 216.73.160.114:50713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ondaparaty.com"] [uri "/wp-login.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqNwAAAkU"]
[Tue Aug 18 12:53:16.667808 2026] [security2:error] [pid 67073:tid 67330] [client 168.62.48.100:16360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqPQAAApE"]
[Tue Aug 18 12:53:16.772636 2026] [security2:error] [pid 67073:tid 67300] [client 20.100.177.66:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.danielimoveispva.com.br"] [uri "/1.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqPwAAAnM"]
[Tue Aug 18 12:53:16.772760 2026] [security2:error] [pid 67073:tid 67300] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/1.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqPwAAAnM"]
[Tue Aug 18 12:53:16.777808 2026] [security2:error] [pid 66623:tid 66815] [client 4.232.151.198:28765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/function/function.php"] [unique_id "aoR_7NO5rbWdOArH04J4qgAAATs"]
[Tue Aug 18 12:53:16.825552 2026] [security2:error] [pid 66623:tid 66729] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/imscjpg.php"] [unique_id "aoR_7NO5rbWdOArH04J4qwABJVw"]
[Tue Aug 18 12:53:16.826062 2026] [security2:error] [pid 67073:tid 67206] [client 52.238.210.254:27632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/chosen.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqQQAAAhU"]
[Tue Aug 18 12:53:16.843554 2026] [security2:error] [pid 66623:tid 66869] [client 172.182.200.96:14138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/museu/yhweq.php"] [unique_id "aoR_7NO5rbWdOArH04J4rAAAAXE"]
[Tue Aug 18 12:53:16.850368 2026] [security2:error] [pid 67073:tid 67272] [client 20.119.58.187:14616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/xmrlpc.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqQgAAAlc"]
[Tue Aug 18 12:53:16.871660 2026] [security2:error] [pid 66623:tid 66769] [client 132.196.61.152:23848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/wp-admin/maint/index.php"] [unique_id "aoR_7NO5rbWdOArH04J4swAAAQ0"]
[Tue Aug 18 12:53:16.885727 2026] [security2:error] [pid 67073:tid 67314] [client 4.223.164.152:6905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqQwAAAoE"]
[Tue Aug 18 12:53:16.895049 2026] [security2:error] [pid 67073:tid 67212] [client 104.209.144.33:32692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqRAAAAhs"]
[Tue Aug 18 12:53:16.897776 2026] [security2:error] [pid 66623:tid 66868] [client 4.223.164.152:54212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/av.php"] [unique_id "aoR_7NO5rbWdOArH04J4vgAAAXA"]
[Tue Aug 18 12:53:16.900505 2026] [security2:error] [pid 66623:tid 66785] [client 168.62.48.100:16341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoR_7NO5rbWdOArH04J4vwAAAR0"]
[Tue Aug 18 12:53:16.920972 2026] [security2:error] [pid 66623:tid 66873] [client 20.104.85.180:43580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_7NO5rbWdOArH04J4wAAAAXU"]
[Tue Aug 18 12:53:16.927864 2026] [security2:error] [pid 67073:tid 67214] [client 68.221.73.131:4332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/shiny.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqRQAAAh0"]
[Tue Aug 18 12:53:16.953507 2026] [security2:error] [pid 67073:tid 67213] [client 52.173.121.69:50731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/.cache/x.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqRgAAAhw"]
[Tue Aug 18 12:53:16.956523 2026] [security2:error] [pid 67073:tid 67207] [client 68.155.154.236:63393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqRwAAAhY"]
[Tue Aug 18 12:53:16.961004 2026] [security2:error] [pid 66623:tid 66768] [client 20.104.100.201:54078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/bal.php"] [unique_id "aoR_7NO5rbWdOArH04J4wgAAAQw"]
[Tue Aug 18 12:53:16.977117 2026] [security2:error] [pid 67073:tid 67217] [client 20.171.51.14:33706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/37.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqSAAAAiA"]
[Tue Aug 18 12:53:16.982068 2026] [security2:error] [pid 66623:tid 66763] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/qlex1.php"] [unique_id "aoR_7NO5rbWdOArH04J4xQABCn4"]
[Tue Aug 18 12:53:17.062596 2026] [security2:error] [pid 67073:tid 67238] [client 52.238.210.254:10200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/w.php"] [unique_id "aoR_7fcmepr5_nHgLbMqTQAAAjU"]
[Tue Aug 18 12:53:17.085899 2026] [security2:error] [pid 67073:tid 67118] [remote 157.230.98.178:47954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.98.230.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/wp-login.php"] [unique_id "aoR_7fcmepr5_nHgLbMqTgACiyo"]
[Tue Aug 18 12:53:17.127792 2026] [security2:error] [pid 67073:tid 67248] [client 20.104.100.201:65127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/reop3.php"] [unique_id "aoR_7fcmepr5_nHgLbMqUAAAAj8"]
[Tue Aug 18 12:53:17.139793 2026] [security2:error] [pid 66623:tid 66707] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/mariju.php"] [unique_id "aoR_7dO5rbWdOArH04J4zAABZEY"]
[Tue Aug 18 12:53:17.144559 2026] [security2:error] [pid 67073:tid 67308] [client 168.62.48.100:16288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoR_7fcmepr5_nHgLbMqUQAAAns"]
[Tue Aug 18 12:53:17.171402 2026] [security2:error] [pid 66623:tid 66830] [client 213.35.127.232:49335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoR_7dO5rbWdOArH04J4zQAAAUo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:17.173406 2026] [security2:error] [pid 67073:tid 67286] [client 20.65.69.59:59569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/te.php"] [unique_id "aoR_7fcmepr5_nHgLbMqUgAAAmU"]
[Tue Aug 18 12:53:17.173406 2026] [security2:error] [pid 66623:tid 66840] [client 20.91.215.254:20258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoR_7dO5rbWdOArH04J4zgAAAVQ"]
[Tue Aug 18 12:53:17.178443 2026] [security2:error] [pid 67073:tid 67257] [client 132.196.61.152:44442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/cabs.php"] [unique_id "aoR_7fcmepr5_nHgLbMqUwAAAkg"]
[Tue Aug 18 12:53:17.212775 2026] [security2:error] [pid 67073:tid 67260] [client 20.104.85.180:18847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_7fcmepr5_nHgLbMqVAAAAks"]
[Tue Aug 18 12:53:17.217652 2026] [security2:error] [pid 67073:tid 67216] [client 158.158.74.177:13741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/asd.php"] [unique_id "aoR_7fcmepr5_nHgLbMqVQAAAh8"]
[Tue Aug 18 12:53:17.217988 2026] [security2:error] [pid 67073:tid 67245] [client 20.119.58.187:14798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "aoR_7fcmepr5_nHgLbMqVgAAAjw"]
[Tue Aug 18 12:53:17.275280 2026] [security2:error] [pid 67073:tid 67237] [client 74.248.18.37:62395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/modules/mod_footer.php"] [unique_id "aoR_7fcmepr5_nHgLbMqVwAAAjQ"]
[Tue Aug 18 12:53:17.288245 2026] [security2:error] [pid 67073:tid 67323] [client 20.42.19.40:2716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/images/class-config.php"] [unique_id "aoR_7fcmepr5_nHgLbMqWAAAAoo"]
[Tue Aug 18 12:53:17.298931 2026] [security2:error] [pid 67073:tid 67250] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/img.php"] [unique_id "aoR_7fcmepr5_nHgLbMqWQAAAkE"]
[Tue Aug 18 12:53:17.308044 2026] [security2:error] [pid 66623:tid 66756] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/cofbgxlk.php"] [unique_id "aoR_7dO5rbWdOArH04J42gABfnc"]
[Tue Aug 18 12:53:17.325619 2026] [security2:error] [pid 67073:tid 67239] [client 40.85.222.29:31621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoR_7fcmepr5_nHgLbMqWwAAAjY"]
[Tue Aug 18 12:53:17.345350 2026] [security2:error] [pid 67073:tid 67275] [client 68.221.73.131:4861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/403dd.php"] [unique_id "aoR_7fcmepr5_nHgLbMqXAAAAlo"]
[Tue Aug 18 12:53:17.367234 2026] [security2:error] [pid 67073:tid 67215] [client 4.223.164.152:37278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoR_7fcmepr5_nHgLbMqXQAAAh4"]
[Tue Aug 18 12:53:17.382084 2026] [security2:error] [pid 66623:tid 66805] [client 168.62.48.100:14725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/assets/admin/login/info.php"] [unique_id "aoR_7dO5rbWdOArH04J43AAAATE"]
[Tue Aug 18 12:53:17.416523 2026] [security2:error] [pid 67073:tid 67321] [client 20.100.169.31:31268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoR_7fcmepr5_nHgLbMqXgAAAog"]
[Tue Aug 18 12:53:17.431423 2026] [security2:error] [pid 67073:tid 67268] [client 104.209.144.33:31253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoR_7fcmepr5_nHgLbMqXwAAAlM"]
[Tue Aug 18 12:53:17.474083 2026] [security2:error] [pid 67073:tid 67307] [client 104.209.144.33:32645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoR_7fcmepr5_nHgLbMqZwAAAno"]
[Tue Aug 18 12:53:17.487896 2026] [security2:error] [pid 66623:tid 66726] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/contacto.php"] [unique_id "aoR_7dO5rbWdOArH04J43gABJFk"]
[Tue Aug 18 12:53:17.491530 2026] [security2:error] [pid 67073:tid 67311] [client 4.223.164.152:7069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoR_7fcmepr5_nHgLbMqaQAAAn4"]
[Tue Aug 18 12:53:17.493574 2026] [security2:error] [pid 67073:tid 67274] [client 132.196.61.152:45174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/insc.php"] [unique_id "aoR_7fcmepr5_nHgLbMqagAAAlk"]
[Tue Aug 18 12:53:17.521403 2026] [security2:error] [pid 67073:tid 67282] [client 20.65.69.59:59553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/kc.php"] [unique_id "aoR_7fcmepr5_nHgLbMqawAAAmE"]
[Tue Aug 18 12:53:17.530370 2026] [security2:error] [pid 67073:tid 67283] [client 68.155.154.236:64529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/index/function.php"] [unique_id "aoR_7fcmepr5_nHgLbMqbAAAAmI"]
[Tue Aug 18 12:53:17.568642 2026] [security2:error] [pid 66623:tid 66838] [client 20.104.85.180:18846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/admin.php"] [unique_id "aoR_7dO5rbWdOArH04J44QAAAVI"]
[Tue Aug 18 12:53:17.574137 2026] [security2:error] [pid 66623:tid 66782] [client 52.173.121.69:17978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoR_7dO5rbWdOArH04J44gAAARo"]
[Tue Aug 18 12:53:17.574137 2026] [security2:error] [pid 67073:tid 67270] [client 20.119.58.187:15242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoR_7fcmepr5_nHgLbMqbQAAAlU"]
[Tue Aug 18 12:53:17.619452 2026] [security2:error] [pid 66623:tid 66835] [client 168.62.48.100:16311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoR_7dO5rbWdOArH04J45QAAAU8"]
[Tue Aug 18 12:53:17.634977 2026] [security2:error] [pid 67073:tid 67292] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/222.php"] [unique_id "aoR_7fcmepr5_nHgLbMqbwAAAms"]
[Tue Aug 18 12:53:17.689915 2026] [security2:error] [pid 66623:tid 66784] [client 52.238.210.254:10112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/file.php"] [unique_id "aoR_7dO5rbWdOArH04J46gAAARw"]
[Tue Aug 18 12:53:17.708622 2026] [security2:error] [pid 66623:tid 66839] [client 20.42.19.40:2188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/alfa.php"] [unique_id "aoR_7dO5rbWdOArH04J46wAAAVM"]
[Tue Aug 18 12:53:17.760012 2026] [security2:error] [pid 66623:tid 66808] [client 68.221.73.131:4860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/baba.php"] [unique_id "aoR_7dO5rbWdOArH04J47gAAATQ"]
[Tue Aug 18 12:53:17.769518 2026] [security2:error] [pid 67073:tid 67128] [remote 2a02:c207:2345:2647::1:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paneladechocolate.com.br"] [uri "/.env"] [unique_id "aoR_7fcmepr5_nHgLbMqcQACkjQ"]
[Tue Aug 18 12:53:17.787356 2026] [security2:error] [pid 66623:tid 66858] [client 132.196.61.152:25723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/file.php"] [unique_id "aoR_7dO5rbWdOArH04J48AAAAWY"]
[Tue Aug 18 12:53:17.792782 2026] [security2:error] [pid 66623:tid 66736] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/image2.php"] [unique_id "aoR_7dO5rbWdOArH04J48gABFmM"]
[Tue Aug 18 12:53:17.808005 2026] [security2:error] [pid 67073:tid 67314] [client 4.223.164.152:46158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoR_7fcmepr5_nHgLbMqcgAAAoE"]
[Tue Aug 18 12:53:17.808747 2026] [security2:error] [pid 67073:tid 67208] [client 157.20.138.62:49874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_7fcmepr5_nHgLbMqbgAAAhc"]
[Tue Aug 18 12:53:17.808926 2026] [security2:error] [pid 67073:tid 67208] [client 157.20.138.62:49874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_7fcmepr5_nHgLbMqbgAAAhc"]
[Tue Aug 18 12:53:17.815739 2026] [security2:error] [pid 67073:tid 67322] [client 20.91.215.254:20230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/ebs.php7"] [unique_id "aoR_7fcmepr5_nHgLbMqcwAAAok"]
[Tue Aug 18 12:53:17.854011 2026] [security2:error] [pid 66623:tid 66866] [client 168.62.48.100:16285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoR_7dO5rbWdOArH04J49gAAAW4"]
[Tue Aug 18 12:53:17.854449 2026] [security2:error] [pid 67073:tid 67207] [client 20.104.85.180:43567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/public/css.php"] [unique_id "aoR_7fcmepr5_nHgLbMqdQAAAhY"]
[Tue Aug 18 12:53:17.903023 2026] [security2:error] [pid 67073:tid 67205] [client 20.65.69.59:58402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/jn.php"] [unique_id "aoR_7fcmepr5_nHgLbMqdgAAAhQ"]
[Tue Aug 18 12:53:17.907959 2026] [security2:error] [pid 67073:tid 67329] [client 74.248.18.37:62789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/moon.php"] [unique_id "aoR_7fcmepr5_nHgLbMqdwAAApA"]
[Tue Aug 18 12:53:17.925795 2026] [security2:error] [pid 67073:tid 67210] [client 104.209.144.33:25308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoR_7fcmepr5_nHgLbMqeQAAAhk"]
[Tue Aug 18 12:53:17.930068 2026] [security2:error] [pid 67073:tid 67217] [client 104.209.144.33:24842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoR_7fcmepr5_nHgLbMqegAAAiA"]
[Tue Aug 18 12:53:17.938446 2026] [security2:error] [pid 67073:tid 67131] [remote 57.141.22.94:57566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_7fcmepr5_nHgLbMqfAACKTc"]
[Tue Aug 18 12:53:17.948456 2026] [security2:error] [pid 67073:tid 67306] [client 20.119.58.187:15340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/img/xmrlpc.php"] [unique_id "aoR_7fcmepr5_nHgLbMqfQAAAnk"]
[Tue Aug 18 12:53:17.952356 2026] [security2:error] [pid 66623:tid 66693] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/fb.php"] [unique_id "aoR_7dO5rbWdOArH04J4-QABFzg"]
[Tue Aug 18 12:53:17.960402 2026] [security2:error] [pid 67073:tid 67288] [client 20.171.51.14:58370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/you.php"] [unique_id "aoR_7fcmepr5_nHgLbMqfgAAAmc"]
[Tue Aug 18 12:53:17.968621 2026] [security2:error] [pid 67073:tid 67132] [remote 190.6.176.90:50272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.176.6.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/wp-login.php"] [unique_id "aoR_7fcmepr5_nHgLbMqfwACLDg"]
[Tue Aug 18 12:53:17.970751 2026] [security2:error] [pid 67073:tid 67223] [client 20.171.51.14:16736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/md.php"] [unique_id "aoR_7fcmepr5_nHgLbMqgAAAAiY"]
[Tue Aug 18 12:53:17.977090 2026] [security2:error] [pid 67073:tid 67327] [client 158.158.74.177:13792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/akc.php"] [unique_id "aoR_7fcmepr5_nHgLbMqgQAAAo4"]
[Tue Aug 18 12:53:17.995284 2026] [security2:error] [pid 67073:tid 67297] [client 20.104.100.201:53855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/yawa.php"] [unique_id "aoR_7fcmepr5_nHgLbMqggAAAnA"]
[Tue Aug 18 12:53:18.005776 2026] [security2:error] [pid 66623:tid 66837] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/key.php"] [unique_id "aoR_7tO5rbWdOArH04J4_AAAAVE"]
[Tue Aug 18 12:53:18.094592 2026] [security2:error] [pid 67073:tid 67258] [client 74.249.206.207:51241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/xx.php"] [unique_id "aoR_7vcmepr5_nHgLbMqjgAAAkk"]
[Tue Aug 18 12:53:18.098132 2026] [security2:error] [pid 67073:tid 67260] [client 168.62.48.100:14829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoR_7vcmepr5_nHgLbMqjwAAAks"]
[Tue Aug 18 12:53:18.112990 2026] [security2:error] [pid 66623:tid 66685] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/gi.php"] [unique_id "aoR_7tO5rbWdOArH04J4_gABJzA"]
[Tue Aug 18 12:53:18.131711 2026] [security2:error] [pid 67073:tid 67247] [client 20.104.85.180:18839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/classwithtostring.php"] [unique_id "aoR_7vcmepr5_nHgLbMqkAAAAj4"]
[Tue Aug 18 12:53:18.147403 2026] [security2:error] [pid 67073:tid 67255] [client 74.248.18.37:44281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/min.php"] [unique_id "aoR_7vcmepr5_nHgLbMqkQAAAkY"]
[Tue Aug 18 12:53:18.165777 2026] [security2:error] [pid 67073:tid 67265] [client 132.196.61.152:23837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/dex.php"] [unique_id "aoR_7vcmepr5_nHgLbMqkgAAAlA"]
[Tue Aug 18 12:53:18.184524 2026] [security2:error] [pid 67073:tid 67262] [client 20.42.19.40:2217] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/1.php"] [unique_id "aoR_7vcmepr5_nHgLbMqkwAAAk0"]
[Tue Aug 18 12:53:18.184615 2026] [security2:error] [pid 67073:tid 67262] [client 20.42.19.40:2217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/1.php"] [unique_id "aoR_7vcmepr5_nHgLbMqkwAAAk0"]
[Tue Aug 18 12:53:18.189136 2026] [security2:error] [pid 67073:tid 67213] [client 213.35.127.232:49553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoR_7vcmepr5_nHgLbMqlAAAAhw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:18.208689 2026] [security2:error] [pid 67073:tid 67146] [remote 57.141.22.18:37254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_7vcmepr5_nHgLbMqlQACH0Y"]
[Tue Aug 18 12:53:18.228667 2026] [security2:error] [pid 67073:tid 67275] [client 68.221.73.131:4802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/site.php"] [unique_id "aoR_7vcmepr5_nHgLbMqlgAAAlo"]
[Tue Aug 18 12:53:18.229136 2026] [security2:error] [pid 67073:tid 67215] [client 4.223.164.152:37282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-blog.php"] [unique_id "aoR_7vcmepr5_nHgLbMqlwAAAh4"]
[Tue Aug 18 12:53:18.238637 2026] [security2:error] [pid 66623:tid 66890] [client 149.34.210.141:56936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_7tO5rbWdOArH04J5GQAAAYY"]
[Tue Aug 18 12:53:18.247745 2026] [security2:error] [pid 66623:tid 66769] [client 68.155.154.236:64453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoR_7tO5rbWdOArH04J5GgAAAQ0"]
[Tue Aug 18 12:53:18.267984 2026] [security2:error] [pid 66623:tid 66745] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/video.php"] [unique_id "aoR_7tO5rbWdOArH04J5HAABgmw"]
[Tue Aug 18 12:53:18.269268 2026] [security2:error] [pid 67073:tid 67280] [client 20.151.109.219:20983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/56.php"] [unique_id "aoR_7vcmepr5_nHgLbMqmgAAAl8"]
[Tue Aug 18 12:53:18.301754 2026] [security2:error] [pid 67073:tid 67222] [client 20.119.58.187:14593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/css/colors/coffee/xmrlpc.php"] [unique_id "aoR_7vcmepr5_nHgLbMqmwAAAiU"]
[Tue Aug 18 12:53:18.334798 2026] [security2:error] [pid 67073:tid 67305] [client 168.62.48.100:14755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoR_7vcmepr5_nHgLbMqnQAAAng"]
[Tue Aug 18 12:53:18.338503 2026] [security2:error] [pid 67073:tid 67271] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/chosen.php"] [unique_id "aoR_7vcmepr5_nHgLbMqngAAAlY"]
[Tue Aug 18 12:53:18.341428 2026] [security2:error] [pid 67073:tid 67307] [client 52.238.210.254:10167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/adminfuns.php"] [unique_id "aoR_7vcmepr5_nHgLbMqnwAAAno"]
[Tue Aug 18 12:53:18.343586 2026] [security2:error] [pid 67073:tid 67295] [client 4.223.164.152:6907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/simple.php"] [unique_id "aoR_7vcmepr5_nHgLbMqoAAAAm4"]
[Tue Aug 18 12:53:18.345638 2026] [security2:error] [pid 66623:tid 66873] [client 20.48.236.86:65093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/8.php"] [unique_id "aoR_7tO5rbWdOArH04J5IAAAAXU"]
[Tue Aug 18 12:53:18.423677 2026] [security2:error] [pid 66623:tid 66662] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/hel.php"] [unique_id "aoR_7tO5rbWdOArH04J5JQABNRk"]
[Tue Aug 18 12:53:18.428118 2026] [security2:error] [pid 67073:tid 67312] [client 20.171.51.14:1978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/iy.php"] [unique_id "aoR_7vcmepr5_nHgLbMqogAAAn8"]
[Tue Aug 18 12:53:18.473249 2026] [security2:error] [pid 66623:tid 66799] [client 132.196.61.152:45136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/key.php"] [unique_id "aoR_7tO5rbWdOArH04J5JwAAASs"]
[Tue Aug 18 12:53:18.496784 2026] [security2:error] [pid 66623:tid 66800] [client 172.202.39.151:56998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/lv.php"] [unique_id "aoR_7tO5rbWdOArH04J5KAAAASw"]
[Tue Aug 18 12:53:18.516988 2026] [security2:error] [pid 66623:tid 66890] [client 149.34.210.141:56936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_7tO5rbWdOArH04J5GQAAAYY"]
[Tue Aug 18 12:53:18.527258 2026] [security2:error] [pid 67073:tid 67292] [client 20.104.100.201:57311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/php5.php"] [unique_id "aoR_7vcmepr5_nHgLbMqpAAAAms"]
[Tue Aug 18 12:53:18.554684 2026] [security2:error] [pid 67073:tid 67302] [client 74.248.18.37:62374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/n.php"] [unique_id "aoR_7vcmepr5_nHgLbMqpgAAAnU"]
[Tue Aug 18 12:53:18.566483 2026] [security2:error] [pid 67073:tid 67309] [client 168.62.48.100:16364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoR_7vcmepr5_nHgLbMqpwAAAnw"]
[Tue Aug 18 12:53:18.572093 2026] [security2:error] [pid 66623:tid 66830] [client 104.209.144.33:31236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoR_7tO5rbWdOArH04J5MAAAAUo"]
[Tue Aug 18 12:53:18.573394 2026] [security2:error] [pid 66623:tid 66840] [client 104.209.144.33:25309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoR_7tO5rbWdOArH04J5MQAAAVQ"]
[Tue Aug 18 12:53:18.589328 2026] [security2:error] [pid 67073:tid 67269] [client 52.173.121.69:61824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoR_7vcmepr5_nHgLbMqqAAAAlQ"]
[Tue Aug 18 12:53:18.590605 2026] [security2:error] [pid 67073:tid 67281] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/x.php"] [unique_id "aoR_7vcmepr5_nHgLbMqqQAAAmA"]
[Tue Aug 18 12:53:18.592674 2026] [security2:error] [pid 66623:tid 66827] [client 185.168.31.100:62993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.31.168.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "acpecasebaterias.com.br"] [uri "/wp-login.php"] [unique_id "aoR_7tO5rbWdOArH04J5JAAAAUc"]
[Tue Aug 18 12:53:18.607004 2026] [security2:error] [pid 66623:tid 66768] [client 158.158.74.177:13712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/maintenance.php"] [unique_id "aoR_7tO5rbWdOArH04J5MwAAAQw"]
[Tue Aug 18 12:53:18.613671 2026] [security2:error] [pid 66623:tid 66712] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/grok.php"] [unique_id "aoR_7tO5rbWdOArH04J5NQABfks"]
[Tue Aug 18 12:53:18.629618 2026] [security2:error] [pid 66623:tid 66794] [client 74.248.136.165:1071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/snq.php"] [unique_id "aoR_7tO5rbWdOArH04J5OAAAASY"]
[Tue Aug 18 12:53:18.666630 2026] [security2:error] [pid 66623:tid 66791] [client 20.119.58.187:15337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/images/xmrlpc.php"] [unique_id "aoR_7tO5rbWdOArH04J5OgAAASM"]
[Tue Aug 18 12:53:18.680319 2026] [security2:error] [pid 67073:tid 67206] [client 68.221.73.131:4840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoR_7vcmepr5_nHgLbMqqgAAAhU"]
[Tue Aug 18 12:53:18.685662 2026] [autoindex:error] [pid 66623:tid 66855] [client 4.223.164.152:54224] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:18.690995 2026] [security2:error] [pid 66623:tid 66820] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/thoms.php"] [unique_id "aoR_7tO5rbWdOArH04J5OwAAAUA"]
[Tue Aug 18 12:53:18.698749 2026] [security2:error] [pid 67073:tid 67221] [client 20.100.169.31:15088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/h.php"] [unique_id "aoR_7vcmepr5_nHgLbMqqwAAAiQ"]
[Tue Aug 18 12:53:18.720945 2026] [security2:error] [pid 67073:tid 67261] [client 20.91.215.254:20256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoR_7vcmepr5_nHgLbMqrQAAAkw"]
[Tue Aug 18 12:53:18.745299 2026] [security2:error] [pid 67073:tid 67322] [client 52.238.210.254:10202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/aa.php"] [unique_id "aoR_7vcmepr5_nHgLbMqrgAAAok"]
[Tue Aug 18 12:53:18.769534 2026] [security2:error] [pid 66623:tid 66751] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/indes.php"] [unique_id "aoR_7tO5rbWdOArH04J5QAABM3I"]
[Tue Aug 18 12:53:18.792281 2026] [security2:error] [pid 67073:tid 67284] [client 40.85.222.29:46061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-2019.php"] [unique_id "aoR_7vcmepr5_nHgLbMqrwAAAmM"]
[Tue Aug 18 12:53:18.805417 2026] [security2:error] [pid 67073:tid 67287] [client 168.62.48.100:16315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoR_7vcmepr5_nHgLbMqsAAAAmY"]
[Tue Aug 18 12:53:18.820494 2026] [security2:error] [pid 66623:tid 66842] [client 132.196.61.152:38365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/kir.php"] [unique_id "aoR_7tO5rbWdOArH04J5RQAAAVY"]
[Tue Aug 18 12:53:18.841280 2026] [security2:error] [pid 66623:tid 66784] [client 20.104.100.201:54045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoR_7tO5rbWdOArH04J5RgAAARw"]
[Tue Aug 18 12:53:18.877678 2026] [security2:error] [pid 67073:tid 67290] [client 52.173.121.69:25019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoR_7vcmepr5_nHgLbMqsQAAAmk"]
[Tue Aug 18 12:53:18.926171 2026] [security2:error] [pid 66623:tid 66732] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/tTPcH.php"] [unique_id "aoR_7tO5rbWdOArH04J5SwABiF8"]
[Tue Aug 18 12:53:18.942990 2026] [security2:error] [pid 66623:tid 66858] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/index/function.php"] [unique_id "aoR_7tO5rbWdOArH04J5TAAAAWY"]
[Tue Aug 18 12:53:19.006403 2026] [security2:error] [pid 67073:tid 67306] [client 74.249.206.207:56226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/av.php"] [unique_id "aoR_7_cmepr5_nHgLbMqsgAAAnk"]
[Tue Aug 18 12:53:19.007187 2026] [security2:error] [pid 66623:tid 66767] [client 5.253.205.188:35728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/export.bak"] [unique_id "aoR_79O5rbWdOArH04J5TwAAAQs"], referer: https://medihub.com.br/export.bak
[Tue Aug 18 12:53:19.026319 2026] [security2:error] [pid 67073:tid 67259] [client 20.119.58.187:14592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/images/xmrlpc.php"] [unique_id "aoR_7_cmepr5_nHgLbMqswAAAko"]
[Tue Aug 18 12:53:19.041778 2026] [security2:error] [pid 66623:tid 66812] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/wpxml.php"] [unique_id "aoR_79O5rbWdOArH04J5UAAAATg"]
[Tue Aug 18 12:53:19.055114 2026] [security2:error] [pid 66623:tid 66887] [client 52.238.210.254:10123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/classwithtostring.php"] [unique_id "aoR_79O5rbWdOArH04J5UQAAAYM"]
[Tue Aug 18 12:53:19.072916 2026] [security2:error] [pid 66623:tid 66866] [client 168.62.48.100:14788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoR_79O5rbWdOArH04J5UgAAAW4"]
[Tue Aug 18 12:53:19.088090 2026] [security2:error] [pid 66623:tid 66757] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/bs1.php"] [unique_id "aoR_79O5rbWdOArH04J5VAABRng"]
[Tue Aug 18 12:53:19.100750 2026] [security2:error] [pid 66623:tid 66885] [client 4.223.164.152:54224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/adminfuns.php"] [unique_id "aoR_79O5rbWdOArH04J5VQAAAYE"]
[Tue Aug 18 12:53:19.101765 2026] [security2:error] [pid 66623:tid 66833] [client 20.171.51.14:57407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/og.php"] [unique_id "aoR_79O5rbWdOArH04J5VgAAAU0"]
[Tue Aug 18 12:53:19.124268 2026] [security2:error] [pid 66623:tid 66860] [client 68.221.73.131:4849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/cabs.php"] [unique_id "aoR_79O5rbWdOArH04J5WAAAAWg"]
[Tue Aug 18 12:53:19.140716 2026] [security2:error] [pid 66623:tid 66834] [client 132.196.61.152:45135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/nofile.php"] [unique_id "aoR_79O5rbWdOArH04J5WQAAAU4"]
[Tue Aug 18 12:53:19.168653 2026] [security2:error] [pid 66623:tid 66785] [client 157.51.166.53:50082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_79O5rbWdOArH04J5WwAAAR0"]
[Tue Aug 18 12:53:19.168775 2026] [security2:error] [pid 66623:tid 66785] [client 157.51.166.53:50082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_79O5rbWdOArH04J5WwAAAR0"]
[Tue Aug 18 12:53:19.187386 2026] [security2:error] [pid 66623:tid 66813] [client 74.248.18.37:62831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/nc4.php"] [unique_id "aoR_79O5rbWdOArH04J5XAAAATk"]
[Tue Aug 18 12:53:19.197378 2026] [security2:error] [pid 67073:tid 67304] [client 68.155.154.236:63324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/Cachex.php"] [unique_id "aoR_7_cmepr5_nHgLbMqtgAAAnc"]
[Tue Aug 18 12:53:19.202759 2026] [security2:error] [pid 66623:tid 66851] [client 213.35.127.232:49781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoR_79O5rbWdOArH04J5XQAAAV8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:19.222573 2026] [security2:error] [pid 66623:tid 66783] [client 40.85.222.29:27743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoR_79O5rbWdOArH04J5XwAAARs"]
[Tue Aug 18 12:53:19.235824 2026] [security2:error] [pid 67073:tid 67308] [client 20.65.69.59:36375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/bf.php"] [unique_id "aoR_7_cmepr5_nHgLbMqtwAAAns"]
[Tue Aug 18 12:53:19.241376 2026] [security2:error] [pid 67073:tid 67223] [client 158.158.74.177:14223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/options-writing.php"] [unique_id "aoR_7_cmepr5_nHgLbMquAAAAiY"]
[Tue Aug 18 12:53:19.262401 2026] [security2:error] [pid 67073:tid 67313] [client 160.120.140.123:51624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_7_cmepr5_nHgLbMquQAAAoA"]
[Tue Aug 18 12:53:19.262526 2026] [security2:error] [pid 67073:tid 67313] [client 160.120.140.123:51624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_7_cmepr5_nHgLbMquQAAAoA"]
[Tue Aug 18 12:53:19.272663 2026] [security2:error] [pid 66623:tid 66683] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/hp2.php"] [unique_id "aoR_79O5rbWdOArH04J5YgABOy4"]
[Tue Aug 18 12:53:19.314037 2026] [security2:error] [pid 66623:tid 66879] [client 168.62.48.100:14733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoR_79O5rbWdOArH04J5ZAAAAXs"]
[Tue Aug 18 12:53:19.342400 2026] [security2:error] [pid 67073:tid 67314] [client 178.153.171.161:5603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_7_cmepr5_nHgLbMqugAAAoE"]
[Tue Aug 18 12:53:19.342547 2026] [security2:error] [pid 67073:tid 67314] [client 178.153.171.161:5603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_7_cmepr5_nHgLbMqugAAAoE"]
[Tue Aug 18 12:53:19.343914 2026] [security2:error] [pid 66623:tid 66775] [client 20.171.51.14:58414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ez.php"] [unique_id "aoR_79O5rbWdOArH04J5ZQAAARM"]
[Tue Aug 18 12:53:19.378941 2026] [security2:error] [pid 67073:tid 67301] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/file1221.php"] [unique_id "aoR_7_cmepr5_nHgLbMquwAAAnQ"]
[Tue Aug 18 12:53:19.385014 2026] [security2:error] [pid 66623:tid 66824] [client 20.119.58.187:15106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoR_79O5rbWdOArH04J5ZwAAAUQ"]
[Tue Aug 18 12:53:19.390065 2026] [security2:error] [pid 67073:tid 67245] [client 52.238.210.254:10155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/about.php"] [unique_id "aoR_7_cmepr5_nHgLbMqvQAAAjw"]
[Tue Aug 18 12:53:19.428706 2026] [security2:error] [pid 66623:tid 66845] [client 132.196.61.152:54728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/fling.php"] [unique_id "aoR_79O5rbWdOArH04J5aAAAAVk"]
[Tue Aug 18 12:53:19.464585 2026] [security2:error] [pid 66623:tid 66809] [client 172.202.39.151:38391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/new.php"] [unique_id "aoR_79O5rbWdOArH04J5agAAATU"]
[Tue Aug 18 12:53:19.473744 2026] [security2:error] [pid 66623:tid 66874] [client 4.223.164.152:6598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/chosen.php"] [unique_id "aoR_79O5rbWdOArH04J5awAAAXY"]
[Tue Aug 18 12:53:19.485269 2026] [security2:error] [pid 66623:tid 66707] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/yb.php"] [unique_id "aoR_79O5rbWdOArH04J5bAABMEY"]
[Tue Aug 18 12:53:19.548556 2026] [security2:error] [pid 67073:tid 67249] [client 168.62.48.100:14811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoR_7_cmepr5_nHgLbMqwAAAAkA"]
[Tue Aug 18 12:53:19.552843 2026] [security2:error] [pid 66623:tid 66800] [client 68.221.73.131:4845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/insc.php"] [unique_id "aoR_79O5rbWdOArH04J5bgAAASw"]
[Tue Aug 18 12:53:19.553824 2026] [security2:error] [pid 66623:tid 66859] [client 4.223.164.152:64688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/ms-edit.php"] [unique_id "aoR_79O5rbWdOArH04J5bwAAAWc"]
[Tue Aug 18 12:53:19.568055 2026] [security2:error] [pid 67073:tid 67319] [client 20.100.169.31:28435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/archive.php"] [unique_id "aoR_7_cmepr5_nHgLbMqwgAAAoY"]
[Tue Aug 18 12:53:19.588680 2026] [security2:error] [pid 67073:tid 67244] [client 20.91.215.254:20257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoR_7_cmepr5_nHgLbMqwwAAAjs"]
[Tue Aug 18 12:53:19.590160 2026] [security2:error] [pid 66623:tid 66868] [client 20.104.100.201:17318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/7.php"] [unique_id "aoR_79O5rbWdOArH04J5cAAAAXA"]
[Tue Aug 18 12:53:19.611026 2026] [security2:error] [pid 66623:tid 66827] [client 104.209.144.33:24875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoR_79O5rbWdOArH04J5cQAAAUc"]
[Tue Aug 18 12:53:19.619099 2026] [security2:error] [pid 67073:tid 67214] [client 20.65.98.162:28954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_7_cmepr5_nHgLbMqxAAAAh0"]
[Tue Aug 18 12:53:19.622101 2026] [security2:error] [pid 67073:tid 67236] [client 52.139.47.57:47429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/tool.php"] [unique_id "aoR_7_cmepr5_nHgLbMqxQAAAjM"]
[Tue Aug 18 12:53:19.639026 2026] [security2:error] [pid 67073:tid 67279] [client 172.202.39.151:44453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-login.php"] [unique_id "aoR_7_cmepr5_nHgLbMqxgAAAl4"]
[Tue Aug 18 12:53:19.655638 2026] [security2:error] [pid 66623:tid 66741] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/vc.php"] [unique_id "aoR_79O5rbWdOArH04J5dQABVWg"]
[Tue Aug 18 12:53:19.663388 2026] [authz_core:error] [pid 66623:tid 66672] [remote 57.141.22.32:31860] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:19.663661 2026] [authz_core:error] [pid 66623:tid 66672] [remote 57.141.22.32:31860] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:19.723899 2026] [security2:error] [pid 66623:tid 66674] [remote 136.110.27.48:40554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.lencoisflat.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoR_79O5rbWdOArH04J5fQABEiU"]
[Tue Aug 18 12:53:19.734811 2026] [autoindex:error] [pid 66623:tid 66772] [client 198.235.24.147:60110] AH01276: Cannot serve directory /home4/filial35/public_html/spotrestaurante/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:19.742151 2026] [security2:error] [pid 66623:tid 66798] [client 20.119.58.187:14610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/css/colors/xmrlpc.php"] [unique_id "aoR_79O5rbWdOArH04J5gAAAASo"]
[Tue Aug 18 12:53:19.754652 2026] [security2:error] [pid 67073:tid 67280] [client 104.209.144.33:32698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoR_7_cmepr5_nHgLbMqyQAAAl8"]
[Tue Aug 18 12:53:19.766570 2026] [security2:error] [pid 66623:tid 66837] [client 20.100.169.31:31247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/ms-edit.php"] [unique_id "aoR_79O5rbWdOArH04J5ggAAAVE"]
[Tue Aug 18 12:53:19.770016 2026] [security2:error] [pid 67073:tid 67268] [client 132.196.61.152:54725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/zoo1.php"] [unique_id "aoR_7_cmepr5_nHgLbMqywAAAlM"]
[Tue Aug 18 12:53:19.786234 2026] [security2:error] [pid 67073:tid 67293] [client 168.62.48.100:14744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoR_7_cmepr5_nHgLbMqzAAAAmw"]
[Tue Aug 18 12:53:19.850597 2026] [security2:error] [pid 66623:tid 66679] [remote 190.6.176.90:44538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.176.6.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tigre.tur.br.slweb.net.br"] [uri "/wp-login.php"] [unique_id "aoR_79O5rbWdOArH04J5hwABDSo"]
[Tue Aug 18 12:53:19.852256 2026] [security2:error] [pid 66623:tid 66708] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/pema.php"] [unique_id "aoR_79O5rbWdOArH04J5iAABHEc"]
[Tue Aug 18 12:53:19.857738 2026] [security2:error] [pid 66623:tid 66882] [client 74.248.18.37:12514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/new.php"] [unique_id "aoR_79O5rbWdOArH04J5iQAAAX4"]
[Tue Aug 18 12:53:19.864930 2026] [security2:error] [pid 66623:tid 66852] [client 158.158.74.177:13802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoR_79O5rbWdOArH04J5igAAAWA"]
[Tue Aug 18 12:53:19.914401 2026] [security2:error] [pid 66623:tid 66884] [client 68.155.154.236:64532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoR_79O5rbWdOArH04J5jAAAAYA"]
[Tue Aug 18 12:53:19.950266 2026] [security2:error] [pid 67073:tid 67238] [client 20.171.51.14:62498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/lp.php"] [unique_id "aoR_7_cmepr5_nHgLbMqzQAAAjU"]
[Tue Aug 18 12:53:19.955069 2026] [security2:error] [pid 66623:tid 66808] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/nox.php"] [unique_id "aoR_79O5rbWdOArH04J5jQAAATQ"]
[Tue Aug 18 12:53:19.970849 2026] [security2:error] [pid 67073:tid 67283] [client 68.221.73.131:4835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/file.php"] [unique_id "aoR_7_cmepr5_nHgLbMqzgAAAmI"]
[Tue Aug 18 12:53:19.981583 2026] [security2:error] [pid 67073:tid 67312] [client 4.223.164.152:54246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/222.php"] [unique_id "aoR_7_cmepr5_nHgLbMqzwAAAn8"]
[Tue Aug 18 12:53:20.020715 2026] [security2:error] [pid 66623:tid 66680] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/sh.php"] [unique_id "aoR_8NO5rbWdOArH04J5jwABCys"]
[Tue Aug 18 12:53:20.023690 2026] [security2:error] [pid 66623:tid 66883] [client 168.62.48.100:14801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoR_8NO5rbWdOArH04J5kAAAAX8"]
[Tue Aug 18 12:53:20.028224 2026] [security2:error] [pid 67073:tid 67156] [remote 179.64.21.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powerbelt.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq0AACUlA"]
[Tue Aug 18 12:53:20.028388 2026] [security2:error] [pid 67073:tid 67267] [client 179.64.21.92:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "powerbelt.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq0AACUlA"]
[Tue Aug 18 12:53:20.044183 2026] [security2:error] [pid 66623:tid 66812] [client 104.209.144.33:25329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoR_8NO5rbWdOArH04J5kgAAATg"]
[Tue Aug 18 12:53:20.046862 2026] [security2:error] [pid 66623:tid 66887] [client 74.248.136.165:1895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/wp-access.php"] [unique_id "aoR_8NO5rbWdOArH04J5kwAAAYM"]
[Tue Aug 18 12:53:20.055877 2026] [security2:error] [pid 66623:tid 66885] [client 40.85.222.29:45732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/.cache/x.php"] [unique_id "aoR_8NO5rbWdOArH04J5lQAAAYE"]
[Tue Aug 18 12:53:20.057649 2026] [security2:error] [pid 66623:tid 66833] [client 132.196.61.152:44441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/zoo2.php"] [unique_id "aoR_8NO5rbWdOArH04J5lgAAAU0"]
[Tue Aug 18 12:53:20.097766 2026] [security2:error] [pid 67073:tid 67264] [client 20.119.58.187:14612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/includes/xmrlpc.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq0gAAAk8"]
[Tue Aug 18 12:53:20.114755 2026] [security2:error] [pid 67073:tid 67298] [client 74.249.206.207:29678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/media.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq1AAAAnE"]
[Tue Aug 18 12:53:20.114768 2026] [security2:error] [pid 67073:tid 67276] [client 20.48.236.86:10778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/biufile.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq1QAAAls"]
[Tue Aug 18 12:53:20.132166 2026] [security2:error] [pid 66623:tid 66722] [remote 136.110.27.48:40554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.lencoisflat.com.br"] [uri "/wp-config.php.old"] [unique_id "aoR_8NO5rbWdOArH04J5mAABd1U"]
[Tue Aug 18 12:53:20.135160 2026] [security2:error] [pid 66623:tid 66813] [client 52.238.210.254:10186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/goods.php"] [unique_id "aoR_8NO5rbWdOArH04J5mQAAATk"]
[Tue Aug 18 12:53:20.179938 2026] [security2:error] [pid 66623:tid 66728] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/button.php"] [unique_id "aoR_8NO5rbWdOArH04J5nwABPFs"]
[Tue Aug 18 12:53:20.185572 2026] [authz_core:error] [pid 66623:tid 66690] [remote 57.141.22.23:28168] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:20.186024 2026] [authz_core:error] [pid 66623:tid 66690] [remote 57.141.22.23:28168] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:20.201191 2026] [security2:error] [pid 66623:tid 66685] [remote 136.110.27.48:40554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lencoisflat.com.br"] [uri "/config/.env.php"] [unique_id "aoR_8NO5rbWdOArH04J5pAABGzA"]
[Tue Aug 18 12:53:20.202489 2026] [security2:error] [pid 66623:tid 66649] [remote 136.110.27.48:40554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lencoisflat.com.br"] [uri "/.env.php.bak"] [unique_id "aoR_8NO5rbWdOArH04J5pQABegw"]
[Tue Aug 18 12:53:20.221827 2026] [security2:error] [pid 66623:tid 66839] [client 213.35.127.232:50007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoR_8NO5rbWdOArH04J5pwAAAVM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:20.258355 2026] [security2:error] [pid 66623:tid 66866] [client 20.91.215.254:20245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/lite.php"] [unique_id "aoR_8NO5rbWdOArH04J5qgAAAW4"]
[Tue Aug 18 12:53:20.261508 2026] [security2:error] [pid 66623:tid 66823] [client 4.223.164.152:7090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/als.php"] [unique_id "aoR_8NO5rbWdOArH04J5qwAAAUM"]
[Tue Aug 18 12:53:20.262941 2026] [security2:error] [pid 66623:tid 66789] [client 168.62.48.100:16299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoR_8NO5rbWdOArH04J5rAAAASE"]
[Tue Aug 18 12:53:20.286468 2026] [security2:error] [pid 66623:tid 66786] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/akismet.php"] [unique_id "aoR_8NO5rbWdOArH04J5rwAAAR4"]
[Tue Aug 18 12:53:20.306556 2026] [security2:error] [pid 67073:tid 67291] [client 135.136.0.233:63808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.0.136.135.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq1wAAAmo"]
[Tue Aug 18 12:53:20.306791 2026] [security2:error] [pid 67073:tid 67291] [client 135.136.0.233:63808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq1wAAAmo"]
[Tue Aug 18 12:53:20.317168 2026] [security2:error] [pid 66623:tid 66801] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/aaa.php"] [unique_id "aoR_8NO5rbWdOArH04J5sAAAAS0"]
[Tue Aug 18 12:53:20.321151 2026] [security2:error] [pid 66623:tid 66824] [client 20.104.100.201:53842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/ws77.php"] [unique_id "aoR_8NO5rbWdOArH04J5sQAAAUQ"]
[Tue Aug 18 12:53:20.334582 2026] [security2:error] [pid 66623:tid 66645] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/wlc.php"] [unique_id "aoR_8NO5rbWdOArH04J5sgABeQg"]
[Tue Aug 18 12:53:20.352944 2026] [security2:error] [pid 66623:tid 66845] [client 132.196.61.152:7786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/org.php"] [unique_id "aoR_8NO5rbWdOArH04J5swAAAVk"]
[Tue Aug 18 12:53:20.382591 2026] [security2:error] [pid 66623:tid 66804] [client 68.221.73.131:4848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/dex.php"] [unique_id "aoR_8NO5rbWdOArH04J5tQAAATA"]
[Tue Aug 18 12:53:20.415067 2026] [security2:error] [pid 66623:tid 66821] [client 20.104.100.201:65051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/acp.php"] [unique_id "aoR_8NO5rbWdOArH04J5tgAAAUE"]
[Tue Aug 18 12:53:20.437586 2026] [security2:error] [pid 67073:tid 67241] [client 104.209.144.33:31284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq2AAAAjg"]
[Tue Aug 18 12:53:20.455790 2026] [security2:error] [pid 66623:tid 66886] [client 20.119.58.187:14809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/css/colors/blue/xmrlpc.php"] [unique_id "aoR_8NO5rbWdOArH04J5uAAAAYI"]
[Tue Aug 18 12:53:20.457904 2026] [security2:error] [pid 66623:tid 66819] [client 4.223.164.152:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoR_8NO5rbWdOArH04J5ugAAAT8"]
[Tue Aug 18 12:53:20.491005 2026] [security2:error] [pid 66623:tid 66702] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/fi.php"] [unique_id "aoR_8NO5rbWdOArH04J5vAABcEE"]
[Tue Aug 18 12:53:20.495581 2026] [security2:error] [pid 66623:tid 66869] [client 74.248.18.37:62792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/packed.php"] [unique_id "aoR_8NO5rbWdOArH04J5vQAAAXE"]
[Tue Aug 18 12:53:20.500105 2026] [security2:error] [pid 66623:tid 66830] [client 168.62.48.100:14817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoR_8NO5rbWdOArH04J5vgAAAUo"]
[Tue Aug 18 12:53:20.522326 2026] [security2:error] [pid 67073:tid 67305] [client 85.154.68.202:7533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq2gAAAng"]
[Tue Aug 18 12:53:20.522463 2026] [security2:error] [pid 67073:tid 67305] [client 85.154.68.202:7533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq2gAAAng"]
[Tue Aug 18 12:53:20.545364 2026] [security2:error] [pid 66623:tid 66827] [client 20.171.51.14:58408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ey.php"] [unique_id "aoR_8NO5rbWdOArH04J5wAAAAUc"]
[Tue Aug 18 12:53:20.575781 2026] [security2:error] [pid 66623:tid 66873] [client 158.158.74.177:13805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/maint.php"] [unique_id "aoR_8NO5rbWdOArH04J5wwAAAXU"]
[Tue Aug 18 12:53:20.636344 2026] [security2:error] [pid 67073:tid 67212] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/admin.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq2wAAAhs"]
[Tue Aug 18 12:53:20.639904 2026] [security2:error] [pid 67073:tid 67281] [client 4.232.151.198:41951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/nw.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq3AAAAmA"]
[Tue Aug 18 12:53:20.642911 2026] [security2:error] [pid 67073:tid 67284] [client 52.238.210.254:8907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/php8.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq3QAAAmM"]
[Tue Aug 18 12:53:20.655027 2026] [security2:error] [pid 66623:tid 66667] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/chris.php"] [unique_id "aoR_8NO5rbWdOArH04J5xgABMx4"]
[Tue Aug 18 12:53:20.664179 2026] [security2:error] [pid 66623:tid 66792] [client 132.196.61.152:38380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/imageskir.php"] [unique_id "aoR_8NO5rbWdOArH04J5xwAAASQ"]
[Tue Aug 18 12:53:20.664445 2026] [security2:error] [pid 66623:tid 66798] [client 52.173.121.69:17976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoR_8NO5rbWdOArH04J5yAAAASo"]
[Tue Aug 18 12:53:20.666948 2026] [security2:error] [pid 66623:tid 66888] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/abcd.php"] [unique_id "aoR_8NO5rbWdOArH04J5yQAAAYQ"]
[Tue Aug 18 12:53:20.683385 2026] [security2:error] [pid 66623:tid 66835] [client 74.248.18.37:44267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/php8.php"] [unique_id "aoR_8NO5rbWdOArH04J5ygAAAU8"]
[Tue Aug 18 12:53:20.744713 2026] [security2:error] [pid 67073:tid 67218] [client 168.62.48.100:16302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq4AAAAiE"]
[Tue Aug 18 12:53:20.811900 2026] [security2:error] [pid 67073:tid 67282] [client 20.119.58.187:15336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/xmrlpc.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq4QAAAmE"]
[Tue Aug 18 12:53:20.821082 2026] [security2:error] [pid 66623:tid 66770] [client 68.221.73.131:4316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/key.php"] [unique_id "aoR_8NO5rbWdOArH04J50AAAAQ4"]
[Tue Aug 18 12:53:20.848630 2026] [security2:error] [pid 66623:tid 66655] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/doc.php"] [unique_id "aoR_8NO5rbWdOArH04J50QABNBI"]
[Tue Aug 18 12:53:20.851662 2026] [security2:error] [pid 67073:tid 67210] [client 20.171.51.14:61457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/asus.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq4gAAAhk"]
[Tue Aug 18 12:53:20.902109 2026] [security2:error] [pid 67073:tid 67327] [client 4.223.164.152:64666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq4wAAAo4"]
[Tue Aug 18 12:53:20.907634 2026] [security2:error] [pid 67073:tid 67320] [client 4.223.164.152:7061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/nox.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq5AAAAoc"]
[Tue Aug 18 12:53:20.912159 2026] [security2:error] [pid 67073:tid 67230] [client 104.209.144.33:31289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/update/wpupex.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq5QAAAi0"]
[Tue Aug 18 12:53:20.912250 2026] [security2:error] [pid 66623:tid 66892] [client 104.209.144.33:31265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoR_8NO5rbWdOArH04J50wAAAYg"]
[Tue Aug 18 12:53:20.959750 2026] [security2:error] [pid 66623:tid 66767] [client 132.196.61.152:44465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/indexo.php"] [unique_id "aoR_8NO5rbWdOArH04J51AAAAQs"]
[Tue Aug 18 12:53:20.965300 2026] [security2:error] [pid 66623:tid 66883] [client 52.238.210.254:10219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/info.php"] [unique_id "aoR_8NO5rbWdOArH04J51QAAAX8"]
[Tue Aug 18 12:53:20.980968 2026] [security2:error] [pid 67073:tid 67330] [client 168.62.48.100:14735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq6AAAApE"]
[Tue Aug 18 12:53:20.982048 2026] [security2:error] [pid 66623:tid 66826] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/bajah.php"] [unique_id "aoR_8NO5rbWdOArH04J51gAAAUY"]
[Tue Aug 18 12:53:20.989817 2026] [security2:error] [pid 67073:tid 67162] [remote 57.141.22.106:57970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_8Pcmepr5_nHgLbMq6QACIFY"]
[Tue Aug 18 12:53:21.006711 2026] [security2:error] [pid 66623:tid 66834] [client 20.104.100.201:17285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/read.php"] [unique_id "aoR_8dO5rbWdOArH04J52AAAAU4"]
[Tue Aug 18 12:53:21.012343 2026] [security2:error] [pid 66623:tid 66822] [client 20.91.215.254:23716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoR_8dO5rbWdOArH04J52QAAAUI"]
[Tue Aug 18 12:53:21.033694 2026] [security2:error] [pid 67073:tid 67255] [client 5.161.194.92:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "1ba.com.br"] [uri "/index.php"] [unique_id "aoR_7_cmepr5_nHgLbMqvgACRk4"], referer: https://1ba.com.br/
[Tue Aug 18 12:53:21.034402 2026] [security2:error] [pid 67073:tid 67211] [client 68.155.154.236:64555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-2019.php"] [unique_id "aoR_8fcmepr5_nHgLbMq6wAAAho"]
[Tue Aug 18 12:53:21.037520 2026] [security2:error] [pid 66623:tid 66705] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/1337.php"] [unique_id "aoR_8dO5rbWdOArH04J52gABHUQ"]
[Tue Aug 18 12:53:21.095399 2026] [security2:error] [pid 66623:tid 66782] [client 34.198.201.66:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alsconsultoria.com.br"] [uri "/index.php"] [unique_id "aoR_79O5rbWdOArH04J5fwABGnc"], referer: https://alsconsultoria.com.br/
[Tue Aug 18 12:53:21.109738 2026] [security2:error] [pid 66623:tid 66650] [remote 136.110.27.48:40554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lencoisflat.com.br"] [uri "/config.php.bak"] [unique_id "aoR_8dO5rbWdOArH04J53wABXw0"]
[Tue Aug 18 12:53:21.124476 2026] [security2:error] [pid 66623:tid 66723] [remote 136.110.27.48:40554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lencoisflat.com.br"] [uri "/configuration.php.bak"] [unique_id "aoR_8dO5rbWdOArH04J54AABX1Y"]
[Tue Aug 18 12:53:21.171349 2026] [security2:error] [pid 67073:tid 67235] [client 20.119.58.187:14631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/mail.php"] [unique_id "aoR_8fcmepr5_nHgLbMq7QAAAjI"]
[Tue Aug 18 12:53:21.204212 2026] [security2:error] [pid 66623:tid 66854] [client 158.158.74.177:13733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/phpMailer.php"] [unique_id "aoR_8dO5rbWdOArH04J55wAAAWI"]
[Tue Aug 18 12:53:21.219926 2026] [security2:error] [pid 67073:tid 67314] [client 168.62.48.100:14825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoR_8fcmepr5_nHgLbMq7wAAAoE"]
[Tue Aug 18 12:53:21.238975 2026] [security2:error] [pid 67073:tid 67229] [client 213.35.127.232:50211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoR_8fcmepr5_nHgLbMq8AAAAiw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:21.239261 2026] [security2:error] [pid 66623:tid 66724] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/Njima.php"] [unique_id "aoR_8dO5rbWdOArH04J56AABQ1c"]
[Tue Aug 18 12:53:21.249407 2026] [security2:error] [pid 67073:tid 67209] [client 132.196.61.152:23819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/wp_motu_4r80b.php"] [unique_id "aoR_8fcmepr5_nHgLbMq8QAAAhg"]
[Tue Aug 18 12:53:21.257854 2026] [security2:error] [pid 67073:tid 67263] [client 68.221.73.131:4344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/kir.php"] [unique_id "aoR_8fcmepr5_nHgLbMq8gAAAk4"]
[Tue Aug 18 12:53:21.280154 2026] [security2:error] [pid 67073:tid 67260] [client 20.171.51.14:15762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/lv.php"] [unique_id "aoR_8fcmepr5_nHgLbMq8wAAAks"]
[Tue Aug 18 12:53:21.334507 2026] [security2:error] [pid 66623:tid 66789] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/ajax.php"] [unique_id "aoR_8dO5rbWdOArH04J56wAAASE"]
[Tue Aug 18 12:53:21.354932 2026] [autoindex:error] [pid 67073:tid 67323] [client 4.223.164.152:37256] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:21.356370 2026] [security2:error] [pid 66623:tid 66786] [client 4.223.164.152:7059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/file59.php"] [unique_id "aoR_8dO5rbWdOArH04J57AAAAR4"]
[Tue Aug 18 12:53:21.366108 2026] [security2:error] [pid 67073:tid 67299] [client 52.238.210.254:10179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/chosen.php"] [unique_id "aoR_8fcmepr5_nHgLbMq9QAAAnI"]
[Tue Aug 18 12:53:21.393212 2026] [security2:error] [pid 66623:tid 66775] [client 74.248.18.37:62345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/plugin.php"] [unique_id "aoR_8dO5rbWdOArH04J57gAAARM"]
[Tue Aug 18 12:53:21.423269 2026] [security2:error] [pid 66623:tid 66729] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/BIBIL.php"] [unique_id "aoR_8dO5rbWdOArH04J57wABeVw"]
[Tue Aug 18 12:53:21.455175 2026] [security2:error] [pid 66623:tid 66766] [client 168.62.48.100:14830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoR_8dO5rbWdOArH04J58AAAAQo"]
[Tue Aug 18 12:53:21.474909 2026] [security2:error] [pid 66623:tid 66809] [client 52.238.210.254:56205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/simple.php"] [unique_id "aoR_8dO5rbWdOArH04J58gAAATU"]
[Tue Aug 18 12:53:21.487201 2026] [security2:error] [pid 67073:tid 67319] [client 74.248.136.165:1797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/nw.php"] [unique_id "aoR_8fcmepr5_nHgLbMq9gAAAoY"]
[Tue Aug 18 12:53:21.531507 2026] [security2:error] [pid 67073:tid 67236] [client 74.249.206.207:13369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/images.php"] [unique_id "aoR_8fcmepr5_nHgLbMq9wAAAjM"]
[Tue Aug 18 12:53:21.549583 2026] [security2:error] [pid 66623:tid 66804] [client 132.196.61.152:38364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/8pyceeo.php"] [unique_id "aoR_8dO5rbWdOArH04J58wAAATA"]
[Tue Aug 18 12:53:21.560294 2026] [security2:error] [pid 66623:tid 66801] [client 20.119.58.187:15139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/upfile.php"] [unique_id "aoR_8dO5rbWdOArH04J59QAAAS0"]
[Tue Aug 18 12:53:21.562146 2026] [security2:error] [pid 66623:tid 66821] [client 40.85.222.29:45737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoR_8dO5rbWdOArH04J59gAAAUE"]
[Tue Aug 18 12:53:21.610616 2026] [security2:error] [pid 66623:tid 66712] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/too.php"] [unique_id "aoR_8dO5rbWdOArH04J59wABZks"]
[Tue Aug 18 12:53:21.618435 2026] [security2:error] [pid 67073:tid 67256] [client 104.209.144.33:31235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoR_8fcmepr5_nHgLbMq-QAAAkc"]
[Tue Aug 18 12:53:21.621848 2026] [security2:error] [pid 66623:tid 66859] [client 104.209.144.33:24861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoR_8dO5rbWdOArH04J5-AAAAWc"]
[Tue Aug 18 12:53:21.651848 2026] [security2:error] [pid 66623:tid 66845] [client 20.100.169.31:24778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/a7.php"] [unique_id "aoR_8dO5rbWdOArH04J5-QAAAVk"]
[Tue Aug 18 12:53:21.670675 2026] [security2:error] [pid 67073:tid 67277] [client 20.171.51.14:58392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/51.php"] [unique_id "aoR_8fcmepr5_nHgLbMq-gAAAlw"]
[Tue Aug 18 12:53:21.672446 2026] [security2:error] [pid 67073:tid 67321] [client 68.221.73.131:4356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/nofile.php"] [unique_id "aoR_8fcmepr5_nHgLbMq-wAAAog"]
[Tue Aug 18 12:53:21.673922 2026] [security2:error] [pid 66623:tid 66677] [remote 203.99.146.53:54174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villanobreeventos.com.br"] [uri "/wp-login.php"] [unique_id "aoR_8dO5rbWdOArH04J5-wABOyg"]
[Tue Aug 18 12:53:21.675151 2026] [security2:error] [pid 66623:tid 66830] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/adminfuns.php"] [unique_id "aoR_8dO5rbWdOArH04J5_AAAAUo"]
[Tue Aug 18 12:53:21.675883 2026] [security2:error] [pid 67073:tid 67280] [client 20.42.19.40:2232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/222.php"] [unique_id "aoR_8fcmepr5_nHgLbMq_AAAAl8"]
[Tue Aug 18 12:53:21.684375 2026] [security2:error] [pid 66623:tid 66812] [client 20.100.169.31:33167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/bless.php"] [unique_id "aoR_8dO5rbWdOArH04J5_QAAATg"]
[Tue Aug 18 12:53:21.691752 2026] [security2:error] [pid 66623:tid 66779] [client 168.62.48.100:14780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoR_8dO5rbWdOArH04J5_gAAARc"]
[Tue Aug 18 12:53:21.692651 2026] [security2:error] [pid 67073:tid 67222] [client 52.238.210.254:10128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/simple.php"] [unique_id "aoR_8fcmepr5_nHgLbMq_gAAAiU"]
[Tue Aug 18 12:53:21.718851 2026] [security2:error] [pid 67073:tid 67328] [client 68.155.154.236:64450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoR_8fcmepr5_nHgLbMq_wAAAo8"]
[Tue Aug 18 12:53:21.732540 2026] [security2:error] [pid 66623:tid 66841] [client 20.104.100.201:54023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/albin.php"] [unique_id "aoR_8dO5rbWdOArH04J5_wAAAVU"]
[Tue Aug 18 12:53:21.790051 2026] [security2:error] [pid 66623:tid 66805] [client 20.48.236.86:10625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/coffexium.php"] [unique_id "aoR_8dO5rbWdOArH04J6AQAAATE"]
[Tue Aug 18 12:53:21.797292 2026] [security2:error] [pid 67073:tid 67293] [client 4.223.164.152:37256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp.php"] [unique_id "aoR_8fcmepr5_nHgLbMrAQAAAmw"]
[Tue Aug 18 12:53:21.798234 2026] [security2:error] [pid 67073:tid 67271] [client 20.104.100.201:57313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/yas.php"] [unique_id "aoR_8fcmepr5_nHgLbMrAgAAAlY"]
[Tue Aug 18 12:53:21.821068 2026] [security2:error] [pid 66623:tid 66819] [client 20.91.215.254:20264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoR_8dO5rbWdOArH04J6BAAAAT8"]
[Tue Aug 18 12:53:21.841742 2026] [security2:error] [pid 66623:tid 66710] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/g3.php"] [unique_id "aoR_8dO5rbWdOArH04J6BgABKEk"]
[Tue Aug 18 12:53:21.850715 2026] [security2:error] [pid 67073:tid 67257] [client 172.202.39.151:43619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/aa.php"] [unique_id "aoR_8fcmepr5_nHgLbMrAwAAAkg"]
[Tue Aug 18 12:53:21.868901 2026] [security2:error] [pid 66623:tid 66733] [remote 57.141.22.5:29270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_8dO5rbWdOArH04J6CgABImA"]
[Tue Aug 18 12:53:21.893634 2026] [security2:error] [pid 66623:tid 66869] [client 158.158.74.177:13701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoR_8dO5rbWdOArH04J6DAAAAXE"]
[Tue Aug 18 12:53:21.914048 2026] [security2:error] [pid 66623:tid 66791] [client 20.119.58.187:14406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-conflg.php"] [unique_id "aoR_8dO5rbWdOArH04J6DQAAASM"]
[Tue Aug 18 12:53:21.925209 2026] [security2:error] [pid 66623:tid 66842] [client 168.62.48.100:14838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoR_8dO5rbWdOArH04J6DwAAAVY"]
[Tue Aug 18 12:53:21.927004 2026] [security2:error] [pid 67073:tid 67312] [client 20.171.51.14:43348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/22.php"] [unique_id "aoR_8fcmepr5_nHgLbMrBQAAAn8"]
[Tue Aug 18 12:53:21.930652 2026] [security2:error] [pid 67073:tid 67270] [client 132.196.61.152:45143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/.admin.php"] [unique_id "aoR_8fcmepr5_nHgLbMrBwAAAlU"]
[Tue Aug 18 12:53:21.937675 2026] [authz_core:error] [pid 66623:tid 66855] [client 192.178.4.133:64761] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:21.937986 2026] [authz_core:error] [pid 66623:tid 66855] [client 192.178.4.133:64761] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:22.015909 2026] [security2:error] [pid 66623:tid 66784] [client 40.85.222.29:37711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-content/index.php"] [unique_id "aoR_8tO5rbWdOArH04J6EwAAARw"]
[Tue Aug 18 12:53:22.018137 2026] [security2:error] [pid 66623:tid 66811] [client 104.209.144.33:31294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoR_8tO5rbWdOArH04J6FAAAATc"]
[Tue Aug 18 12:53:22.020287 2026] [security2:error] [pid 67073:tid 67298] [client 104.209.144.33:32682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoR_8vcmepr5_nHgLbMrCAAAAnE"]
[Tue Aug 18 12:53:22.058375 2026] [security2:error] [pid 66623:tid 66861] [client 52.238.210.254:10223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/ioxi-o.php"] [unique_id "aoR_8tO5rbWdOArH04J6FwAAAWk"]
[Tue Aug 18 12:53:22.087368 2026] [security2:error] [pid 67073:tid 67254] [client 68.221.73.131:4318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/fling.php"] [unique_id "aoR_8vcmepr5_nHgLbMrCgAAAkU"]
[Tue Aug 18 12:53:22.128378 2026] [security2:error] [pid 66623:tid 66880] [client 4.223.164.152:7049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/admin.php"] [unique_id "aoR_8tO5rbWdOArH04J6GQAAAXw"]
[Tue Aug 18 12:53:22.162299 2026] [security2:error] [pid 66623:tid 66778] [client 168.62.48.100:14820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoR_8tO5rbWdOArH04J6GgAAARY"]
[Tue Aug 18 12:53:22.172121 2026] [security2:error] [pid 66623:tid 66882] [client 3.20.63.178:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "graices.com.br"] [uri "/"] [unique_id "aoR_8tO5rbWdOArH04J6GwABfgc"], referer: https://graices.com.br/
[Tue Aug 18 12:53:22.177115 2026] [security2:error] [pid 67073:tid 67274] [client 52.173.121.69:17982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/blog/byp.php"] [unique_id "aoR_8vcmepr5_nHgLbMrDAAAAlk"]
[Tue Aug 18 12:53:22.247831 2026] [security2:error] [pid 67073:tid 67291] [client 4.223.164.152:46150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/i.php"] [unique_id "aoR_8vcmepr5_nHgLbMrDgAAAmo"]
[Tue Aug 18 12:53:22.252448 2026] [security2:error] [pid 66623:tid 66798] [client 213.35.127.232:50432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoR_8tO5rbWdOArH04J6HQAAASo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:22.261899 2026] [security2:error] [pid 67073:tid 67311] [client 74.248.18.37:62352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/public/moon.php"] [unique_id "aoR_8vcmepr5_nHgLbMrDwAAAn4"]
[Tue Aug 18 12:53:22.267172 2026] [security2:error] [pid 67073:tid 67315] [client 52.173.121.69:54479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-content/index.php"] [unique_id "aoR_8vcmepr5_nHgLbMrEAAAAoI"]
[Tue Aug 18 12:53:22.273240 2026] [security2:error] [pid 67073:tid 67294] [client 132.196.61.152:25673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/wsomini.php"] [unique_id "aoR_8vcmepr5_nHgLbMrEQAAAm0"]
[Tue Aug 18 12:53:22.283192 2026] [security2:error] [pid 67073:tid 67310] [client 20.119.58.187:15353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/xmrlpc.php"] [unique_id "aoR_8vcmepr5_nHgLbMrEgAAAn0"]
[Tue Aug 18 12:53:22.340362 2026] [security2:error] [pid 66623:tid 66787] [client 68.155.154.236:65100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/.cache/x.php"] [unique_id "aoR_8tO5rbWdOArH04J6IAAAAR8"]
[Tue Aug 18 12:53:22.383341 2026] [security2:error] [pid 66623:tid 66875] [client 3.20.63.178:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "graices.com.br"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aoR_8tO5rbWdOArH04J6HwABd34"], referer: https://graices.com.br/
[Tue Aug 18 12:53:22.409716 2026] [security2:error] [pid 67073:tid 67289] [client 172.202.39.151:62613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoR_8vcmepr5_nHgLbMrEwAAAmg"]
[Tue Aug 18 12:53:22.418564 2026] [security2:error] [pid 67073:tid 67212] [client 40.85.222.29:36664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoR_8vcmepr5_nHgLbMrFQAAAhs"]
[Tue Aug 18 12:53:22.419670 2026] [security2:error] [pid 67073:tid 67281] [client 168.62.48.100:14822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoR_8vcmepr5_nHgLbMrFgAAAmA"]
[Tue Aug 18 12:53:22.433513 2026] [security2:error] [pid 66623:tid 66887] [client 20.42.19.40:2699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/asasx.php"] [unique_id "aoR_8tO5rbWdOArH04J6JAAAAYM"]
[Tue Aug 18 12:53:22.441844 2026] [security2:error] [pid 67073:tid 67290] [client 20.104.100.201:17377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/fw/34.php"] [unique_id "aoR_8vcmepr5_nHgLbMrFwAAAmk"]
[Tue Aug 18 12:53:22.471184 2026] [security2:error] [pid 67073:tid 67329] [client 20.171.51.14:33664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ew.php"] [unique_id "aoR_8vcmepr5_nHgLbMrGAAAApA"]
[Tue Aug 18 12:53:22.479787 2026] [security2:error] [pid 67073:tid 67241] [client 20.91.215.254:16653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoR_8vcmepr5_nHgLbMrGQAAAjg"]
[Tue Aug 18 12:53:22.501782 2026] [security2:error] [pid 66623:tid 66854] [client 20.171.51.14:15789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/zs.php"] [unique_id "aoR_8tO5rbWdOArH04J6JgAAAWI"]
[Tue Aug 18 12:53:22.524431 2026] [security2:error] [pid 66623:tid 66785] [client 158.158.74.177:13780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/al.php"] [unique_id "aoR_8tO5rbWdOArH04J6JwAAAR0"]
[Tue Aug 18 12:53:22.526626 2026] [security2:error] [pid 67073:tid 67228] [client 68.221.73.131:4369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/zoo1.php"] [unique_id "aoR_8vcmepr5_nHgLbMrGgAAAis"]
[Tue Aug 18 12:53:22.535358 2026] [security2:error] [pid 66623:tid 66866] [client 104.209.144.33:24852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoR_8tO5rbWdOArH04J6KAAAAW4"]
[Tue Aug 18 12:53:22.558525 2026] [security2:error] [pid 67073:tid 67327] [client 104.209.144.33:24833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoR_8vcmepr5_nHgLbMrHAAAAo4"]
[Tue Aug 18 12:53:22.580198 2026] [security2:error] [pid 67073:tid 67230] [client 74.248.136.165:49781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ws62.php"] [unique_id "aoR_8vcmepr5_nHgLbMrHQAAAi0"]
[Tue Aug 18 12:53:22.630001 2026] [security2:error] [pid 66623:tid 66824] [client 132.196.61.152:45149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/vr.php"] [unique_id "aoR_8tO5rbWdOArH04J6KgAAAUQ"]
[Tue Aug 18 12:53:22.647322 2026] [security2:error] [pid 66623:tid 66797] [client 20.119.58.187:14596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/ae.php"] [unique_id "aoR_8tO5rbWdOArH04J6LAAAASk"]
[Tue Aug 18 12:53:22.664163 2026] [security2:error] [pid 67073:tid 67322] [client 168.62.48.100:14845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoR_8vcmepr5_nHgLbMrHgAAAok"]
[Tue Aug 18 12:53:22.668669 2026] [security2:error] [pid 67073:tid 67259] [client 4.223.164.152:6618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/aa2.php"] [unique_id "aoR_8vcmepr5_nHgLbMrHwAAAko"]
[Tue Aug 18 12:53:22.670362 2026] [security2:error] [pid 67073:tid 67232] [client 4.223.164.152:64697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/abcd.php"] [unique_id "aoR_8vcmepr5_nHgLbMrIAAAAi8"]
[Tue Aug 18 12:53:22.714654 2026] [security2:error] [pid 67073:tid 67276] [client 37.40.227.74:56769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_8vcmepr5_nHgLbMrIQAAAls"]
[Tue Aug 18 12:53:22.714843 2026] [security2:error] [pid 67073:tid 67276] [client 37.40.227.74:56769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_8vcmepr5_nHgLbMrIQAAAls"]
[Tue Aug 18 12:53:22.758860 2026] [security2:error] [pid 67073:tid 67252] [client 172.182.200.96:14194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/nwwha.php"] [unique_id "aoR_8vcmepr5_nHgLbMrIgAAAkM"]
[Tue Aug 18 12:53:22.771753 2026] [security2:error] [pid 66623:tid 66801] [client 172.202.39.151:56975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/222.php"] [unique_id "aoR_8tO5rbWdOArH04J6LwAAAS0"]
[Tue Aug 18 12:53:22.804491 2026] [security2:error] [pid 67073:tid 67205] [client 5.253.205.188:35774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/export.sql"] [unique_id "aoR_8vcmepr5_nHgLbMrIwAAAhQ"], referer: https://medihub.com.br/export.sql
[Tue Aug 18 12:53:22.819899 2026] [security2:error] [pid 67073:tid 67235] [client 20.65.98.162:20407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_8vcmepr5_nHgLbMrJAAAAjI"]
[Tue Aug 18 12:53:22.824285 2026] [security2:error] [pid 67073:tid 67314] [client 52.238.210.254:10231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/av.php"] [unique_id "aoR_8vcmepr5_nHgLbMrJQAAAoE"]
[Tue Aug 18 12:53:22.884892 2026] [security2:error] [pid 67073:tid 67245] [client 20.171.51.14:16753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/pqr.php"] [unique_id "aoR_8vcmepr5_nHgLbMrJgAAAjw"]
[Tue Aug 18 12:53:22.889528 2026] [security2:error] [pid 67073:tid 67263] [client 104.209.144.33:31295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoR_8vcmepr5_nHgLbMrJwAAAk4"]
[Tue Aug 18 12:53:22.890202 2026] [security2:error] [pid 66623:tid 66799] [client 104.209.144.33:25324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoR_8tO5rbWdOArH04J6NAAAASs"]
[Tue Aug 18 12:53:22.891209 2026] [security2:error] [pid 67073:tid 67303] [client 74.248.18.37:62344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/public/storage.php"] [unique_id "aoR_8vcmepr5_nHgLbMrKAAAAnY"]
[Tue Aug 18 12:53:22.896421 2026] [security2:error] [pid 67073:tid 67247] [client 168.62.48.100:14814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoR_8vcmepr5_nHgLbMrKQAAAj4"]
[Tue Aug 18 12:53:22.912340 2026] [security2:error] [pid 66623:tid 66886] [client 20.151.109.219:22955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/rx.php"] [unique_id "aoR_8tO5rbWdOArH04J6NQAAAYI"]
[Tue Aug 18 12:53:22.993920 2026] [security2:error] [pid 67073:tid 67216] [client 68.221.73.131:4804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/zoo2.php"] [unique_id "aoR_8vcmepr5_nHgLbMrKgAAAh8"]
[Tue Aug 18 12:53:23.009259 2026] [security2:error] [pid 67073:tid 67260] [client 20.119.58.187:14594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/moon.php"] [unique_id "aoR_8_cmepr5_nHgLbMrKwAAAks"]
[Tue Aug 18 12:53:23.049152 2026] [security2:error] [pid 66623:tid 66789] [client 149.34.210.157:64406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_89O5rbWdOArH04J6OAAAASE"]
[Tue Aug 18 12:53:23.058819 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:23.059087 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:23.079631 2026] [security2:error] [pid 67073:tid 67253] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-good.php"] [unique_id "aoR_8_cmepr5_nHgLbMrLgAAAkQ"]
[Tue Aug 18 12:53:23.113270 2026] [security2:error] [pid 67073:tid 67328] [client 172.202.39.151:24943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/0x.php"] [unique_id "aoR_8_cmepr5_nHgLbMrLwAAAo8"]
[Tue Aug 18 12:53:23.116754 2026] [security2:error] [pid 67073:tid 67208] [client 52.139.47.57:11552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/twentytwenty/functions.php"] [unique_id "aoR_8_cmepr5_nHgLbMrMAAAAhc"]
[Tue Aug 18 12:53:23.127585 2026] [security2:error] [pid 67073:tid 67293] [client 4.223.164.152:46178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-manager.php"] [unique_id "aoR_8_cmepr5_nHgLbMrMgAAAmw"]
[Tue Aug 18 12:53:23.129641 2026] [authz_core:error] [pid 67073:tid 67170] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:23.129922 2026] [authz_core:error] [pid 67073:tid 67170] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:23.131052 2026] [security2:error] [pid 67073:tid 67271] [client 168.62.48.100:16382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoR_8_cmepr5_nHgLbMrMwAAAlY"]
[Tue Aug 18 12:53:23.138115 2026] [security2:error] [pid 67073:tid 67295] [client 20.48.236.86:65100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/dex.php"] [unique_id "aoR_8_cmepr5_nHgLbMrNAAAAm4"]
[Tue Aug 18 12:53:23.154656 2026] [security2:error] [pid 67073:tid 67273] [client 74.249.206.207:21032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/mac.php"] [unique_id "aoR_8_cmepr5_nHgLbMrNgAAAlg"]
[Tue Aug 18 12:53:23.154680 2026] [security2:error] [pid 67073:tid 67257] [client 40.85.222.29:30502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoR_8_cmepr5_nHgLbMrNQAAAkg"]
[Tue Aug 18 12:53:23.179785 2026] [security2:error] [pid 67073:tid 67249] [client 20.91.215.254:22955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/xmrlpc.php"] [unique_id "aoR_8_cmepr5_nHgLbMrOAAAAkA"]
[Tue Aug 18 12:53:23.189747 2026] [security2:error] [pid 67073:tid 67265] [client 158.158.74.177:13697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/wp.php"] [unique_id "aoR_8_cmepr5_nHgLbMrOQAAAlA"]
[Tue Aug 18 12:53:23.196327 2026] [security2:error] [pid 67073:tid 67238] [client 4.223.164.152:6629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/xamp.php"] [unique_id "aoR_8_cmepr5_nHgLbMrOgAAAjU"]
[Tue Aug 18 12:53:23.261551 2026] [security2:error] [pid 67073:tid 67264] [client 104.209.144.33:24878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoR_8_cmepr5_nHgLbMrOwAAAk8"]
[Tue Aug 18 12:53:23.263074 2026] [security2:error] [pid 66623:tid 66773] [client 213.35.127.232:50674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoR_89O5rbWdOArH04J6PAAAARE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:23.263074 2026] [security2:error] [pid 67073:tid 67251] [client 104.209.144.33:25331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/well-known/index.php"] [unique_id "aoR_8_cmepr5_nHgLbMrPAAAAkI"]
[Tue Aug 18 12:53:23.264830 2026] [security2:error] [pid 67073:tid 67298] [client 20.104.100.201:54044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp9.php"] [unique_id "aoR_8_cmepr5_nHgLbMrPQAAAnE"]
[Tue Aug 18 12:53:23.319309 2026] [security2:error] [pid 66623:tid 66789] [client 149.34.210.157:64406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_89O5rbWdOArH04J6OAAAASE"]
[Tue Aug 18 12:53:23.369887 2026] [security2:error] [pid 67073:tid 67312] [client 20.119.58.187:14608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/ini.php"] [unique_id "aoR_8_cmepr5_nHgLbMrPwAAAn8"]
[Tue Aug 18 12:53:23.403686 2026] [security2:error] [pid 67073:tid 67310] [client 168.62.48.100:14728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoR_8_cmepr5_nHgLbMrQAAAAn0"]
[Tue Aug 18 12:53:23.409507 2026] [security2:error] [pid 67073:tid 67331] [client 52.173.121.69:54437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoR_8_cmepr5_nHgLbMrQQAAApI"]
[Tue Aug 18 12:53:23.431472 2026] [authz_core:error] [pid 67073:tid 67172] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:23.431756 2026] [authz_core:error] [pid 67073:tid 67172] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:23.441739 2026] [security2:error] [pid 67073:tid 67272] [client 68.221.73.131:4226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/org.php"] [unique_id "aoR_8_cmepr5_nHgLbMrQwAAAlc"]
[Tue Aug 18 12:53:23.443107 2026] [security2:error] [pid 67073:tid 67289] [client 20.104.100.201:57329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/ah25.php"] [unique_id "aoR_8_cmepr5_nHgLbMrRAAAAmg"]
[Tue Aug 18 12:53:23.490177 2026] [security2:error] [pid 67073:tid 67212] [client 74.249.206.207:21005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/ops.php"] [unique_id "aoR_8_cmepr5_nHgLbMrRgAAAhs"]
[Tue Aug 18 12:53:23.543400 2026] [security2:error] [pid 67073:tid 67282] [client 52.238.210.254:31474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/ioxi-o.php"] [unique_id "aoR_8_cmepr5_nHgLbMrRwAAAmE"]
[Tue Aug 18 12:53:23.547135 2026] [security2:error] [pid 67073:tid 67210] [client 104.209.144.33:32673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoR_8_cmepr5_nHgLbMrSAAAAhk"]
[Tue Aug 18 12:53:23.552397 2026] [security2:error] [pid 67073:tid 67286] [client 196.12.128.158:53110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoR_8_cmepr5_nHgLbMrSQAAAmU"]
[Tue Aug 18 12:53:23.552563 2026] [security2:error] [pid 67073:tid 67286] [client 196.12.128.158:53110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoR_8_cmepr5_nHgLbMrSQAAAmU"]
[Tue Aug 18 12:53:23.570504 2026] [security2:error] [pid 67073:tid 67274] [client 74.248.18.37:62378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/radio.php"] [unique_id "aoR_8_cmepr5_nHgLbMrSgAAAlk"]
[Tue Aug 18 12:53:23.571859 2026] [security2:error] [pid 66623:tid 66812] [client 104.209.144.33:24844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoR_89O5rbWdOArH04J6RwAAATg"]
[Tue Aug 18 12:53:23.586658 2026] [security2:error] [pid 67073:tid 67241] [client 4.223.164.152:37296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoR_8_cmepr5_nHgLbMrSwAAAjg"]
[Tue Aug 18 12:53:23.606704 2026] [security2:error] [pid 67073:tid 67313] [client 4.232.151.198:30468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/xleet.php"] [unique_id "aoR_8_cmepr5_nHgLbMrTAAAAoA"]
[Tue Aug 18 12:53:23.637937 2026] [security2:error] [pid 67073:tid 67230] [client 168.62.48.100:14803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoR_8_cmepr5_nHgLbMrTQAAAi0"]
[Tue Aug 18 12:53:23.641262 2026] [security2:error] [pid 67073:tid 67297] [client 20.171.51.14:29203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/an.php"] [unique_id "aoR_8_cmepr5_nHgLbMrTgAAAnA"]
[Tue Aug 18 12:53:23.647192 2026] [security2:error] [pid 67073:tid 67217] [client 52.238.210.254:10139] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-admin"] [unique_id "aoR_8_cmepr5_nHgLbMrTwAAAiA"]
[Tue Aug 18 12:53:23.689445 2026] [security2:error] [pid 67073:tid 67232] [client 52.173.121.69:17937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoR_8_cmepr5_nHgLbMrUAAAAi8"]
[Tue Aug 18 12:53:23.727611 2026] [security2:error] [pid 67073:tid 67288] [client 20.119.58.187:15141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/shell.php"] [unique_id "aoR_8_cmepr5_nHgLbMrUQAAAmc"]
[Tue Aug 18 12:53:23.797006 2026] [security2:error] [pid 66623:tid 66891] [client 4.223.164.152:6622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/bless.php"] [unique_id "aoR_89O5rbWdOArH04J6UAAAAYc"]
[Tue Aug 18 12:53:23.815434 2026] [security2:error] [pid 66623:tid 66841] [client 158.158.74.177:13711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/wp-activat.php"] [unique_id "aoR_89O5rbWdOArH04J6UQAAAVU"]
[Tue Aug 18 12:53:23.836640 2026] [security2:error] [pid 66623:tid 66790] [client 68.155.154.236:62613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoR_89O5rbWdOArH04J6UgAAASI"]
[Tue Aug 18 12:53:23.868117 2026] [security2:error] [pid 66623:tid 66814] [client 68.221.73.131:4298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/imageskir.php"] [unique_id "aoR_89O5rbWdOArH04J6VAAAATo"]
[Tue Aug 18 12:53:23.873710 2026] [security2:error] [pid 66623:tid 66792] [client 168.62.48.100:14660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoR_89O5rbWdOArH04J6VQAAASQ"]
[Tue Aug 18 12:53:23.915432 2026] [security2:error] [pid 66623:tid 66791] [client 74.248.136.165:23367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/public/vx.php"] [unique_id "aoR_89O5rbWdOArH04J6WAAAASM"]
[Tue Aug 18 12:53:23.917968 2026] [security2:error] [pid 67073:tid 67301] [client 40.85.222.29:29230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoR_8_cmepr5_nHgLbMrUgAAAnQ"]
[Tue Aug 18 12:53:23.918929 2026] [security2:error] [pid 67073:tid 67262] [client 74.248.18.37:50566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoR_8_cmepr5_nHgLbMrUwAAAk0"]
[Tue Aug 18 12:53:23.936112 2026] [security2:error] [pid 67073:tid 67211] [client 20.91.215.254:16680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoR_8_cmepr5_nHgLbMrVAAAAho"]
[Tue Aug 18 12:53:23.949914 2026] [security2:error] [pid 66623:tid 66888] [client 104.209.144.33:25315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoR_89O5rbWdOArH04J6WgAAAYQ"]
[Tue Aug 18 12:53:23.981089 2026] [security2:error] [pid 66623:tid 66820] [client 104.209.144.33:32659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoR_89O5rbWdOArH04J6XgAAAUA"]
[Tue Aug 18 12:53:23.995472 2026] [security2:error] [pid 67073:tid 67245] [client 20.104.100.201:54042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/save.php"] [unique_id "aoR_8_cmepr5_nHgLbMrVQAAAjw"]
[Tue Aug 18 12:53:24.036442 2026] [security2:error] [pid 66623:tid 66663] [remote 57.141.22.17:58500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_9NO5rbWdOArH04J6XwABVho"]
[Tue Aug 18 12:53:24.079207 2026] [security2:error] [pid 67073:tid 67263] [client 20.151.109.219:42760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/mandrill.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrVgAAAk4"]
[Tue Aug 18 12:53:24.094102 2026] [security2:error] [pid 67073:tid 67303] [client 4.223.164.152:46171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrVwAAAnY"]
[Tue Aug 18 12:53:24.096268 2026] [security2:error] [pid 66623:tid 66835] [client 20.119.58.187:15261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/makeasmtp.php"] [unique_id "aoR_9NO5rbWdOArH04J6YQAAAU8"]
[Tue Aug 18 12:53:24.106319 2026] [security2:error] [pid 67073:tid 67323] [client 168.62.48.100:14720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrWAAAAoo"]
[Tue Aug 18 12:53:24.168299 2026] [security2:error] [pid 67073:tid 67214] [client 74.249.206.207:58196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/coffexium.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrWQAAAh0"]
[Tue Aug 18 12:53:24.185852 2026] [security2:error] [pid 66623:tid 66885] [client 20.171.51.14:33698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/sy.php"] [unique_id "aoR_9NO5rbWdOArH04J6ZQAAAYE"]
[Tue Aug 18 12:53:24.189763 2026] [security2:error] [pid 67073:tid 67236] [client 20.171.51.14:15750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/iz.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrWgAAAjM"]
[Tue Aug 18 12:53:24.212223 2026] [security2:error] [pid 66623:tid 66811] [client 74.248.18.37:62824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/root.php"] [unique_id "aoR_9NO5rbWdOArH04J6ZgAAATc"]
[Tue Aug 18 12:53:24.270640 2026] [security2:error] [pid 67073:tid 67224] [client 52.139.47.57:18360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-admin.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrWwAAAic"]
[Tue Aug 18 12:53:24.274230 2026] [security2:error] [pid 67073:tid 67229] [client 213.35.127.232:50894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrXAAAAiw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:24.300944 2026] [security2:error] [pid 66623:tid 66844] [client 68.221.73.131:4856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/indexo.php"] [unique_id "aoR_9NO5rbWdOArH04J6aAAAAVg"]
[Tue Aug 18 12:53:24.317334 2026] [security2:error] [pid 66623:tid 66813] [client 4.223.164.152:6862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/file25.php"] [unique_id "aoR_9NO5rbWdOArH04J6agAAATk"]
[Tue Aug 18 12:53:24.342843 2026] [security2:error] [pid 66623:tid 66787] [client 168.62.48.100:14681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoR_9NO5rbWdOArH04J6awAAAR8"]
[Tue Aug 18 12:53:24.366005 2026] [security2:error] [pid 66623:tid 66702] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9NO5rbWdOArH04J6bAABJUE"]
[Tue Aug 18 12:53:24.366194 2026] [security2:error] [pid 66623:tid 66793] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9NO5rbWdOArH04J6bAABJUE"]
[Tue Aug 18 12:53:24.372055 2026] [security2:error] [pid 66623:tid 66878] [client 68.155.154.236:63925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-content/index.php"] [unique_id "aoR_9NO5rbWdOArH04J6bQAAAXo"]
[Tue Aug 18 12:53:24.376705 2026] [security2:error] [pid 66623:tid 66783] [client 52.238.210.254:10114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp.php"] [unique_id "aoR_9NO5rbWdOArH04J6bgAAARs"]
[Tue Aug 18 12:53:24.449009 2026] [security2:error] [pid 66623:tid 66807] [client 197.184.64.235:41354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9NO5rbWdOArH04J6cAAAATM"]
[Tue Aug 18 12:53:24.449115 2026] [security2:error] [pid 66623:tid 66807] [client 197.184.64.235:41354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9NO5rbWdOArH04J6cAAAATM"]
[Tue Aug 18 12:53:24.460444 2026] [security2:error] [pid 67073:tid 67231] [client 158.158.74.177:14230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrXgAAAi4"]
[Tue Aug 18 12:53:24.463913 2026] [security2:error] [pid 66623:tid 66816] [client 20.119.58.187:14646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-sigunq.php"] [unique_id "aoR_9NO5rbWdOArH04J6cQAAATw"]
[Tue Aug 18 12:53:24.565813 2026] [security2:error] [pid 67073:tid 67299] [client 20.100.169.31:12625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/sagax1.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrXwAAAnI"]
[Tue Aug 18 12:53:24.572322 2026] [security2:error] [pid 66623:tid 66775] [client 104.209.144.33:25290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoR_9NO5rbWdOArH04J6cwAAARM"]
[Tue Aug 18 12:53:24.578831 2026] [security2:error] [pid 66623:tid 66824] [client 168.62.48.100:14837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoR_9NO5rbWdOArH04J6dAAAAUQ"]
[Tue Aug 18 12:53:24.599210 2026] [security2:error] [pid 66623:tid 66809] [client 20.48.236.86:10678] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "m2mit.info"] [uri "/1.php"] [unique_id "aoR_9NO5rbWdOArH04J6dwAAATU"]
[Tue Aug 18 12:53:24.599308 2026] [security2:error] [pid 66623:tid 66809] [client 20.48.236.86:10678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/1.php"] [unique_id "aoR_9NO5rbWdOArH04J6dwAAATU"]
[Tue Aug 18 12:53:24.629181 2026] [autoindex:error] [pid 66623:tid 66851] [client 20.91.215.254:16651] AH01276: Cannot serve directory /home2/reservamatadapra/public_html/wp-admin/css/colors/ocean/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:24.636416 2026] [security2:error] [pid 66623:tid 66782] [client 20.100.169.31:16591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/manager.php"] [unique_id "aoR_9NO5rbWdOArH04J6eAAAARo"]
[Tue Aug 18 12:53:24.654866 2026] [security2:error] [pid 66623:tid 66795] [client 20.42.19.40:2202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/filemanager.php"] [unique_id "aoR_9NO5rbWdOArH04J6fAAAASc"]
[Tue Aug 18 12:53:24.660351 2026] [security2:error] [pid 66623:tid 66800] [client 40.85.222.29:27770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoR_9NO5rbWdOArH04J6fQAAASw"]
[Tue Aug 18 12:53:24.686215 2026] [security2:error] [pid 67073:tid 67173] [remote 203.99.146.53:54178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guinchomarquette.com.br"] [uri "/wp-login.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrYAACUmE"]
[Tue Aug 18 12:53:24.688168 2026] [security2:error] [pid 66623:tid 66773] [client 20.171.51.14:58878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/57.php"] [unique_id "aoR_9NO5rbWdOArH04J6fgAAARE"]
[Tue Aug 18 12:53:24.720352 2026] [security2:error] [pid 66623:tid 66890] [client 20.171.51.14:36474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/se.php"] [unique_id "aoR_9NO5rbWdOArH04J6gAAAAYY"]
[Tue Aug 18 12:53:24.720647 2026] [security2:error] [pid 66623:tid 66845] [client 68.221.73.131:4294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoR_9NO5rbWdOArH04J6gQAAAVk"]
[Tue Aug 18 12:53:24.738373 2026] [security2:error] [pid 66623:tid 66830] [client 104.209.144.33:25342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoR_9NO5rbWdOArH04J6ggAAAUo"]
[Tue Aug 18 12:53:24.756353 2026] [security2:error] [pid 66623:tid 66801] [client 74.7.241.147:37954] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.halleyhotel.natbrweb.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoR_9NO5rbWdOArH04J6gwABLTY"]
[Tue Aug 18 12:53:24.759492 2026] [security2:error] [pid 66623:tid 66812] [client 20.104.100.201:40402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/ano.php"] [unique_id "aoR_9NO5rbWdOArH04J6hAAAATg"]
[Tue Aug 18 12:53:24.760946 2026] [security2:error] [pid 66623:tid 66827] [client 4.223.164.152:46203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/simple.php"] [unique_id "aoR_9NO5rbWdOArH04J6hQAAAUc"]
[Tue Aug 18 12:53:24.797924 2026] [security2:error] [pid 66623:tid 66779] [client 192.141.172.134:50835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9NO5rbWdOArH04J6hgAAARc"]
[Tue Aug 18 12:53:24.798067 2026] [security2:error] [pid 66623:tid 66779] [client 192.141.172.134:50835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9NO5rbWdOArH04J6hgAAARc"]
[Tue Aug 18 12:53:24.806535 2026] [security2:error] [pid 67073:tid 67271] [client 52.238.210.254:10152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/file2.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrYgAAAlY"]
[Tue Aug 18 12:53:24.813107 2026] [security2:error] [pid 67073:tid 67257] [client 168.62.48.100:14796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrYwAAAkg"]
[Tue Aug 18 12:53:24.815944 2026] [security2:error] [pid 66623:tid 66859] [client 20.119.58.187:14595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wso112233.php"] [unique_id "aoR_9NO5rbWdOArH04J6iAAAAWc"]
[Tue Aug 18 12:53:24.824955 2026] [security2:error] [pid 67073:tid 67249] [client 132.196.61.152:56080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrZAAAAkA"]
[Tue Aug 18 12:53:24.835670 2026] [security2:error] [pid 66623:tid 66772] [client 20.104.100.201:54036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoR_9NO5rbWdOArH04J6igAAARA"]
[Tue Aug 18 12:53:24.838606 2026] [security2:error] [pid 66623:tid 66891] [client 20.91.215.254:16651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/ku.php"] [unique_id "aoR_9NO5rbWdOArH04J6iwAAAYc"]
[Tue Aug 18 12:53:24.854382 2026] [security2:error] [pid 66623:tid 66874] [client 74.248.18.37:62794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/server.php"] [unique_id "aoR_9NO5rbWdOArH04J6jAAAAXY"]
[Tue Aug 18 12:53:24.883773 2026] [security2:error] [pid 66623:tid 66792] [client 68.155.154.236:63830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoR_9NO5rbWdOArH04J6jQAAASQ"]
[Tue Aug 18 12:53:24.896060 2026] [security2:error] [pid 67073:tid 67240] [client 4.223.164.152:6650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/file15.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrZwAAAjc"]
[Tue Aug 18 12:53:24.956860 2026] [security2:error] [pid 66623:tid 66770] [client 74.249.206.207:52122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoR_9NO5rbWdOArH04J6jwAAAQ4"]
[Tue Aug 18 12:53:25.003789 2026] [security2:error] [pid 67073:tid 67250] [client 20.65.98.162:17799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/admin.php"] [unique_id "aoR_9fcmepr5_nHgLbMraQAAAkE"]
[Tue Aug 18 12:53:25.052237 2026] [security2:error] [pid 66623:tid 66880] [client 168.62.48.100:16292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoR_9dO5rbWdOArH04J6kAAAAXw"]
[Tue Aug 18 12:53:25.078952 2026] [security2:error] [pid 67073:tid 67302] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/simple.php"] [unique_id "aoR_9fcmepr5_nHgLbMrawAAAnU"]
[Tue Aug 18 12:53:25.090162 2026] [security2:error] [pid 66623:tid 66790] [client 158.158.74.177:14214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/past1.php"] [unique_id "aoR_9dO5rbWdOArH04J6kQAAASI"]
[Tue Aug 18 12:53:25.095287 2026] [security2:error] [pid 67073:tid 67254] [client 104.209.144.33:25328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/mt/byp.php"] [unique_id "aoR_9fcmepr5_nHgLbMrbAAAAkU"]
[Tue Aug 18 12:53:25.141939 2026] [security2:error] [pid 67073:tid 67285] [client 68.221.73.131:4854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/8pyceeo.php"] [unique_id "aoR_9fcmepr5_nHgLbMrbQAAAmQ"]
[Tue Aug 18 12:53:25.143856 2026] [security2:error] [pid 67073:tid 67225] [client 52.173.121.69:16489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoR_9fcmepr5_nHgLbMrbgAAAig"]
[Tue Aug 18 12:53:25.166705 2026] [security2:error] [pid 66623:tid 66826] [client 104.209.144.33:31280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/rezor.php"] [unique_id "aoR_9dO5rbWdOArH04J6kgAAAUY"]
[Tue Aug 18 12:53:25.170528 2026] [security2:error] [pid 66623:tid 66856] [client 20.119.58.187:15234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/fw.php"] [unique_id "aoR_9dO5rbWdOArH04J6kwAAAWQ"]
[Tue Aug 18 12:53:25.181906 2026] [security2:error] [pid 66623:tid 66882] [client 138.36.100.162:42757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9dO5rbWdOArH04J6lAAAAX4"]
[Tue Aug 18 12:53:25.181988 2026] [security2:error] [pid 66623:tid 66882] [client 138.36.100.162:42757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9dO5rbWdOArH04J6lAAAAX4"]
[Tue Aug 18 12:53:25.242776 2026] [security2:error] [pid 67073:tid 67268] [client 86.120.159.145:61679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9fcmepr5_nHgLbMrcQAAAlM"]
[Tue Aug 18 12:53:25.242930 2026] [security2:error] [pid 67073:tid 67268] [client 86.120.159.145:61679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9fcmepr5_nHgLbMrcQAAAlM"]
[Tue Aug 18 12:53:25.278386 2026] [security2:error] [pid 66623:tid 66834] [client 20.42.19.40:2709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/themes.php"] [unique_id "aoR_9dO5rbWdOArH04J6lgAAAU4"]
[Tue Aug 18 12:53:25.285685 2026] [security2:error] [pid 67073:tid 67215] [client 213.35.127.232:51107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoR_9fcmepr5_nHgLbMrcgAAAh4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:25.286953 2026] [security2:error] [pid 66623:tid 66808] [client 168.62.48.100:16278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoR_9dO5rbWdOArH04J6lwAAATQ"]
[Tue Aug 18 12:53:25.357171 2026] [security2:error] [pid 66623:tid 66706] [remote 103.56.163.133:44822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "docurso.com"] [uri "/wp-login.php"] [unique_id "aoR_9dO5rbWdOArH04J6mAABVEU"]
[Tue Aug 18 12:53:25.409407 2026] [security2:error] [pid 66623:tid 66839] [client 20.171.51.14:15781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ah.php"] [unique_id "aoR_9dO5rbWdOArH04J6mQAAAVM"]
[Tue Aug 18 12:53:25.417585 2026] [security2:error] [pid 66623:tid 66816] [client 20.171.51.14:36441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/vp.php"] [unique_id "aoR_9dO5rbWdOArH04J6mgAAATw"]
[Tue Aug 18 12:53:25.423915 2026] [security2:error] [pid 66623:tid 66867] [client 4.223.164.152:6642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/f35.php"] [unique_id "aoR_9dO5rbWdOArH04J6mwAAAW8"]
[Tue Aug 18 12:53:25.430571 2026] [security2:error] [pid 66623:tid 66785] [client 20.48.236.86:10719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/coffee.php"] [unique_id "aoR_9dO5rbWdOArH04J6nQAAAR0"]
[Tue Aug 18 12:53:25.440190 2026] [security2:error] [pid 66623:tid 66849] [client 20.104.100.201:65142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/nwflm.php"] [unique_id "aoR_9dO5rbWdOArH04J6ngAAAV0"]
[Tue Aug 18 12:53:25.440860 2026] [security2:error] [pid 67073:tid 67317] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/edit-tags.php"] [unique_id "aoR_9fcmepr5_nHgLbMrcwAAAoQ"]
[Tue Aug 18 12:53:25.444939 2026] [security2:error] [pid 66623:tid 66768] [client 5.31.227.224:29912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9dO5rbWdOArH04J6nwAAAQw"]
[Tue Aug 18 12:53:25.445024 2026] [security2:error] [pid 66623:tid 66768] [client 5.31.227.224:29912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9dO5rbWdOArH04J6nwAAAQw"]
[Tue Aug 18 12:53:25.477190 2026] [security2:error] [pid 66623:tid 66824] [client 52.238.210.254:57894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/av.php"] [unique_id "aoR_9dO5rbWdOArH04J6oAAAAUQ"]
[Tue Aug 18 12:53:25.482255 2026] [autoindex:error] [pid 66623:tid 66854] [client 4.223.164.152:64654] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:25.502385 2026] [security2:error] [pid 66623:tid 66797] [client 40.85.222.29:45706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoR_9dO5rbWdOArH04J6oQAAASk"]
[Tue Aug 18 12:53:25.503445 2026] [security2:error] [pid 67073:tid 67272] [client 104.209.144.33:31274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoR_9fcmepr5_nHgLbMrdQAAAlc"]
[Tue Aug 18 12:53:25.516611 2026] [security2:error] [pid 67073:tid 67212] [client 20.226.56.190:21154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/ho.php"] [unique_id "aoR_9fcmepr5_nHgLbMrdgAAAhs"]
[Tue Aug 18 12:53:25.527054 2026] [security2:error] [pid 67073:tid 67206] [client 4.232.151.198:27835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/wp.php"] [unique_id "aoR_9fcmepr5_nHgLbMrdwAAAhU"]
[Tue Aug 18 12:53:25.528167 2026] [security2:error] [pid 66623:tid 66887] [client 20.119.58.187:15317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "aoR_9dO5rbWdOArH04J6ogAAAYM"]
[Tue Aug 18 12:53:25.532411 2026] [security2:error] [pid 66623:tid 66809] [client 172.202.39.151:36454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/zxz.php"] [unique_id "aoR_9dO5rbWdOArH04J6owAAATU"]
[Tue Aug 18 12:53:25.546440 2026] [security2:error] [pid 67073:tid 67218] [client 20.104.100.201:17364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/gecko-new.php"] [unique_id "aoR_9fcmepr5_nHgLbMreAAAAiE"]
[Tue Aug 18 12:53:25.553081 2026] [security2:error] [pid 66623:tid 66851] [client 168.62.48.100:16335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/rezor.php"] [unique_id "aoR_9dO5rbWdOArH04J6pQAAAV8"]
[Tue Aug 18 12:53:25.556337 2026] [security2:error] [pid 67073:tid 67294] [client 52.139.47.57:3993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoR_9fcmepr5_nHgLbMreQAAAm0"]
[Tue Aug 18 12:53:25.559195 2026] [security2:error] [pid 66623:tid 66844] [client 74.248.18.37:62815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoR_9dO5rbWdOArH04J6pgAAAVg"]
[Tue Aug 18 12:53:25.601272 2026] [autoindex:error] [pid 66623:tid 66793] [client 20.91.215.254:23721] AH01276: Cannot serve directory /home2/reservamatadapra/public_html/wp-admin/css/colors/light/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:25.621669 2026] [security2:error] [pid 67073:tid 67210] [client 68.221.73.131:4259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/.admin.php"] [unique_id "aoR_9fcmepr5_nHgLbMregAAAhk"]
[Tue Aug 18 12:53:25.696652 2026] [security2:error] [pid 67073:tid 67313] [client 52.238.210.254:10153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/images/class-config.php"] [unique_id "aoR_9fcmepr5_nHgLbMrfAAAAoA"]
[Tue Aug 18 12:53:25.722995 2026] [security2:error] [pid 67073:tid 67289] [client 158.158.74.177:13707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/file61.php"] [unique_id "aoR_9fcmepr5_nHgLbMrfQAAAmg"]
[Tue Aug 18 12:53:25.731906 2026] [security2:error] [pid 67073:tid 67306] [client 74.248.136.165:58638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/loxi-o.php"] [unique_id "aoR_9fcmepr5_nHgLbMrfgAAAnk"]
[Tue Aug 18 12:53:25.746411 2026] [security2:error] [pid 67073:tid 67327] [client 20.42.19.40:2209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/admin.php"] [unique_id "aoR_9fcmepr5_nHgLbMrfwAAAo4"]
[Tue Aug 18 12:53:25.792430 2026] [security2:error] [pid 66623:tid 66779] [client 168.62.48.100:16267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/uploads/bypass.php"] [unique_id "aoR_9dO5rbWdOArH04J6rwAAARc"]
[Tue Aug 18 12:53:25.811381 2026] [security2:error] [pid 66623:tid 66781] [client 20.91.215.254:23721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/chosen.php"] [unique_id "aoR_9dO5rbWdOArH04J6sAAAARk"]
[Tue Aug 18 12:53:25.848586 2026] [security2:error] [pid 66623:tid 66881] [client 20.171.51.14:57374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/vw.php"] [unique_id "aoR_9dO5rbWdOArH04J6sQAAAX0"]
[Tue Aug 18 12:53:25.869674 2026] [security2:error] [pid 66623:tid 66891] [client 104.209.144.33:25282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoR_9dO5rbWdOArH04J6sgAAAYc"]
[Tue Aug 18 12:53:25.894806 2026] [security2:error] [pid 67073:tid 67330] [client 20.119.58.187:14609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/classsmtps.php"] [unique_id "aoR_9fcmepr5_nHgLbMrgQAAApE"]
[Tue Aug 18 12:53:25.896873 2026] [security2:error] [pid 66623:tid 66874] [client 4.223.164.152:64654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/chosen.php"] [unique_id "aoR_9dO5rbWdOArH04J6swAAAXY"]
[Tue Aug 18 12:53:25.909062 2026] [security2:error] [pid 66623:tid 66792] [client 4.223.164.152:6653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wp-load.php"] [unique_id "aoR_9dO5rbWdOArH04J6tAAAASQ"]
[Tue Aug 18 12:53:25.957451 2026] [security2:error] [pid 66623:tid 66847] [client 132.196.61.152:56084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_9dO5rbWdOArH04J6uAAAAVs"]
[Tue Aug 18 12:53:25.965634 2026] [security2:error] [pid 67073:tid 67252] [client 20.104.100.201:53867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/df.php"] [unique_id "aoR_9fcmepr5_nHgLbMrggAAAkM"]
[Tue Aug 18 12:53:25.979965 2026] [security2:error] [pid 67073:tid 67304] [client 52.173.121.69:50739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoR_9fcmepr5_nHgLbMrgwAAAnc"]
[Tue Aug 18 12:53:25.989564 2026] [security2:error] [pid 67073:tid 67223] [client 52.173.121.69:25000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/images/security.php"] [unique_id "aoR_9fcmepr5_nHgLbMrhQAAAiY"]
[Tue Aug 18 12:53:26.027893 2026] [security2:error] [pid 66623:tid 66805] [client 168.62.48.100:14756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoR_9tO5rbWdOArH04J6uwAAATE"]
[Tue Aug 18 12:53:26.033567 2026] [security2:error] [pid 66623:tid 66780] [client 68.221.73.131:4340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/wsomini.php"] [unique_id "aoR_9tO5rbWdOArH04J6vAAAARg"]
[Tue Aug 18 12:53:26.057611 2026] [autoindex:error] [pid 66623:tid 66880] [client 169.58.72.249:50192] AH01276: Cannot serve directory /var/www/html/.well-known/: No matching DirectoryIndex (index.cgi,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:26.144070 2026] [security2:error] [pid 66623:tid 66811] [client 104.209.144.33:32650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoR_9tO5rbWdOArH04J6xwAAATc"]
[Tue Aug 18 12:53:26.171667 2026] [security2:error] [pid 67073:tid 67216] [client 20.226.56.190:20898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/97.php"] [unique_id "aoR_9vcmepr5_nHgLbMrhwAAAh8"]
[Tue Aug 18 12:53:26.174024 2026] [security2:error] [pid 67073:tid 67319] [client 20.104.100.201:65090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/wp-load.php"] [unique_id "aoR_9vcmepr5_nHgLbMriAAAAoY"]
[Tue Aug 18 12:53:26.178535 2026] [security2:error] [pid 66623:tid 66803] [client 74.249.206.207:63338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/sf.php"] [unique_id "aoR_9tO5rbWdOArH04J6yAAAAS8"]
[Tue Aug 18 12:53:26.192835 2026] [security2:error] [pid 66623:tid 66820] [client 74.248.18.37:62337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/shell.php"] [unique_id "aoR_9tO5rbWdOArH04J6yQAAAUA"]
[Tue Aug 18 12:53:26.224110 2026] [security2:error] [pid 66623:tid 66863] [client 20.42.19.40:2215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/buy.php"] [unique_id "aoR_9tO5rbWdOArH04J6ygAAAWs"]
[Tue Aug 18 12:53:26.262259 2026] [security2:error] [pid 66623:tid 66839] [client 168.62.48.100:14797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/index/function.php"] [unique_id "aoR_9tO5rbWdOArH04J6ywAAAVM"]
[Tue Aug 18 12:53:26.262640 2026] [security2:error] [pid 66623:tid 66788] [client 74.248.18.37:50578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/222.php"] [unique_id "aoR_9tO5rbWdOArH04J6zAAAASA"]
[Tue Aug 18 12:53:26.264317 2026] [security2:error] [pid 66623:tid 66885] [client 20.119.58.187:15328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-blog-header.php"] [unique_id "aoR_9tO5rbWdOArH04J6zQAAAYE"]
[Tue Aug 18 12:53:26.265585 2026] [security2:error] [pid 67073:tid 67213] [client 104.209.144.33:31271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoR_9vcmepr5_nHgLbMrigAAAhw"]
[Tue Aug 18 12:53:26.299424 2026] [security2:error] [pid 67073:tid 67248] [client 213.35.127.232:51312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoR_9vcmepr5_nHgLbMriwAAAj8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:26.302950 2026] [security2:error] [pid 67073:tid 67256] [client 68.155.154.236:64569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoR_9vcmepr5_nHgLbMrjAAAAkc"]
[Tue Aug 18 12:53:26.368572 2026] [autoindex:error] [pid 66623:tid 66866] [client 4.223.164.152:64644] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:26.397814 2026] [security2:error] [pid 67073:tid 67229] [client 20.104.100.201:53835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoR_9vcmepr5_nHgLbMrjQAAAiw"]
[Tue Aug 18 12:53:26.412554 2026] [authz_core:error] [pid 66623:tid 66754] [remote 57.141.22.30:63744] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:26.412813 2026] [authz_core:error] [pid 66623:tid 66754] [remote 57.141.22.30:63744] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:26.451138 2026] [security2:error] [pid 67073:tid 67297] [client 103.184.169.37:41051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9vcmepr5_nHgLbMrjgAAAnA"]
[Tue Aug 18 12:53:26.451268 2026] [security2:error] [pid 67073:tid 67297] [client 103.184.169.37:41051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9vcmepr5_nHgLbMrjgAAAnA"]
[Tue Aug 18 12:53:26.453998 2026] [security2:error] [pid 67073:tid 67246] [client 132.196.61.152:55313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/img.php"] [unique_id "aoR_9vcmepr5_nHgLbMrjwAAAj0"]
[Tue Aug 18 12:53:26.482508 2026] [security2:error] [pid 67073:tid 67231] [client 104.209.144.33:24890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/index/function.php"] [unique_id "aoR_9vcmepr5_nHgLbMrkAAAAi4"]
[Tue Aug 18 12:53:26.497642 2026] [security2:error] [pid 67073:tid 67328] [client 168.62.48.100:14804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoR_9vcmepr5_nHgLbMrkgAAAo8"]
[Tue Aug 18 12:53:26.509534 2026] [security2:error] [pid 67073:tid 67267] [client 68.221.73.131:4320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/vr.php"] [unique_id "aoR_9vcmepr5_nHgLbMrkwAAAlI"]
[Tue Aug 18 12:53:26.550842 2026] [security2:error] [pid 66623:tid 66793] [client 158.158.74.177:13731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/license.php"] [unique_id "aoR_9tO5rbWdOArH04J60gAAASU"]
[Tue Aug 18 12:53:26.561329 2026] [security2:error] [pid 67073:tid 67237] [client 40.85.222.29:26617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoR_9vcmepr5_nHgLbMrlAAAAjQ"]
[Tue Aug 18 12:53:26.564776 2026] [security2:error] [pid 66623:tid 66838] [client 114.119.132.227:42607] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rkazuoveiculos.com.br"] [uri "/veiculo/162200/zafira-eleg-2-0-mpfi-flexpower-8v-5p-aut"] [unique_id "aoR_9tO5rbWdOArH04J60wAAAVI"], referer: https://rkazuoveiculos.com.br/veiculo/162200/zafira-eleg-2-0-mpfi-flexpower-8v-5p-aut
[Tue Aug 18 12:53:26.596320 2026] [security2:error] [pid 67073:tid 67240] [client 104.209.144.33:25284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoR_9vcmepr5_nHgLbMrlQAAAjc"]
[Tue Aug 18 12:53:26.597515 2026] [security2:error] [pid 66623:tid 66822] [client 20.91.215.254:20278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/asd.php"] [unique_id "aoR_9tO5rbWdOArH04J61AAAAUI"]
[Tue Aug 18 12:53:26.619556 2026] [security2:error] [pid 67073:tid 67264] [client 20.65.98.162:32352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/biufile.php"] [unique_id "aoR_9vcmepr5_nHgLbMrmAAAAk8"]
[Tue Aug 18 12:53:26.624942 2026] [security2:error] [pid 66623:tid 66745] [remote 84.205.178.135:26133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.178.205.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "holldyperfuracoes.com.br"] [uri "/wp-login.php"] [unique_id "aoR_9tO5rbWdOArH04J61QABEGw"]
[Tue Aug 18 12:53:26.626230 2026] [security2:error] [pid 67073:tid 67251] [client 20.171.51.14:58406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/lj.php"] [unique_id "aoR_9vcmepr5_nHgLbMrmgAAAkI"]
[Tue Aug 18 12:53:26.688917 2026] [security2:error] [pid 67073:tid 67238] [client 20.119.58.187:15343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-comments-post.php"] [unique_id "aoR_9vcmepr5_nHgLbMrnwAAAjU"]
[Tue Aug 18 12:53:26.737290 2026] [security2:error] [pid 66623:tid 66773] [client 168.62.48.100:14844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/Cachex.php"] [unique_id "aoR_9tO5rbWdOArH04J61wAAARE"]
[Tue Aug 18 12:53:26.740938 2026] [security2:error] [pid 66623:tid 66868] [client 20.104.100.201:53834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/usr.php"] [unique_id "aoR_9tO5rbWdOArH04J62AAAAXA"]
[Tue Aug 18 12:53:26.742363 2026] [security2:error] [pid 66623:tid 66789] [client 74.248.136.165:58626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/sdsa.php"] [unique_id "aoR_9tO5rbWdOArH04J62QAAASE"]
[Tue Aug 18 12:53:26.793557 2026] [security2:error] [pid 66623:tid 66817] [client 4.223.164.152:64644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/als.php"] [unique_id "aoR_9tO5rbWdOArH04J62gAAAT0"]
[Tue Aug 18 12:53:26.803734 2026] [security2:error] [pid 67073:tid 67215] [client 74.249.206.207:51614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/k.php"] [unique_id "aoR_9vcmepr5_nHgLbMrowAAAh4"]
[Tue Aug 18 12:53:26.826878 2026] [security2:error] [pid 67073:tid 67305] [client 20.48.236.86:10701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/classwithtostring.php"] [unique_id "aoR_9vcmepr5_nHgLbMrpAAAAng"]
[Tue Aug 18 12:53:26.836210 2026] [security2:error] [pid 67073:tid 67292] [client 20.171.51.14:10220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ph.php"] [unique_id "aoR_9vcmepr5_nHgLbMrpgAAAms"]
[Tue Aug 18 12:53:26.837660 2026] [security2:error] [pid 67073:tid 67250] [client 74.248.18.37:62797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/sim.php"] [unique_id "aoR_9vcmepr5_nHgLbMrpwAAAkE"]
[Tue Aug 18 12:53:26.842231 2026] [security2:error] [pid 67073:tid 67317] [client 20.104.100.201:57316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/jj.php"] [unique_id "aoR_9vcmepr5_nHgLbMrqAAAAoQ"]
[Tue Aug 18 12:53:26.857462 2026] [security2:error] [pid 67073:tid 67221] [client 104.209.144.33:32702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoR_9vcmepr5_nHgLbMrqgAAAiQ"]
[Tue Aug 18 12:53:26.859864 2026] [security2:error] [pid 67073:tid 67272] [client 52.238.210.254:10147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/alfa.php"] [unique_id "aoR_9vcmepr5_nHgLbMrqwAAAlc"]
[Tue Aug 18 12:53:26.928735 2026] [security2:error] [pid 67073:tid 67212] [client 52.139.47.57:39403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoR_9vcmepr5_nHgLbMrrQAAAhs"]
[Tue Aug 18 12:53:26.942915 2026] [security2:error] [pid 66623:tid 66825] [client 104.209.144.33:32664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoR_9tO5rbWdOArH04J62wAAAUU"]
[Tue Aug 18 12:53:26.974556 2026] [security2:error] [pid 67073:tid 67316] [client 168.62.48.100:14727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoR_9vcmepr5_nHgLbMrsAAAAoM"]
[Tue Aug 18 12:53:27.020946 2026] [security2:error] [pid 66623:tid 66881] [client 20.171.51.14:16708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/kh.php"] [unique_id "aoR_99O5rbWdOArH04J63AAAAX0"]
[Tue Aug 18 12:53:27.049607 2026] [security2:error] [pid 66623:tid 66804] [client 20.119.58.187:15325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-cron.php"] [unique_id "aoR_99O5rbWdOArH04J63QAAATA"]
[Tue Aug 18 12:53:27.052040 2026] [security2:error] [pid 67073:tid 67259] [client 4.223.164.152:6615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoR_9_cmepr5_nHgLbMrswAAAko"]
[Tue Aug 18 12:53:27.128634 2026] [security2:error] [pid 67073:tid 67230] [client 20.104.100.201:53859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoR_9_cmepr5_nHgLbMrtgAAAi0"]
[Tue Aug 18 12:53:27.131194 2026] [security2:error] [pid 67073:tid 67291] [client 20.100.169.31:12655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wpc.php"] [unique_id "aoR_9_cmepr5_nHgLbMruAAAAmo"]
[Tue Aug 18 12:53:27.210635 2026] [security2:error] [pid 67073:tid 67243] [client 168.62.48.100:14766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-2019.php"] [unique_id "aoR_9_cmepr5_nHgLbMruQAAAjo"]
[Tue Aug 18 12:53:27.241633 2026] [security2:error] [pid 66623:tid 66888] [client 4.223.164.152:37264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/nox.php"] [unique_id "aoR_99O5rbWdOArH04J64AAAAYQ"]
[Tue Aug 18 12:53:27.281915 2026] [security2:error] [pid 67073:tid 67308] [client 20.171.51.14:36435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/s.php"] [unique_id "aoR_9_cmepr5_nHgLbMrvAAAAns"]
[Tue Aug 18 12:53:27.290286 2026] [security2:error] [pid 67073:tid 67284] [client 132.196.61.152:27276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/aa.php"] [unique_id "aoR_9_cmepr5_nHgLbMrvQAAAmM"]
[Tue Aug 18 12:53:27.292054 2026] [security2:error] [pid 67073:tid 67205] [client 172.202.39.151:48049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/www.php"] [unique_id "aoR_9_cmepr5_nHgLbMrvgAAAhQ"]
[Tue Aug 18 12:53:27.315279 2026] [security2:error] [pid 67073:tid 67286] [client 213.35.127.232:51535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoR_9_cmepr5_nHgLbMrwAAAAmU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:27.319940 2026] [security2:error] [pid 67073:tid 67208] [client 157.20.138.62:50433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9_cmepr5_nHgLbMrwQAAAhc"]
[Tue Aug 18 12:53:27.320076 2026] [security2:error] [pid 67073:tid 67208] [client 157.20.138.62:50433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9_cmepr5_nHgLbMrwQAAAhc"]
[Tue Aug 18 12:53:27.409744 2026] [security2:error] [pid 66623:tid 66769] [client 20.119.58.187:15332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-load.php"] [unique_id "aoR_99O5rbWdOArH04J64QAAAQ0"]
[Tue Aug 18 12:53:27.445640 2026] [security2:error] [pid 67073:tid 67323] [client 168.62.48.100:14740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoR_9_cmepr5_nHgLbMrxgAAAoo"]
[Tue Aug 18 12:53:27.448678 2026] [security2:error] [pid 66623:tid 66852] [client 20.171.51.14:58873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/jb.php"] [unique_id "aoR_99O5rbWdOArH04J64gAAAWA"]
[Tue Aug 18 12:53:27.470301 2026] [security2:error] [pid 67073:tid 67304] [client 74.248.18.37:12522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/simple.php"] [unique_id "aoR_9_cmepr5_nHgLbMrxwAAAnc"]
[Tue Aug 18 12:53:27.483934 2026] [security2:error] [pid 67073:tid 67252] [client 20.91.215.254:20267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/akc.php"] [unique_id "aoR_9_cmepr5_nHgLbMryAAAAkM"]
[Tue Aug 18 12:53:27.518482 2026] [security2:error] [pid 66623:tid 66805] [client 20.104.100.201:17360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/css/database.php"] [unique_id "aoR_99O5rbWdOArH04J65AAAATE"]
[Tue Aug 18 12:53:27.518492 2026] [security2:error] [pid 66623:tid 66842] [client 104.209.144.33:24851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/Cachex.php"] [unique_id "aoR_99O5rbWdOArH04J64wAAAVY"]
[Tue Aug 18 12:53:27.525876 2026] [security2:error] [pid 66623:tid 66780] [client 104.209.144.33:31279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoR_99O5rbWdOArH04J65QAAARg"]
[Tue Aug 18 12:53:27.551022 2026] [security2:error] [pid 66623:tid 66873] [client 74.248.18.37:25929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoR_99O5rbWdOArH04J65gAAAXU"]
[Tue Aug 18 12:53:27.551888 2026] [security2:error] [pid 66623:tid 66778] [client 52.238.210.254:10130] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.savvy.ind.br"] [uri "/1.php"] [unique_id "aoR_99O5rbWdOArH04J65wAAARY"]
[Tue Aug 18 12:53:27.552035 2026] [security2:error] [pid 66623:tid 66778] [client 52.238.210.254:10130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/1.php"] [unique_id "aoR_99O5rbWdOArH04J65wAAARY"]
[Tue Aug 18 12:53:27.566064 2026] [security2:error] [pid 66623:tid 66790] [client 20.104.100.201:40442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/img.php"] [unique_id "aoR_99O5rbWdOArH04J66AAAASI"]
[Tue Aug 18 12:53:27.629453 2026] [security2:error] [pid 67073:tid 67262] [client 4.232.151.198:46528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/155.php"] [unique_id "aoR_9_cmepr5_nHgLbMrzAAAAk0"]
[Tue Aug 18 12:53:27.642503 2026] [security2:error] [pid 66623:tid 66856] [client 68.155.154.236:64466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoR_99O5rbWdOArH04J66wAAAWQ"]
[Tue Aug 18 12:53:27.657889 2026] [security2:error] [pid 66623:tid 66794] [client 20.100.169.31:15092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/w1.php"] [unique_id "aoR_99O5rbWdOArH04J67AAAASY"]
[Tue Aug 18 12:53:27.672808 2026] [security2:error] [pid 67073:tid 67256] [client 20.226.56.190:6552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/rh.php"] [unique_id "aoR_9_cmepr5_nHgLbMrzQAAAkc"]
[Tue Aug 18 12:53:27.694436 2026] [security2:error] [pid 66623:tid 66837] [client 74.249.206.207:59603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/82.php"] [unique_id "aoR_99O5rbWdOArH04J67QAAAVE"]
[Tue Aug 18 12:53:27.696705 2026] [security2:error] [pid 67073:tid 67280] [client 4.223.164.152:6648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/aaa.php"] [unique_id "aoR_9_cmepr5_nHgLbMrzwAAAl8"]
[Tue Aug 18 12:53:27.700221 2026] [security2:error] [pid 67073:tid 67239] [client 168.62.48.100:14824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/.cache/x.php"] [unique_id "aoR_9_cmepr5_nHgLbMr0AAAAjY"]
[Tue Aug 18 12:53:27.714318 2026] [security2:error] [pid 67073:tid 67226] [client 132.196.61.152:56087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/av.php"] [unique_id "aoR_9_cmepr5_nHgLbMr0QAAAik"]
[Tue Aug 18 12:53:27.770637 2026] [security2:error] [pid 67073:tid 67222] [client 135.225.75.187:9434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_9_cmepr5_nHgLbMr0gAAAiU"]
[Tue Aug 18 12:53:27.771896 2026] [security2:error] [pid 67073:tid 67213] [client 20.119.58.187:14602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-activate.php"] [unique_id "aoR_9_cmepr5_nHgLbMr0wAAAhw"]
[Tue Aug 18 12:53:27.787007 2026] [security2:error] [pid 67073:tid 67297] [client 74.248.136.165:52041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_9_cmepr5_nHgLbMr1AAAAnA"]
[Tue Aug 18 12:53:27.807102 2026] [security2:error] [pid 67073:tid 67246] [client 4.223.164.152:37274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/file59.php"] [unique_id "aoR_9_cmepr5_nHgLbMr1QAAAj0"]
[Tue Aug 18 12:53:27.889428 2026] [security2:error] [pid 67073:tid 67275] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/u.php"] [unique_id "aoR_9_cmepr5_nHgLbMr2AAAAlo"]
[Tue Aug 18 12:53:27.919401 2026] [security2:error] [pid 66623:tid 66783] [client 52.238.210.254:10135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/222.php"] [unique_id "aoR_99O5rbWdOArH04J68AAAARs"]
[Tue Aug 18 12:53:27.933601 2026] [security2:error] [pid 67073:tid 67318] [client 168.62.48.100:16307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoR_9_cmepr5_nHgLbMr2gAAAoU"]
[Tue Aug 18 12:53:27.970404 2026] [security2:error] [pid 67073:tid 67254] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_9_cmepr5_nHgLbMr2wAAAkU"]
[Tue Aug 18 12:53:28.005904 2026] [security2:error] [pid 67073:tid 67269] [client 104.209.144.33:15686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr4QAAAlQ"]
[Tue Aug 18 12:53:28.006081 2026] [security2:error] [pid 67073:tid 67312] [client 104.209.144.33:24868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr4gAAAn8"]
[Tue Aug 18 12:53:28.013113 2026] [security2:error] [pid 67073:tid 67225] [client 20.151.109.219:58342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/main.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr4wAAAig"]
[Tue Aug 18 12:53:28.017922 2026] [security2:error] [pid 67073:tid 67278] [client 20.171.51.14:15749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/uo.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr5AAAAl0"]
[Tue Aug 18 12:53:28.086135 2026] [security2:error] [pid 67073:tid 67293] [client 20.104.100.201:53857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/privdayz.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr6AAAAmw"]
[Tue Aug 18 12:53:28.117181 2026] [security2:error] [pid 67073:tid 67326] [client 74.248.18.37:13205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/st.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr6gAAAo0"]
[Tue Aug 18 12:53:28.117582 2026] [security2:error] [pid 67073:tid 67272] [client 20.171.51.14:16751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/do.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr6wAAAlc"]
[Tue Aug 18 12:53:28.124765 2026] [security2:error] [pid 67073:tid 67302] [client 20.119.58.187:15329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/berlin.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr7AAAAnU"]
[Tue Aug 18 12:53:28.155117 2026] [security2:error] [pid 67073:tid 67212] [client 52.173.121.69:61839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr7QAAAhs"]
[Tue Aug 18 12:53:28.166046 2026] [security2:error] [pid 67073:tid 67290] [client 20.104.100.201:65098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/we.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr7gAAAmk"]
[Tue Aug 18 12:53:28.171122 2026] [security2:error] [pid 67073:tid 67207] [client 168.62.48.100:16368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-content/index.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr7wAAAhY"]
[Tue Aug 18 12:53:28.187935 2026] [security2:error] [pid 66623:tid 66677] [remote 47.128.31.19:15618] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "maxxbox.ind.br"] [uri "/"] [unique_id "aoR_-NO5rbWdOArH04J69QABNyg"]
[Tue Aug 18 12:53:28.189380 2026] [security2:error] [pid 67073:tid 67261] [client 4.223.164.152:6858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/gecko.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr8QAAAkw"]
[Tue Aug 18 12:53:28.204657 2026] [security2:error] [pid 66623:tid 66885] [client 52.139.47.57:29399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-includes/Text/Diff/Engine.php"] [unique_id "aoR_-NO5rbWdOArH04J69gAAAYE"]
[Tue Aug 18 12:53:28.207923 2026] [security2:error] [pid 67073:tid 67313] [client 74.248.136.165:10022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr9AAAAoA"]
[Tue Aug 18 12:53:28.270176 2026] [security2:error] [pid 67073:tid 67306] [client 52.238.210.254:10209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/asasx.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr-AAAAnk"]
[Tue Aug 18 12:53:28.290050 2026] [security2:error] [pid 67073:tid 67259] [client 4.223.164.152:64682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/admin.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr-QAAAko"]
[Tue Aug 18 12:53:28.293524 2026] [security2:error] [pid 67073:tid 67232] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr-gAAAi8"]
[Tue Aug 18 12:53:28.330296 2026] [security2:error] [pid 67073:tid 67238] [client 213.35.127.232:51754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr_gAAAjU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:28.374156 2026] [security2:error] [pid 67073:tid 67243] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsAgAAAjo"]
[Tue Aug 18 12:53:28.380366 2026] [security2:error] [pid 66623:tid 66768] [client 132.196.61.152:56127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/media.php"] [unique_id "aoR_-NO5rbWdOArH04J6-AAAAQw"]
[Tue Aug 18 12:53:28.395019 2026] [security2:error] [pid 67073:tid 67244] [client 104.209.144.33:31251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsAwAAAjs"]
[Tue Aug 18 12:53:28.407852 2026] [security2:error] [pid 67073:tid 67223] [client 168.62.48.100:14841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsBAAAAiY"]
[Tue Aug 18 12:53:28.414453 2026] [security2:error] [pid 67073:tid 67250] [client 20.91.215.254:23738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/maintenance.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsBQAAAkE"]
[Tue Aug 18 12:53:28.415072 2026] [security2:error] [pid 67073:tid 67308] [client 74.248.136.165:20315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/wp-freya.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsBgAAAns"]
[Tue Aug 18 12:53:28.445400 2026] [security2:error] [pid 67073:tid 67208] [client 20.104.100.201:54028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wg459o.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsBwAAAhc"]
[Tue Aug 18 12:53:28.464491 2026] [security2:error] [pid 67073:tid 67301] [client 104.209.144.33:25325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-2019.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsCQAAAnQ"]
[Tue Aug 18 12:53:28.479778 2026] [security2:error] [pid 67073:tid 67324] [client 20.119.58.187:14597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/plugins/not/includes/php8.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsCgAAAos"]
[Tue Aug 18 12:53:28.570609 2026] [security2:error] [pid 67073:tid 67252] [client 52.238.210.254:10136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/filemanager.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsDAAAAkM"]
[Tue Aug 18 12:53:28.592181 2026] [security2:error] [pid 67073:tid 67216] [client 74.249.206.207:63334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/dex.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsDQAAAh8"]
[Tue Aug 18 12:53:28.602230 2026] [security2:error] [pid 66623:tid 66866] [client 20.48.236.86:10729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/wp-ws68.php"] [unique_id "aoR_-NO5rbWdOArH04J6-QAAAW4"]
[Tue Aug 18 12:53:28.626220 2026] [security2:error] [pid 66623:tid 66854] [client 74.248.136.165:58421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ws61.php"] [unique_id "aoR_-NO5rbWdOArH04J6-gAAAWI"]
[Tue Aug 18 12:53:28.641502 2026] [security2:error] [pid 66623:tid 66797] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/h.php"] [unique_id "aoR_-NO5rbWdOArH04J6-wAAASk"]
[Tue Aug 18 12:53:28.645477 2026] [security2:error] [pid 67073:tid 67209] [client 168.62.48.100:14743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsDgAAAhg"]
[Tue Aug 18 12:53:28.688201 2026] [security2:error] [pid 66623:tid 66867] [client 149.34.210.141:57638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_-NO5rbWdOArH04J6_AAAAW8"]
[Tue Aug 18 12:53:28.694830 2026] [security2:error] [pid 67073:tid 67298] [client 114.119.128.132:55759] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.medraeng.com"] [uri "/robots.txt"] [unique_id "aoR_-Pcmepr5_nHgLbMsEAAAAnE"], referer: https://www.medraeng.com/robots.txt
[Tue Aug 18 12:53:28.700840 2026] [security2:error] [pid 67073:tid 67224] [client 4.223.164.152:6633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/xiugai.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsEQAAAic"]
[Tue Aug 18 12:53:28.708708 2026] [security2:error] [pid 67073:tid 67322] [client 5.253.205.188:48154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/file.bak"] [unique_id "aoR_-Pcmepr5_nHgLbMsEwAAAok"], referer: https://medihub.com.br/file.bak
[Tue Aug 18 12:53:28.708847 2026] [security2:error] [pid 66623:tid 66887] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/weozh.php"] [unique_id "aoR_-NO5rbWdOArH04J6_QAAAYM"]
[Tue Aug 18 12:53:28.708911 2026] [security2:error] [pid 67073:tid 67205] [client 109.122.18.177:52915] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edgeresidences.com.br"] [uri "/.env"] [unique_id "aoR_-Pcmepr5_nHgLbMsEgAAAhQ"]
[Tue Aug 18 12:53:28.716276 2026] [security2:error] [pid 67073:tid 67235] [client 4.223.164.152:37293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/aa2.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsFAAAAjI"]
[Tue Aug 18 12:53:28.751857 2026] [security2:error] [pid 67073:tid 67323] [client 74.248.18.37:13220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/subdom/ant/makeasmtp.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsFwAAAoo"]
[Tue Aug 18 12:53:28.766303 2026] [security2:error] [pid 67073:tid 67226] [client 68.155.154.236:65202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsGAAAAik"]
[Tue Aug 18 12:53:28.767442 2026] [security2:error] [pid 67073:tid 67222] [client 20.171.51.14:43344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/yw.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsGQAAAiU"]
[Tue Aug 18 12:53:28.819824 2026] [authz_core:error] [pid 67073:tid 67236] [client 192.178.4.133:61705] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:28.820258 2026] [authz_core:error] [pid 67073:tid 67236] [client 192.178.4.133:61705] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:28.839417 2026] [security2:error] [pid 67073:tid 67274] [client 20.119.58.187:14649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/plugins/wp-theme-editor/php8.php/wp-content/themes/aahana/json.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsHAAAAlk"]
[Tue Aug 18 12:53:28.883653 2026] [security2:error] [pid 67073:tid 67299] [client 132.196.61.152:56110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/images.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsHQAAAnI"]
[Tue Aug 18 12:53:28.889985 2026] [security2:error] [pid 67073:tid 67328] [client 168.62.48.100:14809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/help/crnpwfiu.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsHgAAAo8"]
[Tue Aug 18 12:53:28.890299 2026] [security2:error] [pid 67073:tid 67267] [client 20.104.100.201:53854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/mifta.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsHwAAAlI"]
[Tue Aug 18 12:53:28.946082 2026] [security2:error] [pid 66623:tid 66867] [client 149.34.210.141:57638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_-NO5rbWdOArH04J6_AAAAW8"]
[Tue Aug 18 12:53:28.948614 2026] [security2:error] [pid 67073:tid 67270] [client 20.42.19.40:2200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/dropdown.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsIgAAAlU"]
[Tue Aug 18 12:53:29.011490 2026] [security2:error] [pid 67073:tid 67300] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/rymmm.php"] [unique_id "aoR_-fcmepr5_nHgLbMsJgAAAnM"]
[Tue Aug 18 12:53:29.044660 2026] [security2:error] [pid 67073:tid 67310] [client 74.248.136.165:58249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/rum.php"] [unique_id "aoR_-fcmepr5_nHgLbMsKAAAAn0"]
[Tue Aug 18 12:53:29.048492 2026] [security2:error] [pid 67073:tid 67305] [client 20.65.98.162:16620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/coffexium.php"] [unique_id "aoR_-fcmepr5_nHgLbMsKQAAAng"]
[Tue Aug 18 12:53:29.067402 2026] [security2:error] [pid 67073:tid 67253] [client 52.238.210.254:10201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/themes.php"] [unique_id "aoR_-fcmepr5_nHgLbMsLAAAAkQ"]
[Tue Aug 18 12:53:29.076870 2026] [security2:error] [pid 67073:tid 67317] [client 104.209.144.33:32649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/first.php"] [unique_id "aoR_-fcmepr5_nHgLbMsLQAAAoQ"]
[Tue Aug 18 12:53:29.080182 2026] [security2:error] [pid 66623:tid 66819] [client 104.209.144.33:31285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoR_-dO5rbWdOArH04J7AgAAAT8"]
[Tue Aug 18 12:53:29.083472 2026] [security2:error] [pid 67073:tid 67327] [client 4.232.151.198:48211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/96i.php"] [unique_id "aoR_-fcmepr5_nHgLbMsLgAAAo4"]
[Tue Aug 18 12:53:29.140190 2026] [security2:error] [pid 66623:tid 66859] [client 168.62.48.100:16378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoR_-dO5rbWdOArH04J7AwAAAWc"]
[Tue Aug 18 12:53:29.162248 2026] [security2:error] [pid 67073:tid 67218] [client 4.223.164.152:46169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/xamp.php"] [unique_id "aoR_-fcmepr5_nHgLbMsMQAAAiE"]
[Tue Aug 18 12:53:29.182861 2026] [security2:error] [pid 67073:tid 67316] [client 4.223.164.152:6859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/adminner.php"] [unique_id "aoR_-fcmepr5_nHgLbMsMgAAAoM"]
[Tue Aug 18 12:53:29.194101 2026] [security2:error] [pid 66623:tid 66845] [client 20.119.58.187:14620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/Requests/php8.php"] [unique_id "aoR_-dO5rbWdOArH04J7BAAAAVk"]
[Tue Aug 18 12:53:29.238996 2026] [security2:error] [pid 67073:tid 67282] [client 135.225.75.187:55110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_-fcmepr5_nHgLbMsNAAAAmE"]
[Tue Aug 18 12:53:29.253836 2026] [security2:error] [pid 66623:tid 66804] [client 20.171.51.14:33724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/qh.php"] [unique_id "aoR_-dO5rbWdOArH04J7BQAAATA"]
[Tue Aug 18 12:53:29.271859 2026] [autoindex:error] [pid 66623:tid 66893] [client 172.232.22.88:43722] AH01276: Cannot serve directory /home3/sortistecnologia/weishaupt.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:29.352750 2026] [security2:error] [pid 67073:tid 67285] [client 213.35.127.232:51965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoR_-fcmepr5_nHgLbMsOAAAAmQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:29.374944 2026] [security2:error] [pid 67073:tid 67326] [client 20.91.215.254:23722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/options-writing.php"] [unique_id "aoR_-fcmepr5_nHgLbMsOwAAAo0"]
[Tue Aug 18 12:53:29.380289 2026] [security2:error] [pid 67073:tid 67217] [client 168.62.48.100:14664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoR_-fcmepr5_nHgLbMsPAAAAiA"]
[Tue Aug 18 12:53:29.387196 2026] [security2:error] [pid 66623:tid 66881] [client 74.248.18.37:21915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/system.php"] [unique_id "aoR_-dO5rbWdOArH04J7CAAAAX0"]
[Tue Aug 18 12:53:29.465633 2026] [security2:error] [pid 67073:tid 67255] [client 20.48.236.86:10802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/mgrr.php"] [unique_id "aoR_-fcmepr5_nHgLbMsPgAAAkY"]
[Tue Aug 18 12:53:29.466550 2026] [security2:error] [pid 67073:tid 67291] [client 52.139.47.57:4017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-mail.php"] [unique_id "aoR_-fcmepr5_nHgLbMsPwAAAmo"]
[Tue Aug 18 12:53:29.466578 2026] [security2:error] [pid 67073:tid 67238] [client 74.248.136.165:61640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ze.php"] [unique_id "aoR_-fcmepr5_nHgLbMsQAAAAjU"]
[Tue Aug 18 12:53:29.469450 2026] [security2:error] [pid 67073:tid 67276] [client 52.173.121.69:56353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoR_-fcmepr5_nHgLbMsQgAAAls"]
[Tue Aug 18 12:53:29.482001 2026] [security2:error] [pid 66623:tid 66805] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/lddxs.php"] [unique_id "aoR_-dO5rbWdOArH04J7CwAAATE"]
[Tue Aug 18 12:53:29.525778 2026] [security2:error] [pid 67073:tid 67284] [client 52.238.210.254:10174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/admin.php"] [unique_id "aoR_-fcmepr5_nHgLbMsRQAAAmM"]
[Tue Aug 18 12:53:29.538777 2026] [autoindex:error] [pid 67073:tid 67232] [client 172.236.112.76:56750] AH01276: Cannot serve directory /home3/sortistecnologia/weishaupt.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:29.547266 2026] [security2:error] [pid 67073:tid 67308] [client 20.151.109.219:36676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/ga.php"] [unique_id "aoR_-fcmepr5_nHgLbMsRwAAAns"]
[Tue Aug 18 12:53:29.592490 2026] [security2:error] [pid 66623:tid 66780] [client 104.209.144.33:15697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/.cache/x.php"] [unique_id "aoR_-dO5rbWdOArH04J7DQAAARg"]
[Tue Aug 18 12:53:29.604762 2026] [security2:error] [pid 67073:tid 67307] [client 20.119.58.187:15351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/SimplePie/php8.php"] [unique_id "aoR_-fcmepr5_nHgLbMsSQAAAno"]
[Tue Aug 18 12:53:29.607676 2026] [security2:error] [pid 67073:tid 67324] [client 4.223.164.152:37290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/bless.php"] [unique_id "aoR_-fcmepr5_nHgLbMsSgAAAos"]
[Tue Aug 18 12:53:29.614778 2026] [security2:error] [pid 67073:tid 67245] [client 168.62.48.100:14706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoR_-fcmepr5_nHgLbMsSwAAAjw"]
[Tue Aug 18 12:53:29.618842 2026] [security2:error] [pid 67073:tid 67263] [client 40.85.222.29:30473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoR_-fcmepr5_nHgLbMsTAAAAk4"]
[Tue Aug 18 12:53:29.619315 2026] [security2:error] [pid 66623:tid 66880] [client 132.196.61.152:55353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/admin.php"] [unique_id "aoR_-dO5rbWdOArH04J7DgAAAXw"]
[Tue Aug 18 12:53:29.720029 2026] [security2:error] [pid 67073:tid 67249] [client 157.51.166.53:50694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_-fcmepr5_nHgLbMsTgAAAkA"]
[Tue Aug 18 12:53:29.720150 2026] [security2:error] [pid 67073:tid 67249] [client 157.51.166.53:50694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_-fcmepr5_nHgLbMsTgAAAkA"]
[Tue Aug 18 12:53:29.721089 2026] [security2:error] [pid 66623:tid 66856] [client 74.249.206.207:56222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/puc.php"] [unique_id "aoR_-dO5rbWdOArH04J7EAAAAWQ"]
[Tue Aug 18 12:53:29.725640 2026] [security2:error] [pid 67073:tid 67216] [client 4.223.164.152:6641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/file1221.php"] [unique_id "aoR_-fcmepr5_nHgLbMsTwAAAh8"]
[Tue Aug 18 12:53:29.727932 2026] [security2:error] [pid 67073:tid 67319] [client 104.209.144.33:31258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoR_-fcmepr5_nHgLbMsUAAAAoY"]
[Tue Aug 18 12:53:29.761424 2026] [security2:error] [pid 67073:tid 67262] [client 20.171.51.14:45389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/kx.php"] [unique_id "aoR_-fcmepr5_nHgLbMsUwAAAk0"]
[Tue Aug 18 12:53:29.775227 2026] [security2:error] [pid 67073:tid 67295] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/zjggu.php"] [unique_id "aoR_-fcmepr5_nHgLbMsVAAAAm4"]
[Tue Aug 18 12:53:29.791382 2026] [security2:error] [pid 67073:tid 67224] [client 20.171.51.14:45400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/r.php"] [unique_id "aoR_-fcmepr5_nHgLbMsVQAAAic"]
[Tue Aug 18 12:53:29.806083 2026] [security2:error] [pid 67073:tid 67235] [client 20.104.100.201:53869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoR_-fcmepr5_nHgLbMsVgAAAjI"]
[Tue Aug 18 12:53:29.830752 2026] [security2:error] [pid 67073:tid 67313] [client 160.120.140.123:52188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_-fcmepr5_nHgLbMsVwAAAoA"]
[Tue Aug 18 12:53:29.830861 2026] [security2:error] [pid 67073:tid 67313] [client 160.120.140.123:52188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_-fcmepr5_nHgLbMsVwAAAoA"]
[Tue Aug 18 12:53:29.838943 2026] [security2:error] [pid 67073:tid 67248] [client 20.100.169.31:15081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/fone1.php"] [unique_id "aoR_-fcmepr5_nHgLbMsWQAAAj8"]
[Tue Aug 18 12:53:29.854895 2026] [security2:error] [pid 67073:tid 67297] [client 20.51.153.15:13318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_-fcmepr5_nHgLbMsWgAAAnA"]
[Tue Aug 18 12:53:29.888148 2026] [security2:error] [pid 66623:tid 66799] [client 168.62.48.100:14721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoR_-dO5rbWdOArH04J7EwAAASs"]
[Tue Aug 18 12:53:29.894367 2026] [security2:error] [pid 67073:tid 67299] [client 74.248.136.165:58400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/gjm.php"] [unique_id "aoR_-fcmepr5_nHgLbMsWwAAAnI"]
[Tue Aug 18 12:53:29.918408 2026] [security2:error] [pid 66623:tid 66791] [client 178.153.171.161:28986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_-dO5rbWdOArH04J7FAAAASM"]
[Tue Aug 18 12:53:29.918494 2026] [security2:error] [pid 66623:tid 66791] [client 178.153.171.161:28986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_-dO5rbWdOArH04J7FAAAASM"]
[Tue Aug 18 12:53:29.972595 2026] [security2:error] [pid 67073:tid 67213] [client 20.119.58.187:15324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/banners/php8.php"] [unique_id "aoR_-fcmepr5_nHgLbMsYAAAAhw"]
[Tue Aug 18 12:53:29.993035 2026] [autoindex:error] [pid 66623:tid 66794] [client 20.250.13.23:12040] AH01276: Cannot serve directory /home2/siderurgiabrasil/anuariodasiderurgia.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:30.031399 2026] [security2:error] [pid 67073:tid 67323] [client 74.248.18.37:13202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/system_log.php"] [unique_id "aoR_-vcmepr5_nHgLbMsZQAAAoo"]
[Tue Aug 18 12:53:30.046562 2026] [security2:error] [pid 67073:tid 67286] [client 74.248.18.37:14583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/info.php"] [unique_id "aoR_-vcmepr5_nHgLbMsZgAAAmU"]
[Tue Aug 18 12:53:30.067222 2026] [security2:error] [pid 67073:tid 67233] [client 20.91.215.254:20282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoR_-vcmepr5_nHgLbMsZwAAAjA"]
[Tue Aug 18 12:53:30.090542 2026] [security2:error] [pid 66623:tid 66788] [client 4.223.164.152:64674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/file25.php"] [unique_id "aoR_-tO5rbWdOArH04J7GAAAASA"]
[Tue Aug 18 12:53:30.090954 2026] [security2:error] [pid 67073:tid 67269] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/dlvqo.php"] [unique_id "aoR_-vcmepr5_nHgLbMsaAAAAlQ"]
[Tue Aug 18 12:53:30.139024 2026] [security2:error] [pid 67073:tid 67215] [client 168.62.48.100:16320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/update/wpupex.php"] [unique_id "aoR_-vcmepr5_nHgLbMsawAAAh4"]
[Tue Aug 18 12:53:30.148198 2026] [security2:error] [pid 67073:tid 67305] [client 104.209.144.33:24854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoR_-vcmepr5_nHgLbMsbAAAAng"]
[Tue Aug 18 12:53:30.150605 2026] [security2:error] [pid 67073:tid 67292] [client 172.202.39.151:43271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/chosen.php"] [unique_id "aoR_-vcmepr5_nHgLbMsbQAAAms"]
[Tue Aug 18 12:53:30.151370 2026] [security2:error] [pid 66623:tid 66840] [client 52.238.210.254:8902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/buy.php"] [unique_id "aoR_-tO5rbWdOArH04J7GQAAAVQ"]
[Tue Aug 18 12:53:30.204906 2026] [security2:error] [pid 67073:tid 67221] [client 74.248.136.165:20295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/fleen.php"] [unique_id "aoR_-vcmepr5_nHgLbMsbgAAAiQ"]
[Tue Aug 18 12:53:30.208727 2026] [security2:error] [pid 67073:tid 67317] [client 4.223.164.152:6722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/inx.php"] [unique_id "aoR_-vcmepr5_nHgLbMscAAAAoQ"]
[Tue Aug 18 12:53:30.264635 2026] [security2:error] [pid 66623:tid 66885] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/ms-edit.php"] [unique_id "aoR_-tO5rbWdOArH04J7GgAAAYE"]
[Tue Aug 18 12:53:30.272971 2026] [security2:error] [pid 66623:tid 66836] [client 20.100.169.31:33797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-login.php"] [unique_id "aoR_-tO5rbWdOArH04J7GwAAAVA"]
[Tue Aug 18 12:53:30.311454 2026] [security2:error] [pid 66623:tid 66866] [client 74.248.136.165:46511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/new4.php"] [unique_id "aoR_-tO5rbWdOArH04J7HAAAAW4"]
[Tue Aug 18 12:53:30.321527 2026] [security2:error] [pid 66623:tid 66854] [client 20.171.51.14:62521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/17.php"] [unique_id "aoR_-tO5rbWdOArH04J7HQAAAWI"]
[Tue Aug 18 12:53:30.368684 2026] [security2:error] [pid 67073:tid 67280] [client 213.35.127.232:52170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoR_-vcmepr5_nHgLbMsdQAAAl8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:30.378942 2026] [security2:error] [pid 67073:tid 67218] [client 20.119.58.187:15132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/php8.php"] [unique_id "aoR_-vcmepr5_nHgLbMsdgAAAiE"]
[Tue Aug 18 12:53:30.379237 2026] [security2:error] [pid 67073:tid 67315] [client 168.62.48.100:14846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-admin/install.php"] [unique_id "aoR_-vcmepr5_nHgLbMsdwAAAoI"]
[Tue Aug 18 12:53:30.380835 2026] [security2:error] [pid 66623:tid 66797] [client 74.249.206.207:63328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/inso.php"] [unique_id "aoR_-tO5rbWdOArH04J7HgAAASk"]
[Tue Aug 18 12:53:30.394551 2026] [security2:error] [pid 67073:tid 67241] [client 20.171.51.14:21057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/va.php"] [unique_id "aoR_-vcmepr5_nHgLbMseAAAAjg"]
[Tue Aug 18 12:53:30.419860 2026] [security2:error] [pid 67073:tid 67228] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/pkmoj.php"] [unique_id "aoR_-vcmepr5_nHgLbMsegAAAis"]
[Tue Aug 18 12:53:30.428597 2026] [security2:error] [pid 67073:tid 67265] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_-vcmepr5_nHgLbMsewAAAlA"]
[Tue Aug 18 12:53:30.442055 2026] [security2:error] [pid 67073:tid 67285] [client 20.51.153.15:13427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_-vcmepr5_nHgLbMsfAAAAmQ"]
[Tue Aug 18 12:53:30.491555 2026] [security2:error] [pid 67073:tid 67217] [client 52.238.210.254:10141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/dropdown.php"] [unique_id "aoR_-vcmepr5_nHgLbMsfgAAAiA"]
[Tue Aug 18 12:53:30.517096 2026] [security2:error] [pid 66623:tid 66876] [client 20.104.100.201:17384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/index2.php"] [unique_id "aoR_-tO5rbWdOArH04J7IAAAAXg"]
[Tue Aug 18 12:53:30.524061 2026] [security2:error] [pid 66623:tid 66853] [client 4.223.164.152:37261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/file15.php"] [unique_id "aoR_-tO5rbWdOArH04J7IgAAAWE"]
[Tue Aug 18 12:53:30.605795 2026] [autoindex:error] [pid 66623:tid 66793] [client 172.202.39.151:44358] AH01276: Cannot serve directory /home4/lecarveiculos/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:30.614039 2026] [security2:error] [pid 67073:tid 67284] [client 168.62.48.100:16339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aoR_-vcmepr5_nHgLbMsggAAAmM"]
[Tue Aug 18 12:53:30.622047 2026] [security2:error] [pid 66623:tid 66772] [client 172.202.39.151:16236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wicked.php"] [unique_id "aoR_-tO5rbWdOArH04J7KgAAARA"]
[Tue Aug 18 12:53:30.634069 2026] [security2:error] [pid 67073:tid 67250] [client 132.196.61.152:56077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/222.php"] [unique_id "aoR_-vcmepr5_nHgLbMsgwAAAkE"]
[Tue Aug 18 12:53:30.687053 2026] [security2:error] [pid 66623:tid 66848] [client 68.155.154.236:62643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoR_-tO5rbWdOArH04J7LQAAAVw"]
[Tue Aug 18 12:53:30.728381 2026] [security2:error] [pid 67073:tid 67237] [client 74.248.136.165:10007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-act.php"] [unique_id "aoR_-vcmepr5_nHgLbMshgAAAjQ"]
[Tue Aug 18 12:53:30.733636 2026] [security2:error] [pid 67073:tid 67301] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/kopyw.php"] [unique_id "aoR_-vcmepr5_nHgLbMshwAAAnQ"]
[Tue Aug 18 12:53:30.740302 2026] [security2:error] [pid 66623:tid 66858] [client 20.119.58.187:14641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/.well-known/php8.php"] [unique_id "aoR_-tO5rbWdOArH04J7LgAAAWY"]
[Tue Aug 18 12:53:30.744119 2026] [security2:error] [pid 66623:tid 66810] [client 20.48.236.86:10423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/55.php"] [unique_id "aoR_-tO5rbWdOArH04J7LwAAATY"]
[Tue Aug 18 12:53:30.751374 2026] [security2:error] [pid 67073:tid 67307] [client 172.202.39.151:44444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wso.php"] [unique_id "aoR_-vcmepr5_nHgLbMsiAAAAno"]
[Tue Aug 18 12:53:30.780403 2026] [security2:error] [pid 67073:tid 67245] [client 52.173.121.69:53046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoR_-vcmepr5_nHgLbMsiwAAAjw"]
[Tue Aug 18 12:53:30.792569 2026] [security2:error] [pid 67073:tid 67252] [client 20.171.51.14:16729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ev.php"] [unique_id "aoR_-vcmepr5_nHgLbMsjAAAAkM"]
[Tue Aug 18 12:53:30.808306 2026] [security2:error] [pid 66623:tid 66838] [client 74.248.18.37:13195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/templates/beez3/error.php"] [unique_id "aoR_-tO5rbWdOArH04J7MAAAAVI"]
[Tue Aug 18 12:53:30.815691 2026] [security2:error] [pid 66623:tid 66867] [client 20.51.153.15:13405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/dirs.php"] [unique_id "aoR_-tO5rbWdOArH04J7MQAAAW8"]
[Tue Aug 18 12:53:30.829629 2026] [security2:error] [pid 66623:tid 66890] [client 135.225.75.187:49127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ws61.php"] [unique_id "aoR_-tO5rbWdOArH04J7MgAAAYY"]
[Tue Aug 18 12:53:30.851975 2026] [security2:error] [pid 67073:tid 67234] [client 168.62.48.100:14747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoR_-vcmepr5_nHgLbMsjgAAAjE"]
[Tue Aug 18 12:53:30.913158 2026] [security2:error] [pid 67073:tid 67224] [client 4.223.164.152:6881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/reviall.php"] [unique_id "aoR_-vcmepr5_nHgLbMslAAAAic"]
[Tue Aug 18 12:53:30.947883 2026] [security2:error] [pid 67073:tid 67313] [client 52.28.162.93:46232] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.agrimotor.com.br"] [uri "/"] [unique_id "aoR_-vcmepr5_nHgLbMslQAAAoA"], referer: http://www.agrimotor.com.br/
[Tue Aug 18 12:53:30.948640 2026] [security2:error] [pid 67073:tid 67248] [client 4.223.164.152:37286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/f35.php"] [unique_id "aoR_-vcmepr5_nHgLbMslgAAAj8"]
[Tue Aug 18 12:53:30.957912 2026] [security2:error] [pid 67073:tid 67226] [client 20.65.98.162:23913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/dex.php"] [unique_id "aoR_-vcmepr5_nHgLbMslwAAAik"]
[Tue Aug 18 12:53:30.971089 2026] [security2:error] [pid 66623:tid 66775] [client 85.154.68.202:57277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoR_-tO5rbWdOArH04J7MwAAARM"]
[Tue Aug 18 12:53:30.971192 2026] [security2:error] [pid 66623:tid 66775] [client 85.154.68.202:57277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoR_-tO5rbWdOArH04J7MwAAARM"]
[Tue Aug 18 12:53:30.988036 2026] [security2:error] [pid 67073:tid 67267] [client 20.226.56.190:40155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/yg.php"] [unique_id "aoR_-vcmepr5_nHgLbMsmwAAAlI"]
[Tue Aug 18 12:53:31.002577 2026] [security2:error] [pid 67073:tid 67231] [client 20.171.51.14:62504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/fo.php"] [unique_id "aoR_-_cmepr5_nHgLbMsnQAAAi4"]
[Tue Aug 18 12:53:31.068596 2026] [security2:error] [pid 66623:tid 66827] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/zznmg.php"] [unique_id "aoR_-9O5rbWdOArH04J7NAAAAUc"]
[Tue Aug 18 12:53:31.093052 2026] [security2:error] [pid 67073:tid 67205] [client 52.238.210.254:10206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/inputs.php"] [unique_id "aoR_-_cmepr5_nHgLbMspQAAAhQ"]
[Tue Aug 18 12:53:31.097517 2026] [security2:error] [pid 67073:tid 67299] [client 20.119.58.187:14643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/Text/php8.php"] [unique_id "aoR_-_cmepr5_nHgLbMspgAAAnI"]
[Tue Aug 18 12:53:31.098091 2026] [security2:error] [pid 66623:tid 66859] [client 168.62.48.100:14741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoR_-9O5rbWdOArH04J7NQAAAWc"]
[Tue Aug 18 12:53:31.100988 2026] [security2:error] [pid 67073:tid 67303] [client 20.51.153.15:13378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/fresh.php"] [unique_id "aoR_-_cmepr5_nHgLbMsqAAAAnY"]
[Tue Aug 18 12:53:31.103839 2026] [security2:error] [pid 66623:tid 66877] [client 20.91.215.254:16661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/maint.php"] [unique_id "aoR_-9O5rbWdOArH04J7NwAAAXk"]
[Tue Aug 18 12:53:31.113438 2026] [security2:error] [pid 67073:tid 67270] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_-_cmepr5_nHgLbMsqgAAAlU"]
[Tue Aug 18 12:53:31.148779 2026] [security2:error] [pid 67073:tid 67233] [client 74.248.136.165:19500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/grsiuk.php"] [unique_id "aoR_-_cmepr5_nHgLbMsqwAAAjA"]
[Tue Aug 18 12:53:31.150233 2026] [security2:error] [pid 66623:tid 66822] [client 52.139.47.57:36851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-the.php"] [unique_id "aoR_-9O5rbWdOArH04J7OAAAAUI"]
[Tue Aug 18 12:53:31.258311 2026] [security2:error] [pid 67073:tid 67288] [client 20.250.13.23:13723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/inputs.php"] [unique_id "aoR_-_cmepr5_nHgLbMsrgAAAmc"]
[Tue Aug 18 12:53:31.278087 2026] [security2:error] [pid 67073:tid 67305] [client 20.226.56.190:40511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/et.php"] [unique_id "aoR_-_cmepr5_nHgLbMssQAAAng"]
[Tue Aug 18 12:53:31.286839 2026] [security2:error] [pid 66623:tid 66869] [client 104.209.144.33:32663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoR_-9O5rbWdOArH04J7OgAAAXE"]
[Tue Aug 18 12:53:31.289852 2026] [security2:error] [pid 67073:tid 67328] [client 4.232.151.198:38915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/as.php"] [unique_id "aoR_-_cmepr5_nHgLbMssgAAAo8"]
[Tue Aug 18 12:53:31.339687 2026] [security2:error] [pid 67073:tid 67327] [client 168.62.48.100:14757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/well-known/index.php"] [unique_id "aoR_-_cmepr5_nHgLbMstAAAAo4"]
[Tue Aug 18 12:53:31.340271 2026] [security2:error] [pid 67073:tid 67272] [client 20.51.153.15:13333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/admin404.php"] [unique_id "aoR_-_cmepr5_nHgLbMstQAAAlc"]
[Tue Aug 18 12:53:31.381591 2026] [security2:error] [pid 67073:tid 67315] [client 52.238.210.254:10221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/100.php"] [unique_id "aoR_-_cmepr5_nHgLbMstwAAAoI"]
[Tue Aug 18 12:53:31.388354 2026] [security2:error] [pid 67073:tid 67240] [client 213.35.127.232:52364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoR_-_cmepr5_nHgLbMsuQAAAjc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:31.388657 2026] [security2:error] [pid 67073:tid 67257] [client 4.223.164.152:54235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-load.php"] [unique_id "aoR_-_cmepr5_nHgLbMsuAAAAkg"]
[Tue Aug 18 12:53:31.390151 2026] [security2:error] [pid 67073:tid 67279] [client 172.202.39.151:16215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/HLA-dd.php"] [unique_id "aoR_-_cmepr5_nHgLbMsugAAAl4"]
[Tue Aug 18 12:53:31.392746 2026] [security2:error] [pid 66623:tid 66769] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/bhfnd.php"] [unique_id "aoR_-9O5rbWdOArH04J7PAAAAQ0"]
[Tue Aug 18 12:53:31.410090 2026] [autoindex:error] [pid 66623:tid 66829] [client 169.58.72.249:50192] AH01276: Cannot serve directory /var/www/html/images/: No matching DirectoryIndex (index.cgi,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:31.429974 2026] [security2:error] [pid 67073:tid 67236] [client 52.238.210.254:9017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/about.php"] [unique_id "aoR_-_cmepr5_nHgLbMsvQAAAjM"]
[Tue Aug 18 12:53:31.435150 2026] [security2:error] [pid 67073:tid 67321] [client 20.104.100.201:53849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/8.php"] [unique_id "aoR_-_cmepr5_nHgLbMsvgAAAog"]
[Tue Aug 18 12:53:31.447691 2026] [security2:error] [pid 67073:tid 67256] [client 74.248.18.37:13204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/test.php"] [unique_id "aoR_-_cmepr5_nHgLbMsvwAAAkc"]
[Tue Aug 18 12:53:31.457794 2026] [security2:error] [pid 67073:tid 67317] [client 20.119.58.187:14634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/ID3/php8.php"] [unique_id "aoR_-_cmepr5_nHgLbMswAAAAoQ"]
[Tue Aug 18 12:53:31.465522 2026] [security2:error] [pid 67073:tid 67325] [client 4.223.164.152:6635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/11.php"] [unique_id "aoR_-_cmepr5_nHgLbMswQAAAow"]
[Tue Aug 18 12:53:31.475254 2026] [security2:error] [pid 67073:tid 67217] [client 20.171.51.14:10220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/loading.php"] [unique_id "aoR_-_cmepr5_nHgLbMswgAAAiA"]
[Tue Aug 18 12:53:31.565753 2026] [security2:error] [pid 67073:tid 67238] [client 74.248.136.165:39507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/h.php"] [unique_id "aoR_-_cmepr5_nHgLbMsxwAAAjU"]
[Tue Aug 18 12:53:31.573941 2026] [security2:error] [pid 67073:tid 67276] [client 168.62.48.100:14840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoR_-_cmepr5_nHgLbMszQAAAls"]
[Tue Aug 18 12:53:31.582372 2026] [security2:error] [pid 67073:tid 67225] [client 132.196.61.152:56079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/mac.php"] [unique_id "aoR_-_cmepr5_nHgLbMszgAAAig"]
[Tue Aug 18 12:53:31.598143 2026] [security2:error] [pid 67073:tid 67273] [client 20.51.153.15:13343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/loading.php"] [unique_id "aoR_-_cmepr5_nHgLbMs0AAAAlg"]
[Tue Aug 18 12:53:31.603534 2026] [security2:error] [pid 67073:tid 67232] [client 74.249.206.207:13335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/aa.php"] [unique_id "aoR_-_cmepr5_nHgLbMs0QAAAi8"]
[Tue Aug 18 12:53:31.633925 2026] [security2:error] [pid 67073:tid 67314] [client 20.151.109.219:28754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/wb.php"] [unique_id "aoR_-_cmepr5_nHgLbMs1AAAAoE"]
[Tue Aug 18 12:53:31.679511 2026] [security2:error] [pid 67073:tid 67324] [client 20.171.51.14:21078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/xs.php"] [unique_id "aoR_-_cmepr5_nHgLbMs1QAAAos"]
[Tue Aug 18 12:53:31.682179 2026] [security2:error] [pid 67073:tid 67263] [client 20.226.56.190:9961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/of.php"] [unique_id "aoR_-_cmepr5_nHgLbMs1gAAAk4"]
[Tue Aug 18 12:53:31.682250 2026] [security2:error] [pid 67073:tid 67247] [client 172.202.39.151:44441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/sf.php"] [unique_id "aoR_-_cmepr5_nHgLbMs1wAAAj4"]
[Tue Aug 18 12:53:31.707435 2026] [security2:error] [pid 67073:tid 67304] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/qfvqu.php"] [unique_id "aoR_-_cmepr5_nHgLbMs2QAAAnc"]
[Tue Aug 18 12:53:31.746775 2026] [security2:error] [pid 67073:tid 67221] [client 52.28.162.93:29174] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.agrimotor.com.br"] [uri "/index.php"] [unique_id "aoR_-_cmepr5_nHgLbMsxQAAAiQ"], referer: http://www.agrimotor.com.br/
[Tue Aug 18 12:53:31.763769 2026] [security2:error] [pid 67073:tid 67260] [client 52.238.210.254:8937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/akc.php"] [unique_id "aoR_-_cmepr5_nHgLbMs2wAAAks"]
[Tue Aug 18 12:53:31.771000 2026] [security2:error] [pid 67073:tid 67295] [client 68.155.154.236:65209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoR_-_cmepr5_nHgLbMs3AAAAm4"]
[Tue Aug 18 12:53:31.780294 2026] [security2:error] [pid 67073:tid 67296] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoR_-_cmepr5_nHgLbMs3gAAAm8"]
[Tue Aug 18 12:53:31.812100 2026] [security2:error] [pid 67073:tid 67227] [client 20.119.58.187:14637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/img/php8.php"] [unique_id "aoR_-_cmepr5_nHgLbMs4wAAAio"]
[Tue Aug 18 12:53:31.812582 2026] [authz_core:error] [pid 67073:tid 67164] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:31.812850 2026] [authz_core:error] [pid 67073:tid 67164] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:31.814423 2026] [security2:error] [pid 67073:tid 67222] [client 168.62.48.100:14723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoR_-_cmepr5_nHgLbMs5AAAAiU"]
[Tue Aug 18 12:53:31.817419 2026] [security2:error] [pid 67073:tid 67259] [client 20.100.169.31:25099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/default.php"] [unique_id "aoR_-_cmepr5_nHgLbMs5QAAAko"]
[Tue Aug 18 12:53:31.824657 2026] [autoindex:error] [pid 67073:tid 67226] [client 4.223.164.152:64676] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:31.846945 2026] [security2:error] [pid 66623:tid 66770] [client 20.51.153.15:13330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/conn-test.php"] [unique_id "aoR_-9O5rbWdOArH04J7PgAAAQ4"]
[Tue Aug 18 12:53:31.867210 2026] [security2:error] [pid 67073:tid 67223] [client 74.248.136.165:20325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/e.php"] [unique_id "aoR_-_cmepr5_nHgLbMs5gAAAiY"]
[Tue Aug 18 12:53:31.921345 2026] [security2:error] [pid 67073:tid 67237] [client 20.91.215.254:23740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/phpMailer.php"] [unique_id "aoR_-_cmepr5_nHgLbMs6AAAAjQ"]
[Tue Aug 18 12:53:31.964113 2026] [security2:error] [pid 67073:tid 67264] [client 4.223.164.152:6739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/File.php"] [unique_id "aoR_-_cmepr5_nHgLbMs6gAAAk8"]
[Tue Aug 18 12:53:31.966354 2026] [security2:error] [pid 66623:tid 66780] [client 20.48.236.86:10748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/ajax.php"] [unique_id "aoR_-9O5rbWdOArH04J7PwAAARg"]
[Tue Aug 18 12:53:31.984433 2026] [security2:error] [pid 66623:tid 66861] [client 74.248.136.165:58259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/koiy.php"] [unique_id "aoR_-9O5rbWdOArH04J7QAAAAWk"]
[Tue Aug 18 12:53:32.018770 2026] [security2:error] [pid 67073:tid 67318] [client 172.202.39.151:48021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoR__Pcmepr5_nHgLbMs7QAAAoU"]
[Tue Aug 18 12:53:32.040973 2026] [security2:error] [pid 67073:tid 67233] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/oivcl.php"] [unique_id "aoR__Pcmepr5_nHgLbMs7gAAAjA"]
[Tue Aug 18 12:53:32.051141 2026] [security2:error] [pid 67073:tid 67229] [client 168.62.48.100:14768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoR__Pcmepr5_nHgLbMs7wAAAiw"]
[Tue Aug 18 12:53:32.080161 2026] [security2:error] [pid 67073:tid 67271] [client 74.248.18.37:21946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/test1.php"] [unique_id "aoR__Pcmepr5_nHgLbMs8QAAAlY"]
[Tue Aug 18 12:53:32.099020 2026] [security2:error] [pid 66623:tid 66790] [client 20.51.153.15:13426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/evil.php"] [unique_id "aoR__NO5rbWdOArH04J7RwAAASI"]
[Tue Aug 18 12:53:32.113407 2026] [security2:error] [pid 67073:tid 67283] [client 20.171.51.14:15771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/lmfi2.php"] [unique_id "aoR__Pcmepr5_nHgLbMs8gAAAmI"]
[Tue Aug 18 12:53:32.126578 2026] [security2:error] [pid 66623:tid 66826] [client 20.226.56.190:21141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/bu.php"] [unique_id "aoR__NO5rbWdOArH04J7SAAAAUY"]
[Tue Aug 18 12:53:32.148960 2026] [security2:error] [pid 67073:tid 67288] [client 20.104.100.201:53839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/images.php"] [unique_id "aoR__Pcmepr5_nHgLbMs8wAAAmc"]
[Tue Aug 18 12:53:32.152617 2026] [security2:error] [pid 67073:tid 67305] [client 20.171.51.14:43356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ke.php"] [unique_id "aoR__Pcmepr5_nHgLbMs9AAAAng"]
[Tue Aug 18 12:53:32.156632 2026] [security2:error] [pid 66623:tid 66856] [client 172.202.39.151:62700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/index/function.php"] [unique_id "aoR__NO5rbWdOArH04J7SQAAAWQ"]
[Tue Aug 18 12:53:32.163511 2026] [security2:error] [pid 67073:tid 67218] [client 20.100.169.31:28439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/ncx.php"] [unique_id "aoR__Pcmepr5_nHgLbMs9QAAAiE"]
[Tue Aug 18 12:53:32.173939 2026] [security2:error] [pid 66623:tid 66880] [client 20.119.58.187:14642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/languages/php8.php"] [unique_id "aoR__NO5rbWdOArH04J7SgAAAXw"]
[Tue Aug 18 12:53:32.222525 2026] [security2:error] [pid 67073:tid 67173] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR__Pcmepr5_nHgLbMs9wACf2E"]
[Tue Aug 18 12:53:32.267080 2026] [authz_core:error] [pid 67073:tid 67174] [remote 57.141.22.120:28652] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:32.267556 2026] [authz_core:error] [pid 67073:tid 67174] [remote 57.141.22.120:28652] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:32.290175 2026] [security2:error] [pid 66623:tid 66791] [client 168.62.48.100:14824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/mt/byp.php"] [unique_id "aoR__NO5rbWdOArH04J7TAAAASM"]
[Tue Aug 18 12:53:32.295984 2026] [autoindex:error] [pid 67073:tid 67207] [client 4.223.164.152:64676] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:32.316374 2026] [security2:error] [pid 67073:tid 67268] [client 5.253.205.188:48208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/file.sql"] [unique_id "aoR__Pcmepr5_nHgLbMs-wAAAlM"], referer: https://medihub.com.br/file.sql
[Tue Aug 18 12:53:32.318028 2026] [security2:error] [pid 67073:tid 67286] [client 4.232.151.198:15569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/min.php"] [unique_id "aoR__Pcmepr5_nHgLbMs_AAAAmU"]
[Tue Aug 18 12:53:32.342058 2026] [security2:error] [pid 67073:tid 67261] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/zugvi.php"] [unique_id "aoR__Pcmepr5_nHgLbMs_QAAAkw"]
[Tue Aug 18 12:53:32.379661 2026] [security2:error] [pid 67073:tid 67240] [client 52.238.210.254:10207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoR__Pcmepr5_nHgLbMs_wAAAjc"]
[Tue Aug 18 12:53:32.379850 2026] [security2:error] [pid 67073:tid 67214] [client 20.100.169.31:31936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.julioalvez.com.br"] [uri "/inputs.php"] [unique_id "aoR__Pcmepr5_nHgLbMtAAAAAh0"]
[Tue Aug 18 12:53:32.402629 2026] [security2:error] [pid 66623:tid 66794] [client 74.248.136.165:46519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/fff.php"] [unique_id "aoR__NO5rbWdOArH04J7TwAAASY"]
[Tue Aug 18 12:53:32.406024 2026] [security2:error] [pid 66623:tid 66808] [client 20.51.153.15:13332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/wp-key.php"] [unique_id "aoR__NO5rbWdOArH04J7UAAAATQ"]
[Tue Aug 18 12:53:32.414253 2026] [security2:error] [pid 67073:tid 67294] [client 213.35.127.232:52587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoR__Pcmepr5_nHgLbMtAQAAAm0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:32.442110 2026] [security2:error] [pid 67073:tid 67280] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoR__Pcmepr5_nHgLbMtAgAAAl8"]
[Tue Aug 18 12:53:32.474985 2026] [security2:error] [pid 67073:tid 67239] [client 37.40.227.74:57121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR__Pcmepr5_nHgLbMtBQAAAjY"]
[Tue Aug 18 12:53:32.475127 2026] [security2:error] [pid 67073:tid 67239] [client 37.40.227.74:57121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR__Pcmepr5_nHgLbMtBQAAAjY"]
[Tue Aug 18 12:53:32.478107 2026] [security2:error] [pid 67073:tid 67321] [client 20.171.51.14:45432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/fd.php"] [unique_id "aoR__Pcmepr5_nHgLbMtBgAAAog"]
[Tue Aug 18 12:53:32.507024 2026] [security2:error] [pid 67073:tid 67266] [client 4.223.164.152:64676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoR__Pcmepr5_nHgLbMtCAAAAlE"]
[Tue Aug 18 12:53:32.524789 2026] [security2:error] [pid 66623:tid 66882] [client 52.28.162.93:29186] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agrimotor.com.br"] [uri "/index.php"] [unique_id "aoR__NO5rbWdOArH04J7TgAAAX4"], referer: http://www.agrimotor.com.br/
[Tue Aug 18 12:53:32.527260 2026] [security2:error] [pid 67073:tid 67317] [client 168.62.48.100:16319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/MTOS/byp.php"] [unique_id "aoR__Pcmepr5_nHgLbMtCQAAAoQ"]
[Tue Aug 18 12:53:32.537637 2026] [security2:error] [pid 66623:tid 66863] [client 20.119.58.187:15338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/customize/php8.php"] [unique_id "aoR__NO5rbWdOArH04J7UwAAAWs"]
[Tue Aug 18 12:53:32.541217 2026] [security2:error] [pid 67073:tid 67325] [client 4.223.164.152:6901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/fi22.php"] [unique_id "aoR__Pcmepr5_nHgLbMtCgAAAow"]
[Tue Aug 18 12:53:32.560914 2026] [security2:error] [pid 66623:tid 66811] [client 135.225.75.187:20839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/rum.php"] [unique_id "aoR__NO5rbWdOArH04J7VAAAATc"]
[Tue Aug 18 12:53:32.604054 2026] [security2:error] [pid 66623:tid 66842] [client 74.248.18.37:49748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/a.php"] [unique_id "aoR__NO5rbWdOArH04J7WAAAAVY"]
[Tue Aug 18 12:53:32.616204 2026] [security2:error] [pid 67073:tid 67238] [client 172.202.39.151:60999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/cah.php"] [unique_id "aoR__Pcmepr5_nHgLbMtDAAAAjU"]
[Tue Aug 18 12:53:32.622458 2026] [security2:error] [pid 67073:tid 67275] [client 20.91.215.254:20247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoR__Pcmepr5_nHgLbMtDQAAAlo"]
[Tue Aug 18 12:53:32.634386 2026] [security2:error] [pid 67073:tid 67270] [client 52.139.47.57:17509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp.php"] [unique_id "aoR__Pcmepr5_nHgLbMtDgAAAlU"]
[Tue Aug 18 12:53:32.645232 2026] [security2:error] [pid 67073:tid 67244] [client 132.196.61.152:56083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/ops.php"] [unique_id "aoR__Pcmepr5_nHgLbMtDwAAAjs"]
[Tue Aug 18 12:53:32.654058 2026] [security2:error] [pid 66623:tid 66885] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wsrer.php"] [unique_id "aoR__NO5rbWdOArH04J7WQAAAYE"]
[Tue Aug 18 12:53:32.666808 2026] [security2:error] [pid 67073:tid 67331] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/a7.php"] [unique_id "aoR__Pcmepr5_nHgLbMtEQAAApI"]
[Tue Aug 18 12:53:32.742972 2026] [security2:error] [pid 67073:tid 67256] [client 74.248.18.37:19982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/text.php"] [unique_id "aoR__Pcmepr5_nHgLbMtFQAAAkc"]
[Tue Aug 18 12:53:32.748107 2026] [authz_core:error] [pid 67073:tid 67186] [remote 57.141.22.15:31022] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:32.748386 2026] [authz_core:error] [pid 67073:tid 67186] [remote 57.141.22.15:31022] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:32.760215 2026] [security2:error] [pid 67073:tid 67187] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR__Pcmepr5_nHgLbMtFgACFW8"]
[Tue Aug 18 12:53:32.764764 2026] [security2:error] [pid 67073:tid 67330] [client 168.62.48.100:14776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoR__Pcmepr5_nHgLbMtFwAAApE"]
[Tue Aug 18 12:53:32.779057 2026] [security2:error] [pid 67073:tid 67301] [client 20.51.153.15:13406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/phpcheck.php"] [unique_id "aoR__Pcmepr5_nHgLbMtGQAAAnQ"]
[Tue Aug 18 12:53:32.805635 2026] [security2:error] [pid 67073:tid 67245] [client 20.226.56.190:6392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/rn.php"] [unique_id "aoR__Pcmepr5_nHgLbMtGgAAAjw"]
[Tue Aug 18 12:53:32.820412 2026] [security2:error] [pid 66623:tid 66855] [client 74.248.136.165:58243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/pouhg.php"] [unique_id "aoR__NO5rbWdOArH04J7XQAAAWM"]
[Tue Aug 18 12:53:32.849673 2026] [security2:error] [pid 66623:tid 66839] [client 20.171.51.14:43356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/nh.php"] [unique_id "aoR__NO5rbWdOArH04J7XgAAAVM"]
[Tue Aug 18 12:53:32.902033 2026] [security2:error] [pid 67073:tid 67290] [client 20.119.58.187:15312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes.bak/html-api/php8.php"] [unique_id "aoR__Pcmepr5_nHgLbMtHAAAAmk"]
[Tue Aug 18 12:53:32.945186 2026] [security2:error] [pid 67073:tid 67313] [client 4.223.164.152:54255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/aaa.php"] [unique_id "aoR__Pcmepr5_nHgLbMtHgAAAoA"]
[Tue Aug 18 12:53:32.961912 2026] [security2:error] [pid 66623:tid 66777] [client 20.48.236.86:10369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/yj09.php"] [unique_id "aoR__NO5rbWdOArH04J7YgAAARU"]
[Tue Aug 18 12:53:32.977668 2026] [security2:error] [pid 66623:tid 66828] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/ucpfr.php"] [unique_id "aoR__NO5rbWdOArH04J7YwAAAUg"]
[Tue Aug 18 12:53:32.980223 2026] [security2:error] [pid 66623:tid 66809] [client 20.171.51.14:16717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/info2.php"] [unique_id "aoR__NO5rbWdOArH04J7ZAAAATU"]
[Tue Aug 18 12:53:32.999355 2026] [security2:error] [pid 66623:tid 66851] [client 52.238.210.254:10115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/php.php"] [unique_id "aoR__NO5rbWdOArH04J7ZQAAAV8"]
[Tue Aug 18 12:53:33.003674 2026] [security2:error] [pid 66623:tid 66782] [client 168.62.48.100:14843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoR__dO5rbWdOArH04J7ZgAAARo"]
[Tue Aug 18 12:53:33.022792 2026] [security2:error] [pid 67073:tid 67297] [client 20.104.100.201:53887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/a.php"] [unique_id "aoR__fcmepr5_nHgLbMtIAAAAnA"]
[Tue Aug 18 12:53:33.104979 2026] [security2:error] [pid 67073:tid 67223] [client 20.51.153.15:13341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/mimes.php"] [unique_id "aoR__fcmepr5_nHgLbMtIgAAAiY"]
[Tue Aug 18 12:53:33.109760 2026] [security2:error] [pid 66623:tid 66850] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/xx.php"] [unique_id "aoR__dO5rbWdOArH04J7aAAAAV4"]
[Tue Aug 18 12:53:33.194453 2026] [security2:error] [pid 67073:tid 67215] [client 114.119.153.172:45941] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "v8multimarcasrs.com.br"] [uri "/veiculos"] [unique_id "aoR__fcmepr5_nHgLbMtJAAAAh4"], referer: https://v8multimarcasrs.com.br/veiculos?marca_id=HONDA&page=2
[Tue Aug 18 12:53:33.213706 2026] [security2:error] [pid 67073:tid 67237] [client 20.151.109.219:36687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/xn.php"] [unique_id "aoR__fcmepr5_nHgLbMtJQAAAjQ"]
[Tue Aug 18 12:53:33.232516 2026] [security2:error] [pid 66623:tid 66810] [client 20.118.172.148:33784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/wk/index.php"] [unique_id "aoR__dO5rbWdOArH04J7agAAATY"]
[Tue Aug 18 12:53:33.237294 2026] [security2:error] [pid 66623:tid 66773] [client 74.248.136.165:52072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/moon3.php"] [unique_id "aoR__dO5rbWdOArH04J7awAAARE"]
[Tue Aug 18 12:53:33.247655 2026] [security2:error] [pid 66623:tid 66868] [client 168.62.48.100:14730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoR__dO5rbWdOArH04J7bAAAAXA"]
[Tue Aug 18 12:53:33.256925 2026] [security2:error] [pid 67073:tid 67303] [client 4.223.164.152:7068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoR__fcmepr5_nHgLbMtJwAAAnY"]
[Tue Aug 18 12:53:33.258477 2026] [security2:error] [pid 66623:tid 66806] [client 20.119.58.187:14607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/widgets/php8.php"] [unique_id "aoR__dO5rbWdOArH04J7bQAAATI"]
[Tue Aug 18 12:53:33.267498 2026] [security2:error] [pid 67073:tid 67197] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ws61.php"] [unique_id "aoR__fcmepr5_nHgLbMtKAACink"]
[Tue Aug 18 12:53:33.282064 2026] [security2:error] [pid 66623:tid 66789] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/yxijx.php"] [unique_id "aoR__dO5rbWdOArH04J7bgAAASE"]
[Tue Aug 18 12:53:33.324384 2026] [security2:error] [pid 67073:tid 67318] [client 172.202.39.151:62687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/edit.php"] [unique_id "aoR__fcmepr5_nHgLbMtKwAAAoU"]
[Tue Aug 18 12:53:33.338232 2026] [security2:error] [pid 66623:tid 66817] [client 20.65.98.162:16581] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "jotaautos.com.br"] [uri "/1.php"] [unique_id "aoR__dO5rbWdOArH04J7bwAAAT0"]
[Tue Aug 18 12:53:33.338304 2026] [security2:error] [pid 66623:tid 66817] [client 20.65.98.162:16581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/1.php"] [unique_id "aoR__dO5rbWdOArH04J7bwAAAT0"]
[Tue Aug 18 12:53:33.341154 2026] [security2:error] [pid 67073:tid 67254] [client 52.238.210.254:10144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/t.php"] [unique_id "aoR__fcmepr5_nHgLbMtLQAAAkU"]
[Tue Aug 18 12:53:33.366143 2026] [security2:error] [pid 67073:tid 67267] [client 20.91.215.254:20251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/al.php"] [unique_id "aoR__fcmepr5_nHgLbMtLgAAAlI"]
[Tue Aug 18 12:53:33.366908 2026] [security2:error] [pid 66623:tid 66867] [client 4.223.164.152:54208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/gecko.php"] [unique_id "aoR__dO5rbWdOArH04J7cAAAAW8"]
[Tue Aug 18 12:53:33.377771 2026] [security2:error] [pid 67073:tid 67231] [client 74.248.18.37:13213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/themes/zmousse/otuz1.php"] [unique_id "aoR__fcmepr5_nHgLbMtMAAAAi4"]
[Tue Aug 18 12:53:33.383701 2026] [security2:error] [pid 67073:tid 67229] [client 20.51.153.15:13331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/fraie1p4.php"] [unique_id "aoR__fcmepr5_nHgLbMtMQAAAiw"]
[Tue Aug 18 12:53:33.395884 2026] [security2:error] [pid 66623:tid 66798] [client 4.232.151.198:35493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/php8.php"] [unique_id "aoR__dO5rbWdOArH04J7cQAAASo"]
[Tue Aug 18 12:53:33.417831 2026] [security2:error] [pid 67073:tid 67288] [client 20.171.51.14:15013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/oo.php"] [unique_id "aoR__fcmepr5_nHgLbMtMwAAAmc"]
[Tue Aug 18 12:53:33.418196 2026] [security2:error] [pid 67073:tid 67305] [client 172.202.39.151:59883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/system_log.php"] [unique_id "aoR__fcmepr5_nHgLbMtNAAAAng"]
[Tue Aug 18 12:53:33.427104 2026] [security2:error] [pid 67073:tid 67242] [client 213.35.127.232:52807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoR__fcmepr5_nHgLbMtNgAAAjk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:33.451619 2026] [security2:error] [pid 67073:tid 67200] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/rum.php"] [unique_id "aoR__fcmepr5_nHgLbMtOgACRHw"]
[Tue Aug 18 12:53:33.464657 2026] [security2:error] [pid 67073:tid 67246] [client 104.209.144.33:32661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/blog/byp.php"] [unique_id "aoR__fcmepr5_nHgLbMtPAAAAj0"]
[Tue Aug 18 12:53:33.491151 2026] [security2:error] [pid 67073:tid 67272] [client 74.249.206.207:52137] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/1.php"] [unique_id "aoR__fcmepr5_nHgLbMtPgAAAlc"]
[Tue Aug 18 12:53:33.491278 2026] [security2:error] [pid 67073:tid 67272] [client 74.249.206.207:52137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/1.php"] [unique_id "aoR__fcmepr5_nHgLbMtPgAAAlc"]
[Tue Aug 18 12:53:33.491533 2026] [security2:error] [pid 67073:tid 67316] [client 20.226.56.190:7315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/ut.php"] [unique_id "aoR__fcmepr5_nHgLbMtPwAAAoM"]
[Tue Aug 18 12:53:33.492609 2026] [security2:error] [pid 67073:tid 67212] [client 168.62.48.100:16359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoR__fcmepr5_nHgLbMtQAAAAhs"]
[Tue Aug 18 12:53:33.512329 2026] [security2:error] [pid 67073:tid 67261] [client 20.104.85.180:18831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoR__fcmepr5_nHgLbMtQwAAAkw"]
[Tue Aug 18 12:53:33.569735 2026] [security2:error] [pid 67073:tid 67294] [client 20.171.51.14:58868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/sx.php"] [unique_id "aoR__fcmepr5_nHgLbMtSQAAAm0"]
[Tue Aug 18 12:53:33.593582 2026] [security2:error] [pid 67073:tid 67241] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/zwlsv.php"] [unique_id "aoR__fcmepr5_nHgLbMtSwAAAjg"]
[Tue Aug 18 12:53:33.595618 2026] [authz_core:error] [pid 67073:tid 67086] [remote 57.141.22.24:43678] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:33.595936 2026] [authz_core:error] [pid 67073:tid 67086] [remote 57.141.22.24:43678] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:33.623028 2026] [security2:error] [pid 67073:tid 67286] [client 20.119.58.187:15145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/IXR/php8.php"] [unique_id "aoR__fcmepr5_nHgLbMtTAAAAmU"]
[Tue Aug 18 12:53:33.629326 2026] [security2:error] [pid 66623:tid 66858] [client 149.34.210.157:65044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR__dO5rbWdOArH04J7cgAAAWY"]
[Tue Aug 18 12:53:33.645383 2026] [security2:error] [pid 66623:tid 66825] [client 135.225.75.187:57813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ze.php"] [unique_id "aoR__dO5rbWdOArH04J7cwAAAUU"]
[Tue Aug 18 12:53:33.646406 2026] [security2:error] [pid 67073:tid 67230] [client 172.202.39.151:55599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/info.php"] [unique_id "aoR__fcmepr5_nHgLbMtTgAAAi0"]
[Tue Aug 18 12:53:33.651938 2026] [security2:error] [pid 67073:tid 67255] [client 20.51.153.15:13382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/pqr.php"] [unique_id "aoR__fcmepr5_nHgLbMtTwAAAkY"]
[Tue Aug 18 12:53:33.652852 2026] [security2:error] [pid 67073:tid 67238] [client 74.248.136.165:17248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/opts.php"] [unique_id "aoR__fcmepr5_nHgLbMtUAAAAjU"]
[Tue Aug 18 12:53:33.685540 2026] [security2:error] [pid 67073:tid 67088] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ze.php"] [unique_id "aoR__fcmepr5_nHgLbMtUgACKAw"]
[Tue Aug 18 12:53:33.731062 2026] [security2:error] [pid 67073:tid 67326] [client 168.62.48.100:16324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoR__fcmepr5_nHgLbMtVwAAAo0"]
[Tue Aug 18 12:53:33.757781 2026] [security2:error] [pid 67073:tid 67256] [client 132.196.61.152:56092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/8.php"] [unique_id "aoR__fcmepr5_nHgLbMtWAAAAkc"]
[Tue Aug 18 12:53:33.763651 2026] [security2:error] [pid 67073:tid 67232] [client 20.104.100.201:54057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoR__fcmepr5_nHgLbMtWgAAAi8"]
[Tue Aug 18 12:53:33.773117 2026] [security2:error] [pid 66623:tid 66774] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/av.php"] [unique_id "aoR__dO5rbWdOArH04J7dgAAARI"]
[Tue Aug 18 12:53:33.786821 2026] [security2:error] [pid 66623:tid 66877] [client 4.223.164.152:37273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/xiugai.php"] [unique_id "aoR__dO5rbWdOArH04J7dwAAAXk"]
[Tue Aug 18 12:53:33.822233 2026] [security2:error] [pid 67073:tid 67309] [client 20.104.85.180:7013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/gelay.php"] [unique_id "aoR__fcmepr5_nHgLbMtWwAAAnw"]
[Tue Aug 18 12:53:33.896270 2026] [security2:error] [pid 67073:tid 67247] [client 20.51.153.15:13314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/lmfi2.php"] [unique_id "aoR__fcmepr5_nHgLbMtXgAAAj4"]
[Tue Aug 18 12:53:33.904946 2026] [security2:error] [pid 67073:tid 67094] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/gjm.php"] [unique_id "aoR__fcmepr5_nHgLbMtXwACeRI"]
[Tue Aug 18 12:53:33.905333 2026] [security2:error] [pid 67073:tid 67252] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/jrpga.php"] [unique_id "aoR__fcmepr5_nHgLbMtYAAAAkM"]
[Tue Aug 18 12:53:33.906259 2026] [security2:error] [pid 66623:tid 66858] [client 149.34.210.157:65044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR__dO5rbWdOArH04J7cgAAAWY"]
[Tue Aug 18 12:53:33.930859 2026] [security2:error] [pid 66623:tid 66860] [client 20.100.169.31:28418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoR__dO5rbWdOArH04J7eQAAAWg"]
[Tue Aug 18 12:53:33.933967 2026] [security2:error] [pid 66623:tid 66804] [client 52.238.210.254:8876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/index/function.php"] [unique_id "aoR__dO5rbWdOArH04J7egAAATA"]
[Tue Aug 18 12:53:33.968432 2026] [security2:error] [pid 67073:tid 67262] [client 168.62.48.100:14779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoR__fcmepr5_nHgLbMtZAAAAk0"]
[Tue Aug 18 12:53:33.977460 2026] [security2:error] [pid 67073:tid 67324] [client 20.119.58.187:15157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/js/php8.php"] [unique_id "aoR__fcmepr5_nHgLbMtZgAAAos"]
[Tue Aug 18 12:53:33.978499 2026] [security2:error] [pid 66623:tid 66812] [client 20.226.56.190:11586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/eh.php"] [unique_id "aoR__dO5rbWdOArH04J7ewAAATg"]
[Tue Aug 18 12:53:33.979150 2026] [security2:error] [pid 67073:tid 67221] [client 20.42.19.40:2187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/inputs.php"] [unique_id "aoR__fcmepr5_nHgLbMtZwAAAiQ"]
[Tue Aug 18 12:53:34.020250 2026] [security2:error] [pid 67073:tid 67330] [client 74.248.18.37:13187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/u.php"] [unique_id "aoR__vcmepr5_nHgLbMtagAAApE"]
[Tue Aug 18 12:53:34.037982 2026] [security2:error] [pid 67073:tid 67278] [client 196.12.128.158:53841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoR__vcmepr5_nHgLbMtawAAAl0"]
[Tue Aug 18 12:53:34.038152 2026] [security2:error] [pid 67073:tid 67278] [client 196.12.128.158:53841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoR__vcmepr5_nHgLbMtawAAAl0"]
[Tue Aug 18 12:53:34.070475 2026] [security2:error] [pid 67073:tid 67296] [client 74.248.136.165:58247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/zwq13.php"] [unique_id "aoR__vcmepr5_nHgLbMtbQAAAm8"]
[Tue Aug 18 12:53:34.079234 2026] [security2:error] [pid 67073:tid 67222] [client 213.202.253.4:60149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "affaripericiacontabil.com.br"] [uri "/schallfuns.php"] [unique_id "aoR__vcmepr5_nHgLbMtbgAAAiU"], referer: www.google.com
[Tue Aug 18 12:53:34.120579 2026] [security2:error] [pid 66623:tid 66784] [client 4.223.164.152:6877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoR__tO5rbWdOArH04J7fAAAARw"]
[Tue Aug 18 12:53:34.204572 2026] [security2:error] [pid 66623:tid 66781] [client 20.51.153.15:13342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/info2.php"] [unique_id "aoR__tO5rbWdOArH04J7fQAAARk"]
[Tue Aug 18 12:53:34.206952 2026] [security2:error] [pid 66623:tid 66805] [client 20.104.85.180:43559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoR__tO5rbWdOArH04J7fgAAATE"]
[Tue Aug 18 12:53:34.210458 2026] [security2:error] [pid 67073:tid 67223] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoR__vcmepr5_nHgLbMtdQAAAiY"]
[Tue Aug 18 12:53:34.217599 2026] [security2:error] [pid 66623:tid 66770] [client 168.62.48.100:14827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/first.php"] [unique_id "aoR__tO5rbWdOArH04J7fwAAAQ4"]
[Tue Aug 18 12:53:34.226107 2026] [security2:error] [pid 67073:tid 67220] [client 4.223.164.152:37295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/adminner.php"] [unique_id "aoR__vcmepr5_nHgLbMtdgAAAiM"]
[Tue Aug 18 12:53:34.228758 2026] [security2:error] [pid 67073:tid 67098] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/new4.php"] [unique_id "aoR__vcmepr5_nHgLbMtdwACbBY"]
[Tue Aug 18 12:53:34.288433 2026] [security2:error] [pid 67073:tid 67105] [remote 115.146.125.52:58574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/wp-login.php"] [unique_id "aoR__vcmepr5_nHgLbMtegACOh0"]
[Tue Aug 18 12:53:34.301210 2026] [security2:error] [pid 67073:tid 67299] [client 20.171.51.14:58841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/nu.php"] [unique_id "aoR__vcmepr5_nHgLbMtewAAAnI"]
[Tue Aug 18 12:53:34.367142 2026] [security2:error] [pid 66623:tid 66861] [client 20.119.58.187:14613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/.well-known/pki-validation/php8.php"] [unique_id "aoR__tO5rbWdOArH04J7gAAAAWk"]
[Tue Aug 18 12:53:34.376565 2026] [security2:error] [pid 66623:tid 66665] [remote 203.99.146.53:52288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "immobili.adm.br"] [uri "/wp-login.php"] [unique_id "aoR__tO5rbWdOArH04J7ggABWRw"]
[Tue Aug 18 12:53:34.376762 2026] [security2:error] [pid 66623:tid 66891] [client 20.91.215.254:16693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp.php"] [unique_id "aoR__tO5rbWdOArH04J7gQAAAYc"]
[Tue Aug 18 12:53:34.409372 2026] [security2:error] [pid 67073:tid 67320] [client 20.171.51.14:59317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ja.php"] [unique_id "aoR__vcmepr5_nHgLbMtfQAAAoc"]
[Tue Aug 18 12:53:34.417662 2026] [security2:error] [pid 67073:tid 67318] [client 52.238.210.254:10137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wk/index.php"] [unique_id "aoR__vcmepr5_nHgLbMtfgAAAoU"]
[Tue Aug 18 12:53:34.418470 2026] [security2:error] [pid 67073:tid 67269] [client 20.226.56.190:10608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/ad.php"] [unique_id "aoR__vcmepr5_nHgLbMtfwAAAlQ"]
[Tue Aug 18 12:53:34.423552 2026] [security2:error] [pid 67073:tid 67109] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-act.php"] [unique_id "aoR__vcmepr5_nHgLbMtgAACRSE"]
[Tue Aug 18 12:53:34.445602 2026] [security2:error] [pid 66623:tid 66766] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/media.php"] [unique_id "aoR__tO5rbWdOArH04J7hQAAAQo"]
[Tue Aug 18 12:53:34.445975 2026] [security2:error] [pid 66623:tid 66870] [client 213.35.127.232:53012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoR__tO5rbWdOArH04J7hgAAAXI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:34.453096 2026] [security2:error] [pid 66623:tid 66837] [client 168.62.48.100:14750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoR__tO5rbWdOArH04J7iAAAAVE"]
[Tue Aug 18 12:53:34.487030 2026] [security2:error] [pid 67073:tid 67300] [client 74.248.136.165:49481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/Okxob.php"] [unique_id "aoR__vcmepr5_nHgLbMtggAAAnM"]
[Tue Aug 18 12:53:34.496072 2026] [security2:error] [pid 67073:tid 67288] [client 20.104.85.180:18836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/adminfuns.php"] [unique_id "aoR__vcmepr5_nHgLbMtgwAAAmc"]
[Tue Aug 18 12:53:34.500201 2026] [security2:error] [pid 66623:tid 66886] [client 20.51.153.15:13386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/test_info.php"] [unique_id "aoR__tO5rbWdOArH04J7igAAAYI"]
[Tue Aug 18 12:53:34.546541 2026] [authz_core:error] [pid 67073:tid 67112] [remote 57.141.22.26:50700] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:34.546851 2026] [authz_core:error] [pid 67073:tid 67112] [remote 57.141.22.26:50700] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:34.580041 2026] [security2:error] [pid 66623:tid 66767] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/nwwha.php"] [unique_id "aoR__tO5rbWdOArH04J7iwAAAQs"]
[Tue Aug 18 12:53:34.625635 2026] [security2:error] [pid 67073:tid 67104] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/grsiuk.php"] [unique_id "aoR__vcmepr5_nHgLbMthgACfRw"]
[Tue Aug 18 12:53:34.638169 2026] [security2:error] [pid 66623:tid 66829] [client 4.232.151.198:48227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoR__tO5rbWdOArH04J7jQAAAUk"]
[Tue Aug 18 12:53:34.644695 2026] [security2:error] [pid 67073:tid 67272] [client 172.202.39.151:44456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoR__vcmepr5_nHgLbMtiAAAAlc"]
[Tue Aug 18 12:53:34.651551 2026] [security2:error] [pid 66623:tid 66788] [client 135.225.75.187:49114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/gjm.php"] [unique_id "aoR__tO5rbWdOArH04J7jgAAASA"]
[Tue Aug 18 12:53:34.651773 2026] [security2:error] [pid 67073:tid 67271] [client 74.248.18.37:13243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/updates.php"] [unique_id "aoR__vcmepr5_nHgLbMtiQAAAlY"]
[Tue Aug 18 12:53:34.670177 2026] [security2:error] [pid 67073:tid 67237] [client 20.250.13.23:14127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/admin.php"] [unique_id "aoR__vcmepr5_nHgLbMtiwAAAjQ"]
[Tue Aug 18 12:53:34.671457 2026] [security2:error] [pid 67073:tid 67212] [client 4.223.164.152:54219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/file1221.php"] [unique_id "aoR__vcmepr5_nHgLbMtjAAAAhs"]
[Tue Aug 18 12:53:34.672957 2026] [security2:error] [pid 66623:tid 66821] [client 20.171.51.14:16722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ko.php"] [unique_id "aoR__tO5rbWdOArH04J7jwAAAUE"]
[Tue Aug 18 12:53:34.690534 2026] [security2:error] [pid 67073:tid 67205] [client 20.104.100.201:17346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/99.php"] [unique_id "aoR__vcmepr5_nHgLbMtjQAAAhQ"]
[Tue Aug 18 12:53:34.691235 2026] [security2:error] [pid 67073:tid 67268] [client 168.62.48.100:14669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoR__vcmepr5_nHgLbMtjgAAAlM"]
[Tue Aug 18 12:53:34.699806 2026] [security2:error] [pid 67073:tid 67261] [client 104.209.144.33:25317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoR__vcmepr5_nHgLbMtjwAAAkw"]
[Tue Aug 18 12:53:34.710175 2026] [security2:error] [pid 67073:tid 67210] [client 20.48.236.86:65126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/scxy.php"] [unique_id "aoR__vcmepr5_nHgLbMtkAAAAhk"]
[Tue Aug 18 12:53:34.721320 2026] [security2:error] [pid 66623:tid 66794] [client 20.119.58.187:14617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/pomo/php8.php"] [unique_id "aoR__tO5rbWdOArH04J7kAAAASY"]
[Tue Aug 18 12:53:34.748574 2026] [security2:error] [pid 66623:tid 66842] [client 20.51.153.15:2009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/xynz1.php"] [unique_id "aoR__tO5rbWdOArH04J7kQAAAVY"]
[Tue Aug 18 12:53:34.768027 2026] [security2:error] [pid 67073:tid 67280] [client 68.155.154.236:64573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoR__vcmepr5_nHgLbMtkwAAAl8"]
[Tue Aug 18 12:53:34.795919 2026] [security2:error] [pid 67073:tid 67291] [client 74.248.18.37:32261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/chosen.php"] [unique_id "aoR__vcmepr5_nHgLbMtlAAAAmo"]
[Tue Aug 18 12:53:34.844607 2026] [security2:error] [pid 67073:tid 67321] [client 132.196.61.152:55297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/biufile.php"] [unique_id "aoR__vcmepr5_nHgLbMtmAAAAog"]
[Tue Aug 18 12:53:34.864190 2026] [security2:error] [pid 67073:tid 67228] [client 4.223.164.152:6609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoR__vcmepr5_nHgLbMtmgAAAis"]
[Tue Aug 18 12:53:34.874641 2026] [security2:error] [pid 67073:tid 67120] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/h.php"] [unique_id "aoR__vcmepr5_nHgLbMtmwACZSw"]
[Tue Aug 18 12:53:34.888254 2026] [security2:error] [pid 67073:tid 67230] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/opsqt.php"] [unique_id "aoR__vcmepr5_nHgLbMtnQAAAi0"]
[Tue Aug 18 12:53:34.912636 2026] [security2:error] [pid 66623:tid 66835] [client 74.248.136.165:39515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/file59.php"] [unique_id "aoR__tO5rbWdOArH04J7lAAAAU8"]
[Tue Aug 18 12:53:34.926104 2026] [security2:error] [pid 67073:tid 67315] [client 168.62.48.100:14752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoR__vcmepr5_nHgLbMtnwAAAoI"]
[Tue Aug 18 12:53:34.964193 2026] [security2:error] [pid 66623:tid 66839] [client 74.248.136.165:63257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/hello.php"] [unique_id "aoR__tO5rbWdOArH04J7mAAAAVM"]
[Tue Aug 18 12:53:34.978881 2026] [security2:error] [pid 67073:tid 67251] [client 197.184.64.235:41355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR__vcmepr5_nHgLbMtogAAAkI"]
[Tue Aug 18 12:53:34.979003 2026] [security2:error] [pid 67073:tid 67251] [client 197.184.64.235:41355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR__vcmepr5_nHgLbMtogAAAkI"]
[Tue Aug 18 12:53:34.995273 2026] [security2:error] [pid 67073:tid 67302] [client 20.51.153.15:13385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/album.php"] [unique_id "aoR__vcmepr5_nHgLbMtowAAAnU"]
[Tue Aug 18 12:53:35.052883 2026] [security2:error] [pid 67073:tid 67255] [client 52.139.47.57:39405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wso.php"] [unique_id "aoR___cmepr5_nHgLbMtpgAAAkY"]
[Tue Aug 18 12:53:35.075667 2026] [security2:error] [pid 67073:tid 67331] [client 20.119.58.187:14605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/block-patterns/php8.php"] [unique_id "aoR___cmepr5_nHgLbMtpwAAApI"]
[Tue Aug 18 12:53:35.088763 2026] [security2:error] [pid 66623:tid 66887] [client 20.226.56.190:20889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/vd.php"] [unique_id "aoR__9O5rbWdOArH04J7mQAAAYM"]
[Tue Aug 18 12:53:35.088766 2026] [security2:error] [pid 66623:tid 66853] [client 52.238.210.254:8952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-blink.php"] [unique_id "aoR__9O5rbWdOArH04J7mgAAAWE"]
[Tue Aug 18 12:53:35.090716 2026] [security2:error] [pid 66623:tid 66777] [client 20.171.51.14:33697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/xx.php"] [unique_id "aoR__9O5rbWdOArH04J7mwAAARU"]
[Tue Aug 18 12:53:35.092502 2026] [security2:error] [pid 66623:tid 66828] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/manager.php"] [unique_id "aoR__9O5rbWdOArH04J7nAAAAUg"]
[Tue Aug 18 12:53:35.103353 2026] [security2:error] [pid 67073:tid 67309] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/images.php"] [unique_id "aoR___cmepr5_nHgLbMtqgAAAnw"]
[Tue Aug 18 12:53:35.126002 2026] [security2:error] [pid 67073:tid 67263] [client 20.171.51.14:61493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/pl.php"] [unique_id "aoR___cmepr5_nHgLbMtrAAAAk4"]
[Tue Aug 18 12:53:35.143024 2026] [security2:error] [pid 67073:tid 67245] [client 4.223.164.152:54254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/inx.php"] [unique_id "aoR___cmepr5_nHgLbMtrQAAAjw"]
[Tue Aug 18 12:53:35.159091 2026] [security2:error] [pid 67073:tid 67304] [client 172.202.39.151:44361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-good.php"] [unique_id "aoR___cmepr5_nHgLbMtrwAAAnc"]
[Tue Aug 18 12:53:35.162352 2026] [security2:error] [pid 67073:tid 67306] [client 168.62.48.100:14673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/blog/byp.php"] [unique_id "aoR___cmepr5_nHgLbMtsAAAAnk"]
[Tue Aug 18 12:53:35.213996 2026] [security2:error] [pid 66623:tid 66879] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/jvcpa.php"] [unique_id "aoR__9O5rbWdOArH04J7nwAAAXs"]
[Tue Aug 18 12:53:35.260494 2026] [security2:error] [pid 67073:tid 67260] [client 20.51.153.15:13384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/creds.php"] [unique_id "aoR___cmepr5_nHgLbMttAAAAks"]
[Tue Aug 18 12:53:35.284146 2026] [security2:error] [pid 67073:tid 67317] [client 74.248.18.37:13215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/upload/autoload_classmap.php"] [unique_id "aoR___cmepr5_nHgLbMttgAAAoQ"]
[Tue Aug 18 12:53:35.295582 2026] [security2:error] [pid 67073:tid 67224] [client 20.104.100.201:17387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/yup.php"] [unique_id "aoR___cmepr5_nHgLbMttwAAAic"]
[Tue Aug 18 12:53:35.303235 2026] [security2:error] [pid 67073:tid 67126] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/koiy.php"] [unique_id "aoR___cmepr5_nHgLbMtuQACGDI"]
[Tue Aug 18 12:53:35.308424 2026] [security2:error] [pid 67073:tid 67296] [client 4.223.164.152:6602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoR___cmepr5_nHgLbMtugAAAm8"]
[Tue Aug 18 12:53:35.330507 2026] [security2:error] [pid 67073:tid 67222] [client 74.248.136.165:39523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/eauu.php"] [unique_id "aoR___cmepr5_nHgLbMtuwAAAiU"]
[Tue Aug 18 12:53:35.398738 2026] [security2:error] [pid 67073:tid 67311] [client 20.163.43.14:3162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR___cmepr5_nHgLbMtvgAAAn4"]
[Tue Aug 18 12:53:35.402340 2026] [security2:error] [pid 66623:tid 66823] [client 168.62.48.100:14760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoR__9O5rbWdOArH04J7oQAAAUM"]
[Tue Aug 18 12:53:35.405360 2026] [security2:error] [pid 67073:tid 67282] [client 52.238.210.254:10212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/xfun.php"] [unique_id "aoR___cmepr5_nHgLbMtvwAAAmE"]
[Tue Aug 18 12:53:35.425589 2026] [security2:error] [pid 66623:tid 66864] [client 192.141.172.134:51397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR__9O5rbWdOArH04J7ogAAAWw"]
[Tue Aug 18 12:53:35.425713 2026] [security2:error] [pid 66623:tid 66864] [client 192.141.172.134:51397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR__9O5rbWdOArH04J7ogAAAWw"]
[Tue Aug 18 12:53:35.459150 2026] [security2:error] [pid 66623:tid 66800] [client 213.35.127.232:53228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoR__9O5rbWdOArH04J7owAAASw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:35.462607 2026] [security2:error] [pid 67073:tid 67226] [client 20.119.58.187:15320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/updraft/php8.php"] [unique_id "aoR___cmepr5_nHgLbMtwwAAAik"]
[Tue Aug 18 12:53:35.463536 2026] [security2:error] [pid 67073:tid 67213] [client 104.209.144.33:32669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoR___cmepr5_nHgLbMtxAAAAhw"]
[Tue Aug 18 12:53:35.466959 2026] [security2:error] [pid 67073:tid 67279] [client 172.182.200.96:14102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/opsqt.php"] [unique_id "aoR___cmepr5_nHgLbMtxgAAAl4"]
[Tue Aug 18 12:53:35.476270 2026] [security2:error] [pid 67073:tid 67299] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/w1.php"] [unique_id "aoR___cmepr5_nHgLbMtxwAAAnI"]
[Tue Aug 18 12:53:35.482106 2026] [security2:error] [pid 67073:tid 67324] [client 4.232.151.198:41082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/222.php"] [unique_id "aoR___cmepr5_nHgLbMtyAAAAos"]
[Tue Aug 18 12:53:35.507109 2026] [security2:error] [pid 67073:tid 67131] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/fff.php"] [unique_id "aoR___cmepr5_nHgLbMtywACRTc"]
[Tue Aug 18 12:53:35.525617 2026] [security2:error] [pid 66623:tid 66809] [client 20.91.215.254:16656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-activat.php"] [unique_id "aoR__9O5rbWdOArH04J7pAAAATU"]
[Tue Aug 18 12:53:35.539355 2026] [security2:error] [pid 67073:tid 67233] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoR___cmepr5_nHgLbMtzAAAAjA"]
[Tue Aug 18 12:53:35.586844 2026] [security2:error] [pid 67073:tid 67218] [client 74.249.206.207:26437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/img.php"] [unique_id "aoR___cmepr5_nHgLbMtzwAAAiE"]
[Tue Aug 18 12:53:35.590811 2026] [security2:error] [pid 67073:tid 67310] [client 20.51.153.15:13395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/mandrill.php"] [unique_id "aoR___cmepr5_nHgLbMt0AAAAn0"]
[Tue Aug 18 12:53:35.600459 2026] [security2:error] [pid 67073:tid 67328] [client 4.223.164.152:46145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/reviall.php"] [unique_id "aoR___cmepr5_nHgLbMt0gAAAo8"]
[Tue Aug 18 12:53:35.606961 2026] [security2:error] [pid 67073:tid 67272] [client 20.118.172.148:33771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/wp-act.php"] [unique_id "aoR___cmepr5_nHgLbMt1AAAAlc"]
[Tue Aug 18 12:53:35.641689 2026] [security2:error] [pid 67073:tid 67237] [client 168.62.48.100:14767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoR___cmepr5_nHgLbMt1QAAAjQ"]
[Tue Aug 18 12:53:35.716014 2026] [security2:error] [pid 67073:tid 67210] [client 20.65.98.162:29483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/coffee.php"] [unique_id "aoR___cmepr5_nHgLbMt2QAAAhk"]
[Tue Aug 18 12:53:35.723759 2026] [security2:error] [pid 67073:tid 67240] [client 20.104.100.201:17298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/222.php"] [unique_id "aoR___cmepr5_nHgLbMt2gAAAjc"]
[Tue Aug 18 12:53:35.730862 2026] [security2:error] [pid 67073:tid 67143] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/pouhg.php"] [unique_id "aoR___cmepr5_nHgLbMt2wACHUM"]
[Tue Aug 18 12:53:35.739059 2026] [security2:error] [pid 67073:tid 67291] [client 20.171.51.14:29199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/conn-test.php"] [unique_id "aoR___cmepr5_nHgLbMt3AAAAmo"]
[Tue Aug 18 12:53:35.748754 2026] [security2:error] [pid 66623:tid 66841] [client 74.248.136.165:65109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/dsd.php"] [unique_id "aoR__9O5rbWdOArH04J7pgAAAVU"]
[Tue Aug 18 12:53:35.773732 2026] [security2:error] [pid 66623:tid 66775] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/mac.php"] [unique_id "aoR__9O5rbWdOArH04J7qAAAARM"]
[Tue Aug 18 12:53:35.788558 2026] [security2:error] [pid 67073:tid 67227] [client 86.120.159.145:62230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR___cmepr5_nHgLbMt3wAAAio"]
[Tue Aug 18 12:53:35.788640 2026] [security2:error] [pid 67073:tid 67227] [client 86.120.159.145:62230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR___cmepr5_nHgLbMt3wAAAio"]
[Tue Aug 18 12:53:35.799512 2026] [security2:error] [pid 66623:tid 66824] [client 20.163.43.14:3172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR__9O5rbWdOArH04J7qQAAAUQ"]
[Tue Aug 18 12:53:35.801576 2026] [security2:error] [pid 66623:tid 66801] [client 20.226.56.190:21121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/56.php"] [unique_id "aoR__9O5rbWdOArH04J7qgAAAS0"]
[Tue Aug 18 12:53:35.813167 2026] [security2:error] [pid 67073:tid 67265] [client 20.171.51.14:58418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/env.php"] [unique_id "aoR___cmepr5_nHgLbMt4AAAAlA"]
[Tue Aug 18 12:53:35.824170 2026] [security2:error] [pid 67073:tid 67207] [client 20.119.58.187:14603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/upgrade-temp-backup/php8.php"] [unique_id "aoR___cmepr5_nHgLbMt4QAAAhY"]
[Tue Aug 18 12:53:35.825854 2026] [security2:error] [pid 67073:tid 67230] [client 4.223.164.152:6903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoR___cmepr5_nHgLbMt4gAAAi0"]
[Tue Aug 18 12:53:35.847524 2026] [security2:error] [pid 67073:tid 67238] [client 20.51.153.15:13423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/main.php"] [unique_id "aoR___cmepr5_nHgLbMt5AAAAjU"]
[Tue Aug 18 12:53:35.851751 2026] [security2:error] [pid 66623:tid 66827] [client 135.225.75.187:9420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/new4.php"] [unique_id "aoR__9O5rbWdOArH04J7qwAAAUc"]
[Tue Aug 18 12:53:35.859430 2026] [security2:error] [pid 67073:tid 67315] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoR___cmepr5_nHgLbMt5gAAAoI"]
[Tue Aug 18 12:53:35.875165 2026] [security2:error] [pid 66623:tid 66819] [client 168.62.48.100:16316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/images/security.php"] [unique_id "aoR__9O5rbWdOArH04J7rAAAAT8"]
[Tue Aug 18 12:53:35.901308 2026] [security2:error] [pid 67073:tid 67284] [client 132.196.61.152:56105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/coffexium.php"] [unique_id "aoR___cmepr5_nHgLbMt6QAAAmM"]
[Tue Aug 18 12:53:35.917053 2026] [security2:error] [pid 66623:tid 66815] [client 74.248.18.37:13216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/uploads/admin.php"] [unique_id "aoR__9O5rbWdOArH04J7rQAAATs"]
[Tue Aug 18 12:53:35.934531 2026] [security2:error] [pid 67073:tid 67142] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/moon3.php"] [unique_id "aoR___cmepr5_nHgLbMt6gACdUI"]
[Tue Aug 18 12:53:36.041366 2026] [security2:error] [pid 67073:tid 67245] [client 4.223.164.152:37276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/11.php"] [unique_id "aoSAAPcmepr5_nHgLbMt7AAAAjw"]
[Tue Aug 18 12:53:36.048652 2026] [security2:error] [pid 67073:tid 67306] [client 20.151.109.219:58334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/47.php"] [unique_id "aoSAAPcmepr5_nHgLbMt7QAAAnk"]
[Tue Aug 18 12:53:36.065081 2026] [security2:error] [pid 67073:tid 67283] [client 20.100.169.31:14582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wso.php"] [unique_id "aoSAAPcmepr5_nHgLbMt7gAAAmI"]
[Tue Aug 18 12:53:36.112277 2026] [security2:error] [pid 66623:tid 66792] [client 20.51.153.15:13394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/payout.php"] [unique_id "aoSAANO5rbWdOArH04J7sAAAASQ"]
[Tue Aug 18 12:53:36.123933 2026] [security2:error] [pid 66623:tid 66869] [client 20.163.43.14:3154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/admin.php"] [unique_id "aoSAANO5rbWdOArH04J7sQAAAXE"]
[Tue Aug 18 12:53:36.157916 2026] [security2:error] [pid 67073:tid 67152] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/opts.php"] [unique_id "aoSAAPcmepr5_nHgLbMt8wACaUw"]
[Tue Aug 18 12:53:36.174205 2026] [security2:error] [pid 66623:tid 66847] [client 104.209.144.33:24870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/images/security.php"] [unique_id "aoSAANO5rbWdOArH04J7tAAAAVs"]
[Tue Aug 18 12:53:36.178757 2026] [security2:error] [pid 66623:tid 66769] [client 74.248.136.165:49530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/c4.php"] [unique_id "aoSAANO5rbWdOArH04J7tQAAAQ0"]
[Tue Aug 18 12:53:36.179293 2026] [security2:error] [pid 67073:tid 67252] [client 20.119.58.187:15269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/themes/php8.php"] [unique_id "aoSAAPcmepr5_nHgLbMt9QAAAkM"]
[Tue Aug 18 12:53:36.207802 2026] [security2:error] [pid 67073:tid 67219] [client 74.248.18.37:49846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAAPcmepr5_nHgLbMt9wAAAiI"]
[Tue Aug 18 12:53:36.212575 2026] [security2:error] [pid 67073:tid 67274] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSAAPcmepr5_nHgLbMt-AAAAlk"]
[Tue Aug 18 12:53:36.223617 2026] [security2:error] [pid 66623:tid 66868] [client 5.31.227.224:7854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAANO5rbWdOArH04J7tgAAAXA"]
[Tue Aug 18 12:53:36.234229 2026] [security2:error] [pid 66623:tid 66868] [client 5.31.227.224:7854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAANO5rbWdOArH04J7tgAAAXA"]
[Tue Aug 18 12:53:36.254565 2026] [security2:error] [pid 67073:tid 67317] [client 20.226.56.190:8309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/rx.php"] [unique_id "aoSAAPcmepr5_nHgLbMt-gAAAoQ"]
[Tue Aug 18 12:53:36.299882 2026] [security2:error] [pid 66623:tid 66892] [client 4.223.164.152:6596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSAANO5rbWdOArH04J7twAAAYg"]
[Tue Aug 18 12:53:36.301303 2026] [security2:error] [pid 66623:tid 66825] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAANO5rbWdOArH04J7swABRSs"]
[Tue Aug 18 12:53:36.314571 2026] [security2:error] [pid 67073:tid 67314] [client 52.87.72.16:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "1td.com.br"] [uri "/index.php"] [unique_id "aoSAAPcmepr5_nHgLbMt8gACgUY"], referer: https://1td.com.br
[Tue Aug 18 12:53:36.322901 2026] [security2:error] [pid 67073:tid 67250] [client 68.155.154.236:65098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSAAPcmepr5_nHgLbMt_QAAAkE"]
[Tue Aug 18 12:53:36.348120 2026] [security2:error] [pid 66623:tid 66852] [client 20.171.51.14:58389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/mz.php"] [unique_id "aoSAANO5rbWdOArH04J7ugAAAWA"]
[Tue Aug 18 12:53:36.350580 2026] [security2:error] [pid 67073:tid 67155] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/zwq13.php"] [unique_id "aoSAAPcmepr5_nHgLbMt_gACMk8"]
[Tue Aug 18 12:53:36.407074 2026] [security2:error] [pid 66623:tid 66870] [client 20.51.153.15:13336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/Mailgun.php"] [unique_id "aoSAANO5rbWdOArH04J7uwAAAXI"]
[Tue Aug 18 12:53:36.410958 2026] [security2:error] [pid 67073:tid 67226] [client 52.238.210.254:9055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/goods.php"] [unique_id "aoSAAPcmepr5_nHgLbMuBAAAAik"]
[Tue Aug 18 12:53:36.430638 2026] [security2:error] [pid 67073:tid 67243] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/ops.php"] [unique_id "aoSAAPcmepr5_nHgLbMuBQAAAjo"]
[Tue Aug 18 12:53:36.439156 2026] [security2:error] [pid 66623:tid 66888] [client 4.232.151.198:41058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSAANO5rbWdOArH04J7vQAAAYQ"]
[Tue Aug 18 12:53:36.460971 2026] [security2:error] [pid 67073:tid 67322] [client 4.223.164.152:64664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/File.php"] [unique_id "aoSAAPcmepr5_nHgLbMuBgAAAok"]
[Tue Aug 18 12:53:36.466484 2026] [security2:error] [pid 67073:tid 67299] [client 20.163.43.14:3182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/public/css.php"] [unique_id "aoSAAPcmepr5_nHgLbMuCAAAAnI"]
[Tue Aug 18 12:53:36.479187 2026] [security2:error] [pid 66623:tid 66786] [client 213.35.127.232:53431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAANO5rbWdOArH04J7vgAAAR4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:36.518977 2026] [security2:error] [pid 67073:tid 67292] [client 74.249.206.207:56243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/222.php"] [unique_id "aoSAAPcmepr5_nHgLbMuCQAAAms"]
[Tue Aug 18 12:53:36.533715 2026] [security2:error] [pid 67073:tid 67162] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/Okxob.php"] [unique_id "aoSAAPcmepr5_nHgLbMuCgACbFY"]
[Tue Aug 18 12:53:36.535457 2026] [security2:error] [pid 66623:tid 66770] [client 20.100.169.31:28382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/i.php"] [unique_id "aoSAANO5rbWdOArH04J7vwAAAQ4"]
[Tue Aug 18 12:53:36.537961 2026] [security2:error] [pid 67073:tid 67303] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSAAPcmepr5_nHgLbMuCwAAAnY"]
[Tue Aug 18 12:53:36.541610 2026] [security2:error] [pid 67073:tid 67215] [client 20.119.58.187:15263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/includes/php8.php"] [unique_id "aoSAAPcmepr5_nHgLbMuDAAAAh4"]
[Tue Aug 18 12:53:36.551820 2026] [security2:error] [pid 67073:tid 67323] [client 20.186.30.159:14240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAAPcmepr5_nHgLbMuDQAAAoo"]
[Tue Aug 18 12:53:36.566843 2026] [security2:error] [pid 66623:tid 66875] [client 104.209.144.33:32644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAANO5rbWdOArH04J7wAAAAXc"]
[Tue Aug 18 12:53:36.574799 2026] [security2:error] [pid 67073:tid 67324] [client 52.238.210.254:8936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/p.php"] [unique_id "aoSAAPcmepr5_nHgLbMuEAAAAos"]
[Tue Aug 18 12:53:36.575123 2026] [security2:error] [pid 67073:tid 67217] [client 20.226.56.190:10615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/mandrill.php"] [unique_id "aoSAAPcmepr5_nHgLbMuEQAAAiA"]
[Tue Aug 18 12:53:36.580505 2026] [security2:error] [pid 67073:tid 67269] [client 172.202.39.151:62681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/tes.php"] [unique_id "aoSAAPcmepr5_nHgLbMuEgAAAlQ"]
[Tue Aug 18 12:53:36.596355 2026] [security2:error] [pid 67073:tid 67318] [client 74.248.136.165:61649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/an7.php"] [unique_id "aoSAAPcmepr5_nHgLbMuEwAAAoU"]
[Tue Aug 18 12:53:36.694693 2026] [security2:error] [pid 67073:tid 67218] [client 20.51.153.15:13411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/oauth.php"] [unique_id "aoSAAPcmepr5_nHgLbMuFgAAAiE"]
[Tue Aug 18 12:53:36.754482 2026] [security2:error] [pid 66623:tid 66821] [client 132.196.61.152:56093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/dex.php"] [unique_id "aoSAANO5rbWdOArH04J7wwAAAUE"]
[Tue Aug 18 12:53:36.788513 2026] [security2:error] [pid 67073:tid 67166] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/file59.php"] [unique_id "aoSAAPcmepr5_nHgLbMuGgACkFo"]
[Tue Aug 18 12:53:36.794780 2026] [security2:error] [pid 66623:tid 66816] [client 20.163.43.14:3164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAANO5rbWdOArH04J7xQAAATw"]
[Tue Aug 18 12:53:36.795837 2026] [security2:error] [pid 67073:tid 67267] [client 45.131.195.188:29631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.195.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "meupix.net"] [uri "/wp-login.php"] [unique_id "aoSAAPcmepr5_nHgLbMuFAAAAlI"]
[Tue Aug 18 12:53:36.801397 2026] [security2:error] [pid 66623:tid 66826] [client 20.171.51.14:61443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ft.php"] [unique_id "aoSAANO5rbWdOArH04J7xgAAAUY"]
[Tue Aug 18 12:53:36.815399 2026] [security2:error] [pid 67073:tid 67268] [client 20.186.30.159:14308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAAPcmepr5_nHgLbMuGwAAAlM"]
[Tue Aug 18 12:53:36.861178 2026] [security2:error] [pid 67073:tid 67210] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSAAPcmepr5_nHgLbMuHwAAAhk"]
[Tue Aug 18 12:53:36.875053 2026] [security2:error] [pid 66623:tid 66840] [client 4.223.164.152:6730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/media.php"] [unique_id "aoSAANO5rbWdOArH04J7xwAAAVQ"]
[Tue Aug 18 12:53:36.886319 2026] [security2:error] [pid 66623:tid 66849] [client 104.209.144.33:25326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSAANO5rbWdOArH04J7yAAAAV0"]
[Tue Aug 18 12:53:36.904883 2026] [security2:error] [pid 66623:tid 66878] [client 20.48.236.86:10789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/ws13.php"] [unique_id "aoSAANO5rbWdOArH04J7yQAAAXo"]
[Tue Aug 18 12:53:36.914160 2026] [security2:error] [pid 67073:tid 67280] [client 4.223.164.152:37270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/fi22.php"] [unique_id "aoSAAPcmepr5_nHgLbMuIAAAAl8"]
[Tue Aug 18 12:53:36.919506 2026] [security2:error] [pid 66623:tid 66811] [client 20.119.58.187:14652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/images/php8.php"] [unique_id "aoSAANO5rbWdOArH04J7ygAAATc"]
[Tue Aug 18 12:53:36.966095 2026] [security2:error] [pid 67073:tid 67227] [client 20.51.153.15:13381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/timeclock.php"] [unique_id "aoSAAPcmepr5_nHgLbMuJgAAAio"]
[Tue Aug 18 12:53:36.966605 2026] [security2:error] [pid 66623:tid 66780] [client 103.184.169.37:41112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAANO5rbWdOArH04J7ywAAARg"]
[Tue Aug 18 12:53:36.966705 2026] [security2:error] [pid 66623:tid 66780] [client 103.184.169.37:41112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAANO5rbWdOArH04J7ywAAARg"]
[Tue Aug 18 12:53:36.970099 2026] [security2:error] [pid 67073:tid 67228] [client 20.104.100.201:53873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-temp.php"] [unique_id "aoSAAPcmepr5_nHgLbMuJwAAAis"]
[Tue Aug 18 12:53:36.972941 2026] [security2:error] [pid 67073:tid 67266] [client 135.225.75.187:33017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-act.php"] [unique_id "aoSAAPcmepr5_nHgLbMuKAAAAlE"]
[Tue Aug 18 12:53:36.994173 2026] [security2:error] [pid 67073:tid 67265] [client 20.151.109.219:28737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/payout.php"] [unique_id "aoSAAPcmepr5_nHgLbMuKQAAAlA"]
[Tue Aug 18 12:53:37.014486 2026] [security2:error] [pid 67073:tid 67275] [client 74.248.136.165:40845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/bsg-management/php.php"] [unique_id "aoSAAfcmepr5_nHgLbMuKwAAAlo"]
[Tue Aug 18 12:53:37.054606 2026] [security2:error] [pid 66623:tid 66776] [client 52.173.121.69:56342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSAAdO5rbWdOArH04J7zgAAARQ"]
[Tue Aug 18 12:53:37.057875 2026] [security2:error] [pid 66623:tid 66855] [client 20.91.215.254:9096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSAAdO5rbWdOArH04J7zwAAAWM"]
[Tue Aug 18 12:53:37.061529 2026] [security2:error] [pid 67073:tid 67270] [client 20.186.30.159:14299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/media.php"] [unique_id "aoSAAfcmepr5_nHgLbMuLgAAAlU"]
[Tue Aug 18 12:53:37.091499 2026] [security2:error] [pid 67073:tid 67315] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/coffexium.php"] [unique_id "aoSAAfcmepr5_nHgLbMuLwAAAoI"]
[Tue Aug 18 12:53:37.118672 2026] [security2:error] [pid 66623:tid 66839] [client 74.249.206.207:51240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/key.php"] [unique_id "aoSAAdO5rbWdOArH04J70AAAAVM"]
[Tue Aug 18 12:53:37.164779 2026] [security2:error] [pid 67073:tid 67308] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSAAfcmepr5_nHgLbMuMgAAAns"]
[Tue Aug 18 12:53:37.194726 2026] [security2:error] [pid 67073:tid 67304] [client 104.209.144.33:24856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSAAfcmepr5_nHgLbMuNgAAAnc"]
[Tue Aug 18 12:53:37.199373 2026] [security2:error] [pid 67073:tid 67283] [client 20.118.172.148:46386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSAAfcmepr5_nHgLbMuNwAAAmI"]
[Tue Aug 18 12:53:37.214155 2026] [security2:error] [pid 67073:tid 67234] [client 20.51.153.15:13421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/email.php"] [unique_id "aoSAAfcmepr5_nHgLbMuOAAAAjE"]
[Tue Aug 18 12:53:37.219389 2026] [security2:error] [pid 67073:tid 67238] [client 138.36.100.162:41929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAAfcmepr5_nHgLbMuOQAAAjU"]
[Tue Aug 18 12:53:37.219471 2026] [security2:error] [pid 67073:tid 67238] [client 138.36.100.162:41929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAAfcmepr5_nHgLbMuOQAAAjU"]
[Tue Aug 18 12:53:37.235673 2026] [security2:error] [pid 67073:tid 67192] [remote 162.214.205.212:59528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnomor.com.br"] [uri "/wp-login.php"] [unique_id "aoSAAfcmepr5_nHgLbMuOwACO3Q"]
[Tue Aug 18 12:53:37.236277 2026] [security2:error] [pid 66623:tid 66795] [client 20.42.19.40:2702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/100.php"] [unique_id "aoSAAdO5rbWdOArH04J70QAAASc"]
[Tue Aug 18 12:53:37.251332 2026] [security2:error] [pid 66623:tid 66843] [client 20.226.56.190:42490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/main.php"] [unique_id "aoSAAdO5rbWdOArH04J70gAAAVc"]
[Tue Aug 18 12:53:37.274785 2026] [security2:error] [pid 66623:tid 66829] [client 45.8.19.134:24591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "baccovaledosvinhedos.com.br"] [uri "/wp-login.php"] [unique_id "aoSAAdO5rbWdOArH04J71AAAAUk"]
[Tue Aug 18 12:53:37.281835 2026] [security2:error] [pid 67073:tid 67290] [client 52.238.210.254:12544] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/wp-admin"] [unique_id "aoSAAfcmepr5_nHgLbMuPQAAAmk"]
[Tue Aug 18 12:53:37.283701 2026] [security2:error] [pid 66623:tid 66777] [client 20.171.51.14:15757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/fg.php"] [unique_id "aoSAAdO5rbWdOArH04J71QAAARU"]
[Tue Aug 18 12:53:37.292842 2026] [security2:error] [pid 67073:tid 67252] [client 20.171.51.14:58857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/h.php"] [unique_id "aoSAAfcmepr5_nHgLbMuPgAAAkM"]
[Tue Aug 18 12:53:37.295500 2026] [security2:error] [pid 67073:tid 67309] [client 20.119.58.187:15252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/blogs.dir/php8.php"] [unique_id "aoSAAfcmepr5_nHgLbMuQAAAAnw"]
[Tue Aug 18 12:53:37.296058 2026] [security2:error] [pid 67073:tid 67219] [client 52.238.210.254:8901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAAfcmepr5_nHgLbMuQQAAAiI"]
[Tue Aug 18 12:53:37.325708 2026] [security2:error] [pid 67073:tid 67317] [client 20.186.30.159:14277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/admin.php"] [unique_id "aoSAAfcmepr5_nHgLbMuRAAAAoQ"]
[Tue Aug 18 12:53:37.337846 2026] [security2:error] [pid 67073:tid 67310] [client 74.248.18.37:38964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/vx.php"] [unique_id "aoSAAfcmepr5_nHgLbMuRQAAAn0"]
[Tue Aug 18 12:53:37.358491 2026] [security2:error] [pid 67073:tid 67296] [client 4.223.164.152:54209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAAfcmepr5_nHgLbMuRgAAAm8"]
[Tue Aug 18 12:53:37.363321 2026] [security2:error] [pid 67073:tid 67222] [client 172.202.39.151:44406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/files/index.php"] [unique_id "aoSAAfcmepr5_nHgLbMuRwAAAiU"]
[Tue Aug 18 12:53:37.432687 2026] [security2:error] [pid 67073:tid 67312] [client 4.223.164.152:6601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/inso.php"] [unique_id "aoSAAfcmepr5_nHgLbMuSQAAAn8"]
[Tue Aug 18 12:53:37.433133 2026] [security2:error] [pid 67073:tid 67250] [client 74.248.136.165:49506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/byp8.php"] [unique_id "aoSAAfcmepr5_nHgLbMuSgAAAkE"]
[Tue Aug 18 12:53:37.446235 2026] [security2:error] [pid 67073:tid 67291] [client 4.232.151.198:38918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/info.php"] [unique_id "aoSAAfcmepr5_nHgLbMuSwAAAmo"]
[Tue Aug 18 12:53:37.452137 2026] [security2:error] [pid 67073:tid 67223] [client 20.51.153.15:13312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/profile.php"] [unique_id "aoSAAfcmepr5_nHgLbMuTAAAAiY"]
[Tue Aug 18 12:53:37.456808 2026] [security2:error] [pid 67073:tid 67298] [client 20.163.43.14:3101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAAfcmepr5_nHgLbMuTQAAAnE"]
[Tue Aug 18 12:53:37.462847 2026] [security2:error] [pid 67073:tid 67213] [client 132.196.61.152:56121] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.riosafe.com.br"] [uri "/1.php"] [unique_id "aoSAAfcmepr5_nHgLbMuUAAAAhw"]
[Tue Aug 18 12:53:37.462928 2026] [security2:error] [pid 67073:tid 67213] [client 132.196.61.152:56121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/1.php"] [unique_id "aoSAAfcmepr5_nHgLbMuUAAAAhw"]
[Tue Aug 18 12:53:37.482707 2026] [security2:error] [pid 67073:tid 67220] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSAAfcmepr5_nHgLbMuUQAAAiM"]
[Tue Aug 18 12:53:37.489369 2026] [security2:error] [pid 67073:tid 67211] [client 213.35.127.232:53617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAAfcmepr5_nHgLbMuUgAAAho"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:37.561360 2026] [security2:error] [pid 67073:tid 67323] [client 20.151.109.219:20713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/bh.php"] [unique_id "aoSAAfcmepr5_nHgLbMuVAAAAoo"]
[Tue Aug 18 12:53:37.570774 2026] [security2:error] [pid 67073:tid 67217] [client 20.186.30.159:14219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/mac.php"] [unique_id "aoSAAfcmepr5_nHgLbMuVQAAAiA"]
[Tue Aug 18 12:53:37.651455 2026] [security2:error] [pid 67073:tid 67215] [client 20.119.58.187:15257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/images/php8.php"] [unique_id "aoSAAfcmepr5_nHgLbMuVwAAAh4"]
[Tue Aug 18 12:53:37.695474 2026] [security2:error] [pid 67073:tid 67322] [client 20.91.215.254:20198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSAAfcmepr5_nHgLbMuWAAAAok"]
[Tue Aug 18 12:53:37.702379 2026] [security2:error] [pid 67073:tid 67080] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/eauu.php"] [unique_id "aoSAAfcmepr5_nHgLbMuWgACVwQ"]
[Tue Aug 18 12:53:37.708172 2026] [security2:error] [pid 67073:tid 67271] [client 158.23.17.4:57038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/rx.php"] [unique_id "aoSAAfcmepr5_nHgLbMuWwAAAlY"]
[Tue Aug 18 12:53:37.753737 2026] [security2:error] [pid 67073:tid 67329] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAAfcmepr5_nHgLbMuXQAAApA"]
[Tue Aug 18 12:53:37.757784 2026] [security2:error] [pid 67073:tid 67267] [client 104.209.144.33:25338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSAAfcmepr5_nHgLbMuXgAAAlI"]
[Tue Aug 18 12:53:37.774471 2026] [security2:error] [pid 67073:tid 67264] [client 20.104.100.201:53884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/spadex.php"] [unique_id "aoSAAfcmepr5_nHgLbMuYAAAAk8"]
[Tue Aug 18 12:53:37.778897 2026] [security2:error] [pid 67073:tid 67240] [client 20.51.153.15:13362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/summary.php"] [unique_id "aoSAAfcmepr5_nHgLbMuYQAAAjc"]
[Tue Aug 18 12:53:37.786041 2026] [security2:error] [pid 67073:tid 67214] [client 52.238.210.254:10199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/aaa.php"] [unique_id "aoSAAfcmepr5_nHgLbMuYgAAAh0"]
[Tue Aug 18 12:53:37.786099 2026] [security2:error] [pid 67073:tid 67281] [client 4.223.164.152:64656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSAAfcmepr5_nHgLbMuYwAAAmA"]
[Tue Aug 18 12:53:37.791067 2026] [security2:error] [pid 67073:tid 67321] [client 20.171.51.14:65104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ve.php"] [unique_id "aoSAAfcmepr5_nHgLbMuZQAAAog"]
[Tue Aug 18 12:53:37.804419 2026] [security2:error] [pid 67073:tid 67266] [client 40.85.222.29:27775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSAAfcmepr5_nHgLbMuZwAAAlE"]
[Tue Aug 18 12:53:37.814708 2026] [security2:error] [pid 67073:tid 67285] [client 20.171.51.14:51776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/40.php"] [unique_id "aoSAAfcmepr5_nHgLbMuaQAAAmQ"]
[Tue Aug 18 12:53:37.820774 2026] [security2:error] [pid 67073:tid 67313] [client 114.119.153.50:51549] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mhost.com.br"] [uri "/teste-vimeo"] [unique_id "aoSAAfcmepr5_nHgLbMuagAAAoA"], referer: https://mhost.com.br/3457-dpt99476-aplicativos-de-paquera-gratuito.html
[Tue Aug 18 12:53:37.837999 2026] [security2:error] [pid 67073:tid 67265] [client 20.186.30.159:14330] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "residencial.multiveicular.org.br"] [uri "/1.php"] [unique_id "aoSAAfcmepr5_nHgLbMubAAAAlA"]
[Tue Aug 18 12:53:37.838109 2026] [security2:error] [pid 67073:tid 67265] [client 20.186.30.159:14330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/1.php"] [unique_id "aoSAAfcmepr5_nHgLbMubAAAAlA"]
[Tue Aug 18 12:53:37.838451 2026] [security2:error] [pid 67073:tid 67325] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSAAfcmepr5_nHgLbMubQAAAow"]
[Tue Aug 18 12:53:37.850155 2026] [security2:error] [pid 67073:tid 67230] [client 74.248.136.165:17225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/plugins.php"] [unique_id "aoSAAfcmepr5_nHgLbMubgAAAi0"]
[Tue Aug 18 12:53:37.858131 2026] [security2:error] [pid 67073:tid 67294] [client 20.226.56.190:40455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/ga.php"] [unique_id "aoSAAfcmepr5_nHgLbMubwAAAm0"]
[Tue Aug 18 12:53:37.864920 2026] [security2:error] [pid 66623:tid 66773] [client 20.163.43.14:3139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/gelay.php"] [unique_id "aoSAAdO5rbWdOArH04J72AAAARE"]
[Tue Aug 18 12:53:37.901133 2026] [authz_core:error] [pid 67073:tid 67085] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:37.901510 2026] [authz_core:error] [pid 67073:tid 67085] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:37.922906 2026] [security2:error] [pid 67073:tid 67273] [client 157.20.138.62:51204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAAfcmepr5_nHgLbMucgAAAlg"]
[Tue Aug 18 12:53:37.923044 2026] [security2:error] [pid 67073:tid 67273] [client 157.20.138.62:51204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAAfcmepr5_nHgLbMucgAAAlg"]
[Tue Aug 18 12:53:37.942269 2026] [security2:error] [pid 67073:tid 67076] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/dsd.php"] [unique_id "aoSAAfcmepr5_nHgLbMucwACRwA"]
[Tue Aug 18 12:53:38.007904 2026] [security2:error] [pid 67073:tid 67315] [client 20.119.58.187:15359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/php8.php"] [unique_id "aoSAAvcmepr5_nHgLbMudgAAAoI"]
[Tue Aug 18 12:53:38.030364 2026] [security2:error] [pid 67073:tid 67249] [client 20.226.56.190:10591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/wb.php"] [unique_id "aoSAAvcmepr5_nHgLbMudwAAAkA"]
[Tue Aug 18 12:53:38.037504 2026] [security2:error] [pid 67073:tid 67262] [client 74.249.206.207:58563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/chosen.php"] [unique_id "aoSAAvcmepr5_nHgLbMueAAAAk0"]
[Tue Aug 18 12:53:38.047367 2026] [security2:error] [pid 67073:tid 67307] [client 4.223.164.152:6637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/shiny.php"] [unique_id "aoSAAvcmepr5_nHgLbMueQAAAno"]
[Tue Aug 18 12:53:38.052897 2026] [security2:error] [pid 67073:tid 67290] [client 20.51.153.15:1992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/conf.php"] [unique_id "aoSAAvcmepr5_nHgLbMuewAAAmk"]
[Tue Aug 18 12:53:38.070169 2026] [security2:error] [pid 67073:tid 67089] [remote 34.83.187.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.187.83.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.atekrefrigeracao.com.br"] [uri "/.env.php.bak"] [unique_id "aoSAAvcmepr5_nHgLbMufgACIg0"]
[Tue Aug 18 12:53:38.071377 2026] [security2:error] [pid 67073:tid 67195] [remote 34.83.187.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.187.83.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.atekrefrigeracao.com.br"] [uri "/config/.env.php"] [unique_id "aoSAAvcmepr5_nHgLbMufQACInc"]
[Tue Aug 18 12:53:38.083651 2026] [security2:error] [pid 67073:tid 67295] [client 20.186.30.159:14227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/coffee.php"] [unique_id "aoSAAvcmepr5_nHgLbMugQAAAm4"]
[Tue Aug 18 12:53:38.155979 2026] [security2:error] [pid 67073:tid 67092] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/c4.php"] [unique_id "aoSAAvcmepr5_nHgLbMuhgACSRA"]
[Tue Aug 18 12:53:38.161460 2026] [security2:error] [pid 67073:tid 67259] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSAAvcmepr5_nHgLbMuhwAAAko"]
[Tue Aug 18 12:53:38.199358 2026] [security2:error] [pid 67073:tid 67291] [client 20.163.43.14:3196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAAvcmepr5_nHgLbMujQAAAmo"]
[Tue Aug 18 12:53:38.203439 2026] [security2:error] [pid 67073:tid 67226] [client 4.223.164.152:64664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAAvcmepr5_nHgLbMujwAAAik"]
[Tue Aug 18 12:53:38.206488 2026] [security2:error] [pid 67073:tid 67213] [client 52.173.121.69:53016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSAAvcmepr5_nHgLbMukAAAAhw"]
[Tue Aug 18 12:53:38.221181 2026] [security2:error] [pid 67073:tid 67234] [client 5.253.205.188:46740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/files.bak"] [unique_id "aoSAAvcmepr5_nHgLbMukQAAAjE"], referer: https://medihub.com.br/files.bak
[Tue Aug 18 12:53:38.273182 2026] [security2:error] [pid 67073:tid 67211] [client 74.248.136.165:19256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/100.kb.php"] [unique_id "aoSAAvcmepr5_nHgLbMukgAAAho"]
[Tue Aug 18 12:53:38.280611 2026] [security2:error] [pid 67073:tid 67292] [client 104.209.144.33:24859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSAAvcmepr5_nHgLbMukwAAAms"]
[Tue Aug 18 12:53:38.302936 2026] [security2:error] [pid 67073:tid 67303] [client 20.171.51.14:43366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ee.php"] [unique_id "aoSAAvcmepr5_nHgLbMulQAAAnY"]
[Tue Aug 18 12:53:38.305125 2026] [security2:error] [pid 66623:tid 66841] [client 135.225.75.187:49108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/grsiuk.php"] [unique_id "aoSAAtO5rbWdOArH04J73AAAAVU"]
[Tue Aug 18 12:53:38.325637 2026] [security2:error] [pid 67073:tid 67320] [client 20.186.30.159:14242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/classwithtostring.php"] [unique_id "aoSAAvcmepr5_nHgLbMulgAAAoc"]
[Tue Aug 18 12:53:38.335716 2026] [security2:error] [pid 67073:tid 67217] [client 20.226.56.190:10607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/xn.php"] [unique_id "aoSAAvcmepr5_nHgLbMulwAAAiA"]
[Tue Aug 18 12:53:38.335894 2026] [security2:error] [pid 67073:tid 67324] [client 20.51.153.15:13348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/bala.php"] [unique_id "aoSAAvcmepr5_nHgLbMumAAAAos"]
[Tue Aug 18 12:53:38.361319 2026] [security2:error] [pid 66623:tid 66775] [client 172.202.39.151:44390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAAtO5rbWdOArH04J73QAAARM"]
[Tue Aug 18 12:53:38.370830 2026] [security2:error] [pid 67073:tid 67318] [client 20.65.98.162:16631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAAvcmepr5_nHgLbMumQAAAoU"]
[Tue Aug 18 12:53:38.372091 2026] [security2:error] [pid 67073:tid 67220] [client 20.119.58.187:14428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/cgi-bin/php8.php"] [unique_id "aoSAAvcmepr5_nHgLbMumgAAAiM"]
[Tue Aug 18 12:53:38.374803 2026] [security2:error] [pid 67073:tid 67254] [client 20.104.100.201:17307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSAAvcmepr5_nHgLbMumwAAAkU"]
[Tue Aug 18 12:53:38.375738 2026] [security2:error] [pid 67073:tid 67236] [client 52.139.47.57:7588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/www.php"] [unique_id "aoSAAvcmepr5_nHgLbMunAAAAjM"]
[Tue Aug 18 12:53:38.387926 2026] [security2:error] [pid 67073:tid 67086] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/an7.php"] [unique_id "aoSAAvcmepr5_nHgLbMunQACLAo"]
[Tue Aug 18 12:53:38.393380 2026] [security2:error] [pid 66623:tid 66857] [client 20.100.169.31:12667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/zup.php73"] [unique_id "aoSAAtO5rbWdOArH04J73gAAAWU"]
[Tue Aug 18 12:53:38.398488 2026] [security2:error] [pid 67073:tid 67167] [remote 34.83.187.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.187.83.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.atekrefrigeracao.com.br"] [uri "/config.php.bak"] [unique_id "aoSAAvcmepr5_nHgLbMunwACXFs"]
[Tue Aug 18 12:53:38.422308 2026] [security2:error] [pid 67073:tid 67253] [client 74.248.136.165:16832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/brc.php"] [unique_id "aoSAAvcmepr5_nHgLbMuoAAAAkQ"]
[Tue Aug 18 12:53:38.434761 2026] [security2:error] [pid 67073:tid 67322] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/sf.php"] [unique_id "aoSAAvcmepr5_nHgLbMuoQAAAok"]
[Tue Aug 18 12:53:38.439342 2026] [security2:error] [pid 67073:tid 67316] [client 20.226.56.190:2512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAAvcmepr5_nHgLbMuogAAAoM"]
[Tue Aug 18 12:53:38.466223 2026] [security2:error] [pid 67073:tid 67267] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSAAvcmepr5_nHgLbMuowAAAlI"]
[Tue Aug 18 12:53:38.478211 2026] [security2:error] [pid 67073:tid 67212] [client 20.226.56.190:8263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/47.php"] [unique_id "aoSAAvcmepr5_nHgLbMupgAAAhs"]
[Tue Aug 18 12:53:38.490731 2026] [security2:error] [pid 67073:tid 67240] [client 52.238.210.254:10185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/term.php"] [unique_id "aoSAAvcmepr5_nHgLbMupwAAAjc"]
[Tue Aug 18 12:53:38.501378 2026] [security2:error] [pid 67073:tid 67091] [remote 34.83.187.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.187.83.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.atekrefrigeracao.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSAAvcmepr5_nHgLbMuqAACNA8"]
[Tue Aug 18 12:53:38.505108 2026] [security2:error] [pid 67073:tid 67280] [client 132.196.61.152:55349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/coffee.php"] [unique_id "aoSAAvcmepr5_nHgLbMuqgAAAl8"]
[Tue Aug 18 12:53:38.506843 2026] [security2:error] [pid 67073:tid 67314] [client 213.35.127.232:53823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAAvcmepr5_nHgLbMuqwAAAoE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:38.519655 2026] [security2:error] [pid 66623:tid 66824] [client 40.85.222.29:18550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSAAtO5rbWdOArH04J73wAAAUQ"]
[Tue Aug 18 12:53:38.526390 2026] [security2:error] [pid 67073:tid 67285] [client 20.163.43.14:3099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAAvcmepr5_nHgLbMurQAAAmQ"]
[Tue Aug 18 12:53:38.551390 2026] [security2:error] [pid 67073:tid 67224] [client 20.91.215.254:9098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSAAvcmepr5_nHgLbMurgAAAic"]
[Tue Aug 18 12:53:38.563506 2026] [security2:error] [pid 66623:tid 66832] [client 104.209.144.33:15681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSAAtO5rbWdOArH04J74AAAAUw"]
[Tue Aug 18 12:53:38.573596 2026] [security2:error] [pid 67073:tid 67325] [client 20.186.30.159:14301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/wp-ws68.php"] [unique_id "aoSAAvcmepr5_nHgLbMusAAAAow"]
[Tue Aug 18 12:53:38.587405 2026] [security2:error] [pid 67073:tid 67326] [client 20.51.153.15:13391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/222.php"] [unique_id "aoSAAvcmepr5_nHgLbMusgAAAo0"]
[Tue Aug 18 12:53:38.599233 2026] [security2:error] [pid 67073:tid 67176] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/bsg-management/php.php"] [unique_id "aoSAAvcmepr5_nHgLbMuswACKGQ"]
[Tue Aug 18 12:53:38.605158 2026] [security2:error] [pid 66623:tid 66819] [client 20.48.236.86:10807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/btx25.php"] [unique_id "aoSAAtO5rbWdOArH04J74QAAAT8"]
[Tue Aug 18 12:53:38.621982 2026] [security2:error] [pid 67073:tid 67289] [client 172.202.39.151:34770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAAvcmepr5_nHgLbMutAAAAmg"]
[Tue Aug 18 12:53:38.630501 2026] [security2:error] [pid 67073:tid 67305] [client 4.223.164.152:37303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSAAvcmepr5_nHgLbMutQAAAng"]
[Tue Aug 18 12:53:38.695078 2026] [security2:error] [pid 67073:tid 67308] [client 74.248.136.165:49533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/mamzi.php"] [unique_id "aoSAAvcmepr5_nHgLbMuuAAAAns"]
[Tue Aug 18 12:53:38.726047 2026] [security2:error] [pid 67073:tid 67207] [client 20.119.58.187:15153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/gallery/php8.php"] [unique_id "aoSAAvcmepr5_nHgLbMuuQAAAhY"]
[Tue Aug 18 12:53:38.727842 2026] [security2:error] [pid 67073:tid 67238] [client 74.248.18.37:14656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wap.php"] [unique_id "aoSAAvcmepr5_nHgLbMuugAAAjU"]
[Tue Aug 18 12:53:38.777091 2026] [security2:error] [pid 67073:tid 67309] [client 20.171.51.14:29227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ak.php"] [unique_id "aoSAAvcmepr5_nHgLbMuwAAAAnw"]
[Tue Aug 18 12:53:38.784928 2026] [security2:error] [pid 67073:tid 67104] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/byp8.php"] [unique_id "aoSAAvcmepr5_nHgLbMuwQACWxw"]
[Tue Aug 18 12:53:38.823221 2026] [authz_core:error] [pid 67073:tid 67306] [client 192.178.4.133:35836] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:38.823499 2026] [authz_core:error] [pid 67073:tid 67306] [client 192.178.4.133:35836] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:38.825999 2026] [security2:error] [pid 67073:tid 67260] [client 20.186.30.159:14225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/yj09.php"] [unique_id "aoSAAvcmepr5_nHgLbMuwwAAAks"]
[Tue Aug 18 12:53:38.860340 2026] [security2:error] [pid 66623:tid 66871] [client 52.173.121.69:54459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSAAtO5rbWdOArH04J74gAAAXM"]
[Tue Aug 18 12:53:38.887741 2026] [security2:error] [pid 66623:tid 66858] [client 4.223.164.152:6879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/403dd.php"] [unique_id "aoSAAtO5rbWdOArH04J74wAAAWY"]
[Tue Aug 18 12:53:38.908281 2026] [security2:error] [pid 67073:tid 67228] [client 20.51.153.15:13399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/routes.php"] [unique_id "aoSAAvcmepr5_nHgLbMuyAAAAis"]
[Tue Aug 18 12:53:38.938686 2026] [security2:error] [pid 67073:tid 67235] [client 172.202.39.151:44457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAAvcmepr5_nHgLbMuywAAAjI"]
[Tue Aug 18 12:53:38.947930 2026] [security2:error] [pid 67073:tid 67279] [client 20.104.100.201:53880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/srontol.php"] [unique_id "aoSAAvcmepr5_nHgLbMuzAAAAl4"]
[Tue Aug 18 12:53:38.988537 2026] [security2:error] [pid 67073:tid 67108] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/plugins.php"] [unique_id "aoSAAvcmepr5_nHgLbMuzgACJCA"]
[Tue Aug 18 12:53:39.010797 2026] [security2:error] [pid 66623:tid 66872] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSAA9O5rbWdOArH04J75AAAAXQ"]
[Tue Aug 18 12:53:39.059182 2026] [security2:error] [pid 67073:tid 67257] [client 104.209.144.33:15709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSAA_cmepr5_nHgLbMu0gAAAkg"]
[Tue Aug 18 12:53:39.060101 2026] [security2:error] [pid 66623:tid 66804] [client 4.223.164.152:46194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSAA9O5rbWdOArH04J75QAAATA"]
[Tue Aug 18 12:53:39.066849 2026] [security2:error] [pid 67073:tid 67323] [client 20.186.30.159:14226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/scxy.php"] [unique_id "aoSAA_cmepr5_nHgLbMu0wAAAoo"]
[Tue Aug 18 12:53:39.072995 2026] [security2:error] [pid 67073:tid 67311] [client 74.249.206.207:26491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/thoms.php"] [unique_id "aoSAA_cmepr5_nHgLbMu1AAAAn4"]
[Tue Aug 18 12:53:39.082910 2026] [security2:error] [pid 67073:tid 67226] [client 20.119.58.187:14648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/blocks/php8.php"] [unique_id "aoSAA_cmepr5_nHgLbMu1QAAAik"]
[Tue Aug 18 12:53:39.084758 2026] [security2:error] [pid 67073:tid 67320] [client 52.238.210.254:10237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/7.php"] [unique_id "aoSAA_cmepr5_nHgLbMu1gAAAoc"]
[Tue Aug 18 12:53:39.101697 2026] [security2:error] [pid 67073:tid 67232] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/k.php"] [unique_id "aoSAA_cmepr5_nHgLbMu2AAAAi8"]
[Tue Aug 18 12:53:39.103465 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:39.103747 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:39.106380 2026] [security2:error] [pid 67073:tid 67254] [client 20.226.56.190:23760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAA_cmepr5_nHgLbMu2QAAAkU"]
[Tue Aug 18 12:53:39.112444 2026] [security2:error] [pid 66623:tid 66814] [client 74.248.136.165:52053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ms.php"] [unique_id "aoSAA9O5rbWdOArH04J75gAAATo"]
[Tue Aug 18 12:53:39.170944 2026] [security2:error] [pid 67073:tid 67229] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-login.php"] [unique_id "aoSAA_cmepr5_nHgLbMu3AAAAiw"]
[Tue Aug 18 12:53:39.173187 2026] [security2:error] [pid 67073:tid 67110] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/100.kb.php"] [unique_id "aoSAA_cmepr5_nHgLbMu3QACXCI"]
[Tue Aug 18 12:53:39.179925 2026] [security2:error] [pid 67073:tid 67315] [client 149.34.210.141:58333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAA_cmepr5_nHgLbMu3gAAAoI"]
[Tue Aug 18 12:53:39.181972 2026] [security2:error] [pid 67073:tid 67215] [client 20.163.43.14:3095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSAA_cmepr5_nHgLbMu3wAAAh4"]
[Tue Aug 18 12:53:39.203510 2026] [security2:error] [pid 67073:tid 67243] [client 20.91.215.254:20214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/st.php"] [unique_id "aoSAA_cmepr5_nHgLbMu4AAAAjo"]
[Tue Aug 18 12:53:39.261399 2026] [security2:error] [pid 66623:tid 66860] [client 20.250.13.23:31436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/goods.php"] [unique_id "aoSAA9O5rbWdOArH04J75wAAAWg"]
[Tue Aug 18 12:53:39.279138 2026] [security2:error] [pid 67073:tid 67329] [client 20.51.153.15:13424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/php5.php"] [unique_id "aoSAA_cmepr5_nHgLbMu4wAAApA"]
[Tue Aug 18 12:53:39.310138 2026] [security2:error] [pid 67073:tid 67267] [client 158.23.17.4:11789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/mandrill.php"] [unique_id "aoSAA_cmepr5_nHgLbMu5AAAAlI"]
[Tue Aug 18 12:53:39.318372 2026] [security2:error] [pid 67073:tid 67261] [client 20.151.109.219:28762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/ct.php"] [unique_id "aoSAA_cmepr5_nHgLbMu5gAAAkw"]
[Tue Aug 18 12:53:39.319927 2026] [security2:error] [pid 67073:tid 67264] [client 20.171.51.14:15764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ia.php"] [unique_id "aoSAA_cmepr5_nHgLbMu6AAAAk8"]
[Tue Aug 18 12:53:39.331473 2026] [security2:error] [pid 67073:tid 67212] [client 20.186.30.159:14217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSAA_cmepr5_nHgLbMu6QAAAhs"]
[Tue Aug 18 12:53:39.341215 2026] [security2:error] [pid 67073:tid 67210] [client 20.171.51.14:16749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/test_info.php"] [unique_id "aoSAA_cmepr5_nHgLbMu6wAAAhk"]
[Tue Aug 18 12:53:39.390490 2026] [security2:error] [pid 67073:tid 67178] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/mamzi.php"] [unique_id "aoSAA_cmepr5_nHgLbMu7QACX2Y"]
[Tue Aug 18 12:53:39.392159 2026] [security2:error] [pid 67073:tid 67314] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSAA_cmepr5_nHgLbMu7gAAAoE"]
[Tue Aug 18 12:53:39.398168 2026] [security2:error] [pid 67073:tid 67266] [client 20.226.56.190:31653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/st.php"] [unique_id "aoSAA_cmepr5_nHgLbMu8AAAAlE"]
[Tue Aug 18 12:53:39.445793 2026] [security2:error] [pid 67073:tid 67315] [client 149.34.210.141:58333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAA_cmepr5_nHgLbMu3gAAAoI"]
[Tue Aug 18 12:53:39.460567 2026] [security2:error] [pid 66623:tid 66873] [client 20.91.215.254:16686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSAA9O5rbWdOArH04J76QAAAXU"]
[Tue Aug 18 12:53:39.466026 2026] [authz_core:error] [pid 67073:tid 67119] [remote 57.141.22.100:38094] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:39.466320 2026] [authz_core:error] [pid 67073:tid 67119] [remote 57.141.22.100:38094] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:39.482714 2026] [security2:error] [pid 66623:tid 66868] [client 172.202.39.151:44378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAA9O5rbWdOArH04J76gAAAXA"]
[Tue Aug 18 12:53:39.489328 2026] [security2:error] [pid 67073:tid 67270] [client 4.223.164.152:64641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSAA_cmepr5_nHgLbMu9wAAAlU"]
[Tue Aug 18 12:53:39.499457 2026] [security2:error] [pid 67073:tid 67252] [client 4.232.151.198:39365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/a.php"] [unique_id "aoSAA_cmepr5_nHgLbMu-AAAAkM"]
[Tue Aug 18 12:53:39.515897 2026] [security2:error] [pid 67073:tid 67326] [client 20.163.43.14:3160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/about.php"] [unique_id "aoSAA_cmepr5_nHgLbMu-gAAAo0"]
[Tue Aug 18 12:53:39.521501 2026] [security2:error] [pid 67073:tid 67218] [client 213.35.127.232:54040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAA_cmepr5_nHgLbMu-wAAAiE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:39.531377 2026] [security2:error] [pid 67073:tid 67302] [client 74.248.136.165:17242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/gfile.php"] [unique_id "aoSAA_cmepr5_nHgLbMu_AAAAnU"]
[Tue Aug 18 12:53:39.539932 2026] [security2:error] [pid 67073:tid 67273] [client 20.51.153.15:13416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/Black.php"] [unique_id "aoSAA_cmepr5_nHgLbMu_QAAAlg"]
[Tue Aug 18 12:53:39.564384 2026] [security2:error] [pid 66623:tid 66778] [client 4.223.164.152:6873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/baba.php"] [unique_id "aoSAA9O5rbWdOArH04J76wAAARY"]
[Tue Aug 18 12:53:39.565793 2026] [security2:error] [pid 67073:tid 67256] [client 40.85.222.29:37736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSAA_cmepr5_nHgLbMu_gAAAkc"]
[Tue Aug 18 12:53:39.572029 2026] [security2:error] [pid 67073:tid 67241] [client 20.186.30.159:14295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAA_cmepr5_nHgLbMu_wAAAjg"]
[Tue Aug 18 12:53:39.581262 2026] [security2:error] [pid 66623:tid 66790] [client 135.225.75.187:23127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/h.php"] [unique_id "aoSAA9O5rbWdOArH04J77AAAASI"]
[Tue Aug 18 12:53:39.586158 2026] [security2:error] [pid 66623:tid 66892] [client 52.238.210.254:10175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/file5.php"] [unique_id "aoSAA9O5rbWdOArH04J77QAAAYg"]
[Tue Aug 18 12:53:39.615808 2026] [security2:error] [pid 67073:tid 67244] [client 20.226.56.190:21143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/payout.php"] [unique_id "aoSAA_cmepr5_nHgLbMvAgAAAjs"]
[Tue Aug 18 12:53:39.664463 2026] [security2:error] [pid 67073:tid 67206] [client 20.226.6.191:6539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAA_cmepr5_nHgLbMvBAAAAhU"]
[Tue Aug 18 12:53:39.708236 2026] [security2:error] [pid 67073:tid 67249] [client 132.196.61.152:56074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAA_cmepr5_nHgLbMvBgAAAkA"]
[Tue Aug 18 12:53:39.739935 2026] [security2:error] [pid 66623:tid 66852] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSAA9O5rbWdOArH04J77wAAAWA"]
[Tue Aug 18 12:53:39.763422 2026] [security2:error] [pid 66623:tid 66861] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/82.php"] [unique_id "aoSAA9O5rbWdOArH04J78AAAAWk"]
[Tue Aug 18 12:53:39.834396 2026] [security2:error] [pid 67073:tid 67219] [client 20.186.30.159:14319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/blurbs.php"] [unique_id "aoSAA_cmepr5_nHgLbMvCgAAAiI"]
[Tue Aug 18 12:53:39.838972 2026] [security2:error] [pid 66623:tid 66781] [client 20.100.169.31:33794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSAA9O5rbWdOArH04J78QAAARk"]
[Tue Aug 18 12:53:39.840231 2026] [security2:error] [pid 67073:tid 67248] [client 20.171.51.14:43332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/kn.php"] [unique_id "aoSAA_cmepr5_nHgLbMvCwAAAj8"]
[Tue Aug 18 12:53:39.843801 2026] [security2:error] [pid 66623:tid 66825] [client 20.91.215.254:9116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSAA9O5rbWdOArH04J78gAAAUU"]
[Tue Aug 18 12:53:39.859825 2026] [security2:error] [pid 67073:tid 67295] [client 20.163.43.14:3098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSAA_cmepr5_nHgLbMvDAAAAm4"]
[Tue Aug 18 12:53:39.862108 2026] [security2:error] [pid 67073:tid 67330] [client 20.51.153.15:13371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/filesystems.php"] [unique_id "aoSAA_cmepr5_nHgLbMvDQAAApE"]
[Tue Aug 18 12:53:39.878303 2026] [security2:error] [pid 67073:tid 67310] [client 20.171.51.14:45409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/14.php"] [unique_id "aoSAA_cmepr5_nHgLbMvDgAAAn0"]
[Tue Aug 18 12:53:39.919740 2026] [security2:error] [pid 67073:tid 67319] [client 4.223.164.152:54236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/media.php"] [unique_id "aoSAA_cmepr5_nHgLbMvEAAAAoY"]
[Tue Aug 18 12:53:39.937872 2026] [security2:error] [pid 67073:tid 67235] [client 20.104.100.201:17398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/file5.php"] [unique_id "aoSAA_cmepr5_nHgLbMvEQAAAjI"]
[Tue Aug 18 12:53:39.957645 2026] [security2:error] [pid 67073:tid 67291] [client 74.248.136.165:61642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/public/wp-blog.php"] [unique_id "aoSAA_cmepr5_nHgLbMvEgAAAmo"]
[Tue Aug 18 12:53:39.959358 2026] [security2:error] [pid 67073:tid 67279] [client 172.202.39.151:61034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAA_cmepr5_nHgLbMvEwAAAl4"]
[Tue Aug 18 12:53:40.016555 2026] [security2:error] [pid 66623:tid 66799] [client 52.238.210.254:10204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/makeasmtp.php"] [unique_id "aoSABNO5rbWdOArH04J78wAAASs"]
[Tue Aug 18 12:53:40.085326 2026] [security2:error] [pid 67073:tid 67293] [client 20.186.30.159:14252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/bajah.php"] [unique_id "aoSABPcmepr5_nHgLbMvGgAAAmw"]
[Tue Aug 18 12:53:40.086785 2026] [security2:error] [pid 66623:tid 66791] [client 74.249.206.207:13334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/wpxml.php"] [unique_id "aoSABNO5rbWdOArH04J79AAAASM"]
[Tue Aug 18 12:53:40.146442 2026] [security2:error] [pid 67073:tid 67226] [client 20.226.56.190:23753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/le.php"] [unique_id "aoSABPcmepr5_nHgLbMvHAAAAik"]
[Tue Aug 18 12:53:40.148369 2026] [security2:error] [pid 66623:tid 66870] [client 20.91.215.254:20225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/past1.php"] [unique_id "aoSABNO5rbWdOArH04J79QAAAXI"]
[Tue Aug 18 12:53:40.165254 2026] [security2:error] [pid 66623:tid 66803] [client 20.226.56.190:41958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/bh.php"] [unique_id "aoSABNO5rbWdOArH04J79gAAAS8"]
[Tue Aug 18 12:53:40.180058 2026] [security2:error] [pid 67073:tid 67269] [client 20.51.153.15:2022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/showphpinfo.php"] [unique_id "aoSABPcmepr5_nHgLbMvHwAAAlQ"]
[Tue Aug 18 12:53:40.206949 2026] [security2:error] [pid 67073:tid 67290] [client 20.250.13.23:53033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/file.php"] [unique_id "aoSABPcmepr5_nHgLbMvIAAAAmk"]
[Tue Aug 18 12:53:40.231800 2026] [security2:error] [pid 67073:tid 67236] [client 20.163.43.14:3140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/f35.php"] [unique_id "aoSABPcmepr5_nHgLbMvIQAAAjM"]
[Tue Aug 18 12:53:40.235374 2026] [security2:error] [pid 66623:tid 66821] [client 172.202.39.151:44382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/rip.php"] [unique_id "aoSABNO5rbWdOArH04J79wAAAUE"]
[Tue Aug 18 12:53:40.249033 2026] [security2:error] [pid 67073:tid 67286] [client 20.42.19.40:2720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/akc.php"] [unique_id "aoSABPcmepr5_nHgLbMvIgAAAmU"]
[Tue Aug 18 12:53:40.261312 2026] [security2:error] [pid 67073:tid 67277] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSABPcmepr5_nHgLbMvJAAAAlw"]
[Tue Aug 18 12:53:40.303568 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:40.303839 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:40.324631 2026] [security2:error] [pid 67073:tid 67300] [client 20.171.51.14:51807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/tk.php"] [unique_id "aoSABPcmepr5_nHgLbMvJgAAAnM"]
[Tue Aug 18 12:53:40.326652 2026] [security2:error] [pid 67073:tid 67243] [client 20.186.30.159:14318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/domvf.php"] [unique_id "aoSABPcmepr5_nHgLbMvJwAAAjo"]
[Tue Aug 18 12:53:40.342157 2026] [security2:error] [pid 67073:tid 67209] [client 20.226.56.190:8264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/ct.php"] [unique_id "aoSABPcmepr5_nHgLbMvKAAAAhg"]
[Tue Aug 18 12:53:40.375311 2026] [security2:error] [pid 66623:tid 66846] [client 74.248.136.165:19208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/cu.php"] [unique_id "aoSABNO5rbWdOArH04J7-QAAAVo"]
[Tue Aug 18 12:53:40.386393 2026] [security2:error] [pid 66623:tid 66812] [client 4.223.164.152:46197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/inso.php"] [unique_id "aoSABNO5rbWdOArH04J7-gAAATg"]
[Tue Aug 18 12:53:40.400480 2026] [security2:error] [pid 67073:tid 67264] [client 74.248.136.165:51195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/file52.php"] [unique_id "aoSABPcmepr5_nHgLbMvLgAAAk8"]
[Tue Aug 18 12:53:40.417882 2026] [security2:error] [pid 66623:tid 66849] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/dex.php"] [unique_id "aoSABNO5rbWdOArH04J7-wAAAV0"]
[Tue Aug 18 12:53:40.429091 2026] [security2:error] [pid 67073:tid 67263] [client 160.120.140.123:52776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSABPcmepr5_nHgLbMvLwAAAk4"]
[Tue Aug 18 12:53:40.429205 2026] [security2:error] [pid 67073:tid 67263] [client 160.120.140.123:52776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSABPcmepr5_nHgLbMvLwAAAk4"]
[Tue Aug 18 12:53:40.435126 2026] [security2:error] [pid 66623:tid 66878] [client 52.173.121.69:45396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSABNO5rbWdOArH04J7_AAAAXo"]
[Tue Aug 18 12:53:40.437399 2026] [security2:error] [pid 66623:tid 66856] [client 178.153.171.161:11196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSABNO5rbWdOArH04J7_QAAAWQ"]
[Tue Aug 18 12:53:40.437476 2026] [security2:error] [pid 66623:tid 66856] [client 178.153.171.161:11196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSABNO5rbWdOArH04J7_QAAAWQ"]
[Tue Aug 18 12:53:40.478161 2026] [security2:error] [pid 66623:tid 66794] [client 20.91.215.254:9136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp-configs.php"] [unique_id "aoSABNO5rbWdOArH04J7_gAAASY"]
[Tue Aug 18 12:53:40.483961 2026] [security2:error] [pid 67073:tid 67321] [client 20.171.51.14:58836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/wm.php"] [unique_id "aoSABPcmepr5_nHgLbMvMQAAAog"]
[Tue Aug 18 12:53:40.485231 2026] [security2:error] [pid 66623:tid 66882] [client 20.226.6.191:6536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSABNO5rbWdOArH04J7_wAAAX4"]
[Tue Aug 18 12:53:40.507744 2026] [security2:error] [pid 66623:tid 66780] [client 20.51.153.15:13313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/phpstatus.php"] [unique_id "aoSABNO5rbWdOArH04J8AAAAARg"]
[Tue Aug 18 12:53:40.523189 2026] [security2:error] [pid 67073:tid 67238] [client 157.51.166.53:5504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSABPcmepr5_nHgLbMvMwAAAjU"]
[Tue Aug 18 12:53:40.523328 2026] [security2:error] [pid 67073:tid 67238] [client 157.51.166.53:5504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSABPcmepr5_nHgLbMvMwAAAjU"]
[Tue Aug 18 12:53:40.529666 2026] [security2:error] [pid 67073:tid 67307] [client 52.139.47.57:3422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/x.php"] [unique_id "aoSABPcmepr5_nHgLbMvNAAAAno"]
[Tue Aug 18 12:53:40.532674 2026] [security2:error] [pid 67073:tid 67281] [client 158.23.17.4:55179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/main.php"] [unique_id "aoSABPcmepr5_nHgLbMvNQAAAmA"]
[Tue Aug 18 12:53:40.532700 2026] [security2:error] [pid 66623:tid 66807] [client 213.35.127.232:54258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSABNO5rbWdOArH04J8AgAAATM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:40.567468 2026] [security2:error] [pid 67073:tid 67285] [client 20.186.30.159:14232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/fpwch.php"] [unique_id "aoSABPcmepr5_nHgLbMvNwAAAmQ"]
[Tue Aug 18 12:53:40.587256 2026] [security2:error] [pid 67073:tid 67224] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSABPcmepr5_nHgLbMvOQAAAic"]
[Tue Aug 18 12:53:40.629284 2026] [security2:error] [pid 66623:tid 66797] [client 132.196.61.152:27270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSABNO5rbWdOArH04J8AwAAASk"]
[Tue Aug 18 12:53:40.642854 2026] [security2:error] [pid 66623:tid 66839] [client 104.209.144.33:25280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSABNO5rbWdOArH04J8BAAAAVM"]
[Tue Aug 18 12:53:40.680467 2026] [security2:error] [pid 67073:tid 67270] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/default.php"] [unique_id "aoSABPcmepr5_nHgLbMvPQAAAlU"]
[Tue Aug 18 12:53:40.696300 2026] [security2:error] [pid 66623:tid 66785] [client 4.223.164.152:6623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/site.php"] [unique_id "aoSABNO5rbWdOArH04J8BQAAAR0"]
[Tue Aug 18 12:53:40.699751 2026] [security2:error] [pid 67073:tid 67205] [client 74.248.18.37:38925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSABPcmepr5_nHgLbMvPgAAAhQ"]
[Tue Aug 18 12:53:40.710840 2026] [security2:error] [pid 67073:tid 67326] [client 20.48.236.86:10425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/SDsadqwrf.php"] [unique_id "aoSABPcmepr5_nHgLbMvPwAAAo0"]
[Tue Aug 18 12:53:40.713700 2026] [security2:error] [pid 67073:tid 67267] [client 143.244.161.13:63737] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "stampi.ind.br"] [uri "/"] [unique_id "aoSABPcmepr5_nHgLbMvQAAAAlI"]
[Tue Aug 18 12:53:40.719449 2026] [security2:error] [pid 66623:tid 66795] [client 135.225.75.187:23155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/koiy.php"] [unique_id "aoSABNO5rbWdOArH04J8BgAAASc"]
[Tue Aug 18 12:53:40.738846 2026] [security2:error] [pid 67073:tid 67305] [client 20.163.43.14:3170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/inputs.php"] [unique_id "aoSABPcmepr5_nHgLbMvQQAAAng"]
[Tue Aug 18 12:53:40.752882 2026] [security2:error] [pid 67073:tid 67256] [client 74.249.206.207:51228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/file1221.php"] [unique_id "aoSABPcmepr5_nHgLbMvRAAAAkc"]
[Tue Aug 18 12:53:40.755594 2026] [security2:error] [pid 67073:tid 67244] [client 20.226.56.190:21162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/gy.php"] [unique_id "aoSABPcmepr5_nHgLbMvRQAAAjs"]
[Tue Aug 18 12:53:40.764916 2026] [security2:error] [pid 67073:tid 67268] [client 20.100.169.31:28383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSABPcmepr5_nHgLbMvRgAAAlM"]
[Tue Aug 18 12:53:40.766017 2026] [security2:error] [pid 67073:tid 67228] [client 213.202.253.4:57951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "affaripericiacontabil.com.br"] [uri "/schallfuns.php"] [unique_id "aoSABPcmepr5_nHgLbMvRwAAAis"], referer: www.google.com
[Tue Aug 18 12:53:40.787229 2026] [security2:error] [pid 66623:tid 66813] [client 4.232.151.198:36220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/chosen.php"] [unique_id "aoSABNO5rbWdOArH04J8BwAAATk"]
[Tue Aug 18 12:53:40.792112 2026] [security2:error] [pid 67073:tid 67247] [client 74.248.136.165:19259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/X57.php"] [unique_id "aoSABPcmepr5_nHgLbMvSQAAAj4"]
[Tue Aug 18 12:53:40.824040 2026] [security2:error] [pid 67073:tid 67308] [client 4.223.164.152:64671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/shiny.php"] [unique_id "aoSABPcmepr5_nHgLbMvSgAAAns"]
[Tue Aug 18 12:53:40.827494 2026] [security2:error] [pid 67073:tid 67239] [client 20.51.153.15:13400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/del.php"] [unique_id "aoSABPcmepr5_nHgLbMvSwAAAjY"]
[Tue Aug 18 12:53:40.840217 2026] [security2:error] [pid 67073:tid 67245] [client 20.171.51.14:58821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/hp.php"] [unique_id "aoSABPcmepr5_nHgLbMvTQAAAjw"]
[Tue Aug 18 12:53:40.858085 2026] [security2:error] [pid 67073:tid 67309] [client 52.238.210.254:57873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/wp.php"] [unique_id "aoSABPcmepr5_nHgLbMvTgAAAnw"]
[Tue Aug 18 12:53:40.872767 2026] [security2:error] [pid 67073:tid 67276] [client 20.186.30.159:14280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/adminner.php"] [unique_id "aoSABPcmepr5_nHgLbMvUAAAAls"]
[Tue Aug 18 12:53:40.886077 2026] [security2:error] [pid 66623:tid 66828] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSABNO5rbWdOArH04J8CAAAAUg"]
[Tue Aug 18 12:53:40.910418 2026] [security2:error] [pid 67073:tid 67310] [client 20.151.109.219:40450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/gy.php"] [unique_id "aoSABPcmepr5_nHgLbMvUgAAAn0"]
[Tue Aug 18 12:53:40.911196 2026] [autoindex:error] [pid 67073:tid 67301] [client 172.202.39.151:33107] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:40.920980 2026] [security2:error] [pid 67073:tid 67259] [client 20.226.56.190:52049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/hr.php"] [unique_id "aoSABPcmepr5_nHgLbMvUwAAAko"]
[Tue Aug 18 12:53:40.958820 2026] [security2:error] [pid 67073:tid 67291] [client 20.171.51.14:33687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ac.php"] [unique_id "aoSABPcmepr5_nHgLbMvWQAAAmo"]
[Tue Aug 18 12:53:41.042594 2026] [security2:error] [pid 67073:tid 67147] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ms.php"] [unique_id "aoSABfcmepr5_nHgLbMvXAACH0c"]
[Tue Aug 18 12:53:41.083076 2026] [security2:error] [pid 67073:tid 67320] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/puc.php"] [unique_id "aoSABfcmepr5_nHgLbMvYAAAAoc"]
[Tue Aug 18 12:53:41.117197 2026] [security2:error] [pid 67073:tid 67318] [client 20.186.30.159:7274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/abcd.php"] [unique_id "aoSABfcmepr5_nHgLbMvYQAAAoU"]
[Tue Aug 18 12:53:41.117573 2026] [security2:error] [pid 67073:tid 67330] [client 20.91.215.254:9102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp-post.php"] [unique_id "aoSABfcmepr5_nHgLbMvYgAAApE"]
[Tue Aug 18 12:53:41.123085 2026] [security2:error] [pid 67073:tid 67290] [client 20.226.56.190:28250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kt.php"] [unique_id "aoSABfcmepr5_nHgLbMvZQAAAmk"]
[Tue Aug 18 12:53:41.131472 2026] [security2:error] [pid 67073:tid 67236] [client 20.226.6.191:6649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/admin.php"] [unique_id "aoSABfcmepr5_nHgLbMvZgAAAjM"]
[Tue Aug 18 12:53:41.181385 2026] [security2:error] [pid 66623:tid 66793] [client 20.104.100.201:17292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/yup.php"] [unique_id "aoSABdO5rbWdOArH04J8CQAAASU"]
[Tue Aug 18 12:53:41.182518 2026] [security2:error] [pid 67073:tid 67250] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSABfcmepr5_nHgLbMvaAAAAkE"]
[Tue Aug 18 12:53:41.191770 2026] [security2:error] [pid 67073:tid 67253] [client 20.226.56.190:40169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/tt.php"] [unique_id "aoSABfcmepr5_nHgLbMvagAAAkQ"]
[Tue Aug 18 12:53:41.206813 2026] [security2:error] [pid 67073:tid 67233] [client 192.141.172.134:51701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSABfcmepr5_nHgLbMvbQAAAjA"]
[Tue Aug 18 12:53:41.206925 2026] [security2:error] [pid 67073:tid 67233] [client 192.141.172.134:51701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSABfcmepr5_nHgLbMvbQAAAjA"]
[Tue Aug 18 12:53:41.210313 2026] [security2:error] [pid 66623:tid 66808] [client 74.248.136.165:58352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/forbidals.php"] [unique_id "aoSABdO5rbWdOArH04J8CgAAATQ"]
[Tue Aug 18 12:53:41.214600 2026] [security2:error] [pid 67073:tid 67243] [client 52.238.210.254:10211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/index.php"] [unique_id "aoSABfcmepr5_nHgLbMvbwAAAjo"]
[Tue Aug 18 12:53:41.219169 2026] [security2:error] [pid 67073:tid 67272] [client 172.202.39.151:33107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSABfcmepr5_nHgLbMvcQAAAlc"]
[Tue Aug 18 12:53:41.221494 2026] [security2:error] [pid 67073:tid 67328] [client 20.51.153.15:13429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/moderator.php"] [unique_id "aoSABfcmepr5_nHgLbMvcgAAAo8"]
[Tue Aug 18 12:53:41.229889 2026] [security2:error] [pid 67073:tid 67185] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/gfile.php"] [unique_id "aoSABfcmepr5_nHgLbMvdAACPW0"]
[Tue Aug 18 12:53:41.245203 2026] [security2:error] [pid 67073:tid 67261] [client 158.23.17.4:58710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/ga.php"] [unique_id "aoSABfcmepr5_nHgLbMvdgAAAkw"]
[Tue Aug 18 12:53:41.261008 2026] [security2:error] [pid 67073:tid 67210] [client 74.249.206.207:63291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/nox.php"] [unique_id "aoSABfcmepr5_nHgLbMvdwAAAhk"]
[Tue Aug 18 12:53:41.276905 2026] [security2:error] [pid 67073:tid 67263] [client 4.223.164.152:37307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/403dd.php"] [unique_id "aoSABfcmepr5_nHgLbMveAAAAk4"]
[Tue Aug 18 12:53:41.281757 2026] [security2:error] [pid 67073:tid 67323] [client 20.171.51.14:58847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wx.php"] [unique_id "aoSABfcmepr5_nHgLbMveQAAAoo"]
[Tue Aug 18 12:53:41.403361 2026] [security2:error] [pid 67073:tid 67285] [client 20.163.43.14:3133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/alfa.php"] [unique_id "aoSABfcmepr5_nHgLbMvfAAAAmQ"]
[Tue Aug 18 12:53:41.451083 2026] [security2:error] [pid 67073:tid 67304] [client 20.91.215.254:16658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/file61.php"] [unique_id "aoSABfcmepr5_nHgLbMvfQAAAnc"]
[Tue Aug 18 12:53:41.470281 2026] [security2:error] [pid 67073:tid 67230] [client 132.196.61.152:55345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/mgrr.php"] [unique_id "aoSABfcmepr5_nHgLbMvfgAAAi0"]
[Tue Aug 18 12:53:41.484083 2026] [security2:error] [pid 67073:tid 67294] [client 172.202.39.151:44431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSABfcmepr5_nHgLbMvfwAAAm0"]
[Tue Aug 18 12:53:41.507265 2026] [security2:error] [pid 67073:tid 67252] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSABfcmepr5_nHgLbMvgQAAAkM"]
[Tue Aug 18 12:53:41.511554 2026] [security2:error] [pid 67073:tid 67225] [client 20.65.98.162:23922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSABfcmepr5_nHgLbMvggAAAig"]
[Tue Aug 18 12:53:41.512448 2026] [security2:error] [pid 67073:tid 67205] [client 20.171.51.14:16735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/yz.php"] [unique_id "aoSABfcmepr5_nHgLbMvgwAAAhQ"]
[Tue Aug 18 12:53:41.546583 2026] [security2:error] [pid 67073:tid 67300] [client 213.35.127.232:54464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSABfcmepr5_nHgLbMvhAAAAnM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:41.563232 2026] [security2:error] [pid 67073:tid 67284] [client 20.51.153.15:1985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/infoinfo.php"] [unique_id "aoSABfcmepr5_nHgLbMvhgAAAmM"]
[Tue Aug 18 12:53:41.626316 2026] [security2:error] [pid 67073:tid 67244] [client 74.248.136.165:40837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/edit.php"] [unique_id "aoSABfcmepr5_nHgLbMviAAAAjs"]
[Tue Aug 18 12:53:41.662832 2026] [security2:error] [pid 67073:tid 67247] [client 20.171.51.14:14982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/dj.php"] [unique_id "aoSABfcmepr5_nHgLbMviQAAAj4"]
[Tue Aug 18 12:53:41.713424 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:41.713697 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:41.719748 2026] [security2:error] [pid 67073:tid 67207] [client 52.173.121.69:54468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSABfcmepr5_nHgLbMvjAAAAhY"]
[Tue Aug 18 12:53:41.732131 2026] [security2:error] [pid 67073:tid 67309] [client 20.163.43.14:3097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/lock360.php"] [unique_id "aoSABfcmepr5_nHgLbMvjQAAAnw"]
[Tue Aug 18 12:53:41.746166 2026] [security2:error] [pid 67073:tid 67267] [client 20.91.215.254:20193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSABfcmepr5_nHgLbMvjgAAAlI"]
[Tue Aug 18 12:53:41.748259 2026] [security2:error] [pid 67073:tid 67276] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/inso.php"] [unique_id "aoSABfcmepr5_nHgLbMvjwAAAls"]
[Tue Aug 18 12:53:41.764638 2026] [security2:error] [pid 66623:tid 66838] [client 20.226.56.190:28245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ww.php"] [unique_id "aoSABdO5rbWdOArH04J8DAAAAVI"]
[Tue Aug 18 12:53:41.772429 2026] [security2:error] [pid 66623:tid 66867] [client 4.223.164.152:54217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/baba.php"] [unique_id "aoSABdO5rbWdOArH04J8DQAAAW8"]
[Tue Aug 18 12:53:41.773376 2026] [security2:error] [pid 67073:tid 67260] [client 4.223.164.152:7074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSABfcmepr5_nHgLbMvkgAAAks"]
[Tue Aug 18 12:53:41.797281 2026] [security2:error] [pid 67073:tid 67242] [client 47.128.22.219:57886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gabrielabrandao.adv.br"] [uri "/robots.txt"] [unique_id "aoSABfcmepr5_nHgLbMvkwAAAjk"]
[Tue Aug 18 12:53:41.802051 2026] [security2:error] [pid 67073:tid 67295] [client 20.51.153.15:13326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/c99shell.php"] [unique_id "aoSABfcmepr5_nHgLbMvlAAAAm4"]
[Tue Aug 18 12:53:41.818166 2026] [security2:error] [pid 67073:tid 67220] [client 5.253.205.188:46794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/files.sql"] [unique_id "aoSABfcmepr5_nHgLbMvlQAAAiM"], referer: https://medihub.com.br/files.sql
[Tue Aug 18 12:53:41.820186 2026] [security2:error] [pid 67073:tid 67324] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSABfcmepr5_nHgLbMvlgAAAos"]
[Tue Aug 18 12:53:41.840644 2026] [security2:error] [pid 67073:tid 67301] [client 104.209.144.33:25319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSABfcmepr5_nHgLbMvmAAAAnQ"]
[Tue Aug 18 12:53:41.886080 2026] [security2:error] [pid 67073:tid 67219] [client 54.87.112.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bn2s.com.br"] [uri "/index.php"] [unique_id "aoSABfcmepr5_nHgLbMvkAAAAiI"], referer: https://bn2s.com.br/
[Tue Aug 18 12:53:41.927688 2026] [security2:error] [pid 67073:tid 67234] [client 20.48.236.86:10761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSABfcmepr5_nHgLbMvnAAAAjE"]
[Tue Aug 18 12:53:41.977317 2026] [security2:error] [pid 67073:tid 67275] [client 132.196.61.152:55338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/55.php"] [unique_id "aoSABfcmepr5_nHgLbMvngAAAlo"]
[Tue Aug 18 12:53:41.990480 2026] [security2:error] [pid 67073:tid 67292] [client 20.171.51.14:33679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/kj.php"] [unique_id "aoSABfcmepr5_nHgLbMvnwAAAms"]
[Tue Aug 18 12:53:42.001962 2026] [security2:error] [pid 67073:tid 67186] [remote 34.26.95.176:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "atekrefrigeracao.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aoSABvcmepr5_nHgLbMvoAACRm4"]
[Tue Aug 18 12:53:42.009975 2026] [security2:error] [pid 66623:tid 66857] [client 135.225.75.187:20805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/fff.php"] [unique_id "aoSABtO5rbWdOArH04J8DgAAAWU"]
[Tue Aug 18 12:53:42.025764 2026] [security2:error] [pid 67073:tid 67303] [client 158.23.17.4:15124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/wb.php"] [unique_id "aoSABvcmepr5_nHgLbMvoQAAAnY"]
[Tue Aug 18 12:53:42.035849 2026] [security2:error] [pid 67073:tid 67264] [client 74.248.18.37:15140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/bgymj.php"] [unique_id "aoSABvcmepr5_nHgLbMvowAAAk8"]
[Tue Aug 18 12:53:42.044766 2026] [security2:error] [pid 67073:tid 67215] [client 74.248.136.165:19222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/kj.php"] [unique_id "aoSABvcmepr5_nHgLbMvpAAAAh4"]
[Tue Aug 18 12:53:42.046303 2026] [security2:error] [pid 67073:tid 67184] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/public/wp-blog.php"] [unique_id "aoSABvcmepr5_nHgLbMvpQACKWw"]
[Tue Aug 18 12:53:42.051127 2026] [security2:error] [pid 67073:tid 67320] [client 20.51.153.15:13433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/profiler.php"] [unique_id "aoSABvcmepr5_nHgLbMvpgAAAoc"]
[Tue Aug 18 12:53:42.061886 2026] [security2:error] [pid 67073:tid 67238] [client 85.154.68.202:8221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSABvcmepr5_nHgLbMvqAAAAjU"]
[Tue Aug 18 12:53:42.062016 2026] [security2:error] [pid 67073:tid 67238] [client 85.154.68.202:8221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSABvcmepr5_nHgLbMvqAAAAjU"]
[Tue Aug 18 12:53:42.067098 2026] [security2:error] [pid 67073:tid 67269] [client 20.163.43.14:3117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/flower.php"] [unique_id "aoSABvcmepr5_nHgLbMvqQAAAlQ"]
[Tue Aug 18 12:53:42.084860 2026] [security2:error] [pid 67073:tid 67330] [client 20.42.19.40:2689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/php.php"] [unique_id "aoSABvcmepr5_nHgLbMvqgAAApE"]
[Tue Aug 18 12:53:42.159612 2026] [security2:error] [pid 67073:tid 67277] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSABvcmepr5_nHgLbMvrQAAAlw"]
[Tue Aug 18 12:53:42.168998 2026] [security2:error] [pid 67073:tid 67288] [client 172.202.39.151:63931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/abc.php"] [unique_id "aoSABvcmepr5_nHgLbMvsAAAAmc"]
[Tue Aug 18 12:53:42.190922 2026] [security2:error] [pid 67073:tid 67322] [client 4.223.164.152:64650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/site.php"] [unique_id "aoSABvcmepr5_nHgLbMvsgAAAok"]
[Tue Aug 18 12:53:42.235291 2026] [security2:error] [pid 67073:tid 67188] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/cu.php"] [unique_id "aoSABvcmepr5_nHgLbMvswACGHA"]
[Tue Aug 18 12:53:42.240941 2026] [security2:error] [pid 67073:tid 67296] [client 114.119.144.65:53003] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tivinalili.com.br"] [uri "/mestre-derivan-lanca-o-livro-ultimate-bartender-book-2018"] [unique_id "aoSABvcmepr5_nHgLbMvtQAAAm8"], referer: https://tivinalili.com.br/mestre-derivan-lanca-o-livro-ultimate-bartender-book-2018
[Tue Aug 18 12:53:42.252391 2026] [security2:error] [pid 67073:tid 67311] [client 20.226.56.190:3049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/mo.php"] [unique_id "aoSABvcmepr5_nHgLbMvtgAAAn4"]
[Tue Aug 18 12:53:42.305206 2026] [autoindex:error] [pid 67073:tid 67197] [remote 172.182.217.32:0] AH01276: Cannot serve directory /home3/pcjnl23s/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:42.320884 2026] [security2:error] [pid 66623:tid 66774] [client 20.51.153.15:13439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/findes.php"] [unique_id "aoSABtO5rbWdOArH04J8EQAAARI"]
[Tue Aug 18 12:53:42.359797 2026] [security2:error] [pid 67073:tid 67263] [client 20.104.100.201:53886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSABvcmepr5_nHgLbMvuQAAAk4"]
[Tue Aug 18 12:53:42.365203 2026] [security2:error] [pid 67073:tid 67231] [client 4.223.164.152:6645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/cabs.php"] [unique_id "aoSABvcmepr5_nHgLbMvugAAAi4"]
[Tue Aug 18 12:53:42.368577 2026] [security2:error] [pid 66623:tid 66847] [client 20.100.169.31:28458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/k.php"] [unique_id "aoSABtO5rbWdOArH04J8EgAAAVs"]
[Tue Aug 18 12:53:42.383673 2026] [security2:error] [pid 67073:tid 67323] [client 104.209.144.33:15690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSABvcmepr5_nHgLbMvuwAAAoo"]
[Tue Aug 18 12:53:42.386026 2026] [security2:error] [pid 67073:tid 67326] [client 20.100.169.31:31989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.julioalvez.com.br"] [uri "/admin.php"] [unique_id "aoSABvcmepr5_nHgLbMvvAAAAo0"]
[Tue Aug 18 12:53:42.386033 2026] [security2:error] [pid 67073:tid 67280] [client 74.249.206.207:63353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/akismet.php"] [unique_id "aoSABvcmepr5_nHgLbMvvQAAAl8"]
[Tue Aug 18 12:53:42.404385 2026] [security2:error] [pid 67073:tid 67233] [client 20.91.215.254:9113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSABvcmepr5_nHgLbMvvgAAAjA"]
[Tue Aug 18 12:53:42.404929 2026] [security2:error] [pid 67073:tid 67316] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/aa.php"] [unique_id "aoSABvcmepr5_nHgLbMvvwAAAoM"]
[Tue Aug 18 12:53:42.423948 2026] [security2:error] [pid 66623:tid 66806] [client 172.202.39.151:44375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/moon.php"] [unique_id "aoSABtO5rbWdOArH04J8FQAAATI"]
[Tue Aug 18 12:53:42.434483 2026] [security2:error] [pid 67073:tid 67241] [client 20.250.13.23:30518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/adminfuns.php"] [unique_id "aoSABvcmepr5_nHgLbMvwQAAAjg"]
[Tue Aug 18 12:53:42.448343 2026] [security2:error] [pid 66623:tid 66877] [client 20.163.43.14:3187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/13.php"] [unique_id "aoSABtO5rbWdOArH04J8FwAAAXk"]
[Tue Aug 18 12:53:42.455106 2026] [security2:error] [pid 67073:tid 67080] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/X57.php"] [unique_id "aoSABvcmepr5_nHgLbMvwgACUQQ"]
[Tue Aug 18 12:53:42.462203 2026] [security2:error] [pid 67073:tid 67312] [client 74.248.136.165:65151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/bes.php"] [unique_id "aoSABvcmepr5_nHgLbMvwwAAAn8"]
[Tue Aug 18 12:53:42.481323 2026] [security2:error] [pid 66623:tid 66871] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSABtO5rbWdOArH04J8GQAAAXM"]
[Tue Aug 18 12:53:42.491775 2026] [security2:error] [pid 66623:tid 66890] [client 40.85.222.29:2860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSABtO5rbWdOArH04J8GgAAAYY"]
[Tue Aug 18 12:53:42.492892 2026] [security2:error] [pid 67073:tid 67164] [remote 34.26.95.176:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.95.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atekrefrigeracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSABvcmepr5_nHgLbMvrwACTVg"]
[Tue Aug 18 12:53:42.508678 2026] [security2:error] [pid 67073:tid 67235] [client 20.100.169.31:33824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/gecko-new.php"] [unique_id "aoSABvcmepr5_nHgLbMvxQAAAjI"]
[Tue Aug 18 12:53:42.575584 2026] [security2:error] [pid 67073:tid 67306] [client 213.35.127.232:54664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSABvcmepr5_nHgLbMvyQAAAnk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:42.609789 2026] [security2:error] [pid 67073:tid 67225] [client 20.226.56.190:3037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/qr.php"] [unique_id "aoSABvcmepr5_nHgLbMvywAAAig"]
[Tue Aug 18 12:53:42.654255 2026] [security2:error] [pid 66623:tid 66860] [client 20.171.51.14:15805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/fa.php"] [unique_id "aoSABtO5rbWdOArH04J8GwAAAWg"]
[Tue Aug 18 12:53:42.655377 2026] [security2:error] [pid 67073:tid 67268] [client 4.223.164.152:54218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSABvcmepr5_nHgLbMvzgAAAlM"]
[Tue Aug 18 12:53:42.680138 2026] [security2:error] [pid 66623:tid 66869] [client 132.196.61.152:56118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/ajax.php"] [unique_id "aoSABtO5rbWdOArH04J8HAAAAXE"]
[Tue Aug 18 12:53:42.780075 2026] [security2:error] [pid 67073:tid 67309] [client 20.163.43.14:3122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/cc.php"] [unique_id "aoSABvcmepr5_nHgLbMv0wAAAnw"]
[Tue Aug 18 12:53:42.783538 2026] [security2:error] [pid 67073:tid 67276] [client 20.48.236.86:10727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/BDKR28WP.php"] [unique_id "aoSABvcmepr5_nHgLbMv1QAAAls"]
[Tue Aug 18 12:53:42.797152 2026] [security2:error] [pid 67073:tid 67260] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSABvcmepr5_nHgLbMv1gAAAks"]
[Tue Aug 18 12:53:42.819299 2026] [security2:error] [pid 67073:tid 67248] [client 172.202.39.151:61024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/akcc.php"] [unique_id "aoSABvcmepr5_nHgLbMv2AAAAj8"]
[Tue Aug 18 12:53:42.820635 2026] [security2:error] [pid 67073:tid 67242] [client 52.238.210.254:57914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/file2.php"] [unique_id "aoSABvcmepr5_nHgLbMv2QAAAjk"]
[Tue Aug 18 12:53:42.880138 2026] [security2:error] [pid 67073:tid 67324] [client 74.248.136.165:19254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ws60.php"] [unique_id "aoSABvcmepr5_nHgLbMv2gAAAos"]
[Tue Aug 18 12:53:42.905569 2026] [security2:error] [pid 67073:tid 67278] [client 158.158.74.177:25866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSABvcmepr5_nHgLbMv3AAAAl0"]
[Tue Aug 18 12:53:42.911613 2026] [authz_core:error] [pid 67073:tid 67201] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:42.911891 2026] [authz_core:error] [pid 67073:tid 67201] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:42.921201 2026] [security2:error] [pid 67073:tid 67297] [client 20.226.56.190:3067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/dirs.php"] [unique_id "aoSABvcmepr5_nHgLbMv3gAAAnA"]
[Tue Aug 18 12:53:42.928924 2026] [security2:error] [pid 67073:tid 67219] [client 4.223.164.152:6599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/insc.php"] [unique_id "aoSABvcmepr5_nHgLbMv3wAAAiI"]
[Tue Aug 18 12:53:42.957862 2026] [security2:error] [pid 67073:tid 67289] [client 20.65.98.162:22693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/mgrr.php"] [unique_id "aoSABvcmepr5_nHgLbMv4AAAAmg"]
[Tue Aug 18 12:53:43.000824 2026] [security2:error] [pid 67073:tid 67221] [client 20.226.56.190:10595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/mq.php"] [unique_id "aoSAB_cmepr5_nHgLbMv5AAAAiQ"]
[Tue Aug 18 12:53:43.006348 2026] [security2:error] [pid 67073:tid 67255] [client 20.51.153.15:13317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/fedora.php"] [unique_id "aoSAB_cmepr5_nHgLbMv5QAAAkY"]
[Tue Aug 18 12:53:43.007729 2026] [security2:error] [pid 67073:tid 67195] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/forbidals.php"] [unique_id "aoSAB_cmepr5_nHgLbMv5gACbHc"]
[Tue Aug 18 12:53:43.038715 2026] [security2:error] [pid 67073:tid 67295] [client 20.91.215.254:20182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp-2019.php"] [unique_id "aoSAB_cmepr5_nHgLbMv5wAAAm4"]
[Tue Aug 18 12:53:43.066443 2026] [security2:error] [pid 66623:tid 66892] [client 20.171.51.14:45434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/fb.php"] [unique_id "aoSAB9O5rbWdOArH04J8HwAAAYg"]
[Tue Aug 18 12:53:43.067805 2026] [security2:error] [pid 67073:tid 67264] [client 20.24.67.246:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/1.php"] [unique_id "aoSAB_cmepr5_nHgLbMv6AAAAk8"]
[Tue Aug 18 12:53:43.067882 2026] [security2:error] [pid 67073:tid 67264] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/1.php"] [unique_id "aoSAB_cmepr5_nHgLbMv6AAAAk8"]
[Tue Aug 18 12:53:43.094535 2026] [security2:error] [pid 67073:tid 67238] [client 4.223.164.152:54225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/cabs.php"] [unique_id "aoSAB_cmepr5_nHgLbMv6gAAAjU"]
[Tue Aug 18 12:53:43.102713 2026] [security2:error] [pid 67073:tid 67269] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSAB_cmepr5_nHgLbMv6wAAAlQ"]
[Tue Aug 18 12:53:43.114413 2026] [security2:error] [pid 66623:tid 66778] [client 158.158.74.177:25858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSAB9O5rbWdOArH04J8IAAAARY"]
[Tue Aug 18 12:53:43.144103 2026] [security2:error] [pid 67073:tid 67286] [client 20.163.43.14:3108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAB_cmepr5_nHgLbMv7AAAAmU"]
[Tue Aug 18 12:53:43.152469 2026] [security2:error] [pid 67073:tid 67277] [client 135.225.75.187:9987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/pouhg.php"] [unique_id "aoSAB_cmepr5_nHgLbMv7QAAAlw"]
[Tue Aug 18 12:53:43.168388 2026] [security2:error] [pid 66623:tid 66698] [remote 57.141.22.113:33344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSAB9O5rbWdOArH04J8IQABIj0"]
[Tue Aug 18 12:53:43.178138 2026] [security2:error] [pid 66623:tid 66868] [client 74.248.18.37:38913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/aa.php"] [unique_id "aoSAB9O5rbWdOArH04J8IgAAAXA"]
[Tue Aug 18 12:53:43.253300 2026] [security2:error] [pid 67073:tid 67240] [client 20.250.13.23:31479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/404.php"] [unique_id "aoSAB_cmepr5_nHgLbMv8gAAAjc"]
[Tue Aug 18 12:53:43.257591 2026] [security2:error] [pid 67073:tid 67092] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/edit.php"] [unique_id "aoSAB_cmepr5_nHgLbMv8wACGBA"]
[Tue Aug 18 12:53:43.276318 2026] [security2:error] [pid 66623:tid 66891] [client 20.91.215.254:22912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/license.php"] [unique_id "aoSAB9O5rbWdOArH04J8IwAAAYc"]
[Tue Aug 18 12:53:43.298495 2026] [security2:error] [pid 67073:tid 67246] [client 74.248.136.165:41175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/olfclass.php"] [unique_id "aoSAB_cmepr5_nHgLbMv9QAAAj0"]
[Tue Aug 18 12:53:43.315119 2026] [security2:error] [pid 66623:tid 66881] [client 52.139.47.57:13510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSAB9O5rbWdOArH04J8JAAAAX0"]
[Tue Aug 18 12:53:43.315828 2026] [security2:error] [pid 66623:tid 66781] [client 20.48.236.86:16356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAB9O5rbWdOArH04J8JQAAARk"]
[Tue Aug 18 12:53:43.326011 2026] [security2:error] [pid 66623:tid 66805] [client 20.51.153.15:13389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/path.php"] [unique_id "aoSAB9O5rbWdOArH04J8JwAAATE"]
[Tue Aug 18 12:53:43.357665 2026] [security2:error] [pid 67073:tid 67303] [client 114.119.145.125:62393] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lecarveiculospira.com.br"] [uri "/estoque/veiculos/marca-volkswagen_modelo-fox_ordem-year-desc"] [unique_id "aoSAB_cmepr5_nHgLbMv9gAAAnY"], referer: https://www.lecarveiculospira.com.br/estoque/veiculos/marca-volkswagen_modelo-fox_ordem-price-desc
[Tue Aug 18 12:53:43.363157 2026] [security2:error] [pid 67073:tid 67290] [client 20.118.172.148:44279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAB_cmepr5_nHgLbMv9wAAAmk"]
[Tue Aug 18 12:53:43.406538 2026] [security2:error] [pid 67073:tid 67275] [client 20.100.169.31:28378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-blink.php"] [unique_id "aoSAB_cmepr5_nHgLbMv-QAAAlo"]
[Tue Aug 18 12:53:43.441210 2026] [security2:error] [pid 66623:tid 66820] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSAB9O5rbWdOArH04J8KAAAAUA"]
[Tue Aug 18 12:53:43.443091 2026] [security2:error] [pid 66623:tid 66888] [client 20.226.56.190:20396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/sn.php"] [unique_id "aoSAB9O5rbWdOArH04J8KQAAAYQ"]
[Tue Aug 18 12:53:43.452045 2026] [security2:error] [pid 66623:tid 66886] [client 20.42.19.40:2705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/t.php"] [unique_id "aoSAB9O5rbWdOArH04J8KgAAAYI"]
[Tue Aug 18 12:53:43.469418 2026] [security2:error] [pid 66623:tid 66865] [client 158.23.17.4:54737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/xn.php"] [unique_id "aoSAB9O5rbWdOArH04J8KwAAAW0"]
[Tue Aug 18 12:53:43.481343 2026] [security2:error] [pid 67073:tid 67083] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/kj.php"] [unique_id "aoSAB_cmepr5_nHgLbMv-wACTgc"]
[Tue Aug 18 12:53:43.533010 2026] [security2:error] [pid 66623:tid 66875] [client 20.163.43.14:3188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSAB9O5rbWdOArH04J8LQAAAXc"]
[Tue Aug 18 12:53:43.533057 2026] [security2:error] [pid 66623:tid 66870] [client 52.173.121.69:54236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAB9O5rbWdOArH04J8LAAAAXI"]
[Tue Aug 18 12:53:43.544296 2026] [security2:error] [pid 67073:tid 67326] [client 4.223.164.152:54227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/insc.php"] [unique_id "aoSAB_cmepr5_nHgLbMv_AAAAo0"]
[Tue Aug 18 12:53:43.548881 2026] [security2:error] [pid 67073:tid 67314] [client 4.223.164.152:6620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/file.php"] [unique_id "aoSAB_cmepr5_nHgLbMv_QAAAoE"]
[Tue Aug 18 12:53:43.557574 2026] [security2:error] [pid 67073:tid 67233] [client 20.171.51.14:58397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/gw.php"] [unique_id "aoSAB_cmepr5_nHgLbMv_gAAAjA"]
[Tue Aug 18 12:53:43.563751 2026] [security2:error] [pid 67073:tid 67316] [client 132.196.61.152:56094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/yj09.php"] [unique_id "aoSAB_cmepr5_nHgLbMv_wAAAoM"]
[Tue Aug 18 12:53:43.602016 2026] [security2:error] [pid 67073:tid 67307] [client 20.104.100.201:17344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-the.php"] [unique_id "aoSAB_cmepr5_nHgLbMwAgAAAno"]
[Tue Aug 18 12:53:43.602070 2026] [security2:error] [pid 67073:tid 67328] [client 213.35.127.232:54881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAB_cmepr5_nHgLbMwAwAAAo8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:43.611111 2026] [security2:error] [pid 67073:tid 67281] [client 172.202.39.151:44359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/cache.php"] [unique_id "aoSAB_cmepr5_nHgLbMwBQAAAmA"]
[Tue Aug 18 12:53:43.611139 2026] [security2:error] [pid 67073:tid 67312] [client 20.226.6.191:6529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/public/css.php"] [unique_id "aoSAB_cmepr5_nHgLbMwBAAAAn8"]
[Tue Aug 18 12:53:43.628436 2026] [security2:error] [pid 67073:tid 67229] [client 20.100.169.31:29645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/NewFile.php"] [unique_id "aoSAB_cmepr5_nHgLbMwBgAAAiw"]
[Tue Aug 18 12:53:43.637861 2026] [security2:error] [pid 66623:tid 66884] [client 52.238.210.254:30059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/images/class-config.php"] [unique_id "aoSAB9O5rbWdOArH04J8MAAAAYA"]
[Tue Aug 18 12:53:43.638386 2026] [security2:error] [pid 66623:tid 66821] [client 20.226.56.190:7311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/13.php"] [unique_id "aoSAB9O5rbWdOArH04J8MQAAAUE"]
[Tue Aug 18 12:53:43.641447 2026] [security2:error] [pid 66623:tid 66863] [client 20.51.153.15:13436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/456.php"] [unique_id "aoSAB9O5rbWdOArH04J8MgAAAWs"]
[Tue Aug 18 12:53:43.670844 2026] [security2:error] [pid 67073:tid 67078] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/bes.php"] [unique_id "aoSAB_cmepr5_nHgLbMwCAACjgI"]
[Tue Aug 18 12:53:43.677905 2026] [security2:error] [pid 67073:tid 67210] [client 20.91.215.254:20204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/cjfuns.php"] [unique_id "aoSAB_cmepr5_nHgLbMwCQAAAhk"]
[Tue Aug 18 12:53:43.682098 2026] [security2:error] [pid 67073:tid 67224] [client 20.48.236.86:16341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAB_cmepr5_nHgLbMwCgAAAic"]
[Tue Aug 18 12:53:43.724129 2026] [security2:error] [pid 67073:tid 67325] [client 74.248.136.165:17232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wpver.php"] [unique_id "aoSAB_cmepr5_nHgLbMwCwAAAow"]
[Tue Aug 18 12:53:43.725910 2026] [security2:error] [pid 67073:tid 67230] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/img.php"] [unique_id "aoSAB_cmepr5_nHgLbMwDAAAAi0"]
[Tue Aug 18 12:53:43.739324 2026] [security2:error] [pid 67073:tid 67317] [client 40.85.222.29:37753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSAB_cmepr5_nHgLbMwDQAAAoQ"]
[Tue Aug 18 12:53:43.747492 2026] [security2:error] [pid 66623:tid 66878] [client 172.182.200.96:14098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/jvcpa.php"] [unique_id "aoSAB9O5rbWdOArH04J8NAAAAXo"]
[Tue Aug 18 12:53:43.763484 2026] [security2:error] [pid 67073:tid 67205] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSAB_cmepr5_nHgLbMwDgAAAhQ"]
[Tue Aug 18 12:53:43.812280 2026] [security2:error] [pid 67073:tid 67258] [client 158.158.74.177:25880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSAB_cmepr5_nHgLbMwEgAAAkk"]
[Tue Aug 18 12:53:43.840504 2026] [security2:error] [pid 67073:tid 67244] [client 20.226.56.190:52052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/43.php"] [unique_id "aoSAB_cmepr5_nHgLbMwEwAAAjs"]
[Tue Aug 18 12:53:43.878207 2026] [security2:error] [pid 67073:tid 67247] [client 20.51.153.15:2023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/SMTP.php"] [unique_id "aoSAB_cmepr5_nHgLbMwFgAAAj4"]
[Tue Aug 18 12:53:43.878378 2026] [security2:error] [pid 67073:tid 67308] [client 20.163.43.14:3146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/01.php"] [unique_id "aoSAB_cmepr5_nHgLbMwFwAAAns"]
[Tue Aug 18 12:53:43.883471 2026] [security2:error] [pid 66623:tid 66811] [client 20.48.236.86:65118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/sky.php"] [unique_id "aoSAB9O5rbWdOArH04J8NQAAATc"]
[Tue Aug 18 12:53:43.908028 2026] [security2:error] [pid 66623:tid 66779] [client 74.249.206.207:36638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/admin.php"] [unique_id "aoSAB9O5rbWdOArH04J8NgAAARc"]
[Tue Aug 18 12:53:43.916098 2026] [security2:error] [pid 66623:tid 66854] [client 52.238.210.254:10160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSAB9O5rbWdOArH04J8NwAAAWI"]
[Tue Aug 18 12:53:43.961067 2026] [security2:error] [pid 67073:tid 67171] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ws60.php"] [unique_id "aoSAB_cmepr5_nHgLbMwGgACP18"]
[Tue Aug 18 12:53:43.967621 2026] [security2:error] [pid 67073:tid 67242] [client 20.171.51.14:45385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/sw.php"] [unique_id "aoSAB_cmepr5_nHgLbMwGwAAAjk"]
[Tue Aug 18 12:53:43.975590 2026] [security2:error] [pid 67073:tid 67228] [client 4.223.164.152:37259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/file.php"] [unique_id "aoSAB_cmepr5_nHgLbMwHAAAAis"]
[Tue Aug 18 12:53:43.987574 2026] [security2:error] [pid 66623:tid 66882] [client 20.100.169.31:31997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.julioalvez.com.br"] [uri "/goods.php"] [unique_id "aoSAB9O5rbWdOArH04J8OQAAAX4"]
[Tue Aug 18 12:53:44.059901 2026] [security2:error] [pid 67073:tid 67291] [client 74.248.136.165:63289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/sxdfrt.php"] [unique_id "aoSACPcmepr5_nHgLbMwHwAAAmo"]
[Tue Aug 18 12:53:44.073049 2026] [security2:error] [pid 66623:tid 66839] [client 20.171.51.14:1938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/vg.php"] [unique_id "aoSACNO5rbWdOArH04J8OgAAAVM"]
[Tue Aug 18 12:53:44.075618 2026] [security2:error] [pid 66623:tid 66835] [client 20.48.236.86:16349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSACNO5rbWdOArH04J8OwAAAU8"]
[Tue Aug 18 12:53:44.081957 2026] [security2:error] [pid 67073:tid 67279] [client 4.223.164.152:6917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/dex.php"] [unique_id "aoSACPcmepr5_nHgLbMwIAAAAl4"]
[Tue Aug 18 12:53:44.105207 2026] [security2:error] [pid 67073:tid 67304] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSACPcmepr5_nHgLbMwIQAAAnc"]
[Tue Aug 18 12:53:44.113497 2026] [security2:error] [pid 67073:tid 67289] [client 20.51.153.15:13328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/vbseo.php"] [unique_id "aoSACPcmepr5_nHgLbMwIgAAAmg"]
[Tue Aug 18 12:53:44.133490 2026] [authz_core:error] [pid 67073:tid 67099] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:44.133760 2026] [authz_core:error] [pid 67073:tid 67099] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:44.140493 2026] [security2:error] [pid 67073:tid 67221] [client 74.248.136.165:58367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/thui.php"] [unique_id "aoSACPcmepr5_nHgLbMwJgAAAiQ"]
[Tue Aug 18 12:53:44.158859 2026] [security2:error] [pid 67073:tid 67293] [client 158.23.17.4:55205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/47.php"] [unique_id "aoSACPcmepr5_nHgLbMwKAAAAmw"]
[Tue Aug 18 12:53:44.158917 2026] [security2:error] [pid 67073:tid 67093] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/olfclass.php"] [unique_id "aoSACPcmepr5_nHgLbMwJwACRhE"]
[Tue Aug 18 12:53:44.206912 2026] [security2:error] [pid 66623:tid 66866] [client 20.104.100.201:53872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSACNO5rbWdOArH04J8PAAAAW4"]
[Tue Aug 18 12:53:44.214968 2026] [security2:error] [pid 66623:tid 66795] [client 20.163.43.14:3103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/lv.php"] [unique_id "aoSACNO5rbWdOArH04J8PQAAASc"]
[Tue Aug 18 12:53:44.239514 2026] [security2:error] [pid 66623:tid 66813] [client 20.65.98.162:18100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/55.php"] [unique_id "aoSACNO5rbWdOArH04J8PwAAATk"]
[Tue Aug 18 12:53:44.252731 2026] [security2:error] [pid 67073:tid 67264] [client 135.225.75.187:23146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/moon3.php"] [unique_id "aoSACPcmepr5_nHgLbMwKgAAAk8"]
[Tue Aug 18 12:53:44.268968 2026] [security2:error] [pid 67073:tid 67302] [client 149.34.210.157:49294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSACPcmepr5_nHgLbMwKwAAAnU"]
[Tue Aug 18 12:53:44.309340 2026] [security2:error] [pid 66623:tid 66785] [client 20.91.215.254:20174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSACNO5rbWdOArH04J8QAAAAR0"]
[Tue Aug 18 12:53:44.320254 2026] [security2:error] [pid 67073:tid 67320] [client 132.196.61.152:56121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/scxy.php"] [unique_id "aoSACPcmepr5_nHgLbMwLwAAAoc"]
[Tue Aug 18 12:53:44.383444 2026] [security2:error] [pid 67073:tid 67108] [remote 34.26.95.176:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.95.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atekrefrigeracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACPcmepr5_nHgLbMwMAACkSA"]
[Tue Aug 18 12:53:44.383641 2026] [security2:error] [pid 67073:tid 67330] [client 34.26.95.176:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "atekrefrigeracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACPcmepr5_nHgLbMwMAACkSA"]
[Tue Aug 18 12:53:44.398674 2026] [security2:error] [pid 66623:tid 66793] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/222.php"] [unique_id "aoSACNO5rbWdOArH04J8QQAAASU"]
[Tue Aug 18 12:53:44.399873 2026] [security2:error] [pid 67073:tid 67249] [client 4.223.164.152:54267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/dex.php"] [unique_id "aoSACPcmepr5_nHgLbMwMQAAAkA"]
[Tue Aug 18 12:53:44.399942 2026] [security2:error] [pid 67073:tid 67217] [client 20.226.56.190:47105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/fresh.php"] [unique_id "aoSACPcmepr5_nHgLbMwMgAAAiA"]
[Tue Aug 18 12:53:44.405419 2026] [security2:error] [pid 67073:tid 67236] [client 20.51.153.15:1991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/sysinfo.php"] [unique_id "aoSACPcmepr5_nHgLbMwMwAAAjM"]
[Tue Aug 18 12:53:44.407845 2026] [security2:error] [pid 66623:tid 66772] [client 20.226.56.190:6381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/so.php"] [unique_id "aoSACNO5rbWdOArH04J8QgAAARA"]
[Tue Aug 18 12:53:44.420697 2026] [security2:error] [pid 67073:tid 67286] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSACPcmepr5_nHgLbMwNQAAAmU"]
[Tue Aug 18 12:53:44.423027 2026] [security2:error] [pid 67073:tid 67214] [client 52.139.47.57:24627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/aaa.php"] [unique_id "aoSACPcmepr5_nHgLbMwNwAAAh0"]
[Tue Aug 18 12:53:44.440597 2026] [security2:error] [pid 66623:tid 66818] [client 158.158.74.177:25875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/st.php"] [unique_id "aoSACNO5rbWdOArH04J8QwAAAT4"]
[Tue Aug 18 12:53:44.498328 2026] [security2:error] [pid 66623:tid 66848] [client 74.249.206.207:10732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/bajah.php"] [unique_id "aoSACNO5rbWdOArH04J8RQAAAVw"]
[Tue Aug 18 12:53:44.547771 2026] [security2:error] [pid 67073:tid 67302] [client 149.34.210.157:49294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSACPcmepr5_nHgLbMwKwAAAnU"]
[Tue Aug 18 12:53:44.556289 2026] [security2:error] [pid 67073:tid 67305] [client 74.248.18.37:35942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-mail.php"] [unique_id "aoSACPcmepr5_nHgLbMwOgAAAng"]
[Tue Aug 18 12:53:44.558583 2026] [security2:error] [pid 67073:tid 67209] [client 74.248.136.165:40838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/tmpls.php"] [unique_id "aoSACPcmepr5_nHgLbMwOwAAAhg"]
[Tue Aug 18 12:53:44.563797 2026] [security2:error] [pid 67073:tid 67246] [client 104.209.144.33:24832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSACPcmepr5_nHgLbMwPQAAAj0"]
[Tue Aug 18 12:53:44.565731 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:44.566004 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:44.596105 2026] [security2:error] [pid 66623:tid 66889] [client 196.12.128.158:54578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSACNO5rbWdOArH04J8RwAAAYU"]
[Tue Aug 18 12:53:44.596220 2026] [security2:error] [pid 66623:tid 66889] [client 196.12.128.158:54578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSACNO5rbWdOArH04J8RwAAAYU"]
[Tue Aug 18 12:53:44.610427 2026] [security2:error] [pid 66623:tid 66810] [client 20.163.43.14:3136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/new.php"] [unique_id "aoSACNO5rbWdOArH04J8SAAAATY"]
[Tue Aug 18 12:53:44.617436 2026] [security2:error] [pid 67073:tid 67215] [client 213.35.127.232:55081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSACPcmepr5_nHgLbMwPwAAAh4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:44.648502 2026] [security2:error] [pid 66623:tid 66800] [client 20.51.153.15:13316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/ppinfo.php"] [unique_id "aoSACNO5rbWdOArH04J8SQAAASw"]
[Tue Aug 18 12:53:44.662306 2026] [security2:error] [pid 66623:tid 66789] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/i.php"] [unique_id "aoSACNO5rbWdOArH04J8SgAAASE"]
[Tue Aug 18 12:53:44.686167 2026] [security2:error] [pid 66623:tid 66883] [client 20.171.51.14:36431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/gc.php"] [unique_id "aoSACNO5rbWdOArH04J8SwAAAX8"]
[Tue Aug 18 12:53:44.709949 2026] [security2:error] [pid 67073:tid 67290] [client 40.85.222.29:37709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/well-known/index.php"] [unique_id "aoSACPcmepr5_nHgLbMwQwAAAmk"]
[Tue Aug 18 12:53:44.748326 2026] [security2:error] [pid 66623:tid 66867] [client 20.48.236.86:16351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSACNO5rbWdOArH04J8TAAAAW8"]
[Tue Aug 18 12:53:44.763634 2026] [security2:error] [pid 67073:tid 67275] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSACPcmepr5_nHgLbMwRAAAAlo"]
[Tue Aug 18 12:53:44.766647 2026] [security2:error] [pid 66623:tid 66851] [client 20.250.13.23:25228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wk/index.php"] [unique_id "aoSACNO5rbWdOArH04J8TQAAAV8"]
[Tue Aug 18 12:53:44.769161 2026] [security2:error] [pid 66623:tid 66830] [client 52.238.210.254:57858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/alfa.php"] [unique_id "aoSACNO5rbWdOArH04J8TgAAAUo"]
[Tue Aug 18 12:53:44.789913 2026] [security2:error] [pid 67073:tid 67231] [client 20.226.56.190:52052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gj.php"] [unique_id "aoSACPcmepr5_nHgLbMwSAAAAi4"]
[Tue Aug 18 12:53:44.836110 2026] [security2:error] [pid 66623:tid 66841] [client 20.104.100.201:17358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/xwpg.php"] [unique_id "aoSACNO5rbWdOArH04J8UAAAAVU"]
[Tue Aug 18 12:53:44.858991 2026] [security2:error] [pid 67073:tid 67314] [client 20.48.236.86:65145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/file5.php"] [unique_id "aoSACPcmepr5_nHgLbMwSQAAAoE"]
[Tue Aug 18 12:53:44.861111 2026] [security2:error] [pid 66623:tid 66857] [client 4.223.164.152:37254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/key.php"] [unique_id "aoSACNO5rbWdOArH04J8UQAAAWU"]
[Tue Aug 18 12:53:44.896593 2026] [security2:error] [pid 66623:tid 66827] [client 20.51.153.15:13398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/globals.php"] [unique_id "aoSACNO5rbWdOArH04J8UgAAAUc"]
[Tue Aug 18 12:53:44.928948 2026] [security2:error] [pid 66623:tid 66847] [client 132.196.61.152:55334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/ws13.php"] [unique_id "aoSACNO5rbWdOArH04J8UwAAAVs"]
[Tue Aug 18 12:53:44.952136 2026] [security2:error] [pid 67073:tid 67261] [client 20.91.215.254:20221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSACPcmepr5_nHgLbMwTAAAAkw"]
[Tue Aug 18 12:53:44.975827 2026] [security2:error] [pid 67073:tid 67254] [client 74.248.136.165:40877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/nzv.php"] [unique_id "aoSACPcmepr5_nHgLbMwTwAAAkU"]
[Tue Aug 18 12:53:44.980871 2026] [security2:error] [pid 67073:tid 67266] [client 20.163.43.14:3137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/222.php"] [unique_id "aoSACPcmepr5_nHgLbMwUAAAAlE"]
[Tue Aug 18 12:53:44.995087 2026] [security2:error] [pid 67073:tid 67114] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wpver.php"] [unique_id "aoSACPcmepr5_nHgLbMwUQACjyY"]
[Tue Aug 18 12:53:45.018150 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:45.018421 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:45.034928 2026] [security2:error] [pid 66623:tid 66871] [client 74.249.206.207:26458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/ajax.php"] [unique_id "aoSACdO5rbWdOArH04J8VQAAAXM"]
[Tue Aug 18 12:53:45.066325 2026] [security2:error] [pid 66623:tid 66824] [client 20.226.56.190:20390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/pd.php"] [unique_id "aoSACdO5rbWdOArH04J8VwAAAUQ"]
[Tue Aug 18 12:53:45.069523 2026] [security2:error] [pid 66623:tid 66872] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/key.php"] [unique_id "aoSACdO5rbWdOArH04J8WAAAAXQ"]
[Tue Aug 18 12:53:45.075590 2026] [security2:error] [pid 66623:tid 66833] [client 20.48.236.86:16376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/xx.php"] [unique_id "aoSACdO5rbWdOArH04J8WQAAAU0"]
[Tue Aug 18 12:53:45.093462 2026] [security2:error] [pid 66623:tid 66814] [client 52.173.121.69:54451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSACdO5rbWdOArH04J8WgAAATo"]
[Tue Aug 18 12:53:45.106499 2026] [security2:error] [pid 67073:tid 67227] [client 20.118.172.148:20634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSACfcmepr5_nHgLbMwVAAAAio"]
[Tue Aug 18 12:53:45.109898 2026] [security2:error] [pid 66623:tid 66832] [client 158.158.74.177:25903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSACdO5rbWdOArH04J8WwAAAUw"]
[Tue Aug 18 12:53:45.115003 2026] [security2:error] [pid 67073:tid 67331] [client 172.202.39.151:43051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wk/index.php"] [unique_id "aoSACfcmepr5_nHgLbMwVQAAApI"]
[Tue Aug 18 12:53:45.120960 2026] [security2:error] [pid 66623:tid 66860] [client 20.171.51.14:43375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/uq.php"] [unique_id "aoSACdO5rbWdOArH04J8XAAAAWg"]
[Tue Aug 18 12:53:45.121004 2026] [security2:error] [pid 67073:tid 67229] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSACfcmepr5_nHgLbMwVgAAAiw"]
[Tue Aug 18 12:53:45.131995 2026] [security2:error] [pid 66623:tid 66869] [client 20.51.153.15:13383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/yindu.php"] [unique_id "aoSACdO5rbWdOArH04J8XQAAAXE"]
[Tue Aug 18 12:53:45.167648 2026] [security2:error] [pid 67073:tid 67211] [client 4.223.164.152:6619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/key.php"] [unique_id "aoSACfcmepr5_nHgLbMwWAAAAho"]
[Tue Aug 18 12:53:45.185920 2026] [security2:error] [pid 67073:tid 67122] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/thui.php"] [unique_id "aoSACfcmepr5_nHgLbMwWQACGS4"]
[Tue Aug 18 12:53:45.198922 2026] [security2:error] [pid 67073:tid 67224] [client 52.238.210.254:8919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/atomlib.php"] [unique_id "aoSACfcmepr5_nHgLbMwWgAAAic"]
[Tue Aug 18 12:53:45.213667 2026] [security2:error] [pid 66623:tid 66721] [remote 103.56.163.133:57168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centraldasvariedades.com.br"] [uri "/wp-login.php"] [unique_id "aoSACdO5rbWdOArH04J8XgABC1Q"]
[Tue Aug 18 12:53:45.227913 2026] [security2:error] [pid 67073:tid 67325] [client 172.202.39.151:62701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSACfcmepr5_nHgLbMwXAAAAow"]
[Tue Aug 18 12:53:45.250849 2026] [security2:error] [pid 67073:tid 67238] [client 47.128.17.52:44372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.rodriguesesoutoadvocacia.com.br"] [uri "/robots.txt"] [unique_id "aoSACfcmepr5_nHgLbMwXgAAAjU"]
[Tue Aug 18 12:53:45.290607 2026] [security2:error] [pid 66623:tid 66801] [client 20.100.169.31:29663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSACdO5rbWdOArH04J8XwAAAS0"]
[Tue Aug 18 12:53:45.298841 2026] [security2:error] [pid 66623:tid 66790] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSACdO5rbWdOArH04J8YAAAASI"]
[Tue Aug 18 12:53:45.308272 2026] [security2:error] [pid 67073:tid 67205] [client 20.163.43.14:3177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/chosen.php"] [unique_id "aoSACfcmepr5_nHgLbMwYAAAAhQ"]
[Tue Aug 18 12:53:45.385773 2026] [security2:error] [pid 67073:tid 67172] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/tmpls.php"] [unique_id "aoSACfcmepr5_nHgLbMwYwACFWA"]
[Tue Aug 18 12:53:45.392039 2026] [security2:error] [pid 66623:tid 66861] [client 74.248.136.165:17252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/error1.php"] [unique_id "aoSACdO5rbWdOArH04J8YQAAAWk"]
[Tue Aug 18 12:53:45.392702 2026] [security2:error] [pid 66623:tid 66845] [client 4.223.164.152:46151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/kir.php"] [unique_id "aoSACdO5rbWdOArH04J8YgAAAVk"]
[Tue Aug 18 12:53:45.408509 2026] [security2:error] [pid 67073:tid 67283] [client 20.48.236.86:16331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/av.php"] [unique_id "aoSACfcmepr5_nHgLbMwZAAAAmI"]
[Tue Aug 18 12:53:45.410585 2026] [security2:error] [pid 67073:tid 67207] [client 114.119.144.41:42043] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.capitalcaminhonetes.com.br"] [uri "/veiculo/993911/ranger-xlt-3-2-20v-4x4-cd-diesel-aut"] [unique_id "aoSACfcmepr5_nHgLbMwZQAAAhY"], referer: http://www.capitalcaminhonetes.com.br/veiculo/90162/hilux-sw4-srv-d4-d-4x4-3-0-tdi-dies-aut
[Tue Aug 18 12:53:45.415823 2026] [security2:error] [pid 67073:tid 67267] [client 20.42.19.40:2236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/index/function.php"] [unique_id "aoSACfcmepr5_nHgLbMwZwAAAlI"]
[Tue Aug 18 12:53:45.416939 2026] [security2:error] [pid 67073:tid 67260] [client 20.171.51.14:33708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/sm.php"] [unique_id "aoSACfcmepr5_nHgLbMwaAAAAks"]
[Tue Aug 18 12:53:45.428573 2026] [security2:error] [pid 66623:tid 66881] [client 20.104.100.201:17385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/dex.php"] [unique_id "aoSACdO5rbWdOArH04J8YwAAAX0"]
[Tue Aug 18 12:53:45.437546 2026] [security2:error] [pid 67073:tid 67242] [client 20.226.56.190:30983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/th.php"] [unique_id "aoSACfcmepr5_nHgLbMwawAAAjk"]
[Tue Aug 18 12:53:45.441669 2026] [security2:error] [pid 66623:tid 66781] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSACdO5rbWdOArH04J8ZAAAARk"]
[Tue Aug 18 12:53:45.504870 2026] [security2:error] [pid 66623:tid 66886] [client 132.196.61.152:55298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/btx25.php"] [unique_id "aoSACdO5rbWdOArH04J8ZQAAAYI"]
[Tue Aug 18 12:53:45.506307 2026] [security2:error] [pid 66623:tid 66819] [client 197.184.64.235:41914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACdO5rbWdOArH04J8ZgAAAT8"]
[Tue Aug 18 12:53:45.510993 2026] [security2:error] [pid 66623:tid 66819] [client 197.184.64.235:41914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACdO5rbWdOArH04J8ZgAAAT8"]
[Tue Aug 18 12:53:45.542378 2026] [security2:error] [pid 67073:tid 67279] [client 20.226.6.191:6639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSACfcmepr5_nHgLbMwbwAAAl4"]
[Tue Aug 18 12:53:45.590351 2026] [security2:error] [pid 67073:tid 67244] [client 20.91.215.254:8770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/import.php"] [unique_id "aoSACfcmepr5_nHgLbMwcAAAAjs"]
[Tue Aug 18 12:53:45.604315 2026] [security2:error] [pid 67073:tid 67257] [client 158.23.17.4:54762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/payout.php"] [unique_id "aoSACfcmepr5_nHgLbMwcgAAAkg"]
[Tue Aug 18 12:53:45.630708 2026] [security2:error] [pid 66623:tid 66859] [client 213.35.127.232:55299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSACdO5rbWdOArH04J8aQAAAWc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:45.640322 2026] [security2:error] [pid 67073:tid 67320] [client 20.171.51.14:58390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/32.php"] [unique_id "aoSACfcmepr5_nHgLbMwdAAAAoc"]
[Tue Aug 18 12:53:45.649519 2026] [security2:error] [pid 67073:tid 67270] [client 20.51.153.15:13334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/sxx.php"] [unique_id "aoSACfcmepr5_nHgLbMwdQAAAlU"]
[Tue Aug 18 12:53:45.654117 2026] [security2:error] [pid 67073:tid 67318] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSACfcmepr5_nHgLbMwdgAAAoU"]
[Tue Aug 18 12:53:45.667123 2026] [security2:error] [pid 66623:tid 66792] [client 74.248.18.37:14877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/bolt.php"] [unique_id "aoSACdO5rbWdOArH04J8agAAASQ"]
[Tue Aug 18 12:53:45.667685 2026] [security2:error] [pid 67073:tid 67249] [client 74.249.206.207:65100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSACfcmepr5_nHgLbMweAAAAkA"]
[Tue Aug 18 12:53:45.668444 2026] [security2:error] [pid 67073:tid 67102] [remote 157.55.39.52:60102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2026/08/15/study-report-on-pirots-5s-compatibility-across-different-devices/"] [unique_id "aoSACfcmepr5_nHgLbMwdwACYxo"]
[Tue Aug 18 12:53:45.700398 2026] [security2:error] [pid 66623:tid 66870] [client 20.65.98.162:16512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/ajax.php"] [unique_id "aoSACdO5rbWdOArH04J8awAAAXI"]
[Tue Aug 18 12:53:45.720382 2026] [security2:error] [pid 67073:tid 67230] [client 20.250.13.23:31465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/about.php"] [unique_id "aoSACfcmepr5_nHgLbMwegAAAi0"]
[Tue Aug 18 12:53:45.726915 2026] [security2:error] [pid 66623:tid 66884] [client 20.163.43.14:3181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/info.php"] [unique_id "aoSACdO5rbWdOArH04J8bAAAAYA"]
[Tue Aug 18 12:53:45.731386 2026] [security2:error] [pid 67073:tid 67236] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/chosen.php"] [unique_id "aoSACfcmepr5_nHgLbMwewAAAjM"]
[Tue Aug 18 12:53:45.748058 2026] [security2:error] [pid 67073:tid 67214] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSACfcmepr5_nHgLbMwfQAAAh0"]
[Tue Aug 18 12:53:45.759592 2026] [security2:error] [pid 66623:tid 66863] [client 135.225.75.187:49107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/opts.php"] [unique_id "aoSACdO5rbWdOArH04J8bQAAAWs"]
[Tue Aug 18 12:53:45.781707 2026] [security2:error] [pid 67073:tid 67288] [client 20.226.56.190:45030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/admin404.php"] [unique_id "aoSACfcmepr5_nHgLbMwfgAAAmc"]
[Tue Aug 18 12:53:45.797128 2026] [security2:error] [pid 67073:tid 67228] [client 20.100.169.31:7385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.julioalvez.com.br"] [uri "/file.php"] [unique_id "aoSACfcmepr5_nHgLbMwfwAAAis"]
[Tue Aug 18 12:53:45.810541 2026] [security2:error] [pid 67073:tid 67240] [client 74.248.136.165:49476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/155.php"] [unique_id "aoSACfcmepr5_nHgLbMwgQAAAjc"]
[Tue Aug 18 12:53:45.840659 2026] [security2:error] [pid 66623:tid 66688] [remote 47.86.33.52:54554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/wp-login.php"] [unique_id "aoSACdO5rbWdOArH04J8bwABZjM"]
[Tue Aug 18 12:53:45.851976 2026] [security2:error] [pid 67073:tid 67215] [client 4.223.164.152:64693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/nofile.php"] [unique_id "aoSACfcmepr5_nHgLbMwggAAAh4"]
[Tue Aug 18 12:53:45.858714 2026] [security2:error] [pid 67073:tid 67226] [client 158.158.74.177:25886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-configs.php"] [unique_id "aoSACfcmepr5_nHgLbMwgwAAAik"]
[Tue Aug 18 12:53:45.895663 2026] [security2:error] [pid 66623:tid 66880] [client 20.48.236.86:16348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/media.php"] [unique_id "aoSACdO5rbWdOArH04J8cAAAAXw"]
[Tue Aug 18 12:53:45.900084 2026] [security2:error] [pid 66623:tid 66812] [client 20.171.51.14:51819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/28.php"] [unique_id "aoSACdO5rbWdOArH04J8cQAAATg"]
[Tue Aug 18 12:53:45.912936 2026] [security2:error] [pid 66623:tid 66849] [client 20.51.153.15:13414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/settings.php"] [unique_id "aoSACdO5rbWdOArH04J8cgAAAV0"]
[Tue Aug 18 12:53:45.947852 2026] [security2:error] [pid 67073:tid 67271] [client 114.5.214.109:49793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACfcmepr5_nHgLbMwhwAAAlY"]
[Tue Aug 18 12:53:45.947955 2026] [security2:error] [pid 67073:tid 67271] [client 114.5.214.109:49793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACfcmepr5_nHgLbMwhwAAAlY"]
[Tue Aug 18 12:53:45.953729 2026] [security2:error] [pid 67073:tid 67140] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/nzv.php"] [unique_id "aoSACfcmepr5_nHgLbMwiAACikA"]
[Tue Aug 18 12:53:45.987389 2026] [security2:error] [pid 67073:tid 67233] [client 20.104.100.201:17355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/xyn.php"] [unique_id "aoSACfcmepr5_nHgLbMwigAAAjA"]
[Tue Aug 18 12:53:46.016080 2026] [security2:error] [pid 67073:tid 67254] [client 4.223.164.152:7100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/kir.php"] [unique_id "aoSACvcmepr5_nHgLbMwjgAAAkU"]
[Tue Aug 18 12:53:46.016347 2026] [security2:error] [pid 67073:tid 67266] [client 20.171.51.14:31617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/73.php"] [unique_id "aoSACvcmepr5_nHgLbMwjwAAAlE"]
[Tue Aug 18 12:53:46.040821 2026] [security2:error] [pid 67073:tid 67281] [client 20.226.56.190:45055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/qo.php"] [unique_id "aoSACvcmepr5_nHgLbMwkAAAAmA"]
[Tue Aug 18 12:53:46.047264 2026] [security2:error] [pid 67073:tid 67269] [client 52.139.47.57:7592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/fpwch.php"] [unique_id "aoSACvcmepr5_nHgLbMwkQAAAlQ"]
[Tue Aug 18 12:53:46.069966 2026] [security2:error] [pid 67073:tid 67268] [client 37.40.227.74:56864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACvcmepr5_nHgLbMwkgAAAlM"]
[Tue Aug 18 12:53:46.072589 2026] [security2:error] [pid 67073:tid 67208] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSACvcmepr5_nHgLbMwkwAAAhc"]
[Tue Aug 18 12:53:46.073716 2026] [security2:error] [pid 67073:tid 67268] [client 37.40.227.74:56864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACvcmepr5_nHgLbMwkgAAAlM"]
[Tue Aug 18 12:53:46.110862 2026] [security2:error] [pid 66623:tid 66783] [client 20.48.236.86:65089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/xyn.php"] [unique_id "aoSACtO5rbWdOArH04J8dQAAARs"]
[Tue Aug 18 12:53:46.140141 2026] [security2:error] [pid 67073:tid 67117] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/error1.php"] [unique_id "aoSACvcmepr5_nHgLbMwlgACGSk"]
[Tue Aug 18 12:53:46.168145 2026] [security2:error] [pid 67073:tid 67218] [client 40.85.222.29:29247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSACvcmepr5_nHgLbMwlwAAAiE"]
[Tue Aug 18 12:53:46.171921 2026] [security2:error] [pid 67073:tid 67238] [client 20.226.56.190:20406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/sd.php"] [unique_id "aoSACvcmepr5_nHgLbMwmAAAAjU"]
[Tue Aug 18 12:53:46.212882 2026] [security2:error] [pid 67073:tid 67306] [client 158.23.17.4:58727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/bh.php"] [unique_id "aoSACvcmepr5_nHgLbMwmwAAAnk"]
[Tue Aug 18 12:53:46.224740 2026] [security2:error] [pid 66623:tid 66807] [client 20.91.215.254:20187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/cropper.php"] [unique_id "aoSACtO5rbWdOArH04J8dwAAATM"]
[Tue Aug 18 12:53:46.229604 2026] [security2:error] [pid 67073:tid 67225] [client 74.248.136.165:53464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/fasx.php"] [unique_id "aoSACvcmepr5_nHgLbMwnAAAAig"]
[Tue Aug 18 12:53:46.253051 2026] [security2:error] [pid 66623:tid 66835] [client 20.51.153.15:13407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/spip.php"] [unique_id "aoSACtO5rbWdOArH04J8eAAAAU8"]
[Tue Aug 18 12:53:46.274907 2026] [security2:error] [pid 66623:tid 66866] [client 4.223.164.152:54228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/fling.php"] [unique_id "aoSACtO5rbWdOArH04J8eQAAAW4"]
[Tue Aug 18 12:53:46.300260 2026] [security2:error] [pid 67073:tid 67303] [client 86.120.159.145:1399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACvcmepr5_nHgLbMwoQAAAnY"]
[Tue Aug 18 12:53:46.300357 2026] [security2:error] [pid 67073:tid 67303] [client 86.120.159.145:1399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACvcmepr5_nHgLbMwoQAAAnY"]
[Tue Aug 18 12:53:46.315477 2026] [security2:error] [pid 67073:tid 67223] [client 20.48.236.86:16261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/images.php"] [unique_id "aoSACvcmepr5_nHgLbMwpAAAAiY"]
[Tue Aug 18 12:53:46.317194 2026] [security2:error] [pid 67073:tid 67242] [client 52.238.210.254:8925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/min.php"] [unique_id "aoSACvcmepr5_nHgLbMwpQAAAjk"]
[Tue Aug 18 12:53:46.332698 2026] [security2:error] [pid 66623:tid 66853] [client 20.171.51.14:51813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/m.php"] [unique_id "aoSACtO5rbWdOArH04J8egAAAWE"]
[Tue Aug 18 12:53:46.344827 2026] [security2:error] [pid 67073:tid 67231] [client 20.100.169.31:28365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSACvcmepr5_nHgLbMwpwAAAi4"]
[Tue Aug 18 12:53:46.373393 2026] [authz_core:error] [pid 67073:tid 67152] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:46.373800 2026] [authz_core:error] [pid 67073:tid 67152] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:46.377635 2026] [security2:error] [pid 67073:tid 67145] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/155.php"] [unique_id "aoSACvcmepr5_nHgLbMwqgACaEU"]
[Tue Aug 18 12:53:46.380214 2026] [security2:error] [pid 67073:tid 67221] [client 20.42.19.40:2727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wk/index.php"] [unique_id "aoSACvcmepr5_nHgLbMwqwAAAiQ"]
[Tue Aug 18 12:53:46.390811 2026] [security2:error] [pid 67073:tid 67292] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/thoms.php"] [unique_id "aoSACvcmepr5_nHgLbMwrAAAAms"]
[Tue Aug 18 12:53:46.391391 2026] [security2:error] [pid 67073:tid 67293] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSACvcmepr5_nHgLbMwrQAAAmw"]
[Tue Aug 18 12:53:46.406507 2026] [security2:error] [pid 67073:tid 67276] [client 20.163.43.14:3174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSACvcmepr5_nHgLbMwrgAAAls"]
[Tue Aug 18 12:53:46.459326 2026] [security2:error] [pid 66623:tid 66813] [client 104.209.144.33:15740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSACtO5rbWdOArH04J8fQAAATk"]
[Tue Aug 18 12:53:46.475747 2026] [security2:error] [pid 67073:tid 67309] [client 172.202.39.151:44437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-mail.php"] [unique_id "aoSACvcmepr5_nHgLbMwsAAAAnw"]
[Tue Aug 18 12:53:46.495757 2026] [security2:error] [pid 67073:tid 67257] [client 20.118.172.148:20612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSACvcmepr5_nHgLbMwsQAAAkg"]
[Tue Aug 18 12:53:46.513701 2026] [security2:error] [pid 67073:tid 67267] [client 158.158.74.177:25894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-post.php"] [unique_id "aoSACvcmepr5_nHgLbMwsgAAAlI"]
[Tue Aug 18 12:53:46.533118 2026] [security2:error] [pid 67073:tid 67270] [client 132.196.61.152:55351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSACvcmepr5_nHgLbMwswAAAlU"]
[Tue Aug 18 12:53:46.562912 2026] [security2:error] [pid 67073:tid 67155] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/fasx.php"] [unique_id "aoSACvcmepr5_nHgLbMwtQACkU8"]
[Tue Aug 18 12:53:46.582091 2026] [security2:error] [pid 67073:tid 67308] [client 74.248.18.37:14896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/bthil.php"] [unique_id "aoSACvcmepr5_nHgLbMwtgAAAns"]
[Tue Aug 18 12:53:46.638425 2026] [security2:error] [pid 67073:tid 67230] [client 20.48.236.86:16368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/mac.php"] [unique_id "aoSACvcmepr5_nHgLbMwtwAAAi0"]
[Tue Aug 18 12:53:46.644359 2026] [security2:error] [pid 67073:tid 67236] [client 20.104.100.201:17365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSACvcmepr5_nHgLbMwuQAAAjM"]
[Tue Aug 18 12:53:46.649430 2026] [security2:error] [pid 66623:tid 66772] [client 74.248.136.165:53359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-good.php"] [unique_id "aoSACtO5rbWdOArH04J8fgAAARA"]
[Tue Aug 18 12:53:46.654318 2026] [security2:error] [pid 67073:tid 67220] [client 213.35.127.232:55492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSACvcmepr5_nHgLbMwugAAAiM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:46.665732 2026] [security2:error] [pid 66623:tid 66818] [client 20.171.51.14:16720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ib.php"] [unique_id "aoSACtO5rbWdOArH04J8fwAAAT4"]
[Tue Aug 18 12:53:46.667118 2026] [security2:error] [pid 66623:tid 66808] [client 114.119.129.110:62439] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "onlineveiculoscachoeira.com.br"] [uri "/robots.txt"] [unique_id "aoSACtO5rbWdOArH04J8gAAAATQ"], referer: http://onlineveiculoscachoeira.com.br/robots.txt
[Tue Aug 18 12:53:46.697502 2026] [security2:error] [pid 67073:tid 67214] [client 4.223.164.152:54257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/zoo1.php"] [unique_id "aoSACvcmepr5_nHgLbMwvAAAAh0"]
[Tue Aug 18 12:53:46.712331 2026] [security2:error] [pid 67073:tid 67234] [client 20.51.153.15:13435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/search.php"] [unique_id "aoSACvcmepr5_nHgLbMwvgAAAjE"]
[Tue Aug 18 12:53:46.728737 2026] [security2:error] [pid 66623:tid 66823] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSACtO5rbWdOArH04J8gQAAAUM"]
[Tue Aug 18 12:53:46.745995 2026] [security2:error] [pid 67073:tid 67243] [client 20.163.43.14:3081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSACvcmepr5_nHgLbMwwAAAAjo"]
[Tue Aug 18 12:53:46.771697 2026] [security2:error] [pid 67073:tid 67154] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-good.php"] [unique_id "aoSACvcmepr5_nHgLbMwwgACb04"]
[Tue Aug 18 12:53:46.788175 2026] [security2:error] [pid 66623:tid 66855] [client 5.31.227.224:59015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACtO5rbWdOArH04J8ggAAAWM"]
[Tue Aug 18 12:53:46.792283 2026] [security2:error] [pid 66623:tid 66855] [client 5.31.227.224:59015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACtO5rbWdOArH04J8ggAAAWM"]
[Tue Aug 18 12:53:46.861099 2026] [security2:error] [pid 66623:tid 66793] [client 20.91.215.254:20188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSACtO5rbWdOArH04J8gwAAASU"]
[Tue Aug 18 12:53:46.897642 2026] [security2:error] [pid 66623:tid 66800] [client 192.141.172.134:51952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACtO5rbWdOArH04J8hQAAASw"]
[Tue Aug 18 12:53:46.897768 2026] [security2:error] [pid 66623:tid 66800] [client 192.141.172.134:51952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACtO5rbWdOArH04J8hQAAASw"]
[Tue Aug 18 12:53:46.969130 2026] [security2:error] [pid 67073:tid 67250] [client 20.171.51.14:33675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/nl.php"] [unique_id "aoSACvcmepr5_nHgLbMwxQAAAkE"]
[Tue Aug 18 12:53:46.970663 2026] [security2:error] [pid 67073:tid 67157] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/zxin.php"] [unique_id "aoSACvcmepr5_nHgLbMwxgACaVE"]
[Tue Aug 18 12:53:46.976619 2026] [security2:error] [pid 67073:tid 67275] [client 20.51.153.15:2008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/build.php"] [unique_id "aoSACvcmepr5_nHgLbMwyAAAAlo"]
[Tue Aug 18 12:53:46.983540 2026] [security2:error] [pid 67073:tid 67329] [client 158.23.17.4:15151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/ct.php"] [unique_id "aoSACvcmepr5_nHgLbMwyQAAApA"]
[Tue Aug 18 12:53:46.988598 2026] [security2:error] [pid 67073:tid 67327] [client 213.202.253.4:58567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "affaripericiacontabil.com.br"] [uri "/wp-content/schallfuns.php"] [unique_id "aoSACvcmepr5_nHgLbMwygAAAo4"], referer: www.google.com
[Tue Aug 18 12:53:47.014882 2026] [security2:error] [pid 66623:tid 66851] [client 20.104.100.201:54051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-good.php"] [unique_id "aoSAC9O5rbWdOArH04J8iAAAAV8"]
[Tue Aug 18 12:53:47.016560 2026] [security2:error] [pid 67073:tid 67258] [client 20.48.236.86:16340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/ops.php"] [unique_id "aoSAC_cmepr5_nHgLbMwzAAAAkk"]
[Tue Aug 18 12:53:47.035593 2026] [security2:error] [pid 67073:tid 67271] [client 4.223.164.152:7040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/nofile.php"] [unique_id "aoSAC_cmepr5_nHgLbMw1wAAAlY"]
[Tue Aug 18 12:53:47.048137 2026] [security2:error] [pid 67073:tid 67323] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/wpxml.php"] [unique_id "aoSAC_cmepr5_nHgLbMw2AAAAoo"]
[Tue Aug 18 12:53:47.053694 2026] [security2:error] [pid 67073:tid 67237] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSAC_cmepr5_nHgLbMw2QAAAjQ"]
[Tue Aug 18 12:53:47.065935 2026] [security2:error] [pid 67073:tid 67314] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAC_cmepr5_nHgLbMw2gAAAoE"]
[Tue Aug 18 12:53:47.066515 2026] [security2:error] [pid 67073:tid 67233] [client 74.248.136.165:58313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/zxin.php"] [unique_id "aoSAC_cmepr5_nHgLbMw2wAAAjA"]
[Tue Aug 18 12:53:47.097291 2026] [security2:error] [pid 67073:tid 67316] [client 20.163.43.14:3178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/k.php"] [unique_id "aoSAC_cmepr5_nHgLbMw3QAAAoM"]
[Tue Aug 18 12:53:47.120708 2026] [security2:error] [pid 66623:tid 66809] [client 4.223.164.152:54244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/zoo2.php"] [unique_id "aoSAC9O5rbWdOArH04J8iQAAATU"]
[Tue Aug 18 12:53:47.124242 2026] [security2:error] [pid 66623:tid 66857] [client 172.202.39.151:44421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/o.php"] [unique_id "aoSAC9O5rbWdOArH04J8igAAAWU"]
[Tue Aug 18 12:53:47.150415 2026] [security2:error] [pid 66623:tid 66844] [client 20.171.51.14:58407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/xm.php"] [unique_id "aoSAC9O5rbWdOArH04J8iwAAAVg"]
[Tue Aug 18 12:53:47.155265 2026] [security2:error] [pid 67073:tid 67226] [client 158.158.74.177:9361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSAC_cmepr5_nHgLbMw4QAAAik"]
[Tue Aug 18 12:53:47.191263 2026] [security2:error] [pid 67073:tid 67186] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/pass4.php"] [unique_id "aoSAC_cmepr5_nHgLbMw5wACKm4"]
[Tue Aug 18 12:53:47.219030 2026] [security2:error] [pid 66623:tid 66847] [client 20.51.153.15:13358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/defaul.php"] [unique_id "aoSAC9O5rbWdOArH04J8jAAAAVs"]
[Tue Aug 18 12:53:47.243771 2026] [security2:error] [pid 66623:tid 66806] [client 20.226.6.191:6530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAC9O5rbWdOArH04J8jgAAATI"]
[Tue Aug 18 12:53:47.272989 2026] [security2:error] [pid 66623:tid 66822] [client 52.238.210.254:10130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/mac.php"] [unique_id "aoSAC9O5rbWdOArH04J8jwAAAUI"]
[Tue Aug 18 12:53:47.274102 2026] [authz_core:error] [pid 67073:tid 67194] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:47.274377 2026] [authz_core:error] [pid 67073:tid 67194] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:47.281786 2026] [security2:error] [pid 67073:tid 67235] [client 135.225.75.187:57835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/zwq13.php"] [unique_id "aoSAC_cmepr5_nHgLbMxAQAAAjI"]
[Tue Aug 18 12:53:47.291343 2026] [security2:error] [pid 67073:tid 67215] [client 114.119.166.95:45207] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jcveiculosutilitarios.com.br"] [uri "/ficha-cadastral"] [unique_id "aoSAC_cmepr5_nHgLbMxAgAAAh4"], referer: https://www.jcveiculosutilitarios.com.br/estoque
[Tue Aug 18 12:53:47.366478 2026] [security2:error] [pid 67073:tid 67306] [client 20.48.236.86:16273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/coffexium.php"] [unique_id "aoSAC_cmepr5_nHgLbMxDAAAAnk"]
[Tue Aug 18 12:53:47.373970 2026] [security2:error] [pid 67073:tid 67077] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSAC_cmepr5_nHgLbMxDgACQwE"]
[Tue Aug 18 12:53:47.382986 2026] [security2:error] [pid 66623:tid 66893] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSAC9O5rbWdOArH04J8kQAAAYk"]
[Tue Aug 18 12:53:47.397502 2026] [security2:error] [pid 66623:tid 66832] [client 20.226.56.190:20369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/km.php"] [unique_id "aoSAC9O5rbWdOArH04J8kgAAAUw"]
[Tue Aug 18 12:53:47.399026 2026] [security2:error] [pid 66623:tid 66860] [client 20.65.98.162:16611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/yj09.php"] [unique_id "aoSAC9O5rbWdOArH04J8kwAAAWg"]
[Tue Aug 18 12:53:47.408816 2026] [security2:error] [pid 66623:tid 66798] [client 132.196.61.152:27303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAC9O5rbWdOArH04J8lAAAASo"]
[Tue Aug 18 12:53:47.446809 2026] [security2:error] [pid 66623:tid 66864] [client 103.184.169.37:41166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAC9O5rbWdOArH04J8lgAAAWw"]
[Tue Aug 18 12:53:47.446941 2026] [security2:error] [pid 66623:tid 66864] [client 103.184.169.37:41166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAC9O5rbWdOArH04J8lgAAAWw"]
[Tue Aug 18 12:53:47.452485 2026] [security2:error] [pid 66623:tid 66796] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/NewFile.php"] [unique_id "aoSAC9O5rbWdOArH04J8lwAAASg"]
[Tue Aug 18 12:53:47.458229 2026] [security2:error] [pid 67073:tid 67225] [client 20.171.51.14:59324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/68.php"] [unique_id "aoSAC_cmepr5_nHgLbMxDwAAAig"]
[Tue Aug 18 12:53:47.484265 2026] [security2:error] [pid 67073:tid 67206] [client 74.248.136.165:41184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/pass4.php"] [unique_id "aoSAC_cmepr5_nHgLbMxEQAAAhU"]
[Tue Aug 18 12:53:47.484542 2026] [security2:error] [pid 67073:tid 67247] [client 20.51.153.15:13434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/twin.php"] [unique_id "aoSAC_cmepr5_nHgLbMxEgAAAj4"]
[Tue Aug 18 12:53:47.511328 2026] [security2:error] [pid 66623:tid 66876] [client 68.155.154.236:65208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSAC9O5rbWdOArH04J8mAAAAXg"]
[Tue Aug 18 12:53:47.530186 2026] [security2:error] [pid 67073:tid 67218] [client 20.91.215.254:20202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSAC_cmepr5_nHgLbMxEwAAAiE"]
[Tue Aug 18 12:53:47.545682 2026] [security2:error] [pid 66623:tid 66868] [client 4.223.164.152:54251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/org.php"] [unique_id "aoSAC9O5rbWdOArH04J8mQAAAXA"]
[Tue Aug 18 12:53:47.553477 2026] [security2:error] [pid 66623:tid 66852] [client 20.226.56.190:2559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/mf.php"] [unique_id "aoSAC9O5rbWdOArH04J8mwAAAWA"]
[Tue Aug 18 12:53:47.586632 2026] [security2:error] [pid 66623:tid 66845] [client 20.163.43.14:3090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/403.php"] [unique_id "aoSAC9O5rbWdOArH04J8nAAAAVk"]
[Tue Aug 18 12:53:47.633189 2026] [security2:error] [pid 66623:tid 66781] [client 104.209.144.33:25327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/well-known/index.php"] [unique_id "aoSAC9O5rbWdOArH04J8nQAAARk"]
[Tue Aug 18 12:53:47.649820 2026] [security2:error] [pid 66623:tid 66767] [client 5.253.205.188:35534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/forumacplibinserts.bak"] [unique_id "aoSAC9O5rbWdOArH04J8ngAAAQs"], referer: https://medihub.com.br/forumacplibinserts.bak
[Tue Aug 18 12:53:47.657748 2026] [security2:error] [pid 67073:tid 67315] [client 20.226.56.190:6344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/10.php"] [unique_id "aoSAC_cmepr5_nHgLbMxGgAAAoI"]
[Tue Aug 18 12:53:47.664040 2026] [security2:error] [pid 67073:tid 67238] [client 213.35.127.232:55660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAC_cmepr5_nHgLbMxGwAAAjU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:47.695596 2026] [security2:error] [pid 67073:tid 67279] [client 20.104.100.201:17396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wmore1.php"] [unique_id "aoSAC_cmepr5_nHgLbMxHAAAAl4"]
[Tue Aug 18 12:53:47.709767 2026] [security2:error] [pid 66623:tid 66825] [client 138.36.100.162:42976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAC9O5rbWdOArH04J8nwAAAUU"]
[Tue Aug 18 12:53:47.712828 2026] [security2:error] [pid 67073:tid 67304] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/file1221.php"] [unique_id "aoSAC_cmepr5_nHgLbMxHQAAAnc"]
[Tue Aug 18 12:53:47.726076 2026] [authz_core:error] [pid 67073:tid 67176] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:47.726340 2026] [authz_core:error] [pid 67073:tid 67176] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:47.728011 2026] [security2:error] [pid 66623:tid 66786] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSAC9O5rbWdOArH04J8oAAAAR4"]
[Tue Aug 18 12:53:47.793756 2026] [security2:error] [pid 67073:tid 67264] [client 20.48.236.86:16258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAC_cmepr5_nHgLbMxIAAAAk8"]
[Tue Aug 18 12:53:47.797560 2026] [security2:error] [pid 67073:tid 67309] [client 4.223.164.152:6610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/fling.php"] [unique_id "aoSAC_cmepr5_nHgLbMxIQAAAnw"]
[Tue Aug 18 12:53:47.812627 2026] [security2:error] [pid 67073:tid 67257] [client 20.171.51.14:43386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/zy.php"] [unique_id "aoSAC_cmepr5_nHgLbMxIgAAAkg"]
[Tue Aug 18 12:53:47.819769 2026] [security2:error] [pid 66623:tid 66891] [client 158.158.74.177:25859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSAC9O5rbWdOArH04J8oQAAAYc"]
[Tue Aug 18 12:53:47.831378 2026] [security2:error] [pid 66623:tid 66803] [client 20.51.153.15:13387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/new2.php"] [unique_id "aoSAC9O5rbWdOArH04J8ogAAAS8"]
[Tue Aug 18 12:53:47.831578 2026] [security2:error] [pid 66623:tid 66884] [client 20.118.172.148:45262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAC9O5rbWdOArH04J8owAAAYA"]
[Tue Aug 18 12:53:47.845702 2026] [security2:error] [pid 67073:tid 67267] [client 74.248.18.37:35912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/x.php"] [unique_id "aoSAC_cmepr5_nHgLbMxIwAAAlI"]
[Tue Aug 18 12:53:47.902438 2026] [security2:error] [pid 66623:tid 66842] [client 74.248.136.165:59917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSAC9O5rbWdOArH04J8pAAAAVY"]
[Tue Aug 18 12:53:47.946688 2026] [security2:error] [pid 67073:tid 67259] [client 158.23.17.4:60768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/gy.php"] [unique_id "aoSAC_cmepr5_nHgLbMxJwAAAko"]
[Tue Aug 18 12:53:47.981258 2026] [security2:error] [pid 67073:tid 67297] [client 20.226.56.190:17958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/te.php"] [unique_id "aoSAC_cmepr5_nHgLbMxKwAAAnA"]
[Tue Aug 18 12:53:47.981820 2026] [security2:error] [pid 67073:tid 67230] [client 4.223.164.152:54243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/imageskir.php"] [unique_id "aoSAC_cmepr5_nHgLbMxLAAAAi0"]
[Tue Aug 18 12:53:48.013178 2026] [security2:error] [pid 67073:tid 67277] [client 172.202.39.151:21824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-admin/network/index.php"] [unique_id "aoSADPcmepr5_nHgLbMxLQAAAlw"]
[Tue Aug 18 12:53:48.052796 2026] [security2:error] [pid 67073:tid 67296] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSADPcmepr5_nHgLbMxLwAAAm8"]
[Tue Aug 18 12:53:48.066588 2026] [security2:error] [pid 67073:tid 67228] [client 20.51.153.15:13419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/rex.php"] [unique_id "aoSADPcmepr5_nHgLbMxMAAAAis"]
[Tue Aug 18 12:53:48.086382 2026] [security2:error] [pid 66623:tid 66778] [client 20.250.13.23:23866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/term.php"] [unique_id "aoSADNO5rbWdOArH04J8pwAAARY"]
[Tue Aug 18 12:53:48.104408 2026] [security2:error] [pid 66623:tid 66825] [client 138.36.100.162:42976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAC9O5rbWdOArH04J8nwAAAUU"]
[Tue Aug 18 12:53:48.138656 2026] [security2:error] [pid 67073:tid 67322] [client 172.202.39.151:21873] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.formedesign.com.br"] [uri "/1.php"] [unique_id "aoSADPcmepr5_nHgLbMxNgAAAok"]
[Tue Aug 18 12:53:48.138774 2026] [security2:error] [pid 67073:tid 67322] [client 172.202.39.151:21873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/1.php"] [unique_id "aoSADPcmepr5_nHgLbMxNgAAAok"]
[Tue Aug 18 12:53:48.144047 2026] [security2:error] [pid 67073:tid 67258] [client 20.48.236.86:16332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/sf.php"] [unique_id "aoSADPcmepr5_nHgLbMxOAAAAkk"]
[Tue Aug 18 12:53:48.152373 2026] [security2:error] [pid 67073:tid 67237] [client 132.196.61.152:56112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSADPcmepr5_nHgLbMxOgAAAjQ"]
[Tue Aug 18 12:53:48.181908 2026] [security2:error] [pid 67073:tid 67308] [client 20.91.215.254:20181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/goat.php"] [unique_id "aoSADPcmepr5_nHgLbMxOwAAAns"]
[Tue Aug 18 12:53:48.186462 2026] [security2:error] [pid 67073:tid 67316] [client 52.238.210.254:10169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/nc4.php"] [unique_id "aoSADPcmepr5_nHgLbMxPAAAAoM"]
[Tue Aug 18 12:53:48.246880 2026] [security2:error] [pid 67073:tid 67269] [client 20.48.236.86:11041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSADPcmepr5_nHgLbMxPgAAAlQ"]
[Tue Aug 18 12:53:48.261138 2026] [security2:error] [pid 67073:tid 67266] [client 20.104.100.201:53831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/special.php"] [unique_id "aoSADPcmepr5_nHgLbMxPwAAAlE"]
[Tue Aug 18 12:53:48.320796 2026] [security2:error] [pid 67073:tid 67274] [client 74.248.136.165:53467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/z.php"] [unique_id "aoSADPcmepr5_nHgLbMxRAAAAlk"]
[Tue Aug 18 12:53:48.326554 2026] [security2:error] [pid 67073:tid 67211] [client 20.51.153.15:13361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/verification.php"] [unique_id "aoSADPcmepr5_nHgLbMxRQAAAho"]
[Tue Aug 18 12:53:48.344887 2026] [security2:error] [pid 66623:tid 66780] [client 52.173.121.69:43897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/well-known/index.php"] [unique_id "aoSADNO5rbWdOArH04J8qQAAARg"]
[Tue Aug 18 12:53:48.373492 2026] [security2:error] [pid 67073:tid 67215] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/nox.php"] [unique_id "aoSADPcmepr5_nHgLbMxRwAAAh4"]
[Tue Aug 18 12:53:48.416629 2026] [security2:error] [pid 67073:tid 67283] [client 74.248.136.165:51159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/path.php"] [unique_id "aoSADPcmepr5_nHgLbMxSgAAAmI"]
[Tue Aug 18 12:53:48.424622 2026] [security2:error] [pid 67073:tid 67206] [client 20.171.51.14:31635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/jl.php"] [unique_id "aoSADPcmepr5_nHgLbMxTAAAAhU"]
[Tue Aug 18 12:53:48.433316 2026] [security2:error] [pid 67073:tid 67280] [client 4.223.164.152:46163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/indexo.php"] [unique_id "aoSADPcmepr5_nHgLbMxTQAAAl8"]
[Tue Aug 18 12:53:48.456704 2026] [security2:error] [pid 67073:tid 67325] [client 20.163.43.14:3077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/gecko.php"] [unique_id "aoSADPcmepr5_nHgLbMxTgAAAow"]
[Tue Aug 18 12:53:48.478411 2026] [security2:error] [pid 66623:tid 66799] [client 157.20.138.62:51812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSADNO5rbWdOArH04J8qwAAASs"]
[Tue Aug 18 12:53:48.478513 2026] [security2:error] [pid 66623:tid 66799] [client 157.20.138.62:51812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSADNO5rbWdOArH04J8qwAAASs"]
[Tue Aug 18 12:53:48.498739 2026] [security2:error] [pid 67073:tid 67218] [client 20.48.236.86:16329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/k.php"] [unique_id "aoSADPcmepr5_nHgLbMxUQAAAiE"]
[Tue Aug 18 12:53:48.508074 2026] [security2:error] [pid 67073:tid 67124] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/z.php"] [unique_id "aoSADPcmepr5_nHgLbMxUgACJjA"]
[Tue Aug 18 12:53:48.531701 2026] [security2:error] [pid 67073:tid 67242] [client 20.226.56.190:17886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ie.php"] [unique_id "aoSADPcmepr5_nHgLbMxVAAAAjk"]
[Tue Aug 18 12:53:48.542655 2026] [security2:error] [pid 67073:tid 67317] [client 20.171.51.14:16715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/q.php"] [unique_id "aoSADPcmepr5_nHgLbMxVQAAAoQ"]
[Tue Aug 18 12:53:48.551603 2026] [security2:error] [pid 66623:tid 66779] [client 158.158.74.177:9518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-2019.php"] [unique_id "aoSADNO5rbWdOArH04J8rAAAARc"]
[Tue Aug 18 12:53:48.570624 2026] [security2:error] [pid 66623:tid 66839] [client 135.225.75.187:23167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/Okxob.php"] [unique_id "aoSADNO5rbWdOArH04J8rQAAAVM"]
[Tue Aug 18 12:53:48.592924 2026] [security2:error] [pid 66623:tid 66837] [client 20.51.153.15:2017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/smtp.php"] [unique_id "aoSADNO5rbWdOArH04J8rgAAAVE"]
[Tue Aug 18 12:53:48.605945 2026] [security2:error] [pid 67073:tid 67315] [client 172.202.39.151:44465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/bb.php"] [unique_id "aoSADPcmepr5_nHgLbMxWAAAAoI"]
[Tue Aug 18 12:53:48.610477 2026] [security2:error] [pid 66623:tid 66866] [client 20.226.56.190:45194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/kc.php"] [unique_id "aoSADNO5rbWdOArH04J8rwAAAW4"]
[Tue Aug 18 12:53:48.625657 2026] [authz_core:error] [pid 67073:tid 67123] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:48.625939 2026] [authz_core:error] [pid 67073:tid 67123] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:48.658012 2026] [security2:error] [pid 67073:tid 67261] [client 158.23.17.4:15135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/tt.php"] [unique_id "aoSADPcmepr5_nHgLbMxXgAAAkw"]
[Tue Aug 18 12:53:48.667919 2026] [security2:error] [pid 66623:tid 66811] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/rezor.php"] [unique_id "aoSADNO5rbWdOArH04J8sAAAATc"]
[Tue Aug 18 12:53:48.671012 2026] [security2:error] [pid 67073:tid 67229] [client 4.223.164.152:6647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/zoo1.php"] [unique_id "aoSADPcmepr5_nHgLbMxXwAAAiw"]
[Tue Aug 18 12:53:48.679204 2026] [security2:error] [pid 67073:tid 67235] [client 213.35.127.232:55879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSADPcmepr5_nHgLbMxYwAAAjI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:48.680097 2026] [security2:error] [pid 67073:tid 67126] [remote 34.62.54.143:47708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.env"] [unique_id "aoSADPcmepr5_nHgLbMxYgACczI"]
[Tue Aug 18 12:53:48.690805 2026] [security2:error] [pid 67073:tid 67138] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/222.php"] [unique_id "aoSADPcmepr5_nHgLbMxaAACOz4"]
[Tue Aug 18 12:53:48.738738 2026] [security2:error] [pid 66623:tid 66777] [client 74.248.136.165:50889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/222.php"] [unique_id "aoSADNO5rbWdOArH04J8sQAAARU"]
[Tue Aug 18 12:53:48.741173 2026] [security2:error] [pid 67073:tid 67264] [client 132.196.61.152:56100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/sky.php"] [unique_id "aoSADPcmepr5_nHgLbMxawAAAk8"]
[Tue Aug 18 12:53:48.827930 2026] [security2:error] [pid 66623:tid 66836] [client 20.42.19.40:2210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-blink.php"] [unique_id "aoSADNO5rbWdOArH04J8sgAAAVA"]
[Tue Aug 18 12:53:48.839808 2026] [security2:error] [pid 66623:tid 66879] [client 52.238.210.254:10205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/as.php"] [unique_id "aoSADNO5rbWdOArH04J8swAAAXs"]
[Tue Aug 18 12:53:48.853678 2026] [security2:error] [pid 66623:tid 66853] [client 20.91.215.254:20192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/Session.php"] [unique_id "aoSADNO5rbWdOArH04J8tAAAAWE"]
[Tue Aug 18 12:53:48.854426 2026] [security2:error] [pid 67073:tid 67282] [client 4.223.164.152:64699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSADPcmepr5_nHgLbMxcAAAAmE"]
[Tue Aug 18 12:53:48.904146 2026] [security2:error] [pid 67073:tid 67330] [client 20.51.153.15:13340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/teste.php"] [unique_id "aoSADPcmepr5_nHgLbMxcwAAApE"]
[Tue Aug 18 12:53:48.928398 2026] [authz_core:error] [pid 67073:tid 67132] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:48.928663 2026] [authz_core:error] [pid 67073:tid 67132] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:48.977320 2026] [security2:error] [pid 66623:tid 66808] [client 40.85.222.29:37705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSADNO5rbWdOArH04J8tQAAATQ"]
[Tue Aug 18 12:53:48.978750 2026] [security2:error] [pid 67073:tid 67243] [client 20.226.56.190:52057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/nw.php"] [unique_id "aoSADPcmepr5_nHgLbMxfAAAAjo"]
[Tue Aug 18 12:53:48.992558 2026] [security2:error] [pid 67073:tid 67253] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSADPcmepr5_nHgLbMxfQAAAkQ"]
[Tue Aug 18 12:53:48.993100 2026] [security2:error] [pid 66623:tid 66889] [client 20.65.98.162:23910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/scxy.php"] [unique_id "aoSADNO5rbWdOArH04J8tgAAAYU"]
[Tue Aug 18 12:53:49.018713 2026] [security2:error] [pid 67073:tid 67212] [client 20.104.100.201:53871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSADfcmepr5_nHgLbMxgQAAAhs"]
[Tue Aug 18 12:53:49.046631 2026] [security2:error] [pid 67073:tid 67322] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/akismet.php"] [unique_id "aoSADfcmepr5_nHgLbMxhQAAAok"]
[Tue Aug 18 12:53:49.050918 2026] [security2:error] [pid 66623:tid 66855] [client 20.48.236.86:16323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/82.php"] [unique_id "aoSADdO5rbWdOArH04J8uAAAAWM"]
[Tue Aug 18 12:53:49.072996 2026] [security2:error] [pid 67073:tid 67260] [client 74.248.18.37:38465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/index/function.php"] [unique_id "aoSADfcmepr5_nHgLbMxhgAAAks"]
[Tue Aug 18 12:53:49.102703 2026] [security2:error] [pid 67073:tid 67237] [client 20.171.51.14:59327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/xf.php"] [unique_id "aoSADfcmepr5_nHgLbMxigAAAjQ"]
[Tue Aug 18 12:53:49.103747 2026] [security2:error] [pid 67073:tid 67233] [client 20.171.51.14:51824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/tq.php"] [unique_id "aoSADfcmepr5_nHgLbMxiwAAAjA"]
[Tue Aug 18 12:53:49.158234 2026] [security2:error] [pid 67073:tid 67241] [client 74.248.136.165:58338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/G-in.php"] [unique_id "aoSADfcmepr5_nHgLbMxkwAAAjg"]
[Tue Aug 18 12:53:49.158418 2026] [security2:error] [pid 67073:tid 67158] [remote 34.62.54.143:47708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transevang.com.br"] [uri "/wp-login.php"] [unique_id "aoSADfcmepr5_nHgLbMxlAACTlI"], referer: https://transevang.com.br/login
[Tue Aug 18 12:53:49.179921 2026] [security2:error] [pid 67073:tid 67310] [client 20.51.153.15:13413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/local.php"] [unique_id "aoSADfcmepr5_nHgLbMxlQAAAn0"]
[Tue Aug 18 12:53:49.186702 2026] [security2:error] [pid 67073:tid 67288] [client 158.158.74.177:25893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/cjfuns.php"] [unique_id "aoSADfcmepr5_nHgLbMxmAAAAmc"]
[Tue Aug 18 12:53:49.195228 2026] [security2:error] [pid 67073:tid 67281] [client 20.163.43.14:3143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/aa.php"] [unique_id "aoSADfcmepr5_nHgLbMxmgAAAmA"]
[Tue Aug 18 12:53:49.221934 2026] [security2:error] [pid 67073:tid 67222] [client 132.196.61.152:55335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/file5.php"] [unique_id "aoSADfcmepr5_nHgLbMxoAAAAiU"]
[Tue Aug 18 12:53:49.223350 2026] [security2:error] [pid 67073:tid 67286] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSADfcmepr5_nHgLbMxjQACZTY"]
[Tue Aug 18 12:53:49.228296 2026] [security2:error] [pid 67073:tid 67266] [client 20.42.19.40:2701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/xfun.php"] [unique_id "aoSADfcmepr5_nHgLbMxogAAAlE"]
[Tue Aug 18 12:53:49.228346 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:49.228631 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:49.273111 2026] [security2:error] [pid 66623:tid 66867] [client 20.226.56.190:20875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/jn.php"] [unique_id "aoSADdO5rbWdOArH04J8uQAAAW8"]
[Tue Aug 18 12:53:49.275080 2026] [security2:error] [pid 67073:tid 67227] [client 4.223.164.152:28486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSADfcmepr5_nHgLbMxowAAAio"]
[Tue Aug 18 12:53:49.296480 2026] [security2:error] [pid 67073:tid 67208] [client 52.238.210.254:10162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/k.php"] [unique_id "aoSADfcmepr5_nHgLbMxpAAAAhc"]
[Tue Aug 18 12:53:49.302997 2026] [security2:error] [pid 66623:tid 66850] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSADdO5rbWdOArH04J8ugAAAV4"]
[Tue Aug 18 12:53:49.326958 2026] [security2:error] [pid 66623:tid 66795] [client 20.226.56.190:47154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/sb.php"] [unique_id "aoSADdO5rbWdOArH04J8uwAAASc"]
[Tue Aug 18 12:53:49.352536 2026] [security2:error] [pid 67073:tid 67285] [client 4.223.164.152:6632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/zoo2.php"] [unique_id "aoSADfcmepr5_nHgLbMxpgAAAmQ"]
[Tue Aug 18 12:53:49.358986 2026] [security2:error] [pid 67073:tid 67294] [client 104.209.144.33:34129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSADfcmepr5_nHgLbMxpwAAAm0"]
[Tue Aug 18 12:53:49.387088 2026] [security2:error] [pid 67073:tid 67273] [client 158.23.17.4:57074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/mq.php"] [unique_id "aoSADfcmepr5_nHgLbMxqAAAAlg"]
[Tue Aug 18 12:53:49.427550 2026] [security2:error] [pid 66623:tid 66831] [client 20.51.153.15:13403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/wp_sitting.php"] [unique_id "aoSADdO5rbWdOArH04J8vAAAAUs"]
[Tue Aug 18 12:53:49.494586 2026] [security2:error] [pid 66623:tid 66838] [client 20.91.215.254:9103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSADdO5rbWdOArH04J8vQAAAVI"]
[Tue Aug 18 12:53:49.516813 2026] [security2:error] [pid 67073:tid 67210] [client 143.244.161.13:50956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "stampi.ind.br"] [uri "/.env"] [unique_id "aoSADfcmepr5_nHgLbMxrQAAAhk"]
[Tue Aug 18 12:53:49.528318 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:49.528582 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:49.546037 2026] [security2:error] [pid 67073:tid 67315] [client 135.225.75.187:32971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/file59.php"] [unique_id "aoSADfcmepr5_nHgLbMxrwAAAoI"]
[Tue Aug 18 12:53:49.547600 2026] [security2:error] [pid 67073:tid 67254] [client 20.163.43.14:3157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/0x.php"] [unique_id "aoSADfcmepr5_nHgLbMxsAAAAkU"]
[Tue Aug 18 12:53:49.562975 2026] [security2:error] [pid 67073:tid 67265] [client 20.171.51.14:14979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/cv.php"] [unique_id "aoSADfcmepr5_nHgLbMxsQAAAlA"]
[Tue Aug 18 12:53:49.575820 2026] [security2:error] [pid 67073:tid 67231] [client 74.248.136.165:19307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/xxx.php"] [unique_id "aoSADfcmepr5_nHgLbMxswAAAi4"]
[Tue Aug 18 12:53:49.587983 2026] [security2:error] [pid 66623:tid 66827] [client 20.226.56.190:52083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/xj.php"] [unique_id "aoSADdO5rbWdOArH04J8vgAAAUc"]
[Tue Aug 18 12:53:49.604830 2026] [security2:error] [pid 67073:tid 67199] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/G-in.php"] [unique_id "aoSADfcmepr5_nHgLbMxtQACans"]
[Tue Aug 18 12:53:49.676202 2026] [security2:error] [pid 67073:tid 67279] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/index/function.php"] [unique_id "aoSADfcmepr5_nHgLbMxtwAAAl4"]
[Tue Aug 18 12:53:49.685400 2026] [security2:error] [pid 67073:tid 67289] [client 20.226.56.190:40137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/bf.php"] [unique_id "aoSADfcmepr5_nHgLbMxuQAAAmg"]
[Tue Aug 18 12:53:49.690193 2026] [security2:error] [pid 67073:tid 67221] [client 172.202.39.151:62695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSADfcmepr5_nHgLbMxugAAAiQ"]
[Tue Aug 18 12:53:49.694469 2026] [security2:error] [pid 67073:tid 67292] [client 20.51.153.15:13370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/ninja.php"] [unique_id "aoSADfcmepr5_nHgLbMxuwAAAms"]
[Tue Aug 18 12:53:49.694494 2026] [security2:error] [pid 66623:tid 66802] [client 213.35.127.232:56091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSADdO5rbWdOArH04J8vwAAAS4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:53:49.720002 2026] [security2:error] [pid 67073:tid 67235] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/admin.php"] [unique_id "aoSADfcmepr5_nHgLbMxwgAAAjI"]
[Tue Aug 18 12:53:49.722497 2026] [security2:error] [pid 67073:tid 67269] [client 149.34.210.141:59032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSADfcmepr5_nHgLbMxwwAAAlQ"]
[Tue Aug 18 12:53:49.728840 2026] [security2:error] [pid 67073:tid 67244] [client 4.223.164.152:54271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/.admin.php"] [unique_id "aoSADfcmepr5_nHgLbMxxQAAAjs"]
[Tue Aug 18 12:53:49.737770 2026] [security2:error] [pid 67073:tid 67213] [client 52.238.210.254:10191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSADfcmepr5_nHgLbMxxgAAAhw"]
[Tue Aug 18 12:53:49.741074 2026] [security2:error] [pid 66623:tid 66815] [client 20.171.51.14:15799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/gb.php"] [unique_id "aoSADdO5rbWdOArH04J8wAAAATs"]
[Tue Aug 18 12:53:49.746610 2026] [security2:error] [pid 67073:tid 67198] [remote 34.62.54.143:47708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.env.bak"] [unique_id "aoSADfcmepr5_nHgLbMxyAACbHo"]
[Tue Aug 18 12:53:49.746620 2026] [security2:error] [pid 67073:tid 67080] [remote 34.62.54.143:47708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.env.backup"] [unique_id "aoSADfcmepr5_nHgLbMxxwACbAQ"]
[Tue Aug 18 12:53:49.746816 2026] [security2:error] [pid 67073:tid 67191] [remote 34.62.54.143:47708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.env.old"] [unique_id "aoSADfcmepr5_nHgLbMxyQACbHM"]
[Tue Aug 18 12:53:49.782565 2026] [security2:error] [pid 66623:tid 66877] [client 132.196.61.152:56117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/xyn.php"] [unique_id "aoSADdO5rbWdOArH04J8wgAAAXk"]
[Tue Aug 18 12:53:49.789831 2026] [security2:error] [pid 67073:tid 67190] [remote 34.62.54.143:47708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transevang.com.br"] [uri "/wp-login.php"] [unique_id "aoSADfcmepr5_nHgLbMxygACbHI"], referer: https://transevang.com.br/wp-admin/
[Tue Aug 18 12:53:49.790053 2026] [security2:error] [pid 67073:tid 67177] [remote 34.62.54.143:47708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transevang.com.br"] [uri "/wp-login.php"] [unique_id "aoSADfcmepr5_nHgLbMxywACbGU"], referer: https://transevang.com.br/wp-admin/
[Tue Aug 18 12:53:49.812445 2026] [security2:error] [pid 67073:tid 67264] [client 20.104.85.180:43524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSADfcmepr5_nHgLbMxzAAAAk8"]
[Tue Aug 18 12:53:49.822330 2026] [security2:error] [pid 67073:tid 67200] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/xxx.php"] [unique_id "aoSADfcmepr5_nHgLbMxzQACfHw"]
[Tue Aug 18 12:53:49.893064 2026] [security2:error] [pid 66623:tid 66822] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSADdO5rbWdOArH04J8wwAAAUI"]
[Tue Aug 18 12:53:49.902997 2026] [security2:error] [pid 67073:tid 67276] [client 158.158.74.177:9507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSADfcmepr5_nHgLbMxzwAAAls"]
[Tue Aug 18 12:53:49.992638 2026] [security2:error] [pid 66623:tid 66890] [client 74.248.136.165:53351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/un.php"] [unique_id "aoSADdO5rbWdOArH04J8xAAAAYY"]
[Tue Aug 18 12:53:50.022466 2026] [security2:error] [pid 66623:tid 66824] [client 20.226.6.191:6647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/gelay.php"] [unique_id "aoSADtO5rbWdOArH04J8xQAAAUQ"]
[Tue Aug 18 12:53:50.026637 2026] [security2:error] [pid 67073:tid 67269] [client 149.34.210.141:59032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSADfcmepr5_nHgLbMxwwAAAlQ"]
[Tue Aug 18 12:53:50.071083 2026] [security2:error] [pid 66623:tid 66833] [client 20.51.153.15:13344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/phpprobe.php"] [unique_id "aoSADtO5rbWdOArH04J8xgAAAU0"]
[Tue Aug 18 12:53:50.083799 2026] [security2:error] [pid 66623:tid 66814] [client 20.48.236.86:65108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/inso.php"] [unique_id "aoSADtO5rbWdOArH04J8xwAAATo"]
[Tue Aug 18 12:53:50.086497 2026] [security2:error] [pid 67073:tid 67236] [client 20.226.56.190:28267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ns.php"] [unique_id "aoSADvcmepr5_nHgLbMx0wAAAjM"]
[Tue Aug 18 12:53:50.130991 2026] [security2:error] [pid 67073:tid 67220] [client 20.104.85.180:18838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/about.php"] [unique_id "aoSADvcmepr5_nHgLbMx1AAAAiM"]
[Tue Aug 18 12:53:50.339879 2026] [security2:error] [pid 67073:tid 67228] [client 20.171.51.14:43330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/jp.php"] [unique_id "aoSADvcmepr5_nHgLbMx1QAAAis"]
[Tue Aug 18 12:53:50.421421 2026] [security2:error] [pid 67073:tid 67313] [client 4.232.151.198:48235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSADvcmepr5_nHgLbMx1gAAAoA"]
[Tue Aug 18 12:53:50.476950 2026] [security2:error] [pid 67073:tid 67251] [client 20.104.100.201:17351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/thoms.php"] [unique_id "aoSADvcmepr5_nHgLbMx1wAAAkI"]
[Tue Aug 18 12:53:50.560583 2026] [security2:error] [pid 67073:tid 67311] [client 20.48.236.86:16362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/dex.php"] [unique_id "aoSADvcmepr5_nHgLbMx2AAAAn4"]
[Tue Aug 18 12:53:50.588862 2026] [security2:error] [pid 67073:tid 67272] [client 20.163.43.14:3161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/zxz.php"] [unique_id "aoSADvcmepr5_nHgLbMx2QAAAlc"]
[Tue Aug 18 12:53:50.631626 2026] [security2:error] [pid 67073:tid 67327] [client 158.23.17.4:17571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/13.php"] [unique_id "aoSADvcmepr5_nHgLbMx2gAAAo4"]
[Tue Aug 18 12:53:50.670987 2026] [security2:error] [pid 67073:tid 67258] [client 52.238.210.254:10133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/system_log.php"] [unique_id "aoSADvcmepr5_nHgLbMx2wAAAkk"]
[Tue Aug 18 12:53:50.726861 2026] [authz_core:error] [pid 67073:tid 67076] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:50.727129 2026] [authz_core:error] [pid 67073:tid 67076] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:50.770021 2026] [security2:error] [pid 67073:tid 67316] [client 20.171.51.14:59291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/un.php"] [unique_id "aoSADvcmepr5_nHgLbMx3QAAAoM"]
[Tue Aug 18 12:53:50.772777 2026] [security2:error] [pid 67073:tid 67290] [client 135.225.75.187:9462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/eauu.php"] [unique_id "aoSADvcmepr5_nHgLbMx3gAAAmk"]
[Tue Aug 18 12:53:50.807680 2026] [security2:error] [pid 67073:tid 67226] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSADvcmepr5_nHgLbMx3wAAAik"]
[Tue Aug 18 12:53:50.829105 2026] [security2:error] [pid 67073:tid 67207] [client 20.65.98.162:18926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/ws13.php"] [unique_id "aoSADvcmepr5_nHgLbMx4AAAAhY"]
[Tue Aug 18 12:53:50.878438 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:50.878717 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:50.946311 2026] [security2:error] [pid 66623:tid 66800] [client 20.100.169.31:47511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.julioalvez.com.br"] [uri "/adminfuns.php"] [unique_id "aoSADtO5rbWdOArH04J8yQAAASw"]
[Tue Aug 18 12:53:51.015213 2026] [security2:error] [pid 67073:tid 67266] [client 20.171.51.14:16731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/eq.php"] [unique_id "aoSAD_cmepr5_nHgLbMx4gAAAlE"]
[Tue Aug 18 12:53:51.043286 2026] [security2:error] [pid 67073:tid 67248] [client 20.48.236.86:16263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/puc.php"] [unique_id "aoSAD_cmepr5_nHgLbMx4wAAAj8"]
[Tue Aug 18 12:53:51.052888 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:51.053139 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:51.059061 2026] [security2:error] [pid 66623:tid 66798] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSAD9O5rbWdOArH04J8ygAAASo"]
[Tue Aug 18 12:53:51.159496 2026] [security2:error] [pid 67073:tid 67281] [client 158.158.74.177:9382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSAD_cmepr5_nHgLbMx5gAAAmA"]
[Tue Aug 18 12:53:51.160874 2026] [security2:error] [pid 67073:tid 67268] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/themes.php"] [unique_id "aoSAD_cmepr5_nHgLbMx5wAAAlM"]
[Tue Aug 18 12:53:51.188664 2026] [security2:error] [pid 66623:tid 66769] [client 52.238.210.254:30369] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/1.php"] [unique_id "aoSAD9O5rbWdOArH04J8ywAAAQ0"]
[Tue Aug 18 12:53:51.188758 2026] [security2:error] [pid 66623:tid 66769] [client 52.238.210.254:30369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/1.php"] [unique_id "aoSAD9O5rbWdOArH04J8ywAAAQ0"]
[Tue Aug 18 12:53:51.255829 2026] [security2:error] [pid 67073:tid 67245] [client 157.51.166.53:51940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAD_cmepr5_nHgLbMx6AAAAjw"]
[Tue Aug 18 12:53:51.255945 2026] [security2:error] [pid 67073:tid 67245] [client 157.51.166.53:51940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAD_cmepr5_nHgLbMx6AAAAjw"]
[Tue Aug 18 12:53:51.265692 2026] [security2:error] [pid 66623:tid 66876] [client 20.51.153.15:13347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/wp-title.php"] [unique_id "aoSAD9O5rbWdOArH04J8zAAAAXg"]
[Tue Aug 18 12:53:51.474441 2026] [security2:error] [pid 66623:tid 66774] [client 74.248.136.165:36376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/autogooey.php"] [unique_id "aoSAD9O5rbWdOArH04J8zQAAARI"]
[Tue Aug 18 12:53:51.480879 2026] [security2:error] [pid 66623:tid 66845] [client 20.104.85.180:18857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSAD9O5rbWdOArH04J8zgAAAVk"]
[Tue Aug 18 12:53:51.527208 2026] [security2:error] [pid 66623:tid 66781] [client 4.223.164.152:64687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wsomini.php"] [unique_id "aoSAD9O5rbWdOArH04J8zwAAARk"]
[Tue Aug 18 12:53:51.605922 2026] [security2:error] [pid 67073:tid 67175] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/un.php"] [unique_id "aoSAD_cmepr5_nHgLbMx8wACQ2M"]
[Tue Aug 18 12:53:51.620431 2026] [security2:error] [pid 67073:tid 67263] [client 20.48.236.86:16361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/inso.php"] [unique_id "aoSAD_cmepr5_nHgLbMx9QAAAk4"]
[Tue Aug 18 12:53:51.648214 2026] [security2:error] [pid 67073:tid 67249] [client 20.91.215.254:9088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/abcd.php"] [unique_id "aoSAD_cmepr5_nHgLbMx9gAAAkA"]
[Tue Aug 18 12:53:51.659662 2026] [security2:error] [pid 66623:tid 66796] [client 4.232.151.198:27770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/vx.php"] [unique_id "aoSAD9O5rbWdOArH04J80AAAASg"]
[Tue Aug 18 12:53:51.829811 2026] [security2:error] [pid 66623:tid 66791] [client 158.23.17.4:51157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/so.php"] [unique_id "aoSAD9O5rbWdOArH04J80wAAASM"]
[Tue Aug 18 12:53:52.031754 2026] [security2:error] [pid 66623:tid 66891] [client 104.209.144.33:20430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAENO5rbWdOArH04J81gAAAYc"]
[Tue Aug 18 12:53:52.118034 2026] [security2:error] [pid 67073:tid 67280] [client 20.48.236.86:16266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/aa.php"] [unique_id "aoSAEPcmepr5_nHgLbMx-gAAAl8"]
[Tue Aug 18 12:53:52.162234 2026] [security2:error] [pid 67073:tid 67303] [client 52.238.210.254:10146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/x.php"] [unique_id "aoSAEPcmepr5_nHgLbMx_AAAAnY"]
[Tue Aug 18 12:53:52.362812 2026] [security2:error] [pid 67073:tid 67331] [client 172.202.39.151:36376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSAEPcmepr5_nHgLbMx_QAAApI"]
[Tue Aug 18 12:53:52.417537 2026] [security2:error] [pid 67073:tid 67324] [client 172.202.39.151:49637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/k.php"] [unique_id "aoSAEPcmepr5_nHgLbMx_wAAAos"]
[Tue Aug 18 12:53:52.489203 2026] [security2:error] [pid 67073:tid 67254] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/bajah.php"] [unique_id "aoSAEPcmepr5_nHgLbMyAAAAAkU"]
[Tue Aug 18 12:53:52.489423 2026] [security2:error] [pid 67073:tid 67265] [client 20.171.51.14:62465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ep.php"] [unique_id "aoSAEPcmepr5_nHgLbMyAgAAAlA"]
[Tue Aug 18 12:53:52.489661 2026] [security2:error] [pid 67073:tid 67317] [client 20.226.56.190:28261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gk.php"] [unique_id "aoSAEPcmepr5_nHgLbMyAQAAAoQ"]
[Tue Aug 18 12:53:52.512232 2026] [security2:error] [pid 67073:tid 67291] [client 20.51.153.15:2000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/styles.php"] [unique_id "aoSAEPcmepr5_nHgLbMyAwAAAmo"]
[Tue Aug 18 12:53:52.515566 2026] [security2:error] [pid 67073:tid 67217] [client 74.248.136.165:53449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/sty.php"] [unique_id "aoSAEPcmepr5_nHgLbMyBAAAAiA"]
[Tue Aug 18 12:53:52.568209 2026] [security2:error] [pid 67073:tid 67279] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/cv.php"] [unique_id "aoSAEPcmepr5_nHgLbMyBQAAAl4"]
[Tue Aug 18 12:53:52.635886 2026] [security2:error] [pid 67073:tid 67292] [client 20.226.56.190:47155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/wn.php"] [unique_id "aoSAEPcmepr5_nHgLbMyBgAAAms"]
[Tue Aug 18 12:53:52.736324 2026] [security2:error] [pid 67073:tid 67273] [client 158.158.74.177:9486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/import.php"] [unique_id "aoSAEPcmepr5_nHgLbMyCAAAAlg"]
[Tue Aug 18 12:53:52.805660 2026] [security2:error] [pid 66623:tid 66881] [client 160.120.140.123:53378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAENO5rbWdOArH04J84QAAAX0"]
[Tue Aug 18 12:53:52.805791 2026] [security2:error] [pid 66623:tid 66881] [client 160.120.140.123:53378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAENO5rbWdOArH04J84QAAAX0"]
[Tue Aug 18 12:53:52.824571 2026] [security2:error] [pid 67073:tid 67264] [client 20.51.153.15:13367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/server.php"] [unique_id "aoSAEPcmepr5_nHgLbMyCQAAAk8"]
[Tue Aug 18 12:53:52.842941 2026] [security2:error] [pid 67073:tid 67309] [client 20.104.85.180:18843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/f35.php"] [unique_id "aoSAEPcmepr5_nHgLbMyCgAAAnw"]
[Tue Aug 18 12:53:52.933425 2026] [security2:error] [pid 67073:tid 67205] [client 52.238.210.254:10203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/autoload_classmap.php"] [unique_id "aoSAEPcmepr5_nHgLbMyCwAAAhQ"]
[Tue Aug 18 12:53:52.988981 2026] [security2:error] [pid 67073:tid 67089] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/autogooey.php"] [unique_id "aoSAEPcmepr5_nHgLbMyDAACWw0"]
[Tue Aug 18 12:53:53.056895 2026] [security2:error] [pid 67073:tid 67259] [client 20.226.6.191:6543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAEfcmepr5_nHgLbMyDQAAAko"]
[Tue Aug 18 12:53:53.152995 2026] [security2:error] [pid 66623:tid 66885] [client 20.42.19.40:2199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/p.php"] [unique_id "aoSAEdO5rbWdOArH04J84gAAAYE"]
[Tue Aug 18 12:53:53.180677 2026] [security2:error] [pid 66623:tid 66780] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/ajax.php"] [unique_id "aoSAEdO5rbWdOArH04J84wAAARg"]
[Tue Aug 18 12:53:53.210949 2026] [security2:error] [pid 66623:tid 66768] [client 20.51.153.15:13409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/xinfo.php"] [unique_id "aoSAEdO5rbWdOArH04J85AAAAQw"]
[Tue Aug 18 12:53:53.211699 2026] [security2:error] [pid 67073:tid 67218] [client 20.91.215.254:20190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/kj.php"] [unique_id "aoSAEfcmepr5_nHgLbMyFwAAAiE"]
[Tue Aug 18 12:53:53.289677 2026] [security2:error] [pid 66623:tid 66783] [client 20.104.100.201:54048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSAEdO5rbWdOArH04J85QAAARs"]
[Tue Aug 18 12:53:53.377344 2026] [security2:error] [pid 67073:tid 67284] [client 4.223.164.152:37284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/vr.php"] [unique_id "aoSAEfcmepr5_nHgLbMyGQAAAmM"]
[Tue Aug 18 12:53:53.410599 2026] [security2:error] [pid 66623:tid 66835] [client 20.65.98.162:21540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/btx25.php"] [unique_id "aoSAEdO5rbWdOArH04J85gAAAU8"]
[Tue Aug 18 12:53:53.573553 2026] [security2:error] [pid 66623:tid 66779] [client 74.248.133.44:15359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/f5.php"] [unique_id "aoSAEdO5rbWdOArH04J86gAAARc"]
[Tue Aug 18 12:53:53.582274 2026] [security2:error] [pid 67073:tid 67194] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/sty.php"] [unique_id "aoSAEfcmepr5_nHgLbMyHAACgHY"]
[Tue Aug 18 12:53:53.620849 2026] [security2:error] [pid 67073:tid 67238] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/Cachex.php"] [unique_id "aoSAEfcmepr5_nHgLbMyHQAAAjU"]
[Tue Aug 18 12:53:53.689982 2026] [security2:error] [pid 67073:tid 67297] [client 20.42.19.40:2732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAEfcmepr5_nHgLbMyHwAAAnA"]
[Tue Aug 18 12:53:53.692657 2026] [security2:error] [pid 67073:tid 67272] [client 20.118.172.148:15361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/0x.php"] [unique_id "aoSAEfcmepr5_nHgLbMyIAAAAlc"]
[Tue Aug 18 12:53:53.760823 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:53.761083 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:53.828934 2026] [security2:error] [pid 67073:tid 67230] [client 37.40.227.74:57106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAEfcmepr5_nHgLbMyJQAAAi0"]
[Tue Aug 18 12:53:53.829026 2026] [security2:error] [pid 67073:tid 67230] [client 37.40.227.74:57106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAEfcmepr5_nHgLbMyJQAAAi0"]
[Tue Aug 18 12:53:53.940203 2026] [security2:error] [pid 66623:tid 66828] [client 104.209.144.33:29857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/weozh.php"] [unique_id "aoSAEdO5rbWdOArH04J87AAAAUg"]
[Tue Aug 18 12:53:54.020951 2026] [security2:error] [pid 67073:tid 67260] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSAEvcmepr5_nHgLbMyJgAAAks"]
[Tue Aug 18 12:53:54.025518 2026] [security2:error] [pid 66623:tid 66813] [client 158.158.74.177:9534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/cropper.php"] [unique_id "aoSAEtO5rbWdOArH04J87wAAATk"]
[Tue Aug 18 12:53:54.060322 2026] [security2:error] [pid 67073:tid 67104] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wio.php"] [unique_id "aoSAEvcmepr5_nHgLbMyKAACkBw"]
[Tue Aug 18 12:53:54.064657 2026] [security2:error] [pid 67073:tid 67308] [client 20.171.51.14:65097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/rf.php"] [unique_id "aoSAEvcmepr5_nHgLbMyKQAAAns"]
[Tue Aug 18 12:53:54.084652 2026] [security2:error] [pid 67073:tid 67290] [client 20.104.100.201:17350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/root.php"] [unique_id "aoSAEvcmepr5_nHgLbMyKgAAAmk"]
[Tue Aug 18 12:53:54.152121 2026] [security2:error] [pid 66623:tid 66818] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAEtO5rbWdOArH04J88AAAAT4"]
[Tue Aug 18 12:53:54.174043 2026] [security2:error] [pid 67073:tid 67246] [client 20.91.215.254:20199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/languages.php"] [unique_id "aoSAEvcmepr5_nHgLbMyKwAAAj0"]
[Tue Aug 18 12:53:54.229198 2026] [security2:error] [pid 67073:tid 67207] [client 45.131.195.116:54925] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.foxalpha.com.br"] [uri "/"] [unique_id "aoSAEvcmepr5_nHgLbMyLwAAAhY"]
[Tue Aug 18 12:53:54.316321 2026] [security2:error] [pid 67073:tid 67286] [client 74.248.136.165:58327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wio.php"] [unique_id "aoSAEvcmepr5_nHgLbMyMAAAAmU"]
[Tue Aug 18 12:53:54.400359 2026] [security2:error] [pid 67073:tid 67281] [client 20.171.51.14:1940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/evil.php"] [unique_id "aoSAEvcmepr5_nHgLbMyMwAAAmA"]
[Tue Aug 18 12:53:54.455262 2026] [security2:error] [pid 66623:tid 66809] [client 114.5.214.109:49794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAEtO5rbWdOArH04J88wAAATU"]
[Tue Aug 18 12:53:54.523912 2026] [security2:error] [pid 66623:tid 66789] [client 104.209.144.33:33710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/rymmm.php"] [unique_id "aoSAEtO5rbWdOArH04J89AAAASE"]
[Tue Aug 18 12:53:54.681425 2026] [security2:error] [pid 66623:tid 66883] [client 20.171.51.14:16706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/xynz1.php"] [unique_id "aoSAEtO5rbWdOArH04J89QAAAX8"]
[Tue Aug 18 12:53:54.696458 2026] [security2:error] [pid 66623:tid 66867] [client 52.238.210.254:10154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/hosty.php"] [unique_id "aoSAEtO5rbWdOArH04J89gAAAW8"]
[Tue Aug 18 12:53:54.703265 2026] [security2:error] [pid 67073:tid 67240] [client 178.153.171.161:27589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAEPcmepr5_nHgLbMyBwAAAjc"]
[Tue Aug 18 12:53:54.703366 2026] [security2:error] [pid 67073:tid 67240] [client 178.153.171.161:27589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAEPcmepr5_nHgLbMyBwAAAjc"]
[Tue Aug 18 12:53:54.752869 2026] [security2:error] [pid 67073:tid 67113] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/1061.php"] [unique_id "aoSAEvcmepr5_nHgLbMyNwACTiU"]
[Tue Aug 18 12:53:54.757991 2026] [security2:error] [pid 66623:tid 66795] [client 172.202.39.151:31570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAEtO5rbWdOArH04J8-AAAASc"]
[Tue Aug 18 12:53:54.829186 2026] [security2:error] [pid 66623:tid 66848] [client 20.51.153.15:13377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/sym.php"] [unique_id "aoSAEtO5rbWdOArH04J8-QAAAVw"]
[Tue Aug 18 12:53:54.949515 2026] [authz_core:error] [pid 67073:tid 67178] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:54.949799 2026] [authz_core:error] [pid 67073:tid 67178] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:55.061510 2026] [security2:error] [pid 67073:tid 67300] [client 213.202.253.4:61130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "affaripericiacontabil.com.br"] [uri "/wp-content/schallfuns.php"] [unique_id "aoSAE_cmepr5_nHgLbMyOQAAAnM"], referer: www.google.com
[Tue Aug 18 12:53:55.094553 2026] [security2:error] [pid 67073:tid 67206] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/ws83.php"] [unique_id "aoSAE_cmepr5_nHgLbMyOgAAAhU"]
[Tue Aug 18 12:53:55.099753 2026] [security2:error] [pid 66623:tid 66844] [client 20.171.51.14:61503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/pw.php"] [unique_id "aoSAE9O5rbWdOArH04J8_AAAAVg"]
[Tue Aug 18 12:53:55.138384 2026] [security2:error] [pid 66623:tid 66874] [client 20.51.153.15:13422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/ye.php"] [unique_id "aoSAE9O5rbWdOArH04J8_QAAAXY"]
[Tue Aug 18 12:53:55.194441 2026] [security2:error] [pid 67073:tid 67331] [client 20.48.236.86:10758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/puc.php"] [unique_id "aoSAE_cmepr5_nHgLbMyPQAAApI"]
[Tue Aug 18 12:53:55.345758 2026] [security2:error] [pid 66623:tid 66871] [client 45.131.195.129:34015] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.foxalpha.com.br"] [uri "/wp-includes/css/buttons.css"] [unique_id "aoSAE9O5rbWdOArH04J8_wAAAXM"]
[Tue Aug 18 12:53:55.359533 2026] [security2:error] [pid 66623:tid 66890] [client 74.248.136.165:36391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/1061.php"] [unique_id "aoSAE9O5rbWdOArH04J9AAAAAYY"]
[Tue Aug 18 12:53:55.396298 2026] [security2:error] [pid 66623:tid 66862] [client 74.248.133.44:32424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/al.php"] [unique_id "aoSAE9O5rbWdOArH04J9AQAAAWo"]
[Tue Aug 18 12:53:55.468292 2026] [security2:error] [pid 67073:tid 67278] [client 52.173.121.69:50707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSAE_cmepr5_nHgLbMyQQAAAl0"]
[Tue Aug 18 12:53:55.480763 2026] [security2:error] [pid 66623:tid 66872] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/atex1.php"] [unique_id "aoSAE9O5rbWdOArH04J9AgAAAXQ"]
[Tue Aug 18 12:53:55.511748 2026] [security2:error] [pid 66623:tid 66892] [client 20.250.13.23:21481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAE9O5rbWdOArH04J9AwAAAYg"]
[Tue Aug 18 12:53:55.511888 2026] [security2:error] [pid 67073:tid 67131] [remote 84.205.178.135:49426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.178.205.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nadianobre.com.br"] [uri "/wp-login.php"] [unique_id "aoSAE_cmepr5_nHgLbMyQwACXjc"]
[Tue Aug 18 12:53:55.552329 2026] [authz_core:error] [pid 67073:tid 67135] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:55.552584 2026] [authz_core:error] [pid 67073:tid 67135] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:55.625311 2026] [security2:error] [pid 66623:tid 66832] [client 52.238.210.254:8928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/test1.php"] [unique_id "aoSAE9O5rbWdOArH04J9BAAAAUw"]
[Tue Aug 18 12:53:55.742824 2026] [security2:error] [pid 67073:tid 67314] [client 4.223.164.152:7077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/org.php"] [unique_id "aoSAE_cmepr5_nHgLbMySAAAAoE"]
[Tue Aug 18 12:53:55.829926 2026] [security2:error] [pid 67073:tid 67273] [client 74.248.136.165:10177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/gec.php"] [unique_id "aoSAE_cmepr5_nHgLbMySgAAAlg"]
[Tue Aug 18 12:53:55.835011 2026] [security2:error] [pid 66623:tid 66869] [client 20.104.100.201:54037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/fpwch.php"] [unique_id "aoSAE9O5rbWdOArH04J9BgAAAXE"]
[Tue Aug 18 12:53:55.890383 2026] [security2:error] [pid 67073:tid 67295] [client 20.91.215.254:9112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/nw.php"] [unique_id "aoSAE_cmepr5_nHgLbMyTAAAAm4"]
[Tue Aug 18 12:53:55.902440 2026] [security2:error] [pid 67073:tid 67229] [client 20.65.98.162:21542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSAE_cmepr5_nHgLbMyTQAAAiw"]
[Tue Aug 18 12:53:55.936135 2026] [security2:error] [pid 66623:tid 66809] [client 114.5.214.109:49794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAEtO5rbWdOArH04J88wAAATU"]
[Tue Aug 18 12:53:55.985480 2026] [security2:error] [pid 67073:tid 67102] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/gec.php"] [unique_id "aoSAE_cmepr5_nHgLbMyTgACFBo"]
[Tue Aug 18 12:53:56.023894 2026] [security2:error] [pid 66623:tid 66798] [client 172.182.200.96:14108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSAFNO5rbWdOArH04J9BwAAASo"]
[Tue Aug 18 12:53:56.046679 2026] [security2:error] [pid 67073:tid 67320] [client 20.48.236.86:10788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/19.php"] [unique_id "aoSAFPcmepr5_nHgLbMyTwAAAoc"]
[Tue Aug 18 12:53:56.107625 2026] [security2:error] [pid 66623:tid 66876] [client 20.42.19.40:2694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/aaa.php"] [unique_id "aoSAFNO5rbWdOArH04J9CQAAAXg"]
[Tue Aug 18 12:53:56.205758 2026] [security2:error] [pid 66623:tid 66861] [client 52.238.210.254:8927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/zwso.php"] [unique_id "aoSAFNO5rbWdOArH04J9CgAAAWk"]
[Tue Aug 18 12:53:56.324291 2026] [security2:error] [pid 67073:tid 67228] [client 4.223.164.152:7088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/imageskir.php"] [unique_id "aoSAFPcmepr5_nHgLbMyVgAAAis"]
[Tue Aug 18 12:53:56.376970 2026] [security2:error] [pid 66623:tid 66852] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/class-t.api.php"] [unique_id "aoSAFNO5rbWdOArH04J9CwAAAWA"]
[Tue Aug 18 12:53:56.464041 2026] [security2:error] [pid 67073:tid 67212] [client 45.131.195.166:58049] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.foxalpha.com.br"] [uri "/media/system/js/core.js"] [unique_id "aoSAFPcmepr5_nHgLbMyWAAAAhs"]
[Tue Aug 18 12:53:56.595800 2026] [security2:error] [pid 67073:tid 67141] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/scx.php7"] [unique_id "aoSAFPcmepr5_nHgLbMyYgACjkE"]
[Tue Aug 18 12:53:56.655769 2026] [security2:error] [pid 67073:tid 67258] [client 52.238.210.254:10181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/Geforce.php"] [unique_id "aoSAFPcmepr5_nHgLbMyYwAAAkk"]
[Tue Aug 18 12:53:56.705410 2026] [security2:error] [pid 66623:tid 66769] [client 20.250.13.23:23850] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/1.php"] [unique_id "aoSAFNO5rbWdOArH04J9DwAAAQ0"]
[Tue Aug 18 12:53:56.705508 2026] [security2:error] [pid 66623:tid 66769] [client 20.250.13.23:23850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/1.php"] [unique_id "aoSAFNO5rbWdOArH04J9DwAAAQ0"]
[Tue Aug 18 12:53:56.741651 2026] [security2:error] [pid 67073:tid 67298] [client 158.158.74.177:9390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSAFPcmepr5_nHgLbMyawAAAnE"]
[Tue Aug 18 12:53:56.748586 2026] [security2:error] [pid 67073:tid 67254] [client 196.12.128.158:55309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAFPcmepr5_nHgLbMyaQAAAkU"]
[Tue Aug 18 12:53:56.748704 2026] [security2:error] [pid 67073:tid 67254] [client 196.12.128.158:55309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAFPcmepr5_nHgLbMyaQAAAkU"]
[Tue Aug 18 12:53:56.749538 2026] [security2:error] [pid 66623:tid 66770] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/w.php"] [unique_id "aoSAFNO5rbWdOArH04J9EAAAAQ4"]
[Tue Aug 18 12:53:56.766154 2026] [security2:error] [pid 66623:tid 66792] [client 172.202.39.151:10910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/as.php"] [unique_id "aoSAFNO5rbWdOArH04J9EQAAASQ"]
[Tue Aug 18 12:53:56.808749 2026] [security2:error] [pid 67073:tid 67137] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-admin/sc.php"] [unique_id "aoSAFPcmepr5_nHgLbMybAACSD0"]
[Tue Aug 18 12:53:56.814278 2026] [security2:error] [pid 67073:tid 67304] [client 20.171.51.14:43358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/vo.php"] [unique_id "aoSAFPcmepr5_nHgLbMybQAAAnc"]
[Tue Aug 18 12:53:56.906490 2026] [security2:error] [pid 66623:tid 66891] [client 20.171.51.14:58421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/fn.php"] [unique_id "aoSAFNO5rbWdOArH04J9FAAAAYc"]
[Tue Aug 18 12:53:56.971257 2026] [security2:error] [pid 66623:tid 66875] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAFNO5rbWdOArH04J9FQAAAXc"]
[Tue Aug 18 12:53:57.057088 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:57.057370 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:57.140593 2026] [security2:error] [pid 67073:tid 67230] [client 74.248.133.44:11456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/inc.php"] [unique_id "aoSAFfcmepr5_nHgLbMycgAAAi0"]
[Tue Aug 18 12:53:57.143202 2026] [authz_core:error] [pid 66623:tid 66671] [remote 57.141.8.5:30556] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:57.143464 2026] [authz_core:error] [pid 66623:tid 66671] [remote 57.141.8.5:30556] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:57.159536 2026] [security2:error] [pid 66623:tid 66880] [client 20.42.19.40:2710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/term.php"] [unique_id "aoSAFdO5rbWdOArH04J9FwAAAXw"]
[Tue Aug 18 12:53:57.212273 2026] [security2:error] [pid 66623:tid 66778] [client 4.223.164.152:6883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/indexo.php"] [unique_id "aoSAFdO5rbWdOArH04J9GAAAARY"]
[Tue Aug 18 12:53:57.316341 2026] [security2:error] [pid 66623:tid 66881] [client 74.248.136.165:53314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/scx.php7"] [unique_id "aoSAFdO5rbWdOArH04J9GQAAAX0"]
[Tue Aug 18 12:53:57.357215 2026] [authz_core:error] [pid 67073:tid 67134] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:57.357471 2026] [authz_core:error] [pid 67073:tid 67134] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:57.393114 2026] [security2:error] [pid 66623:tid 66806] [client 20.100.169.31:32761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/themes.php"] [unique_id "aoSAFdO5rbWdOArH04J9GwAAATI"]
[Tue Aug 18 12:53:57.399313 2026] [security2:error] [pid 67073:tid 67158] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp5.php"] [unique_id "aoSAFfcmepr5_nHgLbMydQACWVI"]
[Tue Aug 18 12:53:57.426709 2026] [security2:error] [pid 66623:tid 66859] [client 192.141.172.134:52511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAFdO5rbWdOArH04J9HAAAAWc"]
[Tue Aug 18 12:53:57.426834 2026] [security2:error] [pid 66623:tid 66859] [client 192.141.172.134:52511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAFdO5rbWdOArH04J9HAAAAWc"]
[Tue Aug 18 12:53:57.435941 2026] [security2:error] [pid 67073:tid 67215] [client 20.65.98.162:22687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAFfcmepr5_nHgLbMydgAAAh4"]
[Tue Aug 18 12:53:57.451514 2026] [security2:error] [pid 67073:tid 67319] [client 132.196.61.152:55348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAFfcmepr5_nHgLbMydwAAAoY"]
[Tue Aug 18 12:53:57.501733 2026] [security2:error] [pid 66623:tid 66768] [client 172.202.39.151:62716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSAFdO5rbWdOArH04J9JAAAAQw"]
[Tue Aug 18 12:53:57.514133 2026] [security2:error] [pid 67073:tid 67253] [client 20.91.215.254:20197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSAFfcmepr5_nHgLbMyeAAAAkQ"]
[Tue Aug 18 12:53:57.521805 2026] [autoindex:error] [pid 66623:tid 66780] [client 172.202.39.151:12981] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:57.574291 2026] [security2:error] [pid 67073:tid 67263] [client 20.226.6.191:6626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAFfcmepr5_nHgLbMyeQAAAk4"]
[Tue Aug 18 12:53:57.577371 2026] [security2:error] [pid 67073:tid 67249] [client 20.104.100.201:17401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/mg.php"] [unique_id "aoSAFfcmepr5_nHgLbMyegAAAkA"]
[Tue Aug 18 12:53:57.781632 2026] [security2:error] [pid 66623:tid 66807] [client 158.23.17.4:54760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/10.php"] [unique_id "aoSAFdO5rbWdOArH04J9JQAAATM"]
[Tue Aug 18 12:53:57.815591 2026] [security2:error] [pid 67073:tid 67223] [client 74.248.136.165:36369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-admin/sc.php"] [unique_id "aoSAFfcmepr5_nHgLbMyfgAAAiY"]
[Tue Aug 18 12:53:57.851695 2026] [security2:error] [pid 67073:tid 67245] [client 85.208.96.202:32418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cainelli.com.br"] [uri "/blog/page/3/"] [unique_id "aoSAFfcmepr5_nHgLbMyfwAAAjw"]
[Tue Aug 18 12:53:57.851807 2026] [security2:error] [pid 67073:tid 67245] [client 85.208.96.202:32418] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.cainelli.com.br"] [uri "/blog/page/3/"] [unique_id "aoSAFfcmepr5_nHgLbMyfwAAAjw"]
[Tue Aug 18 12:53:57.856935 2026] [security2:error] [pid 66623:tid 66790] [client 172.202.39.151:12981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/403.php"] [unique_id "aoSAFdO5rbWdOArH04J9JwAAASI"]
[Tue Aug 18 12:53:57.898479 2026] [security2:error] [pid 66623:tid 66811] [client 4.223.164.152:6853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSAFdO5rbWdOArH04J9KAAAATc"]
[Tue Aug 18 12:53:57.974882 2026] [security2:error] [pid 67073:tid 67231] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-2019.php"] [unique_id "aoSAFfcmepr5_nHgLbMygAAAAi4"]
[Tue Aug 18 12:53:58.095905 2026] [security2:error] [pid 67073:tid 67154] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/a2.php"] [unique_id "aoSAFvcmepr5_nHgLbMygQACXk4"]
[Tue Aug 18 12:53:58.296349 2026] [security2:error] [pid 66623:tid 66782] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/archive.php"] [unique_id "aoSAFtO5rbWdOArH04J9KQAAARo"]
[Tue Aug 18 12:53:58.339706 2026] [security2:error] [pid 66623:tid 66812] [client 20.100.169.31:15049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/ww5.php"] [unique_id "aoSAFtO5rbWdOArH04J9KgAAATg"]
[Tue Aug 18 12:53:58.346974 2026] [security2:error] [pid 66623:tid 66813] [client 20.171.51.14:58879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/kf.php"] [unique_id "aoSAFtO5rbWdOArH04J9KwAAATk"]
[Tue Aug 18 12:53:58.376919 2026] [security2:error] [pid 67073:tid 67132] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/app.php"] [unique_id "aoSAFvcmepr5_nHgLbMyjwACOzg"]
[Tue Aug 18 12:53:58.419332 2026] [security2:error] [pid 67073:tid 67213] [client 4.232.151.198:28398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/wap.php"] [unique_id "aoSAFvcmepr5_nHgLbMynQAAAhw"]
[Tue Aug 18 12:53:58.484587 2026] [security2:error] [pid 67073:tid 67251] [client 5.253.205.188:35582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/forumacplibinserts.sql"] [unique_id "aoSAFvcmepr5_nHgLbMyngAAAkI"], referer: https://medihub.com.br/forumacplibinserts.sql
[Tue Aug 18 12:53:58.525776 2026] [security2:error] [pid 67073:tid 67264] [client 40.85.222.29:36668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSAFvcmepr5_nHgLbMynwAAAk8"]
[Tue Aug 18 12:53:58.630404 2026] [security2:error] [pid 67073:tid 67267] [client 20.171.51.14:58410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wu.php"] [unique_id "aoSAFvcmepr5_nHgLbMypwAAAlI"]
[Tue Aug 18 12:53:58.675833 2026] [security2:error] [pid 67073:tid 67330] [client 104.209.144.33:25340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSAFvcmepr5_nHgLbMyqQAAApE"]
[Tue Aug 18 12:53:58.678653 2026] [security2:error] [pid 67073:tid 67221] [client 172.182.200.96:14280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAFvcmepr5_nHgLbMyqwAAAiQ"]
[Tue Aug 18 12:53:58.763769 2026] [security2:error] [pid 67073:tid 67321] [client 20.100.169.31:18007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/cv.php"] [unique_id "aoSAFvcmepr5_nHgLbMyvgAAAog"]
[Tue Aug 18 12:53:58.849928 2026] [security2:error] [pid 67073:tid 67305] [client 74.248.136.165:53327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp5.php"] [unique_id "aoSAFvcmepr5_nHgLbMyywAAAng"]
[Tue Aug 18 12:53:58.854324 2026] [autoindex:error] [pid 67073:tid 67099] [remote 135.225.75.187:0] AH01276: Cannot serve directory /home3/savanasolucoes/public_html/wp-includes/js/tinymce/themes/inlite/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:53:58.885870 2026] [security2:error] [pid 67073:tid 67311] [client 20.42.19.40:2884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/7.php"] [unique_id "aoSAFvcmepr5_nHgLbMyzwAAAn4"]
[Tue Aug 18 12:53:58.954144 2026] [security2:error] [pid 67073:tid 67322] [client 158.23.17.4:9837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/te.php"] [unique_id "aoSAFvcmepr5_nHgLbMy0AAAAok"]
[Tue Aug 18 12:53:59.008135 2026] [security2:error] [pid 67073:tid 67258] [client 20.104.100.201:53868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/reop3.php"] [unique_id "aoSAF_cmepr5_nHgLbMy0QAAAkk"]
[Tue Aug 18 12:53:59.132376 2026] [security2:error] [pid 66623:tid 66797] [client 74.248.18.37:41188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/aaa.php"] [unique_id "aoSAF9O5rbWdOArH04J9PgAAASk"]
[Tue Aug 18 12:53:59.162116 2026] [authz_core:error] [pid 67073:tid 67093] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:59.162417 2026] [authz_core:error] [pid 67073:tid 67093] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:59.206871 2026] [security2:error] [pid 67073:tid 67327] [client 158.158.74.177:9395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSAF_cmepr5_nHgLbMy1QAAAo4"]
[Tue Aug 18 12:53:59.239138 2026] [security2:error] [pid 67073:tid 67225] [client 20.100.169.31:28384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/2.php"] [unique_id "aoSAF_cmepr5_nHgLbMy1gAAAig"]
[Tue Aug 18 12:53:59.292144 2026] [security2:error] [pid 66623:tid 66846] [client 20.118.172.148:47282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/222.php"] [unique_id "aoSAF9O5rbWdOArH04J9RQAAAVo"]
[Tue Aug 18 12:53:59.292186 2026] [security2:error] [pid 66623:tid 66673] [remote 34.62.54.143:45372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.github/.env"] [unique_id "aoSAF9O5rbWdOArH04J9RAABXyQ"]
[Tue Aug 18 12:53:59.362021 2026] [security2:error] [pid 66623:tid 66848] [client 172.202.39.151:52582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAF9O5rbWdOArH04J9RgAAAVw"]
[Tue Aug 18 12:53:59.375181 2026] [security2:error] [pid 66623:tid 66830] [client 20.171.51.14:51811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/de.php"] [unique_id "aoSAF9O5rbWdOArH04J9RwAAAUo"]
[Tue Aug 18 12:53:59.465173 2026] [security2:error] [pid 67073:tid 67294] [client 132.196.61.152:55316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/inso.php"] [unique_id "aoSAF_cmepr5_nHgLbMy3gAAAm0"]
[Tue Aug 18 12:53:59.465340 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:53:59.465737 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:53:59.469645 2026] [security2:error] [pid 67073:tid 67301] [client 197.184.64.235:41915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAF_cmepr5_nHgLbMy3wAAAnQ"]
[Tue Aug 18 12:53:59.469767 2026] [security2:error] [pid 67073:tid 67301] [client 197.184.64.235:41915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAF_cmepr5_nHgLbMy3wAAAnQ"]
[Tue Aug 18 12:53:59.538414 2026] [security2:error] [pid 67073:tid 67239] [client 135.225.75.187:57816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/dsd.php"] [unique_id "aoSAF_cmepr5_nHgLbMy4AAAAjY"]
[Tue Aug 18 12:53:59.541131 2026] [security2:error] [pid 67073:tid 67268] [client 52.238.210.254:9013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/info.php"] [unique_id "aoSAF_cmepr5_nHgLbMy4QAAAlM"]
[Tue Aug 18 12:53:59.568626 2026] [security2:error] [pid 67073:tid 67274] [client 20.48.236.86:16345] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.onemotos.com.br"] [uri "/1.php"] [unique_id "aoSAF_cmepr5_nHgLbMy4gAAAlk"]
[Tue Aug 18 12:53:59.568732 2026] [security2:error] [pid 67073:tid 67274] [client 20.48.236.86:16345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/1.php"] [unique_id "aoSAF_cmepr5_nHgLbMy4gAAAlk"]
[Tue Aug 18 12:53:59.821736 2026] [security2:error] [pid 67073:tid 67295] [client 149.34.210.157:49932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAF_cmepr5_nHgLbMy6AAAAm4"]
[Tue Aug 18 12:53:59.821868 2026] [security2:error] [pid 67073:tid 67295] [client 149.34.210.157:49932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAF_cmepr5_nHgLbMy6AAAAm4"]
[Tue Aug 18 12:53:59.834655 2026] [security2:error] [pid 66623:tid 66874] [client 4.223.164.152:7067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/8pyceeo.php"] [unique_id "aoSAF9O5rbWdOArH04J9SQAAAXY"]
[Tue Aug 18 12:53:59.842644 2026] [security2:error] [pid 66623:tid 66810] [client 103.184.169.37:41244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAF9O5rbWdOArH04J9SAAAATY"]
[Tue Aug 18 12:53:59.842756 2026] [security2:error] [pid 66623:tid 66810] [client 103.184.169.37:41244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAF9O5rbWdOArH04J9SAAAATY"]
[Tue Aug 18 12:53:59.944596 2026] [security2:error] [pid 67073:tid 67248] [client 20.250.13.23:21502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/alfa.php"] [unique_id "aoSAF_cmepr5_nHgLbMy7QAAAj8"]
[Tue Aug 18 12:53:59.963449 2026] [security2:error] [pid 67073:tid 67300] [client 158.23.17.4:54755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/kc.php"] [unique_id "aoSAF_cmepr5_nHgLbMy7wAAAnM"]
[Tue Aug 18 12:53:59.966101 2026] [security2:error] [pid 66623:tid 66847] [client 20.171.51.14:28814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/album.php"] [unique_id "aoSAF9O5rbWdOArH04J9TAAAAVs"]
[Tue Aug 18 12:54:00.066230 2026] [security2:error] [pid 67073:tid 67091] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAGPcmepr5_nHgLbMy8wACJg8"]
[Tue Aug 18 12:54:00.066804 2026] [authz_core:error] [pid 67073:tid 67077] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:00.067069 2026] [authz_core:error] [pid 67073:tid 67077] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:00.085157 2026] [security2:error] [pid 66623:tid 66877] [client 172.202.39.151:44376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAGNO5rbWdOArH04J9TQAAAXk"]
[Tue Aug 18 12:54:00.282763 2026] [security2:error] [pid 67073:tid 67138] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/cxc.php"] [unique_id "aoSAGPcmepr5_nHgLbMy9gACdT4"]
[Tue Aug 18 12:54:00.286865 2026] [authz_core:error] [pid 66623:tid 66759] [remote 57.141.22.118:40900] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:00.287118 2026] [authz_core:error] [pid 66623:tid 66759] [remote 57.141.22.118:40900] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:00.311821 2026] [authz_core:error] [pid 66623:tid 66644] [remote 57.141.22.97:48036] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:00.312108 2026] [authz_core:error] [pid 66623:tid 66644] [remote 57.141.22.97:48036] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:00.339385 2026] [security2:error] [pid 67073:tid 67217] [client 74.248.136.165:59949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/a2.php"] [unique_id "aoSAGPcmepr5_nHgLbMy9wAAAiA"]
[Tue Aug 18 12:54:00.342892 2026] [security2:error] [pid 67073:tid 67244] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/bless.php"] [unique_id "aoSAGPcmepr5_nHgLbMy-AAAAjs"]
[Tue Aug 18 12:54:00.500334 2026] [security2:error] [pid 67073:tid 67273] [client 172.182.200.96:14233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAGPcmepr5_nHgLbMy-QAAAlg"]
[Tue Aug 18 12:54:00.509492 2026] [security2:error] [pid 67073:tid 67122] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSAGPcmepr5_nHgLbMy-gACQi4"]
[Tue Aug 18 12:54:00.599461 2026] [security2:error] [pid 67073:tid 67267] [client 20.226.56.190:28262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/app.php"] [unique_id "aoSAGPcmepr5_nHgLbMy_QAAAlI"]
[Tue Aug 18 12:54:00.680356 2026] [authz_core:error] [pid 67073:tid 67144] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:00.680610 2026] [authz_core:error] [pid 67073:tid 67144] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:00.753976 2026] [security2:error] [pid 67073:tid 67137] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/0.php"] [unique_id "aoSAGPcmepr5_nHgLbMzAwACHT0"]
[Tue Aug 18 12:54:00.964192 2026] [security2:error] [pid 67073:tid 67313] [client 52.238.210.254:10140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/fpwch.php"] [unique_id "aoSAGPcmepr5_nHgLbMzDAAAAoA"]
[Tue Aug 18 12:54:00.966526 2026] [security2:error] [pid 67073:tid 67107] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/dom.php"] [unique_id "aoSAGPcmepr5_nHgLbMzDQACfh8"]
[Tue Aug 18 12:54:00.970717 2026] [authz_core:error] [pid 67073:tid 67155] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:00.970992 2026] [authz_core:error] [pid 67073:tid 67155] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:01.014663 2026] [security2:error] [pid 66623:tid 66774] [client 158.23.17.4:60337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/jn.php"] [unique_id "aoSAGdO5rbWdOArH04J9VAAAARI"]
[Tue Aug 18 12:54:01.068133 2026] [security2:error] [pid 66623:tid 66845] [client 172.202.39.151:21783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSAGdO5rbWdOArH04J9VQAAAVk"]
[Tue Aug 18 12:54:01.083011 2026] [security2:error] [pid 67073:tid 67258] [client 20.104.100.201:17375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/php5.php"] [unique_id "aoSAGfcmepr5_nHgLbMzDwAAAkk"]
[Tue Aug 18 12:54:01.111308 2026] [security2:error] [pid 67073:tid 67254] [client 20.226.6.191:6535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSAGfcmepr5_nHgLbMzEAAAAkU"]
[Tue Aug 18 12:54:01.183048 2026] [security2:error] [pid 67073:tid 67125] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/bb.php"] [unique_id "aoSAGfcmepr5_nHgLbMzEwACMTE"]
[Tue Aug 18 12:54:01.248168 2026] [security2:error] [pid 66623:tid 66792] [client 20.226.56.190:44999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/87.php"] [unique_id "aoSAGdO5rbWdOArH04J9VwAAASQ"]
[Tue Aug 18 12:54:01.265141 2026] [security2:error] [pid 66623:tid 66891] [client 20.48.236.86:16373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/img.php"] [unique_id "aoSAGdO5rbWdOArH04J9WgAAAYc"]
[Tue Aug 18 12:54:01.275785 2026] [authz_core:error] [pid 67073:tid 67118] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:01.276223 2026] [authz_core:error] [pid 67073:tid 67118] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:01.340692 2026] [security2:error] [pid 67073:tid 67207] [client 135.225.75.187:55139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/c4.php"] [unique_id "aoSAGfcmepr5_nHgLbMzGAAAAhY"]
[Tue Aug 18 12:54:01.354124 2026] [security2:error] [pid 67073:tid 67263] [client 158.158.74.177:25869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/goat.php"] [unique_id "aoSAGfcmepr5_nHgLbMzGQAAAk4"]
[Tue Aug 18 12:54:01.431485 2026] [security2:error] [pid 67073:tid 67323] [client 74.248.18.37:45942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/abcd.php"] [unique_id "aoSAGfcmepr5_nHgLbMzGgAAAoo"]
[Tue Aug 18 12:54:01.432973 2026] [security2:error] [pid 67073:tid 67298] [client 138.36.100.162:42487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAF_cmepr5_nHgLbMy2wAAAnE"]
[Tue Aug 18 12:54:01.433146 2026] [security2:error] [pid 67073:tid 67298] [client 138.36.100.162:42487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAF_cmepr5_nHgLbMy2wAAAnE"]
[Tue Aug 18 12:54:01.437824 2026] [security2:error] [pid 67073:tid 67316] [client 172.182.200.96:14168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSAGfcmepr5_nHgLbMzGwAAAoM"]
[Tue Aug 18 12:54:01.447406 2026] [security2:error] [pid 67073:tid 67294] [client 172.182.200.96:14273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/weozh.php"] [unique_id "aoSAGfcmepr5_nHgLbMzHQAAAm0"]
[Tue Aug 18 12:54:01.475528 2026] [security2:error] [pid 67073:tid 67154] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ok.php"] [unique_id "aoSAGfcmepr5_nHgLbMzHgACdE4"]
[Tue Aug 18 12:54:01.492859 2026] [security2:error] [pid 66623:tid 66798] [client 178.153.171.161:62877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAGdO5rbWdOArH04J9XgAAASo"]
[Tue Aug 18 12:54:01.536958 2026] [security2:error] [pid 67073:tid 67274] [client 51.89.129.229:17220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.julioalvez.com.br"] [uri "/robots.txt"] [unique_id "aoSAGfcmepr5_nHgLbMzIQAAAlk"]
[Tue Aug 18 12:54:01.537126 2026] [security2:error] [pid 67073:tid 67274] [client 51.89.129.229:17220] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.julioalvez.com.br"] [uri "/robots.txt"] [unique_id "aoSAGfcmepr5_nHgLbMzIQAAAlk"]
[Tue Aug 18 12:54:01.581164 2026] [security2:error] [pid 67073:tid 67262] [client 20.250.13.23:52999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/edit.php"] [unique_id "aoSAGfcmepr5_nHgLbMzIgAAAk0"]
[Tue Aug 18 12:54:01.588856 2026] [autoindex:error] [pid 66623:tid 66880] [client 172.202.39.151:49203] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:01.602179 2026] [security2:error] [pid 66623:tid 66778] [client 132.196.61.152:55343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/puc.php"] [unique_id "aoSAGdO5rbWdOArH04J9YQAAARY"]
[Tue Aug 18 12:54:01.614401 2026] [security2:error] [pid 66623:tid 66886] [client 20.42.19.40:2222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/file5.php"] [unique_id "aoSAGdO5rbWdOArH04J9YgAAAYI"]
[Tue Aug 18 12:54:01.683976 2026] [security2:error] [pid 67073:tid 67249] [client 20.104.100.201:17347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/acp.php"] [unique_id "aoSAGfcmepr5_nHgLbMzIwAAAkA"]
[Tue Aug 18 12:54:01.690976 2026] [security2:error] [pid 67073:tid 67166] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp9.php"] [unique_id "aoSAGfcmepr5_nHgLbMzJAACYFo"]
[Tue Aug 18 12:54:01.698433 2026] [security2:error] [pid 67073:tid 67215] [client 20.226.6.191:6655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/about.php"] [unique_id "aoSAGfcmepr5_nHgLbMzJQAAAh4"]
[Tue Aug 18 12:54:01.719899 2026] [security2:error] [pid 66623:tid 66770] [client 114.119.140.137:58833] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mairabordignon.com.br"] [uri "/2022/11/30/technics-brand-discontinued"] [unique_id "aoSAGdO5rbWdOArH04J9ZAAAAQ4"], referer: https://evga-nvidiageforce.com/2022/11/30/wedding-card-gift-amount
[Tue Aug 18 12:54:01.724498 2026] [security2:error] [pid 67073:tid 67326] [client 5.161.75.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jgbdominiosolucoes.com.br"] [uri "/index.php"] [unique_id "aoSAF_cmepr5_nHgLbMy6wACjR4"], referer: https://jgbdominiosolucoes.com.br/
[Tue Aug 18 12:54:01.906148 2026] [security2:error] [pid 66623:tid 66856] [client 172.182.200.96:14311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/rymmm.php"] [unique_id "aoSAGdO5rbWdOArH04J9ZQAAAWQ"]
[Tue Aug 18 12:54:01.917401 2026] [security2:error] [pid 67073:tid 67278] [client 20.42.19.40:2213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/makeasmtp.php"] [unique_id "aoSAGfcmepr5_nHgLbMzKgAAAl0"]
[Tue Aug 18 12:54:01.943358 2026] [security2:error] [pid 66623:tid 66878] [client 74.248.133.44:11751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSAGdO5rbWdOArH04J9ZgAAAXo"]
[Tue Aug 18 12:54:01.959570 2026] [security2:error] [pid 67073:tid 67186] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ws59.php"] [unique_id "aoSAGfcmepr5_nHgLbMzLAACam4"]
[Tue Aug 18 12:54:01.983098 2026] [security2:error] [pid 66623:tid 66796] [client 52.238.210.254:10218] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/mini"] [unique_id "aoSAGdO5rbWdOArH04J9ZwAAASg"]
[Tue Aug 18 12:54:02.139290 2026] [security2:error] [pid 66623:tid 66868] [client 20.226.6.191:6638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSAGtO5rbWdOArH04J9aQAAAXA"]
[Tue Aug 18 12:54:02.168578 2026] [security2:error] [pid 66623:tid 66776] [client 158.23.17.4:55197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/bf.php"] [unique_id "aoSAGtO5rbWdOArH04J9agAAARQ"]
[Tue Aug 18 12:54:02.236671 2026] [security2:error] [pid 66623:tid 66864] [client 213.202.253.4:61751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/txets.php"] [unique_id "aoSAGtO5rbWdOArH04J9awAAAWw"], referer: www.google.com
[Tue Aug 18 12:54:02.309209 2026] [security2:error] [pid 66623:tid 66839] [client 172.182.200.96:14213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/lddxs.php"] [unique_id "aoSAGtO5rbWdOArH04J9bAAAAVM"]
[Tue Aug 18 12:54:02.335051 2026] [security2:error] [pid 66623:tid 66790] [client 20.171.51.14:51796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/su.php"] [unique_id "aoSAGtO5rbWdOArH04J9bQAAASI"]
[Tue Aug 18 12:54:02.364072 2026] [security2:error] [pid 66623:tid 66784] [client 20.104.100.201:53827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/yas.php"] [unique_id "aoSAGtO5rbWdOArH04J9bgAAARw"]
[Tue Aug 18 12:54:02.461400 2026] [security2:error] [pid 66623:tid 66798] [client 178.153.171.161:62877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAGdO5rbWdOArH04J9XgAAASo"]
[Tue Aug 18 12:54:02.535121 2026] [authz_core:error] [pid 66623:tid 66747] [remote 57.141.22.101:46704] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:02.535404 2026] [authz_core:error] [pid 66623:tid 66747] [remote 57.141.22.101:46704] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:02.550827 2026] [security2:error] [pid 67073:tid 67199] [remote 74.220.219.216:37372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.219.220.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/wp-login.php"] [unique_id "aoSAGvcmepr5_nHgLbMzOQACgns"]
[Tue Aug 18 12:54:02.642529 2026] [security2:error] [pid 67073:tid 67276] [client 20.42.19.40:2690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/index.php"] [unique_id "aoSAGvcmepr5_nHgLbMzOgAAAls"]
[Tue Aug 18 12:54:02.681909 2026] [security2:error] [pid 66623:tid 66843] [client 132.196.61.152:55346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/19.php"] [unique_id "aoSAGtO5rbWdOArH04J9cgAAAVc"]
[Tue Aug 18 12:54:02.729908 2026] [security2:error] [pid 66623:tid 66853] [client 4.223.164.152:6627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/.admin.php"] [unique_id "aoSAGtO5rbWdOArH04J9dAAAAWE"]
[Tue Aug 18 12:54:02.931351 2026] [security2:error] [pid 66623:tid 66820] [client 20.104.100.201:58935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAGtO5rbWdOArH04J9eAAAAUA"]
[Tue Aug 18 12:54:02.946356 2026] [security2:error] [pid 67073:tid 67216] [client 20.42.19.40:2191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSAGvcmepr5_nHgLbMzQwAAAh8"]
[Tue Aug 18 12:54:03.026867 2026] [autoindex:error] [pid 66623:tid 66883] [client 172.202.39.151:49203] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:03.103507 2026] [security2:error] [pid 66623:tid 66795] [client 20.104.100.201:53861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/ah25.php"] [unique_id "aoSAG9O5rbWdOArH04J9fAAAASc"]
[Tue Aug 18 12:54:03.210710 2026] [fcgid:warn] [pid 67073:tid 67265] (70014)End of file found: [client 66.132.195.55:53860] mod_fcgid: can't get data from http client
[Tue Aug 18 12:54:03.273689 2026] [security2:error] [pid 67073:tid 67257] [client 20.104.100.201:58906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAG_cmepr5_nHgLbMzSwAAAkg"]
[Tue Aug 18 12:54:03.298728 2026] [security2:error] [pid 66623:tid 66742] [remote 188.164.197.230:53238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/wp-login.php"] [unique_id "aoSAG9O5rbWdOArH04J9gQABWGk"]
[Tue Aug 18 12:54:03.416654 2026] [security2:error] [pid 67073:tid 67246] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/sagax1.php"] [unique_id "aoSAG_cmepr5_nHgLbMzTAAAAj0"]
[Tue Aug 18 12:54:03.457916 2026] [security2:error] [pid 67073:tid 67221] [client 160.120.140.123:53939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAG_cmepr5_nHgLbMzTgAAAiQ"]
[Tue Aug 18 12:54:03.458050 2026] [security2:error] [pid 67073:tid 67221] [client 160.120.140.123:53939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAG_cmepr5_nHgLbMzTgAAAiQ"]
[Tue Aug 18 12:54:03.556437 2026] [security2:error] [pid 67073:tid 67220] [client 20.65.98.162:18068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAG_cmepr5_nHgLbMzTwAAAiM"]
[Tue Aug 18 12:54:03.580111 2026] [security2:error] [pid 67073:tid 67309] [client 213.35.127.232:58276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAG_cmepr5_nHgLbMzUQAAAnw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:03.634306 2026] [security2:error] [pid 67073:tid 67234] [client 20.250.13.23:40602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/elp.php"] [unique_id "aoSAG_cmepr5_nHgLbMzUwAAAjE"]
[Tue Aug 18 12:54:03.645007 2026] [security2:error] [pid 67073:tid 67228] [client 104.209.144.33:35893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/lddxs.php"] [unique_id "aoSAG_cmepr5_nHgLbMzVAAAAis"]
[Tue Aug 18 12:54:03.678485 2026] [authz_core:error] [pid 67073:tid 67181] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:03.678748 2026] [authz_core:error] [pid 67073:tid 67181] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:03.696823 2026] [security2:error] [pid 66623:tid 66799] [client 135.225.75.187:19237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/an7.php"] [unique_id "aoSAG9O5rbWdOArH04J9ggAAASs"]
[Tue Aug 18 12:54:03.734616 2026] [security2:error] [pid 66623:tid 66874] [client 172.202.39.151:49203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/gecko.php"] [unique_id "aoSAG9O5rbWdOArH04J9gwAAAXY"]
[Tue Aug 18 12:54:03.780205 2026] [security2:error] [pid 66623:tid 66828] [client 74.248.133.44:32390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/x.php"] [unique_id "aoSAG9O5rbWdOArH04J9hAAAAUg"]
[Tue Aug 18 12:54:03.828467 2026] [security2:error] [pid 67073:tid 67230] [client 74.248.136.165:36383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/app.php"] [unique_id "aoSAG_cmepr5_nHgLbMzXQAAAi0"]
[Tue Aug 18 12:54:03.873076 2026] [security2:error] [pid 66623:tid 66866] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wpc.php"] [unique_id "aoSAG9O5rbWdOArH04J9hQAAAW4"]
[Tue Aug 18 12:54:03.879295 2026] [security2:error] [pid 66623:tid 66847] [client 172.182.200.96:14222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/zjggu.php"] [unique_id "aoSAG9O5rbWdOArH04J9hgAAAVs"]
[Tue Aug 18 12:54:03.900972 2026] [security2:error] [pid 67073:tid 67169] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/Ov-Simple1.php"] [unique_id "aoSAG_cmepr5_nHgLbMzXwACTV0"]
[Tue Aug 18 12:54:03.976052 2026] [security2:error] [pid 66623:tid 66833] [client 172.202.39.151:62661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/file.php"] [unique_id "aoSAG9O5rbWdOArH04J9iAAAAU0"]
[Tue Aug 18 12:54:03.981328 2026] [authz_core:error] [pid 67073:tid 67081] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:03.981601 2026] [authz_core:error] [pid 67073:tid 67081] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:03.999785 2026] [security2:error] [pid 67073:tid 67252] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSAG_cmepr5_nHgLbMzYQAAAkM"]
[Tue Aug 18 12:54:04.019000 2026] [security2:error] [pid 66623:tid 66832] [client 20.171.51.14:51615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/wp-key.php"] [unique_id "aoSAHNO5rbWdOArH04J9iQAAAUw"]
[Tue Aug 18 12:54:04.076832 2026] [security2:error] [pid 67073:tid 67261] [client 20.226.6.191:6603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/f35.php"] [unique_id "aoSAHPcmepr5_nHgLbMzYwAAAkw"]
[Tue Aug 18 12:54:04.135620 2026] [security2:error] [pid 67073:tid 67090] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSAHPcmepr5_nHgLbMzZQACYA4"]
[Tue Aug 18 12:54:04.209112 2026] [security2:error] [pid 67073:tid 67193] [remote 47.128.60.119:56950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.galeriadoengenho.com"] [uri "/robots.txt"] [unique_id "aoSAHPcmepr5_nHgLbMzZgACInU"]
[Tue Aug 18 12:54:04.253241 2026] [security2:error] [pid 66623:tid 66876] [client 20.42.19.40:2237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/atomlib.php"] [unique_id "aoSAHNO5rbWdOArH04J9iwAAAXg"]
[Tue Aug 18 12:54:04.255957 2026] [security2:error] [pid 67073:tid 67326] [client 20.171.51.14:58384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/kv.php"] [unique_id "aoSAHPcmepr5_nHgLbMzZwAAAo0"]
[Tue Aug 18 12:54:04.291439 2026] [security2:error] [pid 66623:tid 66774] [client 172.182.200.96:14284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/dlvqo.php"] [unique_id "aoSAHNO5rbWdOArH04J9jAAAARI"]
[Tue Aug 18 12:54:04.370364 2026] [security2:error] [pid 66623:tid 66791] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/.cache/x.php"] [unique_id "aoSAHNO5rbWdOArH04J9jgAAASM"]
[Tue Aug 18 12:54:04.461732 2026] [security2:error] [pid 67073:tid 67275] [client 157.51.166.53:52558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAHPcmepr5_nHgLbMzawAAAlo"]
[Tue Aug 18 12:54:04.461871 2026] [security2:error] [pid 67073:tid 67275] [client 157.51.166.53:52558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAHPcmepr5_nHgLbMzawAAAlo"]
[Tue Aug 18 12:54:04.503517 2026] [authz_core:error] [pid 67073:tid 67188] [remote 57.141.22.87:32008] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:04.503789 2026] [authz_core:error] [pid 67073:tid 67188] [remote 57.141.22.87:32008] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:04.505660 2026] [security2:error] [pid 67073:tid 67299] [client 37.40.227.74:56956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAHPcmepr5_nHgLbMzbgAAAnI"]
[Tue Aug 18 12:54:04.575458 2026] [autoindex:error] [pid 67073:tid 67245] [client 172.202.39.151:33734] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:04.615941 2026] [authz_core:error] [pid 67073:tid 67284] [client 192.178.4.135:42426] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:04.616197 2026] [authz_core:error] [pid 67073:tid 67284] [client 192.178.4.135:42426] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:04.722289 2026] [security2:error] [pid 67073:tid 67270] [client 104.209.144.33:19638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/zjggu.php"] [unique_id "aoSAHPcmepr5_nHgLbMzcgAAAlU"]
[Tue Aug 18 12:54:04.729109 2026] [security2:error] [pid 67073:tid 67227] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSAHPcmepr5_nHgLbMzcwAAAio"]
[Tue Aug 18 12:54:04.760968 2026] [security2:error] [pid 66623:tid 66822] [client 85.154.68.202:59260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAHNO5rbWdOArH04J9kwAAAUI"]
[Tue Aug 18 12:54:04.761149 2026] [security2:error] [pid 66623:tid 66822] [client 85.154.68.202:59260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAHNO5rbWdOArH04J9kwAAAUI"]
[Tue Aug 18 12:54:04.776453 2026] [security2:error] [pid 67073:tid 67241] [client 172.182.200.96:14293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/pkmoj.php"] [unique_id "aoSAHPcmepr5_nHgLbMzdAAAAjg"]
[Tue Aug 18 12:54:04.869141 2026] [security2:error] [pid 67073:tid 67320] [client 20.104.100.201:17301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/ano.php"] [unique_id "aoSAHPcmepr5_nHgLbMzdgAAAoc"]
[Tue Aug 18 12:54:05.013226 2026] [security2:error] [pid 67073:tid 67330] [client 4.232.151.198:6182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/lock360.php"] [unique_id "aoSAHfcmepr5_nHgLbMzeAAAApE"]
[Tue Aug 18 12:54:05.036225 2026] [security2:error] [pid 67073:tid 67250] [client 4.223.164.152:7057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wsomini.php"] [unique_id "aoSAHfcmepr5_nHgLbMzeQAAAkE"]
[Tue Aug 18 12:54:05.071886 2026] [security2:error] [pid 67073:tid 67321] [client 20.48.236.86:16372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/222.php"] [unique_id "aoSAHfcmepr5_nHgLbMzegAAAog"]
[Tue Aug 18 12:54:05.103938 2026] [security2:error] [pid 67073:tid 67229] [client 20.104.85.180:8011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAHfcmepr5_nHgLbMzewAAAiw"]
[Tue Aug 18 12:54:05.136072 2026] [security2:error] [pid 66623:tid 66794] [client 20.42.19.40:2691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/min.php"] [unique_id "aoSAHdO5rbWdOArH04J9lAAAASY"]
[Tue Aug 18 12:54:05.142991 2026] [security2:error] [pid 67073:tid 67243] [client 114.119.152.77:24539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adepol.com.br"] [uri "/vsncga/your-friend-the-rat.html"] [unique_id "aoSAHfcmepr5_nHgLbMzfAAAAjo"], referer: https://www.ballthai.com/%e0%b9%80%e0%b8%95%e0%b9%87%e0%b8%a1%e0%b8%97%e0%b8%b5%e0%b9%88%e0%b9%81%e0%b8%99%e0%b9%88%e0%b8%99%e0%b8%ad%e0%b8%99-%e0%b9%82%e0%b8%84%e0%b9%89%e0%b8%8a%e0%b8%ab%e0%b8%99%e0%b8%b6%e0%b9%88
[Tue Aug 18 12:54:05.147853 2026] [security2:error] [pid 67073:tid 67313] [client 172.202.39.151:50223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAHfcmepr5_nHgLbMzfQAAAoA"]
[Tue Aug 18 12:54:05.179241 2026] [security2:error] [pid 67073:tid 67314] [client 40.85.222.29:32466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/mt/byp.php"] [unique_id "aoSAHfcmepr5_nHgLbMzfgAAAoE"]
[Tue Aug 18 12:54:05.255809 2026] [security2:error] [pid 66623:tid 66818] [client 114.119.139.42:24919] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.luzpatchwork.com.br"] [uri "/tecidos-pre-cortados"] [unique_id "aoSAHdO5rbWdOArH04J9lQAAAT4"], referer: https://www.luzpatchwork.com.br/tecidos-pre-cortados
[Tue Aug 18 12:54:05.264285 2026] [security2:error] [pid 67073:tid 67258] [client 172.182.200.96:14317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/kopyw.php"] [unique_id "aoSAHfcmepr5_nHgLbMzgAAAAkk"]
[Tue Aug 18 12:54:05.347334 2026] [security2:error] [pid 67073:tid 67286] [client 20.100.169.31:33154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSAHfcmepr5_nHgLbMzgQAAAmU"]
[Tue Aug 18 12:54:05.433825 2026] [security2:error] [pid 67073:tid 67214] [client 114.119.132.101:56219] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.economycarsmultimarcas.com.br"] [uri "/veiculo/87035/cruze-ltz-1-8-16v-flexpower-4p-aut"] [unique_id "aoSAHfcmepr5_nHgLbMzhAAAAh0"], referer: https://www.economycarsmultimarcas.com.br/estoque?page=2
[Tue Aug 18 12:54:05.439148 2026] [security2:error] [pid 67073:tid 67232] [client 172.202.39.151:33734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/aa.php"] [unique_id "aoSAHfcmepr5_nHgLbMzhQAAAi8"]
[Tue Aug 18 12:54:05.456241 2026] [security2:error] [pid 67073:tid 67329] [client 20.48.236.86:16354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/key.php"] [unique_id "aoSAHfcmepr5_nHgLbMzhgAAApA"]
[Tue Aug 18 12:54:05.485034 2026] [authz_core:error] [pid 67073:tid 67194] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:05.485310 2026] [authz_core:error] [pid 67073:tid 67194] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:05.512162 2026] [security2:error] [pid 67073:tid 67216] [client 74.248.18.37:21185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-good.php"] [unique_id "aoSAHfcmepr5_nHgLbMzjAAAAh8"]
[Tue Aug 18 12:54:05.515543 2026] [security2:error] [pid 67073:tid 67217] [client 149.34.210.157:50568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAHfcmepr5_nHgLbMzjQAAAiA"]
[Tue Aug 18 12:54:05.520808 2026] [security2:error] [pid 67073:tid 67307] [client 20.65.98.162:29465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/sky.php"] [unique_id "aoSAHfcmepr5_nHgLbMzjgAAAno"]
[Tue Aug 18 12:54:05.528163 2026] [security2:error] [pid 67073:tid 67206] [client 158.158.74.177:9405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/Session.php"] [unique_id "aoSAHfcmepr5_nHgLbMzjwAAAhU"]
[Tue Aug 18 12:54:05.530394 2026] [security2:error] [pid 67073:tid 67109] [remote 162.55.89.48:61900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/wp-login.php"] [unique_id "aoSAHfcmepr5_nHgLbMziwACSiE"]
[Tue Aug 18 12:54:05.617512 2026] [security2:error] [pid 66623:tid 66854] [client 74.248.136.165:21121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAHdO5rbWdOArH04J9mQAAAWI"]
[Tue Aug 18 12:54:05.672882 2026] [security2:error] [pid 67073:tid 67299] [client 37.40.227.74:56956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAHPcmepr5_nHgLbMzbgAAAnI"]
[Tue Aug 18 12:54:05.698713 2026] [security2:error] [pid 67073:tid 67228] [client 20.104.100.201:17362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/nwflm.php"] [unique_id "aoSAHfcmepr5_nHgLbMzkQAAAis"]
[Tue Aug 18 12:54:05.730532 2026] [security2:error] [pid 67073:tid 67312] [client 20.250.13.23:31484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAHfcmepr5_nHgLbMzkgAAAn8"]
[Tue Aug 18 12:54:05.787811 2026] [authz_core:error] [pid 67073:tid 67083] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:05.788068 2026] [authz_core:error] [pid 67073:tid 67083] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:05.793860 2026] [security2:error] [pid 67073:tid 67274] [client 20.51.153.15:9104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAHfcmepr5_nHgLbMzlAAAAlk"]
[Tue Aug 18 12:54:05.814701 2026] [security2:error] [pid 67073:tid 67217] [client 149.34.210.157:50568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAHfcmepr5_nHgLbMzjQAAAiA"]
[Tue Aug 18 12:54:05.827968 2026] [security2:error] [pid 66623:tid 66786] [client 20.48.236.86:16272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/chosen.php"] [unique_id "aoSAHdO5rbWdOArH04J9mgAAAR4"]
[Tue Aug 18 12:54:05.855114 2026] [security2:error] [pid 67073:tid 67322] [client 114.119.133.194:29757] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.marthaimenes.com"] [uri "/lander"] [unique_id "aoSAHfcmepr5_nHgLbMzlgAAAok"], referer: https://www.marthaimenes.com/lander?oref=https%3A%2F%2Fwww.marthaimenes.com%2Foi-tv-abre-canais-hbo-e-max-para-todos-clientes
[Tue Aug 18 12:54:05.875944 2026] [security2:error] [pid 67073:tid 67271] [client 74.248.136.165:56304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/a1vx.php"] [unique_id "aoSAHfcmepr5_nHgLbMzmAAAAlY"]
[Tue Aug 18 12:54:05.892370 2026] [security2:error] [pid 67073:tid 67240] [client 20.151.109.219:40507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/mq.php"] [unique_id "aoSAHfcmepr5_nHgLbMzmgAAAjc"]
[Tue Aug 18 12:54:05.969331 2026] [security2:error] [pid 67073:tid 67310] [client 52.238.210.254:10124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-blog-header.php"] [unique_id "aoSAHfcmepr5_nHgLbMznAAAAn0"]
[Tue Aug 18 12:54:06.018674 2026] [security2:error] [pid 66623:tid 66784] [client 20.163.43.14:3155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wicked.php"] [unique_id "aoSAHtO5rbWdOArH04J9nwAAARw"]
[Tue Aug 18 12:54:06.068423 2026] [security2:error] [pid 66623:tid 66885] [client 4.232.151.198:48153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/log.php"] [unique_id "aoSAHtO5rbWdOArH04J9oAAAAYE"]
[Tue Aug 18 12:54:06.149483 2026] [security2:error] [pid 67073:tid 67223] [client 20.118.172.148:7674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/aa.php"] [unique_id "aoSAHvcmepr5_nHgLbMzrQAAAiY"]
[Tue Aug 18 12:54:06.257014 2026] [security2:error] [pid 67073:tid 67245] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/fone1.php"] [unique_id "aoSAHvcmepr5_nHgLbMzsAAAAjw"]
[Tue Aug 18 12:54:06.412787 2026] [security2:error] [pid 67073:tid 67320] [client 20.163.43.14:3193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSAHvcmepr5_nHgLbMzsgAAAoc"]
[Tue Aug 18 12:54:06.447197 2026] [security2:error] [pid 67073:tid 67296] [client 104.209.144.33:24874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAHvcmepr5_nHgLbMzswAAAm8"]
[Tue Aug 18 12:54:06.552173 2026] [security2:error] [pid 67073:tid 67218] [client 20.226.6.191:6627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/inputs.php"] [unique_id "aoSAHvcmepr5_nHgLbMztQAAAiE"]
[Tue Aug 18 12:54:06.569459 2026] [security2:error] [pid 67073:tid 67330] [client 132.196.61.152:56091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/133.php"] [unique_id "aoSAHvcmepr5_nHgLbMztgAAApE"]
[Tue Aug 18 12:54:06.661765 2026] [security2:error] [pid 66623:tid 66821] [client 74.248.136.165:21164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/cxc.php"] [unique_id "aoSAHtO5rbWdOArH04J9qwAAAUE"]
[Tue Aug 18 12:54:06.690129 2026] [authz_core:error] [pid 67073:tid 67158] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:06.690382 2026] [authz_core:error] [pid 67073:tid 67158] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:06.747503 2026] [security2:error] [pid 66623:tid 66789] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAHtO5rbWdOArH04J9rgAAASE"]
[Tue Aug 18 12:54:06.980037 2026] [security2:error] [pid 66623:tid 66797] [client 52.238.210.254:10190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/about/function.php"] [unique_id "aoSAHtO5rbWdOArH04J9rwAAASk"]
[Tue Aug 18 12:54:06.982485 2026] [security2:error] [pid 66623:tid 66782] [client 114.119.132.10:41681] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "zanoniautomoveis.com.br"] [uri "/multipla/modelo-marca/ONIX"] [unique_id "aoSAHtO5rbWdOArH04J9sAAAARo"], referer: https://zanoniautomoveis.com.br/financiamento?veiculo=66199
[Tue Aug 18 12:54:07.005585 2026] [security2:error] [pid 67073:tid 67264] [client 172.182.200.96:14294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/zznmg.php"] [unique_id "aoSAH_cmepr5_nHgLbMzyAAAAk8"]
[Tue Aug 18 12:54:07.010482 2026] [security2:error] [pid 67073:tid 67210] [client 197.184.64.235:41916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAHvcmepr5_nHgLbMzxwAAAhk"]
[Tue Aug 18 12:54:07.010737 2026] [security2:error] [pid 67073:tid 67210] [client 197.184.64.235:41916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAHvcmepr5_nHgLbMzxwAAAhk"]
[Tue Aug 18 12:54:07.136444 2026] [security2:error] [pid 66623:tid 66777] [client 114.119.145.123:40005] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.rsmoto.com.br"] [uri "/veiculo/108061/ybr-125-factor-ed-factor-edition"] [unique_id "aoSAH9O5rbWdOArH04J9sgAAARU"], referer: https://www.rsmoto.com.br/veiculo/108061/ybr-125-factor-ed-factor-edition
[Tue Aug 18 12:54:07.137878 2026] [security2:error] [pid 67073:tid 67329] [client 74.248.136.165:32990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSAH_cmepr5_nHgLbMz0wAAApA"]
[Tue Aug 18 12:54:07.149911 2026] [security2:error] [pid 67073:tid 67289] [client 51.161.65.180:62790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.julioalvez.com.br"] [uri "/"] [unique_id "aoSAH_cmepr5_nHgLbMz1AAAAmg"]
[Tue Aug 18 12:54:07.149999 2026] [security2:error] [pid 67073:tid 67289] [client 51.161.65.180:62790] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.julioalvez.com.br"] [uri "/"] [unique_id "aoSAH_cmepr5_nHgLbMz1AAAAmg"]
[Tue Aug 18 12:54:07.179179 2026] [security2:error] [pid 66623:tid 66848] [client 20.65.98.162:2232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/file5.php"] [unique_id "aoSAH9O5rbWdOArH04J9swAAAVw"]
[Tue Aug 18 12:54:07.180942 2026] [security2:error] [pid 67073:tid 67251] [client 114.119.144.163:47583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.avenidaveiculossc.com.br"] [uri "/veiculo/55771/hilux-sw4-srv-d4-d-4x4-3-0-tdi-dies-aut"] [unique_id "aoSAH_cmepr5_nHgLbMz1QAAAkI"], referer: https://www.avenidaveiculossc.com.br/veiculo/55771/hilux-sw4-srv-d4-d-4x4-3-0-tdi-dies-aut
[Tue Aug 18 12:54:07.316875 2026] [security2:error] [pid 66623:tid 66846] [client 4.232.151.198:6166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/lv.php"] [unique_id "aoSAH9O5rbWdOArH04J9tAAAAVo"]
[Tue Aug 18 12:54:07.329401 2026] [security2:error] [pid 67073:tid 67255] [client 20.48.236.86:16343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/thoms.php"] [unique_id "aoSAH_cmepr5_nHgLbMz2QAAAkY"]
[Tue Aug 18 12:54:07.534333 2026] [security2:error] [pid 67073:tid 67234] [client 172.202.39.151:57375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/0x.php"] [unique_id "aoSAH_cmepr5_nHgLbMz3gAAAjE"]
[Tue Aug 18 12:54:07.541541 2026] [security2:error] [pid 67073:tid 67326] [client 196.12.128.158:56038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAH_cmepr5_nHgLbMz3wAAAo0"]
[Tue Aug 18 12:54:07.541661 2026] [security2:error] [pid 67073:tid 67326] [client 196.12.128.158:56038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAH_cmepr5_nHgLbMz3wAAAo0"]
[Tue Aug 18 12:54:07.550443 2026] [security2:error] [pid 67073:tid 67257] [client 192.141.172.134:53075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAH_cmepr5_nHgLbMz4AAAAkg"]
[Tue Aug 18 12:54:07.550549 2026] [security2:error] [pid 67073:tid 67257] [client 192.141.172.134:53075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAH_cmepr5_nHgLbMz4AAAAkg"]
[Tue Aug 18 12:54:07.557315 2026] [security2:error] [pid 66623:tid 66645] [remote 64.225.17.112:60780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.17.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samarapraseres.com.br"] [uri "/wp-login.php"] [unique_id "aoSAH9O5rbWdOArH04J9tgABJwg"]
[Tue Aug 18 12:54:07.607471 2026] [security2:error] [pid 66623:tid 66830] [client 158.158.74.177:23788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSAH9O5rbWdOArH04J9uAAAAUo"]
[Tue Aug 18 12:54:07.618112 2026] [security2:error] [pid 67073:tid 67312] [client 74.248.136.165:21128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/0.php"] [unique_id "aoSAH_cmepr5_nHgLbMz4gAAAn8"]
[Tue Aug 18 12:54:07.684115 2026] [security2:error] [pid 67073:tid 67226] [client 20.171.51.14:57344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/gg.php"] [unique_id "aoSAH_cmepr5_nHgLbMz4wAAAik"]
[Tue Aug 18 12:54:07.698024 2026] [security2:error] [pid 67073:tid 67268] [client 135.225.75.187:32974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/bsg-management/php.php"] [unique_id "aoSAH_cmepr5_nHgLbMz5AAAAlM"]
[Tue Aug 18 12:54:07.722598 2026] [security2:error] [pid 66623:tid 66831] [client 20.250.13.23:53048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/666.php"] [unique_id "aoSAH9O5rbWdOArH04J9ugAAAUs"]
[Tue Aug 18 12:54:07.863619 2026] [security2:error] [pid 67073:tid 67212] [client 20.48.236.86:16292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/wpxml.php"] [unique_id "aoSAH_cmepr5_nHgLbMz6wAAAhs"]
[Tue Aug 18 12:54:08.179208 2026] [security2:error] [pid 67073:tid 67302] [client 20.163.43.14:3116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAIPcmepr5_nHgLbMz8gAAAnU"]
[Tue Aug 18 12:54:08.201688 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:08.202154 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:08.269985 2026] [security2:error] [pid 67073:tid 67279] [client 20.104.85.180:6984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/inputs.php"] [unique_id "aoSAIPcmepr5_nHgLbMz9gAAAl4"]
[Tue Aug 18 12:54:08.461922 2026] [security2:error] [pid 67073:tid 67219] [client 138.36.100.162:42317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAIPcmepr5_nHgLbM0HAAAAiI"]
[Tue Aug 18 12:54:08.462011 2026] [security2:error] [pid 67073:tid 67219] [client 138.36.100.162:42317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAIPcmepr5_nHgLbM0HAAAAiI"]
[Tue Aug 18 12:54:08.478375 2026] [security2:error] [pid 67073:tid 67327] [client 20.226.56.190:47108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/zi.php"] [unique_id "aoSAIPcmepr5_nHgLbM0HQAAAo4"]
[Tue Aug 18 12:54:08.517596 2026] [security2:error] [pid 66623:tid 66852] [client 213.35.127.232:59040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAINO5rbWdOArH04J9vQAAAWA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:08.556629 2026] [security2:error] [pid 66623:tid 66828] [client 103.184.169.37:41279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAINO5rbWdOArH04J9vgAAAUg"]
[Tue Aug 18 12:54:08.556807 2026] [security2:error] [pid 66623:tid 66828] [client 103.184.169.37:41279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAINO5rbWdOArH04J9vgAAAUg"]
[Tue Aug 18 12:54:08.698159 2026] [security2:error] [pid 67073:tid 67252] [client 104.209.144.33:24850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSAIPcmepr5_nHgLbM0IgAAAkM"]
[Tue Aug 18 12:54:08.706095 2026] [security2:error] [pid 67073:tid 67284] [client 20.118.172.148:47277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/abcd.php"] [unique_id "aoSAIPcmepr5_nHgLbM0IwAAAmM"]
[Tue Aug 18 12:54:08.789764 2026] [security2:error] [pid 66623:tid 66845] [client 20.171.51.14:51832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/gi.php"] [unique_id "aoSAINO5rbWdOArH04J9wQAAAVk"]
[Tue Aug 18 12:54:08.901507 2026] [security2:error] [pid 66623:tid 66641] [remote 47.86.33.52:46226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "site.supercarconsulting.com.br"] [uri "/wp-login.php"] [unique_id "aoSAINO5rbWdOArH04J9wwABHwQ"]
[Tue Aug 18 12:54:09.032947 2026] [security2:error] [pid 67073:tid 67215] [client 4.223.164.152:6631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/vr.php"] [unique_id "aoSAIfcmepr5_nHgLbM0KQAAAh4"]
[Tue Aug 18 12:54:09.081856 2026] [security2:error] [pid 67073:tid 67292] [client 135.225.75.187:19210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/byp8.php"] [unique_id "aoSAIfcmepr5_nHgLbM0KgAAAms"]
[Tue Aug 18 12:54:09.099198 2026] [authz_core:error] [pid 67073:tid 67095] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:09.099466 2026] [authz_core:error] [pid 67073:tid 67095] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:09.115598 2026] [security2:error] [pid 67073:tid 67301] [client 172.202.39.151:25685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/zxz.php"] [unique_id "aoSAIfcmepr5_nHgLbM0LAAAAnQ"]
[Tue Aug 18 12:54:09.133350 2026] [security2:error] [pid 67073:tid 67210] [client 20.226.56.190:52068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/92.php"] [unique_id "aoSAIfcmepr5_nHgLbM0LQAAAhk"]
[Tue Aug 18 12:54:09.162358 2026] [security2:error] [pid 67073:tid 67275] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAIfcmepr5_nHgLbM0LwAAAlo"]
[Tue Aug 18 12:54:09.199159 2026] [autoindex:error] [pid 66623:tid 66659] [remote 40.74.68.220:0] AH01276: Cannot serve directory /home3/cp38imobibrasil/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:09.203210 2026] [security2:error] [pid 67073:tid 67251] [client 172.202.39.151:65267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAIfcmepr5_nHgLbM0MAAAAkI"]
[Tue Aug 18 12:54:09.248363 2026] [security2:error] [pid 67073:tid 67235] [client 20.48.236.86:16365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/file1221.php"] [unique_id "aoSAIfcmepr5_nHgLbM0MgAAAjI"]
[Tue Aug 18 12:54:09.402781 2026] [authz_core:error] [pid 67073:tid 67126] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:09.403050 2026] [authz_core:error] [pid 67073:tid 67126] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:09.426675 2026] [security2:error] [pid 67073:tid 67214] [client 74.248.136.165:46456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/dom.php"] [unique_id "aoSAIfcmepr5_nHgLbM0OAAAAh0"]
[Tue Aug 18 12:54:09.456274 2026] [security2:error] [pid 67073:tid 67326] [client 20.171.51.14:45392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/pz.php"] [unique_id "aoSAIfcmepr5_nHgLbM0OQAAAo0"]
[Tue Aug 18 12:54:09.491045 2026] [security2:error] [pid 67073:tid 67257] [client 20.104.85.180:8004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAIfcmepr5_nHgLbM0OwAAAkg"]
[Tue Aug 18 12:54:09.508387 2026] [security2:error] [pid 67073:tid 67311] [client 20.250.13.23:31452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/ws54.php"] [unique_id "aoSAIfcmepr5_nHgLbM0PAAAAn4"]
[Tue Aug 18 12:54:09.547733 2026] [security2:error] [pid 67073:tid 67268] [client 20.65.98.162:21536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/xyn.php"] [unique_id "aoSAIfcmepr5_nHgLbM0PgAAAlM"]
[Tue Aug 18 12:54:09.615614 2026] [security2:error] [pid 67073:tid 67276] [client 5.31.227.224:30438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAIfcmepr5_nHgLbM0QAAAAls"]
[Tue Aug 18 12:54:09.664570 2026] [security2:error] [pid 67073:tid 67076] [remote 57.141.22.88:40286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSAIfcmepr5_nHgLbM0QgACKQA"]
[Tue Aug 18 12:54:09.673523 2026] [security2:error] [pid 67073:tid 67230] [client 49.13.164.148:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "blog.tinna.com.br"] [uri "/index.php"] [unique_id "aoSAIfcmepr5_nHgLbM0PwAAAi0"], referer: http://blog.tinna.com.br
[Tue Aug 18 12:54:09.792166 2026] [security2:error] [pid 67073:tid 67099] [remote 203.99.146.53:47094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mempel.com.br"] [uri "/wp-login.php"] [unique_id "aoSAIPcmepr5_nHgLbM0JgACOxc"]
[Tue Aug 18 12:54:09.884508 2026] [security2:error] [pid 66623:tid 66819] [client 104.209.144.33:31245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/mt/byp.php"] [unique_id "aoSAIdO5rbWdOArH04J9xwAAAT8"]
[Tue Aug 18 12:54:09.900499 2026] [security2:error] [pid 66623:tid 66767] [client 20.104.85.180:8051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/admin.php"] [unique_id "aoSAIdO5rbWdOArH04J9yAAAAQs"]
[Tue Aug 18 12:54:09.905560 2026] [security2:error] [pid 66623:tid 66794] [client 74.248.136.165:42462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/bb.php"] [unique_id "aoSAIdO5rbWdOArH04J9yQAAASY"]
[Tue Aug 18 12:54:09.972040 2026] [security2:error] [pid 67073:tid 67212] [client 20.226.56.190:47148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/jm.php"] [unique_id "aoSAIfcmepr5_nHgLbM0RgAAAhs"]
[Tue Aug 18 12:54:09.986751 2026] [security2:error] [pid 67073:tid 67271] [client 52.238.210.254:10228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/function/function.php"] [unique_id "aoSAIfcmepr5_nHgLbM0RwAAAlY"]
[Tue Aug 18 12:54:10.000285 2026] [security2:error] [pid 66623:tid 66880] [client 5.253.205.188:47636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/fullbackup.bak"] [unique_id "aoSAIdO5rbWdOArH04J9ygAAAXw"], referer: https://medihub.com.br/fullbackup.bak
[Tue Aug 18 12:54:10.002216 2026] [authz_core:error] [pid 67073:tid 67087] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:10.002478 2026] [authz_core:error] [pid 67073:tid 67087] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:10.069072 2026] [security2:error] [pid 67073:tid 67102] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/vx.php"] [unique_id "aoSAIvcmepr5_nHgLbM0SgACfRo"]
[Tue Aug 18 12:54:10.122698 2026] [security2:error] [pid 67073:tid 67280] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSAIvcmepr5_nHgLbM0TAAAAl8"]
[Tue Aug 18 12:54:10.150362 2026] [security2:error] [pid 67073:tid 67332] [client 158.158.74.177:23773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/abcd.php"] [unique_id "aoSAIvcmepr5_nHgLbM0TQAAApM"]
[Tue Aug 18 12:54:10.194496 2026] [security2:error] [pid 66623:tid 66872] [client 20.51.153.15:9214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAItO5rbWdOArH04J9zAAAAXQ"]
[Tue Aug 18 12:54:10.228071 2026] [security2:error] [pid 67073:tid 67302] [client 20.226.56.190:31661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/wj.php"] [unique_id "aoSAIvcmepr5_nHgLbM0UQAAAnU"]
[Tue Aug 18 12:54:10.271298 2026] [security2:error] [pid 67073:tid 67291] [client 20.226.6.191:6643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/alfa.php"] [unique_id "aoSAIvcmepr5_nHgLbM0UwAAAmo"]
[Tue Aug 18 12:54:10.357538 2026] [security2:error] [pid 67073:tid 67138] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ah25.php"] [unique_id "aoSAIvcmepr5_nHgLbM0VQACbz4"]
[Tue Aug 18 12:54:10.426207 2026] [security2:error] [pid 67073:tid 67261] [client 86.120.159.145:2383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAIvcmepr5_nHgLbM0VgAAAkw"]
[Tue Aug 18 12:54:10.426333 2026] [security2:error] [pid 67073:tid 67261] [client 86.120.159.145:2383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAIvcmepr5_nHgLbM0VgAAAkw"]
[Tue Aug 18 12:54:10.483566 2026] [security2:error] [pid 67073:tid 67315] [client 40.85.222.29:2853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSAIvcmepr5_nHgLbM0XQAAAoI"]
[Tue Aug 18 12:54:10.550652 2026] [security2:error] [pid 67073:tid 67228] [client 114.119.128.181:56763] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "brazilcoa.com.br"] [uri "/quem-somos/"] [unique_id "aoSAIvcmepr5_nHgLbM0XgAAAis"], referer: https://brazilcoa.com.br/cacau-como-aproveitar-esta-fruta-tao-especial/
[Tue Aug 18 12:54:10.599727 2026] [security2:error] [pid 67073:tid 67282] [client 20.100.169.31:25972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/atomlib.php"] [unique_id "aoSAIvcmepr5_nHgLbM0YAAAAmE"]
[Tue Aug 18 12:54:10.633361 2026] [security2:error] [pid 66623:tid 66783] [client 104.209.144.33:15692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSAItO5rbWdOArH04J90gAAARs"]
[Tue Aug 18 12:54:10.638221 2026] [security2:error] [pid 66623:tid 66801] [client 104.209.144.33:29834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/dlvqo.php"] [unique_id "aoSAItO5rbWdOArH04J90wAAAS0"]
[Tue Aug 18 12:54:10.639378 2026] [security2:error] [pid 66623:tid 66776] [client 20.226.56.190:31672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/74.php"] [unique_id "aoSAItO5rbWdOArH04J91AAAARQ"]
[Tue Aug 18 12:54:10.645518 2026] [lsapi:error] [pid 67073:tid 67131] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] [host adobank.com.br] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown
[Tue Aug 18 12:54:10.645535 2026] [lsapi:error] [pid 67073:tid 67131] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] [host adobank.com.br] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache
[Tue Aug 18 12:54:10.645541 2026] [lsapi:error] [pid 67073:tid 67131] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] [host adobank.com.br] Client error on sending request(POST /xmlrpc.php HTTP/2.0); uri(/xmlrpc.php) content-length(714): user_get_body(tmpstackbuf, 16384): read from client failed
[Tue Aug 18 12:54:10.674631 2026] [security2:error] [pid 67073:tid 67208] [client 114.119.158.189:30845] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "espacosvilaolimpia.com.br"] [uri "/wp-content/themes/wilcity/assets/vendors"] [unique_id "aoSAIvcmepr5_nHgLbM0YgAAAhc"], referer: https://espacosvilaolimpia.com.br/wp-content/themes/wilcity/assets/vendors?C=M%3BO%3DA
[Tue Aug 18 12:54:10.762704 2026] [security2:error] [pid 67073:tid 67254] [client 172.182.200.96:14285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/bhfnd.php"] [unique_id "aoSAIvcmepr5_nHgLbM0ZwAAAkU"]
[Tue Aug 18 12:54:10.763638 2026] [security2:error] [pid 67073:tid 67276] [client 5.31.227.224:30438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAIfcmepr5_nHgLbM0QAAAAls"]
[Tue Aug 18 12:54:10.908735 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:10.908980 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:10.948455 2026] [security2:error] [pid 67073:tid 67289] [client 74.248.136.165:32971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ok.php"] [unique_id "aoSAIvcmepr5_nHgLbM0hwAAAmg"]
[Tue Aug 18 12:54:11.134103 2026] [security2:error] [pid 67073:tid 67255] [client 132.196.61.152:27274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/1xmomo.php"] [unique_id "aoSAI_cmepr5_nHgLbM0jwAAAkY"]
[Tue Aug 18 12:54:11.174554 2026] [security2:error] [pid 66623:tid 66788] [client 158.158.74.177:9394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/kj.php"] [unique_id "aoSAI9O5rbWdOArH04J93QAAASA"]
[Tue Aug 18 12:54:11.207248 2026] [authz_core:error] [pid 67073:tid 67092] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:11.207543 2026] [authz_core:error] [pid 67073:tid 67092] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:11.275577 2026] [security2:error] [pid 66623:tid 66812] [client 20.104.85.180:7943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/public/css.php"] [unique_id "aoSAI9O5rbWdOArH04J93gAAATg"]
[Tue Aug 18 12:54:11.410935 2026] [security2:error] [pid 67073:tid 67306] [client 74.248.136.165:30165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp9.php"] [unique_id "aoSAI_cmepr5_nHgLbM0kwAAAnk"]
[Tue Aug 18 12:54:11.478616 2026] [security2:error] [pid 66623:tid 66829] [client 135.225.75.187:31421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/plugins.php"] [unique_id "aoSAI9O5rbWdOArH04J93wAAAUk"]
[Tue Aug 18 12:54:11.480373 2026] [security2:error] [pid 67073:tid 67214] [client 74.248.18.37:25069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/simple.php"] [unique_id "aoSAI_cmepr5_nHgLbM0lAAAAh0"]
[Tue Aug 18 12:54:11.508359 2026] [authz_core:error] [pid 67073:tid 67188] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:11.508846 2026] [authz_core:error] [pid 67073:tid 67188] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:11.543120 2026] [security2:error] [pid 67073:tid 67270] [client 149.34.210.141:60440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAI_cmepr5_nHgLbM0mQAAAlU"]
[Tue Aug 18 12:54:11.548403 2026] [security2:error] [pid 67073:tid 67201] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/tt.php"] [unique_id "aoSAI_cmepr5_nHgLbM0mgACNn0"]
[Tue Aug 18 12:54:11.602073 2026] [security2:error] [pid 66623:tid 66789] [client 20.163.43.14:3184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/cah.php"] [unique_id "aoSAI9O5rbWdOArH04J94QAAASE"]
[Tue Aug 18 12:54:11.628802 2026] [security2:error] [pid 66623:tid 66766] [client 20.104.85.180:8023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAI9O5rbWdOArH04J94wAAAQo"]
[Tue Aug 18 12:54:11.694707 2026] [security2:error] [pid 66623:tid 66820] [client 52.238.210.254:10180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-signin.php"] [unique_id "aoSAI9O5rbWdOArH04J95QAAAUA"]
[Tue Aug 18 12:54:11.695568 2026] [security2:error] [pid 66623:tid 66836] [client 20.51.153.15:9142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/st.php"] [unique_id "aoSAI9O5rbWdOArH04J95gAAAVA"]
[Tue Aug 18 12:54:11.830958 2026] [security2:error] [pid 67073:tid 67270] [client 149.34.210.141:60440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAI_cmepr5_nHgLbM0mQAAAlU"]
[Tue Aug 18 12:54:11.879713 2026] [security2:error] [pid 66623:tid 66782] [client 74.248.136.165:48164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ty.php"] [unique_id "aoSAI9O5rbWdOArH04J96AAAARo"]
[Tue Aug 18 12:54:11.882831 2026] [security2:error] [pid 66623:tid 66777] [client 20.48.236.86:10769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/1xmomo.php"] [unique_id "aoSAI9O5rbWdOArH04J96QAAARU"]
[Tue Aug 18 12:54:11.898950 2026] [security2:error] [pid 66623:tid 66844] [client 172.202.39.151:35868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/www.php"] [unique_id "aoSAI9O5rbWdOArH04J96gAAAVg"]
[Tue Aug 18 12:54:11.993557 2026] [security2:error] [pid 67073:tid 67205] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/ncx.php"] [unique_id "aoSAI_cmepr5_nHgLbM0qQAAAhQ"]
[Tue Aug 18 12:54:12.023113 2026] [security2:error] [pid 67073:tid 67311] [client 178.153.171.161:18869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAJPcmepr5_nHgLbM0qgAAAn4"]
[Tue Aug 18 12:54:12.138651 2026] [security2:error] [pid 67073:tid 67263] [client 20.171.51.14:51778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/kk.php"] [unique_id "aoSAJPcmepr5_nHgLbM0rQAAAk4"]
[Tue Aug 18 12:54:12.141309 2026] [security2:error] [pid 66623:tid 66841] [client 20.65.98.162:29443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/inso.php"] [unique_id "aoSAJNO5rbWdOArH04J96wAAAVU"]
[Tue Aug 18 12:54:12.204550 2026] [security2:error] [pid 67073:tid 67213] [client 52.173.121.69:17945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAJPcmepr5_nHgLbM0rwAAAhw"]
[Tue Aug 18 12:54:12.241070 2026] [security2:error] [pid 66623:tid 66846] [client 52.238.210.254:9016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/chosen.php"] [unique_id "aoSAJNO5rbWdOArH04J97AAAAVo"]
[Tue Aug 18 12:54:12.340092 2026] [security2:error] [pid 67073:tid 67279] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAJPcmepr5_nHgLbM0sAAAAl4"]
[Tue Aug 18 12:54:12.361646 2026] [security2:error] [pid 66623:tid 66831] [client 20.118.172.148:15218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/admin.php"] [unique_id "aoSAJNO5rbWdOArH04J97QAAAUs"]
[Tue Aug 18 12:54:12.387591 2026] [security2:error] [pid 67073:tid 67325] [client 20.226.6.191:6611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/lock360.php"] [unique_id "aoSAJPcmepr5_nHgLbM0sQAAAow"]
[Tue Aug 18 12:54:12.439772 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:12.439797 2026] [authz_core:error] [pid 67073:tid 67088] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:12.440042 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:12.440046 2026] [authz_core:error] [pid 67073:tid 67088] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:12.451963 2026] [security2:error] [pid 67073:tid 67223] [client 20.51.153.15:9166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/dirs.php"] [unique_id "aoSAJPcmepr5_nHgLbM0tAAAAiY"]
[Tue Aug 18 12:54:12.453636 2026] [security2:error] [pid 66623:tid 66775] [client 20.42.19.40:2711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/mac.php"] [unique_id "aoSAJNO5rbWdOArH04J98AAAARM"]
[Tue Aug 18 12:54:12.458147 2026] [autoindex:error] [pid 66623:tid 66813] [client 20.104.85.180:8018] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:12.475346 2026] [security2:error] [pid 67073:tid 67132] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/xqq.php"] [unique_id "aoSAJPcmepr5_nHgLbM0twACIjg"]
[Tue Aug 18 12:54:12.492338 2026] [security2:error] [pid 67073:tid 67147] [remote 162.214.205.212:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fabispinazolapilates.com.br"] [uri "/wp-login.php"] [unique_id "aoSAJPcmepr5_nHgLbM0tQACgkc"]
[Tue Aug 18 12:54:12.539797 2026] [security2:error] [pid 67073:tid 67282] [client 20.48.236.86:11068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/mosty.php"] [unique_id "aoSAJPcmepr5_nHgLbM0ugAAAmE"]
[Tue Aug 18 12:54:12.543984 2026] [security2:error] [pid 66623:tid 66827] [client 74.248.18.37:20018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/lock360.php"] [unique_id "aoSAJNO5rbWdOArH04J98QAAAUc"]
[Tue Aug 18 12:54:12.546585 2026] [security2:error] [pid 66623:tid 66889] [client 172.182.200.96:14323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/qfvqu.php"] [unique_id "aoSAJNO5rbWdOArH04J98gAAAYU"]
[Tue Aug 18 12:54:12.576864 2026] [security2:error] [pid 67073:tid 67317] [client 213.202.253.4:57307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/txets.php"] [unique_id "aoSAJPcmepr5_nHgLbM0vAAAAoQ"], referer: www.google.com
[Tue Aug 18 12:54:12.616373 2026] [authz_core:error] [pid 67073:tid 67175] [remote 57.141.22.7:36512] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:12.616742 2026] [authz_core:error] [pid 67073:tid 67175] [remote 57.141.22.7:36512] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:12.633081 2026] [security2:error] [pid 66623:tid 66882] [client 20.100.169.31:25396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAJNO5rbWdOArH04J98wAAAX4"]
[Tue Aug 18 12:54:12.640903 2026] [security2:error] [pid 67073:tid 67322] [client 158.158.74.177:9366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/languages.php"] [unique_id "aoSAJPcmepr5_nHgLbM0wQAAAok"]
[Tue Aug 18 12:54:12.644816 2026] [security2:error] [pid 67073:tid 67252] [client 104.209.144.33:35857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/pkmoj.php"] [unique_id "aoSAJPcmepr5_nHgLbM0wgAAAkM"]
[Tue Aug 18 12:54:12.688220 2026] [security2:error] [pid 67073:tid 67305] [client 20.48.236.86:16265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/nox.php"] [unique_id "aoSAJPcmepr5_nHgLbM0xAAAAng"]
[Tue Aug 18 12:54:12.690036 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:12.690347 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:12.788876 2026] [security2:error] [pid 66623:tid 66828] [client 20.104.85.180:8018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAJNO5rbWdOArH04J99AAAAUg"]
[Tue Aug 18 12:54:12.882111 2026] [security2:error] [pid 67073:tid 67215] [client 20.163.43.14:3175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/system_log.php"] [unique_id "aoSAJPcmepr5_nHgLbM0yAAAAh4"]
[Tue Aug 18 12:54:12.895169 2026] [security2:error] [pid 67073:tid 67233] [client 74.248.136.165:30199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ws59.php"] [unique_id "aoSAJPcmepr5_nHgLbM0yQAAAjA"]
[Tue Aug 18 12:54:12.968070 2026] [security2:error] [pid 66623:tid 66826] [client 172.202.39.151:63109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/admin.php"] [unique_id "aoSAJNO5rbWdOArH04J99QAAAUY"]
[Tue Aug 18 12:54:12.994120 2026] [security2:error] [pid 67073:tid 67231] [client 172.182.200.96:14326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/oivcl.php"] [unique_id "aoSAJPcmepr5_nHgLbM0ywAAAi4"]
[Tue Aug 18 12:54:13.029781 2026] [security2:error] [pid 67073:tid 67235] [client 20.91.215.254:13290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSAJfcmepr5_nHgLbM0zAAAAjI"]
[Tue Aug 18 12:54:13.096300 2026] [security2:error] [pid 67073:tid 67304] [client 20.250.13.23:40586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSAJfcmepr5_nHgLbM00AAAAnc"]
[Tue Aug 18 12:54:13.164103 2026] [security2:error] [pid 67073:tid 67130] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/06.php"] [unique_id "aoSAJfcmepr5_nHgLbM00QACJDY"]
[Tue Aug 18 12:54:13.180746 2026] [security2:error] [pid 67073:tid 67295] [client 20.48.236.86:10693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/blurbs.php"] [unique_id "aoSAJfcmepr5_nHgLbM00wAAAm4"]
[Tue Aug 18 12:54:13.212082 2026] [security2:error] [pid 67073:tid 67308] [client 172.202.39.151:44400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/epinyins.php"] [unique_id "aoSAJfcmepr5_nHgLbM01AAAAns"]
[Tue Aug 18 12:54:13.352396 2026] [security2:error] [pid 67073:tid 67274] [client 74.248.18.37:19969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/log.php"] [unique_id "aoSAJfcmepr5_nHgLbM02AAAAlk"]
[Tue Aug 18 12:54:13.384856 2026] [security2:error] [pid 67073:tid 67109] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/166.php"] [unique_id "aoSAJfcmepr5_nHgLbM02gACRCE"]
[Tue Aug 18 12:54:13.635199 2026] [security2:error] [pid 67073:tid 67300] [client 52.238.210.254:10159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/f35.php"] [unique_id "aoSAJfcmepr5_nHgLbM03AAAAnM"]
[Tue Aug 18 12:54:13.660835 2026] [security2:error] [pid 67073:tid 67248] [client 54.167.223.174:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "markettohome.com.br"] [uri "/index.php"] [unique_id "aoSAIvcmepr5_nHgLbM0VAACPwg"], referer: https://markettohome.com.br/
[Tue Aug 18 12:54:13.672768 2026] [security2:error] [pid 66623:tid 66878] [client 20.104.100.201:17243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-load.php"] [unique_id "aoSAJdO5rbWdOArH04J9-QAAAXo"]
[Tue Aug 18 12:54:13.713638 2026] [security2:error] [pid 66623:tid 66865] [client 135.225.75.187:31373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/100.kb.php"] [unique_id "aoSAJdO5rbWdOArH04J9-wAAAW0"]
[Tue Aug 18 12:54:13.769521 2026] [security2:error] [pid 67073:tid 67291] [client 20.100.169.31:25922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/rip.php"] [unique_id "aoSAJfcmepr5_nHgLbM03QAAAmo"]
[Tue Aug 18 12:54:13.890079 2026] [security2:error] [pid 66623:tid 66819] [client 52.173.121.69:16450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAJdO5rbWdOArH04J9_QAAAT8"]
[Tue Aug 18 12:54:13.918643 2026] [security2:error] [pid 66623:tid 66794] [client 20.151.109.219:36315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/13.php"] [unique_id "aoSAJdO5rbWdOArH04J9_gAAASY"]
[Tue Aug 18 12:54:13.922756 2026] [security2:error] [pid 67073:tid 67296] [client 114.119.155.217:64053] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autofacilchapeco.com.br"] [uri "/veiculo/1029964/fit-lx-1-4-1-4-flex-8v-16v-5p-aut"] [unique_id "aoSAJfcmepr5_nHgLbM05QAAAm8"], referer: https://www.autofacilchapeco.com.br/index.php?pg=detran
[Tue Aug 18 12:54:13.933066 2026] [security2:error] [pid 67073:tid 67331] [client 74.248.136.165:43682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/Ov-Simple1.php"] [unique_id "aoSAJfcmepr5_nHgLbM05wAAApI"]
[Tue Aug 18 12:54:13.952270 2026] [security2:error] [pid 67073:tid 67170] [remote 47.128.58.0:46020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.padariaeconfeitariabrasil.com.br"] [uri "/site/servicos/confeitaria/"] [unique_id "aoSAJfcmepr5_nHgLbM06QACjV4"]
[Tue Aug 18 12:54:13.953305 2026] [security2:error] [pid 67073:tid 67126] [remote 193.104.157.85:55532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.157.104.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ancavisi.com.br"] [uri "/wp-login.php"] [unique_id "aoSAJfcmepr5_nHgLbM04gACXjI"]
[Tue Aug 18 12:54:14.000132 2026] [security2:error] [pid 67073:tid 67102] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/snq.php"] [unique_id "aoSAJfcmepr5_nHgLbM06wACjBo"]
[Tue Aug 18 12:54:14.071928 2026] [security2:error] [pid 66623:tid 66881] [client 20.42.19.40:2190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/nc4.php"] [unique_id "aoSAJtO5rbWdOArH04J-AAAAAX0"]
[Tue Aug 18 12:54:14.118753 2026] [security2:error] [pid 66623:tid 66796] [client 104.209.144.33:24835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAJtO5rbWdOArH04J-AQAAASg"]
[Tue Aug 18 12:54:14.140964 2026] [security2:error] [pid 67073:tid 67261] [client 78.138.24.128:52109] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zanseg.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aoSAJvcmepr5_nHgLbM08AAAAkw"]
[Tue Aug 18 12:54:14.145420 2026] [security2:error] [pid 67073:tid 67223] [client 20.104.85.180:8017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/gelay.php"] [unique_id "aoSAJvcmepr5_nHgLbM08QAAAiY"]
[Tue Aug 18 12:54:14.200654 2026] [security2:error] [pid 66623:tid 66806] [client 20.65.98.162:23847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/puc.php"] [unique_id "aoSAJtO5rbWdOArH04J-AgAAATI"]
[Tue Aug 18 12:54:14.208403 2026] [security2:error] [pid 67073:tid 67104] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-access.php"] [unique_id "aoSAJvcmepr5_nHgLbM08wACghw"]
[Tue Aug 18 12:54:14.295999 2026] [security2:error] [pid 67073:tid 67317] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wso.php"] [unique_id "aoSAJvcmepr5_nHgLbM09gAAAoQ"]
[Tue Aug 18 12:54:14.322176 2026] [security2:error] [pid 67073:tid 67227] [client 20.171.51.14:43387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/phpcheck.php"] [unique_id "aoSAJvcmepr5_nHgLbM0-AAAAio"]
[Tue Aug 18 12:54:14.406182 2026] [security2:error] [pid 67073:tid 67284] [client 74.248.136.165:43707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSAJvcmepr5_nHgLbM0-wAAAmM"]
[Tue Aug 18 12:54:14.413291 2026] [security2:error] [pid 66623:tid 66868] [client 172.182.200.96:14231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/zugvi.php"] [unique_id "aoSAJtO5rbWdOArH04J-AwAAAXA"]
[Tue Aug 18 12:54:14.447208 2026] [security2:error] [pid 67073:tid 67091] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/nw.php"] [unique_id "aoSAJvcmepr5_nHgLbM0_wACIQ8"]
[Tue Aug 18 12:54:14.476680 2026] [security2:error] [pid 67073:tid 67216] [client 20.118.172.148:7589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAJvcmepr5_nHgLbM1AAAAAh8"]
[Tue Aug 18 12:54:14.499504 2026] [authz_core:error] [pid 67073:tid 67105] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:14.499773 2026] [authz_core:error] [pid 67073:tid 67105] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:14.500283 2026] [security2:error] [pid 66623:tid 66786] [client 40.85.222.29:18830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAJtO5rbWdOArH04J-BAAAAR4"]
[Tue Aug 18 12:54:14.506659 2026] [security2:error] [pid 67073:tid 67208] [client 20.104.85.180:8030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAJvcmepr5_nHgLbM1AgAAAhc"]
[Tue Aug 18 12:54:14.649106 2026] [security2:error] [pid 67073:tid 67211] [client 52.238.210.254:8392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/simple.php"] [unique_id "aoSAJvcmepr5_nHgLbM1BgAAAho"]
[Tue Aug 18 12:54:14.657971 2026] [security2:error] [pid 67073:tid 67085] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ws62.php"] [unique_id "aoSAJvcmepr5_nHgLbM1BwACLgk"]
[Tue Aug 18 12:54:14.661130 2026] [security2:error] [pid 67073:tid 67305] [client 74.248.18.37:21424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/lv.php"] [unique_id "aoSAJvcmepr5_nHgLbM1CAAAAng"]
[Tue Aug 18 12:54:14.671612 2026] [security2:error] [pid 67073:tid 67289] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/zup.php73"] [unique_id "aoSAJvcmepr5_nHgLbM1CQAAAmg"]
[Tue Aug 18 12:54:14.794036 2026] [autoindex:error] [pid 66623:tid 66876] [client 158.158.74.177:9344] AH01276: Cannot serve directory /home3/evandrobene/public_html/wp-content/uploads/2022/07/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:14.850931 2026] [security2:error] [pid 67073:tid 67233] [client 85.208.96.195:20048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1752870780/1753920000/"] [unique_id "aoSAJvcmepr5_nHgLbM1CwAAAjA"]
[Tue Aug 18 12:54:14.851056 2026] [security2:error] [pid 67073:tid 67233] [client 85.208.96.195:20048] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1752870780/1753920000/"] [unique_id "aoSAJvcmepr5_nHgLbM1CwAAAjA"]
[Tue Aug 18 12:54:15.003973 2026] [authz_core:error] [pid 66623:tid 66705] [remote 57.141.22.42:52118] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:15.004236 2026] [authz_core:error] [pid 66623:tid 66705] [remote 57.141.22.42:52118] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:15.061977 2026] [security2:error] [pid 67073:tid 67304] [client 4.232.151.198:48145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/mah/function.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1DwAAAnc"]
[Tue Aug 18 12:54:15.094369 2026] [security2:error] [pid 66623:tid 66821] [client 104.209.144.33:24837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAJ9O5rbWdOArH04J-DgAAAUE"]
[Tue Aug 18 12:54:15.103147 2026] [security2:error] [pid 67073:tid 67226] [client 157.51.166.53:53187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1EQAAAik"]
[Tue Aug 18 12:54:15.103305 2026] [security2:error] [pid 67073:tid 67226] [client 157.51.166.53:53187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1EQAAAik"]
[Tue Aug 18 12:54:15.110215 2026] [authz_core:error] [pid 67073:tid 67116] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:15.110481 2026] [authz_core:error] [pid 67073:tid 67116] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:15.323387 2026] [security2:error] [pid 67073:tid 67239] [client 20.104.85.180:8066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1FAAAAjY"]
[Tue Aug 18 12:54:15.332653 2026] [security2:error] [pid 67073:tid 67312] [client 20.226.6.191:6650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/flower.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1FQAAAn8"]
[Tue Aug 18 12:54:15.364100 2026] [security2:error] [pid 66623:tid 66766] [client 172.182.200.96:14277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wsrer.php"] [unique_id "aoSAJ9O5rbWdOArH04J-PAAAAQo"]
[Tue Aug 18 12:54:15.401527 2026] [authz_core:error] [pid 67073:tid 67089] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:15.401845 2026] [authz_core:error] [pid 67073:tid 67089] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:15.453880 2026] [security2:error] [pid 67073:tid 67212] [client 74.248.136.165:44742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/vx.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1FwAAAhs"]
[Tue Aug 18 12:54:15.491142 2026] [security2:error] [pid 67073:tid 67271] [client 172.202.39.151:62675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1GAAAAlY"]
[Tue Aug 18 12:54:15.520201 2026] [security2:error] [pid 67073:tid 67247] [client 20.151.109.219:58321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/so.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1GQAAAj4"]
[Tue Aug 18 12:54:15.527473 2026] [security2:error] [pid 66623:tid 66886] [client 104.209.144.33:31272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSAJ9O5rbWdOArH04J-PgAAAYI"]
[Tue Aug 18 12:54:15.577300 2026] [autoindex:error] [pid 66623:tid 66817] [client 52.73.140.57:45938] AH01276: Cannot serve directory /home2/atlasi11/About.atlas-ia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:15.602625 2026] [security2:error] [pid 66623:tid 66867] [client 20.118.172.148:48713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/akc.php"] [unique_id "aoSAJ9O5rbWdOArH04J-QAAAAW8"]
[Tue Aug 18 12:54:15.697611 2026] [security2:error] [pid 67073:tid 67125] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/public/vx.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1KgACczE"]
[Tue Aug 18 12:54:15.739912 2026] [security2:error] [pid 66623:tid 66790] [client 103.120.71.157:1299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAJtO5rbWdOArH04J-BgAAASI"]
[Tue Aug 18 12:54:15.740073 2026] [security2:error] [pid 66623:tid 66790] [client 103.120.71.157:1299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAJtO5rbWdOArH04J-BgAAASI"]
[Tue Aug 18 12:54:15.918917 2026] [security2:error] [pid 66623:tid 66846] [client 20.42.19.40:2181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/as.php"] [unique_id "aoSAJ9O5rbWdOArH04J-YgAAAVo"]
[Tue Aug 18 12:54:15.927201 2026] [security2:error] [pid 67073:tid 67308] [client 20.250.13.23:21185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/function/function.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1LAAAAns"]
[Tue Aug 18 12:54:15.931515 2026] [security2:error] [pid 66623:tid 66799] [client 74.248.136.165:30178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ah25.php"] [unique_id "aoSAJ9O5rbWdOArH04J-YwAAASs"]
[Tue Aug 18 12:54:16.029323 2026] [security2:error] [pid 67073:tid 67241] [client 20.171.51.14:58819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/dg.php"] [unique_id "aoSAKPcmepr5_nHgLbM1LQAAAjg"]
[Tue Aug 18 12:54:16.063039 2026] [security2:error] [pid 67073:tid 67223] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/k.php"] [unique_id "aoSAKPcmepr5_nHgLbM1LgAAAiY"]
[Tue Aug 18 12:54:16.139991 2026] [security2:error] [pid 67073:tid 67320] [client 20.48.236.86:16377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/akismet.php"] [unique_id "aoSAKPcmepr5_nHgLbM1MQAAAoc"]
[Tue Aug 18 12:54:16.233002 2026] [security2:error] [pid 66623:tid 66866] [client 158.158.74.177:9344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/nw.php"] [unique_id "aoSAKNO5rbWdOArH04J-ZgAAAW4"]
[Tue Aug 18 12:54:16.343824 2026] [security2:error] [pid 67073:tid 67201] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/loxi-o.php"] [unique_id "aoSAKPcmepr5_nHgLbM1PAACaX0"]
[Tue Aug 18 12:54:16.344853 2026] [security2:error] [pid 67073:tid 67284] [client 68.155.154.236:64489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAKPcmepr5_nHgLbM1PQAAAmM"]
[Tue Aug 18 12:54:16.362582 2026] [security2:error] [pid 67073:tid 67220] [client 20.163.43.14:3087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAKPcmepr5_nHgLbM1PwAAAiM"]
[Tue Aug 18 12:54:16.410170 2026] [security2:error] [pid 67073:tid 67266] [client 74.248.136.165:30144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/tt.php"] [unique_id "aoSAKPcmepr5_nHgLbM1QQAAAlE"]
[Tue Aug 18 12:54:16.429778 2026] [security2:error] [pid 66623:tid 66775] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-blink.php"] [unique_id "aoSAKNO5rbWdOArH04J-aAAAARM"]
[Tue Aug 18 12:54:16.527127 2026] [security2:error] [pid 67073:tid 67318] [client 172.202.39.151:56901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wicked.php"] [unique_id "aoSAKPcmepr5_nHgLbM1RQAAAoU"]
[Tue Aug 18 12:54:16.537463 2026] [security2:error] [pid 67073:tid 67127] [remote 157.55.39.52:60134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2026/08/15/study-report-on-pirots-5s-compatibility-across-different-devices/"] [unique_id "aoSAKPcmepr5_nHgLbM1RgACTDM"]
[Tue Aug 18 12:54:16.556892 2026] [security2:error] [pid 67073:tid 67264] [client 20.48.236.86:16313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/admin.php"] [unique_id "aoSAKPcmepr5_nHgLbM1RwAAAk8"]
[Tue Aug 18 12:54:16.599382 2026] [security2:error] [pid 67073:tid 67189] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/sdsa.php"] [unique_id "aoSAKPcmepr5_nHgLbM1SQACgXE"]
[Tue Aug 18 12:54:16.810916 2026] [security2:error] [pid 66623:tid 66772] [client 20.91.215.254:12716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSAKNO5rbWdOArH04J-awAAARA"]
[Tue Aug 18 12:54:16.829494 2026] [security2:error] [pid 67073:tid 67080] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-freya.php"] [unique_id "aoSAKPcmepr5_nHgLbM1SwACSwQ"]
[Tue Aug 18 12:54:16.905329 2026] [authz_core:error] [pid 67073:tid 67167] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:16.905590 2026] [authz_core:error] [pid 67073:tid 67167] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:17.025066 2026] [security2:error] [pid 67073:tid 67323] [client 104.209.144.33:29867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/kopyw.php"] [unique_id "aoSAKfcmepr5_nHgLbM1TgAAAoo"]
[Tue Aug 18 12:54:17.151453 2026] [security2:error] [pid 67073:tid 67254] [client 40.85.222.29:16560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAKfcmepr5_nHgLbM1UwAAAkU"]
[Tue Aug 18 12:54:17.197881 2026] [security2:error] [pid 66623:tid 66862] [client 43.155.129.131:45818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.129.155.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "campingatoba.com.br"] [uri "/wp-login.php"] [unique_id "aoSAI9O5rbWdOArH04J95wAAAWo"]
[Tue Aug 18 12:54:17.273168 2026] [security2:error] [pid 67073:tid 67222] [client 160.120.140.123:54500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAKfcmepr5_nHgLbM1VwAAAiU"]
[Tue Aug 18 12:54:17.273314 2026] [security2:error] [pid 67073:tid 67222] [client 160.120.140.123:54500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAKfcmepr5_nHgLbM1VwAAAiU"]
[Tue Aug 18 12:54:17.281834 2026] [security2:error] [pid 67073:tid 67330] [client 85.154.68.202:9217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAKfcmepr5_nHgLbM1WAAAApE"]
[Tue Aug 18 12:54:17.281957 2026] [security2:error] [pid 67073:tid 67330] [client 85.154.68.202:9217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAKfcmepr5_nHgLbM1WAAAApE"]
[Tue Aug 18 12:54:17.404394 2026] [security2:error] [pid 66623:tid 66879] [client 135.225.75.187:33039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/mamzi.php"] [unique_id "aoSAKdO5rbWdOArH04J-bQAAAXs"]
[Tue Aug 18 12:54:17.436903 2026] [security2:error] [pid 67073:tid 67278] [client 52.173.121.69:17961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/weozh.php"] [unique_id "aoSAKfcmepr5_nHgLbM1WgAAAl0"]
[Tue Aug 18 12:54:17.439996 2026] [security2:error] [pid 66623:tid 66815] [client 74.248.136.165:16884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/vgtyu.php"] [unique_id "aoSAKdO5rbWdOArH04J-bwAAATs"]
[Tue Aug 18 12:54:17.442187 2026] [security2:error] [pid 66623:tid 66814] [client 20.51.153.15:9199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/sn.php"] [unique_id "aoSAKdO5rbWdOArH04J-cAAAATo"]
[Tue Aug 18 12:54:17.452525 2026] [security2:error] [pid 67073:tid 67142] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/fleen.php"] [unique_id "aoSAKfcmepr5_nHgLbM1WwACHUI"]
[Tue Aug 18 12:54:17.507438 2026] [security2:error] [pid 67073:tid 67311] [client 178.153.171.161:18869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "400"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAJPcmepr5_nHgLbM0qgAAAn4"]
[Tue Aug 18 12:54:17.515004 2026] [security2:error] [pid 67073:tid 67239] [client 20.118.172.148:39701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/buy.php"] [unique_id "aoSAKfcmepr5_nHgLbM1XgAAAjY"]
[Tue Aug 18 12:54:17.639853 2026] [security2:error] [pid 67073:tid 67306] [client 20.91.215.254:12718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSAKfcmepr5_nHgLbM1YAAAAnk"]
[Tue Aug 18 12:54:17.715806 2026] [security2:error] [pid 66623:tid 66884] [client 172.182.200.96:14178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSAKdO5rbWdOArH04J-cgAAAYA"]
[Tue Aug 18 12:54:17.736449 2026] [security2:error] [pid 66623:tid 66878] [client 68.155.154.236:62599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSAKdO5rbWdOArH04J-cwAAAXo"]
[Tue Aug 18 12:54:17.767148 2026] [security2:error] [pid 66623:tid 66865] [client 20.104.100.201:17405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/jj.php"] [unique_id "aoSAKdO5rbWdOArH04J-dAAAAW0"]
[Tue Aug 18 12:54:17.790914 2026] [authz_core:error] [pid 67073:tid 67136] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:17.791191 2026] [authz_core:error] [pid 67073:tid 67136] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:17.795779 2026] [security2:error] [pid 67073:tid 67237] [client 196.12.128.158:56784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAKfcmepr5_nHgLbM1ZAAAAjQ"]
[Tue Aug 18 12:54:17.795881 2026] [security2:error] [pid 67073:tid 67237] [client 196.12.128.158:56784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAKfcmepr5_nHgLbM1ZAAAAjQ"]
[Tue Aug 18 12:54:17.812922 2026] [security2:error] [pid 66623:tid 66856] [client 114.119.158.58:41047] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lojaodovidraceiro.com"] [uri "/categoria-produto/vidros/"] [unique_id "aoSAKdO5rbWdOArH04J-dQAAAWQ"], referer: https://lojaodovidraceiro.com/categoria-produto/acessorios
[Tue Aug 18 12:54:17.881777 2026] [security2:error] [pid 67073:tid 67292] [client 20.65.98.162:18087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/19.php"] [unique_id "aoSAKfcmepr5_nHgLbM1bAAAAms"]
[Tue Aug 18 12:54:17.934592 2026] [security2:error] [pid 67073:tid 67248] [client 20.48.236.86:16370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/bajah.php"] [unique_id "aoSAKfcmepr5_nHgLbM1bgAAAj8"]
[Tue Aug 18 12:54:17.964689 2026] [security2:error] [pid 67073:tid 67291] [client 52.173.121.69:24991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/rymmm.php"] [unique_id "aoSAKfcmepr5_nHgLbM1cAAAAmo"]
[Tue Aug 18 12:54:18.091264 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:18.091519 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:18.111479 2026] [security2:error] [pid 67073:tid 67273] [client 74.248.133.44:12083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/filemanager.php"] [unique_id "aoSAKvcmepr5_nHgLbM1dgAAAlg"]
[Tue Aug 18 12:54:18.279307 2026] [security2:error] [pid 67073:tid 67182] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/e.php"] [unique_id "aoSAKvcmepr5_nHgLbM1egACgmo"]
[Tue Aug 18 12:54:18.315040 2026] [security2:error] [pid 66623:tid 66800] [client 37.40.227.74:56729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAKtO5rbWdOArH04J-egAAASw"]
[Tue Aug 18 12:54:18.315136 2026] [security2:error] [pid 66623:tid 66800] [client 37.40.227.74:56729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAKtO5rbWdOArH04J-egAAASw"]
[Tue Aug 18 12:54:18.320268 2026] [security2:error] [pid 67073:tid 67327] [client 20.48.236.86:16380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/ajax.php"] [unique_id "aoSAKvcmepr5_nHgLbM1fAAAAo4"]
[Tue Aug 18 12:54:18.359599 2026] [security2:error] [pid 67073:tid 67256] [client 114.119.155.69:63481] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mahokosveiculos.com.br"] [uri "/Anuncio/Details/551182"] [unique_id "aoSAKvcmepr5_nHgLbM1fQAAAkc"], referer: http://www.mahokosveiculos.com.br/Anuncio/Details/487903
[Tue Aug 18 12:54:18.433201 2026] [security2:error] [pid 66623:tid 66888] [client 172.202.39.151:44407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSAKtO5rbWdOArH04J-fAAAAYQ"]
[Tue Aug 18 12:54:18.512434 2026] [security2:error] [pid 67073:tid 67188] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/hello.php"] [unique_id "aoSAKvcmepr5_nHgLbM1fwACI3A"]
[Tue Aug 18 12:54:18.528570 2026] [security2:error] [pid 66623:tid 66854] [client 52.238.210.254:10149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/gg.php"] [unique_id "aoSAKtO5rbWdOArH04J-fQAAAWI"]
[Tue Aug 18 12:54:18.534245 2026] [security2:error] [pid 67073:tid 67218] [client 52.173.121.69:17981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/lddxs.php"] [unique_id "aoSAKvcmepr5_nHgLbM1gAAAAiE"]
[Tue Aug 18 12:54:18.651797 2026] [security2:error] [pid 67073:tid 67264] [client 20.104.100.201:58913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/cok.php"] [unique_id "aoSAKvcmepr5_nHgLbM1gwAAAk8"]
[Tue Aug 18 12:54:18.691822 2026] [security2:error] [pid 66623:tid 66794] [client 20.91.215.254:20546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/st.php"] [unique_id "aoSAKtO5rbWdOArH04J-fwAAASY"]
[Tue Aug 18 12:54:18.702743 2026] [security2:error] [pid 67073:tid 67238] [client 20.100.169.31:25359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/ws83.php"] [unique_id "aoSAKvcmepr5_nHgLbM1hQAAAjU"]
[Tue Aug 18 12:54:18.726119 2026] [security2:error] [pid 67073:tid 67086] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/brc.php"] [unique_id "aoSAKvcmepr5_nHgLbM1hgACdAo"]
[Tue Aug 18 12:54:18.799007 2026] [security2:error] [pid 67073:tid 67316] [client 4.232.151.198:6146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSAKvcmepr5_nHgLbM1hwAAAoM"]
[Tue Aug 18 12:54:18.802929 2026] [security2:error] [pid 67073:tid 67283] [client 172.182.200.96:14302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/ucpfr.php"] [unique_id "aoSAKvcmepr5_nHgLbM1iQAAAmI"]
[Tue Aug 18 12:54:18.844296 2026] [security2:error] [pid 67073:tid 67260] [client 20.51.153.15:9096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/43.php"] [unique_id "aoSAKvcmepr5_nHgLbM1jAAAAks"]
[Tue Aug 18 12:54:18.985125 2026] [security2:error] [pid 67073:tid 67281] [client 104.209.144.33:19615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/zznmg.php"] [unique_id "aoSAKvcmepr5_nHgLbM1kgAAAmA"]
[Tue Aug 18 12:54:18.989944 2026] [security2:error] [pid 67073:tid 67222] [client 20.104.100.201:58891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/accesson.php"] [unique_id "aoSAKvcmepr5_nHgLbM1kwAAAiU"]
[Tue Aug 18 12:54:19.026660 2026] [security2:error] [pid 67073:tid 67302] [client 103.184.169.37:41315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK_cmepr5_nHgLbM1lAAAAnU"]
[Tue Aug 18 12:54:19.026819 2026] [security2:error] [pid 67073:tid 67302] [client 103.184.169.37:41315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK_cmepr5_nHgLbM1lAAAAnU"]
[Tue Aug 18 12:54:19.066153 2026] [security2:error] [pid 66623:tid 66835] [client 52.173.121.69:17969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/zjggu.php"] [unique_id "aoSAK9O5rbWdOArH04J-lgAAAU8"]
[Tue Aug 18 12:54:19.088443 2026] [security2:error] [pid 67073:tid 67224] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/ww5.php"] [unique_id "aoSAK_cmepr5_nHgLbM1lQAAAic"]
[Tue Aug 18 12:54:19.088855 2026] [security2:error] [pid 67073:tid 67278] [client 104.209.144.33:24845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSAK_cmepr5_nHgLbM1lgAAAl0"]
[Tue Aug 18 12:54:19.136446 2026] [authz_core:error] [pid 67073:tid 67180] [remote 57.141.22.114:49336] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:19.136922 2026] [authz_core:error] [pid 67073:tid 67180] [remote 57.141.22.114:49336] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:19.159866 2026] [security2:error] [pid 67073:tid 67244] [client 20.51.153.15:9133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/fresh.php"] [unique_id "aoSAK_cmepr5_nHgLbM1mQAAAjs"]
[Tue Aug 18 12:54:19.191949 2026] [security2:error] [pid 66623:tid 66890] [client 74.7.230.22:46944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.memorialpax.com.br"] [uri "/index.php"] [unique_id "aoSAK9O5rbWdOArH04J-lwABhjo"]
[Tue Aug 18 12:54:19.205549 2026] [security2:error] [pid 66623:tid 66766] [client 20.42.19.40:2730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/k.php"] [unique_id "aoSAK9O5rbWdOArH04J-mQAAAQo"]
[Tue Aug 18 12:54:19.234863 2026] [security2:error] [pid 67073:tid 67211] [client 197.184.64.235:41917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK_cmepr5_nHgLbM1nQAAAho"]
[Tue Aug 18 12:54:19.244344 2026] [security2:error] [pid 67073:tid 67329] [client 172.182.200.96:14276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/yxijx.php"] [unique_id "aoSAK_cmepr5_nHgLbM1ngAAApA"]
[Tue Aug 18 12:54:19.344133 2026] [security2:error] [pid 67073:tid 67237] [client 20.104.100.201:58434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/av.php"] [unique_id "aoSAK_cmepr5_nHgLbM1oAAAAjQ"]
[Tue Aug 18 12:54:19.369913 2026] [security2:error] [pid 67073:tid 67298] [client 132.196.61.152:56072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/mosty.php"] [unique_id "aoSAK_cmepr5_nHgLbM1ogAAAnE"]
[Tue Aug 18 12:54:19.393122 2026] [security2:error] [pid 67073:tid 67293] [client 20.91.215.254:20592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSAK_cmepr5_nHgLbM1owAAAmw"]
[Tue Aug 18 12:54:19.404158 2026] [security2:error] [pid 67073:tid 67174] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/file52.php"] [unique_id "aoSAK_cmepr5_nHgLbM1pQACP2I"]
[Tue Aug 18 12:54:19.466206 2026] [autoindex:error] [pid 67073:tid 67289] [client 74.248.133.44:45712] AH01276: Cannot serve directory /home3/hyundai/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:19.480343 2026] [security2:error] [pid 67073:tid 67124] [remote 179.64.21.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powerbelt.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK_cmepr5_nHgLbM1qAACTjA"]
[Tue Aug 18 12:54:19.480568 2026] [security2:error] [pid 67073:tid 67263] [client 179.64.21.92:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "powerbelt.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK_cmepr5_nHgLbM1qAACTjA"]
[Tue Aug 18 12:54:19.488509 2026] [security2:error] [pid 67073:tid 67279] [client 68.155.154.236:63334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/well-known/index.php"] [unique_id "aoSAK_cmepr5_nHgLbM1qQAAAl4"]
[Tue Aug 18 12:54:19.568546 2026] [security2:error] [pid 66623:tid 66651] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAK9O5rbWdOArH04J-ogABPQ4"]
[Tue Aug 18 12:54:19.584126 2026] [security2:error] [pid 66623:tid 66704] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAK9O5rbWdOArH04J-owABEUM"]
[Tue Aug 18 12:54:19.597877 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:19.598156 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:19.638173 2026] [security2:error] [pid 67073:tid 67267] [client 20.171.51.14:61442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/bm.php"] [unique_id "aoSAK_cmepr5_nHgLbM1rQAAAlI"]
[Tue Aug 18 12:54:19.672664 2026] [security2:error] [pid 67073:tid 67249] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSAK_cmepr5_nHgLbM1rgAAAkA"]
[Tue Aug 18 12:54:19.675950 2026] [security2:error] [pid 66623:tid 66660] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/weozh.php"] [unique_id "aoSAK9O5rbWdOArH04J-pQABUxc"]
[Tue Aug 18 12:54:19.686911 2026] [security2:error] [pid 66623:tid 66807] [client 20.104.100.201:58443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/kj.php"] [unique_id "aoSAK9O5rbWdOArH04J-pgAAATM"]
[Tue Aug 18 12:54:19.748975 2026] [security2:error] [pid 67073:tid 67209] [client 104.234.53.26:31911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samavelveiculos.com.br"] [uri "/wp-login.php"] [unique_id "aoSAKvcmepr5_nHgLbM1hAAAAhg"]
[Tue Aug 18 12:54:19.757117 2026] [security2:error] [pid 66623:tid 66681] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/rymmm.php"] [unique_id "aoSAK9O5rbWdOArH04J-pwABVSw"]
[Tue Aug 18 12:54:19.764775 2026] [security2:error] [pid 66623:tid 66793] [client 138.36.100.162:42602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK9O5rbWdOArH04J-qAAAASU"]
[Tue Aug 18 12:54:19.764886 2026] [security2:error] [pid 66623:tid 66793] [client 138.36.100.162:42602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK9O5rbWdOArH04J-qAAAASU"]
[Tue Aug 18 12:54:19.772829 2026] [security2:error] [pid 67073:tid 67324] [client 74.248.133.44:45712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAK_cmepr5_nHgLbM1sAAAAos"]
[Tue Aug 18 12:54:19.774267 2026] [security2:error] [pid 66623:tid 66661] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/lddxs.php"] [unique_id "aoSAK9O5rbWdOArH04J-qQABZRg"]
[Tue Aug 18 12:54:19.776263 2026] [security2:error] [pid 67073:tid 67253] [client 4.232.151.198:6161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/mass.php"] [unique_id "aoSAK_cmepr5_nHgLbM1sQAAAkQ"]
[Tue Aug 18 12:54:19.778157 2026] [security2:error] [pid 67073:tid 67327] [client 20.104.100.201:17357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/img.php"] [unique_id "aoSAK_cmepr5_nHgLbM1sgAAAo4"]
[Tue Aug 18 12:54:19.786654 2026] [security2:error] [pid 67073:tid 67282] [client 20.163.43.14:3125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAK_cmepr5_nHgLbM1tAAAAmE"]
[Tue Aug 18 12:54:19.794074 2026] [security2:error] [pid 67073:tid 67256] [client 52.173.121.69:25001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/dlvqo.php"] [unique_id "aoSAK_cmepr5_nHgLbM1tQAAAkc"]
[Tue Aug 18 12:54:19.819577 2026] [security2:error] [pid 67073:tid 67214] [client 5.31.227.224:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK_cmepr5_nHgLbM1ugAAAh0"]
[Tue Aug 18 12:54:19.819687 2026] [security2:error] [pid 67073:tid 67214] [client 5.31.227.224:59060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK_cmepr5_nHgLbM1ugAAAh0"]
[Tue Aug 18 12:54:19.827870 2026] [security2:error] [pid 67073:tid 67239] [client 114.119.132.171:62037] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.confiancaveiculostj.com.br"] [uri "/veiculo/176235/c3-excl-1-6-vti-flex-start-16v-5p-mec"] [unique_id "aoSAK_cmepr5_nHgLbM1uwAAAjY"], referer: https://www.confiancaveiculostj.com.br/veiculo/176235/c3-excl-1-6-vti-flex-start-16v-5p-mec
[Tue Aug 18 12:54:19.848159 2026] [security2:error] [pid 66623:tid 66797] [client 74.248.136.165:65315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/xqq.php"] [unique_id "aoSAK9O5rbWdOArH04J-qgAAASk"]
[Tue Aug 18 12:54:19.884645 2026] [security2:error] [pid 66623:tid 66727] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/zjggu.php"] [unique_id "aoSAK9O5rbWdOArH04J-qwABZ1o"]
[Tue Aug 18 12:54:19.963425 2026] [security2:error] [pid 67073:tid 67216] [client 78.138.24.128:52182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.24.138.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zanseg.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAKfcmepr5_nHgLbM1bQAAAh8"]
[Tue Aug 18 12:54:19.969005 2026] [security2:error] [pid 67073:tid 67314] [client 20.51.153.15:9138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/gj.php"] [unique_id "aoSAK_cmepr5_nHgLbM1vQAAAoE"]
[Tue Aug 18 12:54:19.970070 2026] [security2:error] [pid 67073:tid 67240] [client 20.104.100.201:58458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSAK_cmepr5_nHgLbM1vgAAAjc"]
[Tue Aug 18 12:54:20.006854 2026] [security2:error] [pid 67073:tid 67185] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/sxdfrt.php"] [unique_id "aoSALPcmepr5_nHgLbM1wAACYm0"]
[Tue Aug 18 12:54:20.021698 2026] [security2:error] [pid 67073:tid 67317] [client 158.158.74.177:15844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSALPcmepr5_nHgLbM1wQAAAoQ"]
[Tue Aug 18 12:54:20.045234 2026] [security2:error] [pid 67073:tid 67210] [client 20.151.109.219:22929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/10.php"] [unique_id "aoSALPcmepr5_nHgLbM1xAAAAhk"]
[Tue Aug 18 12:54:20.058957 2026] [security2:error] [pid 67073:tid 67235] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/2.php"] [unique_id "aoSALPcmepr5_nHgLbM1xQAAAjI"]
[Tue Aug 18 12:54:20.067517 2026] [security2:error] [pid 66623:tid 66696] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/dlvqo.php"] [unique_id "aoSALNO5rbWdOArH04J-rQABbjs"]
[Tue Aug 18 12:54:20.083202 2026] [security2:error] [pid 66623:tid 66749] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/pkmoj.php"] [unique_id "aoSALNO5rbWdOArH04J-rgABW3A"]
[Tue Aug 18 12:54:20.105510 2026] [authz_core:error] [pid 67073:tid 67087] [remote 57.141.22.6:53752] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:20.105781 2026] [authz_core:error] [pid 67073:tid 67087] [remote 57.141.22.6:53752] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:20.107018 2026] [security2:error] [pid 67073:tid 67326] [client 20.91.215.254:20555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-configs.php"] [unique_id "aoSALPcmepr5_nHgLbM1yQAAAo0"]
[Tue Aug 18 12:54:20.127365 2026] [security2:error] [pid 67073:tid 67222] [client 20.163.43.14:3191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/abc.php"] [unique_id "aoSALPcmepr5_nHgLbM1zAAAAiU"]
[Tue Aug 18 12:54:20.137546 2026] [security2:error] [pid 66623:tid 66648] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/kopyw.php"] [unique_id "aoSALNO5rbWdOArH04J-tQABRws"]
[Tue Aug 18 12:54:20.152238 2026] [security2:error] [pid 66623:tid 66637] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/zznmg.php"] [unique_id "aoSALNO5rbWdOArH04J-tgABTQA"]
[Tue Aug 18 12:54:20.155002 2026] [security2:error] [pid 67073:tid 67224] [client 20.171.51.14:65128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/vu.php"] [unique_id "aoSALPcmepr5_nHgLbM1zgAAAic"]
[Tue Aug 18 12:54:20.168641 2026] [security2:error] [pid 67073:tid 67244] [client 40.85.222.29:31688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSALPcmepr5_nHgLbM1zwAAAjs"]
[Tue Aug 18 12:54:20.210367 2026] [security2:error] [pid 67073:tid 67158] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/path.php"] [unique_id "aoSALPcmepr5_nHgLbM10QACVlI"]
[Tue Aug 18 12:54:20.232800 2026] [security2:error] [pid 66623:tid 66716] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/bhfnd.php"] [unique_id "aoSALNO5rbWdOArH04J-ugABak8"]
[Tue Aug 18 12:54:20.249249 2026] [security2:error] [pid 67073:tid 67313] [client 20.104.100.201:58934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/png.php"] [unique_id "aoSALPcmepr5_nHgLbM10wAAAoA"]
[Tue Aug 18 12:54:20.268086 2026] [security2:error] [pid 66623:tid 66838] [client 74.248.136.165:62755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/06.php"] [unique_id "aoSALNO5rbWdOArH04J-uwAAAVI"]
[Tue Aug 18 12:54:20.276271 2026] [security2:error] [pid 67073:tid 67293] [client 20.65.98.162:21021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/133.php"] [unique_id "aoSALPcmepr5_nHgLbM11AAAAmw"]
[Tue Aug 18 12:54:20.277138 2026] [security2:error] [pid 66623:tid 66751] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/qfvqu.php"] [unique_id "aoSALNO5rbWdOArH04J-vQABOnI"]
[Tue Aug 18 12:54:20.315501 2026] [security2:error] [pid 67073:tid 67242] [client 74.248.18.37:28391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/edit-tags.php"] [unique_id "aoSALPcmepr5_nHgLbM12QAAAjk"]
[Tue Aug 18 12:54:20.335891 2026] [security2:error] [pid 67073:tid 67249] [client 172.182.200.96:14186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSALPcmepr5_nHgLbM12wAAAkA"]
[Tue Aug 18 12:54:20.336920 2026] [security2:error] [pid 67073:tid 67100] [remote 47.89.174.181:64940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agenda.automasantos.com.br"] [uri "/.env"] [unique_id "aoSALPcmepr5_nHgLbM12gACkBg"]
[Tue Aug 18 12:54:20.394030 2026] [security2:error] [pid 66623:tid 66733] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/oivcl.php"] [unique_id "aoSALNO5rbWdOArH04J-vgABI2A"]
[Tue Aug 18 12:54:20.400024 2026] [security2:error] [pid 67073:tid 67122] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wpo.php"] [unique_id "aoSALPcmepr5_nHgLbM13QACTC4"]
[Tue Aug 18 12:54:20.400388 2026] [security2:error] [pid 66623:tid 66882] [client 4.232.151.198:6156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/memberfuns.php"] [unique_id "aoSALNO5rbWdOArH04J-vwAAAX4"]
[Tue Aug 18 12:54:20.403132 2026] [security2:error] [pid 66623:tid 66777] [client 74.248.18.37:21438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/mah/function.php"] [unique_id "aoSALNO5rbWdOArH04J-wAAAARU"]
[Tue Aug 18 12:54:20.448589 2026] [security2:error] [pid 67073:tid 67211] [client 197.184.64.235:41917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK_cmepr5_nHgLbM1nQAAAho"]
[Tue Aug 18 12:54:20.458810 2026] [security2:error] [pid 67073:tid 67256] [client 20.163.43.14:3169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/akcc.php"] [unique_id "aoSALPcmepr5_nHgLbM13wAAAkc"]
[Tue Aug 18 12:54:20.465462 2026] [security2:error] [pid 66623:tid 66832] [client 52.238.210.254:8929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/class.php"] [unique_id "aoSALNO5rbWdOArH04J-wgAAAUw"]
[Tue Aug 18 12:54:20.469958 2026] [security2:error] [pid 66623:tid 66643] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/zugvi.php"] [unique_id "aoSALNO5rbWdOArH04J-wwABegY"]
[Tue Aug 18 12:54:20.481563 2026] [security2:error] [pid 67073:tid 67206] [client 20.51.153.15:9114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/pd.php"] [unique_id "aoSALPcmepr5_nHgLbM14QAAAhU"]
[Tue Aug 18 12:54:20.497767 2026] [security2:error] [pid 67073:tid 67219] [client 20.104.100.201:17305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/we.php"] [unique_id "aoSALPcmepr5_nHgLbM14wAAAiI"]
[Tue Aug 18 12:54:20.501139 2026] [authz_core:error] [pid 67073:tid 67154] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:20.501507 2026] [authz_core:error] [pid 67073:tid 67154] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:20.515388 2026] [security2:error] [pid 67073:tid 67284] [client 68.155.154.236:64452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSALPcmepr5_nHgLbM15AAAAmM"]
[Tue Aug 18 12:54:20.520094 2026] [security2:error] [pid 66623:tid 66870] [client 104.209.144.33:24882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSALNO5rbWdOArH04J-xQAAAXI"]
[Tue Aug 18 12:54:20.524365 2026] [security2:error] [pid 67073:tid 67218] [client 20.104.100.201:58447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/ab.php"] [unique_id "aoSALPcmepr5_nHgLbM15QAAAiE"]
[Tue Aug 18 12:54:20.528461 2026] [security2:error] [pid 66623:tid 66822] [client 52.238.210.254:8993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSALNO5rbWdOArH04J-xgAAAUI"]
[Tue Aug 18 12:54:20.532515 2026] [security2:error] [pid 66623:tid 66787] [client 52.173.121.69:16457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/pkmoj.php"] [unique_id "aoSALNO5rbWdOArH04J-xwAAAR8"]
[Tue Aug 18 12:54:20.541023 2026] [security2:error] [pid 66623:tid 66844] [client 213.202.253.4:58006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/wp-content/txets.php"] [unique_id "aoSALNO5rbWdOArH04J-yAAAAVg"], referer: www.google.com
[Tue Aug 18 12:54:20.544506 2026] [security2:error] [pid 66623:tid 66739] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wsrer.php"] [unique_id "aoSALNO5rbWdOArH04J-yQABWWY"]
[Tue Aug 18 12:54:20.577513 2026] [security2:error] [pid 66623:tid 66666] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/ucpfr.php"] [unique_id "aoSALNO5rbWdOArH04J-ywABUR0"]
[Tue Aug 18 12:54:20.592232 2026] [security2:error] [pid 66623:tid 66646] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/yxijx.php"] [unique_id "aoSALNO5rbWdOArH04J-zAABRQk"]
[Tue Aug 18 12:54:20.606228 2026] [security2:error] [pid 66623:tid 66642] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/zwlsv.php"] [unique_id "aoSALNO5rbWdOArH04J-zQABJAU"]
[Tue Aug 18 12:54:20.624522 2026] [security2:error] [pid 66623:tid 66723] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/jrpga.php"] [unique_id "aoSALNO5rbWdOArH04J-zgABfVY"]
[Tue Aug 18 12:54:20.655180 2026] [autoindex:error] [pid 67073:tid 67253] [client 158.158.74.177:15856] AH01276: Cannot serve directory /home3/evandrobene/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:20.668858 2026] [security2:error] [pid 67073:tid 67305] [client 172.182.200.96:14292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/zwlsv.php"] [unique_id "aoSALPcmepr5_nHgLbM17AAAAng"]
[Tue Aug 18 12:54:20.678204 2026] [security2:error] [pid 66623:tid 66710] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSALNO5rbWdOArH04J-zwABhEk"]
[Tue Aug 18 12:54:20.685913 2026] [security2:error] [pid 67073:tid 67232] [client 20.250.13.23:50304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/nw.php"] [unique_id "aoSALPcmepr5_nHgLbM17QAAAi8"]
[Tue Aug 18 12:54:20.687452 2026] [security2:error] [pid 67073:tid 67317] [client 74.248.136.165:63872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/166.php"] [unique_id "aoSALPcmepr5_nHgLbM17gAAAoQ"]
[Tue Aug 18 12:54:20.749861 2026] [security2:error] [pid 67073:tid 67266] [client 20.91.215.254:20604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-post.php"] [unique_id "aoSALPcmepr5_nHgLbM18QAAAlE"]
[Tue Aug 18 12:54:20.754850 2026] [security2:error] [pid 66623:tid 66768] [client 20.171.51.14:59286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ic.php"] [unique_id "aoSALNO5rbWdOArH04J-0QAAAQw"]
[Tue Aug 18 12:54:20.792668 2026] [security2:error] [pid 67073:tid 67312] [client 20.51.153.15:9169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/th.php"] [unique_id "aoSALPcmepr5_nHgLbM18gAAAn8"]
[Tue Aug 18 12:54:20.794811 2026] [security2:error] [pid 67073:tid 67260] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSALPcmepr5_nHgLbM17wACS2A"]
[Tue Aug 18 12:54:20.796016 2026] [security2:error] [pid 67073:tid 67326] [client 20.104.100.201:58925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/12.php"] [unique_id "aoSALPcmepr5_nHgLbM18wAAAo0"]
[Tue Aug 18 12:54:20.801826 2026] [security2:error] [pid 66623:tid 66697] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/nwwha.php"] [unique_id "aoSALNO5rbWdOArH04J-0gABJjw"]
[Tue Aug 18 12:54:20.807589 2026] [security2:error] [pid 67073:tid 67221] [client 20.226.6.191:6584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/13.php"] [unique_id "aoSALPcmepr5_nHgLbM19AAAAiQ"]
[Tue Aug 18 12:54:20.807612 2026] [security2:error] [pid 67073:tid 67254] [client 20.48.236.86:10404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/bajah.php"] [unique_id "aoSALPcmepr5_nHgLbM19QAAAkU"]
[Tue Aug 18 12:54:20.844640 2026] [security2:error] [pid 66623:tid 66732] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/opsqt.php"] [unique_id "aoSALNO5rbWdOArH04J-0wABX18"]
[Tue Aug 18 12:54:20.860374 2026] [security2:error] [pid 67073:tid 67330] [client 158.158.74.177:15856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSALPcmepr5_nHgLbM1-AAAApE"]
[Tue Aug 18 12:54:20.860375 2026] [security2:error] [pid 66623:tid 66672] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/jvcpa.php"] [unique_id "aoSALNO5rbWdOArH04J-1AABGyM"]
[Tue Aug 18 12:54:20.877406 2026] [security2:error] [pid 66623:tid 66730] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSALNO5rbWdOArH04J-1QABFF0"]
[Tue Aug 18 12:54:20.884883 2026] [security2:error] [pid 66623:tid 66885] [client 20.163.43.14:3089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wk/index.php"] [unique_id "aoSALNO5rbWdOArH04J-1gAAAYE"]
[Tue Aug 18 12:54:20.893467 2026] [security2:error] [pid 66623:tid 66699] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSALNO5rbWdOArH04J-1wABGD4"]
[Tue Aug 18 12:54:20.907535 2026] [security2:error] [pid 66623:tid 66713] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSALNO5rbWdOArH04J-2AABg0w"]
[Tue Aug 18 12:54:20.935394 2026] [security2:error] [pid 67073:tid 67309] [client 132.196.61.152:55310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/blurbs.php"] [unique_id "aoSALPcmepr5_nHgLbM1-gAAAnw"]
[Tue Aug 18 12:54:20.951434 2026] [security2:error] [pid 67073:tid 67214] [client 86.120.159.145:2904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSALPcmepr5_nHgLbM1-wAAAh0"]
[Tue Aug 18 12:54:20.951552 2026] [security2:error] [pid 67073:tid 67214] [client 86.120.159.145:2904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSALPcmepr5_nHgLbM1-wAAAh0"]
[Tue Aug 18 12:54:20.958807 2026] [security2:error] [pid 67073:tid 67213] [client 111.225.148.160:20386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gustavofrison.com.br"] [uri "/gloria-kalil-lanca-novo-livro-em-campinas/"] [unique_id "aoSALPcmepr5_nHgLbM1_AAAAhw"]
[Tue Aug 18 12:54:20.959963 2026] [security2:error] [pid 67073:tid 67299] [client 104.209.144.33:24892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSALPcmepr5_nHgLbM1_QAAAnI"]
[Tue Aug 18 12:54:20.963302 2026] [security2:error] [pid 67073:tid 67311] [client 68.155.154.236:64544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSALPcmepr5_nHgLbM1_gAAAn4"]
[Tue Aug 18 12:54:20.965058 2026] [security2:error] [pid 67073:tid 67332] [client 74.248.136.165:50872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/mans.php"] [unique_id "aoSALPcmepr5_nHgLbM1_wAAApM"]
[Tue Aug 18 12:54:20.990838 2026] [security2:error] [pid 66623:tid 66754] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSALNO5rbWdOArH04J-2QABF3U"]
[Tue Aug 18 12:54:21.011482 2026] [security2:error] [pid 67073:tid 67313] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSALfcmepr5_nHgLbM2AQAAAoA"]
[Tue Aug 18 12:54:21.014847 2026] [security2:error] [pid 67073:tid 67225] [client 172.182.200.96:14235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/jrpga.php"] [unique_id "aoSALfcmepr5_nHgLbM2AgAAAig"]
[Tue Aug 18 12:54:21.018296 2026] [security2:error] [pid 67073:tid 67293] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSALfcmepr5_nHgLbM2AwAAAmw"]
[Tue Aug 18 12:54:21.022928 2026] [security2:error] [pid 66623:tid 66868] [client 4.232.151.198:48165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/meta.php"] [unique_id "aoSALdO5rbWdOArH04J-2gAAAXA"]
[Tue Aug 18 12:54:21.023009 2026] [security2:error] [pid 67073:tid 67233] [client 20.118.172.148:7953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/cong.php"] [unique_id "aoSALfcmepr5_nHgLbM2BAAAAjA"]
[Tue Aug 18 12:54:21.031101 2026] [security2:error] [pid 66623:tid 66786] [client 74.248.18.37:19970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSALdO5rbWdOArH04J-2wAAAR4"]
[Tue Aug 18 12:54:21.052243 2026] [security2:error] [pid 66623:tid 66821] [client 20.51.153.15:9187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/admin404.php"] [unique_id "aoSALdO5rbWdOArH04J-3AAAAUE"]
[Tue Aug 18 12:54:21.075730 2026] [security2:error] [pid 66623:tid 66835] [client 20.104.100.201:58907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/x1da.php"] [unique_id "aoSALdO5rbWdOArH04J-3QAAAU8"]
[Tue Aug 18 12:54:21.101063 2026] [authz_core:error] [pid 67073:tid 67125] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:21.101359 2026] [authz_core:error] [pid 67073:tid 67125] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:21.105272 2026] [security2:error] [pid 67073:tid 67263] [client 74.248.136.165:43698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/snq.php"] [unique_id "aoSALfcmepr5_nHgLbM2CgAAAk4"]
[Tue Aug 18 12:54:21.182509 2026] [security2:error] [pid 66623:tid 66766] [client 52.173.121.69:6106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/kopyw.php"] [unique_id "aoSALdO5rbWdOArH04J-3wAAAQo"]
[Tue Aug 18 12:54:21.193832 2026] [security2:error] [pid 66623:tid 66673] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSALdO5rbWdOArH04J-4AABSSQ"]
[Tue Aug 18 12:54:21.229972 2026] [security2:error] [pid 66623:tid 66798] [client 20.163.43.14:3145] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ns2.noise2.com.br"] [uri "/1.php"] [unique_id "aoSALdO5rbWdOArH04J-4QAAASo"]
[Tue Aug 18 12:54:21.230078 2026] [security2:error] [pid 66623:tid 66798] [client 20.163.43.14:3145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/1.php"] [unique_id "aoSALdO5rbWdOArH04J-4QAAASo"]
[Tue Aug 18 12:54:21.236286 2026] [security2:error] [pid 67073:tid 67320] [client 149.34.210.141:61148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSALfcmepr5_nHgLbM2DAAAAoc"]
[Tue Aug 18 12:54:21.253650 2026] [security2:error] [pid 67073:tid 67223] [client 20.171.51.14:15804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ue.php"] [unique_id "aoSALfcmepr5_nHgLbM2DQAAAiY"]
[Tue Aug 18 12:54:21.270905 2026] [security2:error] [pid 66623:tid 66684] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSALdO5rbWdOArH04J-4gABby8"]
[Tue Aug 18 12:54:21.300427 2026] [security2:error] [pid 66623:tid 66839] [client 20.151.109.219:31690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/te.php"] [unique_id "aoSALdO5rbWdOArH04J-4wAAAVM"]
[Tue Aug 18 12:54:21.308710 2026] [security2:error] [pid 67073:tid 67230] [client 132.196.61.152:56102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/bajah.php"] [unique_id "aoSALfcmepr5_nHgLbM2EAAAAi0"]
[Tue Aug 18 12:54:21.312681 2026] [security2:error] [pid 67073:tid 67290] [client 157.20.138.62:53651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSALfcmepr5_nHgLbM2EQAAAmk"]
[Tue Aug 18 12:54:21.312852 2026] [security2:error] [pid 67073:tid 67290] [client 157.20.138.62:53651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSALfcmepr5_nHgLbM2EQAAAmk"]
[Tue Aug 18 12:54:21.353668 2026] [security2:error] [pid 66623:tid 66793] [client 20.51.153.15:9122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/qo.php"] [unique_id "aoSALdO5rbWdOArH04J-5QAAASU"]
[Tue Aug 18 12:54:21.366999 2026] [security2:error] [pid 66623:tid 66848] [client 52.173.121.69:54976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSALdO5rbWdOArH04J-6AAAAVw"]
[Tue Aug 18 12:54:21.369665 2026] [security2:error] [pid 66623:tid 66846] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSALdO5rbWdOArH04J-6QAAAVo"]
[Tue Aug 18 12:54:21.373809 2026] [security2:error] [pid 67073:tid 67282] [client 20.104.100.201:58888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/mcs.php"] [unique_id "aoSALfcmepr5_nHgLbM2FAAAAmE"]
[Tue Aug 18 12:54:21.385262 2026] [security2:error] [pid 66623:tid 66863] [client 104.209.144.33:25295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/first.php"] [unique_id "aoSALdO5rbWdOArH04J-6wAAAWs"]
[Tue Aug 18 12:54:21.424921 2026] [security2:error] [pid 67073:tid 67256] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/atomlib.php"] [unique_id "aoSALfcmepr5_nHgLbM2FwAAAkc"]
[Tue Aug 18 12:54:21.429911 2026] [security2:error] [pid 66623:tid 66831] [client 104.209.144.33:33707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/bhfnd.php"] [unique_id "aoSALdO5rbWdOArH04J-7gAAAUs"]
[Tue Aug 18 12:54:21.430511 2026] [security2:error] [pid 66623:tid 66690] [remote 20.75.217.69:13840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/wp-login.php"] [unique_id "aoSALdO5rbWdOArH04J-7QABDjU"]
[Tue Aug 18 12:54:21.442950 2026] [security2:error] [pid 67073:tid 67296] [client 114.119.132.72:24689] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "financeiro.fabioweb.com.br"] [uri "/pwreset.php"] [unique_id "aoSALfcmepr5_nHgLbM2GAAAAm8"], referer: https://financeiro.fabioweb.com.br/pwreset.php?language=norwegian
[Tue Aug 18 12:54:21.444402 2026] [security2:error] [pid 66623:tid 66859] [client 172.182.200.96:14328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSALdO5rbWdOArH04J-7wAAAWc"]
[Tue Aug 18 12:54:21.481859 2026] [security2:error] [pid 66623:tid 66817] [client 20.91.215.254:24332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSALdO5rbWdOArH04J-8gAAAT0"]
[Tue Aug 18 12:54:21.492889 2026] [security2:error] [pid 67073:tid 67261] [client 158.158.74.177:17162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSALfcmepr5_nHgLbM2GgAAAkw"]
[Tue Aug 18 12:54:21.492909 2026] [security2:error] [pid 67073:tid 67117] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/a1vx.php"] [unique_id "aoSALfcmepr5_nHgLbM2GwACYyk"]
[Tue Aug 18 12:54:21.502945 2026] [security2:error] [pid 67073:tid 67320] [client 149.34.210.141:61148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSALfcmepr5_nHgLbM2DAAAAoc"]
[Tue Aug 18 12:54:21.523165 2026] [security2:error] [pid 66623:tid 66847] [client 74.248.136.165:23475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-access.php"] [unique_id "aoSALdO5rbWdOArH04J-8wAAAVs"]
[Tue Aug 18 12:54:21.545771 2026] [security2:error] [pid 66623:tid 66841] [client 5.253.205.188:34796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/fullbackup.sql"] [unique_id "aoSALdO5rbWdOArH04J-9AAAAVU"], referer: https://medihub.com.br/fullbackup.sql
[Tue Aug 18 12:54:21.558236 2026] [security2:error] [pid 66623:tid 66833] [client 68.155.154.236:65192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSALdO5rbWdOArH04J-9QAAAU0"]
[Tue Aug 18 12:54:21.567631 2026] [security2:error] [pid 66623:tid 66877] [client 20.163.43.14:3132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSALdO5rbWdOArH04J-9gAAAXk"]
[Tue Aug 18 12:54:21.616539 2026] [security2:error] [pid 66623:tid 66772] [client 20.51.153.15:9215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/sd.php"] [unique_id "aoSALdO5rbWdOArH04J--AAAARA"]
[Tue Aug 18 12:54:21.635502 2026] [security2:error] [pid 66623:tid 66725] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSALdO5rbWdOArH04J--QABYFg"]
[Tue Aug 18 12:54:21.643545 2026] [security2:error] [pid 66623:tid 66828] [client 20.104.100.201:58456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/adminner.php"] [unique_id "aoSALdO5rbWdOArH04J--gAAAUg"]
[Tue Aug 18 12:54:21.652131 2026] [security2:error] [pid 66623:tid 66795] [client 4.232.151.198:6150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/mini.php"] [unique_id "aoSALdO5rbWdOArH04J--wAAASc"]
[Tue Aug 18 12:54:21.661766 2026] [security2:error] [pid 67073:tid 67307] [client 74.248.18.37:20014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/mass.php"] [unique_id "aoSALfcmepr5_nHgLbM2HwAAAno"]
[Tue Aug 18 12:54:21.670103 2026] [security2:error] [pid 66623:tid 66711] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSALdO5rbWdOArH04J-_AABcUo"]
[Tue Aug 18 12:54:21.672575 2026] [security2:error] [pid 67073:tid 67191] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ty.php"] [unique_id "aoSALfcmepr5_nHgLbM2IAACFnM"]
[Tue Aug 18 12:54:21.685591 2026] [security2:error] [pid 66623:tid 66729] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSALdO5rbWdOArH04J-_QABe1w"]
[Tue Aug 18 12:54:21.692715 2026] [security2:error] [pid 66623:tid 66815] [client 20.48.236.86:16358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/adminfuns.php"] [unique_id "aoSALdO5rbWdOArH04J-_gAAATs"]
[Tue Aug 18 12:54:21.706090 2026] [authz_core:error] [pid 67073:tid 67196] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:21.706357 2026] [authz_core:error] [pid 67073:tid 67196] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:21.713397 2026] [security2:error] [pid 66623:tid 66814] [client 135.225.75.187:19222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ms.php"] [unique_id "aoSALdO5rbWdOArH04J-_wAAATo"]
[Tue Aug 18 12:54:21.731795 2026] [security2:error] [pid 66623:tid 66774] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSALdO5rbWdOArH04J_AAAAARI"]
[Tue Aug 18 12:54:21.733088 2026] [security2:error] [pid 66623:tid 66882] [client 132.196.61.152:56082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/h.php"] [unique_id "aoSALdO5rbWdOArH04J_AQAAAX4"]
[Tue Aug 18 12:54:21.753537 2026] [security2:error] [pid 66623:tid 66769] [client 40.85.222.29:53876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSALdO5rbWdOArH04J_AgAAAQ0"]
[Tue Aug 18 12:54:21.758045 2026] [security2:error] [pid 66623:tid 66755] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSALdO5rbWdOArH04J_AwABTHY"]
[Tue Aug 18 12:54:21.762577 2026] [security2:error] [pid 66623:tid 66884] [client 52.173.121.69:17983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/zznmg.php"] [unique_id "aoSALdO5rbWdOArH04J_BAAAAYA"]
[Tue Aug 18 12:54:21.774284 2026] [security2:error] [pid 66623:tid 66655] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSALdO5rbWdOArH04J_BgABehI"]
[Tue Aug 18 12:54:21.791936 2026] [security2:error] [pid 66623:tid 66731] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSALdO5rbWdOArH04J_BwABP14"]
[Tue Aug 18 12:54:21.807241 2026] [security2:error] [pid 66623:tid 66892] [client 172.182.200.96:14303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/nwwha.php"] [unique_id "aoSALdO5rbWdOArH04J_CAAAAYg"]
[Tue Aug 18 12:54:21.807822 2026] [security2:error] [pid 66623:tid 66718] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSALdO5rbWdOArH04J_CQABC1E"]
[Tue Aug 18 12:54:21.822348 2026] [security2:error] [pid 66623:tid 66753] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSALdO5rbWdOArH04J_CgABUXQ"]
[Tue Aug 18 12:54:21.837133 2026] [security2:error] [pid 66623:tid 66759] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSALdO5rbWdOArH04J_CwABRXo"]
[Tue Aug 18 12:54:21.895247 2026] [security2:error] [pid 66623:tid 66762] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSALdO5rbWdOArH04J_DQABMn0"]
[Tue Aug 18 12:54:21.918596 2026] [security2:error] [pid 66623:tid 66873] [client 20.104.100.201:58889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/dragonshell.php"] [unique_id "aoSALdO5rbWdOArH04J_DgAAAXU"]
[Tue Aug 18 12:54:21.925318 2026] [security2:error] [pid 67073:tid 67268] [client 20.51.153.15:9185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/km.php"] [unique_id "aoSALfcmepr5_nHgLbM2JgAAAlM"]
[Tue Aug 18 12:54:21.941355 2026] [security2:error] [pid 66623:tid 66794] [client 74.248.136.165:37932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/nw.php"] [unique_id "aoSALdO5rbWdOArH04J_EAAAASY"]
[Tue Aug 18 12:54:21.957361 2026] [security2:error] [pid 66623:tid 66750] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSALdO5rbWdOArH04J_EQABeHE"]
[Tue Aug 18 12:54:21.958588 2026] [security2:error] [pid 66623:tid 66776] [client 20.163.43.14:3180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSALdO5rbWdOArH04J_EgAAARQ"]
[Tue Aug 18 12:54:22.028679 2026] [security2:error] [pid 66623:tid 66748] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSALtO5rbWdOArH04J_FQABc28"]
[Tue Aug 18 12:54:22.034127 2026] [security2:error] [pid 67073:tid 67210] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSALvcmepr5_nHgLbM2KgAAAhk"]
[Tue Aug 18 12:54:22.073555 2026] [security2:error] [pid 66623:tid 66868] [client 20.65.98.162:22676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/1xmomo.php"] [unique_id "aoSALtO5rbWdOArH04J_FwAAAXA"]
[Tue Aug 18 12:54:22.119617 2026] [security2:error] [pid 66623:tid 66875] [client 20.91.215.254:20357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSALtO5rbWdOArH04J_GAAAAXc"]
[Tue Aug 18 12:54:22.144426 2026] [security2:error] [pid 66623:tid 66834] [client 158.158.74.177:20539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/f7.php"] [unique_id "aoSALtO5rbWdOArH04J_GQAAAU4"]
[Tue Aug 18 12:54:22.153567 2026] [security2:error] [pid 66623:tid 66640] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSALtO5rbWdOArH04J_GgABQQM"]
[Tue Aug 18 12:54:22.161135 2026] [security2:error] [pid 66623:tid 66803] [client 172.182.200.96:14275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/opsqt.php"] [unique_id "aoSALtO5rbWdOArH04J_GwAAAS8"]
[Tue Aug 18 12:54:22.170327 2026] [security2:error] [pid 66623:tid 66703] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSALtO5rbWdOArH04J_HAABT0I"]
[Tue Aug 18 12:54:22.179237 2026] [security2:error] [pid 67073:tid 67312] [client 20.171.51.14:16756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/lr.php"] [unique_id "aoSALvcmepr5_nHgLbM2LAAAAn8"]
[Tue Aug 18 12:54:22.186242 2026] [security2:error] [pid 66623:tid 66726] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSALtO5rbWdOArH04J_HQABhlk"]
[Tue Aug 18 12:54:22.187302 2026] [security2:error] [pid 66623:tid 66808] [client 172.202.39.151:62618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSALtO5rbWdOArH04J_HgAAATQ"]
[Tue Aug 18 12:54:22.187832 2026] [security2:error] [pid 67073:tid 67260] [client 20.51.153.15:9095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/mf.php"] [unique_id "aoSALvcmepr5_nHgLbM2LQAAAks"]
[Tue Aug 18 12:54:22.194376 2026] [security2:error] [pid 67073:tid 67326] [client 52.173.121.69:24960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/bhfnd.php"] [unique_id "aoSALvcmepr5_nHgLbM2MAAAAo0"]
[Tue Aug 18 12:54:22.195309 2026] [security2:error] [pid 67073:tid 67212] [client 20.104.100.201:58448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/setup-config.php"] [unique_id "aoSALvcmepr5_nHgLbM2MQAAAhs"]
[Tue Aug 18 12:54:22.229273 2026] [security2:error] [pid 66623:tid 66752] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSALtO5rbWdOArH04J_IAABSXM"]
[Tue Aug 18 12:54:22.246702 2026] [security2:error] [pid 66623:tid 66738] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSALtO5rbWdOArH04J_IQABOGU"]
[Tue Aug 18 12:54:22.253557 2026] [security2:error] [pid 66623:tid 66801] [client 20.100.169.31:25982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/atex1.php"] [unique_id "aoSALtO5rbWdOArH04J_IgAAAS0"]
[Tue Aug 18 12:54:22.272491 2026] [security2:error] [pid 67073:tid 67239] [client 20.250.13.23:44667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/xleet.php"] [unique_id "aoSALvcmepr5_nHgLbM2MgAAAjY"]
[Tue Aug 18 12:54:22.273168 2026] [security2:error] [pid 67073:tid 67254] [client 104.209.144.33:31292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSALvcmepr5_nHgLbM2MwAAAkU"]
[Tue Aug 18 12:54:22.275749 2026] [security2:error] [pid 67073:tid 67235] [client 4.232.151.198:6173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/mm.php"] [unique_id "aoSALvcmepr5_nHgLbM2NAAAAjI"]
[Tue Aug 18 12:54:22.284816 2026] [security2:error] [pid 67073:tid 67251] [client 213.35.127.232:62602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSALvcmepr5_nHgLbM2NgAAAkI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:22.306914 2026] [security2:error] [pid 67073:tid 67222] [client 20.48.236.86:10743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/h.php"] [unique_id "aoSALvcmepr5_nHgLbM2NwAAAiU"]
[Tue Aug 18 12:54:22.307127 2026] [security2:error] [pid 67073:tid 67281] [client 68.155.154.236:63893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/mt/byp.php"] [unique_id "aoSALvcmepr5_nHgLbM2OAAAAmA"]
[Tue Aug 18 12:54:22.321250 2026] [security2:error] [pid 67073:tid 67257] [client 172.182.200.96:14144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/assets/admin/login/info.php"] [unique_id "aoSALvcmepr5_nHgLbM2OQAAAkg"]
[Tue Aug 18 12:54:22.328354 2026] [security2:error] [pid 67073:tid 67234] [client 20.163.43.14:3144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/as.php"] [unique_id "aoSALvcmepr5_nHgLbM2OwAAAjE"]
[Tue Aug 18 12:54:22.336752 2026] [security2:error] [pid 66623:tid 66665] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSALtO5rbWdOArH04J_IwABHBw"]
[Tue Aug 18 12:54:22.349245 2026] [security2:error] [pid 67073:tid 67278] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSALvcmepr5_nHgLbM2PAAAAl0"]
[Tue Aug 18 12:54:22.360182 2026] [security2:error] [pid 67073:tid 67258] [client 74.248.136.165:60137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ws62.php"] [unique_id "aoSALvcmepr5_nHgLbM2PQAAAkk"]
[Tue Aug 18 12:54:22.408950 2026] [security2:error] [pid 67073:tid 67208] [client 74.248.18.37:19982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/memberfuns.php"] [unique_id "aoSALvcmepr5_nHgLbM2QAAAAhc"]
[Tue Aug 18 12:54:22.462112 2026] [security2:error] [pid 67073:tid 67078] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/vgtyu.php"] [unique_id "aoSALvcmepr5_nHgLbM2RwACfgI"]
[Tue Aug 18 12:54:22.475912 2026] [security2:error] [pid 67073:tid 67332] [client 20.104.100.201:58912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/f35.update.php"] [unique_id "aoSALvcmepr5_nHgLbM2SQAAApM"]
[Tue Aug 18 12:54:22.480512 2026] [security2:error] [pid 66623:tid 66707] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSALtO5rbWdOArH04J_JQABb0Y"]
[Tue Aug 18 12:54:22.484573 2026] [security2:error] [pid 67073:tid 67225] [client 20.51.153.15:9157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ie.php"] [unique_id "aoSALvcmepr5_nHgLbM2SgAAAig"]
[Tue Aug 18 12:54:22.498664 2026] [security2:error] [pid 66623:tid 66792] [client 178.153.171.161:39177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSALtO5rbWdOArH04J_JgAAASQ"]
[Tue Aug 18 12:54:22.498789 2026] [security2:error] [pid 66623:tid 66792] [client 178.153.171.161:39177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSALtO5rbWdOArH04J_JgAAASQ"]
[Tue Aug 18 12:54:22.528559 2026] [security2:error] [pid 66623:tid 66741] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSALtO5rbWdOArH04J_JwABEWg"]
[Tue Aug 18 12:54:22.542984 2026] [security2:error] [pid 66623:tid 66679] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSALtO5rbWdOArH04J_KAABGio"]
[Tue Aug 18 12:54:22.559586 2026] [security2:error] [pid 66623:tid 66743] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSALtO5rbWdOArH04J_KQABJWo"]
[Tue Aug 18 12:54:22.559605 2026] [security2:error] [pid 67073:tid 67274] [client 172.182.200.96:14253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/jvcpa.php"] [unique_id "aoSALvcmepr5_nHgLbM2TgAAAlk"]
[Tue Aug 18 12:54:22.575166 2026] [security2:error] [pid 66623:tid 66764] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSALtO5rbWdOArH04J_KgABWn8"]
[Tue Aug 18 12:54:22.656396 2026] [security2:error] [pid 67073:tid 67223] [client 20.163.43.14:3082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSALvcmepr5_nHgLbM2VAAAAiY"]
[Tue Aug 18 12:54:22.682282 2026] [security2:error] [pid 67073:tid 67205] [client 172.202.39.151:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/public/css.php"] [unique_id "aoSALvcmepr5_nHgLbM2VwAAAhQ"]
[Tue Aug 18 12:54:22.684151 2026] [security2:error] [pid 67073:tid 67241] [client 74.248.18.37:24326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/u.php"] [unique_id "aoSALvcmepr5_nHgLbM2WAAAAjg"]
[Tue Aug 18 12:54:22.690893 2026] [security2:error] [pid 66623:tid 66830] [client 20.42.19.40:2220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSALtO5rbWdOArH04J_LAAAAUo"]
[Tue Aug 18 12:54:22.691679 2026] [security2:error] [pid 67073:tid 67230] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSALvcmepr5_nHgLbM2WwAAAi0"]
[Tue Aug 18 12:54:22.708205 2026] [security2:error] [pid 67073:tid 67319] [client 20.100.169.31:33841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/p.php"] [unique_id "aoSALvcmepr5_nHgLbM2XAAAAoY"]
[Tue Aug 18 12:54:22.731980 2026] [security2:error] [pid 66623:tid 66700] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSALtO5rbWdOArH04J_LQABSz8"]
[Tue Aug 18 12:54:22.732225 2026] [autoindex:error] [pid 67073:tid 67300] [client 20.104.85.180:8019] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:22.750822 2026] [security2:error] [pid 66623:tid 66742] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSALtO5rbWdOArH04J_LgABZ2k"]
[Tue Aug 18 12:54:22.751192 2026] [security2:error] [pid 67073:tid 67256] [client 20.104.100.201:58442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/bdroot.php"] [unique_id "aoSALvcmepr5_nHgLbM2YAAAAkc"]
[Tue Aug 18 12:54:22.763742 2026] [security2:error] [pid 66623:tid 66849] [client 158.158.74.177:15841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/photo.php"] [unique_id "aoSALtO5rbWdOArH04J_LwAAAV0"]
[Tue Aug 18 12:54:22.777526 2026] [security2:error] [pid 66623:tid 66823] [client 20.151.109.219:28793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/kc.php"] [unique_id "aoSALtO5rbWdOArH04J_MAAAAUM"]
[Tue Aug 18 12:54:22.778498 2026] [security2:error] [pid 67073:tid 67296] [client 74.248.136.165:39586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/public/vx.php"] [unique_id "aoSALvcmepr5_nHgLbM2YQAAAm8"]
[Tue Aug 18 12:54:22.778639 2026] [security2:error] [pid 67073:tid 67308] [client 20.171.51.14:31624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ka.php"] [unique_id "aoSALvcmepr5_nHgLbM2YgAAAns"]
[Tue Aug 18 12:54:22.791629 2026] [security2:error] [pid 66623:tid 66683] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSALtO5rbWdOArH04J_MQABdi4"]
[Tue Aug 18 12:54:22.800555 2026] [security2:error] [pid 66623:tid 66866] [client 20.51.153.15:8712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/nw.php"] [unique_id "aoSALtO5rbWdOArH04J_MgAAAW4"]
[Tue Aug 18 12:54:22.813524 2026] [security2:error] [pid 66623:tid 66763] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSALtO5rbWdOArH04J_MwABW34"]
[Tue Aug 18 12:54:22.831242 2026] [security2:error] [pid 66623:tid 66757] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSALtO5rbWdOArH04J_NAABNng"]
[Tue Aug 18 12:54:22.851969 2026] [security2:error] [pid 67073:tid 67297] [client 52.173.121.69:17948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/qfvqu.php"] [unique_id "aoSALvcmepr5_nHgLbM2agAAAnA"]
[Tue Aug 18 12:54:22.874516 2026] [security2:error] [pid 66623:tid 66877] [client 104.209.144.33:36494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/qfvqu.php"] [unique_id "aoSALtO5rbWdOArH04J_NgAAAXk"]
[Tue Aug 18 12:54:22.901830 2026] [security2:error] [pid 66623:tid 66887] [client 47.128.26.38:19740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.affaripericiacontabil.com.br"] [uri "/robots.txt"] [unique_id "aoSALtO5rbWdOArH04J_NwAAAYM"]
[Tue Aug 18 12:54:22.904464 2026] [security2:error] [pid 66623:tid 66693] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSALtO5rbWdOArH04J_OAABMDg"]
[Tue Aug 18 12:54:22.908459 2026] [authz_core:error] [pid 67073:tid 67188] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:22.908743 2026] [authz_core:error] [pid 67073:tid 67188] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:22.917623 2026] [security2:error] [pid 67073:tid 67314] [client 172.182.200.96:14325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSALvcmepr5_nHgLbM2cAAAAoE"]
[Tue Aug 18 12:54:22.919682 2026] [security2:error] [pid 67073:tid 67290] [client 4.232.151.198:48191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/modules/mod_footer.php"] [unique_id "aoSALvcmepr5_nHgLbM2cQAAAmk"]
[Tue Aug 18 12:54:22.925535 2026] [security2:error] [pid 66623:tid 66802] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/rip.php"] [unique_id "aoSALtO5rbWdOArH04J_OgAAAS4"]
[Tue Aug 18 12:54:22.944429 2026] [security2:error] [pid 66623:tid 66656] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSALtO5rbWdOArH04J_TwABYBM"]
[Tue Aug 18 12:54:22.946173 2026] [security2:error] [pid 67073:tid 67236] [client 20.91.215.254:24376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-2019.php"] [unique_id "aoSALvcmepr5_nHgLbM2dAAAAjM"]
[Tue Aug 18 12:54:22.962967 2026] [security2:error] [pid 67073:tid 67220] [client 68.155.154.236:64562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSALvcmepr5_nHgLbM2dwAAAiM"]
[Tue Aug 18 12:54:22.982881 2026] [security2:error] [pid 67073:tid 67231] [client 40.85.222.29:45205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSALvcmepr5_nHgLbM2eAAAAi4"]
[Tue Aug 18 12:54:22.986292 2026] [security2:error] [pid 67073:tid 67321] [client 135.225.75.187:58946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/gfile.php"] [unique_id "aoSALvcmepr5_nHgLbM2eQAAAog"]
[Tue Aug 18 12:54:23.002758 2026] [security2:error] [pid 67073:tid 67232] [client 20.104.85.180:8019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSAL_cmepr5_nHgLbM2egAAAi8"]
[Tue Aug 18 12:54:23.022552 2026] [security2:error] [pid 66623:tid 66826] [client 20.104.100.201:58937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-temp.php"] [unique_id "aoSAL9O5rbWdOArH04J_eAAAAUY"]
[Tue Aug 18 12:54:23.036393 2026] [security2:error] [pid 66623:tid 66637] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSAL9O5rbWdOArH04J_eQABewA"]
[Tue Aug 18 12:54:23.040126 2026] [security2:error] [pid 67073:tid 67292] [client 74.248.18.37:20010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/meta.php"] [unique_id "aoSAL_cmepr5_nHgLbM2fgAAAms"]
[Tue Aug 18 12:54:23.054897 2026] [security2:error] [pid 66623:tid 66676] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSAL9O5rbWdOArH04J_ewABOic"]
[Tue Aug 18 12:54:23.071702 2026] [security2:error] [pid 66623:tid 66667] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/rezor.php"] [unique_id "aoSAL9O5rbWdOArH04J_fQABIx4"]
[Tue Aug 18 12:54:23.085620 2026] [security2:error] [pid 67073:tid 67235] [client 20.51.153.15:9188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/sb.php"] [unique_id "aoSAL_cmepr5_nHgLbM2gAAAAjI"]
[Tue Aug 18 12:54:23.086614 2026] [security2:error] [pid 67073:tid 67327] [client 20.163.43.14:3073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSAL_cmepr5_nHgLbM2gQAAAo4"]
[Tue Aug 18 12:54:23.089755 2026] [security2:error] [pid 66623:tid 66733] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSAL9O5rbWdOArH04J_fwABfmA"]
[Tue Aug 18 12:54:23.149974 2026] [security2:error] [pid 66623:tid 66669] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSAL9O5rbWdOArH04J_ggABTCA"]
[Tue Aug 18 12:54:23.195449 2026] [security2:error] [pid 67073:tid 67213] [client 74.248.136.165:62752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/loxi-o.php"] [unique_id "aoSAL_cmepr5_nHgLbM2hgAAAhw"]
[Tue Aug 18 12:54:23.203087 2026] [security2:error] [pid 66623:tid 66878] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSAL9O5rbWdOArH04J_hwAAAXo"]
[Tue Aug 18 12:54:23.213928 2026] [security2:error] [pid 67073:tid 67303] [client 157.51.166.53:53838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAL_cmepr5_nHgLbM2igAAAnY"]
[Tue Aug 18 12:54:23.214058 2026] [security2:error] [pid 67073:tid 67303] [client 157.51.166.53:53838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAL_cmepr5_nHgLbM2igAAAnY"]
[Tue Aug 18 12:54:23.222163 2026] [security2:error] [pid 66623:tid 66797] [client 20.48.236.86:10372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/ano.php"] [unique_id "aoSAL9O5rbWdOArH04J_iAAAASk"]
[Tue Aug 18 12:54:23.231992 2026] [security2:error] [pid 66623:tid 66863] [client 160.120.140.123:55069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAL9O5rbWdOArH04J_iQAAAWs"]
[Tue Aug 18 12:54:23.232334 2026] [security2:error] [pid 66623:tid 66863] [client 160.120.140.123:55069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAL9O5rbWdOArH04J_iQAAAWs"]
[Tue Aug 18 12:54:23.245688 2026] [authz_core:error] [pid 67073:tid 67179] [remote 57.141.22.118:21656] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:23.246116 2026] [authz_core:error] [pid 67073:tid 67179] [remote 57.141.22.118:21656] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:23.253467 2026] [security2:error] [pid 67073:tid 67293] [client 172.182.200.96:14227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSAL_cmepr5_nHgLbM2jAAAAmw"]
[Tue Aug 18 12:54:23.254584 2026] [security2:error] [pid 67073:tid 67225] [client 20.118.172.148:7648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSAL_cmepr5_nHgLbM2jQAAAig"]
[Tue Aug 18 12:54:23.298397 2026] [security2:error] [pid 66623:tid 66787] [client 20.104.100.201:58941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-css.php"] [unique_id "aoSAL9O5rbWdOArH04J_iwAAAR8"]
[Tue Aug 18 12:54:23.300290 2026] [security2:error] [pid 67073:tid 67315] [client 213.35.127.232:62839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAL_cmepr5_nHgLbM2jwAAAoI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:23.303144 2026] [security2:error] [pid 66623:tid 66678] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/index/function.php"] [unique_id "aoSAL9O5rbWdOArH04J_jAABWCk"]
[Tue Aug 18 12:54:23.309817 2026] [security2:error] [pid 67073:tid 67262] [client 20.104.85.180:8071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/about.php"] [unique_id "aoSAL_cmepr5_nHgLbM2kQAAAk0"]
[Tue Aug 18 12:54:23.312176 2026] [security2:error] [pid 67073:tid 67316] [client 52.173.121.69:16484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/oivcl.php"] [unique_id "aoSAL_cmepr5_nHgLbM2kgAAAoM"]
[Tue Aug 18 12:54:23.314064 2026] [security2:error] [pid 67073:tid 67229] [client 20.171.51.14:14989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ot.php"] [unique_id "aoSAL_cmepr5_nHgLbM2kwAAAiw"]
[Tue Aug 18 12:54:23.346968 2026] [security2:error] [pid 67073:tid 67279] [client 20.151.109.219:36711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/jn.php"] [unique_id "aoSAL_cmepr5_nHgLbM2lQAAAl4"]
[Tue Aug 18 12:54:23.379347 2026] [security2:error] [pid 66623:tid 66827] [client 20.51.153.15:9141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/xj.php"] [unique_id "aoSAL9O5rbWdOArH04J_jgAAAUc"]
[Tue Aug 18 12:54:23.390102 2026] [security2:error] [pid 66623:tid 66697] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSAL9O5rbWdOArH04J_jwABRDw"]
[Tue Aug 18 12:54:23.393278 2026] [security2:error] [pid 67073:tid 67243] [client 158.158.74.177:20501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-aa.php"] [unique_id "aoSAL_cmepr5_nHgLbM2mAAAAjo"]
[Tue Aug 18 12:54:23.394055 2026] [security2:error] [pid 67073:tid 67286] [client 74.248.136.165:31897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/co.php"] [unique_id "aoSAL_cmepr5_nHgLbM2mQAAAmU"]
[Tue Aug 18 12:54:23.416427 2026] [security2:error] [pid 66623:tid 66880] [client 20.163.43.14:3093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSAL9O5rbWdOArH04J_kAAAAXw"]
[Tue Aug 18 12:54:23.428341 2026] [security2:error] [pid 67073:tid 67273] [client 192.141.172.134:53931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAL_cmepr5_nHgLbM2mwAAAlg"]
[Tue Aug 18 12:54:23.428462 2026] [security2:error] [pid 67073:tid 67273] [client 192.141.172.134:53931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAL_cmepr5_nHgLbM2mwAAAlg"]
[Tue Aug 18 12:54:23.446380 2026] [security2:error] [pid 67073:tid 67259] [client 78.46.190.63:28362] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.connectformaturas.com.br"] [uri "/index.php"] [unique_id "aoSALvcmepr5_nHgLbM2LgAAAko"], referer: https://www.connectformaturas.com.br
[Tue Aug 18 12:54:23.470883 2026] [security2:error] [pid 66623:tid 66732] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/Cachex.php"] [unique_id "aoSAL9O5rbWdOArH04J_kQABKF8"]
[Tue Aug 18 12:54:23.483208 2026] [security2:error] [pid 67073:tid 67246] [client 213.35.127.232:60020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAL_cmepr5_nHgLbM2ngAAAj0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:23.496424 2026] [security2:error] [pid 67073:tid 67104] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/mans.php"] [unique_id "aoSAL_cmepr5_nHgLbM2ogACLRw"]
[Tue Aug 18 12:54:23.506511 2026] [security2:error] [pid 67073:tid 67319] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAL_cmepr5_nHgLbM2pAAAAoY"]
[Tue Aug 18 12:54:23.511557 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:23.511818 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:23.518195 2026] [security2:error] [pid 66623:tid 66672] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSAL9O5rbWdOArH04J_kgABYiM"]
[Tue Aug 18 12:54:23.536489 2026] [security2:error] [pid 66623:tid 66730] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-2019.php"] [unique_id "aoSAL9O5rbWdOArH04J_kwABDF0"]
[Tue Aug 18 12:54:23.537894 2026] [security2:error] [pid 67073:tid 67274] [client 4.232.151.198:6169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/moon.php"] [unique_id "aoSAL_cmepr5_nHgLbM2pQAAAlk"]
[Tue Aug 18 12:54:23.552099 2026] [security2:error] [pid 66623:tid 66699] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSAL9O5rbWdOArH04J_lAABJj4"]
[Tue Aug 18 12:54:23.562014 2026] [security2:error] [pid 66623:tid 66851] [client 132.196.61.152:26824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/ano.php"] [unique_id "aoSAL9O5rbWdOArH04J_lQAAAV8"]
[Tue Aug 18 12:54:23.570084 2026] [security2:error] [pid 67073:tid 67324] [client 68.155.154.236:65195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAL_cmepr5_nHgLbM2pgAAAos"]
[Tue Aug 18 12:54:23.573112 2026] [security2:error] [pid 66623:tid 66783] [client 20.104.100.201:58932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/flox.php"] [unique_id "aoSAL9O5rbWdOArH04J_lgAAARs"]
[Tue Aug 18 12:54:23.580028 2026] [security2:error] [pid 66623:tid 66713] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/.cache/x.php"] [unique_id "aoSAL9O5rbWdOArH04J_lwABFEw"]
[Tue Aug 18 12:54:23.589903 2026] [security2:error] [pid 66623:tid 66780] [client 52.238.210.254:8975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/av.php"] [unique_id "aoSAL9O5rbWdOArH04J_mAAAARg"]
[Tue Aug 18 12:54:23.612798 2026] [security2:error] [pid 67073:tid 67256] [client 74.248.136.165:37942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/sdsa.php"] [unique_id "aoSAL_cmepr5_nHgLbM2qAAAAkc"]
[Tue Aug 18 12:54:23.619047 2026] [security2:error] [pid 66623:tid 66871] [client 20.226.6.191:6648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/cc.php"] [unique_id "aoSAL9O5rbWdOArH04J_mQAAAXM"]
[Tue Aug 18 12:54:23.622020 2026] [security2:error] [pid 67073:tid 67255] [client 20.104.85.180:43526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/alfa.php"] [unique_id "aoSAL_cmepr5_nHgLbM2qQAAAkY"]
[Tue Aug 18 12:54:23.625304 2026] [security2:error] [pid 67073:tid 67250] [client 20.91.215.254:24380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/cjfuns.php"] [unique_id "aoSAL_cmepr5_nHgLbM2qgAAAkE"]
[Tue Aug 18 12:54:23.644543 2026] [security2:error] [pid 66623:tid 66671] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSAL9O5rbWdOArH04J_mgABPiI"]
[Tue Aug 18 12:54:23.677095 2026] [security2:error] [pid 67073:tid 67091] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/co.php"] [unique_id "aoSAL_cmepr5_nHgLbM2uAACIg8"]
[Tue Aug 18 12:54:23.679647 2026] [security2:error] [pid 67073:tid 67284] [client 172.182.200.96:14237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSAL_cmepr5_nHgLbM2uQAAAmM"]
[Tue Aug 18 12:54:23.683767 2026] [security2:error] [pid 66623:tid 66806] [client 74.248.18.37:12311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/mini.php"] [unique_id "aoSAL9O5rbWdOArH04J_mwAAATI"]
[Tue Aug 18 12:54:23.695065 2026] [security2:error] [pid 66623:tid 66754] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAL9O5rbWdOArH04J_nAABf3U"]
[Tue Aug 18 12:54:23.739410 2026] [security2:error] [pid 66623:tid 66821] [client 20.51.153.15:9108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ns.php"] [unique_id "aoSAL9O5rbWdOArH04J_nwAAAUE"]
[Tue Aug 18 12:54:23.756247 2026] [security2:error] [pid 67073:tid 67210] [client 85.154.68.202:60398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAL_cmepr5_nHgLbM2ugAAAhk"]
[Tue Aug 18 12:54:23.756404 2026] [security2:error] [pid 67073:tid 67210] [client 85.154.68.202:60398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAL_cmepr5_nHgLbM2ugAAAhk"]
[Tue Aug 18 12:54:23.758436 2026] [security2:error] [pid 67073:tid 67307] [client 20.65.98.162:18095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/mosty.php"] [unique_id "aoSAL_cmepr5_nHgLbM2vAAAAno"]
[Tue Aug 18 12:54:23.763306 2026] [security2:error] [pid 67073:tid 67270] [client 52.139.47.57:13529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/hplfuns.php"] [unique_id "aoSAL_cmepr5_nHgLbM2vQAAAlU"]
[Tue Aug 18 12:54:23.764187 2026] [security2:error] [pid 67073:tid 67301] [client 20.104.85.180:7936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSAL_cmepr5_nHgLbM2vgAAAnQ"]
[Tue Aug 18 12:54:23.781106 2026] [security2:error] [pid 67073:tid 67264] [client 104.209.144.33:15705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSAL_cmepr5_nHgLbM2vwAAAk8"]
[Tue Aug 18 12:54:23.785932 2026] [security2:error] [pid 67073:tid 67238] [client 20.163.43.14:3092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAL_cmepr5_nHgLbM2wAAAAjU"]
[Tue Aug 18 12:54:23.808118 2026] [security2:error] [pid 66623:tid 66808] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSAL9O5rbWdOArH04J_oAAAATQ"]
[Tue Aug 18 12:54:23.813558 2026] [security2:error] [pid 66623:tid 66673] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAL9O5rbWdOArH04J_oQABSSQ"]
[Tue Aug 18 12:54:23.818109 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:23.818567 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:23.839328 2026] [security2:error] [pid 67073:tid 67314] [client 20.171.51.14:58849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ih.php"] [unique_id "aoSAL_cmepr5_nHgLbM2wgAAAoE"]
[Tue Aug 18 12:54:23.850049 2026] [security2:error] [pid 66623:tid 66865] [client 74.248.18.37:45024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAL9O5rbWdOArH04J_ogAAAW0"]
[Tue Aug 18 12:54:23.852512 2026] [security2:error] [pid 67073:tid 67295] [client 20.104.100.201:58893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/op.php"] [unique_id "aoSAL_cmepr5_nHgLbM2xAAAAm4"]
[Tue Aug 18 12:54:23.856047 2026] [security2:error] [pid 67073:tid 67108] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/btx25.php"] [unique_id "aoSAL_cmepr5_nHgLbM2xQACdSA"]
[Tue Aug 18 12:54:23.857372 2026] [security2:error] [pid 67073:tid 67326] [client 20.250.13.23:44638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp.php"] [unique_id "aoSAL_cmepr5_nHgLbM2xgAAAo0"]
[Tue Aug 18 12:54:23.893798 2026] [security2:error] [pid 66623:tid 66811] [client 20.104.85.180:43552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/lock360.php"] [unique_id "aoSAL9O5rbWdOArH04J_owAAATc"]
[Tue Aug 18 12:54:23.926416 2026] [security2:error] [pid 66623:tid 66872] [client 68.155.154.236:65125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAL9O5rbWdOArH04J_pAAAAXQ"]
[Tue Aug 18 12:54:23.941696 2026] [security2:error] [pid 66623:tid 66798] [client 52.173.121.69:24829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/zugvi.php"] [unique_id "aoSAL9O5rbWdOArH04J_pQAAASo"]
[Tue Aug 18 12:54:23.960659 2026] [security2:error] [pid 67073:tid 67321] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/p.php"] [unique_id "aoSAL_cmepr5_nHgLbM2yAAAAog"]
[Tue Aug 18 12:54:23.991423 2026] [security2:error] [pid 66623:tid 66892] [client 20.100.169.31:20240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/php.php"] [unique_id "aoSAL9O5rbWdOArH04J_pwAAAYg"]
[Tue Aug 18 12:54:23.999548 2026] [security2:error] [pid 66623:tid 66684] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSAL9O5rbWdOArH04J_qAABUC8"]
[Tue Aug 18 12:54:24.015230 2026] [security2:error] [pid 66623:tid 66766] [client 158.158.74.177:15849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/d.php"] [unique_id "aoSAMNO5rbWdOArH04J_qQAAAQo"]
[Tue Aug 18 12:54:24.030934 2026] [security2:error] [pid 67073:tid 67212] [client 74.248.136.165:23433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-freya.php"] [unique_id "aoSAMPcmepr5_nHgLbM2ywAAAhs"]
[Tue Aug 18 12:54:24.064260 2026] [security2:error] [pid 67073:tid 67122] [remote 179.64.21.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powerbelt.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAMPcmepr5_nHgLbM2zAACji4"]
[Tue Aug 18 12:54:24.064402 2026] [security2:error] [pid 67073:tid 67327] [client 179.64.21.92:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "powerbelt.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAMPcmepr5_nHgLbM2zAACji4"]
[Tue Aug 18 12:54:24.067039 2026] [security2:error] [pid 67073:tid 67178] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/avim.php"] [unique_id "aoSAMPcmepr5_nHgLbM2zQACQmY"]
[Tue Aug 18 12:54:24.078157 2026] [security2:error] [pid 67073:tid 67323] [client 172.182.200.96:14333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSAMPcmepr5_nHgLbM2zwAAAoo"]
[Tue Aug 18 12:54:24.117234 2026] [security2:error] [pid 67073:tid 67278] [client 132.196.61.152:56104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/ai.php"] [unique_id "aoSAMPcmepr5_nHgLbM20wAAAl0"]
[Tue Aug 18 12:54:24.130017 2026] [security2:error] [pid 66623:tid 66793] [client 20.104.100.201:58449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/1xmomo.php"] [unique_id "aoSAMNO5rbWdOArH04J_rQAAASU"]
[Tue Aug 18 12:54:24.144190 2026] [security2:error] [pid 67073:tid 67271] [client 135.225.75.187:32968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/public/wp-blog.php"] [unique_id "aoSAMPcmepr5_nHgLbM21QAAAlY"]
[Tue Aug 18 12:54:24.145795 2026] [security2:error] [pid 66623:tid 66848] [client 20.104.85.180:8049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/f35.php"] [unique_id "aoSAMNO5rbWdOArH04J_rgAAAVw"]
[Tue Aug 18 12:54:24.151960 2026] [security2:error] [pid 66623:tid 66846] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/well-known/index.php"] [unique_id "aoSAMNO5rbWdOArH04J_rwAAAVo"]
[Tue Aug 18 12:54:24.178036 2026] [security2:error] [pid 66623:tid 66725] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSAMNO5rbWdOArH04J_sAABXlg"]
[Tue Aug 18 12:54:24.188569 2026] [security2:error] [pid 67073:tid 67283] [client 4.232.151.198:6193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/n.php"] [unique_id "aoSAMPcmepr5_nHgLbM21wAAAmI"]
[Tue Aug 18 12:54:24.215416 2026] [security2:error] [pid 66623:tid 66711] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSAMNO5rbWdOArH04J_sQABSko"]
[Tue Aug 18 12:54:24.234523 2026] [security2:error] [pid 66623:tid 66770] [client 20.171.51.14:58824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/k.php"] [unique_id "aoSAMNO5rbWdOArH04J_sgAAAQ4"]
[Tue Aug 18 12:54:24.238580 2026] [security2:error] [pid 66623:tid 66859] [client 20.104.85.180:18879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/flower.php"] [unique_id "aoSAMNO5rbWdOArH04J_swAAAWc"]
[Tue Aug 18 12:54:24.246941 2026] [security2:error] [pid 67073:tid 67087] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/myfile.php"] [unique_id "aoSAMPcmepr5_nHgLbM22QACcgs"]
[Tue Aug 18 12:54:24.260130 2026] [security2:error] [pid 67073:tid 67254] [client 20.91.215.254:26370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSAMPcmepr5_nHgLbM22gAAAkU"]
[Tue Aug 18 12:54:24.264005 2026] [security2:error] [pid 67073:tid 67305] [client 20.226.6.191:6545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAMPcmepr5_nHgLbM22wAAAng"]
[Tue Aug 18 12:54:24.294521 2026] [security2:error] [pid 66623:tid 66761] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSAMNO5rbWdOArH04J_tQABPXw"]
[Tue Aug 18 12:54:24.309863 2026] [security2:error] [pid 67073:tid 67293] [client 74.248.136.165:1109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/btx25.php"] [unique_id "aoSAMPcmepr5_nHgLbM23QAAAmw"]
[Tue Aug 18 12:54:24.325078 2026] [security2:error] [pid 67073:tid 67232] [client 213.35.127.232:63046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAMPcmepr5_nHgLbM23wAAAi8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:24.348934 2026] [security2:error] [pid 67073:tid 67215] [client 52.139.47.57:3104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/hosty.php"] [unique_id "aoSAMPcmepr5_nHgLbM24AAAAh4"]
[Tue Aug 18 12:54:24.389167 2026] [security2:error] [pid 67073:tid 67315] [client 20.151.109.219:46589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/bf.php"] [unique_id "aoSAMPcmepr5_nHgLbM24QAAAoI"]
[Tue Aug 18 12:54:24.393419 2026] [security2:error] [pid 66623:tid 66773] [client 74.248.18.37:29604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/mm.php"] [unique_id "aoSAMNO5rbWdOArH04J_tgAAARE"]
[Tue Aug 18 12:54:24.411692 2026] [security2:error] [pid 67073:tid 67229] [client 20.104.100.201:58881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/txets.php"] [unique_id "aoSAMPcmepr5_nHgLbM25gAAAiw"]
[Tue Aug 18 12:54:24.417740 2026] [security2:error] [pid 67073:tid 67279] [client 68.155.154.236:64464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSAMPcmepr5_nHgLbM25wAAAl4"]
[Tue Aug 18 12:54:24.418002 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:24.418278 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:24.421067 2026] [security2:error] [pid 66623:tid 66841] [client 20.163.43.14:2012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSAMNO5rbWdOArH04J_twAAAVU"]
[Tue Aug 18 12:54:24.422059 2026] [security2:error] [pid 66623:tid 66807] [client 172.182.200.96:14320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSAMNO5rbWdOArH04J_uAAAATM"]
[Tue Aug 18 12:54:24.449465 2026] [security2:error] [pid 67073:tid 67243] [client 74.248.136.165:62774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/fleen.php"] [unique_id "aoSAMPcmepr5_nHgLbM26AAAAjo"]
[Tue Aug 18 12:54:24.454925 2026] [security2:error] [pid 67073:tid 67286] [client 20.48.236.86:11054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/ai.php"] [unique_id "aoSAMPcmepr5_nHgLbM26QAAAmU"]
[Tue Aug 18 12:54:24.455424 2026] [security2:error] [pid 67073:tid 67151] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/xmy.php"] [unique_id "aoSAMPcmepr5_nHgLbM26gACiUs"]
[Tue Aug 18 12:54:24.478347 2026] [autoindex:error] [pid 66623:tid 66887] [client 20.104.85.180:8006] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:24.498517 2026] [security2:error] [pid 67073:tid 67273] [client 20.51.153.15:9119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/gk.php"] [unique_id "aoSAMPcmepr5_nHgLbM27QAAAlg"]
[Tue Aug 18 12:54:24.503234 2026] [security2:error] [pid 67073:tid 67259] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSAMPcmepr5_nHgLbM27gAAAko"]
[Tue Aug 18 12:54:24.518186 2026] [security2:error] [pid 67073:tid 67249] [client 20.104.85.180:43523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/13.php"] [unique_id "aoSAMPcmepr5_nHgLbM27wAAAkA"]
[Tue Aug 18 12:54:24.542702 2026] [security2:error] [pid 66623:tid 66729] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSAMNO5rbWdOArH04J_ugABLlw"]
[Tue Aug 18 12:54:24.561483 2026] [security2:error] [pid 66623:tid 66755] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSAMNO5rbWdOArH04J_uwABOXY"]
[Tue Aug 18 12:54:24.577158 2026] [security2:error] [pid 66623:tid 66712] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSAMNO5rbWdOArH04J_vAABaks"]
[Tue Aug 18 12:54:24.587127 2026] [security2:error] [pid 67073:tid 67240] [client 20.100.169.31:38027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/class-t.api.php"] [unique_id "aoSAMPcmepr5_nHgLbM2-gAAAjc"]
[Tue Aug 18 12:54:24.607121 2026] [security2:error] [pid 66623:tid 66655] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSAMNO5rbWdOArH04J_vQABJxI"]
[Tue Aug 18 12:54:24.623648 2026] [security2:error] [pid 66623:tid 66731] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSAMNO5rbWdOArH04J_vgABEF4"]
[Tue Aug 18 12:54:24.649657 2026] [security2:error] [pid 67073:tid 67263] [client 158.158.74.177:20536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSAMPcmepr5_nHgLbM3AwAAAk4"]
[Tue Aug 18 12:54:24.680162 2026] [security2:error] [pid 66623:tid 66718] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAMNO5rbWdOArH04J_vwABIlE"]
[Tue Aug 18 12:54:24.683727 2026] [security2:error] [pid 67073:tid 67304] [client 20.104.100.201:58445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/img.php"] [unique_id "aoSAMPcmepr5_nHgLbM3CAAAAnc"]
[Tue Aug 18 12:54:24.693317 2026] [security2:error] [pid 67073:tid 67191] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/xda.php"] [unique_id "aoSAMPcmepr5_nHgLbM3CQACIHM"]
[Tue Aug 18 12:54:24.719124 2026] [authz_core:error] [pid 67073:tid 67153] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:24.719573 2026] [authz_core:error] [pid 67073:tid 67153] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:24.763036 2026] [security2:error] [pid 67073:tid 67329] [client 20.163.43.14:3151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/an.php"] [unique_id "aoSAMPcmepr5_nHgLbM3FwAAApA"]
[Tue Aug 18 12:54:24.771040 2026] [security2:error] [pid 67073:tid 67298] [client 135.225.75.187:33025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/cu.php"] [unique_id "aoSAMPcmepr5_nHgLbM3GQAAAnE"]
[Tue Aug 18 12:54:24.775152 2026] [security2:error] [pid 66623:tid 66879] [client 20.104.85.180:8006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/inputs.php"] [unique_id "aoSAMNO5rbWdOArH04J_wAAAAXs"]
[Tue Aug 18 12:54:24.780536 2026] [security2:error] [pid 67073:tid 67297] [client 172.182.200.96:14299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSAMPcmepr5_nHgLbM3HAAAAnA"]
[Tue Aug 18 12:54:24.803886 2026] [security2:error] [pid 66623:tid 66753] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSAMNO5rbWdOArH04J_wQABOnQ"]
[Tue Aug 18 12:54:24.811444 2026] [security2:error] [pid 67073:tid 67257] [client 20.104.85.180:43520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/cc.php"] [unique_id "aoSAMPcmepr5_nHgLbM3HgAAAkg"]
[Tue Aug 18 12:54:24.815688 2026] [security2:error] [pid 67073:tid 67268] [client 4.232.151.198:48151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/nc4.php"] [unique_id "aoSAMPcmepr5_nHgLbM3HwAAAlM"]
[Tue Aug 18 12:54:24.819472 2026] [security2:error] [pid 66623:tid 66759] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/well-known/index.php"] [unique_id "aoSAMNO5rbWdOArH04J_wgABI3o"]
[Tue Aug 18 12:54:24.821644 2026] [security2:error] [pid 67073:tid 67301] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAMPcmepr5_nHgLbM3IQAAAnQ"]
[Tue Aug 18 12:54:24.831804 2026] [security2:error] [pid 67073:tid 67264] [client 68.155.154.236:65118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSAMPcmepr5_nHgLbM3IgAAAk8"]
[Tue Aug 18 12:54:24.834978 2026] [security2:error] [pid 66623:tid 66762] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSAMNO5rbWdOArH04J_wwABEn0"]
[Tue Aug 18 12:54:24.837279 2026] [security2:error] [pid 66623:tid 66882] [client 104.209.144.33:29865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/oivcl.php"] [unique_id "aoSAMNO5rbWdOArH04J_xAAAAX4"]
[Tue Aug 18 12:54:24.843903 2026] [security2:error] [pid 67073:tid 67280] [client 20.171.51.14:33670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/iu.php"] [unique_id "aoSAMPcmepr5_nHgLbM3IwAAAl8"]
[Tue Aug 18 12:54:24.863199 2026] [security2:error] [pid 67073:tid 67314] [client 172.202.39.151:37162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAMPcmepr5_nHgLbM3JQAAAoE"]
[Tue Aug 18 12:54:24.867826 2026] [security2:error] [pid 66623:tid 66777] [client 74.248.136.165:16976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/e.php"] [unique_id "aoSAMNO5rbWdOArH04J_xQAAARU"]
[Tue Aug 18 12:54:24.882082 2026] [security2:error] [pid 66623:tid 66750] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAMNO5rbWdOArH04J_xgABV3E"]
[Tue Aug 18 12:54:24.913946 2026] [security2:error] [pid 67073:tid 67206] [client 20.91.215.254:24328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSAMPcmepr5_nHgLbM3JgAAAhU"]
[Tue Aug 18 12:54:24.919405 2026] [security2:error] [pid 67073:tid 67155] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/zz.php"] [unique_id "aoSAMPcmepr5_nHgLbM3JwACdU8"]
[Tue Aug 18 12:54:24.922485 2026] [security2:error] [pid 67073:tid 67326] [client 52.173.121.69:24973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wsrer.php"] [unique_id "aoSAMPcmepr5_nHgLbM3KAAAAo0"]
[Tue Aug 18 12:54:24.959952 2026] [security2:error] [pid 66623:tid 66832] [client 20.104.100.201:58446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAMNO5rbWdOArH04J_xwAAAUw"]
[Tue Aug 18 12:54:24.971898 2026] [security2:error] [pid 66623:tid 66748] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSAMNO5rbWdOArH04J_yAABh28"]
[Tue Aug 18 12:54:24.983291 2026] [security2:error] [pid 67073:tid 67227] [client 52.139.47.57:3083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/t.php"] [unique_id "aoSAMPcmepr5_nHgLbM3KwAAAio"]
[Tue Aug 18 12:54:25.001046 2026] [security2:error] [pid 67073:tid 67312] [client 20.51.153.15:9139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/wn.php"] [unique_id "aoSAMfcmepr5_nHgLbM3LAAAAn8"]
[Tue Aug 18 12:54:25.004127 2026] [security2:error] [pid 67073:tid 67233] [client 74.248.18.37:29232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/h.php"] [unique_id "aoSAMfcmepr5_nHgLbM3LQAAAjA"]
[Tue Aug 18 12:54:25.015004 2026] [security2:error] [pid 67073:tid 67266] [client 20.65.98.162:18939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/blurbs.php"] [unique_id "aoSAMfcmepr5_nHgLbM3LgAAAlE"]
[Tue Aug 18 12:54:25.027200 2026] [security2:error] [pid 66623:tid 66860] [client 74.248.18.37:12312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/modules/mod_footer.php"] [unique_id "aoSAMdO5rbWdOArH04J_yQAAAWg"]
[Tue Aug 18 12:54:25.043403 2026] [security2:error] [pid 66623:tid 66639] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/mt/byp.php"] [unique_id "aoSAMdO5rbWdOArH04J_ygABGQI"]
[Tue Aug 18 12:54:25.050831 2026] [security2:error] [pid 66623:tid 66878] [client 40.85.222.29:2400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSAMdO5rbWdOArH04J_ywAAAXo"]
[Tue Aug 18 12:54:25.058746 2026] [security2:error] [pid 66623:tid 66640] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSAMdO5rbWdOArH04J_zAABZAM"]
[Tue Aug 18 12:54:25.085402 2026] [security2:error] [pid 66623:tid 66819] [client 132.196.61.152:56097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/w1px.php"] [unique_id "aoSAMdO5rbWdOArH04J_zQAAAT8"]
[Tue Aug 18 12:54:25.097604 2026] [security2:error] [pid 67073:tid 67251] [client 20.104.85.180:43565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAMfcmepr5_nHgLbM3NQAAAkI"]
[Tue Aug 18 12:54:25.107580 2026] [security2:error] [pid 67073:tid 67160] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/xa.php"] [unique_id "aoSAMfcmepr5_nHgLbM3NwACilQ"]
[Tue Aug 18 12:54:25.141067 2026] [autoindex:error] [pid 67073:tid 67327] [client 20.104.85.180:8063] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:25.148820 2026] [security2:error] [pid 66623:tid 66726] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAMdO5rbWdOArH04J_zwABUVk"]
[Tue Aug 18 12:54:25.164746 2026] [security2:error] [pid 66623:tid 66825] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSAMdO5rbWdOArH04J_0AAAAUU"]
[Tue Aug 18 12:54:25.216444 2026] [security2:error] [pid 67073:tid 67271] [client 172.182.200.96:14304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSAMfcmepr5_nHgLbM3OwAAAlY"]
[Tue Aug 18 12:54:25.237913 2026] [security2:error] [pid 67073:tid 67214] [client 20.104.100.201:58898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAMfcmepr5_nHgLbM3PAAAAh0"]
[Tue Aug 18 12:54:25.241474 2026] [security2:error] [pid 66623:tid 66752] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAMdO5rbWdOArH04J_0gABO3M"]
[Tue Aug 18 12:54:25.247117 2026] [security2:error] [pid 66623:tid 66845] [client 74.248.133.44:19631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/storage/rip.php"] [unique_id "aoSAMdO5rbWdOArH04J_0wAAAVk"]
[Tue Aug 18 12:54:25.256888 2026] [security2:error] [pid 66623:tid 66738] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSAMdO5rbWdOArH04J_1AABVGU"]
[Tue Aug 18 12:54:25.269714 2026] [security2:error] [pid 66623:tid 66797] [client 158.158.74.177:17201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSAMdO5rbWdOArH04J_1QAAASk"]
[Tue Aug 18 12:54:25.273780 2026] [security2:error] [pid 66623:tid 66665] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSAMdO5rbWdOArH04J_1gABYhw"]
[Tue Aug 18 12:54:25.277295 2026] [security2:error] [pid 67073:tid 67305] [client 20.163.43.14:3086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/404.php"] [unique_id "aoSAMfcmepr5_nHgLbM3PgAAAng"]
[Tue Aug 18 12:54:25.285592 2026] [security2:error] [pid 67073:tid 67237] [client 74.248.136.165:37893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/hello.php"] [unique_id "aoSAMfcmepr5_nHgLbM3PwAAAjQ"]
[Tue Aug 18 12:54:25.294246 2026] [security2:error] [pid 67073:tid 67184] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/f6.php"] [unique_id "aoSAMfcmepr5_nHgLbM3QAACTGw"]
[Tue Aug 18 12:54:25.305046 2026] [security2:error] [pid 66623:tid 66838] [client 103.120.71.157:61410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAMdO5rbWdOArH04J_2QAAAVI"]
[Tue Aug 18 12:54:25.305138 2026] [security2:error] [pid 66623:tid 66838] [client 103.120.71.157:61410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAMdO5rbWdOArH04J_2QAAAVI"]
[Tue Aug 18 12:54:25.313442 2026] [security2:error] [pid 66623:tid 66851] [client 20.51.153.15:8813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/app.php"] [unique_id "aoSAMdO5rbWdOArH04J_2wAAAV8"]
[Tue Aug 18 12:54:25.321943 2026] [authz_core:error] [pid 67073:tid 67107] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:25.322194 2026] [authz_core:error] [pid 67073:tid 67107] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:25.339975 2026] [security2:error] [pid 66623:tid 66884] [client 213.35.127.232:63267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAMdO5rbWdOArH04J_3AAAAYA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:25.363462 2026] [security2:error] [pid 67073:tid 67232] [client 20.48.236.86:10794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/w1px.php"] [unique_id "aoSAMfcmepr5_nHgLbM3QwAAAi8"]
[Tue Aug 18 12:54:25.376535 2026] [security2:error] [pid 66623:tid 66780] [client 20.104.85.180:43522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSAMdO5rbWdOArH04J_3QAAARg"]
[Tue Aug 18 12:54:25.389020 2026] [security2:error] [pid 66623:tid 66741] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSAMdO5rbWdOArH04J_3gABc2g"]
[Tue Aug 18 12:54:25.416765 2026] [security2:error] [pid 67073:tid 67262] [client 20.104.85.180:8063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/alfa.php"] [unique_id "aoSAMfcmepr5_nHgLbM3RAAAAk0"]
[Tue Aug 18 12:54:25.457834 2026] [security2:error] [pid 67073:tid 67243] [client 20.251.48.93:58929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAMfcmepr5_nHgLbM3RQAAAjo"]
[Tue Aug 18 12:54:25.462522 2026] [security2:error] [pid 66623:tid 66803] [client 74.248.136.165:62264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/avim.php"] [unique_id "aoSAMdO5rbWdOArH04J_3wAAAS8"]
[Tue Aug 18 12:54:25.464816 2026] [security2:error] [pid 67073:tid 67286] [client 20.171.51.14:45439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/pk.php"] [unique_id "aoSAMfcmepr5_nHgLbM3RgAAAmU"]
[Tue Aug 18 12:54:25.483873 2026] [security2:error] [pid 67073:tid 67317] [client 52.238.210.254:10177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/flower.php"] [unique_id "aoSAMfcmepr5_nHgLbM3SAAAAoQ"]
[Tue Aug 18 12:54:25.493414 2026] [security2:error] [pid 67073:tid 67242] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/mt/byp.php"] [unique_id "aoSAMfcmepr5_nHgLbM3SQAAAjk"]
[Tue Aug 18 12:54:25.497602 2026] [security2:error] [pid 67073:tid 67092] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/mcs.php"] [unique_id "aoSAMfcmepr5_nHgLbM3SgACShA"]
[Tue Aug 18 12:54:25.515147 2026] [security2:error] [pid 66623:tid 66890] [client 68.155.154.236:65190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSAMdO5rbWdOArH04J_4AAAAYY"]
[Tue Aug 18 12:54:25.515398 2026] [security2:error] [pid 67073:tid 67249] [client 20.104.100.201:58435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSAMfcmepr5_nHgLbM3TQAAAkA"]
[Tue Aug 18 12:54:25.521303 2026] [security2:error] [pid 66623:tid 66783] [client 4.232.151.198:48184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/new.php"] [unique_id "aoSAMdO5rbWdOArH04J_4QAAARs"]
[Tue Aug 18 12:54:25.557818 2026] [security2:error] [pid 66623:tid 66800] [client 20.91.215.254:24371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/import.php"] [unique_id "aoSAMdO5rbWdOArH04J_4gAAASw"]
[Tue Aug 18 12:54:25.563817 2026] [security2:error] [pid 66623:tid 66679] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSAMdO5rbWdOArH04J_5AABSSo"]
[Tue Aug 18 12:54:25.571002 2026] [security2:error] [pid 67073:tid 67241] [client 172.182.200.96:14216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSAMfcmepr5_nHgLbM3TwAAAjg"]
[Tue Aug 18 12:54:25.576167 2026] [security2:error] [pid 67073:tid 67316] [client 132.196.61.152:56125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/zi-936.php"] [unique_id "aoSAMfcmepr5_nHgLbM3UAAAAoM"]
[Tue Aug 18 12:54:25.588559 2026] [security2:error] [pid 67073:tid 67240] [client 20.51.153.15:9191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/87.php"] [unique_id "aoSAMfcmepr5_nHgLbM3UQAAAjc"]
[Tue Aug 18 12:54:25.661517 2026] [security2:error] [pid 67073:tid 67221] [client 74.248.18.37:12993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/moon.php"] [unique_id "aoSAMfcmepr5_nHgLbM3VwAAAiQ"]
[Tue Aug 18 12:54:25.664490 2026] [security2:error] [pid 67073:tid 67300] [client 20.104.85.180:43541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/01.php"] [unique_id "aoSAMfcmepr5_nHgLbM3WAAAAnM"]
[Tue Aug 18 12:54:25.677982 2026] [security2:error] [pid 67073:tid 67263] [client 135.225.75.187:58984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/X57.php"] [unique_id "aoSAMfcmepr5_nHgLbM3WQAAAk4"]
[Tue Aug 18 12:54:25.688959 2026] [security2:error] [pid 67073:tid 67112] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/xleet.php"] [unique_id "aoSAMfcmepr5_nHgLbM3WwACkSQ"]
[Tue Aug 18 12:54:25.700276 2026] [security2:error] [pid 67073:tid 67256] [client 78.138.24.128:50593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.24.138.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zanseg.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAMfcmepr5_nHgLbM3XAAAAkc"]
[Tue Aug 18 12:54:25.700408 2026] [security2:error] [pid 67073:tid 67256] [client 78.138.24.128:50593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "zanseg.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAMfcmepr5_nHgLbM3XAAAAkc"]
[Tue Aug 18 12:54:25.704716 2026] [security2:error] [pid 67073:tid 67255] [client 74.248.136.165:29413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/brc.php"] [unique_id "aoSAMfcmepr5_nHgLbM3XQAAAkY"]
[Tue Aug 18 12:54:25.743663 2026] [security2:error] [pid 67073:tid 67304] [client 20.104.85.180:8046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/lock360.php"] [unique_id "aoSAMfcmepr5_nHgLbM3XgAAAnc"]
[Tue Aug 18 12:54:25.743931 2026] [security2:error] [pid 66623:tid 66836] [client 52.139.47.57:19631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAMdO5rbWdOArH04J_5wAAAVA"]
[Tue Aug 18 12:54:25.776947 2026] [security2:error] [pid 66623:tid 66865] [client 20.163.43.14:3189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-login.php"] [unique_id "aoSAMdO5rbWdOArH04J_5QAAAW0"]
[Tue Aug 18 12:54:25.792247 2026] [security2:error] [pid 66623:tid 66839] [client 20.104.100.201:58920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSAMdO5rbWdOArH04J_6AAAAVM"]
[Tue Aug 18 12:54:25.800674 2026] [security2:error] [pid 66623:tid 66834] [client 172.202.39.151:65232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAMdO5rbWdOArH04J_6QAAAU4"]
[Tue Aug 18 12:54:25.830817 2026] [security2:error] [pid 67073:tid 67213] [client 20.51.153.15:9165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/zi.php"] [unique_id "aoSAMfcmepr5_nHgLbM3YAAAAhw"]
[Tue Aug 18 12:54:25.840715 2026] [security2:error] [pid 66623:tid 66848] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSAMdO5rbWdOArH04J_6gAAAVw"]
[Tue Aug 18 12:54:25.876357 2026] [security2:error] [pid 66623:tid 66743] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/first.php"] [unique_id "aoSAMdO5rbWdOArH04J_6wABbGo"]
[Tue Aug 18 12:54:25.899612 2026] [security2:error] [pid 66623:tid 66764] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSAMdO5rbWdOArH04J_7AABWn8"]
[Tue Aug 18 12:54:25.912029 2026] [security2:error] [pid 66623:tid 66886] [client 158.158.74.177:20523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSAMdO5rbWdOArH04J_7QAAAYI"]
[Tue Aug 18 12:54:25.915799 2026] [security2:error] [pid 67073:tid 67084] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/fr/ms.php"] [unique_id "aoSAMfcmepr5_nHgLbM3YgACGgg"]
[Tue Aug 18 12:54:25.918518 2026] [security2:error] [pid 66623:tid 66700] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSAMdO5rbWdOArH04J_7gABSj8"]
[Tue Aug 18 12:54:25.921313 2026] [security2:error] [pid 66623:tid 66824] [client 37.40.227.74:56950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAMdO5rbWdOArH04J_7wAAAUQ"]
[Tue Aug 18 12:54:25.924017 2026] [security2:error] [pid 66623:tid 66824] [client 37.40.227.74:56950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAMdO5rbWdOArH04J_7wAAAUQ"]
[Tue Aug 18 12:54:25.924529 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:25.924780 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:25.965023 2026] [security2:error] [pid 67073:tid 67280] [client 172.182.200.96:14282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSAMfcmepr5_nHgLbM3ZgAAAl8"]
[Tue Aug 18 12:54:25.967868 2026] [security2:error] [pid 66623:tid 66742] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAMdO5rbWdOArH04J_8AABXWk"]
[Tue Aug 18 12:54:25.983282 2026] [security2:error] [pid 66623:tid 66644] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/blog/byp.php"] [unique_id "aoSAMdO5rbWdOArH04J_8QABPQc"]
[Tue Aug 18 12:54:26.005037 2026] [security2:error] [pid 66623:tid 66866] [client 20.171.51.14:59281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ge.php"] [unique_id "aoSAMtO5rbWdOArH04J_8gAAAW4"]
[Tue Aug 18 12:54:26.019160 2026] [security2:error] [pid 67073:tid 67295] [client 52.173.121.69:24775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/ucpfr.php"] [unique_id "aoSAMvcmepr5_nHgLbM3ZwAAAm4"]
[Tue Aug 18 12:54:26.022930 2026] [security2:error] [pid 66623:tid 66683] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSAMtO5rbWdOArH04J_8wABWy4"]
[Tue Aug 18 12:54:26.034813 2026] [security2:error] [pid 67073:tid 67302] [client 20.104.85.180:7945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/flower.php"] [unique_id "aoSAMvcmepr5_nHgLbM3agAAAnU"]
[Tue Aug 18 12:54:26.043099 2026] [security2:error] [pid 66623:tid 66763] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAMtO5rbWdOArH04J_9AABE34"]
[Tue Aug 18 12:54:26.058468 2026] [security2:error] [pid 66623:tid 66757] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/images/security.php"] [unique_id "aoSAMtO5rbWdOArH04J_9QABEXg"]
[Tue Aug 18 12:54:26.071562 2026] [security2:error] [pid 66623:tid 66858] [client 20.104.100.201:58917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/term.php"] [unique_id "aoSAMtO5rbWdOArH04J_9gAAAWY"]
[Tue Aug 18 12:54:26.087565 2026] [security2:error] [pid 67073:tid 67220] [client 20.104.85.180:18845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/lv.php"] [unique_id "aoSAMvcmepr5_nHgLbM3bQAAAiM"]
[Tue Aug 18 12:54:26.094854 2026] [security2:error] [pid 67073:tid 67318] [client 132.196.61.152:55306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/dcsgumnm.php"] [unique_id "aoSAMvcmepr5_nHgLbM3bgAAAoU"]
[Tue Aug 18 12:54:26.117965 2026] [security2:error] [pid 67073:tid 67218] [client 20.163.43.14:2032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAMvcmepr5_nHgLbM3bwAAAiE"]
[Tue Aug 18 12:54:26.123737 2026] [security2:error] [pid 67073:tid 67227] [client 74.248.136.165:29405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/file52.php"] [unique_id "aoSAMvcmepr5_nHgLbM3cQAAAio"]
[Tue Aug 18 12:54:26.134301 2026] [security2:error] [pid 67073:tid 67183] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/gool.php"] [unique_id "aoSAMvcmepr5_nHgLbM3cwACS2s"]
[Tue Aug 18 12:54:26.143966 2026] [security2:error] [pid 67073:tid 67292] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAMvcmepr5_nHgLbM3dAAAAms"]
[Tue Aug 18 12:54:26.143986 2026] [security2:error] [pid 67073:tid 67282] [client 20.51.153.15:9118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/92.php"] [unique_id "aoSAMvcmepr5_nHgLbM3dQAAAmE"]
[Tue Aug 18 12:54:26.146495 2026] [security2:error] [pid 66623:tid 66859] [client 4.232.151.198:48155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/packed.php"] [unique_id "aoSAMtO5rbWdOArH04J_9wAAAWc"]
[Tue Aug 18 12:54:26.207523 2026] [security2:error] [pid 67073:tid 67332] [client 20.100.169.31:38039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/w.php"] [unique_id "aoSAMvcmepr5_nHgLbM3eAAAApM"]
[Tue Aug 18 12:54:26.222179 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:26.222443 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:26.230426 2026] [security2:error] [pid 67073:tid 67323] [client 172.182.200.96:14087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSAMvcmepr5_nHgLbM3egAAAoo"]
[Tue Aug 18 12:54:26.236973 2026] [security2:error] [pid 67073:tid 67314] [client 20.91.215.254:26399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/cropper.php"] [unique_id "aoSAMvcmepr5_nHgLbM3ewAAAoE"]
[Tue Aug 18 12:54:26.241279 2026] [security2:error] [pid 67073:tid 67267] [client 20.251.48.93:58886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAMvcmepr5_nHgLbM3fAAAAlI"]
[Tue Aug 18 12:54:26.277388 2026] [security2:error] [pid 67073:tid 67294] [client 20.48.236.86:10775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/zi-936.php"] [unique_id "aoSAMvcmepr5_nHgLbM3fgAAAm0"]
[Tue Aug 18 12:54:26.294304 2026] [security2:error] [pid 67073:tid 67253] [client 74.248.18.37:12324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/n.php"] [unique_id "aoSAMvcmepr5_nHgLbM3fwAAAkQ"]
[Tue Aug 18 12:54:26.315417 2026] [security2:error] [pid 67073:tid 67283] [client 172.182.200.96:14215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSAMvcmepr5_nHgLbM3gQAAAmI"]
[Tue Aug 18 12:54:26.321914 2026] [security2:error] [pid 66623:tid 66813] [client 20.65.98.162:16551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/bajah.php"] [unique_id "aoSAMtO5rbWdOArH04J_-AAAATk"]
[Tue Aug 18 12:54:26.329359 2026] [security2:error] [pid 67073:tid 67134] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/maxro.php"] [unique_id "aoSAMvcmepr5_nHgLbM3ggACdjo"]
[Tue Aug 18 12:54:26.339580 2026] [security2:error] [pid 67073:tid 67254] [client 20.104.85.180:7991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/13.php"] [unique_id "aoSAMvcmepr5_nHgLbM3hAAAAkU"]
[Tue Aug 18 12:54:26.350568 2026] [security2:error] [pid 67073:tid 67237] [client 20.104.100.201:58886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/black.php"] [unique_id "aoSAMvcmepr5_nHgLbM3hQAAAjQ"]
[Tue Aug 18 12:54:26.360385 2026] [security2:error] [pid 67073:tid 67290] [client 213.35.127.232:63493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAMvcmepr5_nHgLbM3hgAAAmk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:26.362484 2026] [security2:error] [pid 66623:tid 66852] [client 20.104.85.180:43533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/new.php"] [unique_id "aoSAMtO5rbWdOArH04J_-QAAAWA"]
[Tue Aug 18 12:54:26.425808 2026] [security2:error] [pid 67073:tid 67265] [client 40.85.222.29:45238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/first.php"] [unique_id "aoSAMvcmepr5_nHgLbM3igAAAlA"]
[Tue Aug 18 12:54:26.436544 2026] [security2:error] [pid 67073:tid 67248] [client 20.226.6.191:6571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSAMvcmepr5_nHgLbM3iwAAAj8"]
[Tue Aug 18 12:54:26.457420 2026] [security2:error] [pid 66623:tid 66785] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAMtO5rbWdOArH04J_-gAAAR0"]
[Tue Aug 18 12:54:26.458930 2026] [security2:error] [pid 67073:tid 67278] [client 52.139.47.57:3279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/xx.php"] [unique_id "aoSAMvcmepr5_nHgLbM3jAAAAl0"]
[Tue Aug 18 12:54:26.482546 2026] [security2:error] [pid 67073:tid 67317] [client 20.51.153.15:9186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/jm.php"] [unique_id "aoSAMvcmepr5_nHgLbM3jgAAAoQ"]
[Tue Aug 18 12:54:26.506541 2026] [security2:error] [pid 67073:tid 67138] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wdf.php"] [unique_id "aoSAMvcmepr5_nHgLbM3jwACSj4"]
[Tue Aug 18 12:54:26.522503 2026] [authz_core:error] [pid 67073:tid 67130] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:26.522780 2026] [authz_core:error] [pid 67073:tid 67130] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:26.541509 2026] [security2:error] [pid 67073:tid 67311] [client 74.248.136.165:23460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/sxdfrt.php"] [unique_id "aoSAMvcmepr5_nHgLbM3kwAAAn4"]
[Tue Aug 18 12:54:26.541638 2026] [security2:error] [pid 67073:tid 67310] [client 158.158.74.177:17187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAMvcmepr5_nHgLbM3lAAAAn0"]
[Tue Aug 18 12:54:26.550924 2026] [security2:error] [pid 67073:tid 67316] [client 20.42.19.40:2721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/system_log.php"] [unique_id "aoSAMvcmepr5_nHgLbM3lQAAAoM"]
[Tue Aug 18 12:54:26.554214 2026] [security2:error] [pid 67073:tid 67236] [client 149.34.210.157:51830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAMvcmepr5_nHgLbM3lgAAAjM"]
[Tue Aug 18 12:54:26.559811 2026] [security2:error] [pid 66623:tid 66772] [client 20.226.56.190:47164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ag.php"] [unique_id "aoSAMtO5rbWdOArH04J__AAAARA"]
[Tue Aug 18 12:54:26.586750 2026] [security2:error] [pid 67073:tid 67244] [client 74.248.133.44:45737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/.__info.php"] [unique_id "aoSAMvcmepr5_nHgLbM3mAAAAjs"]
[Tue Aug 18 12:54:26.625756 2026] [security2:error] [pid 66623:tid 66791] [client 20.104.85.180:7947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/cc.php"] [unique_id "aoSAMtO5rbWdOArH04J__gAAASM"]
[Tue Aug 18 12:54:26.626287 2026] [security2:error] [pid 66623:tid 66889] [client 20.104.100.201:58450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/as.php"] [unique_id "aoSAMtO5rbWdOArH04J__wAAAYU"]
[Tue Aug 18 12:54:26.669868 2026] [security2:error] [pid 67073:tid 67330] [client 172.182.200.96:14234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSAMvcmepr5_nHgLbM3nQAAApE"]
[Tue Aug 18 12:54:26.682370 2026] [security2:error] [pid 67073:tid 67256] [client 132.196.61.152:27265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/php.php"] [unique_id "aoSAMvcmepr5_nHgLbM3ngAAAkc"]
[Tue Aug 18 12:54:26.693443 2026] [security2:error] [pid 67073:tid 67255] [client 68.155.154.236:65106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSAMvcmepr5_nHgLbM3nwAAAkY"]
[Tue Aug 18 12:54:26.702966 2026] [security2:error] [pid 67073:tid 67313] [client 20.104.85.180:7047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/222.php"] [unique_id "aoSAMvcmepr5_nHgLbM3oQAAAoA"]
[Tue Aug 18 12:54:26.762691 2026] [security2:error] [pid 66623:tid 66891] [client 20.226.6.191:6568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/01.php"] [unique_id "aoSAMtO5rbWdOArH04KAAQAAAYc"]
[Tue Aug 18 12:54:26.768128 2026] [security2:error] [pid 66623:tid 66810] [client 196.12.128.158:57523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAMtO5rbWdOArH04KAAgAAATY"]
[Tue Aug 18 12:54:26.768230 2026] [security2:error] [pid 66623:tid 66810] [client 196.12.128.158:57523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAMtO5rbWdOArH04KAAgAAATY"]
[Tue Aug 18 12:54:26.795324 2026] [security2:error] [pid 66623:tid 66857] [client 20.51.153.15:9115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/wj.php"] [unique_id "aoSAMtO5rbWdOArH04KABAAAAWU"]
[Tue Aug 18 12:54:26.798579 2026] [security2:error] [pid 66623:tid 66870] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSAMtO5rbWdOArH04KABQAAAXI"]
[Tue Aug 18 12:54:26.802903 2026] [security2:error] [pid 67073:tid 67207] [client 20.171.51.14:61459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/kl.php"] [unique_id "aoSAMvcmepr5_nHgLbM3pQAAAhY"]
[Tue Aug 18 12:54:26.803080 2026] [autoindex:error] [pid 67073:tid 67325] [client 20.163.43.14:3142] AH01276: Cannot serve directory /var/www/html/.well-known/: No matching DirectoryIndex (index.cgi,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:26.827854 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:26.828263 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:26.832310 2026] [security2:error] [pid 67073:tid 67236] [client 149.34.210.157:51830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAMvcmepr5_nHgLbM3lgAAAjM"]
[Tue Aug 18 12:54:26.865390 2026] [security2:error] [pid 67073:tid 67211] [client 74.248.136.165:31878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/myfile.php"] [unique_id "aoSAMvcmepr5_nHgLbM3pwAAAho"]
[Tue Aug 18 12:54:26.875459 2026] [security2:error] [pid 66623:tid 66843] [client 20.91.215.254:24344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSAMtO5rbWdOArH04KABwAAAVc"]
[Tue Aug 18 12:54:26.898623 2026] [security2:error] [pid 67073:tid 67272] [client 52.238.210.254:10165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/motu.php"] [unique_id "aoSAMvcmepr5_nHgLbM3qgAAAlc"]
[Tue Aug 18 12:54:26.906122 2026] [security2:error] [pid 66623:tid 66787] [client 20.104.100.201:58903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/pucci.php"] [unique_id "aoSAMtO5rbWdOArH04KACAAAAR8"]
[Tue Aug 18 12:54:26.924631 2026] [security2:error] [pid 66623:tid 66832] [client 52.139.47.57:3295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/zwso.php"] [unique_id "aoSAMtO5rbWdOArH04KACQAAAUw"]
[Tue Aug 18 12:54:26.949242 2026] [security2:error] [pid 66623:tid 66767] [client 52.173.121.69:24778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/yxijx.php"] [unique_id "aoSAMtO5rbWdOArH04KACgAAAQs"]
[Tue Aug 18 12:54:26.960029 2026] [security2:error] [pid 67073:tid 67216] [client 74.248.136.165:39576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/path.php"] [unique_id "aoSAMvcmepr5_nHgLbM3rAAAAh8"]
[Tue Aug 18 12:54:26.965904 2026] [security2:error] [pid 67073:tid 67295] [client 20.163.43.14:3142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wso.php"] [unique_id "aoSAMvcmepr5_nHgLbM3rQAAAm4"]
[Tue Aug 18 12:54:26.982979 2026] [security2:error] [pid 67073:tid 67263] [client 114.119.159.62:40687] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bioarquitetar.com"] [uri "/portfolio/casacor-minas-gerais/"] [unique_id "aoSAMvcmepr5_nHgLbM3rwAAAk4"], referer: https://mobillegends.net/24a-casacor-minas-gerais-apresenta-o-tema-a-casa-viva-blog-do
[Tue Aug 18 12:54:26.988684 2026] [security2:error] [pid 66623:tid 66888] [client 4.232.151.198:6174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/plugin.php"] [unique_id "aoSAMtO5rbWdOArH04KACwAAAYQ"]
[Tue Aug 18 12:54:26.988894 2026] [security2:error] [pid 66623:tid 66881] [client 20.104.85.180:8005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAMtO5rbWdOArH04KADAAAAX0"]
[Tue Aug 18 12:54:26.992452 2026] [security2:error] [pid 67073:tid 67206] [client 20.104.85.180:43582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/chosen.php"] [unique_id "aoSAMvcmepr5_nHgLbM3sAAAAhU"]
[Tue Aug 18 12:54:27.018404 2026] [security2:error] [pid 67073:tid 67318] [client 135.225.75.187:63993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/forbidals.php"] [unique_id "aoSAM_cmepr5_nHgLbM3sQAAAoU"]
[Tue Aug 18 12:54:27.025215 2026] [security2:error] [pid 67073:tid 67252] [client 74.248.18.37:12410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/nc4.php"] [unique_id "aoSAM_cmepr5_nHgLbM3sgAAAkM"]
[Tue Aug 18 12:54:27.027538 2026] [security2:error] [pid 67073:tid 67175] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ff1.php"] [unique_id "aoSAM_cmepr5_nHgLbM3swACIWM"]
[Tue Aug 18 12:54:27.034715 2026] [security2:error] [pid 67073:tid 67329] [client 213.202.253.4:54538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/wp-content/txets.php"] [unique_id "aoSAM_cmepr5_nHgLbM3tAAAApA"], referer: www.google.com
[Tue Aug 18 12:54:27.057376 2026] [security2:error] [pid 66623:tid 66796] [client 172.182.200.96:14208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSAM9O5rbWdOArH04KADQAAASg"]
[Tue Aug 18 12:54:27.071408 2026] [security2:error] [pid 66623:tid 66873] [client 20.51.153.15:9145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/av.php"] [unique_id "aoSAM9O5rbWdOArH04KADgAAAXU"]
[Tue Aug 18 12:54:27.124925 2026] [authz_core:error] [pid 67073:tid 67123] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:27.125223 2026] [authz_core:error] [pid 67073:tid 67123] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:27.147525 2026] [security2:error] [pid 67073:tid 67322] [client 20.250.13.23:53285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/155.php"] [unique_id "aoSAM_cmepr5_nHgLbM3uQAAAok"]
[Tue Aug 18 12:54:27.153692 2026] [security2:error] [pid 66623:tid 66827] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSAM9O5rbWdOArH04KADwAAAUc"]
[Tue Aug 18 12:54:27.164607 2026] [security2:error] [pid 66623:tid 66825] [client 158.158.74.177:15828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAM9O5rbWdOArH04KAEAAAAUU"]
[Tue Aug 18 12:54:27.187098 2026] [security2:error] [pid 67073:tid 67332] [client 20.104.100.201:58897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wicked.php"] [unique_id "aoSAM_cmepr5_nHgLbM3uwAAApM"]
[Tue Aug 18 12:54:27.205891 2026] [security2:error] [pid 67073:tid 67136] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/guk.php"] [unique_id "aoSAM_cmepr5_nHgLbM3vAACajw"]
[Tue Aug 18 12:54:27.231321 2026] [security2:error] [pid 67073:tid 67267] [client 172.202.39.151:32089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/HLA-dd.php"] [unique_id "aoSAM_cmepr5_nHgLbM3vQAAAlI"]
[Tue Aug 18 12:54:27.266465 2026] [security2:error] [pid 67073:tid 67294] [client 20.104.85.180:8024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSAM_cmepr5_nHgLbM3vwAAAm0"]
[Tue Aug 18 12:54:27.271083 2026] [security2:error] [pid 67073:tid 67208] [client 132.196.61.152:56078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/sf.php"] [unique_id "aoSAM_cmepr5_nHgLbM3wAAAAhc"]
[Tue Aug 18 12:54:27.277179 2026] [security2:error] [pid 67073:tid 67327] [client 20.104.85.180:43569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/info.php"] [unique_id "aoSAM_cmepr5_nHgLbM3wQAAAo4"]
[Tue Aug 18 12:54:27.321657 2026] [security2:error] [pid 66623:tid 66780] [client 20.163.43.14:2014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/sf.php"] [unique_id "aoSAM9O5rbWdOArH04KAEQAAARg"]
[Tue Aug 18 12:54:27.336788 2026] [security2:error] [pid 66623:tid 66871] [client 20.171.51.14:57362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/gs.php"] [unique_id "aoSAM9O5rbWdOArH04KAEgAAAXM"]
[Tue Aug 18 12:54:27.367112 2026] [security2:error] [pid 67073:tid 67299] [client 52.173.121.69:24964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/zwlsv.php"] [unique_id "aoSAM_cmepr5_nHgLbM3wwAAAnI"]
[Tue Aug 18 12:54:27.377987 2026] [security2:error] [pid 67073:tid 67250] [client 74.248.136.165:44743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wpo.php"] [unique_id "aoSAM_cmepr5_nHgLbM3xAAAAkE"]
[Tue Aug 18 12:54:27.392645 2026] [security2:error] [pid 66623:tid 66845] [client 213.35.127.232:63708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAM9O5rbWdOArH04KAEwAAAVk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:27.407754 2026] [security2:error] [pid 67073:tid 67225] [client 172.182.200.96:14308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSAM_cmepr5_nHgLbM3xgAAAig"]
[Tue Aug 18 12:54:27.416610 2026] [security2:error] [pid 66623:tid 66806] [client 20.226.6.191:6605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/lv.php"] [unique_id "aoSAM9O5rbWdOArH04KAFAAAATI"]
[Tue Aug 18 12:54:27.425591 2026] [authz_core:error] [pid 67073:tid 67095] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:27.425856 2026] [authz_core:error] [pid 67073:tid 67095] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:27.428180 2026] [security2:error] [pid 67073:tid 67179] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-the.php"] [unique_id "aoSAM_cmepr5_nHgLbM3yAACaWc"]
[Tue Aug 18 12:54:27.440445 2026] [security2:error] [pid 66623:tid 66875] [client 104.209.144.33:24836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAM9O5rbWdOArH04KAFQAAAXc"]
[Tue Aug 18 12:54:27.463142 2026] [security2:error] [pid 67073:tid 67284] [client 20.104.100.201:58463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/water.php"] [unique_id "aoSAM_cmepr5_nHgLbM3yQAAAmM"]
[Tue Aug 18 12:54:27.494230 2026] [security2:error] [pid 67073:tid 67232] [client 20.51.153.15:9162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ag.php"] [unique_id "aoSAM_cmepr5_nHgLbM3ywAAAi8"]
[Tue Aug 18 12:54:27.502524 2026] [security2:error] [pid 67073:tid 67215] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSAM_cmepr5_nHgLbM3zAAAAh4"]
[Tue Aug 18 12:54:27.514968 2026] [security2:error] [pid 67073:tid 67253] [client 5.253.205.188:40682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/fullwebsite.bak"] [unique_id "aoSAM_cmepr5_nHgLbM3zQAAAkQ"], referer: https://medihub.com.br/fullwebsite.bak
[Tue Aug 18 12:54:27.522968 2026] [security2:error] [pid 67073:tid 67309] [client 20.91.215.254:26383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSAM_cmepr5_nHgLbM3zgAAAnw"]
[Tue Aug 18 12:54:27.527699 2026] [security2:error] [pid 67073:tid 67315] [client 20.226.56.190:28276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ig.php"] [unique_id "aoSAM_cmepr5_nHgLbM3zwAAAoI"]
[Tue Aug 18 12:54:27.544831 2026] [security2:error] [pid 66623:tid 66821] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/php.php"] [unique_id "aoSAM9O5rbWdOArH04KAFgAAAUE"]
[Tue Aug 18 12:54:27.545189 2026] [security2:error] [pid 66623:tid 66835] [client 20.104.85.180:8052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/01.php"] [unique_id "aoSAM9O5rbWdOArH04KAFwAAAU8"]
[Tue Aug 18 12:54:27.558014 2026] [security2:error] [pid 67073:tid 67278] [client 52.139.47.57:48951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/x.php"] [unique_id "aoSAM_cmepr5_nHgLbM30AAAAl0"]
[Tue Aug 18 12:54:27.618964 2026] [security2:error] [pid 67073:tid 67124] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/sbhu.php"] [unique_id "aoSAM_cmepr5_nHgLbM30wAChDA"]
[Tue Aug 18 12:54:27.640936 2026] [security2:error] [pid 67073:tid 67273] [client 20.48.236.86:10756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/dcsgumnm.php"] [unique_id "aoSAM_cmepr5_nHgLbM31AAAAlg"]
[Tue Aug 18 12:54:27.682817 2026] [security2:error] [pid 67073:tid 67249] [client 20.163.43.14:3088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/index/function.php"] [unique_id "aoSAM_cmepr5_nHgLbM31gAAAkA"]
[Tue Aug 18 12:54:27.716692 2026] [security2:error] [pid 66623:tid 66808] [client 132.196.61.152:27300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/xx.php"] [unique_id "aoSAM9O5rbWdOArH04KAGQAAATQ"]
[Tue Aug 18 12:54:27.716692 2026] [security2:error] [pid 67073:tid 67265] [client 74.248.18.37:12302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/new.php"] [unique_id "aoSAM_cmepr5_nHgLbM31wAAAlA"]
[Tue Aug 18 12:54:27.717892 2026] [security2:error] [pid 66623:tid 66708] [remote 103.56.163.133:59632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/wp-login.php"] [unique_id "aoSAM9O5rbWdOArH04KAGgABK0c"]
[Tue Aug 18 12:54:27.740707 2026] [security2:error] [pid 67073:tid 67240] [client 20.104.100.201:58437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/fine.php"] [unique_id "aoSAM_cmepr5_nHgLbM32AAAAjc"]
[Tue Aug 18 12:54:27.752437 2026] [security2:error] [pid 66623:tid 66818] [client 68.155.154.236:65102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/first.php"] [unique_id "aoSAM9O5rbWdOArH04KAGwAAAT4"]
[Tue Aug 18 12:54:27.758401 2026] [security2:error] [pid 66623:tid 66880] [client 172.182.200.96:14229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSAM9O5rbWdOArH04KAHAAAAXw"]
[Tue Aug 18 12:54:27.797462 2026] [security2:error] [pid 66623:tid 66811] [client 74.248.136.165:16999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/a1vx.php"] [unique_id "aoSAM9O5rbWdOArH04KAHQAAATc"]
[Tue Aug 18 12:54:27.801880 2026] [security2:error] [pid 66623:tid 66805] [client 20.251.48.93:2143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/media.php"] [unique_id "aoSAM9O5rbWdOArH04KAHgAAATE"]
[Tue Aug 18 12:54:27.808152 2026] [security2:error] [pid 67073:tid 67226] [client 158.158.74.177:15832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/abc.php"] [unique_id "aoSAM_cmepr5_nHgLbM32wAAAik"]
[Tue Aug 18 12:54:27.823926 2026] [security2:error] [pid 67073:tid 67233] [client 197.184.64.235:41918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAM_cmepr5_nHgLbM33AAAAjA"]
[Tue Aug 18 12:54:27.824047 2026] [security2:error] [pid 67073:tid 67233] [client 197.184.64.235:41918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAM_cmepr5_nHgLbM33AAAAjA"]
[Tue Aug 18 12:54:27.826561 2026] [security2:error] [pid 67073:tid 67209] [client 4.232.151.198:48133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/public/moon.php"] [unique_id "aoSAM_cmepr5_nHgLbM33QAAAhg"]
[Tue Aug 18 12:54:27.829486 2026] [security2:error] [pid 67073:tid 67319] [client 114.5.214.109:49797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAM_cmepr5_nHgLbM33gAAAoY"]
[Tue Aug 18 12:54:27.832396 2026] [security2:error] [pid 66623:tid 66798] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSAM9O5rbWdOArH04KAIAAAASo"]
[Tue Aug 18 12:54:27.838541 2026] [security2:error] [pid 67073:tid 67319] [client 114.5.214.109:49797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAM_cmepr5_nHgLbM33gAAAoY"]
[Tue Aug 18 12:54:27.867251 2026] [security2:error] [pid 66623:tid 66836] [client 4.223.164.152:46161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAM9O5rbWdOArH04KAIQAAAVA"]
[Tue Aug 18 12:54:27.867693 2026] [security2:error] [pid 66623:tid 66766] [client 20.104.85.180:8054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/lv.php"] [unique_id "aoSAM9O5rbWdOArH04KAIgAAAQo"]
[Tue Aug 18 12:54:27.887556 2026] [security2:error] [pid 66623:tid 66867] [client 52.173.121.69:17957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/jrpga.php"] [unique_id "aoSAM9O5rbWdOArH04KAIwAAAW8"]
[Tue Aug 18 12:54:27.960063 2026] [security2:error] [pid 66623:tid 66865] [client 20.226.6.191:6560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/new.php"] [unique_id "aoSAM9O5rbWdOArH04KAJAAAAW0"]
[Tue Aug 18 12:54:27.995003 2026] [security2:error] [pid 66623:tid 66820] [client 52.139.47.57:3273] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.plenitude.com.br"] [uri "/1.php"] [unique_id "aoSAM9O5rbWdOArH04KAJgAAAUA"]
[Tue Aug 18 12:54:27.995104 2026] [security2:error] [pid 66623:tid 66820] [client 52.139.47.57:3273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/1.php"] [unique_id "aoSAM9O5rbWdOArH04KAJgAAAUA"]
[Tue Aug 18 12:54:28.025608 2026] [security2:error] [pid 66623:tid 66831] [client 20.163.43.14:3109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/edit.php"] [unique_id "aoSANNO5rbWdOArH04KAJwAAAUs"]
[Tue Aug 18 12:54:28.027043 2026] [security2:error] [pid 66623:tid 66770] [client 20.104.100.201:21445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/loader.php"] [unique_id "aoSANNO5rbWdOArH04KAKAAAAQ4"]
[Tue Aug 18 12:54:28.029732 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:28.029999 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:28.040273 2026] [security2:error] [pid 67073:tid 67178] [remote 185.118.190.176:56930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.190.118.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carnescapellari.top"] [uri "/wp-login.php"] [unique_id "aoSANPcmepr5_nHgLbM34wACLWY"]
[Tue Aug 18 12:54:28.049502 2026] [security2:error] [pid 67073:tid 67241] [client 20.171.51.14:59309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/lw.php"] [unique_id "aoSANPcmepr5_nHgLbM35AAAAjg"]
[Tue Aug 18 12:54:28.115191 2026] [security2:error] [pid 66623:tid 66872] [client 74.248.133.44:60461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/access.php"] [unique_id "aoSANNO5rbWdOArH04KAKwAAAXQ"]
[Tue Aug 18 12:54:28.140603 2026] [security2:error] [pid 67073:tid 67298] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/first.php"] [unique_id "aoSANPcmepr5_nHgLbM35gAAAnE"]
[Tue Aug 18 12:54:28.163563 2026] [security2:error] [pid 66623:tid 66775] [client 172.182.200.96:14236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSANNO5rbWdOArH04KALAAAARM"]
[Tue Aug 18 12:54:28.196480 2026] [security2:error] [pid 67073:tid 67307] [client 172.202.39.151:63213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSANPcmepr5_nHgLbM36QAAAno"]
[Tue Aug 18 12:54:28.201247 2026] [security2:error] [pid 66623:tid 66848] [client 20.91.215.254:26406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/goat.php"] [unique_id "aoSANNO5rbWdOArH04KALgAAAVw"]
[Tue Aug 18 12:54:28.214651 2026] [security2:error] [pid 66623:tid 66841] [client 74.248.136.165:37889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ty.php"] [unique_id "aoSANNO5rbWdOArH04KALwAAAVU"]
[Tue Aug 18 12:54:28.241125 2026] [security2:error] [pid 66623:tid 66859] [client 20.104.85.180:8057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/new.php"] [unique_id "aoSANNO5rbWdOArH04KAMAAAAWc"]
[Tue Aug 18 12:54:28.273278 2026] [security2:error] [pid 66623:tid 66804] [client 20.116.17.175:57607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSANNO5rbWdOArH04KAMQAAATA"]
[Tue Aug 18 12:54:28.285635 2026] [security2:error] [pid 67073:tid 67264] [client 4.223.164.152:54232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSANPcmepr5_nHgLbM36wAAAk8"]
[Tue Aug 18 12:54:28.288779 2026] [security2:error] [pid 66623:tid 66784] [client 52.173.121.69:6090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSANNO5rbWdOArH04KAMgAAARw"]
[Tue Aug 18 12:54:28.317994 2026] [security2:error] [pid 67073:tid 67216] [client 20.104.100.201:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/zero.php"] [unique_id "aoSANPcmepr5_nHgLbM37gAAAh8"]
[Tue Aug 18 12:54:28.326243 2026] [security2:error] [pid 67073:tid 67121] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/zc-318.php"] [unique_id "aoSANPcmepr5_nHgLbM38AACFC0"]
[Tue Aug 18 12:54:28.328547 2026] [authz_core:error] [pid 67073:tid 67193] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:28.328816 2026] [authz_core:error] [pid 67073:tid 67193] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:28.342822 2026] [security2:error] [pid 66623:tid 66862] [client 192.141.172.134:54192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSANNO5rbWdOArH04KAMwAAAWo"]
[Tue Aug 18 12:54:28.342919 2026] [security2:error] [pid 66623:tid 66862] [client 192.141.172.134:54192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSANNO5rbWdOArH04KAMwAAAWo"]
[Tue Aug 18 12:54:28.364673 2026] [security2:error] [pid 66623:tid 66795] [client 135.225.75.187:19224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/edit.php"] [unique_id "aoSANNO5rbWdOArH04KANAAAASc"]
[Tue Aug 18 12:54:28.385954 2026] [security2:error] [pid 66623:tid 66814] [client 132.196.61.152:56096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/uwu.php"] [unique_id "aoSANNO5rbWdOArH04KANQAAATo"]
[Tue Aug 18 12:54:28.411964 2026] [security2:error] [pid 67073:tid 67320] [client 213.35.127.232:63896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSANPcmepr5_nHgLbM38gAAAoc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:28.420181 2026] [security2:error] [pid 67073:tid 67270] [client 52.139.47.57:3314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/z.php"] [unique_id "aoSANPcmepr5_nHgLbM38wAAAlU"]
[Tue Aug 18 12:54:28.432378 2026] [security2:error] [pid 67073:tid 67257] [client 74.248.18.37:12360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/packed.php"] [unique_id "aoSANPcmepr5_nHgLbM39AAAAkg"]
[Tue Aug 18 12:54:28.444093 2026] [security2:error] [pid 66623:tid 66807] [client 158.158.74.177:17206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/sf.php"] [unique_id "aoSANNO5rbWdOArH04KAOAAAATM"]
[Tue Aug 18 12:54:28.456209 2026] [security2:error] [pid 66623:tid 66891] [client 20.226.6.191:6540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/222.php"] [unique_id "aoSANNO5rbWdOArH04KAOQAAAYc"]
[Tue Aug 18 12:54:28.457305 2026] [security2:error] [pid 66623:tid 66781] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSANNO5rbWdOArH04KAOgAAARk"]
[Tue Aug 18 12:54:28.461420 2026] [security2:error] [pid 67073:tid 67211] [client 4.232.151.198:6151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/public/storage.php"] [unique_id "aoSANPcmepr5_nHgLbM39gAAAho"]
[Tue Aug 18 12:54:28.468521 2026] [security2:error] [pid 67073:tid 67206] [client 20.65.98.162:22715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/h.php"] [unique_id "aoSANPcmepr5_nHgLbM39wAAAhU"]
[Tue Aug 18 12:54:28.477542 2026] [security2:error] [pid 66623:tid 66861] [client 86.120.159.145:64974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSANNO5rbWdOArH04KAPAAAAWk"]
[Tue Aug 18 12:54:28.477619 2026] [security2:error] [pid 66623:tid 66861] [client 86.120.159.145:64974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSANNO5rbWdOArH04KAPAAAAWk"]
[Tue Aug 18 12:54:28.477634 2026] [security2:error] [pid 67073:tid 67321] [client 114.119.148.64:29859] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bomcarmultimarcas.com.br"] [uri "/veiculo/270316/brasilia"] [unique_id "aoSANPcmepr5_nHgLbM3-QAAAog"], referer: https://bomcarmultimarcas.com.br/veiculo/270316/brasilia
[Tue Aug 18 12:54:28.497494 2026] [security2:error] [pid 66623:tid 66826] [client 20.171.51.14:15768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/vj.php"] [unique_id "aoSANNO5rbWdOArH04KAPwAAAUY"]
[Tue Aug 18 12:54:28.500865 2026] [security2:error] [pid 66623:tid 66856] [client 52.238.210.254:8904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/404.php"] [unique_id "aoSANNO5rbWdOArH04KAQAAAAWQ"]
[Tue Aug 18 12:54:28.507301 2026] [security2:error] [pid 67073:tid 67148] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ccou.php"] [unique_id "aoSANPcmepr5_nHgLbM3-wACjUg"]
[Tue Aug 18 12:54:28.528672 2026] [security2:error] [pid 67073:tid 67318] [client 172.182.200.96:14224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSANPcmepr5_nHgLbM3_AAAAoU"]
[Tue Aug 18 12:54:28.533224 2026] [security2:error] [pid 66623:tid 66870] [client 104.209.144.33:35902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/zugvi.php"] [unique_id "aoSANNO5rbWdOArH04KAQQAAAXI"]
[Tue Aug 18 12:54:28.534046 2026] [security2:error] [pid 66623:tid 66819] [client 20.104.85.180:8016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/222.php"] [unique_id "aoSANNO5rbWdOArH04KAQgAAAT8"]
[Tue Aug 18 12:54:28.542336 2026] [security2:error] [pid 67073:tid 67213] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSANPcmepr5_nHgLbM39QACHBk"]
[Tue Aug 18 12:54:28.605879 2026] [security2:error] [pid 66623:tid 66788] [client 20.104.100.201:58462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/002.php"] [unique_id "aoSANNO5rbWdOArH04KARQAAASA"]
[Tue Aug 18 12:54:28.611706 2026] [security2:error] [pid 67073:tid 67296] [client 20.48.236.86:10752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/php.php"] [unique_id "aoSANPcmepr5_nHgLbM3_wAAAm8"]
[Tue Aug 18 12:54:28.630040 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:28.630319 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:28.632098 2026] [security2:error] [pid 66623:tid 66888] [client 74.248.136.165:16989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/vgtyu.php"] [unique_id "aoSANNO5rbWdOArH04KARgAAAYQ"]
[Tue Aug 18 12:54:28.648500 2026] [security2:error] [pid 66623:tid 66654] [remote 192.250.229.214:59490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.229.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fabyfranco.com.br"] [uri "/wp-login.php"] [unique_id "aoSANNO5rbWdOArH04KARwABIxE"]
[Tue Aug 18 12:54:28.689349 2026] [security2:error] [pid 67073:tid 67186] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/txets.php"] [unique_id "aoSANPcmepr5_nHgLbM4AgACa24"]
[Tue Aug 18 12:54:28.695476 2026] [security2:error] [pid 67073:tid 67328] [client 20.116.17.175:57614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSANPcmepr5_nHgLbM4AwAAAo8"]
[Tue Aug 18 12:54:28.746821 2026] [security2:error] [pid 67073:tid 67251] [client 52.173.121.69:16475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/nwwha.php"] [unique_id "aoSANPcmepr5_nHgLbM4BAAAAkI"]
[Tue Aug 18 12:54:28.752984 2026] [security2:error] [pid 67073:tid 67267] [client 40.85.222.29:26161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSANPcmepr5_nHgLbM4BQAAAlI"]
[Tue Aug 18 12:54:28.757642 2026] [security2:error] [pid 66623:tid 66833] [client 20.163.43.14:3163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSANNO5rbWdOArH04KASAAAAU0"]
[Tue Aug 18 12:54:28.788054 2026] [security2:error] [pid 66623:tid 66827] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSANNO5rbWdOArH04KASQAAAUc"]
[Tue Aug 18 12:54:28.792198 2026] [security2:error] [pid 67073:tid 67271] [client 4.223.164.152:37285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/domvf.php"] [unique_id "aoSANPcmepr5_nHgLbM4CAAAAlY"]
[Tue Aug 18 12:54:28.851286 2026] [security2:error] [pid 66623:tid 66837] [client 20.91.215.254:20545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/Session.php"] [unique_id "aoSANNO5rbWdOArH04KASgAAAVE"]
[Tue Aug 18 12:54:28.856086 2026] [security2:error] [pid 67073:tid 67214] [client 172.182.200.96:14223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSANPcmepr5_nHgLbM4CgAAAh0"]
[Tue Aug 18 12:54:28.890628 2026] [security2:error] [pid 66623:tid 66884] [client 20.104.85.180:7942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/chosen.php"] [unique_id "aoSANNO5rbWdOArH04KASwAAAYA"]
[Tue Aug 18 12:54:28.891608 2026] [security2:error] [pid 67073:tid 67299] [client 20.104.100.201:58911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/zxz.php"] [unique_id "aoSANPcmepr5_nHgLbM4CwAAAnI"]
[Tue Aug 18 12:54:28.898966 2026] [security2:error] [pid 66623:tid 66779] [client 74.248.136.165:1727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/xmy.php"] [unique_id "aoSANNO5rbWdOArH04KATQAAARc"]
[Tue Aug 18 12:54:28.906584 2026] [authz_core:error] [pid 67073:tid 67190] [remote 57.141.22.21:45994] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:28.907003 2026] [authz_core:error] [pid 67073:tid 67190] [remote 57.141.22.21:45994] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:28.913160 2026] [autoindex:error] [pid 66623:tid 66780] [client 172.202.39.151:65245] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:28.932275 2026] [authz_core:error] [pid 67073:tid 67149] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:28.932536 2026] [authz_core:error] [pid 67073:tid 67149] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:28.949637 2026] [security2:error] [pid 67073:tid 67261] [client 20.226.6.191:6644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/chosen.php"] [unique_id "aoSANPcmepr5_nHgLbM4EAAAAkw"]
[Tue Aug 18 12:54:28.951288 2026] [security2:error] [pid 67073:tid 67284] [client 20.51.153.15:9120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ig.php"] [unique_id "aoSANPcmepr5_nHgLbM4EQAAAmM"]
[Tue Aug 18 12:54:28.959629 2026] [security2:error] [pid 66623:tid 66838] [client 52.139.47.57:19619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/ee.php"] [unique_id "aoSANNO5rbWdOArH04KATwAAAVI"]
[Tue Aug 18 12:54:29.011054 2026] [security2:error] [pid 67073:tid 67232] [client 20.171.51.14:45423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/mimes.php"] [unique_id "aoSANfcmepr5_nHgLbM4EgAAAi8"]
[Tue Aug 18 12:54:29.049798 2026] [security2:error] [pid 67073:tid 67315] [client 74.248.136.165:17334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/mans.php"] [unique_id "aoSANfcmepr5_nHgLbM4FAAAAoI"]
[Tue Aug 18 12:54:29.061946 2026] [security2:error] [pid 67073:tid 67303] [client 158.158.74.177:20510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/chosen.php"] [unique_id "aoSANfcmepr5_nHgLbM4FQAAAnY"]
[Tue Aug 18 12:54:29.090092 2026] [security2:error] [pid 67073:tid 67332] [client 74.248.133.44:23762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/02.php"] [unique_id "aoSANfcmepr5_nHgLbM4GAAAApM"]
[Tue Aug 18 12:54:29.094515 2026] [security2:error] [pid 66623:tid 66794] [client 135.225.75.187:9403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/kj.php"] [unique_id "aoSANdO5rbWdOArH04KAUQAAASY"]
[Tue Aug 18 12:54:29.103226 2026] [security2:error] [pid 67073:tid 67279] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSANfcmepr5_nHgLbM4GQAAAl4"]
[Tue Aug 18 12:54:29.113838 2026] [security2:error] [pid 66623:tid 66800] [client 20.163.43.14:3120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-good.php"] [unique_id "aoSANdO5rbWdOArH04KAUgAAASw"]
[Tue Aug 18 12:54:29.143315 2026] [security2:error] [pid 67073:tid 67222] [client 132.196.61.152:26844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/signon.php"] [unique_id "aoSANfcmepr5_nHgLbM4GwAAAiU"]
[Tue Aug 18 12:54:29.144586 2026] [security2:error] [pid 66623:tid 66845] [client 4.232.151.198:48186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/radio.php"] [unique_id "aoSANdO5rbWdOArH04KAUwAAAVk"]
[Tue Aug 18 12:54:29.165210 2026] [security2:error] [pid 66623:tid 66818] [client 20.104.100.201:21489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/memberfuns.php"] [unique_id "aoSANdO5rbWdOArH04KAVAAAAT4"]
[Tue Aug 18 12:54:29.174516 2026] [security2:error] [pid 67073:tid 67117] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/fun.php"] [unique_id "aoSANfcmepr5_nHgLbM4HAAChCk"]
[Tue Aug 18 12:54:29.187801 2026] [fcgid:warn] [pid 66623:tid 66880] (70014)End of file found: [client 199.45.155.71:43980] mod_fcgid: can't get data from http client
[Tue Aug 18 12:54:29.201855 2026] [security2:error] [pid 66623:tid 66812] [client 172.202.39.151:65245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSANdO5rbWdOArH04KAVgAAATg"]
[Tue Aug 18 12:54:29.203777 2026] [security2:error] [pid 67073:tid 67259] [client 104.209.144.33:19619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wsrer.php"] [unique_id "aoSANfcmepr5_nHgLbM4HgAAAko"]
[Tue Aug 18 12:54:29.206384 2026] [security2:error] [pid 66623:tid 66776] [client 114.119.136.12:52413] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.novapack.com.br"] [uri "/produto/np-70tb"] [unique_id "aoSANdO5rbWdOArH04KAVwAAARQ"], referer: https://www.novapack.com.br/produto/np-30t
[Tue Aug 18 12:54:29.209475 2026] [security2:error] [pid 67073:tid 67217] [client 20.100.169.31:39851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/archive.php"] [unique_id "aoSANfcmepr5_nHgLbM4HwAAAiA"]
[Tue Aug 18 12:54:29.210669 2026] [security2:error] [pid 67073:tid 67310] [client 20.104.85.180:8022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/info.php"] [unique_id "aoSANfcmepr5_nHgLbM4IAAAAn0"]
[Tue Aug 18 12:54:29.224229 2026] [security2:error] [pid 67073:tid 67244] [client 4.223.164.152:64695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSANfcmepr5_nHgLbM4IgAAAjs"]
[Tue Aug 18 12:54:29.230023 2026] [security2:error] [pid 67073:tid 67324] [client 20.51.153.15:9170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ta.php"] [unique_id "aoSANfcmepr5_nHgLbM4JAAAAos"]
[Tue Aug 18 12:54:29.232312 2026] [authz_core:error] [pid 67073:tid 67159] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:29.232638 2026] [authz_core:error] [pid 67073:tid 67159] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:29.239457 2026] [security2:error] [pid 67073:tid 67252] [client 5.31.227.224:30425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSANfcmepr5_nHgLbM4JQAAAkM"]
[Tue Aug 18 12:54:29.248325 2026] [security2:error] [pid 67073:tid 67274] [client 172.182.200.96:14239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSANfcmepr5_nHgLbM4JgAAAlk"]
[Tue Aug 18 12:54:29.250298 2026] [security2:error] [pid 67073:tid 67252] [client 5.31.227.224:30425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSANfcmepr5_nHgLbM4JQAAAkM"]
[Tue Aug 18 12:54:29.301590 2026] [security2:error] [pid 66623:tid 66836] [client 52.173.121.69:17971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/opsqt.php"] [unique_id "aoSANdO5rbWdOArH04KAWAAAAVA"]
[Tue Aug 18 12:54:29.375507 2026] [security2:error] [pid 66623:tid 66834] [client 20.116.17.175:57648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSANdO5rbWdOArH04KAWQAAAU4"]
[Tue Aug 18 12:54:29.383242 2026] [security2:error] [pid 67073:tid 67125] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/jq.php"] [unique_id "aoSANfcmepr5_nHgLbM4KQACLTE"]
[Tue Aug 18 12:54:29.385274 2026] [security2:error] [pid 66623:tid 66796] [client 103.184.169.37:41353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSANdO5rbWdOArH04KAWgAAASg"]
[Tue Aug 18 12:54:29.385568 2026] [security2:error] [pid 66623:tid 66796] [client 103.184.169.37:41353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSANdO5rbWdOArH04KAWgAAASg"]
[Tue Aug 18 12:54:29.419986 2026] [security2:error] [pid 67073:tid 67298] [client 20.171.51.14:43388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ni.php"] [unique_id "aoSANfcmepr5_nHgLbM4KwAAAnE"]
[Tue Aug 18 12:54:29.430450 2026] [security2:error] [pid 66623:tid 66853] [client 213.35.127.232:64108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSANdO5rbWdOArH04KAXAAAAWE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:29.433567 2026] [security2:error] [pid 66623:tid 66641] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/img/class-wp-http-client.php"] [unique_id "aoSANdO5rbWdOArH04KAXQABSQQ"]
[Tue Aug 18 12:54:29.439630 2026] [security2:error] [pid 67073:tid 67207] [client 20.104.100.201:58480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/aa.php"] [unique_id "aoSANfcmepr5_nHgLbM4LQAAAhY"]
[Tue Aug 18 12:54:29.452062 2026] [security2:error] [pid 66623:tid 66846] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/blog/byp.php"] [unique_id "aoSANdO5rbWdOArH04KAXgAAAVo"]
[Tue Aug 18 12:54:29.466809 2026] [security2:error] [pid 66623:tid 66830] [client 74.248.136.165:16966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/co.php"] [unique_id "aoSANdO5rbWdOArH04KAXwAAAUo"]
[Tue Aug 18 12:54:29.509508 2026] [security2:error] [pid 66623:tid 66849] [client 52.238.210.254:10214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/lite.php"] [unique_id "aoSANdO5rbWdOArH04KAYQAAAV0"]
[Tue Aug 18 12:54:29.511359 2026] [autoindex:error] [pid 66623:tid 66831] [client 20.104.85.180:8009] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:29.521348 2026] [security2:error] [pid 66623:tid 66823] [client 20.51.153.15:9208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/34.php"] [unique_id "aoSANdO5rbWdOArH04KAYgAAAUM"]
[Tue Aug 18 12:54:29.533230 2026] [authz_core:error] [pid 67073:tid 67076] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:29.533499 2026] [authz_core:error] [pid 67073:tid 67076] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:29.562474 2026] [security2:error] [pid 67073:tid 67094] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/sys.php"] [unique_id "aoSANfcmepr5_nHgLbM4MAACNRI"]
[Tue Aug 18 12:54:29.575490 2026] [security2:error] [pid 66623:tid 66773] [client 20.65.98.162:21535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/ano.php"] [unique_id "aoSANdO5rbWdOArH04KAZAAAARE"]
[Tue Aug 18 12:54:29.589857 2026] [security2:error] [pid 67073:tid 67272] [client 172.182.200.96:14289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSANfcmepr5_nHgLbM4MgAAAlc"]
[Tue Aug 18 12:54:29.636922 2026] [security2:error] [pid 66623:tid 66859] [client 52.173.121.69:53521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/mt/byp.php"] [unique_id "aoSANdO5rbWdOArH04KAZQAAAWc"]
[Tue Aug 18 12:54:29.655110 2026] [security2:error] [pid 67073:tid 67295] [client 52.173.121.69:24987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/jvcpa.php"] [unique_id "aoSANfcmepr5_nHgLbM4NAAAAm4"]
[Tue Aug 18 12:54:29.690951 2026] [security2:error] [pid 66623:tid 66804] [client 20.48.236.86:65112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/sf.php"] [unique_id "aoSANdO5rbWdOArH04KAZwAAATA"]
[Tue Aug 18 12:54:29.690979 2026] [security2:error] [pid 66623:tid 66839] [client 20.226.56.190:31035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ta.php"] [unique_id "aoSANdO5rbWdOArH04KAZgAAAVM"]
[Tue Aug 18 12:54:29.719016 2026] [security2:error] [pid 67073:tid 67320] [client 20.104.100.201:58438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/echkm.php"] [unique_id "aoSANfcmepr5_nHgLbM4OAAAAoc"]
[Tue Aug 18 12:54:29.738114 2026] [security2:error] [pid 67073:tid 67270] [client 20.118.172.148:8258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/db.php"] [unique_id "aoSANfcmepr5_nHgLbM4OQAAAlU"]
[Tue Aug 18 12:54:29.740966 2026] [security2:error] [pid 66623:tid 66828] [client 4.223.164.152:64691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/gec.php"] [unique_id "aoSANdO5rbWdOArH04KAaQAAAUg"]
[Tue Aug 18 12:54:29.743691 2026] [security2:error] [pid 67073:tid 67128] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/pp.php"] [unique_id "aoSANfcmepr5_nHgLbM4OgACSDQ"]
[Tue Aug 18 12:54:29.773923 2026] [security2:error] [pid 66623:tid 66775] [client 4.232.151.198:48157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/root.php"] [unique_id "aoSANdO5rbWdOArH04KAagAAARM"]
[Tue Aug 18 12:54:29.802851 2026] [security2:error] [pid 67073:tid 67321] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSANfcmepr5_nHgLbM4PAAAAog"]
[Tue Aug 18 12:54:29.834447 2026] [authz_core:error] [pid 67073:tid 67156] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:29.834755 2026] [authz_core:error] [pid 67073:tid 67156] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:29.853974 2026] [security2:error] [pid 67073:tid 67245] [client 20.226.6.191:6631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/info.php"] [unique_id "aoSANfcmepr5_nHgLbM4PgAAAjw"]
[Tue Aug 18 12:54:29.868052 2026] [security2:error] [pid 66623:tid 66862] [client 74.248.18.37:13038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/plugin.php"] [unique_id "aoSANdO5rbWdOArH04KAbAAAAWo"]
[Tue Aug 18 12:54:29.893370 2026] [security2:error] [pid 67073:tid 67326] [client 20.51.153.15:9200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/he.php"] [unique_id "aoSANfcmepr5_nHgLbM4QAAAAo0"]
[Tue Aug 18 12:54:29.900177 2026] [security2:error] [pid 67073:tid 67318] [client 20.226.56.190:47106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/34.php"] [unique_id "aoSANfcmepr5_nHgLbM4QQAAAoU"]
[Tue Aug 18 12:54:29.932864 2026] [security2:error] [pid 67073:tid 67218] [client 20.251.48.93:2128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/admin.php"] [unique_id "aoSANfcmepr5_nHgLbM4QgAAAiE"]
[Tue Aug 18 12:54:29.938125 2026] [security2:error] [pid 67073:tid 67296] [client 172.182.200.96:14278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSANfcmepr5_nHgLbM4QwAAAm8"]
[Tue Aug 18 12:54:29.967874 2026] [security2:error] [pid 67073:tid 67280] [client 20.171.51.14:15776] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "jcarvalhoimport.com.br"] [uri "/1.php"] [unique_id "aoSANfcmepr5_nHgLbM4RAAAAl8"]
[Tue Aug 18 12:54:29.967968 2026] [security2:error] [pid 67073:tid 67280] [client 20.171.51.14:15776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/1.php"] [unique_id "aoSANfcmepr5_nHgLbM4RAAAAl8"]
[Tue Aug 18 12:54:29.983886 2026] [security2:error] [pid 66623:tid 66814] [client 172.182.200.96:7625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSANdO5rbWdOArH04KAbQAAATo"]
[Tue Aug 18 12:54:29.987556 2026] [security2:error] [pid 67073:tid 67275] [client 132.196.61.152:56086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/file61.php"] [unique_id "aoSANfcmepr5_nHgLbM4RgAAAlo"]
[Tue Aug 18 12:54:29.989819 2026] [security2:error] [pid 66623:tid 66824] [client 158.158.74.177:15809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/u.php"] [unique_id "aoSANdO5rbWdOArH04KAbgAAAUQ"]
[Tue Aug 18 12:54:30.026326 2026] [security2:error] [pid 66623:tid 66811] [client 52.139.47.57:39251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/we.php"] [unique_id "aoSANtO5rbWdOArH04KAbwAAATc"]
[Tue Aug 18 12:54:30.050643 2026] [security2:error] [pid 67073:tid 67223] [client 20.100.169.31:12379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/bless.php"] [unique_id "aoSANvcmepr5_nHgLbM4SQAAAiY"]
[Tue Aug 18 12:54:30.167664 2026] [security2:error] [pid 67073:tid 67231] [client 172.202.39.151:44459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp.php"] [unique_id "aoSANvcmepr5_nHgLbM4TAAAAi4"]
[Tue Aug 18 12:54:30.174296 2026] [security2:error] [pid 66623:tid 66891] [client 20.104.85.180:8009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSANtO5rbWdOArH04KAcQAAAYc"]
[Tue Aug 18 12:54:30.179622 2026] [security2:error] [pid 67073:tid 67323] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSANvcmepr5_nHgLbM4TQAAAoo"]
[Tue Aug 18 12:54:30.250378 2026] [security2:error] [pid 66623:tid 66850] [client 20.163.43.14:3197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/tes.php"] [unique_id "aoSANtO5rbWdOArH04KAcgAAAV4"]
[Tue Aug 18 12:54:30.323302 2026] [security2:error] [pid 67073:tid 67289] [client 20.91.215.254:26426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSANvcmepr5_nHgLbM4UAAAAmg"]
[Tue Aug 18 12:54:30.328204 2026] [security2:error] [pid 66623:tid 66856] [client 172.182.200.96:14218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSANtO5rbWdOArH04KAcwAAAWQ"]
[Tue Aug 18 12:54:30.350303 2026] [security2:error] [pid 66623:tid 66656] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/in.php"] [unique_id "aoSANtO5rbWdOArH04KAdAABFRM"]
[Tue Aug 18 12:54:30.355498 2026] [security2:error] [pid 67073:tid 67214] [client 135.225.75.187:9351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/bes.php"] [unique_id "aoSANvcmepr5_nHgLbM4UQAAAh0"]
[Tue Aug 18 12:54:30.358278 2026] [security2:error] [pid 67073:tid 67234] [client 52.238.210.254:8898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/lock360.php"] [unique_id "aoSANvcmepr5_nHgLbM4UgAAAjE"]
[Tue Aug 18 12:54:30.425061 2026] [authz_core:error] [pid 67073:tid 67093] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:30.425316 2026] [authz_core:error] [pid 67073:tid 67093] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:30.491689 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:30.492001 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:30.537382 2026] [security2:error] [pid 67073:tid 67208] [client 20.104.85.180:8059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSANvcmepr5_nHgLbM4VwAAAhc"]
[Tue Aug 18 12:54:30.561284 2026] [security2:error] [pid 66623:tid 66767] [client 104.209.144.33:25322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/blog/byp.php"] [unique_id "aoSANtO5rbWdOArH04KAdgAAAQs"]
[Tue Aug 18 12:54:30.603708 2026] [security2:error] [pid 67073:tid 67284] [client 20.171.51.14:58396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/88.php"] [unique_id "aoSANvcmepr5_nHgLbM4WQAAAmM"]
[Tue Aug 18 12:54:30.623318 2026] [security2:error] [pid 67073:tid 67293] [client 68.155.154.236:63873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSANvcmepr5_nHgLbM4WgAAAmw"]
[Tue Aug 18 12:54:30.633525 2026] [security2:error] [pid 67073:tid 67161] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wqqs.php"] [unique_id "aoSANvcmepr5_nHgLbM4WwACL1U"]
[Tue Aug 18 12:54:30.677413 2026] [security2:error] [pid 67073:tid 67253] [client 132.196.61.152:55327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/copypaths.php"] [unique_id "aoSANvcmepr5_nHgLbM4XAAAAkQ"]
[Tue Aug 18 12:54:30.712427 2026] [security2:error] [pid 67073:tid 67248] [client 172.182.200.96:14248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSANvcmepr5_nHgLbM4XQAAAj8"]
[Tue Aug 18 12:54:30.713599 2026] [security2:error] [pid 66623:tid 66802] [client 20.226.6.191:6632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSANtO5rbWdOArH04KAdwAAAS4"]
[Tue Aug 18 12:54:30.718242 2026] [security2:error] [pid 66623:tid 66885] [client 4.223.164.152:64647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/sky.php"] [unique_id "aoSANtO5rbWdOArH04KAeAAAAYE"]
[Tue Aug 18 12:54:30.736412 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:30.736663 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:30.790148 2026] [security2:error] [pid 66623:tid 66797] [client 172.202.39.151:61319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSANtO5rbWdOArH04KAeQAAASk"]
[Tue Aug 18 12:54:30.798858 2026] [autoindex:error] [pid 66623:tid 66844] [client 147.185.132.60:59878] AH01276: Cannot serve directory /home1/deliciacom/public_html/: No matching DirectoryIndex (public/index.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:30.828656 2026] [security2:error] [pid 67073:tid 67171] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/clasa99.php"] [unique_id "aoSANvcmepr5_nHgLbM4YQACLF8"]
[Tue Aug 18 12:54:30.853153 2026] [security2:error] [pid 67073:tid 67332] [client 20.116.17.175:57427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/cok.php"] [unique_id "aoSANvcmepr5_nHgLbM4YgAAApM"]
[Tue Aug 18 12:54:31.042270 2026] [security2:error] [pid 67073:tid 67160] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/666.php"] [unique_id "aoSAN_cmepr5_nHgLbM4ZgACeFQ"]
[Tue Aug 18 12:54:31.052203 2026] [security2:error] [pid 67073:tid 67273] [client 20.104.100.201:58482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/domvf.php"] [unique_id "aoSAN_cmepr5_nHgLbM4ZwAAAlg"]
[Tue Aug 18 12:54:31.100929 2026] [security2:error] [pid 67073:tid 67290] [client 74.248.133.44:63237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/menu.php"] [unique_id "aoSAN_cmepr5_nHgLbM4aQAAAmk"]
[Tue Aug 18 12:54:31.110579 2026] [security2:error] [pid 67073:tid 67249] [client 74.248.136.165:65312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/btx25.php"] [unique_id "aoSAN_cmepr5_nHgLbM4agAAAkA"]
[Tue Aug 18 12:54:31.118947 2026] [security2:error] [pid 66623:tid 66837] [client 172.182.200.96:14287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSAN9O5rbWdOArH04KAfgAAAVE"]
[Tue Aug 18 12:54:31.121730 2026] [security2:error] [pid 67073:tid 67311] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/images/security.php"] [unique_id "aoSAN_cmepr5_nHgLbM4awAAAn4"]
[Tue Aug 18 12:54:31.184902 2026] [security2:error] [pid 67073:tid 67316] [client 132.196.61.152:26820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/bless6.php"] [unique_id "aoSAN_cmepr5_nHgLbM4bgAAAoM"]
[Tue Aug 18 12:54:31.234422 2026] [autoindex:error] [pid 67073:tid 67274] [client 52.73.140.57:52382] AH01276: Cannot serve directory /home3/aceunai/public_html/abraceocomerciodeunai.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:31.352253 2026] [security2:error] [pid 66623:tid 66736] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/inc.php"] [unique_id "aoSAN9O5rbWdOArH04KAfwABF2M"]
[Tue Aug 18 12:54:31.352867 2026] [security2:error] [pid 67073:tid 67209] [client 40.85.222.29:2250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSAN_cmepr5_nHgLbM4cgAAAhg"]
[Tue Aug 18 12:54:31.375304 2026] [security2:error] [pid 67073:tid 67300] [client 20.104.100.201:58880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/red.php"] [unique_id "aoSAN_cmepr5_nHgLbM4dAAAAnM"]
[Tue Aug 18 12:54:31.547595 2026] [security2:error] [pid 67073:tid 67241] [client 172.202.39.151:29701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/an.php"] [unique_id "aoSAN_cmepr5_nHgLbM4dwAAAjg"]
[Tue Aug 18 12:54:31.576876 2026] [security2:error] [pid 66623:tid 66838] [client 172.182.200.96:14220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSAN9O5rbWdOArH04KAggAAAVI"]
[Tue Aug 18 12:54:31.631366 2026] [security2:error] [pid 66623:tid 66875] [client 172.202.39.151:50219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/gelay.php"] [unique_id "aoSAN9O5rbWdOArH04KAhAAAAXc"]
[Tue Aug 18 12:54:31.657231 2026] [security2:error] [pid 67073:tid 67092] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/thui.php"] [unique_id "aoSAN_cmepr5_nHgLbM4eQACcBA"]
[Tue Aug 18 12:54:31.672883 2026] [security2:error] [pid 66623:tid 66668] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/index.php"] [unique_id "aoSAN9O5rbWdOArH04KAhQABGh8"]
[Tue Aug 18 12:54:31.765302 2026] [security2:error] [pid 67073:tid 67236] [client 74.248.136.165:53569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/xda.php"] [unique_id "aoSAN_cmepr5_nHgLbM4ewAAAjM"]
[Tue Aug 18 12:54:31.769873 2026] [security2:error] [pid 67073:tid 67222] [client 157.20.138.62:54266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAN_cmepr5_nHgLbM4fAAAAiU"]
[Tue Aug 18 12:54:31.769963 2026] [security2:error] [pid 67073:tid 67222] [client 157.20.138.62:54266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAN_cmepr5_nHgLbM4fAAAAiU"]
[Tue Aug 18 12:54:31.830136 2026] [security2:error] [pid 66623:tid 66842] [client 74.248.18.37:29196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAN9O5rbWdOArH04KAhgAAAVY"]
[Tue Aug 18 12:54:31.844043 2026] [security2:error] [pid 66623:tid 66794] [client 20.51.153.15:9091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/gz.php"] [unique_id "aoSAN9O5rbWdOArH04KAhwAAASY"]
[Tue Aug 18 12:54:31.850239 2026] [security2:error] [pid 67073:tid 67272] [client 104.209.144.33:21413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/ucpfr.php"] [unique_id "aoSAN_cmepr5_nHgLbM4fQAAAlc"]
[Tue Aug 18 12:54:31.913109 2026] [security2:error] [pid 66623:tid 66868] [client 4.232.151.198:6467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/server.php"] [unique_id "aoSAN9O5rbWdOArH04KAiAAAAXA"]
[Tue Aug 18 12:54:31.925556 2026] [security2:error] [pid 67073:tid 67264] [client 20.104.85.180:8012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/k.php"] [unique_id "aoSAN_cmepr5_nHgLbM4fgAAAk8"]
[Tue Aug 18 12:54:31.931036 2026] [security2:error] [pid 66623:tid 66822] [client 20.116.17.175:57623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/accesson.php"] [unique_id "aoSAN9O5rbWdOArH04KAiQAAAUI"]
[Tue Aug 18 12:54:31.942733 2026] [security2:error] [pid 67073:tid 67268] [client 172.202.39.151:44417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/function/function.php"] [unique_id "aoSAN_cmepr5_nHgLbM4fwAAAlM"]
[Tue Aug 18 12:54:31.983639 2026] [security2:error] [pid 66623:tid 66890] [client 132.196.61.152:56109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/special.php"] [unique_id "aoSAN9O5rbWdOArH04KAjAAAAYY"]
[Tue Aug 18 12:54:31.984241 2026] [autoindex:error] [pid 66623:tid 66863] [client 158.158.74.177:20492] AH01276: Cannot serve directory /home3/evandrobene/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:31.993390 2026] [security2:error] [pid 66623:tid 66799] [client 172.182.200.96:14238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSAN9O5rbWdOArH04KAjQAAASs"]
[Tue Aug 18 12:54:32.008983 2026] [security2:error] [pid 67073:tid 67295] [client 172.182.200.96:14159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSAOPcmepr5_nHgLbM4gAAAAm4"]
[Tue Aug 18 12:54:32.107649 2026] [security2:error] [pid 66623:tid 66818] [client 52.238.210.254:10116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSAONO5rbWdOArH04KAjgAAAT4"]
[Tue Aug 18 12:54:32.145739 2026] [security2:error] [pid 67073:tid 67301] [client 52.173.121.69:48403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSAOPcmepr5_nHgLbM4gQAAAnQ"]
[Tue Aug 18 12:54:32.170471 2026] [security2:error] [pid 67073:tid 67210] [client 20.104.100.201:58938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/JawirGenk.php"] [unique_id "aoSAOPcmepr5_nHgLbM4ggAAAhk"]
[Tue Aug 18 12:54:32.219246 2026] [security2:error] [pid 66623:tid 66812] [client 158.158.74.177:20492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/customize.php"] [unique_id "aoSAONO5rbWdOArH04KAjwAAATg"]
[Tue Aug 18 12:54:32.225132 2026] [security2:error] [pid 66623:tid 66776] [client 20.171.51.14:28803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/hj.php"] [unique_id "aoSAONO5rbWdOArH04KAkAAAARQ"]
[Tue Aug 18 12:54:32.233674 2026] [security2:error] [pid 67073:tid 67245] [client 20.226.6.191:6555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSAOPcmepr5_nHgLbM4gwAAAjw"]
[Tue Aug 18 12:54:32.237012 2026] [security2:error] [pid 67073:tid 67302] [client 20.226.56.190:45039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/he.php"] [unique_id "aoSAOPcmepr5_nHgLbM4hAAAAnU"]
[Tue Aug 18 12:54:32.245641 2026] [authz_core:error] [pid 67073:tid 67096] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:32.245897 2026] [authz_core:error] [pid 67073:tid 67096] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:32.247284 2026] [security2:error] [pid 67073:tid 67112] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/agg.php"] [unique_id "aoSAOPcmepr5_nHgLbM4hgACjSQ"]
[Tue Aug 18 12:54:32.251317 2026] [security2:error] [pid 66623:tid 66816] [client 213.35.127.232:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAONO5rbWdOArH04KAkQAAATw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:32.264547 2026] [security2:error] [pid 67073:tid 67206] [client 138.36.100.162:41464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAOPcmepr5_nHgLbM4hwAAAhU"]
[Tue Aug 18 12:54:32.264644 2026] [security2:error] [pid 67073:tid 67206] [client 138.36.100.162:41464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAOPcmepr5_nHgLbM4hwAAAhU"]
[Tue Aug 18 12:54:32.412349 2026] [autoindex:error] [pid 67073:tid 67275] [client 199.45.155.71:43984] AH01276: Cannot serve directory /home4/filial35/public_html/kazanovapapeldeparede/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:32.451493 2026] [security2:error] [pid 67073:tid 67266] [client 172.182.200.96:14286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSAOPcmepr5_nHgLbM4iQAAAlE"]
[Tue Aug 18 12:54:32.484659 2026] [security2:error] [pid 66623:tid 66836] [client 20.65.98.162:23869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/ai.php"] [unique_id "aoSAONO5rbWdOArH04KAkwAAAVA"]
[Tue Aug 18 12:54:32.520801 2026] [security2:error] [pid 67073:tid 67205] [client 52.139.47.57:13533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/to.php"] [unique_id "aoSAOPcmepr5_nHgLbM4iwAAAhQ"]
[Tue Aug 18 12:54:32.533992 2026] [security2:error] [pid 67073:tid 67235] [client 74.248.18.37:12315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/public/moon.php"] [unique_id "aoSAOPcmepr5_nHgLbM4jAAAAjI"]
[Tue Aug 18 12:54:32.552924 2026] [authz_core:error] [pid 67073:tid 67105] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:32.553177 2026] [authz_core:error] [pid 67073:tid 67105] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:32.622011 2026] [security2:error] [pid 67073:tid 67260] [client 4.232.151.198:6491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSAOPcmepr5_nHgLbM4jgAAAks"]
[Tue Aug 18 12:54:32.649108 2026] [security2:error] [pid 67073:tid 67291] [client 20.51.153.15:9147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/nf.php"] [unique_id "aoSAOPcmepr5_nHgLbM4jwAAAmo"]
[Tue Aug 18 12:54:32.705797 2026] [security2:error] [pid 67073:tid 67277] [client 68.155.154.236:63381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSAOPcmepr5_nHgLbM4kQAAAlw"]
[Tue Aug 18 12:54:32.731142 2026] [security2:error] [pid 66623:tid 66662] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/index/function.php"] [unique_id "aoSAONO5rbWdOArH04KAlAABSRk"]
[Tue Aug 18 12:54:32.761559 2026] [security2:error] [pid 67073:tid 67289] [client 20.171.51.14:16748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ij.php"] [unique_id "aoSAOPcmepr5_nHgLbM4lAAAAmg"]
[Tue Aug 18 12:54:32.768902 2026] [security2:error] [pid 67073:tid 67283] [client 20.116.17.175:57611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/av.php"] [unique_id "aoSAOPcmepr5_nHgLbM4lQAAAmI"]
[Tue Aug 18 12:54:32.786155 2026] [security2:error] [pid 67073:tid 67214] [client 20.65.98.162:58110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAOPcmepr5_nHgLbM4lgAAAh0"]
[Tue Aug 18 12:54:32.845278 2026] [authz_core:error] [pid 67073:tid 67084] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:32.845545 2026] [authz_core:error] [pid 67073:tid 67084] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:32.847089 2026] [security2:error] [pid 67073:tid 67261] [client 20.226.56.190:2554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gz.php"] [unique_id "aoSAOPcmepr5_nHgLbM4mQAAAkw"]
[Tue Aug 18 12:54:32.955406 2026] [security2:error] [pid 66623:tid 66770] [client 172.202.39.151:30472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/cah.php"] [unique_id "aoSAONO5rbWdOArH04KAlgAAAQ4"]
[Tue Aug 18 12:54:32.964963 2026] [security2:error] [pid 66623:tid 66849] [client 20.104.100.201:58919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/options.php"] [unique_id "aoSAONO5rbWdOArH04KAlwAAAV0"]
[Tue Aug 18 12:54:33.009812 2026] [security2:error] [pid 66623:tid 66880] [client 20.250.13.23:37941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/96i.php"] [unique_id "aoSAOdO5rbWdOArH04KAmAAAAXw"]
[Tue Aug 18 12:54:33.035785 2026] [security2:error] [pid 67073:tid 67279] [client 20.163.43.14:1993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/files/index.php"] [unique_id "aoSAOfcmepr5_nHgLbM4nAAAAl4"]
[Tue Aug 18 12:54:33.054946 2026] [security2:error] [pid 66623:tid 66653] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/index4.php"] [unique_id "aoSAOdO5rbWdOArH04KAmQABQxA"]
[Tue Aug 18 12:54:33.058818 2026] [security2:error] [pid 67073:tid 67135] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/erty.php"] [unique_id "aoSAOfcmepr5_nHgLbM4ngACfzs"]
[Tue Aug 18 12:54:33.061172 2026] [authz_core:error] [pid 67073:tid 67182] [remote 57.141.22.35:45836] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:33.061436 2026] [authz_core:error] [pid 67073:tid 67182] [remote 57.141.22.35:45836] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:33.082423 2026] [security2:error] [pid 67073:tid 67269] [client 20.251.48.93:58893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/mac.php"] [unique_id "aoSAOfcmepr5_nHgLbM4oAAAAlQ"]
[Tue Aug 18 12:54:33.157877 2026] [security2:error] [pid 67073:tid 67290] [client 104.209.144.33:17257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/yxijx.php"] [unique_id "aoSAOfcmepr5_nHgLbM4oQAAAmk"]
[Tue Aug 18 12:54:33.282059 2026] [security2:error] [pid 67073:tid 67119] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/mini.php"] [unique_id "aoSAOfcmepr5_nHgLbM4qQACOys"]
[Tue Aug 18 12:54:33.293216 2026] [autoindex:error] [pid 67073:tid 67310] [client 20.104.85.180:7966] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:33.342818 2026] [autoindex:error] [pid 66623:tid 66859] [client 194.36.25.35:56723] AH01276: Cannot serve directory /home1/hawaiedu/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:33.368846 2026] [security2:error] [pid 66623:tid 66658] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/info.php"] [unique_id "aoSAOdO5rbWdOArH04KAnAABgxU"]
[Tue Aug 18 12:54:33.372118 2026] [security2:error] [pid 66623:tid 66804] [client 52.173.121.69:16479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSAOdO5rbWdOArH04KAnQAAATA"]
[Tue Aug 18 12:54:33.378741 2026] [security2:error] [pid 67073:tid 67233] [client 20.51.153.15:8785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/xv.php"] [unique_id "aoSAOfcmepr5_nHgLbM4rQAAAjA"]
[Tue Aug 18 12:54:33.532327 2026] [security2:error] [pid 67073:tid 67138] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/sid3.php"] [unique_id "aoSAOfcmepr5_nHgLbM4sAACZD4"]
[Tue Aug 18 12:54:33.595639 2026] [security2:error] [pid 67073:tid 67258] [client 20.104.85.180:7966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/403.php"] [unique_id "aoSAOfcmepr5_nHgLbM4swAAAkk"]
[Tue Aug 18 12:54:33.691355 2026] [security2:error] [pid 66623:tid 66704] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/init.php"] [unique_id "aoSAOdO5rbWdOArH04KAoAABHUM"]
[Tue Aug 18 12:54:33.701699 2026] [security2:error] [pid 66623:tid 66775] [client 132.196.61.152:26825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/fz.php"] [unique_id "aoSAOdO5rbWdOArH04KAoQAAARM"]
[Tue Aug 18 12:54:33.753165 2026] [authz_core:error] [pid 67073:tid 67081] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:33.753641 2026] [authz_core:error] [pid 67073:tid 67081] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:33.859492 2026] [security2:error] [pid 66623:tid 66793] [client 52.238.210.254:8903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-links-opml.php"] [unique_id "aoSAOdO5rbWdOArH04KAogAAASU"]
[Tue Aug 18 12:54:33.866318 2026] [security2:error] [pid 66623:tid 66772] [client 20.171.51.14:29190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ud.php"] [unique_id "aoSAOdO5rbWdOArH04KAowAAARA"]
[Tue Aug 18 12:54:33.902486 2026] [security2:error] [pid 67073:tid 67238] [client 172.182.200.96:14335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSAOfcmepr5_nHgLbM4uAAAAjU"]
[Tue Aug 18 12:54:33.932608 2026] [security2:error] [pid 66623:tid 66811] [client 172.202.39.151:50233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAOdO5rbWdOArH04KApgAAATc"]
[Tue Aug 18 12:54:33.969955 2026] [autoindex:error] [pid 67073:tid 67268] [client 20.104.85.180:7993] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:33.981857 2026] [security2:error] [pid 67073:tid 67295] [client 20.163.43.14:3100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAOfcmepr5_nHgLbM4uwAAAm4"]
[Tue Aug 18 12:54:33.986030 2026] [security2:error] [pid 67073:tid 67220] [client 74.248.133.44:48297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/spip.php"] [unique_id "aoSAOfcmepr5_nHgLbM4vAAAAiM"]
[Tue Aug 18 12:54:33.992309 2026] [security2:error] [pid 67073:tid 67278] [client 78.47.173.76:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.doroincorporacoes.com.br"] [uri "/index.php"] [unique_id "aoSAOfcmepr5_nHgLbM4mwACXRs"], referer: https://www.doroincorporacoes.com.br/
[Tue Aug 18 12:54:34.046426 2026] [security2:error] [pid 67073:tid 67267] [client 20.51.153.15:8831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/mx.php"] [unique_id "aoSAOvcmepr5_nHgLbM4vgAAAlI"]
[Tue Aug 18 12:54:34.049743 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:34.050008 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:34.066657 2026] [security2:error] [pid 67073:tid 67307] [client 20.250.13.23:13685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/as.php"] [unique_id "aoSAOvcmepr5_nHgLbM4vwAAAno"]
[Tue Aug 18 12:54:34.077053 2026] [security2:error] [pid 67073:tid 67097] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/moon.php"] [unique_id "aoSAOvcmepr5_nHgLbM4wAACSBU"]
[Tue Aug 18 12:54:34.122838 2026] [security2:error] [pid 66623:tid 66824] [client 5.253.205.188:40734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/fullwebsite.sql"] [unique_id "aoSAOtO5rbWdOArH04KAqAAAAUQ"], referer: https://medihub.com.br/fullwebsite.sql
[Tue Aug 18 12:54:34.195127 2026] [security2:error] [pid 66623:tid 66810] [client 20.226.56.190:30984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/nf.php"] [unique_id "aoSAOtO5rbWdOArH04KAqQAAATY"]
[Tue Aug 18 12:54:34.223861 2026] [security2:error] [pid 66623:tid 66877] [client 52.139.47.57:19624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/ty.php"] [unique_id "aoSAOtO5rbWdOArH04KAqgAAAXk"]
[Tue Aug 18 12:54:34.228416 2026] [security2:error] [pid 66623:tid 66856] [client 4.223.164.152:64670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/sixxis.php"] [unique_id "aoSAOtO5rbWdOArH04KAqwAAAWQ"]
[Tue Aug 18 12:54:34.297164 2026] [security2:error] [pid 67073:tid 67174] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ms.php"] [unique_id "aoSAOvcmepr5_nHgLbM4wgACdWI"]
[Tue Aug 18 12:54:34.316916 2026] [security2:error] [pid 67073:tid 67202] [remote 203.99.146.53:38680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "macambio.com"] [uri "/wp-login.php"] [unique_id "aoSAOvcmepr5_nHgLbM4wwACVn4"]
[Tue Aug 18 12:54:34.329003 2026] [security2:error] [pid 66623:tid 66860] [client 213.35.127.232:64892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAOtO5rbWdOArH04KArQAAAWg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:34.340471 2026] [autoindex:error] [pid 67073:tid 67318] [client 20.104.85.180:7993] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:34.340905 2026] [security2:error] [pid 67073:tid 67227] [client 20.51.153.15:9155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/45.php"] [unique_id "aoSAOvcmepr5_nHgLbM4xQAAAio"]
[Tue Aug 18 12:54:34.351306 2026] [authz_core:error] [pid 67073:tid 67115] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:34.351568 2026] [authz_core:error] [pid 67073:tid 67115] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:34.384343 2026] [security2:error] [pid 66623:tid 66847] [client 20.100.169.31:25398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/sagax1.php"] [unique_id "aoSAOtO5rbWdOArH04KArgAAAVs"]
[Tue Aug 18 12:54:34.432563 2026] [security2:error] [pid 67073:tid 67280] [client 135.225.75.187:56882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ws60.php"] [unique_id "aoSAOvcmepr5_nHgLbM4zAAAAl8"]
[Tue Aug 18 12:54:34.444145 2026] [security2:error] [pid 67073:tid 67275] [client 20.118.172.148:7937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/dropdown.php"] [unique_id "aoSAOvcmepr5_nHgLbM4zQAAAlo"]
[Tue Aug 18 12:54:34.492930 2026] [security2:error] [pid 67073:tid 67167] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wsws.php"] [unique_id "aoSAOvcmepr5_nHgLbM4zgACPls"]
[Tue Aug 18 12:54:34.500511 2026] [security2:error] [pid 67073:tid 67205] [client 20.163.43.14:2022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAOvcmepr5_nHgLbM4zwAAAhQ"]
[Tue Aug 18 12:54:34.515810 2026] [security2:error] [pid 67073:tid 67235] [client 20.104.85.180:7993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/gecko.php"] [unique_id "aoSAOvcmepr5_nHgLbM40AAAAjI"]
[Tue Aug 18 12:54:34.545758 2026] [autoindex:error] [pid 67073:tid 67260] [client 172.202.39.151:42789] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/js/tinymce/plugins/compat3x/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:34.600799 2026] [security2:error] [pid 66623:tid 66660] [remote 46.62.208.238:48548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.208.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/wp-login.php"] [unique_id "aoSAOtO5rbWdOArH04KAsgABPRc"]
[Tue Aug 18 12:54:34.602951 2026] [security2:error] [pid 67073:tid 67251] [client 52.173.121.69:24986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSAOvcmepr5_nHgLbM40wAAAkI"]
[Tue Aug 18 12:54:34.685519 2026] [authz_core:error] [pid 67073:tid 67118] [remote 57.141.22.48:29922] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:34.685782 2026] [authz_core:error] [pid 67073:tid 67118] [remote 57.141.22.48:29922] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:34.688284 2026] [security2:error] [pid 66623:tid 66885] [client 20.226.56.190:3013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/xv.php"] [unique_id "aoSAOtO5rbWdOArH04KAuAAAAYE"]
[Tue Aug 18 12:54:34.688400 2026] [autoindex:error] [pid 66623:tid 66802] [client 194.36.25.35:56723] AH01276: Cannot serve directory /home1/hawaiedu/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:34.730062 2026] [security2:error] [pid 66623:tid 66789] [client 74.248.18.37:12301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/public/storage.php"] [unique_id "aoSAOtO5rbWdOArH04KAugAAASE"]
[Tue Aug 18 12:54:34.835200 2026] [security2:error] [pid 67073:tid 67261] [client 4.223.164.152:28480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/yj09.php"] [unique_id "aoSAOvcmepr5_nHgLbM42QAAAkw"]
[Tue Aug 18 12:54:34.976945 2026] [security2:error] [pid 67073:tid 67289] [client 4.232.151.198:6489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/shell.php"] [unique_id "aoSAOvcmepr5_nHgLbM43AAAAmg"]
[Tue Aug 18 12:54:35.149449 2026] [security2:error] [pid 67073:tid 67269] [client 20.65.98.162:46566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAO_cmepr5_nHgLbM43gAAAlQ"]
[Tue Aug 18 12:54:35.161344 2026] [security2:error] [pid 67073:tid 67203] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/motu.php"] [unique_id "aoSAO_cmepr5_nHgLbM43wAChH8"]
[Tue Aug 18 12:54:35.196606 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.56.190:2510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/mx.php"] [unique_id "aoSAO_cmepr5_nHgLbM44AAAAlg"]
[Tue Aug 18 12:54:35.198614 2026] [security2:error] [pid 66623:tid 66773] [client 160.120.140.123:55637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAO9O5rbWdOArH04KAwAAAARE"]
[Tue Aug 18 12:54:35.198731 2026] [security2:error] [pid 66623:tid 66773] [client 160.120.140.123:55637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAO9O5rbWdOArH04KAwAAAARE"]
[Tue Aug 18 12:54:35.205105 2026] [security2:error] [pid 67073:tid 67249] [client 20.226.6.191:6619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/k.php"] [unique_id "aoSAO_cmepr5_nHgLbM44gAAAkA"]
[Tue Aug 18 12:54:35.206176 2026] [security2:error] [pid 66623:tid 66837] [client 20.171.51.14:50576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/xg.php"] [unique_id "aoSAO9O5rbWdOArH04KAwQAAAVE"]
[Tue Aug 18 12:54:35.268914 2026] [authz_core:error] [pid 67073:tid 67091] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:35.269181 2026] [authz_core:error] [pid 67073:tid 67091] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:35.279026 2026] [security2:error] [pid 67073:tid 67284] [client 172.202.39.151:44464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSAO_cmepr5_nHgLbM45QAAAmM"]
[Tue Aug 18 12:54:35.285196 2026] [security2:error] [pid 67073:tid 67277] [client 52.139.47.57:19626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/ak.php"] [unique_id "aoSAO_cmepr5_nHgLbM45wAAAlw"]
[Tue Aug 18 12:54:35.331497 2026] [security2:error] [pid 66623:tid 66825] [client 20.100.169.31:24506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wpc.php"] [unique_id "aoSAO9O5rbWdOArH04KAxAAAAUU"]
[Tue Aug 18 12:54:35.352929 2026] [autoindex:error] [pid 67073:tid 67233] [client 20.104.85.180:7234] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:35.379442 2026] [security2:error] [pid 67073:tid 67120] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/fff.php"] [unique_id "aoSAO_cmepr5_nHgLbM46gACjCw"]
[Tue Aug 18 12:54:35.416281 2026] [security2:error] [pid 67073:tid 67255] [client 20.163.43.14:3149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAO_cmepr5_nHgLbM46wAAAkY"]
[Tue Aug 18 12:54:35.459481 2026] [security2:error] [pid 67073:tid 67252] [client 74.248.18.37:12388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/radio.php"] [unique_id "aoSAO_cmepr5_nHgLbM47QAAAkM"]
[Tue Aug 18 12:54:35.460181 2026] [security2:error] [pid 67073:tid 67217] [client 20.151.109.219:12884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAO_cmepr5_nHgLbM47gAAAiA"]
[Tue Aug 18 12:54:35.559764 2026] [authz_core:error] [pid 67073:tid 67099] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:35.560179 2026] [authz_core:error] [pid 67073:tid 67099] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:35.600746 2026] [security2:error] [pid 67073:tid 67095] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/66.php"] [unique_id "aoSAO_cmepr5_nHgLbM48wACdxM"]
[Tue Aug 18 12:54:35.603164 2026] [security2:error] [pid 67073:tid 67223] [client 68.155.155.199:10459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAOvcmepr5_nHgLbM40gAAAiY"]
[Tue Aug 18 12:54:35.634838 2026] [security2:error] [pid 67073:tid 67207] [client 172.182.200.96:14249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSAO_cmepr5_nHgLbM49gAAAhY"]
[Tue Aug 18 12:54:35.680812 2026] [security2:error] [pid 67073:tid 67237] [client 4.232.151.198:48140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/sim.php"] [unique_id "aoSAO_cmepr5_nHgLbM49wAAAjQ"]
[Tue Aug 18 12:54:35.737144 2026] [security2:error] [pid 66623:tid 66803] [client 20.118.172.148:47235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/file.php"] [unique_id "aoSAO9O5rbWdOArH04KAyAAAAS8"]
[Tue Aug 18 12:54:35.797846 2026] [security2:error] [pid 67073:tid 67238] [client 20.151.109.219:53222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAO_cmepr5_nHgLbM4-gAAAjU"]
[Tue Aug 18 12:54:35.804136 2026] [security2:error] [pid 66623:tid 66794] [client 20.163.43.14:3150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/rip.php"] [unique_id "aoSAO9O5rbWdOArH04KAyQAAASY"]
[Tue Aug 18 12:54:35.813413 2026] [security2:error] [pid 67073:tid 67121] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/g.php"] [unique_id "aoSAO_cmepr5_nHgLbM4-wACVy0"]
[Tue Aug 18 12:54:35.865969 2026] [security2:error] [pid 66623:tid 66868] [client 20.251.48.93:35083] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.activevalue.com.br"] [uri "/1.php"] [unique_id "aoSAO9O5rbWdOArH04KAygAAAXA"]
[Tue Aug 18 12:54:35.866058 2026] [security2:error] [pid 66623:tid 66868] [client 20.251.48.93:35083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/1.php"] [unique_id "aoSAO9O5rbWdOArH04KAygAAAXA"]
[Tue Aug 18 12:54:35.892847 2026] [security2:error] [pid 67073:tid 67278] [client 52.238.210.254:10138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/.alf.php"] [unique_id "aoSAO_cmepr5_nHgLbM5JAAAAl0"]
[Tue Aug 18 12:54:35.942989 2026] [security2:error] [pid 67073:tid 67301] [client 20.51.153.15:9189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/wy.php"] [unique_id "aoSAO_cmepr5_nHgLbM5JQAAAnQ"]
[Tue Aug 18 12:54:35.956878 2026] [security2:error] [pid 67073:tid 67210] [client 172.202.39.151:36880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/404.php"] [unique_id "aoSAO_cmepr5_nHgLbM5JgAAAhk"]
[Tue Aug 18 12:54:36.050127 2026] [security2:error] [pid 67073:tid 67321] [client 20.171.51.14:43362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ip.php"] [unique_id "aoSAPPcmepr5_nHgLbM5KAAAAog"]
[Tue Aug 18 12:54:36.185546 2026] [security2:error] [pid 67073:tid 67227] [client 20.226.56.190:3039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/45.php"] [unique_id "aoSAPPcmepr5_nHgLbM5KgAAAio"]
[Tue Aug 18 12:54:36.264901 2026] [security2:error] [pid 67073:tid 67218] [client 20.51.153.15:9106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/f.php"] [unique_id "aoSAPPcmepr5_nHgLbM5KwAAAiE"]
[Tue Aug 18 12:54:36.268207 2026] [security2:error] [pid 67073:tid 67296] [client 172.202.39.151:55425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAPPcmepr5_nHgLbM5LAAAAm8"]
[Tue Aug 18 12:54:36.310050 2026] [security2:error] [pid 66623:tid 66705] [remote 162.241.153.188:49040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.153.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melocorretordeimoveis.com.br"] [uri "/wp-login.php"] [unique_id "aoSAO9O5rbWdOArH04KAwwABiUQ"]
[Tue Aug 18 12:54:36.311319 2026] [security2:error] [pid 67073:tid 67266] [client 4.223.164.152:64680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/k.php"] [unique_id "aoSAPPcmepr5_nHgLbM5LQAAAlE"]
[Tue Aug 18 12:54:36.320838 2026] [security2:error] [pid 67073:tid 67235] [client 20.104.100.201:58452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSAPPcmepr5_nHgLbM5LgAAAjI"]
[Tue Aug 18 12:54:36.369481 2026] [security2:error] [pid 67073:tid 67291] [client 52.238.210.254:10143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/.trash7206/index.php"] [unique_id "aoSAPPcmepr5_nHgLbM5MAAAAmo"]
[Tue Aug 18 12:54:36.490321 2026] [security2:error] [pid 67073:tid 67276] [client 213.202.253.4:56320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/filefuns.php"] [unique_id "aoSAPPcmepr5_nHgLbM5MgAAAls"], referer: www.google.com
[Tue Aug 18 12:54:36.556370 2026] [security2:error] [pid 67073:tid 67215] [client 74.248.136.165:1112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/zz.php"] [unique_id "aoSAPPcmepr5_nHgLbM5NQAAAh4"]
[Tue Aug 18 12:54:36.582028 2026] [security2:error] [pid 66623:tid 66744] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/inputs.php"] [unique_id "aoSAPNO5rbWdOArH04KA2wABLWs"]
[Tue Aug 18 12:54:36.597970 2026] [security2:error] [pid 67073:tid 67312] [client 20.151.109.219:24854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/st.php"] [unique_id "aoSAPPcmepr5_nHgLbM5NgAAAn8"]
[Tue Aug 18 12:54:36.713870 2026] [security2:error] [pid 67073:tid 67265] [client 20.104.85.180:7234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/aa.php"] [unique_id "aoSAPPcmepr5_nHgLbM5RAAAAlA"]
[Tue Aug 18 12:54:36.719776 2026] [autoindex:error] [pid 67073:tid 67311] [client 209.38.140.160:57374] AH01276: Cannot serve directory /home1/numem/console.numem.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:36.738736 2026] [security2:error] [pid 67073:tid 67306] [client 52.139.47.57:7442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/fm.php"] [unique_id "aoSAPPcmepr5_nHgLbM5RQAAAnk"]
[Tue Aug 18 12:54:36.790935 2026] [security2:error] [pid 66623:tid 66822] [client 37.40.227.74:56715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAPNO5rbWdOArH04KA3wAAAUI"]
[Tue Aug 18 12:54:36.791549 2026] [security2:error] [pid 66623:tid 66822] [client 37.40.227.74:56715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAPNO5rbWdOArH04KA3wAAAUI"]
[Tue Aug 18 12:54:36.871925 2026] [security2:error] [pid 66623:tid 66798] [client 52.238.210.254:9086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/wp-login.php"] [unique_id "aoSAPNO5rbWdOArH04KA3gAAASo"]
[Tue Aug 18 12:54:36.909466 2026] [security2:error] [pid 67073:tid 67173] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/x7.php"] [unique_id "aoSAPPcmepr5_nHgLbM5SwACRmE"]
[Tue Aug 18 12:54:36.922845 2026] [security2:error] [pid 67073:tid 67258] [client 20.226.6.191:6651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/403.php"] [unique_id "aoSAPPcmepr5_nHgLbM5TAAAAkk"]
[Tue Aug 18 12:54:36.972910 2026] [security2:error] [pid 67073:tid 67217] [client 52.173.121.69:25017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSAPPcmepr5_nHgLbM5TgAAAiA"]
[Tue Aug 18 12:54:36.984896 2026] [security2:error] [pid 67073:tid 67257] [client 74.248.18.37:12305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/root.php"] [unique_id "aoSAPPcmepr5_nHgLbM5TwAAAkg"]
[Tue Aug 18 12:54:37.076086 2026] [security2:error] [pid 66623:tid 66875] [client 85.154.68.202:9861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAPdO5rbWdOArH04KA4gAAAXc"]
[Tue Aug 18 12:54:37.076232 2026] [security2:error] [pid 66623:tid 66875] [client 85.154.68.202:9861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAPdO5rbWdOArH04KA4gAAAXc"]
[Tue Aug 18 12:54:37.078216 2026] [security2:error] [pid 66623:tid 66834] [client 52.238.210.254:10235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSAPdO5rbWdOArH04KA4wAAAU4"]
[Tue Aug 18 12:54:37.107859 2026] [security2:error] [pid 67073:tid 67098] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/god.php"] [unique_id "aoSAPfcmepr5_nHgLbM5UQACdxY"]
[Tue Aug 18 12:54:37.179315 2026] [security2:error] [pid 67073:tid 67283] [client 172.202.39.151:42789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/system_log.php"] [unique_id "aoSAPfcmepr5_nHgLbM5UgAAAmI"]
[Tue Aug 18 12:54:37.224690 2026] [security2:error] [pid 67073:tid 67237] [client 104.209.144.33:32677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSAPfcmepr5_nHgLbM5UwAAAjQ"]
[Tue Aug 18 12:54:37.275234 2026] [security2:error] [pid 66623:tid 66853] [client 135.225.75.187:63947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/olfclass.php"] [unique_id "aoSAPdO5rbWdOArH04KA5QAAAWE"]
[Tue Aug 18 12:54:37.291129 2026] [security2:error] [pid 67073:tid 67222] [client 20.118.172.148:39682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/goods.php"] [unique_id "aoSAPfcmepr5_nHgLbM5VAAAAiU"]
[Tue Aug 18 12:54:37.295503 2026] [security2:error] [pid 66623:tid 66829] [client 20.171.51.14:15760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/nd.php"] [unique_id "aoSAPdO5rbWdOArH04KA5gAAAUk"]
[Tue Aug 18 12:54:37.304962 2026] [security2:error] [pid 67073:tid 67112] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ebahvhhh.php"] [unique_id "aoSAPfcmepr5_nHgLbM5VQACNSQ"]
[Tue Aug 18 12:54:37.355008 2026] [security2:error] [pid 67073:tid 67223] [client 52.139.47.57:63070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/wp.php"] [unique_id "aoSAPfcmepr5_nHgLbM5VwAAAiY"]
[Tue Aug 18 12:54:37.437016 2026] [security2:error] [pid 67073:tid 67307] [client 20.151.109.219:24873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/le.php"] [unique_id "aoSAPfcmepr5_nHgLbM5XgAAAno"]
[Tue Aug 18 12:54:37.454191 2026] [security2:error] [pid 67073:tid 67210] [client 4.223.164.152:46199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/w.php"] [unique_id "aoSAPfcmepr5_nHgLbM5XwAAAhk"]
[Tue Aug 18 12:54:37.460940 2026] [security2:error] [pid 67073:tid 67293] [client 213.35.127.232:65346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAPfcmepr5_nHgLbM5YAAAAmw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:37.489056 2026] [security2:error] [pid 66623:tid 66881] [client 20.51.153.15:9164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/30.php"] [unique_id "aoSAPdO5rbWdOArH04KA5wAAAX0"]
[Tue Aug 18 12:54:37.502296 2026] [security2:error] [pid 67073:tid 67297] [client 20.251.48.93:29306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/coffee.php"] [unique_id "aoSAPfcmepr5_nHgLbM5YQAAAnA"]
[Tue Aug 18 12:54:37.502333 2026] [security2:error] [pid 67073:tid 67192] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/8.php"] [unique_id "aoSAPfcmepr5_nHgLbM5YgACiHQ"]
[Tue Aug 18 12:54:37.509312 2026] [security2:error] [pid 67073:tid 67324] [client 20.250.13.23:45400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/min.php"] [unique_id "aoSAPfcmepr5_nHgLbM5ZAAAAos"]
[Tue Aug 18 12:54:37.580734 2026] [security2:error] [pid 67073:tid 67271] [client 20.163.43.14:3171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAPfcmepr5_nHgLbM5agAAAlY"]
[Tue Aug 18 12:54:37.595045 2026] [security2:error] [pid 67073:tid 67206] [client 52.173.121.69:9916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAPfcmepr5_nHgLbM5bAAAAhU"]
[Tue Aug 18 12:54:37.697794 2026] [security2:error] [pid 67073:tid 67153] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/koiy.php"] [unique_id "aoSAPfcmepr5_nHgLbM5bQACWk0"]
[Tue Aug 18 12:54:37.698401 2026] [security2:error] [pid 67073:tid 67308] [client 68.155.155.199:7320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAPfcmepr5_nHgLbM5bgAAAns"]
[Tue Aug 18 12:54:37.718821 2026] [security2:error] [pid 67073:tid 67211] [client 74.248.133.44:11913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/ab1ux1ft.php"] [unique_id "aoSAPfcmepr5_nHgLbM5cQAAAho"]
[Tue Aug 18 12:54:37.791419 2026] [security2:error] [pid 67073:tid 67214] [client 20.151.109.219:24889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/hr.php"] [unique_id "aoSAPfcmepr5_nHgLbM5dAAAAh0"]
[Tue Aug 18 12:54:37.855694 2026] [security2:error] [pid 67073:tid 67317] [client 157.51.166.53:54488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAPfcmepr5_nHgLbM5dQAAAoQ"]
[Tue Aug 18 12:54:37.855841 2026] [security2:error] [pid 67073:tid 67317] [client 157.51.166.53:54488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAPfcmepr5_nHgLbM5dQAAAoQ"]
[Tue Aug 18 12:54:37.891380 2026] [security2:error] [pid 67073:tid 67181] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/iko.php"] [unique_id "aoSAPfcmepr5_nHgLbM5dgACFGk"]
[Tue Aug 18 12:54:37.934023 2026] [security2:error] [pid 67073:tid 67232] [client 20.65.98.162:58174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/admin.php"] [unique_id "aoSAPfcmepr5_nHgLbM5dwAAAi8"]
[Tue Aug 18 12:54:37.936181 2026] [security2:error] [pid 67073:tid 67282] [client 4.223.164.152:28499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/fpwch.php"] [unique_id "aoSAPfcmepr5_nHgLbM5eAAAAmE"]
[Tue Aug 18 12:54:38.046366 2026] [security2:error] [pid 67073:tid 67247] [client 52.139.47.57:43563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/33.php"] [unique_id "aoSAPvcmepr5_nHgLbM5fQAAAj4"]
[Tue Aug 18 12:54:38.055854 2026] [security2:error] [pid 67073:tid 67327] [client 20.163.43.14:1965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/moon.php"] [unique_id "aoSAPvcmepr5_nHgLbM5fgAAAo4"]
[Tue Aug 18 12:54:38.131906 2026] [security2:error] [pid 67073:tid 67284] [client 158.158.74.177:20527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/mah/function.php"] [unique_id "aoSAPvcmepr5_nHgLbM5gQAAAmM"]
[Tue Aug 18 12:54:38.133522 2026] [security2:error] [pid 67073:tid 67277] [client 20.151.109.219:59721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kt.php"] [unique_id "aoSAPvcmepr5_nHgLbM5ggAAAlw"]
[Tue Aug 18 12:54:38.172957 2026] [security2:error] [pid 66623:tid 66858] [client 132.196.61.152:61025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAPtO5rbWdOArH04KA6gAAAWY"]
[Tue Aug 18 12:54:38.180886 2026] [security2:error] [pid 67073:tid 67286] [client 20.48.236.86:10738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/xx.php"] [unique_id "aoSAPvcmepr5_nHgLbM5gwAAAmU"]
[Tue Aug 18 12:54:38.268908 2026] [security2:error] [pid 66623:tid 66839] [client 52.238.210.254:8947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSAPtO5rbWdOArH04KA6wAAAVM"]
[Tue Aug 18 12:54:38.270607 2026] [security2:error] [pid 67073:tid 67250] [client 20.104.100.201:21463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSAPvcmepr5_nHgLbM5hAAAAkE"]
[Tue Aug 18 12:54:38.285825 2026] [authz_core:error] [pid 67073:tid 67147] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:38.286284 2026] [authz_core:error] [pid 67073:tid 67147] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:38.373493 2026] [security2:error] [pid 67073:tid 67097] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/raw.php"] [unique_id "aoSAPvcmepr5_nHgLbM5igACjBU"]
[Tue Aug 18 12:54:38.440383 2026] [security2:error] [pid 67073:tid 67257] [client 4.223.164.152:46200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/FWAZ.php"] [unique_id "aoSAPvcmepr5_nHgLbM5iwAAAkg"]
[Tue Aug 18 12:54:38.496453 2026] [security2:error] [pid 67073:tid 67298] [client 74.248.136.165:1149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/xa.php"] [unique_id "aoSAPvcmepr5_nHgLbM5jAAAAnE"]
[Tue Aug 18 12:54:38.515148 2026] [security2:error] [pid 67073:tid 67236] [client 68.155.154.236:64499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAPvcmepr5_nHgLbM5jQAAAjM"]
[Tue Aug 18 12:54:38.517543 2026] [security2:error] [pid 67073:tid 67256] [client 135.225.75.187:58996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wpver.php"] [unique_id "aoSAPvcmepr5_nHgLbM5jwAAAkc"]
[Tue Aug 18 12:54:38.556591 2026] [security2:error] [pid 66623:tid 66785] [client 20.163.43.14:3079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/cache.php"] [unique_id "aoSAPtO5rbWdOArH04KA7AAAAR0"]
[Tue Aug 18 12:54:38.561538 2026] [security2:error] [pid 67073:tid 67081] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/05.php"] [unique_id "aoSAPvcmepr5_nHgLbM5kAACVwU"]
[Tue Aug 18 12:54:38.565232 2026] [autoindex:error] [pid 67073:tid 67237] [client 172.202.39.151:50206] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:38.664234 2026] [security2:error] [pid 67073:tid 67283] [client 52.139.47.57:16813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/az.php"] [unique_id "aoSAPvcmepr5_nHgLbM5kwAAAmI"]
[Tue Aug 18 12:54:38.672840 2026] [security2:error] [pid 66623:tid 66772] [client 20.118.172.148:7658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/hplfuns.php"] [unique_id "aoSAPtO5rbWdOArH04KA7wAAARA"]
[Tue Aug 18 12:54:38.675814 2026] [security2:error] [pid 67073:tid 67223] [client 20.104.85.180:7245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/0x.php"] [unique_id "aoSAPvcmepr5_nHgLbM5lAAAAiY"]
[Tue Aug 18 12:54:38.715918 2026] [security2:error] [pid 67073:tid 67246] [client 20.91.215.254:24370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/abcd.php"] [unique_id "aoSAPvcmepr5_nHgLbM5lQAAAj0"]
[Tue Aug 18 12:54:38.843364 2026] [ssl:error] [pid 67073:tid 67212] [client 3.233.59.216:41770] AH02032: Hostname srv254.prodns.com.br (default host as no SNI was provided) and hostname www.renatawelinski.com.br provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue Aug 18 12:54:38.847510 2026] [security2:error] [pid 66623:tid 66878] [client 20.171.51.14:45429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ri.php"] [unique_id "aoSAPtO5rbWdOArH04KA8gAAAXo"]
[Tue Aug 18 12:54:38.848364 2026] [security2:error] [pid 66623:tid 66824] [client 20.226.6.191:6612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/gecko.php"] [unique_id "aoSAPtO5rbWdOArH04KA8wAAAUQ"]
[Tue Aug 18 12:54:38.902889 2026] [security2:error] [pid 67073:tid 67309] [client 172.182.200.96:14184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSAPvcmepr5_nHgLbM5nAAAAnw"]
[Tue Aug 18 12:54:38.907434 2026] [security2:error] [pid 67073:tid 67305] [client 20.205.121.237:4105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/tmp/index.php"] [unique_id "aoSAPvcmepr5_nHgLbM5nQAAAng"]
[Tue Aug 18 12:54:39.017787 2026] [security2:error] [pid 67073:tid 67326] [client 20.251.48.93:58909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAP_cmepr5_nHgLbM5oAAAAo0"]
[Tue Aug 18 12:54:39.042877 2026] [security2:error] [pid 67073:tid 67206] [client 172.182.200.96:14313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSAP_cmepr5_nHgLbM5ogAAAhU"]
[Tue Aug 18 12:54:39.055539 2026] [security2:error] [pid 66623:tid 66781] [client 74.248.18.37:54198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/server.php"] [unique_id "aoSAP9O5rbWdOArH04KA9QAAARk"]
[Tue Aug 18 12:54:39.075847 2026] [security2:error] [pid 67073:tid 67260] [client 20.104.100.201:58928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/output.php"] [unique_id "aoSAP_cmepr5_nHgLbM5pAAAAks"]
[Tue Aug 18 12:54:39.103495 2026] [autoindex:error] [pid 67073:tid 67332] [client 172.202.39.151:41871] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:39.116344 2026] [security2:error] [pid 67073:tid 67152] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/public/hi.php"] [unique_id "aoSAP_cmepr5_nHgLbM5pgAChUw"]
[Tue Aug 18 12:54:39.141856 2026] [security2:error] [pid 67073:tid 67261] [client 20.100.169.31:12381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/fone1.php"] [unique_id "aoSAP_cmepr5_nHgLbM5qAAAAkw"]
[Tue Aug 18 12:54:39.184859 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:39.185119 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:39.230792 2026] [security2:error] [pid 66623:tid 66860] [client 52.173.121.69:17975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSAP9O5rbWdOArH04KA-AAAAWg"]
[Tue Aug 18 12:54:39.320440 2026] [security2:error] [pid 67073:tid 67136] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/get.php"] [unique_id "aoSAP_cmepr5_nHgLbM5rAACHTw"]
[Tue Aug 18 12:54:39.353163 2026] [security2:error] [pid 66623:tid 66845] [client 192.141.172.134:54486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAP9O5rbWdOArH04KA-gAAAVk"]
[Tue Aug 18 12:54:39.353305 2026] [security2:error] [pid 66623:tid 66845] [client 192.141.172.134:54486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAP9O5rbWdOArH04KA-gAAAVk"]
[Tue Aug 18 12:54:39.357950 2026] [security2:error] [pid 67073:tid 67234] [client 68.155.154.236:63901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/blog/byp.php"] [unique_id "aoSAP_cmepr5_nHgLbM5rQAAAjE"]
[Tue Aug 18 12:54:39.402269 2026] [security2:error] [pid 66623:tid 66682] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/install.php"] [unique_id "aoSAP9O5rbWdOArH04KA_QABSy0"]
[Tue Aug 18 12:54:39.406830 2026] [security2:error] [pid 67073:tid 67281] [client 20.104.100.201:58921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/tiny2.php"] [unique_id "aoSAP_cmepr5_nHgLbM5rgAAAmA"]
[Tue Aug 18 12:54:39.407761 2026] [security2:error] [pid 66623:tid 66815] [client 20.51.153.15:9175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/pu.php"] [unique_id "aoSAP9O5rbWdOArH04KA_gAAATs"]
[Tue Aug 18 12:54:39.461750 2026] [security2:error] [pid 66623:tid 66791] [client 172.182.200.96:14281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSAP9O5rbWdOArH04KA_wAAASM"]
[Tue Aug 18 12:54:39.486480 2026] [security2:error] [pid 67073:tid 67215] [client 20.118.172.148:7562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/htaccess.php"] [unique_id "aoSAP_cmepr5_nHgLbM5sQAAAh4"]
[Tue Aug 18 12:54:39.500645 2026] [security2:error] [pid 67073:tid 67315] [client 20.151.109.219:53237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ww.php"] [unique_id "aoSAP_cmepr5_nHgLbM5sgAAAoI"]
[Tue Aug 18 12:54:39.509214 2026] [security2:error] [pid 67073:tid 67312] [client 172.202.39.151:50206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSAP_cmepr5_nHgLbM5swAAAn8"]
[Tue Aug 18 12:54:39.522887 2026] [security2:error] [pid 67073:tid 67104] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/rpk.php"] [unique_id "aoSAP_cmepr5_nHgLbM5tAACgRw"]
[Tue Aug 18 12:54:39.585436 2026] [security2:error] [pid 67073:tid 67265] [client 172.202.39.151:41871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAP_cmepr5_nHgLbM5tQAAAlA"]
[Tue Aug 18 12:54:39.658154 2026] [security2:error] [pid 66623:tid 66854] [client 40.85.222.29:26146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAP9O5rbWdOArH04KBAgAAAWI"]
[Tue Aug 18 12:54:39.663702 2026] [security2:error] [pid 66623:tid 66887] [client 213.35.127.232:49592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAP9O5rbWdOArH04KBAwAAAYM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:39.694773 2026] [security2:error] [pid 67073:tid 67276] [client 114.119.155.69:43983] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.viacentroveiculos.com.br"] [uri "/photo-resize/2026/970771/gb-ab3e66a.jpeg/0"] [unique_id "aoSAP_cmepr5_nHgLbM5uAAAAls"], referer: https://www.viacentroveiculos.com.br/veiculo/970771/i30-2-0-16v-145cv-5p-aut
[Tue Aug 18 12:54:39.713829 2026] [security2:error] [pid 67073:tid 67085] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-blog.php"] [unique_id "aoSAP_cmepr5_nHgLbM5uQACKgk"]
[Tue Aug 18 12:54:39.714307 2026] [security2:error] [pid 66623:tid 66773] [client 20.51.153.15:9156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ry.php"] [unique_id "aoSAP9O5rbWdOArH04KBBAAAARE"]
[Tue Aug 18 12:54:39.731997 2026] [security2:error] [pid 66623:tid 66646] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAP9O5rbWdOArH04KBBQABUQk"]
[Tue Aug 18 12:54:39.757080 2026] [security2:error] [pid 66623:tid 66779] [client 68.155.155.199:7340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/admin.php"] [unique_id "aoSAP9O5rbWdOArH04KBBgAAARc"]
[Tue Aug 18 12:54:39.780004 2026] [security2:error] [pid 67073:tid 67235] [client 194.36.25.35:57102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.25.36.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hawaieducacional.com.br"] [uri "/wp-login.php"] [unique_id "aoSAPfcmepr5_nHgLbM5cAAAAjI"]
[Tue Aug 18 12:54:39.886115 2026] [security2:error] [pid 66623:tid 66842] [client 68.155.154.236:64517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSAP9O5rbWdOArH04KBCAAAAVY"]
[Tue Aug 18 12:54:39.902629 2026] [security2:error] [pid 67073:tid 67290] [client 52.139.47.57:19601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/sx.php"] [unique_id "aoSAP_cmepr5_nHgLbM5vgAAAmk"]
[Tue Aug 18 12:54:39.920315 2026] [security2:error] [pid 66623:tid 66794] [client 20.171.51.14:51827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/99.php"] [unique_id "aoSAP9O5rbWdOArH04KBCQAAASY"]
[Tue Aug 18 12:54:39.934022 2026] [security2:error] [pid 67073:tid 67094] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/mga.php"] [unique_id "aoSAP_cmepr5_nHgLbM5wAACZBI"]
[Tue Aug 18 12:54:39.988284 2026] [security2:error] [pid 67073:tid 67224] [client 103.120.71.157:2899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAP_cmepr5_nHgLbM5wwAAAic"]
[Tue Aug 18 12:54:39.988387 2026] [security2:error] [pid 67073:tid 67224] [client 103.120.71.157:2899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAP_cmepr5_nHgLbM5wwAAAic"]
[Tue Aug 18 12:54:40.011510 2026] [security2:error] [pid 66623:tid 66843] [client 5.31.227.224:59043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQNO5rbWdOArH04KBCwAAAVc"]
[Tue Aug 18 12:54:40.011599 2026] [security2:error] [pid 66623:tid 66843] [client 5.31.227.224:59043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQNO5rbWdOArH04KBCwAAAVc"]
[Tue Aug 18 12:54:40.015630 2026] [security2:error] [pid 67073:tid 67328] [client 52.173.121.69:6097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSAQPcmepr5_nHgLbM5xQAAAo8"]
[Tue Aug 18 12:54:40.036458 2026] [security2:error] [pid 66623:tid 66847] [client 103.184.169.37:41391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQNO5rbWdOArH04KBDAAAAVs"]
[Tue Aug 18 12:54:40.036540 2026] [security2:error] [pid 66623:tid 66847] [client 103.184.169.37:41391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQNO5rbWdOArH04KBDAAAAVs"]
[Tue Aug 18 12:54:40.063016 2026] [security2:error] [pid 66623:tid 66678] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/iqps3ldefault.php"] [unique_id "aoSAQNO5rbWdOArH04KBDQABKyk"]
[Tue Aug 18 12:54:40.098049 2026] [security2:error] [pid 66623:tid 66865] [client 74.248.136.165:60123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/avim.php"] [unique_id "aoSAQNO5rbWdOArH04KBDgAAAW0"]
[Tue Aug 18 12:54:40.109821 2026] [security2:error] [pid 66623:tid 66800] [client 20.104.85.180:8033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/zxz.php"] [unique_id "aoSAQNO5rbWdOArH04KBDwAAASw"]
[Tue Aug 18 12:54:40.123832 2026] [security2:error] [pid 67073:tid 67166] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/fs.php"] [unique_id "aoSAQPcmepr5_nHgLbM5ywACKFo"]
[Tue Aug 18 12:54:40.219127 2026] [security2:error] [pid 66623:tid 66790] [client 158.158.74.177:9898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/filter.php"] [unique_id "aoSAQNO5rbWdOArH04KBEQAAASI"]
[Tue Aug 18 12:54:40.235149 2026] [security2:error] [pid 67073:tid 67106] [remote 179.64.21.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powerbelt.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQPcmepr5_nHgLbM50AACJR4"]
[Tue Aug 18 12:54:40.235293 2026] [security2:error] [pid 67073:tid 67222] [client 179.64.21.92:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "powerbelt.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQPcmepr5_nHgLbM50AACJR4"]
[Tue Aug 18 12:54:40.258922 2026] [security2:error] [pid 66623:tid 66862] [client 86.120.159.145:3977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQNO5rbWdOArH04KBEgAAAWo"]
[Tue Aug 18 12:54:40.259016 2026] [security2:error] [pid 66623:tid 66862] [client 86.120.159.145:3977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQNO5rbWdOArH04KBEgAAAWo"]
[Tue Aug 18 12:54:40.314464 2026] [security2:error] [pid 66623:tid 66876] [client 4.223.164.152:54220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/blurbs.php"] [unique_id "aoSAQNO5rbWdOArH04KBEwAAAXg"]
[Tue Aug 18 12:54:40.318411 2026] [security2:error] [pid 67073:tid 67151] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-tem.php"] [unique_id "aoSAQPcmepr5_nHgLbM50gACdEs"]
[Tue Aug 18 12:54:40.328889 2026] [security2:error] [pid 67073:tid 67283] [client 20.151.109.219:59736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/mo.php"] [unique_id "aoSAQPcmepr5_nHgLbM50wAAAmI"]
[Tue Aug 18 12:54:40.350086 2026] [security2:error] [pid 67073:tid 67223] [client 3.79.134.69:19554] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.webeb.com.br"] [uri "/index.php"] [unique_id "aoSAQPcmepr5_nHgLbM51AAAAiY"], referer: http://www.webeb.com.br
[Tue Aug 18 12:54:40.389233 2026] [security2:error] [pid 66623:tid 66697] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/item.php"] [unique_id "aoSAQNO5rbWdOArH04KBFQABczw"]
[Tue Aug 18 12:54:40.472984 2026] [security2:error] [pid 66623:tid 66861] [client 52.139.47.57:16789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/tfm.php"] [unique_id "aoSAQNO5rbWdOArH04KBFgAAAWk"]
[Tue Aug 18 12:54:40.478217 2026] [security2:error] [pid 67073:tid 67272] [client 20.91.215.254:20551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/kj.php"] [unique_id "aoSAQPcmepr5_nHgLbM51gAAAlc"]
[Tue Aug 18 12:54:40.479189 2026] [security2:error] [pid 67073:tid 67220] [client 20.42.19.40:9698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAQPcmepr5_nHgLbM51wAAAiM"]
[Tue Aug 18 12:54:40.505015 2026] [security2:error] [pid 67073:tid 67126] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/sadd.php"] [unique_id "aoSAQPcmepr5_nHgLbM52QACkDI"]
[Tue Aug 18 12:54:40.519335 2026] [security2:error] [pid 66623:tid 66891] [client 4.232.151.198:6486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/simple.php"] [unique_id "aoSAQNO5rbWdOArH04KBFwAAAYc"]
[Tue Aug 18 12:54:40.571726 2026] [security2:error] [pid 67073:tid 67327] [client 74.248.18.37:33333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/a7.php"] [unique_id "aoSAQPcmepr5_nHgLbM53AAAAo4"]
[Tue Aug 18 12:54:40.574617 2026] [security2:error] [pid 67073:tid 67207] [client 20.171.51.14:43365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/tp.php"] [unique_id "aoSAQPcmepr5_nHgLbM53gAAAhY"]
[Tue Aug 18 12:54:40.591323 2026] [security2:error] [pid 67073:tid 67212] [client 20.116.17.175:57608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/kj.php"] [unique_id "aoSAQPcmepr5_nHgLbM54AAAAhs"]
[Tue Aug 18 12:54:40.596434 2026] [security2:error] [pid 67073:tid 67293] [client 20.51.153.15:9197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/pm.php"] [unique_id "aoSAQPcmepr5_nHgLbM54QAAAmw"]
[Tue Aug 18 12:54:40.609935 2026] [security2:error] [pid 67073:tid 67213] [client 20.48.236.86:11010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/uwu.php"] [unique_id "aoSAQPcmepr5_nHgLbM54gAAAhw"]
[Tue Aug 18 12:54:40.668338 2026] [authz_core:error] [pid 67073:tid 67125] [remote 57.141.22.106:27906] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:40.668595 2026] [authz_core:error] [pid 67073:tid 67125] [remote 57.141.22.106:27906] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:40.694851 2026] [security2:error] [pid 66623:tid 66803] [client 114.5.214.109:49798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQNO5rbWdOArH04KBGQAAAS8"]
[Tue Aug 18 12:54:40.694981 2026] [security2:error] [pid 66623:tid 66803] [client 114.5.214.109:49798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQNO5rbWdOArH04KBGQAAAS8"]
[Tue Aug 18 12:54:40.696865 2026] [security2:error] [pid 67073:tid 67186] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ex.php"] [unique_id "aoSAQPcmepr5_nHgLbM55AACGG4"]
[Tue Aug 18 12:54:40.704691 2026] [security2:error] [pid 67073:tid 67326] [client 104.209.144.33:25625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/zwlsv.php"] [unique_id "aoSAQPcmepr5_nHgLbM55wAAAo0"]
[Tue Aug 18 12:54:40.707668 2026] [authz_core:error] [pid 67073:tid 67157] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:40.707962 2026] [authz_core:error] [pid 67073:tid 67157] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:40.723234 2026] [security2:error] [pid 66623:tid 66732] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/jga.php"] [unique_id "aoSAQNO5rbWdOArH04KBGgABTl8"]
[Tue Aug 18 12:54:40.737801 2026] [security2:error] [pid 67073:tid 67148] [remote 52.167.144.194:57406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memo.ind.br"] [uri "/index.php/produtos/acessorios/mangueira-de-chope"] [unique_id "aoSAQPcmepr5_nHgLbM55gACGUg"]
[Tue Aug 18 12:54:40.769805 2026] [security2:error] [pid 67073:tid 67218] [client 20.118.172.148:48732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/images/wso.php"] [unique_id "aoSAQPcmepr5_nHgLbM56wAAAiE"]
[Tue Aug 18 12:54:40.829915 2026] [security2:error] [pid 67073:tid 67280] [client 172.202.39.151:45214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/ioxi-o.php"] [unique_id "aoSAQPcmepr5_nHgLbM57AAAAl8"]
[Tue Aug 18 12:54:40.851111 2026] [security2:error] [pid 67073:tid 67246] [client 138.36.100.162:42154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQPcmepr5_nHgLbM57gAAAj0"]
[Tue Aug 18 12:54:40.851212 2026] [security2:error] [pid 67073:tid 67246] [client 138.36.100.162:42154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQPcmepr5_nHgLbM57gAAAj0"]
[Tue Aug 18 12:54:40.860447 2026] [security2:error] [pid 67073:tid 67308] [client 20.251.48.93:2984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSAQPcmepr5_nHgLbM57wAAAns"]
[Tue Aug 18 12:54:40.886635 2026] [security2:error] [pid 67073:tid 67211] [client 20.171.51.14:45391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/er.php"] [unique_id "aoSAQPcmepr5_nHgLbM58QAAAho"]
[Tue Aug 18 12:54:40.893304 2026] [security2:error] [pid 67073:tid 67143] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/tax.php"] [unique_id "aoSAQPcmepr5_nHgLbM58gACakM"]
[Tue Aug 18 12:54:40.961321 2026] [security2:error] [pid 67073:tid 67215] [client 4.223.164.152:54242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/100.php"] [unique_id "aoSAQPcmepr5_nHgLbM59AAAAh4"]
[Tue Aug 18 12:54:41.006860 2026] [security2:error] [pid 67073:tid 67320] [client 20.42.19.40:2898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/autoload_classmap.php"] [unique_id "aoSAQfcmepr5_nHgLbM59QAAAoc"]
[Tue Aug 18 12:54:41.048856 2026] [security2:error] [pid 66623:tid 66699] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/jquery.php"] [unique_id "aoSAQdO5rbWdOArH04KBHQABDj4"]
[Tue Aug 18 12:54:41.079575 2026] [security2:error] [pid 67073:tid 67243] [client 74.248.136.165:53622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/f6.php"] [unique_id "aoSAQfcmepr5_nHgLbM59wAAAjo"]
[Tue Aug 18 12:54:41.136101 2026] [security2:error] [pid 66623:tid 66782] [client 20.151.109.219:17539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/qr.php"] [unique_id "aoSAQdO5rbWdOArH04KBIAAAARo"]
[Tue Aug 18 12:54:41.153474 2026] [security2:error] [pid 67073:tid 67149] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/X7x.php"] [unique_id "aoSAQfcmepr5_nHgLbM5-QACXEk"]
[Tue Aug 18 12:54:41.205434 2026] [security2:error] [pid 66623:tid 66822] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQdO5rbWdOArH04KBHwABQkw"]
[Tue Aug 18 12:54:41.216754 2026] [security2:error] [pid 67073:tid 67268] [client 52.173.121.69:17955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSAQfcmepr5_nHgLbM5-wAAAlM"]
[Tue Aug 18 12:54:41.269063 2026] [security2:error] [pid 67073:tid 67311] [client 172.182.200.96:14329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSAQfcmepr5_nHgLbM5_gAAAn4"]
[Tue Aug 18 12:54:41.301564 2026] [security2:error] [pid 67073:tid 67250] [client 20.116.17.175:57638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSAQfcmepr5_nHgLbM5_wAAAkE"]
[Tue Aug 18 12:54:41.375374 2026] [security2:error] [pid 66623:tid 66671] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/k.php"] [unique_id "aoSAQdO5rbWdOArH04KBIQABdiI"]
[Tue Aug 18 12:54:41.387758 2026] [security2:error] [pid 67073:tid 67168] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ocxla.php"] [unique_id "aoSAQfcmepr5_nHgLbM6AgACjFw"]
[Tue Aug 18 12:54:41.442711 2026] [security2:error] [pid 67073:tid 67234] [client 74.248.18.37:54171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSAQfcmepr5_nHgLbM6AwAAAjE"]
[Tue Aug 18 12:54:41.508912 2026] [security2:error] [pid 67073:tid 67254] [client 20.104.85.180:8044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/www.php"] [unique_id "aoSAQfcmepr5_nHgLbM6BAAAAkU"]
[Tue Aug 18 12:54:41.511665 2026] [security2:error] [pid 67073:tid 67232] [client 135.225.75.187:58985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/thui.php"] [unique_id "aoSAQfcmepr5_nHgLbM6BQAAAi8"]
[Tue Aug 18 12:54:41.515515 2026] [security2:error] [pid 66623:tid 66776] [client 68.155.154.236:63915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAQdO5rbWdOArH04KBIgAAARQ"]
[Tue Aug 18 12:54:41.518695 2026] [security2:error] [pid 67073:tid 67239] [client 20.151.109.219:65007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/dirs.php"] [unique_id "aoSAQfcmepr5_nHgLbM6BgAAAjY"]
[Tue Aug 18 12:54:41.524986 2026] [security2:error] [pid 67073:tid 67304] [client 52.238.210.254:9083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/wp.php"] [unique_id "aoSAQfcmepr5_nHgLbM6BwAAAnc"]
[Tue Aug 18 12:54:41.545557 2026] [security2:error] [pid 67073:tid 67225] [client 132.196.61.152:26816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/clque.php"] [unique_id "aoSAQfcmepr5_nHgLbM6CAAAAig"]
[Tue Aug 18 12:54:41.564978 2026] [security2:error] [pid 67073:tid 67256] [client 20.163.43.14:3127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAQfcmepr5_nHgLbM6CgAAAkc"]
[Tue Aug 18 12:54:41.570924 2026] [security2:error] [pid 67073:tid 67331] [client 20.65.98.162:18933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/sf.php"] [unique_id "aoSAQfcmepr5_nHgLbM6CwAAApI"]
[Tue Aug 18 12:54:41.576319 2026] [security2:error] [pid 67073:tid 67222] [client 20.118.172.148:47274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/index/function.php"] [unique_id "aoSAQfcmepr5_nHgLbM6DAAAAiU"]
[Tue Aug 18 12:54:41.580132 2026] [security2:error] [pid 66623:tid 66872] [client 20.171.51.14:29228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/qk.php"] [unique_id "aoSAQdO5rbWdOArH04KBIwAAAXQ"]
[Tue Aug 18 12:54:41.589139 2026] [security2:error] [pid 67073:tid 67137] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/post.php"] [unique_id "aoSAQfcmepr5_nHgLbM6DQACdD0"]
[Tue Aug 18 12:54:41.604563 2026] [security2:error] [pid 67073:tid 67283] [client 172.202.39.151:44412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSAQfcmepr5_nHgLbM6DwAAAmI"]
[Tue Aug 18 12:54:41.607179 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:41.607440 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:41.696411 2026] [security2:error] [pid 67073:tid 67272] [client 172.182.200.96:14261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSAQfcmepr5_nHgLbM6EQAAAlc"]
[Tue Aug 18 12:54:41.707164 2026] [security2:error] [pid 66623:tid 66853] [client 52.139.47.57:19943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/asd.php"] [unique_id "aoSAQdO5rbWdOArH04KBJAAAAWE"]
[Tue Aug 18 12:54:41.790698 2026] [security2:error] [pid 67073:tid 67212] [client 172.182.200.96:14192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSAQfcmepr5_nHgLbM6EgAAAhs"]
[Tue Aug 18 12:54:41.802784 2026] [security2:error] [pid 66623:tid 66784] [client 20.42.19.40:9623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAQdO5rbWdOArH04KBJwAAARw"]
[Tue Aug 18 12:54:41.885779 2026] [security2:error] [pid 66623:tid 66772] [client 74.248.136.165:29417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/myfile.php"] [unique_id "aoSAQdO5rbWdOArH04KBKAAAARA"]
[Tue Aug 18 12:54:41.911383 2026] [security2:error] [pid 67073:tid 67180] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/nhr.php"] [unique_id "aoSAQfcmepr5_nHgLbM6FgACHGg"]
[Tue Aug 18 12:54:42.075022 2026] [security2:error] [pid 67073:tid 67287] [client 52.238.210.254:10196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSAQvcmepr5_nHgLbM6HAAAAmY"]
[Tue Aug 18 12:54:42.097818 2026] [security2:error] [pid 67073:tid 67201] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAQvcmepr5_nHgLbM6HgACcH0"]
[Tue Aug 18 12:54:42.114273 2026] [security2:error] [pid 67073:tid 67275] [client 52.173.121.69:9922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAQvcmepr5_nHgLbM6HwAAAlo"]
[Tue Aug 18 12:54:42.132636 2026] [security2:error] [pid 67073:tid 67246] [client 132.196.61.152:61038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAQvcmepr5_nHgLbM6IAAAAj0"]
[Tue Aug 18 12:54:42.156875 2026] [security2:error] [pid 67073:tid 67308] [client 20.48.236.86:10421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/signon.php"] [unique_id "aoSAQvcmepr5_nHgLbM6IQAAAns"]
[Tue Aug 18 12:54:42.164125 2026] [security2:error] [pid 67073:tid 67321] [client 74.248.18.37:54196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/shell.php"] [unique_id "aoSAQvcmepr5_nHgLbM6IgAAAog"]
[Tue Aug 18 12:54:42.192750 2026] [security2:error] [pid 67073:tid 67214] [client 172.182.200.96:14301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSAQvcmepr5_nHgLbM6JgAAAh0"]
[Tue Aug 18 12:54:42.214546 2026] [authz_core:error] [pid 67073:tid 67139] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:42.214992 2026] [authz_core:error] [pid 67073:tid 67139] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:42.227648 2026] [security2:error] [pid 67073:tid 67266] [client 20.171.51.14:29226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSAQvcmepr5_nHgLbM6KQAAAlE"]
[Tue Aug 18 12:54:42.248314 2026] [security2:error] [pid 67073:tid 67330] [client 68.155.155.199:5536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/edit.php"] [unique_id "aoSAQvcmepr5_nHgLbM6KwAAApE"]
[Tue Aug 18 12:54:42.257055 2026] [security2:error] [pid 67073:tid 67221] [client 114.119.137.28:40123] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "monroviaexport.com.br"] [uri "/2022/12/30/trend-single-wirklich-kostenlos-musik"] [unique_id "aoSAQvcmepr5_nHgLbM6LAAAAiQ"], referer: https://www.sikuraservizi.it/2022/12/29/singles-rheinland-pfalz-gruppenticket
[Tue Aug 18 12:54:42.269469 2026] [security2:error] [pid 67073:tid 67245] [client 197.184.64.235:41919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQvcmepr5_nHgLbM6LQAAAjw"]
[Tue Aug 18 12:54:42.269571 2026] [security2:error] [pid 67073:tid 67245] [client 197.184.64.235:41919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQvcmepr5_nHgLbM6LQAAAjw"]
[Tue Aug 18 12:54:42.276470 2026] [security2:error] [pid 66623:tid 66725] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/k2.php"] [unique_id "aoSAQtO5rbWdOArH04KBKgABJ1g"]
[Tue Aug 18 12:54:42.316408 2026] [security2:error] [pid 67073:tid 67131] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ws79.php"] [unique_id "aoSAQvcmepr5_nHgLbM6LwACRjc"]
[Tue Aug 18 12:54:42.318452 2026] [security2:error] [pid 67073:tid 67315] [client 20.226.6.191:6551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/aa.php"] [unique_id "aoSAQvcmepr5_nHgLbM6MAAAAoI"]
[Tue Aug 18 12:54:42.332757 2026] [security2:error] [pid 66623:tid 66807] [client 20.65.98.162:8215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/biufile.php"] [unique_id "aoSAQtO5rbWdOArH04KBKwAAATM"]
[Tue Aug 18 12:54:42.364218 2026] [security2:error] [pid 66623:tid 66824] [client 74.248.136.165:41200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/xmy.php"] [unique_id "aoSAQtO5rbWdOArH04KBLQAAAUQ"]
[Tue Aug 18 12:54:42.385453 2026] [security2:error] [pid 67073:tid 67262] [client 20.163.43.14:3128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAQvcmepr5_nHgLbM6MQAAAk0"]
[Tue Aug 18 12:54:42.445338 2026] [security2:error] [pid 67073:tid 67284] [client 20.118.172.148:47238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/info.php"] [unique_id "aoSAQvcmepr5_nHgLbM6MwAAAmM"]
[Tue Aug 18 12:54:42.481571 2026] [security2:error] [pid 67073:tid 67322] [client 158.158.74.177:24678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/input.php"] [unique_id "aoSAQvcmepr5_nHgLbM6NAAAAok"]
[Tue Aug 18 12:54:42.535282 2026] [security2:error] [pid 67073:tid 67090] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/rtx.php"] [unique_id "aoSAQvcmepr5_nHgLbM6NQACUw4"]
[Tue Aug 18 12:54:42.551469 2026] [security2:error] [pid 66623:tid 66826] [client 52.173.121.69:25023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSAQtO5rbWdOArH04KBMAAAAUY"]
[Tue Aug 18 12:54:42.647121 2026] [security2:error] [pid 66623:tid 66809] [client 149.34.210.157:52463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAQtO5rbWdOArH04KBMQAAATU"]
[Tue Aug 18 12:54:42.668347 2026] [security2:error] [pid 67073:tid 67216] [client 74.248.133.44:48280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/aksinet.php"] [unique_id "aoSAQvcmepr5_nHgLbM6OQAAAh8"]
[Tue Aug 18 12:54:42.707886 2026] [security2:error] [pid 66623:tid 66810] [client 20.42.19.40:2750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/hosty.php"] [unique_id "aoSAQtO5rbWdOArH04KBMgAAATY"]
[Tue Aug 18 12:54:42.753702 2026] [security2:error] [pid 67073:tid 67298] [client 20.91.215.254:20559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/languages.php"] [unique_id "aoSAQvcmepr5_nHgLbM6PAAAAnE"]
[Tue Aug 18 12:54:42.767085 2026] [security2:error] [pid 67073:tid 67325] [client 20.104.100.201:58489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wpxml.php"] [unique_id "aoSAQvcmepr5_nHgLbM6PQAAAow"]
[Tue Aug 18 12:54:42.797413 2026] [security2:error] [pid 67073:tid 67233] [client 20.163.43.14:3131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/o.php"] [unique_id "aoSAQvcmepr5_nHgLbM6PgAAAjA"]
[Tue Aug 18 12:54:42.804624 2026] [security2:error] [pid 67073:tid 67224] [client 114.119.159.210:47623] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.grupofoco.com.br"] [uri "/focotalentos"] [unique_id "aoSAQvcmepr5_nHgLbM6PwAAAic"], referer: http://www.grupofoco.com.br/focotalentos?C=D%3BO%3DA
[Tue Aug 18 12:54:42.897207 2026] [security2:error] [pid 67073:tid 67254] [client 20.116.17.175:57629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/png.php"] [unique_id "aoSAQvcmepr5_nHgLbM6QQAAAkU"]
[Tue Aug 18 12:54:42.900202 2026] [security2:error] [pid 66623:tid 66777] [client 40.85.222.29:42894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/blog/byp.php"] [unique_id "aoSAQtO5rbWdOArH04KBNwAAARU"]
[Tue Aug 18 12:54:42.937621 2026] [security2:error] [pid 66623:tid 66880] [client 213.35.127.232:50071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAQtO5rbWdOArH04KBOAAAAXw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:42.940924 2026] [security2:error] [pid 66623:tid 66809] [client 149.34.210.157:52463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAQtO5rbWdOArH04KBMQAAATU"]
[Tue Aug 18 12:54:43.005775 2026] [security2:error] [pid 67073:tid 67228] [client 20.171.51.14:45399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/fs.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6RgAAAis"]
[Tue Aug 18 12:54:43.120420 2026] [security2:error] [pid 67073:tid 67098] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/end.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6SAACIxY"]
[Tue Aug 18 12:54:43.121177 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:43.121444 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:43.130445 2026] [security2:error] [pid 67073:tid 67272] [client 68.155.155.199:5735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/w.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6SQAAAlc"]
[Tue Aug 18 12:54:43.136864 2026] [security2:error] [pid 66623:tid 66864] [client 114.119.158.167:62867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.paranavans.com.br"] [uri "/veiculo/205997/8-150-e-delivery-2p-bau-2009"] [unique_id "aoSAQ9O5rbWdOArH04KBOQAAAWw"], referer: https://www.paranavans.com.br
[Tue Aug 18 12:54:43.145854 2026] [security2:error] [pid 66623:tid 66852] [client 20.250.13.23:13644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/php8.php"] [unique_id "aoSAQ9O5rbWdOArH04KBOgAAAWA"]
[Tue Aug 18 12:54:43.150256 2026] [security2:error] [pid 66623:tid 66860] [client 172.202.39.151:30465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/abc.php"] [unique_id "aoSAQ9O5rbWdOArH04KBOwAAAWg"]
[Tue Aug 18 12:54:43.174850 2026] [security2:error] [pid 66623:tid 66755] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/license.php"] [unique_id "aoSAQ9O5rbWdOArH04KBPAABUnY"]
[Tue Aug 18 12:54:43.185369 2026] [security2:error] [pid 67073:tid 67263] [client 20.163.43.14:3194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/bb.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6SgAAAk4"]
[Tue Aug 18 12:54:43.248840 2026] [security2:error] [pid 67073:tid 67327] [client 20.251.48.93:35105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/yj09.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6TgAAAo4"]
[Tue Aug 18 12:54:43.311614 2026] [security2:error] [pid 67073:tid 67127] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ae.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6UQACfDM"]
[Tue Aug 18 12:54:43.334524 2026] [security2:error] [pid 67073:tid 67223] [client 158.158.74.177:9863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/jquery.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6UgAAAiY"]
[Tue Aug 18 12:54:43.422092 2026] [authz_core:error] [pid 67073:tid 67153] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:43.422361 2026] [authz_core:error] [pid 67073:tid 67153] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:43.435390 2026] [security2:error] [pid 67073:tid 67205] [client 20.163.43.14:4319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6VQAAAhQ"]
[Tue Aug 18 12:54:43.477851 2026] [security2:error] [pid 67073:tid 67192] [remote 69.165.68.30:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.68.165.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metodomsd.sttudio.com.br"] [uri "/index.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6UAAChHQ"], referer: https://metodomsd.sttudio.com.br
[Tue Aug 18 12:54:43.500420 2026] [security2:error] [pid 66623:tid 66802] [client 20.51.153.15:9097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/dr.php"] [unique_id "aoSAQ9O5rbWdOArH04KBPQAAAS4"]
[Tue Aug 18 12:54:43.501776 2026] [security2:error] [pid 66623:tid 66712] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/link.php"] [unique_id "aoSAQ9O5rbWdOArH04KBPgABVEs"]
[Tue Aug 18 12:54:43.572850 2026] [security2:error] [pid 67073:tid 67287] [client 20.163.43.14:2016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6WAAAAmY"]
[Tue Aug 18 12:54:43.634392 2026] [security2:error] [pid 67073:tid 67285] [client 4.232.151.198:25814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/st.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6WQAAAmQ"]
[Tue Aug 18 12:54:43.639798 2026] [security2:error] [pid 67073:tid 67318] [client 172.182.200.96:14290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6WgAAAoU"]
[Tue Aug 18 12:54:43.828647 2026] [security2:error] [pid 66623:tid 66655] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/lite.php"] [unique_id "aoSAQ9O5rbWdOArH04KBPwABgxI"]
[Tue Aug 18 12:54:43.869241 2026] [security2:error] [pid 67073:tid 67282] [client 20.51.153.15:9090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ts.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6bgAAAmE"]
[Tue Aug 18 12:54:43.888149 2026] [security2:error] [pid 67073:tid 67330] [client 20.116.17.175:57639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/ab.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6bwAAApE"]
[Tue Aug 18 12:54:44.025052 2026] [authz_core:error] [pid 67073:tid 67174] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:44.025315 2026] [authz_core:error] [pid 67073:tid 67174] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:44.025322 2026] [security2:error] [pid 67073:tid 67247] [client 135.225.75.187:56868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/tmpls.php"] [unique_id "aoSARPcmepr5_nHgLbM6cQAAAj4"]
[Tue Aug 18 12:54:44.041274 2026] [security2:error] [pid 67073:tid 67249] [client 20.163.43.14:4341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSARPcmepr5_nHgLbM6cgAAAkA"]
[Tue Aug 18 12:54:44.072671 2026] [security2:error] [pid 67073:tid 67276] [client 172.182.200.96:13925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSARPcmepr5_nHgLbM6dAAAAls"]
[Tue Aug 18 12:54:44.079385 2026] [security2:error] [pid 67073:tid 67277] [client 20.171.51.14:58830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/rb.php"] [unique_id "aoSARPcmepr5_nHgLbM6dQAAAlw"]
[Tue Aug 18 12:54:44.109584 2026] [security2:error] [pid 67073:tid 67280] [client 20.104.100.201:21454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSARPcmepr5_nHgLbM6dwAAAl8"]
[Tue Aug 18 12:54:44.161656 2026] [security2:error] [pid 67073:tid 67286] [client 74.248.136.165:65253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/xda.php"] [unique_id "aoSARPcmepr5_nHgLbM6eAAAAmU"]
[Tue Aug 18 12:54:44.220068 2026] [security2:error] [pid 67073:tid 67295] [client 157.20.138.62:54881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSARPcmepr5_nHgLbM6egAAAm4"]
[Tue Aug 18 12:54:44.220209 2026] [security2:error] [pid 67073:tid 67295] [client 157.20.138.62:54881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSARPcmepr5_nHgLbM6egAAAm4"]
[Tue Aug 18 12:54:44.285421 2026] [security2:error] [pid 67073:tid 67231] [client 20.226.56.190:31621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/wy.php"] [unique_id "aoSARPcmepr5_nHgLbM6ewAAAi4"]
[Tue Aug 18 12:54:44.297820 2026] [security2:error] [pid 67073:tid 67216] [client 20.116.17.175:57660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/12.php"] [unique_id "aoSARPcmepr5_nHgLbM6fAAAAh8"]
[Tue Aug 18 12:54:44.324817 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:44.325075 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:44.372407 2026] [security2:error] [pid 66623:tid 66873] [client 20.42.19.40:2192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/test1.php"] [unique_id "aoSARNO5rbWdOArH04KBQQAAAXU"]
[Tue Aug 18 12:54:44.407837 2026] [security2:error] [pid 67073:tid 67233] [client 132.196.61.152:60999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/img.php"] [unique_id "aoSARPcmepr5_nHgLbM6gQAAAjA"]
[Tue Aug 18 12:54:44.550118 2026] [security2:error] [pid 67073:tid 67257] [client 20.118.172.148:7553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/profile.php"] [unique_id "aoSARPcmepr5_nHgLbM6iAAAAkg"]
[Tue Aug 18 12:54:44.566932 2026] [security2:error] [pid 66623:tid 66863] [client 196.12.128.158:58257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSARNO5rbWdOArH04KBQwAAAWs"]
[Tue Aug 18 12:54:44.567039 2026] [security2:error] [pid 66623:tid 66863] [client 196.12.128.158:58257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSARNO5rbWdOArH04KBQwAAAWs"]
[Tue Aug 18 12:54:44.627182 2026] [authz_core:error] [pid 67073:tid 67167] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:44.627447 2026] [authz_core:error] [pid 67073:tid 67167] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:44.640000 2026] [security2:error] [pid 67073:tid 67228] [client 74.248.136.165:34623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/zz.php"] [unique_id "aoSARPcmepr5_nHgLbM6iwAAAis"]
[Tue Aug 18 12:54:44.678374 2026] [security2:error] [pid 67073:tid 67290] [client 20.250.13.23:13662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSARPcmepr5_nHgLbM6jQAAAmk"]
[Tue Aug 18 12:54:44.707802 2026] [security2:error] [pid 66623:tid 66731] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/load.php"] [unique_id "aoSARNO5rbWdOArH04KBRQABLF4"]
[Tue Aug 18 12:54:44.745959 2026] [security2:error] [pid 67073:tid 67278] [client 68.155.155.199:19044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/file.php"] [unique_id "aoSARPcmepr5_nHgLbM6mwAAAl0"]
[Tue Aug 18 12:54:44.767071 2026] [security2:error] [pid 67073:tid 67222] [client 20.100.169.31:12407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/ncx.php"] [unique_id "aoSARPcmepr5_nHgLbM6nAAAAiU"]
[Tue Aug 18 12:54:44.809421 2026] [security2:error] [pid 67073:tid 67328] [client 157.51.166.53:55141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSARPcmepr5_nHgLbM6nQAAAo8"]
[Tue Aug 18 12:54:44.813017 2026] [security2:error] [pid 67073:tid 67217] [client 40.85.222.29:49286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSARPcmepr5_nHgLbM6ngAAAiA"]
[Tue Aug 18 12:54:44.813168 2026] [security2:error] [pid 67073:tid 67328] [client 157.51.166.53:55141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSARPcmepr5_nHgLbM6nQAAAo8"]
[Tue Aug 18 12:54:44.829965 2026] [security2:error] [pid 67073:tid 67327] [client 52.173.121.69:24825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSARPcmepr5_nHgLbM6nwAAAo4"]
[Tue Aug 18 12:54:44.914339 2026] [security2:error] [pid 67073:tid 67267] [client 20.104.85.180:8070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wicked.php"] [unique_id "aoSARPcmepr5_nHgLbM6oAAAAlI"]
[Tue Aug 18 12:54:44.917747 2026] [security2:error] [pid 67073:tid 67237] [client 4.232.151.198:25799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/subdom/ant/makeasmtp.php"] [unique_id "aoSARPcmepr5_nHgLbM6oQAAAjQ"]
[Tue Aug 18 12:54:45.034290 2026] [security2:error] [pid 66623:tid 66718] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/log.php"] [unique_id "aoSARdO5rbWdOArH04KBRgABGFE"]
[Tue Aug 18 12:54:45.034760 2026] [security2:error] [pid 66623:tid 66871] [client 20.118.172.148:8260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/sx.php"] [unique_id "aoSARdO5rbWdOArH04KBRwAAAXM"]
[Tue Aug 18 12:54:45.037588 2026] [security2:error] [pid 67073:tid 67297] [client 178.153.171.161:37026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSARfcmepr5_nHgLbM6vgAAAnA"]
[Tue Aug 18 12:54:45.037701 2026] [security2:error] [pid 67073:tid 67297] [client 178.153.171.161:37026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSARfcmepr5_nHgLbM6vgAAAnA"]
[Tue Aug 18 12:54:45.050453 2026] [security2:error] [pid 67073:tid 67320] [client 213.202.253.4:52385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/filefuns.php"] [unique_id "aoSARfcmepr5_nHgLbM6vwAAAoc"], referer: www.google.com
[Tue Aug 18 12:54:45.056661 2026] [security2:error] [pid 66623:tid 66789] [client 135.225.75.187:26505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/nzv.php"] [unique_id "aoSARdO5rbWdOArH04KBSAAAASE"]
[Tue Aug 18 12:54:45.069001 2026] [security2:error] [pid 66623:tid 66797] [client 213.35.127.232:50766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSARdO5rbWdOArH04KBSQAAASk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:45.104111 2026] [security2:error] [pid 67073:tid 67207] [client 20.42.19.40:2731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/zwso.php"] [unique_id "aoSARfcmepr5_nHgLbM6wAAAAhY"]
[Tue Aug 18 12:54:45.178345 2026] [security2:error] [pid 66623:tid 66891] [client 20.226.56.190:47130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/f.php"] [unique_id "aoSARdO5rbWdOArH04KBSgAAAYc"]
[Tue Aug 18 12:54:45.211972 2026] [security2:error] [pid 66623:tid 66836] [client 20.226.6.191:6640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/0x.php"] [unique_id "aoSARdO5rbWdOArH04KBSwAAAVA"]
[Tue Aug 18 12:54:45.252468 2026] [security2:error] [pid 66623:tid 66867] [client 20.104.85.180:8056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSARdO5rbWdOArH04KBTQAAAW8"]
[Tue Aug 18 12:54:45.306250 2026] [security2:error] [pid 66623:tid 66829] [client 172.202.39.151:21964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/akcc.php"] [unique_id "aoSARdO5rbWdOArH04KBUAAAAUk"]
[Tue Aug 18 12:54:45.360345 2026] [security2:error] [pid 66623:tid 66759] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/lufix.php"] [unique_id "aoSARdO5rbWdOArH04KBUQABQHo"]
[Tue Aug 18 12:54:45.369525 2026] [security2:error] [pid 67073:tid 67285] [client 132.196.61.152:61003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/aa.php"] [unique_id "aoSARfcmepr5_nHgLbM6xAAAAmQ"]
[Tue Aug 18 12:54:45.430995 2026] [authz_core:error] [pid 67073:tid 67165] [remote 57.141.22.123:64170] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:45.431290 2026] [authz_core:error] [pid 67073:tid 67165] [remote 57.141.22.123:64170] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:45.442127 2026] [security2:error] [pid 67073:tid 67246] [client 20.251.48.93:3001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/scxy.php"] [unique_id "aoSARfcmepr5_nHgLbM6yQAAAj0"]
[Tue Aug 18 12:54:45.451397 2026] [security2:error] [pid 67073:tid 67321] [client 20.42.19.40:2193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/Geforce.php"] [unique_id "aoSARfcmepr5_nHgLbM6ygAAAog"]
[Tue Aug 18 12:54:45.455731 2026] [security2:error] [pid 67073:tid 67271] [client 20.104.100.201:58484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/ccou.php"] [unique_id "aoSARfcmepr5_nHgLbM6ywAAAlY"]
[Tue Aug 18 12:54:45.545396 2026] [security2:error] [pid 67073:tid 67266] [client 172.182.200.96:14310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSARfcmepr5_nHgLbM60wAAAlE"]
[Tue Aug 18 12:54:45.575836 2026] [security2:error] [pid 67073:tid 67221] [client 20.226.6.191:6572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/zxz.php"] [unique_id "aoSARfcmepr5_nHgLbM61gAAAiQ"]
[Tue Aug 18 12:54:45.605542 2026] [security2:error] [pid 67073:tid 67312] [client 104.209.144.33:35868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/jrpga.php"] [unique_id "aoSARfcmepr5_nHgLbM62QAAAn8"]
[Tue Aug 18 12:54:45.642799 2026] [security2:error] [pid 67073:tid 67249] [client 20.104.85.180:8055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSARfcmepr5_nHgLbM62gAAAkA"]
[Tue Aug 18 12:54:45.676071 2026] [security2:error] [pid 66623:tid 66884] [client 74.248.136.165:31835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/xa.php"] [unique_id "aoSARdO5rbWdOArH04KBUwAAAYA"]
[Tue Aug 18 12:54:45.685111 2026] [security2:error] [pid 66623:tid 66762] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/ly.php"] [unique_id "aoSARdO5rbWdOArH04KBVAABGn0"]
[Tue Aug 18 12:54:45.714271 2026] [security2:error] [pid 66623:tid 66783] [client 20.104.85.180:43542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSARdO5rbWdOArH04KBVQAAARs"]
[Tue Aug 18 12:54:45.785668 2026] [security2:error] [pid 67073:tid 67277] [client 20.104.100.201:58918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/crgio.php"] [unique_id "aoSARfcmepr5_nHgLbM63AAAAlw"]
[Tue Aug 18 12:54:45.799332 2026] [security2:error] [pid 67073:tid 67280] [client 20.226.56.190:3063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/30.php"] [unique_id "aoSARfcmepr5_nHgLbM63QAAAl8"]
[Tue Aug 18 12:54:45.835327 2026] [authz_core:error] [pid 67073:tid 67156] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:45.835782 2026] [authz_core:error] [pid 67073:tid 67156] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:45.955561 2026] [security2:error] [pid 67073:tid 67311] [client 172.182.200.96:14219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSARfcmepr5_nHgLbM66gAAAn4"]
[Tue Aug 18 12:54:45.975836 2026] [security2:error] [pid 67073:tid 67316] [client 20.250.27.191:1872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSARfcmepr5_nHgLbM66wAAAoM"]
[Tue Aug 18 12:54:45.995441 2026] [security2:error] [pid 67073:tid 67264] [client 20.116.17.175:57620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/x1da.php"] [unique_id "aoSARfcmepr5_nHgLbM67QAAAk8"]
[Tue Aug 18 12:54:46.011993 2026] [security2:error] [pid 67073:tid 67250] [client 20.104.85.180:7948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/cah.php"] [unique_id "aoSARvcmepr5_nHgLbM67gAAAkE"]
[Tue Aug 18 12:54:46.066387 2026] [security2:error] [pid 67073:tid 67240] [client 172.202.39.151:61344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-login.php"] [unique_id "aoSAQvcmepr5_nHgLbM6RQAAAjc"]
[Tue Aug 18 12:54:46.104700 2026] [security2:error] [pid 67073:tid 67319] [client 68.155.155.199:8325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/adminfuns.php"] [unique_id "aoSARvcmepr5_nHgLbM68wAAAoY"]
[Tue Aug 18 12:54:46.131759 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:46.132018 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:46.184808 2026] [security2:error] [pid 67073:tid 67248] [client 52.238.210.254:8833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSARvcmepr5_nHgLbM69QAAAj8"]
[Tue Aug 18 12:54:46.316955 2026] [security2:error] [pid 67073:tid 67256] [client 40.85.222.29:25817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSARvcmepr5_nHgLbM69wAAAkc"]
[Tue Aug 18 12:54:46.342670 2026] [security2:error] [pid 67073:tid 67331] [client 20.65.98.162:44172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/coffexium.php"] [unique_id "aoSARvcmepr5_nHgLbM6-AAAApI"]
[Tue Aug 18 12:54:46.351767 2026] [security2:error] [pid 67073:tid 67228] [client 132.196.61.152:27273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/nano.php"] [unique_id "aoSARvcmepr5_nHgLbM6-QAAAis"]
[Tue Aug 18 12:54:46.564901 2026] [security2:error] [pid 66623:tid 66640] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/m.php"] [unique_id "aoSARtO5rbWdOArH04KBWwABMwM"]
[Tue Aug 18 12:54:46.638381 2026] [security2:error] [pid 67073:tid 67309] [client 172.202.39.151:50214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/about.php"] [unique_id "aoSARvcmepr5_nHgLbM6_wAAAnw"]
[Tue Aug 18 12:54:46.662795 2026] [security2:error] [pid 67073:tid 67239] [client 52.173.121.69:51810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSARvcmepr5_nHgLbM7AAAAAjY"]
[Tue Aug 18 12:54:46.670385 2026] [security2:error] [pid 66623:tid 66792] [client 160.120.140.123:56207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSARtO5rbWdOArH04KBXgAAASQ"]
[Tue Aug 18 12:54:46.670479 2026] [security2:error] [pid 66623:tid 66792] [client 160.120.140.123:56207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSARtO5rbWdOArH04KBXgAAASQ"]
[Tue Aug 18 12:54:46.766049 2026] [security2:error] [pid 67073:tid 67212] [client 20.42.19.40:2746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/fpwch.php"] [unique_id "aoSARvcmepr5_nHgLbM7BAAAAhs"]
[Tue Aug 18 12:54:46.824712 2026] [security2:error] [pid 67073:tid 67320] [client 172.182.200.96:14268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSARvcmepr5_nHgLbM7JQAAAoc"]
[Tue Aug 18 12:54:46.850548 2026] [security2:error] [pid 67073:tid 67317] [client 20.116.17.175:57605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/mcs.php"] [unique_id "aoSARvcmepr5_nHgLbM7JgAAAoQ"]
[Tue Aug 18 12:54:46.922030 2026] [security2:error] [pid 67073:tid 67210] [client 104.209.144.33:39304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/museu/yhweq.php"] [unique_id "aoSARvcmepr5_nHgLbM7KQAAAhk"]
[Tue Aug 18 12:54:46.959682 2026] [security2:error] [pid 67073:tid 67232] [client 135.225.75.187:23923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/error1.php"] [unique_id "aoSARvcmepr5_nHgLbM7KgAAAi8"]
[Tue Aug 18 12:54:46.966475 2026] [security2:error] [pid 67073:tid 67205] [client 74.248.133.44:31783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/simple.php"] [unique_id "aoSARvcmepr5_nHgLbM7KwAAAhQ"]
[Tue Aug 18 12:54:46.969863 2026] [security2:error] [pid 67073:tid 67218] [client 20.91.215.254:20579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/nw.php"] [unique_id "aoSARvcmepr5_nHgLbM7LAAAAiE"]
[Tue Aug 18 12:54:47.012729 2026] [security2:error] [pid 67073:tid 67308] [client 114.119.158.251:20191] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arruelasdobrasil.com.br"] [uri "/pt/galeria-de-fotos"] [unique_id "aoSAR_cmepr5_nHgLbM7LwAAAns"], referer: http://www.arruelasdobrasil.com.br/pt/galeria-de-fotos?func=detail&id=6
[Tue Aug 18 12:54:47.032758 2026] [security2:error] [pid 67073:tid 67246] [client 172.202.39.151:39997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wk/index.php"] [unique_id "aoSAR_cmepr5_nHgLbM7MQAAAj0"]
[Tue Aug 18 12:54:47.057072 2026] [security2:error] [pid 67073:tid 67304] [client 20.42.19.40:9690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/admin.php"] [unique_id "aoSAR_cmepr5_nHgLbM7MgAAAnc"]
[Tue Aug 18 12:54:47.070277 2026] [security2:error] [pid 67073:tid 67321] [client 52.173.121.69:17963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSAR_cmepr5_nHgLbM7MwAAAog"]
[Tue Aug 18 12:54:47.073100 2026] [security2:error] [pid 67073:tid 67271] [client 20.42.19.40:2714] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/mini"] [unique_id "aoSAR_cmepr5_nHgLbM7NAAAAlY"]
[Tue Aug 18 12:54:47.079268 2026] [security2:error] [pid 67073:tid 67261] [client 20.104.85.180:7042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSAR_cmepr5_nHgLbM7NQAAAkw"]
[Tue Aug 18 12:54:47.127651 2026] [security2:error] [pid 66623:tid 66848] [client 20.104.100.201:21475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSAR9O5rbWdOArH04KBZgAAAVw"]
[Tue Aug 18 12:54:47.176389 2026] [security2:error] [pid 67073:tid 67299] [client 40.85.222.29:25446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/images/security.php"] [unique_id "aoSAR_cmepr5_nHgLbM7NwAAAnI"]
[Tue Aug 18 12:54:47.334314 2026] [security2:error] [pid 67073:tid 67276] [client 172.202.39.151:29741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAR_cmepr5_nHgLbM7PAAAAls"]
[Tue Aug 18 12:54:47.334856 2026] [authz_core:error] [pid 67073:tid 67195] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:47.335124 2026] [authz_core:error] [pid 67073:tid 67195] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:47.408780 2026] [security2:error] [pid 67073:tid 67251] [client 52.173.121.69:59784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSAR_cmepr5_nHgLbM7PQAAAkI"]
[Tue Aug 18 12:54:47.434644 2026] [security2:error] [pid 66623:tid 66852] [client 20.42.19.40:2737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-blog-header.php"] [unique_id "aoSAR9O5rbWdOArH04KBaQAAAWA"]
[Tue Aug 18 12:54:47.464734 2026] [security2:error] [pid 66623:tid 66764] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/m57.php"] [unique_id "aoSAR9O5rbWdOArH04KBawABaH8"]
[Tue Aug 18 12:54:47.476962 2026] [security2:error] [pid 67073:tid 67301] [client 52.139.47.57:9025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/nij.php"] [unique_id "aoSAR_cmepr5_nHgLbM7PgAAAnQ"]
[Tue Aug 18 12:54:47.581887 2026] [security2:error] [pid 66623:tid 66838] [client 132.196.61.152:60293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/av.php"] [unique_id "aoSAR9O5rbWdOArH04KBbAAAAVI"]
[Tue Aug 18 12:54:47.587360 2026] [security2:error] [pid 67073:tid 67220] [client 4.232.151.198:25829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/system.php"] [unique_id "aoSAR_cmepr5_nHgLbM7PwAAAiM"]
[Tue Aug 18 12:54:47.689251 2026] [security2:error] [pid 67073:tid 67231] [client 172.182.200.96:14096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSAR_cmepr5_nHgLbM7QQAAAi4"]
[Tue Aug 18 12:54:47.766251 2026] [security2:error] [pid 67073:tid 67298] [client 20.42.19.40:2901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/about/function.php"] [unique_id "aoSAR_cmepr5_nHgLbM7QgAAAnE"]
[Tue Aug 18 12:54:47.779843 2026] [security2:error] [pid 67073:tid 67233] [client 68.155.155.199:19241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/aa.php"] [unique_id "aoSAR_cmepr5_nHgLbM7QwAAAjA"]
[Tue Aug 18 12:54:47.790625 2026] [security2:error] [pid 66623:tid 66644] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/mac.php"] [unique_id "aoSAR9O5rbWdOArH04KBbwABIwc"]
[Tue Aug 18 12:54:47.820349 2026] [security2:error] [pid 67073:tid 67226] [client 74.248.18.37:37726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/manager.php"] [unique_id "aoSAR_cmepr5_nHgLbM7RQAAAik"]
[Tue Aug 18 12:54:47.991438 2026] [security2:error] [pid 67073:tid 67224] [client 52.139.47.57:42966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/404.php"] [unique_id "aoSAR_cmepr5_nHgLbM7SQAAAic"]
[Tue Aug 18 12:54:48.012944 2026] [security2:error] [pid 66623:tid 66775] [client 20.100.169.31:24479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSASNO5rbWdOArH04KBeAAAARM"]
[Tue Aug 18 12:54:48.035432 2026] [security2:error] [pid 67073:tid 67227] [client 20.250.13.23:14179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/222.php"] [unique_id "aoSASPcmepr5_nHgLbM7SgAAAio"]
[Tue Aug 18 12:54:48.105941 2026] [security2:error] [pid 67073:tid 67263] [client 135.225.75.187:40054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/155.php"] [unique_id "aoSASPcmepr5_nHgLbM7SwAAAk4"]
[Tue Aug 18 12:54:48.154616 2026] [security2:error] [pid 66623:tid 66821] [client 20.251.48.93:21325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSASNO5rbWdOArH04KBeQAAAUE"]
[Tue Aug 18 12:54:48.171455 2026] [security2:error] [pid 67073:tid 67217] [client 20.42.19.40:2887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/function/function.php"] [unique_id "aoSASPcmepr5_nHgLbM7TQAAAiA"]
[Tue Aug 18 12:54:48.237575 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:48.237842 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:48.371657 2026] [security2:error] [pid 66623:tid 66833] [client 20.42.19.40:9727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/edit.php"] [unique_id "aoSASNO5rbWdOArH04KBewAAAU0"]
[Tue Aug 18 12:54:48.431271 2026] [security2:error] [pid 67073:tid 67237] [client 20.205.121.237:4103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/tmpls.php"] [unique_id "aoSASPcmepr5_nHgLbM7UgAAAjQ"]
[Tue Aug 18 12:54:48.450271 2026] [autoindex:error] [pid 67073:tid 67325] [client 20.104.85.180:8026] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/js/tinymce/plugins/compat3x/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:48.473461 2026] [security2:error] [pid 67073:tid 67206] [client 20.104.100.201:58441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/css.php"] [unique_id "aoSASPcmepr5_nHgLbM7VAAAAhU"]
[Tue Aug 18 12:54:48.507332 2026] [security2:error] [pid 66623:tid 66785] [client 103.120.71.157:62594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSASNO5rbWdOArH04KBfAAAAR0"]
[Tue Aug 18 12:54:48.507444 2026] [security2:error] [pid 66623:tid 66785] [client 103.120.71.157:62594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSASNO5rbWdOArH04KBfAAAAR0"]
[Tue Aug 18 12:54:48.507618 2026] [security2:error] [pid 67073:tid 67293] [client 20.91.215.254:24333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSASPcmepr5_nHgLbM7VQAAAmw"]
[Tue Aug 18 12:54:48.507643 2026] [security2:error] [pid 66623:tid 66768] [client 20.42.19.40:2695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-signin.php"] [unique_id "aoSASNO5rbWdOArH04KBfQAAAQw"]
[Tue Aug 18 12:54:48.590959 2026] [security2:error] [pid 67073:tid 67285] [client 52.173.121.69:47384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSASPcmepr5_nHgLbM7VwAAAmQ"]
[Tue Aug 18 12:54:48.677570 2026] [security2:error] [pid 66623:tid 66656] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/mah.php"] [unique_id "aoSASNO5rbWdOArH04KBgwABFhM"]
[Tue Aug 18 12:54:48.794594 2026] [security2:error] [pid 67073:tid 67260] [client 20.104.85.180:8026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/system_log.php"] [unique_id "aoSASPcmepr5_nHgLbM7WwAAAks"]
[Tue Aug 18 12:54:48.813043 2026] [security2:error] [pid 67073:tid 67246] [client 20.104.100.201:58475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSASPcmepr5_nHgLbM7XAAAAj0"]
[Tue Aug 18 12:54:48.852023 2026] [security2:error] [pid 66623:tid 66794] [client 20.226.6.191:6597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/www.php"] [unique_id "aoSASNO5rbWdOArH04KBhgAAASY"]
[Tue Aug 18 12:54:48.906655 2026] [security2:error] [pid 66623:tid 66843] [client 20.151.109.219:61379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/sn.php"] [unique_id "aoSASNO5rbWdOArH04KBhwAAAVc"]
[Tue Aug 18 12:54:48.914737 2026] [security2:error] [pid 66623:tid 66847] [client 20.171.51.14:62478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/zj.php"] [unique_id "aoSASNO5rbWdOArH04KBiAAAAVs"]
[Tue Aug 18 12:54:49.004828 2026] [security2:error] [pid 66623:tid 66736] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSASdO5rbWdOArH04KBiQABhmM"]
[Tue Aug 18 12:54:49.007649 2026] [security2:error] [pid 66623:tid 66781] [client 20.116.17.175:57645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/adminner.php"] [unique_id "aoSASdO5rbWdOArH04KBigAAARk"]
[Tue Aug 18 12:54:49.049165 2026] [security2:error] [pid 67073:tid 67255] [client 20.226.56.190:23769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/pu.php"] [unique_id "aoSASfcmepr5_nHgLbM7XgAAAkY"]
[Tue Aug 18 12:54:49.094335 2026] [security2:error] [pid 67073:tid 67262] [client 20.42.19.40:9606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/w.php"] [unique_id "aoSASfcmepr5_nHgLbM7XwAAAk0"]
[Tue Aug 18 12:54:49.155352 2026] [security2:error] [pid 67073:tid 67289] [client 20.104.100.201:21487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/epinyins.php"] [unique_id "aoSASfcmepr5_nHgLbM7YQAAAmg"]
[Tue Aug 18 12:54:49.307562 2026] [security2:error] [pid 67073:tid 67251] [client 135.225.75.187:58042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/fasx.php"] [unique_id "aoSASfcmepr5_nHgLbM7YwAAAkI"]
[Tue Aug 18 12:54:49.319792 2026] [security2:error] [pid 66623:tid 66776] [client 213.35.127.232:51164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSASdO5rbWdOArH04KBjAAAARQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:49.334956 2026] [security2:error] [pid 66623:tid 66662] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/manager.php"] [unique_id "aoSASdO5rbWdOArH04KBjQABPBk"]
[Tue Aug 18 12:54:49.426674 2026] [security2:error] [pid 66623:tid 66871] [client 20.42.19.40:9723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/file.php"] [unique_id "aoSASdO5rbWdOArH04KBjwAAAXM"]
[Tue Aug 18 12:54:49.496083 2026] [security2:error] [pid 67073:tid 67264] [client 132.196.61.152:60297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/media.php"] [unique_id "aoSASfcmepr5_nHgLbM7ZQAAAk8"]
[Tue Aug 18 12:54:49.497100 2026] [security2:error] [pid 67073:tid 67324] [client 74.248.136.165:41202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/f6.php"] [unique_id "aoSASfcmepr5_nHgLbM7ZgAAAos"]
[Tue Aug 18 12:54:49.583244 2026] [security2:error] [pid 66623:tid 66797] [client 20.91.215.254:20563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSASdO5rbWdOArH04KBkQAAASk"]
[Tue Aug 18 12:54:49.595003 2026] [security2:error] [pid 67073:tid 67240] [client 20.171.51.14:57366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/x.php"] [unique_id "aoSASfcmepr5_nHgLbM7ZwAAAjc"]
[Tue Aug 18 12:54:49.637682 2026] [security2:error] [pid 67073:tid 67310] [client 52.139.47.57:63076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/mah.php"] [unique_id "aoSASfcmepr5_nHgLbM7aAAAAn0"]
[Tue Aug 18 12:54:49.672911 2026] [security2:error] [pid 67073:tid 67234] [client 68.155.154.236:63323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/images/security.php"] [unique_id "aoSASfcmepr5_nHgLbM7bgAAAjE"]
[Tue Aug 18 12:54:49.711650 2026] [security2:error] [pid 67073:tid 67222] [client 197.184.64.235:41920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSASfcmepr5_nHgLbM7cAAAAiU"]
[Tue Aug 18 12:54:49.711763 2026] [security2:error] [pid 67073:tid 67222] [client 197.184.64.235:41920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSASfcmepr5_nHgLbM7cAAAAiU"]
[Tue Aug 18 12:54:49.745253 2026] [security2:error] [pid 67073:tid 67303] [client 20.42.19.40:9680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/adminfuns.php"] [unique_id "aoSASfcmepr5_nHgLbM7cwAAAnY"]
[Tue Aug 18 12:54:49.767107 2026] [security2:error] [pid 67073:tid 67250] [client 4.223.164.152:37306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/ccc.php"] [unique_id "aoSASfcmepr5_nHgLbM7dAAAAkE"]
[Tue Aug 18 12:54:49.851828 2026] [security2:error] [pid 67073:tid 67261] [client 116.179.37.120:30090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSASfcmepr5_nHgLbM7dgAAAkw"], referer: https://plenitude.com.br/como-conquistar-felicidade-em-sua-vida/
[Tue Aug 18 12:54:49.885926 2026] [security2:error] [pid 67073:tid 67146] [remote 192.250.235.185:38510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.235.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qriarfood.com"] [uri "/wp-login.php"] [unique_id "aoSARvcmepr5_nHgLbM7KAACXkY"]
[Tue Aug 18 12:54:49.923780 2026] [security2:error] [pid 67073:tid 67228] [client 74.248.136.165:31899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/mcs.php"] [unique_id "aoSASfcmepr5_nHgLbM7dwAAAis"]
[Tue Aug 18 12:54:49.936781 2026] [security2:error] [pid 67073:tid 67300] [client 20.251.48.93:35110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSASfcmepr5_nHgLbM7eAAAAnM"]
[Tue Aug 18 12:54:49.998987 2026] [authz_core:error] [pid 66623:tid 66721] [remote 57.141.22.116:54256] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:49.999239 2026] [authz_core:error] [pid 66623:tid 66721] [remote 57.141.22.116:54256] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:50.047122 2026] [security2:error] [pid 67073:tid 67278] [client 20.42.19.40:9675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/aa.php"] [unique_id "aoSASvcmepr5_nHgLbM7fQAAAl0"]
[Tue Aug 18 12:54:50.109642 2026] [security2:error] [pid 66623:tid 66780] [client 192.141.172.134:55322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAStO5rbWdOArH04KBlAAAARg"]
[Tue Aug 18 12:54:50.109812 2026] [security2:error] [pid 66623:tid 66780] [client 192.141.172.134:55322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAStO5rbWdOArH04KBlAAAARg"]
[Tue Aug 18 12:54:50.183536 2026] [autoindex:error] [pid 67073:tid 67272] [client 20.104.85.180:8010] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:50.214390 2026] [security2:error] [pid 66623:tid 66689] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/mar.php"] [unique_id "aoSAStO5rbWdOArH04KBlgABdjQ"]
[Tue Aug 18 12:54:50.278755 2026] [security2:error] [pid 67073:tid 67257] [client 52.173.121.69:57999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSASvcmepr5_nHgLbM7mQAAAkg"]
[Tue Aug 18 12:54:50.310428 2026] [security2:error] [pid 66623:tid 66862] [client 4.232.151.198:6791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/system_log.php"] [unique_id "aoSAStO5rbWdOArH04KBmAAAAWo"]
[Tue Aug 18 12:54:50.345363 2026] [security2:error] [pid 67073:tid 67290] [client 52.173.121.69:17964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSASvcmepr5_nHgLbM7mgAAAmk"]
[Tue Aug 18 12:54:50.376011 2026] [security2:error] [pid 66623:tid 66830] [client 20.42.19.40:9610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/classwithtostring.php"] [unique_id "aoSAStO5rbWdOArH04KBmQAAAUo"]
[Tue Aug 18 12:54:50.401574 2026] [security2:error] [pid 66623:tid 66858] [client 20.226.56.190:20388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ry.php"] [unique_id "aoSAStO5rbWdOArH04KBmgAAAWY"]
[Tue Aug 18 12:54:50.407864 2026] [security2:error] [pid 67073:tid 67227] [client 138.36.100.162:41861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSASvcmepr5_nHgLbM7mwAAAio"]
[Tue Aug 18 12:54:50.408015 2026] [security2:error] [pid 67073:tid 67227] [client 138.36.100.162:41861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSASvcmepr5_nHgLbM7mwAAAio"]
[Tue Aug 18 12:54:50.452731 2026] [security2:error] [pid 67073:tid 67292] [client 20.104.85.180:43579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/k.php"] [unique_id "aoSASvcmepr5_nHgLbM7nAAAAms"]
[Tue Aug 18 12:54:50.491122 2026] [authz_core:error] [pid 67073:tid 67198] [remote 57.141.22.34:38912] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:50.491557 2026] [authz_core:error] [pid 67073:tid 67198] [remote 57.141.22.34:38912] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:50.513355 2026] [security2:error] [pid 66623:tid 66798] [client 103.184.169.37:41431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAStO5rbWdOArH04KBmwAAASo"]
[Tue Aug 18 12:54:50.513478 2026] [security2:error] [pid 66623:tid 66798] [client 103.184.169.37:41431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAStO5rbWdOArH04KBmwAAASo"]
[Tue Aug 18 12:54:50.540523 2026] [security2:error] [pid 66623:tid 66658] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/maxro.php"] [unique_id "aoSAStO5rbWdOArH04KBnAABORU"]
[Tue Aug 18 12:54:50.554500 2026] [security2:error] [pid 67073:tid 67293] [client 20.163.43.14:3166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSASvcmepr5_nHgLbM7oAAAAmw"]
[Tue Aug 18 12:54:50.557280 2026] [security2:error] [pid 66623:tid 66783] [client 20.205.121.237:4114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/tool.php"] [unique_id "aoSAStO5rbWdOArH04KBnQAAARs"]
[Tue Aug 18 12:54:50.596688 2026] [security2:error] [pid 66623:tid 66882] [client 52.238.210.254:8899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/xmr.php"] [unique_id "aoSAStO5rbWdOArH04KBngAAAX4"]
[Tue Aug 18 12:54:50.724176 2026] [security2:error] [pid 67073:tid 67277] [client 172.182.200.96:13949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/rezor.php"] [unique_id "aoSASvcmepr5_nHgLbM7qAAAAlw"]
[Tue Aug 18 12:54:50.748494 2026] [security2:error] [pid 67073:tid 67282] [client 20.226.6.191:6579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wicked.php"] [unique_id "aoSASvcmepr5_nHgLbM7qQAAAmE"]
[Tue Aug 18 12:54:50.785606 2026] [security2:error] [pid 66623:tid 66795] [client 20.226.56.190:3047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/pm.php"] [unique_id "aoSAStO5rbWdOArH04KBoQAAASc"]
[Tue Aug 18 12:54:50.787445 2026] [security2:error] [pid 66623:tid 66825] [client 52.139.47.57:27942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/ws.php7"] [unique_id "aoSAStO5rbWdOArH04KBogAAAUU"]
[Tue Aug 18 12:54:50.797202 2026] [security2:error] [pid 67073:tid 67212] [client 74.248.133.44:35822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/berax.php"] [unique_id "aoSASvcmepr5_nHgLbM7qgAAAhs"]
[Tue Aug 18 12:54:50.803548 2026] [security2:error] [pid 66623:tid 66807] [client 20.104.100.201:58468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/load.php"] [unique_id "aoSAStO5rbWdOArH04KBowAAATM"]
[Tue Aug 18 12:54:50.806695 2026] [security2:error] [pid 66623:tid 66824] [client 20.171.51.14:16733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/yn.php"] [unique_id "aoSAStO5rbWdOArH04KBpQAAAUQ"]
[Tue Aug 18 12:54:50.866387 2026] [security2:error] [pid 66623:tid 66681] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/mds.php"] [unique_id "aoSAStO5rbWdOArH04KBpwABOiw"]
[Tue Aug 18 12:54:50.888895 2026] [security2:error] [pid 66623:tid 66859] [client 20.151.109.219:12872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/43.php"] [unique_id "aoSAStO5rbWdOArH04KBqAAAAWc"]
[Tue Aug 18 12:54:50.893515 2026] [security2:error] [pid 67073:tid 67275] [client 20.91.215.254:24341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSASvcmepr5_nHgLbM7rAAAAlo"]
[Tue Aug 18 12:54:50.923315 2026] [security2:error] [pid 67073:tid 67318] [client 74.248.18.37:48252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/w1.php"] [unique_id "aoSASvcmepr5_nHgLbM7rQAAAoU"]
[Tue Aug 18 12:54:50.951397 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:50.951671 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:50.986540 2026] [security2:error] [pid 67073:tid 67312] [client 74.248.136.165:9418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/mcs.php"] [unique_id "aoSASvcmepr5_nHgLbM7uwAAAn8"]
[Tue Aug 18 12:54:51.006541 2026] [security2:error] [pid 67073:tid 67247] [client 20.104.85.180:8010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAS_cmepr5_nHgLbM7vAAAAj4"]
[Tue Aug 18 12:54:51.009785 2026] [security2:error] [pid 67073:tid 67289] [client 20.163.43.14:3152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAS_cmepr5_nHgLbM7vQAAAmg"]
[Tue Aug 18 12:54:51.078732 2026] [security2:error] [pid 67073:tid 67283] [client 104.209.144.33:21427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/nwwha.php"] [unique_id "aoSAS_cmepr5_nHgLbM7vwAAAmI"]
[Tue Aug 18 12:54:51.111646 2026] [security2:error] [pid 67073:tid 67280] [client 172.182.200.96:14327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSAS_cmepr5_nHgLbM7wQAAAl8"]
[Tue Aug 18 12:54:51.139996 2026] [security2:error] [pid 67073:tid 67301] [client 20.104.100.201:58455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSAS_cmepr5_nHgLbM7wgAAAnQ"]
[Tue Aug 18 12:54:51.198209 2026] [security2:error] [pid 66623:tid 66691] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/media.php"] [unique_id "aoSAS9O5rbWdOArH04KBqwABezY"]
[Tue Aug 18 12:54:51.230133 2026] [security2:error] [pid 67073:tid 67316] [client 20.51.153.15:9121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/you.php"] [unique_id "aoSAS_cmepr5_nHgLbM7xAAAAoM"]
[Tue Aug 18 12:54:51.241676 2026] [security2:error] [pid 66623:tid 66848] [client 20.151.109.219:53215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/fresh.php"] [unique_id "aoSAS9O5rbWdOArH04KBrAAAAVw"]
[Tue Aug 18 12:54:51.294382 2026] [security2:error] [pid 66623:tid 66880] [client 4.223.164.152:46156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/get.php"] [unique_id "aoSAS9O5rbWdOArH04KBrgAAAXw"]
[Tue Aug 18 12:54:51.294396 2026] [security2:error] [pid 66623:tid 66724] [remote 103.56.163.133:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ondaseventos.com"] [uri "/wp-login.php"] [unique_id "aoSAS9O5rbWdOArH04KBrQABTlc"]
[Tue Aug 18 12:54:51.358945 2026] [security2:error] [pid 66623:tid 66809] [client 172.202.39.151:16163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wso.php"] [unique_id "aoSAS9O5rbWdOArH04KBrwAAATU"]
[Tue Aug 18 12:54:51.417563 2026] [security2:error] [pid 66623:tid 66852] [client 52.139.47.57:27934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/as.php"] [unique_id "aoSAS9O5rbWdOArH04KBsAAAAWA"]
[Tue Aug 18 12:54:51.460912 2026] [security2:error] [pid 66623:tid 66767] [client 74.248.136.165:35196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/xleet.php"] [unique_id "aoSAS9O5rbWdOArH04KBsQAAAQs"]
[Tue Aug 18 12:54:51.470095 2026] [security2:error] [pid 66623:tid 66869] [client 20.65.98.162:38033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/dex.php"] [unique_id "aoSAS9O5rbWdOArH04KBsgAAAXE"]
[Tue Aug 18 12:54:51.492438 2026] [security2:error] [pid 67073:tid 67222] [client 52.238.210.254:8957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/about.php"] [unique_id "aoSAS_cmepr5_nHgLbM72wAAAiU"]
[Tue Aug 18 12:54:51.502618 2026] [security2:error] [pid 67073:tid 67319] [client 116.179.37.220:34894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSASvcmepr5_nHgLbM7nQAAAoY"], referer: https://plenitude.com.br/como-conquistar-felicidade-em-sua-vida/
[Tue Aug 18 12:54:51.519311 2026] [security2:error] [pid 67073:tid 67208] [client 20.226.56.190:30992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/dr.php"] [unique_id "aoSAS_cmepr5_nHgLbM73QAAAhc"]
[Tue Aug 18 12:54:51.616048 2026] [security2:error] [pid 66623:tid 66878] [client 132.196.61.152:60291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/images.php"] [unique_id "aoSAS9O5rbWdOArH04KBtAAAAXo"]
[Tue Aug 18 12:54:51.623328 2026] [security2:error] [pid 66623:tid 66864] [client 20.91.215.254:20544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/f7.php"] [unique_id "aoSAS9O5rbWdOArH04KBtQAAAWw"]
[Tue Aug 18 12:54:51.741094 2026] [security2:error] [pid 66623:tid 66822] [client 20.250.13.23:14157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSAS9O5rbWdOArH04KBtgAAAUI"]
[Tue Aug 18 12:54:51.815614 2026] [security2:error] [pid 67073:tid 67278] [client 20.104.85.180:7973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAS_cmepr5_nHgLbM74QAAAl0"]
[Tue Aug 18 12:54:51.815614 2026] [security2:error] [pid 66623:tid 66883] [client 213.202.253.4:57993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/wp-content/postnews.php"] [unique_id "aoSAS9O5rbWdOArH04KBtwAAAX8"], referer: www.google.com
[Tue Aug 18 12:54:51.870761 2026] [security2:error] [pid 67073:tid 67230] [client 20.251.48.93:20719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/blurbs.php"] [unique_id "aoSAS_cmepr5_nHgLbM74wAAAi0"]
[Tue Aug 18 12:54:51.949376 2026] [security2:error] [pid 67073:tid 67215] [client 74.248.136.165:31815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/fr/ms.php"] [unique_id "aoSAS_cmepr5_nHgLbM75QAAAh4"]
[Tue Aug 18 12:54:51.990540 2026] [security2:error] [pid 67073:tid 67309] [client 172.202.39.151:42979] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "loja1.queroficarnanet.com"] [uri "/1.php"] [unique_id "aoSAS_cmepr5_nHgLbM76AAAAnw"]
[Tue Aug 18 12:54:51.990645 2026] [security2:error] [pid 67073:tid 67309] [client 172.202.39.151:42979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/1.php"] [unique_id "aoSAS_cmepr5_nHgLbM76AAAAnw"]
[Tue Aug 18 12:54:52.023015 2026] [security2:error] [pid 67073:tid 67239] [client 172.182.200.96:14279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSATPcmepr5_nHgLbM76QAAAjY"]
[Tue Aug 18 12:54:52.051474 2026] [security2:error] [pid 67073:tid 67267] [client 20.226.56.190:31632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ts.php"] [unique_id "aoSATPcmepr5_nHgLbM76gAAAlI"]
[Tue Aug 18 12:54:52.160513 2026] [authz_core:error] [pid 67073:tid 67156] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:52.160782 2026] [authz_core:error] [pid 67073:tid 67156] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:52.161496 2026] [security2:error] [pid 67073:tid 67243] [client 172.202.39.151:30490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/sf.php"] [unique_id "aoSATPcmepr5_nHgLbM78AAAAjo"]
[Tue Aug 18 12:54:52.282254 2026] [security2:error] [pid 66623:tid 66806] [client 20.226.56.190:20367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/53.php"] [unique_id "aoSATNO5rbWdOArH04KBvQAAATI"]
[Tue Aug 18 12:54:52.350237 2026] [security2:error] [pid 67073:tid 67297] [client 20.91.215.254:20560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/photo.php"] [unique_id "aoSATPcmepr5_nHgLbM79QAAAnA"]
[Tue Aug 18 12:54:52.443531 2026] [security2:error] [pid 67073:tid 67285] [client 20.163.43.14:3113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/file.php"] [unique_id "aoSATPcmepr5_nHgLbM79gAAAmQ"]
[Tue Aug 18 12:54:52.498148 2026] [security2:error] [pid 67073:tid 67321] [client 52.173.121.69:24793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSATPcmepr5_nHgLbM79wAAAog"]
[Tue Aug 18 12:54:52.535154 2026] [security2:error] [pid 67073:tid 67205] [client 20.163.43.14:4288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/admin.php"] [unique_id "aoSATPcmepr5_nHgLbM7-AAAAhQ"]
[Tue Aug 18 12:54:52.698123 2026] [security2:error] [pid 67073:tid 67323] [client 20.171.51.14:65091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/11.php"] [unique_id "aoSATPcmepr5_nHgLbM8AAAAAoo"]
[Tue Aug 18 12:54:52.704579 2026] [security2:error] [pid 66623:tid 66876] [client 5.31.227.224:7823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAStO5rbWdOArH04KBoAAAAXg"]
[Tue Aug 18 12:54:52.704744 2026] [security2:error] [pid 66623:tid 66876] [client 5.31.227.224:7823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAStO5rbWdOArH04KBoAAAAXg"]
[Tue Aug 18 12:54:52.706113 2026] [security2:error] [pid 67073:tid 67275] [client 52.238.210.254:9008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/file2.php"] [unique_id "aoSATPcmepr5_nHgLbM8AQAAAlo"]
[Tue Aug 18 12:54:52.755035 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:52.755304 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:52.818937 2026] [security2:error] [pid 66623:tid 66794] [client 20.226.6.191:6598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSATNO5rbWdOArH04KBwAAAASY"]
[Tue Aug 18 12:54:52.847686 2026] [security2:error] [pid 66623:tid 66851] [client 20.51.153.15:9094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ez.php"] [unique_id "aoSATNO5rbWdOArH04KBwQAAAV8"]
[Tue Aug 18 12:54:52.853082 2026] [security2:error] [pid 67073:tid 67247] [client 68.155.155.199:14013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSATPcmepr5_nHgLbM8BAAAAj4"]
[Tue Aug 18 12:54:52.859381 2026] [security2:error] [pid 66623:tid 66837] [client 20.163.43.14:1990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/epinyins.php"] [unique_id "aoSATNO5rbWdOArH04KBwgAAAVE"]
[Tue Aug 18 12:54:52.866036 2026] [security2:error] [pid 66623:tid 66843] [client 172.202.39.151:44472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/ok.php"] [unique_id "aoSATNO5rbWdOArH04KBwwAAAVc"]
[Tue Aug 18 12:54:52.961858 2026] [security2:error] [pid 67073:tid 67324] [client 157.20.138.62:55499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSATPcmepr5_nHgLbM8BwAAAos"]
[Tue Aug 18 12:54:52.961962 2026] [security2:error] [pid 67073:tid 67324] [client 157.20.138.62:55499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSATPcmepr5_nHgLbM8BwAAAos"]
[Tue Aug 18 12:54:52.964801 2026] [security2:error] [pid 67073:tid 67295] [client 20.251.48.93:2969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/bajah.php"] [unique_id "aoSATPcmepr5_nHgLbM8CAAAAm4"]
[Tue Aug 18 12:54:53.014075 2026] [security2:error] [pid 67073:tid 67316] [client 52.238.210.254:8920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/admin.php"] [unique_id "aoSATfcmepr5_nHgLbM8EgAAAoM"]
[Tue Aug 18 12:54:53.024815 2026] [security2:error] [pid 67073:tid 67284] [client 4.232.151.198:6817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/templates/beez3/error.php"] [unique_id "aoSATfcmepr5_nHgLbM8GwAAAmM"]
[Tue Aug 18 12:54:53.110419 2026] [security2:error] [pid 66623:tid 66812] [client 20.104.100.201:58924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/ty.php"] [unique_id "aoSATdO5rbWdOArH04KBxAAAATg"]
[Tue Aug 18 12:54:53.157649 2026] [security2:error] [pid 67073:tid 67252] [client 20.104.85.180:7946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/abc.php"] [unique_id "aoSATfcmepr5_nHgLbM8JgAAAkM"]
[Tue Aug 18 12:54:53.229645 2026] [security2:error] [pid 67073:tid 67273] [client 4.223.164.152:54240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/images.php"] [unique_id "aoSATfcmepr5_nHgLbM8LQAAAlg"]
[Tue Aug 18 12:54:53.247989 2026] [security2:error] [pid 67073:tid 67208] [client 20.163.43.14:3118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSATfcmepr5_nHgLbM8LwAAAhc"]
[Tue Aug 18 12:54:53.288047 2026] [security2:error] [pid 67073:tid 67242] [client 74.248.133.44:23395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/fi2.php"] [unique_id "aoSATfcmepr5_nHgLbM8NwAAAjk"]
[Tue Aug 18 12:54:53.342476 2026] [security2:error] [pid 67073:tid 67259] [client 74.248.18.37:54144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/sim.php"] [unique_id "aoSATfcmepr5_nHgLbM8OQAAAko"]
[Tue Aug 18 12:54:53.399021 2026] [security2:error] [pid 67073:tid 67226] [client 20.163.43.14:4234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/public/css.php"] [unique_id "aoSATfcmepr5_nHgLbM8OwAAAik"]
[Tue Aug 18 12:54:53.448440 2026] [security2:error] [pid 66623:tid 66891] [client 20.104.100.201:58901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSATdO5rbWdOArH04KByAAAAYc"]
[Tue Aug 18 12:54:53.487170 2026] [security2:error] [pid 67073:tid 67302] [client 20.118.172.148:8223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSATfcmepr5_nHgLbM8PAAAAnU"]
[Tue Aug 18 12:54:53.499763 2026] [security2:error] [pid 67073:tid 67278] [client 20.104.85.180:7955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/akcc.php"] [unique_id "aoSATfcmepr5_nHgLbM8PQAAAl0"]
[Tue Aug 18 12:54:53.501585 2026] [security2:error] [pid 66623:tid 66772] [client 20.226.56.190:52064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/lq.php"] [unique_id "aoSATdO5rbWdOArH04KByQAAARA"]
[Tue Aug 18 12:54:53.534338 2026] [security2:error] [pid 67073:tid 67236] [client 49.13.167.123:52216] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.institutoferiani.com.br"] [uri "/index.php"] [unique_id "aoSATPcmepr5_nHgLbM7-QAAAjM"], referer: https://www.institutoferiani.com.br
[Tue Aug 18 12:54:53.579183 2026] [security2:error] [pid 66623:tid 66770] [client 20.250.27.191:1871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSATdO5rbWdOArH04KBzQAAAQ4"]
[Tue Aug 18 12:54:53.583805 2026] [security2:error] [pid 66623:tid 66830] [client 20.116.17.175:57425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/dragonshell.php"] [unique_id "aoSATdO5rbWdOArH04KBzgAAAUo"]
[Tue Aug 18 12:54:53.694662 2026] [security2:error] [pid 67073:tid 67328] [client 213.35.127.232:52101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSATfcmepr5_nHgLbM8PgAAAo8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:53.710367 2026] [security2:error] [pid 67073:tid 67215] [client 4.223.164.152:64677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/alls.php"] [unique_id "aoSATfcmepr5_nHgLbM8QQAAAh4"]
[Tue Aug 18 12:54:53.733076 2026] [security2:error] [pid 66623:tid 66717] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/mini.php"] [unique_id "aoSATdO5rbWdOArH04KB0gABK1A"]
[Tue Aug 18 12:54:53.789324 2026] [security2:error] [pid 67073:tid 67309] [client 20.104.100.201:58486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/dot.php"] [unique_id "aoSATfcmepr5_nHgLbM8RAAAAnw"]
[Tue Aug 18 12:54:53.829154 2026] [security2:error] [pid 67073:tid 67287] [client 20.205.121.237:7015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/txets.php"] [unique_id "aoSATfcmepr5_nHgLbM8RQAAAmY"]
[Tue Aug 18 12:54:53.846445 2026] [security2:error] [pid 67073:tid 67332] [client 20.104.85.180:7984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wk/index.php"] [unique_id "aoSATfcmepr5_nHgLbM8TAAAApM"]
[Tue Aug 18 12:54:53.854214 2026] [security2:error] [pid 67073:tid 67301] [client 52.139.47.57:16691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/atex1.php"] [unique_id "aoSATfcmepr5_nHgLbM8TQAAAnQ"]
[Tue Aug 18 12:54:53.873675 2026] [security2:error] [pid 67073:tid 67113] [remote 47.86.33.52:61602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "becacao.us"] [uri "/wp-login.php"] [unique_id "aoSATfcmepr5_nHgLbM8TgACeiU"]
[Tue Aug 18 12:54:54.034758 2026] [security2:error] [pid 67073:tid 67210] [client 20.42.19.40:9704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/about.php"] [unique_id "aoSATvcmepr5_nHgLbM8UQAAAhk"]
[Tue Aug 18 12:54:54.038129 2026] [security2:error] [pid 67073:tid 67265] [client 20.250.27.191:1906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/media.php"] [unique_id "aoSATvcmepr5_nHgLbM8UgAAAlA"]
[Tue Aug 18 12:54:54.050375 2026] [security2:error] [pid 67073:tid 67235] [client 74.248.136.165:34381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/xleet.php"] [unique_id "aoSATvcmepr5_nHgLbM8UwAAAjI"]
[Tue Aug 18 12:54:54.058330 2026] [security2:error] [pid 66623:tid 66675] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/miru1.php"] [unique_id "aoSATtO5rbWdOArH04KB1wABKCY"]
[Tue Aug 18 12:54:54.095668 2026] [security2:error] [pid 67073:tid 67260] [client 20.51.153.15:9178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/asus.php"] [unique_id "aoSATvcmepr5_nHgLbM8VAAAAks"]
[Tue Aug 18 12:54:54.113494 2026] [security2:error] [pid 66623:tid 66857] [client 20.42.19.40:2218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/f35.php"] [unique_id "aoSATtO5rbWdOArH04KB2AAAAWU"]
[Tue Aug 18 12:54:54.167213 2026] [security2:error] [pid 67073:tid 67223] [client 68.155.155.199:13992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/about.php"] [unique_id "aoSATvcmepr5_nHgLbM8VQAAAiY"]
[Tue Aug 18 12:54:54.189951 2026] [security2:error] [pid 66623:tid 66784] [client 4.223.164.152:64645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/coffexium.php"] [unique_id "aoSATtO5rbWdOArH04KB2QAAARw"]
[Tue Aug 18 12:54:54.216804 2026] [security2:error] [pid 66623:tid 66777] [client 20.104.85.180:8048] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "rodrigolocadora.com.br"] [uri "/1.php"] [unique_id "aoSATtO5rbWdOArH04KB2gAAARU"]
[Tue Aug 18 12:54:54.216929 2026] [security2:error] [pid 66623:tid 66777] [client 20.104.85.180:8048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/1.php"] [unique_id "aoSATtO5rbWdOArH04KB2gAAARU"]
[Tue Aug 18 12:54:54.222682 2026] [security2:error] [pid 66623:tid 66859] [client 74.248.133.44:18998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/feeds.php"] [unique_id "aoSATtO5rbWdOArH04KB2wAAAWc"]
[Tue Aug 18 12:54:54.225385 2026] [security2:error] [pid 66623:tid 66848] [client 20.65.98.162:52892] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "gruposchopan.com.br"] [uri "/1.php"] [unique_id "aoSATtO5rbWdOArH04KB3AAAAVw"]
[Tue Aug 18 12:54:54.225472 2026] [security2:error] [pid 66623:tid 66848] [client 20.65.98.162:52892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/1.php"] [unique_id "aoSATtO5rbWdOArH04KB3AAAAVw"]
[Tue Aug 18 12:54:54.248882 2026] [security2:error] [pid 67073:tid 67093] [remote 188.164.197.230:53160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sci.atlas-ia.com"] [uri "/wp-login.php"] [unique_id "aoSATvcmepr5_nHgLbM8VgACbxE"]
[Tue Aug 18 12:54:54.314339 2026] [authz_core:error] [pid 66623:tid 66705] [remote 57.141.22.16:34878] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:54.314594 2026] [authz_core:error] [pid 66623:tid 66705] [remote 57.141.22.16:34878] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:54.377292 2026] [security2:error] [pid 66623:tid 66709] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/mjq.php"] [unique_id "aoSATtO5rbWdOArH04KB3gABfEg"]
[Tue Aug 18 12:54:54.444389 2026] [security2:error] [pid 67073:tid 67282] [client 20.51.153.15:9190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/22.php"] [unique_id "aoSATvcmepr5_nHgLbM8WgAAAmE"]
[Tue Aug 18 12:54:54.503299 2026] [security2:error] [pid 66623:tid 66767] [client 20.250.27.191:1885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/admin.php"] [unique_id "aoSATtO5rbWdOArH04KB3wAAAQs"]
[Tue Aug 18 12:54:54.540119 2026] [security2:error] [pid 66623:tid 66847] [client 20.91.215.254:20569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-aa.php"] [unique_id "aoSATtO5rbWdOArH04KB4AAAAVs"]
[Tue Aug 18 12:54:54.575729 2026] [security2:error] [pid 67073:tid 67245] [client 20.104.100.201:58929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/005.php"] [unique_id "aoSATvcmepr5_nHgLbM8WwAAAjw"]
[Tue Aug 18 12:54:54.625479 2026] [security2:error] [pid 66623:tid 66807] [client 74.248.18.37:12394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/simple.php"] [unique_id "aoSATtO5rbWdOArH04KB4QAAATM"]
[Tue Aug 18 12:54:54.627134 2026] [security2:error] [pid 66623:tid 66889] [client 52.139.47.57:16653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/jga.php"] [unique_id "aoSATtO5rbWdOArH04KB4gAAAYU"]
[Tue Aug 18 12:54:54.698613 2026] [security2:error] [pid 66623:tid 66664] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "aoSATtO5rbWdOArH04KB4wABHxs"]
[Tue Aug 18 12:54:54.710068 2026] [security2:error] [pid 66623:tid 66828] [client 20.48.236.86:10688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/file61.php"] [unique_id "aoSATtO5rbWdOArH04KB5QAAAUg"]
[Tue Aug 18 12:54:54.830563 2026] [security2:error] [pid 66623:tid 66885] [client 132.196.61.152:60323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/admin.php"] [unique_id "aoSATtO5rbWdOArH04KB5gAAAYE"]
[Tue Aug 18 12:54:54.846034 2026] [security2:error] [pid 66623:tid 66888] [client 178.153.171.161:32932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSATtO5rbWdOArH04KB5wAAAYQ"]
[Tue Aug 18 12:54:54.846160 2026] [security2:error] [pid 66623:tid 66888] [client 178.153.171.161:32932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSATtO5rbWdOArH04KB5wAAAYQ"]
[Tue Aug 18 12:54:54.908711 2026] [security2:error] [pid 67073:tid 67268] [client 20.104.100.201:58890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/v2.php"] [unique_id "aoSATvcmepr5_nHgLbM8XwAAAlM"]
[Tue Aug 18 12:54:54.909333 2026] [security2:error] [pid 67073:tid 67324] [client 52.173.121.69:44970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/first.php"] [unique_id "aoSATvcmepr5_nHgLbM8YAAAAos"]
[Tue Aug 18 12:54:54.964920 2026] [security2:error] [pid 66623:tid 66808] [client 20.250.27.191:1862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/mac.php"] [unique_id "aoSATtO5rbWdOArH04KB6AAAATQ"]
[Tue Aug 18 12:54:54.974639 2026] [security2:error] [pid 67073:tid 67207] [client 20.163.43.14:4239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSATvcmepr5_nHgLbM8YQAAAhY"]
[Tue Aug 18 12:54:55.061403 2026] [security2:error] [pid 67073:tid 67216] [client 132.196.61.152:27268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "webmail.riosafe.com.br"] [uri "/.mopj.php"] [unique_id "aoSAT_cmepr5_nHgLbM8YgAAAh8"]
[Tue Aug 18 12:54:55.068438 2026] [security2:error] [pid 67073:tid 67224] [client 20.251.48.93:29307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/domvf.php"] [unique_id "aoSAT_cmepr5_nHgLbM8YwAAAic"]
[Tue Aug 18 12:54:55.170307 2026] [security2:error] [pid 67073:tid 67222] [client 20.171.51.14:16743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/vm.php"] [unique_id "aoSAT_cmepr5_nHgLbM8ZgAAAiU"]
[Tue Aug 18 12:54:55.234624 2026] [security2:error] [pid 67073:tid 67242] [client 20.104.100.201:58916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wkl.php"] [unique_id "aoSAT_cmepr5_nHgLbM8agAAAjk"]
[Tue Aug 18 12:54:55.325853 2026] [security2:error] [pid 66623:tid 66785] [client 20.42.19.40:1373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/goods.php"] [unique_id "aoSAT9O5rbWdOArH04KB6wAAAR0"]
[Tue Aug 18 12:54:55.416755 2026] [security2:error] [pid 67073:tid 67319] [client 74.248.18.37:47614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-login.php"] [unique_id "aoSAT_cmepr5_nHgLbM8ZwAAAoY"]
[Tue Aug 18 12:54:55.438110 2026] [security2:error] [pid 66623:tid 66768] [client 20.250.27.191:1875] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/1.php"] [unique_id "aoSAT9O5rbWdOArH04KB7QAAAQw"]
[Tue Aug 18 12:54:55.438235 2026] [security2:error] [pid 66623:tid 66768] [client 20.250.27.191:1875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/1.php"] [unique_id "aoSAT9O5rbWdOArH04KB7QAAAQw"]
[Tue Aug 18 12:54:55.469089 2026] [security2:error] [pid 67073:tid 67217] [client 85.154.68.202:10535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAT_cmepr5_nHgLbM8awAAAiA"]
[Tue Aug 18 12:54:55.469206 2026] [security2:error] [pid 67073:tid 67217] [client 85.154.68.202:10535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAT_cmepr5_nHgLbM8awAAAiA"]
[Tue Aug 18 12:54:55.490638 2026] [security2:error] [pid 66623:tid 66811] [client 20.118.172.148:8508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAT9O5rbWdOArH04KB7gAAATc"]
[Tue Aug 18 12:54:55.571557 2026] [security2:error] [pid 67073:tid 67286] [client 132.196.61.152:55318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/bengi.php"] [unique_id "aoSAT_cmepr5_nHgLbM8bQAAAmU"]
[Tue Aug 18 12:54:55.599035 2026] [security2:error] [pid 67073:tid 67267] [client 135.225.75.187:20242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-good.php"] [unique_id "aoSAT_cmepr5_nHgLbM8bgAAAlI"]
[Tue Aug 18 12:54:55.605887 2026] [security2:error] [pid 66623:tid 66851] [client 20.163.43.14:3147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSAT9O5rbWdOArH04KB8gAAAV8"]
[Tue Aug 18 12:54:55.642974 2026] [security2:error] [pid 66623:tid 66837] [client 20.251.48.93:35089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/fpwch.php"] [unique_id "aoSAT9O5rbWdOArH04KB8wAAAVE"]
[Tue Aug 18 12:54:55.648318 2026] [security2:error] [pid 67073:tid 67228] [client 5.253.205.188:51058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/home.bak"] [unique_id "aoSAT_cmepr5_nHgLbM8bwAAAis"], referer: https://medihub.com.br/home.bak
[Tue Aug 18 12:54:55.658574 2026] [security2:error] [pid 67073:tid 67269] [client 52.173.121.69:16468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSAT_cmepr5_nHgLbM8cQAAAlQ"]
[Tue Aug 18 12:54:55.769342 2026] [security2:error] [pid 67073:tid 67220] [client 52.139.47.57:27943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/166.php"] [unique_id "aoSAT_cmepr5_nHgLbM8cwAAAiM"]
[Tue Aug 18 12:54:55.806277 2026] [security2:error] [pid 66623:tid 66890] [client 172.202.39.151:62665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/item.php"] [unique_id "aoSAT9O5rbWdOArH04KB9AAAAYY"]
[Tue Aug 18 12:54:55.903987 2026] [security2:error] [pid 66623:tid 66843] [client 74.248.18.37:12706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/st.php"] [unique_id "aoSAT9O5rbWdOArH04KB-AAAAVc"]
[Tue Aug 18 12:54:55.905297 2026] [security2:error] [pid 67073:tid 67309] [client 20.250.27.191:1888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/coffee.php"] [unique_id "aoSAT_cmepr5_nHgLbM8dAAAAnw"]
[Tue Aug 18 12:54:55.992067 2026] [security2:error] [pid 66623:tid 66790] [client 20.163.43.14:3186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAT9O5rbWdOArH04KB-QAAASI"]
[Tue Aug 18 12:54:56.066351 2026] [authz_core:error] [pid 67073:tid 67141] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:56.066611 2026] [authz_core:error] [pid 67073:tid 67141] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:56.157066 2026] [security2:error] [pid 67073:tid 67313] [client 74.248.133.44:42067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/curl.php"] [unique_id "aoSAUPcmepr5_nHgLbM8egAAAoA"]
[Tue Aug 18 12:54:56.213223 2026] [security2:error] [pid 66623:tid 66891] [client 74.248.136.165:62389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/fr/ms.php"] [unique_id "aoSAUNO5rbWdOArH04KB_AAAAYc"]
[Tue Aug 18 12:54:56.263839 2026] [security2:error] [pid 67073:tid 67317] [client 52.238.210.254:9032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/images/class-config.php"] [unique_id "aoSAUPcmepr5_nHgLbM8ewAAAoQ"]
[Tue Aug 18 12:54:56.284515 2026] [security2:error] [pid 67073:tid 67237] [client 20.65.98.162:38016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/coffee.php"] [unique_id "aoSAUPcmepr5_nHgLbM8fQAAAjQ"]
[Tue Aug 18 12:54:56.292138 2026] [security2:error] [pid 67073:tid 67272] [client 132.196.61.152:27296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/file2.php"] [unique_id "aoSAUPcmepr5_nHgLbM8fgAAAlc"]
[Tue Aug 18 12:54:56.309644 2026] [security2:error] [pid 67073:tid 67227] [client 20.251.48.93:35082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/adminner.php"] [unique_id "aoSAUPcmepr5_nHgLbM8fwAAAio"]
[Tue Aug 18 12:54:56.391373 2026] [security2:error] [pid 67073:tid 67325] [client 20.163.43.14:3168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp.php"] [unique_id "aoSAUPcmepr5_nHgLbM8gAAAAow"]
[Tue Aug 18 12:54:56.441324 2026] [security2:error] [pid 67073:tid 67265] [client 20.226.56.190:20377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/you.php"] [unique_id "aoSAUPcmepr5_nHgLbM8gQAAAlA"]
[Tue Aug 18 12:54:56.562739 2026] [security2:error] [pid 67073:tid 67321] [client 20.42.19.40:9689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/php8.php"] [unique_id "aoSAUPcmepr5_nHgLbM8ggAAAog"]
[Tue Aug 18 12:54:56.564733 2026] [security2:error] [pid 67073:tid 67253] [client 52.139.47.57:16697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/log.php"] [unique_id "aoSAUPcmepr5_nHgLbM8gwAAAkQ"]
[Tue Aug 18 12:54:56.595701 2026] [security2:error] [pid 67073:tid 67205] [client 20.104.100.201:21482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-asudo.php"] [unique_id "aoSAUPcmepr5_nHgLbM8hgAAAhQ"]
[Tue Aug 18 12:54:56.683188 2026] [security2:error] [pid 66623:tid 66844] [client 213.35.113.47:55191] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "lubarbosaassessoria.com.br"] [uri "/"] [unique_id "aoSAT9O5rbWdOArH04KB8QAAAVg"]
[Tue Aug 18 12:54:56.745643 2026] [security2:error] [pid 66623:tid 66836] [client 4.232.151.198:25808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/test.php"] [unique_id "aoSAUNO5rbWdOArH04KCAQAAAVA"]
[Tue Aug 18 12:54:56.822892 2026] [security2:error] [pid 67073:tid 67323] [client 20.171.51.14:33696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/eg.php"] [unique_id "aoSAUPcmepr5_nHgLbM8iQAAAoo"]
[Tue Aug 18 12:54:56.838934 2026] [security2:error] [pid 67073:tid 67318] [client 20.48.236.86:10734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/copypaths.php"] [unique_id "aoSAUPcmepr5_nHgLbM8igAAAoU"]
[Tue Aug 18 12:54:56.864235 2026] [security2:error] [pid 67073:tid 67300] [client 213.35.127.232:53036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAUPcmepr5_nHgLbM8jAAAAnM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:54:56.904661 2026] [security2:error] [pid 67073:tid 67245] [client 20.250.27.191:1891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAUPcmepr5_nHgLbM8jgAAAjw"]
[Tue Aug 18 12:54:56.928581 2026] [security2:error] [pid 67073:tid 67280] [client 52.173.121.69:45866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSAUPcmepr5_nHgLbM8jwAAAl8"]
[Tue Aug 18 12:54:56.941704 2026] [security2:error] [pid 66623:tid 66687] [remote 216.194.122.158:47092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.122.194.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/wp-login.php"] [unique_id "aoSAUNO5rbWdOArH04KCAgABWTI"]
[Tue Aug 18 12:54:56.948802 2026] [security2:error] [pid 66623:tid 66766] [client 52.238.210.254:8883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/adminfuns.php"] [unique_id "aoSAUNO5rbWdOArH04KCAwAAAQo"]
[Tue Aug 18 12:54:56.949217 2026] [security2:error] [pid 66623:tid 66882] [client 135.225.75.187:40005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/zxin.php"] [unique_id "aoSAUNO5rbWdOArH04KCBAAAAX4"]
[Tue Aug 18 12:54:56.969932 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:56.970182 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:57.016990 2026] [security2:error] [pid 66623:tid 66855] [client 132.196.61.152:55309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/gm.php"] [unique_id "aoSAUdO5rbWdOArH04KCBQAAAWM"]
[Tue Aug 18 12:54:57.077672 2026] [security2:error] [pid 67073:tid 67276] [client 20.163.43.14:4231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAUfcmepr5_nHgLbM8kQAAAls"]
[Tue Aug 18 12:54:57.147416 2026] [security2:error] [pid 67073:tid 67247] [client 74.248.18.37:12705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/subdom/ant/makeasmtp.php"] [unique_id "aoSAUfcmepr5_nHgLbM8kwAAAj4"]
[Tue Aug 18 12:54:57.183974 2026] [security2:error] [pid 67073:tid 67211] [client 20.91.215.254:20595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/d.php"] [unique_id "aoSAUfcmepr5_nHgLbM8lAAAAho"]
[Tue Aug 18 12:54:57.220124 2026] [security2:error] [pid 67073:tid 67278] [client 157.51.166.53:55787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAUfcmepr5_nHgLbM8lgAAAl0"]
[Tue Aug 18 12:54:57.220248 2026] [security2:error] [pid 67073:tid 67278] [client 157.51.166.53:55787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAUfcmepr5_nHgLbM8lgAAAl0"]
[Tue Aug 18 12:54:57.269604 2026] [authz_core:error] [pid 67073:tid 67130] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:57.269902 2026] [authz_core:error] [pid 67073:tid 67130] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:57.287145 2026] [security2:error] [pid 67073:tid 67208] [client 20.42.19.40:9618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/info.php"] [unique_id "aoSAUfcmepr5_nHgLbM8mQAAAhc"]
[Tue Aug 18 12:54:57.362380 2026] [security2:error] [pid 67073:tid 67259] [client 20.171.51.14:21081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/37.php"] [unique_id "aoSAUfcmepr5_nHgLbM8mgAAAko"]
[Tue Aug 18 12:54:57.370875 2026] [security2:error] [pid 67073:tid 67279] [client 20.250.27.191:1890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSAUfcmepr5_nHgLbM8mwAAAl4"]
[Tue Aug 18 12:54:57.536359 2026] [security2:error] [pid 67073:tid 67217] [client 20.226.6.191:6636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAUfcmepr5_nHgLbM8nwAAAiA"]
[Tue Aug 18 12:54:57.556358 2026] [security2:error] [pid 67073:tid 67235] [client 149.34.210.141:63258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAUfcmepr5_nHgLbM8ngAAAjI"]
[Tue Aug 18 12:54:57.649007 2026] [security2:error] [pid 66623:tid 66839] [client 20.163.43.14:4306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/gelay.php"] [unique_id "aoSAUdO5rbWdOArH04KCCQAAAVM"]
[Tue Aug 18 12:54:57.673000 2026] [security2:error] [pid 66623:tid 66796] [client 20.251.48.93:2976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/abcd.php"] [unique_id "aoSAUdO5rbWdOArH04KCCgAAASg"]
[Tue Aug 18 12:54:57.677822 2026] [security2:error] [pid 66623:tid 66832] [client 74.248.130.103:15412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAUdO5rbWdOArH04KCCwAAAUw"]
[Tue Aug 18 12:54:57.706228 2026] [security2:error] [pid 67073:tid 67250] [client 20.116.17.175:57647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/setup-config.php"] [unique_id "aoSAUfcmepr5_nHgLbM8sAAAAkE"]
[Tue Aug 18 12:54:57.707087 2026] [security2:error] [pid 67073:tid 67229] [client 52.139.47.57:3142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/file.php"] [unique_id "aoSAUfcmepr5_nHgLbM8sQAAAiw"]
[Tue Aug 18 12:54:57.753107 2026] [security2:error] [pid 66623:tid 66784] [client 4.223.164.152:46190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/red.php"] [unique_id "aoSAUdO5rbWdOArH04KCDAAAARw"]
[Tue Aug 18 12:54:57.873613 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:57.873903 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:57.919536 2026] [security2:error] [pid 66623:tid 66835] [client 20.104.100.201:58461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/az.php"] [unique_id "aoSAUdO5rbWdOArH04KCDwAAAU8"]
[Tue Aug 18 12:54:57.965182 2026] [security2:error] [pid 67073:tid 67317] [client 20.65.98.162:52638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAUfcmepr5_nHgLbM8tgAAAoQ"]
[Tue Aug 18 12:54:58.029849 2026] [security2:error] [pid 66623:tid 66774] [client 20.100.169.31:24504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wso.php"] [unique_id "aoSAUtO5rbWdOArH04KCEQAAARI"]
[Tue Aug 18 12:54:58.045239 2026] [security2:error] [pid 67073:tid 67222] [client 37.40.227.74:57161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAUvcmepr5_nHgLbM8twAAAiU"]
[Tue Aug 18 12:54:58.045364 2026] [security2:error] [pid 67073:tid 67222] [client 37.40.227.74:57161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAUvcmepr5_nHgLbM8twAAAiU"]
[Tue Aug 18 12:54:58.093348 2026] [security2:error] [pid 66623:tid 66767] [client 216.244.66.243:58110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/tensei+shitara+slime+datta+ken+3+temporada+dublado-2/"] [unique_id "aoSAUtO5rbWdOArH04KCEwAAAQs"]
[Tue Aug 18 12:54:58.093484 2026] [security2:error] [pid 66623:tid 66767] [client 216.244.66.243:58110] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/tensei+shitara+slime+datta+ken+3+temporada+dublado-2/"] [unique_id "aoSAUtO5rbWdOArH04KCEwAAAQs"]
[Tue Aug 18 12:54:58.096855 2026] [security2:error] [pid 67073:tid 67209] [client 185.198.240.219:33805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "celleiromoveis.com"] [uri "/wp-login.php"] [unique_id "aoSAUfcmepr5_nHgLbM8tAAAAhg"]
[Tue Aug 18 12:54:58.335299 2026] [security2:error] [pid 66623:tid 66877] [client 74.248.130.103:15417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAUtO5rbWdOArH04KCPQAAAXk"]
[Tue Aug 18 12:54:58.348529 2026] [security2:error] [pid 67073:tid 67293] [client 52.173.121.69:17953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSAUvcmepr5_nHgLbM8uQAAAmw"]
[Tue Aug 18 12:54:58.372998 2026] [security2:error] [pid 66623:tid 66888] [client 52.238.210.254:9043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/alfa.php"] [unique_id "aoSAUtO5rbWdOArH04KCPgAAAYQ"]
[Tue Aug 18 12:54:58.374268 2026] [security2:error] [pid 66623:tid 66857] [client 196.12.128.158:59734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAUtO5rbWdOArH04KCPwAAAWU"]
[Tue Aug 18 12:54:58.374374 2026] [security2:error] [pid 66623:tid 66857] [client 196.12.128.158:59734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAUtO5rbWdOArH04KCPwAAAWU"]
[Tue Aug 18 12:54:58.400382 2026] [security2:error] [pid 67073:tid 67308] [client 114.119.130.97:26083] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "leguizaimoveis.com.br"] [uri "/imoveis/property/51/resid%C3%AAncia-de-alto-luxo-num-dos-melhores-condom%C3%ADnios-de-itaipu.html"] [unique_id "aoSAUvcmepr5_nHgLbM8ugAAAns"], referer: https://leguizaimoveis.com.br/imoveis/property/51/resid%C3%AAncia-de-alto-luxo-num-dos-melhores-condom%C3%ADnios-de-itaipu.html
[Tue Aug 18 12:54:58.432229 2026] [security2:error] [pid 66623:tid 66840] [client 74.248.136.165:59475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/gool.php"] [unique_id "aoSAUtO5rbWdOArH04KCQAAAAVQ"]
[Tue Aug 18 12:54:58.461473 2026] [security2:error] [pid 67073:tid 67326] [client 20.48.236.86:11013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/bless6.php"] [unique_id "aoSAUvcmepr5_nHgLbM8uwAAAo0"]
[Tue Aug 18 12:54:58.477748 2026] [authz_core:error] [pid 67073:tid 67085] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:58.478011 2026] [authz_core:error] [pid 67073:tid 67085] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:58.540220 2026] [security2:error] [pid 67073:tid 67223] [client 20.226.56.190:20364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ez.php"] [unique_id "aoSAUvcmepr5_nHgLbM8vQAAAiY"]
[Tue Aug 18 12:54:58.545076 2026] [security2:error] [pid 66623:tid 66778] [client 4.232.151.198:42300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/inputs.php"] [unique_id "aoSAUtO5rbWdOArH04KCQQAAARY"]
[Tue Aug 18 12:54:58.611166 2026] [security2:error] [pid 67073:tid 67235] [client 149.34.210.141:63258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAUfcmepr5_nHgLbM8ngAAAjI"]
[Tue Aug 18 12:54:58.681619 2026] [security2:error] [pid 66623:tid 66846] [client 132.196.61.152:61036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/222.php"] [unique_id "aoSAUtO5rbWdOArH04KCQwAAAVo"]
[Tue Aug 18 12:54:58.699648 2026] [security2:error] [pid 67073:tid 67296] [client 132.196.61.152:27319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/ws55.php"] [unique_id "aoSAUvcmepr5_nHgLbM82wAAAm8"]
[Tue Aug 18 12:54:58.720860 2026] [security2:error] [pid 66623:tid 66870] [client 20.151.109.219:17580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gj.php"] [unique_id "aoSAUtO5rbWdOArH04KCRAAAAXI"]
[Tue Aug 18 12:54:58.721289 2026] [security2:error] [pid 67073:tid 67323] [client 20.104.100.201:21468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/z43agz.php"] [unique_id "aoSAUvcmepr5_nHgLbM83AAAAoo"]
[Tue Aug 18 12:54:58.775640 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:58.775898 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:58.885305 2026] [security2:error] [pid 67073:tid 67312] [client 20.116.17.175:57616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/f35.update.php"] [unique_id "aoSAUvcmepr5_nHgLbM85QAAAn8"]
[Tue Aug 18 12:54:58.897785 2026] [security2:error] [pid 67073:tid 67262] [client 20.42.19.40:9607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/chosen.php"] [unique_id "aoSAUvcmepr5_nHgLbM85gAAAk0"]
[Tue Aug 18 12:54:58.945180 2026] [security2:error] [pid 67073:tid 67171] [remote 57.141.22.54:33458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSAUvcmepr5_nHgLbM85wACWV8"]
[Tue Aug 18 12:54:58.955125 2026] [security2:error] [pid 67073:tid 67330] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAUvcmepr5_nHgLbM85AACkVs"]
[Tue Aug 18 12:54:58.982093 2026] [security2:error] [pid 67073:tid 67316] [client 20.171.51.14:33702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/uk.php"] [unique_id "aoSAUvcmepr5_nHgLbM86AAAAoM"]
[Tue Aug 18 12:54:59.020545 2026] [security2:error] [pid 66623:tid 66811] [client 74.248.130.103:14410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/domvf.php"] [unique_id "aoSAU9O5rbWdOArH04KCRwAAATc"]
[Tue Aug 18 12:54:59.023527 2026] [autoindex:error] [pid 66623:tid 66703] [remote 52.167.144.17:32059] AH01276: Cannot serve directory /home2/natbrw01/uhequeimado.com.br/web/wp-content/themes/vamtam-landscaping/vamtam/assets/css/dist/woocommerce/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:54:59.075679 2026] [security2:error] [pid 67073:tid 67224] [client 20.100.169.31:31436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/ioxi-o.php"] [unique_id "aoSAU_cmepr5_nHgLbM86gAAAic"]
[Tue Aug 18 12:54:59.106199 2026] [security2:error] [pid 67073:tid 67246] [client 103.120.71.157:4101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAU_cmepr5_nHgLbM86wAAAj0"]
[Tue Aug 18 12:54:59.106328 2026] [security2:error] [pid 67073:tid 67246] [client 103.120.71.157:4101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAU_cmepr5_nHgLbM86wAAAj0"]
[Tue Aug 18 12:54:59.146319 2026] [security2:error] [pid 67073:tid 67290] [client 4.232.151.198:6843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/test1.php"] [unique_id "aoSAU_cmepr5_nHgLbM87AAAAmk"]
[Tue Aug 18 12:54:59.159938 2026] [security2:error] [pid 66623:tid 66868] [client 20.163.43.14:4228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAU9O5rbWdOArH04KCSQAAAXA"]
[Tue Aug 18 12:54:59.204238 2026] [security2:error] [pid 67073:tid 67206] [client 20.91.215.254:24343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSAU_cmepr5_nHgLbM88gAAAhU"]
[Tue Aug 18 12:54:59.270676 2026] [security2:error] [pid 67073:tid 67304] [client 20.29.77.16:56341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAU_cmepr5_nHgLbM88wAAAnc"]
[Tue Aug 18 12:54:59.300821 2026] [security2:error] [pid 67073:tid 67331] [client 172.182.200.96:14288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/index/function.php"] [unique_id "aoSAU_cmepr5_nHgLbM89AAAApI"]
[Tue Aug 18 12:54:59.377527 2026] [authz_core:error] [pid 67073:tid 67188] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:54:59.377793 2026] [authz_core:error] [pid 67073:tid 67188] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:54:59.432046 2026] [security2:error] [pid 67073:tid 67212] [client 74.248.18.37:12682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/system.php"] [unique_id "aoSAU_cmepr5_nHgLbM8-QAAAhs"]
[Tue Aug 18 12:54:59.484025 2026] [security2:error] [pid 67073:tid 67277] [client 114.5.214.109:49799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAU_cmepr5_nHgLbM8-gAAAlw"]
[Tue Aug 18 12:54:59.484204 2026] [security2:error] [pid 67073:tid 67277] [client 114.5.214.109:49799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAU_cmepr5_nHgLbM8-gAAAlw"]
[Tue Aug 18 12:54:59.569444 2026] [security2:error] [pid 66623:tid 66843] [client 20.151.109.219:12914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/pd.php"] [unique_id "aoSAU9O5rbWdOArH04KCTAAAAVc"]
[Tue Aug 18 12:54:59.581430 2026] [security2:error] [pid 67073:tid 67328] [client 135.225.75.187:9502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/pass4.php"] [unique_id "aoSAU_cmepr5_nHgLbM8_QAAAo8"]
[Tue Aug 18 12:54:59.584392 2026] [security2:error] [pid 66623:tid 66779] [client 4.223.164.152:54265] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/sodium_compat/"] [unique_id "aoSAU9O5rbWdOArH04KCTQAAARc"]
[Tue Aug 18 12:54:59.634863 2026] [security2:error] [pid 66623:tid 66793] [client 104.209.144.33:24857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/images/security.php"] [unique_id "aoSAU9O5rbWdOArH04KCTgAAASU"]
[Tue Aug 18 12:54:59.640607 2026] [security2:error] [pid 67073:tid 67232] [client 52.173.121.69:63278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSAU_cmepr5_nHgLbM8_gAAAi8"]
[Tue Aug 18 12:54:59.657641 2026] [security2:error] [pid 67073:tid 67250] [client 104.209.144.33:39356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/opsqt.php"] [unique_id "aoSAU_cmepr5_nHgLbM9AAAAAkE"]
[Tue Aug 18 12:54:59.684635 2026] [security2:error] [pid 67073:tid 67239] [client 20.163.43.14:4335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAU_cmepr5_nHgLbM9AwAAAjY"]
[Tue Aug 18 12:54:59.689402 2026] [security2:error] [pid 67073:tid 67287] [client 20.226.56.190:2556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/asus.php"] [unique_id "aoSAU_cmepr5_nHgLbM9BAAAAmY"]
[Tue Aug 18 12:54:59.741828 2026] [security2:error] [pid 66623:tid 66856] [client 160.120.140.123:56772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAU9O5rbWdOArH04KCTwAAAWQ"]
[Tue Aug 18 12:54:59.741965 2026] [security2:error] [pid 66623:tid 66856] [client 160.120.140.123:56772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAU9O5rbWdOArH04KCTwAAAWQ"]
[Tue Aug 18 12:54:59.750452 2026] [security2:error] [pid 67073:tid 67218] [client 132.196.61.152:61013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/mac.php"] [unique_id "aoSAU_cmepr5_nHgLbM9BwAAAiE"]
[Tue Aug 18 12:54:59.953111 2026] [security2:error] [pid 67073:tid 67210] [client 20.151.109.219:21660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/th.php"] [unique_id "aoSAU_cmepr5_nHgLbM9DAAAAhk"]
[Tue Aug 18 12:54:59.983568 2026] [security2:error] [pid 67073:tid 67265] [client 172.202.39.151:32439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-content/x/index.php"] [unique_id "aoSAU_cmepr5_nHgLbM9DQAAAlA"]
[Tue Aug 18 12:55:00.029136 2026] [security2:error] [pid 67073:tid 67243] [client 192.141.172.134:56046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVPcmepr5_nHgLbM9DwAAAjo"]
[Tue Aug 18 12:55:00.029276 2026] [security2:error] [pid 67073:tid 67243] [client 192.141.172.134:56046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVPcmepr5_nHgLbM9DwAAAjo"]
[Tue Aug 18 12:55:00.043847 2026] [security2:error] [pid 67073:tid 67306] [client 20.42.19.40:2751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/gg.php"] [unique_id "aoSAVPcmepr5_nHgLbM9EQAAAnk"]
[Tue Aug 18 12:55:00.077192 2026] [security2:error] [pid 67073:tid 67285] [client 4.223.164.152:64675] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/Text/"] [unique_id "aoSAVPcmepr5_nHgLbM9EgAAAmQ"]
[Tue Aug 18 12:55:00.082942 2026] [security2:error] [pid 67073:tid 67284] [client 20.104.100.201:58930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/3.php"] [unique_id "aoSAVPcmepr5_nHgLbM9EwAAAmM"]
[Tue Aug 18 12:55:00.161438 2026] [security2:error] [pid 67073:tid 67227] [client 74.248.18.37:12694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/system_log.php"] [unique_id "aoSAVPcmepr5_nHgLbM9FQAAAio"]
[Tue Aug 18 12:55:00.196733 2026] [security2:error] [pid 67073:tid 67303] [client 20.42.19.40:9608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/simple.php"] [unique_id "aoSAVPcmepr5_nHgLbM9FwAAAnY"]
[Tue Aug 18 12:55:00.236643 2026] [security2:error] [pid 67073:tid 67257] [client 86.120.159.145:50260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVPcmepr5_nHgLbM9GQAAAkg"]
[Tue Aug 18 12:55:00.237004 2026] [security2:error] [pid 67073:tid 67257] [client 86.120.159.145:50260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVPcmepr5_nHgLbM9GQAAAkg"]
[Tue Aug 18 12:55:00.251564 2026] [security2:error] [pid 67073:tid 67301] [client 20.91.215.254:24251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSAVPcmepr5_nHgLbM9GgAAAnQ"]
[Tue Aug 18 12:55:00.309379 2026] [security2:error] [pid 67073:tid 67323] [client 132.196.61.152:27318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/m.php"] [unique_id "aoSAVPcmepr5_nHgLbM9HAAAAoo"]
[Tue Aug 18 12:55:00.313850 2026] [security2:error] [pid 67073:tid 67302] [client 20.151.109.219:17585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/admin404.php"] [unique_id "aoSAVPcmepr5_nHgLbM9HQAAAnU"]
[Tue Aug 18 12:55:00.341907 2026] [security2:error] [pid 67073:tid 67254] [client 52.173.121.69:24797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSAVPcmepr5_nHgLbM9HgAAAkU"]
[Tue Aug 18 12:55:00.376100 2026] [security2:error] [pid 67073:tid 67268] [client 172.182.200.96:14221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSAVPcmepr5_nHgLbM9HwAAAlM"]
[Tue Aug 18 12:55:00.401986 2026] [security2:error] [pid 67073:tid 67329] [client 4.232.151.198:41312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/admin.php"] [unique_id "aoSAVPcmepr5_nHgLbM9IAAAApA"]
[Tue Aug 18 12:55:00.475807 2026] [security2:error] [pid 67073:tid 67280] [client 20.48.236.86:65149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/special.php"] [unique_id "aoSAVPcmepr5_nHgLbM9IgAAAl8"]
[Tue Aug 18 12:55:00.489341 2026] [security2:error] [pid 67073:tid 67225] [client 197.184.64.235:41921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVPcmepr5_nHgLbM9IwAAAig"]
[Tue Aug 18 12:55:00.489507 2026] [security2:error] [pid 67073:tid 67225] [client 197.184.64.235:41921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVPcmepr5_nHgLbM9IwAAAig"]
[Tue Aug 18 12:55:00.523789 2026] [security2:error] [pid 66623:tid 66891] [client 20.116.17.175:57446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/bdroot.php"] [unique_id "aoSAVNO5rbWdOArH04KCUwAAAYc"]
[Tue Aug 18 12:55:00.593878 2026] [security2:error] [pid 67073:tid 67220] [client 20.100.169.31:2222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/0x.php"] [unique_id "aoSAVPcmepr5_nHgLbM9JAAAAiM"]
[Tue Aug 18 12:55:00.605855 2026] [security2:error] [pid 67073:tid 67260] [client 213.35.127.232:53686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAVPcmepr5_nHgLbM9JQAAAks"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:00.616237 2026] [security2:error] [pid 67073:tid 67240] [client 20.91.215.254:27427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-content/backup.php"] [unique_id "aoSAVPcmepr5_nHgLbM9JgAAAjc"]
[Tue Aug 18 12:55:00.684292 2026] [security2:error] [pid 66623:tid 66806] [client 213.202.253.4:53414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/wp-content/postnews.php"] [unique_id "aoSAVNO5rbWdOArH04KCVQAAATI"], referer: www.google.com
[Tue Aug 18 12:55:00.696077 2026] [security2:error] [pid 66623:tid 66818] [client 20.100.169.31:24496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/zup.php73"] [unique_id "aoSAVNO5rbWdOArH04KCVgAAAT4"]
[Tue Aug 18 12:55:00.745495 2026] [security2:error] [pid 67073:tid 67331] [client 74.248.130.103:14458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSAVPcmepr5_nHgLbM9KAAAApI"]
[Tue Aug 18 12:55:00.784745 2026] [security2:error] [pid 67073:tid 67226] [client 20.171.51.14:36473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/creds.php"] [unique_id "aoSAVPcmepr5_nHgLbM9KgAAAik"]
[Tue Aug 18 12:55:00.806335 2026] [security2:error] [pid 67073:tid 67212] [client 74.248.136.165:1694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/maxro.php"] [unique_id "aoSAVPcmepr5_nHgLbM9LAAAAhs"]
[Tue Aug 18 12:55:00.854385 2026] [security2:error] [pid 67073:tid 67217] [client 20.250.27.191:1860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/yj09.php"] [unique_id "aoSAVPcmepr5_nHgLbM9LgAAAiA"]
[Tue Aug 18 12:55:00.887134 2026] [security2:error] [pid 67073:tid 67267] [client 20.104.100.201:21469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/log.php"] [unique_id "aoSAVPcmepr5_nHgLbM9MAAAAlI"]
[Tue Aug 18 12:55:00.942225 2026] [security2:error] [pid 66623:tid 66797] [client 172.202.39.151:50204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSAVNO5rbWdOArH04KCWQAAASk"]
[Tue Aug 18 12:55:00.948809 2026] [security2:error] [pid 67073:tid 67273] [client 74.248.18.37:12719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/templates/beez3/error.php"] [unique_id "aoSAVPcmepr5_nHgLbM9NgAAAlg"]
[Tue Aug 18 12:55:00.975705 2026] [security2:error] [pid 67073:tid 67140] [remote 84.205.178.135:32681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.178.205.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jic.org.br"] [uri "/wp-login.php"] [unique_id "aoSAVPcmepr5_nHgLbM9NQACJEA"]
[Tue Aug 18 12:55:01.012798 2026] [security2:error] [pid 67073:tid 67232] [client 20.163.43.14:4253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSAVfcmepr5_nHgLbM9NwAAAi8"]
[Tue Aug 18 12:55:01.063169 2026] [security2:error] [pid 67073:tid 67250] [client 104.209.144.33:29871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/jvcpa.php"] [unique_id "aoSAVfcmepr5_nHgLbM9OQAAAkE"]
[Tue Aug 18 12:55:01.188844 2026] [security2:error] [pid 67073:tid 67244] [client 34.177.98.83:48128] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "pisogranitina.com.br"] [uri "/"] [unique_id "aoSAVfcmepr5_nHgLbM9PAAAAjs"]
[Tue Aug 18 12:55:01.227056 2026] [security2:error] [pid 67073:tid 67251] [client 20.104.100.201:21440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/ohct.php"] [unique_id "aoSAVfcmepr5_nHgLbM9PgAAAkI"]
[Tue Aug 18 12:55:01.229570 2026] [security2:error] [pid 67073:tid 67235] [client 4.232.151.198:6809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/text.php"] [unique_id "aoSAVfcmepr5_nHgLbM9PwAAAjI"]
[Tue Aug 18 12:55:01.267034 2026] [security2:error] [pid 67073:tid 67265] [client 66.249.77.98:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "buscacep.linkasites.com.br"] [uri "/robots.txt"] [unique_id "aoSAVfcmepr5_nHgLbM9QAAAAlA"]
[Tue Aug 18 12:55:01.290961 2026] [security2:error] [pid 67073:tid 67261] [client 52.139.47.57:2054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/bolt.php"] [unique_id "aoSAVfcmepr5_nHgLbM9QQAAAkw"]
[Tue Aug 18 12:55:01.317775 2026] [security2:error] [pid 67073:tid 67293] [client 20.250.27.191:1913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/scxy.php"] [unique_id "aoSAVfcmepr5_nHgLbM9QgAAAmw"]
[Tue Aug 18 12:55:01.357299 2026] [security2:error] [pid 67073:tid 67297] [client 20.171.51.14:58368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ho.php"] [unique_id "aoSAVfcmepr5_nHgLbM9RAAAAnA"]
[Tue Aug 18 12:55:01.408631 2026] [security2:error] [pid 67073:tid 67253] [client 20.29.77.16:56322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAVfcmepr5_nHgLbM9RgAAAkQ"]
[Tue Aug 18 12:55:01.548172 2026] [security2:error] [pid 66623:tid 66781] [client 132.196.61.152:61030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/ops.php"] [unique_id "aoSAVdO5rbWdOArH04KCZgAAARk"]
[Tue Aug 18 12:55:01.562264 2026] [security2:error] [pid 67073:tid 67301] [client 20.104.100.201:58933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/ot.php"] [unique_id "aoSAVfcmepr5_nHgLbM9SAAAAnQ"]
[Tue Aug 18 12:55:01.612964 2026] [security2:error] [pid 67073:tid 67255] [client 74.248.18.37:37722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/default.php"] [unique_id "aoSAVfcmepr5_nHgLbM9SgAAAkY"]
[Tue Aug 18 12:55:01.621995 2026] [security2:error] [pid 67073:tid 67207] [client 52.238.210.254:9021] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mirenax.com.br"] [uri "/1.php"] [unique_id "aoSAVfcmepr5_nHgLbM9SwAAAhY"]
[Tue Aug 18 12:55:01.622095 2026] [security2:error] [pid 67073:tid 67207] [client 52.238.210.254:9021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/1.php"] [unique_id "aoSAVfcmepr5_nHgLbM9SwAAAhY"]
[Tue Aug 18 12:55:01.626749 2026] [security2:error] [pid 66623:tid 66823] [client 20.104.85.180:7996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSAVdO5rbWdOArH04KCaQAAAUM"]
[Tue Aug 18 12:55:01.639618 2026] [security2:error] [pid 66623:tid 66780] [client 172.202.39.151:14650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/index/function.php"] [unique_id "aoSAVdO5rbWdOArH04KCagAAARg"]
[Tue Aug 18 12:55:01.669786 2026] [security2:error] [pid 67073:tid 67318] [client 138.36.100.162:42282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVfcmepr5_nHgLbM9TAAAAoU"]
[Tue Aug 18 12:55:01.678202 2026] [security2:error] [pid 66623:tid 66829] [client 20.151.109.219:64977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/qo.php"] [unique_id "aoSAVdO5rbWdOArH04KCawAAAUk"]
[Tue Aug 18 12:55:01.761614 2026] [security2:error] [pid 66623:tid 66777] [client 52.173.121.69:16510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSAVdO5rbWdOArH04KCbgAAARU"]
[Tue Aug 18 12:55:01.795185 2026] [security2:error] [pid 67073:tid 67279] [client 20.91.215.254:20600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSAVfcmepr5_nHgLbM9UAAAAl4"]
[Tue Aug 18 12:55:01.818935 2026] [security2:error] [pid 67073:tid 67215] [client 20.100.169.31:31054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/222.php"] [unique_id "aoSAVfcmepr5_nHgLbM9UQAAAh4"]
[Tue Aug 18 12:55:01.834988 2026] [security2:error] [pid 67073:tid 67280] [client 20.48.236.86:10650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/fz.php"] [unique_id "aoSAVfcmepr5_nHgLbM9UwAAAl8"]
[Tue Aug 18 12:55:01.838142 2026] [security2:error] [pid 67073:tid 67219] [client 158.158.74.177:16216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/media-new.php"] [unique_id "aoSAVfcmepr5_nHgLbM9VAAAAiI"]
[Tue Aug 18 12:55:01.857098 2026] [security2:error] [pid 67073:tid 67258] [client 20.51.153.15:8788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/zs.php"] [unique_id "aoSAVfcmepr5_nHgLbM9VQAAAkk"]
[Tue Aug 18 12:55:01.893287 2026] [security2:error] [pid 67073:tid 67224] [client 20.104.100.201:21462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/v5.php"] [unique_id "aoSAVfcmepr5_nHgLbM9WAAAAic"]
[Tue Aug 18 12:55:01.924318 2026] [security2:error] [pid 67073:tid 67252] [client 20.163.43.14:4284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/about.php"] [unique_id "aoSAVfcmepr5_nHgLbM9WQAAAkM"]
[Tue Aug 18 12:55:01.941021 2026] [security2:error] [pid 67073:tid 67254] [client 4.232.151.198:6808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/themes/zmousse/otuz1.php"] [unique_id "aoSAVfcmepr5_nHgLbM9WgAAAkU"]
[Tue Aug 18 12:55:01.963778 2026] [security2:error] [pid 67073:tid 67160] [remote 156.59.198.135:48720] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tribunadolitoral.com"] [uri "/wp-content/uploads/2024/11/edital_PSS-Educacao-PR.pdf"] [unique_id "aoSAVfcmepr5_nHgLbM9WwACGVQ"]
[Tue Aug 18 12:55:02.011645 2026] [security2:error] [pid 67073:tid 67237] [client 20.91.215.254:11744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSAVvcmepr5_nHgLbM9XQAAAjQ"]
[Tue Aug 18 12:55:02.028475 2026] [security2:error] [pid 67073:tid 67240] [client 104.209.144.33:20468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSAVvcmepr5_nHgLbM9XgAAAjc"]
[Tue Aug 18 12:55:02.064634 2026] [security2:error] [pid 67073:tid 67238] [client 20.171.51.14:36440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/97.php"] [unique_id "aoSAVvcmepr5_nHgLbM9XwAAAjU"]
[Tue Aug 18 12:55:02.084651 2026] [security2:error] [pid 67073:tid 67305] [client 74.248.133.44:23762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/Njima.php"] [unique_id "aoSAVvcmepr5_nHgLbM9YAAAAng"]
[Tue Aug 18 12:55:02.188372 2026] [security2:error] [pid 67073:tid 67226] [client 20.226.6.191:6599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/cah.php"] [unique_id "aoSAVvcmepr5_nHgLbM9YwAAAik"]
[Tue Aug 18 12:55:02.189006 2026] [security2:error] [pid 66623:tid 66893] [client 135.225.75.187:62892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSAVtO5rbWdOArH04KCeAAAAYk"]
[Tue Aug 18 12:55:02.305916 2026] [security2:error] [pid 67073:tid 67323] [client 5.31.227.224:7810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVvcmepr5_nHgLbM9ZwAAAoo"]
[Tue Aug 18 12:55:02.310735 2026] [security2:error] [pid 67073:tid 67323] [client 5.31.227.224:7810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVvcmepr5_nHgLbM9ZwAAAoo"]
[Tue Aug 18 12:55:02.388450 2026] [authz_core:error] [pid 67073:tid 67176] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:02.388701 2026] [authz_core:error] [pid 67073:tid 67176] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:02.405057 2026] [security2:error] [pid 66623:tid 66857] [client 20.29.77.16:27218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/dirs.php"] [unique_id "aoSAVtO5rbWdOArH04KCfAAAAWU"]
[Tue Aug 18 12:55:02.418428 2026] [security2:error] [pid 67073:tid 67246] [client 52.238.210.254:10210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/as.php"] [unique_id "aoSAVvcmepr5_nHgLbM9agAAAj0"]
[Tue Aug 18 12:55:02.454948 2026] [security2:error] [pid 67073:tid 67309] [client 74.248.136.165:42909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/wdf.php"] [unique_id "aoSAVvcmepr5_nHgLbM9bAAAAnw"]
[Tue Aug 18 12:55:02.519422 2026] [security2:error] [pid 67073:tid 67300] [client 20.226.6.191:6559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/system_log.php"] [unique_id "aoSAVvcmepr5_nHgLbM9bgAAAnM"]
[Tue Aug 18 12:55:02.555460 2026] [security2:error] [pid 67073:tid 67296] [client 20.100.169.31:39044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/k.php"] [unique_id "aoSAVvcmepr5_nHgLbM9bwAAAm8"]
[Tue Aug 18 12:55:02.574604 2026] [security2:error] [pid 67073:tid 67222] [client 20.163.43.14:4351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSAVvcmepr5_nHgLbM9cAAAAiU"]
[Tue Aug 18 12:55:02.587523 2026] [security2:error] [pid 67073:tid 67320] [client 52.139.47.57:27925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/atomlib.php"] [unique_id "aoSAVvcmepr5_nHgLbM9cQAAAoc"]
[Tue Aug 18 12:55:02.659778 2026] [security2:error] [pid 67073:tid 67232] [client 4.232.151.198:6792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/u.php"] [unique_id "aoSAVvcmepr5_nHgLbM9dAAAAi8"]
[Tue Aug 18 12:55:02.662993 2026] [security2:error] [pid 67073:tid 67269] [client 20.104.100.201:58454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoSAVvcmepr5_nHgLbM9dQAAAlQ"]
[Tue Aug 18 12:55:02.706941 2026] [security2:error] [pid 67073:tid 67099] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/i8hqok6nr.php"] [unique_id "aoSAVvcmepr5_nHgLbM9dgACjxc"]
[Tue Aug 18 12:55:02.749042 2026] [security2:error] [pid 66623:tid 66776] [client 132.196.61.152:61039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/8.php"] [unique_id "aoSAVtO5rbWdOArH04KCgQAAARQ"]
[Tue Aug 18 12:55:02.865140 2026] [security2:error] [pid 66623:tid 66794] [client 20.171.51.14:28816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/rh.php"] [unique_id "aoSAVtO5rbWdOArH04KCgwAAASY"]
[Tue Aug 18 12:55:02.869139 2026] [security2:error] [pid 67073:tid 67321] [client 66.249.77.96:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "buscacep.linkasites.com.br"] [uri "/livrocep/sp/limeira/jardim-colinas-de-sao-joao/img/avenida-luiz-berto-jardim-colinas-de-sao-joao-limeira-sp.webp"] [unique_id "aoSAVvcmepr5_nHgLbM9ewAAAog"]
[Tue Aug 18 12:55:02.933473 2026] [security2:error] [pid 67073:tid 67227] [client 20.48.236.86:10708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/clque.php"] [unique_id "aoSAVvcmepr5_nHgLbM9fQAAAio"]
[Tue Aug 18 12:55:02.948466 2026] [security2:error] [pid 67073:tid 67318] [client 138.36.100.162:42282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVfcmepr5_nHgLbM9TAAAAoU"]
[Tue Aug 18 12:55:02.977436 2026] [security2:error] [pid 67073:tid 67212] [client 52.139.47.57:18190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/item.php"] [unique_id "aoSAVvcmepr5_nHgLbM9fgAAAhs"]
[Tue Aug 18 12:55:02.994844 2026] [security2:error] [pid 67073:tid 67242] [client 20.116.17.175:57658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-temp.php"] [unique_id "aoSAVvcmepr5_nHgLbM9fwAAAjk"]
[Tue Aug 18 12:55:03.016513 2026] [security2:error] [pid 67073:tid 67303] [client 74.248.130.103:36809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/gec.php"] [unique_id "aoSAV_cmepr5_nHgLbM9gAAAAnY"]
[Tue Aug 18 12:55:03.019462 2026] [security2:error] [pid 67073:tid 67097] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/moon.php"] [unique_id "aoSAV_cmepr5_nHgLbM9gQACchU"]
[Tue Aug 18 12:55:03.035058 2026] [security2:error] [pid 67073:tid 67266] [client 20.163.43.14:4297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/f35.php"] [unique_id "aoSAV_cmepr5_nHgLbM9ggAAAlE"]
[Tue Aug 18 12:55:03.064330 2026] [security2:error] [pid 67073:tid 67308] [client 20.100.169.31:31430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/aa.php"] [unique_id "aoSAV_cmepr5_nHgLbM9hAAAAns"]
[Tue Aug 18 12:55:03.076330 2026] [security2:error] [pid 66623:tid 66872] [client 172.202.39.151:54021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/edit.php"] [unique_id "aoSAV9O5rbWdOArH04KCiAAAAXQ"]
[Tue Aug 18 12:55:03.323988 2026] [security2:error] [pid 66623:tid 66843] [client 20.104.85.180:7950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAV9O5rbWdOArH04KCjwAAAVc"]
[Tue Aug 18 12:55:03.326927 2026] [security2:error] [pid 66623:tid 66779] [client 20.151.109.219:12873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/sd.php"] [unique_id "aoSAV9O5rbWdOArH04KCkAAAARc"]
[Tue Aug 18 12:55:03.359175 2026] [security2:error] [pid 67073:tid 67325] [client 52.173.121.69:25012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSAV_cmepr5_nHgLbM9igAAAow"]
[Tue Aug 18 12:55:03.453498 2026] [security2:error] [pid 67073:tid 67312] [client 4.232.151.198:25820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/updates.php"] [unique_id "aoSAV_cmepr5_nHgLbM9jgAAAn8"]
[Tue Aug 18 12:55:03.473217 2026] [security2:error] [pid 66623:tid 66789] [client 20.51.153.15:9167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/iz.php"] [unique_id "aoSAV9O5rbWdOArH04KClAAAASE"]
[Tue Aug 18 12:55:03.496637 2026] [security2:error] [pid 66623:tid 66883] [client 149.34.210.141:63963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAV9O5rbWdOArH04KClgAAAX8"]
[Tue Aug 18 12:55:03.505620 2026] [security2:error] [pid 66623:tid 66833] [client 20.250.27.191:1874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSAV9O5rbWdOArH04KClwAAAU0"]
[Tue Aug 18 12:55:03.515553 2026] [security2:error] [pid 67073:tid 67203] [remote 50.6.108.183:44036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.108.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "proj.vitimarketing.com.br"] [uri "/wp-login.php"] [unique_id "aoSAV_cmepr5_nHgLbM9jAAChH8"]
[Tue Aug 18 12:55:03.591763 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:03.592024 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:03.601446 2026] [security2:error] [pid 67073:tid 67277] [client 20.91.215.254:12235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-admin/sx.php"] [unique_id "aoSAV_cmepr5_nHgLbM9kgAAAlw"]
[Tue Aug 18 12:55:03.633076 2026] [security2:error] [pid 67073:tid 67252] [client 135.225.75.187:23889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/z.php"] [unique_id "aoSAV_cmepr5_nHgLbM9lgAAAkM"]
[Tue Aug 18 12:55:03.658197 2026] [security2:error] [pid 67073:tid 67290] [client 4.223.164.152:37289] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-content/uploads/"] [unique_id "aoSAV_cmepr5_nHgLbM9lwAAAmk"]
[Tue Aug 18 12:55:03.659402 2026] [security2:error] [pid 67073:tid 67264] [client 20.226.6.191:6544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAV_cmepr5_nHgLbM9mAAAAk8"]
[Tue Aug 18 12:55:03.731849 2026] [security2:error] [pid 67073:tid 67240] [client 20.151.109.219:53242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/km.php"] [unique_id "aoSAV_cmepr5_nHgLbM9mQAAAjc"]
[Tue Aug 18 12:55:03.736414 2026] [security2:error] [pid 66623:tid 66817] [client 4.232.151.198:37277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/goods.php"] [unique_id "aoSAV9O5rbWdOArH04KCmQAAAT0"]
[Tue Aug 18 12:55:03.785380 2026] [security2:error] [pid 67073:tid 67310] [client 172.182.200.96:13824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/Cachex.php"] [unique_id "aoSAV_cmepr5_nHgLbM9mwAAAn0"]
[Tue Aug 18 12:55:03.791568 2026] [security2:error] [pid 66623:tid 66883] [client 149.34.210.141:63963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAV9O5rbWdOArH04KClgAAAX8"]
[Tue Aug 18 12:55:03.793377 2026] [security2:error] [pid 66623:tid 66818] [client 132.196.61.152:61020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/biufile.php"] [unique_id "aoSAV9O5rbWdOArH04KCmwAAAT4"]
[Tue Aug 18 12:55:03.839984 2026] [security2:error] [pid 67073:tid 67305] [client 20.226.56.190:3050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/22.php"] [unique_id "aoSAV_cmepr5_nHgLbM9nQAAAng"]
[Tue Aug 18 12:55:03.943160 2026] [security2:error] [pid 67073:tid 67306] [client 103.184.169.37:41488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAV_cmepr5_nHgLbM9nwAAAnk"]
[Tue Aug 18 12:55:03.943294 2026] [security2:error] [pid 67073:tid 67306] [client 103.184.169.37:41488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAV_cmepr5_nHgLbM9nwAAAnk"]
[Tue Aug 18 12:55:03.960786 2026] [security2:error] [pid 67073:tid 67258] [client 74.248.18.37:47608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/i.php"] [unique_id "aoSAV_cmepr5_nHgLbM9oQAAAkk"]
[Tue Aug 18 12:55:03.964699 2026] [security2:error] [pid 67073:tid 67220] [client 74.248.133.44:17534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/colors.php"] [unique_id "aoSAV_cmepr5_nHgLbM9ogAAAiM"]
[Tue Aug 18 12:55:03.972830 2026] [security2:error] [pid 67073:tid 67228] [client 20.250.27.191:1900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAV_cmepr5_nHgLbM9owAAAis"]
[Tue Aug 18 12:55:03.981229 2026] [security2:error] [pid 67073:tid 67324] [client 20.48.236.86:11028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/nano.php"] [unique_id "aoSAV_cmepr5_nHgLbM9pAAAAos"]
[Tue Aug 18 12:55:03.998021 2026] [security2:error] [pid 67073:tid 67323] [client 20.104.100.201:58905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoSAV_cmepr5_nHgLbM9pgAAAoo"]
[Tue Aug 18 12:55:04.027854 2026] [autoindex:error] [pid 67073:tid 67311] [client 3.86.142.91:56386] AH01276: Cannot serve directory /home4/vaicercom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:04.095225 2026] [security2:error] [pid 67073:tid 67130] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/motu.php"] [unique_id "aoSAWPcmepr5_nHgLbM9qQACZTY"]
[Tue Aug 18 12:55:04.138845 2026] [security2:error] [pid 66623:tid 66792] [client 20.163.43.14:3076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/function/function.php"] [unique_id "aoSAWNO5rbWdOArH04KCqwAAASQ"]
[Tue Aug 18 12:55:04.158498 2026] [security2:error] [pid 67073:tid 67221] [client 20.116.17.175:11230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-css.php"] [unique_id "aoSAWPcmepr5_nHgLbM9sQAAAiQ"]
[Tue Aug 18 12:55:04.168732 2026] [security2:error] [pid 67073:tid 67259] [client 4.232.151.198:25800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/upload/autoload_classmap.php"] [unique_id "aoSAWPcmepr5_nHgLbM9sgAAAko"]
[Tue Aug 18 12:55:04.175100 2026] [security2:error] [pid 66623:tid 66853] [client 172.182.200.96:14232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSAWNO5rbWdOArH04KCrAAAAWE"]
[Tue Aug 18 12:55:04.220641 2026] [security2:error] [pid 67073:tid 67210] [client 20.91.215.254:20358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAWPcmepr5_nHgLbM9tAAAAhk"]
[Tue Aug 18 12:55:04.287790 2026] [security2:error] [pid 66623:tid 66766] [client 104.209.144.33:34171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSAWNO5rbWdOArH04KCrQAAAQo"]
[Tue Aug 18 12:55:04.322698 2026] [security2:error] [pid 66623:tid 66814] [client 52.173.121.69:58030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAWNO5rbWdOArH04KCrgAAATo"]
[Tue Aug 18 12:55:04.338057 2026] [security2:error] [pid 66623:tid 66799] [client 74.248.136.165:64101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ff1.php"] [unique_id "aoSAWNO5rbWdOArH04KCsQAAASs"]
[Tue Aug 18 12:55:04.405700 2026] [security2:error] [pid 67073:tid 67171] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAWPcmepr5_nHgLbM9zwACb18"]
[Tue Aug 18 12:55:04.444524 2026] [security2:error] [pid 67073:tid 67298] [client 74.248.18.37:12387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/test.php"] [unique_id "aoSAWPcmepr5_nHgLbM90AAAAnE"]
[Tue Aug 18 12:55:04.566561 2026] [security2:error] [pid 66623:tid 66780] [client 20.29.77.16:49251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/fresh.php"] [unique_id "aoSAWNO5rbWdOArH04KCtAAAARg"]
[Tue Aug 18 12:55:04.691622 2026] [security2:error] [pid 66623:tid 66772] [client 20.250.13.23:42542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/info.php"] [unique_id "aoSAWNO5rbWdOArH04KCuAAAARA"]
[Tue Aug 18 12:55:04.792085 2026] [security2:error] [pid 67073:tid 67307] [client 20.104.100.201:21459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/dk.php"] [unique_id "aoSAWPcmepr5_nHgLbM91wAAAno"]
[Tue Aug 18 12:55:04.916840 2026] [security2:error] [pid 67073:tid 67242] [client 20.171.51.14:58843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/yg.php"] [unique_id "aoSAWPcmepr5_nHgLbM93AAAAjk"]
[Tue Aug 18 12:55:04.945525 2026] [security2:error] [pid 66623:tid 66805] [client 52.139.47.57:19934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/sid3.php"] [unique_id "aoSAWNO5rbWdOArH04KCvgAAATE"]
[Tue Aug 18 12:55:05.097712 2026] [authz_core:error] [pid 67073:tid 67125] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:05.097990 2026] [authz_core:error] [pid 67073:tid 67125] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:05.176454 2026] [security2:error] [pid 67073:tid 67245] [client 172.202.39.151:33515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-content/index.php"] [unique_id "aoSAWfcmepr5_nHgLbM97gAAAjw"]
[Tue Aug 18 12:55:05.322185 2026] [security2:error] [pid 67073:tid 67312] [client 172.202.39.151:65261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/f35.php"] [unique_id "aoSAWfcmepr5_nHgLbM98AAAAn8"]
[Tue Aug 18 12:55:05.325101 2026] [security2:error] [pid 66623:tid 66869] [client 20.65.98.162:54975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSAWdO5rbWdOArH04KCwAAAAXE"]
[Tue Aug 18 12:55:05.399076 2026] [authz_core:error] [pid 67073:tid 67198] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:05.399344 2026] [authz_core:error] [pid 67073:tid 67198] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:05.408586 2026] [security2:error] [pid 66623:tid 66815] [client 52.238.210.254:8932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/bolt.php"] [unique_id "aoSAWdO5rbWdOArH04KCwgAAATs"]
[Tue Aug 18 12:55:05.431979 2026] [security2:error] [pid 67073:tid 67219] [client 20.151.109.219:53224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/mf.php"] [unique_id "aoSAWfcmepr5_nHgLbM98wAAAiI"]
[Tue Aug 18 12:55:05.474814 2026] [security2:error] [pid 67073:tid 67277] [client 172.202.39.151:14692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSAWfcmepr5_nHgLbM99AAAAlw"]
[Tue Aug 18 12:55:05.494614 2026] [security2:error] [pid 67073:tid 67279] [client 52.139.47.57:9041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/size.php"] [unique_id "aoSAWfcmepr5_nHgLbM99QAAAl4"]
[Tue Aug 18 12:55:05.496498 2026] [security2:error] [pid 66623:tid 66831] [client 4.223.164.152:37280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAWdO5rbWdOArH04KCwwAAAUs"]
[Tue Aug 18 12:55:05.516840 2026] [security2:error] [pid 67073:tid 67327] [client 20.91.215.254:27407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/st.php"] [unique_id "aoSAWfcmepr5_nHgLbM99gAAAo4"]
[Tue Aug 18 12:55:05.699476 2026] [authz_core:error] [pid 67073:tid 67140] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:05.699746 2026] [authz_core:error] [pid 67073:tid 67140] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:05.733376 2026] [security2:error] [pid 67073:tid 67316] [client 52.238.210.254:8333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/222.php"] [unique_id "aoSAWfcmepr5_nHgLbM9-AAAAoM"]
[Tue Aug 18 12:55:05.740994 2026] [security2:error] [pid 67073:tid 67290] [client 192.141.172.134:56422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAWfcmepr5_nHgLbM9-QAAAmk"]
[Tue Aug 18 12:55:05.741181 2026] [security2:error] [pid 67073:tid 67290] [client 192.141.172.134:56422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAWfcmepr5_nHgLbM9-QAAAmk"]
[Tue Aug 18 12:55:05.769006 2026] [security2:error] [pid 67073:tid 67310] [client 20.250.27.191:1877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/blurbs.php"] [unique_id "aoSAWfcmepr5_nHgLbM9-gAAAn0"]
[Tue Aug 18 12:55:05.805367 2026] [security2:error] [pid 66623:tid 66781] [client 213.35.127.232:54547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAWdO5rbWdOArH04KCxgAAARk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:05.820979 2026] [security2:error] [pid 66623:tid 66808] [client 135.225.75.187:9508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/222.php"] [unique_id "aoSAWdO5rbWdOArH04KCxwAAATQ"]
[Tue Aug 18 12:55:05.840936 2026] [security2:error] [pid 67073:tid 67331] [client 20.163.43.14:3199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSAWfcmepr5_nHgLbM9_gAAApI"]
[Tue Aug 18 12:55:05.858460 2026] [security2:error] [pid 67073:tid 67275] [client 104.209.144.33:19589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSAWfcmepr5_nHgLbM9_wAAAlo"]
[Tue Aug 18 12:55:05.889453 2026] [security2:error] [pid 67073:tid 67217] [client 20.151.109.219:12886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ie.php"] [unique_id "aoSAWfcmepr5_nHgLbM-AAAAAiA"]
[Tue Aug 18 12:55:05.892206 2026] [security2:error] [pid 67073:tid 67301] [client 52.139.47.57:63050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/black.php"] [unique_id "aoSAWfcmepr5_nHgLbM-AQAAAnQ"]
[Tue Aug 18 12:55:05.944701 2026] [security2:error] [pid 67073:tid 67303] [client 74.248.18.37:12672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/test1.php"] [unique_id "aoSAWfcmepr5_nHgLbM-AgAAAnY"]
[Tue Aug 18 12:55:05.961483 2026] [security2:error] [pid 67073:tid 67278] [client 20.91.215.254:20402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAWfcmepr5_nHgLbM-AwAAAl0"]
[Tue Aug 18 12:55:06.128946 2026] [security2:error] [pid 67073:tid 67236] [client 20.104.100.201:58466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/bal.php"] [unique_id "aoSAWvcmepr5_nHgLbM-BQAAAjM"]
[Tue Aug 18 12:55:06.152580 2026] [security2:error] [pid 67073:tid 67267] [client 74.248.136.165:59458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/guk.php"] [unique_id "aoSAWvcmepr5_nHgLbM-BgAAAlI"]
[Tue Aug 18 12:55:06.165393 2026] [security2:error] [pid 66623:tid 66863] [client 74.248.133.44:12161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "aoSAWtO5rbWdOArH04KCyAAAAWs"]
[Tue Aug 18 12:55:06.169963 2026] [security2:error] [pid 66623:tid 66866] [client 20.116.17.175:57467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/flox.php"] [unique_id "aoSAWtO5rbWdOArH04KCyQAAAW4"]
[Tue Aug 18 12:55:06.216608 2026] [security2:error] [pid 66623:tid 66857] [client 4.232.151.198:6804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/uploads/admin.php"] [unique_id "aoSAWtO5rbWdOArH04KCygAAAWU"]
[Tue Aug 18 12:55:06.235855 2026] [security2:error] [pid 67073:tid 67309] [client 20.250.27.191:1901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/bajah.php"] [unique_id "aoSAWvcmepr5_nHgLbM-CQAAAnw"]
[Tue Aug 18 12:55:06.355829 2026] [security2:error] [pid 67073:tid 67296] [client 20.104.85.180:18854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/403.php"] [unique_id "aoSAWvcmepr5_nHgLbM-DAAAAm8"]
[Tue Aug 18 12:55:06.379507 2026] [security2:error] [pid 66623:tid 66794] [client 20.48.236.86:10781] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "m2mit.info"] [uri "/.mopj.php"] [unique_id "aoSAWtO5rbWdOArH04KCywAAASY"]
[Tue Aug 18 12:55:06.385646 2026] [security2:error] [pid 66623:tid 66851] [client 20.29.77.16:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/admin404.php"] [unique_id "aoSAWtO5rbWdOArH04KCzAAAAV8"]
[Tue Aug 18 12:55:06.425272 2026] [security2:error] [pid 67073:tid 67273] [client 178.153.171.161:41304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAWfcmepr5_nHgLbM98QAAAlg"]
[Tue Aug 18 12:55:06.425449 2026] [security2:error] [pid 67073:tid 67273] [client 178.153.171.161:41304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAWfcmepr5_nHgLbM98QAAAlg"]
[Tue Aug 18 12:55:06.440144 2026] [security2:error] [pid 67073:tid 67222] [client 20.226.56.190:2511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/zs.php"] [unique_id "aoSAWvcmepr5_nHgLbM-DQAAAiU"]
[Tue Aug 18 12:55:06.600709 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:06.600989 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:06.683751 2026] [security2:error] [pid 67073:tid 67252] [client 114.5.214.109:49800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAWvcmepr5_nHgLbM-FAAAAkM"]
[Tue Aug 18 12:55:06.683906 2026] [security2:error] [pid 67073:tid 67252] [client 114.5.214.109:49800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAWvcmepr5_nHgLbM-FAAAAkM"]
[Tue Aug 18 12:55:06.700422 2026] [security2:error] [pid 67073:tid 67244] [client 20.250.27.191:1864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/domvf.php"] [unique_id "aoSAWvcmepr5_nHgLbM-FQAAAjs"]
[Tue Aug 18 12:55:06.729148 2026] [security2:error] [pid 66623:tid 66812] [client 4.223.164.152:28518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/admin.php"] [unique_id "aoSAWtO5rbWdOArH04KC0QAAATg"]
[Tue Aug 18 12:55:06.797347 2026] [security2:error] [pid 66623:tid 66887] [client 52.173.121.69:63236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/blog/byp.php"] [unique_id "aoSAWtO5rbWdOArH04KC0gAAAYM"]
[Tue Aug 18 12:55:06.825146 2026] [security2:error] [pid 67073:tid 67208] [client 20.51.153.15:9172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/se.php"] [unique_id "aoSAWvcmepr5_nHgLbM-GwAAAhc"]
[Tue Aug 18 12:55:06.942778 2026] [security2:error] [pid 67073:tid 67313] [client 20.100.169.31:31459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/abcd.php"] [unique_id "aoSAWvcmepr5_nHgLbM-IQAAAoA"]
[Tue Aug 18 12:55:06.959760 2026] [security2:error] [pid 67073:tid 67243] [client 20.48.236.86:10746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/bengi.php"] [unique_id "aoSAWvcmepr5_nHgLbM-IgAAAjo"]
[Tue Aug 18 12:55:07.088796 2026] [security2:error] [pid 67073:tid 67307] [client 52.139.47.57:18208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/tgrs.php"] [unique_id "aoSAW_cmepr5_nHgLbM-IwAAAno"]
[Tue Aug 18 12:55:07.160437 2026] [security2:error] [pid 67073:tid 67255] [client 20.250.27.191:1889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/fpwch.php"] [unique_id "aoSAW_cmepr5_nHgLbM-KwAAAkY"]
[Tue Aug 18 12:55:07.308741 2026] [security2:error] [pid 67073:tid 67212] [client 20.91.215.254:27401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSAW_cmepr5_nHgLbM-LQAAAhs"]
[Tue Aug 18 12:55:07.337955 2026] [autoindex:error] [pid 66623:tid 66779] [client 172.202.39.151:65216] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:07.422869 2026] [security2:error] [pid 67073:tid 67183] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/ncx.php"] [unique_id "aoSAW_cmepr5_nHgLbM-MgACKGs"]
[Tue Aug 18 12:55:07.520947 2026] [security2:error] [pid 67073:tid 67264] [client 20.42.19.40:9709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/ioxi-o.php"] [unique_id "aoSAW_cmepr5_nHgLbM-NQAAAk8"]
[Tue Aug 18 12:55:07.534557 2026] [security2:error] [pid 67073:tid 67228] [client 158.158.34.183:26145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/f5.php"] [unique_id "aoSAWvcmepr5_nHgLbM-EAAAAis"]
[Tue Aug 18 12:55:07.626228 2026] [security2:error] [pid 67073:tid 67290] [client 20.65.98.162:38042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/mgrr.php"] [unique_id "aoSAW_cmepr5_nHgLbM-OwAAAmk"]
[Tue Aug 18 12:55:07.653049 2026] [security2:error] [pid 67073:tid 67240] [client 20.48.236.86:10387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/file2.php"] [unique_id "aoSAW_cmepr5_nHgLbM-PAAAAjc"]
[Tue Aug 18 12:55:07.703572 2026] [security2:error] [pid 67073:tid 67272] [client 104.209.144.33:19637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSAW_cmepr5_nHgLbM-PwAAAlc"]
[Tue Aug 18 12:55:07.812817 2026] [security2:error] [pid 67073:tid 67301] [client 20.42.19.40:9696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/av.php"] [unique_id "aoSAW_cmepr5_nHgLbM-QwAAAnQ"]
[Tue Aug 18 12:55:07.820781 2026] [security2:error] [pid 67073:tid 67279] [client 52.139.47.57:42975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/ws83.php"] [unique_id "aoSAW_cmepr5_nHgLbM-RAAAAl4"]
[Tue Aug 18 12:55:07.939636 2026] [lsapi:error] [pid 67073:tid 67103] [remote 168.181.166.128:1505] [host riobrancoconsultorios.com.br] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown, referer: https://riobrancoconsultorios.com.br/agenda/painel/index.php?pagina=agendamentos_form
[Tue Aug 18 12:55:07.939654 2026] [lsapi:error] [pid 67073:tid 67103] [remote 168.181.166.128:1505] [host riobrancoconsultorios.com.br] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache, referer: https://riobrancoconsultorios.com.br/agenda/painel/index.php?pagina=agendamentos_form
[Tue Aug 18 12:55:07.939659 2026] [lsapi:error] [pid 67073:tid 67103] [remote 168.181.166.128:1505] [host riobrancoconsultorios.com.br] Client error on sending request(POST /agenda/painel/paginas/agendamentos/listar-horarios.php HTTP/2.0); uri(/agenda/painel/paginas/agendamentos/listar-horarios.php) content-length(59): user_get_body(tmpstackbuf, 16384): read from client failed, referer: https://riobrancoconsultorios.com.br/agenda/painel/index.php?pagina=agendamentos_form
[Tue Aug 18 12:55:08.049014 2026] [security2:error] [pid 67073:tid 67217] [client 20.91.215.254:27432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-configs.php"] [unique_id "aoSAXPcmepr5_nHgLbM-TwAAAiA"]
[Tue Aug 18 12:55:08.131323 2026] [security2:error] [pid 67073:tid 67275] [client 20.205.121.237:5089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/ty.php"] [unique_id "aoSAXPcmepr5_nHgLbM-UgAAAlo"]
[Tue Aug 18 12:55:08.155321 2026] [security2:error] [pid 67073:tid 67210] [client 20.51.153.15:8811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/vp.php"] [unique_id "aoSAXPcmepr5_nHgLbM-UwAAAhk"]
[Tue Aug 18 12:55:08.179036 2026] [security2:error] [pid 67073:tid 67311] [client 20.100.169.31:3019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/admin.php"] [unique_id "aoSAXPcmepr5_nHgLbM-VAAAAn4"]
[Tue Aug 18 12:55:08.202606 2026] [security2:error] [pid 67073:tid 67300] [client 52.238.210.254:8908] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/cgi-bin/"] [unique_id "aoSAXPcmepr5_nHgLbM-VQAAAnM"]
[Tue Aug 18 12:55:08.208507 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.6.191:6561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAXPcmepr5_nHgLbM-VgAAAlg"]
[Tue Aug 18 12:55:08.349354 2026] [security2:error] [pid 67073:tid 67251] [client 74.248.18.37:17551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSAXPcmepr5_nHgLbM-WAAAAkI"]
[Tue Aug 18 12:55:08.354568 2026] [security2:error] [pid 67073:tid 67282] [client 20.29.77.16:51354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/loading.php"] [unique_id "aoSAXPcmepr5_nHgLbM-WQAAAmE"]
[Tue Aug 18 12:55:08.493438 2026] [security2:error] [pid 67073:tid 67205] [client 20.48.236.86:10385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/gm.php"] [unique_id "aoSAXPcmepr5_nHgLbM-XQAAAhQ"]
[Tue Aug 18 12:55:08.649867 2026] [security2:error] [pid 67073:tid 67121] [remote 14.194.153.54:39392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.153.194.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cesarinox.com"] [uri "/wp-login.php"] [unique_id "aoSAXPcmepr5_nHgLbM-YAACiC0"]
[Tue Aug 18 12:55:08.676120 2026] [security2:error] [pid 67073:tid 67243] [client 20.42.19.40:9719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp.php"] [unique_id "aoSAXPcmepr5_nHgLbM-YQAAAjo"]
[Tue Aug 18 12:55:08.801794 2026] [security2:error] [pid 67073:tid 67242] [client 4.223.164.152:46198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/file52.php"] [unique_id "aoSAXPcmepr5_nHgLbM-YwAAAjk"]
[Tue Aug 18 12:55:08.938747 2026] [security2:error] [pid 67073:tid 67266] [client 20.250.27.191:1857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/adminner.php"] [unique_id "aoSAXPcmepr5_nHgLbM-ZwAAAlE"]
[Tue Aug 18 12:55:09.028122 2026] [security2:error] [pid 66623:tid 66817] [client 132.196.61.152:61004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/coffexium.php"] [unique_id "aoSAXdO5rbWdOArH04KC2AAAAT0"]
[Tue Aug 18 12:55:09.159289 2026] [security2:error] [pid 67073:tid 67312] [client 104.209.144.33:33718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/assets/admin/login/info.php"] [unique_id "aoSAXfcmepr5_nHgLbM-bAAAAn8"]
[Tue Aug 18 12:55:09.312226 2026] [authz_core:error] [pid 67073:tid 67177] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:09.312497 2026] [authz_core:error] [pid 67073:tid 67177] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:09.334024 2026] [security2:error] [pid 66623:tid 66872] [client 5.253.205.188:56868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/home.sql"] [unique_id "aoSAXdO5rbWdOArH04KC2wAAAXQ"], referer: https://medihub.com.br/home.sql
[Tue Aug 18 12:55:09.406015 2026] [security2:error] [pid 67073:tid 67277] [client 20.250.27.191:1911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/abcd.php"] [unique_id "aoSAXfcmepr5_nHgLbM-dAAAAlw"]
[Tue Aug 18 12:55:09.429302 2026] [security2:error] [pid 67073:tid 67264] [client 52.173.121.69:51509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSAXfcmepr5_nHgLbM-fAAAAk8"]
[Tue Aug 18 12:55:09.477569 2026] [security2:error] [pid 67073:tid 67262] [client 20.104.100.201:58882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/yawa.php"] [unique_id "aoSAXfcmepr5_nHgLbM-fgAAAk0"]
[Tue Aug 18 12:55:09.520215 2026] [security2:error] [pid 67073:tid 67285] [client 74.248.133.44:11652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/radio.php"] [unique_id "aoSAXfcmepr5_nHgLbM-fwAAAmQ"]
[Tue Aug 18 12:55:09.546780 2026] [security2:error] [pid 67073:tid 67248] [client 20.29.77.16:20810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/conn-test.php"] [unique_id "aoSAXfcmepr5_nHgLbM-gAAAAj8"]
[Tue Aug 18 12:55:09.563524 2026] [security2:error] [pid 67073:tid 67304] [client 20.91.215.254:20388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/abc.php"] [unique_id "aoSAXfcmepr5_nHgLbM-gQAAAnc"]
[Tue Aug 18 12:55:09.584213 2026] [security2:error] [pid 67073:tid 67224] [client 20.163.43.14:3129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSAXfcmepr5_nHgLbM-gwAAAic"]
[Tue Aug 18 12:55:09.595328 2026] [security2:error] [pid 67073:tid 67208] [client 20.91.215.254:12140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-post.php"] [unique_id "aoSAXfcmepr5_nHgLbM-hAAAAhc"]
[Tue Aug 18 12:55:09.625643 2026] [security2:error] [pid 67073:tid 67272] [client 52.238.210.254:9039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/asasx.php"] [unique_id "aoSAXfcmepr5_nHgLbM-hQAAAlc"]
[Tue Aug 18 12:55:09.629910 2026] [security2:error] [pid 66623:tid 66672] [remote 89.185.225.24:32892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.225.185.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "boscoagriturismo.com"] [uri "/wp-login.php"] [unique_id "aoSAWtO5rbWdOArH04KCzgABeCM"]
[Tue Aug 18 12:55:09.787746 2026] [security2:error] [pid 66623:tid 66836] [client 20.116.17.175:57632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/op.php"] [unique_id "aoSAXdO5rbWdOArH04KC3AAAAVA"]
[Tue Aug 18 12:55:09.857929 2026] [security2:error] [pid 66623:tid 66892] [client 20.51.153.15:9204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/s.php"] [unique_id "aoSAXdO5rbWdOArH04KC3QAAAYg"]
[Tue Aug 18 12:55:09.953221 2026] [security2:error] [pid 66623:tid 66801] [client 135.225.75.187:17641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/G-in.php"] [unique_id "aoSAXdO5rbWdOArH04KC3gAAAS0"]
[Tue Aug 18 12:55:09.957926 2026] [security2:error] [pid 67073:tid 67297] [client 52.139.47.57:16692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/style.php"] [unique_id "aoSAXfcmepr5_nHgLbM-jwAAAnA"]
[Tue Aug 18 12:55:09.994680 2026] [security2:error] [pid 67073:tid 67230] [client 52.238.210.254:8910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/class-t.api.php"] [unique_id "aoSAXfcmepr5_nHgLbM-kAAAAi0"]
[Tue Aug 18 12:55:10.036334 2026] [security2:error] [pid 66623:tid 66861] [client 132.196.61.152:55311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/33.php"] [unique_id "aoSAXtO5rbWdOArH04KC3wAAAWk"]
[Tue Aug 18 12:55:10.043877 2026] [security2:error] [pid 67073:tid 67267] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAXfcmepr5_nHgLbM-jgACUn4"]
[Tue Aug 18 12:55:10.214865 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:10.215134 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:10.268699 2026] [security2:error] [pid 66623:tid 66879] [client 158.158.34.183:16580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/al.php"] [unique_id "aoSAXtO5rbWdOArH04KC4AAAAXs"]
[Tue Aug 18 12:55:10.300239 2026] [security2:error] [pid 66623:tid 66820] [client 20.250.13.23:49341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/a.php"] [unique_id "aoSAXtO5rbWdOArH04KC4QAAAUA"]
[Tue Aug 18 12:55:10.310052 2026] [security2:error] [pid 67073:tid 67320] [client 20.42.19.40:9611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/file2.php"] [unique_id "aoSAXvcmepr5_nHgLbM-mAAAAoc"]
[Tue Aug 18 12:55:10.369714 2026] [security2:error] [pid 66623:tid 66730] [remote 162.240.105.3:57678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.105.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocionais.com.br"] [uri "/wp-login.php"] [unique_id "aoSAXtO5rbWdOArH04KC4gABOl0"]
[Tue Aug 18 12:55:10.386254 2026] [security2:error] [pid 66623:tid 66795] [client 20.116.17.175:57646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/1xmomo.php"] [unique_id "aoSAXtO5rbWdOArH04KC4wAAASc"]
[Tue Aug 18 12:55:10.461799 2026] [security2:error] [pid 67073:tid 67282] [client 52.173.121.69:24969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSAXvcmepr5_nHgLbM-nAAAAmE"]
[Tue Aug 18 12:55:10.468822 2026] [security2:error] [pid 67073:tid 67252] [client 20.163.43.14:2000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/ok.php"] [unique_id "aoSAXvcmepr5_nHgLbM-nQAAAkM"]
[Tue Aug 18 12:55:10.506250 2026] [security2:error] [pid 67073:tid 67235] [client 20.100.169.31:31425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/adminfuns.php"] [unique_id "aoSAXvcmepr5_nHgLbM-ngAAAjI"]
[Tue Aug 18 12:55:10.603324 2026] [security2:error] [pid 66623:tid 66849] [client 20.42.19.40:9686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/images/class-config.php"] [unique_id "aoSAXtO5rbWdOArH04KC5AAAAV0"]
[Tue Aug 18 12:55:10.632164 2026] [security2:error] [pid 67073:tid 67250] [client 153.67.129.223:50022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.129.67.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "i-databi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAXfcmepr5_nHgLbM-bwAAAkE"]
[Tue Aug 18 12:55:10.632299 2026] [security2:error] [pid 67073:tid 67250] [client 153.67.129.223:50022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "i-databi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAXfcmepr5_nHgLbM-bwAAAkE"]
[Tue Aug 18 12:55:10.659988 2026] [security2:error] [pid 67073:tid 67233] [client 197.184.64.235:41922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAXvcmepr5_nHgLbM-ogAAAjA"]
[Tue Aug 18 12:55:10.660078 2026] [security2:error] [pid 67073:tid 67233] [client 197.184.64.235:41922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAXvcmepr5_nHgLbM-ogAAAjA"]
[Tue Aug 18 12:55:10.688574 2026] [security2:error] [pid 67073:tid 67247] [client 20.104.85.180:7240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/as.php"] [unique_id "aoSAXvcmepr5_nHgLbM-pAAAAj4"]
[Tue Aug 18 12:55:10.798075 2026] [security2:error] [pid 67073:tid 67249] [client 52.238.210.254:8265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/edit.php"] [unique_id "aoSAXvcmepr5_nHgLbM-qAAAAkA"]
[Tue Aug 18 12:55:10.819745 2026] [security2:error] [pid 67073:tid 67216] [client 20.104.100.201:58883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSAXvcmepr5_nHgLbM-qQAAAh8"]
[Tue Aug 18 12:55:10.852185 2026] [security2:error] [pid 67073:tid 67255] [client 20.163.43.14:1991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/item.php"] [unique_id "aoSAXvcmepr5_nHgLbM-qgAAAkY"]
[Tue Aug 18 12:55:10.874290 2026] [security2:error] [pid 67073:tid 67281] [client 192.141.172.134:56718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAXvcmepr5_nHgLbM-qwAAAmA"]
[Tue Aug 18 12:55:10.970082 2026] [security2:error] [pid 66623:tid 66884] [client 135.225.75.187:45868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/xxx.php"] [unique_id "aoSAXtO5rbWdOArH04KC5wAAAYA"]
[Tue Aug 18 12:55:10.983907 2026] [security2:error] [pid 67073:tid 67276] [client 167.235.143.113:12324] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.saojudas.com.br"] [uri "/index.php"] [unique_id "aoSAXvcmepr5_nHgLbM-rAAAAls"], referer: https://www.saojudas.com.br/
[Tue Aug 18 12:55:11.027708 2026] [security2:error] [pid 67073:tid 67240] [client 213.35.127.232:55645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAX_cmepr5_nHgLbM-rQAAAjc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:11.110382 2026] [authz_core:error] [pid 67073:tid 67179] [remote 57.141.22.8:29896] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:11.110642 2026] [authz_core:error] [pid 67073:tid 67179] [remote 57.141.22.8:29896] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:11.118378 2026] [authz_core:error] [pid 67073:tid 67076] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:11.118627 2026] [authz_core:error] [pid 67073:tid 67076] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:11.167915 2026] [security2:error] [pid 67073:tid 67290] [client 172.182.200.96:14199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSAX_cmepr5_nHgLbM-tAAAAmk"]
[Tue Aug 18 12:55:11.182422 2026] [security2:error] [pid 67073:tid 67248] [client 104.209.144.33:21390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSAX_cmepr5_nHgLbM-tQAAAj8"]
[Tue Aug 18 12:55:11.205405 2026] [security2:error] [pid 66623:tid 66839] [client 20.100.169.31:2954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/akc.php"] [unique_id "aoSAX9O5rbWdOArH04KC6AAAAVM"]
[Tue Aug 18 12:55:11.245940 2026] [security2:error] [pid 67073:tid 67281] [client 192.141.172.134:56718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAXvcmepr5_nHgLbM-qwAAAmA"]
[Tue Aug 18 12:55:11.272142 2026] [security2:error] [pid 67073:tid 67215] [client 20.65.69.59:3658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAX_cmepr5_nHgLbM-2QAAAh4"]
[Tue Aug 18 12:55:11.301275 2026] [security2:error] [pid 67073:tid 67302] [client 20.205.121.237:5079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/u.php"] [unique_id "aoSAX_cmepr5_nHgLbM-2gAAAnU"]
[Tue Aug 18 12:55:11.322156 2026] [security2:error] [pid 67073:tid 67265] [client 20.42.19.40:9627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/alfa.php"] [unique_id "aoSAX_cmepr5_nHgLbM-2wAAAlA"]
[Tue Aug 18 12:55:11.424387 2026] [security2:error] [pid 67073:tid 67301] [client 213.202.253.4:54798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/postnews.php"] [unique_id "aoSAX_cmepr5_nHgLbM-3wAAAnQ"], referer: www.google.com
[Tue Aug 18 12:55:11.457079 2026] [security2:error] [pid 66623:tid 66882] [client 138.36.100.162:43183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAX9O5rbWdOArH04KC6QAAAX4"]
[Tue Aug 18 12:55:11.457214 2026] [security2:error] [pid 66623:tid 66882] [client 138.36.100.162:43183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAX9O5rbWdOArH04KC6QAAAX4"]
[Tue Aug 18 12:55:11.629640 2026] [security2:error] [pid 67073:tid 67306] [client 52.173.121.69:16507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSAX_cmepr5_nHgLbM-4wAAAnk"]
[Tue Aug 18 12:55:11.754126 2026] [security2:error] [pid 67073:tid 67254] [client 4.232.151.198:42240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/file.php"] [unique_id "aoSAX_cmepr5_nHgLbM-5gAAAkU"]
[Tue Aug 18 12:55:11.773005 2026] [security2:error] [pid 67073:tid 67320] [client 52.238.210.254:10134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/ff1.php"] [unique_id "aoSAX_cmepr5_nHgLbM-5wAAAoc"]
[Tue Aug 18 12:55:11.849306 2026] [security2:error] [pid 67073:tid 67258] [client 20.250.13.23:51508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/chosen.php"] [unique_id "aoSAX_cmepr5_nHgLbM-6QAAAkk"]
[Tue Aug 18 12:55:11.885654 2026] [security2:error] [pid 66623:tid 66807] [client 20.226.56.190:45013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/iz.php"] [unique_id "aoSAX9O5rbWdOArH04KC7AAAATM"]
[Tue Aug 18 12:55:11.982657 2026] [security2:error] [pid 67073:tid 67287] [client 132.196.61.152:60288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/dex.php"] [unique_id "aoSAX_cmepr5_nHgLbM-7gAAAmY"]
[Tue Aug 18 12:55:12.007298 2026] [security2:error] [pid 67073:tid 67266] [client 3.79.134.69:4264] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.saojudas.com.br"] [uri "/index.php"] [unique_id "aoSAX_cmepr5_nHgLbM-7AAAAlE"], referer: https://www.saojudas.com.br
[Tue Aug 18 12:55:12.026454 2026] [security2:error] [pid 66623:tid 66805] [client 20.104.85.180:8020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAYNO5rbWdOArH04KC7QAAATE"]
[Tue Aug 18 12:55:12.040328 2026] [security2:error] [pid 67073:tid 67261] [client 52.139.47.57:42950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/bs1.php"] [unique_id "aoSAYPcmepr5_nHgLbM-8AAAAkw"]
[Tue Aug 18 12:55:12.053202 2026] [security2:error] [pid 66623:tid 66834] [client 104.209.144.33:20442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSAYNO5rbWdOArH04KC7gAAAU4"]
[Tue Aug 18 12:55:12.063397 2026] [security2:error] [pid 66623:tid 66770] [client 20.42.19.40:9726] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "plantaodasbaterias.aju.br"] [uri "/1.php"] [unique_id "aoSAYNO5rbWdOArH04KC7wAAAQ4"]
[Tue Aug 18 12:55:12.063470 2026] [security2:error] [pid 66623:tid 66770] [client 20.42.19.40:9726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/1.php"] [unique_id "aoSAYNO5rbWdOArH04KC7wAAAQ4"]
[Tue Aug 18 12:55:12.088135 2026] [security2:error] [pid 66623:tid 66838] [client 4.223.164.152:54210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/geck.php"] [unique_id "aoSAYNO5rbWdOArH04KC8AAAAVI"]
[Tue Aug 18 12:55:12.134578 2026] [security2:error] [pid 66623:tid 66893] [client 172.202.39.151:55121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/as.php"] [unique_id "aoSAYNO5rbWdOArH04KC8QAAAYk"]
[Tue Aug 18 12:55:12.235037 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:12.235310 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:12.299254 2026] [security2:error] [pid 67073:tid 67277] [client 20.91.215.254:13270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/sf.php"] [unique_id "aoSAYPcmepr5_nHgLbM-9wAAAlw"]
[Tue Aug 18 12:55:12.306583 2026] [security2:error] [pid 67073:tid 67331] [client 20.65.98.162:52625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/55.php"] [unique_id "aoSAYPcmepr5_nHgLbM--AAAApI"]
[Tue Aug 18 12:55:12.373078 2026] [security2:error] [pid 66623:tid 66777] [client 20.104.85.180:7957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSAYNO5rbWdOArH04KC8gAAARU"]
[Tue Aug 18 12:55:12.388327 2026] [security2:error] [pid 66623:tid 66885] [client 20.42.19.40:9681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/222.php"] [unique_id "aoSAYNO5rbWdOArH04KC8wAAAYE"]
[Tue Aug 18 12:55:12.400671 2026] [security2:error] [pid 67073:tid 67323] [client 158.158.34.183:58243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/inc.php"] [unique_id "aoSAYPcmepr5_nHgLbM--wAAAoo"]
[Tue Aug 18 12:55:12.408915 2026] [security2:error] [pid 67073:tid 67310] [client 103.120.71.157:4697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAYPcmepr5_nHgLbM-_AAAAn0"]
[Tue Aug 18 12:55:12.408995 2026] [security2:error] [pid 67073:tid 67310] [client 103.120.71.157:4697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAYPcmepr5_nHgLbM-_AAAAn0"]
[Tue Aug 18 12:55:12.484640 2026] [security2:error] [pid 66623:tid 66712] [remote 20.237.251.56:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.251.237.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/wp-login.php"] [unique_id "aoSAYNO5rbWdOArH04KC9gABDUs"]
[Tue Aug 18 12:55:12.508023 2026] [security2:error] [pid 67073:tid 67222] [client 5.31.227.224:59022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAYPcmepr5_nHgLbM-_wAAAiU"]
[Tue Aug 18 12:55:12.510798 2026] [security2:error] [pid 67073:tid 67222] [client 5.31.227.224:59022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAYPcmepr5_nHgLbM-_wAAAiU"]
[Tue Aug 18 12:55:12.548576 2026] [security2:error] [pid 66623:tid 66854] [client 20.65.69.59:57033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAYNO5rbWdOArH04KC9wAAAWI"]
[Tue Aug 18 12:55:12.558730 2026] [security2:error] [pid 67073:tid 67223] [client 172.182.200.96:14119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSAYPcmepr5_nHgLbM_AgAAAiY"]
[Tue Aug 18 12:55:12.570665 2026] [security2:error] [pid 67073:tid 67216] [client 20.171.51.14:28813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/md.php"] [unique_id "aoSAYPcmepr5_nHgLbM_AwAAAh8"]
[Tue Aug 18 12:55:12.577834 2026] [security2:error] [pid 67073:tid 67273] [client 213.35.127.232:56772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAYPcmepr5_nHgLbM_BAAAAlg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:12.585681 2026] [security2:error] [pid 67073:tid 67285] [client 74.248.133.44:64943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSAYPcmepr5_nHgLbM_BQAAAmQ"]
[Tue Aug 18 12:55:12.669885 2026] [security2:error] [pid 66623:tid 66794] [client 4.223.164.152:46206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/biufile.php"] [unique_id "aoSAYNO5rbWdOArH04KC-AAAASY"]
[Tue Aug 18 12:55:12.688057 2026] [security2:error] [pid 66623:tid 66637] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/network.php"] [unique_id "aoSAYNO5rbWdOArH04KC-QABXAA"]
[Tue Aug 18 12:55:12.724353 2026] [security2:error] [pid 67073:tid 67305] [client 20.100.169.31:25928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-blink.php"] [unique_id "aoSAYPcmepr5_nHgLbM_BwAAAng"]
[Tue Aug 18 12:55:12.741907 2026] [security2:error] [pid 67073:tid 67275] [client 20.91.215.254:24811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp/images/my.php"] [unique_id "aoSAYPcmepr5_nHgLbM_CAAAAlo"]
[Tue Aug 18 12:55:12.774712 2026] [security2:error] [pid 67073:tid 67314] [client 196.12.128.158:60475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAXvcmepr5_nHgLbM-pQAAAoE"]
[Tue Aug 18 12:55:12.774859 2026] [security2:error] [pid 67073:tid 67314] [client 196.12.128.158:60475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAXvcmepr5_nHgLbM-pQAAAoE"]
[Tue Aug 18 12:55:12.794117 2026] [security2:error] [pid 66623:tid 66847] [client 135.225.75.187:62889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/un.php"] [unique_id "aoSAYNO5rbWdOArH04KC_AAAAVs"]
[Tue Aug 18 12:55:12.857494 2026] [security2:error] [pid 67073:tid 67312] [client 74.248.136.165:1678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/wp-the.php"] [unique_id "aoSAYPcmepr5_nHgLbM_CgAAAn8"]
[Tue Aug 18 12:55:12.996704 2026] [security2:error] [pid 66623:tid 66723] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/new.php"] [unique_id "aoSAYNO5rbWdOArH04KC_wABdVY"]
[Tue Aug 18 12:55:13.008699 2026] [security2:error] [pid 67073:tid 67262] [client 172.202.39.151:42996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-good.php"] [unique_id "aoSAYfcmepr5_nHgLbM_DgAAAk0"]
[Tue Aug 18 12:55:13.009536 2026] [security2:error] [pid 66623:tid 66781] [client 4.232.151.198:30599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAYdO5rbWdOArH04KDAQAAARk"]
[Tue Aug 18 12:55:13.014513 2026] [security2:error] [pid 67073:tid 67212] [client 20.100.169.31:28567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/buy.php"] [unique_id "aoSAYfcmepr5_nHgLbM_DwAAAhs"]
[Tue Aug 18 12:55:13.078530 2026] [security2:error] [pid 67073:tid 67264] [client 20.42.19.40:9673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/asasx.php"] [unique_id "aoSAYfcmepr5_nHgLbM_EAAAAk8"]
[Tue Aug 18 12:55:13.144183 2026] [security2:error] [pid 67073:tid 67208] [client 20.226.6.191:7116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/abc.php"] [unique_id "aoSAYfcmepr5_nHgLbM_EQAAAhc"]
[Tue Aug 18 12:55:13.211642 2026] [security2:error] [pid 66623:tid 66779] [client 20.48.236.86:10368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/ws55.php"] [unique_id "aoSAYdO5rbWdOArH04KDAgAAARc"]
[Tue Aug 18 12:55:13.213914 2026] [security2:error] [pid 66623:tid 66773] [client 52.238.210.254:10122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/fff.php"] [unique_id "aoSAYdO5rbWdOArH04KDAwAAARE"]
[Tue Aug 18 12:55:13.217479 2026] [security2:error] [pid 67073:tid 67316] [client 20.65.69.59:57038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/dirs.php"] [unique_id "aoSAYfcmepr5_nHgLbM_FAAAAoM"]
[Tue Aug 18 12:55:13.253611 2026] [security2:error] [pid 66623:tid 66819] [client 20.205.121.237:5067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/ultra.php"] [unique_id "aoSAYdO5rbWdOArH04KDBAAAAT8"]
[Tue Aug 18 12:55:13.431546 2026] [security2:error] [pid 66623:tid 66821] [client 20.42.19.40:9702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/filemanager.php"] [unique_id "aoSAYdO5rbWdOArH04KDBQAAAUE"]
[Tue Aug 18 12:55:13.443600 2026] [security2:error] [pid 66623:tid 66790] [client 74.248.136.165:9756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/maxro.php"] [unique_id "aoSAYdO5rbWdOArH04KDBgAAASI"]
[Tue Aug 18 12:55:13.674399 2026] [security2:error] [pid 67073:tid 67286] [client 213.35.127.232:57092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAYfcmepr5_nHgLbM_HQAAAmU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:13.702350 2026] [security2:error] [pid 66623:tid 66810] [client 74.248.18.37:12361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/text.php"] [unique_id "aoSAYdO5rbWdOArH04KDBwAAATY"]
[Tue Aug 18 12:55:13.715632 2026] [security2:error] [pid 67073:tid 67231] [client 20.65.98.162:8284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/ajax.php"] [unique_id "aoSAYfcmepr5_nHgLbM_HwAAAi4"]
[Tue Aug 18 12:55:13.725029 2026] [security2:error] [pid 66623:tid 66872] [client 20.42.19.40:9674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/themes.php"] [unique_id "aoSAYdO5rbWdOArH04KDCAAAAXQ"]
[Tue Aug 18 12:55:13.737805 2026] [authz_core:error] [pid 67073:tid 67090] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:13.738070 2026] [authz_core:error] [pid 67073:tid 67090] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:13.810140 2026] [security2:error] [pid 67073:tid 67284] [client 172.202.39.151:33513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAYfcmepr5_nHgLbM_IQAAAmM"]
[Tue Aug 18 12:55:13.912695 2026] [security2:error] [pid 67073:tid 67228] [client 20.51.153.15:9130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/uo.php"] [unique_id "aoSAYfcmepr5_nHgLbM_IwAAAis"]
[Tue Aug 18 12:55:13.944712 2026] [security2:error] [pid 66623:tid 66892] [client 20.116.17.175:57449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/txets.php"] [unique_id "aoSAYdO5rbWdOArH04KDDQAAAYg"]
[Tue Aug 18 12:55:13.974478 2026] [security2:error] [pid 66623:tid 66824] [client 132.196.61.152:56123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/packed.php"] [unique_id "aoSAYdO5rbWdOArH04KDDwAAAUQ"]
[Tue Aug 18 12:55:14.138165 2026] [security2:error] [pid 67073:tid 67209] [client 157.20.138.62:56740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAYvcmepr5_nHgLbM_JwAAAhg"]
[Tue Aug 18 12:55:14.138299 2026] [security2:error] [pid 67073:tid 67209] [client 157.20.138.62:56740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAYvcmepr5_nHgLbM_JwAAAhg"]
[Tue Aug 18 12:55:14.166737 2026] [security2:error] [pid 67073:tid 67252] [client 20.251.48.93:18405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAYvcmepr5_nHgLbM_KQAAAkM"]
[Tue Aug 18 12:55:14.170209 2026] [security2:error] [pid 66623:tid 66853] [client 20.104.100.201:58470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/7.php"] [unique_id "aoSAYtO5rbWdOArH04KDGgAAAWE"]
[Tue Aug 18 12:55:14.200368 2026] [security2:error] [pid 66623:tid 66813] [client 104.209.144.33:29887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSAYtO5rbWdOArH04KDIQAAATk"]
[Tue Aug 18 12:55:14.261002 2026] [security2:error] [pid 66623:tid 66798] [client 52.139.47.57:16644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/wp-the.php"] [unique_id "aoSAYtO5rbWdOArH04KDIgAAASo"]
[Tue Aug 18 12:55:14.272943 2026] [security2:error] [pid 66623:tid 66801] [client 20.100.169.31:31444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/cong.php"] [unique_id "aoSAYtO5rbWdOArH04KDIwAAAS0"]
[Tue Aug 18 12:55:14.379441 2026] [security2:error] [pid 66623:tid 66830] [client 20.205.121.237:5119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/up.php"] [unique_id "aoSAYtO5rbWdOArH04KDJAAAAUo"]
[Tue Aug 18 12:55:14.449358 2026] [security2:error] [pid 67073:tid 67239] [client 20.48.236.86:65117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/m.php"] [unique_id "aoSAYvcmepr5_nHgLbM_MgAAAjY"]
[Tue Aug 18 12:55:14.482566 2026] [security2:error] [pid 67073:tid 67234] [client 74.248.136.165:62578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wdf.php"] [unique_id "aoSAYvcmepr5_nHgLbM_MwAAAjE"]
[Tue Aug 18 12:55:14.542901 2026] [security2:error] [pid 67073:tid 67328] [client 103.184.169.37:41580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAX_cmepr5_nHgLbM-4AAAAo8"]
[Tue Aug 18 12:55:14.543009 2026] [security2:error] [pid 67073:tid 67328] [client 103.184.169.37:41580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAX_cmepr5_nHgLbM-4AAAAo8"]
[Tue Aug 18 12:55:14.620683 2026] [security2:error] [pid 67073:tid 67323] [client 20.171.51.14:16734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/iy.php"] [unique_id "aoSAYvcmepr5_nHgLbM_NAAAAoo"]
[Tue Aug 18 12:55:14.629575 2026] [security2:error] [pid 67073:tid 67247] [client 20.226.6.191:6635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/akcc.php"] [unique_id "aoSAYvcmepr5_nHgLbM_NQAAAj4"]
[Tue Aug 18 12:55:14.678861 2026] [security2:error] [pid 66623:tid 66842] [client 52.173.121.69:24967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSAYtO5rbWdOArH04KDNgAAAVY"]
[Tue Aug 18 12:55:14.741455 2026] [security2:error] [pid 67073:tid 67235] [client 20.29.77.16:56321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/evil.php"] [unique_id "aoSAYvcmepr5_nHgLbM_OQAAAjI"]
[Tue Aug 18 12:55:14.756513 2026] [authz_core:error] [pid 67073:tid 67100] [remote 57.141.22.89:54638] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:14.756783 2026] [authz_core:error] [pid 67073:tid 67100] [remote 57.141.22.89:54638] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:14.824841 2026] [security2:error] [pid 67073:tid 67313] [client 52.139.47.57:42955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/plugin.php"] [unique_id "aoSAYvcmepr5_nHgLbM_OwAAAoA"]
[Tue Aug 18 12:55:14.833955 2026] [security2:error] [pid 67073:tid 67254] [client 20.91.215.254:27437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-content/function.php"] [unique_id "aoSAYvcmepr5_nHgLbM_PAAAAkU"]
[Tue Aug 18 12:55:14.847874 2026] [security2:error] [pid 66623:tid 66692] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/new4.php"] [unique_id "aoSAYtO5rbWdOArH04KDOgABHjc"]
[Tue Aug 18 12:55:14.987884 2026] [security2:error] [pid 66623:tid 66882] [client 20.51.153.15:9134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/kx.php"] [unique_id "aoSAYtO5rbWdOArH04KDOwAAAX4"]
[Tue Aug 18 12:55:15.017125 2026] [security2:error] [pid 67073:tid 67321] [client 20.42.19.40:9721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAY_cmepr5_nHgLbM_PwAAAog"]
[Tue Aug 18 12:55:15.076975 2026] [security2:error] [pid 66623:tid 66886] [client 74.248.130.103:14447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/sky.php"] [unique_id "aoSAY9O5rbWdOArH04KDPAAAAYI"]
[Tue Aug 18 12:55:15.257294 2026] [security2:error] [pid 66623:tid 66880] [client 20.251.48.93:9755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAY9O5rbWdOArH04KDPgAAAXw"]
[Tue Aug 18 12:55:15.263432 2026] [security2:error] [pid 66623:tid 66797] [client 20.250.13.23:51486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAY9O5rbWdOArH04KDPwAAASk"]
[Tue Aug 18 12:55:15.296956 2026] [security2:error] [pid 67073:tid 67310] [client 178.153.171.161:48142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAY_cmepr5_nHgLbM_QwAAAn0"]
[Tue Aug 18 12:55:15.297085 2026] [security2:error] [pid 67073:tid 67310] [client 178.153.171.161:48142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAY_cmepr5_nHgLbM_QwAAAn0"]
[Tue Aug 18 12:55:15.308750 2026] [security2:error] [pid 67073:tid 67257] [client 20.42.19.40:9628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/buy.php"] [unique_id "aoSAY_cmepr5_nHgLbM_RAAAAkg"]
[Tue Aug 18 12:55:15.342050 2026] [security2:error] [pid 66623:tid 66893] [client 20.116.17.175:57636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/img.php"] [unique_id "aoSAY9O5rbWdOArH04KDQgAAAYk"]
[Tue Aug 18 12:55:15.371056 2026] [security2:error] [pid 66623:tid 66774] [client 158.158.34.183:47533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSAY9O5rbWdOArH04KDRAAAARI"]
[Tue Aug 18 12:55:15.474666 2026] [security2:error] [pid 67073:tid 67330] [client 86.120.159.145:4805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAY_cmepr5_nHgLbM_SAAAApE"]
[Tue Aug 18 12:55:15.474783 2026] [security2:error] [pid 67073:tid 67330] [client 86.120.159.145:4805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAY_cmepr5_nHgLbM_SAAAApE"]
[Tue Aug 18 12:55:15.545223 2026] [security2:error] [pid 67073:tid 67269] [client 4.232.151.198:30635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/404.php"] [unique_id "aoSAY_cmepr5_nHgLbM_TQAAAlQ"]
[Tue Aug 18 12:55:15.545244 2026] [security2:error] [pid 67073:tid 67292] [client 20.65.69.59:57047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/fresh.php"] [unique_id "aoSAY_cmepr5_nHgLbM_TAAAAms"]
[Tue Aug 18 12:55:15.548864 2026] [security2:error] [pid 67073:tid 67250] [client 68.155.155.199:8193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/goods.php"] [unique_id "aoSAY_cmepr5_nHgLbM_TgAAAkE"]
[Tue Aug 18 12:55:15.567464 2026] [security2:error] [pid 66623:tid 66807] [client 52.139.47.57:18479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/readme.php"] [unique_id "aoSAY9O5rbWdOArH04KDRQAAATM"]
[Tue Aug 18 12:55:15.616628 2026] [security2:error] [pid 67073:tid 67279] [client 20.42.19.40:9711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/dropdown.php"] [unique_id "aoSAY_cmepr5_nHgLbM_UQAAAl4"]
[Tue Aug 18 12:55:15.728342 2026] [security2:error] [pid 67073:tid 67221] [client 20.51.153.15:9148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/va.php"] [unique_id "aoSAY_cmepr5_nHgLbM_UgAAAiQ"]
[Tue Aug 18 12:55:15.733863 2026] [security2:error] [pid 66623:tid 66775] [client 52.238.210.254:10225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/inputs.php"] [unique_id "aoSAY9O5rbWdOArH04KDRgAAARM"]
[Tue Aug 18 12:55:15.813713 2026] [security2:error] [pid 67073:tid 67215] [client 20.91.215.254:27421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-2019.php"] [unique_id "aoSAY_cmepr5_nHgLbM_UwAAAh4"]
[Tue Aug 18 12:55:15.820370 2026] [security2:error] [pid 67073:tid 67253] [client 20.104.100.201:21442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/ws77.php"] [unique_id "aoSAY_cmepr5_nHgLbM_VQAAAkQ"]
[Tue Aug 18 12:55:15.833970 2026] [security2:error] [pid 67073:tid 67131] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAY_cmepr5_nHgLbM_VgACjTc"]
[Tue Aug 18 12:55:15.846125 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:15.846387 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:15.849634 2026] [security2:error] [pid 67073:tid 67225] [client 20.100.169.31:2468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSAY_cmepr5_nHgLbM_WAAAAig"]
[Tue Aug 18 12:55:15.853014 2026] [security2:error] [pid 67073:tid 67311] [client 20.29.77.16:57025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/wp-key.php"] [unique_id "aoSAY_cmepr5_nHgLbM_WQAAAn4"]
[Tue Aug 18 12:55:15.869607 2026] [security2:error] [pid 66623:tid 66827] [client 52.173.121.69:16491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSAY9O5rbWdOArH04KDSAAAAUc"]
[Tue Aug 18 12:55:15.871494 2026] [security2:error] [pid 66623:tid 66785] [client 20.171.51.14:33710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/og.php"] [unique_id "aoSAY9O5rbWdOArH04KDSQAAAR0"]
[Tue Aug 18 12:55:15.959871 2026] [security2:error] [pid 67073:tid 67281] [client 185.191.171.1:55304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1750938813/1751241600/"] [unique_id "aoSAY_cmepr5_nHgLbM_XQAAAmA"]
[Tue Aug 18 12:55:15.959990 2026] [security2:error] [pid 67073:tid 67281] [client 185.191.171.1:55304] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1750938813/1751241600/"] [unique_id "aoSAY_cmepr5_nHgLbM_XQAAAmA"]
[Tue Aug 18 12:55:15.964086 2026] [security2:error] [pid 67073:tid 67283] [client 20.65.98.162:19084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/uwu.php"] [unique_id "aoSAY_cmepr5_nHgLbM_XwAAAmI"]
[Tue Aug 18 12:55:16.007368 2026] [security2:error] [pid 66623:tid 66778] [client 52.173.121.69:9587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAZNO5rbWdOArH04KDSgAAARY"]
[Tue Aug 18 12:55:16.053020 2026] [security2:error] [pid 66623:tid 66877] [client 74.248.18.37:12752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/themes/zmousse/otuz1.php"] [unique_id "aoSAZNO5rbWdOArH04KDSwAAAXk"]
[Tue Aug 18 12:55:16.102937 2026] [security2:error] [pid 66623:tid 66854] [client 52.139.47.57:3203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/chosen.php"] [unique_id "aoSAZNO5rbWdOArH04KDTgAAAWI"]
[Tue Aug 18 12:55:16.147090 2026] [security2:error] [pid 66623:tid 66776] [client 74.248.130.103:36841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/sixxis.php"] [unique_id "aoSAZNO5rbWdOArH04KDTwAAARQ"]
[Tue Aug 18 12:55:16.157652 2026] [security2:error] [pid 66623:tid 66831] [client 20.226.6.191:6615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wk/index.php"] [unique_id "aoSAZNO5rbWdOArH04KDUAAAAUs"]
[Tue Aug 18 12:55:16.293969 2026] [security2:error] [pid 67073:tid 67220] [client 74.248.136.165:9946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ff1.php"] [unique_id "aoSAZPcmepr5_nHgLbM_aQAAAiM"]
[Tue Aug 18 12:55:16.313158 2026] [security2:error] [pid 67073:tid 67266] [client 172.202.39.151:42956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-config-sample.php"] [unique_id "aoSAZPcmepr5_nHgLbM_awAAAlE"]
[Tue Aug 18 12:55:16.327685 2026] [security2:error] [pid 66623:tid 66890] [client 20.226.6.191:6641] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/1.php"] [unique_id "aoSAZNO5rbWdOArH04KDUgAAAYY"]
[Tue Aug 18 12:55:16.327797 2026] [security2:error] [pid 66623:tid 66890] [client 20.226.6.191:6641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/1.php"] [unique_id "aoSAZNO5rbWdOArH04KDUgAAAYY"]
[Tue Aug 18 12:55:16.368434 2026] [security2:error] [pid 66623:tid 66856] [client 52.238.210.254:8949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/ioxi-o.php"] [unique_id "aoSAZNO5rbWdOArH04KDUwAAAWQ"]
[Tue Aug 18 12:55:16.447016 2026] [security2:error] [pid 66623:tid 66819] [client 172.202.39.151:34770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/tes.php"] [unique_id "aoSAZNO5rbWdOArH04KDVAAAAT8"]
[Tue Aug 18 12:55:16.575701 2026] [security2:error] [pid 66623:tid 66654] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/newfile.php"] [unique_id "aoSAZNO5rbWdOArH04KDVwABQRE"]
[Tue Aug 18 12:55:16.590756 2026] [security2:error] [pid 66623:tid 66840] [client 157.51.166.53:57081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAZNO5rbWdOArH04KDWQAAAVQ"]
[Tue Aug 18 12:55:16.590883 2026] [security2:error] [pid 66623:tid 66840] [client 157.51.166.53:57081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAZNO5rbWdOArH04KDWQAAAVQ"]
[Tue Aug 18 12:55:16.605575 2026] [security2:error] [pid 67073:tid 67219] [client 4.223.164.152:64657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/dejavu.php"] [unique_id "aoSAZPcmepr5_nHgLbM_cgAAAiI"]
[Tue Aug 18 12:55:16.659999 2026] [security2:error] [pid 66623:tid 66784] [client 20.226.6.191:6578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSAZNO5rbWdOArH04KDXAAAARw"]
[Tue Aug 18 12:55:16.668358 2026] [security2:error] [pid 66623:tid 66817] [client 135.225.75.187:9302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/autogooey.php"] [unique_id "aoSAZNO5rbWdOArH04KDXQAAAT0"]
[Tue Aug 18 12:55:16.681163 2026] [security2:error] [pid 66623:tid 66891] [client 20.116.17.175:57454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAZNO5rbWdOArH04KDXgAAAYc"]
[Tue Aug 18 12:55:16.738083 2026] [security2:error] [pid 66623:tid 66804] [client 74.248.18.37:12354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/u.php"] [unique_id "aoSAZNO5rbWdOArH04KDYQAAATA"]
[Tue Aug 18 12:55:16.759764 2026] [security2:error] [pid 66623:tid 66841] [client 20.65.69.59:49341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/admin404.php"] [unique_id "aoSAZNO5rbWdOArH04KDYgAAAVU"]
[Tue Aug 18 12:55:16.772082 2026] [security2:error] [pid 66623:tid 66663] [remote 178.156.200.16:57644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.200.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tersaudefitness.com.br.elizangelabrito.com.br"] [uri "/wp-login.php"] [unique_id "aoSAZNO5rbWdOArH04KDYAABOBo"]
[Tue Aug 18 12:55:16.775746 2026] [security2:error] [pid 66623:tid 66875] [client 132.196.61.152:60325] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/1.php"] [unique_id "aoSAZNO5rbWdOArH04KDYwAAAXc"]
[Tue Aug 18 12:55:16.775819 2026] [security2:error] [pid 66623:tid 66875] [client 132.196.61.152:60325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/1.php"] [unique_id "aoSAZNO5rbWdOArH04KDYwAAAXc"]
[Tue Aug 18 12:55:16.825617 2026] [security2:error] [pid 67073:tid 67129] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAZPcmepr5_nHgLbM_dQACVjU"]
[Tue Aug 18 12:55:16.854169 2026] [security2:error] [pid 66623:tid 66883] [client 20.226.6.191:6608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAZNO5rbWdOArH04KDZQAAAX8"]
[Tue Aug 18 12:55:16.882316 2026] [security2:error] [pid 67073:tid 67244] [client 20.65.98.162:44271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/yj09.php"] [unique_id "aoSAZPcmepr5_nHgLbM_dgAAAjs"]
[Tue Aug 18 12:55:16.885799 2026] [security2:error] [pid 66623:tid 66645] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/nf.php"] [unique_id "aoSAZNO5rbWdOArH04KDZgABHwg"]
[Tue Aug 18 12:55:16.897225 2026] [security2:error] [pid 67073:tid 67302] [client 160.120.140.123:57898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAZPcmepr5_nHgLbM_dwAAAnU"]
[Tue Aug 18 12:55:16.897343 2026] [security2:error] [pid 67073:tid 67302] [client 160.120.140.123:57898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAZPcmepr5_nHgLbM_dwAAAnU"]
[Tue Aug 18 12:55:16.973692 2026] [security2:error] [pid 67073:tid 67247] [client 20.226.7.189:9778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/666.php"] [unique_id "aoSAZPcmepr5_nHgLbM_eAAAAj4"]
[Tue Aug 18 12:55:17.040549 2026] [security2:error] [pid 67073:tid 67222] [client 74.248.130.103:14450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/yj09.php"] [unique_id "aoSAZfcmepr5_nHgLbM_egAAAiU"]
[Tue Aug 18 12:55:17.069422 2026] [security2:error] [pid 67073:tid 67101] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/st.php"] [unique_id "aoSAZfcmepr5_nHgLbM_ewACJhk"]
[Tue Aug 18 12:55:17.099066 2026] [security2:error] [pid 67073:tid 67277] [client 20.91.215.254:27442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/cjfuns.php"] [unique_id "aoSAZfcmepr5_nHgLbM_fAAAAlw"]
[Tue Aug 18 12:55:17.113675 2026] [security2:error] [pid 66623:tid 66872] [client 20.250.13.23:30401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/vx.php"] [unique_id "aoSAZdO5rbWdOArH04KDagAAAXQ"]
[Tue Aug 18 12:55:17.136553 2026] [security2:error] [pid 66623:tid 66766] [client 4.223.164.152:64696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/aaf.php"] [unique_id "aoSAZdO5rbWdOArH04KDbAAAAQo"]
[Tue Aug 18 12:55:17.146994 2026] [security2:error] [pid 67073:tid 67235] [client 20.226.7.189:9663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/bgymj.php"] [unique_id "aoSAZfcmepr5_nHgLbM_fQAAAjI"]
[Tue Aug 18 12:55:17.231191 2026] [security2:error] [pid 67073:tid 67285] [client 20.226.6.191:6652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/as.php"] [unique_id "aoSAZfcmepr5_nHgLbM_fgAAAmQ"]
[Tue Aug 18 12:55:17.270712 2026] [security2:error] [pid 66623:tid 66799] [client 20.226.7.189:9015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/bthil.php"] [unique_id "aoSAZdO5rbWdOArH04KDbQAAASs"]
[Tue Aug 18 12:55:17.298940 2026] [security2:error] [pid 67073:tid 67327] [client 52.173.121.69:24978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSAZfcmepr5_nHgLbM_fwAAAo4"]
[Tue Aug 18 12:55:17.319304 2026] [security2:error] [pid 66623:tid 66853] [client 52.139.47.57:3205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/system.php"] [unique_id "aoSAZdO5rbWdOArH04KDbwAAAWE"]
[Tue Aug 18 12:55:17.358516 2026] [security2:error] [pid 66623:tid 66842] [client 20.51.153.15:8709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/fo.php"] [unique_id "aoSAZdO5rbWdOArH04KDcAAAAVY"]
[Tue Aug 18 12:55:17.479078 2026] [security2:error] [pid 66623:tid 66822] [client 85.154.68.202:11203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAZdO5rbWdOArH04KDcgAAAUI"]
[Tue Aug 18 12:55:17.479208 2026] [security2:error] [pid 66623:tid 66822] [client 85.154.68.202:11203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAZdO5rbWdOArH04KDcgAAAUI"]
[Tue Aug 18 12:55:17.491848 2026] [security2:error] [pid 66623:tid 66809] [client 158.158.34.183:33560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/x.php"] [unique_id "aoSAZdO5rbWdOArH04KDcwAAATU"]
[Tue Aug 18 12:55:17.521420 2026] [security2:error] [pid 67073:tid 67246] [client 114.5.214.109:49801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAZfcmepr5_nHgLbM_oAAAAj0"]
[Tue Aug 18 12:55:17.521501 2026] [security2:error] [pid 67073:tid 67246] [client 114.5.214.109:49801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAZfcmepr5_nHgLbM_oAAAAj0"]
[Tue Aug 18 12:55:17.564683 2026] [security2:error] [pid 67073:tid 67224] [client 172.182.200.96:14167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSAZfcmepr5_nHgLbM_oQAAAic"]
[Tue Aug 18 12:55:17.646909 2026] [security2:error] [pid 67073:tid 67208] [client 20.251.48.93:61135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAZfcmepr5_nHgLbM_ogAAAhc"]
[Tue Aug 18 12:55:17.695092 2026] [authz_core:error] [pid 67073:tid 67093] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:17.695349 2026] [authz_core:error] [pid 67073:tid 67093] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:17.696094 2026] [security2:error] [pid 66623:tid 66788] [client 74.248.130.103:15385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/k.php"] [unique_id "aoSAZdO5rbWdOArH04KDdAAAASA"]
[Tue Aug 18 12:55:17.726121 2026] [security2:error] [pid 67073:tid 67221] [client 20.51.153.15:8818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ve.php"] [unique_id "aoSAZfcmepr5_nHgLbM_pQAAAiQ"]
[Tue Aug 18 12:55:17.736189 2026] [security2:error] [pid 67073:tid 67297] [client 20.171.51.14:58854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/lp.php"] [unique_id "aoSAZfcmepr5_nHgLbM_pgAAAnA"]
[Tue Aug 18 12:55:17.756299 2026] [security2:error] [pid 67073:tid 67215] [client 172.202.39.151:28073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/files/index.php"] [unique_id "aoSAZfcmepr5_nHgLbM_qAAAAh4"]
[Tue Aug 18 12:55:17.818203 2026] [security2:error] [pid 67073:tid 67309] [client 104.209.144.33:35863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSAZfcmepr5_nHgLbM_qwAAAnw"]
[Tue Aug 18 12:55:17.835393 2026] [security2:error] [pid 66623:tid 66814] [client 192.141.172.134:57011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAZdO5rbWdOArH04KDdwAAATo"]
[Tue Aug 18 12:55:17.835485 2026] [security2:error] [pid 66623:tid 66814] [client 192.141.172.134:57011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAZdO5rbWdOArH04KDdwAAATo"]
[Tue Aug 18 12:55:17.931552 2026] [security2:error] [pid 67073:tid 67304] [client 52.238.210.254:10230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/lite.php"] [unique_id "aoSAZfcmepr5_nHgLbM_rwAAAnc"]
[Tue Aug 18 12:55:18.018662 2026] [security2:error] [pid 67073:tid 67255] [client 20.226.7.189:19164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/xp.php"] [unique_id "aoSAZvcmepr5_nHgLbM_sAAAAkY"]
[Tue Aug 18 12:55:18.032891 2026] [security2:error] [pid 66623:tid 66880] [client 20.163.43.14:4443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAZtO5rbWdOArH04KDeAAAAXw"]
[Tue Aug 18 12:55:18.049619 2026] [security2:error] [pid 67073:tid 67228] [client 20.116.17.175:57640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAZvcmepr5_nHgLbM_sQAAAis"]
[Tue Aug 18 12:55:18.137026 2026] [security2:error] [pid 66623:tid 66806] [client 4.232.151.198:16024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/wk/index.php"] [unique_id "aoSAZtO5rbWdOArH04KDeQAAATI"]
[Tue Aug 18 12:55:18.220331 2026] [security2:error] [pid 66623:tid 66886] [client 20.100.169.31:31452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/db.php"] [unique_id "aoSAZtO5rbWdOArH04KDegAAAYI"]
[Tue Aug 18 12:55:18.303002 2026] [security2:error] [pid 67073:tid 67282] [client 20.226.7.189:2372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/reze.php"] [unique_id "aoSAZvcmepr5_nHgLbM_ugAAAmE"]
[Tue Aug 18 12:55:18.392088 2026] [security2:error] [pid 67073:tid 67300] [client 20.29.77.16:51369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/phpcheck.php"] [unique_id "aoSAZvcmepr5_nHgLbM_wQAAAnM"]
[Tue Aug 18 12:55:18.422300 2026] [security2:error] [pid 66623:tid 66882] [client 52.139.47.57:44670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/wp-load.php"] [unique_id "aoSAZtO5rbWdOArH04KDewAAAX4"]
[Tue Aug 18 12:55:18.453859 2026] [security2:error] [pid 66623:tid 66869] [client 74.248.136.165:37182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/guk.php"] [unique_id "aoSAZtO5rbWdOArH04KDfAAAAXE"]
[Tue Aug 18 12:55:18.528064 2026] [security2:error] [pid 67073:tid 67266] [client 20.205.121.237:5116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/upload.php"] [unique_id "aoSAZvcmepr5_nHgLbM_zgAAAlE"]
[Tue Aug 18 12:55:18.531542 2026] [security2:error] [pid 67073:tid 67111] [remote 103.56.163.133:37774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faganelli.com.br.bergoninf.com"] [uri "/wp-login.php"] [unique_id "aoSAZvcmepr5_nHgLbM_zwACHyM"]
[Tue Aug 18 12:55:18.540854 2026] [security2:error] [pid 67073:tid 67235] [client 20.65.69.59:3753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/loading.php"] [unique_id "aoSAZvcmepr5_nHgLbM_0AAAAjI"]
[Tue Aug 18 12:55:18.554235 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:18.554492 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:18.748524 2026] [security2:error] [pid 67073:tid 67287] [client 74.248.133.44:58477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSAZvcmepr5_nHgLbM_5gAAAmY"]
[Tue Aug 18 12:55:18.756029 2026] [security2:error] [pid 67073:tid 67268] [client 132.196.61.152:61008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/coffee.php"] [unique_id "aoSAZvcmepr5_nHgLbM_5wAAAlM"]
[Tue Aug 18 12:55:18.822363 2026] [security2:error] [pid 66623:tid 66777] [client 135.225.75.187:9337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/sty.php"] [unique_id "aoSAZtO5rbWdOArH04KDfQAAARU"]
[Tue Aug 18 12:55:18.862045 2026] [security2:error] [pid 67073:tid 67246] [client 52.238.210.254:8864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/ms-edit.php"] [unique_id "aoSAZvcmepr5_nHgLbM_8QAAAj0"]
[Tue Aug 18 12:55:18.876377 2026] [security2:error] [pid 66623:tid 66815] [client 20.42.19.40:2205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/flower.php"] [unique_id "aoSAZtO5rbWdOArH04KDfwAAATs"]
[Tue Aug 18 12:55:18.939467 2026] [security2:error] [pid 67073:tid 67297] [client 20.42.19.40:9683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/inputs.php"] [unique_id "aoSAZvcmepr5_nHgLbM_9AAAAnA"]
[Tue Aug 18 12:55:18.953482 2026] [security2:error] [pid 67073:tid 67215] [client 172.202.39.151:60952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAZvcmepr5_nHgLbM_9QAAAh4"]
[Tue Aug 18 12:55:18.957543 2026] [security2:error] [pid 67073:tid 67296] [client 213.35.127.232:57303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAZvcmepr5_nHgLbM_9gAAAm8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:18.985788 2026] [security2:error] [pid 67073:tid 67191] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/le.php"] [unique_id "aoSAZvcmepr5_nHgLbM_-AACLHM"]
[Tue Aug 18 12:55:18.992298 2026] [security2:error] [pid 67073:tid 67329] [client 20.100.169.31:31451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/dropdown.php"] [unique_id "aoSAZvcmepr5_nHgLbM_-QAAApA"]
[Tue Aug 18 12:55:19.010989 2026] [security2:error] [pid 67073:tid 67218] [client 20.163.43.14:4377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAZ_cmepr5_nHgLbM_-gAAAiE"]
[Tue Aug 18 12:55:19.026271 2026] [security2:error] [pid 67073:tid 67210] [client 20.163.43.14:4263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/inputs.php"] [unique_id "aoSAZ_cmepr5_nHgLbM_-wAAAhk"]
[Tue Aug 18 12:55:19.035792 2026] [security2:error] [pid 67073:tid 67292] [client 52.139.47.57:9076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/files/8.php"] [unique_id "aoSAZ_cmepr5_nHgLbM__AAAAms"]
[Tue Aug 18 12:55:19.108113 2026] [authz_core:error] [pid 67073:tid 67156] [remote 57.141.22.100:50894] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:19.108420 2026] [authz_core:error] [pid 67073:tid 67156] [remote 57.141.22.100:50894] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:19.153796 2026] [security2:error] [pid 67073:tid 67286] [client 20.226.6.191:6645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAZ_cmepr5_nHgLbNAAAAAAmU"]
[Tue Aug 18 12:55:19.216387 2026] [security2:error] [pid 67073:tid 67272] [client 20.91.215.254:20677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSAZ_cmepr5_nHgLbNAAgAAAlc"]
[Tue Aug 18 12:55:19.226623 2026] [security2:error] [pid 67073:tid 67140] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/hr.php"] [unique_id "aoSAZ_cmepr5_nHgLbNAAwACh0A"]
[Tue Aug 18 12:55:19.228246 2026] [security2:error] [pid 67073:tid 67304] [client 52.238.210.254:10131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/rip.php"] [unique_id "aoSAZ_cmepr5_nHgLbNABAAAAnc"]
[Tue Aug 18 12:55:19.292399 2026] [security2:error] [pid 66623:tid 66827] [client 52.238.210.254:33418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/filemanager.php"] [unique_id "aoSAZ9O5rbWdOArH04KDgAAAAUc"]
[Tue Aug 18 12:55:19.311100 2026] [security2:error] [pid 67073:tid 67261] [client 158.158.34.183:11420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/filemanager.php"] [unique_id "aoSAZ_cmepr5_nHgLbNABwAAAkw"]
[Tue Aug 18 12:55:19.378167 2026] [security2:error] [pid 67073:tid 67306] [client 74.248.130.103:36832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/w.php"] [unique_id "aoSAZ_cmepr5_nHgLbNACAAAAnk"]
[Tue Aug 18 12:55:19.443370 2026] [security2:error] [pid 67073:tid 67228] [client 20.65.98.162:28492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/signon.php"] [unique_id "aoSAZ_cmepr5_nHgLbNACgAAAis"]
[Tue Aug 18 12:55:19.460953 2026] [authz_core:error] [pid 67073:tid 67149] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:19.461213 2026] [authz_core:error] [pid 67073:tid 67149] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:19.489930 2026] [security2:error] [pid 66623:tid 66859] [client 172.202.39.151:65229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/inputs.php"] [unique_id "aoSAZ9O5rbWdOArH04KDggAAAWc"]
[Tue Aug 18 12:55:19.531066 2026] [security2:error] [pid 67073:tid 67310] [client 196.12.128.158:61383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAZ_cmepr5_nHgLbNADAAAAn0"]
[Tue Aug 18 12:55:19.531175 2026] [security2:error] [pid 67073:tid 67310] [client 196.12.128.158:61383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAZ_cmepr5_nHgLbNADAAAAn0"]
[Tue Aug 18 12:55:19.672973 2026] [security2:error] [pid 66623:tid 66776] [client 20.42.19.40:9600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/100.php"] [unique_id "aoSAZ9O5rbWdOArH04KDgwAAARQ"]
[Tue Aug 18 12:55:19.761611 2026] [security2:error] [pid 67073:tid 67252] [client 20.163.43.14:4370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/admin.php"] [unique_id "aoSAZ_cmepr5_nHgLbNADwAAAkM"]
[Tue Aug 18 12:55:19.765159 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:19.765530 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:19.821032 2026] [security2:error] [pid 67073:tid 67314] [client 178.156.185.231:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thatianysantana.com.br"] [uri "/index.php"] [unique_id "aoSAZ_cmepr5_nHgLbNADQACgU0"], referer: https://thatianysantana.com.br/
[Tue Aug 18 12:55:19.914120 2026] [security2:error] [pid 67073:tid 67302] [client 20.91.215.254:12660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/chosen.php"] [unique_id "aoSAZ_cmepr5_nHgLbNAEgAAAnU"]
[Tue Aug 18 12:55:19.933013 2026] [security2:error] [pid 67073:tid 67107] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kt.php"] [unique_id "aoSAZ_cmepr5_nHgLbNAEwACHx8"]
[Tue Aug 18 12:55:19.979656 2026] [security2:error] [pid 66623:tid 66873] [client 172.182.200.96:14104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSAZ9O5rbWdOArH04KDhAAAAXU"]
[Tue Aug 18 12:55:20.016009 2026] [security2:error] [pid 67073:tid 67313] [client 20.42.19.40:9613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/akc.php"] [unique_id "aoSAaPcmepr5_nHgLbNAFgAAAoA"]
[Tue Aug 18 12:55:20.058545 2026] [authz_core:error] [pid 67073:tid 67109] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:20.058812 2026] [authz_core:error] [pid 67073:tid 67109] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:20.161497 2026] [security2:error] [pid 67073:tid 67240] [client 103.120.71.157:5300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAaPcmepr5_nHgLbNAGQAAAjc"]
[Tue Aug 18 12:55:20.171910 2026] [security2:error] [pid 67073:tid 67307] [client 20.42.19.40:2719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/motu.php"] [unique_id "aoSAaPcmepr5_nHgLbNAGgAAAno"]
[Tue Aug 18 12:55:20.181067 2026] [security2:error] [pid 67073:tid 67187] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ww.php"] [unique_id "aoSAaPcmepr5_nHgLbNAGwACKW8"]
[Tue Aug 18 12:55:20.191758 2026] [fcgid:warn] [pid 66623:tid 66819] (70014)End of file found: [client 66.132.172.184:27208] mod_fcgid: can't get data from http client
[Tue Aug 18 12:55:20.208789 2026] [security2:error] [pid 67073:tid 67322] [client 74.248.130.103:36832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/fpwch.php"] [unique_id "aoSAaPcmepr5_nHgLbNAHQAAAok"]
[Tue Aug 18 12:55:20.255978 2026] [security2:error] [pid 67073:tid 67273] [client 78.47.98.55:37500] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.saojudas.com.br"] [uri "/index.php"] [unique_id "aoSAaPcmepr5_nHgLbNAHAAAAlg"], referer: https://www.saojudas.com.br
[Tue Aug 18 12:55:20.299259 2026] [security2:error] [pid 67073:tid 67239] [client 20.42.19.40:9725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSAaPcmepr5_nHgLbNAHwAAAjY"]
[Tue Aug 18 12:55:20.306744 2026] [security2:error] [pid 67073:tid 67285] [client 52.139.47.57:16664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/colors/blue/about.php"] [unique_id "aoSAaPcmepr5_nHgLbNAIAAAAmQ"]
[Tue Aug 18 12:55:20.356913 2026] [security2:error] [pid 67073:tid 67224] [client 132.196.61.152:60290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAaPcmepr5_nHgLbNAIQAAAic"]
[Tue Aug 18 12:55:20.387950 2026] [security2:error] [pid 67073:tid 67207] [client 4.232.151.198:16053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/about.php"] [unique_id "aoSAaPcmepr5_nHgLbNAIwAAAhY"]
[Tue Aug 18 12:55:20.490296 2026] [security2:error] [pid 67073:tid 67229] [client 20.65.69.59:49294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/conn-test.php"] [unique_id "aoSAaPcmepr5_nHgLbNAKgAAAiw"]
[Tue Aug 18 12:55:20.545531 2026] [security2:error] [pid 67073:tid 67292] [client 74.248.136.165:55484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/sbhu.php"] [unique_id "aoSAaPcmepr5_nHgLbNALAAAAms"]
[Tue Aug 18 12:55:20.629854 2026] [security2:error] [pid 67073:tid 67330] [client 74.248.136.165:37160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-the.php"] [unique_id "aoSAaPcmepr5_nHgLbNALwAAApE"]
[Tue Aug 18 12:55:20.640480 2026] [security2:error] [pid 66623:tid 66860] [client 135.225.75.187:9315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wio.php"] [unique_id "aoSAaNO5rbWdOArH04KDiAAAAWg"]
[Tue Aug 18 12:55:20.651081 2026] [security2:error] [pid 67073:tid 67286] [client 196.251.121.142:39420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "fbenevides.com"] [uri "/geoserver/web/"] [unique_id "aoSAaPcmepr5_nHgLbNAMAAAAmU"]
[Tue Aug 18 12:55:20.663881 2026] [authz_core:error] [pid 67073:tid 67180] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:20.664139 2026] [authz_core:error] [pid 67073:tid 67180] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:20.725688 2026] [security2:error] [pid 66623:tid 66841] [client 52.238.210.254:8926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/update/da222.php"] [unique_id "aoSAaNO5rbWdOArH04KDiQAAAVU"]
[Tue Aug 18 12:55:20.744135 2026] [security2:error] [pid 67073:tid 67231] [client 20.29.77.16:20811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/mimes.php"] [unique_id "aoSAaPcmepr5_nHgLbNANAAAAi4"]
[Tue Aug 18 12:55:20.779236 2026] [security2:error] [pid 67073:tid 67308] [client 213.35.127.232:58409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAaPcmepr5_nHgLbNANgAAAns"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:20.794115 2026] [security2:error] [pid 67073:tid 67233] [client 20.163.43.14:4296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/alfa.php"] [unique_id "aoSAaPcmepr5_nHgLbNANwAAAjA"]
[Tue Aug 18 12:55:20.844872 2026] [security2:error] [pid 67073:tid 67283] [client 20.65.98.162:39993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/scxy.php"] [unique_id "aoSAaPcmepr5_nHgLbNAOAAAAmI"]
[Tue Aug 18 12:55:20.874563 2026] [security2:error] [pid 67073:tid 67260] [client 20.171.51.14:16759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/of.php"] [unique_id "aoSAaPcmepr5_nHgLbNAOQAAAks"]
[Tue Aug 18 12:55:20.942071 2026] [security2:error] [pid 67073:tid 67318] [client 197.184.64.235:41924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAaPcmepr5_nHgLbNAOgAAAoU"]
[Tue Aug 18 12:55:20.942194 2026] [security2:error] [pid 67073:tid 67318] [client 197.184.64.235:41924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAaPcmepr5_nHgLbNAOgAAAoU"]
[Tue Aug 18 12:55:20.965944 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:20.966198 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:20.980733 2026] [security2:error] [pid 67073:tid 67301] [client 74.248.18.37:40043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAaPcmepr5_nHgLbNAPAAAAnQ"]
[Tue Aug 18 12:55:20.987749 2026] [security2:error] [pid 67073:tid 67261] [client 74.248.130.103:14462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/FWAZ.php"] [unique_id "aoSAaPcmepr5_nHgLbNAPQAAAkw"]
[Tue Aug 18 12:55:21.022941 2026] [security2:error] [pid 67073:tid 67241] [client 4.223.164.152:54223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSAafcmepr5_nHgLbNAPgAAAjg"]
[Tue Aug 18 12:55:21.029696 2026] [security2:error] [pid 66623:tid 66883] [client 20.51.153.15:9183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ia.php"] [unique_id "aoSAadO5rbWdOArH04KDjAAAAX8"]
[Tue Aug 18 12:55:21.085028 2026] [security2:error] [pid 67073:tid 67295] [client 20.91.215.254:24768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSAafcmepr5_nHgLbNAQgAAAm4"]
[Tue Aug 18 12:55:21.207981 2026] [security2:error] [pid 67073:tid 67220] [client 52.238.210.254:10193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/upload.php"] [unique_id "aoSAafcmepr5_nHgLbNAQwAAAiM"]
[Tue Aug 18 12:55:21.265538 2026] [authz_core:error] [pid 67073:tid 67139] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:21.265817 2026] [authz_core:error] [pid 67073:tid 67139] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:21.369198 2026] [security2:error] [pid 67073:tid 67263] [client 132.196.61.152:60294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSAafcmepr5_nHgLbNASQAAAk4"]
[Tue Aug 18 12:55:21.388497 2026] [security2:error] [pid 67073:tid 67252] [client 20.51.153.15:9182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/kn.php"] [unique_id "aoSAafcmepr5_nHgLbNASgAAAkM"]
[Tue Aug 18 12:55:21.456741 2026] [autoindex:error] [pid 67073:tid 67302] [client 3.210.118.109:65379] AH01276: Cannot serve directory /home1/xsolutions/aceauto.3xsolutions.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:21.535605 2026] [security2:error] [pid 67073:tid 67243] [client 213.202.253.4:51422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/postnews.php"] [unique_id "aoSAafcmepr5_nHgLbNAUQAAAjo"], referer: www.google.com
[Tue Aug 18 12:55:21.544634 2026] [security2:error] [pid 66623:tid 66784] [client 20.226.7.189:19190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/2026w.php"] [unique_id "aoSAadO5rbWdOArH04KDjgAAARw"]
[Tue Aug 18 12:55:21.545748 2026] [security2:error] [pid 67073:tid 67235] [client 20.171.51.14:59301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ey.php"] [unique_id "aoSAafcmepr5_nHgLbNAUgAAAjI"]
[Tue Aug 18 12:55:21.566650 2026] [authz_core:error] [pid 67073:tid 67092] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:21.566918 2026] [authz_core:error] [pid 67073:tid 67092] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:21.605112 2026] [security2:error] [pid 67073:tid 67331] [client 20.42.19.40:9612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/php.php"] [unique_id "aoSAafcmepr5_nHgLbNAXwAAApI"]
[Tue Aug 18 12:55:21.614690 2026] [security2:error] [pid 67073:tid 67289] [client 135.225.75.187:29107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/1061.php"] [unique_id "aoSAafcmepr5_nHgLbNAYQAAAmg"]
[Tue Aug 18 12:55:21.671253 2026] [security2:error] [pid 67073:tid 67327] [client 74.248.136.165:28664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/sbhu.php"] [unique_id "aoSAafcmepr5_nHgLbNAZAAAAo4"]
[Tue Aug 18 12:55:21.811623 2026] [security2:error] [pid 67073:tid 67165] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/mo.php"] [unique_id "aoSAafcmepr5_nHgLbNAZQACWlk"]
[Tue Aug 18 12:55:21.913947 2026] [security2:error] [pid 67073:tid 67262] [client 20.226.7.189:38631] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "valeriana.com.br"] [uri "/1.php"] [unique_id "aoSAafcmepr5_nHgLbNAaAAAAk0"]
[Tue Aug 18 12:55:21.914057 2026] [security2:error] [pid 67073:tid 67262] [client 20.226.7.189:38631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/1.php"] [unique_id "aoSAafcmepr5_nHgLbNAaAAAAk0"]
[Tue Aug 18 12:55:21.914962 2026] [security2:error] [pid 67073:tid 67279] [client 86.120.159.145:5067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAafcmepr5_nHgLbNAagAAAl4"]
[Tue Aug 18 12:55:21.915057 2026] [security2:error] [pid 67073:tid 67279] [client 86.120.159.145:5067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAafcmepr5_nHgLbNAagAAAl4"]
[Tue Aug 18 12:55:21.919671 2026] [security2:error] [pid 67073:tid 67268] [client 20.205.121.237:5078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/v5.php"] [unique_id "aoSAafcmepr5_nHgLbNAawAAAlM"]
[Tue Aug 18 12:55:22.008484 2026] [security2:error] [pid 67073:tid 67303] [client 196.251.121.142:38934] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "fbenevides.com"] [uri "/geoserver/wfs"] [unique_id "aoSAavcmepr5_nHgLbNAbgAAAnY"]
[Tue Aug 18 12:55:22.015166 2026] [security2:error] [pid 67073:tid 67219] [client 103.184.169.37:41633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAavcmepr5_nHgLbNAbwAAAiI"]
[Tue Aug 18 12:55:22.015515 2026] [security2:error] [pid 67073:tid 67219] [client 103.184.169.37:41633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAavcmepr5_nHgLbNAbwAAAiI"]
[Tue Aug 18 12:55:22.025463 2026] [security2:error] [pid 67073:tid 67326] [client 20.226.7.189:10078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/2.php"] [unique_id "aoSAavcmepr5_nHgLbNAcAAAAo0"]
[Tue Aug 18 12:55:22.033617 2026] [security2:error] [pid 67073:tid 67166] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/qr.php"] [unique_id "aoSAavcmepr5_nHgLbNAcQACLFo"]
[Tue Aug 18 12:55:22.118980 2026] [security2:error] [pid 67073:tid 67286] [client 20.171.51.14:29217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/bu.php"] [unique_id "aoSAavcmepr5_nHgLbNAcwAAAmU"]
[Tue Aug 18 12:55:22.237967 2026] [security2:error] [pid 67073:tid 67269] [client 20.226.7.189:19174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/7.php"] [unique_id "aoSAavcmepr5_nHgLbNAdgAAAlQ"]
[Tue Aug 18 12:55:22.271073 2026] [security2:error] [pid 67073:tid 67115] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/dirs.php"] [unique_id "aoSAavcmepr5_nHgLbNAeQACLSc"]
[Tue Aug 18 12:55:22.291551 2026] [security2:error] [pid 67073:tid 67294] [client 157.90.155.240:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.antoniopericiacontabil.com.br"] [uri "/index.php"] [unique_id "aoSAavcmepr5_nHgLbNAeAAAAm0"], referer: https://www.antoniopericiacontabil.com.br/
[Tue Aug 18 12:55:22.300893 2026] [security2:error] [pid 67073:tid 67296] [client 74.248.130.103:15361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/blurbs.php"] [unique_id "aoSAavcmepr5_nHgLbNAegAAAm8"]
[Tue Aug 18 12:55:22.301434 2026] [security2:error] [pid 67073:tid 67281] [client 20.116.17.175:57663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSAavcmepr5_nHgLbNAewAAAmA"]
[Tue Aug 18 12:55:22.332227 2026] [security2:error] [pid 67073:tid 67272] [client 172.182.200.96:14131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSAavcmepr5_nHgLbNAfAAAAlc"]
[Tue Aug 18 12:55:22.342600 2026] [security2:error] [pid 66623:tid 66853] [client 20.42.19.40:9701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/t.php"] [unique_id "aoSAatO5rbWdOArH04KDkgAAAWE"]
[Tue Aug 18 12:55:22.410890 2026] [security2:error] [pid 67073:tid 67309] [client 192.141.172.134:57281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAavcmepr5_nHgLbNAfwAAAnw"]
[Tue Aug 18 12:55:22.410990 2026] [security2:error] [pid 67073:tid 67309] [client 192.141.172.134:57281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAavcmepr5_nHgLbNAfwAAAnw"]
[Tue Aug 18 12:55:22.470318 2026] [authz_core:error] [pid 67073:tid 67130] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:22.470583 2026] [authz_core:error] [pid 67073:tid 67130] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:22.477307 2026] [security2:error] [pid 66623:tid 66861] [client 20.91.215.254:12751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/u.php"] [unique_id "aoSAatO5rbWdOArH04KDkwAAAWk"]
[Tue Aug 18 12:55:22.483636 2026] [security2:error] [pid 67073:tid 67190] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/sn.php"] [unique_id "aoSAavcmepr5_nHgLbNAggAChXI"]
[Tue Aug 18 12:55:22.550784 2026] [security2:error] [pid 66623:tid 66849] [client 20.163.43.14:4304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/lock360.php"] [unique_id "aoSAatO5rbWdOArH04KDlAAAAV0"]
[Tue Aug 18 12:55:22.604740 2026] [security2:error] [pid 67073:tid 67284] [client 20.226.7.189:10071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/10.php"] [unique_id "aoSAavcmepr5_nHgLbNAhQAAAmM"]
[Tue Aug 18 12:55:22.613376 2026] [security2:error] [pid 67073:tid 67256] [client 74.248.133.44:62492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/u.php"] [unique_id "aoSAavcmepr5_nHgLbNAhwAAAkc"]
[Tue Aug 18 12:55:22.637362 2026] [autoindex:error] [pid 67073:tid 67295] [client 172.202.39.151:50212] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:22.639714 2026] [security2:error] [pid 67073:tid 67290] [client 20.42.19.40:9660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/index/function.php"] [unique_id "aoSAavcmepr5_nHgLbNAiAAAAmk"]
[Tue Aug 18 12:55:22.749141 2026] [security2:error] [pid 67073:tid 67232] [client 20.226.6.191:7105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSAavcmepr5_nHgLbNAiwAAAi8"]
[Tue Aug 18 12:55:22.772073 2026] [security2:error] [pid 66623:tid 66772] [client 20.171.51.14:16766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/rn.php"] [unique_id "aoSAatO5rbWdOArH04KDlwAAARA"]
[Tue Aug 18 12:55:22.809402 2026] [security2:error] [pid 67073:tid 67276] [client 157.90.155.240:12502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.antoniopericiacontabil.com"] [uri "/index.php"] [unique_id "aoSAavcmepr5_nHgLbNAjAAAAls"], referer: https://www.antoniopericiacontabil.com.br/
[Tue Aug 18 12:55:22.976219 2026] [security2:error] [pid 66623:tid 66780] [client 20.163.43.14:4303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/flower.php"] [unique_id "aoSAatO5rbWdOArH04KDmQAAARg"]
[Tue Aug 18 12:55:22.979742 2026] [security2:error] [pid 67073:tid 67253] [client 172.202.39.151:50212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/alfa.php"] [unique_id "aoSAavcmepr5_nHgLbNAqAAAAkQ"]
[Tue Aug 18 12:55:22.980591 2026] [security2:error] [pid 67073:tid 67277] [client 20.65.98.162:17054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/file61.php"] [unique_id "aoSAavcmepr5_nHgLbNAqQAAAlw"]
[Tue Aug 18 12:55:23.147747 2026] [security2:error] [pid 66623:tid 66835] [client 20.29.77.16:47765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSAa9O5rbWdOArH04KDmgAAAU8"]
[Tue Aug 18 12:55:23.192030 2026] [security2:error] [pid 67073:tid 67313] [client 74.248.130.103:15378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/100.php"] [unique_id "aoSAa_cmepr5_nHgLbNArgAAAoA"]
[Tue Aug 18 12:55:23.286196 2026] [security2:error] [pid 66623:tid 66806] [client 132.196.61.152:34753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/mgrr.php"] [unique_id "aoSAa9O5rbWdOArH04KDmwAAATI"]
[Tue Aug 18 12:55:23.305603 2026] [security2:error] [pid 67073:tid 67289] [client 20.163.43.14:4436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/public/css.php"] [unique_id "aoSAa_cmepr5_nHgLbNAwgAAAmg"]
[Tue Aug 18 12:55:23.332602 2026] [authz_core:error] [pid 67073:tid 67172] [remote 57.141.22.37:44302] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:23.332868 2026] [authz_core:error] [pid 67073:tid 67172] [remote 57.141.22.37:44302] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:23.353111 2026] [security2:error] [pid 67073:tid 67218] [client 196.251.121.142:34138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "fbenevides.com"] [uri "/geoserver/web/"] [unique_id "aoSAa_cmepr5_nHgLbNAxAAAAiE"]
[Tue Aug 18 12:55:23.365299 2026] [security2:error] [pid 67073:tid 67225] [client 20.42.19.40:2916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/404.php"] [unique_id "aoSAa_cmepr5_nHgLbNAxQAAAig"]
[Tue Aug 18 12:55:23.393321 2026] [security2:error] [pid 66623:tid 66886] [client 52.238.210.254:35203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/themes.php"] [unique_id "aoSAa9O5rbWdOArH04KDngAAAYI"]
[Tue Aug 18 12:55:23.422433 2026] [security2:error] [pid 67073:tid 67327] [client 20.171.51.14:16728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/lv.php"] [unique_id "aoSAa_cmepr5_nHgLbNAxwAAAo4"]
[Tue Aug 18 12:55:23.484994 2026] [security2:error] [pid 67073:tid 67322] [client 20.104.100.201:58900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/read.php"] [unique_id "aoSAa_cmepr5_nHgLbNAyAAAAok"]
[Tue Aug 18 12:55:23.501029 2026] [security2:error] [pid 67073:tid 67248] [client 20.250.13.23:50806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wap.php"] [unique_id "aoSAa_cmepr5_nHgLbNAyQAAAj8"]
[Tue Aug 18 12:55:23.519744 2026] [security2:error] [pid 66623:tid 66893] [client 20.65.98.162:58716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/ws13.php"] [unique_id "aoSAa9O5rbWdOArH04KDoAAAAYk"]
[Tue Aug 18 12:55:23.597450 2026] [security2:error] [pid 66623:tid 66774] [client 20.51.153.15:8806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/wm.php"] [unique_id "aoSAa9O5rbWdOArH04KDoQAAARI"]
[Tue Aug 18 12:55:23.869000 2026] [security2:error] [pid 67073:tid 67242] [client 20.171.51.14:62485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ut.php"] [unique_id "aoSAa_cmepr5_nHgLbNA3gAAAjk"]
[Tue Aug 18 12:55:23.957275 2026] [security2:error] [pid 67073:tid 67318] [client 20.42.19.40:9682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wk/index.php"] [unique_id "aoSAa_cmepr5_nHgLbNA5AAAAoU"]
[Tue Aug 18 12:55:24.025011 2026] [security2:error] [pid 66623:tid 66815] [client 172.202.39.151:50228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/lock360.php"] [unique_id "aoSAbNO5rbWdOArH04KDpAAAATs"]
[Tue Aug 18 12:55:24.159978 2026] [security2:error] [pid 67073:tid 67207] [client 52.139.47.57:13509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/con7.php"] [unique_id "aoSAbPcmepr5_nHgLbNA8AAAAhY"]
[Tue Aug 18 12:55:24.220967 2026] [security2:error] [pid 67073:tid 67311] [client 20.42.19.40:2744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/lite.php"] [unique_id "aoSAbPcmepr5_nHgLbNA8QAAAn4"]
[Tue Aug 18 12:55:24.251049 2026] [security2:error] [pid 67073:tid 67319] [client 20.42.19.40:9708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-blink.php"] [unique_id "aoSAbPcmepr5_nHgLbNA8gAAAoY"]
[Tue Aug 18 12:55:24.300251 2026] [security2:error] [pid 67073:tid 67212] [client 52.238.210.254:8943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wk/index.php"] [unique_id "aoSAbPcmepr5_nHgLbNA9QAAAhs"]
[Tue Aug 18 12:55:24.404825 2026] [security2:error] [pid 67073:tid 67236] [client 4.223.164.152:54229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/155.php"] [unique_id "aoSAbPcmepr5_nHgLbNA-AAAAjM"]
[Tue Aug 18 12:55:24.424727 2026] [security2:error] [pid 67073:tid 67314] [client 20.163.43.14:4350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/13.php"] [unique_id "aoSAbPcmepr5_nHgLbNA_QAAAoE"]
[Tue Aug 18 12:55:24.441450 2026] [security2:error] [pid 67073:tid 67203] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/43.php"] [unique_id "aoSAbPcmepr5_nHgLbNA_gACMn8"]
[Tue Aug 18 12:55:24.465871 2026] [security2:error] [pid 67073:tid 67289] [client 172.202.39.151:11146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAbPcmepr5_nHgLbNA_wAAAmg"]
[Tue Aug 18 12:55:24.492044 2026] [security2:error] [pid 66623:tid 66830] [client 138.36.100.162:42724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbNO5rbWdOArH04KDpwAAAUo"]
[Tue Aug 18 12:55:24.492142 2026] [security2:error] [pid 66623:tid 66830] [client 138.36.100.162:42724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbNO5rbWdOArH04KDpwAAAUo"]
[Tue Aug 18 12:55:24.497507 2026] [security2:error] [pid 66623:tid 66775] [client 196.251.121.142:34140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "fbenevides.com"] [uri "/geoserver/wfs"] [unique_id "aoSAbNO5rbWdOArH04KDqQAAARM"]
[Tue Aug 18 12:55:24.502161 2026] [security2:error] [pid 67073:tid 67293] [client 20.42.19.40:9629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/xfun.php"] [unique_id "aoSAbPcmepr5_nHgLbNBAAAAAmw"]
[Tue Aug 18 12:55:24.514017 2026] [security2:error] [pid 66623:tid 66851] [client 20.251.48.93:56910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAbNO5rbWdOArH04KDqgAAAV8"]
[Tue Aug 18 12:55:24.588242 2026] [security2:error] [pid 67073:tid 67284] [client 149.34.210.141:65378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAbPcmepr5_nHgLbNBCgAAAmM"]
[Tue Aug 18 12:55:24.589861 2026] [security2:error] [pid 67073:tid 67275] [client 68.155.154.236:16356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAbPcmepr5_nHgLbNBCwAAAlo"]
[Tue Aug 18 12:55:24.610019 2026] [security2:error] [pid 67073:tid 67224] [client 172.202.39.151:32402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSAbPcmepr5_nHgLbNBDwAAAic"]
[Tue Aug 18 12:55:24.611684 2026] [security2:error] [pid 66623:tid 66802] [client 172.182.200.96:13899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSAbNO5rbWdOArH04KDzwAAAS4"]
[Tue Aug 18 12:55:24.637949 2026] [security2:error] [pid 67073:tid 67303] [client 20.42.19.40:2725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/lock360.php"] [unique_id "aoSAbPcmepr5_nHgLbNBEwAAAnY"]
[Tue Aug 18 12:55:24.667751 2026] [security2:error] [pid 67073:tid 67273] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbPcmepr5_nHgLbNBCAACWCk"]
[Tue Aug 18 12:55:24.672047 2026] [security2:error] [pid 67073:tid 67279] [client 4.232.151.198:18583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/inputs.php"] [unique_id "aoSAbPcmepr5_nHgLbNBFQAAAl4"]
[Tue Aug 18 12:55:24.678091 2026] [security2:error] [pid 67073:tid 67302] [client 157.20.138.62:57362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbPcmepr5_nHgLbNBFgAAAnU"]
[Tue Aug 18 12:55:24.678177 2026] [security2:error] [pid 67073:tid 67302] [client 157.20.138.62:57362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbPcmepr5_nHgLbNBFgAAAnU"]
[Tue Aug 18 12:55:24.703231 2026] [security2:error] [pid 67073:tid 67193] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/fresh.php"] [unique_id "aoSAbPcmepr5_nHgLbNBFwACNHU"]
[Tue Aug 18 12:55:24.747212 2026] [security2:error] [pid 66623:tid 66872] [client 4.232.151.198:41299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/term.php"] [unique_id "aoSAbNO5rbWdOArH04KD0QAAAXQ"]
[Tue Aug 18 12:55:24.773343 2026] [security2:error] [pid 66623:tid 66831] [client 20.91.215.254:19535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/customize.php"] [unique_id "aoSAbNO5rbWdOArH04KD0gAAAUs"]
[Tue Aug 18 12:55:24.773745 2026] [security2:error] [pid 66623:tid 66887] [client 20.104.100.201:58892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/albin.php"] [unique_id "aoSAbNO5rbWdOArH04KD0wAAAYM"]
[Tue Aug 18 12:55:24.786799 2026] [security2:error] [pid 67073:tid 67269] [client 20.163.43.14:4455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAbPcmepr5_nHgLbNBGAAAAlQ"]
[Tue Aug 18 12:55:24.791977 2026] [security2:error] [pid 67073:tid 67230] [client 20.42.19.40:9631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/p.php"] [unique_id "aoSAbPcmepr5_nHgLbNBGQAAAi0"]
[Tue Aug 18 12:55:24.813850 2026] [security2:error] [pid 66623:tid 66890] [client 20.163.43.14:4305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/cc.php"] [unique_id "aoSAbNO5rbWdOArH04KD1AAAAYY"]
[Tue Aug 18 12:55:24.835271 2026] [security2:error] [pid 66623:tid 66839] [client 20.226.7.189:19178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/13.php"] [unique_id "aoSAbNO5rbWdOArH04KD1QAAAVM"]
[Tue Aug 18 12:55:24.856037 2026] [security2:error] [pid 66623:tid 66769] [client 20.226.7.189:11287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/100.php"] [unique_id "aoSAbNO5rbWdOArH04KD1gAAAQ0"]
[Tue Aug 18 12:55:24.869258 2026] [security2:error] [pid 67073:tid 67284] [client 149.34.210.141:65378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAbPcmepr5_nHgLbNBCgAAAmM"]
[Tue Aug 18 12:55:24.884248 2026] [security2:error] [pid 67073:tid 67317] [client 4.223.164.152:28506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/ops.php"] [unique_id "aoSAbPcmepr5_nHgLbNBHQAAAoQ"]
[Tue Aug 18 12:55:24.890965 2026] [security2:error] [pid 67073:tid 67210] [client 20.51.153.15:8783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ac.php"] [unique_id "aoSAbPcmepr5_nHgLbNBHwAAAhk"]
[Tue Aug 18 12:55:24.949456 2026] [security2:error] [pid 67073:tid 67250] [client 52.173.121.69:6086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSAbPcmepr5_nHgLbNBIQAAAkE"]
[Tue Aug 18 12:55:24.976629 2026] [security2:error] [pid 67073:tid 67324] [client 20.226.7.189:18021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/222.php"] [unique_id "aoSAbPcmepr5_nHgLbNBIgAAAos"]
[Tue Aug 18 12:55:25.037524 2026] [security2:error] [pid 67073:tid 67205] [client 20.42.19.40:1356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAbfcmepr5_nHgLbNBJwAAAhQ"]
[Tue Aug 18 12:55:25.069569 2026] [security2:error] [pid 66623:tid 66776] [client 52.139.47.57:18196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/contact-form-7/includes/js/jquery-ui/themes/smoothness/RxRywmgzyK.php"] [unique_id "aoSAbdO5rbWdOArH04KD2gAAARQ"]
[Tue Aug 18 12:55:25.087503 2026] [security2:error] [pid 67073:tid 67244] [client 20.104.100.201:58895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/fw/34.php"] [unique_id "aoSAbfcmepr5_nHgLbNBKQAAAjs"]
[Tue Aug 18 12:55:25.093512 2026] [security2:error] [pid 67073:tid 67253] [client 74.248.136.165:10070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/zc-318.php"] [unique_id "aoSAbfcmepr5_nHgLbNBKgAAAkQ"]
[Tue Aug 18 12:55:25.127849 2026] [security2:error] [pid 67073:tid 67328] [client 20.51.153.15:9184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/yz.php"] [unique_id "aoSAbfcmepr5_nHgLbNBLAAAAo8"]
[Tue Aug 18 12:55:25.159161 2026] [security2:error] [pid 67073:tid 67310] [client 68.155.154.236:16267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAbfcmepr5_nHgLbNBLgAAAn0"]
[Tue Aug 18 12:55:25.192953 2026] [security2:error] [pid 67073:tid 67148] [remote 129.121.103.155:33692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centrodosorrisosobral.com.br"] [uri "/wp-login.php"] [unique_id "aoSAbfcmepr5_nHgLbNBLwACQ0g"]
[Tue Aug 18 12:55:25.217148 2026] [security2:error] [pid 67073:tid 67292] [client 20.251.48.93:57237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/xx.php"] [unique_id "aoSAbfcmepr5_nHgLbNBMAAAAms"]
[Tue Aug 18 12:55:25.218332 2026] [security2:error] [pid 67073:tid 67327] [client 20.171.51.14:21101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/eh.php"] [unique_id "aoSAbfcmepr5_nHgLbNBMQAAAo4"]
[Tue Aug 18 12:55:25.280537 2026] [security2:error] [pid 67073:tid 67224] [client 20.42.19.40:9609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/aaa.php"] [unique_id "aoSAbfcmepr5_nHgLbNBNAAAAic"]
[Tue Aug 18 12:55:25.285394 2026] [security2:error] [pid 66623:tid 66841] [client 20.226.7.189:9759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAbdO5rbWdOArH04KD3QAAAVU"]
[Tue Aug 18 12:55:25.304306 2026] [security2:error] [pid 66623:tid 66850] [client 20.226.7.189:18632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/abcd.php"] [unique_id "aoSAbdO5rbWdOArH04KD3gAAAV4"]
[Tue Aug 18 12:55:25.305220 2026] [security2:error] [pid 66623:tid 66824] [client 52.238.210.254:10184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-act.php"] [unique_id "aoSAbdO5rbWdOArH04KD3wAAAUQ"]
[Tue Aug 18 12:55:25.308383 2026] [security2:error] [pid 67073:tid 67262] [client 20.163.43.14:4249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAbfcmepr5_nHgLbNBNgAAAk0"]
[Tue Aug 18 12:55:25.318193 2026] [security2:error] [pid 66623:tid 66795] [client 20.48.236.86:16360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAbdO5rbWdOArH04KD4AAAASc"]
[Tue Aug 18 12:55:25.320595 2026] [security2:error] [pid 67073:tid 67248] [client 20.171.51.14:31627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/51.php"] [unique_id "aoSAbfcmepr5_nHgLbNBOAAAAj8"]
[Tue Aug 18 12:55:25.332010 2026] [security2:error] [pid 67073:tid 67303] [client 20.226.7.189:38644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/al.php"] [unique_id "aoSAbfcmepr5_nHgLbNBOgAAAnY"]
[Tue Aug 18 12:55:25.332635 2026] [security2:error] [pid 67073:tid 67249] [client 4.223.164.152:54247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/mac.php"] [unique_id "aoSAbfcmepr5_nHgLbNBOwAAAkA"]
[Tue Aug 18 12:55:25.351774 2026] [security2:error] [pid 67073:tid 67279] [client 20.226.7.189:10741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/alfa.php"] [unique_id "aoSAbfcmepr5_nHgLbNBPwAAAl4"]
[Tue Aug 18 12:55:25.352567 2026] [security2:error] [pid 67073:tid 67102] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gj.php"] [unique_id "aoSAbfcmepr5_nHgLbNBQAACNBo"]
[Tue Aug 18 12:55:25.371963 2026] [security2:error] [pid 67073:tid 67241] [client 20.100.169.31:31464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/file.php"] [unique_id "aoSAbfcmepr5_nHgLbNBQwAAAjg"]
[Tue Aug 18 12:55:25.373105 2026] [security2:error] [pid 67073:tid 67330] [client 20.29.77.16:52757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/pqr.php"] [unique_id "aoSAbfcmepr5_nHgLbNBRAAAApE"]
[Tue Aug 18 12:55:25.374306 2026] [security2:error] [pid 66623:tid 66784] [client 20.226.7.189:17993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/as.php"] [unique_id "aoSAbdO5rbWdOArH04KD4QAAARw"]
[Tue Aug 18 12:55:25.378728 2026] [security2:error] [pid 66623:tid 66791] [client 20.226.6.191:59940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAbdO5rbWdOArH04KD4gAAASM"]
[Tue Aug 18 12:55:25.393451 2026] [security2:error] [pid 67073:tid 67286] [client 20.226.7.189:19149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/aa.php"] [unique_id "aoSAbfcmepr5_nHgLbNBRQAAAmU"]
[Tue Aug 18 12:55:25.397134 2026] [security2:error] [pid 67073:tid 67315] [client 20.104.100.201:58936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp9.php"] [unique_id "aoSAbfcmepr5_nHgLbNBRgAAAoI"]
[Tue Aug 18 12:55:25.401397 2026] [security2:error] [pid 67073:tid 67233] [client 20.51.153.15:8770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/kj.php"] [unique_id "aoSAbfcmepr5_nHgLbNBRwAAAjA"]
[Tue Aug 18 12:55:25.411485 2026] [security2:error] [pid 67073:tid 67296] [client 20.226.7.189:19141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/abc.php"] [unique_id "aoSAbfcmepr5_nHgLbNBSAAAAm8"]
[Tue Aug 18 12:55:25.425455 2026] [security2:error] [pid 67073:tid 67317] [client 132.196.61.152:61042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/55.php"] [unique_id "aoSAbfcmepr5_nHgLbNBSgAAAoQ"]
[Tue Aug 18 12:55:25.434955 2026] [security2:error] [pid 67073:tid 67272] [client 20.226.7.189:9770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/av.php"] [unique_id "aoSAbfcmepr5_nHgLbNBSwAAAlc"]
[Tue Aug 18 12:55:25.449641 2026] [security2:error] [pid 67073:tid 67216] [client 158.158.34.183:54897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAbfcmepr5_nHgLbNBTQAAAh8"]
[Tue Aug 18 12:55:25.470337 2026] [security2:error] [pid 67073:tid 67229] [client 20.226.7.189:11297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSAbfcmepr5_nHgLbNBTwAAAiw"]
[Tue Aug 18 12:55:25.484526 2026] [authz_core:error] [pid 67073:tid 67111] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:25.484916 2026] [authz_core:error] [pid 67073:tid 67111] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:25.499910 2026] [security2:error] [pid 67073:tid 67256] [client 172.182.200.96:14332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/.cache/x.php"] [unique_id "aoSAbfcmepr5_nHgLbNBUQAAAkc"]
[Tue Aug 18 12:55:25.501109 2026] [security2:error] [pid 66623:tid 66858] [client 52.238.210.254:11579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAbdO5rbWdOArH04KD5AAAAWY"]
[Tue Aug 18 12:55:25.513959 2026] [security2:error] [pid 67073:tid 67267] [client 74.248.136.165:9936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ccou.php"] [unique_id "aoSAbfcmepr5_nHgLbNBUgAAAlI"]
[Tue Aug 18 12:55:25.518610 2026] [security2:error] [pid 67073:tid 67331] [client 78.47.173.76:38174] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.parquefazendadasflores.com.br"] [uri "/index.php"] [unique_id "aoSAbPcmepr5_nHgLbNA5wAAApI"], referer: https://www.parquefazendadasflores.com.br
[Tue Aug 18 12:55:25.521167 2026] [security2:error] [pid 66623:tid 66833] [client 20.226.7.189:10052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/asus.php"] [unique_id "aoSAbdO5rbWdOArH04KD5gAAAU0"]
[Tue Aug 18 12:55:25.526461 2026] [autoindex:error] [pid 66623:tid 66876] [client 198.235.24.29:60974] AH01276: Cannot serve directory /home3/lidero37/novidades.lidero.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:25.537955 2026] [security2:error] [pid 67073:tid 67223] [client 135.225.75.187:9281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/gec.php"] [unique_id "aoSAbfcmepr5_nHgLbNBVwAAAiY"]
[Tue Aug 18 12:55:25.540749 2026] [security2:error] [pid 67073:tid 67255] [client 20.163.43.14:4363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAbfcmepr5_nHgLbNBWAAAAkY"]
[Tue Aug 18 12:55:25.565081 2026] [security2:error] [pid 66623:tid 66823] [client 74.248.133.44:24761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/k.php"] [unique_id "aoSAbdO5rbWdOArH04KD5wAAAUM"]
[Tue Aug 18 12:55:25.571501 2026] [security2:error] [pid 67073:tid 67205] [client 20.226.7.189:18015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/about.php"] [unique_id "aoSAbfcmepr5_nHgLbNBXAAAAhQ"]
[Tue Aug 18 12:55:25.598764 2026] [security2:error] [pid 67073:tid 67276] [client 20.226.7.189:38632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/atomlib.php"] [unique_id "aoSAbfcmepr5_nHgLbNBXgAAAls"]
[Tue Aug 18 12:55:25.599325 2026] [security2:error] [pid 67073:tid 67244] [client 20.42.19.40:1384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/term.php"] [unique_id "aoSAbfcmepr5_nHgLbNBXwAAAjs"]
[Tue Aug 18 12:55:25.604804 2026] [security2:error] [pid 67073:tid 67083] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/pd.php"] [unique_id "aoSAbfcmepr5_nHgLbNBYAACMwc"]
[Tue Aug 18 12:55:25.608053 2026] [security2:error] [pid 66623:tid 66853] [client 172.182.200.96:14117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSAbdO5rbWdOArH04KD6AAAAWE"]
[Tue Aug 18 12:55:25.615192 2026] [security2:error] [pid 66623:tid 66861] [client 20.48.236.86:16347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAbdO5rbWdOArH04KD6QAAAWk"]
[Tue Aug 18 12:55:25.620319 2026] [security2:error] [pid 66623:tid 66845] [client 20.226.7.189:2372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSAbdO5rbWdOArH04KD6gAAAVk"]
[Tue Aug 18 12:55:25.625797 2026] [security2:error] [pid 66623:tid 66786] [client 172.202.39.151:14683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAbdO5rbWdOArH04KD6wAAAR4"]
[Tue Aug 18 12:55:25.637826 2026] [security2:error] [pid 66623:tid 66836] [client 20.226.7.189:10738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/b.php"] [unique_id "aoSAbdO5rbWdOArH04KD7QAAAVA"]
[Tue Aug 18 12:55:25.639666 2026] [security2:error] [pid 66623:tid 66796] [client 20.163.43.14:4326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSAbdO5rbWdOArH04KD7gAAASg"]
[Tue Aug 18 12:55:25.651642 2026] [security2:error] [pid 66623:tid 66772] [client 20.51.153.15:9177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/vg.php"] [unique_id "aoSAbdO5rbWdOArH04KD7wAAARA"]
[Tue Aug 18 12:55:25.659393 2026] [security2:error] [pid 66623:tid 66780] [client 20.226.7.189:18674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/buy.php"] [unique_id "aoSAbdO5rbWdOArH04KD8AAAARg"]
[Tue Aug 18 12:55:25.669783 2026] [security2:error] [pid 67073:tid 67310] [client 20.91.215.254:12521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/mah/function.php"] [unique_id "aoSAbfcmepr5_nHgLbNBYgAAAn0"]
[Tue Aug 18 12:55:25.682030 2026] [security2:error] [pid 67073:tid 67252] [client 20.226.7.189:10746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/bless.php"] [unique_id "aoSAbfcmepr5_nHgLbNBZAAAAkM"]
[Tue Aug 18 12:55:25.683482 2026] [security2:error] [pid 67073:tid 67215] [client 178.153.171.161:32465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbfcmepr5_nHgLbNBZQAAAh4"]
[Tue Aug 18 12:55:25.683581 2026] [security2:error] [pid 67073:tid 67215] [client 178.153.171.161:32465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbfcmepr5_nHgLbNBZQAAAh4"]
[Tue Aug 18 12:55:25.702579 2026] [security2:error] [pid 66623:tid 66797] [client 20.226.7.189:9772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/class-t.api.php"] [unique_id "aoSAbdO5rbWdOArH04KD9gAAASk"]
[Tue Aug 18 12:55:25.721954 2026] [security2:error] [pid 66623:tid 66838] [client 20.226.7.189:38621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/cache.php"] [unique_id "aoSAbdO5rbWdOArH04KD9wAAAVI"]
[Tue Aug 18 12:55:25.743002 2026] [security2:error] [pid 67073:tid 67224] [client 20.226.7.189:38597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/content.php"] [unique_id "aoSAbfcmepr5_nHgLbNBaAAAAic"]
[Tue Aug 18 12:55:25.750601 2026] [security2:error] [pid 67073:tid 67299] [client 20.116.17.175:57450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSAbfcmepr5_nHgLbNBaQAAAnI"]
[Tue Aug 18 12:55:25.762960 2026] [security2:error] [pid 67073:tid 67239] [client 20.226.7.189:10733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAbfcmepr5_nHgLbNBagAAAjY"]
[Tue Aug 18 12:55:25.782483 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:25.782757 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:25.785425 2026] [security2:error] [pid 66623:tid 66807] [client 20.226.7.189:18648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/css.php"] [unique_id "aoSAbdO5rbWdOArH04KD-QAAATM"]
[Tue Aug 18 12:55:25.802550 2026] [security2:error] [pid 66623:tid 66814] [client 20.226.7.189:38601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/chosen.php"] [unique_id "aoSAbdO5rbWdOArH04KD-gAAATo"]
[Tue Aug 18 12:55:25.826023 2026] [security2:error] [pid 67073:tid 67084] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/th.php"] [unique_id "aoSAbfcmepr5_nHgLbNBbQACbgg"]
[Tue Aug 18 12:55:25.828102 2026] [security2:error] [pid 66623:tid 66785] [client 20.226.7.189:18019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/doc.php"] [unique_id "aoSAbdO5rbWdOArH04KD_gAAAR0"]
[Tue Aug 18 12:55:25.830940 2026] [security2:error] [pid 67073:tid 67241] [client 20.104.100.201:58885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/save.php"] [unique_id "aoSAbfcmepr5_nHgLbNBbgAAAjg"]
[Tue Aug 18 12:55:25.849346 2026] [security2:error] [pid 67073:tid 67330] [client 20.226.7.189:19156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/elp.php"] [unique_id "aoSAbfcmepr5_nHgLbNBbwAAApE"]
[Tue Aug 18 12:55:25.852241 2026] [security2:error] [pid 67073:tid 67211] [client 20.42.19.40:9691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/7.php"] [unique_id "aoSAbfcmepr5_nHgLbNBcAAAAho"]
[Tue Aug 18 12:55:25.862477 2026] [security2:error] [pid 66623:tid 66851] [client 4.223.164.152:64660] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "aoSAbdO5rbWdOArH04KD_wAAAV8"]
[Tue Aug 18 12:55:25.867355 2026] [security2:error] [pid 66623:tid 66863] [client 20.226.7.189:19185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/Exception-class.php"] [unique_id "aoSAbdO5rbWdOArH04KEAAAAAWs"]
[Tue Aug 18 12:55:25.876019 2026] [security2:error] [pid 66623:tid 66868] [client 172.182.200.96:13940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSAbdO5rbWdOArH04KEAQAAAXA"]
[Tue Aug 18 12:55:25.888666 2026] [security2:error] [pid 67073:tid 67294] [client 20.226.7.189:19194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/ee.php"] [unique_id "aoSAbfcmepr5_nHgLbNBdAAAAm0"]
[Tue Aug 18 12:55:25.908383 2026] [security2:error] [pid 67073:tid 67316] [client 20.226.7.189:9609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/edit.php"] [unique_id "aoSAbfcmepr5_nHgLbNBdQAAAoM"]
[Tue Aug 18 12:55:25.927292 2026] [security2:error] [pid 66623:tid 66802] [client 20.226.7.189:18667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/f35.php"] [unique_id "aoSAbdO5rbWdOArH04KEAwAAAS4"]
[Tue Aug 18 12:55:25.931392 2026] [security2:error] [pid 66623:tid 66837] [client 74.248.136.165:27946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/txets.php"] [unique_id "aoSAbdO5rbWdOArH04KEBAAAAVE"]
[Tue Aug 18 12:55:25.948610 2026] [security2:error] [pid 66623:tid 66857] [client 20.226.7.189:18660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/fff.php"] [unique_id "aoSAbdO5rbWdOArH04KEBgAAAWU"]
[Tue Aug 18 12:55:25.967518 2026] [security2:error] [pid 67073:tid 67317] [client 20.171.51.14:58382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ew.php"] [unique_id "aoSAbfcmepr5_nHgLbNBeQAAAoQ"]
[Tue Aug 18 12:55:25.967555 2026] [security2:error] [pid 67073:tid 67266] [client 20.51.153.15:9137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/sm.php"] [unique_id "aoSAbfcmepr5_nHgLbNBegAAAlE"]
[Tue Aug 18 12:55:25.969680 2026] [security2:error] [pid 66623:tid 66872] [client 20.226.7.189:10059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/ff1.php"] [unique_id "aoSAbdO5rbWdOArH04KECAAAAXQ"]
[Tue Aug 18 12:55:25.978482 2026] [security2:error] [pid 66623:tid 66783] [client 20.205.121.237:5082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/w.php"] [unique_id "aoSAbdO5rbWdOArH04KECQAAARs"]
[Tue Aug 18 12:55:25.988668 2026] [security2:error] [pid 67073:tid 67322] [client 20.163.43.14:4429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/gelay.php"] [unique_id "aoSAbfcmepr5_nHgLbNBfQAAAok"]
[Tue Aug 18 12:55:25.991470 2026] [security2:error] [pid 67073:tid 67225] [client 20.226.7.189:19151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/flower.php"] [unique_id "aoSAbfcmepr5_nHgLbNBfgAAAig"]
[Tue Aug 18 12:55:25.994945 2026] [security2:error] [pid 67073:tid 67274] [client 52.238.210.254:8948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSAbfcmepr5_nHgLbNBfwAAAlk"]
[Tue Aug 18 12:55:26.000620 2026] [security2:error] [pid 66623:tid 66805] [client 20.100.169.31:2432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/goods.php"] [unique_id "aoSAbdO5rbWdOArH04KECgAAATE"]
[Tue Aug 18 12:55:26.012559 2026] [security2:error] [pid 67073:tid 67229] [client 20.226.7.189:18036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/file.php"] [unique_id "aoSAbvcmepr5_nHgLbNBgAAAAiw"]
[Tue Aug 18 12:55:26.029315 2026] [security2:error] [pid 67073:tid 67279] [client 52.139.47.57:9024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/dist/alfa-rex.php"] [unique_id "aoSAbvcmepr5_nHgLbNBgQAAAl4"]
[Tue Aug 18 12:55:26.034032 2026] [security2:error] [pid 67073:tid 67313] [client 20.226.7.189:11286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/goods.php"] [unique_id "aoSAbvcmepr5_nHgLbNBggAAAoA"]
[Tue Aug 18 12:55:26.059319 2026] [security2:error] [pid 67073:tid 67306] [client 20.226.7.189:10070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/g.php"] [unique_id "aoSAbvcmepr5_nHgLbNBhQAAAnk"]
[Tue Aug 18 12:55:26.063050 2026] [security2:error] [pid 67073:tid 67093] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/admin404.php"] [unique_id "aoSAbvcmepr5_nHgLbNBhgACFhE"]
[Tue Aug 18 12:55:26.063343 2026] [security2:error] [pid 67073:tid 67210] [client 4.232.151.198:42247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAbvcmepr5_nHgLbNBhwAAAhk"]
[Tue Aug 18 12:55:26.080613 2026] [security2:error] [pid 67073:tid 67311] [client 20.226.7.189:9226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/hplfuns.php"] [unique_id "aoSAbvcmepr5_nHgLbNBiQAAAn4"]
[Tue Aug 18 12:55:26.084144 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:26.084416 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:26.099271 2026] [security2:error] [pid 67073:tid 67276] [client 20.65.98.162:43818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/copypaths.php"] [unique_id "aoSAbvcmepr5_nHgLbNBiwAAAls"]
[Tue Aug 18 12:55:26.100972 2026] [security2:error] [pid 67073:tid 67323] [client 20.226.7.189:19173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAbvcmepr5_nHgLbNBjAAAAoo"]
[Tue Aug 18 12:55:26.107119 2026] [security2:error] [pid 67073:tid 67244] [client 132.196.61.152:60303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/ajax.php"] [unique_id "aoSAbvcmepr5_nHgLbNBjQAAAjs"]
[Tue Aug 18 12:55:26.119969 2026] [security2:error] [pid 67073:tid 67277] [client 20.226.7.189:38626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/in.php"] [unique_id "aoSAbvcmepr5_nHgLbNBjgAAAlw"]
[Tue Aug 18 12:55:26.122870 2026] [security2:error] [pid 66623:tid 66821] [client 20.42.19.40:9605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/file5.php"] [unique_id "aoSAbtO5rbWdOArH04KEDAAAAUE"]
[Tue Aug 18 12:55:26.125788 2026] [security2:error] [pid 66623:tid 66870] [client 20.163.43.14:4274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/01.php"] [unique_id "aoSAbtO5rbWdOArH04KEDQAAAXI"]
[Tue Aug 18 12:55:26.139904 2026] [security2:error] [pid 66623:tid 66866] [client 20.65.98.162:56694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/btx25.php"] [unique_id "aoSAbtO5rbWdOArH04KEDgAAAW4"]
[Tue Aug 18 12:55:26.142442 2026] [security2:error] [pid 66623:tid 66840] [client 20.226.7.189:18639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/info.php"] [unique_id "aoSAbtO5rbWdOArH04KEDwAAAVQ"]
[Tue Aug 18 12:55:26.150456 2026] [security2:error] [pid 66623:tid 66817] [client 20.104.100.201:58493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoSAbtO5rbWdOArH04KEEAAAAT0"]
[Tue Aug 18 12:55:26.166367 2026] [security2:error] [pid 66623:tid 66860] [client 20.226.7.189:11278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/inputs.php"] [unique_id "aoSAbtO5rbWdOArH04KEEwAAAWg"]
[Tue Aug 18 12:55:26.168586 2026] [security2:error] [pid 66623:tid 66808] [client 114.119.137.70:46851] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nacur.com.br"] [uri "/sitemap_index_13.xml"] [unique_id "aoSAbtO5rbWdOArH04KEFAAAATQ"]
[Tue Aug 18 12:55:26.192652 2026] [security2:error] [pid 67073:tid 67280] [client 20.226.7.189:19199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/item.php"] [unique_id "aoSAbvcmepr5_nHgLbNBkAAAAl8"]
[Tue Aug 18 12:55:26.213478 2026] [security2:error] [pid 67073:tid 67327] [client 20.226.7.189:11311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/k.php"] [unique_id "aoSAbvcmepr5_nHgLbNBkgAAAo4"]
[Tue Aug 18 12:55:26.223489 2026] [security2:error] [pid 67073:tid 67227] [client 20.251.48.93:25018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/av.php"] [unique_id "aoSAbvcmepr5_nHgLbNBkwAAAio"]
[Tue Aug 18 12:55:26.232355 2026] [security2:error] [pid 67073:tid 67332] [client 20.226.7.189:10697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/license.php"] [unique_id "aoSAbvcmepr5_nHgLbNBlAAAApM"]
[Tue Aug 18 12:55:26.255027 2026] [security2:error] [pid 67073:tid 67224] [client 20.226.7.189:9742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/load.php"] [unique_id "aoSAbvcmepr5_nHgLbNBlgAAAic"]
[Tue Aug 18 12:55:26.255961 2026] [security2:error] [pid 67073:tid 67248] [client 20.42.19.40:2715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSAbvcmepr5_nHgLbNBlwAAAj8"]
[Tue Aug 18 12:55:26.268301 2026] [security2:error] [pid 67073:tid 67303] [client 172.182.200.96:14295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAbvcmepr5_nHgLbNBmAAAAnY"]
[Tue Aug 18 12:55:26.275096 2026] [security2:error] [pid 67073:tid 67284] [client 20.226.7.189:9620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/manager.php"] [unique_id "aoSAbvcmepr5_nHgLbNBmQAAAmM"]
[Tue Aug 18 12:55:26.285940 2026] [security2:error] [pid 67073:tid 67208] [client 4.223.164.152:64667] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-admin/js/"] [unique_id "aoSAbvcmepr5_nHgLbNBmgAAAhc"]
[Tue Aug 18 12:55:26.294047 2026] [security2:error] [pid 66623:tid 66850] [client 20.226.7.189:10703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/media.php"] [unique_id "aoSAbtO5rbWdOArH04KEFQAAAV4"]
[Tue Aug 18 12:55:26.307130 2026] [security2:error] [pid 67073:tid 67282] [client 20.51.153.15:9135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/28.php"] [unique_id "aoSAbvcmepr5_nHgLbNBmwAAAmE"]
[Tue Aug 18 12:55:26.307651 2026] [security2:error] [pid 67073:tid 67295] [client 20.116.17.175:57661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/term.php"] [unique_id "aoSAbvcmepr5_nHgLbNBnAAAAm4"]
[Tue Aug 18 12:55:26.312115 2026] [security2:error] [pid 67073:tid 67241] [client 20.48.236.86:16290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAbvcmepr5_nHgLbNBnQAAAjg"]
[Tue Aug 18 12:55:26.322734 2026] [security2:error] [pid 67073:tid 67330] [client 20.226.7.189:38609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/mar.php"] [unique_id "aoSAbvcmepr5_nHgLbNBnwAAApE"]
[Tue Aug 18 12:55:26.337326 2026] [security2:error] [pid 66623:tid 66822] [client 20.250.13.23:20692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSAbtO5rbWdOArH04KEFwAAAUI"]
[Tue Aug 18 12:55:26.342291 2026] [security2:error] [pid 67073:tid 67286] [client 20.226.7.189:9250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/my1.php"] [unique_id "aoSAbvcmepr5_nHgLbNBoAAAAmU"]
[Tue Aug 18 12:55:26.349443 2026] [security2:error] [pid 67073:tid 67230] [client 74.248.136.165:9964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/fun.php"] [unique_id "aoSAbvcmepr5_nHgLbNBoQAAAi0"]
[Tue Aug 18 12:55:26.354050 2026] [security2:error] [pid 66623:tid 66816] [client 20.91.215.254:12522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/filter.php"] [unique_id "aoSAbtO5rbWdOArH04KEGAAAATw"]
[Tue Aug 18 12:55:26.360842 2026] [security2:error] [pid 67073:tid 67214] [client 20.226.7.189:38654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/mm.php"] [unique_id "aoSAbvcmepr5_nHgLbNBpQAAAh0"]
[Tue Aug 18 12:55:26.364111 2026] [security2:error] [pid 67073:tid 67123] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/qo.php"] [unique_id "aoSAbvcmepr5_nHgLbNBpgACiC8"]
[Tue Aug 18 12:55:26.381891 2026] [authz_core:error] [pid 67073:tid 67164] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:26.382179 2026] [authz_core:error] [pid 67073:tid 67164] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:26.382749 2026] [security2:error] [pid 67073:tid 67234] [client 20.226.7.189:11270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/network.php"] [unique_id "aoSAbvcmepr5_nHgLbNBqgAAAjE"]
[Tue Aug 18 12:55:26.385049 2026] [security2:error] [pid 67073:tid 67257] [client 20.42.19.40:1378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/makeasmtp.php"] [unique_id "aoSAbvcmepr5_nHgLbNBqwAAAkg"]
[Tue Aug 18 12:55:26.390373 2026] [security2:error] [pid 67073:tid 67318] [client 5.161.75.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/index.php"] [unique_id "aoSAbPcmepr5_nHgLbNBIAAChUQ"], referer: https://tecpolorefrigeracaosp.com.br/
[Tue Aug 18 12:55:26.402450 2026] [security2:error] [pid 67073:tid 67272] [client 20.226.7.189:19156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/new.php"] [unique_id "aoSAbvcmepr5_nHgLbNBrAAAAlc"]
[Tue Aug 18 12:55:26.411239 2026] [security2:error] [pid 67073:tid 67320] [client 20.163.43.14:4464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAbvcmepr5_nHgLbNBrQAAAoc"]
[Tue Aug 18 12:55:26.422023 2026] [security2:error] [pid 67073:tid 67301] [client 20.226.7.189:19194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/0x.php"] [unique_id "aoSAbvcmepr5_nHgLbNBrgAAAnQ"]
[Tue Aug 18 12:55:26.429625 2026] [security2:error] [pid 67073:tid 67322] [client 20.104.100.201:21470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAbvcmepr5_nHgLbNBrwAAAok"]
[Tue Aug 18 12:55:26.444183 2026] [security2:error] [pid 67073:tid 67226] [client 20.226.7.189:11312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/0.php"] [unique_id "aoSAbvcmepr5_nHgLbNBsAAAAik"]
[Tue Aug 18 12:55:26.463969 2026] [security2:error] [pid 67073:tid 67242] [client 20.226.7.189:10059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/oxshell.php"] [unique_id "aoSAbvcmepr5_nHgLbNBsgAAAjk"]
[Tue Aug 18 12:55:26.471675 2026] [security2:error] [pid 67073:tid 67275] [client 20.100.169.31:36289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/ww5.php"] [unique_id "aoSAbvcmepr5_nHgLbNBswAAAlo"]
[Tue Aug 18 12:55:26.481432 2026] [security2:error] [pid 67073:tid 67267] [client 20.226.7.189:11306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/php8.php"] [unique_id "aoSAbvcmepr5_nHgLbNBtAAAAlI"]
[Tue Aug 18 12:55:26.499319 2026] [security2:error] [pid 67073:tid 67290] [client 20.226.7.189:18036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/p.php"] [unique_id "aoSAbvcmepr5_nHgLbNBtQAAAmk"]
[Tue Aug 18 12:55:26.517073 2026] [security2:error] [pid 67073:tid 67205] [client 20.226.7.189:38604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/php.php"] [unique_id "aoSAbvcmepr5_nHgLbNBtgAAAhQ"]
[Tue Aug 18 12:55:26.534871 2026] [security2:error] [pid 66623:tid 66768] [client 20.226.7.189:19143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/past.php"] [unique_id "aoSAbtO5rbWdOArH04KEGQAAAQw"]
[Tue Aug 18 12:55:26.535556 2026] [security2:error] [pid 67073:tid 67264] [client 68.155.154.236:16335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/weozh.php"] [unique_id "aoSAbvcmepr5_nHgLbNBtwAAAk8"]
[Tue Aug 18 12:55:26.549251 2026] [security2:error] [pid 66623:tid 66858] [client 135.225.75.187:29079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/scx.php7"] [unique_id "aoSAbtO5rbWdOArH04KEGgAAAWY"]
[Tue Aug 18 12:55:26.553912 2026] [security2:error] [pid 67073:tid 67323] [client 20.226.7.189:19137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/root.php"] [unique_id "aoSAbvcmepr5_nHgLbNBuAAAAoo"]
[Tue Aug 18 12:55:26.562518 2026] [security2:error] [pid 67073:tid 67244] [client 20.163.43.14:4340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/lv.php"] [unique_id "aoSAbvcmepr5_nHgLbNBuQAAAjs"]
[Tue Aug 18 12:55:26.595451 2026] [security2:error] [pid 67073:tid 67277] [client 20.226.7.189:38626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/r.php"] [unique_id "aoSAbvcmepr5_nHgLbNBvAAAAlw"]
[Tue Aug 18 12:55:26.598062 2026] [security2:error] [pid 67073:tid 67247] [client 20.151.109.219:53216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/sb.php"] [unique_id "aoSAbvcmepr5_nHgLbNBvgAAAj4"]
[Tue Aug 18 12:55:26.620359 2026] [security2:error] [pid 66623:tid 66800] [client 172.182.200.96:14271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAbtO5rbWdOArH04KEGwAAASw"]
[Tue Aug 18 12:55:26.623568 2026] [security2:error] [pid 66623:tid 66801] [client 52.238.210.254:8283] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-admin/js/"] [unique_id "aoSAbtO5rbWdOArH04KEHAAAAS0"]
[Tue Aug 18 12:55:26.628666 2026] [security2:error] [pid 67073:tid 67269] [client 20.100.169.31:2444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/hplfuns.php"] [unique_id "aoSAbvcmepr5_nHgLbNBwQAAAlQ"]
[Tue Aug 18 12:55:26.632211 2026] [security2:error] [pid 66623:tid 66823] [client 20.51.153.15:9100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/m.php"] [unique_id "aoSAbtO5rbWdOArH04KEHgAAAUM"]
[Tue Aug 18 12:55:26.647236 2026] [security2:error] [pid 67073:tid 67108] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/sd.php"] [unique_id "aoSAbvcmepr5_nHgLbNBywACISA"]
[Tue Aug 18 12:55:26.649935 2026] [security2:error] [pid 67073:tid 67281] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbPcmepr5_nHgLbNBGgACYDI"]
[Tue Aug 18 12:55:26.669022 2026] [security2:error] [pid 67073:tid 67319] [client 160.120.140.123:58461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbvcmepr5_nHgLbNBzgAAAoY"]
[Tue Aug 18 12:55:26.669179 2026] [security2:error] [pid 67073:tid 67319] [client 160.120.140.123:58461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbvcmepr5_nHgLbNBzgAAAoY"]
[Tue Aug 18 12:55:26.674388 2026] [security2:error] [pid 66623:tid 66844] [client 172.202.39.151:65259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/flower.php"] [unique_id "aoSAbtO5rbWdOArH04KEIgAAAVg"]
[Tue Aug 18 12:55:26.682098 2026] [security2:error] [pid 67073:tid 67287] [client 192.141.172.134:57571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAbvcmepr5_nHgLbNB0AAAAmY"]
[Tue Aug 18 12:55:26.682231 2026] [security2:error] [pid 67073:tid 67287] [client 192.141.172.134:57571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAbvcmepr5_nHgLbNB0AAAAmY"]
[Tue Aug 18 12:55:26.685182 2026] [security2:error] [pid 66623:tid 66849] [client 20.42.19.40:9676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/index.php"] [unique_id "aoSAbtO5rbWdOArH04KEJAAAAV0"]
[Tue Aug 18 12:55:26.687537 2026] [security2:error] [pid 66623:tid 66786] [client 20.171.51.14:51823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ad.php"] [unique_id "aoSAbtO5rbWdOArH04KEJQAAAR4"]
[Tue Aug 18 12:55:26.697848 2026] [security2:error] [pid 66623:tid 66836] [client 20.48.236.86:16259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/av.php"] [unique_id "aoSAbtO5rbWdOArH04KEJgAAAVA"]
[Tue Aug 18 12:55:26.721631 2026] [security2:error] [pid 67073:tid 67224] [client 20.226.7.189:19180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/sid3.php"] [unique_id "aoSAbvcmepr5_nHgLbNB0wAAAic"]
[Tue Aug 18 12:55:26.735705 2026] [security2:error] [pid 67073:tid 67313] [client 74.248.18.37:40054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAbvcmepr5_nHgLbNB1AAAAoA"]
[Tue Aug 18 12:55:26.739825 2026] [security2:error] [pid 67073:tid 67331] [client 85.154.68.202:11529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAbvcmepr5_nHgLbNB1QAAApI"]
[Tue Aug 18 12:55:26.739950 2026] [security2:error] [pid 67073:tid 67331] [client 85.154.68.202:11529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAbvcmepr5_nHgLbNB1QAAApI"]
[Tue Aug 18 12:55:26.748217 2026] [security2:error] [pid 66623:tid 66809] [client 20.226.7.189:10698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/ss.php"] [unique_id "aoSAbtO5rbWdOArH04KEJwAAATU"]
[Tue Aug 18 12:55:26.768061 2026] [security2:error] [pid 67073:tid 67295] [client 74.248.136.165:30925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/jq.php"] [unique_id "aoSAbvcmepr5_nHgLbNB2AAAAm4"]
[Tue Aug 18 12:55:26.769608 2026] [security2:error] [pid 66623:tid 66820] [client 20.226.7.189:9620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/sts.php"] [unique_id "aoSAbtO5rbWdOArH04KEKgAAAUA"]
[Tue Aug 18 12:55:26.787958 2026] [security2:error] [pid 66623:tid 66806] [client 20.171.51.14:51810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/pqr.php"] [unique_id "aoSAbtO5rbWdOArH04KEKwAAATI"]
[Tue Aug 18 12:55:26.791188 2026] [security2:error] [pid 67073:tid 67211] [client 20.226.7.189:38609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/shell.php"] [unique_id "aoSAbvcmepr5_nHgLbNB2wAAAho"]
[Tue Aug 18 12:55:26.794893 2026] [security2:error] [pid 66623:tid 66797] [client 4.223.164.152:28493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSAbtO5rbWdOArH04KELAAAASk"]
[Tue Aug 18 12:55:26.813173 2026] [security2:error] [pid 66623:tid 66879] [client 20.226.7.189:38654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/setup-config.php"] [unique_id "aoSAbtO5rbWdOArH04KELQAAAXs"]
[Tue Aug 18 12:55:26.816886 2026] [security2:error] [pid 67073:tid 67230] [client 52.173.121.69:17940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSAbvcmepr5_nHgLbNB3AAAAi0"]
[Tue Aug 18 12:55:26.821190 2026] [security2:error] [pid 66623:tid 66826] [client 172.182.200.96:14129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSAbtO5rbWdOArH04KELgAAAUY"]
[Tue Aug 18 12:55:26.834288 2026] [security2:error] [pid 66623:tid 66869] [client 20.226.7.189:10751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/t.php"] [unique_id "aoSAbtO5rbWdOArH04KELwAAAXE"]
[Tue Aug 18 12:55:26.835317 2026] [security2:error] [pid 66623:tid 66782] [client 157.90.155.240:28410] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.antoniopericiacontabil.com"] [uri "/index.php"] [unique_id "aoSAbtO5rbWdOArH04KEHQAAARo"], referer: https://www.antoniopericiacontabil.com.br/
[Tue Aug 18 12:55:26.839885 2026] [security2:error] [pid 67073:tid 67214] [client 20.163.43.14:4425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAbvcmepr5_nHgLbNB3QAAAh0"]
[Tue Aug 18 12:55:26.850952 2026] [security2:error] [pid 67073:tid 67234] [client 20.104.100.201:58432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/df.php"] [unique_id "aoSAbvcmepr5_nHgLbNB3gAAAjE"]
[Tue Aug 18 12:55:26.856601 2026] [security2:error] [pid 67073:tid 67212] [client 20.226.7.189:9767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/up.php"] [unique_id "aoSAbvcmepr5_nHgLbNB3wAAAhs"]
[Tue Aug 18 12:55:26.865143 2026] [security2:error] [pid 66623:tid 66799] [client 5.253.205.188:48236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/install.bak"] [unique_id "aoSAbtO5rbWdOArH04KEMAAAASs"], referer: https://medihub.com.br/install.bak
[Tue Aug 18 12:55:26.871497 2026] [security2:error] [pid 67073:tid 67169] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/km.php"] [unique_id "aoSAbvcmepr5_nHgLbNB4AACZF0"]
[Tue Aug 18 12:55:26.875115 2026] [security2:error] [pid 66623:tid 66878] [client 20.226.7.189:9781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/ultra.php"] [unique_id "aoSAbtO5rbWdOArH04KEMwAAAXo"]
[Tue Aug 18 12:55:26.924142 2026] [security2:error] [pid 67073:tid 67272] [client 20.51.153.15:9168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/nl.php"] [unique_id "aoSAbvcmepr5_nHgLbNB5AAAAlc"]
[Tue Aug 18 12:55:26.925181 2026] [security2:error] [pid 66623:tid 66871] [client 20.42.19.40:9703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSAbtO5rbWdOArH04KENQAAAXM"]
[Tue Aug 18 12:55:26.942331 2026] [security2:error] [pid 67073:tid 67317] [client 20.151.109.219:21676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/xj.php"] [unique_id "aoSAbvcmepr5_nHgLbNB5QAAAoQ"]
[Tue Aug 18 12:55:26.971517 2026] [security2:error] [pid 67073:tid 67307] [client 4.232.151.198:42284] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "uniaoac.com.br"] [uri "/1.php"] [unique_id "aoSAbvcmepr5_nHgLbNB6AAAAno"]
[Tue Aug 18 12:55:26.971634 2026] [security2:error] [pid 67073:tid 67307] [client 4.232.151.198:42284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/1.php"] [unique_id "aoSAbvcmepr5_nHgLbNB6AAAAno"]
[Tue Aug 18 12:55:26.980956 2026] [security2:error] [pid 67073:tid 67226] [client 20.163.43.14:4321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/new.php"] [unique_id "aoSAbvcmepr5_nHgLbNB6wAAAik"]
[Tue Aug 18 12:55:26.989972 2026] [security2:error] [pid 66623:tid 66785] [client 74.248.130.103:15415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/ccc.php"] [unique_id "aoSAbtO5rbWdOArH04KENgAAAR0"]
[Tue Aug 18 12:55:26.989973 2026] [security2:error] [pid 67073:tid 67330] [client 20.91.215.254:13194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/input.php"] [unique_id "aoSAbvcmepr5_nHgLbNB7AAAApE"]
[Tue Aug 18 12:55:27.015941 2026] [security2:error] [pid 67073:tid 67327] [client 20.205.121.237:5065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/we.php"] [unique_id "aoSAb_cmepr5_nHgLbNB7QAAAo4"]
[Tue Aug 18 12:55:27.021697 2026] [security2:error] [pid 66623:tid 66851] [client 20.226.6.191:38236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAb9O5rbWdOArH04KENwAAAV8"]
[Tue Aug 18 12:55:27.064732 2026] [security2:error] [pid 66623:tid 66877] [client 172.182.200.96:13905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSAb9O5rbWdOArH04KEOAAAAXk"]
[Tue Aug 18 12:55:27.097628 2026] [security2:error] [pid 66623:tid 66773] [client 4.232.151.198:36128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/admin.php"] [unique_id "aoSAb9O5rbWdOArH04KEOQAAARE"]
[Tue Aug 18 12:55:27.098491 2026] [security2:error] [pid 66623:tid 66790] [client 20.65.69.59:3700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/evil.php"] [unique_id "aoSAb9O5rbWdOArH04KEOgAAASI"]
[Tue Aug 18 12:55:27.121155 2026] [security2:error] [pid 67073:tid 67216] [client 78.46.190.63:1296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "orientadoraespiritualbhsp.com.br"] [uri "/index.php"] [unique_id "aoSAbvcmepr5_nHgLbNB5wAAAh8"], referer: http://orientadoraespiritualbhsp.com.br/
[Tue Aug 18 12:55:27.135743 2026] [security2:error] [pid 67073:tid 67207] [client 20.104.100.201:58914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSAb_cmepr5_nHgLbNB7wAAAhY"]
[Tue Aug 18 12:55:27.137210 2026] [security2:error] [pid 67073:tid 67210] [client 20.171.51.14:59325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/vd.php"] [unique_id "aoSAb_cmepr5_nHgLbNB8AAAAhk"]
[Tue Aug 18 12:55:27.145328 2026] [security2:error] [pid 67073:tid 67254] [client 20.48.236.86:16268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/images.php"] [unique_id "aoSAb_cmepr5_nHgLbNB8QAAAkU"]
[Tue Aug 18 12:55:27.151145 2026] [security2:error] [pid 67073:tid 67258] [client 132.196.61.152:61054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/yj09.php"] [unique_id "aoSAb_cmepr5_nHgLbNB8wAAAkk"]
[Tue Aug 18 12:55:27.158958 2026] [security2:error] [pid 67073:tid 67255] [client 68.155.154.236:16338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/rymmm.php"] [unique_id "aoSAb_cmepr5_nHgLbNB9gAAAkY"]
[Tue Aug 18 12:55:27.159589 2026] [security2:error] [pid 67073:tid 67264] [client 20.42.19.40:9720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/atomlib.php"] [unique_id "aoSAb_cmepr5_nHgLbNB9wAAAk8"]
[Tue Aug 18 12:55:27.168500 2026] [security2:error] [pid 67073:tid 67231] [client 158.158.34.183:62789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/storage/rip.php"] [unique_id "aoSAb_cmepr5_nHgLbNB-AAAAi4"]
[Tue Aug 18 12:55:27.168956 2026] [security2:error] [pid 67073:tid 67276] [client 20.251.48.93:31792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/media.php"] [unique_id "aoSAb_cmepr5_nHgLbNB-QAAAls"]
[Tue Aug 18 12:55:27.176192 2026] [security2:error] [pid 67073:tid 67323] [client 20.116.17.175:57606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/black.php"] [unique_id "aoSAb_cmepr5_nHgLbNB-wAAAoo"]
[Tue Aug 18 12:55:27.179425 2026] [security2:error] [pid 67073:tid 67253] [client 135.225.75.187:20865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-admin/sc.php"] [unique_id "aoSAb_cmepr5_nHgLbNB_AAAAkQ"]
[Tue Aug 18 12:55:27.180254 2026] [security2:error] [pid 67073:tid 67110] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/mf.php"] [unique_id "aoSAb_cmepr5_nHgLbNB_QACOyI"]
[Tue Aug 18 12:55:27.185022 2026] [security2:error] [pid 67073:tid 67243] [client 74.248.136.165:9516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/sys.php"] [unique_id "aoSAb_cmepr5_nHgLbNB_gAAAjo"]
[Tue Aug 18 12:55:27.193211 2026] [security2:error] [pid 67073:tid 67304] [client 52.238.210.254:10176] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-admin/js/widgets/"] [unique_id "aoSAb_cmepr5_nHgLbNB_wAAAnc"]
[Tue Aug 18 12:55:27.198085 2026] [security2:error] [pid 67073:tid 67329] [client 20.51.153.15:9149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/68.php"] [unique_id "aoSAb_cmepr5_nHgLbNCAAAAApA"]
[Tue Aug 18 12:55:27.224797 2026] [security2:error] [pid 66623:tid 66846] [client 4.223.164.152:46187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSAb9O5rbWdOArH04KEPAAAAVo"]
[Tue Aug 18 12:55:27.243227 2026] [security2:error] [pid 67073:tid 67209] [client 5.31.227.224:7851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAb_cmepr5_nHgLbNCAgAAAhg"]
[Tue Aug 18 12:55:27.248137 2026] [security2:error] [pid 67073:tid 67209] [client 5.31.227.224:7851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAb_cmepr5_nHgLbNCAgAAAhg"]
[Tue Aug 18 12:55:27.259993 2026] [security2:error] [pid 66623:tid 66802] [client 20.100.169.31:31450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/htaccess.php"] [unique_id "aoSAb9O5rbWdOArH04KEPQAAAS4"]
[Tue Aug 18 12:55:27.262935 2026] [security2:error] [pid 67073:tid 67232] [client 20.100.169.31:33042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/inputs.php"] [unique_id "aoSAb_cmepr5_nHgLbNCBAAAAi8"]
[Tue Aug 18 12:55:27.283514 2026] [security2:error] [pid 67073:tid 67215] [client 20.65.98.162:52864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSAb_cmepr5_nHgLbNCBgAAAh4"]
[Tue Aug 18 12:55:27.327726 2026] [security2:error] [pid 67073:tid 67326] [client 20.151.109.219:59727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ns.php"] [unique_id "aoSAb_cmepr5_nHgLbNCBwAAAo0"]
[Tue Aug 18 12:55:27.345254 2026] [security2:error] [pid 67073:tid 67246] [client 157.51.166.53:57722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAb_cmepr5_nHgLbNCCgAAAj0"]
[Tue Aug 18 12:55:27.345459 2026] [security2:error] [pid 67073:tid 67246] [client 157.51.166.53:57722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAb_cmepr5_nHgLbNCCgAAAj0"]
[Tue Aug 18 12:55:27.368465 2026] [security2:error] [pid 67073:tid 67250] [client 47.128.22.69:32722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "terrassis.com.br"] [uri "/robots.txt"] [unique_id "aoSAb_cmepr5_nHgLbNCDQAAAkE"]
[Tue Aug 18 12:55:27.397853 2026] [security2:error] [pid 67073:tid 67286] [client 20.42.19.40:9649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/min.php"] [unique_id "aoSAb_cmepr5_nHgLbNCEQAAAmU"]
[Tue Aug 18 12:55:27.399911 2026] [security2:error] [pid 67073:tid 67308] [client 52.139.47.57:13537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/elementor/wp-login.php"] [unique_id "aoSAb_cmepr5_nHgLbNCEgAAAns"]
[Tue Aug 18 12:55:27.418063 2026] [security2:error] [pid 67073:tid 67180] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ie.php"] [unique_id "aoSAb_cmepr5_nHgLbNCEwACHWg"]
[Tue Aug 18 12:55:27.435751 2026] [security2:error] [pid 67073:tid 67233] [client 172.182.200.96:14306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSAb_cmepr5_nHgLbNCFQAAAjA"]
[Tue Aug 18 12:55:27.440498 2026] [security2:error] [pid 67073:tid 67234] [client 20.104.100.201:58474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/usr.php"] [unique_id "aoSAb_cmepr5_nHgLbNCFgAAAjE"]
[Tue Aug 18 12:55:27.442984 2026] [security2:error] [pid 67073:tid 67256] [client 20.100.169.31:12291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/2.php"] [unique_id "aoSAb_cmepr5_nHgLbNCFwAAAkc"]
[Tue Aug 18 12:55:27.473602 2026] [security2:error] [pid 66623:tid 66881] [client 20.163.43.14:4316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/222.php"] [unique_id "aoSAb9O5rbWdOArH04KEPwAAAX0"]
[Tue Aug 18 12:55:27.479340 2026] [security2:error] [pid 66623:tid 66819] [client 20.42.19.40:2723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-links-opml.php"] [unique_id "aoSAb9O5rbWdOArH04KEQAAAAT8"]
[Tue Aug 18 12:55:27.481400 2026] [security2:error] [pid 66623:tid 66867] [client 20.51.153.15:9111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/jl.php"] [unique_id "aoSAb9O5rbWdOArH04KEQQAAAW8"]
[Tue Aug 18 12:55:27.515342 2026] [security2:error] [pid 67073:tid 67223] [client 20.48.236.86:16336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/ops.php"] [unique_id "aoSAb_cmepr5_nHgLbNCGQAAAiY"]
[Tue Aug 18 12:55:27.531274 2026] [security2:error] [pid 67073:tid 67320] [client 20.163.43.14:4462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSAb_cmepr5_nHgLbNCHAAAAoc"]
[Tue Aug 18 12:55:27.602990 2026] [security2:error] [pid 66623:tid 66840] [client 74.248.136.165:17066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/pp.php"] [unique_id "aoSAb9O5rbWdOArH04KEQwAAAVQ"]
[Tue Aug 18 12:55:27.615946 2026] [security2:error] [pid 67073:tid 67279] [client 74.248.130.103:15371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/get.php"] [unique_id "aoSAb_cmepr5_nHgLbNCIAAAAl4"]
[Tue Aug 18 12:55:27.630396 2026] [security2:error] [pid 67073:tid 67263] [client 74.7.241.149:60512] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "brooklynmodamasculina.com.br"] [uri "/index.php"] [unique_id "aoSAbfcmepr5_nHgLbNBKAACTm0"]
[Tue Aug 18 12:55:27.650506 2026] [security2:error] [pid 67073:tid 67076] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/nw.php"] [unique_id "aoSAb_cmepr5_nHgLbNCIgACUgA"]
[Tue Aug 18 12:55:27.678150 2026] [security2:error] [pid 66623:tid 66832] [client 20.104.85.180:8040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAb9O5rbWdOArH04KERQAAAUw"]
[Tue Aug 18 12:55:27.698450 2026] [security2:error] [pid 66623:tid 66777] [client 20.42.19.40:9615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/mac.php"] [unique_id "aoSAb9O5rbWdOArH04KERwAAARU"]
[Tue Aug 18 12:55:27.700492 2026] [security2:error] [pid 67073:tid 67328] [client 78.46.190.63:1290] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "ancavisi.com.br"] [uri "/index.php"] [unique_id "aoSAbvcmepr5_nHgLbNBjwAAAo8"], referer: http://ancavisi.com.br/
[Tue Aug 18 12:55:27.716417 2026] [security2:error] [pid 67073:tid 67205] [client 20.51.153.15:9125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/tq.php"] [unique_id "aoSAb_cmepr5_nHgLbNCJQAAAhQ"]
[Tue Aug 18 12:55:27.721847 2026] [security2:error] [pid 67073:tid 67318] [client 78.46.190.63:57566] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "orientadoraespiritualbhsp.com.br"] [uri "/index.php"] [unique_id "aoSAb_cmepr5_nHgLbNCJAAAAoU"], referer: http://orientadoraespiritualbhsp.com.br/
[Tue Aug 18 12:55:27.741514 2026] [security2:error] [pid 67073:tid 67317] [client 20.91.215.254:12416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/jquery.php"] [unique_id "aoSAb_cmepr5_nHgLbNCJgAAAoQ"]
[Tue Aug 18 12:55:27.765103 2026] [security2:error] [pid 66623:tid 66859] [client 20.104.100.201:58490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSAb9O5rbWdOArH04KESAAAAWc"]
[Tue Aug 18 12:55:27.766732 2026] [security2:error] [pid 67073:tid 67255] [client 20.29.77.16:33001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/lmfi2.php"] [unique_id "aoSAb_cmepr5_nHgLbNCJwAAAkY"]
[Tue Aug 18 12:55:27.776744 2026] [security2:error] [pid 67073:tid 67231] [client 52.238.210.254:8832] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-admin/maint/"] [unique_id "aoSAb_cmepr5_nHgLbNCKQAAAi4"]
[Tue Aug 18 12:55:27.783978 2026] [security2:error] [pid 66623:tid 66841] [client 172.182.200.96:13915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSAb9O5rbWdOArH04KESQAAAVU"]
[Tue Aug 18 12:55:27.843242 2026] [security2:error] [pid 66623:tid 66811] [client 4.223.164.152:54245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/system_log.php"] [unique_id "aoSAb9O5rbWdOArH04KESgAAATc"]
[Tue Aug 18 12:55:27.855420 2026] [security2:error] [pid 67073:tid 67195] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/sb.php"] [unique_id "aoSAb_cmepr5_nHgLbNCLAACkHc"]
[Tue Aug 18 12:55:27.883960 2026] [security2:error] [pid 66623:tid 66860] [client 20.100.169.31:3016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/images/wso.php"] [unique_id "aoSAb9O5rbWdOArH04KEUQAAAWg"]
[Tue Aug 18 12:55:27.888437 2026] [security2:error] [pid 67073:tid 67209] [client 20.163.43.14:4225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/chosen.php"] [unique_id "aoSAb_cmepr5_nHgLbNCMQAAAhg"]
[Tue Aug 18 12:55:27.888620 2026] [authz_core:error] [pid 67073:tid 67200] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:27.888805 2026] [security2:error] [pid 66623:tid 66865] [client 20.151.109.219:53212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gk.php"] [unique_id "aoSAb9O5rbWdOArH04KEUgAAAW0"]
[Tue Aug 18 12:55:27.888881 2026] [authz_core:error] [pid 67073:tid 67200] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:27.914933 2026] [security2:error] [pid 66623:tid 66795] [client 20.226.7.189:10711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/vv.php"] [unique_id "aoSAb9O5rbWdOArH04KEVAAAASc"]
[Tue Aug 18 12:55:27.933804 2026] [security2:error] [pid 67073:tid 67281] [client 20.163.43.14:4467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/about.php"] [unique_id "aoSAb_cmepr5_nHgLbNCMgAAAmA"]
[Tue Aug 18 12:55:27.934438 2026] [security2:error] [pid 67073:tid 67292] [client 20.116.17.175:57414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/as.php"] [unique_id "aoSAb_cmepr5_nHgLbNCMwAAAms"]
[Tue Aug 18 12:55:27.943085 2026] [security2:error] [pid 66623:tid 66784] [client 20.42.19.40:9604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/nc4.php"] [unique_id "aoSAb9O5rbWdOArH04KEVQAAARw"]
[Tue Aug 18 12:55:27.944546 2026] [security2:error] [pid 67073:tid 67218] [client 20.226.7.189:9732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/V5.php"] [unique_id "aoSAb_cmepr5_nHgLbNCNQAAAiE"]
[Tue Aug 18 12:55:27.949700 2026] [authz_core:error] [pid 67073:tid 67201] [remote 57.141.22.35:43122] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:27.950058 2026] [authz_core:error] [pid 67073:tid 67201] [remote 57.141.22.35:43122] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:27.967860 2026] [security2:error] [pid 66623:tid 66813] [client 20.226.7.189:22756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-user.php"] [unique_id "aoSAb9O5rbWdOArH04KEVgAAATk"]
[Tue Aug 18 12:55:27.983790 2026] [security2:error] [pid 67073:tid 67248] [client 20.51.153.15:9089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/cv.php"] [unique_id "aoSAb_cmepr5_nHgLbNCOAAAAj8"]
[Tue Aug 18 12:55:27.988050 2026] [security2:error] [pid 66623:tid 66893] [client 20.48.236.86:16320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/coffexium.php"] [unique_id "aoSAb9O5rbWdOArH04KEVwAAAYk"]
[Tue Aug 18 12:55:27.989478 2026] [security2:error] [pid 67073:tid 67262] [client 20.226.7.189:19158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-blog.php"] [unique_id "aoSAb_cmepr5_nHgLbNCOQAAAk0"]
[Tue Aug 18 12:55:27.996057 2026] [autoindex:error] [pid 67073:tid 67332] [client 20.104.85.180:7983] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/images/smilies/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:28.014411 2026] [security2:error] [pid 66623:tid 66804] [client 20.226.7.189:22773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp.php"] [unique_id "aoSAcNO5rbWdOArH04KEWAAAATA"]
[Tue Aug 18 12:55:28.019929 2026] [security2:error] [pid 66623:tid 66768] [client 74.248.136.165:29064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wqqs.php"] [unique_id "aoSAcNO5rbWdOArH04KEWQAAAQw"]
[Tue Aug 18 12:55:28.036561 2026] [security2:error] [pid 67073:tid 67246] [client 20.226.7.189:19158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/worksec.php"] [unique_id "aoSAcPcmepr5_nHgLbNCOwAAAj0"]
[Tue Aug 18 12:55:28.040386 2026] [security2:error] [pid 66623:tid 66833] [client 20.104.100.201:58910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/css/database.php"] [unique_id "aoSAcNO5rbWdOArH04KEWgAAAU0"]
[Tue Aug 18 12:55:28.051578 2026] [security2:error] [pid 67073:tid 67258] [client 20.205.121.237:5061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wk/index.php"] [unique_id "aoSAcPcmepr5_nHgLbNCPAAAAkk"]
[Tue Aug 18 12:55:28.058376 2026] [security2:error] [pid 66623:tid 66876] [client 20.226.7.189:22780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-themes.php"] [unique_id "aoSAcNO5rbWdOArH04KEWwAAAXg"]
[Tue Aug 18 12:55:28.062133 2026] [security2:error] [pid 66623:tid 66823] [client 20.65.69.59:57030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/wp-key.php"] [unique_id "aoSAcNO5rbWdOArH04KEXAAAAUM"]
[Tue Aug 18 12:55:28.064462 2026] [security2:error] [pid 67073:tid 67293] [client 20.226.6.191:39384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/admin.php"] [unique_id "aoSAcPcmepr5_nHgLbNCPgAAAmw"]
[Tue Aug 18 12:55:28.071353 2026] [security2:error] [pid 67073:tid 67155] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/xj.php"] [unique_id "aoSAcPcmepr5_nHgLbNCPwACQU8"]
[Tue Aug 18 12:55:28.075882 2026] [security2:error] [pid 66623:tid 66861] [client 20.251.48.93:14415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/images.php"] [unique_id "aoSAcNO5rbWdOArH04KEXQAAAWk"]
[Tue Aug 18 12:55:28.077101 2026] [security2:error] [pid 67073:tid 67247] [client 20.226.7.189:9740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-signin.php"] [unique_id "aoSAcPcmepr5_nHgLbNCQAAAAj4"]
[Tue Aug 18 12:55:28.081187 2026] [security2:error] [pid 66623:tid 66845] [client 68.155.154.236:16328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/lddxs.php"] [unique_id "aoSAcNO5rbWdOArH04KEXgAAAVk"]
[Tue Aug 18 12:55:28.094587 2026] [security2:error] [pid 67073:tid 67295] [client 132.196.61.152:60320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/scxy.php"] [unique_id "aoSAcPcmepr5_nHgLbNCQQAAAm4"]
[Tue Aug 18 12:55:28.100365 2026] [security2:error] [pid 67073:tid 67228] [client 20.226.7.189:38627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSAcPcmepr5_nHgLbNCQgAAAis"]
[Tue Aug 18 12:55:28.138965 2026] [security2:error] [pid 66623:tid 66772] [client 52.173.121.69:16474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSAcNO5rbWdOArH04KEXwAAARA"]
[Tue Aug 18 12:55:28.149448 2026] [security2:error] [pid 66623:tid 66809] [client 172.182.200.96:14309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSAcNO5rbWdOArH04KEYAAAATU"]
[Tue Aug 18 12:55:28.154106 2026] [security2:error] [pid 66623:tid 66810] [client 135.225.75.187:21879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp5.php"] [unique_id "aoSAcNO5rbWdOArH04KEYQAAATY"]
[Tue Aug 18 12:55:28.167659 2026] [security2:error] [pid 66623:tid 66780] [client 20.171.51.14:43343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/56.php"] [unique_id "aoSAcNO5rbWdOArH04KEYgAAARg"]
[Tue Aug 18 12:55:28.178051 2026] [security2:error] [pid 67073:tid 67241] [client 20.42.19.40:9630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/as.php"] [unique_id "aoSAcPcmepr5_nHgLbNCRgAAAjg"]
[Tue Aug 18 12:55:28.195688 2026] [security2:error] [pid 66623:tid 66835] [client 20.171.51.14:59308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/an.php"] [unique_id "aoSAcNO5rbWdOArH04KEYwAAAU8"]
[Tue Aug 18 12:55:28.276007 2026] [security2:error] [pid 67073:tid 67233] [client 20.104.85.180:7983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSAcPcmepr5_nHgLbNCSQAAAjA"]
[Tue Aug 18 12:55:28.291082 2026] [security2:error] [pid 67073:tid 67106] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ns.php"] [unique_id "aoSAcPcmepr5_nHgLbNCSgACMR4"]
[Tue Aug 18 12:55:28.292166 2026] [security2:error] [pid 67073:tid 67256] [client 4.223.164.152:64702] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-admin/css/"] [unique_id "aoSAcPcmepr5_nHgLbNCSwAAAkc"]
[Tue Aug 18 12:55:28.305401 2026] [security2:error] [pid 67073:tid 67316] [client 74.248.130.103:36810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/images.php"] [unique_id "aoSAcPcmepr5_nHgLbNCTAAAAoM"]
[Tue Aug 18 12:55:28.310092 2026] [security2:error] [pid 67073:tid 67257] [client 20.48.236.86:16293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAcPcmepr5_nHgLbNCTQAAAkg"]
[Tue Aug 18 12:55:28.312259 2026] [security2:error] [pid 67073:tid 67285] [client 20.104.100.201:21496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/privdayz.php"] [unique_id "aoSAcPcmepr5_nHgLbNCTgAAAmQ"]
[Tue Aug 18 12:55:28.319403 2026] [security2:error] [pid 66623:tid 66869] [client 20.151.109.219:24846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/wn.php"] [unique_id "aoSAcNO5rbWdOArH04KEagAAAXE"]
[Tue Aug 18 12:55:28.326645 2026] [security2:error] [pid 66623:tid 66889] [client 20.163.43.14:4416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSAcNO5rbWdOArH04KEawAAAYU"]
[Tue Aug 18 12:55:28.331631 2026] [security2:error] [pid 66623:tid 66782] [client 20.163.43.14:4266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/info.php"] [unique_id "aoSAcNO5rbWdOArH04KEbAAAARo"]
[Tue Aug 18 12:55:28.346820 2026] [security2:error] [pid 67073:tid 67302] [client 172.202.39.151:63104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/13.php"] [unique_id "aoSAcPcmepr5_nHgLbNCUAAAAnU"]
[Tue Aug 18 12:55:28.365727 2026] [security2:error] [pid 66623:tid 66882] [client 20.51.153.15:8774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/un.php"] [unique_id "aoSAcNO5rbWdOArH04KEdAAAAX4"]
[Tue Aug 18 12:55:28.374913 2026] [security2:error] [pid 67073:tid 67223] [client 20.226.7.189:9620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/ws.php"] [unique_id "aoSAcPcmepr5_nHgLbNCUQAAAiY"]
[Tue Aug 18 12:55:28.394310 2026] [security2:error] [pid 66623:tid 66891] [client 20.100.169.31:39458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSAcNO5rbWdOArH04KEdQAAAYc"]
[Tue Aug 18 12:55:28.399002 2026] [security2:error] [pid 66623:tid 66815] [client 20.226.7.189:11291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wsa.php"] [unique_id "aoSAcNO5rbWdOArH04KEdgAAATs"]
[Tue Aug 18 12:55:28.400211 2026] [security2:error] [pid 67073:tid 67299] [client 74.248.18.37:40040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/NewFile.php"] [unique_id "aoSAcPcmepr5_nHgLbNCUgAAAnI"]
[Tue Aug 18 12:55:28.416273 2026] [security2:error] [pid 66623:tid 66827] [client 20.42.19.40:9650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/k.php"] [unique_id "aoSAcNO5rbWdOArH04KEdwAAAUc"]
[Tue Aug 18 12:55:28.417857 2026] [security2:error] [pid 66623:tid 66814] [client 20.226.7.189:19179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/w.php"] [unique_id "aoSAcNO5rbWdOArH04KEeAAAATo"]
[Tue Aug 18 12:55:28.422591 2026] [security2:error] [pid 66623:tid 66844] [client 78.46.190.63:57568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ancavisi.com.br"] [uri "/index.php"] [unique_id "aoSAcNO5rbWdOArH04KEZgAAAVg"], referer: http://ancavisi.com.br/
[Tue Aug 18 12:55:28.437992 2026] [security2:error] [pid 66623:tid 66871] [client 20.226.7.189:10694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/x.php"] [unique_id "aoSAcNO5rbWdOArH04KEegAAAXM"]
[Tue Aug 18 12:55:28.438006 2026] [security2:error] [pid 66623:tid 66778] [client 74.248.136.165:43659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/clasa99.php"] [unique_id "aoSAcNO5rbWdOArH04KEewAAARY"]
[Tue Aug 18 12:55:28.465398 2026] [security2:error] [pid 67073:tid 67330] [client 20.226.7.189:10694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/xx.php"] [unique_id "aoSAcPcmepr5_nHgLbNCVgAAApE"]
[Tue Aug 18 12:55:28.468424 2026] [security2:error] [pid 66623:tid 66806] [client 20.91.215.254:13214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/media-new.php"] [unique_id "aoSAcNO5rbWdOArH04KEfAAAATI"]
[Tue Aug 18 12:55:28.477057 2026] [security2:error] [pid 67073:tid 67271] [client 114.5.214.109:49803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAcPcmepr5_nHgLbNCVwAAAlY"]
[Tue Aug 18 12:55:28.477166 2026] [security2:error] [pid 67073:tid 67271] [client 114.5.214.109:49803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAcPcmepr5_nHgLbNCVwAAAlY"]
[Tue Aug 18 12:55:28.490040 2026] [security2:error] [pid 67073:tid 67280] [client 20.226.7.189:10707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAcPcmepr5_nHgLbNCWAAAAl8"]
[Tue Aug 18 12:55:28.511728 2026] [security2:error] [pid 67073:tid 67267] [client 20.226.7.189:11284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/y.php"] [unique_id "aoSAcPcmepr5_nHgLbNCWgAAAlI"]
[Tue Aug 18 12:55:28.514106 2026] [security2:error] [pid 67073:tid 67306] [client 213.202.253.4:63334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/userfuns.php"] [unique_id "aoSAcPcmepr5_nHgLbNCWwAAAnk"], referer: www.google.com
[Tue Aug 18 12:55:28.516986 2026] [security2:error] [pid 67073:tid 67118] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gk.php"] [unique_id "aoSAcPcmepr5_nHgLbNCXAACHyo"]
[Tue Aug 18 12:55:28.522048 2026] [security2:error] [pid 66623:tid 66767] [client 20.100.169.31:31469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/index/function.php"] [unique_id "aoSAcNO5rbWdOArH04KEfQAAAQs"]
[Tue Aug 18 12:55:28.530799 2026] [security2:error] [pid 67073:tid 67207] [client 52.238.210.254:8913] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-admin/"] [unique_id "aoSAcPcmepr5_nHgLbNCXQAAAhY"]
[Tue Aug 18 12:55:28.569896 2026] [security2:error] [pid 66623:tid 66837] [client 52.139.47.57:16683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/goat1.php"] [unique_id "aoSAcNO5rbWdOArH04KEfgAAAVE"]
[Tue Aug 18 12:55:28.575130 2026] [security2:error] [pid 66623:tid 66888] [client 158.158.34.183:47507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/.__info.php"] [unique_id "aoSAcNO5rbWdOArH04KEfwAAAYQ"]
[Tue Aug 18 12:55:28.577991 2026] [security2:error] [pid 67073:tid 67290] [client 20.104.85.180:7979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/an.php"] [unique_id "aoSAcPcmepr5_nHgLbNCXwAAAmk"]
[Tue Aug 18 12:55:28.585918 2026] [security2:error] [pid 67073:tid 67235] [client 172.182.200.96:13927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSAcPcmepr5_nHgLbNCYAAAAjI"]
[Tue Aug 18 12:55:28.588537 2026] [security2:error] [pid 67073:tid 67328] [client 20.104.100.201:58459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wg459o.php"] [unique_id "aoSAcPcmepr5_nHgLbNCYQAAAo8"]
[Tue Aug 18 12:55:28.598618 2026] [security2:error] [pid 67073:tid 67259] [client 20.51.153.15:9103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/evil.php"] [unique_id "aoSAcPcmepr5_nHgLbNCYwAAAko"]
[Tue Aug 18 12:55:28.630380 2026] [security2:error] [pid 66623:tid 66792] [client 20.65.98.162:60292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAcNO5rbWdOArH04KEgAAAASQ"]
[Tue Aug 18 12:55:28.640522 2026] [security2:error] [pid 67073:tid 67232] [client 20.100.169.31:28134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/admin.php"] [unique_id "aoSAcPcmepr5_nHgLbNCZQAAAi8"]
[Tue Aug 18 12:55:28.653815 2026] [security2:error] [pid 66623:tid 66846] [client 20.42.19.40:9624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSAcNO5rbWdOArH04KEgQAAAVo"]
[Tue Aug 18 12:55:28.668932 2026] [security2:error] [pid 67073:tid 67255] [client 20.151.109.219:59745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/app.php"] [unique_id "aoSAcPcmepr5_nHgLbNCZgAAAkY"]
[Tue Aug 18 12:55:28.724500 2026] [security2:error] [pid 67073:tid 67236] [client 20.48.236.86:16289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/sf.php"] [unique_id "aoSAcPcmepr5_nHgLbNCaQAAAjM"]
[Tue Aug 18 12:55:28.728729 2026] [security2:error] [pid 66623:tid 66836] [client 4.232.151.198:36721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/alfa.php"] [unique_id "aoSAcNO5rbWdOArH04KEgwAAAVA"]
[Tue Aug 18 12:55:28.736437 2026] [security2:error] [pid 67073:tid 67251] [client 4.223.164.152:28536] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-admin/css/colors/modern/"] [unique_id "aoSAcPcmepr5_nHgLbNCawAAAkI"]
[Tue Aug 18 12:55:28.749397 2026] [security2:error] [pid 66623:tid 66890] [client 20.29.77.16:47758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/info2.php"] [unique_id "aoSAcNO5rbWdOArH04KEhAAAAYY"]
[Tue Aug 18 12:55:28.749536 2026] [security2:error] [pid 67073:tid 67270] [client 52.173.121.69:24815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSAcPcmepr5_nHgLbNCbQAAAlU"]
[Tue Aug 18 12:55:28.750556 2026] [security2:error] [pid 67073:tid 67210] [client 20.91.215.254:20727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/import.php"] [unique_id "aoSAcPcmepr5_nHgLbNCbgAAAhk"]
[Tue Aug 18 12:55:28.773903 2026] [security2:error] [pid 67073:tid 67189] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/wn.php"] [unique_id "aoSAcPcmepr5_nHgLbNCcAACHnE"]
[Tue Aug 18 12:55:28.794109 2026] [security2:error] [pid 67073:tid 67292] [client 20.42.19.40:2707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/.alf.php"] [unique_id "aoSAcPcmepr5_nHgLbNCcgAAAms"]
[Tue Aug 18 12:55:28.834197 2026] [security2:error] [pid 67073:tid 67287] [client 135.225.75.187:21838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/a2.php"] [unique_id "aoSAcPcmepr5_nHgLbNCdAAAAmY"]
[Tue Aug 18 12:55:28.855617 2026] [security2:error] [pid 67073:tid 67237] [client 74.248.136.165:43655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/666.php"] [unique_id "aoSAcPcmepr5_nHgLbNCdQAAAjQ"]
[Tue Aug 18 12:55:28.866073 2026] [security2:error] [pid 67073:tid 67262] [client 20.104.100.201:58436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/mifta.php"] [unique_id "aoSAcPcmepr5_nHgLbNCdgAAAk0"]
[Tue Aug 18 12:55:28.867842 2026] [security2:error] [pid 66623:tid 66881] [client 20.163.43.14:4242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAcNO5rbWdOArH04KEhQAAAX0"]
[Tue Aug 18 12:55:28.882550 2026] [security2:error] [pid 67073:tid 67332] [client 68.155.154.236:16370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/zjggu.php"] [unique_id "aoSAcPcmepr5_nHgLbNCegAAApM"]
[Tue Aug 18 12:55:28.888419 2026] [security2:error] [pid 67073:tid 67266] [client 20.116.17.175:57432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/pucci.php"] [unique_id "aoSAcPcmepr5_nHgLbNCewAAAlE"]
[Tue Aug 18 12:55:28.890726 2026] [security2:error] [pid 66623:tid 66794] [client 4.232.151.198:49839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/goods.php"] [unique_id "aoSAcNO5rbWdOArH04KEhgAAASY"]
[Tue Aug 18 12:55:28.906324 2026] [security2:error] [pid 67073:tid 67258] [client 20.163.43.14:4359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/f35.php"] [unique_id "aoSAcPcmepr5_nHgLbNCfAAAAkk"]
[Tue Aug 18 12:55:28.906957 2026] [security2:error] [pid 67073:tid 67293] [client 20.42.19.40:9621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/system_log.php"] [unique_id "aoSAcPcmepr5_nHgLbNCfQAAAmw"]
[Tue Aug 18 12:55:28.910318 2026] [security2:error] [pid 67073:tid 67250] [client 20.51.153.15:9144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/pw.php"] [unique_id "aoSAcPcmepr5_nHgLbNCfwAAAkE"]
[Tue Aug 18 12:55:28.923557 2026] [autoindex:error] [pid 67073:tid 67303] [client 20.104.85.180:8002] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:28.973731 2026] [security2:error] [pid 67073:tid 67331] [client 172.182.200.96:14243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSAcPcmepr5_nHgLbNCgAAAApI"]
[Tue Aug 18 12:55:28.974407 2026] [security2:error] [pid 67073:tid 67193] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/app.php"] [unique_id "aoSAcPcmepr5_nHgLbNCgQACGnU"]
[Tue Aug 18 12:55:28.995747 2026] [security2:error] [pid 67073:tid 67230] [client 74.248.130.103:15384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/alls.php"] [unique_id "aoSAcPcmepr5_nHgLbNCggAAAi0"]
[Tue Aug 18 12:55:29.011918 2026] [security2:error] [pid 67073:tid 67308] [client 20.171.51.14:59292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/rx.php"] [unique_id "aoSAcfcmepr5_nHgLbNChAAAAns"]
[Tue Aug 18 12:55:29.038174 2026] [security2:error] [pid 67073:tid 67214] [client 20.151.109.219:53218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/87.php"] [unique_id "aoSAcfcmepr5_nHgLbNChgAAAh0"]
[Tue Aug 18 12:55:29.140599 2026] [security2:error] [pid 67073:tid 67242] [client 213.35.127.232:58826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAcfcmepr5_nHgLbNCiwAAAjk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:29.142173 2026] [security2:error] [pid 67073:tid 67285] [client 20.104.100.201:58923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSAcfcmepr5_nHgLbNCjAAAAmQ"]
[Tue Aug 18 12:55:29.144569 2026] [security2:error] [pid 67073:tid 67213] [client 20.42.19.40:9637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/x.php"] [unique_id "aoSAcfcmepr5_nHgLbNCjQAAAhw"]
[Tue Aug 18 12:55:29.148106 2026] [security2:error] [pid 67073:tid 67247] [client 20.100.169.31:31440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/info.php"] [unique_id "aoSAcfcmepr5_nHgLbNCjwAAAj4"]
[Tue Aug 18 12:55:29.166037 2026] [security2:error] [pid 66623:tid 66817] [client 20.51.153.15:9126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/fn.php"] [unique_id "aoSAcdO5rbWdOArH04KEiQAAAT0"]
[Tue Aug 18 12:55:29.175317 2026] [security2:error] [pid 67073:tid 67314] [client 74.248.133.44:18407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/elp.php"] [unique_id "aoSAcfcmepr5_nHgLbNCkAAAAoE"]
[Tue Aug 18 12:55:29.198340 2026] [security2:error] [pid 67073:tid 67299] [client 20.104.85.180:8002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/404.php"] [unique_id "aoSAcfcmepr5_nHgLbNCkgAAAnI"]
[Tue Aug 18 12:55:29.234728 2026] [security2:error] [pid 67073:tid 67315] [client 20.163.43.14:4255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSAcfcmepr5_nHgLbNClQAAAoI"]
[Tue Aug 18 12:55:29.244096 2026] [security2:error] [pid 67073:tid 67222] [client 20.48.236.86:16325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/k.php"] [unique_id "aoSAcfcmepr5_nHgLbNClgAAAiU"]
[Tue Aug 18 12:55:29.265451 2026] [security2:error] [pid 67073:tid 67275] [client 4.223.164.152:54249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/pucci.php"] [unique_id "aoSAcfcmepr5_nHgLbNClwAAAlo"]
[Tue Aug 18 12:55:29.274414 2026] [security2:error] [pid 67073:tid 67263] [client 74.248.136.165:9527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/thui.php"] [unique_id "aoSAcfcmepr5_nHgLbNCmAAAAk4"]
[Tue Aug 18 12:55:29.275056 2026] [security2:error] [pid 67073:tid 67151] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/87.php"] [unique_id "aoSAcfcmepr5_nHgLbNCmQACfEs"]
[Tue Aug 18 12:55:29.278227 2026] [security2:error] [pid 67073:tid 67234] [client 20.91.215.254:13199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSAcfcmepr5_nHgLbNCmgAAAjE"]
[Tue Aug 18 12:55:29.362085 2026] [security2:error] [pid 67073:tid 67235] [client 172.182.200.96:13891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSAcfcmepr5_nHgLbNCnQAAAjI"]
[Tue Aug 18 12:55:29.383138 2026] [security2:error] [pid 67073:tid 67305] [client 20.42.19.40:9638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/autoload_classmap.php"] [unique_id "aoSAcfcmepr5_nHgLbNCnwAAAng"]
[Tue Aug 18 12:55:29.403027 2026] [security2:error] [pid 67073:tid 67244] [client 20.151.109.219:59712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/zi.php"] [unique_id "aoSAcfcmepr5_nHgLbNCogAAAjs"]
[Tue Aug 18 12:55:29.414035 2026] [security2:error] [pid 67073:tid 67279] [client 52.139.47.57:16654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/google-seo-rank/module.php"] [unique_id "aoSAcfcmepr5_nHgLbNCowAAAl4"]
[Tue Aug 18 12:55:29.422964 2026] [security2:error] [pid 66623:tid 66777] [client 20.104.100.201:58465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/index2.php"] [unique_id "aoSAcdO5rbWdOArH04KEiwAAARU"]
[Tue Aug 18 12:55:29.434057 2026] [security2:error] [pid 67073:tid 67251] [client 20.171.51.14:15024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/sy.php"] [unique_id "aoSAcfcmepr5_nHgLbNCpAAAAkI"]
[Tue Aug 18 12:55:29.435754 2026] [security2:error] [pid 67073:tid 67270] [client 20.226.6.191:64115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/public/css.php"] [unique_id "aoSAcfcmepr5_nHgLbNCpgAAAlU"]
[Tue Aug 18 12:55:29.437315 2026] [security2:error] [pid 67073:tid 67210] [client 20.205.121.237:4097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/worksec.php"] [unique_id "aoSAcfcmepr5_nHgLbNCpwAAAhk"]
[Tue Aug 18 12:55:29.442848 2026] [security2:error] [pid 67073:tid 67209] [client 52.238.210.254:10163] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/themes/"] [unique_id "aoSAcfcmepr5_nHgLbNCqQAAAhg"]
[Tue Aug 18 12:55:29.442863 2026] [security2:error] [pid 67073:tid 67322] [client 20.91.215.254:27415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/cropper.php"] [unique_id "aoSAcfcmepr5_nHgLbNCqAAAAok"]
[Tue Aug 18 12:55:29.449017 2026] [security2:error] [pid 67073:tid 67231] [client 20.65.98.162:15512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/bless6.php"] [unique_id "aoSAcfcmepr5_nHgLbNCqwAAAi4"]
[Tue Aug 18 12:55:29.460466 2026] [security2:error] [pid 67073:tid 67215] [client 20.251.48.93:9771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/mac.php"] [unique_id "aoSAcfcmepr5_nHgLbNCrAAAAh4"]
[Tue Aug 18 12:55:29.461633 2026] [security2:error] [pid 66623:tid 66859] [client 20.51.153.15:8753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/kf.php"] [unique_id "aoSAcdO5rbWdOArH04KEjAAAAWc"]
[Tue Aug 18 12:55:29.507163 2026] [security2:error] [pid 67073:tid 67224] [client 20.104.85.180:7974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-login.php"] [unique_id "aoSAcfcmepr5_nHgLbNCrgAAAic"]
[Tue Aug 18 12:55:29.544460 2026] [security2:error] [pid 67073:tid 67208] [client 68.155.154.236:16321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/dlvqo.php"] [unique_id "aoSAcfcmepr5_nHgLbNCsQAAAhc"]
[Tue Aug 18 12:55:29.545787 2026] [security2:error] [pid 67073:tid 67102] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/zi.php"] [unique_id "aoSAcfcmepr5_nHgLbNCsgACSRo"]
[Tue Aug 18 12:55:29.561175 2026] [security2:error] [pid 67073:tid 67239] [client 20.163.43.14:4311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/k.php"] [unique_id "aoSAcfcmepr5_nHgLbNCswAAAjY"]
[Tue Aug 18 12:55:29.566628 2026] [security2:error] [pid 67073:tid 67313] [client 20.48.236.86:16277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/82.php"] [unique_id "aoSAcfcmepr5_nHgLbNCtAAAAoA"]
[Tue Aug 18 12:55:29.592359 2026] [security2:error] [pid 67073:tid 67295] [client 20.226.6.191:6569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSAcfcmepr5_nHgLbNCtgAAAm4"]
[Tue Aug 18 12:55:29.610473 2026] [security2:error] [pid 67073:tid 67211] [client 20.163.43.14:4418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/inputs.php"] [unique_id "aoSAcfcmepr5_nHgLbNCtwAAAho"]
[Tue Aug 18 12:55:29.621009 2026] [security2:error] [pid 67073:tid 67228] [client 20.42.19.40:9602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/hosty.php"] [unique_id "aoSAcfcmepr5_nHgLbNCuAAAAis"]
[Tue Aug 18 12:55:29.622911 2026] [security2:error] [pid 67073:tid 67230] [client 20.29.77.16:52736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/test_info.php"] [unique_id "aoSAcfcmepr5_nHgLbNCuQAAAi0"]
[Tue Aug 18 12:55:29.679701 2026] [security2:error] [pid 67073:tid 67321] [client 52.173.121.69:17942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSAcfcmepr5_nHgLbNCuwAAAog"]
[Tue Aug 18 12:55:29.692621 2026] [security2:error] [pid 67073:tid 67310] [client 74.248.136.165:9932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/agg.php"] [unique_id "aoSAcfcmepr5_nHgLbNCvQAAAn0"]
[Tue Aug 18 12:55:29.697040 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:29.697300 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:29.697696 2026] [security2:error] [pid 67073:tid 67256] [client 20.104.100.201:58460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/8.php"] [unique_id "aoSAcfcmepr5_nHgLbNCvgAAAkc"]
[Tue Aug 18 12:55:29.698707 2026] [security2:error] [pid 66623:tid 66811] [client 172.182.200.96:13838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSAcdO5rbWdOArH04KEjgAAATc"]
[Tue Aug 18 12:55:29.709325 2026] [security2:error] [pid 66623:tid 66789] [client 20.51.153.15:9213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/su.php"] [unique_id "aoSAcdO5rbWdOArH04KEjwAAASE"]
[Tue Aug 18 12:55:29.714784 2026] [security2:error] [pid 67073:tid 67329] [client 74.248.130.103:36855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/coffexium.php"] [unique_id "aoSAcfcmepr5_nHgLbNCvwAAApA"]
[Tue Aug 18 12:55:29.717504 2026] [security2:error] [pid 67073:tid 67282] [client 103.120.71.157:64962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAcfcmepr5_nHgLbNCwAAAAmE"]
[Tue Aug 18 12:55:29.717605 2026] [security2:error] [pid 67073:tid 67282] [client 103.120.71.157:64962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAcfcmepr5_nHgLbNCwAAAAmE"]
[Tue Aug 18 12:55:29.722164 2026] [security2:error] [pid 67073:tid 67257] [client 4.223.164.152:64681] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/blocks/details/"] [unique_id "aoSAcfcmepr5_nHgLbNCwQAAAkg"]
[Tue Aug 18 12:55:29.722855 2026] [security2:error] [pid 67073:tid 67300] [client 52.87.72.16:39912] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.autocred360.com.br"] [uri "/index.php"] [unique_id "aoSAcPcmepr5_nHgLbNCdwAAAnM"], referer: https://www.autocred360.com.br
[Tue Aug 18 12:55:29.771874 2026] [security2:error] [pid 67073:tid 67278] [client 20.100.169.31:31457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/profile.php"] [unique_id "aoSAcfcmepr5_nHgLbNCxQAAAl0"]
[Tue Aug 18 12:55:29.792469 2026] [security2:error] [pid 67073:tid 67149] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/92.php"] [unique_id "aoSAcfcmepr5_nHgLbNCyAACekk"]
[Tue Aug 18 12:55:29.833418 2026] [security2:error] [pid 67073:tid 67279] [client 20.151.109.219:24871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/92.php"] [unique_id "aoSAcfcmepr5_nHgLbNCzgAAAl4"]
[Tue Aug 18 12:55:29.856354 2026] [security2:error] [pid 66623:tid 66791] [client 20.104.85.180:8058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAcdO5rbWdOArH04KEkQAAASM"]
[Tue Aug 18 12:55:29.883982 2026] [security2:error] [pid 67073:tid 67311] [client 196.12.128.158:62172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAcfcmepr5_nHgLbNC1QAAAn4"]
[Tue Aug 18 12:55:29.884112 2026] [security2:error] [pid 67073:tid 67311] [client 196.12.128.158:62172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAcfcmepr5_nHgLbNC1QAAAn4"]
[Tue Aug 18 12:55:29.889120 2026] [security2:error] [pid 67073:tid 67227] [client 20.42.19.40:9671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/test1.php"] [unique_id "aoSAcfcmepr5_nHgLbNC1gAAAio"]
[Tue Aug 18 12:55:29.901487 2026] [security2:error] [pid 67073:tid 67327] [client 20.171.51.14:29194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/mandrill.php"] [unique_id "aoSAcfcmepr5_nHgLbNC1wAAAo4"]
[Tue Aug 18 12:55:29.966183 2026] [security2:error] [pid 67073:tid 67213] [client 20.91.215.254:12600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSAcfcmepr5_nHgLbNC3gAAAhw"]
[Tue Aug 18 12:55:29.969132 2026] [security2:error] [pid 67073:tid 67293] [client 20.104.100.201:21381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/images.php"] [unique_id "aoSAcfcmepr5_nHgLbNC3wAAAmw"]
[Tue Aug 18 12:55:29.981685 2026] [security2:error] [pid 67073:tid 67167] [remote 111.225.148.38:20390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gustavofrison.com.br"] [uri "/wp-content/uploads/2016/10/instagram.png"] [unique_id "aoSAcfcmepr5_nHgLbNC4QACdls"]
[Tue Aug 18 12:55:29.986511 2026] [security2:error] [pid 67073:tid 67259] [client 4.232.151.198:27365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/file.php"] [unique_id "aoSAcfcmepr5_nHgLbNC4gAAAko"]
[Tue Aug 18 12:55:29.989788 2026] [security2:error] [pid 67073:tid 67080] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/jm.php"] [unique_id "aoSAcfcmepr5_nHgLbNC4wACgAQ"]
[Tue Aug 18 12:55:30.000709 2026] [authz_core:error] [pid 67073:tid 67084] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:30.001156 2026] [authz_core:error] [pid 67073:tid 67084] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:30.008235 2026] [security2:error] [pid 67073:tid 67211] [client 20.116.17.175:57470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wicked.php"] [unique_id "aoSAcvcmepr5_nHgLbNC5gAAAho"]
[Tue Aug 18 12:55:30.022269 2026] [security2:error] [pid 67073:tid 67230] [client 20.51.153.15:9098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/wp-key.php"] [unique_id "aoSAcvcmepr5_nHgLbNC6AAAAi0"]
[Tue Aug 18 12:55:30.043654 2026] [security2:error] [pid 67073:tid 67321] [client 172.182.200.96:14241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSAcvcmepr5_nHgLbNC7QAAAog"]
[Tue Aug 18 12:55:30.048474 2026] [security2:error] [pid 67073:tid 67214] [client 20.48.236.86:16322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/dex.php"] [unique_id "aoSAcvcmepr5_nHgLbNC7gAAAh0"]
[Tue Aug 18 12:55:30.052082 2026] [security2:error] [pid 67073:tid 67271] [client 74.248.18.37:43483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSAcvcmepr5_nHgLbNC7wAAAlY"]
[Tue Aug 18 12:55:30.053337 2026] [security2:error] [pid 66623:tid 66853] [client 20.226.6.191:59932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSActO5rbWdOArH04KElgAAAWE"]
[Tue Aug 18 12:55:30.062316 2026] [security2:error] [pid 66623:tid 66861] [client 135.225.75.187:45937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/app.php"] [unique_id "aoSActO5rbWdOArH04KElwAAAWk"]
[Tue Aug 18 12:55:30.064091 2026] [security2:error] [pid 66623:tid 66769] [client 52.139.47.57:19951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/h.php"] [unique_id "aoSActO5rbWdOArH04KEmAAAAQ0"]
[Tue Aug 18 12:55:30.109970 2026] [security2:error] [pid 66623:tid 66845] [client 74.248.136.165:29063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/erty.php"] [unique_id "aoSActO5rbWdOArH04KEmQAAAVk"]
[Tue Aug 18 12:55:30.112061 2026] [security2:error] [pid 66623:tid 66822] [client 20.171.51.14:45380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/57.php"] [unique_id "aoSActO5rbWdOArH04KEmgAAAUI"]
[Tue Aug 18 12:55:30.124079 2026] [security2:error] [pid 67073:tid 67248] [client 20.250.13.23:20706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/bgymj.php"] [unique_id "aoSAcvcmepr5_nHgLbNC9AAAAj8"]
[Tue Aug 18 12:55:30.125796 2026] [security2:error] [pid 67073:tid 67205] [client 78.46.190.63:1302] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "ceussmedicina.com.br"] [uri "/index.php"] [unique_id "aoSAcPcmepr5_nHgLbNCYgAAAhQ"], referer: http://ceussmedicina.com.br/
[Tue Aug 18 12:55:30.141149 2026] [security2:error] [pid 67073:tid 67242] [client 20.42.19.40:9705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/zwso.php"] [unique_id "aoSAcvcmepr5_nHgLbNC9QAAAjk"]
[Tue Aug 18 12:55:30.154906 2026] [security2:error] [pid 66623:tid 66850] [client 213.35.127.232:60632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSActO5rbWdOArH04KEnAAAAV4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:30.155181 2026] [autoindex:error] [pid 66623:tid 66786] [client 20.104.85.180:8064] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:30.156056 2026] [security2:error] [pid 66623:tid 66796] [client 20.163.43.14:4309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/403.php"] [unique_id "aoSActO5rbWdOArH04KEnQAAASg"]
[Tue Aug 18 12:55:30.166565 2026] [security2:error] [pid 66623:tid 66772] [client 4.223.164.152:46182] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/blocks/audio/"] [unique_id "aoSActO5rbWdOArH04KEngAAARA"]
[Tue Aug 18 12:55:30.197412 2026] [security2:error] [pid 66623:tid 66809] [client 20.251.48.93:57261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/ops.php"] [unique_id "aoSActO5rbWdOArH04KEnwAAATU"]
[Tue Aug 18 12:55:30.213633 2026] [security2:error] [pid 67073:tid 67222] [client 20.163.43.14:4368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/alfa.php"] [unique_id "aoSAcvcmepr5_nHgLbNC9wAAAiU"]
[Tue Aug 18 12:55:30.214041 2026] [security2:error] [pid 67073:tid 67252] [client 20.151.109.219:17537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/jm.php"] [unique_id "aoSAcvcmepr5_nHgLbNC-AAAAkM"]
[Tue Aug 18 12:55:30.229894 2026] [security2:error] [pid 66623:tid 66875] [client 37.40.227.74:57266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSActO5rbWdOArH04KEoAAAAXc"]
[Tue Aug 18 12:55:30.232108 2026] [security2:error] [pid 67073:tid 67173] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/wj.php"] [unique_id "aoSAcvcmepr5_nHgLbNC-QACemE"]
[Tue Aug 18 12:55:30.233777 2026] [security2:error] [pid 66623:tid 66875] [client 37.40.227.74:57266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSActO5rbWdOArH04KEoAAAAXc"]
[Tue Aug 18 12:55:30.236115 2026] [security2:error] [pid 67073:tid 67295] [client 20.91.215.254:20676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/images/xmrlpc.php"] [unique_id "aoSAcvcmepr5_nHgLbNC-gAAAm4"]
[Tue Aug 18 12:55:30.244605 2026] [security2:error] [pid 67073:tid 67263] [client 20.104.100.201:21458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/a.php"] [unique_id "aoSAcvcmepr5_nHgLbNC-wAAAk4"]
[Tue Aug 18 12:55:30.262287 2026] [security2:error] [pid 67073:tid 67234] [client 20.51.153.15:9099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/gg.php"] [unique_id "aoSAcvcmepr5_nHgLbNC_AAAAjE"]
[Tue Aug 18 12:55:30.274777 2026] [autoindex:error] [pid 67073:tid 67324] [client 52.73.140.57:25391] AH01276: Cannot serve directory /home4/acessoso/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:30.294372 2026] [authz_core:error] [pid 67073:tid 67154] [remote 57.141.22.107:46916] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:30.294803 2026] [authz_core:error] [pid 67073:tid 67154] [remote 57.141.22.107:46916] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:30.297509 2026] [security2:error] [pid 66623:tid 66804] [client 74.248.133.44:24712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSActO5rbWdOArH04KEoQAAATA"]
[Tue Aug 18 12:55:30.300607 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:30.301023 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:30.340068 2026] [security2:error] [pid 66623:tid 66766] [client 20.29.77.16:52790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/xynz1.php"] [unique_id "aoSActO5rbWdOArH04KEowAAAQo"]
[Tue Aug 18 12:55:30.348291 2026] [security2:error] [pid 67073:tid 67279] [client 74.248.130.103:38666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/red.php"] [unique_id "aoSAcvcmepr5_nHgLbNDCwAAAl4"]
[Tue Aug 18 12:55:30.377752 2026] [security2:error] [pid 67073:tid 67209] [client 20.42.19.40:1385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/Geforce.php"] [unique_id "aoSAcvcmepr5_nHgLbNDDAAAAhg"]
[Tue Aug 18 12:55:30.392183 2026] [security2:error] [pid 67073:tid 67281] [client 172.182.200.96:14225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAcvcmepr5_nHgLbNDDgAAAmA"]
[Tue Aug 18 12:55:30.393051 2026] [security2:error] [pid 67073:tid 67299] [client 20.100.169.31:31446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/sx.php"] [unique_id "aoSAcvcmepr5_nHgLbNDDwAAAnI"]
[Tue Aug 18 12:55:30.395932 2026] [security2:error] [pid 67073:tid 67292] [client 20.48.236.86:16364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/puc.php"] [unique_id "aoSAcvcmepr5_nHgLbNDEAAAAms"]
[Tue Aug 18 12:55:30.458446 2026] [autoindex:error] [pid 66623:tid 66826] [client 20.104.85.180:8064] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:30.465774 2026] [security2:error] [pid 66623:tid 66885] [client 216.73.161.209:23695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-login.php"] [unique_id "aoSActO5rbWdOArH04KEogAAAYE"], referer: https://ozzyfernandesoficial.com.br/wp-login.php
[Tue Aug 18 12:55:30.491865 2026] [autoindex:error] [pid 67073:tid 67327] [client 20.226.6.191:55772] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:30.497320 2026] [security2:error] [pid 67073:tid 67096] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/74.php"] [unique_id "aoSAcvcmepr5_nHgLbNDFAACURQ"]
[Tue Aug 18 12:55:30.526969 2026] [security2:error] [pid 67073:tid 67284] [client 20.104.100.201:58926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSAcvcmepr5_nHgLbNDFQAAAmM"]
[Tue Aug 18 12:55:30.532311 2026] [security2:error] [pid 67073:tid 67317] [client 52.139.47.57:19944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/import/csv1.php"] [unique_id "aoSAcvcmepr5_nHgLbNDFgAAAoQ"]
[Tue Aug 18 12:55:30.533377 2026] [security2:error] [pid 66623:tid 66874] [client 74.248.136.165:49621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/mini.php"] [unique_id "aoSActO5rbWdOArH04KEqAAAAXY"]
[Tue Aug 18 12:55:30.565862 2026] [security2:error] [pid 67073:tid 67213] [client 20.151.109.219:53217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/wj.php"] [unique_id "aoSAcvcmepr5_nHgLbNDFwAAAhw"]
[Tue Aug 18 12:55:30.592636 2026] [security2:error] [pid 66623:tid 66878] [client 20.51.153.15:9152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/gi.php"] [unique_id "aoSActO5rbWdOArH04KEqQAAAXo"]
[Tue Aug 18 12:55:30.595320 2026] [security2:error] [pid 66623:tid 66787] [client 20.104.85.180:8064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wso.php"] [unique_id "aoSActO5rbWdOArH04KEqgAAAR8"]
[Tue Aug 18 12:55:30.603664 2026] [security2:error] [pid 67073:tid 67293] [client 20.226.6.191:55772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAcvcmepr5_nHgLbNDGgAAAmw"]
[Tue Aug 18 12:55:30.614095 2026] [security2:error] [pid 67073:tid 67275] [client 20.42.19.40:2013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/fpwch.php"] [unique_id "aoSAcvcmepr5_nHgLbNDGwAAAlo"]
[Tue Aug 18 12:55:30.636136 2026] [security2:error] [pid 67073:tid 67258] [client 52.238.210.254:8922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAcvcmepr5_nHgLbNDHQAAAkk"]
[Tue Aug 18 12:55:30.638135 2026] [security2:error] [pid 67073:tid 67318] [client 20.163.43.14:4447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/lock360.php"] [unique_id "aoSAcvcmepr5_nHgLbNDHgAAAoU"]
[Tue Aug 18 12:55:30.639199 2026] [security2:error] [pid 67073:tid 67259] [client 4.223.164.152:37277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-temp.php"] [unique_id "aoSAcvcmepr5_nHgLbNDHwAAAko"]
[Tue Aug 18 12:55:30.656762 2026] [security2:error] [pid 66623:tid 66827] [client 20.48.236.86:10755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/packed.php"] [unique_id "aoSActO5rbWdOArH04KErAAAAUc"]
[Tue Aug 18 12:55:30.688760 2026] [security2:error] [pid 67073:tid 67212] [client 197.184.64.235:41925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAcvcmepr5_nHgLbNDIgAAAhs"]
[Tue Aug 18 12:55:30.688872 2026] [security2:error] [pid 67073:tid 67212] [client 197.184.64.235:41925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAcvcmepr5_nHgLbNDIgAAAhs"]
[Tue Aug 18 12:55:30.698587 2026] [security2:error] [pid 67073:tid 67169] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/av.php"] [unique_id "aoSAcvcmepr5_nHgLbNDIwACGl0"]
[Tue Aug 18 12:55:30.701958 2026] [security2:error] [pid 67073:tid 67287] [client 4.232.151.198:25671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/edit.php"] [unique_id "aoSAcvcmepr5_nHgLbNDJQAAAmY"]
[Tue Aug 18 12:55:30.702859 2026] [security2:error] [pid 67073:tid 67328] [client 5.253.205.188:48278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/install.sql"] [unique_id "aoSAcvcmepr5_nHgLbNDJAAAAo8"], referer: https://medihub.com.br/install.sql
[Tue Aug 18 12:55:30.758890 2026] [security2:error] [pid 66623:tid 66785] [client 52.173.121.69:24977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSActO5rbWdOArH04KErQAAAR0"]
[Tue Aug 18 12:55:30.760540 2026] [security2:error] [pid 66623:tid 66889] [client 20.91.215.254:12588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-admin/import.php"] [unique_id "aoSActO5rbWdOArH04KErgAAAYU"]
[Tue Aug 18 12:55:30.774982 2026] [security2:error] [pid 67073:tid 67272] [client 20.100.169.31:33547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/goods.php"] [unique_id "aoSAcvcmepr5_nHgLbNDJwAAAlc"]
[Tue Aug 18 12:55:30.780777 2026] [security2:error] [pid 67073:tid 67321] [client 20.48.236.86:16260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/inso.php"] [unique_id "aoSAcvcmepr5_nHgLbNDKAAAAog"]
[Tue Aug 18 12:55:30.790337 2026] [security2:error] [pid 67073:tid 67214] [client 172.182.200.96:14307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSAcvcmepr5_nHgLbNDKgAAAh0"]
[Tue Aug 18 12:55:30.806298 2026] [security2:error] [pid 67073:tid 67310] [client 20.104.100.201:58908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/99.php"] [unique_id "aoSAcvcmepr5_nHgLbNDKwAAAn0"]
[Tue Aug 18 12:55:30.821097 2026] [security2:error] [pid 66623:tid 66830] [client 20.205.121.237:5081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-access.php"] [unique_id "aoSActO5rbWdOArH04KErwAAAUo"]
[Tue Aug 18 12:55:30.871754 2026] [security2:error] [pid 67073:tid 67257] [client 20.104.85.180:7958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/sf.php"] [unique_id "aoSAcvcmepr5_nHgLbNDLwAAAkg"]
[Tue Aug 18 12:55:30.910355 2026] [security2:error] [pid 67073:tid 67280] [client 20.51.153.15:8791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ic.php"] [unique_id "aoSAcvcmepr5_nHgLbNDNQAAAl8"]
[Tue Aug 18 12:55:30.920043 2026] [security2:error] [pid 67073:tid 67125] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ag.php"] [unique_id "aoSAcvcmepr5_nHgLbNDNwACKTE"]
[Tue Aug 18 12:55:30.924506 2026] [security2:error] [pid 67073:tid 67241] [client 20.91.215.254:13909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSAcvcmepr5_nHgLbNDOAAAAjg"]
[Tue Aug 18 12:55:30.924608 2026] [security2:error] [pid 67073:tid 67330] [client 20.151.109.219:24871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/74.php"] [unique_id "aoSAcvcmepr5_nHgLbNDOQAAApE"]
[Tue Aug 18 12:55:30.925752 2026] [security2:error] [pid 67073:tid 67261] [client 20.171.51.14:1958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/main.php"] [unique_id "aoSAcvcmepr5_nHgLbNDOgAAAkw"]
[Tue Aug 18 12:55:30.951295 2026] [security2:error] [pid 67073:tid 67219] [client 74.248.136.165:28627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/sid3.php"] [unique_id "aoSAcvcmepr5_nHgLbNDPQAAAiI"]
[Tue Aug 18 12:55:30.966355 2026] [security2:error] [pid 67073:tid 67234] [client 20.42.19.40:9616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-blog-header.php"] [unique_id "aoSAcvcmepr5_nHgLbNDPgAAAjE"]
[Tue Aug 18 12:55:30.979904 2026] [security2:error] [pid 67073:tid 67306] [client 20.226.6.191:32107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/gelay.php"] [unique_id "aoSAcvcmepr5_nHgLbNDQAAAAnk"]
[Tue Aug 18 12:55:30.980630 2026] [security2:error] [pid 66623:tid 66851] [client 20.65.69.59:3760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/phpcheck.php"] [unique_id "aoSActO5rbWdOArH04KEsAAAAV8"]
[Tue Aug 18 12:55:31.005815 2026] [security2:error] [pid 67073:tid 67207] [client 20.163.43.14:4269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/gecko.php"] [unique_id "aoSAc_cmepr5_nHgLbNDQQAAAhY"]
[Tue Aug 18 12:55:31.015909 2026] [security2:error] [pid 67073:tid 67223] [client 20.100.169.31:2967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSAc_cmepr5_nHgLbNDQwAAAiY"]
[Tue Aug 18 12:55:31.040029 2026] [security2:error] [pid 67073:tid 67276] [client 20.163.43.14:4369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/flower.php"] [unique_id "aoSAc_cmepr5_nHgLbNDRgAAAls"]
[Tue Aug 18 12:55:31.085434 2026] [security2:error] [pid 67073:tid 67235] [client 20.104.100.201:58457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/yup.php"] [unique_id "aoSAc_cmepr5_nHgLbNDRwAAAjI"]
[Tue Aug 18 12:55:31.114106 2026] [security2:error] [pid 67073:tid 67252] [client 52.139.47.57:16657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/index.bak.php"] [unique_id "aoSAc_cmepr5_nHgLbNDSQAAAkM"]
[Tue Aug 18 12:55:31.122062 2026] [security2:error] [pid 66623:tid 66868] [client 4.223.164.152:28502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAc9O5rbWdOArH04KEsQAAAXA"]
[Tue Aug 18 12:55:31.149449 2026] [security2:error] [pid 67073:tid 67299] [client 135.225.75.187:32714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAc_cmepr5_nHgLbNDTAAAAnI"]
[Tue Aug 18 12:55:31.150580 2026] [security2:error] [pid 67073:tid 67292] [client 20.51.153.15:8790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/lr.php"] [unique_id "aoSAc_cmepr5_nHgLbNDTQAAAms"]
[Tue Aug 18 12:55:31.155431 2026] [security2:error] [pid 67073:tid 67296] [client 172.182.200.96:14226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/well-known/index.php"] [unique_id "aoSAc_cmepr5_nHgLbNDTgAAAm8"]
[Tue Aug 18 12:55:31.166342 2026] [security2:error] [pid 66623:tid 66856] [client 20.226.6.191:6620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAc9O5rbWdOArH04KEsgAAAWQ"]
[Tue Aug 18 12:55:31.168147 2026] [security2:error] [pid 67073:tid 67274] [client 213.35.127.232:60863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAc_cmepr5_nHgLbNDUAAAAlk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:31.174683 2026] [security2:error] [pid 67073:tid 67124] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ig.php"] [unique_id "aoSAc_cmepr5_nHgLbNDUQACJzA"]
[Tue Aug 18 12:55:31.185430 2026] [security2:error] [pid 67073:tid 67266] [client 20.48.236.86:16288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/aa.php"] [unique_id "aoSAc_cmepr5_nHgLbNDUgAAAlE"]
[Tue Aug 18 12:55:31.200646 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:31.200942 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:31.212777 2026] [security2:error] [pid 67073:tid 67284] [client 20.226.6.191:38252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAc_cmepr5_nHgLbNDVQAAAmM"]
[Tue Aug 18 12:55:31.215645 2026] [security2:error] [pid 66623:tid 66888] [client 132.196.61.152:60339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/ws13.php"] [unique_id "aoSAc9O5rbWdOArH04KEswAAAYQ"]
[Tue Aug 18 12:55:31.225715 2026] [security2:error] [pid 67073:tid 67220] [client 20.42.19.40:9677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/about/function.php"] [unique_id "aoSAc_cmepr5_nHgLbNDVgAAAiM"]
[Tue Aug 18 12:55:31.236118 2026] [security2:error] [pid 67073:tid 67315] [client 78.46.190.63:64714] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ceussmedicina.com.br"] [uri "/index.php"] [unique_id "aoSAc_cmepr5_nHgLbNDSgAAAoI"], referer: http://ceussmedicina.com.br/
[Tue Aug 18 12:55:31.247522 2026] [security2:error] [pid 66623:tid 66757] [remote 50.6.169.131:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.169.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "altostima.com.br"] [uri "/wp-login.php"] [unique_id "aoSAc9O5rbWdOArH04KEtAABC3g"]
[Tue Aug 18 12:55:31.257894 2026] [security2:error] [pid 67073:tid 67323] [client 20.104.85.180:7985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/index/function.php"] [unique_id "aoSAc_cmepr5_nHgLbNDWAAAAoo"]
[Tue Aug 18 12:55:31.276379 2026] [security2:error] [pid 67073:tid 67275] [client 20.251.48.93:31797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/coffexium.php"] [unique_id "aoSAc_cmepr5_nHgLbNDWQAAAlo"]
[Tue Aug 18 12:55:31.276951 2026] [security2:error] [pid 67073:tid 67239] [client 20.226.6.191:64117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAc_cmepr5_nHgLbNDWgAAAjY"]
[Tue Aug 18 12:55:31.295552 2026] [security2:error] [pid 67073:tid 67318] [client 20.151.109.219:61387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/av.php"] [unique_id "aoSAc_cmepr5_nHgLbNDXAAAAoU"]
[Tue Aug 18 12:55:31.360707 2026] [security2:error] [pid 67073:tid 67272] [client 20.104.100.201:58491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/222.php"] [unique_id "aoSAc_cmepr5_nHgLbNDYwAAAlc"]
[Tue Aug 18 12:55:31.370199 2026] [security2:error] [pid 66623:tid 66862] [client 74.248.136.165:29072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/moon.php"] [unique_id "aoSAc9O5rbWdOArH04KEtQAAAWo"]
[Tue Aug 18 12:55:31.385879 2026] [autoindex:error] [pid 67073:tid 67218] [client 20.226.6.191:36372] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:31.400975 2026] [security2:error] [pid 67073:tid 67324] [client 74.248.18.37:29284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSAc_cmepr5_nHgLbNDZQAAAos"]
[Tue Aug 18 12:55:31.404420 2026] [security2:error] [pid 67073:tid 67316] [client 20.226.6.191:36372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSAc_cmepr5_nHgLbNDZgAAAoM"]
[Tue Aug 18 12:55:31.409385 2026] [security2:error] [pid 67073:tid 67180] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ta.php"] [unique_id "aoSAc_cmepr5_nHgLbNDaAACc2g"]
[Tue Aug 18 12:55:31.423775 2026] [security2:error] [pid 66623:tid 66846] [client 52.238.210.254:10226] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/uploads/"] [unique_id "aoSAc9O5rbWdOArH04KEtwAAAVo"]
[Tue Aug 18 12:55:31.425129 2026] [security2:error] [pid 67073:tid 67248] [client 20.29.77.16:56518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/album.php"] [unique_id "aoSAc_cmepr5_nHgLbNDawAAAj8"]
[Tue Aug 18 12:55:31.434005 2026] [security2:error] [pid 67073:tid 67225] [client 20.163.43.14:4461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/13.php"] [unique_id "aoSAc_cmepr5_nHgLbNDbAAAAig"]
[Tue Aug 18 12:55:31.435545 2026] [security2:error] [pid 66623:tid 66831] [client 20.171.51.14:1983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ah.php"] [unique_id "aoSAc9O5rbWdOArH04KEuAAAAUs"]
[Tue Aug 18 12:55:31.482760 2026] [security2:error] [pid 66623:tid 66805] [client 20.42.19.40:9603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/function/function.php"] [unique_id "aoSAc9O5rbWdOArH04KEuQAAATE"]
[Tue Aug 18 12:55:31.496465 2026] [security2:error] [pid 67073:tid 67330] [client 20.226.6.191:45832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/about.php"] [unique_id "aoSAc_cmepr5_nHgLbNDcAAAApE"]
[Tue Aug 18 12:55:31.501477 2026] [security2:error] [pid 67073:tid 67216] [client 20.91.215.254:22595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSAc_cmepr5_nHgLbNDcQAAAh8"]
[Tue Aug 18 12:55:31.502888 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:31.503144 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:31.510460 2026] [security2:error] [pid 67073:tid 67219] [client 172.182.200.96:14301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSAc_cmepr5_nHgLbNDcgAAAiI"]
[Tue Aug 18 12:55:31.518742 2026] [security2:error] [pid 67073:tid 67234] [client 20.51.153.15:8706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/iy.php"] [unique_id "aoSAc_cmepr5_nHgLbNDcwAAAjE"]
[Tue Aug 18 12:55:31.530843 2026] [security2:error] [pid 67073:tid 67306] [client 20.48.236.86:16328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/img.php"] [unique_id "aoSAc_cmepr5_nHgLbNDdAAAAnk"]
[Tue Aug 18 12:55:31.564226 2026] [security2:error] [pid 67073:tid 67207] [client 20.104.85.180:8060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/edit.php"] [unique_id "aoSAc_cmepr5_nHgLbNDdgAAAhY"]
[Tue Aug 18 12:55:31.566575 2026] [security2:error] [pid 67073:tid 67223] [client 4.223.164.152:37310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/puc.php"] [unique_id "aoSAc_cmepr5_nHgLbNDdwAAAiY"]
[Tue Aug 18 12:55:31.582008 2026] [security2:error] [pid 67073:tid 67244] [client 20.163.43.14:4289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/aa.php"] [unique_id "aoSAc_cmepr5_nHgLbNDeQAAAjs"]
[Tue Aug 18 12:55:31.588480 2026] [security2:error] [pid 67073:tid 67242] [client 20.226.6.191:38268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSAc_cmepr5_nHgLbNDegAAAjk"]
[Tue Aug 18 12:55:31.591253 2026] [core:notice] [pid 67073:tid 67229] AH00113: /home3/uniaonutri/public_html/.htaccess:34 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Tue Aug 18 12:55:31.595201 2026] [security2:error] [pid 67073:tid 67243] [client 20.151.109.219:12896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ag.php"] [unique_id "aoSAc_cmepr5_nHgLbNDfAAAAjo"]
[Tue Aug 18 12:55:31.613364 2026] [security2:error] [pid 67073:tid 67210] [client 132.196.61.152:61002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/btx25.php"] [unique_id "aoSAc_cmepr5_nHgLbNDfgAAAhk"]
[Tue Aug 18 12:55:31.616508 2026] [security2:error] [pid 67073:tid 67235] [client 68.155.154.236:16357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/pkmoj.php"] [unique_id "aoSAc_cmepr5_nHgLbNDfwAAAjI"]
[Tue Aug 18 12:55:31.632448 2026] [security2:error] [pid 67073:tid 67209] [client 20.104.100.201:21473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-temp.php"] [unique_id "aoSAc_cmepr5_nHgLbNDgQAAAhg"]
[Tue Aug 18 12:55:31.644491 2026] [security2:error] [pid 67073:tid 67116] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/34.php"] [unique_id "aoSAc_cmepr5_nHgLbNDgwACHig"]
[Tue Aug 18 12:55:31.646924 2026] [security2:error] [pid 67073:tid 67292] [client 20.226.6.191:56226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/f35.php"] [unique_id "aoSAc_cmepr5_nHgLbNDhAAAAms"]
[Tue Aug 18 12:55:31.647436 2026] [security2:error] [pid 66623:tid 66887] [client 20.100.169.31:2447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAc9O5rbWdOArH04KEugAAAYM"]
[Tue Aug 18 12:55:31.662201 2026] [security2:error] [pid 67073:tid 67265] [client 74.248.130.103:15379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-content/index.php"] [unique_id "aoSAc_cmepr5_nHgLbNDhQAAAlA"]
[Tue Aug 18 12:55:31.712785 2026] [security2:error] [pid 67073:tid 67224] [client 52.173.121.69:16477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSAc_cmepr5_nHgLbNDhwAAAic"]
[Tue Aug 18 12:55:31.720548 2026] [security2:error] [pid 66623:tid 66770] [client 20.42.19.40:9620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-signin.php"] [unique_id "aoSAc9O5rbWdOArH04KEuwAAAQ4"]
[Tue Aug 18 12:55:31.747953 2026] [autoindex:error] [pid 67073:tid 67266] [client 20.226.6.191:64020] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:31.748112 2026] [security2:error] [pid 67073:tid 67267] [client 20.91.215.254:27450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/goat.php"] [unique_id "aoSAc_cmepr5_nHgLbNDiQAAAlI"]
[Tue Aug 18 12:55:31.759207 2026] [security2:error] [pid 67073:tid 67320] [client 20.226.6.191:64020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/inputs.php"] [unique_id "aoSAc_cmepr5_nHgLbNDiwAAAoc"]
[Tue Aug 18 12:55:31.759994 2026] [security2:error] [pid 66623:tid 66781] [client 20.51.153.15:8800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/lp.php"] [unique_id "aoSAc9O5rbWdOArH04KEvQAAARk"]
[Tue Aug 18 12:55:31.780780 2026] [security2:error] [pid 67073:tid 67228] [client 86.120.159.145:5335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAc_cmepr5_nHgLbNDjAAAAis"]
[Tue Aug 18 12:55:31.781048 2026] [security2:error] [pid 67073:tid 67228] [client 86.120.159.145:5335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAc_cmepr5_nHgLbNDjAAAAis"]
[Tue Aug 18 12:55:31.787333 2026] [security2:error] [pid 67073:tid 67282] [client 74.248.136.165:43702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ms.php"] [unique_id "aoSAc_cmepr5_nHgLbNDjgAAAmE"]
[Tue Aug 18 12:55:31.794623 2026] [security2:error] [pid 66623:tid 66881] [client 20.163.43.14:4366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/cc.php"] [unique_id "aoSAc9O5rbWdOArH04KEvgAAAX0"]
[Tue Aug 18 12:55:31.815918 2026] [security2:error] [pid 66623:tid 66794] [client 20.65.98.162:15506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/special.php"] [unique_id "aoSAc9O5rbWdOArH04KEvwAAASY"]
[Tue Aug 18 12:55:31.833051 2026] [security2:error] [pid 67073:tid 67323] [client 20.48.236.86:16334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/222.php"] [unique_id "aoSAc_cmepr5_nHgLbNDkAAAAoo"]
[Tue Aug 18 12:55:31.834414 2026] [security2:error] [pid 66623:tid 66867] [client 104.209.144.33:33670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSAc9O5rbWdOArH04KEwAAAAW8"]
[Tue Aug 18 12:55:31.853117 2026] [security2:error] [pid 67073:tid 67295] [client 20.205.121.237:4118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin.php"] [unique_id "aoSAc_cmepr5_nHgLbNDkgAAAm4"]
[Tue Aug 18 12:55:31.862156 2026] [security2:error] [pid 67073:tid 67275] [client 20.171.51.14:43380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ga.php"] [unique_id "aoSAc_cmepr5_nHgLbNDkwAAAlo"]
[Tue Aug 18 12:55:31.895576 2026] [security2:error] [pid 67073:tid 67168] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/he.php"] [unique_id "aoSAc_cmepr5_nHgLbNDlQACdlw"]
[Tue Aug 18 12:55:31.905785 2026] [security2:error] [pid 66623:tid 66776] [client 20.104.100.201:21444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/spadex.php"] [unique_id "aoSAc9O5rbWdOArH04KEwQAAARQ"]
[Tue Aug 18 12:55:31.910745 2026] [security2:error] [pid 67073:tid 67326] [client 20.100.169.31:15489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/atomlib.php"] [unique_id "aoSAc_cmepr5_nHgLbNDlgAAAo0"]
[Tue Aug 18 12:55:31.914221 2026] [security2:error] [pid 66623:tid 66783] [client 135.225.75.187:31148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/cxc.php"] [unique_id "aoSAc9O5rbWdOArH04KEwgAAARs"]
[Tue Aug 18 12:55:31.917605 2026] [security2:error] [pid 66623:tid 66857] [client 52.238.210.254:8940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSAc9O5rbWdOArH04KEwwAAAWU"]
[Tue Aug 18 12:55:31.961073 2026] [security2:error] [pid 67073:tid 67212] [client 20.42.19.40:9717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/f35.php"] [unique_id "aoSAc_cmepr5_nHgLbNDmQAAAhs"]
[Tue Aug 18 12:55:31.962178 2026] [autoindex:error] [pid 67073:tid 67287] [client 74.248.133.44:24736] AH01276: Cannot serve directory /home3/hyundai/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:31.973569 2026] [security2:error] [pid 67073:tid 67273] [client 20.151.109.219:24878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ig.php"] [unique_id "aoSAc_cmepr5_nHgLbNDmgAAAlg"]
[Tue Aug 18 12:55:31.978317 2026] [security2:error] [pid 66623:tid 66872] [client 20.100.169.31:42680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/file.php"] [unique_id "aoSAc9O5rbWdOArH04KExAAAAXQ"]
[Tue Aug 18 12:55:31.988568 2026] [security2:error] [pid 67073:tid 67230] [client 172.182.200.96:14242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAc_cmepr5_nHgLbNDnAAAAi0"]
[Tue Aug 18 12:55:31.991057 2026] [security2:error] [pid 67073:tid 67272] [client 4.223.164.152:64684] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/Requests/"] [unique_id "aoSAc_cmepr5_nHgLbNDnQAAAlc"]
[Tue Aug 18 12:55:31.993212 2026] [autoindex:error] [pid 67073:tid 67328] [client 20.104.85.180:8061] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:32.031765 2026] [security2:error] [pid 67073:tid 67310] [client 20.163.43.14:4344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/0x.php"] [unique_id "aoSAdPcmepr5_nHgLbNDoAAAAn0"]
[Tue Aug 18 12:55:32.060155 2026] [security2:error] [pid 67073:tid 67237] [client 20.51.153.15:9202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ey.php"] [unique_id "aoSAdPcmepr5_nHgLbNDoQAAAjQ"]
[Tue Aug 18 12:55:32.101169 2026] [security2:error] [pid 67073:tid 67155] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gz.php"] [unique_id "aoSAdPcmepr5_nHgLbNDqQACgU8"]
[Tue Aug 18 12:55:32.109247 2026] [authz_core:error] [pid 67073:tid 67097] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:32.109685 2026] [authz_core:error] [pid 67073:tid 67097] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:32.160846 2026] [security2:error] [pid 67073:tid 67318] [client 20.91.215.254:13243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/ebs.php7"] [unique_id "aoSAdPcmepr5_nHgLbNDrAAAAoU"]
[Tue Aug 18 12:55:32.165807 2026] [security2:error] [pid 66623:tid 66808] [client 20.48.236.86:16271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/key.php"] [unique_id "aoSAdNO5rbWdOArH04KExgAAATQ"]
[Tue Aug 18 12:55:32.167317 2026] [security2:error] [pid 66623:tid 66777] [client 4.232.151.198:24570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/elp.php"] [unique_id "aoSAdNO5rbWdOArH04KExwAAARU"]
[Tue Aug 18 12:55:32.172378 2026] [security2:error] [pid 67073:tid 67222] [client 74.248.133.44:24736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/o.php"] [unique_id "aoSAdPcmepr5_nHgLbNDrQAAAiU"]
[Tue Aug 18 12:55:32.182338 2026] [security2:error] [pid 66623:tid 66832] [client 20.171.51.14:65103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/vw.php"] [unique_id "aoSAdNO5rbWdOArH04KEyAAAAUw"]
[Tue Aug 18 12:55:32.185113 2026] [security2:error] [pid 67073:tid 67293] [client 213.35.127.232:61141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAdPcmepr5_nHgLbNDrgAAAmw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:32.187858 2026] [security2:error] [pid 67073:tid 67234] [client 68.221.73.131:61198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAdPcmepr5_nHgLbNDrwAAAjE"]
[Tue Aug 18 12:55:32.194088 2026] [security2:error] [pid 67073:tid 67254] [client 20.104.100.201:21398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSAdPcmepr5_nHgLbNDsAAAAkU"]
[Tue Aug 18 12:55:32.214061 2026] [security2:error] [pid 67073:tid 67253] [client 74.248.136.165:9965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wsws.php"] [unique_id "aoSAdPcmepr5_nHgLbNDsgAAAkQ"]
[Tue Aug 18 12:55:32.214296 2026] [security2:error] [pid 67073:tid 67244] [client 20.163.43.14:4477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAdPcmepr5_nHgLbNDswAAAjs"]
[Tue Aug 18 12:55:32.226143 2026] [security2:error] [pid 67073:tid 67279] [client 20.116.17.175:57453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/water.php"] [unique_id "aoSAdPcmepr5_nHgLbNDtAAAAl4"]
[Tue Aug 18 12:55:32.259476 2026] [security2:error] [pid 67073:tid 67270] [client 20.151.109.219:24881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ta.php"] [unique_id "aoSAdPcmepr5_nHgLbNDtQAAAlU"]
[Tue Aug 18 12:55:32.277249 2026] [security2:error] [pid 67073:tid 67210] [client 20.104.85.180:8061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSAdPcmepr5_nHgLbNDtgAAAhk"]
[Tue Aug 18 12:55:32.290715 2026] [security2:error] [pid 67073:tid 67305] [client 4.232.151.198:27348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAdPcmepr5_nHgLbNDuAAAAng"]
[Tue Aug 18 12:55:32.305911 2026] [security2:error] [pid 67073:tid 67209] [client 20.226.6.191:6602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSAdPcmepr5_nHgLbNDuQAAAhg"]
[Tue Aug 18 12:55:32.350435 2026] [security2:error] [pid 67073:tid 67319] [client 158.158.34.183:62788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/access.php"] [unique_id "aoSAdPcmepr5_nHgLbNDvgAAAoY"]
[Tue Aug 18 12:55:32.367923 2026] [security2:error] [pid 67073:tid 67262] [client 103.184.169.37:41687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdPcmepr5_nHgLbNDvwAAAk0"]
[Tue Aug 18 12:55:32.368047 2026] [security2:error] [pid 67073:tid 67262] [client 103.184.169.37:41687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdPcmepr5_nHgLbNDvwAAAk0"]
[Tue Aug 18 12:55:32.370353 2026] [security2:error] [pid 67073:tid 67227] [client 74.248.130.103:15379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/admin.php"] [unique_id "aoSAdPcmepr5_nHgLbNDwAAAAio"]
[Tue Aug 18 12:55:32.388044 2026] [security2:error] [pid 67073:tid 67160] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/nf.php"] [unique_id "aoSAdPcmepr5_nHgLbNDwQACU1Q"]
[Tue Aug 18 12:55:32.391487 2026] [security2:error] [pid 67073:tid 67327] [client 20.215.241.237:16510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAdPcmepr5_nHgLbNDwgAAAo4"]
[Tue Aug 18 12:55:32.394648 2026] [security2:error] [pid 67073:tid 67309] [client 20.91.215.254:20693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/Session.php"] [unique_id "aoSAdPcmepr5_nHgLbNDwwAAAnw"]
[Tue Aug 18 12:55:32.397208 2026] [security2:error] [pid 67073:tid 67330] [client 52.139.47.57:44641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/lite.php"] [unique_id "aoSAdPcmepr5_nHgLbNDxAAAApE"]
[Tue Aug 18 12:55:32.416436 2026] [security2:error] [pid 67073:tid 67317] [client 52.173.121.69:17920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSAdPcmepr5_nHgLbNDyAAAAoQ"]
[Tue Aug 18 12:55:32.424333 2026] [security2:error] [pid 66623:tid 66892] [client 4.223.164.152:28530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/8.php"] [unique_id "aoSAdNO5rbWdOArH04KEyQAAAYg"]
[Tue Aug 18 12:55:32.424837 2026] [security2:error] [pid 66623:tid 66795] [client 20.51.153.15:8726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/lv.php"] [unique_id "aoSAdNO5rbWdOArH04KEygAAASc"]
[Tue Aug 18 12:55:32.431136 2026] [security2:error] [pid 66623:tid 66784] [client 52.238.210.254:8946] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-includes/"] [unique_id "aoSAdNO5rbWdOArH04KEzAAAARw"]
[Tue Aug 18 12:55:32.467351 2026] [security2:error] [pid 67073:tid 67255] [client 20.104.100.201:58478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/srontol.php"] [unique_id "aoSAdPcmepr5_nHgLbND0wAAAkY"]
[Tue Aug 18 12:55:32.481203 2026] [security2:error] [pid 67073:tid 67228] [client 172.202.39.151:50234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/cc.php"] [unique_id "aoSAdPcmepr5_nHgLbND1AAAAis"]
[Tue Aug 18 12:55:32.485935 2026] [security2:error] [pid 67073:tid 67282] [client 20.48.236.86:16303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/chosen.php"] [unique_id "aoSAdPcmepr5_nHgLbND1QAAAmE"]
[Tue Aug 18 12:55:32.506510 2026] [autoindex:error] [pid 67073:tid 67312] [client 20.226.6.191:32276] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:32.518330 2026] [security2:error] [pid 67073:tid 67323] [client 20.163.43.14:4294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/zxz.php"] [unique_id "aoSAdPcmepr5_nHgLbND1wAAAoo"]
[Tue Aug 18 12:55:32.535815 2026] [security2:error] [pid 67073:tid 67275] [client 172.182.200.96:14262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSAdPcmepr5_nHgLbND2QAAAlo"]
[Tue Aug 18 12:55:32.540581 2026] [security2:error] [pid 67073:tid 67276] [client 20.226.6.191:32276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/alfa.php"] [unique_id "aoSAdPcmepr5_nHgLbND2gAAAls"]
[Tue Aug 18 12:55:32.554443 2026] [authz_core:error] [pid 66623:tid 66707] [remote 57.141.22.31:59788] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:32.554702 2026] [authz_core:error] [pid 66623:tid 66707] [remote 57.141.22.31:59788] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:32.556805 2026] [security2:error] [pid 67073:tid 67269] [client 20.100.169.31:31478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAdPcmepr5_nHgLbND2wAAAlQ"]
[Tue Aug 18 12:55:32.573619 2026] [security2:error] [pid 67073:tid 67299] [client 20.104.85.180:8027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-good.php"] [unique_id "aoSAdPcmepr5_nHgLbND3AAAAnI"]
[Tue Aug 18 12:55:32.575068 2026] [security2:error] [pid 67073:tid 67290] [client 20.251.48.93:61120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAdPcmepr5_nHgLbND3QAAAmk"]
[Tue Aug 18 12:55:32.626560 2026] [security2:error] [pid 67073:tid 67272] [client 20.151.109.219:53243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/34.php"] [unique_id "aoSAdPcmepr5_nHgLbND4AAAAlc"]
[Tue Aug 18 12:55:32.637174 2026] [security2:error] [pid 67073:tid 67321] [client 74.248.136.165:9922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/motu.php"] [unique_id "aoSAdPcmepr5_nHgLbND4QAAAog"]
[Tue Aug 18 12:55:32.644224 2026] [security2:error] [pid 67073:tid 67283] [client 74.248.136.165:49038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/zc-318.php"] [unique_id "aoSAdPcmepr5_nHgLbND4gAAAmI"]
[Tue Aug 18 12:55:32.652927 2026] [security2:error] [pid 67073:tid 67308] [client 68.221.73.131:61260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAdPcmepr5_nHgLbND4wAAAns"]
[Tue Aug 18 12:55:32.674109 2026] [security2:error] [pid 67073:tid 67260] [client 20.51.153.15:9134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/51.php"] [unique_id "aoSAdPcmepr5_nHgLbND5AAAAks"]
[Tue Aug 18 12:55:32.685454 2026] [security2:error] [pid 67073:tid 67186] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/xv.php"] [unique_id "aoSAdPcmepr5_nHgLbND5wACkG4"]
[Tue Aug 18 12:55:32.726606 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:32.726891 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:32.731617 2026] [security2:error] [pid 66623:tid 66772] [client 20.163.43.14:4383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSAdNO5rbWdOArH04KE0AAAARA"]
[Tue Aug 18 12:55:32.742309 2026] [security2:error] [pid 67073:tid 67331] [client 20.104.100.201:58453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/file5.php"] [unique_id "aoSAdPcmepr5_nHgLbND6QAAApI"]
[Tue Aug 18 12:55:32.751418 2026] [security2:error] [pid 67073:tid 67278] [client 20.29.77.16:51373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/creds.php"] [unique_id "aoSAdPcmepr5_nHgLbND6gAAAl0"]
[Tue Aug 18 12:55:32.753281 2026] [security2:error] [pid 66623:tid 66809] [client 52.238.210.254:29109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/buy.php"] [unique_id "aoSAdNO5rbWdOArH04KE0QAAATU"]
[Tue Aug 18 12:55:32.755394 2026] [security2:error] [pid 66623:tid 66810] [client 20.171.51.14:15751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wb.php"] [unique_id "aoSAdNO5rbWdOArH04KE0gAAATY"]
[Tue Aug 18 12:55:32.774607 2026] [security2:error] [pid 67073:tid 67216] [client 20.48.236.86:16357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/wpxml.php"] [unique_id "aoSAdPcmepr5_nHgLbND7QAAAh8"]
[Tue Aug 18 12:55:32.798071 2026] [security2:error] [pid 67073:tid 67222] [client 132.196.61.152:61023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSAdPcmepr5_nHgLbND7wAAAiU"]
[Tue Aug 18 12:55:32.839361 2026] [security2:error] [pid 66623:tid 66880] [client 20.226.6.191:6596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/an.php"] [unique_id "aoSAdNO5rbWdOArH04KE0wAAAXw"]
[Tue Aug 18 12:55:32.851228 2026] [security2:error] [pid 66623:tid 66804] [client 4.223.164.152:46202] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/1.php"] [unique_id "aoSAdNO5rbWdOArH04KE1AAAATA"]
[Tue Aug 18 12:55:32.851348 2026] [security2:error] [pid 66623:tid 66804] [client 4.223.164.152:46202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/1.php"] [unique_id "aoSAdNO5rbWdOArH04KE1AAAATA"]
[Tue Aug 18 12:55:32.874855 2026] [security2:error] [pid 67073:tid 67211] [client 20.91.215.254:12455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoSAdPcmepr5_nHgLbND8gAAAho"]
[Tue Aug 18 12:55:32.915728 2026] [security2:error] [pid 67073:tid 67242] [client 20.163.43.14:4252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/www.php"] [unique_id "aoSAdPcmepr5_nHgLbND9AAAAjk"]
[Tue Aug 18 12:55:32.924524 2026] [security2:error] [pid 67073:tid 67279] [client 135.225.75.187:60104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSAdPcmepr5_nHgLbNEDQAAAl4"]
[Tue Aug 18 12:55:32.931860 2026] [security2:error] [pid 67073:tid 67270] [client 20.42.19.40:2910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/.trash7206/index.php"] [unique_id "aoSAdPcmepr5_nHgLbNEDwAAAlU"]
[Tue Aug 18 12:55:32.941734 2026] [security2:error] [pid 67073:tid 67300] [client 74.248.130.103:36843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/file52.php"] [unique_id "aoSAdPcmepr5_nHgLbNEEAAAAnM"]
[Tue Aug 18 12:55:32.950710 2026] [autoindex:error] [pid 67073:tid 67325] [client 20.104.85.180:7938] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:32.953474 2026] [security2:error] [pid 67073:tid 67235] [client 172.182.200.96:13876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/mt/byp.php"] [unique_id "aoSAdPcmepr5_nHgLbNEEQAAAjI"]
[Tue Aug 18 12:55:32.954752 2026] [security2:error] [pid 67073:tid 67198] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/mx.php"] [unique_id "aoSAdPcmepr5_nHgLbNEEgACGHo"]
[Tue Aug 18 12:55:32.963832 2026] [security2:error] [pid 67073:tid 67322] [client 20.151.109.219:24849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/he.php"] [unique_id "aoSAdPcmepr5_nHgLbNEFAAAAok"]
[Tue Aug 18 12:55:32.979745 2026] [security2:error] [pid 67073:tid 67219] [client 20.51.153.15:9174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ew.php"] [unique_id "aoSAdPcmepr5_nHgLbNEFQAAAiI"]
[Tue Aug 18 12:55:33.009397 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:33.009670 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:33.018272 2026] [security2:error] [pid 67073:tid 67215] [client 20.104.100.201:58440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/yup.php"] [unique_id "aoSAdfcmepr5_nHgLbNEGAAAAh4"]
[Tue Aug 18 12:55:33.038843 2026] [security2:error] [pid 67073:tid 67262] [client 20.65.69.59:49329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/mimes.php"] [unique_id "aoSAdfcmepr5_nHgLbNEGgAAAk0"]
[Tue Aug 18 12:55:33.054560 2026] [security2:error] [pid 66623:tid 66869] [client 74.248.136.165:10084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/fff.php"] [unique_id "aoSAddO5rbWdOArH04KE1gAAAXE"]
[Tue Aug 18 12:55:33.064349 2026] [security2:error] [pid 67073:tid 67292] [client 5.31.227.224:59071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdfcmepr5_nHgLbNEHgAAAms"]
[Tue Aug 18 12:55:33.064436 2026] [security2:error] [pid 67073:tid 67292] [client 5.31.227.224:59071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdfcmepr5_nHgLbNEHgAAAms"]
[Tue Aug 18 12:55:33.064582 2026] [security2:error] [pid 67073:tid 67293] [client 4.232.151.198:38221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAdfcmepr5_nHgLbNEHQAAAmw"]
[Tue Aug 18 12:55:33.067881 2026] [security2:error] [pid 66623:tid 66858] [client 20.48.236.86:16298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/file1221.php"] [unique_id "aoSAddO5rbWdOArH04KE1wAAAWY"]
[Tue Aug 18 12:55:33.073572 2026] [security2:error] [pid 66623:tid 66811] [client 47.128.19.54:43862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.galeriadoengenho.com"] [uri "/robots.txt"] [unique_id "aoSAddO5rbWdOArH04KE2AAAATc"]
[Tue Aug 18 12:55:33.127707 2026] [security2:error] [pid 67073:tid 67330] [client 20.65.98.162:56700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAdfcmepr5_nHgLbNEHwAAApE"]
[Tue Aug 18 12:55:33.154374 2026] [security2:error] [pid 67073:tid 67098] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/45.php"] [unique_id "aoSAdfcmepr5_nHgLbNEIQACQBY"]
[Tue Aug 18 12:55:33.165459 2026] [security2:error] [pid 67073:tid 67324] [client 20.91.215.254:20682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/acme-challenge.php"] [unique_id "aoSAdfcmepr5_nHgLbNEIwAAAos"]
[Tue Aug 18 12:55:33.188855 2026] [security2:error] [pid 67073:tid 67303] [client 20.100.169.31:15543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/rip.php"] [unique_id "aoSAdfcmepr5_nHgLbNEJAAAAnY"]
[Tue Aug 18 12:55:33.194997 2026] [security2:error] [pid 67073:tid 67315] [client 20.163.43.14:4428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/01.php"] [unique_id "aoSAdfcmepr5_nHgLbNEJQAAAoI"]
[Tue Aug 18 12:55:33.204040 2026] [security2:error] [pid 66623:tid 66818] [client 213.35.127.232:61412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAddO5rbWdOArH04KE3AAAAT4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:33.217348 2026] [security2:error] [pid 67073:tid 67320] [client 138.36.100.162:42757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdfcmepr5_nHgLbNEJwAAAoc"]
[Tue Aug 18 12:55:33.218132 2026] [security2:error] [pid 67073:tid 67320] [client 138.36.100.162:42757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdfcmepr5_nHgLbNEJwAAAoc"]
[Tue Aug 18 12:55:33.222448 2026] [autoindex:error] [pid 67073:tid 67194] [remote 40.77.167.70:60661] AH01276: Cannot serve directory /home1/verona/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:33.246920 2026] [security2:error] [pid 67073:tid 67295] [client 20.51.153.15:9131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/pqr.php"] [unique_id "aoSAdfcmepr5_nHgLbNEKgAAAm4"]
[Tue Aug 18 12:55:33.247975 2026] [security2:error] [pid 66623:tid 66799] [client 20.205.121.237:4110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/advanced1.php"] [unique_id "aoSAddO5rbWdOArH04KE3QAAASs"]
[Tue Aug 18 12:55:33.268123 2026] [security2:error] [pid 67073:tid 67275] [client 20.163.43.14:4337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wicked.php"] [unique_id "aoSAdfcmepr5_nHgLbNELAAAAlo"]
[Tue Aug 18 12:55:33.269884 2026] [security2:error] [pid 66623:tid 66891] [client 20.151.109.219:59740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gz.php"] [unique_id "aoSAddO5rbWdOArH04KE3wAAAYc"]
[Tue Aug 18 12:55:33.278899 2026] [security2:error] [pid 66623:tid 66815] [client 4.223.164.152:54234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/about.php"] [unique_id "aoSAddO5rbWdOArH04KE4AAAATs"]
[Tue Aug 18 12:55:33.290226 2026] [security2:error] [pid 66623:tid 66878] [client 20.226.6.191:56196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/lock360.php"] [unique_id "aoSAddO5rbWdOArH04KE4QAAAXo"]
[Tue Aug 18 12:55:33.297095 2026] [autoindex:error] [pid 67073:tid 67213] [client 20.104.85.180:7938] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-admin/css/colors/midnight/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:33.298071 2026] [security2:error] [pid 67073:tid 67326] [client 20.104.100.201:21485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAdfcmepr5_nHgLbNELQAAAo0"]
[Tue Aug 18 12:55:33.304717 2026] [security2:error] [pid 67073:tid 67299] [client 172.182.200.96:13929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSAdfcmepr5_nHgLbNELwAAAnI"]
[Tue Aug 18 12:55:33.309599 2026] [authz_core:error] [pid 67073:tid 67144] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:33.309867 2026] [authz_core:error] [pid 67073:tid 67144] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:33.325501 2026] [security2:error] [pid 67073:tid 67212] [client 68.221.73.131:61300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAdfcmepr5_nHgLbNEMQAAAhs"]
[Tue Aug 18 12:55:33.356174 2026] [security2:error] [pid 66623:tid 66827] [client 68.155.154.236:16261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/kopyw.php"] [unique_id "aoSAddO5rbWdOArH04KE4wAAAUc"]
[Tue Aug 18 12:55:33.366802 2026] [security2:error] [pid 66623:tid 66875] [client 4.232.151.198:19957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/404.php"] [unique_id "aoSAddO5rbWdOArH04KE5AAAAXc"]
[Tue Aug 18 12:55:33.367315 2026] [security2:error] [pid 67073:tid 67272] [client 20.48.236.86:16281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/nox.php"] [unique_id "aoSAdfcmepr5_nHgLbNEMgAAAlc"]
[Tue Aug 18 12:55:33.407382 2026] [security2:error] [pid 66623:tid 66797] [client 20.100.169.31:31442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/about.php"] [unique_id "aoSAddO5rbWdOArH04KE5QAAASk"]
[Tue Aug 18 12:55:33.411838 2026] [security2:error] [pid 67073:tid 67141] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/wy.php"] [unique_id "aoSAdfcmepr5_nHgLbNENgACMEE"]
[Tue Aug 18 12:55:33.433398 2026] [security2:error] [pid 67073:tid 67236] [client 20.104.85.180:7938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/tes.php"] [unique_id "aoSAdfcmepr5_nHgLbNEOAAAAjM"]
[Tue Aug 18 12:55:33.472275 2026] [security2:error] [pid 66623:tid 66785] [client 74.248.136.165:10062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/66.php"] [unique_id "aoSAddO5rbWdOArH04KE5gAAAR0"]
[Tue Aug 18 12:55:33.498708 2026] [security2:error] [pid 67073:tid 67302] [client 52.139.47.57:19914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/live.php"] [unique_id "aoSAdfcmepr5_nHgLbNEPAAAAnU"]
[Tue Aug 18 12:55:33.505464 2026] [security2:error] [pid 66623:tid 66806] [client 74.248.130.103:38673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/geck.php"] [unique_id "aoSAddO5rbWdOArH04KE5wAAATI"]
[Tue Aug 18 12:55:33.537715 2026] [security2:error] [pid 66623:tid 66852] [client 20.116.17.175:57657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/fine.php"] [unique_id "aoSAddO5rbWdOArH04KE6AAAAWA"]
[Tue Aug 18 12:55:33.542588 2026] [security2:error] [pid 66623:tid 66879] [client 52.173.121.69:16501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSAddO5rbWdOArH04KE6QAAAXs"]
[Tue Aug 18 12:55:33.556188 2026] [security2:error] [pid 67073:tid 67229] [client 20.51.153.15:9129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/an.php"] [unique_id "aoSAdfcmepr5_nHgLbNEPwAAAiw"]
[Tue Aug 18 12:55:33.567424 2026] [security2:error] [pid 66623:tid 66863] [client 20.104.100.201:21486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-the.php"] [unique_id "aoSAddO5rbWdOArH04KE6gAAAWs"]
[Tue Aug 18 12:55:33.570387 2026] [security2:error] [pid 67073:tid 67230] [client 20.91.215.254:14272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSAdfcmepr5_nHgLbNEQAAAAi0"]
[Tue Aug 18 12:55:33.586662 2026] [security2:error] [pid 67073:tid 67216] [client 20.151.109.219:24876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/nf.php"] [unique_id "aoSAdfcmepr5_nHgLbNEQQAAAh8"]
[Tue Aug 18 12:55:33.592211 2026] [security2:error] [pid 66623:tid 66868] [client 20.171.51.14:58391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/lj.php"] [unique_id "aoSAddO5rbWdOArH04KE6wAAAXA"]
[Tue Aug 18 12:55:33.611213 2026] [authz_core:error] [pid 67073:tid 67096] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:33.611470 2026] [authz_core:error] [pid 67073:tid 67096] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:33.621858 2026] [security2:error] [pid 67073:tid 67084] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/f.php"] [unique_id "aoSAdfcmepr5_nHgLbNERgACJQg"]
[Tue Aug 18 12:55:33.624876 2026] [security2:error] [pid 66623:tid 66888] [client 20.251.48.93:64066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/sf.php"] [unique_id "aoSAddO5rbWdOArH04KE7AAAAYQ"]
[Tue Aug 18 12:55:33.637678 2026] [security2:error] [pid 66623:tid 66773] [client 20.163.43.14:4237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSAddO5rbWdOArH04KE7QAAARE"]
[Tue Aug 18 12:55:33.662598 2026] [security2:error] [pid 67073:tid 67225] [client 158.158.34.183:33539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/02.php"] [unique_id "aoSAdfcmepr5_nHgLbNERwAAAig"]
[Tue Aug 18 12:55:33.672644 2026] [security2:error] [pid 67073:tid 67254] [client 20.163.43.14:4441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/lv.php"] [unique_id "aoSAdfcmepr5_nHgLbNESAAAAkU"]
[Tue Aug 18 12:55:33.675822 2026] [security2:error] [pid 67073:tid 67207] [client 20.48.236.86:16285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/akismet.php"] [unique_id "aoSAdfcmepr5_nHgLbNESQAAAhY"]
[Tue Aug 18 12:55:33.691686 2026] [security2:error] [pid 67073:tid 67223] [client 132.196.61.152:61032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAdfcmepr5_nHgLbNETwAAAiY"]
[Tue Aug 18 12:55:33.696149 2026] [security2:error] [pid 67073:tid 67264] [client 4.223.164.152:54263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/admin.php"] [unique_id "aoSAdfcmepr5_nHgLbNEUAAAAk8"]
[Tue Aug 18 12:55:33.703741 2026] [security2:error] [pid 67073:tid 67206] [client 20.226.112.14:32203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "monroviaexport.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAdfcmepr5_nHgLbNEUQAAAhU"]
[Tue Aug 18 12:55:33.720321 2026] [security2:error] [pid 67073:tid 67286] [client 20.215.241.237:23280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAdfcmepr5_nHgLbNEUgAAAmU"]
[Tue Aug 18 12:55:33.751877 2026] [security2:error] [pid 66623:tid 66805] [client 68.221.73.131:61272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAddO5rbWdOArH04KE7wAAATE"]
[Tue Aug 18 12:55:33.755640 2026] [security2:error] [pid 66623:tid 66877] [client 172.182.200.96:14228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAddO5rbWdOArH04KE8AAAAXk"]
[Tue Aug 18 12:55:33.756417 2026] [security2:error] [pid 66623:tid 66802] [client 20.226.6.191:64002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/flower.php"] [unique_id "aoSAddO5rbWdOArH04KE8QAAAS4"]
[Tue Aug 18 12:55:33.779440 2026] [security2:error] [pid 67073:tid 67210] [client 20.104.85.180:8041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/files/index.php"] [unique_id "aoSAdfcmepr5_nHgLbNEVgAAAhk"]
[Tue Aug 18 12:55:33.781073 2026] [security2:error] [pid 67073:tid 67305] [client 52.238.210.254:8944] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-includes/js/crop/"] [unique_id "aoSAdfcmepr5_nHgLbNEVwAAAng"]
[Tue Aug 18 12:55:33.826673 2026] [security2:error] [pid 67073:tid 67319] [client 135.225.75.187:62031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/0.php"] [unique_id "aoSAdfcmepr5_nHgLbNEWgAAAoY"]
[Tue Aug 18 12:55:33.848919 2026] [security2:error] [pid 67073:tid 67296] [client 20.104.100.201:21481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSAdfcmepr5_nHgLbNEWwAAAm8"]
[Tue Aug 18 12:55:33.856784 2026] [security2:error] [pid 66623:tid 66781] [client 20.51.153.15:9207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/57.php"] [unique_id "aoSAddO5rbWdOArH04KE8wAAARk"]
[Tue Aug 18 12:55:33.863129 2026] [security2:error] [pid 66623:tid 66881] [client 20.171.51.14:33721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/xn.php"] [unique_id "aoSAddO5rbWdOArH04KE9AAAAX0"]
[Tue Aug 18 12:55:33.869021 2026] [security2:error] [pid 67073:tid 67263] [client 4.232.151.198:42190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/666.php"] [unique_id "aoSAdfcmepr5_nHgLbNEXQAAAk4"]
[Tue Aug 18 12:55:33.896326 2026] [security2:error] [pid 67073:tid 67327] [client 74.248.136.165:43667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/g.php"] [unique_id "aoSAdfcmepr5_nHgLbNEYQAAAo4"]
[Tue Aug 18 12:55:33.903465 2026] [security2:error] [pid 67073:tid 67271] [client 20.250.13.23:24868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/aa.php"] [unique_id "aoSAdfcmepr5_nHgLbNEYgAAAlY"]
[Tue Aug 18 12:55:33.908592 2026] [security2:error] [pid 66623:tid 66792] [client 20.91.215.254:27403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/abcd.php"] [unique_id "aoSAddO5rbWdOArH04KE9QAAASQ"]
[Tue Aug 18 12:55:33.960791 2026] [security2:error] [pid 67073:tid 67099] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/30.php"] [unique_id "aoSAdfcmepr5_nHgLbNEYwACHRc"]
[Tue Aug 18 12:55:33.980746 2026] [security2:error] [pid 67073:tid 67267] [client 20.151.109.219:64965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/xv.php"] [unique_id "aoSAdfcmepr5_nHgLbNEZgAAAlI"]
[Tue Aug 18 12:55:34.005785 2026] [security2:error] [pid 66623:tid 66776] [client 20.48.236.86:16264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/admin.php"] [unique_id "aoSAdtO5rbWdOArH04KE9gAAARQ"]
[Tue Aug 18 12:55:34.010096 2026] [security2:error] [pid 67073:tid 67224] [client 20.100.169.31:45603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAdvcmepr5_nHgLbNEZwAAAic"]
[Tue Aug 18 12:55:34.026915 2026] [security2:error] [pid 67073:tid 67320] [client 20.163.43.14:4250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAdvcmepr5_nHgLbNEaQAAAoc"]
[Tue Aug 18 12:55:34.036713 2026] [security2:error] [pid 67073:tid 67261] [client 20.100.169.31:33098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSAdvcmepr5_nHgLbNEagAAAkw"]
[Tue Aug 18 12:55:34.054243 2026] [security2:error] [pid 67073:tid 67323] [client 20.65.69.59:3707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/fraie1p4.php"] [unique_id "aoSAdvcmepr5_nHgLbNEawAAAoo"]
[Tue Aug 18 12:55:34.058607 2026] [security2:error] [pid 66623:tid 66857] [client 20.171.51.14:58827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/kh.php"] [unique_id "aoSAdtO5rbWdOArH04KE9wAAAWU"]
[Tue Aug 18 12:55:34.065188 2026] [security2:error] [pid 67073:tid 67295] [client 20.226.6.191:6607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/404.php"] [unique_id "aoSAdvcmepr5_nHgLbNEbAAAAm4"]
[Tue Aug 18 12:55:34.079841 2026] [security2:error] [pid 67073:tid 67276] [client 20.104.85.180:8031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAdvcmepr5_nHgLbNEbgAAAls"]
[Tue Aug 18 12:55:34.094400 2026] [security2:error] [pid 66623:tid 66819] [client 52.173.121.69:17954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSAdtO5rbWdOArH04KE-AAAAT8"]
[Tue Aug 18 12:55:34.124494 2026] [security2:error] [pid 66623:tid 66883] [client 4.223.164.152:54268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/edit.php"] [unique_id "aoSAdtO5rbWdOArH04KE-QAAAX8"]
[Tue Aug 18 12:55:34.126771 2026] [security2:error] [pid 67073:tid 67326] [client 20.104.100.201:58467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/xwpg.php"] [unique_id "aoSAdvcmepr5_nHgLbNEcAAAAo0"]
[Tue Aug 18 12:55:34.139414 2026] [security2:error] [pid 67073:tid 67290] [client 20.51.153.15:8808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/yw.php"] [unique_id "aoSAdvcmepr5_nHgLbNEcgAAAmk"]
[Tue Aug 18 12:55:34.146810 2026] [security2:error] [pid 67073:tid 67313] [client 172.182.200.96:14245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAdvcmepr5_nHgLbNEdQAAAoA"]
[Tue Aug 18 12:55:34.177376 2026] [security2:error] [pid 67073:tid 67246] [client 20.163.43.14:4371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/new.php"] [unique_id "aoSAdvcmepr5_nHgLbNEdgAAAj0"]
[Tue Aug 18 12:55:34.192331 2026] [security2:error] [pid 67073:tid 67272] [client 20.226.6.191:56255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/13.php"] [unique_id "aoSAdvcmepr5_nHgLbNEdwAAAlc"]
[Tue Aug 18 12:55:34.205369 2026] [security2:error] [pid 67073:tid 67142] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/pu.php"] [unique_id "aoSAdvcmepr5_nHgLbNEeAACiEI"]
[Tue Aug 18 12:55:34.212288 2026] [authz_core:error] [pid 67073:tid 67147] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:34.212550 2026] [authz_core:error] [pid 67073:tid 67147] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:34.215270 2026] [security2:error] [pid 67073:tid 67268] [client 213.35.127.232:61655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAdvcmepr5_nHgLbNEegAAAlM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:34.255609 2026] [security2:error] [pid 66623:tid 66832] [client 74.248.130.103:14449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/biufile.php"] [unique_id "aoSAdtO5rbWdOArH04KE-gAAAUw"]
[Tue Aug 18 12:55:34.296708 2026] [security2:error] [pid 67073:tid 67238] [client 20.42.19.40:2201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSAdvcmepr5_nHgLbNEfgAAAjU"]
[Tue Aug 18 12:55:34.313485 2026] [security2:error] [pid 67073:tid 67241] [client 74.248.136.165:38219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/x7.php"] [unique_id "aoSAdvcmepr5_nHgLbNEfwAAAjg"]
[Tue Aug 18 12:55:34.326594 2026] [security2:error] [pid 67073:tid 67255] [client 20.91.215.254:14290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/lite.php"] [unique_id "aoSAdvcmepr5_nHgLbNEgAAAAkY"]
[Tue Aug 18 12:55:34.331357 2026] [security2:error] [pid 67073:tid 67229] [client 20.116.17.175:57435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/loader.php"] [unique_id "aoSAdvcmepr5_nHgLbNEggAAAiw"]
[Tue Aug 18 12:55:34.334394 2026] [security2:error] [pid 67073:tid 67218] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdvcmepr5_nHgLbNEewACIVg"]
[Tue Aug 18 12:55:34.343043 2026] [security2:error] [pid 66623:tid 66825] [client 20.151.109.219:59744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/mx.php"] [unique_id "aoSAdtO5rbWdOArH04KE-wAAAUU"]
[Tue Aug 18 12:55:34.358851 2026] [security2:error] [pid 67073:tid 67277] [client 20.48.236.86:16350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/ajax.php"] [unique_id "aoSAdvcmepr5_nHgLbNEhAAAAlw"]
[Tue Aug 18 12:55:34.365538 2026] [security2:error] [pid 67073:tid 67285] [client 68.221.73.131:61293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/xx.php"] [unique_id "aoSAdvcmepr5_nHgLbNEhwAAAmQ"]
[Tue Aug 18 12:55:34.368197 2026] [security2:error] [pid 67073:tid 67234] [client 20.104.85.180:8050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAdvcmepr5_nHgLbNEiAAAAjE"]
[Tue Aug 18 12:55:34.382893 2026] [security2:error] [pid 67073:tid 67306] [client 20.163.43.14:4323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/cah.php"] [unique_id "aoSAdvcmepr5_nHgLbNEiQAAAnk"]
[Tue Aug 18 12:55:34.400182 2026] [security2:error] [pid 66623:tid 66841] [client 52.139.47.57:16684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/bypass.php"] [unique_id "aoSAdtO5rbWdOArH04KE_AAAAVU"]
[Tue Aug 18 12:55:34.412828 2026] [security2:error] [pid 66623:tid 66860] [client 20.104.100.201:21452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/dex.php"] [unique_id "aoSAdtO5rbWdOArH04KE_gAAAWg"]
[Tue Aug 18 12:55:34.441156 2026] [security2:error] [pid 66623:tid 66767] [client 157.20.138.62:57984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdtO5rbWdOArH04KE_wAAAQs"]
[Tue Aug 18 12:55:34.441303 2026] [security2:error] [pid 66623:tid 66767] [client 157.20.138.62:57984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdtO5rbWdOArH04KE_wAAAQs"]
[Tue Aug 18 12:55:34.462736 2026] [security2:error] [pid 67073:tid 67223] [client 52.238.210.254:10194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-links-opml.php"] [unique_id "aoSAdvcmepr5_nHgLbNEjAAAAiY"]
[Tue Aug 18 12:55:34.487293 2026] [security2:error] [pid 67073:tid 67135] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ry.php"] [unique_id "aoSAdvcmepr5_nHgLbNEjQACFTs"]
[Tue Aug 18 12:55:34.488353 2026] [security2:error] [pid 66623:tid 66784] [client 132.196.61.152:60997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAdtO5rbWdOArH04KFAAAAARw"]
[Tue Aug 18 12:55:34.491257 2026] [security2:error] [pid 67073:tid 67308] [client 172.182.200.96:14260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSAdvcmepr5_nHgLbNEjwAAAns"]
[Tue Aug 18 12:55:34.505450 2026] [security2:error] [pid 67073:tid 67244] [client 20.226.6.191:38247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/cc.php"] [unique_id "aoSAdvcmepr5_nHgLbNEkAAAAjs"]
[Tue Aug 18 12:55:34.536439 2026] [security2:error] [pid 67073:tid 67283] [client 158.158.34.183:62215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/menu.php"] [unique_id "aoSAdvcmepr5_nHgLbNEkwAAAmI"]
[Tue Aug 18 12:55:34.537950 2026] [security2:error] [pid 66623:tid 66893] [client 20.51.153.15:9205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/qh.php"] [unique_id "aoSAdtO5rbWdOArH04KFAQAAAYk"]
[Tue Aug 18 12:55:34.559673 2026] [security2:error] [pid 67073:tid 67273] [client 74.248.133.44:16722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/theme.php"] [unique_id "aoSAdvcmepr5_nHgLbNElAAAAlg"]
[Tue Aug 18 12:55:34.560889 2026] [security2:error] [pid 67073:tid 67301] [client 20.163.43.14:4435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/222.php"] [unique_id "aoSAdvcmepr5_nHgLbNElQAAAnQ"]
[Tue Aug 18 12:55:34.564181 2026] [security2:error] [pid 67073:tid 67278] [client 4.223.164.152:54259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAdvcmepr5_nHgLbNElgAAAl0"]
[Tue Aug 18 12:55:34.638960 2026] [security2:error] [pid 67073:tid 67262] [client 20.48.236.86:16302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/abe.php"] [unique_id "aoSAdvcmepr5_nHgLbNEmgAAAk0"]
[Tue Aug 18 12:55:34.652779 2026] [security2:error] [pid 66623:tid 66876] [client 20.226.6.191:6586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-login.php"] [unique_id "aoSAdtO5rbWdOArH04KFAgAAAXg"]
[Tue Aug 18 12:55:34.679788 2026] [security2:error] [pid 67073:tid 67332] [client 20.100.169.31:3013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAdvcmepr5_nHgLbNEmwAAApM"]
[Tue Aug 18 12:55:34.680093 2026] [security2:error] [pid 67073:tid 67293] [client 20.171.51.14:43333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/jb.php"] [unique_id "aoSAdvcmepr5_nHgLbNEnAAAAmw"]
[Tue Aug 18 12:55:34.684055 2026] [security2:error] [pid 67073:tid 67134] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/pm.php"] [unique_id "aoSAdvcmepr5_nHgLbNEnQACbzo"]
[Tue Aug 18 12:55:34.685578 2026] [security2:error] [pid 67073:tid 67227] [client 20.104.100.201:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/xyn.php"] [unique_id "aoSAdvcmepr5_nHgLbNEngAAAio"]
[Tue Aug 18 12:55:34.701209 2026] [security2:error] [pid 67073:tid 67263] [client 68.155.154.236:16346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/zznmg.php"] [unique_id "aoSAdvcmepr5_nHgLbNEoAAAAk4"]
[Tue Aug 18 12:55:34.701236 2026] [security2:error] [pid 67073:tid 67265] [client 135.225.75.187:57882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/dom.php"] [unique_id "aoSAdvcmepr5_nHgLbNEoQAAAlA"]
[Tue Aug 18 12:55:34.709305 2026] [security2:error] [pid 67073:tid 67310] [client 20.151.109.219:59767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/45.php"] [unique_id "aoSAdvcmepr5_nHgLbNEogAAAn0"]
[Tue Aug 18 12:55:34.716109 2026] [security2:error] [pid 67073:tid 67327] [client 20.104.85.180:7280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAdvcmepr5_nHgLbNEowAAAo4"]
[Tue Aug 18 12:55:34.734097 2026] [security2:error] [pid 67073:tid 67330] [client 74.248.136.165:10074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/god.php"] [unique_id "aoSAdvcmepr5_nHgLbNEpAAAApE"]
[Tue Aug 18 12:55:34.734118 2026] [security2:error] [pid 67073:tid 67231] [client 20.116.17.175:57624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/zero.php"] [unique_id "aoSAdvcmepr5_nHgLbNEpQAAAi4"]
[Tue Aug 18 12:55:34.737041 2026] [security2:error] [pid 67073:tid 67249] [client 20.205.121.237:5081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAdvcmepr5_nHgLbNEpgAAAkA"]
[Tue Aug 18 12:55:34.741662 2026] [security2:error] [pid 67073:tid 67205] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdvcmepr5_nHgLbNEmQACFG8"]
[Tue Aug 18 12:55:34.752800 2026] [security2:error] [pid 67073:tid 67266] [client 20.171.51.14:29205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/47.php"] [unique_id "aoSAdvcmepr5_nHgLbNEpwAAAlE"]
[Tue Aug 18 12:55:34.754530 2026] [security2:error] [pid 67073:tid 67214] [client 20.65.98.162:52153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/sky.php"] [unique_id "aoSAdvcmepr5_nHgLbNEqAAAAh0"]
[Tue Aug 18 12:55:34.771597 2026] [security2:error] [pid 67073:tid 67220] [client 20.51.153.15:9194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/r.php"] [unique_id "aoSAdvcmepr5_nHgLbNEqgAAAiM"]
[Tue Aug 18 12:55:34.773319 2026] [security2:error] [pid 67073:tid 67315] [client 20.226.6.191:55797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAdvcmepr5_nHgLbNEqwAAAoI"]
[Tue Aug 18 12:55:34.803860 2026] [security2:error] [pid 67073:tid 67215] [client 20.91.215.254:27436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/kj.php"] [unique_id "aoSAdvcmepr5_nHgLbNErgAAAh4"]
[Tue Aug 18 12:55:34.818125 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:34.818577 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:34.818594 2026] [security2:error] [pid 67073:tid 67312] [client 74.248.130.103:14403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/dejavu.php"] [unique_id "aoSAdvcmepr5_nHgLbNEsAAAAn8"]
[Tue Aug 18 12:55:34.846702 2026] [security2:error] [pid 67073:tid 67295] [client 68.221.73.131:61204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/av.php"] [unique_id "aoSAdvcmepr5_nHgLbNEsQAAAm4"]
[Tue Aug 18 12:55:34.899809 2026] [security2:error] [pid 67073:tid 67290] [client 20.29.77.16:49227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/mandrill.php"] [unique_id "aoSAdvcmepr5_nHgLbNEswAAAmk"]
[Tue Aug 18 12:55:34.917065 2026] [security2:error] [pid 67073:tid 67259] [client 20.163.43.14:4379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/chosen.php"] [unique_id "aoSAdvcmepr5_nHgLbNEtAAAAko"]
[Tue Aug 18 12:55:34.928298 2026] [security2:error] [pid 67073:tid 67152] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/dr.php"] [unique_id "aoSAdvcmepr5_nHgLbNEtQACKUw"]
[Tue Aug 18 12:55:34.932475 2026] [security2:error] [pid 67073:tid 67287] [client 20.163.43.14:4313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/system_log.php"] [unique_id "aoSAdvcmepr5_nHgLbNEtgAAAmY"]
[Tue Aug 18 12:55:34.934678 2026] [security2:error] [pid 67073:tid 67291] [client 172.182.200.96:14256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSAdvcmepr5_nHgLbNEtwAAAmo"]
[Tue Aug 18 12:55:34.942299 2026] [security2:error] [pid 67073:tid 67246] [client 20.48.236.86:16321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/bs1.php"] [unique_id "aoSAdvcmepr5_nHgLbNEuAAAAj0"]
[Tue Aug 18 12:55:34.964612 2026] [security2:error] [pid 66623:tid 66850] [client 20.104.100.201:58899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAdtO5rbWdOArH04KFBQAAAV4"]
[Tue Aug 18 12:55:34.987611 2026] [security2:error] [pid 66623:tid 66813] [client 149.34.210.141:49712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAdtO5rbWdOArH04KFBgAAATk"]
[Tue Aug 18 12:55:35.004743 2026] [security2:error] [pid 67073:tid 67282] [client 20.91.215.254:14334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSAd_cmepr5_nHgLbNEvAAAAmE"]
[Tue Aug 18 12:55:35.014623 2026] [security2:error] [pid 67073:tid 67280] [client 4.223.164.152:37268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/inputs.php"] [unique_id "aoSAd_cmepr5_nHgLbNEvgAAAl8"]
[Tue Aug 18 12:55:35.029176 2026] [security2:error] [pid 67073:tid 67257] [client 20.151.109.219:59753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/wy.php"] [unique_id "aoSAd_cmepr5_nHgLbNEvwAAAkg"]
[Tue Aug 18 12:55:35.055712 2026] [security2:error] [pid 67073:tid 67238] [client 20.42.19.40:2738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSAd_cmepr5_nHgLbNEwQAAAjU"]
[Tue Aug 18 12:55:35.115506 2026] [security2:error] [pid 67073:tid 67222] [client 20.116.17.175:57652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/002.php"] [unique_id "aoSAd_cmepr5_nHgLbNEwgAAAiU"]
[Tue Aug 18 12:55:35.148518 2026] [security2:error] [pid 66623:tid 66880] [client 20.104.85.180:7995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/rip.php"] [unique_id "aoSAd9O5rbWdOArH04KFCAAAAXw"]
[Tue Aug 18 12:55:35.152419 2026] [security2:error] [pid 67073:tid 67232] [client 20.251.48.93:9748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/k.php"] [unique_id "aoSAd_cmepr5_nHgLbNExgAAAi8"]
[Tue Aug 18 12:55:35.154844 2026] [security2:error] [pid 67073:tid 67306] [client 52.139.47.57:16641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/lock360.php"] [unique_id "aoSAd_cmepr5_nHgLbNExwAAAnk"]
[Tue Aug 18 12:55:35.159185 2026] [security2:error] [pid 66623:tid 66804] [client 74.248.136.165:30915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ebahvhhh.php"] [unique_id "aoSAd9O5rbWdOArH04KFCQAAATA"]
[Tue Aug 18 12:55:35.166847 2026] [security2:error] [pid 67073:tid 67104] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ts.php"] [unique_id "aoSAd_cmepr5_nHgLbNEyQACRxw"]
[Tue Aug 18 12:55:35.222892 2026] [security2:error] [pid 66623:tid 66817] [client 213.202.253.4:49463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/userfuns.php"] [unique_id "aoSAd9O5rbWdOArH04KFCgAAAT0"], referer: www.google.com
[Tue Aug 18 12:55:35.226715 2026] [security2:error] [pid 67073:tid 67326] [client 213.35.127.232:61867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAd_cmepr5_nHgLbNEzAAAAo0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:35.241842 2026] [security2:error] [pid 66623:tid 66835] [client 20.104.100.201:58904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-good.php"] [unique_id "aoSAd9O5rbWdOArH04KFCwAAAU8"]
[Tue Aug 18 12:55:35.253199 2026] [security2:error] [pid 66623:tid 66813] [client 149.34.210.141:49712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAdtO5rbWdOArH04KFBgAAATk"]
[Tue Aug 18 12:55:35.253338 2026] [security2:error] [pid 67073:tid 67308] [client 20.51.153.15:8807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ev.php"] [unique_id "aoSAd_cmepr5_nHgLbNEzgAAAns"]
[Tue Aug 18 12:55:35.312882 2026] [security2:error] [pid 67073:tid 67240] [client 103.120.71.157:5300] ModSecurity: Warning. String match "408" at RESPONSE_STATUS. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "35"] [id "343434"] [rev "1"] [msg "Atomicorp.com WAF Rules: Client Connection dropped by Apache due to slow connection, possible Slowaris attack"] [severity "WARNING"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAaPcmepr5_nHgLbNAGQAAAjc"]
[Tue Aug 18 12:55:35.312938 2026] [security2:error] [pid 67073:tid 67240] [client 103.120.71.157:5300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "408"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAaPcmepr5_nHgLbNAGQAAAjc"]
[Tue Aug 18 12:55:35.314878 2026] [security2:error] [pid 67073:tid 67244] [client 172.182.200.96:14316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSAd_cmepr5_nHgLbNEzwAAAjs"]
[Tue Aug 18 12:55:35.321525 2026] [security2:error] [pid 67073:tid 67242] [client 20.48.236.86:16375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/yes.php"] [unique_id "aoSAd_cmepr5_nHgLbNE0AAAAjk"]
[Tue Aug 18 12:55:35.325944 2026] [security2:error] [pid 67073:tid 67210] [client 20.163.43.14:4356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/info.php"] [unique_id "aoSAd_cmepr5_nHgLbNE0gAAAhk"]
[Tue Aug 18 12:55:35.348238 2026] [security2:error] [pid 66623:tid 66780] [client 20.100.169.31:3022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/content.php"] [unique_id "aoSAd9O5rbWdOArH04KFDAAAARg"]
[Tue Aug 18 12:55:35.359330 2026] [security2:error] [pid 66623:tid 66766] [client 74.248.130.103:15402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/aaf.php"] [unique_id "aoSAd9O5rbWdOArH04KFDQAAAQo"]
[Tue Aug 18 12:55:35.369544 2026] [security2:error] [pid 66623:tid 66834] [client 20.151.109.219:21646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/f.php"] [unique_id "aoSAd9O5rbWdOArH04KFDgAAAU4"]
[Tue Aug 18 12:55:35.371457 2026] [security2:error] [pid 67073:tid 67235] [client 20.171.51.14:65101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/do.php"] [unique_id "aoSAd_cmepr5_nHgLbNE1QAAAjI"]
[Tue Aug 18 12:55:35.387473 2026] [security2:error] [pid 66623:tid 66884] [client 132.196.61.152:60299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/sky.php"] [unique_id "aoSAd9O5rbWdOArH04KFEAAAAYA"]
[Tue Aug 18 12:55:35.400887 2026] [security2:error] [pid 67073:tid 67301] [client 68.221.73.131:61232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/media.php"] [unique_id "aoSAd_cmepr5_nHgLbNE1gAAAnQ"]
[Tue Aug 18 12:55:35.426020 2026] [security2:error] [pid 67073:tid 67136] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/53.php"] [unique_id "aoSAd_cmepr5_nHgLbNE2QAChjw"]
[Tue Aug 18 12:55:35.432155 2026] [security2:error] [pid 67073:tid 67252] [client 20.171.51.14:62502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/payout.php"] [unique_id "aoSAd_cmepr5_nHgLbNE2gAAAkM"]
[Tue Aug 18 12:55:35.446244 2026] [security2:error] [pid 67073:tid 67332] [client 4.223.164.152:28523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/av.php"] [unique_id "aoSAd_cmepr5_nHgLbNE2wAAApM"]
[Tue Aug 18 12:55:35.461254 2026] [security2:error] [pid 67073:tid 67296] [client 20.215.241.237:24193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAd_cmepr5_nHgLbNE3AAAAm8"]
[Tue Aug 18 12:55:35.509394 2026] [security2:error] [pid 67073:tid 67271] [client 20.163.43.14:4298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAd_cmepr5_nHgLbNE3wAAAlY"]
[Tue Aug 18 12:55:35.516783 2026] [security2:error] [pid 67073:tid 67330] [client 135.225.75.187:62051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/bb.php"] [unique_id "aoSAd_cmepr5_nHgLbNE4QAAApE"]
[Tue Aug 18 12:55:35.520187 2026] [security2:error] [pid 67073:tid 67249] [client 20.104.100.201:58439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wmore1.php"] [unique_id "aoSAd_cmepr5_nHgLbNE4gAAAkA"]
[Tue Aug 18 12:55:35.522980 2026] [security2:error] [pid 67073:tid 67325] [client 147.224.249.133:61068] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www2.lazzarevestimentos.com.br"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "aoSAd_cmepr5_nHgLbNE4wAAAow"]
[Tue Aug 18 12:55:35.524691 2026] [autoindex:error] [pid 67073:tid 67231] [client 20.104.85.180:8003] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:35.566555 2026] [security2:error] [pid 67073:tid 67267] [client 20.42.19.40:1363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/gg.php"] [unique_id "aoSAd_cmepr5_nHgLbNE5QAAAlI"]
[Tue Aug 18 12:55:35.571325 2026] [security2:error] [pid 66623:tid 66801] [client 4.232.151.198:35346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/wk/index.php"] [unique_id "aoSAd9O5rbWdOArH04KFEQAAAS0"]
[Tue Aug 18 12:55:35.576136 2026] [security2:error] [pid 67073:tid 67270] [client 20.91.215.254:27438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/languages.php"] [unique_id "aoSAd_cmepr5_nHgLbNE5wAAAlU"]
[Tue Aug 18 12:55:35.576706 2026] [security2:error] [pid 67073:tid 67220] [client 74.248.136.165:9940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/8.php"] [unique_id "aoSAd_cmepr5_nHgLbNE6AAAAiM"]
[Tue Aug 18 12:55:35.579823 2026] [security2:error] [pid 67073:tid 67224] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/nine2code.php"] [unique_id "aoSAd_cmepr5_nHgLbNE6wAAAic"]
[Tue Aug 18 12:55:35.599529 2026] [security2:error] [pid 67073:tid 67219] [client 52.238.210.254:8257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/ioxi-o.php"] [unique_id "aoSAd_cmepr5_nHgLbNE8AAAAiI"]
[Tue Aug 18 12:55:35.646851 2026] [security2:error] [pid 67073:tid 67275] [client 20.48.236.86:16314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/go.php"] [unique_id "aoSAd_cmepr5_nHgLbNE9QAAAlo"]
[Tue Aug 18 12:55:35.662000 2026] [security2:error] [pid 67073:tid 67293] [client 20.91.215.254:14277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSAd_cmepr5_nHgLbNE-AAAAmw"]
[Tue Aug 18 12:55:35.664075 2026] [security2:error] [pid 67073:tid 67208] [client 172.202.39.151:50220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAd_cmepr5_nHgLbNE-QAAAhc"]
[Tue Aug 18 12:55:35.670577 2026] [security2:error] [pid 67073:tid 67269] [client 172.182.200.96:14217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSAd_cmepr5_nHgLbNE-wAAAlQ"]
[Tue Aug 18 12:55:35.712308 2026] [security2:error] [pid 67073:tid 67146] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/lq.php"] [unique_id "aoSAd_cmepr5_nHgLbNE_wACZkY"]
[Tue Aug 18 12:55:35.716499 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:35.716824 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:35.717713 2026] [security2:error] [pid 67073:tid 67291] [client 20.226.56.190:52074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/vp.php"] [unique_id "aoSAd_cmepr5_nHgLbNFAAAAAmo"]
[Tue Aug 18 12:55:35.739957 2026] [security2:error] [pid 67073:tid 67321] [client 20.151.109.219:53184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/30.php"] [unique_id "aoSAd_cmepr5_nHgLbNFAQAAAog"]
[Tue Aug 18 12:55:35.784146 2026] [security2:error] [pid 66623:tid 66891] [client 52.173.121.69:24963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSAd9O5rbWdOArH04KFFAAAAYc"]
[Tue Aug 18 12:55:35.788176 2026] [security2:error] [pid 67073:tid 67292] [client 20.205.121.237:5083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/file-admin.php"] [unique_id "aoSAd_cmepr5_nHgLbNFBgAAAms"]
[Tue Aug 18 12:55:35.796344 2026] [security2:error] [pid 67073:tid 67329] [client 20.104.100.201:21416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/special.php"] [unique_id "aoSAd_cmepr5_nHgLbNFBwAAApA"]
[Tue Aug 18 12:55:35.798854 2026] [security2:error] [pid 67073:tid 67261] [client 20.104.85.180:8003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAd_cmepr5_nHgLbNFCAAAAkw"]
[Tue Aug 18 12:55:35.826635 2026] [security2:error] [pid 66623:tid 66815] [client 20.42.19.40:9715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/class.php"] [unique_id "aoSAd9O5rbWdOArH04KFFQAAATs"]
[Tue Aug 18 12:55:35.908167 2026] [security2:error] [pid 67073:tid 67277] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/num.php"] [unique_id "aoSAd_cmepr5_nHgLbNFDgAAAlw"]
[Tue Aug 18 12:55:35.913278 2026] [security2:error] [pid 67073:tid 67285] [client 4.223.164.152:37287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAd_cmepr5_nHgLbNFDwAAAmQ"]
[Tue Aug 18 12:55:35.919612 2026] [security2:error] [pid 67073:tid 67222] [client 20.42.19.40:2693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSAd_cmepr5_nHgLbNFEAAAAiU"]
[Tue Aug 18 12:55:35.930403 2026] [security2:error] [pid 66623:tid 66878] [client 20.163.43.14:4466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAd9O5rbWdOArH04KFFgAAAXo"]
[Tue Aug 18 12:55:35.930962 2026] [security2:error] [pid 66623:tid 66829] [client 20.171.51.14:58374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/yw.php"] [unique_id "aoSAd9O5rbWdOArH04KFFwAAAUk"]
[Tue Aug 18 12:55:35.949318 2026] [security2:error] [pid 67073:tid 67306] [client 74.248.133.44:24705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSAd_cmepr5_nHgLbNFEQAAAnk"]
[Tue Aug 18 12:55:35.957696 2026] [security2:error] [pid 66623:tid 66814] [client 20.226.6.191:6591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAd9O5rbWdOArH04KFGAAAATo"]
[Tue Aug 18 12:55:35.974558 2026] [security2:error] [pid 67073:tid 67260] [client 20.100.169.31:31429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/index.php"] [unique_id "aoSAd_cmepr5_nHgLbNFEwAAAks"]
[Tue Aug 18 12:55:35.996799 2026] [security2:error] [pid 67073:tid 67254] [client 74.248.136.165:29118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/koiy.php"] [unique_id "aoSAd_cmepr5_nHgLbNFFgAAAkU"]
[Tue Aug 18 12:55:36.011243 2026] [security2:error] [pid 67073:tid 67264] [client 20.163.43.14:4348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAePcmepr5_nHgLbNFGAAAAk8"]
[Tue Aug 18 12:55:36.017757 2026] [authz_core:error] [pid 67073:tid 67101] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:36.018020 2026] [authz_core:error] [pid 67073:tid 67101] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:36.049132 2026] [security2:error] [pid 67073:tid 67081] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/you.php"] [unique_id "aoSAePcmepr5_nHgLbNFGQACFQU"]
[Tue Aug 18 12:55:36.058930 2026] [security2:error] [pid 67073:tid 67297] [client 147.224.249.133:61236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.249.224.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www2.lazzarevestimentos.com.br"] [uri "/wp-content/plugins/pods/init.php"] [unique_id "aoSAePcmepr5_nHgLbNFGgAAAnA"]
[Tue Aug 18 12:55:36.059589 2026] [security2:error] [pid 67073:tid 67308] [client 20.116.17.175:57644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/zxz.php"] [unique_id "aoSAePcmepr5_nHgLbNFHAAAAns"]
[Tue Aug 18 12:55:36.067931 2026] [security2:error] [pid 67073:tid 67253] [client 74.248.130.103:36850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/h02ugyh.php"] [unique_id "aoSAePcmepr5_nHgLbNFHQAAAkQ"]
[Tue Aug 18 12:55:36.072918 2026] [security2:error] [pid 67073:tid 67286] [client 20.104.100.201:58488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAePcmepr5_nHgLbNFHgAAAmU"]
[Tue Aug 18 12:55:36.090155 2026] [security2:error] [pid 66623:tid 66875] [client 20.104.85.180:8062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/moon.php"] [unique_id "aoSAeNO5rbWdOArH04KFGQAAAXc"]
[Tue Aug 18 12:55:36.092067 2026] [security2:error] [pid 67073:tid 67244] [client 52.139.47.57:16696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/majalahpro-core/lib/index.php"] [unique_id "aoSAePcmepr5_nHgLbNFHwAAAjs"]
[Tue Aug 18 12:55:36.092098 2026] [security2:error] [pid 67073:tid 67240] [client 20.42.19.40:9619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/flower.php"] [unique_id "aoSAePcmepr5_nHgLbNFIAAAAjc"]
[Tue Aug 18 12:55:36.095240 2026] [security2:error] [pid 66623:tid 66797] [client 172.182.200.96:14252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/first.php"] [unique_id "aoSAeNO5rbWdOArH04KFGgAAASk"]
[Tue Aug 18 12:55:36.110454 2026] [security2:error] [pid 67073:tid 67242] [client 20.226.6.191:64033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSAePcmepr5_nHgLbNFIQAAAjk"]
[Tue Aug 18 12:55:36.133826 2026] [security2:error] [pid 67073:tid 67214] [client 178.153.171.161:48961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAePcmepr5_nHgLbNFIgAAAh0"]
[Tue Aug 18 12:55:36.133956 2026] [security2:error] [pid 67073:tid 67214] [client 178.153.171.161:48961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAePcmepr5_nHgLbNFIgAAAh0"]
[Tue Aug 18 12:55:36.135766 2026] [security2:error] [pid 67073:tid 67305] [client 20.151.109.219:64980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/pu.php"] [unique_id "aoSAePcmepr5_nHgLbNFIwAAAng"]
[Tue Aug 18 12:55:36.155036 2026] [security2:error] [pid 67073:tid 67235] [client 20.65.69.59:3689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/pqr.php"] [unique_id "aoSAePcmepr5_nHgLbNFJQAAAjI"]
[Tue Aug 18 12:55:36.194893 2026] [security2:error] [pid 66623:tid 66785] [client 68.155.154.236:16331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/bhfnd.php"] [unique_id "aoSAeNO5rbWdOArH04KFHAAAAR0"]
[Tue Aug 18 12:55:36.204165 2026] [security2:error] [pid 66623:tid 66842] [client 68.221.73.131:61249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/images.php"] [unique_id "aoSAeNO5rbWdOArH04KFHQAAAVY"]
[Tue Aug 18 12:55:36.232091 2026] [security2:error] [pid 67073:tid 67263] [client 20.42.19.40:2224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSAePcmepr5_nHgLbNFKQAAAk4"]
[Tue Aug 18 12:55:36.237676 2026] [security2:error] [pid 67073:tid 67230] [client 213.35.127.232:62117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAePcmepr5_nHgLbNFKgAAAi0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:36.272808 2026] [security2:error] [pid 66623:tid 66775] [client 20.163.43.14:4400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSAeNO5rbWdOArH04KFHgAAARM"]
[Tue Aug 18 12:55:36.293306 2026] [security2:error] [pid 67073:tid 67302] [client 20.65.98.162:15535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/fz.php"] [unique_id "aoSAePcmepr5_nHgLbNFLQAAAnU"]
[Tue Aug 18 12:55:36.317766 2026] [authz_core:error] [pid 67073:tid 67102] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:36.318039 2026] [authz_core:error] [pid 67073:tid 67102] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:36.319218 2026] [security2:error] [pid 67073:tid 67330] [client 20.48.236.86:16366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/cof.php"] [unique_id "aoSAePcmepr5_nHgLbNFMQAAApE"]
[Tue Aug 18 12:55:36.328560 2026] [security2:error] [pid 67073:tid 67198] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ez.php"] [unique_id "aoSAePcmepr5_nHgLbNFMwACjHo"]
[Tue Aug 18 12:55:36.334876 2026] [security2:error] [pid 67073:tid 67266] [client 20.226.6.191:36403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/01.php"] [unique_id "aoSAePcmepr5_nHgLbNFOAAAAlE"]
[Tue Aug 18 12:55:36.336687 2026] [security2:error] [pid 67073:tid 67267] [client 20.42.19.40:9640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/motu.php"] [unique_id "aoSAePcmepr5_nHgLbNFOQAAAlI"]
[Tue Aug 18 12:55:36.343647 2026] [security2:error] [pid 67073:tid 67220] [client 20.29.77.16:27201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/main.php"] [unique_id "aoSAePcmepr5_nHgLbNFOgAAAiM"]
[Tue Aug 18 12:55:36.353451 2026] [security2:error] [pid 67073:tid 67281] [client 20.171.51.14:29241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/bh.php"] [unique_id "aoSAePcmepr5_nHgLbNFOwAAAmA"]
[Tue Aug 18 12:55:36.353757 2026] [security2:error] [pid 67073:tid 67315] [client 20.104.100.201:21451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/thoms.php"] [unique_id "aoSAePcmepr5_nHgLbNFPAAAAoI"]
[Tue Aug 18 12:55:36.365446 2026] [security2:error] [pid 66623:tid 66828] [client 20.104.85.180:8065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/cache.php"] [unique_id "aoSAeNO5rbWdOArH04KFHwAAAUg"]
[Tue Aug 18 12:55:36.368428 2026] [security2:error] [pid 67073:tid 67320] [client 4.223.164.152:46175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAePcmepr5_nHgLbNFPQAAAoc"]
[Tue Aug 18 12:55:36.380715 2026] [security2:error] [pid 66623:tid 66788] [client 20.163.43.14:4247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/abc.php"] [unique_id "aoSAeNO5rbWdOArH04KFIAAAASA"]
[Tue Aug 18 12:55:36.408974 2026] [security2:error] [pid 67073:tid 67323] [client 147.224.249.133:61377] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www2.lazzarevestimentos.com.br"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "aoSAePcmepr5_nHgLbNFPgAAAoo"]
[Tue Aug 18 12:55:36.412513 2026] [security2:error] [pid 67073:tid 67295] [client 74.248.136.165:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/iko.php"] [unique_id "aoSAePcmepr5_nHgLbNFPwAAAm4"]
[Tue Aug 18 12:55:36.418963 2026] [security2:error] [pid 66623:tid 66889] [client 20.91.215.254:14309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSAeNO5rbWdOArH04KFIQAAAYU"]
[Tue Aug 18 12:55:36.436000 2026] [security2:error] [pid 67073:tid 67289] [client 20.51.153.15:8827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/xs.php"] [unique_id "aoSAePcmepr5_nHgLbNFQgAAAmg"]
[Tue Aug 18 12:55:36.451126 2026] [security2:error] [pid 67073:tid 67208] [client 20.151.109.219:24851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ry.php"] [unique_id "aoSAePcmepr5_nHgLbNFQwAAAhc"]
[Tue Aug 18 12:55:36.495878 2026] [security2:error] [pid 67073:tid 67303] [client 20.251.48.93:62643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/82.php"] [unique_id "aoSAePcmepr5_nHgLbNFRAAAAnY"]
[Tue Aug 18 12:55:36.495878 2026] [security2:error] [pid 66623:tid 66888] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/odf7udtspqtpxzyxmw2rccdefault.php"] [unique_id "aoSAeNO5rbWdOArH04KFIgAAAYQ"]
[Tue Aug 18 12:55:36.504154 2026] [security2:error] [pid 67073:tid 67237] [client 52.238.210.254:8912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/0x.php"] [unique_id "aoSAePcmepr5_nHgLbNFRQAAAjQ"]
[Tue Aug 18 12:55:36.542159 2026] [security2:error] [pid 67073:tid 67246] [client 20.116.17.175:57612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/memberfuns.php"] [unique_id "aoSAePcmepr5_nHgLbNFRwAAAj0"]
[Tue Aug 18 12:55:36.563187 2026] [security2:error] [pid 67073:tid 67268] [client 20.91.215.254:20721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/nw.php"] [unique_id "aoSAePcmepr5_nHgLbNFSQAAAlM"]
[Tue Aug 18 12:55:36.563217 2026] [security2:error] [pid 67073:tid 67293] [client 66.249.70.4:43493] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.drogavilla.com.br"] [uri "/robots.txt"] [unique_id "aoSAePcmepr5_nHgLbNFSAAAAmw"]
[Tue Aug 18 12:55:36.570627 2026] [security2:error] [pid 67073:tid 67282] [client 135.225.75.187:55226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ok.php"] [unique_id "aoSAePcmepr5_nHgLbNFSgAAAmE"]
[Tue Aug 18 12:55:36.586014 2026] [security2:error] [pid 67073:tid 67248] [client 74.248.130.103:36839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/155.php"] [unique_id "aoSAePcmepr5_nHgLbNFSwAAAj8"]
[Tue Aug 18 12:55:36.588202 2026] [security2:error] [pid 66623:tid 66793] [client 172.182.200.96:13895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSAeNO5rbWdOArH04KFJAAAASU"]
[Tue Aug 18 12:55:36.599501 2026] [security2:error] [pid 66623:tid 66846] [client 20.42.19.40:9695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/404.php"] [unique_id "aoSAeNO5rbWdOArH04KFJgAAAVo"]
[Tue Aug 18 12:55:36.601207 2026] [security2:error] [pid 67073:tid 67215] [client 20.100.169.31:52437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSAePcmepr5_nHgLbNFTQAAAh4"]
[Tue Aug 18 12:55:36.615379 2026] [security2:error] [pid 66623:tid 66805] [client 20.163.43.14:4424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/k.php"] [unique_id "aoSAeNO5rbWdOArH04KFKAAAATE"]
[Tue Aug 18 12:55:36.627270 2026] [security2:error] [pid 67073:tid 67255] [client 20.104.100.201:21456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSAePcmepr5_nHgLbNFTwAAAkY"]
[Tue Aug 18 12:55:36.630594 2026] [security2:error] [pid 67073:tid 67250] [client 5.253.205.188:38544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/installdatadata_en_us.bak"] [unique_id "aoSAePcmepr5_nHgLbNFUAAAAkE"], referer: https://medihub.com.br/installdatadata_en_us.bak
[Tue Aug 18 12:55:36.634784 2026] [security2:error] [pid 67073:tid 67092] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/asus.php"] [unique_id "aoSAePcmepr5_nHgLbNFUQACIRA"]
[Tue Aug 18 12:55:36.644882 2026] [security2:error] [pid 67073:tid 67277] [client 20.104.85.180:43545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/gecko.php"] [unique_id "aoSAePcmepr5_nHgLbNFUgAAAlw"]
[Tue Aug 18 12:55:36.692156 2026] [autoindex:error] [pid 66623:tid 66848] [client 20.104.85.180:8001] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:36.732918 2026] [security2:error] [pid 66623:tid 66770] [client 20.163.43.14:4212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/akcc.php"] [unique_id "aoSAeNO5rbWdOArH04KFLAAAAQ4"]
[Tue Aug 18 12:55:36.742381 2026] [security2:error] [pid 66623:tid 66774] [client 20.226.6.191:6642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wso.php"] [unique_id "aoSAeNO5rbWdOArH04KFLQAAARI"]
[Tue Aug 18 12:55:36.748407 2026] [security2:error] [pid 67073:tid 67313] [client 147.224.249.133:61489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.249.224.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www2.lazzarevestimentos.com.br"] [uri "/wp-content/plugins/pods/init.php"] [unique_id "aoSAePcmepr5_nHgLbNFVwAAAoA"]
[Tue Aug 18 12:55:36.782538 2026] [security2:error] [pid 67073:tid 67311] [client 68.221.73.131:61206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/mac.php"] [unique_id "aoSAePcmepr5_nHgLbNFWQAAAn4"]
[Tue Aug 18 12:55:36.801702 2026] [security2:error] [pid 67073:tid 67253] [client 132.196.61.152:61055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/file5.php"] [unique_id "aoSAePcmepr5_nHgLbNFWwAAAkQ"]
[Tue Aug 18 12:55:36.805015 2026] [security2:error] [pid 67073:tid 67286] [client 4.223.164.152:37311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-blog.php"] [unique_id "aoSAePcmepr5_nHgLbNFXAAAAmU"]
[Tue Aug 18 12:55:36.806729 2026] [security2:error] [pid 67073:tid 67240] [client 20.151.109.219:64960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/pm.php"] [unique_id "aoSAePcmepr5_nHgLbNFXQAAAjc"]
[Tue Aug 18 12:55:36.820155 2026] [security2:error] [pid 66623:tid 66867] [client 4.232.151.198:37352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/ws54.php"] [unique_id "aoSAeNO5rbWdOArH04KFLgAAAW8"]
[Tue Aug 18 12:55:36.830066 2026] [security2:error] [pid 66623:tid 66870] [client 74.248.136.165:28641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/raw.php"] [unique_id "aoSAeNO5rbWdOArH04KFLwAAAXI"]
[Tue Aug 18 12:55:36.851754 2026] [security2:error] [pid 67073:tid 67300] [client 20.42.19.40:9647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/lite.php"] [unique_id "aoSAePcmepr5_nHgLbNFXwAAAnM"]
[Tue Aug 18 12:55:36.865964 2026] [security2:error] [pid 67073:tid 67287] [client 20.205.121.237:4119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/file.php"] [unique_id "aoSAePcmepr5_nHgLbNFYQAAAmY"]
[Tue Aug 18 12:55:36.898818 2026] [security2:error] [pid 66623:tid 66776] [client 20.104.100.201:21484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/root.php"] [unique_id "aoSAeNO5rbWdOArH04KFMAAAARQ"]
[Tue Aug 18 12:55:36.904878 2026] [security2:error] [pid 67073:tid 67199] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/22.php"] [unique_id "aoSAePcmepr5_nHgLbNFYwACYns"]
[Tue Aug 18 12:55:36.953217 2026] [security2:error] [pid 67073:tid 67252] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAePcmepr5_nHgLbNFZQAAAkM"]
[Tue Aug 18 12:55:37.015497 2026] [security2:error] [pid 67073:tid 67326] [client 172.182.200.96:14324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSAefcmepr5_nHgLbNFaAAAAo0"]
[Tue Aug 18 12:55:37.049992 2026] [security2:error] [pid 67073:tid 67284] [client 20.100.169.31:38082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/p.php"] [unique_id "aoSAefcmepr5_nHgLbNFaQAAAmM"]
[Tue Aug 18 12:55:37.073560 2026] [security2:error] [pid 67073:tid 67214] [client 20.91.215.254:24648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAefcmepr5_nHgLbNFawAAAh0"]
[Tue Aug 18 12:55:37.074098 2026] [security2:error] [pid 67073:tid 67302] [client 20.215.241.237:31694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAefcmepr5_nHgLbNFbAAAAnU"]
[Tue Aug 18 12:55:37.085809 2026] [security2:error] [pid 66623:tid 66824] [client 20.226.6.191:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/lv.php"] [unique_id "aoSAedO5rbWdOArH04KFNQAAAUQ"]
[Tue Aug 18 12:55:37.092050 2026] [security2:error] [pid 66623:tid 66777] [client 20.116.17.175:57625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/aa.php"] [unique_id "aoSAedO5rbWdOArH04KFNgAAARU"]
[Tue Aug 18 12:55:37.095986 2026] [security2:error] [pid 66623:tid 66832] [client 20.42.19.40:9642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/lock360.php"] [unique_id "aoSAedO5rbWdOArH04KFNwAAAUw"]
[Tue Aug 18 12:55:37.113855 2026] [security2:error] [pid 67073:tid 67325] [client 20.226.6.191:6646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/sf.php"] [unique_id "aoSAefcmepr5_nHgLbNFbwAAAow"]
[Tue Aug 18 12:55:37.119770 2026] [security2:error] [pid 66623:tid 66854] [client 20.163.43.14:4437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/403.php"] [unique_id "aoSAedO5rbWdOArH04KFOAAAAWI"]
[Tue Aug 18 12:55:37.143981 2026] [security2:error] [pid 67073:tid 67084] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/zs.php"] [unique_id "aoSAefcmepr5_nHgLbNFcQACFAg"]
[Tue Aug 18 12:55:37.164987 2026] [security2:error] [pid 67073:tid 67267] [client 74.248.130.103:15362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/ops.php"] [unique_id "aoSAefcmepr5_nHgLbNFcwAAAlI"]
[Tue Aug 18 12:55:37.167090 2026] [security2:error] [pid 67073:tid 67324] [client 20.151.109.219:45727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/dr.php"] [unique_id "aoSAefcmepr5_nHgLbNFdAAAAos"]
[Tue Aug 18 12:55:37.173830 2026] [security2:error] [pid 67073:tid 67270] [client 20.104.100.201:21493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/fpwch.php"] [unique_id "aoSAefcmepr5_nHgLbNFdQAAAlU"]
[Tue Aug 18 12:55:37.175134 2026] [security2:error] [pid 67073:tid 67297] [client 52.139.47.57:9053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/pwnd/as.php"] [unique_id "aoSAefcmepr5_nHgLbNFdgAAAnA"]
[Tue Aug 18 12:55:37.198371 2026] [security2:error] [pid 67073:tid 67312] [client 20.163.43.14:4346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wk/index.php"] [unique_id "aoSAefcmepr5_nHgLbNFewAAAn8"]
[Tue Aug 18 12:55:37.211392 2026] [security2:error] [pid 67073:tid 67331] [client 160.120.140.123:59025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAefcmepr5_nHgLbNFfAAAApI"]
[Tue Aug 18 12:55:37.211481 2026] [security2:error] [pid 67073:tid 67331] [client 160.120.140.123:59025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAefcmepr5_nHgLbNFfAAAApI"]
[Tue Aug 18 12:55:37.216097 2026] [security2:error] [pid 67073:tid 67281] [client 192.141.172.134:58132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAefcmepr5_nHgLbNFfgAAAmA"]
[Tue Aug 18 12:55:37.216185 2026] [security2:error] [pid 67073:tid 67281] [client 192.141.172.134:58132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAefcmepr5_nHgLbNFfgAAAmA"]
[Tue Aug 18 12:55:37.220496 2026] [authz_core:error] [pid 67073:tid 67154] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:37.220748 2026] [authz_core:error] [pid 67073:tid 67154] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:37.237548 2026] [security2:error] [pid 67073:tid 67292] [client 85.154.68.202:64384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAefcmepr5_nHgLbNFfwAAAms"]
[Tue Aug 18 12:55:37.237662 2026] [security2:error] [pid 67073:tid 67292] [client 85.154.68.202:64384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAefcmepr5_nHgLbNFfwAAAms"]
[Tue Aug 18 12:55:37.246809 2026] [security2:error] [pid 67073:tid 67239] [client 52.238.210.254:8897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/222.php"] [unique_id "aoSAefcmepr5_nHgLbNFgAAAAjY"]
[Tue Aug 18 12:55:37.247132 2026] [security2:error] [pid 67073:tid 67275] [client 74.248.136.165:30924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/05.php"] [unique_id "aoSAefcmepr5_nHgLbNFgQAAAlo"]
[Tue Aug 18 12:55:37.248340 2026] [security2:error] [pid 67073:tid 67202] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.env"] [unique_id "aoSAefcmepr5_nHgLbNFggACaH4"]
[Tue Aug 18 12:55:37.253527 2026] [security2:error] [pid 67073:tid 67208] [client 4.223.164.152:28509] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/js/jquery/"] [unique_id "aoSAefcmepr5_nHgLbNFhAAAAhc"]
[Tue Aug 18 12:55:37.257744 2026] [security2:error] [pid 67073:tid 67280] [client 213.35.127.232:62355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAefcmepr5_nHgLbNFgwAAAl8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:37.264481 2026] [security2:error] [pid 67073:tid 67230] [client 20.100.169.31:2464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSAefcmepr5_nHgLbNFhgAAAi0"]
[Tue Aug 18 12:55:37.283877 2026] [security2:error] [pid 66623:tid 66795] [client 68.221.73.131:61186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/ops.php"] [unique_id "aoSAedO5rbWdOArH04KFOQAAASc"]
[Tue Aug 18 12:55:37.287532 2026] [security2:error] [pid 67073:tid 67217] [client 158.158.34.183:25695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/spip.php"] [unique_id "aoSAefcmepr5_nHgLbNFiAAAAiA"]
[Tue Aug 18 12:55:37.326323 2026] [security2:error] [pid 66623:tid 66825] [client 20.91.215.254:27413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/lofmebwd.php"] [unique_id "aoSAedO5rbWdOArH04KFOgAAAUU"]
[Tue Aug 18 12:55:37.352249 2026] [security2:error] [pid 67073:tid 67321] [client 135.225.75.187:62021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp9.php"] [unique_id "aoSAefcmepr5_nHgLbNFiwAAAog"]
[Tue Aug 18 12:55:37.358922 2026] [security2:error] [pid 67073:tid 67274] [client 20.100.169.31:8068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/404.php"] [unique_id "aoSAefcmepr5_nHgLbNFjAAAAlk"]
[Tue Aug 18 12:55:37.366803 2026] [security2:error] [pid 67073:tid 67114] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/iz.php"] [unique_id "aoSAefcmepr5_nHgLbNFjQACUyY"]
[Tue Aug 18 12:55:37.375474 2026] [security2:error] [pid 66623:tid 66885] [client 20.48.236.86:16300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/Engine.php"] [unique_id "aoSAedO5rbWdOArH04KFPAAAAYE"]
[Tue Aug 18 12:55:37.380414 2026] [security2:error] [pid 66623:tid 66893] [client 20.42.19.40:9700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSAedO5rbWdOArH04KFPQAAAYk"]
[Tue Aug 18 12:55:37.388890 2026] [security2:error] [pid 66623:tid 66768] [client 20.171.51.14:51812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/qh.php"] [unique_id "aoSAedO5rbWdOArH04KFPwAAAQw"]
[Tue Aug 18 12:55:37.454663 2026] [security2:error] [pid 67073:tid 67238] [client 20.104.100.201:21449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/mg.php"] [unique_id "aoSAefcmepr5_nHgLbNFkAAAAjU"]
[Tue Aug 18 12:55:37.455901 2026] [security2:error] [pid 67073:tid 67209] [client 103.82.26.211:60053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.26.82.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "massagemrelax.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSAefcmepr5_nHgLbNFkQAAAhg"]
[Tue Aug 18 12:55:37.493686 2026] [security2:error] [pid 66623:tid 66853] [client 20.116.17.175:57438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/echkm.php"] [unique_id "aoSAedO5rbWdOArH04KFQQAAAWE"]
[Tue Aug 18 12:55:37.513211 2026] [security2:error] [pid 67073:tid 67234] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAefcmepr5_nHgLbNFkgAAAjE"]
[Tue Aug 18 12:55:37.527784 2026] [authz_core:error] [pid 67073:tid 67103] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:37.528190 2026] [authz_core:error] [pid 67073:tid 67103] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:37.539881 2026] [security2:error] [pid 67073:tid 67222] [client 20.151.109.219:17576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ts.php"] [unique_id "aoSAefcmepr5_nHgLbNFlQAAAiU"]
[Tue Aug 18 12:55:37.542631 2026] [security2:error] [pid 67073:tid 67225] [client 20.226.6.191:6628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/index/function.php"] [unique_id "aoSAefcmepr5_nHgLbNFlgAAAig"]
[Tue Aug 18 12:55:37.548761 2026] [security2:error] [pid 66623:tid 66822] [client 20.163.43.14:4320] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.mabelini.com.br"] [uri "/1.php"] [unique_id "aoSAedO5rbWdOArH04KFQgAAAUI"]
[Tue Aug 18 12:55:37.548881 2026] [security2:error] [pid 66623:tid 66822] [client 20.163.43.14:4320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/1.php"] [unique_id "aoSAedO5rbWdOArH04KFQgAAAUI"]
[Tue Aug 18 12:55:37.565015 2026] [security2:error] [pid 67073:tid 67156] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/se.php"] [unique_id "aoSAefcmepr5_nHgLbNFmAACR1A"]
[Tue Aug 18 12:55:37.577605 2026] [security2:error] [pid 67073:tid 67206] [client 172.182.200.96:13913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAefcmepr5_nHgLbNFmQAAAhU"]
[Tue Aug 18 12:55:37.666328 2026] [security2:error] [pid 66623:tid 66809] [client 74.248.136.165:28621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/public/hi.php"] [unique_id "aoSAedO5rbWdOArH04KFRAAAATU"]
[Tue Aug 18 12:55:37.729395 2026] [security2:error] [pid 67073:tid 67233] [client 20.48.236.86:16223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/hehe.php"] [unique_id "aoSAefcmepr5_nHgLbNFngAAAjA"]
[Tue Aug 18 12:55:37.731219 2026] [security2:error] [pid 67073:tid 67305] [client 20.104.100.201:58472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/reop3.php"] [unique_id "aoSAefcmepr5_nHgLbNFnwAAAng"]
[Tue Aug 18 12:55:37.733080 2026] [security2:error] [pid 67073:tid 67309] [client 20.91.215.254:24657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoSAefcmepr5_nHgLbNFoAAAAnw"]
[Tue Aug 18 12:55:37.743041 2026] [security2:error] [pid 67073:tid 67235] [client 4.223.164.152:46173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAefcmepr5_nHgLbNFoQAAAjI"]
[Tue Aug 18 12:55:37.765032 2026] [security2:error] [pid 66623:tid 66813] [client 20.42.19.40:1344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-links-opml.php"] [unique_id "aoSAedO5rbWdOArH04KFRgAAATk"]
[Tue Aug 18 12:55:37.772894 2026] [security2:error] [pid 67073:tid 67236] [client 74.248.130.103:38686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/mac.php"] [unique_id "aoSAefcmepr5_nHgLbNFogAAAjM"]
[Tue Aug 18 12:55:37.809218 2026] [security2:error] [pid 67073:tid 67332] [client 20.171.51.14:33683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ct.php"] [unique_id "aoSAefcmepr5_nHgLbNFpAAAApM"]
[Tue Aug 18 12:55:37.810287 2026] [security2:error] [pid 67073:tid 67228] [client 52.238.210.254:10239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/aa.php"] [unique_id "aoSAefcmepr5_nHgLbNFpQAAAis"]
[Tue Aug 18 12:55:37.819251 2026] [security2:error] [pid 67073:tid 67229] [client 20.226.6.191:36400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/new.php"] [unique_id "aoSAefcmepr5_nHgLbNFqAAAAiw"]
[Tue Aug 18 12:55:37.844009 2026] [security2:error] [pid 67073:tid 67227] [client 202.46.68.84:10299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.68.46.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idealesquadriasivoti.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAefcmepr5_nHgLbNFqQAAAio"]
[Tue Aug 18 12:55:37.844135 2026] [security2:error] [pid 67073:tid 67227] [client 202.46.68.84:10299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "idealesquadriasivoti.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAefcmepr5_nHgLbNFqQAAAio"]
[Tue Aug 18 12:55:37.859205 2026] [security2:error] [pid 67073:tid 67144] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/vp.php"] [unique_id "aoSAefcmepr5_nHgLbNFrAACTkQ"]
[Tue Aug 18 12:55:37.866279 2026] [security2:error] [pid 66623:tid 66880] [client 20.100.169.31:31486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAedO5rbWdOArH04KFRwAAAXw"]
[Tue Aug 18 12:55:37.893851 2026] [security2:error] [pid 67073:tid 67279] [client 20.42.19.40:2179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/xmr.php"] [unique_id "aoSAefcmepr5_nHgLbNFrgAAAl4"]
[Tue Aug 18 12:55:37.900875 2026] [security2:error] [pid 67073:tid 67214] [client 20.163.43.14:4450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/gecko.php"] [unique_id "aoSAefcmepr5_nHgLbNFsAAAAh0"]
[Tue Aug 18 12:55:37.916534 2026] [security2:error] [pid 67073:tid 67271] [client 68.221.73.131:61188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/coffexium.php"] [unique_id "aoSAefcmepr5_nHgLbNFsgAAAlY"]
[Tue Aug 18 12:55:37.918228 2026] [security2:error] [pid 67073:tid 67330] [client 20.163.43.14:4182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSAefcmepr5_nHgLbNFswAAApE"]
[Tue Aug 18 12:55:37.923316 2026] [security2:error] [pid 66623:tid 66866] [client 157.51.166.53:58476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAedO5rbWdOArH04KFSQAAAW4"]
[Tue Aug 18 12:55:37.923429 2026] [security2:error] [pid 66623:tid 66866] [client 157.51.166.53:58476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAedO5rbWdOArH04KFSQAAAW4"]
[Tue Aug 18 12:55:37.926373 2026] [security2:error] [pid 67073:tid 67231] [client 20.151.109.219:12868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/53.php"] [unique_id "aoSAefcmepr5_nHgLbNFtQAAAi4"]
[Tue Aug 18 12:55:37.955971 2026] [security2:error] [pid 67073:tid 67270] [client 52.173.121.69:16485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSAefcmepr5_nHgLbNFtgAAAlU"]
[Tue Aug 18 12:55:37.956448 2026] [security2:error] [pid 67073:tid 67297] [client 172.182.200.96:13938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/blog/byp.php"] [unique_id "aoSAefcmepr5_nHgLbNFtwAAAnA"]
[Tue Aug 18 12:55:37.962036 2026] [security2:error] [pid 67073:tid 67224] [client 132.196.61.152:34770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/xyn.php"] [unique_id "aoSAefcmepr5_nHgLbNFugAAAic"]
[Tue Aug 18 12:55:37.962771 2026] [security2:error] [pid 67073:tid 67180] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.env.backup"] [unique_id "aoSAefcmepr5_nHgLbNFuQACI2g"]
[Tue Aug 18 12:55:37.977209 2026] [security2:error] [pid 67073:tid 67315] [client 20.116.17.175:57457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/domvf.php"] [unique_id "aoSAefcmepr5_nHgLbNFuwAAAoI"]
[Tue Aug 18 12:55:37.981539 2026] [security2:error] [pid 67073:tid 67112] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.env.bak"] [unique_id "aoSAefcmepr5_nHgLbNFvAACfyQ"]
[Tue Aug 18 12:55:38.001647 2026] [security2:error] [pid 67073:tid 67323] [client 20.42.19.40:1370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/.alf.php"] [unique_id "aoSAevcmepr5_nHgLbNFvwAAAoo"]
[Tue Aug 18 12:55:38.008799 2026] [security2:error] [pid 66623:tid 66812] [client 20.104.100.201:21483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/php5.php"] [unique_id "aoSAetO5rbWdOArH04KFSgAAATg"]
[Tue Aug 18 12:55:38.076710 2026] [security2:error] [pid 67073:tid 67280] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/media.php"] [unique_id "aoSAevcmepr5_nHgLbNFwAAAAl8"]
[Tue Aug 18 12:55:38.084321 2026] [security2:error] [pid 67073:tid 67213] [client 74.248.136.165:9931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/get.php"] [unique_id "aoSAevcmepr5_nHgLbNFwgAAAhw"]
[Tue Aug 18 12:55:38.122545 2026] [security2:error] [pid 67073:tid 67095] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ph.php"] [unique_id "aoSAevcmepr5_nHgLbNFxgACjxM"]
[Tue Aug 18 12:55:38.123130 2026] [security2:error] [pid 67073:tid 67129] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.env.old"] [unique_id "aoSAevcmepr5_nHgLbNFxQACajU"]
[Tue Aug 18 12:55:38.132448 2026] [authz_core:error] [pid 67073:tid 67110] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:38.132942 2026] [authz_core:error] [pid 67073:tid 67110] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:38.156419 2026] [security2:error] [pid 67073:tid 67293] [client 20.48.236.86:16220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/dkSUq.php"] [unique_id "aoSAevcmepr5_nHgLbNFyAAAAmw"]
[Tue Aug 18 12:55:38.189070 2026] [security2:error] [pid 67073:tid 67282] [client 4.223.164.152:46179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAevcmepr5_nHgLbNFygAAAmE"]
[Tue Aug 18 12:55:38.228416 2026] [security2:error] [pid 67073:tid 67261] [client 20.29.77.16:44777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/payout.php"] [unique_id "aoSAevcmepr5_nHgLbNFzAAAAkw"]
[Tue Aug 18 12:55:38.241795 2026] [security2:error] [pid 67073:tid 67248] [client 20.151.109.219:53187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/lq.php"] [unique_id "aoSAevcmepr5_nHgLbNFzQAAAj8"]
[Tue Aug 18 12:55:38.255345 2026] [security2:error] [pid 67073:tid 67290] [client 20.205.121.237:5111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAevcmepr5_nHgLbNFzgAAAmk"]
[Tue Aug 18 12:55:38.256835 2026] [security2:error] [pid 67073:tid 67255] [client 20.42.19.40:9707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/.trash7206/index.php"] [unique_id "aoSAevcmepr5_nHgLbNF0AAAAkY"]
[Tue Aug 18 12:55:38.279618 2026] [security2:error] [pid 67073:tid 67205] [client 213.35.127.232:62586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAevcmepr5_nHgLbNF0gAAAhQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:38.283450 2026] [security2:error] [pid 66623:tid 66849] [client 20.104.100.201:21387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/acp.php"] [unique_id "aoSAetO5rbWdOArH04KFSwAAAV0"]
[Tue Aug 18 12:55:38.305595 2026] [security2:error] [pid 67073:tid 67218] [client 20.251.48.93:56938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/dex.php"] [unique_id "aoSAevcmepr5_nHgLbNF1gAAAiE"]
[Tue Aug 18 12:55:38.349893 2026] [security2:error] [pid 66623:tid 66826] [client 20.226.6.191:7121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/edit.php"] [unique_id "aoSAetO5rbWdOArH04KFTAAAAUY"]
[Tue Aug 18 12:55:38.360050 2026] [security2:error] [pid 67073:tid 67245] [client 74.248.18.37:51363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/themes.php"] [unique_id "aoSAevcmepr5_nHgLbNF2AAAAjw"]
[Tue Aug 18 12:55:38.372200 2026] [security2:error] [pid 67073:tid 67152] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/s.php"] [unique_id "aoSAevcmepr5_nHgLbNF2QACZEw"]
[Tue Aug 18 12:55:38.373868 2026] [security2:error] [pid 67073:tid 67268] [client 52.139.47.57:44638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/rk2.php"] [unique_id "aoSAevcmepr5_nHgLbNF2gAAAlM"]
[Tue Aug 18 12:55:38.379437 2026] [security2:error] [pid 67073:tid 67225] [client 52.238.210.254:10173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/abcd.php"] [unique_id "aoSAevcmepr5_nHgLbNF2wAAAig"]
[Tue Aug 18 12:55:38.386376 2026] [security2:error] [pid 67073:tid 67306] [client 20.215.241.237:32475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/xx.php"] [unique_id "aoSAevcmepr5_nHgLbNF3AAAAnk"]
[Tue Aug 18 12:55:38.405968 2026] [security2:error] [pid 67073:tid 67313] [client 135.225.75.187:62924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ws59.php"] [unique_id "aoSAevcmepr5_nHgLbNF3gAAAoA"]
[Tue Aug 18 12:55:38.416576 2026] [security2:error] [pid 67073:tid 67308] [client 20.163.43.14:4330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAevcmepr5_nHgLbNF3wAAAns"]
[Tue Aug 18 12:55:38.427558 2026] [authz_core:error] [pid 67073:tid 67109] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:38.427826 2026] [authz_core:error] [pid 67073:tid 67109] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:38.431497 2026] [security2:error] [pid 67073:tid 67258] [client 20.163.43.14:4473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/aa.php"] [unique_id "aoSAevcmepr5_nHgLbNF4QAAAkk"]
[Tue Aug 18 12:55:38.434761 2026] [security2:error] [pid 67073:tid 67206] [client 68.221.73.131:61255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAevcmepr5_nHgLbNF4gAAAhU"]
[Tue Aug 18 12:55:38.446888 2026] [security2:error] [pid 67073:tid 67237] [client 20.226.56.190:31620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ph.php"] [unique_id "aoSAevcmepr5_nHgLbNF5QAAAjQ"]
[Tue Aug 18 12:55:38.460803 2026] [security2:error] [pid 67073:tid 67242] [client 172.182.200.96:14315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSAevcmepr5_nHgLbNF6AAAAjk"]
[Tue Aug 18 12:55:38.482296 2026] [security2:error] [pid 67073:tid 67314] [client 20.65.69.59:40554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/lmfi2.php"] [unique_id "aoSAevcmepr5_nHgLbNF6QAAAoE"]
[Tue Aug 18 12:55:38.489710 2026] [security2:error] [pid 67073:tid 67195] [remote 162.241.153.188:36300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.153.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naorar.com.br"] [uri "/wp-login.php"] [unique_id "aoSAevcmepr5_nHgLbNF6gACkHc"]
[Tue Aug 18 12:55:38.500365 2026] [security2:error] [pid 67073:tid 67241] [client 20.42.19.40:9684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSAevcmepr5_nHgLbNF6wAAAjg"]
[Tue Aug 18 12:55:38.502457 2026] [security2:error] [pid 67073:tid 67305] [client 20.91.215.254:20713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSAevcmepr5_nHgLbNF7AAAAng"]
[Tue Aug 18 12:55:38.503887 2026] [security2:error] [pid 66623:tid 66799] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/option.php"] [unique_id "aoSAetO5rbWdOArH04KFTQAAASs"]
[Tue Aug 18 12:55:38.505536 2026] [security2:error] [pid 67073:tid 67233] [client 74.248.136.165:44254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/rpk.php"] [unique_id "aoSAevcmepr5_nHgLbNF7QAAAjA"]
[Tue Aug 18 12:55:38.518662 2026] [security2:error] [pid 66623:tid 66811] [client 20.100.169.31:52421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSAetO5rbWdOArH04KFTgAAATc"]
[Tue Aug 18 12:55:38.533409 2026] [security2:error] [pid 66623:tid 66876] [client 4.232.151.198:42264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSAetO5rbWdOArH04KFTwAAAXg"]
[Tue Aug 18 12:55:38.555835 2026] [security2:error] [pid 67073:tid 67229] [client 20.104.100.201:21492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/yas.php"] [unique_id "aoSAevcmepr5_nHgLbNF8QAAAiw"]
[Tue Aug 18 12:55:38.575051 2026] [security2:error] [pid 67073:tid 67227] [client 20.116.17.175:57609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/red.php"] [unique_id "aoSAevcmepr5_nHgLbNF8wAAAio"]
[Tue Aug 18 12:55:38.593507 2026] [security2:error] [pid 67073:tid 67279] [client 20.151.109.219:53234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/you.php"] [unique_id "aoSAevcmepr5_nHgLbNF9gAAAl4"]
[Tue Aug 18 12:55:38.617459 2026] [security2:error] [pid 67073:tid 67211] [client 20.91.215.254:14316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/ku.php"] [unique_id "aoSAevcmepr5_nHgLbNF9wAAAho"]
[Tue Aug 18 12:55:38.634614 2026] [security2:error] [pid 67073:tid 67136] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/api/.env"] [unique_id "aoSAevcmepr5_nHgLbNF-QACizw"]
[Tue Aug 18 12:55:38.635668 2026] [security2:error] [pid 67073:tid 67120] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/uo.php"] [unique_id "aoSAevcmepr5_nHgLbNF-gACVSw"]
[Tue Aug 18 12:55:38.644094 2026] [security2:error] [pid 67073:tid 67159] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/config/.env"] [unique_id "aoSAevcmepr5_nHgLbNF-wACcFM"]
[Tue Aug 18 12:55:38.644923 2026] [security2:error] [pid 67073:tid 67165] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/backend/.env"] [unique_id "aoSAevcmepr5_nHgLbNF_AACcFk"]
[Tue Aug 18 12:55:38.651498 2026] [security2:error] [pid 67073:tid 67220] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/admin.php"] [unique_id "aoSAevcmepr5_nHgLbNF_gAAAiM"]
[Tue Aug 18 12:55:38.671557 2026] [security2:error] [pid 67073:tid 67219] [client 4.223.164.152:28487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/222.php"] [unique_id "aoSAevcmepr5_nHgLbNF_wAAAiI"]
[Tue Aug 18 12:55:38.690925 2026] [security2:error] [pid 67073:tid 67273] [client 20.65.98.162:29530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/clque.php"] [unique_id "aoSAevcmepr5_nHgLbNGAQAAAlg"]
[Tue Aug 18 12:55:38.694169 2026] [security2:error] [pid 67073:tid 67301] [client 20.100.169.31:38121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/php.php"] [unique_id "aoSAevcmepr5_nHgLbNGAwAAAnQ"]
[Tue Aug 18 12:55:38.710587 2026] [security2:error] [pid 67073:tid 67317] [client 20.48.236.86:16275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/qwas.php"] [unique_id "aoSAevcmepr5_nHgLbNGBAAAAoQ"]
[Tue Aug 18 12:55:38.733370 2026] [security2:error] [pid 66623:tid 66782] [client 20.226.6.191:32093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/222.php"] [unique_id "aoSAetO5rbWdOArH04KFUAAAARo"]
[Tue Aug 18 12:55:38.742067 2026] [security2:error] [pid 67073:tid 67230] [client 20.163.43.14:4229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/as.php"] [unique_id "aoSAevcmepr5_nHgLbNGCAAAAi0"]
[Tue Aug 18 12:55:38.747897 2026] [security2:error] [pid 67073:tid 67213] [client 20.171.51.14:58402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/r.php"] [unique_id "aoSAevcmepr5_nHgLbNGCQAAAhw"]
[Tue Aug 18 12:55:38.774211 2026] [security2:error] [pid 67073:tid 67299] [client 68.155.154.236:16315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/qfvqu.php"] [unique_id "aoSAevcmepr5_nHgLbNGDAAAAnI"]
[Tue Aug 18 12:55:38.778975 2026] [security2:error] [pid 67073:tid 67217] [client 20.163.43.14:4354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/0x.php"] [unique_id "aoSAevcmepr5_nHgLbNGDQAAAiA"]
[Tue Aug 18 12:55:38.780682 2026] [security2:error] [pid 67073:tid 67254] [client 20.100.169.31:48066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wk/index.php"] [unique_id "aoSAevcmepr5_nHgLbNGDgAAAkU"]
[Tue Aug 18 12:55:38.793413 2026] [security2:error] [pid 67073:tid 67328] [client 20.42.19.40:3338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAevcmepr5_nHgLbNGDwAAAo8"]
[Tue Aug 18 12:55:38.799152 2026] [security2:error] [pid 66623:tid 66864] [client 20.226.56.190:47115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/s.php"] [unique_id "aoSAetO5rbWdOArH04KFUQAAAWw"]
[Tue Aug 18 12:55:38.806553 2026] [security2:error] [pid 66623:tid 66843] [client 20.42.19.40:9654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSAetO5rbWdOArH04KFUgAAAVc"]
[Tue Aug 18 12:55:38.814833 2026] [security2:error] [pid 67073:tid 67272] [client 172.182.200.96:13845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAevcmepr5_nHgLbNGEQAAAlc"]
[Tue Aug 18 12:55:38.831052 2026] [security2:error] [pid 67073:tid 67261] [client 20.104.100.201:21497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/ah25.php"] [unique_id "aoSAevcmepr5_nHgLbNGEgAAAkw"]
[Tue Aug 18 12:55:38.851100 2026] [security2:error] [pid 67073:tid 67118] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kx.php"] [unique_id "aoSAevcmepr5_nHgLbNGEwACFCo"]
[Tue Aug 18 12:55:38.861187 2026] [security2:error] [pid 67073:tid 67281] [client 158.158.34.183:50201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/ab1ux1ft.php"] [unique_id "aoSAevcmepr5_nHgLbNGFAAAAmA"]
[Tue Aug 18 12:55:38.924428 2026] [security2:error] [pid 67073:tid 67234] [client 74.248.136.165:30935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-blog.php"] [unique_id "aoSAevcmepr5_nHgLbNGGQAAAjE"]
[Tue Aug 18 12:55:38.934423 2026] [security2:error] [pid 67073:tid 67268] [client 20.29.77.16:33020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/Mailgun.php"] [unique_id "aoSAevcmepr5_nHgLbNGGgAAAlM"]
[Tue Aug 18 12:55:38.939281 2026] [security2:error] [pid 67073:tid 67260] [client 68.221.73.131:61193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/sf.php"] [unique_id "aoSAevcmepr5_nHgLbNGGwAAAks"]
[Tue Aug 18 12:55:38.974418 2026] [security2:error] [pid 67073:tid 67237] [client 20.151.109.219:53231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ez.php"] [unique_id "aoSAevcmepr5_nHgLbNGHgAAAjQ"]
[Tue Aug 18 12:55:39.008153 2026] [security2:error] [pid 67073:tid 67291] [client 52.139.47.57:43561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/storage/rip.php"] [unique_id "aoSAe_cmepr5_nHgLbNGIgAAAmo"]
[Tue Aug 18 12:55:39.019847 2026] [security2:error] [pid 67073:tid 67314] [client 52.238.210.254:8847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/admin.php"] [unique_id "aoSAe_cmepr5_nHgLbNGJAAAAoE"]
[Tue Aug 18 12:55:39.044091 2026] [security2:error] [pid 67073:tid 67287] [client 20.42.19.40:9632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSAe_cmepr5_nHgLbNGJgAAAmY"]
[Tue Aug 18 12:55:39.082542 2026] [security2:error] [pid 67073:tid 67332] [client 20.163.43.14:4300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAe_cmepr5_nHgLbNGKAAAApM"]
[Tue Aug 18 12:55:39.099061 2026] [security2:error] [pid 66623:tid 66785] [client 20.104.85.180:8001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAe9O5rbWdOArH04KFVQAAAR0"]
[Tue Aug 18 12:55:39.103143 2026] [security2:error] [pid 67073:tid 67320] [client 20.104.100.201:21426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/ano.php"] [unique_id "aoSAe_cmepr5_nHgLbNGKgAAAoc"]
[Tue Aug 18 12:55:39.118454 2026] [security2:error] [pid 67073:tid 67227] [client 4.223.164.152:28496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSAe_cmepr5_nHgLbNGLAAAAio"]
[Tue Aug 18 12:55:39.127832 2026] [security2:error] [pid 66623:tid 66775] [client 20.226.6.191:6566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSAe9O5rbWdOArH04KFVwAAARM"]
[Tue Aug 18 12:55:39.133646 2026] [security2:error] [pid 67073:tid 67265] [client 74.248.130.103:14428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/makeasmtp.php"] [unique_id "aoSAe_cmepr5_nHgLbNGLQAAAlA"]
[Tue Aug 18 12:55:39.136460 2026] [security2:error] [pid 67073:tid 67243] [client 20.48.236.86:16286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/OK.php"] [unique_id "aoSAe_cmepr5_nHgLbNGLgAAAjo"]
[Tue Aug 18 12:55:39.141006 2026] [security2:error] [pid 67073:tid 67285] [client 20.100.169.31:31471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSAe_cmepr5_nHgLbNGLwAAAmQ"]
[Tue Aug 18 12:55:39.149008 2026] [security2:error] [pid 67073:tid 67279] [client 20.163.43.14:4433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/zxz.php"] [unique_id "aoSAe_cmepr5_nHgLbNGMAAAAl4"]
[Tue Aug 18 12:55:39.159351 2026] [security2:error] [pid 67073:tid 67214] [client 20.42.19.40:3429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAe_cmepr5_nHgLbNGMgAAAh0"]
[Tue Aug 18 12:55:39.185667 2026] [security2:error] [pid 67073:tid 67271] [client 20.171.51.14:15760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/gy.php"] [unique_id "aoSAe_cmepr5_nHgLbNGNQAAAlY"]
[Tue Aug 18 12:55:39.201290 2026] [security2:error] [pid 67073:tid 67151] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/va.php"] [unique_id "aoSAe_cmepr5_nHgLbNGOAACGks"]
[Tue Aug 18 12:55:39.216632 2026] [security2:error] [pid 67073:tid 67266] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/p.php"] [unique_id "aoSAe_cmepr5_nHgLbNGOwAAAlE"]
[Tue Aug 18 12:55:39.225881 2026] [security2:error] [pid 67073:tid 67324] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/mac.php"] [unique_id "aoSAe_cmepr5_nHgLbNGPQAAAos"]
[Tue Aug 18 12:55:39.251113 2026] [security2:error] [pid 66623:tid 66828] [client 20.65.69.59:40516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/info2.php"] [unique_id "aoSAe9O5rbWdOArH04KFWQAAAUg"]
[Tue Aug 18 12:55:39.273865 2026] [security2:error] [pid 67073:tid 67323] [client 172.182.200.96:13888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/images/security.php"] [unique_id "aoSAe_cmepr5_nHgLbNGQAAAAoo"]
[Tue Aug 18 12:55:39.274224 2026] [security2:error] [pid 67073:tid 67249] [client 20.151.109.219:21641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/asus.php"] [unique_id "aoSAe_cmepr5_nHgLbNGQQAAAkA"]
[Tue Aug 18 12:55:39.280572 2026] [security2:error] [pid 67073:tid 67273] [client 20.42.19.40:2024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSAe_cmepr5_nHgLbNGQgAAAlg"]
[Tue Aug 18 12:55:39.291891 2026] [security2:error] [pid 66623:tid 66889] [client 20.42.19.40:2235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/about.php"] [unique_id "aoSAe9O5rbWdOArH04KFWgAAAYU"]
[Tue Aug 18 12:55:39.295011 2026] [security2:error] [pid 67073:tid 67207] [client 20.205.121.237:5087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSAe_cmepr5_nHgLbNGRAAAAhY"]
[Tue Aug 18 12:55:39.301894 2026] [security2:error] [pid 67073:tid 67264] [client 213.35.127.232:62829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAe_cmepr5_nHgLbNGRQAAAk8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:39.331598 2026] [authz_core:error] [pid 67073:tid 67172] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:39.331895 2026] [authz_core:error] [pid 67073:tid 67172] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:39.342687 2026] [security2:error] [pid 66623:tid 66816] [client 74.248.136.165:43656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/mga.php"] [unique_id "aoSAe9O5rbWdOArH04KFWwAAATw"]
[Tue Aug 18 12:55:39.346666 2026] [security2:error] [pid 66623:tid 66827] [client 20.116.17.175:57430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/JawirGenk.php"] [unique_id "aoSAe9O5rbWdOArH04KFXAAAAUc"]
[Tue Aug 18 12:55:39.351015 2026] [security2:error] [pid 66623:tid 66842] [client 4.232.151.198:42237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/function/function.php"] [unique_id "aoSAe9O5rbWdOArH04KFXQAAAVY"]
[Tue Aug 18 12:55:39.379589 2026] [security2:error] [pid 67073:tid 67312] [client 20.104.100.201:21477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/nwflm.php"] [unique_id "aoSAe_cmepr5_nHgLbNGTAAAAn8"]
[Tue Aug 18 12:55:39.400946 2026] [security2:error] [pid 67073:tid 67217] [client 20.171.51.14:45424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/17.php"] [unique_id "aoSAe_cmepr5_nHgLbNGTwAAAiA"]
[Tue Aug 18 12:55:39.400983 2026] [autoindex:error] [pid 66623:tid 66888] [client 20.104.85.180:7233] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/js/crop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:39.411289 2026] [security2:error] [pid 67073:tid 67318] [client 68.221.73.131:61280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/k.php"] [unique_id "aoSAe_cmepr5_nHgLbNGUAAAAoU"]
[Tue Aug 18 12:55:39.420558 2026] [security2:error] [pid 67073:tid 67090] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/fo.php"] [unique_id "aoSAe_cmepr5_nHgLbNGUQACjw4"]
[Tue Aug 18 12:55:39.449249 2026] [security2:error] [pid 67073:tid 67329] [client 20.91.215.254:27392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSAe_cmepr5_nHgLbNGVAAAApA"]
[Tue Aug 18 12:55:39.465929 2026] [security2:error] [pid 67073:tid 67274] [client 52.238.210.254:8923] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/admin/controller/extension/extension/"] [unique_id "aoSAe_cmepr5_nHgLbNGWAAAAlk"]
[Tue Aug 18 12:55:39.475315 2026] [security2:error] [pid 66623:tid 66871] [client 20.226.6.191:56199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/chosen.php"] [unique_id "aoSAe9O5rbWdOArH04KFYAAAAXM"]
[Tue Aug 18 12:55:39.501984 2026] [security2:error] [pid 67073:tid 67290] [client 20.163.43.14:4360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/www.php"] [unique_id "aoSAe_cmepr5_nHgLbNGXAAAAmk"]
[Tue Aug 18 12:55:39.505957 2026] [security2:error] [pid 67073:tid 67215] [client 20.163.43.14:4256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSAe_cmepr5_nHgLbNGXQAAAh4"]
[Tue Aug 18 12:55:39.533379 2026] [security2:error] [pid 67073:tid 67234] [client 20.226.6.191:6589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-good.php"] [unique_id "aoSAe_cmepr5_nHgLbNGXwAAAjE"]
[Tue Aug 18 12:55:39.541819 2026] [security2:error] [pid 67073:tid 67226] [client 20.42.19.40:1348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/xmr.php"] [unique_id "aoSAe_cmepr5_nHgLbNGYQAAAik"]
[Tue Aug 18 12:55:39.569012 2026] [security2:error] [pid 67073:tid 67225] [client 4.223.164.152:28514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAe_cmepr5_nHgLbNGZAAAAig"]
[Tue Aug 18 12:55:39.583499 2026] [security2:error] [pid 67073:tid 67260] [client 20.91.215.254:24642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/chosen.php"] [unique_id "aoSAe_cmepr5_nHgLbNGZgAAAks"]
[Tue Aug 18 12:55:39.602240 2026] [security2:error] [pid 67073:tid 67308] [client 20.151.109.219:59757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/22.php"] [unique_id "aoSAe_cmepr5_nHgLbNGZwAAAns"]
[Tue Aug 18 12:55:39.629612 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:39.629876 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:39.656222 2026] [security2:error] [pid 67073:tid 67123] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/loading.php"] [unique_id "aoSAe_cmepr5_nHgLbNGfgACMy8"]
[Tue Aug 18 12:55:39.656405 2026] [security2:error] [pid 66623:tid 66848] [client 20.104.100.201:21465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-load.php"] [unique_id "aoSAe9O5rbWdOArH04KFYQAAAVw"]
[Tue Aug 18 12:55:39.657197 2026] [security2:error] [pid 66623:tid 66806] [client 20.48.236.86:16363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/13.php"] [unique_id "aoSAe9O5rbWdOArH04KFYgAAATI"]
[Tue Aug 18 12:55:39.676280 2026] [security2:error] [pid 66623:tid 66890] [client 20.104.85.180:7233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAe9O5rbWdOArH04KFYwAAAYY"]
[Tue Aug 18 12:55:39.691873 2026] [security2:error] [pid 67073:tid 67227] [client 135.225.75.187:10122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/Ov-Simple1.php"] [unique_id "aoSAe_cmepr5_nHgLbNGfwAAAio"]
[Tue Aug 18 12:55:39.723208 2026] [security2:error] [pid 67073:tid 67243] [client 20.215.241.237:27982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/av.php"] [unique_id "aoSAe_cmepr5_nHgLbNGhAAAAjo"]
[Tue Aug 18 12:55:39.733529 2026] [security2:error] [pid 67073:tid 67327] [client 20.42.19.40:3346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/admin.php"] [unique_id "aoSAe_cmepr5_nHgLbNGhgAAAo4"]
[Tue Aug 18 12:55:39.750069 2026] [security2:error] [pid 67073:tid 67245] [client 20.226.56.190:23761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/uo.php"] [unique_id "aoSAe_cmepr5_nHgLbNGigAAAjw"]
[Tue Aug 18 12:55:39.761874 2026] [security2:error] [pid 67073:tid 67271] [client 74.248.136.165:17047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/fs.php"] [unique_id "aoSAe_cmepr5_nHgLbNGiwAAAlY"]
[Tue Aug 18 12:55:39.768897 2026] [security2:error] [pid 67073:tid 67330] [client 74.248.130.103:36802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSAe_cmepr5_nHgLbNGjAAAApE"]
[Tue Aug 18 12:55:39.771770 2026] [security2:error] [pid 67073:tid 67268] [client 20.100.169.31:3029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSAe_cmepr5_nHgLbNGjQAAAlM"]
[Tue Aug 18 12:55:39.800602 2026] [security2:error] [pid 67073:tid 67266] [client 20.42.19.40:9664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/about.php"] [unique_id "aoSAe_cmepr5_nHgLbNGjgAAAlE"]
[Tue Aug 18 12:55:39.826583 2026] [security2:error] [pid 67073:tid 67232] [client 40.74.65.169:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/1.php"] [unique_id "aoSAe_cmepr5_nHgLbNGkQAAAi8"]
[Tue Aug 18 12:55:39.826670 2026] [security2:error] [pid 67073:tid 67232] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/1.php"] [unique_id "aoSAe_cmepr5_nHgLbNGkQAAAi8"]
[Tue Aug 18 12:55:39.834617 2026] [security2:error] [pid 67073:tid 67309] [client 52.139.47.57:44649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/tool.php"] [unique_id "aoSAe_cmepr5_nHgLbNGkwAAAnw"]
[Tue Aug 18 12:55:39.836372 2026] [security2:error] [pid 66623:tid 66781] [client 132.196.61.152:61012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAe9O5rbWdOArH04KFZAAAARk"]
[Tue Aug 18 12:55:39.846601 2026] [security2:error] [pid 67073:tid 67220] [client 20.163.43.14:4324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSAe_cmepr5_nHgLbNGlQAAAiM"]
[Tue Aug 18 12:55:39.854329 2026] [security2:error] [pid 67073:tid 67201] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ke.php"] [unique_id "aoSAe_cmepr5_nHgLbNGlgACin0"]
[Tue Aug 18 12:55:39.878979 2026] [security2:error] [pid 66623:tid 66792] [client 20.171.51.14:58419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/tt.php"] [unique_id "aoSAe9O5rbWdOArH04KFZQAAASQ"]
[Tue Aug 18 12:55:39.882314 2026] [security2:error] [pid 67073:tid 67295] [client 20.163.43.14:4372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wicked.php"] [unique_id "aoSAe_cmepr5_nHgLbNGlwAAAm4"]
[Tue Aug 18 12:55:39.893948 2026] [security2:error] [pid 67073:tid 67191] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.github/.env"] [unique_id "aoSAe_cmepr5_nHgLbNGoAACXHM"]
[Tue Aug 18 12:55:39.915929 2026] [security2:error] [pid 67073:tid 67292] [client 158.23.17.4:63651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAe_cmepr5_nHgLbNGpwAAAms"]
[Tue Aug 18 12:55:39.928807 2026] [security2:error] [pid 67073:tid 67317] [client 20.104.100.201:21384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/jj.php"] [unique_id "aoSAe_cmepr5_nHgLbNGqgAAAoQ"]
[Tue Aug 18 12:55:39.934012 2026] [authz_core:error] [pid 67073:tid 67153] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:39.934408 2026] [authz_core:error] [pid 67073:tid 67153] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:39.947412 2026] [security2:error] [pid 67073:tid 67230] [client 20.151.109.219:64981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/zs.php"] [unique_id "aoSAe_cmepr5_nHgLbNGqwAAAi0"]
[Tue Aug 18 12:55:39.955023 2026] [security2:error] [pid 67073:tid 67272] [client 20.100.169.31:42639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/about.php"] [unique_id "aoSAe_cmepr5_nHgLbNGrAAAAlc"]
[Tue Aug 18 12:55:39.956475 2026] [security2:error] [pid 67073:tid 67319] [client 20.104.85.180:7969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/o.php"] [unique_id "aoSAe_cmepr5_nHgLbNGrQAAAoY"]
[Tue Aug 18 12:55:39.957881 2026] [security2:error] [pid 67073:tid 67213] [client 52.238.210.254:10120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/adminfuns.php"] [unique_id "aoSAe_cmepr5_nHgLbNGrgAAAhw"]
[Tue Aug 18 12:55:39.978817 2026] [security2:error] [pid 67073:tid 67256] [client 68.221.73.131:61262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/82.php"] [unique_id "aoSAe_cmepr5_nHgLbNGtQAAAkc"]
[Tue Aug 18 12:55:40.029252 2026] [security2:error] [pid 67073:tid 67304] [client 74.248.18.37:14823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/cv.php"] [unique_id "aoSAfPcmepr5_nHgLbNGvwAAAnc"]
[Tue Aug 18 12:55:40.041100 2026] [security2:error] [pid 67073:tid 67255] [client 20.42.19.40:1369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/admin.php"] [unique_id "aoSAfPcmepr5_nHgLbNGwAAAAkY"]
[Tue Aug 18 12:55:40.041504 2026] [security2:error] [pid 67073:tid 67281] [client 4.223.164.152:54269] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/l10n/"] [unique_id "aoSAfPcmepr5_nHgLbNGwQAAAmA"]
[Tue Aug 18 12:55:40.070050 2026] [security2:error] [pid 67073:tid 67120] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/nh.php"] [unique_id "aoSAfPcmepr5_nHgLbNGwgACQSw"]
[Tue Aug 18 12:55:40.091162 2026] [security2:error] [pid 67073:tid 67222] [client 20.48.236.86:16284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/file.php"] [unique_id "aoSAfPcmepr5_nHgLbNGxQAAAiU"]
[Tue Aug 18 12:55:40.112942 2026] [security2:error] [pid 67073:tid 67260] [client 20.65.69.59:3720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/test_info.php"] [unique_id "aoSAfPcmepr5_nHgLbNGxwAAAks"]
[Tue Aug 18 12:55:40.178216 2026] [security2:error] [pid 67073:tid 67305] [client 74.248.136.165:29081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-tem.php"] [unique_id "aoSAfPcmepr5_nHgLbNGygAAAng"]
[Tue Aug 18 12:55:40.180758 2026] [security2:error] [pid 67073:tid 67269] [client 5.253.205.188:38596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/installdatadata_en_us.sql"] [unique_id "aoSAfPcmepr5_nHgLbNGzAAAAlQ"], referer: https://medihub.com.br/installdatadata_en_us.sql
[Tue Aug 18 12:55:40.201359 2026] [security2:error] [pid 67073:tid 67262] [client 20.104.100.201:58927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/img.php"] [unique_id "aoSAfPcmepr5_nHgLbNGzgAAAk0"]
[Tue Aug 18 12:55:40.201375 2026] [security2:error] [pid 67073:tid 67252] [client 20.163.43.14:4280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAfPcmepr5_nHgLbNGzQAAAkM"]
[Tue Aug 18 12:55:40.203187 2026] [security2:error] [pid 67073:tid 67228] [client 68.155.154.236:16210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/oivcl.php"] [unique_id "aoSAfPcmepr5_nHgLbNGzwAAAis"]
[Tue Aug 18 12:55:40.235275 2026] [security2:error] [pid 67073:tid 67296] [client 20.251.48.93:62640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/puc.php"] [unique_id "aoSAfPcmepr5_nHgLbNG0AAAAm8"]
[Tue Aug 18 12:55:40.238785 2026] [security2:error] [pid 67073:tid 67290] [client 20.91.215.254:24647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/asd.php"] [unique_id "aoSAfPcmepr5_nHgLbNG0QAAAmk"]
[Tue Aug 18 12:55:40.239962 2026] [security2:error] [pid 66623:tid 66821] [client 20.104.85.180:8034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/bb.php"] [unique_id "aoSAfNO5rbWdOArH04KFZwAAAUE"]
[Tue Aug 18 12:55:40.258551 2026] [security2:error] [pid 67073:tid 67326] [client 20.151.109.219:24850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/iz.php"] [unique_id "aoSAfPcmepr5_nHgLbNG1AAAAo0"]
[Tue Aug 18 12:55:40.264576 2026] [security2:error] [pid 67073:tid 67245] [client 20.163.43.14:4398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSAfPcmepr5_nHgLbNG1QAAAjw"]
[Tue Aug 18 12:55:40.289530 2026] [security2:error] [pid 67073:tid 67077] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/oo.php"] [unique_id "aoSAfPcmepr5_nHgLbNG1wACXgE"]
[Tue Aug 18 12:55:40.301371 2026] [security2:error] [pid 66623:tid 66776] [client 20.42.19.40:9693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/adminfuns.php"] [unique_id "aoSAfNO5rbWdOArH04KFaAAAARQ"]
[Tue Aug 18 12:55:40.315295 2026] [security2:error] [pid 67073:tid 67318] [client 213.35.127.232:63051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAfPcmepr5_nHgLbNG2wAAAoU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:40.354230 2026] [security2:error] [pid 67073:tid 67268] [client 20.29.77.16:49236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/oauth.php"] [unique_id "aoSAfPcmepr5_nHgLbNG3AAAAlM"]
[Tue Aug 18 12:55:40.355896 2026] [security2:error] [pid 67073:tid 67221] [client 20.250.13.23:48414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAfPcmepr5_nHgLbNG3QAAAiQ"]
[Tue Aug 18 12:55:40.392445 2026] [security2:error] [pid 67073:tid 67232] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/coffee.php"] [unique_id "aoSAfPcmepr5_nHgLbNG4AAAAi8"]
[Tue Aug 18 12:55:40.392543 2026] [security2:error] [pid 67073:tid 67233] [client 20.100.169.31:31426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAfPcmepr5_nHgLbNG3wAAAjA"]
[Tue Aug 18 12:55:40.406870 2026] [security2:error] [pid 67073:tid 67257] [client 45.92.229.87:24087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.229.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/index.php"] [unique_id "aoSAfPcmepr5_nHgLbNG4gAAAkg"], referer: https://ozzyfernandesoficial.com.br/wp-login.php
[Tue Aug 18 12:55:40.410565 2026] [security2:error] [pid 67073:tid 67224] [client 20.48.236.86:16383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/rezor.php"] [unique_id "aoSAfPcmepr5_nHgLbNG4wAAAic"]
[Tue Aug 18 12:55:40.421911 2026] [security2:error] [pid 66623:tid 66839] [client 196.12.128.158:62916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAfNO5rbWdOArH04KFagAAAVM"]
[Tue Aug 18 12:55:40.422022 2026] [security2:error] [pid 66623:tid 66839] [client 196.12.128.158:62916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAfNO5rbWdOArH04KFagAAAVM"]
[Tue Aug 18 12:55:40.427865 2026] [security2:error] [pid 67073:tid 67295] [client 20.116.17.175:57434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/options.php"] [unique_id "aoSAfPcmepr5_nHgLbNG5gAAAm4"]
[Tue Aug 18 12:55:40.437994 2026] [security2:error] [pid 66623:tid 66831] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/past.php"] [unique_id "aoSAfNO5rbWdOArH04KFawAAAUs"]
[Tue Aug 18 12:55:40.445783 2026] [security2:error] [pid 67073:tid 67301] [client 135.225.75.187:25703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSAfPcmepr5_nHgLbNG6AAAAnQ"]
[Tue Aug 18 12:55:40.475113 2026] [security2:error] [pid 67073:tid 67317] [client 20.104.100.201:58492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/we.php"] [unique_id "aoSAfPcmepr5_nHgLbNG6gAAAoQ"]
[Tue Aug 18 12:55:40.490524 2026] [security2:error] [pid 67073:tid 67280] [client 20.226.6.191:6557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/tes.php"] [unique_id "aoSAfPcmepr5_nHgLbNG6wAAAl8"]
[Tue Aug 18 12:55:40.499978 2026] [security2:error] [pid 67073:tid 67230] [client 52.238.210.254:10220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/akc.php"] [unique_id "aoSAfPcmepr5_nHgLbNG7AAAAi0"]
[Tue Aug 18 12:55:40.500947 2026] [security2:error] [pid 66623:tid 66789] [client 4.223.164.152:17643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp.php"] [unique_id "aoSAfNO5rbWdOArH04KFbQAAASE"]
[Tue Aug 18 12:55:40.518309 2026] [security2:error] [pid 67073:tid 67219] [client 103.120.71.157:49170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfPcmepr5_nHgLbNG7gAAAiI"]
[Tue Aug 18 12:55:40.518416 2026] [security2:error] [pid 67073:tid 67219] [client 103.120.71.157:49170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfPcmepr5_nHgLbNG7gAAAiI"]
[Tue Aug 18 12:55:40.529089 2026] [authz_core:error] [pid 67073:tid 67139] [remote 34.62.54.143:52216] AH01630: client denied by server configuration: /home2/natbrw01/uhequeimado.com.br/.htpasswd
[Tue Aug 18 12:55:40.535356 2026] [authz_core:error] [pid 67073:tid 67127] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:40.535604 2026] [authz_core:error] [pid 67073:tid 67127] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:40.535769 2026] [security2:error] [pid 67073:tid 67303] [client 20.104.85.180:7992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSAfPcmepr5_nHgLbNG8QAAAnY"]
[Tue Aug 18 12:55:40.538908 2026] [security2:error] [pid 67073:tid 67182] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ja.php"] [unique_id "aoSAfPcmepr5_nHgLbNG8gACIGo"]
[Tue Aug 18 12:55:40.542714 2026] [security2:error] [pid 67073:tid 67259] [client 20.226.6.191:45836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/info.php"] [unique_id "aoSAfPcmepr5_nHgLbNG9QAAAko"]
[Tue Aug 18 12:55:40.545847 2026] [security2:error] [pid 67073:tid 67328] [client 20.42.19.40:9635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/as.php"] [unique_id "aoSAfPcmepr5_nHgLbNG9gAAAo8"]
[Tue Aug 18 12:55:40.596652 2026] [security2:error] [pid 66623:tid 66767] [client 74.248.136.165:43699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/sadd.php"] [unique_id "aoSAfNO5rbWdOArH04KFbwAAAQs"]
[Tue Aug 18 12:55:40.616817 2026] [security2:error] [pid 66623:tid 66825] [client 20.163.43.14:4470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAfNO5rbWdOArH04KFcAAAAUU"]
[Tue Aug 18 12:55:40.640080 2026] [security2:error] [pid 67073:tid 67215] [client 20.151.109.219:32986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/se.php"] [unique_id "aoSAfPcmepr5_nHgLbNG_AAAAh4"]
[Tue Aug 18 12:55:40.689403 2026] [security2:error] [pid 66623:tid 66885] [client 20.205.121.237:5099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/includes/about.php"] [unique_id "aoSAfNO5rbWdOArH04KFcQAAAYE"]
[Tue Aug 18 12:55:40.693616 2026] [security2:error] [pid 67073:tid 67225] [client 20.42.19.40:3421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/edit.php"] [unique_id "aoSAfPcmepr5_nHgLbNG_gAAAig"]
[Tue Aug 18 12:55:40.714575 2026] [security2:error] [pid 67073:tid 67313] [client 20.48.236.86:16369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/3p8jj8r.php"] [unique_id "aoSAfPcmepr5_nHgLbNG_wAAAoA"]
[Tue Aug 18 12:55:40.723305 2026] [security2:error] [pid 67073:tid 67220] [client 52.139.47.57:19963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/twentytwenty/functions.php"] [unique_id "aoSAfPcmepr5_nHgLbNHAAAAAiM"]
[Tue Aug 18 12:55:40.733566 2026] [security2:error] [pid 67073:tid 67260] [client 68.221.73.131:61211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/dex.php"] [unique_id "aoSAfPcmepr5_nHgLbNHAgAAAks"]
[Tue Aug 18 12:55:40.741922 2026] [security2:error] [pid 66623:tid 66893] [client 20.163.43.14:4214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSAfNO5rbWdOArH04KFcgAAAYk"]
[Tue Aug 18 12:55:40.742958 2026] [security2:error] [pid 67073:tid 67292] [client 20.91.215.254:11979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/f7.php"] [unique_id "aoSAfPcmepr5_nHgLbNHAwAAAms"]
[Tue Aug 18 12:55:40.757362 2026] [security2:error] [pid 66623:tid 66641] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAfNO5rbWdOArH04KFcwABJwQ"]
[Tue Aug 18 12:55:40.801920 2026] [security2:error] [pid 67073:tid 67258] [client 20.42.19.40:1362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/bolt.php"] [unique_id "aoSAfPcmepr5_nHgLbNHBQAAAkk"]
[Tue Aug 18 12:55:40.837102 2026] [authz_core:error] [pid 67073:tid 67081] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:40.837349 2026] [authz_core:error] [pid 67073:tid 67081] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:40.844446 2026] [security2:error] [pid 67073:tid 67242] [client 20.251.48.93:62605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/inso.php"] [unique_id "aoSAfPcmepr5_nHgLbNHCgAAAjk"]
[Tue Aug 18 12:55:40.846032 2026] [security2:error] [pid 67073:tid 67113] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/xx.php"] [unique_id "aoSAfPcmepr5_nHgLbNHCwACaiU"]
[Tue Aug 18 12:55:40.850602 2026] [autoindex:error] [pid 67073:tid 67240] [client 20.226.6.191:45840] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:40.858191 2026] [security2:error] [pid 66623:tid 66860] [client 20.100.169.31:17502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/term.php"] [unique_id "aoSAfNO5rbWdOArH04KFdQAAAWg"]
[Tue Aug 18 12:55:40.858684 2026] [security2:error] [pid 67073:tid 67284] [client 20.226.6.191:45840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAfPcmepr5_nHgLbNHDAAAAmM"]
[Tue Aug 18 12:55:40.861988 2026] [security2:error] [pid 67073:tid 67252] [client 20.171.51.14:58840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/mq.php"] [unique_id "aoSAfPcmepr5_nHgLbNHDQAAAkM"]
[Tue Aug 18 12:55:40.863577 2026] [security2:error] [pid 67073:tid 67262] [client 20.171.51.14:58425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ev.php"] [unique_id "aoSAfPcmepr5_nHgLbNHDgAAAk0"]
[Tue Aug 18 12:55:40.882682 2026] [security2:error] [pid 67073:tid 67208] [client 20.91.215.254:13061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/akc.php"] [unique_id "aoSAfPcmepr5_nHgLbNHDwAAAhc"]
[Tue Aug 18 12:55:40.904976 2026] [security2:error] [pid 67073:tid 67210] [client 52.238.210.254:8296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/buy.php"] [unique_id "aoSAfPcmepr5_nHgLbNHEAAAAhk"]
[Tue Aug 18 12:55:40.925397 2026] [security2:error] [pid 67073:tid 67080] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/0x.php"] [unique_id "aoSAfPcmepr5_nHgLbNHEgACbwQ"]
[Tue Aug 18 12:55:40.931241 2026] [security2:error] [pid 67073:tid 67290] [client 20.151.109.219:21667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/vp.php"] [unique_id "aoSAfPcmepr5_nHgLbNHEwAAAmk"]
[Tue Aug 18 12:55:40.939414 2026] [security2:error] [pid 67073:tid 67243] [client 74.248.130.103:14402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/system_log.php"] [unique_id "aoSAfPcmepr5_nHgLbNHFAAAAjo"]
[Tue Aug 18 12:55:40.960593 2026] [security2:error] [pid 67073:tid 67326] [client 4.223.164.152:28542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/i.php"] [unique_id "aoSAfPcmepr5_nHgLbNHFQAAAo0"]
[Tue Aug 18 12:55:40.986342 2026] [security2:error] [pid 67073:tid 67318] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAfPcmepr5_nHgLbNHGwAAAoU"]
[Tue Aug 18 12:55:41.019480 2026] [security2:error] [pid 67073:tid 67231] [client 74.248.136.165:30919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ex.php"] [unique_id "aoSAffcmepr5_nHgLbNHHgAAAi4"]
[Tue Aug 18 12:55:41.020639 2026] [security2:error] [pid 67073:tid 67237] [client 20.100.169.31:2437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAffcmepr5_nHgLbNHHwAAAjQ"]
[Tue Aug 18 12:55:41.045477 2026] [cgid:error] [pid 67073:tid 67266] [client 20.42.19.40:9697] AH01265: stderr from /home4/plantaodasbateri/public_html/cgi-bin/: attempt to invoke directory as script
[Tue Aug 18 12:55:41.054779 2026] [security2:error] [pid 66623:tid 66783] [client 37.40.227.74:56892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfdO5rbWdOArH04KFdwAAARs"]
[Tue Aug 18 12:55:41.054877 2026] [security2:error] [pid 66623:tid 66783] [client 37.40.227.74:56892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfdO5rbWdOArH04KFdwAAARs"]
[Tue Aug 18 12:55:41.067864 2026] [security2:error] [pid 67073:tid 67309] [client 20.163.43.14:4328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/an.php"] [unique_id "aoSAffcmepr5_nHgLbNHJAAAAnw"]
[Tue Aug 18 12:55:41.082583 2026] [security2:error] [pid 67073:tid 67249] [client 20.48.236.86:16295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/dapa.php"] [unique_id "aoSAffcmepr5_nHgLbNHJQAAAkA"]
[Tue Aug 18 12:55:41.084110 2026] [security2:error] [pid 67073:tid 67316] [client 4.232.151.198:39145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/about.php"] [unique_id "aoSAffcmepr5_nHgLbNHJgAAAoM"]
[Tue Aug 18 12:55:41.085579 2026] [security2:error] [pid 67073:tid 67295] [client 20.65.98.162:28543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/nano.php"] [unique_id "aoSAffcmepr5_nHgLbNHJwAAAm4"]
[Tue Aug 18 12:55:41.086782 2026] [security2:error] [pid 67073:tid 67198] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/conn-test.php"] [unique_id "aoSAffcmepr5_nHgLbNHKAACFno"]
[Tue Aug 18 12:55:41.091795 2026] [security2:error] [pid 66623:tid 66693] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/222.php"] [unique_id "aoSAfdO5rbWdOArH04KFeAABNTg"]
[Tue Aug 18 12:55:41.129805 2026] [security2:error] [pid 67073:tid 67301] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/php.php"] [unique_id "aoSAffcmepr5_nHgLbNHKwAAAnQ"]
[Tue Aug 18 12:55:41.138801 2026] [authz_core:error] [pid 67073:tid 67091] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:41.139063 2026] [authz_core:error] [pid 67073:tid 67091] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:41.169581 2026] [security2:error] [pid 67073:tid 67235] [client 20.163.43.14:4479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/cah.php"] [unique_id "aoSAffcmepr5_nHgLbNHLQAAAjI"]
[Tue Aug 18 12:55:41.207272 2026] [security2:error] [pid 66623:tid 66817] [client 172.202.39.151:65220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSAfdO5rbWdOArH04KFegAAAT0"]
[Tue Aug 18 12:55:41.209081 2026] [security2:error] [pid 67073:tid 67083] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSAffcmepr5_nHgLbNHLwACNgc"]
[Tue Aug 18 12:55:41.223252 2026] [security2:error] [pid 67073:tid 67317] [client 20.226.56.190:2534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kx.php"] [unique_id "aoSAffcmepr5_nHgLbNHMAAAAoQ"]
[Tue Aug 18 12:55:41.223783 2026] [security2:error] [pid 67073:tid 67238] [client 197.184.64.235:41926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAffcmepr5_nHgLbNHMQAAAjU"]
[Tue Aug 18 12:55:41.223872 2026] [security2:error] [pid 67073:tid 67238] [client 197.184.64.235:41926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAffcmepr5_nHgLbNHMQAAAjU"]
[Tue Aug 18 12:55:41.258008 2026] [security2:error] [pid 67073:tid 67160] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/aa.php"] [unique_id "aoSAffcmepr5_nHgLbNHMgACIlQ"]
[Tue Aug 18 12:55:41.268015 2026] [security2:error] [pid 67073:tid 67303] [client 20.151.109.219:21673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ph.php"] [unique_id "aoSAffcmepr5_nHgLbNHMwAAAnY"]
[Tue Aug 18 12:55:41.279203 2026] [security2:error] [pid 67073:tid 67289] [client 20.42.19.40:9697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/class-t.api.php"] [unique_id "aoSAffcmepr5_nHgLbNHNQAAAmg"]
[Tue Aug 18 12:55:41.289588 2026] [security2:error] [pid 67073:tid 67188] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/fg.php"] [unique_id "aoSAffcmepr5_nHgLbNHNwACSnA"]
[Tue Aug 18 12:55:41.301944 2026] [security2:error] [pid 67073:tid 67293] [client 132.196.61.152:61015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/inso.php"] [unique_id "aoSAffcmepr5_nHgLbNHOAAAAmw"]
[Tue Aug 18 12:55:41.327648 2026] [security2:error] [pid 67073:tid 67268] [client 213.35.127.232:63270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAffcmepr5_nHgLbNHOQAAAlM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:41.356624 2026] [security2:error] [pid 67073:tid 67329] [client 68.221.73.131:61297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/puc.php"] [unique_id "aoSAffcmepr5_nHgLbNHOgAAApA"]
[Tue Aug 18 12:55:41.377750 2026] [security2:error] [pid 67073:tid 67248] [client 20.226.6.191:7114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/files/index.php"] [unique_id "aoSAffcmepr5_nHgLbNHPAAAAj8"]
[Tue Aug 18 12:55:41.386131 2026] [security2:error] [pid 67073:tid 67255] [client 4.223.164.152:46166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/abcd.php"] [unique_id "aoSAffcmepr5_nHgLbNHPQAAAkY"]
[Tue Aug 18 12:55:41.429313 2026] [security2:error] [pid 66623:tid 66658] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/abcd.php"] [unique_id "aoSAfdO5rbWdOArH04KFfAABLBU"]
[Tue Aug 18 12:55:41.438930 2026] [authz_core:error] [pid 67073:tid 67117] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:41.439179 2026] [authz_core:error] [pid 67073:tid 67117] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:41.442988 2026] [security2:error] [pid 66623:tid 66866] [client 74.248.136.165:49663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/tax.php"] [unique_id "aoSAfdO5rbWdOArH04KFfQAAAW4"]
[Tue Aug 18 12:55:41.453548 2026] [security2:error] [pid 67073:tid 67220] [client 20.42.19.40:3422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/w.php"] [unique_id "aoSAffcmepr5_nHgLbNHQQAAAiM"]
[Tue Aug 18 12:55:41.468204 2026] [security2:error] [pid 66623:tid 66884] [client 20.171.51.14:16755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/xs.php"] [unique_id "aoSAfdO5rbWdOArH04KFfgAAAYA"]
[Tue Aug 18 12:55:41.488776 2026] [security2:error] [pid 67073:tid 67258] [client 135.225.75.187:31205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/vx.php"] [unique_id "aoSAffcmepr5_nHgLbNHRQAAAkk"]
[Tue Aug 18 12:55:41.505179 2026] [security2:error] [pid 67073:tid 67253] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/php8.php"] [unique_id "aoSAffcmepr5_nHgLbNHRgAAAkQ"]
[Tue Aug 18 12:55:41.512391 2026] [security2:error] [pid 67073:tid 67305] [client 20.48.236.86:16267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/Ipv6.php"] [unique_id "aoSAffcmepr5_nHgLbNHRwAAAng"]
[Tue Aug 18 12:55:41.519928 2026] [security2:error] [pid 67073:tid 67269] [client 20.42.19.40:1394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/edit.php"] [unique_id "aoSAffcmepr5_nHgLbNHSAAAAlQ"]
[Tue Aug 18 12:55:41.540024 2026] [security2:error] [pid 67073:tid 67170] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ve.php"] [unique_id "aoSAffcmepr5_nHgLbNHSwACal4"]
[Tue Aug 18 12:55:41.570290 2026] [security2:error] [pid 67073:tid 67261] [client 20.91.215.254:14327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/maintenance.php"] [unique_id "aoSAffcmepr5_nHgLbNHTgAAAkw"]
[Tue Aug 18 12:55:41.574936 2026] [security2:error] [pid 67073:tid 67082] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSAffcmepr5_nHgLbNHUAACTQY"]
[Tue Aug 18 12:55:41.575560 2026] [security2:error] [pid 67073:tid 67228] [client 20.163.43.14:4332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/404.php"] [unique_id "aoSAffcmepr5_nHgLbNHUwAAAis"]
[Tue Aug 18 12:55:41.576766 2026] [security2:error] [pid 67073:tid 67310] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSAffcmepr5_nHgLbNHVAAAAn0"]
[Tue Aug 18 12:55:41.592441 2026] [security2:error] [pid 67073:tid 67216] [client 20.151.109.219:65019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/s.php"] [unique_id "aoSAffcmepr5_nHgLbNHVgAAAh8"]
[Tue Aug 18 12:55:41.595296 2026] [security2:error] [pid 67073:tid 67108] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/admin.php"] [unique_id "aoSAffcmepr5_nHgLbNHVwACGSA"]
[Tue Aug 18 12:55:41.605203 2026] [security2:error] [pid 66623:tid 66812] [client 20.251.48.93:25023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/aa.php"] [unique_id "aoSAfdO5rbWdOArH04KFgAAAATg"]
[Tue Aug 18 12:55:41.646936 2026] [security2:error] [pid 67073:tid 67285] [client 20.116.17.175:57410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSAffcmepr5_nHgLbNHXAAAAmQ"]
[Tue Aug 18 12:55:41.678393 2026] [security2:error] [pid 67073:tid 67245] [client 20.29.77.16:52747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/timeclock.php"] [unique_id "aoSAffcmepr5_nHgLbNHXwAAAjw"]
[Tue Aug 18 12:55:41.683030 2026] [security2:error] [pid 67073:tid 67330] [client 52.238.210.254:10164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/cong.php"] [unique_id "aoSAffcmepr5_nHgLbNHYAAAApE"]
[Tue Aug 18 12:55:41.722311 2026] [security2:error] [pid 66623:tid 66803] [client 20.205.121.237:4106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/includes/colour.php"] [unique_id "aoSAfdO5rbWdOArH04KFggAAAS8"]
[Tue Aug 18 12:55:41.734422 2026] [security2:error] [pid 67073:tid 67237] [client 20.104.85.180:7940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-login.php"] [unique_id "aoSAffcmepr5_nHgLbNHYwAAAjQ"]
[Tue Aug 18 12:55:41.773547 2026] [security2:error] [pid 67073:tid 67232] [client 158.23.17.4:38857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAffcmepr5_nHgLbNHZAAAAi8"]
[Tue Aug 18 12:55:41.777917 2026] [security2:error] [pid 67073:tid 67292] [client 20.91.215.254:27435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/photo.php"] [unique_id "aoSAffcmepr5_nHgLbNHZgAAAms"]
[Tue Aug 18 12:55:41.783490 2026] [security2:error] [pid 67073:tid 67267] [client 20.42.19.40:9645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/ff1.php"] [unique_id "aoSAffcmepr5_nHgLbNHZwAAAlI"]
[Tue Aug 18 12:55:41.785928 2026] [security2:error] [pid 67073:tid 67309] [client 20.171.51.14:61484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/13.php"] [unique_id "aoSAffcmepr5_nHgLbNHaAAAAnw"]
[Tue Aug 18 12:55:41.790337 2026] [security2:error] [pid 67073:tid 67173] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ia.php"] [unique_id "aoSAffcmepr5_nHgLbNHaQACJ2E"]
[Tue Aug 18 12:55:41.800962 2026] [security2:error] [pid 66623:tid 66849] [client 20.163.43.14:4460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/system_log.php"] [unique_id "aoSAfdO5rbWdOArH04KFhAAAAV0"]
[Tue Aug 18 12:55:41.812295 2026] [security2:error] [pid 67073:tid 67249] [client 20.226.6.191:64060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSAffcmepr5_nHgLbNHawAAAkA"]
[Tue Aug 18 12:55:41.844763 2026] [security2:error] [pid 67073:tid 67244] [client 4.223.164.152:46157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-manager.php"] [unique_id "aoSAffcmepr5_nHgLbNHbQAAAjs"]
[Tue Aug 18 12:55:41.860377 2026] [security2:error] [pid 67073:tid 67235] [client 74.248.136.165:30945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/X7x.php"] [unique_id "aoSAffcmepr5_nHgLbNHbgAAAjI"]
[Tue Aug 18 12:55:41.883956 2026] [security2:error] [pid 67073:tid 67280] [client 20.104.85.180:7975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSAffcmepr5_nHgLbNHcAAAAl8"]
[Tue Aug 18 12:55:41.896105 2026] [security2:error] [pid 67073:tid 67302] [client 114.5.214.109:49806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAffcmepr5_nHgLbNHcQAAAnU"]
[Tue Aug 18 12:55:41.896221 2026] [security2:error] [pid 67073:tid 67302] [client 114.5.214.109:49806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAffcmepr5_nHgLbNHcQAAAnU"]
[Tue Aug 18 12:55:41.949362 2026] [security2:error] [pid 67073:tid 67319] [client 20.226.56.190:3062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/va.php"] [unique_id "aoSAffcmepr5_nHgLbNHdAAAAoY"]
[Tue Aug 18 12:55:41.952420 2026] [security2:error] [pid 67073:tid 67213] [client 20.151.109.219:12927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/uo.php"] [unique_id "aoSAffcmepr5_nHgLbNHdgAAAhw"]
[Tue Aug 18 12:55:41.953226 2026] [security2:error] [pid 67073:tid 67279] [client 172.202.39.151:13402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/rip.php"] [unique_id "aoSAffcmepr5_nHgLbNHdwAAAl4"]
[Tue Aug 18 12:55:41.961512 2026] [security2:error] [pid 67073:tid 67303] [client 132.196.61.152:61021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/puc.php"] [unique_id "aoSAffcmepr5_nHgLbNHeAAAAnY"]
[Tue Aug 18 12:55:41.962746 2026] [security2:error] [pid 67073:tid 67289] [client 20.48.236.86:16245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/first.php"] [unique_id "aoSAffcmepr5_nHgLbNHegAAAmg"]
[Tue Aug 18 12:55:41.981943 2026] [security2:error] [pid 67073:tid 67111] [remote 129.121.74.194:35718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.74.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/wp-login.php"] [unique_id "aoSAffcmepr5_nHgLbNHfAACZSM"]
[Tue Aug 18 12:55:41.996855 2026] [security2:error] [pid 67073:tid 67283] [client 74.248.18.37:28818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAffcmepr5_nHgLbNHfQAAAmI"]
[Tue Aug 18 12:55:42.018583 2026] [security2:error] [pid 67073:tid 67158] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kn.php"] [unique_id "aoSAfvcmepr5_nHgLbNHgAACkFI"]
[Tue Aug 18 12:55:42.026558 2026] [security2:error] [pid 67073:tid 67304] [client 20.42.19.40:9662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/fff.php"] [unique_id "aoSAfvcmepr5_nHgLbNHgQAAAnc"]
[Tue Aug 18 12:55:42.043354 2026] [security2:error] [pid 67073:tid 67263] [client 192.141.172.134:58399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfvcmepr5_nHgLbNHgwAAAk4"]
[Tue Aug 18 12:55:42.043453 2026] [security2:error] [pid 67073:tid 67263] [client 192.141.172.134:58399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfvcmepr5_nHgLbNHgwAAAk4"]
[Tue Aug 18 12:55:42.052334 2026] [security2:error] [pid 67073:tid 67277] [client 68.221.73.131:61228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/inso.php"] [unique_id "aoSAfvcmepr5_nHgLbNHhAAAAlw"]
[Tue Aug 18 12:55:42.053958 2026] [security2:error] [pid 67073:tid 67255] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/phpinfo.php"] [unique_id "aoSAfvcmepr5_nHgLbNHhQAAAkY"]
[Tue Aug 18 12:55:42.073281 2026] [security2:error] [pid 67073:tid 67297] [client 20.100.169.31:2440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSAfvcmepr5_nHgLbNHhgAAAnA"]
[Tue Aug 18 12:55:42.095566 2026] [security2:error] [pid 67073:tid 67230] [client 20.163.43.14:4312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-login.php"] [unique_id "aoSAffcmepr5_nHgLbNHcwAAAi0"]
[Tue Aug 18 12:55:42.105394 2026] [authz_core:error] [pid 67073:tid 67154] [remote 57.141.22.104:54644] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:42.105644 2026] [authz_core:error] [pid 67073:tid 67154] [remote 57.141.22.104:54644] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:42.111135 2026] [security2:error] [pid 67073:tid 67205] [client 20.215.241.237:52549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/media.php"] [unique_id "aoSAfvcmepr5_nHgLbNHiQAAAhQ"]
[Tue Aug 18 12:55:42.116697 2026] [security2:error] [pid 67073:tid 67211] [client 52.139.47.57:18216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/wp-admin.php"] [unique_id "aoSAfvcmepr5_nHgLbNHigAAAho"]
[Tue Aug 18 12:55:42.122180 2026] [security2:error] [pid 66623:tid 66819] [client 52.238.210.254:8853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSAftO5rbWdOArH04KFhgAAAT8"]
[Tue Aug 18 12:55:42.135450 2026] [security2:error] [pid 67073:tid 67258] [client 68.155.154.236:16378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/zugvi.php"] [unique_id "aoSAfvcmepr5_nHgLbNHjAAAAkk"]
[Tue Aug 18 12:55:42.139378 2026] [security2:error] [pid 67073:tid 67201] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/id_rsa"] [unique_id "aoSAfvcmepr5_nHgLbNHjQACRH0"]
[Tue Aug 18 12:55:42.163852 2026] [security2:error] [pid 67073:tid 67269] [client 20.104.85.180:7941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAfvcmepr5_nHgLbNHjgAAAlQ"]
[Tue Aug 18 12:55:42.174962 2026] [security2:error] [pid 67073:tid 67291] [client 20.42.19.40:3344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/file.php"] [unique_id "aoSAfvcmepr5_nHgLbNHjwAAAmo"]
[Tue Aug 18 12:55:42.194997 2026] [security2:error] [pid 67073:tid 67284] [client 20.226.6.191:45838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/k.php"] [unique_id "aoSAfvcmepr5_nHgLbNHkwAAAmM"]
[Tue Aug 18 12:55:42.195165 2026] [security2:error] [pid 67073:tid 67169] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/id_dsa"] [unique_id "aoSAfvcmepr5_nHgLbNHkgACN10"]
[Tue Aug 18 12:55:42.215633 2026] [security2:error] [pid 67073:tid 67180] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/wm.php"] [unique_id "aoSAfvcmepr5_nHgLbNHlgACH2g"]
[Tue Aug 18 12:55:42.220687 2026] [security2:error] [pid 67073:tid 67246] [client 20.91.215.254:20539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/options-writing.php"] [unique_id "aoSAfvcmepr5_nHgLbNHlwAAAj0"]
[Tue Aug 18 12:55:42.228216 2026] [security2:error] [pid 67073:tid 67320] [client 20.226.56.190:2552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/fo.php"] [unique_id "aoSAfvcmepr5_nHgLbNHmAAAAoc"]
[Tue Aug 18 12:55:42.235528 2026] [security2:error] [pid 67073:tid 67210] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/yj09.php"] [unique_id "aoSAfvcmepr5_nHgLbNHmQAAAhk"]
[Tue Aug 18 12:55:42.245243 2026] [security2:error] [pid 67073:tid 67218] [client 213.202.253.4:49293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/gdftps.php"] [unique_id "aoSAfvcmepr5_nHgLbNHmgAAAiE"], referer: www.google.com
[Tue Aug 18 12:55:42.250506 2026] [security2:error] [pid 67073:tid 67112] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAfvcmepr5_nHgLbNHnAACjyQ"]
[Tue Aug 18 12:55:42.265254 2026] [security2:error] [pid 66623:tid 66891] [client 20.42.19.40:9667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/inputs.php"] [unique_id "aoSAftO5rbWdOArH04KFiAAAAYc"]
[Tue Aug 18 12:55:42.266019 2026] [security2:error] [pid 66623:tid 66882] [client 20.151.109.219:12890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kx.php"] [unique_id "aoSAftO5rbWdOArH04KFiQAAAX4"]
[Tue Aug 18 12:55:42.274303 2026] [security2:error] [pid 67073:tid 67273] [client 86.120.159.145:5685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfvcmepr5_nHgLbNHngAAAlg"]
[Tue Aug 18 12:55:42.274425 2026] [security2:error] [pid 67073:tid 67273] [client 86.120.159.145:5685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfvcmepr5_nHgLbNHngAAAlg"]
[Tue Aug 18 12:55:42.278282 2026] [security2:error] [pid 67073:tid 67225] [client 74.248.136.165:44260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ocxla.php"] [unique_id "aoSAfvcmepr5_nHgLbNHoAAAAig"]
[Tue Aug 18 12:55:42.337112 2026] [security2:error] [pid 67073:tid 67237] [client 20.171.51.14:33713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/so.php"] [unique_id "aoSAfvcmepr5_nHgLbNHpAAAAjQ"]
[Tue Aug 18 12:55:42.346405 2026] [authz_core:error] [pid 67073:tid 67126] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:42.346854 2026] [authz_core:error] [pid 67073:tid 67126] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:42.349942 2026] [security2:error] [pid 67073:tid 67274] [client 213.35.127.232:63484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAfvcmepr5_nHgLbNHpQAAAlk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:42.360762 2026] [security2:error] [pid 67073:tid 67322] [client 20.163.43.14:4382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAfvcmepr5_nHgLbNHpgAAAok"]
[Tue Aug 18 12:55:42.364753 2026] [security2:error] [pid 67073:tid 67241] [client 20.65.69.59:3673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/xynz1.php"] [unique_id "aoSAfvcmepr5_nHgLbNHqgAAAjg"]
[Tue Aug 18 12:55:42.370077 2026] [security2:error] [pid 67073:tid 67314] [client 158.158.34.183:11282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/aksinet.php"] [unique_id "aoSAfvcmepr5_nHgLbNHqwAAAoE"]
[Tue Aug 18 12:55:42.385710 2026] [security2:error] [pid 67073:tid 67232] [client 4.223.164.152:46189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSAfvcmepr5_nHgLbNHrAAAAi8"]
[Tue Aug 18 12:55:42.422493 2026] [security2:error] [pid 66623:tid 66704] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/akc.php"] [unique_id "aoSAftO5rbWdOArH04KFiwABbEM"]
[Tue Aug 18 12:55:42.444260 2026] [security2:error] [pid 66623:tid 66843] [client 20.104.85.180:7267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/file.php"] [unique_id "aoSAftO5rbWdOArH04KFjQAAAVc"]
[Tue Aug 18 12:55:42.462310 2026] [security2:error] [pid 67073:tid 67323] [client 20.163.43.14:4164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAfvcmepr5_nHgLbNHsAAAAoo"]
[Tue Aug 18 12:55:42.501961 2026] [security2:error] [pid 67073:tid 67239] [client 20.42.19.40:1398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/ioxi-o.php"] [unique_id "aoSAfvcmepr5_nHgLbNHsgAAAjY"]
[Tue Aug 18 12:55:42.516832 2026] [security2:error] [pid 67073:tid 67152] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/key.pem"] [unique_id "aoSAfvcmepr5_nHgLbNHswACeUw"]
[Tue Aug 18 12:55:42.517199 2026] [security2:error] [pid 67073:tid 67275] [client 132.196.61.152:60316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/19.php"] [unique_id "aoSAfvcmepr5_nHgLbNHtAAAAlo"]
[Tue Aug 18 12:55:42.523750 2026] [security2:error] [pid 67073:tid 67326] [client 20.226.6.191:6577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAfvcmepr5_nHgLbNHtQAAAo0"]
[Tue Aug 18 12:55:42.546463 2026] [security2:error] [pid 67073:tid 67145] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ac.php"] [unique_id "aoSAfvcmepr5_nHgLbNHtwACV0U"]
[Tue Aug 18 12:55:42.552651 2026] [security2:error] [pid 66623:tid 66797] [client 20.65.98.162:56672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/file5.php"] [unique_id "aoSAftO5rbWdOArH04KFkQAAASk"]
[Tue Aug 18 12:55:42.573945 2026] [security2:error] [pid 67073:tid 67279] [client 68.221.73.131:61226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/aa.php"] [unique_id "aoSAfvcmepr5_nHgLbNHuAAAAl4"]
[Tue Aug 18 12:55:42.589222 2026] [security2:error] [pid 66623:tid 66875] [client 52.238.210.254:8874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/db.php"] [unique_id "aoSAftO5rbWdOArH04KFkgAAAXc"]
[Tue Aug 18 12:55:42.590177 2026] [security2:error] [pid 67073:tid 67089] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/buy.php"] [unique_id "aoSAfvcmepr5_nHgLbNHugACcg0"]
[Tue Aug 18 12:55:42.596564 2026] [security2:error] [pid 67073:tid 67195] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/privatekey.key"] [unique_id "aoSAfvcmepr5_nHgLbNHuwACInc"]
[Tue Aug 18 12:55:42.598684 2026] [security2:error] [pid 66623:tid 66852] [client 135.225.75.187:47174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ah25.php"] [unique_id "aoSAftO5rbWdOArH04KFkwAAAWA"]
[Tue Aug 18 12:55:42.605908 2026] [security2:error] [pid 66623:tid 66775] [client 20.42.19.40:3397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAftO5rbWdOArH04KFlAAAARM"]
[Tue Aug 18 12:55:42.632409 2026] [security2:error] [pid 67073:tid 67268] [client 20.48.236.86:16333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/wpupex.php"] [unique_id "aoSAfvcmepr5_nHgLbNHwQAAAlM"]
[Tue Aug 18 12:55:42.642223 2026] [authz_core:error] [pid 67073:tid 67136] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:42.642486 2026] [authz_core:error] [pid 67073:tid 67136] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:42.656332 2026] [security2:error] [pid 67073:tid 67229] [client 4.232.151.198:15653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/nw.php"] [unique_id "aoSAfvcmepr5_nHgLbNHxgAAAiw"]
[Tue Aug 18 12:55:42.674686 2026] [security2:error] [pid 67073:tid 67307] [client 20.91.215.254:11977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-aa.php"] [unique_id "aoSAfvcmepr5_nHgLbNHyQAAAno"]
[Tue Aug 18 12:55:42.704324 2026] [security2:error] [pid 67073:tid 67226] [client 74.248.136.165:44248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/post.php"] [unique_id "aoSAfvcmepr5_nHgLbNHygAAAik"]
[Tue Aug 18 12:55:42.727758 2026] [security2:error] [pid 67073:tid 67313] [client 20.163.43.14:4420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAfvcmepr5_nHgLbNHzgAAAoA"]
[Tue Aug 18 12:55:42.728039 2026] [security2:error] [pid 67073:tid 67220] [client 20.104.85.180:7265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/epinyins.php"] [unique_id "aoSAfvcmepr5_nHgLbNHzwAAAiM"]
[Tue Aug 18 12:55:42.750106 2026] [security2:error] [pid 67073:tid 67234] [client 20.151.109.219:24893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/va.php"] [unique_id "aoSAfvcmepr5_nHgLbNH0AAAAjE"]
[Tue Aug 18 12:55:42.752592 2026] [security2:error] [pid 67073:tid 67257] [client 20.205.121.237:5056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/includes/xmrlpc.php"] [unique_id "aoSAfvcmepr5_nHgLbNH0QAAAkg"]
[Tue Aug 18 12:55:42.754086 2026] [security2:error] [pid 67073:tid 67260] [client 20.42.19.40:1353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/lite.php"] [unique_id "aoSAfvcmepr5_nHgLbNH0gAAAks"]
[Tue Aug 18 12:55:42.757419 2026] [security2:error] [pid 66623:tid 66856] [client 20.226.56.190:45016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/loading.php"] [unique_id "aoSAftO5rbWdOArH04KFlQAAAWQ"]
[Tue Aug 18 12:55:42.762787 2026] [security2:error] [pid 67073:tid 67122] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/cong.php"] [unique_id "aoSAfvcmepr5_nHgLbNH0wACfi4"]
[Tue Aug 18 12:55:42.818519 2026] [security2:error] [pid 66623:tid 66863] [client 20.100.169.31:52454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-fclass.php"] [unique_id "aoSAftO5rbWdOArH04KFlwAAAWs"]
[Tue Aug 18 12:55:42.822656 2026] [security2:error] [pid 67073:tid 67114] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/yz.php"] [unique_id "aoSAfvcmepr5_nHgLbNH1wACeCY"]
[Tue Aug 18 12:55:42.830025 2026] [security2:error] [pid 67073:tid 67284] [client 4.223.164.152:54231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSAfvcmepr5_nHgLbNH2AAAAmM"]
[Tue Aug 18 12:55:42.850063 2026] [security2:error] [pid 67073:tid 67310] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/scxy.php"] [unique_id "aoSAfvcmepr5_nHgLbNH2QAAAn0"]
[Tue Aug 18 12:55:42.868986 2026] [security2:error] [pid 67073:tid 67242] [client 103.184.169.37:41727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfvcmepr5_nHgLbNH2gAAAjk"]
[Tue Aug 18 12:55:42.869437 2026] [security2:error] [pid 67073:tid 67242] [client 103.184.169.37:41727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfvcmepr5_nHgLbNH2gAAAjk"]
[Tue Aug 18 12:55:42.873445 2026] [security2:error] [pid 67073:tid 67304] [client 20.91.215.254:24650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSAfvcmepr5_nHgLbNH2wAAAnc"]
[Tue Aug 18 12:55:42.897232 2026] [security2:error] [pid 67073:tid 67213] [client 20.250.13.23:20674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/bolt.php"] [unique_id "aoSAfvcmepr5_nHgLbNH3QAAAhw"]
[Tue Aug 18 12:55:42.926884 2026] [security2:error] [pid 66623:tid 66691] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSAftO5rbWdOArH04KFmAABXjY"]
[Tue Aug 18 12:55:42.933947 2026] [security2:error] [pid 66623:tid 66888] [client 74.248.130.103:14422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/pucci.php"] [unique_id "aoSAftO5rbWdOArH04KFmQAAAYQ"]
[Tue Aug 18 12:55:42.944791 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:42.945128 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:42.949672 2026] [security2:error] [pid 67073:tid 67245] [client 132.196.61.152:60302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/133.php"] [unique_id "aoSAfvcmepr5_nHgLbNH4wAAAjw"]
[Tue Aug 18 12:55:42.998842 2026] [security2:error] [pid 67073:tid 67327] [client 20.42.19.40:3404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/aa.php"] [unique_id "aoSAfvcmepr5_nHgLbNH5wAAAo4"]
[Tue Aug 18 12:55:43.006229 2026] [security2:error] [pid 67073:tid 67231] [client 20.42.19.40:1360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/ms-edit.php"] [unique_id "aoSAf_cmepr5_nHgLbNH6gAAAi4"]
[Tue Aug 18 12:55:43.020807 2026] [security2:error] [pid 67073:tid 67109] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kj.php"] [unique_id "aoSAf_cmepr5_nHgLbNH7QACWSE"]
[Tue Aug 18 12:55:43.062920 2026] [security2:error] [pid 67073:tid 67297] [client 52.139.47.57:19904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSAf_cmepr5_nHgLbNH7wAAAnA"]
[Tue Aug 18 12:55:43.076038 2026] [security2:error] [pid 67073:tid 67331] [client 20.151.109.219:53245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/fo.php"] [unique_id "aoSAf_cmepr5_nHgLbNH8QAAApI"]
[Tue Aug 18 12:55:43.088363 2026] [security2:error] [pid 67073:tid 67309] [client 20.226.56.190:23764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ke.php"] [unique_id "aoSAf_cmepr5_nHgLbNH8gAAAnw"]
[Tue Aug 18 12:55:43.092291 2026] [security2:error] [pid 67073:tid 67182] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/db.php"] [unique_id "aoSAf_cmepr5_nHgLbNH8wACQmo"]
[Tue Aug 18 12:55:43.093227 2026] [security2:error] [pid 67073:tid 67224] [client 68.221.73.131:9749] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.maxhost.com.br"] [uri "/1.php"] [unique_id "aoSAf_cmepr5_nHgLbNH9QAAAic"]
[Tue Aug 18 12:55:43.093315 2026] [security2:error] [pid 67073:tid 67224] [client 68.221.73.131:9749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/1.php"] [unique_id "aoSAf_cmepr5_nHgLbNH9QAAAic"]
[Tue Aug 18 12:55:43.105791 2026] [security2:error] [pid 67073:tid 67227] [client 158.158.34.183:11317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/simple.php"] [unique_id "aoSAf_cmepr5_nHgLbNH9wAAAio"]
[Tue Aug 18 12:55:43.110430 2026] [security2:error] [pid 67073:tid 67207] [client 20.163.43.14:4463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/abc.php"] [unique_id "aoSAf_cmepr5_nHgLbNH-AAAAhY"]
[Tue Aug 18 12:55:43.121839 2026] [security2:error] [pid 67073:tid 67301] [client 74.248.136.165:44280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/nhr.php"] [unique_id "aoSAf_cmepr5_nHgLbNH-QAAAnQ"]
[Tue Aug 18 12:55:43.143672 2026] [security2:error] [pid 66623:tid 66871] [client 20.104.85.180:7279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAf9O5rbWdOArH04KFnAAAAXM"]
[Tue Aug 18 12:55:43.144195 2026] [security2:error] [pid 66623:tid 66793] [client 20.171.51.14:46015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/10.php"] [unique_id "aoSAf9O5rbWdOArH04KFnQAAASU"]
[Tue Aug 18 12:55:43.158138 2026] [security2:error] [pid 66623:tid 66868] [client 20.163.43.14:4293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wso.php"] [unique_id "aoSAf9O5rbWdOArH04KFngAAAXA"]
[Tue Aug 18 12:55:43.173022 2026] [security2:error] [pid 66623:tid 66830] [client 20.251.48.93:9790] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "filmecompleto.com.br"] [uri "/1.php"] [unique_id "aoSAf9O5rbWdOArH04KFnwAAAUo"]
[Tue Aug 18 12:55:43.173132 2026] [security2:error] [pid 66623:tid 66830] [client 20.251.48.93:9790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/1.php"] [unique_id "aoSAf9O5rbWdOArH04KFnwAAAUo"]
[Tue Aug 18 12:55:43.176640 2026] [security2:error] [pid 66623:tid 66805] [client 52.238.210.254:8869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/dropdown.php"] [unique_id "aoSAf9O5rbWdOArH04KFoAAAATE"]
[Tue Aug 18 12:55:43.203670 2026] [security2:error] [pid 67073:tid 67209] [client 20.100.169.31:46192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAf_cmepr5_nHgLbNH_gAAAhg"]
[Tue Aug 18 12:55:43.253214 2026] [security2:error] [pid 66623:tid 66836] [client 20.42.19.40:2021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/rip.php"] [unique_id "aoSAf9O5rbWdOArH04KFoQAAAVA"]
[Tue Aug 18 12:55:43.258322 2026] [security2:error] [pid 67073:tid 67279] [client 158.23.17.4:10972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/dirs.php"] [unique_id "aoSAf_cmepr5_nHgLbNIAQAAAl4"]
[Tue Aug 18 12:55:43.262941 2026] [security2:error] [pid 67073:tid 67097] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/dropdown.php"] [unique_id "aoSAf_cmepr5_nHgLbNIAgACbhU"]
[Tue Aug 18 12:55:43.263524 2026] [security2:error] [pid 67073:tid 67299] [client 20.42.19.40:3342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAf_cmepr5_nHgLbNIAwAAAnI"]
[Tue Aug 18 12:55:43.269420 2026] [autoindex:error] [pid 67073:tid 67317] [client 20.226.6.191:45867] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:43.293840 2026] [security2:error] [pid 67073:tid 67219] [client 20.226.56.190:20403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/nh.php"] [unique_id "aoSAf_cmepr5_nHgLbNIBQAAAiI"]
[Tue Aug 18 12:55:43.303732 2026] [security2:error] [pid 67073:tid 67217] [client 20.226.6.191:45867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/403.php"] [unique_id "aoSAf_cmepr5_nHgLbNIBgAAAiA"]
[Tue Aug 18 12:55:43.333737 2026] [security2:error] [pid 67073:tid 67283] [client 4.223.164.152:54239] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-content/"] [unique_id "aoSAf_cmepr5_nHgLbNIBwAAAmI"]
[Tue Aug 18 12:55:43.376578 2026] [security2:error] [pid 67073:tid 67241] [client 213.35.127.232:63699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAf_cmepr5_nHgLbNICgAAAjg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:43.383798 2026] [security2:error] [pid 67073:tid 67127] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/vg.php"] [unique_id "aoSAf_cmepr5_nHgLbNICwACkDM"]
[Tue Aug 18 12:55:43.388895 2026] [security2:error] [pid 67073:tid 67321] [client 20.91.215.254:20728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/d.php"] [unique_id "aoSAf_cmepr5_nHgLbNIDAAAAog"]
[Tue Aug 18 12:55:43.407092 2026] [security2:error] [pid 66623:tid 66867] [client 20.65.98.162:17024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "jotaautos.com.br"] [uri "/.mopj.php"] [unique_id "aoSAf9O5rbWdOArH04KFowAAAW8"]
[Tue Aug 18 12:55:43.407697 2026] [security2:error] [pid 66623:tid 66870] [client 20.151.109.219:17566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/loading.php"] [unique_id "aoSAf9O5rbWdOArH04KFpAAAAXI"]
[Tue Aug 18 12:55:43.417961 2026] [security2:error] [pid 67073:tid 67113] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSAf_cmepr5_nHgLbNIDQACLCU"]
[Tue Aug 18 12:55:43.420960 2026] [security2:error] [pid 66623:tid 66821] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSAf9O5rbWdOArH04KFpQAAAUE"]
[Tue Aug 18 12:55:43.422826 2026] [security2:error] [pid 67073:tid 67263] [client 172.202.39.151:65251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/01.php"] [unique_id "aoSAf_cmepr5_nHgLbNIEAAAAk4"]
[Tue Aug 18 12:55:43.432072 2026] [autoindex:error] [pid 67073:tid 67215] [client 20.104.85.180:8021] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:43.432462 2026] [security2:error] [pid 66623:tid 66696] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/file.php"] [unique_id "aoSAf9O5rbWdOArH04KFpgABFDs"]
[Tue Aug 18 12:55:43.461539 2026] [security2:error] [pid 66623:tid 66872] [client 20.226.56.190:45049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/oo.php"] [unique_id "aoSAf9O5rbWdOArH04KFqAAAAXQ"]
[Tue Aug 18 12:55:43.465864 2026] [security2:error] [pid 67073:tid 67222] [client 20.163.43.14:4440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/akcc.php"] [unique_id "aoSAf_cmepr5_nHgLbNIFAAAAiU"]
[Tue Aug 18 12:55:43.473127 2026] [security2:error] [pid 67073:tid 67247] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/post.php"] [unique_id "aoSAf_cmepr5_nHgLbNIFQAAAj4"]
[Tue Aug 18 12:55:43.487214 2026] [security2:error] [pid 66623:tid 66855] [client 20.226.6.191:6653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAf9O5rbWdOArH04KFqQAAAWM"]
[Tue Aug 18 12:55:43.503144 2026] [security2:error] [pid 67073:tid 67230] [client 20.163.43.14:4264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/sf.php"] [unique_id "aoSAf_cmepr5_nHgLbNIFgAAAi0"]
[Tue Aug 18 12:55:43.504046 2026] [security2:error] [pid 67073:tid 67234] [client 20.42.19.40:2006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/update/da222.php"] [unique_id "aoSAf_cmepr5_nHgLbNIFwAAAjE"]
[Tue Aug 18 12:55:43.534169 2026] [security2:error] [pid 67073:tid 67311] [client 52.238.210.254:40244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/dropdown.php"] [unique_id "aoSAf_cmepr5_nHgLbNIGAAAAn4"]
[Tue Aug 18 12:55:43.540986 2026] [security2:error] [pid 67073:tid 67208] [client 74.248.136.165:9902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAf_cmepr5_nHgLbNIGgAAAhc"]
[Tue Aug 18 12:55:43.546710 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:43.546973 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:43.560549 2026] [security2:error] [pid 66623:tid 66887] [client 20.91.215.254:13094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/maint.php"] [unique_id "aoSAf9O5rbWdOArH04KFqgAAAYM"]
[Tue Aug 18 12:55:43.574902 2026] [security2:error] [pid 67073:tid 67332] [client 4.232.151.198:15965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/xleet.php"] [unique_id "aoSAf_cmepr5_nHgLbNIIAAAApM"]
[Tue Aug 18 12:55:43.585674 2026] [security2:error] [pid 66623:tid 66859] [client 74.7.241.168:54862] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "veiculossaojose.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSAf9O5rbWdOArH04KFrAABZzo"]
[Tue Aug 18 12:55:43.598146 2026] [security2:error] [pid 67073:tid 67198] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/goods.php"] [unique_id "aoSAf_cmepr5_nHgLbNIIQACM3o"]
[Tue Aug 18 12:55:43.617127 2026] [security2:error] [pid 67073:tid 67211] [client 138.36.100.162:41935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAf_cmepr5_nHgLbNIIgAAAho"]
[Tue Aug 18 12:55:43.617221 2026] [security2:error] [pid 67073:tid 67211] [client 138.36.100.162:41935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAf_cmepr5_nHgLbNIIgAAAho"]
[Tue Aug 18 12:55:43.637232 2026] [security2:error] [pid 67073:tid 67081] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/sm.php"] [unique_id "aoSAf_cmepr5_nHgLbNIIwACYQU"]
[Tue Aug 18 12:55:43.648227 2026] [security2:error] [pid 67073:tid 67246] [client 52.238.210.254:10117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/file.php"] [unique_id "aoSAf_cmepr5_nHgLbNIJQAAAj0"]
[Tue Aug 18 12:55:43.673000 2026] [security2:error] [pid 67073:tid 67296] [client 20.226.56.190:31633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ja.php"] [unique_id "aoSAf_cmepr5_nHgLbNIJwAAAm8"]
[Tue Aug 18 12:55:43.699565 2026] [security2:error] [pid 67073:tid 67285] [client 20.151.109.219:45730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ke.php"] [unique_id "aoSAf_cmepr5_nHgLbNIKAAAAmQ"]
[Tue Aug 18 12:55:43.702988 2026] [security2:error] [pid 67073:tid 67273] [client 20.104.85.180:8021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSAf_cmepr5_nHgLbNIKQAAAlg"]
[Tue Aug 18 12:55:43.706958 2026] [security2:error] [pid 66623:tid 66767] [client 20.42.19.40:3450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/about.php"] [unique_id "aoSAf9O5rbWdOArH04KFrgAAAQs"]
[Tue Aug 18 12:55:43.707661 2026] [security2:error] [pid 67073:tid 67245] [client 132.196.61.152:60343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/1xmomo.php"] [unique_id "aoSAf_cmepr5_nHgLbNIKgAAAjw"]
[Tue Aug 18 12:55:43.718615 2026] [security2:error] [pid 67073:tid 67266] [client 20.48.236.86:16276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/bibil.php"] [unique_id "aoSAf_cmepr5_nHgLbNILAAAAlE"]
[Tue Aug 18 12:55:43.720284 2026] [security2:error] [pid 67073:tid 67318] [client 172.202.39.151:53074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAf_cmepr5_nHgLbNILQAAAoU"]
[Tue Aug 18 12:55:43.739206 2026] [security2:error] [pid 67073:tid 67231] [client 20.42.19.40:9651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/upload.php"] [unique_id "aoSAf_cmepr5_nHgLbNILwAAAi4"]
[Tue Aug 18 12:55:43.751550 2026] [security2:error] [pid 66623:tid 66808] [client 172.182.200.96:14141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSAf9O5rbWdOArH04KFsAAAATQ"]
[Tue Aug 18 12:55:43.769128 2026] [security2:error] [pid 67073:tid 67181] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/hplfuns.php"] [unique_id "aoSAf_cmepr5_nHgLbNIMAACh2k"]
[Tue Aug 18 12:55:43.774822 2026] [security2:error] [pid 66623:tid 66893] [client 4.223.164.152:46172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/simple.php"] [unique_id "aoSAf9O5rbWdOArH04KFsgAAAYk"]
[Tue Aug 18 12:55:43.785446 2026] [security2:error] [pid 66623:tid 66857] [client 20.205.121.237:5098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/install.php"] [unique_id "aoSAf9O5rbWdOArH04KFswAAAWU"]
[Tue Aug 18 12:55:43.795169 2026] [security2:error] [pid 67073:tid 67314] [client 20.163.43.14:4441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wk/index.php"] [unique_id "aoSAf_cmepr5_nHgLbNIMgAAAoE"]
[Tue Aug 18 12:55:43.803916 2026] [security2:error] [pid 67073:tid 67271] [client 178.156.189.249:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "yycc.com.br"] [uri "/index.php"] [unique_id "aoSAfvcmepr5_nHgLbNHuQACVm8"], referer: https://yycc.com.br/
[Tue Aug 18 12:55:43.814372 2026] [security2:error] [pid 66623:tid 66862] [client 5.31.227.224:7833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAf9O5rbWdOArH04KFtQAAAWo"]
[Tue Aug 18 12:55:43.814453 2026] [security2:error] [pid 66623:tid 66862] [client 5.31.227.224:7833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAf9O5rbWdOArH04KFtQAAAWo"]
[Tue Aug 18 12:55:43.829609 2026] [security2:error] [pid 66623:tid 66769] [client 68.221.73.131:61269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/img.php"] [unique_id "aoSAf9O5rbWdOArH04KFtgAAAQ0"]
[Tue Aug 18 12:55:43.832981 2026] [security2:error] [pid 67073:tid 67297] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/public/assets/design_1/css/parts/course_cards/grid_card_1.min.php"] [unique_id "aoSAf_cmepr5_nHgLbNINAAAAnA"]
[Tue Aug 18 12:55:43.835026 2026] [security2:error] [pid 67073:tid 67232] [client 20.163.43.14:4230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/index/function.php"] [unique_id "aoSAf_cmepr5_nHgLbNINQAAAi8"]
[Tue Aug 18 12:55:43.857703 2026] [security2:error] [pid 67073:tid 67207] [client 20.100.169.31:28577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSAf_cmepr5_nHgLbNIOAAAAhY"]
[Tue Aug 18 12:55:43.880390 2026] [security2:error] [pid 67073:tid 67188] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/28.php"] [unique_id "aoSAf_cmepr5_nHgLbNIOgACW3A"]
[Tue Aug 18 12:55:43.895392 2026] [security2:error] [pid 67073:tid 67206] [client 158.23.17.4:9283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/fresh.php"] [unique_id "aoSAf_cmepr5_nHgLbNIOwAAAhU"]
[Tue Aug 18 12:55:43.933083 2026] [security2:error] [pid 66623:tid 66720] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/htaccess.php"] [unique_id "aoSAf9O5rbWdOArH04KFtwABQ1M"]
[Tue Aug 18 12:55:43.958698 2026] [security2:error] [pid 67073:tid 67209] [client 74.248.136.165:10093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ws79.php"] [unique_id "aoSAf_cmepr5_nHgLbNIPgAAAhg"]
[Tue Aug 18 12:55:43.982154 2026] [security2:error] [pid 67073:tid 67326] [client 20.42.19.40:9652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wk/index.php"] [unique_id "aoSAf_cmepr5_nHgLbNIPwAAAo0"]
[Tue Aug 18 12:55:43.988260 2026] [security2:error] [pid 66623:tid 66783] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAf9O5rbWdOArH04KFuQAAARs"]
[Tue Aug 18 12:55:43.996150 2026] [security2:error] [pid 66623:tid 66772] [client 20.151.109.219:24884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/nh.php"] [unique_id "aoSAf9O5rbWdOArH04KFugAAARA"]
[Tue Aug 18 12:55:44.005418 2026] [security2:error] [pid 67073:tid 67302] [client 52.139.47.57:9063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAgPcmepr5_nHgLbNIQQAAAnU"]
[Tue Aug 18 12:55:44.011784 2026] [security2:error] [pid 66623:tid 66809] [client 135.225.75.187:18714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/tt.php"] [unique_id "aoSAgNO5rbWdOArH04KFuwAAATU"]
[Tue Aug 18 12:55:44.022811 2026] [security2:error] [pid 66623:tid 66784] [client 20.171.51.14:28863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/te.php"] [unique_id "aoSAgNO5rbWdOArH04KFvQAAARw"]
[Tue Aug 18 12:55:44.023137 2026] [security2:error] [pid 66623:tid 66835] [client 20.116.17.175:57630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSAgNO5rbWdOArH04KFvgAAAU8"]
[Tue Aug 18 12:55:44.032317 2026] [security2:error] [pid 66623:tid 66786] [client 20.104.85.180:7982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAgNO5rbWdOArH04KFvwAAAR4"]
[Tue Aug 18 12:55:44.094290 2026] [security2:error] [pid 67073:tid 67115] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/m.php"] [unique_id "aoSAgPcmepr5_nHgLbNIRQACbic"]
[Tue Aug 18 12:55:44.098573 2026] [security2:error] [pid 67073:tid 67192] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/images/wso.php"] [unique_id "aoSAgPcmepr5_nHgLbNIRwACcnQ"]
[Tue Aug 18 12:55:44.123066 2026] [security2:error] [pid 66623:tid 66861] [client 20.163.43.14:2944] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/1.php"] [unique_id "aoSAgNO5rbWdOArH04KFyAAAAWk"]
[Tue Aug 18 12:55:44.123100 2026] [security2:error] [pid 66623:tid 66812] [client 20.42.19.40:3331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/goods.php"] [unique_id "aoSAgNO5rbWdOArH04KFxwAAATg"]
[Tue Aug 18 12:55:44.123157 2026] [security2:error] [pid 66623:tid 66861] [client 20.163.43.14:2944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/1.php"] [unique_id "aoSAgNO5rbWdOArH04KFyAAAAWk"]
[Tue Aug 18 12:55:44.136229 2026] [security2:error] [pid 66623:tid 66820] [client 20.226.56.190:2525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/xx.php"] [unique_id "aoSAgNO5rbWdOArH04KFyQAAAUA"]
[Tue Aug 18 12:55:44.153101 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:44.153540 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:44.202523 2026] [security2:error] [pid 66623:tid 66877] [client 20.163.43.14:4172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/edit.php"] [unique_id "aoSAgNO5rbWdOArH04KFzgAAAXk"]
[Tue Aug 18 12:55:44.203800 2026] [security2:error] [pid 67073:tid 67306] [client 158.158.34.183:17485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/berax.php"] [unique_id "aoSAgPcmepr5_nHgLbNIUAAAAnk"]
[Tue Aug 18 12:55:44.210867 2026] [security2:error] [pid 67073:tid 67324] [client 20.91.215.254:20730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-includes/widgets.php"] [unique_id "aoSAgPcmepr5_nHgLbNIUQAAAos"]
[Tue Aug 18 12:55:44.219446 2026] [security2:error] [pid 67073:tid 67303] [client 20.42.19.40:9706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-act.php"] [unique_id "aoSAgPcmepr5_nHgLbNIUgAAAnY"]
[Tue Aug 18 12:55:44.226815 2026] [security2:error] [pid 67073:tid 67223] [client 4.223.164.152:46185] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-admin/css/colors/blue/"] [unique_id "aoSAgPcmepr5_nHgLbNIUwAAAiY"]
[Tue Aug 18 12:55:44.256687 2026] [security2:error] [pid 67073:tid 67268] [client 20.251.48.93:61159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/img.php"] [unique_id "aoSAgPcmepr5_nHgLbNIVgAAAlM"]
[Tue Aug 18 12:55:44.257628 2026] [security2:error] [pid 66623:tid 66882] [client 52.238.210.254:8905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/goods.php"] [unique_id "aoSAgNO5rbWdOArH04KFzwAAAX4"]
[Tue Aug 18 12:55:44.267077 2026] [security2:error] [pid 66623:tid 66782] [client 132.196.61.152:61007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/mosty.php"] [unique_id "aoSAgNO5rbWdOArH04KF0AAAARo"]
[Tue Aug 18 12:55:44.269120 2026] [security2:error] [pid 67073:tid 67174] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/index/function.php"] [unique_id "aoSAgPcmepr5_nHgLbNIVwACbGI"]
[Tue Aug 18 12:55:44.273831 2026] [security2:error] [pid 66623:tid 66829] [client 20.65.69.59:49312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/album.php"] [unique_id "aoSAgNO5rbWdOArH04KF0QAAAUk"]
[Tue Aug 18 12:55:44.278827 2026] [security2:error] [pid 66623:tid 66840] [client 20.91.215.254:19510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/phpMailer.php"] [unique_id "aoSAgNO5rbWdOArH04KF0gAAAVQ"]
[Tue Aug 18 12:55:44.293158 2026] [security2:error] [pid 67073:tid 67184] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.hermes/.env"] [unique_id "aoSAgPcmepr5_nHgLbNIWQACXWw"]
[Tue Aug 18 12:55:44.296685 2026] [security2:error] [pid 67073:tid 67256] [client 20.226.6.191:7153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAgPcmepr5_nHgLbNIWgAAAkc"]
[Tue Aug 18 12:55:44.317824 2026] [security2:error] [pid 66623:tid 66775] [client 20.104.85.180:8028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp.php"] [unique_id "aoSAgNO5rbWdOArH04KF0wAAARM"]
[Tue Aug 18 12:55:44.326069 2026] [security2:error] [pid 67073:tid 67307] [client 20.48.236.86:16382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/halo.php"] [unique_id "aoSAgPcmepr5_nHgLbNIXAAAAno"]
[Tue Aug 18 12:55:44.340231 2026] [security2:error] [pid 67073:tid 67212] [client 20.151.109.219:17579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/oo.php"] [unique_id "aoSAgPcmepr5_nHgLbNIXQAAAhs"]
[Tue Aug 18 12:55:44.378674 2026] [security2:error] [pid 66623:tid 66856] [client 74.248.136.165:29107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/rtx.php"] [unique_id "aoSAgNO5rbWdOArH04KF1QAAAWQ"]
[Tue Aug 18 12:55:44.380849 2026] [security2:error] [pid 67073:tid 67313] [client 68.155.154.236:16366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wsrer.php"] [unique_id "aoSAgPcmepr5_nHgLbNIYgAAAoA"]
[Tue Aug 18 12:55:44.388629 2026] [security2:error] [pid 67073:tid 67228] [client 213.35.127.232:63910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAgPcmepr5_nHgLbNIYwAAAis"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:44.410333 2026] [security2:error] [pid 66623:tid 66863] [client 68.221.73.131:61266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/222.php"] [unique_id "aoSAgNO5rbWdOArH04KF1gAAAWs"]
[Tue Aug 18 12:55:44.413563 2026] [security2:error] [pid 67073:tid 67173] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/nl.php"] [unique_id "aoSAgPcmepr5_nHgLbNIZAACMWE"]
[Tue Aug 18 12:55:44.436457 2026] [security2:error] [pid 66623:tid 66705] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/info.php"] [unique_id "aoSAgNO5rbWdOArH04KF1wABXkQ"]
[Tue Aug 18 12:55:44.472635 2026] [security2:error] [pid 67073:tid 67258] [client 20.163.43.14:4355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSAgPcmepr5_nHgLbNIZwAAAkk"]
[Tue Aug 18 12:55:44.476806 2026] [security2:error] [pid 67073:tid 67284] [client 20.42.19.40:9625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSAgPcmepr5_nHgLbNIaAAAAmM"]
[Tue Aug 18 12:55:44.480171 2026] [security2:error] [pid 67073:tid 67329] [client 20.100.169.31:31480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSAgPcmepr5_nHgLbNIaQAAApA"]
[Tue Aug 18 12:55:44.482669 2026] [security2:error] [pid 67073:tid 67305] [client 20.226.56.190:47107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/conn-test.php"] [unique_id "aoSAgPcmepr5_nHgLbNIagAAAng"]
[Tue Aug 18 12:55:44.501756 2026] [security2:error] [pid 67073:tid 67332] [client 20.42.19.40:3409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/php8.php"] [unique_id "aoSAgPcmepr5_nHgLbNIbAAAApM"]
[Tue Aug 18 12:55:44.531861 2026] [security2:error] [pid 67073:tid 67310] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/public/css.php"] [unique_id "aoSAgPcmepr5_nHgLbNIbgAAAn0"]
[Tue Aug 18 12:55:44.533203 2026] [security2:error] [pid 66623:tid 66790] [client 20.171.51.14:45424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/kc.php"] [unique_id "aoSAgNO5rbWdOArH04KF2QAAASI"]
[Tue Aug 18 12:55:44.545145 2026] [security2:error] [pid 67073:tid 67242] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/blurbs.php"] [unique_id "aoSAgPcmepr5_nHgLbNIcAAAAjk"]
[Tue Aug 18 12:55:44.582411 2026] [security2:error] [pid 66623:tid 66793] [client 74.248.130.103:14451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-temp.php"] [unique_id "aoSAgNO5rbWdOArH04KF2gAAASU"]
[Tue Aug 18 12:55:44.597884 2026] [security2:error] [pid 66623:tid 66868] [client 20.104.85.180:8038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/function/function.php"] [unique_id "aoSAgNO5rbWdOArH04KF2wAAAXA"]
[Tue Aug 18 12:55:44.602087 2026] [security2:error] [pid 67073:tid 67091] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/profile.php"] [unique_id "aoSAgPcmepr5_nHgLbNIcwACGQ8"]
[Tue Aug 18 12:55:44.620331 2026] [security2:error] [pid 67073:tid 67194] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/68.php"] [unique_id "aoSAgPcmepr5_nHgLbNIdAACUHY"]
[Tue Aug 18 12:55:44.623849 2026] [security2:error] [pid 66623:tid 66805] [client 52.238.210.254:8879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/hplfuns.php"] [unique_id "aoSAgNO5rbWdOArH04KF3AAAATE"]
[Tue Aug 18 12:55:44.625299 2026] [security2:error] [pid 66623:tid 66787] [client 20.151.109.219:24860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ja.php"] [unique_id "aoSAgNO5rbWdOArH04KF3QAAAR8"]
[Tue Aug 18 12:55:44.658778 2026] [security2:error] [pid 67073:tid 67225] [client 4.223.164.152:64700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/chosen.php"] [unique_id "aoSAgPcmepr5_nHgLbNIdwAAAig"]
[Tue Aug 18 12:55:44.672632 2026] [security2:error] [pid 67073:tid 67233] [client 20.29.77.16:52765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/email.php"] [unique_id "aoSAgPcmepr5_nHgLbNIeAAAAjA"]
[Tue Aug 18 12:55:44.705011 2026] [security2:error] [pid 67073:tid 67266] [client 20.226.56.190:2557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/fg.php"] [unique_id "aoSAgPcmepr5_nHgLbNIegAAAlE"]
[Tue Aug 18 12:55:44.737960 2026] [security2:error] [pid 67073:tid 67271] [client 20.163.43.14:4343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSAgPcmepr5_nHgLbNIgQAAAlY"]
[Tue Aug 18 12:55:44.752461 2026] [authz_core:error] [pid 67073:tid 67158] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:44.752776 2026] [authz_core:error] [pid 67073:tid 67158] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:44.773017 2026] [security2:error] [pid 67073:tid 67178] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/sx.php"] [unique_id "aoSAgPcmepr5_nHgLbNIgwACkWY"]
[Tue Aug 18 12:55:44.774901 2026] [security2:error] [pid 67073:tid 67297] [client 158.23.17.4:9349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/admin404.php"] [unique_id "aoSAgPcmepr5_nHgLbNIhAAAAnA"]
[Tue Aug 18 12:55:44.784245 2026] [security2:error] [pid 67073:tid 67292] [client 20.226.6.191:6621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/rip.php"] [unique_id "aoSAgPcmepr5_nHgLbNIhgAAAms"]
[Tue Aug 18 12:55:44.801993 2026] [security2:error] [pid 67073:tid 67316] [client 74.248.136.165:43695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/end.php"] [unique_id "aoSAgPcmepr5_nHgLbNIhwAAAoM"]
[Tue Aug 18 12:55:44.814763 2026] [security2:error] [pid 67073:tid 67207] [client 20.163.43.14:4465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAgPcmepr5_nHgLbNIiAAAAhY"]
[Tue Aug 18 12:55:44.837312 2026] [security2:error] [pid 67073:tid 67276] [client 20.116.17.175:57642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/output.php"] [unique_id "aoSAgPcmepr5_nHgLbNIjAAAAls"]
[Tue Aug 18 12:55:44.876949 2026] [security2:error] [pid 67073:tid 67201] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/jl.php"] [unique_id "aoSAgPcmepr5_nHgLbNIjgACGH0"]
[Tue Aug 18 12:55:44.883590 2026] [security2:error] [pid 67073:tid 67326] [client 132.196.61.152:61026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/blurbs.php"] [unique_id "aoSAgPcmepr5_nHgLbNIjwAAAo0"]
[Tue Aug 18 12:55:44.900479 2026] [security2:error] [pid 66623:tid 66794] [client 20.104.85.180:7283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSAgNO5rbWdOArH04KF3wAAASY"]
[Tue Aug 18 12:55:44.903983 2026] [security2:error] [pid 67073:tid 67238] [client 20.151.109.219:59774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/xx.php"] [unique_id "aoSAgPcmepr5_nHgLbNIkQAAAjU"]
[Tue Aug 18 12:55:44.923975 2026] [security2:error] [pid 67073:tid 67318] [client 20.91.215.254:14301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSAgPcmepr5_nHgLbNIkwAAAoU"]
[Tue Aug 18 12:55:44.939128 2026] [fcgid:warn] [pid 66623:tid 66870] (70014)End of file found: [client 66.132.186.180:34584] mod_fcgid: can't get data from http client
[Tue Aug 18 12:55:44.945128 2026] [security2:error] [pid 67073:tid 67096] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSAgPcmepr5_nHgLbNImAACRRQ"]
[Tue Aug 18 12:55:44.958551 2026] [security2:error] [pid 66623:tid 66780] [client 20.100.169.31:45627] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/1.php"] [unique_id "aoSAgNO5rbWdOArH04KF4QAAARg"]
[Tue Aug 18 12:55:44.958648 2026] [security2:error] [pid 66623:tid 66780] [client 20.100.169.31:45627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/1.php"] [unique_id "aoSAgNO5rbWdOArH04KF4QAAARg"]
[Tue Aug 18 12:55:44.978904 2026] [security2:error] [pid 67073:tid 67223] [client 52.139.47.57:47632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/wp-includes/Text/Diff/Engine.php"] [unique_id "aoSAgPcmepr5_nHgLbNImwAAAiY"]
[Tue Aug 18 12:55:44.979623 2026] [security2:error] [pid 66623:tid 66811] [client 157.20.138.62:58604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAgNO5rbWdOArH04KF4gAAATc"]
[Tue Aug 18 12:55:44.979739 2026] [security2:error] [pid 66623:tid 66811] [client 157.20.138.62:58604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAgNO5rbWdOArH04KF4gAAATc"]
[Tue Aug 18 12:55:44.979832 2026] [security2:error] [pid 66623:tid 66821] [client 172.202.39.151:50227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/lv.php"] [unique_id "aoSAgNO5rbWdOArH04KF4wAAAUE"]
[Tue Aug 18 12:55:44.995836 2026] [security2:error] [pid 66623:tid 66776] [client 20.48.236.86:16270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/ajq1s.php"] [unique_id "aoSAgNO5rbWdOArH04KF5AAAARQ"]
[Tue Aug 18 12:55:45.047013 2026] [security2:error] [pid 67073:tid 67278] [client 20.42.19.40:3430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/info.php"] [unique_id "aoSAgfcmepr5_nHgLbNIogAAAl0"]
[Tue Aug 18 12:55:45.053203 2026] [authz_core:error] [pid 67073:tid 67124] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:45.053443 2026] [authz_core:error] [pid 67073:tid 67124] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:45.057587 2026] [security2:error] [pid 67073:tid 67256] [client 20.65.69.59:57027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/creds.php"] [unique_id "aoSAgfcmepr5_nHgLbNIowAAAkc"]
[Tue Aug 18 12:55:45.060454 2026] [security2:error] [pid 67073:tid 67281] [client 20.163.43.14:4347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-good.php"] [unique_id "aoSAgfcmepr5_nHgLbNIpAAAAmA"]
[Tue Aug 18 12:55:45.075621 2026] [security2:error] [pid 67073:tid 67263] [client 68.221.73.131:61292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/key.php"] [unique_id "aoSAgfcmepr5_nHgLbNIpQAAAk4"]
[Tue Aug 18 12:55:45.077501 2026] [security2:error] [pid 67073:tid 67289] [client 4.223.164.152:46183] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/block-bindings/"] [unique_id "aoSAgfcmepr5_nHgLbNIpgAAAmg"]
[Tue Aug 18 12:55:45.087474 2026] [security2:error] [pid 67073:tid 67231] [client 20.91.215.254:20714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSAgfcmepr5_nHgLbNIqAAAAi4"]
[Tue Aug 18 12:55:45.107400 2026] [security2:error] [pid 67073:tid 67259] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/bajah.php"] [unique_id "aoSAgfcmepr5_nHgLbNIqwAAAko"]
[Tue Aug 18 12:55:45.114985 2026] [security2:error] [pid 67073:tid 67152] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAgfcmepr5_nHgLbNIrAACNkw"]
[Tue Aug 18 12:55:45.117843 2026] [security2:error] [pid 67073:tid 67145] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/tq.php"] [unique_id "aoSAgfcmepr5_nHgLbNIrQACG0U"]
[Tue Aug 18 12:55:45.180246 2026] [security2:error] [pid 67073:tid 67313] [client 20.205.121.237:5063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAgfcmepr5_nHgLbNIsAAAAoA"]
[Tue Aug 18 12:55:45.189224 2026] [security2:error] [pid 67073:tid 67257] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/r.php"] [unique_id "aoSAgfcmepr5_nHgLbNIsgAAAkg"]
[Tue Aug 18 12:55:45.189684 2026] [security2:error] [pid 66623:tid 66859] [client 135.225.75.187:37273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/xqq.php"] [unique_id "aoSAgdO5rbWdOArH04KF5QAAAWc"]
[Tue Aug 18 12:55:45.197780 2026] [security2:error] [pid 66623:tid 66831] [client 158.158.74.177:16561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/g.php"] [unique_id "aoSAgdO5rbWdOArH04KF5gAAAUs"]
[Tue Aug 18 12:55:45.219205 2026] [security2:error] [pid 67073:tid 67208] [client 20.171.51.14:51797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/lmfi2.php"] [unique_id "aoSAgfcmepr5_nHgLbNIswAAAhc"]
[Tue Aug 18 12:55:45.220494 2026] [security2:error] [pid 66623:tid 66854] [client 74.248.136.165:44282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ae.php"] [unique_id "aoSAgdO5rbWdOArH04KF6AAAAWI"]
[Tue Aug 18 12:55:45.220943 2026] [security2:error] [pid 66623:tid 66841] [client 20.171.51.14:59290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/jn.php"] [unique_id "aoSAgdO5rbWdOArH04KF6QAAAVU"]
[Tue Aug 18 12:55:45.224260 2026] [security2:error] [pid 67073:tid 67252] [client 20.163.43.14:4423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/as.php"] [unique_id "aoSAgfcmepr5_nHgLbNItAAAAkM"]
[Tue Aug 18 12:55:45.229128 2026] [security2:error] [pid 67073:tid 67305] [client 20.104.85.180:8032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSAgfcmepr5_nHgLbNItgAAAng"]
[Tue Aug 18 12:55:45.260693 2026] [security2:error] [pid 67073:tid 67240] [client 52.173.121.69:24972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSAgfcmepr5_nHgLbNIuAAAAjc"]
[Tue Aug 18 12:55:45.271160 2026] [security2:error] [pid 66623:tid 66802] [client 20.151.109.219:64991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/conn-test.php"] [unique_id "aoSAgdO5rbWdOArH04KF7QAAAS4"]
[Tue Aug 18 12:55:45.276346 2026] [security2:error] [pid 67073:tid 67232] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAgfcmepr5_nHgLbNIpwACL0I"]
[Tue Aug 18 12:55:45.286710 2026] [security2:error] [pid 67073:tid 67306] [client 158.158.34.183:50216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/fi2.php"] [unique_id "aoSAgfcmepr5_nHgLbNIuwAAAnk"]
[Tue Aug 18 12:55:45.332339 2026] [autoindex:error] [pid 67073:tid 67141] [remote 74.248.18.37:0] AH01276: Cannot serve directory /home1/powerbelt/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:45.339371 2026] [security2:error] [pid 67073:tid 67210] [client 20.100.169.31:33136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSAgfcmepr5_nHgLbNIvQAAAhk"]
[Tue Aug 18 12:55:45.342656 2026] [security2:error] [pid 67073:tid 67296] [client 20.116.17.175:57429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/tiny2.php"] [unique_id "aoSAgfcmepr5_nHgLbNIvgAAAm8"]
[Tue Aug 18 12:55:45.348035 2026] [security2:error] [pid 67073:tid 67243] [client 20.42.19.40:9678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAgfcmepr5_nHgLbNIwAAAAjo"]
[Tue Aug 18 12:55:45.353014 2026] [security2:error] [pid 67073:tid 67154] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/cv.php"] [unique_id "aoSAgfcmepr5_nHgLbNIwQACUE4"]
[Tue Aug 18 12:55:45.387739 2026] [security2:error] [pid 67073:tid 67135] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "uhequeimado.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSAgfcmepr5_nHgLbNIxAACZjs"]
[Tue Aug 18 12:55:45.389467 2026] [security2:error] [pid 66623:tid 66826] [client 4.232.151.198:33876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/wp.php"] [unique_id "aoSAgdO5rbWdOArH04KF7gAAAUY"]
[Tue Aug 18 12:55:45.400425 2026] [security2:error] [pid 67073:tid 67255] [client 213.35.127.232:64130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAgfcmepr5_nHgLbNIxwAAAkY"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:45.401911 2026] [security2:error] [pid 66623:tid 66824] [client 158.158.74.177:22730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/gecko.php"] [unique_id "aoSAgdO5rbWdOArH04KF7wAAAUQ"]
[Tue Aug 18 12:55:45.409203 2026] [security2:error] [pid 67073:tid 67274] [client 20.226.6.191:6547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAgfcmepr5_nHgLbNIyAAAAlk"]
[Tue Aug 18 12:55:45.504938 2026] [security2:error] [pid 67073:tid 67095] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAgfcmepr5_nHgLbNIzAACKhM"]
[Tue Aug 18 12:55:45.506489 2026] [security2:error] [pid 67073:tid 67207] [client 20.226.56.190:2547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ve.php"] [unique_id "aoSAgfcmepr5_nHgLbNIzQAAAhY"]
[Tue Aug 18 12:55:45.530874 2026] [security2:error] [pid 66623:tid 66853] [client 20.104.85.180:7243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/ok.php"] [unique_id "aoSAgdO5rbWdOArH04KF8AAAAWE"]
[Tue Aug 18 12:55:45.551635 2026] [security2:error] [pid 67073:tid 67206] [client 4.223.164.152:64665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/als.php"] [unique_id "aoSAgfcmepr5_nHgLbNI0AAAAhU"]
[Tue Aug 18 12:55:45.554966 2026] [security2:error] [pid 67073:tid 67107] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/un.php"] [unique_id "aoSAgfcmepr5_nHgLbNI0QACWh8"]
[Tue Aug 18 12:55:45.558635 2026] [autoindex:error] [pid 66623:tid 66769] [client 20.226.6.191:56214] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:45.566186 2026] [security2:error] [pid 66623:tid 66825] [client 20.91.215.254:14289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/al.php"] [unique_id "aoSAgdO5rbWdOArH04KF8wAAAUU"]
[Tue Aug 18 12:55:45.575438 2026] [security2:error] [pid 67073:tid 67280] [client 20.151.109.219:53211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/fg.php"] [unique_id "aoSAgfcmepr5_nHgLbNI1AAAAl8"]
[Tue Aug 18 12:55:45.593633 2026] [security2:error] [pid 66623:tid 66832] [client 20.163.43.14:4365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAgdO5rbWdOArH04KF9QAAAUw"]
[Tue Aug 18 12:55:45.609237 2026] [security2:error] [pid 67073:tid 67286] [client 126.159.39.191:56562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.39.159.126.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innacorp.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAgfcmepr5_nHgLbNIygAAAmU"]
[Tue Aug 18 12:55:45.609345 2026] [security2:error] [pid 67073:tid 67286] [client 126.159.39.191:56562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innacorp.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAgfcmepr5_nHgLbNIygAAAmU"]
[Tue Aug 18 12:55:45.623841 2026] [security2:error] [pid 67073:tid 67222] [client 149.34.210.141:50421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAgfcmepr5_nHgLbNI1gAAAiU"]
[Tue Aug 18 12:55:45.636217 2026] [autoindex:error] [pid 67073:tid 67291] [client 52.73.140.57:14715] AH01276: Cannot serve directory /home1/xsolutions/advoguide.3xsolutions.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:45.671439 2026] [security2:error] [pid 67073:tid 67279] [client 20.251.48.93:61175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/222.php"] [unique_id "aoSAgfcmepr5_nHgLbNI2wAAAl4"]
[Tue Aug 18 12:55:45.682005 2026] [security2:error] [pid 67073:tid 67299] [client 20.226.56.190:23748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ia.php"] [unique_id "aoSAgfcmepr5_nHgLbNI3QAAAnI"]
[Tue Aug 18 12:55:45.684471 2026] [security2:error] [pid 66623:tid 66881] [client 35.240.145.190:33724] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "ferreirafreitas.com.br"] [uri "/"] [unique_id "aoSAgdO5rbWdOArH04KF9gAAAX0"]
[Tue Aug 18 12:55:45.687928 2026] [security2:error] [pid 67073:tid 67254] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/domvf.php"] [unique_id "aoSAgfcmepr5_nHgLbNI3wAAAkU"]
[Tue Aug 18 12:55:45.711619 2026] [security2:error] [pid 66623:tid 66809] [client 20.42.19.40:1351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSAgdO5rbWdOArH04KF9wAAATU"]
[Tue Aug 18 12:55:45.717642 2026] [security2:error] [pid 67073:tid 67324] [client 74.248.130.103:38718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAgfcmepr5_nHgLbNI4QAAAos"]
[Tue Aug 18 12:55:45.724877 2026] [autoindex:error] [pid 67073:tid 67125] [remote 74.248.18.37:0] AH01276: Cannot serve directory /home1/powerbelt/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:45.740949 2026] [security2:error] [pid 67073:tid 67268] [client 20.163.43.14:4240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/tes.php"] [unique_id "aoSAgfcmepr5_nHgLbNI4wAAAlM"]
[Tue Aug 18 12:55:45.747990 2026] [security2:error] [pid 67073:tid 67320] [client 68.221.73.131:61294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/chosen.php"] [unique_id "aoSAgfcmepr5_nHgLbNI5AAAAoc"]
[Tue Aug 18 12:55:45.773205 2026] [security2:error] [pid 67073:tid 67235] [client 20.171.51.14:51808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/bf.php"] [unique_id "aoSAgfcmepr5_nHgLbNI5gAAAjI"]
[Tue Aug 18 12:55:45.789412 2026] [security2:error] [pid 67073:tid 67122] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "uhequeimado.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSAgfcmepr5_nHgLbNI5wACXS4"]
[Tue Aug 18 12:55:45.791963 2026] [security2:error] [pid 67073:tid 67229] [client 52.238.210.254:10224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/htaccess.php"] [unique_id "aoSAgfcmepr5_nHgLbNI6QAAAiw"]
[Tue Aug 18 12:55:45.796304 2026] [security2:error] [pid 66623:tid 66786] [client 20.65.98.162:28513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/bengi.php"] [unique_id "aoSAgdO5rbWdOArH04KF-AAAAR4"]
[Tue Aug 18 12:55:45.815087 2026] [security2:error] [pid 67073:tid 67103] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uhequeimado.com.br"] [uri "/config/.env.php"] [unique_id "aoSAgfcmepr5_nHgLbNI6gACYBs"]
[Tue Aug 18 12:55:45.816357 2026] [security2:error] [pid 67073:tid 67219] [client 20.104.85.180:7964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/item.php"] [unique_id "aoSAgfcmepr5_nHgLbNI6wAAAiI"]
[Tue Aug 18 12:55:45.851923 2026] [security2:error] [pid 67073:tid 67263] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/radio.php"] [unique_id "aoSAgfcmepr5_nHgLbNI7QAAAk4"]
[Tue Aug 18 12:55:45.885203 2026] [security2:error] [pid 67073:tid 67165] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/evil.php"] [unique_id "aoSAgfcmepr5_nHgLbNI7gACNlk"]
[Tue Aug 18 12:55:45.891336 2026] [security2:error] [pid 67073:tid 67222] [client 149.34.210.141:50421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAgfcmepr5_nHgLbNI1gAAAiU"]
[Tue Aug 18 12:55:45.900003 2026] [security2:error] [pid 67073:tid 67114] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSAgfcmepr5_nHgLbNI7wACKSY"]
[Tue Aug 18 12:55:45.924372 2026] [security2:error] [pid 67073:tid 67079] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/laravel/.env"] [unique_id "aoSAgfcmepr5_nHgLbNI8QACTwM"]
[Tue Aug 18 12:55:45.948038 2026] [security2:error] [pid 66623:tid 66779] [client 20.65.69.59:40523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/mandrill.php"] [unique_id "aoSAgdO5rbWdOArH04KF-gAAARc"]
[Tue Aug 18 12:55:45.956812 2026] [security2:error] [pid 67073:tid 67328] [client 74.248.18.37:59823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/ws83.php"] [unique_id "aoSAgfcmepr5_nHgLbNI9QAAAo8"]
[Tue Aug 18 12:55:45.960430 2026] [security2:error] [pid 67073:tid 67087] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uhequeimado.com.br"] [uri "/.env.php.bak"] [unique_id "aoSAgfcmepr5_nHgLbNI9gACSws"]
[Tue Aug 18 12:55:45.961585 2026] [security2:error] [pid 67073:tid 67311] [client 20.151.109.219:17544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ve.php"] [unique_id "aoSAgfcmepr5_nHgLbNI9wAAAn4"]
[Tue Aug 18 12:55:45.981991 2026] [security2:error] [pid 67073:tid 67312] [client 20.163.43.14:4357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSAgfcmepr5_nHgLbNI-QAAAn8"]
[Tue Aug 18 12:55:45.991473 2026] [security2:error] [pid 67073:tid 67293] [client 5.253.205.188:50496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/installdemodemo.bak"] [unique_id "aoSAgfcmepr5_nHgLbNI-gAAAmw"], referer: https://medihub.com.br/installdemodemo.bak
[Tue Aug 18 12:55:46.018826 2026] [security2:error] [pid 67073:tid 67252] [client 68.155.154.236:16276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/ucpfr.php"] [unique_id "aoSAgvcmepr5_nHgLbNI_QAAAkM"]
[Tue Aug 18 12:55:46.038747 2026] [security2:error] [pid 67073:tid 67236] [client 4.223.164.152:54262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/nox.php"] [unique_id "aoSAgvcmepr5_nHgLbNI_wAAAjM"]
[Tue Aug 18 12:55:46.047138 2026] [security2:error] [pid 67073:tid 67217] [client 20.91.215.254:20679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-content/abc.php"] [unique_id "aoSAgvcmepr5_nHgLbNJAAAAAiA"]
[Tue Aug 18 12:55:46.069418 2026] [security2:error] [pid 67073:tid 67109] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSAgvcmepr5_nHgLbNJAgACLyE"]
[Tue Aug 18 12:55:46.069946 2026] [security2:error] [pid 67073:tid 67240] [client 20.163.43.14:4282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/files/index.php"] [unique_id "aoSAgvcmepr5_nHgLbNJAwAAAjc"]
[Tue Aug 18 12:55:46.080554 2026] [security2:error] [pid 67073:tid 67216] [client 20.116.17.175:57417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wpxml.php"] [unique_id "aoSAgvcmepr5_nHgLbNJBAAAAh8"]
[Tue Aug 18 12:55:46.085958 2026] [security2:error] [pid 67073:tid 67171] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/pw.php"] [unique_id "aoSAgvcmepr5_nHgLbNJBQACd18"]
[Tue Aug 18 12:55:46.098659 2026] [security2:error] [pid 67073:tid 67139] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/core/.env"] [unique_id "aoSAgvcmepr5_nHgLbNJBwACPT8"]
[Tue Aug 18 12:55:46.112426 2026] [security2:error] [pid 67073:tid 67332] [client 20.48.236.86:16203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/spip.php"] [unique_id "aoSAgvcmepr5_nHgLbNJCQAAApM"]
[Tue Aug 18 12:55:46.129155 2026] [security2:error] [pid 67073:tid 67321] [client 20.226.6.191:6625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/moon.php"] [unique_id "aoSAgvcmepr5_nHgLbNJCgAAAog"]
[Tue Aug 18 12:55:46.187079 2026] [security2:error] [pid 67073:tid 67225] [client 20.42.19.40:1406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-links-opml.php"] [unique_id "aoSAgvcmepr5_nHgLbNJDAAAAig"]
[Tue Aug 18 12:55:46.194006 2026] [security2:error] [pid 66623:tid 66820] [client 20.100.169.31:2438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSAgtO5rbWdOArH04KF_gAAAUA"]
[Tue Aug 18 12:55:46.203862 2026] [security2:error] [pid 67073:tid 67208] [client 20.91.215.254:14288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp.php"] [unique_id "aoSAgvcmepr5_nHgLbNJDgAAAhc"]
[Tue Aug 18 12:55:46.205411 2026] [security2:error] [pid 67073:tid 67234] [client 158.158.74.177:22754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/gettest.php"] [unique_id "aoSAgvcmepr5_nHgLbNJDwAAAjE"]
[Tue Aug 18 12:55:46.206179 2026] [security2:error] [pid 66623:tid 66849] [client 172.182.200.96:7622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSAgtO5rbWdOArH04KF_wAAAV0"]
[Tue Aug 18 12:55:46.226651 2026] [security2:error] [pid 67073:tid 67255] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/randkeyword.php7"] [unique_id "aoSAgvcmepr5_nHgLbNJEQAAAkY"]
[Tue Aug 18 12:55:46.241838 2026] [security2:error] [pid 67073:tid 67314] [client 172.202.39.151:50553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/moon.php"] [unique_id "aoSAgvcmepr5_nHgLbNJFAAAAoE"]
[Tue Aug 18 12:55:46.250737 2026] [security2:error] [pid 66623:tid 66818] [client 20.226.56.190:17907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kn.php"] [unique_id "aoSAgtO5rbWdOArH04KGBAAAAT4"]
[Tue Aug 18 12:55:46.251392 2026] [security2:error] [pid 67073:tid 67186] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAgvcmepr5_nHgLbNJFgACcG4"]
[Tue Aug 18 12:55:46.251537 2026] [security2:error] [pid 67073:tid 67330] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/fpwch.php"] [unique_id "aoSAgvcmepr5_nHgLbNJFwAAApE"]
[Tue Aug 18 12:55:46.257232 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:46.257514 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:46.263195 2026] [security2:error] [pid 67073:tid 67305] [client 4.232.151.198:25690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/155.php"] [unique_id "aoSAgvcmepr5_nHgLbNJGAAAAng"]
[Tue Aug 18 12:55:46.265277 2026] [security2:error] [pid 67073:tid 67249] [client 20.171.51.14:16739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/fd.php"] [unique_id "aoSAgvcmepr5_nHgLbNJGQAAAkA"]
[Tue Aug 18 12:55:46.320801 2026] [security2:error] [pid 67073:tid 67128] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/fn.php"] [unique_id "aoSAgvcmepr5_nHgLbNJHQACRDQ"]
[Tue Aug 18 12:55:46.332534 2026] [security2:error] [pid 67073:tid 67134] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uhequeimado.com.br"] [uri "/config.php.bak"] [unique_id "aoSAgvcmepr5_nHgLbNJHgACOzo"]
[Tue Aug 18 12:55:46.334634 2026] [security2:error] [pid 66623:tid 66869] [client 68.221.73.131:61309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/thoms.php"] [unique_id "aoSAgtO5rbWdOArH04KGBQAAAXE"]
[Tue Aug 18 12:55:46.362589 2026] [security2:error] [pid 66623:tid 66877] [client 20.226.56.190:2721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/wm.php"] [unique_id "aoSAgtO5rbWdOArH04KGBwAAAXk"]
[Tue Aug 18 12:55:46.362591 2026] [security2:error] [pid 67073:tid 67206] [client 132.196.61.152:60318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/bajah.php"] [unique_id "aoSAgvcmepr5_nHgLbNJIAAAAhU"]
[Tue Aug 18 12:55:46.383643 2026] [security2:error] [pid 67073:tid 67272] [client 135.225.75.187:47206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/06.php"] [unique_id "aoSAgvcmepr5_nHgLbNJIgAAAlc"]
[Tue Aug 18 12:55:46.390375 2026] [security2:error] [pid 67073:tid 67077] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uhequeimado.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSAgvcmepr5_nHgLbNJIwACGAE"]
[Tue Aug 18 12:55:46.399115 2026] [security2:error] [pid 67073:tid 67302] [client 52.139.47.57:9049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAgvcmepr5_nHgLbNJJAAAAnU"]
[Tue Aug 18 12:55:46.413399 2026] [security2:error] [pid 67073:tid 67242] [client 213.35.127.232:64335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAgvcmepr5_nHgLbNJJQAAAjk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:46.421223 2026] [security2:error] [pid 67073:tid 67118] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSAgvcmepr5_nHgLbNJJgACcio"]
[Tue Aug 18 12:55:46.424791 2026] [security2:error] [pid 67073:tid 67254] [client 20.163.43.14:4339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAgvcmepr5_nHgLbNJJwAAAkU"]
[Tue Aug 18 12:55:46.425709 2026] [security2:error] [pid 67073:tid 67324] [client 20.163.43.14:4468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSAgvcmepr5_nHgLbNJKAAAAos"]
[Tue Aug 18 12:55:46.432900 2026] [security2:error] [pid 67073:tid 67295] [client 74.248.130.103:38697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/puc.php"] [unique_id "aoSAgvcmepr5_nHgLbNJKQAAAm4"]
[Tue Aug 18 12:55:46.464991 2026] [security2:error] [pid 67073:tid 67268] [client 158.23.17.4:29460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/loading.php"] [unique_id "aoSAgvcmepr5_nHgLbNJKgAAAlM"]
[Tue Aug 18 12:55:46.472481 2026] [security2:error] [pid 67073:tid 67319] [client 158.158.34.183:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/feeds.php"] [unique_id "aoSAgvcmepr5_nHgLbNJKwAAAoY"]
[Tue Aug 18 12:55:46.474967 2026] [security2:error] [pid 67073:tid 67320] [client 20.48.236.86:16202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/wpup.php"] [unique_id "aoSAgvcmepr5_nHgLbNJLAAAAoc"]
[Tue Aug 18 12:55:46.481909 2026] [security2:error] [pid 66623:tid 66878] [client 4.223.164.152:17630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/file59.php"] [unique_id "aoSAgtO5rbWdOArH04KGCAAAAXo"]
[Tue Aug 18 12:55:46.487129 2026] [security2:error] [pid 66623:tid 66864] [client 20.226.56.190:45017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ac.php"] [unique_id "aoSAgtO5rbWdOArH04KGCQAAAWw"]
[Tue Aug 18 12:55:46.530174 2026] [security2:error] [pid 67073:tid 67281] [client 20.42.19.40:9617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/ioxi-o.php"] [unique_id "aoSAgvcmepr5_nHgLbNJLgAAAmA"]
[Tue Aug 18 12:55:46.563167 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:46.563441 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:46.569247 2026] [security2:error] [pid 67073:tid 67097] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kf.php"] [unique_id "aoSAgvcmepr5_nHgLbNJMgACNhU"]
[Tue Aug 18 12:55:46.593153 2026] [security2:error] [pid 67073:tid 67203] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAgvcmepr5_nHgLbNJMwACLX8"]
[Tue Aug 18 12:55:46.615154 2026] [security2:error] [pid 67073:tid 67313] [client 20.151.109.219:53199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ia.php"] [unique_id "aoSAgvcmepr5_nHgLbNJNAAAAoA"]
[Tue Aug 18 12:55:46.617895 2026] [security2:error] [pid 67073:tid 67105] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.env.swp"] [unique_id "aoSAgvcmepr5_nHgLbNJNQACKx0"]
[Tue Aug 18 12:55:46.640397 2026] [security2:error] [pid 66623:tid 66844] [client 20.116.17.175:57659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSAgtO5rbWdOArH04KGCgAAAVg"]
[Tue Aug 18 12:55:46.640762 2026] [security2:error] [pid 67073:tid 67257] [client 52.238.210.254:10216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/images/wso.php"] [unique_id "aoSAgvcmepr5_nHgLbNJOQAAAkg"]
[Tue Aug 18 12:55:46.691059 2026] [security2:error] [pid 67073:tid 67217] [client 20.215.241.237:19959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/images.php"] [unique_id "aoSAgvcmepr5_nHgLbNJPAAAAiA"]
[Tue Aug 18 12:55:46.765428 2026] [security2:error] [pid 67073:tid 67136] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSAgvcmepr5_nHgLbNJPwACHzw"]
[Tue Aug 18 12:55:46.769028 2026] [security2:error] [pid 67073:tid 67218] [client 178.153.171.161:37212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAgvcmepr5_nHgLbNJQAAAAiE"]
[Tue Aug 18 12:55:46.769156 2026] [security2:error] [pid 67073:tid 67218] [client 178.153.171.161:37212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAgvcmepr5_nHgLbNJQAAAAiE"]
[Tue Aug 18 12:55:46.774495 2026] [security2:error] [pid 67073:tid 67304] [client 20.48.236.86:16367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/myy.php"] [unique_id "aoSAgvcmepr5_nHgLbNJQgAAAnc"]
[Tue Aug 18 12:55:46.776668 2026] [security2:error] [pid 67073:tid 67282] [client 20.171.51.14:57378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/info2.php"] [unique_id "aoSAgvcmepr5_nHgLbNJQwAAAmE"]
[Tue Aug 18 12:55:46.787511 2026] [security2:error] [pid 67073:tid 67332] [client 20.42.19.40:9636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/0x.php"] [unique_id "aoSAgvcmepr5_nHgLbNJRAAAApM"]
[Tue Aug 18 12:55:46.790787 2026] [security2:error] [pid 67073:tid 67213] [client 20.226.6.191:6528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/cache.php"] [unique_id "aoSAgvcmepr5_nHgLbNJRQAAAhw"]
[Tue Aug 18 12:55:46.810352 2026] [security2:error] [pid 67073:tid 67247] [client 20.163.43.14:4421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAgvcmepr5_nHgLbNJRgAAAj4"]
[Tue Aug 18 12:55:46.817391 2026] [security2:error] [pid 66623:tid 66829] [client 20.100.169.31:2439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSAgtO5rbWdOArH04KGDQAAAUk"]
[Tue Aug 18 12:55:46.821775 2026] [security2:error] [pid 66623:tid 66785] [client 20.251.48.93:24995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/key.php"] [unique_id "aoSAgtO5rbWdOArH04KGDgAAAR0"]
[Tue Aug 18 12:55:46.828564 2026] [security2:error] [pid 67073:tid 67210] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/adminner.php"] [unique_id "aoSAgvcmepr5_nHgLbNJSQAAAhk"]
[Tue Aug 18 12:55:46.839091 2026] [security2:error] [pid 67073:tid 67229] [client 20.100.169.31:29981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/alfa.php"] [unique_id "aoSAgvcmepr5_nHgLbNJTAAAAiw"]
[Tue Aug 18 12:55:46.839663 2026] [security2:error] [pid 67073:tid 67148] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/public/.env"] [unique_id "aoSAgvcmepr5_nHgLbNJSwACGkg"]
[Tue Aug 18 12:55:46.853750 2026] [security2:error] [pid 67073:tid 67248] [client 20.91.215.254:20702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/classwithtostring.php"] [unique_id "aoSAgvcmepr5_nHgLbNJTQAAAj8"]
[Tue Aug 18 12:55:46.863087 2026] [security2:error] [pid 67073:tid 67265] [client 20.163.43.14:4186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAgvcmepr5_nHgLbNJTgAAAlA"]
[Tue Aug 18 12:55:46.897788 2026] [security2:error] [pid 67073:tid 67234] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/readme.php"] [unique_id "aoSAgvcmepr5_nHgLbNJUAAAAjE"]
[Tue Aug 18 12:55:46.909587 2026] [security2:error] [pid 67073:tid 67287] [client 4.223.164.152:46148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/admin.php"] [unique_id "aoSAgvcmepr5_nHgLbNJUQAAAmY"]
[Tue Aug 18 12:55:46.917020 2026] [security2:error] [pid 67073:tid 67081] [remote 212.29.237.5:59180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.237.29.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-login.php"] [unique_id "aoSAgvcmepr5_nHgLbNJUwACHgU"]
[Tue Aug 18 12:55:46.920371 2026] [security2:error] [pid 67073:tid 67329] [client 20.91.215.254:14325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-activat.php"] [unique_id "aoSAgvcmepr5_nHgLbNJVAAAApA"]
[Tue Aug 18 12:55:46.922588 2026] [security2:error] [pid 67073:tid 67252] [client 158.158.74.177:2631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/goods.php"] [unique_id "aoSAgvcmepr5_nHgLbNJVQAAAkM"]
[Tue Aug 18 12:55:46.936126 2026] [security2:error] [pid 67073:tid 67155] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSAgvcmepr5_nHgLbNJVgACRk8"]
[Tue Aug 18 12:55:46.943741 2026] [security2:error] [pid 67073:tid 67220] [client 68.221.73.131:61196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/wpxml.php"] [unique_id "aoSAgvcmepr5_nHgLbNJVwAAAiM"]
[Tue Aug 18 12:55:46.945087 2026] [security2:error] [pid 67073:tid 67181] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/su.php"] [unique_id "aoSAgvcmepr5_nHgLbNJWAACZGk"]
[Tue Aug 18 12:55:46.956934 2026] [security2:error] [pid 67073:tid 67160] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/web/.env"] [unique_id "aoSAgvcmepr5_nHgLbNJWQACgVQ"]
[Tue Aug 18 12:55:46.985461 2026] [security2:error] [pid 66623:tid 66884] [client 20.151.109.219:17590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kn.php"] [unique_id "aoSAgtO5rbWdOArH04KGDwAAAYA"]
[Tue Aug 18 12:55:46.994117 2026] [security2:error] [pid 67073:tid 67297] [client 132.196.61.152:34691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/h.php"] [unique_id "aoSAgvcmepr5_nHgLbNJXAAAAnA"]
[Tue Aug 18 12:55:47.004610 2026] [security2:error] [pid 67073:tid 67251] [client 20.65.98.162:31723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/file2.php"] [unique_id "aoSAg_cmepr5_nHgLbNJXwAAAkI"]
[Tue Aug 18 12:55:47.043194 2026] [security2:error] [pid 67073:tid 67249] [client 20.42.19.40:2904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/admin.php"] [unique_id "aoSAg_cmepr5_nHgLbNJYAAAAkA"]
[Tue Aug 18 12:55:47.050779 2026] [security2:error] [pid 67073:tid 67316] [client 20.116.17.175:11252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/ccou.php"] [unique_id "aoSAg_cmepr5_nHgLbNJYQAAAoM"]
[Tue Aug 18 12:55:47.054430 2026] [security2:error] [pid 67073:tid 67207] [client 20.42.19.40:9658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/222.php"] [unique_id "aoSAg_cmepr5_nHgLbNJYgAAAhY"]
[Tue Aug 18 12:55:47.111080 2026] [security2:error] [pid 67073:tid 67143] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAg_cmepr5_nHgLbNJZQACjUM"]
[Tue Aug 18 12:55:47.140427 2026] [security2:error] [pid 67073:tid 67292] [client 52.139.47.57:9033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/wp-the.php"] [unique_id "aoSAg_cmepr5_nHgLbNJaAAAAms"]
[Tue Aug 18 12:55:47.158916 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:47.159200 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:47.199157 2026] [security2:error] [pid 67073:tid 67223] [client 74.248.130.103:15369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/8.php"] [unique_id "aoSAg_cmepr5_nHgLbNJbAAAAiY"]
[Tue Aug 18 12:55:47.212118 2026] [security2:error] [pid 67073:tid 67268] [client 20.48.236.86:16279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/geido.php"] [unique_id "aoSAg_cmepr5_nHgLbNJbgAAAlM"]
[Tue Aug 18 12:55:47.220170 2026] [security2:error] [pid 67073:tid 67320] [client 20.163.43.14:4175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAg_cmepr5_nHgLbNJbwAAAoc"]
[Tue Aug 18 12:55:47.236289 2026] [security2:error] [pid 66623:tid 66828] [client 20.226.56.190:2499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/yz.php"] [unique_id "aoSAg9O5rbWdOArH04KGEAAAAUg"]
[Tue Aug 18 12:55:47.247329 2026] [security2:error] [pid 67073:tid 67192] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/wp-key.php"] [unique_id "aoSAg_cmepr5_nHgLbNJcQACYHQ"]
[Tue Aug 18 12:55:47.247660 2026] [security2:error] [pid 67073:tid 67256] [client 20.226.6.191:6532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAg_cmepr5_nHgLbNJcgAAAkc"]
[Tue Aug 18 12:55:47.252678 2026] [security2:error] [pid 66623:tid 66792] [client 20.226.6.191:56214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/gecko.php"] [unique_id "aoSAg9O5rbWdOArH04KGEQAAASQ"]
[Tue Aug 18 12:55:47.271325 2026] [security2:error] [pid 66623:tid 66837] [client 20.226.56.190:31018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kj.php"] [unique_id "aoSAg9O5rbWdOArH04KGFAAAAVE"]
[Tue Aug 18 12:55:47.276134 2026] [security2:error] [pid 67073:tid 67237] [client 4.232.151.198:16060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/96i.php"] [unique_id "aoSAg_cmepr5_nHgLbNJdQAAAjQ"]
[Tue Aug 18 12:55:47.278585 2026] [security2:error] [pid 66623:tid 66850] [client 20.151.109.219:64620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/wm.php"] [unique_id "aoSAg9O5rbWdOArH04KGFQAAAV4"]
[Tue Aug 18 12:55:47.282813 2026] [security2:error] [pid 67073:tid 67174] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSAg_cmepr5_nHgLbNJdwACG2I"]
[Tue Aug 18 12:55:47.291562 2026] [security2:error] [pid 67073:tid 67313] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/reze.php"] [unique_id "aoSAg_cmepr5_nHgLbNJeAAAAoA"]
[Tue Aug 18 12:55:47.306689 2026] [security2:error] [pid 66623:tid 66845] [client 20.42.19.40:9626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/aa.php"] [unique_id "aoSAg9O5rbWdOArH04KGFgAAAVk"]
[Tue Aug 18 12:55:47.339236 2026] [security2:error] [pid 67073:tid 67328] [client 4.223.164.152:46154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/aa2.php"] [unique_id "aoSAg_cmepr5_nHgLbNJegAAAo8"]
[Tue Aug 18 12:55:47.388755 2026] [security2:error] [pid 67073:tid 67217] [client 52.238.210.254:8317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/index/function.php"] [unique_id "aoSAg_cmepr5_nHgLbNJfQAAAiA"]
[Tue Aug 18 12:55:47.393019 2026] [security2:error] [pid 67073:tid 67279] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/abcd.php"] [unique_id "aoSAg_cmepr5_nHgLbNJfgAAAl4"]
[Tue Aug 18 12:55:47.397116 2026] [security2:error] [pid 67073:tid 67240] [client 20.226.56.190:47145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/vg.php"] [unique_id "aoSAg_cmepr5_nHgLbNJfwAAAjc"]
[Tue Aug 18 12:55:47.398591 2026] [security2:error] [pid 66623:tid 66773] [client 20.42.19.40:2194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/adminfuns.php"] [unique_id "aoSAg9O5rbWdOArH04KGFwAAARE"]
[Tue Aug 18 12:55:47.399465 2026] [security2:error] [pid 67073:tid 67310] [client 172.202.39.151:55484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/new.php"] [unique_id "aoSAg_cmepr5_nHgLbNJgQAAAn0"]
[Tue Aug 18 12:55:47.419673 2026] [security2:error] [pid 67073:tid 67304] [client 20.116.17.175:57447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/crgio.php"] [unique_id "aoSAg_cmepr5_nHgLbNJggAAAnc"]
[Tue Aug 18 12:55:47.426734 2026] [security2:error] [pid 67073:tid 67227] [client 213.35.127.232:64582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAg_cmepr5_nHgLbNJgwAAAio"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:47.433227 2026] [security2:error] [pid 66623:tid 66816] [client 20.163.43.14:4375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSAg9O5rbWdOArH04KGGAAAATw"]
[Tue Aug 18 12:55:47.454000 2026] [security2:error] [pid 67073:tid 67235] [client 20.100.169.31:17869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSAg_cmepr5_nHgLbNJhAAAAjI"]
[Tue Aug 18 12:55:47.463813 2026] [security2:error] [pid 67073:tid 67157] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gg.php"] [unique_id "aoSAg_cmepr5_nHgLbNJhwACk1E"]
[Tue Aug 18 12:55:47.473024 2026] [authz_core:error] [pid 67073:tid 67200] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:47.473383 2026] [authz_core:error] [pid 67073:tid 67200] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:47.478972 2026] [security2:error] [pid 67073:tid 67247] [client 20.226.56.190:31675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/sm.php"] [unique_id "aoSAg_cmepr5_nHgLbNJiQAAAj4"]
[Tue Aug 18 12:55:47.507379 2026] [security2:error] [pid 67073:tid 67170] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSAg_cmepr5_nHgLbNJiwACUl4"]
[Tue Aug 18 12:55:47.537395 2026] [security2:error] [pid 66623:tid 66846] [client 20.48.236.86:16262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/gelay.php"] [unique_id "aoSAg9O5rbWdOArH04KGGQAAAVo"]
[Tue Aug 18 12:55:47.585029 2026] [security2:error] [pid 67073:tid 67215] [client 20.163.43.14:4161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/rip.php"] [unique_id "aoSAg_cmepr5_nHgLbNJjwAAAh4"]
[Tue Aug 18 12:55:47.585746 2026] [security2:error] [pid 66623:tid 66830] [client 20.42.19.40:9692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/abcd.php"] [unique_id "aoSAg9O5rbWdOArH04KGGgAAAUo"]
[Tue Aug 18 12:55:47.624258 2026] [security2:error] [pid 67073:tid 67225] [client 20.65.69.59:49334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/main.php"] [unique_id "aoSAg_cmepr5_nHgLbNJkQAAAig"]
[Tue Aug 18 12:55:47.635518 2026] [security2:error] [pid 67073:tid 67255] [client 20.151.109.219:64161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ac.php"] [unique_id "aoSAg_cmepr5_nHgLbNJkgAAAkY"]
[Tue Aug 18 12:55:47.641166 2026] [security2:error] [pid 67073:tid 67205] [client 20.91.215.254:24664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSAg_cmepr5_nHgLbNJlAAAAhQ"]
[Tue Aug 18 12:55:47.643002 2026] [security2:error] [pid 67073:tid 67285] [client 74.248.136.165:17990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ccou.php"] [unique_id "aoSAg_cmepr5_nHgLbNJlgAAAmQ"]
[Tue Aug 18 12:55:47.653666 2026] [security2:error] [pid 67073:tid 67229] [client 52.139.47.57:44613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/wp.php"] [unique_id "aoSAg_cmepr5_nHgLbNJmAAAAiw"]
[Tue Aug 18 12:55:47.655097 2026] [security2:error] [pid 67073:tid 67232] [client 20.91.215.254:27394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/adminfuns.php"] [unique_id "aoSAg_cmepr5_nHgLbNJmQAAAi8"]
[Tue Aug 18 12:55:47.664591 2026] [security2:error] [pid 67073:tid 67274] [client 135.225.75.187:37309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/166.php"] [unique_id "aoSAg_cmepr5_nHgLbNJmgAAAlk"]
[Tue Aug 18 12:55:47.677042 2026] [security2:error] [pid 66623:tid 66836] [client 20.226.6.191:6537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAg9O5rbWdOArH04KGHAAAAVA"]
[Tue Aug 18 12:55:47.678009 2026] [security2:error] [pid 67073:tid 67091] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSAg_cmepr5_nHgLbNJmwACVg8"]
[Tue Aug 18 12:55:47.709252 2026] [security2:error] [pid 67073:tid 67251] [client 20.226.56.190:45054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/28.php"] [unique_id "aoSAg_cmepr5_nHgLbNJnwAAAkI"]
[Tue Aug 18 12:55:47.766458 2026] [security2:error] [pid 67073:tid 67253] [client 20.163.43.14:4389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/an.php"] [unique_id "aoSAg_cmepr5_nHgLbNJowAAAkQ"]
[Tue Aug 18 12:55:47.773207 2026] [security2:error] [pid 67073:tid 67297] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAg_cmepr5_nHgLbNJnAACcHY"]
[Tue Aug 18 12:55:47.778396 2026] [security2:error] [pid 66623:tid 66847] [client 85.154.68.202:12173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAg9O5rbWdOArH04KGHQAAAVs"]
[Tue Aug 18 12:55:47.778495 2026] [security2:error] [pid 66623:tid 66847] [client 85.154.68.202:12173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAg9O5rbWdOArH04KGHQAAAVs"]
[Tue Aug 18 12:55:47.786388 2026] [security2:error] [pid 67073:tid 67111] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gi.php"] [unique_id "aoSAg_cmepr5_nHgLbNJpQACjSM"]
[Tue Aug 18 12:55:47.788904 2026] [security2:error] [pid 67073:tid 67295] [client 160.120.140.123:59585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAg_cmepr5_nHgLbNJpgAAAm4"]
[Tue Aug 18 12:55:47.789079 2026] [security2:error] [pid 67073:tid 67295] [client 160.120.140.123:59585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAg_cmepr5_nHgLbNJpgAAAm4"]
[Tue Aug 18 12:55:47.804778 2026] [security2:error] [pid 67073:tid 67275] [client 4.223.164.152:64692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/xamp.php"] [unique_id "aoSAg_cmepr5_nHgLbNJpwAAAlo"]
[Tue Aug 18 12:55:47.807074 2026] [security2:error] [pid 67073:tid 67302] [client 20.226.6.191:7128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/o.php"] [unique_id "aoSAg_cmepr5_nHgLbNJqAAAAnU"]
[Tue Aug 18 12:55:47.850016 2026] [security2:error] [pid 67073:tid 67201] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAg_cmepr5_nHgLbNJqgAChX0"]
[Tue Aug 18 12:55:47.861846 2026] [security2:error] [pid 67073:tid 67244] [client 192.141.172.134:58696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAg_cmepr5_nHgLbNJqwAAAjs"]
[Tue Aug 18 12:55:47.861929 2026] [security2:error] [pid 67073:tid 67244] [client 192.141.172.134:58696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAg_cmepr5_nHgLbNJqwAAAjs"]
[Tue Aug 18 12:55:47.867027 2026] [security2:error] [pid 67073:tid 67223] [client 20.226.56.190:2509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/m.php"] [unique_id "aoSAg_cmepr5_nHgLbNJrQAAAiY"]
[Tue Aug 18 12:55:47.871805 2026] [security2:error] [pid 67073:tid 67309] [client 68.221.73.131:61230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/file1221.php"] [unique_id "aoSAg_cmepr5_nHgLbNJrgAAAnw"]
[Tue Aug 18 12:55:47.873077 2026] [security2:error] [pid 66623:tid 66870] [client 20.42.19.40:1350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/admin.php"] [unique_id "aoSAg9O5rbWdOArH04KGIAAAAXI"]
[Tue Aug 18 12:55:47.884303 2026] [security2:error] [pid 67073:tid 67319] [client 20.226.56.190:31665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/nl.php"] [unique_id "aoSAg_cmepr5_nHgLbNJsAAAAoY"]
[Tue Aug 18 12:55:47.896645 2026] [security2:error] [pid 67073:tid 67219] [client 74.248.130.103:15360] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.formularios.filialweb.com"] [uri "/1.php"] [unique_id "aoSAg_cmepr5_nHgLbNJsQAAAiI"]
[Tue Aug 18 12:55:47.896759 2026] [security2:error] [pid 67073:tid 67219] [client 74.248.130.103:15360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/1.php"] [unique_id "aoSAg_cmepr5_nHgLbNJsQAAAiI"]
[Tue Aug 18 12:55:47.911681 2026] [security2:error] [pid 67073:tid 67276] [client 20.48.236.86:16257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/atomlib.php"] [unique_id "aoSAg_cmepr5_nHgLbNJsgAAAls"]
[Tue Aug 18 12:55:47.943787 2026] [security2:error] [pid 67073:tid 67222] [client 20.151.109.219:21692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/yz.php"] [unique_id "aoSAg_cmepr5_nHgLbNJtAAAAiU"]
[Tue Aug 18 12:55:47.946355 2026] [security2:error] [pid 66623:tid 66811] [client 20.226.56.190:28253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/68.php"] [unique_id "aoSAg9O5rbWdOArH04KGIwAAATc"]
[Tue Aug 18 12:55:47.947586 2026] [security2:error] [pid 67073:tid 67224] [client 158.158.34.183:36155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/curl.php"] [unique_id "aoSAg_cmepr5_nHgLbNJtQAAAic"]
[Tue Aug 18 12:55:47.991034 2026] [security2:error] [pid 67073:tid 67264] [client 20.226.56.190:47126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/jl.php"] [unique_id "aoSAg_cmepr5_nHgLbNJtwAAAk8"]
[Tue Aug 18 12:55:48.010651 2026] [security2:error] [pid 67073:tid 67313] [client 20.226.6.191:6585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/bb.php"] [unique_id "aoSAhPcmepr5_nHgLbNJuQAAAoA"]
[Tue Aug 18 12:55:48.020846 2026] [security2:error] [pid 67073:tid 67117] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAhPcmepr5_nHgLbNJugACSCk"]
[Tue Aug 18 12:55:48.029853 2026] [security2:error] [pid 67073:tid 67236] [client 20.251.48.93:9784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/chosen.php"] [unique_id "aoSAhPcmepr5_nHgLbNJuwAAAjM"]
[Tue Aug 18 12:55:48.042618 2026] [security2:error] [pid 67073:tid 67112] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/pz.php"] [unique_id "aoSAhPcmepr5_nHgLbNJvAACSSQ"]
[Tue Aug 18 12:55:48.086040 2026] [security2:error] [pid 66623:tid 66831] [client 20.226.56.190:2522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/tq.php"] [unique_id "aoSAhNO5rbWdOArH04KGJAAAAUs"]
[Tue Aug 18 12:55:48.092107 2026] [security2:error] [pid 66623:tid 66767] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/rh.php"] [unique_id "aoSAhNO5rbWdOArH04KGJQAAAQs"]
[Tue Aug 18 12:55:48.103066 2026] [security2:error] [pid 66623:tid 66808] [client 20.116.17.175:57419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSAhNO5rbWdOArH04KGJgAAATQ"]
[Tue Aug 18 12:55:48.117111 2026] [security2:error] [pid 66623:tid 66872] [client 52.139.47.57:19956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/wso.php"] [unique_id "aoSAhNO5rbWdOArH04KGJwAAAXQ"]
[Tue Aug 18 12:55:48.121569 2026] [security2:error] [pid 66623:tid 66826] [client 20.163.43.14:4291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAhNO5rbWdOArH04KGKAAAAUY"]
[Tue Aug 18 12:55:48.138455 2026] [security2:error] [pid 67073:tid 67218] [client 20.226.56.190:31028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/cv.php"] [unique_id "aoSAhPcmepr5_nHgLbNJwQAAAiE"]
[Tue Aug 18 12:55:48.229304 2026] [security2:error] [pid 66623:tid 66862] [client 4.223.164.152:64668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/bless.php"] [unique_id "aoSAhNO5rbWdOArH04KGLgAAAWo"]
[Tue Aug 18 12:55:48.238176 2026] [security2:error] [pid 67073:tid 67098] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kk.php"] [unique_id "aoSAhPcmepr5_nHgLbNJxQACkxY"]
[Tue Aug 18 12:55:48.244713 2026] [security2:error] [pid 66623:tid 66853] [client 20.226.6.191:6600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSAhNO5rbWdOArH04KGMAAAAWE"]
[Tue Aug 18 12:55:48.248786 2026] [security2:error] [pid 66623:tid 66777] [client 20.42.19.40:9688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/adminfuns.php"] [unique_id "aoSAhNO5rbWdOArH04KGMQAAARU"]
[Tue Aug 18 12:55:48.270917 2026] [security2:error] [pid 66623:tid 66825] [client 20.48.236.86:16319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/ee.php"] [unique_id "aoSAhNO5rbWdOArH04KGMgAAAUU"]
[Tue Aug 18 12:55:48.273562 2026] [security2:error] [pid 67073:tid 67267] [client 20.226.56.190:44994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/un.php"] [unique_id "aoSAhPcmepr5_nHgLbNJxgAAAlI"]
[Tue Aug 18 12:55:48.280421 2026] [security2:error] [pid 66623:tid 66887] [client 20.91.215.254:24672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/past1.php"] [unique_id "aoSAhNO5rbWdOArH04KGMwAAAYM"]
[Tue Aug 18 12:55:48.286803 2026] [security2:error] [pid 67073:tid 67214] [client 20.151.109.219:17570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kj.php"] [unique_id "aoSAhPcmepr5_nHgLbNJyAAAAh0"]
[Tue Aug 18 12:55:48.310220 2026] [security2:error] [pid 66623:tid 66796] [client 20.163.43.14:4458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/404.php"] [unique_id "aoSAhNO5rbWdOArH04KGNAAAASg"]
[Tue Aug 18 12:55:48.365889 2026] [authz_core:error] [pid 67073:tid 67133] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:48.366159 2026] [authz_core:error] [pid 67073:tid 67133] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:48.377552 2026] [security2:error] [pid 66623:tid 66793] [client 213.202.253.4:59026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/gdftps.php"] [unique_id "aoSAhNO5rbWdOArH04KGNgAAASU"], referer: www.google.com
[Tue Aug 18 12:55:48.387889 2026] [security2:error] [pid 67073:tid 67233] [client 52.238.210.254:8921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/info.php"] [unique_id "aoSAhPcmepr5_nHgLbNJzAAAAjA"]
[Tue Aug 18 12:55:48.436419 2026] [security2:error] [pid 67073:tid 67145] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/phpcheck.php"] [unique_id "aoSAhPcmepr5_nHgLbNJzgACHkU"]
[Tue Aug 18 12:55:48.438564 2026] [security2:error] [pid 66623:tid 66855] [client 213.35.127.232:64802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAhNO5rbWdOArH04KGNwAAAWM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:48.444042 2026] [security2:error] [pid 66623:tid 66798] [client 20.91.215.254:11277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/abc.php"] [unique_id "aoSAhNO5rbWdOArH04KGOAAAASo"]
[Tue Aug 18 12:55:48.486559 2026] [security2:error] [pid 67073:tid 67252] [client 20.42.19.40:9672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/akc.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ0AAAAkM"]
[Tue Aug 18 12:55:48.494527 2026] [security2:error] [pid 66623:tid 66861] [client 20.163.43.14:4267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/moon.php"] [unique_id "aoSAhNO5rbWdOArH04KGOQAAAWk"]
[Tue Aug 18 12:55:48.508090 2026] [security2:error] [pid 67073:tid 67254] [client 158.158.74.177:16524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/gulu.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ0gAAAkU"]
[Tue Aug 18 12:55:48.521893 2026] [security2:error] [pid 67073:tid 67255] [client 20.100.169.31:17878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ0wAAAkY"]
[Tue Aug 18 12:55:48.530139 2026] [fcgid:warn] [pid 67073:tid 67245] (70014)End of file found: [client 66.132.195.88:7832] mod_fcgid: can't get data from http client
[Tue Aug 18 12:55:48.555703 2026] [security2:error] [pid 67073:tid 67220] [client 20.29.77.16:27202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/profile.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ1wAAAiM"]
[Tue Aug 18 12:55:48.558229 2026] [security2:error] [pid 66623:tid 66867] [client 20.100.169.31:47419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/edit.php"] [unique_id "aoSAhNO5rbWdOArH04KGOgAAAW8"]
[Tue Aug 18 12:55:48.558510 2026] [security2:error] [pid 67073:tid 67314] [client 20.116.17.175:57643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/css.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ2AAAAoE"]
[Tue Aug 18 12:55:48.590828 2026] [security2:error] [pid 66623:tid 66803] [client 68.221.73.131:61191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/nox.php"] [unique_id "aoSAhNO5rbWdOArH04KGOwAAAS8"]
[Tue Aug 18 12:55:48.619977 2026] [security2:error] [pid 66623:tid 66774] [client 157.51.166.53:59219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAhNO5rbWdOArH04KGPQAAARI"]
[Tue Aug 18 12:55:48.620114 2026] [security2:error] [pid 66623:tid 66774] [client 157.51.166.53:59219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAhNO5rbWdOArH04KGPQAAARI"]
[Tue Aug 18 12:55:48.624111 2026] [security2:error] [pid 66623:tid 66849] [client 20.151.109.219:24895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/vg.php"] [unique_id "aoSAhNO5rbWdOArH04KGPgAAAV0"]
[Tue Aug 18 12:55:48.662124 2026] [security2:error] [pid 66623:tid 66833] [client 52.139.47.57:9028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/www.php"] [unique_id "aoSAhNO5rbWdOArH04KGQAAAAU0"]
[Tue Aug 18 12:55:48.668460 2026] [authz_core:error] [pid 67073:tid 67099] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:48.668869 2026] [authz_core:error] [pid 67073:tid 67099] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:48.674144 2026] [security2:error] [pid 66623:tid 66874] [client 4.223.164.152:54258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/file25.php"] [unique_id "aoSAhNO5rbWdOArH04KGQgAAAXY"]
[Tue Aug 18 12:55:48.674889 2026] [security2:error] [pid 66623:tid 66869] [client 20.163.43.14:4475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-login.php"] [unique_id "aoSAhNO5rbWdOArH04KGQwAAAXE"]
[Tue Aug 18 12:55:48.685056 2026] [security2:error] [pid 67073:tid 67231] [client 132.196.61.152:60341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/ano.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ3AAAAi4"]
[Tue Aug 18 12:55:48.689151 2026] [security2:error] [pid 67073:tid 67271] [client 20.226.56.190:28232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/evil.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ3QAAAlY"]
[Tue Aug 18 12:55:48.703095 2026] [security2:error] [pid 67073:tid 67094] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/dg.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ3gACSxI"]
[Tue Aug 18 12:55:48.708927 2026] [security2:error] [pid 67073:tid 67316] [client 20.42.19.40:2176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/as.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ3wAAAoM"]
[Tue Aug 18 12:55:48.725851 2026] [security2:error] [pid 66623:tid 66819] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/rip.php"] [unique_id "aoSAhNO5rbWdOArH04KGRgAAAT8"]
[Tue Aug 18 12:55:48.730463 2026] [security2:error] [pid 67073:tid 67323] [client 20.48.236.86:16214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/tfm.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ4QAAAoo"]
[Tue Aug 18 12:55:48.740090 2026] [security2:error] [pid 67073:tid 67297] [client 135.225.75.187:18764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/snq.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ4gAAAnA"]
[Tue Aug 18 12:55:48.770885 2026] [security2:error] [pid 67073:tid 67286] [client 20.226.56.190:2058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/pw.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ7AAAAmU"]
[Tue Aug 18 12:55:48.792238 2026] [security2:error] [pid 66623:tid 66878] [client 158.23.17.4:29440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/conn-test.php"] [unique_id "aoSAhNO5rbWdOArH04KGRwAAAXo"]
[Tue Aug 18 12:55:48.800922 2026] [security2:error] [pid 67073:tid 67206] [client 20.42.19.40:9641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/buy.php"] [unique_id "aoSAhPcmepr5_nHgLbNKGQAAAhU"]
[Tue Aug 18 12:55:48.836025 2026] [security2:error] [pid 67073:tid 67317] [client 20.163.43.14:4190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/cache.php"] [unique_id "aoSAhPcmepr5_nHgLbNKGgAAAoQ"]
[Tue Aug 18 12:55:48.843393 2026] [security2:error] [pid 66623:tid 66844] [client 52.173.121.69:24985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSAhNO5rbWdOArH04KGSQAAAVg"]
[Tue Aug 18 12:55:48.874965 2026] [security2:error] [pid 66623:tid 66778] [client 20.251.48.93:65248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/thoms.php"] [unique_id "aoSAhNO5rbWdOArH04KGSgAAARY"]
[Tue Aug 18 12:55:48.886534 2026] [security2:error] [pid 67073:tid 67146] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSAhPcmepr5_nHgLbNKHAACOUY"]
[Tue Aug 18 12:55:48.892595 2026] [security2:error] [pid 67073:tid 67277] [client 20.226.56.190:20407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/fn.php"] [unique_id "aoSAhPcmepr5_nHgLbNKHQAAAlw"]
[Tue Aug 18 12:55:48.895234 2026] [security2:error] [pid 67073:tid 67299] [client 68.155.154.236:16380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/yxijx.php"] [unique_id "aoSAhPcmepr5_nHgLbNKHgAAAnI"]
[Tue Aug 18 12:55:48.927194 2026] [security2:error] [pid 67073:tid 67148] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/bm.php"] [unique_id "aoSAhPcmepr5_nHgLbNKIAACYkg"]
[Tue Aug 18 12:55:48.930659 2026] [security2:error] [pid 67073:tid 67223] [client 20.151.109.219:24843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/sm.php"] [unique_id "aoSAhPcmepr5_nHgLbNKIQAAAiY"]
[Tue Aug 18 12:55:48.959826 2026] [security2:error] [pid 66623:tid 66877] [client 20.91.215.254:14298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/file61.php"] [unique_id "aoSAhNO5rbWdOArH04KGTAAAAXk"]
[Tue Aug 18 12:55:48.974924 2026] [security2:error] [pid 66623:tid 66865] [client 20.226.56.190:20404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kf.php"] [unique_id "aoSAhNO5rbWdOArH04KGTgAAAW0"]
[Tue Aug 18 12:55:49.001858 2026] [security2:error] [pid 67073:tid 67263] [client 74.248.130.103:15376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/about.php"] [unique_id "aoSAhfcmepr5_nHgLbNKLQAAAk4"]
[Tue Aug 18 12:55:49.010442 2026] [security2:error] [pid 66623:tid 66838] [client 20.163.43.14:4373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAhdO5rbWdOArH04KGUAAAAVI"]
[Tue Aug 18 12:55:49.040707 2026] [security2:error] [pid 66623:tid 66827] [client 20.42.19.40:9687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/cong.php"] [unique_id "aoSAhdO5rbWdOArH04KGUQAAAUc"]
[Tue Aug 18 12:55:49.042986 2026] [security2:error] [pid 66623:tid 66850] [client 20.116.17.175:57618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAhdO5rbWdOArH04KGUgAAAV4"]
[Tue Aug 18 12:55:49.057091 2026] [security2:error] [pid 67073:tid 67184] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSAhfcmepr5_nHgLbNKOgACNGw"]
[Tue Aug 18 12:55:49.063194 2026] [security2:error] [pid 67073:tid 67222] [client 52.238.210.254:8867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/profile.php"] [unique_id "aoSAhfcmepr5_nHgLbNKOwAAAiU"]
[Tue Aug 18 12:55:49.083665 2026] [security2:error] [pid 67073:tid 67264] [client 172.202.39.151:50183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/222.php"] [unique_id "aoSAhfcmepr5_nHgLbNKPAAAAk8"]
[Tue Aug 18 12:55:49.084375 2026] [security2:error] [pid 66623:tid 66773] [client 20.48.236.86:16204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/tool.php"] [unique_id "aoSAhdO5rbWdOArH04KGUwAAARE"]
[Tue Aug 18 12:55:49.088820 2026] [security2:error] [pid 67073:tid 67212] [client 20.42.19.40:2657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/bolt.php"] [unique_id "aoSAhfcmepr5_nHgLbNKPgAAAhs"]
[Tue Aug 18 12:55:49.096993 2026] [security2:error] [pid 67073:tid 67221] [client 4.232.151.198:17283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/term.php"] [unique_id "aoSAhfcmepr5_nHgLbNKPwAAAiQ"]
[Tue Aug 18 12:55:49.098496 2026] [security2:error] [pid 66623:tid 66871] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/root.php"] [unique_id "aoSAhdO5rbWdOArH04KGVAAAAXM"]
[Tue Aug 18 12:55:49.106540 2026] [security2:error] [pid 67073:tid 67199] [remote 191.39.149.110:7833] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "barsantajulia.com.br"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "aoSAhfcmepr5_nHgLbNKQwACW3s"], referer: https://barsantajulia.com.br/
[Tue Aug 18 12:55:49.123141 2026] [security2:error] [pid 67073:tid 67226] [client 4.223.164.152:46147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/file15.php"] [unique_id "aoSAhfcmepr5_nHgLbNKTgAAAik"]
[Tue Aug 18 12:55:49.123432 2026] [security2:error] [pid 66623:tid 66863] [client 20.226.56.190:2741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/su.php"] [unique_id "aoSAhdO5rbWdOArH04KGVQAAAWs"]
[Tue Aug 18 12:55:49.186473 2026] [security2:error] [pid 67073:tid 67205] [client 20.250.13.23:14313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/bthil.php"] [unique_id "aoSAhfcmepr5_nHgLbNKUAAAAhQ"]
[Tue Aug 18 12:55:49.187841 2026] [security2:error] [pid 66623:tid 66884] [client 20.91.215.254:11981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/sf.php"] [unique_id "aoSAhdO5rbWdOArH04KGVwAAAYA"]
[Tue Aug 18 12:55:49.201220 2026] [security2:error] [pid 66623:tid 66870] [client 20.171.51.14:16714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/sx.php"] [unique_id "aoSAhdO5rbWdOArH04KGWQAAAXI"]
[Tue Aug 18 12:55:49.206053 2026] [security2:error] [pid 67073:tid 67194] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/vu.php"] [unique_id "aoSAhfcmepr5_nHgLbNKUgACj3Y"]
[Tue Aug 18 12:55:49.213919 2026] [security2:error] [pid 66623:tid 66811] [client 20.226.6.191:6583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSAhdO5rbWdOArH04KGWgAAATc"]
[Tue Aug 18 12:55:49.258744 2026] [security2:error] [pid 67073:tid 67308] [client 20.151.109.219:12911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/28.php"] [unique_id "aoSAhfcmepr5_nHgLbNKVQAAAns"]
[Tue Aug 18 12:55:49.318751 2026] [security2:error] [pid 66623:tid 66841] [client 20.65.69.59:40549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/payout.php"] [unique_id "aoSAhdO5rbWdOArH04KGXQAAAVU"]
[Tue Aug 18 12:55:49.330367 2026] [security2:error] [pid 66623:tid 66872] [client 68.221.73.131:9775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/akismet.php"] [unique_id "aoSAhdO5rbWdOArH04KGXgAAAXQ"]
[Tue Aug 18 12:55:49.352011 2026] [security2:error] [pid 67073:tid 67267] [client 20.42.19.40:1393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSAhfcmepr5_nHgLbNKZAAAAlI"]
[Tue Aug 18 12:55:49.363993 2026] [security2:error] [pid 66623:tid 66888] [client 158.158.74.177:22731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/h.php"] [unique_id "aoSAhdO5rbWdOArH04KGXwAAAYQ"]
[Tue Aug 18 12:55:49.367428 2026] [security2:error] [pid 66623:tid 66768] [client 20.226.56.190:3055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/wp-key.php"] [unique_id "aoSAhdO5rbWdOArH04KGYAAAAQw"]
[Tue Aug 18 12:55:49.370083 2026] [security2:error] [pid 67073:tid 67214] [client 20.100.169.31:17906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAhfcmepr5_nHgLbNKZQAAAh0"]
[Tue Aug 18 12:55:49.423920 2026] [security2:error] [pid 66623:tid 66862] [client 20.48.236.86:16128] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.sitemw.com.br"] [uri "/1.php"] [unique_id "aoSAhdO5rbWdOArH04KGYgAAAWo"]
[Tue Aug 18 12:55:49.424035 2026] [security2:error] [pid 66623:tid 66862] [client 20.48.236.86:16128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/1.php"] [unique_id "aoSAhdO5rbWdOArH04KGYgAAAWo"]
[Tue Aug 18 12:55:49.431178 2026] [security2:error] [pid 67073:tid 67236] [client 158.158.34.183:32230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/Njima.php"] [unique_id "aoSAhfcmepr5_nHgLbNKagAAAjM"]
[Tue Aug 18 12:55:49.446494 2026] [autoindex:error] [pid 67073:tid 67329] [client 20.226.6.191:64099] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:49.455345 2026] [security2:error] [pid 67073:tid 67225] [client 20.226.6.191:64099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/aa.php"] [unique_id "aoSAhfcmepr5_nHgLbNKbwAAAig"]
[Tue Aug 18 12:55:49.458280 2026] [security2:error] [pid 67073:tid 67313] [client 213.35.127.232:65055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAhfcmepr5_nHgLbNKcAAAAoA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:49.463441 2026] [security2:error] [pid 67073:tid 67156] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ic.php"] [unique_id "aoSAhfcmepr5_nHgLbNKcQACRlA"]
[Tue Aug 18 12:55:49.512512 2026] [security2:error] [pid 67073:tid 67229] [client 20.29.77.16:57027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/summary.php"] [unique_id "aoSAhfcmepr5_nHgLbNKdgAAAiw"]
[Tue Aug 18 12:55:49.554039 2026] [security2:error] [pid 67073:tid 67310] [client 52.139.47.57:44623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/x.php"] [unique_id "aoSAhfcmepr5_nHgLbNKdwAAAn0"]
[Tue Aug 18 12:55:49.562242 2026] [security2:error] [pid 67073:tid 67232] [client 20.151.109.219:21672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/m.php"] [unique_id "aoSAhfcmepr5_nHgLbNKeAAAAi8"]
[Tue Aug 18 12:55:49.569707 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:49.570012 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:49.586494 2026] [security2:error] [pid 67073:tid 67251] [client 20.42.19.40:1397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/db.php"] [unique_id "aoSAhfcmepr5_nHgLbNKfgAAAkI"]
[Tue Aug 18 12:55:49.587135 2026] [security2:error] [pid 67073:tid 67260] [client 4.223.164.152:64698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/f35.php"] [unique_id "aoSAhfcmepr5_nHgLbNKfwAAAks"]
[Tue Aug 18 12:55:49.588366 2026] [security2:error] [pid 67073:tid 67305] [client 20.42.19.40:2706] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/cgi-bin/"] [unique_id "aoSAhfcmepr5_nHgLbNKgAAAAng"]
[Tue Aug 18 12:55:49.595960 2026] [security2:error] [pid 67073:tid 67249] [client 20.226.56.190:28261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gg.php"] [unique_id "aoSAhfcmepr5_nHgLbNKhAAAAkA"]
[Tue Aug 18 12:55:49.647457 2026] [security2:error] [pid 67073:tid 67253] [client 74.248.130.103:15374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/admin.php"] [unique_id "aoSAhfcmepr5_nHgLbNKjgAAAkQ"]
[Tue Aug 18 12:55:49.648261 2026] [security2:error] [pid 67073:tid 67266] [client 5.253.205.188:50526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/installdemodemo.sql"] [unique_id "aoSAhfcmepr5_nHgLbNKjQAAAlE"], referer: https://medihub.com.br/installdemodemo.sql
[Tue Aug 18 12:55:49.663358 2026] [security2:error] [pid 67073:tid 67286] [client 135.225.75.187:62126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-access.php"] [unique_id "aoSAhfcmepr5_nHgLbNKkQAAAmU"]
[Tue Aug 18 12:55:49.679410 2026] [security2:error] [pid 67073:tid 67165] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ue.php"] [unique_id "aoSAhfcmepr5_nHgLbNKkwACalk"]
[Tue Aug 18 12:55:49.687958 2026] [security2:error] [pid 67073:tid 67275] [client 20.226.56.190:23786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gi.php"] [unique_id "aoSAhfcmepr5_nHgLbNKlAAAAlo"]
[Tue Aug 18 12:55:49.715281 2026] [security2:error] [pid 66623:tid 66772] [client 20.116.17.175:57650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/epinyins.php"] [unique_id "aoSAhdO5rbWdOArH04KGZgAAARA"]
[Tue Aug 18 12:55:49.734422 2026] [security2:error] [pid 67073:tid 67299] [client 52.238.210.254:8900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/sx.php"] [unique_id "aoSAhfcmepr5_nHgLbNKpAAAAnI"]
[Tue Aug 18 12:55:49.734443 2026] [security2:error] [pid 67073:tid 67277] [client 20.48.236.86:16338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/dev1s.php"] [unique_id "aoSAhfcmepr5_nHgLbNKpQAAAlw"]
[Tue Aug 18 12:55:49.745326 2026] [security2:error] [pid 66623:tid 66809] [client 20.163.43.14:4345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAhdO5rbWdOArH04KGZwAAATU"]
[Tue Aug 18 12:55:49.759030 2026] [security2:error] [pid 67073:tid 67244] [client 20.226.56.190:20399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/pz.php"] [unique_id "aoSAhfcmepr5_nHgLbNKpgAAAjs"]
[Tue Aug 18 12:55:49.762404 2026] [security2:error] [pid 67073:tid 67283] [client 20.226.6.191:6601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAhfcmepr5_nHgLbNKqAAAAmI"]
[Tue Aug 18 12:55:49.767707 2026] [security2:error] [pid 67073:tid 67262] [client 20.163.43.14:4426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wso.php"] [unique_id "aoSAhfcmepr5_nHgLbNKqwAAAk0"]
[Tue Aug 18 12:55:49.804545 2026] [security2:error] [pid 67073:tid 67241] [client 20.91.215.254:13074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/license.php"] [unique_id "aoSAhfcmepr5_nHgLbNKsgAAAjg"]
[Tue Aug 18 12:55:49.850002 2026] [security2:error] [pid 67073:tid 67285] [client 4.232.151.198:19910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAhfcmepr5_nHgLbNKtAAAAmQ"]
[Tue Aug 18 12:55:49.851214 2026] [security2:error] [pid 67073:tid 67219] [client 20.42.19.40:1352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/dropdown.php"] [unique_id "aoSAhfcmepr5_nHgLbNKtQAAAiI"]
[Tue Aug 18 12:55:49.861850 2026] [security2:error] [pid 67073:tid 67243] [client 20.151.109.219:64968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/nl.php"] [unique_id "aoSAhfcmepr5_nHgLbNKtwAAAjo"]
[Tue Aug 18 12:55:49.870458 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:49.870716 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:49.881814 2026] [security2:error] [pid 66623:tid 66775] [client 47.128.60.142:39256] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sunlux.com.br"] [uri "/robots.txt"] [unique_id "aoSAhdO5rbWdOArH04KGaAAAARM"]
[Tue Aug 18 12:55:49.896764 2026] [security2:error] [pid 67073:tid 67118] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/lr.php"] [unique_id "aoSAhfcmepr5_nHgLbNKuwACTyo"]
[Tue Aug 18 12:55:49.907526 2026] [security2:error] [pid 67073:tid 67168] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSAhfcmepr5_nHgLbNKvAACJFw"]
[Tue Aug 18 12:55:49.914681 2026] [security2:error] [pid 66623:tid 66813] [client 20.171.51.14:58872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/nu.php"] [unique_id "aoSAhdO5rbWdOArH04KGaQAAATk"]
[Tue Aug 18 12:55:49.932550 2026] [security2:error] [pid 67073:tid 67278] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/s.php"] [unique_id "aoSAhfcmepr5_nHgLbNKvgAAAl0"]
[Tue Aug 18 12:55:49.940181 2026] [security2:error] [pid 66623:tid 66796] [client 20.91.215.254:12011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/chosen.php"] [unique_id "aoSAhdO5rbWdOArH04KGawAAASg"]
[Tue Aug 18 12:55:50.020310 2026] [security2:error] [pid 66623:tid 66881] [client 20.100.169.31:17880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSAhtO5rbWdOArH04KGbAAAAX0"]
[Tue Aug 18 12:55:50.031383 2026] [security2:error] [pid 67073:tid 67282] [client 4.223.164.152:37275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-load.php"] [unique_id "aoSAhvcmepr5_nHgLbNKyAAAAmE"]
[Tue Aug 18 12:55:50.050475 2026] [security2:error] [pid 67073:tid 67247] [client 20.226.56.190:52090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kk.php"] [unique_id "aoSAhvcmepr5_nHgLbNKywAAAj4"]
[Tue Aug 18 12:55:50.073516 2026] [security2:error] [pid 67073:tid 67237] [client 158.158.74.177:16514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/hello.php"] [unique_id "aoSAhvcmepr5_nHgLbNKzQAAAjQ"]
[Tue Aug 18 12:55:50.078149 2026] [security2:error] [pid 67073:tid 67142] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSAhvcmepr5_nHgLbNKzgACGUI"]
[Tue Aug 18 12:55:50.090057 2026] [security2:error] [pid 66623:tid 66784] [client 74.248.18.37:28137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/atex1.php"] [unique_id "aoSAhtO5rbWdOArH04KGbgAAARw"]
[Tue Aug 18 12:55:50.092479 2026] [security2:error] [pid 67073:tid 67214] [client 20.42.19.40:9668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/file.php"] [unique_id "aoSAhvcmepr5_nHgLbNK0QAAAh0"]
[Tue Aug 18 12:55:50.108269 2026] [authz_core:error] [pid 66623:tid 66672] [remote 57.141.22.12:35772] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:50.108527 2026] [authz_core:error] [pid 66623:tid 66672] [remote 57.141.22.12:35772] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:50.136922 2026] [security2:error] [pid 67073:tid 67246] [client 20.48.236.86:16312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/we.php"] [unique_id "aoSAhvcmepr5_nHgLbNK0wAAAj0"]
[Tue Aug 18 12:55:50.156105 2026] [security2:error] [pid 67073:tid 67160] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ka.php"] [unique_id "aoSAhvcmepr5_nHgLbNK2AACGlQ"]
[Tue Aug 18 12:55:50.188075 2026] [security2:error] [pid 67073:tid 67236] [client 20.151.109.219:51672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/68.php"] [unique_id "aoSAhvcmepr5_nHgLbNK2wAAAjM"]
[Tue Aug 18 12:55:50.198624 2026] [security2:error] [pid 67073:tid 67215] [client 20.116.17.175:57634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/load.php"] [unique_id "aoSAhvcmepr5_nHgLbNK3AAAAh4"]
[Tue Aug 18 12:55:50.204924 2026] [security2:error] [pid 67073:tid 67304] [client 20.226.56.190:52065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/phpcheck.php"] [unique_id "aoSAhvcmepr5_nHgLbNK3QAAAnc"]
[Tue Aug 18 12:55:50.265161 2026] [security2:error] [pid 67073:tid 67245] [client 20.163.43.14:4235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAhvcmepr5_nHgLbNK4AAAAjw"]
[Tue Aug 18 12:55:50.266887 2026] [security2:error] [pid 66623:tid 66820] [client 74.248.130.103:14431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/edit.php"] [unique_id "aoSAhtO5rbWdOArH04KGcAAAAUA"]
[Tue Aug 18 12:55:50.276801 2026] [security2:error] [pid 67073:tid 67229] [client 20.65.98.162:15526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/gm.php"] [unique_id "aoSAhvcmepr5_nHgLbNK4QAAAiw"]
[Tue Aug 18 12:55:50.280817 2026] [security2:error] [pid 67073:tid 67314] [client 20.163.43.14:4471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/sf.php"] [unique_id "aoSAhvcmepr5_nHgLbNK4gAAAoE"]
[Tue Aug 18 12:55:50.296732 2026] [security2:error] [pid 66623:tid 66782] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/sang.php"] [unique_id "aoSAhtO5rbWdOArH04KGcgAAARo"]
[Tue Aug 18 12:55:50.300273 2026] [security2:error] [pid 66623:tid 66866] [client 20.29.77.16:47753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/conf.php"] [unique_id "aoSAhtO5rbWdOArH04KGcwAAAW4"]
[Tue Aug 18 12:55:50.304968 2026] [security2:error] [pid 67073:tid 67322] [client 158.158.34.183:24609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/colors.php"] [unique_id "aoSAhvcmepr5_nHgLbNK4wAAAok"]
[Tue Aug 18 12:55:50.319202 2026] [security2:error] [pid 66623:tid 66858] [client 132.196.61.152:60321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/ai.php"] [unique_id "aoSAhtO5rbWdOArH04KGdAAAAWY"]
[Tue Aug 18 12:55:50.336879 2026] [security2:error] [pid 67073:tid 67228] [client 20.42.19.40:1365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/goods.php"] [unique_id "aoSAhvcmepr5_nHgLbNK5QAAAis"]
[Tue Aug 18 12:55:50.339954 2026] [security2:error] [pid 66623:tid 66799] [client 20.251.48.93:14462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/wpxml.php"] [unique_id "aoSAhtO5rbWdOArH04KGdQAAASs"]
[Tue Aug 18 12:55:50.343023 2026] [security2:error] [pid 66623:tid 66814] [client 52.238.210.254:8915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSAhtO5rbWdOArH04KGdgAAATo"]
[Tue Aug 18 12:55:50.391571 2026] [security2:error] [pid 66623:tid 66833] [client 52.139.47.57:16680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSAhtO5rbWdOArH04KGeAAAAU0"]
[Tue Aug 18 12:55:50.397914 2026] [security2:error] [pid 67073:tid 67205] [client 114.5.214.109:49807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAhvcmepr5_nHgLbNK7QAAAhQ"]
[Tue Aug 18 12:55:50.398043 2026] [security2:error] [pid 67073:tid 67205] [client 114.5.214.109:49807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAhvcmepr5_nHgLbNK7QAAAhQ"]
[Tue Aug 18 12:55:50.402293 2026] [security2:error] [pid 67073:tid 67305] [client 20.65.69.59:40569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/Mailgun.php"] [unique_id "aoSAhvcmepr5_nHgLbNK7wAAAng"]
[Tue Aug 18 12:55:50.421474 2026] [security2:error] [pid 67073:tid 67184] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ot.php"] [unique_id "aoSAhvcmepr5_nHgLbNK8AACF2w"]
[Tue Aug 18 12:55:50.449984 2026] [security2:error] [pid 67073:tid 67253] [client 4.223.164.152:28481] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/assets/"] [unique_id "aoSAhvcmepr5_nHgLbNK8gAAAkQ"]
[Tue Aug 18 12:55:50.471528 2026] [security2:error] [pid 66623:tid 66801] [client 213.35.127.232:65274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAhtO5rbWdOArH04KGeQAAAS0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:50.475533 2026] [authz_core:error] [pid 67073:tid 67170] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:50.475786 2026] [authz_core:error] [pid 67073:tid 67170] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:50.511169 2026] [security2:error] [pid 67073:tid 67291] [client 68.221.73.131:61253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/admin.php"] [unique_id "aoSAhvcmepr5_nHgLbNK9gAAAmo"]
[Tue Aug 18 12:55:50.512074 2026] [security2:error] [pid 67073:tid 67272] [client 20.48.236.86:16301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/gdn.php"] [unique_id "aoSAhvcmepr5_nHgLbNK9wAAAlc"]
[Tue Aug 18 12:55:50.523774 2026] [security2:error] [pid 67073:tid 67302] [client 20.151.109.219:12919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/jl.php"] [unique_id "aoSAhvcmepr5_nHgLbNK-AAAAnU"]
[Tue Aug 18 12:55:50.577045 2026] [security2:error] [pid 66623:tid 66865] [client 20.42.19.40:9699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/hplfuns.php"] [unique_id "aoSAhtO5rbWdOArH04KGegAAAW0"]
[Tue Aug 18 12:55:50.608275 2026] [security2:error] [pid 67073:tid 67173] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSAhvcmepr5_nHgLbNK-wACFWE"]
[Tue Aug 18 12:55:50.609954 2026] [security2:error] [pid 67073:tid 67242] [client 20.163.43.14:4212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/o.php"] [unique_id "aoSAhvcmepr5_nHgLbNK_AAAAjk"]
[Tue Aug 18 12:55:50.650996 2026] [security2:error] [pid 67073:tid 67090] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ih.php"] [unique_id "aoSAhvcmepr5_nHgLbNK_gACkg4"]
[Tue Aug 18 12:55:50.658203 2026] [security2:error] [pid 67073:tid 67234] [client 20.100.169.31:17861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSAhvcmepr5_nHgLbNLAAAAAjE"]
[Tue Aug 18 12:55:50.689734 2026] [security2:error] [pid 66623:tid 66837] [client 158.23.17.4:29457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/evil.php"] [unique_id "aoSAhtO5rbWdOArH04KGewAAAVE"]
[Tue Aug 18 12:55:50.740353 2026] [security2:error] [pid 66623:tid 66790] [client 20.226.56.190:47113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/dg.php"] [unique_id "aoSAhtO5rbWdOArH04KGfQAAASI"]
[Tue Aug 18 12:55:50.758231 2026] [security2:error] [pid 67073:tid 67241] [client 20.163.43.14:4413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/index/function.php"] [unique_id "aoSAhvcmepr5_nHgLbNLCQAAAjg"]
[Tue Aug 18 12:55:50.761529 2026] [security2:error] [pid 66623:tid 66875] [client 20.91.215.254:27405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/u.php"] [unique_id "aoSAhtO5rbWdOArH04KGfgAAAXc"]
[Tue Aug 18 12:55:50.771252 2026] [security2:error] [pid 66623:tid 66773] [client 135.225.75.187:31581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/nw.php"] [unique_id "aoSAhtO5rbWdOArH04KGfwAAARE"]
[Tue Aug 18 12:55:50.775763 2026] [authz_core:error] [pid 67073:tid 67199] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:50.776024 2026] [authz_core:error] [pid 67073:tid 67199] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:50.816936 2026] [security2:error] [pid 67073:tid 67292] [client 158.158.74.177:2659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/images/index.php"] [unique_id "aoSAhvcmepr5_nHgLbNLEgAAAms"]
[Tue Aug 18 12:55:50.829599 2026] [security2:error] [pid 67073:tid 67326] [client 4.232.151.198:35335] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/1.php"] [unique_id "aoSAhvcmepr5_nHgLbNLEwAAAo0"]
[Tue Aug 18 12:55:50.829683 2026] [security2:error] [pid 67073:tid 67326] [client 4.232.151.198:35335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/1.php"] [unique_id "aoSAhvcmepr5_nHgLbNLEwAAAo0"]
[Tue Aug 18 12:55:50.831692 2026] [security2:error] [pid 66623:tid 66805] [client 20.151.109.219:65018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/tq.php"] [unique_id "aoSAhtO5rbWdOArH04KGgAAAATE"]
[Tue Aug 18 12:55:50.860086 2026] [security2:error] [pid 67073:tid 67243] [client 20.250.13.23:14281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/x.php"] [unique_id "aoSAhvcmepr5_nHgLbNLFQAAAjo"]
[Tue Aug 18 12:55:50.862602 2026] [security2:error] [pid 67073:tid 67196] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/k.php"] [unique_id "aoSAhvcmepr5_nHgLbNLFgACJXg"]
[Tue Aug 18 12:55:50.870483 2026] [security2:error] [pid 67073:tid 67224] [client 20.42.19.40:9713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/htaccess.php"] [unique_id "aoSAhvcmepr5_nHgLbNLFwAAAic"]
[Tue Aug 18 12:55:50.873284 2026] [security2:error] [pid 67073:tid 67300] [client 20.48.236.86:16310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/166.php"] [unique_id "aoSAhvcmepr5_nHgLbNLGAAAAnM"]
[Tue Aug 18 12:55:50.881670 2026] [security2:error] [pid 66623:tid 66845] [client 52.139.47.57:18626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/aaa.php"] [unique_id "aoSAhtO5rbWdOArH04KGgQAAAVk"]
[Tue Aug 18 12:55:50.890763 2026] [security2:error] [pid 67073:tid 67230] [client 4.223.164.152:17620] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "aoSAhvcmepr5_nHgLbNLGQAAAi0"]
[Tue Aug 18 12:55:50.898967 2026] [security2:error] [pid 67073:tid 67212] [client 20.116.17.175:57418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSAhvcmepr5_nHgLbNLGwAAAhs"]
[Tue Aug 18 12:55:50.901108 2026] [security2:error] [pid 66623:tid 66819] [client 196.12.128.158:63654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAhtO5rbWdOArH04KGggAAAT8"]
[Tue Aug 18 12:55:50.901213 2026] [security2:error] [pid 66623:tid 66819] [client 196.12.128.158:63654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAhtO5rbWdOArH04KGggAAAT8"]
[Tue Aug 18 12:55:50.939545 2026] [security2:error] [pid 67073:tid 67309] [client 20.163.43.14:4192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/bb.php"] [unique_id "aoSAhvcmepr5_nHgLbNLHgAAAnw"]
[Tue Aug 18 12:55:50.983753 2026] [security2:error] [pid 66623:tid 66870] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/scxy.php"] [unique_id "aoSAhtO5rbWdOArH04KGgwAAAXI"]
[Tue Aug 18 12:55:51.007593 2026] [security2:error] [pid 67073:tid 67240] [client 47.128.96.224:40384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mrguaratoldos.com.br"] [uri "/robots.txt"] [unique_id "aoSAh_cmepr5_nHgLbNLIAAAAjc"]
[Tue Aug 18 12:55:51.066104 2026] [security2:error] [pid 67073:tid 67227] [client 20.29.77.16:52780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/bala.php"] [unique_id "aoSAh_cmepr5_nHgLbNLJAAAAio"]
[Tue Aug 18 12:55:51.066691 2026] [security2:error] [pid 67073:tid 67330] [client 158.158.34.183:24633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "aoSAh_cmepr5_nHgLbNLJQAAApE"]
[Tue Aug 18 12:55:51.081310 2026] [security2:error] [pid 67073:tid 67247] [client 52.238.210.254:8878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAh_cmepr5_nHgLbNLJwAAAj4"]
[Tue Aug 18 12:55:51.083522 2026] [security2:error] [pid 67073:tid 67321] [client 20.163.43.14:4422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/edit.php"] [unique_id "aoSAh_cmepr5_nHgLbNLKAAAAog"]
[Tue Aug 18 12:55:51.095299 2026] [security2:error] [pid 67073:tid 67163] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/iu.php"] [unique_id "aoSAh_cmepr5_nHgLbNLKQACNFc"]
[Tue Aug 18 12:55:51.104981 2026] [security2:error] [pid 67073:tid 67214] [client 20.215.241.237:52555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/mac.php"] [unique_id "aoSAh_cmepr5_nHgLbNLKgAAAh0"]
[Tue Aug 18 12:55:51.113390 2026] [security2:error] [pid 67073:tid 67265] [client 20.42.19.40:1372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/images/wso.php"] [unique_id "aoSAh_cmepr5_nHgLbNLKwAAAlA"]
[Tue Aug 18 12:55:51.123785 2026] [security2:error] [pid 67073:tid 67156] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSAh_cmepr5_nHgLbNLLwACMFA"]
[Tue Aug 18 12:55:51.160758 2026] [authz_core:error] [pid 67073:tid 67152] [remote 57.141.22.31:53966] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:51.161020 2026] [authz_core:error] [pid 67073:tid 67152] [remote 57.141.22.31:53966] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:51.166711 2026] [security2:error] [pid 66623:tid 66780] [client 20.151.109.219:53241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/cv.php"] [unique_id "aoSAh9O5rbWdOArH04KGhgAAARg"]
[Tue Aug 18 12:55:51.194400 2026] [security2:error] [pid 66623:tid 66839] [client 68.221.73.131:61288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/bajah.php"] [unique_id "aoSAh9O5rbWdOArH04KGhwAAAVM"]
[Tue Aug 18 12:55:51.244236 2026] [security2:error] [pid 67073:tid 67250] [client 20.48.236.86:16221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/file3.php"] [unique_id "aoSAh_cmepr5_nHgLbNLNwAAAkE"]
[Tue Aug 18 12:55:51.258814 2026] [security2:error] [pid 67073:tid 67229] [client 52.173.121.69:16509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSAh_cmepr5_nHgLbNLOAAAAiw"]
[Tue Aug 18 12:55:51.274243 2026] [security2:error] [pid 67073:tid 67261] [client 74.248.130.103:15420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-content/admin.php"] [unique_id "aoSAh_cmepr5_nHgLbNLOQAAAkw"]
[Tue Aug 18 12:55:51.296388 2026] [security2:error] [pid 67073:tid 67201] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSAh_cmepr5_nHgLbNLOgACL30"]
[Tue Aug 18 12:55:51.317759 2026] [security2:error] [pid 67073:tid 67159] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/pk.php"] [unique_id "aoSAh_cmepr5_nHgLbNLPQACjlM"]
[Tue Aug 18 12:55:51.343613 2026] [security2:error] [pid 66623:tid 66893] [client 20.163.43.14:4176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSAh9O5rbWdOArH04KGiAAAAYk"]
[Tue Aug 18 12:55:51.346305 2026] [security2:error] [pid 66623:tid 66872] [client 4.223.164.152:28519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSAh9O5rbWdOArH04KGiQAAAXQ"]
[Tue Aug 18 12:55:51.379302 2026] [authz_core:error] [pid 67073:tid 67089] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:51.379558 2026] [authz_core:error] [pid 67073:tid 67089] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:51.386186 2026] [security2:error] [pid 67073:tid 67305] [client 20.42.19.40:1998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/index/function.php"] [unique_id "aoSAh_cmepr5_nHgLbNLQgAAAng"]
[Tue Aug 18 12:55:51.412830 2026] [security2:error] [pid 67073:tid 67316] [client 132.196.61.152:61050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/w1px.php"] [unique_id "aoSAh_cmepr5_nHgLbNLRQAAAoM"]
[Tue Aug 18 12:55:51.438042 2026] [security2:error] [pid 67073:tid 67195] [remote 103.56.163.133:56086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/wp-login.php"] [unique_id "aoSAh_cmepr5_nHgLbNLRwAChXc"]
[Tue Aug 18 12:55:51.467675 2026] [security2:error] [pid 67073:tid 67085] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSAh_cmepr5_nHgLbNLSAACVQk"]
[Tue Aug 18 12:55:51.492370 2026] [security2:error] [pid 67073:tid 67280] [client 20.151.109.219:12912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/un.php"] [unique_id "aoSAh_cmepr5_nHgLbNLSgAAAl8"]
[Tue Aug 18 12:55:51.495588 2026] [security2:error] [pid 67073:tid 67287] [client 213.35.127.232:65480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAh_cmepr5_nHgLbNLSwAAAmY"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:51.497122 2026] [security2:error] [pid 67073:tid 67286] [client 68.155.154.236:16375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/zwlsv.php"] [unique_id "aoSAh_cmepr5_nHgLbNLTAAAAmU"]
[Tue Aug 18 12:55:51.508402 2026] [security2:error] [pid 67073:tid 67275] [client 20.100.169.31:17870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-themes.php"] [unique_id "aoSAh_cmepr5_nHgLbNLTQAAAlo"]
[Tue Aug 18 12:55:51.546928 2026] [security2:error] [pid 67073:tid 67131] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ge.php"] [unique_id "aoSAh_cmepr5_nHgLbNLTgACFTc"]
[Tue Aug 18 12:55:51.585544 2026] [security2:error] [pid 67073:tid 67324] [client 20.48.236.86:16192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/y.php"] [unique_id "aoSAh_cmepr5_nHgLbNLUQAAAos"]
[Tue Aug 18 12:55:51.587949 2026] [autoindex:error] [pid 67073:tid 67331] [client 44.215.89.156:48563] AH01276: Cannot serve directory /home1/activevaluecom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:51.609343 2026] [security2:error] [pid 67073:tid 67220] [client 20.163.43.14:4444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSAh_cmepr5_nHgLbNLUgAAAiM"]
[Tue Aug 18 12:55:51.615933 2026] [security2:error] [pid 67073:tid 67244] [client 20.91.215.254:20672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/customize.php"] [unique_id "aoSAh_cmepr5_nHgLbNLUwAAAjs"]
[Tue Aug 18 12:55:51.630615 2026] [security2:error] [pid 67073:tid 67262] [client 20.42.19.40:9639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/info.php"] [unique_id "aoSAh_cmepr5_nHgLbNLVAAAAk0"]
[Tue Aug 18 12:55:51.638250 2026] [security2:error] [pid 66623:tid 66848] [client 37.40.227.74:56582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAh9O5rbWdOArH04KGjQAAAVw"]
[Tue Aug 18 12:55:51.638410 2026] [security2:error] [pid 66623:tid 66848] [client 37.40.227.74:56582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAh9O5rbWdOArH04KGjQAAAVw"]
[Tue Aug 18 12:55:51.644400 2026] [security2:error] [pid 67073:tid 67319] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/sd.php"] [unique_id "aoSAh_cmepr5_nHgLbNLVgAAAoY"]
[Tue Aug 18 12:55:51.696079 2026] [security2:error] [pid 67073:tid 67256] [client 20.116.17.175:57445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/ty.php"] [unique_id "aoSAh_cmepr5_nHgLbNLWgAAAkc"]
[Tue Aug 18 12:55:51.708951 2026] [security2:error] [pid 67073:tid 67243] [client 158.23.17.4:8738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/wp-key.php"] [unique_id "aoSAh_cmepr5_nHgLbNLWwAAAjo"]
[Tue Aug 18 12:55:51.757494 2026] [security2:error] [pid 67073:tid 67268] [client 20.29.77.16:51365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/222.php"] [unique_id "aoSAh_cmepr5_nHgLbNLXQAAAlM"]
[Tue Aug 18 12:55:51.767858 2026] [security2:error] [pid 67073:tid 67281] [client 88.99.80.227:10116] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.meucrescer.com.br"] [uri "/index.php"] [unique_id "aoSAh_cmepr5_nHgLbNLWQAAAmA"], referer: https://www.meucrescer.com.br
[Tue Aug 18 12:55:51.822487 2026] [security2:error] [pid 67073:tid 67328] [client 20.171.51.14:43360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ko.php"] [unique_id "aoSAh_cmepr5_nHgLbNLYAAAAo8"]
[Tue Aug 18 12:55:51.843804 2026] [security2:error] [pid 67073:tid 67312] [client 20.226.56.190:23774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/bm.php"] [unique_id "aoSAh_cmepr5_nHgLbNLZQAAAn8"]
[Tue Aug 18 12:55:51.851022 2026] [security2:error] [pid 67073:tid 67234] [client 158.158.74.177:22761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/index.bak.php"] [unique_id "aoSAh_cmepr5_nHgLbNLZgAAAjE"]
[Tue Aug 18 12:55:51.851155 2026] [security2:error] [pid 67073:tid 67161] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kl.php"] [unique_id "aoSAh_cmepr5_nHgLbNLZwACbFU"]
[Tue Aug 18 12:55:51.854712 2026] [security2:error] [pid 67073:tid 67258] [client 20.151.109.219:21689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/evil.php"] [unique_id "aoSAh_cmepr5_nHgLbNLaAAAAkk"]
[Tue Aug 18 12:55:51.864256 2026] [security2:error] [pid 67073:tid 67218] [client 4.223.164.152:28531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/aaa.php"] [unique_id "aoSAh_cmepr5_nHgLbNLagAAAiE"]
[Tue Aug 18 12:55:51.869136 2026] [security2:error] [pid 67073:tid 67283] [client 158.158.34.183:50197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/radio.php"] [unique_id "aoSAh_cmepr5_nHgLbNLawAAAmI"]
[Tue Aug 18 12:55:51.886635 2026] [security2:error] [pid 67073:tid 67292] [client 52.139.47.57:47650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/fpwch.php"] [unique_id "aoSAh_cmepr5_nHgLbNLbAAAAms"]
[Tue Aug 18 12:55:51.888702 2026] [security2:error] [pid 67073:tid 67216] [client 20.163.43.14:4285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSAh_cmepr5_nHgLbNLbQAAAh8"]
[Tue Aug 18 12:55:51.900943 2026] [security2:error] [pid 67073:tid 67330] [client 74.248.130.103:36820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/inputs.php"] [unique_id "aoSAh_cmepr5_nHgLbNLbgAAApE"]
[Tue Aug 18 12:55:51.922033 2026] [security2:error] [pid 67073:tid 67291] [client 4.232.151.198:17290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/alfa.php"] [unique_id "aoSAh_cmepr5_nHgLbNLbwAAAmo"]
[Tue Aug 18 12:55:51.930932 2026] [security2:error] [pid 67073:tid 67214] [client 20.104.85.180:43562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/aa.php"] [unique_id "aoSAh_cmepr5_nHgLbNLcAAAAh0"]
[Tue Aug 18 12:55:51.946465 2026] [security2:error] [pid 67073:tid 67233] [client 20.42.19.40:9663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/profile.php"] [unique_id "aoSAh_cmepr5_nHgLbNLcgAAAjA"]
[Tue Aug 18 12:55:51.968818 2026] [security2:error] [pid 67073:tid 67235] [client 197.184.64.235:41927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAh_cmepr5_nHgLbNLcwAAAjI"]
[Tue Aug 18 12:55:51.968899 2026] [security2:error] [pid 67073:tid 67235] [client 197.184.64.235:41927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAh_cmepr5_nHgLbNLcwAAAjI"]
[Tue Aug 18 12:55:51.977325 2026] [authz_core:error] [pid 67073:tid 67147] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:51.977563 2026] [authz_core:error] [pid 67073:tid 67147] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:51.986175 2026] [security2:error] [pid 67073:tid 67313] [client 135.225.75.187:9830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ws62.php"] [unique_id "aoSAh_cmepr5_nHgLbNLdQAAAoA"]
[Tue Aug 18 12:55:51.991536 2026] [security2:error] [pid 66623:tid 66853] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/sf.php"] [unique_id "aoSAh9O5rbWdOArH04KGjwAAAWE"]
[Tue Aug 18 12:55:52.013057 2026] [security2:error] [pid 67073:tid 67238] [client 20.163.43.14:4381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-good.php"] [unique_id "aoSAiPcmepr5_nHgLbNLdwAAAjU"]
[Tue Aug 18 12:55:52.014568 2026] [security2:error] [pid 67073:tid 67314] [client 20.48.236.86:16237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/modric8QWQCC.php"] [unique_id "aoSAiPcmepr5_nHgLbNLeAAAAoE"]
[Tue Aug 18 12:55:52.055151 2026] [security2:error] [pid 67073:tid 67116] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gs.php"] [unique_id "aoSAiPcmepr5_nHgLbNLegACNig"]
[Tue Aug 18 12:55:52.128150 2026] [security2:error] [pid 67073:tid 67267] [client 20.100.169.31:2443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/xmlrpc.php"] [unique_id "aoSAiPcmepr5_nHgLbNLfAAAAlI"]
[Tue Aug 18 12:55:52.142519 2026] [security2:error] [pid 67073:tid 67253] [client 20.116.17.175:57461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSAiPcmepr5_nHgLbNLfgAAAkQ"]
[Tue Aug 18 12:55:52.153768 2026] [security2:error] [pid 67073:tid 67145] [remote 50.87.182.201:58566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.182.87.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-login.php"] [unique_id "aoSAiPcmepr5_nHgLbNLfwACX0U"]
[Tue Aug 18 12:55:52.155454 2026] [security2:error] [pid 67073:tid 67286] [client 172.202.39.151:50185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/chosen.php"] [unique_id "aoSAiPcmepr5_nHgLbNLgAAAAmU"]
[Tue Aug 18 12:55:52.171792 2026] [security2:error] [pid 66623:tid 66846] [client 20.65.98.162:28480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/ws55.php"] [unique_id "aoSAiNO5rbWdOArH04KGkAAAAVo"]
[Tue Aug 18 12:55:52.177161 2026] [security2:error] [pid 67073:tid 67302] [client 20.65.69.59:57072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/oauth.php"] [unique_id "aoSAiPcmepr5_nHgLbNLgQAAAnU"]
[Tue Aug 18 12:55:52.183209 2026] [security2:error] [pid 67073:tid 67317] [client 20.42.19.40:9643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/sx.php"] [unique_id "aoSAiPcmepr5_nHgLbNLggAAAoQ"]
[Tue Aug 18 12:55:52.200127 2026] [security2:error] [pid 66623:tid 66860] [client 20.151.109.219:59738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/pw.php"] [unique_id "aoSAiNO5rbWdOArH04KGkQAAAWg"]
[Tue Aug 18 12:55:52.210969 2026] [security2:error] [pid 67073:tid 67306] [client 20.104.85.180:18828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/0x.php"] [unique_id "aoSAiPcmepr5_nHgLbNLhAAAAnk"]
[Tue Aug 18 12:55:52.252629 2026] [security2:error] [pid 66623:tid 66825] [client 20.163.43.14:4290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAiNO5rbWdOArH04KGkgAAAUU"]
[Tue Aug 18 12:55:52.266105 2026] [security2:error] [pid 66623:tid 66832] [client 20.226.6.191:7104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/file.php"] [unique_id "aoSAiNO5rbWdOArH04KGkwAAAUw"]
[Tue Aug 18 12:55:52.280555 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:52.280828 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:52.291946 2026] [security2:error] [pid 66623:tid 66791] [client 4.223.164.152:17617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/gecko.php"] [unique_id "aoSAiNO5rbWdOArH04KGlAAAASM"]
[Tue Aug 18 12:55:52.293294 2026] [security2:error] [pid 67073:tid 67324] [client 68.221.73.131:61187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/ajax.php"] [unique_id "aoSAiPcmepr5_nHgLbNLhwAAAos"]
[Tue Aug 18 12:55:52.307968 2026] [security2:error] [pid 67073:tid 67139] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/lw.php"] [unique_id "aoSAiPcmepr5_nHgLbNLiAACOz8"]
[Tue Aug 18 12:55:52.327648 2026] [security2:error] [pid 67073:tid 67162] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSAiPcmepr5_nHgLbNLigACilY"]
[Tue Aug 18 12:55:52.378964 2026] [security2:error] [pid 67073:tid 67222] [client 20.171.51.14:51835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/pl.php"] [unique_id "aoSAiPcmepr5_nHgLbNLjgAAAiU"]
[Tue Aug 18 12:55:52.384194 2026] [security2:error] [pid 67073:tid 67300] [client 52.173.121.69:16493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSAiPcmepr5_nHgLbNLjwAAAnM"]
[Tue Aug 18 12:55:52.425153 2026] [security2:error] [pid 67073:tid 67212] [client 20.42.19.40:2023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSAiPcmepr5_nHgLbNLkQAAAhs"]
[Tue Aug 18 12:55:52.428366 2026] [security2:error] [pid 67073:tid 67221] [client 20.226.56.190:32309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/vu.php"] [unique_id "aoSAiPcmepr5_nHgLbNLkgAAAiQ"]
[Tue Aug 18 12:55:52.448827 2026] [security2:error] [pid 67073:tid 67281] [client 172.182.200.96:14160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSAiPcmepr5_nHgLbNLkwAAAmA"]
[Tue Aug 18 12:55:52.469736 2026] [security2:error] [pid 67073:tid 67278] [client 20.48.236.86:16198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/modric7Z7J2X.php"] [unique_id "aoSAiPcmepr5_nHgLbNLlQAAAl0"]
[Tue Aug 18 12:55:52.477991 2026] [security2:error] [pid 66623:tid 66817] [client 20.226.56.190:17882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ic.php"] [unique_id "aoSAiNO5rbWdOArH04KGlgAAAT0"]
[Tue Aug 18 12:55:52.504913 2026] [security2:error] [pid 67073:tid 67328] [client 20.104.85.180:43529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/zxz.php"] [unique_id "aoSAiPcmepr5_nHgLbNLmAAAAo8"]
[Tue Aug 18 12:55:52.508786 2026] [security2:error] [pid 67073:tid 67297] [client 213.35.127.232:49320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAiPcmepr5_nHgLbNLmQAAAnA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:52.509384 2026] [security2:error] [pid 67073:tid 67257] [client 74.248.130.103:14401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/av.php"] [unique_id "aoSAiPcmepr5_nHgLbNLmgAAAkg"]
[Tue Aug 18 12:55:52.518123 2026] [security2:error] [pid 67073:tid 67274] [client 20.29.77.16:32987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/routes.php"] [unique_id "aoSAiPcmepr5_nHgLbNLmwAAAlk"]
[Tue Aug 18 12:55:52.525235 2026] [security2:error] [pid 66623:tid 66789] [client 20.151.109.219:65020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/fn.php"] [unique_id "aoSAiNO5rbWdOArH04KGmAAAASE"]
[Tue Aug 18 12:55:52.552014 2026] [security2:error] [pid 67073:tid 67276] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAiPcmepr5_nHgLbNLnQAAAls"]
[Tue Aug 18 12:55:52.560338 2026] [security2:error] [pid 67073:tid 67325] [client 20.226.6.191:48824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/0x.php"] [unique_id "aoSAiPcmepr5_nHgLbNLngAAAow"]
[Tue Aug 18 12:55:52.576630 2026] [security2:error] [pid 67073:tid 67118] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/vj.php"] [unique_id "aoSAiPcmepr5_nHgLbNLoQACkyo"]
[Tue Aug 18 12:55:52.580562 2026] [authz_core:error] [pid 67073:tid 67138] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:52.580825 2026] [authz_core:error] [pid 67073:tid 67138] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:52.584251 2026] [security2:error] [pid 66623:tid 66813] [client 158.23.17.4:38879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/phpcheck.php"] [unique_id "aoSAiNO5rbWdOArH04KGmQAAATk"]
[Tue Aug 18 12:55:52.611560 2026] [security2:error] [pid 67073:tid 67321] [client 20.163.43.14:4279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/file.php"] [unique_id "aoSAiPcmepr5_nHgLbNLowAAAog"]
[Tue Aug 18 12:55:52.617102 2026] [security2:error] [pid 66623:tid 66834] [client 103.120.71.157:49770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAiNO5rbWdOArH04KGmgAAAU4"]
[Tue Aug 18 12:55:52.617244 2026] [security2:error] [pid 66623:tid 66834] [client 103.120.71.157:49770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAiNO5rbWdOArH04KGmgAAAU4"]
[Tue Aug 18 12:55:52.629984 2026] [security2:error] [pid 67073:tid 67291] [client 20.226.56.190:2516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ue.php"] [unique_id "aoSAiPcmepr5_nHgLbNLpAAAAmo"]
[Tue Aug 18 12:55:52.659397 2026] [security2:error] [pid 66623:tid 66798] [client 20.42.19.40:9601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAiNO5rbWdOArH04KGmwAAASo"]
[Tue Aug 18 12:55:52.691330 2026] [security2:error] [pid 67073:tid 67269] [client 20.91.215.254:20735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/mah/function.php"] [unique_id "aoSAiPcmepr5_nHgLbNLpgAAAlQ"]
[Tue Aug 18 12:55:52.702831 2026] [security2:error] [pid 66623:tid 66835] [client 158.158.74.177:16534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/index/function.php"] [unique_id "aoSAiNO5rbWdOArH04KGnAAAAU8"]
[Tue Aug 18 12:55:52.703228 2026] [security2:error] [pid 67073:tid 67215] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/shell.php"] [unique_id "aoSAiPcmepr5_nHgLbNLpwAAAh4"]
[Tue Aug 18 12:55:52.711685 2026] [security2:error] [pid 66623:tid 66861] [client 4.223.164.152:37299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/xiugai.php"] [unique_id "aoSAiNO5rbWdOArH04KGnQAAAWk"]
[Tue Aug 18 12:55:52.714424 2026] [security2:error] [pid 67073:tid 67304] [client 20.163.43.14:4472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/tes.php"] [unique_id "aoSAiPcmepr5_nHgLbNLqAAAAnc"]
[Tue Aug 18 12:55:52.721431 2026] [security2:error] [pid 67073:tid 67235] [client 20.116.17.175:57458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/dot.php"] [unique_id "aoSAiPcmepr5_nHgLbNLqQAAAjI"]
[Tue Aug 18 12:55:52.751119 2026] [security2:error] [pid 66623:tid 66809] [client 74.248.18.37:28820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/class-t.api.php"] [unique_id "aoSAiNO5rbWdOArH04KGngAAATU"]
[Tue Aug 18 12:55:52.802233 2026] [security2:error] [pid 67073:tid 67314] [client 20.104.85.180:7019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/www.php"] [unique_id "aoSAiPcmepr5_nHgLbNLrAAAAoE"]
[Tue Aug 18 12:55:52.805588 2026] [security2:error] [pid 67073:tid 67203] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/mimes.php"] [unique_id "aoSAiPcmepr5_nHgLbNLrQACLH8"]
[Tue Aug 18 12:55:52.807234 2026] [security2:error] [pid 67073:tid 67322] [client 20.171.51.14:58826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/env.php"] [unique_id "aoSAiPcmepr5_nHgLbNLrgAAAok"]
[Tue Aug 18 12:55:52.808864 2026] [security2:error] [pid 66623:tid 66774] [client 20.251.48.93:9760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/file1221.php"] [unique_id "aoSAiNO5rbWdOArH04KGnwAAARI"]
[Tue Aug 18 12:55:52.816960 2026] [security2:error] [pid 67073:tid 67261] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAiPcmepr5_nHgLbNLrwAAAkw"]
[Tue Aug 18 12:55:52.819360 2026] [security2:error] [pid 67073:tid 67259] [client 86.120.159.145:5975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAiPcmepr5_nHgLbNLsAAAAko"]
[Tue Aug 18 12:55:52.819524 2026] [security2:error] [pid 67073:tid 67259] [client 86.120.159.145:5975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAiPcmepr5_nHgLbNLsAAAAko"]
[Tue Aug 18 12:55:52.859577 2026] [security2:error] [pid 67073:tid 67151] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAiPcmepr5_nHgLbNLsgACL0s"]
[Tue Aug 18 12:55:52.872989 2026] [security2:error] [pid 67073:tid 67216] [client 158.158.34.183:32212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSAiPcmepr5_nHgLbNLswAAAh8"]
[Tue Aug 18 12:55:52.879618 2026] [security2:error] [pid 67073:tid 67251] [client 20.151.109.219:21657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kf.php"] [unique_id "aoSAiPcmepr5_nHgLbNLtQAAAkI"]
[Tue Aug 18 12:55:52.945549 2026] [security2:error] [pid 67073:tid 67316] [client 20.163.43.14:4116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/epinyins.php"] [unique_id "aoSAiPcmepr5_nHgLbNLtwAAAoM"]
[Tue Aug 18 12:55:52.947048 2026] [security2:error] [pid 67073:tid 67207] [client 20.42.19.40:2708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/class-t.api.php"] [unique_id "aoSAiPcmepr5_nHgLbNLuAAAAhY"]
[Tue Aug 18 12:55:52.958410 2026] [security2:error] [pid 66623:tid 66890] [client 20.48.236.86:16306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/modricXP4D68.php"] [unique_id "aoSAiNO5rbWdOArH04KGoAAAAYY"]
[Tue Aug 18 12:55:53.031340 2026] [security2:error] [pid 67073:tid 67158] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSAifcmepr5_nHgLbNLugACZlI"]
[Tue Aug 18 12:55:53.077980 2026] [security2:error] [pid 67073:tid 67302] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/st.php"] [unique_id "aoSAifcmepr5_nHgLbNLvAAAAnU"]
[Tue Aug 18 12:55:53.088079 2026] [security2:error] [pid 67073:tid 67206] [client 20.104.85.180:6983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wicked.php"] [unique_id "aoSAifcmepr5_nHgLbNLvgAAAhU"]
[Tue Aug 18 12:55:53.131482 2026] [security2:error] [pid 67073:tid 67220] [client 4.223.164.152:54226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/adminner.php"] [unique_id "aoSAifcmepr5_nHgLbNLwQAAAiM"]
[Tue Aug 18 12:55:53.138203 2026] [security2:error] [pid 67073:tid 67248] [client 20.226.6.191:39377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/zxz.php"] [unique_id "aoSAifcmepr5_nHgLbNLwwAAAj8"]
[Tue Aug 18 12:55:53.142743 2026] [security2:error] [pid 67073:tid 67244] [client 68.155.154.236:16323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/jrpga.php"] [unique_id "aoSAifcmepr5_nHgLbNLxAAAAjs"]
[Tue Aug 18 12:55:53.154645 2026] [security2:error] [pid 67073:tid 67323] [client 68.221.73.131:61212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAifcmepr5_nHgLbNLxgAAAoo"]
[Tue Aug 18 12:55:53.181681 2026] [authz_core:error] [pid 67073:tid 67171] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:53.181991 2026] [authz_core:error] [pid 67073:tid 67171] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:53.201987 2026] [security2:error] [pid 67073:tid 67176] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSAifcmepr5_nHgLbNLywACGGQ"]
[Tue Aug 18 12:55:53.218580 2026] [security2:error] [pid 67073:tid 67132] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ni.php"] [unique_id "aoSAifcmepr5_nHgLbNLzQACjTg"]
[Tue Aug 18 12:55:53.219772 2026] [security2:error] [pid 67073:tid 67243] [client 20.29.77.16:49277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/php5.php"] [unique_id "aoSAifcmepr5_nHgLbNLzgAAAjo"]
[Tue Aug 18 12:55:53.219879 2026] [security2:error] [pid 67073:tid 67222] [client 20.163.43.14:4402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/files/index.php"] [unique_id "aoSAifcmepr5_nHgLbNLzwAAAiU"]
[Tue Aug 18 12:55:53.235772 2026] [security2:error] [pid 66623:tid 66866] [client 20.151.109.219:24859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/su.php"] [unique_id "aoSAidO5rbWdOArH04KGpAAAAW4"]
[Tue Aug 18 12:55:53.245521 2026] [security2:error] [pid 66623:tid 66858] [client 20.116.17.175:57442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/005.php"] [unique_id "aoSAidO5rbWdOArH04KGpQAAAWY"]
[Tue Aug 18 12:55:53.256873 2026] [security2:error] [pid 66623:tid 66814] [client 20.48.236.86:16304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/clara.php"] [unique_id "aoSAidO5rbWdOArH04KGpgAAATo"]
[Tue Aug 18 12:55:53.280572 2026] [security2:error] [pid 66623:tid 66869] [client 20.163.43.14:4215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAidO5rbWdOArH04KGpwAAAXE"]
[Tue Aug 18 12:55:53.316150 2026] [security2:error] [pid 67073:tid 67281] [client 135.225.78.186:12992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAifcmepr5_nHgLbNL0wAAAmA"]
[Tue Aug 18 12:55:53.338842 2026] [security2:error] [pid 67073:tid 67210] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/le.php"] [unique_id "aoSAifcmepr5_nHgLbNL1gAAAhk"]
[Tue Aug 18 12:55:53.354273 2026] [security2:error] [pid 67073:tid 67297] [client 74.248.130.103:36835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/classwithtostring.php"] [unique_id "aoSAifcmepr5_nHgLbNL2QAAAnA"]
[Tue Aug 18 12:55:53.361335 2026] [security2:error] [pid 67073:tid 67265] [client 103.184.169.37:41767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAifcmepr5_nHgLbNL2gAAAlA"]
[Tue Aug 18 12:55:53.361745 2026] [security2:error] [pid 67073:tid 67265] [client 103.184.169.37:41767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAifcmepr5_nHgLbNL2gAAAlA"]
[Tue Aug 18 12:55:53.365516 2026] [security2:error] [pid 67073:tid 67303] [client 20.91.215.254:11999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/filter.php"] [unique_id "aoSAifcmepr5_nHgLbNL3AAAAnY"]
[Tue Aug 18 12:55:53.366946 2026] [security2:error] [pid 67073:tid 67240] [client 20.65.69.59:40522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/timeclock.php"] [unique_id "aoSAifcmepr5_nHgLbNL3QAAAjc"]
[Tue Aug 18 12:55:53.367440 2026] [security2:error] [pid 66623:tid 66886] [client 20.104.85.180:43547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSAidO5rbWdOArH04KGqQAAAYI"]
[Tue Aug 18 12:55:53.376000 2026] [security2:error] [pid 67073:tid 67312] [client 135.225.75.187:18805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/public/vx.php"] [unique_id "aoSAifcmepr5_nHgLbNL3wAAAn8"]
[Tue Aug 18 12:55:53.398540 2026] [security2:error] [pid 67073:tid 67211] [client 20.250.13.23:13817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/index/function.php"] [unique_id "aoSAifcmepr5_nHgLbNL4gAAAho"]
[Tue Aug 18 12:55:53.410631 2026] [security2:error] [pid 67073:tid 67319] [client 158.158.74.177:22724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/info.php"] [unique_id "aoSAifcmepr5_nHgLbNL6gAAAoY"]
[Tue Aug 18 12:55:53.464481 2026] [security2:error] [pid 67073:tid 67148] [remote 20.171.51.14:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.fonsecashop.com.br"] [uri "/1.php"] [unique_id "aoSAifcmepr5_nHgLbNL6wACKkg"]
[Tue Aug 18 12:55:53.464583 2026] [security2:error] [pid 67073:tid 67148] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/1.php"] [unique_id "aoSAifcmepr5_nHgLbNL6wACKkg"]
[Tue Aug 18 12:55:53.482700 2026] [authz_core:error] [pid 67073:tid 67184] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:53.482971 2026] [authz_core:error] [pid 67073:tid 67184] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:53.497213 2026] [security2:error] [pid 66623:tid 66797] [client 20.226.6.191:39418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/www.php"] [unique_id "aoSAidO5rbWdOArH04KGqwAAASk"]
[Tue Aug 18 12:55:53.523304 2026] [security2:error] [pid 67073:tid 67289] [client 213.35.127.232:49550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAifcmepr5_nHgLbNL7gAAAmg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:53.573860 2026] [security2:error] [pid 67073:tid 67233] [client 4.223.164.152:46170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/file1221.php"] [unique_id "aoSAifcmepr5_nHgLbNL8QAAAjA"]
[Tue Aug 18 12:55:53.574819 2026] [security2:error] [pid 67073:tid 67249] [client 4.232.151.198:19953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/edit.php"] [unique_id "aoSAifcmepr5_nHgLbNL8gAAAkA"]
[Tue Aug 18 12:55:53.607002 2026] [security2:error] [pid 67073:tid 67215] [client 20.151.109.219:64987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/wp-key.php"] [unique_id "aoSAifcmepr5_nHgLbNL9AAAAh4"]
[Tue Aug 18 12:55:53.608464 2026] [security2:error] [pid 67073:tid 67304] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/hr.php"] [unique_id "aoSAifcmepr5_nHgLbNL9QAAAnc"]
[Tue Aug 18 12:55:53.621450 2026] [security2:error] [pid 67073:tid 67235] [client 158.23.17.4:33491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/mimes.php"] [unique_id "aoSAifcmepr5_nHgLbNL-AAAAjI"]
[Tue Aug 18 12:55:53.632536 2026] [autoindex:error] [pid 67073:tid 67292] [client 172.202.39.151:12704] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/images/smilies/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:53.648286 2026] [security2:error] [pid 67073:tid 67245] [client 20.104.85.180:43554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAifcmepr5_nHgLbNL-wAAAjw"]
[Tue Aug 18 12:55:53.671638 2026] [security2:error] [pid 67073:tid 67314] [client 20.163.43.14:3041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAifcmepr5_nHgLbNL_AAAAoE"]
[Tue Aug 18 12:55:53.683702 2026] [security2:error] [pid 66623:tid 66785] [client 132.196.61.152:60314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/zi-936.php"] [unique_id "aoSAidO5rbWdOArH04KGrQAAAR0"]
[Tue Aug 18 12:55:53.695157 2026] [security2:error] [pid 66623:tid 66889] [client 20.226.6.191:6623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/epinyins.php"] [unique_id "aoSAidO5rbWdOArH04KGrgAAAYU"]
[Tue Aug 18 12:55:53.695622 2026] [security2:error] [pid 67073:tid 67325] [client 157.90.155.240:13666] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.meucrescer.com.br"] [uri "/index.php"] [unique_id "aoSAifcmepr5_nHgLbNL9gAAAow"], referer: https://www.meucrescer.com.br
[Tue Aug 18 12:55:53.705355 2026] [security2:error] [pid 67073:tid 67322] [client 20.29.77.16:52789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/Black.php"] [unique_id "aoSAifcmepr5_nHgLbNL_wAAAok"]
[Tue Aug 18 12:55:53.712250 2026] [security2:error] [pid 66623:tid 66865] [client 172.202.39.151:65231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/info.php"] [unique_id "aoSAidO5rbWdOArH04KGrwAAAW0"]
[Tue Aug 18 12:55:53.716143 2026] [security2:error] [pid 67073:tid 67228] [client 20.100.169.31:45604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/elp.php"] [unique_id "aoSAifcmepr5_nHgLbNMAQAAAis"]
[Tue Aug 18 12:55:53.718474 2026] [security2:error] [pid 67073:tid 67141] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/88.php"] [unique_id "aoSAifcmepr5_nHgLbNMAgACSkE"]
[Tue Aug 18 12:55:53.734003 2026] [security2:error] [pid 67073:tid 67310] [client 135.225.78.186:13018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAifcmepr5_nHgLbNMAwAAAn0"]
[Tue Aug 18 12:55:53.740259 2026] [security2:error] [pid 67073:tid 67232] [client 20.226.56.190:3059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/lr.php"] [unique_id "aoSAifcmepr5_nHgLbNMBAAAAi8"]
[Tue Aug 18 12:55:53.741038 2026] [security2:error] [pid 67073:tid 67090] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-themes.php"] [unique_id "aoSAifcmepr5_nHgLbNMBQACHw4"]
[Tue Aug 18 12:55:53.788055 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:53.788511 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:53.798063 2026] [security2:error] [pid 67073:tid 67330] [client 158.158.34.183:11270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSAifcmepr5_nHgLbNMDAAAApE"]
[Tue Aug 18 12:55:53.800914 2026] [security2:error] [pid 67073:tid 67316] [client 20.163.43.14:4327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSAifcmepr5_nHgLbNMDQAAAoM"]
[Tue Aug 18 12:55:53.844793 2026] [security2:error] [pid 67073:tid 67280] [client 74.248.130.103:36812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAifcmepr5_nHgLbNMDwAAAl8"]
[Tue Aug 18 12:55:53.850760 2026] [security2:error] [pid 67073:tid 67286] [client 20.116.17.175:57424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/v2.php"] [unique_id "aoSAifcmepr5_nHgLbNMEAAAAmU"]
[Tue Aug 18 12:55:53.862514 2026] [security2:error] [pid 67073:tid 67306] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kt.php"] [unique_id "aoSAifcmepr5_nHgLbNMEQAAAnk"]
[Tue Aug 18 12:55:53.915458 2026] [security2:error] [pid 67073:tid 67157] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/hj.php"] [unique_id "aoSAifcmepr5_nHgLbNMFAACclE"]
[Tue Aug 18 12:55:53.919108 2026] [security2:error] [pid 67073:tid 67170] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAifcmepr5_nHgLbNMFQACXF4"]
[Tue Aug 18 12:55:53.933703 2026] [security2:error] [pid 67073:tid 67244] [client 20.104.85.180:18840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/cah.php"] [unique_id "aoSAifcmepr5_nHgLbNMFgAAAjs"]
[Tue Aug 18 12:55:53.940420 2026] [security2:error] [pid 67073:tid 67323] [client 20.151.109.219:59751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gg.php"] [unique_id "aoSAifcmepr5_nHgLbNMFwAAAoo"]
[Tue Aug 18 12:55:53.946688 2026] [security2:error] [pid 67073:tid 67262] [client 172.182.200.96:14101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSAifcmepr5_nHgLbNMGAAAAk0"]
[Tue Aug 18 12:55:53.960987 2026] [security2:error] [pid 67073:tid 67256] [client 20.215.241.237:27976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/ops.php"] [unique_id "aoSAifcmepr5_nHgLbNMGgAAAkc"]
[Tue Aug 18 12:55:53.983903 2026] [security2:error] [pid 67073:tid 67326] [client 52.173.121.69:24997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSAifcmepr5_nHgLbNMHQAAAo0"]
[Tue Aug 18 12:55:53.989480 2026] [security2:error] [pid 67073:tid 67222] [client 172.202.39.151:12704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/cgi-bin/index.php"] [unique_id "aoSAifcmepr5_nHgLbNMHgAAAiU"]
[Tue Aug 18 12:55:54.001520 2026] [security2:error] [pid 67073:tid 67300] [client 20.226.56.190:28281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ka.php"] [unique_id "aoSAivcmepr5_nHgLbNMHwAAAnM"]
[Tue Aug 18 12:55:54.007276 2026] [security2:error] [pid 67073:tid 67318] [client 20.91.215.254:20700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/input.php"] [unique_id "aoSAivcmepr5_nHgLbNMIAAAAoU"]
[Tue Aug 18 12:55:54.086396 2026] [authz_core:error] [pid 67073:tid 67180] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:54.086670 2026] [authz_core:error] [pid 67073:tid 67180] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:54.090114 2026] [security2:error] [pid 67073:tid 67281] [client 4.223.164.152:54211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/inx.php"] [unique_id "aoSAivcmepr5_nHgLbNMIwAAAmA"]
[Tue Aug 18 12:55:54.121500 2026] [security2:error] [pid 67073:tid 67210] [client 20.171.51.14:43351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/mz.php"] [unique_id "aoSAivcmepr5_nHgLbNMJAAAAhk"]
[Tue Aug 18 12:55:54.125133 2026] [security2:error] [pid 66623:tid 66868] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ww.php"] [unique_id "aoSAitO5rbWdOArH04KGsgAAAXA"]
[Tue Aug 18 12:55:54.131247 2026] [security2:error] [pid 67073:tid 67324] [client 158.158.74.177:2944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/inputs.php"] [unique_id "aoSAivcmepr5_nHgLbNMJgAAAos"]
[Tue Aug 18 12:55:54.132257 2026] [security2:error] [pid 67073:tid 67297] [client 20.226.56.190:47153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ot.php"] [unique_id "aoSAivcmepr5_nHgLbNMJwAAAnA"]
[Tue Aug 18 12:55:54.134974 2026] [security2:error] [pid 67073:tid 67303] [client 20.163.43.14:4277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAivcmepr5_nHgLbNMKAAAAnY"]
[Tue Aug 18 12:55:54.156369 2026] [security2:error] [pid 67073:tid 67295] [client 135.225.78.186:13270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/media.php"] [unique_id "aoSAivcmepr5_nHgLbNMKgAAAm4"]
[Tue Aug 18 12:55:54.163613 2026] [security2:error] [pid 67073:tid 67121] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ij.php"] [unique_id "aoSAivcmepr5_nHgLbNMKwACMS0"]
[Tue Aug 18 12:55:54.194542 2026] [security2:error] [pid 67073:tid 67283] [client 20.65.69.59:3723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/email.php"] [unique_id "aoSAivcmepr5_nHgLbNMNQAAAmI"]
[Tue Aug 18 12:55:54.227320 2026] [security2:error] [pid 67073:tid 67332] [client 20.163.43.14:3030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAivcmepr5_nHgLbNMNwAAApM"]
[Tue Aug 18 12:55:54.229820 2026] [security2:error] [pid 67073:tid 67275] [client 138.36.100.162:42989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAivcmepr5_nHgLbNMOAAAAlo"]
[Tue Aug 18 12:55:54.229901 2026] [security2:error] [pid 67073:tid 67275] [client 138.36.100.162:42989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAivcmepr5_nHgLbNMOAAAAlo"]
[Tue Aug 18 12:55:54.252935 2026] [security2:error] [pid 67073:tid 67219] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/sid3.php"] [unique_id "aoSAivcmepr5_nHgLbNMOgAAAiI"]
[Tue Aug 18 12:55:54.342166 2026] [security2:error] [pid 67073:tid 67249] [client 158.23.17.4:63991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSAivcmepr5_nHgLbNMQQAAAkA"]
[Tue Aug 18 12:55:54.367301 2026] [security2:error] [pid 67073:tid 67304] [client 20.116.17.175:11256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wkl.php"] [unique_id "aoSAivcmepr5_nHgLbNMQgAAAnc"]
[Tue Aug 18 12:55:54.379469 2026] [security2:error] [pid 67073:tid 67108] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ud.php"] [unique_id "aoSAivcmepr5_nHgLbNMRAACMiA"]
[Tue Aug 18 12:55:54.382573 2026] [security2:error] [pid 67073:tid 67292] [client 20.151.109.219:21664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gi.php"] [unique_id "aoSAivcmepr5_nHgLbNMRQAAAms"]
[Tue Aug 18 12:55:54.388901 2026] [security2:error] [pid 67073:tid 67329] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/mo.php"] [unique_id "aoSAivcmepr5_nHgLbNMRgAAApA"]
[Tue Aug 18 12:55:54.390415 2026] [authz_core:error] [pid 67073:tid 67166] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:54.390833 2026] [authz_core:error] [pid 67073:tid 67166] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:54.454548 2026] [security2:error] [pid 67073:tid 67322] [client 20.251.48.93:56939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/nox.php"] [unique_id "aoSAivcmepr5_nHgLbNMSgAAAok"]
[Tue Aug 18 12:55:54.463148 2026] [security2:error] [pid 67073:tid 67261] [client 20.226.6.191:64074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wicked.php"] [unique_id "aoSAivcmepr5_nHgLbNMSwAAAkw"]
[Tue Aug 18 12:55:54.480951 2026] [security2:error] [pid 66623:tid 66845] [client 4.232.151.198:40226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/elp.php"] [unique_id "aoSAitO5rbWdOArH04KGtQAAAVk"]
[Tue Aug 18 12:55:54.533291 2026] [security2:error] [pid 67073:tid 67302] [client 5.31.227.224:7854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAivcmepr5_nHgLbNMUgAAAnU"]
[Tue Aug 18 12:55:54.536240 2026] [security2:error] [pid 67073:tid 67293] [client 213.35.127.232:49776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAivcmepr5_nHgLbNMUwAAAmw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:54.542974 2026] [security2:error] [pid 67073:tid 67302] [client 5.31.227.224:7854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAivcmepr5_nHgLbNMUgAAAnU"]
[Tue Aug 18 12:55:54.543685 2026] [security2:error] [pid 66623:tid 66794] [client 4.223.164.152:28528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/reviall.php"] [unique_id "aoSAitO5rbWdOArH04KGtgAAASY"]
[Tue Aug 18 12:55:54.553188 2026] [security2:error] [pid 67073:tid 67225] [client 213.202.253.4:49796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAivcmepr5_nHgLbNMVAAAAig"], referer: www.google.com
[Tue Aug 18 12:55:54.565056 2026] [security2:error] [pid 66623:tid 66829] [client 20.163.43.14:4244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp.php"] [unique_id "aoSAitO5rbWdOArH04KGtwAAAUk"]
[Tue Aug 18 12:55:54.574067 2026] [security2:error] [pid 67073:tid 67205] [client 135.225.78.186:12996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/admin.php"] [unique_id "aoSAivcmepr5_nHgLbNMVwAAAhQ"]
[Tue Aug 18 12:55:54.592871 2026] [security2:error] [pid 67073:tid 67144] [remote 192.250.229.214:52498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.229.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gustavofrison.com.br"] [uri "/wp-login.php"] [unique_id "aoSAivcmepr5_nHgLbNMWQACXUQ"]
[Tue Aug 18 12:55:54.615123 2026] [security2:error] [pid 67073:tid 67236] [client 74.248.130.103:14415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-blog.php"] [unique_id "aoSAivcmepr5_nHgLbNMWwAAAjM"]
[Tue Aug 18 12:55:54.646810 2026] [security2:error] [pid 67073:tid 67316] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/qr.php"] [unique_id "aoSAivcmepr5_nHgLbNMXAAAAoM"]
[Tue Aug 18 12:55:54.653119 2026] [security2:error] [pid 66623:tid 66776] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/simple.php"] [unique_id "aoSAitO5rbWdOArH04KGuAAAARQ"]
[Tue Aug 18 12:55:54.663032 2026] [security2:error] [pid 67073:tid 67231] [client 135.225.75.187:24689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/loxi-o.php"] [unique_id "aoSAivcmepr5_nHgLbNMXgAAAi4"]
[Tue Aug 18 12:55:54.667439 2026] [security2:error] [pid 67073:tid 67267] [client 20.163.43.14:4378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAivcmepr5_nHgLbNMXwAAAlI"]
[Tue Aug 18 12:55:54.707899 2026] [security2:error] [pid 67073:tid 67107] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ip.php"] [unique_id "aoSAivcmepr5_nHgLbNMYQACZR8"]
[Tue Aug 18 12:55:54.712324 2026] [security2:error] [pid 67073:tid 67317] [client 20.151.109.219:61385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/pz.php"] [unique_id "aoSAivcmepr5_nHgLbNMYgAAAoQ"]
[Tue Aug 18 12:55:54.735789 2026] [security2:error] [pid 66623:tid 66816] [client 20.250.13.23:25692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/aaa.php"] [unique_id "aoSAitO5rbWdOArH04KGuwAAATw"]
[Tue Aug 18 12:55:54.762680 2026] [security2:error] [pid 67073:tid 67327] [client 20.91.215.254:20692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/jquery.php"] [unique_id "aoSAivcmepr5_nHgLbNMZAAAAo4"]
[Tue Aug 18 12:55:54.784468 2026] [security2:error] [pid 66623:tid 66802] [client 20.226.6.191:55768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSAitO5rbWdOArH04KGvAAAAS4"]
[Tue Aug 18 12:55:54.794619 2026] [security2:error] [pid 66623:tid 66893] [client 20.65.69.59:57074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/profile.php"] [unique_id "aoSAitO5rbWdOArH04KGvQAAAYk"]
[Tue Aug 18 12:55:54.810324 2026] [security2:error] [pid 67073:tid 67299] [client 20.171.51.14:58380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ft.php"] [unique_id "aoSAivcmepr5_nHgLbNMZgAAAnI"]
[Tue Aug 18 12:55:54.894142 2026] [security2:error] [pid 67073:tid 67326] [client 20.163.43.14:4171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/function/function.php"] [unique_id "aoSAivcmepr5_nHgLbNMagAAAo0"]
[Tue Aug 18 12:55:54.894361 2026] [security2:error] [pid 67073:tid 67243] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/dirs.php"] [unique_id "aoSAivcmepr5_nHgLbNMawAAAjo"]
[Tue Aug 18 12:55:54.924684 2026] [security2:error] [pid 66623:tid 66885] [client 158.23.17.4:33524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/pqr.php"] [unique_id "aoSAitO5rbWdOArH04KGvwAAAYE"]
[Tue Aug 18 12:55:54.988752 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:54.989058 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:54.991010 2026] [security2:error] [pid 67073:tid 67300] [client 135.225.78.186:13006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/mac.php"] [unique_id "aoSAivcmepr5_nHgLbNMbgAAAnM"]
[Tue Aug 18 12:55:54.992808 2026] [security2:error] [pid 67073:tid 67114] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/99.php"] [unique_id "aoSAivcmepr5_nHgLbNMbwACYSY"]
[Tue Aug 18 12:55:55.006941 2026] [security2:error] [pid 67073:tid 67239] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAi_cmepr5_nHgLbNMcQAAAjY"]
[Tue Aug 18 12:55:55.025860 2026] [security2:error] [pid 67073:tid 67268] [client 4.223.164.152:46186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/11.php"] [unique_id "aoSAi_cmepr5_nHgLbNMcgAAAlM"]
[Tue Aug 18 12:55:55.026393 2026] [security2:error] [pid 67073:tid 67226] [client 20.151.109.219:21674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kk.php"] [unique_id "aoSAi_cmepr5_nHgLbNMcwAAAik"]
[Tue Aug 18 12:55:55.036755 2026] [security2:error] [pid 66623:tid 66848] [client 20.42.19.40:2926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/edit.php"] [unique_id "aoSAi9O5rbWdOArH04KGwQAAAVw"]
[Tue Aug 18 12:55:55.108193 2026] [security2:error] [pid 66623:tid 66768] [client 68.155.154.236:16345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSAi9O5rbWdOArH04KGwgAAAQw"]
[Tue Aug 18 12:55:55.111073 2026] [security2:error] [pid 67073:tid 67296] [client 158.158.74.177:2677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/install.php"] [unique_id "aoSAi_cmepr5_nHgLbNMdQAAAm8"]
[Tue Aug 18 12:55:55.116374 2026] [security2:error] [pid 66623:tid 66830] [client 172.202.39.151:11167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/cache.php"] [unique_id "aoSAi9O5rbWdOArH04KGwwAAAUo"]
[Tue Aug 18 12:55:55.136490 2026] [security2:error] [pid 66623:tid 66853] [client 20.226.6.191:32311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAi9O5rbWdOArH04KGxAAAAWE"]
[Tue Aug 18 12:55:55.142111 2026] [security2:error] [pid 66623:tid 66777] [client 20.226.56.190:45034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ih.php"] [unique_id "aoSAi9O5rbWdOArH04KGxgAAARU"]
[Tue Aug 18 12:55:55.142946 2026] [security2:error] [pid 67073:tid 67257] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/sn.php"] [unique_id "aoSAi_cmepr5_nHgLbNMdgAAAkg"]
[Tue Aug 18 12:55:55.143098 2026] [security2:error] [pid 67073:tid 67324] [client 20.163.43.14:4409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/rip.php"] [unique_id "aoSAi_cmepr5_nHgLbNMdwAAAos"]
[Tue Aug 18 12:55:55.168914 2026] [security2:error] [pid 67073:tid 67303] [client 20.116.17.175:11200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-asudo.php"] [unique_id "aoSAi_cmepr5_nHgLbNMeQAAAnY"]
[Tue Aug 18 12:55:55.199686 2026] [security2:error] [pid 66623:tid 66860] [client 20.29.77.16:56379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/filesystems.php"] [unique_id "aoSAi9O5rbWdOArH04KGxwAAAWg"]
[Tue Aug 18 12:55:55.230435 2026] [security2:error] [pid 66623:tid 66791] [client 158.158.34.183:22552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/u.php"] [unique_id "aoSAi9O5rbWdOArH04KGyAAAASM"]
[Tue Aug 18 12:55:55.233517 2026] [security2:error] [pid 67073:tid 67252] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAi_cmepr5_nHgLbNMewAAAkM"]
[Tue Aug 18 12:55:55.247797 2026] [security2:error] [pid 66623:tid 66793] [client 20.65.98.162:18123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/m.php"] [unique_id "aoSAi9O5rbWdOArH04KGyQAAASU"]
[Tue Aug 18 12:55:55.250784 2026] [security2:error] [pid 67073:tid 67332] [client 20.163.43.14:4097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSAi_cmepr5_nHgLbNMfgAAApM"]
[Tue Aug 18 12:55:55.270638 2026] [security2:error] [pid 67073:tid 67165] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/er.php"] [unique_id "aoSAi_cmepr5_nHgLbNMfwACV1k"]
[Tue Aug 18 12:55:55.289178 2026] [authz_core:error] [pid 67073:tid 67135] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:55.289493 2026] [authz_core:error] [pid 67073:tid 67135] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:55.297717 2026] [security2:error] [pid 67073:tid 67247] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/weozh.php"] [unique_id "aoSAi_cmepr5_nHgLbNMgQAAAj4"]
[Tue Aug 18 12:55:55.317577 2026] [security2:error] [pid 67073:tid 67274] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/rymmm.php"] [unique_id "aoSAi_cmepr5_nHgLbNMggAAAlk"]
[Tue Aug 18 12:55:55.325199 2026] [security2:error] [pid 67073:tid 67258] [client 20.151.109.219:53207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/phpcheck.php"] [unique_id "aoSAi_cmepr5_nHgLbNMgwAAAkk"]
[Tue Aug 18 12:55:55.358943 2026] [security2:error] [pid 67073:tid 67285] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/sitemap.php"] [unique_id "aoSAi_cmepr5_nHgLbNMhQAAAmQ"]
[Tue Aug 18 12:55:55.391796 2026] [security2:error] [pid 66623:tid 66789] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/43.php"] [unique_id "aoSAi9O5rbWdOArH04KGygAAASE"]
[Tue Aug 18 12:55:55.393360 2026] [security2:error] [pid 66623:tid 66813] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/lddxs.php"] [unique_id "aoSAi9O5rbWdOArH04KGywAAATk"]
[Tue Aug 18 12:55:55.407528 2026] [security2:error] [pid 66623:tid 66834] [client 135.225.78.186:13256] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/1.php"] [unique_id "aoSAi9O5rbWdOArH04KGzAAAAU4"]
[Tue Aug 18 12:55:55.407629 2026] [security2:error] [pid 66623:tid 66834] [client 135.225.78.186:13256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/1.php"] [unique_id "aoSAi9O5rbWdOArH04KGzAAAAU4"]
[Tue Aug 18 12:55:55.412702 2026] [security2:error] [pid 67073:tid 67249] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/zjggu.php"] [unique_id "aoSAi_cmepr5_nHgLbNMhgAAAkA"]
[Tue Aug 18 12:55:55.415085 2026] [security2:error] [pid 67073:tid 67223] [client 20.171.51.14:45431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/h.php"] [unique_id "aoSAi_cmepr5_nHgLbNMhwAAAiY"]
[Tue Aug 18 12:55:55.435444 2026] [security2:error] [pid 67073:tid 67315] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/dlvqo.php"] [unique_id "aoSAi_cmepr5_nHgLbNMiwAAAoI"]
[Tue Aug 18 12:55:55.438788 2026] [security2:error] [pid 67073:tid 67312] [client 5.253.205.188:50610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/lib.model.schema.bak"] [unique_id "aoSAi_cmepr5_nHgLbNMjAAAAn8"], referer: https://medihub.com.br/lib.model.schema.bak
[Tue Aug 18 12:55:55.449772 2026] [security2:error] [pid 67073:tid 67292] [client 4.223.164.152:28489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/File.php"] [unique_id "aoSAi_cmepr5_nHgLbNMjQAAAms"]
[Tue Aug 18 12:55:55.457920 2026] [security2:error] [pid 66623:tid 66799] [client 74.248.18.37:29256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/w.php"] [unique_id "aoSAi9O5rbWdOArH04KGzQAAASs"]
[Tue Aug 18 12:55:55.468827 2026] [security2:error] [pid 66623:tid 66783] [client 4.232.151.198:39161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAi9O5rbWdOArH04KGzgAAARs"]
[Tue Aug 18 12:55:55.479977 2026] [security2:error] [pid 67073:tid 67329] [client 20.226.56.190:28269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/k.php"] [unique_id "aoSAi_cmepr5_nHgLbNMjgAAApA"]
[Tue Aug 18 12:55:55.512092 2026] [security2:error] [pid 67073:tid 67164] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/qk.php"] [unique_id "aoSAi_cmepr5_nHgLbNMkQACPFg"]
[Tue Aug 18 12:55:55.580505 2026] [security2:error] [pid 66623:tid 66832] [client 213.35.127.232:50023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAi9O5rbWdOArH04KG0AAAAUw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:55.595541 2026] [authz_core:error] [pid 67073:tid 67089] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:55.595806 2026] [authz_core:error] [pid 67073:tid 67089] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:55.597023 2026] [security2:error] [pid 67073:tid 67259] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/pkmoj.php"] [unique_id "aoSAi_cmepr5_nHgLbNMkwAAAko"]
[Tue Aug 18 12:55:55.603031 2026] [security2:error] [pid 66623:tid 66881] [client 20.65.98.162:50119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/xyn.php"] [unique_id "aoSAi9O5rbWdOArH04KG0QAAAX0"]
[Tue Aug 18 12:55:55.627059 2026] [security2:error] [pid 66623:tid 66779] [client 20.151.109.219:61378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/dg.php"] [unique_id "aoSAi9O5rbWdOArH04KG0gAAARc"]
[Tue Aug 18 12:55:55.631831 2026] [security2:error] [pid 67073:tid 67323] [client 157.20.138.62:59224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAi_cmepr5_nHgLbNMlQAAAoo"]
[Tue Aug 18 12:55:55.631956 2026] [security2:error] [pid 67073:tid 67323] [client 157.20.138.62:59224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAi_cmepr5_nHgLbNMlQAAAoo"]
[Tue Aug 18 12:55:55.649115 2026] [security2:error] [pid 66623:tid 66888] [client 20.163.43.14:4233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSAi9O5rbWdOArH04KG1AAAAYQ"]
[Tue Aug 18 12:55:55.649600 2026] [security2:error] [pid 67073:tid 67232] [client 74.248.130.103:14439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/adminfuns.php"] [unique_id "aoSAi_cmepr5_nHgLbNMlgAAAi8"]
[Tue Aug 18 12:55:55.653408 2026] [security2:error] [pid 66623:tid 66890] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/fresh.php"] [unique_id "aoSAi9O5rbWdOArH04KG1QAAAYY"]
[Tue Aug 18 12:55:55.659487 2026] [security2:error] [pid 67073:tid 67255] [client 20.91.215.254:20718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/media-new.php"] [unique_id "aoSAi_cmepr5_nHgLbNMlwAAAkY"]
[Tue Aug 18 12:55:55.659959 2026] [security2:error] [pid 66623:tid 66803] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/kopyw.php"] [unique_id "aoSAi9O5rbWdOArH04KG1gAAAS8"]
[Tue Aug 18 12:55:55.663486 2026] [security2:error] [pid 67073:tid 67251] [client 20.163.43.14:4380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAi_cmepr5_nHgLbNMmAAAAkI"]
[Tue Aug 18 12:55:55.726544 2026] [security2:error] [pid 67073:tid 67293] [client 20.226.6.191:38211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/cah.php"] [unique_id "aoSAi_cmepr5_nHgLbNMmgAAAmw"]
[Tue Aug 18 12:55:55.736086 2026] [security2:error] [pid 67073:tid 67302] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/zznmg.php"] [unique_id "aoSAi_cmepr5_nHgLbNMmwAAAnU"]
[Tue Aug 18 12:55:55.752254 2026] [security2:error] [pid 67073:tid 67134] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSAi_cmepr5_nHgLbNMnQACFDo"]
[Tue Aug 18 12:55:55.777456 2026] [security2:error] [pid 66623:tid 66869] [client 20.116.17.175:57420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/az.php"] [unique_id "aoSAi9O5rbWdOArH04KG2wAAAXE"]
[Tue Aug 18 12:55:55.783280 2026] [security2:error] [pid 67073:tid 67305] [client 20.42.19.40:2915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/ff1.php"] [unique_id "aoSAi_cmepr5_nHgLbNMngAAAng"]
[Tue Aug 18 12:55:55.790118 2026] [security2:error] [pid 66623:tid 66821] [client 135.225.75.187:58360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/sdsa.php"] [unique_id "aoSAi9O5rbWdOArH04KG3AAAAUE"]
[Tue Aug 18 12:55:55.792644 2026] [security2:error] [pid 66623:tid 66843] [client 20.65.69.59:39211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/summary.php"] [unique_id "aoSAi9O5rbWdOArH04KG3QAAAVc"]
[Tue Aug 18 12:55:55.829932 2026] [security2:error] [pid 67073:tid 67271] [client 135.225.78.186:13016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/coffee.php"] [unique_id "aoSAi_cmepr5_nHgLbNMoAAAAlY"]
[Tue Aug 18 12:55:55.832144 2026] [security2:error] [pid 67073:tid 67330] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/bhfnd.php"] [unique_id "aoSAi_cmepr5_nHgLbNMoQAAApE"]
[Tue Aug 18 12:55:55.874966 2026] [security2:error] [pid 66623:tid 66882] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAi9O5rbWdOArH04KG1wABfnY"]
[Tue Aug 18 12:55:55.892239 2026] [security2:error] [pid 67073:tid 67250] [client 20.226.56.190:2530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/iu.php"] [unique_id "aoSAi_cmepr5_nHgLbNMpAAAAkE"]
[Tue Aug 18 12:55:55.903376 2026] [security2:error] [pid 67073:tid 67264] [client 4.223.164.152:64655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/fi22.php"] [unique_id "aoSAi_cmepr5_nHgLbNMpQAAAk8"]
[Tue Aug 18 12:55:55.907820 2026] [security2:error] [pid 67073:tid 67217] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gj.php"] [unique_id "aoSAi_cmepr5_nHgLbNMpgAAAiA"]
[Tue Aug 18 12:55:55.914060 2026] [security2:error] [pid 67073:tid 67211] [client 4.232.151.198:22555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/as.php"] [unique_id "aoSAi_cmepr5_nHgLbNMpwAAAho"]
[Tue Aug 18 12:55:55.932749 2026] [security2:error] [pid 66623:tid 66810] [client 158.158.74.177:2683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAi9O5rbWdOArH04KG4AAAATY"]
[Tue Aug 18 12:55:55.940431 2026] [security2:error] [pid 67073:tid 67327] [client 20.151.109.219:17586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/bm.php"] [unique_id "aoSAi_cmepr5_nHgLbNMqAAAAo4"]
[Tue Aug 18 12:55:55.941412 2026] [security2:error] [pid 67073:tid 67242] [client 158.23.17.4:9284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/lmfi2.php"] [unique_id "aoSAi_cmepr5_nHgLbNMqQAAAjk"]
[Tue Aug 18 12:55:55.964543 2026] [security2:error] [pid 67073:tid 67240] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/qfvqu.php"] [unique_id "aoSAi_cmepr5_nHgLbNMqgAAAjc"]
[Tue Aug 18 12:55:55.985560 2026] [security2:error] [pid 66623:tid 66889] [client 20.163.43.14:4236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/ok.php"] [unique_id "aoSAi9O5rbWdOArH04KG4QAAAYU"]
[Tue Aug 18 12:55:55.994705 2026] [security2:error] [pid 67073:tid 67319] [client 68.155.154.236:16330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/nwwha.php"] [unique_id "aoSAi_cmepr5_nHgLbNMrAAAAoY"]
[Tue Aug 18 12:55:55.995142 2026] [security2:error] [pid 67073:tid 67136] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/fs.php"] [unique_id "aoSAi_cmepr5_nHgLbNMrQACPzw"]
[Tue Aug 18 12:55:56.012957 2026] [security2:error] [pid 66623:tid 66880] [client 20.163.43.14:3028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/moon.php"] [unique_id "aoSAjNO5rbWdOArH04KG4wAAAXw"]
[Tue Aug 18 12:55:56.013335 2026] [security2:error] [pid 66623:tid 66828] [client 20.251.48.93:57259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/akismet.php"] [unique_id "aoSAjNO5rbWdOArH04KG5AAAAUg"]
[Tue Aug 18 12:55:56.030559 2026] [autoindex:error] [pid 66623:tid 66857] [client 20.226.6.191:64121] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/js/tinymce/plugins/compat3x/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:56.036107 2026] [security2:error] [pid 66623:tid 66879] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/size.php"] [unique_id "aoSAjNO5rbWdOArH04KG5gAAAXs"]
[Tue Aug 18 12:55:56.040612 2026] [security2:error] [pid 66623:tid 66838] [client 20.226.6.191:64121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/system_log.php"] [unique_id "aoSAjNO5rbWdOArH04KG5wAAAVI"]
[Tue Aug 18 12:55:56.110461 2026] [security2:error] [pid 67073:tid 67326] [client 20.171.51.14:58412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/40.php"] [unique_id "aoSAjPcmepr5_nHgLbNMsAAAAo0"]
[Tue Aug 18 12:55:56.118037 2026] [security2:error] [pid 66623:tid 66833] [client 74.7.175.153:35792] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.contabilidadecapimgrosso.com.br.foxalpha.com.br"] [uri "/robots.txt"] [unique_id "aoSAjNO5rbWdOArH04KG6AABTXc"]
[Tue Aug 18 12:55:56.128164 2026] [security2:error] [pid 66623:tid 66856] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/oivcl.php"] [unique_id "aoSAjNO5rbWdOArH04KG6QAAAWQ"]
[Tue Aug 18 12:55:56.163278 2026] [security2:error] [pid 67073:tid 67238] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/pd.php"] [unique_id "aoSAjPcmepr5_nHgLbNMsgAAAjU"]
[Tue Aug 18 12:55:56.167577 2026] [security2:error] [pid 67073:tid 67301] [client 149.34.210.141:51128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAjPcmepr5_nHgLbNMswAAAnQ"]
[Tue Aug 18 12:55:56.201257 2026] [security2:error] [pid 67073:tid 67282] [client 20.29.77.16:57079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/showphpinfo.php"] [unique_id "aoSAjPcmepr5_nHgLbNMtgAAAmE"]
[Tue Aug 18 12:55:56.210476 2026] [security2:error] [pid 67073:tid 67230] [client 172.202.39.151:28983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/an.php"] [unique_id "aoSAjPcmepr5_nHgLbNMuQAAAi0"]
[Tue Aug 18 12:55:56.224403 2026] [autoindex:error] [pid 67073:tid 67263] [client 172.202.39.151:50218] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:56.234290 2026] [security2:error] [pid 67073:tid 67221] [client 20.42.19.40:2894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/fff.php"] [unique_id "aoSAjPcmepr5_nHgLbNMuwAAAiQ"]
[Tue Aug 18 12:55:56.245801 2026] [security2:error] [pid 67073:tid 67268] [client 52.173.121.69:16483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/rezor.php"] [unique_id "aoSAjPcmepr5_nHgLbNMvQAAAlM"]
[Tue Aug 18 12:55:56.246542 2026] [security2:error] [pid 67073:tid 67226] [client 135.225.78.186:13282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/classwithtostring.php"] [unique_id "aoSAjPcmepr5_nHgLbNMvgAAAik"]
[Tue Aug 18 12:55:56.249138 2026] [security2:error] [pid 67073:tid 67260] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/zugvi.php"] [unique_id "aoSAjPcmepr5_nHgLbNMvwAAAks"]
[Tue Aug 18 12:55:56.301887 2026] [security2:error] [pid 67073:tid 67088] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/rb.php"] [unique_id "aoSAjPcmepr5_nHgLbNMwAACbww"]
[Tue Aug 18 12:55:56.312469 2026] [security2:error] [pid 67073:tid 67328] [client 74.248.130.103:38682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/ms-edit.php"] [unique_id "aoSAjPcmepr5_nHgLbNMwgAAAo8"]
[Tue Aug 18 12:55:56.323546 2026] [security2:error] [pid 66623:tid 66871] [client 20.151.109.219:12880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/vu.php"] [unique_id "aoSAjNO5rbWdOArH04KG6wAAAXM"]
[Tue Aug 18 12:55:56.325916 2026] [security2:error] [pid 66623:tid 66868] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wsrer.php"] [unique_id "aoSAjNO5rbWdOArH04KG7AAAAXA"]
[Tue Aug 18 12:55:56.328906 2026] [security2:error] [pid 67073:tid 67257] [client 20.226.56.190:45002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/pk.php"] [unique_id "aoSAjPcmepr5_nHgLbNMxAAAAkg"]
[Tue Aug 18 12:55:56.341442 2026] [security2:error] [pid 67073:tid 67270] [client 4.232.151.198:19934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/666.php"] [unique_id "aoSAjPcmepr5_nHgLbNMxgAAAlU"]
[Tue Aug 18 12:55:56.355105 2026] [security2:error] [pid 67073:tid 67295] [client 4.223.164.152:37283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAjPcmepr5_nHgLbNMxwAAAm4"]
[Tue Aug 18 12:55:56.372056 2026] [security2:error] [pid 66623:tid 66836] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/sm.php"] [unique_id "aoSAjNO5rbWdOArH04KG7QAAAVA"]
[Tue Aug 18 12:55:56.396614 2026] [security2:error] [pid 66623:tid 66788] [client 20.163.43.14:4459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/cache.php"] [unique_id "aoSAjNO5rbWdOArH04KG7gAAASA"]
[Tue Aug 18 12:55:56.411838 2026] [security2:error] [pid 66623:tid 66884] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/th.php"] [unique_id "aoSAjNO5rbWdOArH04KG7wAAAYA"]
[Tue Aug 18 12:55:56.414218 2026] [security2:error] [pid 66623:tid 66766] [client 20.163.43.14:4241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/item.php"] [unique_id "aoSAjNO5rbWdOArH04KG8AAAAQo"]
[Tue Aug 18 12:55:56.417914 2026] [security2:error] [pid 66623:tid 66845] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/ucpfr.php"] [unique_id "aoSAjNO5rbWdOArH04KG8QAAAVk"]
[Tue Aug 18 12:55:56.435100 2026] [security2:error] [pid 67073:tid 67301] [client 149.34.210.141:51128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAjPcmepr5_nHgLbNMswAAAnQ"]
[Tue Aug 18 12:55:56.442855 2026] [security2:error] [pid 67073:tid 67239] [client 20.91.215.254:11264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSAjPcmepr5_nHgLbNMygAAAjY"]
[Tue Aug 18 12:55:56.458260 2026] [security2:error] [pid 67073:tid 67275] [client 158.23.17.4:9321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/info2.php"] [unique_id "aoSAjPcmepr5_nHgLbNMywAAAlo"]
[Tue Aug 18 12:55:56.467574 2026] [autoindex:error] [pid 66623:tid 66863] [client 20.226.6.191:59966] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:56.472641 2026] [security2:error] [pid 66623:tid 66847] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/yxijx.php"] [unique_id "aoSAjNO5rbWdOArH04KG9AAAAVs"]
[Tue Aug 18 12:55:56.492774 2026] [security2:error] [pid 67073:tid 67247] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/zwlsv.php"] [unique_id "aoSAjPcmepr5_nHgLbNMzgAAAj4"]
[Tue Aug 18 12:55:56.495189 2026] [authz_core:error] [pid 67073:tid 67105] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:56.495460 2026] [authz_core:error] [pid 67073:tid 67105] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:56.503007 2026] [security2:error] [pid 66623:tid 66802] [client 20.226.6.191:59966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAjNO5rbWdOArH04KG9QAAAS4"]
[Tue Aug 18 12:55:56.521345 2026] [security2:error] [pid 67073:tid 67289] [client 172.202.39.151:50218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAjPcmepr5_nHgLbNM0AAAAmg"]
[Tue Aug 18 12:55:56.551326 2026] [security2:error] [pid 66623:tid 66824] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/jrpga.php"] [unique_id "aoSAjNO5rbWdOArH04KG9wAAAUQ"]
[Tue Aug 18 12:55:56.552586 2026] [security2:error] [pid 66623:tid 66859] [client 20.42.19.40:2182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/inputs.php"] [unique_id "aoSAjNO5rbWdOArH04KG-AAAAWc"]
[Tue Aug 18 12:55:56.558894 2026] [security2:error] [pid 67073:tid 67126] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/37.php"] [unique_id "aoSAjPcmepr5_nHgLbNM0QACNDI"]
[Tue Aug 18 12:55:56.601194 2026] [security2:error] [pid 67073:tid 67266] [client 213.35.127.232:50265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAjPcmepr5_nHgLbNM0gAAAlE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:56.601710 2026] [security2:error] [pid 66623:tid 66830] [client 20.151.109.219:59766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ic.php"] [unique_id "aoSAjNO5rbWdOArH04KG-QAAAUo"]
[Tue Aug 18 12:55:56.641855 2026] [security2:error] [pid 67073:tid 67249] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSAjPcmepr5_nHgLbNM1AAAAkA"]
[Tue Aug 18 12:55:56.662692 2026] [security2:error] [pid 66623:tid 66794] [client 158.158.74.177:22746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/item.php"] [unique_id "aoSAjNO5rbWdOArH04KG-wAAASY"]
[Tue Aug 18 12:55:56.664024 2026] [security2:error] [pid 67073:tid 67312] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/nwwha.php"] [unique_id "aoSAjPcmepr5_nHgLbNM1QAAAn8"]
[Tue Aug 18 12:55:56.664112 2026] [security2:error] [pid 66623:tid 66862] [client 135.225.78.186:13033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/wp-ws68.php"] [unique_id "aoSAjNO5rbWdOArH04KG_AAAAWo"]
[Tue Aug 18 12:55:56.666425 2026] [security2:error] [pid 66623:tid 66853] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/admin404.php"] [unique_id "aoSAjNO5rbWdOArH04KG_QAAAWE"]
[Tue Aug 18 12:55:56.684703 2026] [security2:error] [pid 67073:tid 67292] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/opsqt.php"] [unique_id "aoSAjPcmepr5_nHgLbNM1gAAAms"]
[Tue Aug 18 12:55:56.705254 2026] [security2:error] [pid 66623:tid 66846] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/jvcpa.php"] [unique_id "aoSAjNO5rbWdOArH04KG_wAAAVo"]
[Tue Aug 18 12:55:56.727438 2026] [security2:error] [pid 66623:tid 66795] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSAjNO5rbWdOArH04KHAQAAASc"]
[Tue Aug 18 12:55:56.776414 2026] [security2:error] [pid 67073:tid 67228] [client 68.155.154.236:16258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/opsqt.php"] [unique_id "aoSAjPcmepr5_nHgLbNM2wAAAis"]
[Tue Aug 18 12:55:56.776415 2026] [security2:error] [pid 66623:tid 66873] [client 20.250.13.23:24819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/abcd.php"] [unique_id "aoSAjNO5rbWdOArH04KHBAAAAXU"]
[Tue Aug 18 12:55:56.782942 2026] [security2:error] [pid 66623:tid 66817] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSAjNO5rbWdOArH04KHBQAAAT0"]
[Tue Aug 18 12:55:56.808226 2026] [security2:error] [pid 66623:tid 66789] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSAjNO5rbWdOArH04KHBgAAASE"]
[Tue Aug 18 12:55:56.817244 2026] [security2:error] [pid 67073:tid 67097] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/md.php"] [unique_id "aoSAjPcmepr5_nHgLbNM3gACShU"]
[Tue Aug 18 12:55:56.830604 2026] [security2:error] [pid 67073:tid 67222] [client 74.248.18.37:28098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/archive.php"] [unique_id "aoSAjPcmepr5_nHgLbNM3wAAAiU"]
[Tue Aug 18 12:55:56.833580 2026] [security2:error] [pid 66623:tid 66822] [client 4.223.164.152:54266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSAjNO5rbWdOArH04KHCAAAAUI"]
[Tue Aug 18 12:55:56.838455 2026] [security2:error] [pid 66623:tid 66799] [client 74.248.130.103:15404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/222.php"] [unique_id "aoSAjNO5rbWdOArH04KHCgAAASs"]
[Tue Aug 18 12:55:56.841730 2026] [security2:error] [pid 67073:tid 67308] [client 52.238.210.254:8977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAjPcmepr5_nHgLbNM4AAAAns"]
[Tue Aug 18 12:55:56.851657 2026] [security2:error] [pid 67073:tid 67323] [client 20.226.6.191:59965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAjPcmepr5_nHgLbNM4QAAAoo"]
[Tue Aug 18 12:55:56.853316 2026] [security2:error] [pid 66623:tid 66807] [client 4.232.151.198:37328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/min.php"] [unique_id "aoSAjNO5rbWdOArH04KHCwAAATM"]
[Tue Aug 18 12:55:56.864362 2026] [security2:error] [pid 66623:tid 66783] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSAjNO5rbWdOArH04KHDAAAARs"]
[Tue Aug 18 12:55:56.871493 2026] [security2:error] [pid 66623:tid 66861] [client 158.158.34.183:32238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/k.php"] [unique_id "aoSAjNO5rbWdOArH04KHDQAAAWk"]
[Tue Aug 18 12:55:56.910169 2026] [security2:error] [pid 67073:tid 67216] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSAjPcmepr5_nHgLbNM5QAAAh8"]
[Tue Aug 18 12:55:56.926959 2026] [security2:error] [pid 67073:tid 67251] [client 135.225.75.187:24657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-freya.php"] [unique_id "aoSAjPcmepr5_nHgLbNM5gAAAkI"]
[Tue Aug 18 12:55:56.931125 2026] [security2:error] [pid 67073:tid 67213] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSAjPcmepr5_nHgLbNM5wAAAhw"]
[Tue Aug 18 12:55:56.936631 2026] [security2:error] [pid 67073:tid 67302] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/qo.php"] [unique_id "aoSAjPcmepr5_nHgLbNM6AAAAnU"]
[Tue Aug 18 12:55:56.949690 2026] [security2:error] [pid 67073:tid 67246] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSAjPcmepr5_nHgLbNM6gAAAj0"]
[Tue Aug 18 12:55:56.969472 2026] [security2:error] [pid 66623:tid 66867] [client 20.226.6.191:38210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/abc.php"] [unique_id "aoSAjNO5rbWdOArH04KHDgAAAW8"]
[Tue Aug 18 12:55:57.012840 2026] [security2:error] [pid 66623:tid 66818] [client 20.251.48.93:56928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/admin.php"] [unique_id "aoSAjdO5rbWdOArH04KHEQAAAT4"]
[Tue Aug 18 12:55:57.022989 2026] [security2:error] [pid 66623:tid 66874] [client 20.151.109.219:17595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ue.php"] [unique_id "aoSAjdO5rbWdOArH04KHEgAAAXY"]
[Tue Aug 18 12:55:57.067611 2026] [security2:error] [pid 67073:tid 67138] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/iy.php"] [unique_id "aoSAjfcmepr5_nHgLbNM7gACkT4"]
[Tue Aug 18 12:55:57.082841 2026] [security2:error] [pid 66623:tid 66772] [client 20.100.169.31:42946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAjdO5rbWdOArH04KHFAAAARA"]
[Tue Aug 18 12:55:57.086074 2026] [security2:error] [pid 66623:tid 66784] [client 135.225.78.186:12998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/yj09.php"] [unique_id "aoSAjdO5rbWdOArH04KHFQAAARw"]
[Tue Aug 18 12:55:57.097553 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:57.097883 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:57.103964 2026] [security2:error] [pid 67073:tid 67253] [client 20.226.56.190:30984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ge.php"] [unique_id "aoSAjfcmepr5_nHgLbNM8gAAAkQ"]
[Tue Aug 18 12:55:57.123981 2026] [security2:error] [pid 67073:tid 67250] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/sql.php"] [unique_id "aoSAjfcmepr5_nHgLbNM9AAAAkE"]
[Tue Aug 18 12:55:57.181901 2026] [security2:error] [pid 66623:tid 66882] [client 20.226.6.191:6533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAjdO5rbWdOArH04KHFgAAAX4"]
[Tue Aug 18 12:55:57.201181 2026] [security2:error] [pid 66623:tid 66797] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/sd.php"] [unique_id "aoSAjdO5rbWdOArH04KHFwAAASk"]
[Tue Aug 18 12:55:57.248778 2026] [security2:error] [pid 67073:tid 67217] [client 20.116.17.175:57443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/z43agz.php"] [unique_id "aoSAjfcmepr5_nHgLbNM9wAAAiA"]
[Tue Aug 18 12:55:57.265116 2026] [security2:error] [pid 66623:tid 66877] [client 20.226.6.191:36384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/akcc.php"] [unique_id "aoSAjdO5rbWdOArH04KHGAAAAXk"]
[Tue Aug 18 12:55:57.282764 2026] [security2:error] [pid 67073:tid 67192] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/og.php"] [unique_id "aoSAjfcmepr5_nHgLbNM-QACjnQ"]
[Tue Aug 18 12:55:57.299809 2026] [security2:error] [pid 67073:tid 67242] [client 20.163.43.14:3025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAjfcmepr5_nHgLbNM-gAAAjk"]
[Tue Aug 18 12:55:57.319687 2026] [security2:error] [pid 67073:tid 67248] [client 20.151.109.219:21691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/lr.php"] [unique_id "aoSAjfcmepr5_nHgLbNM_QAAAj8"]
[Tue Aug 18 12:55:57.319732 2026] [security2:error] [pid 67073:tid 67287] [client 20.91.215.254:11998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSAjfcmepr5_nHgLbNM_AAAAmY"]
[Tue Aug 18 12:55:57.340388 2026] [security2:error] [pid 67073:tid 67244] [client 4.223.164.152:28535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAjfcmepr5_nHgLbNM_gAAAjs"]
[Tue Aug 18 12:55:57.354951 2026] [security2:error] [pid 66623:tid 66791] [client 178.153.171.161:43832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAjdO5rbWdOArH04KHGgAAASM"]
[Tue Aug 18 12:55:57.355076 2026] [security2:error] [pid 66623:tid 66791] [client 178.153.171.161:43832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAjdO5rbWdOArH04KHGgAAASM"]
[Tue Aug 18 12:55:57.425450 2026] [security2:error] [pid 67073:tid 67309] [client 172.182.200.96:7627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSAjfcmepr5_nHgLbNNAQAAAnw"]
[Tue Aug 18 12:55:57.445933 2026] [security2:error] [pid 67073:tid 67238] [client 20.215.241.237:24621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/coffexium.php"] [unique_id "aoSAjfcmepr5_nHgLbNNBwAAAjU"]
[Tue Aug 18 12:55:57.456589 2026] [security2:error] [pid 67073:tid 67318] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/km.php"] [unique_id "aoSAjfcmepr5_nHgLbNNCAAAAoU"]
[Tue Aug 18 12:55:57.462773 2026] [security2:error] [pid 66623:tid 66879] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSAjdO5rbWdOArH04KHHAAAAXs"]
[Tue Aug 18 12:55:57.476501 2026] [security2:error] [pid 67073:tid 67243] [client 18.192.166.72:57044] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.pinceisroma.com.br"] [uri "/server.php"] [unique_id "aoSAjfcmepr5_nHgLbNNAgAAAjo"], referer: http://www.pinceisroma.com.br
[Tue Aug 18 12:55:57.481131 2026] [security2:error] [pid 67073:tid 67268] [client 74.248.130.103:36808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/cgi-bin/index.php"] [unique_id "aoSAjfcmepr5_nHgLbNNCQAAAlM"]
[Tue Aug 18 12:55:57.484836 2026] [security2:error] [pid 67073:tid 67226] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSAjfcmepr5_nHgLbNNCgAAAik"]
[Tue Aug 18 12:55:57.503460 2026] [security2:error] [pid 66623:tid 66812] [client 135.225.78.186:13023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/scxy.php"] [unique_id "aoSAjdO5rbWdOArH04KHHQAAATg"]
[Tue Aug 18 12:55:57.505717 2026] [security2:error] [pid 66623:tid 66866] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSAjdO5rbWdOArH04KHHgAAAW4"]
[Tue Aug 18 12:55:57.525316 2026] [security2:error] [pid 67073:tid 67296] [client 20.226.56.190:31669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kl.php"] [unique_id "aoSAjfcmepr5_nHgLbNNDAAAAm8"]
[Tue Aug 18 12:55:57.537924 2026] [security2:error] [pid 67073:tid 67303] [client 52.173.121.69:16470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSAjfcmepr5_nHgLbNNDwAAAnY"]
[Tue Aug 18 12:55:57.549875 2026] [security2:error] [pid 67073:tid 67100] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/lp.php"] [unique_id "aoSAjfcmepr5_nHgLbNNEAACbhg"]
[Tue Aug 18 12:55:57.573601 2026] [security2:error] [pid 67073:tid 67283] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSAjfcmepr5_nHgLbNNEgAAAmI"]
[Tue Aug 18 12:55:57.576316 2026] [security2:error] [pid 66623:tid 66856] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/ss.php"] [unique_id "aoSAjdO5rbWdOArH04KHHwAAAWQ"]
[Tue Aug 18 12:55:57.591799 2026] [security2:error] [pid 66623:tid 66850] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSAjdO5rbWdOArH04KHIAAAAV4"]
[Tue Aug 18 12:55:57.611636 2026] [security2:error] [pid 66623:tid 66767] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSAjdO5rbWdOArH04KHIQAAAQs"]
[Tue Aug 18 12:55:57.617025 2026] [security2:error] [pid 67073:tid 67265] [client 213.35.127.232:50495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAjfcmepr5_nHgLbNNFAAAAlA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:57.644511 2026] [security2:error] [pid 67073:tid 67314] [client 20.151.109.219:64153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ka.php"] [unique_id "aoSAjfcmepr5_nHgLbNNFgAAAoE"]
[Tue Aug 18 12:55:57.656460 2026] [security2:error] [pid 67073:tid 67219] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSAjfcmepr5_nHgLbNNFwAAAiI"]
[Tue Aug 18 12:55:57.676597 2026] [security2:error] [pid 66623:tid 66787] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSAjdO5rbWdOArH04KHJQAAAR8"]
[Tue Aug 18 12:55:57.703833 2026] [authz_core:error] [pid 67073:tid 67171] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:57.704085 2026] [authz_core:error] [pid 67073:tid 67171] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:57.705348 2026] [security2:error] [pid 67073:tid 67274] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/mf.php"] [unique_id "aoSAjfcmepr5_nHgLbNNGQAAAlk"]
[Tue Aug 18 12:55:57.723976 2026] [security2:error] [pid 67073:tid 67262] [client 74.248.18.37:49011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/bless.php"] [unique_id "aoSAjfcmepr5_nHgLbNNGwAAAk0"]
[Tue Aug 18 12:55:57.742977 2026] [security2:error] [pid 67073:tid 67266] [client 158.23.17.4:10976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/test_info.php"] [unique_id "aoSAjfcmepr5_nHgLbNNHAAAAlE"]
[Tue Aug 18 12:55:57.767786 2026] [security2:error] [pid 66623:tid 66788] [client 68.155.154.236:16347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/jvcpa.php"] [unique_id "aoSAjdO5rbWdOArH04KHJgAAASA"]
[Tue Aug 18 12:55:57.773361 2026] [security2:error] [pid 66623:tid 66884] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSAjdO5rbWdOArH04KHJwAAAYA"]
[Tue Aug 18 12:55:57.778477 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.6.191:6538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSAjfcmepr5_nHgLbNNHwAAAlg"]
[Tue Aug 18 12:55:57.784318 2026] [security2:error] [pid 67073:tid 67149] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ey.php"] [unique_id "aoSAjfcmepr5_nHgLbNNIAACf0k"]
[Tue Aug 18 12:55:57.817746 2026] [security2:error] [pid 67073:tid 67292] [client 20.42.19.40:2907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/ioxi-o.php"] [unique_id "aoSAjfcmepr5_nHgLbNNIwAAAms"]
[Tue Aug 18 12:55:57.824007 2026] [autoindex:error] [pid 67073:tid 67328] [client 4.232.151.198:37341] AH01276: Cannot serve directory /home4/uniaoaccom/public_html/.well-known/: No matching DirectoryIndex (index.php) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:55:57.847966 2026] [security2:error] [pid 66623:tid 66780] [client 20.163.43.14:4362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAjdO5rbWdOArH04KHKAAAARg"]
[Tue Aug 18 12:55:57.869218 2026] [security2:error] [pid 67073:tid 67261] [client 20.171.51.14:65150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ee.php"] [unique_id "aoSAjfcmepr5_nHgLbNNJwAAAkw"]
[Tue Aug 18 12:55:57.885768 2026] [security2:error] [pid 67073:tid 67290] [client 20.226.6.191:59905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wk/index.php"] [unique_id "aoSAjfcmepr5_nHgLbNNKQAAAmk"]
[Tue Aug 18 12:55:57.891311 2026] [security2:error] [pid 67073:tid 67245] [client 4.223.164.152:46165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSAjfcmepr5_nHgLbNNKgAAAjw"]
[Tue Aug 18 12:55:57.891601 2026] [security2:error] [pid 67073:tid 67228] [client 18.192.166.72:57060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.pinceisroma.com.br"] [uri "/server.php"] [unique_id "aoSAjfcmepr5_nHgLbNNJgAAAis"], referer: http://www.pinceisroma.com.br
[Tue Aug 18 12:55:57.892158 2026] [security2:error] [pid 67073:tid 67212] [client 20.226.56.190:2520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gs.php"] [unique_id "aoSAjfcmepr5_nHgLbNNKwAAAhs"]
[Tue Aug 18 12:55:57.924461 2026] [security2:error] [pid 67073:tid 67323] [client 135.225.78.186:13009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSAjfcmepr5_nHgLbNNLgAAAoo"]
[Tue Aug 18 12:55:57.956512 2026] [security2:error] [pid 67073:tid 67213] [client 20.65.69.59:40574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/conf.php"] [unique_id "aoSAjfcmepr5_nHgLbNNMAAAAhw"]
[Tue Aug 18 12:55:57.968818 2026] [security2:error] [pid 67073:tid 67302] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ie.php"] [unique_id "aoSAjfcmepr5_nHgLbNNMQAAAnU"]
[Tue Aug 18 12:55:57.980447 2026] [security2:error] [pid 67073:tid 67305] [client 20.29.77.16:57056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/phpstatus.php"] [unique_id "aoSAjfcmepr5_nHgLbNNMwAAAng"]
[Tue Aug 18 12:55:57.986705 2026] [security2:error] [pid 67073:tid 67157] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/lv.php"] [unique_id "aoSAjfcmepr5_nHgLbNNNAACF1E"]
[Tue Aug 18 12:55:58.000824 2026] [security2:error] [pid 67073:tid 67271] [client 20.151.109.219:61377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ot.php"] [unique_id "aoSAjvcmepr5_nHgLbNNNwAAAlY"]
[Tue Aug 18 12:55:58.000984 2026] [authz_core:error] [pid 67073:tid 67115] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:58.001277 2026] [authz_core:error] [pid 67073:tid 67115] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:58.005704 2026] [security2:error] [pid 66623:tid 66845] [client 20.91.215.254:11996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-admin/import.php"] [unique_id "aoSAjtO5rbWdOArH04KHKwAAAVk"]
[Tue Aug 18 12:55:58.015251 2026] [security2:error] [pid 66623:tid 66811] [client 20.226.6.191:6616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAjtO5rbWdOArH04KHLAAAATc"]
[Tue Aug 18 12:55:58.032881 2026] [security2:error] [pid 67073:tid 67324] [client 20.250.13.23:24769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-good.php"] [unique_id "aoSAjvcmepr5_nHgLbNNOAAAAos"]
[Tue Aug 18 12:55:58.051097 2026] [security2:error] [pid 67073:tid 67231] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSAjvcmepr5_nHgLbNNOQAAAi4"]
[Tue Aug 18 12:55:58.070423 2026] [security2:error] [pid 67073:tid 67250] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSAjvcmepr5_nHgLbNNOgAAAkE"]
[Tue Aug 18 12:55:58.071186 2026] [security2:error] [pid 67073:tid 67317] [client 4.232.151.198:37341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/php8.php"] [unique_id "aoSAjvcmepr5_nHgLbNNOwAAAoQ"]
[Tue Aug 18 12:55:58.089986 2026] [security2:error] [pid 67073:tid 67286] [client 158.158.74.177:2674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/js.php"] [unique_id "aoSAjvcmepr5_nHgLbNNPwAAAmU"]
[Tue Aug 18 12:55:58.105821 2026] [security2:error] [pid 67073:tid 67310] [client 20.226.6.191:6564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp.php"] [unique_id "aoSAjvcmepr5_nHgLbNNQAAAAn0"]
[Tue Aug 18 12:55:58.114810 2026] [security2:error] [pid 66623:tid 66859] [client 20.42.19.40:2939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/lite.php"] [unique_id "aoSAjtO5rbWdOArH04KHMAAAAWc"]
[Tue Aug 18 12:55:58.125196 2026] [security2:error] [pid 67073:tid 67211] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSAjvcmepr5_nHgLbNNQQAAAho"]
[Tue Aug 18 12:55:58.154272 2026] [security2:error] [pid 67073:tid 67299] [client 20.226.56.190:31647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/lw.php"] [unique_id "aoSAjvcmepr5_nHgLbNNQwAAAnI"]
[Tue Aug 18 12:55:58.172077 2026] [security2:error] [pid 67073:tid 67248] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSAjvcmepr5_nHgLbNNRAAAAj8"]
[Tue Aug 18 12:55:58.180309 2026] [security2:error] [pid 66623:tid 66781] [client 132.196.61.152:60296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/dcsgumnm.php"] [unique_id "aoSAjtO5rbWdOArH04KHMQAAARk"]
[Tue Aug 18 12:55:58.192344 2026] [security2:error] [pid 66623:tid 66848] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSAjtO5rbWdOArH04KHMgAAAVw"]
[Tue Aug 18 12:55:58.225086 2026] [security2:error] [pid 67073:tid 67209] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/nw.php"] [unique_id "aoSAjvcmepr5_nHgLbNNRgAAAhg"]
[Tue Aug 18 12:55:58.229809 2026] [security2:error] [pid 66623:tid 66794] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSAjtO5rbWdOArH04KHMwAAASY"]
[Tue Aug 18 12:55:58.231056 2026] [security2:error] [pid 67073:tid 67098] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/51.php"] [unique_id "aoSAjvcmepr5_nHgLbNNRwACjBY"]
[Tue Aug 18 12:55:58.248600 2026] [security2:error] [pid 67073:tid 67241] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSAjvcmepr5_nHgLbNNSAAAAjg"]
[Tue Aug 18 12:55:58.263862 2026] [security2:error] [pid 67073:tid 67238] [client 20.163.43.14:4367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/o.php"] [unique_id "aoSAjvcmepr5_nHgLbNNSgAAAjU"]
[Tue Aug 18 12:55:58.288199 2026] [security2:error] [pid 66623:tid 66860] [client 135.225.75.187:25647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/fleen.php"] [unique_id "aoSAjtO5rbWdOArH04KHNgAAAWg"]
[Tue Aug 18 12:55:58.297097 2026] [security2:error] [pid 66623:tid 66790] [client 85.154.68.202:12511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAjtO5rbWdOArH04KHNwAAASI"]
[Tue Aug 18 12:55:58.297244 2026] [security2:error] [pid 66623:tid 66790] [client 85.154.68.202:12511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAjtO5rbWdOArH04KHNwAAASI"]
[Tue Aug 18 12:55:58.302650 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:58.302690 2026] [security2:error] [pid 67073:tid 67291] [client 160.120.140.123:60148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAjvcmepr5_nHgLbNNTAAAAmo"]
[Tue Aug 18 12:55:58.302812 2026] [security2:error] [pid 67073:tid 67291] [client 160.120.140.123:60148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAjvcmepr5_nHgLbNNTAAAAmo"]
[Tue Aug 18 12:55:58.302930 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:58.305219 2026] [security2:error] [pid 66623:tid 66795] [client 52.173.121.69:16451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSAjtO5rbWdOArH04KHOAAAASc"]
[Tue Aug 18 12:55:58.313380 2026] [security2:error] [pid 66623:tid 66823] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSAjtO5rbWdOArH04KHOQAAAUM"]
[Tue Aug 18 12:55:58.322258 2026] [security2:error] [pid 66623:tid 66831] [client 20.100.169.31:46166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/666.php"] [unique_id "aoSAjtO5rbWdOArH04KHOgAAAUs"]
[Tue Aug 18 12:55:58.326405 2026] [security2:error] [pid 66623:tid 66855] [client 4.232.151.198:27353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/ws54.php"] [unique_id "aoSAjtO5rbWdOArH04KHOwAAAWM"]
[Tue Aug 18 12:55:58.334736 2026] [security2:error] [pid 67073:tid 67243] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSAjvcmepr5_nHgLbNNTgAAAjo"]
[Tue Aug 18 12:55:58.342621 2026] [security2:error] [pid 66623:tid 66786] [client 135.225.78.186:13292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAjtO5rbWdOArH04KHPAAAAR4"]
[Tue Aug 18 12:55:58.355942 2026] [security2:error] [pid 67073:tid 67221] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSAjvcmepr5_nHgLbNNUAAAAiQ"]
[Tue Aug 18 12:55:58.366383 2026] [security2:error] [pid 67073:tid 67303] [client 20.251.48.93:31770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/bajah.php"] [unique_id "aoSAjvcmepr5_nHgLbNNUQAAAnY"]
[Tue Aug 18 12:55:58.368054 2026] [security2:error] [pid 67073:tid 67295] [client 74.248.130.103:36837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/BDKR28WP.php"] [unique_id "aoSAjvcmepr5_nHgLbNNUgAAAm4"]
[Tue Aug 18 12:55:58.375308 2026] [security2:error] [pid 66623:tid 66789] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSAjtO5rbWdOArH04KHPQAAASE"]
[Tue Aug 18 12:55:58.382841 2026] [security2:error] [pid 66623:tid 66808] [client 68.155.154.236:16381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSAjtO5rbWdOArH04KHPgAAATQ"]
[Tue Aug 18 12:55:58.384004 2026] [security2:error] [pid 67073:tid 67307] [client 20.151.109.219:64157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ih.php"] [unique_id "aoSAjvcmepr5_nHgLbNNUwAAAno"]
[Tue Aug 18 12:55:58.385087 2026] [security2:error] [pid 67073:tid 67218] [client 20.226.6.191:32995] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/1.php"] [unique_id "aoSAjvcmepr5_nHgLbNNVAAAAiE"]
[Tue Aug 18 12:55:58.385179 2026] [security2:error] [pid 67073:tid 67218] [client 20.226.6.191:32995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/1.php"] [unique_id "aoSAjvcmepr5_nHgLbNNVAAAAiE"]
[Tue Aug 18 12:55:58.393008 2026] [security2:error] [pid 67073:tid 67234] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSAjvcmepr5_nHgLbNNVgAAAjE"]
[Tue Aug 18 12:55:58.412411 2026] [security2:error] [pid 67073:tid 67301] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSAjvcmepr5_nHgLbNNVwAAAnQ"]
[Tue Aug 18 12:55:58.415774 2026] [security2:error] [pid 67073:tid 67239] [client 4.223.164.152:46176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSAjvcmepr5_nHgLbNNWAAAAjY"]
[Tue Aug 18 12:55:58.431444 2026] [security2:error] [pid 67073:tid 67275] [client 20.215.241.237:46700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAjvcmepr5_nHgLbNNWQAAAlo"]
[Tue Aug 18 12:55:58.474966 2026] [security2:error] [pid 66623:tid 66799] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSAjtO5rbWdOArH04KHQAAAASs"]
[Tue Aug 18 12:55:58.483336 2026] [security2:error] [pid 67073:tid 67247] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/sb.php"] [unique_id "aoSAjvcmepr5_nHgLbNNWwAAAj4"]
[Tue Aug 18 12:55:58.491244 2026] [security2:error] [pid 67073:tid 67227] [client 20.226.6.191:6562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/function/function.php"] [unique_id "aoSAjvcmepr5_nHgLbNNXAAAAio"]
[Tue Aug 18 12:55:58.491516 2026] [security2:error] [pid 67073:tid 67078] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ew.php"] [unique_id "aoSAjvcmepr5_nHgLbNNXQACVwI"]
[Tue Aug 18 12:55:58.494607 2026] [security2:error] [pid 67073:tid 67289] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSAjvcmepr5_nHgLbNNXgAAAmg"]
[Tue Aug 18 12:55:58.515851 2026] [security2:error] [pid 67073:tid 67217] [client 142.132.180.39:45340] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "siderurgiabrasil.com.br"] [uri "/index.php"] [unique_id "aoSAjvcmepr5_nHgLbNNTQAAAiA"], referer: https://siderurgiabrasil.com.br
[Tue Aug 18 12:55:58.544145 2026] [security2:error] [pid 66623:tid 66832] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSAjtO5rbWdOArH04KHQgAAAUw"]
[Tue Aug 18 12:55:58.562529 2026] [security2:error] [pid 67073:tid 67266] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSAjvcmepr5_nHgLbNNYAAAAlE"]
[Tue Aug 18 12:55:58.629284 2026] [security2:error] [pid 67073:tid 67318] [client 213.35.127.232:50700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAjvcmepr5_nHgLbNNYQAAAoU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:58.642101 2026] [security2:error] [pid 66623:tid 66818] [client 20.215.241.237:45790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAjtO5rbWdOArH04KHRAAAAT4"]
[Tue Aug 18 12:55:58.652086 2026] [security2:error] [pid 66623:tid 66874] [client 20.226.6.191:6590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSAjtO5rbWdOArH04KHRgAAAXY"]
[Tue Aug 18 12:55:58.695907 2026] [security2:error] [pid 67073:tid 67178] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/pqr.php"] [unique_id "aoSAjvcmepr5_nHgLbNNYwACTGY"]
[Tue Aug 18 12:55:58.702601 2026] [security2:error] [pid 66623:tid 66796] [client 20.91.215.254:20689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSAjtO5rbWdOArH04KHSAAAASg"]
[Tue Aug 18 12:55:58.720916 2026] [security2:error] [pid 67073:tid 67245] [client 20.163.43.14:4415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/bb.php"] [unique_id "aoSAjvcmepr5_nHgLbNNZQAAAjw"]
[Tue Aug 18 12:55:58.734867 2026] [security2:error] [pid 67073:tid 67228] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/stats.php"] [unique_id "aoSAjvcmepr5_nHgLbNNZwAAAis"]
[Tue Aug 18 12:55:58.743565 2026] [security2:error] [pid 66623:tid 66815] [client 20.226.56.190:3056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/vj.php"] [unique_id "aoSAjtO5rbWdOArH04KHSgAAATs"]
[Tue Aug 18 12:55:58.744098 2026] [security2:error] [pid 66623:tid 66775] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/xj.php"] [unique_id "aoSAjtO5rbWdOArH04KHSwAAARM"]
[Tue Aug 18 12:55:58.751803 2026] [security2:error] [pid 67073:tid 67222] [client 20.151.109.219:45711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/k.php"] [unique_id "aoSAjvcmepr5_nHgLbNNaAAAAiU"]
[Tue Aug 18 12:55:58.755380 2026] [security2:error] [pid 67073:tid 67233] [client 20.29.77.16:56368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/del.php"] [unique_id "aoSAjvcmepr5_nHgLbNNaQAAAjA"]
[Tue Aug 18 12:55:58.757711 2026] [security2:error] [pid 67073:tid 67311] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAjfcmepr5_nHgLbNNMgACfgY"]
[Tue Aug 18 12:55:58.759857 2026] [security2:error] [pid 67073:tid 67262] [client 158.158.74.177:3000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/k.php"] [unique_id "aoSAjvcmepr5_nHgLbNNagAAAk0"]
[Tue Aug 18 12:55:58.765445 2026] [security2:error] [pid 67073:tid 67323] [client 135.225.78.186:13289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/blurbs.php"] [unique_id "aoSAjvcmepr5_nHgLbNNawAAAoo"]
[Tue Aug 18 12:55:58.836019 2026] [security2:error] [pid 66623:tid 66822] [client 74.248.18.37:59577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/sagax1.php"] [unique_id "aoSAjtO5rbWdOArH04KHTAAAAUI"]
[Tue Aug 18 12:55:58.855335 2026] [security2:error] [pid 66623:tid 66814] [client 20.226.6.191:7108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSAjtO5rbWdOArH04KHTQAAATo"]
[Tue Aug 18 12:55:58.863431 2026] [security2:error] [pid 66623:tid 66886] [client 4.223.164.152:46188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSAjtO5rbWdOArH04KHTgAAAYI"]
[Tue Aug 18 12:55:58.880761 2026] [security2:error] [pid 66623:tid 66821] [client 158.23.17.4:63981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/xynz1.php"] [unique_id "aoSAjtO5rbWdOArH04KHUAAAAUE"]
[Tue Aug 18 12:55:58.904520 2026] [authz_core:error] [pid 67073:tid 67096] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:58.904834 2026] [authz_core:error] [pid 67073:tid 67096] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:58.941291 2026] [security2:error] [pid 66623:tid 66804] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSAjtO5rbWdOArH04KHUQAAATA"]
[Tue Aug 18 12:55:58.943489 2026] [security2:error] [pid 67073:tid 67305] [client 20.171.51.14:62494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ak.php"] [unique_id "aoSAjvcmepr5_nHgLbNNcwAAAng"]
[Tue Aug 18 12:55:58.966364 2026] [security2:error] [pid 67073:tid 67177] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/an.php"] [unique_id "aoSAjvcmepr5_nHgLbNNdAACXmU"]
[Tue Aug 18 12:55:58.985886 2026] [security2:error] [pid 66623:tid 66797] [client 20.42.19.40:2712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/ms-edit.php"] [unique_id "aoSAjtO5rbWdOArH04KHUgAAASk"]
[Tue Aug 18 12:55:58.996693 2026] [security2:error] [pid 66623:tid 66801] [client 20.226.6.191:6575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/ok.php"] [unique_id "aoSAjtO5rbWdOArH04KHUwAAAS0"]
[Tue Aug 18 12:55:59.004253 2026] [security2:error] [pid 66623:tid 66785] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSAj9O5rbWdOArH04KHVAAAAR0"]
[Tue Aug 18 12:55:59.008124 2026] [security2:error] [pid 67073:tid 67250] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ns.php"] [unique_id "aoSAj_cmepr5_nHgLbNNdwAAAkE"]
[Tue Aug 18 12:55:59.041291 2026] [security2:error] [pid 67073:tid 67317] [client 172.202.39.151:65240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSAj_cmepr5_nHgLbNNegAAAoQ"]
[Tue Aug 18 12:55:59.042525 2026] [security2:error] [pid 66623:tid 66889] [client 20.151.109.219:21680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/iu.php"] [unique_id "aoSAj9O5rbWdOArH04KHVQAAAYU"]
[Tue Aug 18 12:55:59.048636 2026] [security2:error] [pid 67073:tid 67331] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSAj_cmepr5_nHgLbNNewAAApI"]
[Tue Aug 18 12:55:59.068787 2026] [security2:error] [pid 67073:tid 67267] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/sump1.php"] [unique_id "aoSAj_cmepr5_nHgLbNNggAAAlI"]
[Tue Aug 18 12:55:59.103632 2026] [security2:error] [pid 67073:tid 67299] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSAj_cmepr5_nHgLbNNhAAAAnI"]
[Tue Aug 18 12:55:59.105357 2026] [security2:error] [pid 67073:tid 67319] [client 20.226.6.191:38250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSAj_cmepr5_nHgLbNNhQAAAoY"]
[Tue Aug 18 12:55:59.111169 2026] [security2:error] [pid 66623:tid 66772] [client 20.250.13.23:25696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/simple.php"] [unique_id "aoSAj9O5rbWdOArH04KHVgAAARA"]
[Tue Aug 18 12:55:59.121366 2026] [security2:error] [pid 67073:tid 67322] [client 172.182.200.96:14139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSAj_cmepr5_nHgLbNNhgAAAok"]
[Tue Aug 18 12:55:59.122680 2026] [security2:error] [pid 67073:tid 67277] [client 74.248.130.103:15405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp.php"] [unique_id "aoSAj_cmepr5_nHgLbNNiAAAAlw"]
[Tue Aug 18 12:55:59.123463 2026] [security2:error] [pid 67073:tid 67244] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSAj_cmepr5_nHgLbNNiQAAAjs"]
[Tue Aug 18 12:55:59.169300 2026] [security2:error] [pid 67073:tid 67191] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/sy.php"] [unique_id "aoSAj_cmepr5_nHgLbNNjAACNXM"]
[Tue Aug 18 12:55:59.181997 2026] [security2:error] [pid 67073:tid 67315] [client 4.232.151.198:25664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAj_cmepr5_nHgLbNNjgAAAoI"]
[Tue Aug 18 12:55:59.183537 2026] [security2:error] [pid 67073:tid 67269] [client 135.225.78.186:13296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/bajah.php"] [unique_id "aoSAj_cmepr5_nHgLbNNjwAAAlQ"]
[Tue Aug 18 12:55:59.184900 2026] [security2:error] [pid 67073:tid 67175] [remote 47.128.123.68:36678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "caetesturismo.com.br"] [uri "/passeio-de-lancha-pelo-rio-preguicas-ninhal-dos-guaras-novo-passeio"] [unique_id "aoSAj_cmepr5_nHgLbNNkAACFmM"]
[Tue Aug 18 12:55:59.191556 2026] [security2:error] [pid 66623:tid 66838] [client 68.155.156.252:5576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAj9O5rbWdOArH04KHVwAAAVI"]
[Tue Aug 18 12:55:59.192933 2026] [security2:error] [pid 66623:tid 66792] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/rezor.php"] [unique_id "aoSAj9O5rbWdOArH04KHWAAAASQ"]
[Tue Aug 18 12:55:59.198488 2026] [security2:error] [pid 66623:tid 66833] [client 20.163.43.14:4361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSAj9O5rbWdOArH04KHWQAAAU0"]
[Tue Aug 18 12:55:59.205004 2026] [authz_core:error] [pid 67073:tid 67102] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:59.205324 2026] [authz_core:error] [pid 67073:tid 67102] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:59.248986 2026] [security2:error] [pid 67073:tid 67268] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSAj_cmepr5_nHgLbNNlQAAAlM"]
[Tue Aug 18 12:55:59.253051 2026] [security2:error] [pid 67073:tid 67210] [client 157.51.166.53:59868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAj_cmepr5_nHgLbNNlgAAAhk"]
[Tue Aug 18 12:55:59.253198 2026] [security2:error] [pid 67073:tid 67210] [client 157.51.166.53:59868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAj_cmepr5_nHgLbNNlgAAAhk"]
[Tue Aug 18 12:55:59.255930 2026] [security2:error] [pid 67073:tid 67281] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gk.php"] [unique_id "aoSAj_cmepr5_nHgLbNNlwAAAmA"]
[Tue Aug 18 12:55:59.283436 2026] [security2:error] [pid 67073:tid 67296] [client 20.29.77.16:56531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/moderator.php"] [unique_id "aoSAj_cmepr5_nHgLbNNmgAAAm8"]
[Tue Aug 18 12:55:59.288577 2026] [security2:error] [pid 67073:tid 67270] [client 4.223.164.152:46195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/media.php"] [unique_id "aoSAj_cmepr5_nHgLbNNmwAAAlU"]
[Tue Aug 18 12:55:59.307940 2026] [security2:error] [pid 66623:tid 66890] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSAj9O5rbWdOArH04KHWgAAAYY"]
[Tue Aug 18 12:55:59.311396 2026] [security2:error] [pid 67073:tid 67220] [client 20.42.19.40:2917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/rip.php"] [unique_id "aoSAj_cmepr5_nHgLbNNnAAAAiM"]
[Tue Aug 18 12:55:59.319709 2026] [security2:error] [pid 67073:tid 67307] [client 20.226.6.191:7127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/item.php"] [unique_id "aoSAj_cmepr5_nHgLbNNnQAAAno"]
[Tue Aug 18 12:55:59.335055 2026] [security2:error] [pid 67073:tid 67276] [client 20.151.109.219:61391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/pk.php"] [unique_id "aoSAj_cmepr5_nHgLbNNnwAAAls"]
[Tue Aug 18 12:55:59.346604 2026] [authz_core:error] [pid 67073:tid 67199] [remote 57.141.22.108:36282] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:59.346887 2026] [authz_core:error] [pid 67073:tid 67199] [remote 57.141.22.108:36282] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:59.356694 2026] [security2:error] [pid 66623:tid 66876] [client 20.65.69.59:40512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/bala.php"] [unique_id "aoSAj9O5rbWdOArH04KHXAAAAXg"]
[Tue Aug 18 12:55:59.388709 2026] [security2:error] [pid 67073:tid 67239] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/index/function.php"] [unique_id "aoSAj_cmepr5_nHgLbNNogAAAjY"]
[Tue Aug 18 12:55:59.407379 2026] [security2:error] [pid 67073:tid 67309] [client 20.91.215.254:20696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/ebs.php7"] [unique_id "aoSAj_cmepr5_nHgLbNNowAAAnw"]
[Tue Aug 18 12:55:59.407385 2026] [security2:error] [pid 67073:tid 67257] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSAj_cmepr5_nHgLbNNpAAAAkg"]
[Tue Aug 18 12:55:59.409304 2026] [security2:error] [pid 66623:tid 66837] [client 158.158.34.183:50235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/elp.php"] [unique_id "aoSAj9O5rbWdOArH04KHXQAAAVE"]
[Tue Aug 18 12:55:59.409475 2026] [security2:error] [pid 67073:tid 67314] [client 158.23.17.4:8705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/album.php"] [unique_id "aoSAj_cmepr5_nHgLbNNpQAAAoE"]
[Tue Aug 18 12:55:59.432893 2026] [security2:error] [pid 67073:tid 67103] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/57.php"] [unique_id "aoSAj_cmepr5_nHgLbNNqQACKhs"]
[Tue Aug 18 12:55:59.455817 2026] [security2:error] [pid 67073:tid 67254] [client 20.226.56.190:2532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/mimes.php"] [unique_id "aoSAj_cmepr5_nHgLbNNqgAAAkU"]
[Tue Aug 18 12:55:59.505356 2026] [authz_core:error] [pid 67073:tid 67165] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:55:59.505609 2026] [authz_core:error] [pid 67073:tid 67165] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:55:59.511380 2026] [security2:error] [pid 66623:tid 66875] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/wn.php"] [unique_id "aoSAj9O5rbWdOArH04KHXgAAAXc"]
[Tue Aug 18 12:55:59.517511 2026] [security2:error] [pid 67073:tid 67258] [client 68.155.154.236:16205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSAj_cmepr5_nHgLbNNrgAAAkk"]
[Tue Aug 18 12:55:59.566863 2026] [security2:error] [pid 66623:tid 66842] [client 4.232.151.198:35390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSAj9O5rbWdOArH04KHXwAAAVY"]
[Tue Aug 18 12:55:59.598074 2026] [security2:error] [pid 67073:tid 67265] [client 158.158.74.177:16567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/media/index.php"] [unique_id "aoSAj_cmepr5_nHgLbNNsAAAAlA"]
[Tue Aug 18 12:55:59.601378 2026] [security2:error] [pid 67073:tid 67312] [client 135.225.78.186:13011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/domvf.php"] [unique_id "aoSAj_cmepr5_nHgLbNNsQAAAn8"]
[Tue Aug 18 12:55:59.611750 2026] [security2:error] [pid 67073:tid 67318] [client 74.248.130.103:14448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/i.php"] [unique_id "aoSAj_cmepr5_nHgLbNNsgAAAoU"]
[Tue Aug 18 12:55:59.626921 2026] [security2:error] [pid 66623:tid 66836] [client 20.42.19.40:2688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/update/da222.php"] [unique_id "aoSAj9O5rbWdOArH04KHYQAAAVA"]
[Tue Aug 18 12:55:59.643691 2026] [security2:error] [pid 67073:tid 67295] [client 213.35.127.232:50918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAj_cmepr5_nHgLbNNtAAAAm4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:55:59.649362 2026] [security2:error] [pid 67073:tid 67109] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ah.php"] [unique_id "aoSAj_cmepr5_nHgLbNNtQACQCE"]
[Tue Aug 18 12:55:59.664673 2026] [security2:error] [pid 66623:tid 66809] [client 20.151.109.219:64969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ge.php"] [unique_id "aoSAj9O5rbWdOArH04KHYwAAATU"]
[Tue Aug 18 12:55:59.666186 2026] [security2:error] [pid 66623:tid 66857] [client 20.215.241.237:10780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAj9O5rbWdOArH04KHZAAAAWU"]
[Tue Aug 18 12:55:59.671388 2026] [security2:error] [pid 66623:tid 66788] [client 49.13.134.145:56462] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "rakhomed.com.br"] [uri "/"] [unique_id "aoSAj9O5rbWdOArH04KHZQAAASA"], referer: http://rakhomed.com.br
[Tue Aug 18 12:55:59.729078 2026] [security2:error] [pid 67073:tid 67212] [client 4.223.164.152:17604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/inso.php"] [unique_id "aoSAj_cmepr5_nHgLbNNuAAAAhs"]
[Tue Aug 18 12:55:59.774714 2026] [security2:error] [pid 67073:tid 67323] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/app.php"] [unique_id "aoSAj_cmepr5_nHgLbNNugAAAoo"]
[Tue Aug 18 12:55:59.819086 2026] [security2:error] [pid 67073:tid 67320] [client 135.225.75.187:58335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/e.php"] [unique_id "aoSAj_cmepr5_nHgLbNNvQAAAoc"]
[Tue Aug 18 12:55:59.824465 2026] [security2:error] [pid 66623:tid 66773] [client 20.163.43.14:3055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSAj9O5rbWdOArH04KHaAAAARE"]
[Tue Aug 18 12:55:59.826403 2026] [security2:error] [pid 67073:tid 67302] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/Cachex.php"] [unique_id "aoSAj_cmepr5_nHgLbNNvgAAAnU"]
[Tue Aug 18 12:55:59.848113 2026] [security2:error] [pid 66623:tid 66816] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSAj9O5rbWdOArH04KHaQAAATw"]
[Tue Aug 18 12:55:59.853655 2026] [security2:error] [pid 67073:tid 67120] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/vw.php"] [unique_id "aoSAj_cmepr5_nHgLbNNwAACFyw"]
[Tue Aug 18 12:55:59.861567 2026] [security2:error] [pid 66623:tid 66870] [client 20.171.51.14:15026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/test_info.php"] [unique_id "aoSAj9O5rbWdOArH04KHagAAAXI"]
[Tue Aug 18 12:55:59.889256 2026] [security2:error] [pid 67073:tid 67253] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-2019.php"] [unique_id "aoSAj_cmepr5_nHgLbNNwwAAAkQ"]
[Tue Aug 18 12:55:59.910303 2026] [security2:error] [pid 66623:tid 66811] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSAj9O5rbWdOArH04KHbAAAATc"]
[Tue Aug 18 12:55:59.911984 2026] [security2:error] [pid 66623:tid 66793] [client 20.29.77.16:52768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/infoinfo.php"] [unique_id "aoSAj9O5rbWdOArH04KHbQAAASU"]
[Tue Aug 18 12:55:59.942809 2026] [security2:error] [pid 67073:tid 67206] [client 20.251.48.93:9768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/ajax.php"] [unique_id "aoSAj_cmepr5_nHgLbNNxQAAAhU"]
[Tue Aug 18 12:55:59.946959 2026] [security2:error] [pid 66623:tid 66892] [client 128.140.106.114:51048] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.portaltomazzi.com.br"] [uri "/index.php"] [unique_id "aoSAjtO5rbWdOArH04KHRwAAAYg"], referer: https://www.portaltomazzi.com.br/
[Tue Aug 18 12:55:59.972010 2026] [security2:error] [pid 67073:tid 67324] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/.cache/x.php"] [unique_id "aoSAj_cmepr5_nHgLbNNxwAAAos"]
[Tue Aug 18 12:55:59.991538 2026] [security2:error] [pid 67073:tid 67236] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSAj_cmepr5_nHgLbNNyAAAAjM"]
[Tue Aug 18 12:55:59.996994 2026] [security2:error] [pid 66623:tid 66844] [client 172.202.39.151:65238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/k.php"] [unique_id "aoSAj9O5rbWdOArH04KHbgAAAVg"]
[Tue Aug 18 12:56:00.010631 2026] [security2:error] [pid 67073:tid 67299] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAkPcmepr5_nHgLbNNygAAAnI"]
[Tue Aug 18 12:56:00.022136 2026] [security2:error] [pid 67073:tid 67287] [client 135.225.78.186:13283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/fpwch.php"] [unique_id "aoSAkPcmepr5_nHgLbNNzAAAAmY"]
[Tue Aug 18 12:56:00.022420 2026] [security2:error] [pid 67073:tid 67322] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/87.php"] [unique_id "aoSAkPcmepr5_nHgLbNNzQAAAok"]
[Tue Aug 18 12:56:00.030800 2026] [security2:error] [pid 67073:tid 67244] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAkPcmepr5_nHgLbNNzgAAAjs"]
[Tue Aug 18 12:56:00.044473 2026] [security2:error] [pid 66623:tid 66829] [client 20.250.13.23:14327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/edit-tags.php"] [unique_id "aoSAkNO5rbWdOArH04KHbwAAAUk"]
[Tue Aug 18 12:56:00.049929 2026] [security2:error] [pid 67073:tid 67259] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSAkPcmepr5_nHgLbNNzwAAAko"]
[Tue Aug 18 12:56:00.052411 2026] [security2:error] [pid 66623:tid 66824] [client 20.151.109.219:32977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kl.php"] [unique_id "aoSAkNO5rbWdOArH04KHcAAAAUQ"]
[Tue Aug 18 12:56:00.065503 2026] [security2:error] [pid 67073:tid 67300] [client 20.226.6.191:55790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAkPcmepr5_nHgLbNN0AAAAnM"]
[Tue Aug 18 12:56:00.085003 2026] [security2:error] [pid 67073:tid 67269] [client 20.65.98.162:31690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/33.php"] [unique_id "aoSAkPcmepr5_nHgLbNN0QAAAlQ"]
[Tue Aug 18 12:56:00.109072 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:00.109374 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:00.116319 2026] [security2:error] [pid 67073:tid 67139] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/lj.php"] [unique_id "aoSAkPcmepr5_nHgLbNN1AACYT8"]
[Tue Aug 18 12:56:00.119693 2026] [security2:error] [pid 67073:tid 67291] [client 20.42.19.40:2900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/upload.php"] [unique_id "aoSAkPcmepr5_nHgLbNN1gAAAmo"]
[Tue Aug 18 12:56:00.123119 2026] [security2:error] [pid 66623:tid 66848] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSAkNO5rbWdOArH04KHcQAAAVw"]
[Tue Aug 18 12:56:00.144917 2026] [security2:error] [pid 66623:tid 66794] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSAkNO5rbWdOArH04KHcgAAASY"]
[Tue Aug 18 12:56:00.145993 2026] [security2:error] [pid 67073:tid 67279] [client 20.91.215.254:11988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/include/Lurd.class.php"] [unique_id "aoSAkPcmepr5_nHgLbNN1wAAAl4"]
[Tue Aug 18 12:56:00.162823 2026] [security2:error] [pid 66623:tid 66800] [client 4.223.164.152:46153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/shiny.php"] [unique_id "aoSAkNO5rbWdOArH04KHcwAAASw"]
[Tue Aug 18 12:56:00.166623 2026] [security2:error] [pid 66623:tid 66777] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/system.php"] [unique_id "aoSAkNO5rbWdOArH04KHdAAAARU"]
[Tue Aug 18 12:56:00.167649 2026] [security2:error] [pid 66623:tid 66860] [client 68.155.156.252:4688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAkNO5rbWdOArH04KHdQAAAWg"]
[Tue Aug 18 12:56:00.177345 2026] [security2:error] [pid 67073:tid 67268] [client 20.163.43.14:3015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAkPcmepr5_nHgLbNN2AAAAlM"]
[Tue Aug 18 12:56:00.192093 2026] [security2:error] [pid 67073:tid 67260] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSAkPcmepr5_nHgLbNN2QAAAks"]
[Tue Aug 18 12:56:00.217483 2026] [security2:error] [pid 67073:tid 67226] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSAkPcmepr5_nHgLbNN2wAAAik"]
[Tue Aug 18 12:56:00.261999 2026] [security2:error] [pid 67073:tid 67306] [client 158.158.74.177:22748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/memberfuns.php"] [unique_id "aoSAkPcmepr5_nHgLbNN3QAAAnk"]
[Tue Aug 18 12:56:00.273480 2026] [security2:error] [pid 67073:tid 67270] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/zi.php"] [unique_id "aoSAkPcmepr5_nHgLbNN3gAAAlU"]
[Tue Aug 18 12:56:00.290769 2026] [security2:error] [pid 67073:tid 67246] [client 20.226.56.190:30980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ni.php"] [unique_id "aoSAkPcmepr5_nHgLbNN3wAAAj0"]
[Tue Aug 18 12:56:00.302173 2026] [security2:error] [pid 66623:tid 66873] [client 20.65.69.59:40567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/222.php"] [unique_id "aoSAkNO5rbWdOArH04KHdgAAAXU"]
[Tue Aug 18 12:56:00.327035 2026] [security2:error] [pid 67073:tid 67218] [client 20.116.17.175:57641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/3.php"] [unique_id "aoSAkPcmepr5_nHgLbNN4QAAAiE"]
[Tue Aug 18 12:56:00.328055 2026] [security2:error] [pid 67073:tid 67242] [client 74.248.18.37:29307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wpc.php"] [unique_id "aoSAkPcmepr5_nHgLbNN4gAAAjk"]
[Tue Aug 18 12:56:00.328767 2026] [security2:error] [pid 66623:tid 66786] [client 68.155.154.236:16348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSAkNO5rbWdOArH04KHdwAAAR4"]
[Tue Aug 18 12:56:00.336880 2026] [security2:error] [pid 66623:tid 66808] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSAkNO5rbWdOArH04KHeQAAATQ"]
[Tue Aug 18 12:56:00.359183 2026] [security2:error] [pid 66623:tid 66852] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSAkNO5rbWdOArH04KHegAAAWA"]
[Tue Aug 18 12:56:00.364896 2026] [security2:error] [pid 67073:tid 67301] [client 20.151.109.219:53198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gs.php"] [unique_id "aoSAkPcmepr5_nHgLbNN5AAAAnQ"]
[Tue Aug 18 12:56:00.376237 2026] [security2:error] [pid 67073:tid 67264] [client 4.232.151.198:41973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/222.php"] [unique_id "aoSAkPcmepr5_nHgLbNN5QAAAk8"]
[Tue Aug 18 12:56:00.442876 2026] [security2:error] [pid 67073:tid 67329] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAkPcmepr5_nHgLbNN4wACkBw"]
[Tue Aug 18 12:56:00.445118 2026] [security2:error] [pid 67073:tid 67239] [client 135.225.78.186:13024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/adminner.php"] [unique_id "aoSAkPcmepr5_nHgLbNN6AAAAjY"]
[Tue Aug 18 12:56:00.450805 2026] [security2:error] [pid 66623:tid 66769] [client 20.226.6.191:56202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/as.php"] [unique_id "aoSAkNO5rbWdOArH04KHewAAAQ0"]
[Tue Aug 18 12:56:00.454262 2026] [security2:error] [pid 67073:tid 67167] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kh.php"] [unique_id "aoSAkPcmepr5_nHgLbNN6QACg1s"]
[Tue Aug 18 12:56:00.505828 2026] [security2:error] [pid 67073:tid 67303] [client 20.171.51.14:61453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/14.php"] [unique_id "aoSAkPcmepr5_nHgLbNN7AAAAnY"]
[Tue Aug 18 12:56:00.508253 2026] [security2:error] [pid 67073:tid 67227] [client 74.248.130.103:14425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/abcd.php"] [unique_id "aoSAkPcmepr5_nHgLbNN7QAAAio"]
[Tue Aug 18 12:56:00.526796 2026] [security2:error] [pid 67073:tid 67289] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSAkPcmepr5_nHgLbNN7gAAAmg"]
[Tue Aug 18 12:56:00.531136 2026] [security2:error] [pid 67073:tid 67247] [client 20.163.43.14:4454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/file.php"] [unique_id "aoSAkPcmepr5_nHgLbNN7wAAAj4"]
[Tue Aug 18 12:56:00.534275 2026] [security2:error] [pid 67073:tid 67217] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/92.php"] [unique_id "aoSAkPcmepr5_nHgLbNN8AAAAiA"]
[Tue Aug 18 12:56:00.548286 2026] [security2:error] [pid 66623:tid 66834] [client 20.226.56.190:31011] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "rakhomed.com.br"] [uri "/1.php"] [unique_id "aoSAkNO5rbWdOArH04KHfAAAAU4"]
[Tue Aug 18 12:56:00.548395 2026] [security2:error] [pid 66623:tid 66834] [client 20.226.56.190:31011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/1.php"] [unique_id "aoSAkNO5rbWdOArH04KHfAAAAU4"]
[Tue Aug 18 12:56:00.576789 2026] [security2:error] [pid 67073:tid 67266] [client 20.100.169.31:39353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/ws54.php"] [unique_id "aoSAkPcmepr5_nHgLbNN8gAAAlE"]
[Tue Aug 18 12:56:00.606094 2026] [security2:error] [pid 67073:tid 67285] [client 4.223.164.152:64662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/403dd.php"] [unique_id "aoSAkPcmepr5_nHgLbNN9AAAAmQ"]
[Tue Aug 18 12:56:00.656964 2026] [security2:error] [pid 66623:tid 66855] [client 213.35.127.232:51136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAkNO5rbWdOArH04KHfgAAAWM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:00.698365 2026] [security2:error] [pid 66623:tid 66820] [client 20.151.109.219:12888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/lw.php"] [unique_id "aoSAkNO5rbWdOArH04KHfwAAAUA"]
[Tue Aug 18 12:56:00.709290 2026] [security2:error] [pid 67073:tid 67126] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/jb.php"] [unique_id "aoSAkPcmepr5_nHgLbNN9wACazI"]
[Tue Aug 18 12:56:00.724429 2026] [security2:error] [pid 67073:tid 67245] [client 52.173.121.69:24802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/index/function.php"] [unique_id "aoSAkPcmepr5_nHgLbNN-AAAAjw"]
[Tue Aug 18 12:56:00.753781 2026] [security2:error] [pid 66623:tid 66815] [client 20.226.6.191:39397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAkNO5rbWdOArH04KHgQAAATs"]
[Tue Aug 18 12:56:00.757817 2026] [security2:error] [pid 66623:tid 66775] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSAkNO5rbWdOArH04KHggAAARM"]
[Tue Aug 18 12:56:00.757989 2026] [security2:error] [pid 67073:tid 67147] [remote 135.236.141.8:21379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.141.236.135.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maxhost.com.br"] [uri "/wp-login.php"] [unique_id "aoSAkPcmepr5_nHgLbNN-QACWkc"]
[Tue Aug 18 12:56:00.778877 2026] [security2:error] [pid 66623:tid 66854] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAkNO5rbWdOArH04KHhAAAAWI"]
[Tue Aug 18 12:56:00.801715 2026] [security2:error] [pid 67073:tid 67212] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSAkPcmepr5_nHgLbNN_AAAAhs"]
[Tue Aug 18 12:56:00.802077 2026] [security2:error] [pid 66623:tid 66858] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/jm.php"] [unique_id "aoSAkNO5rbWdOArH04KHhQAAAWY"]
[Tue Aug 18 12:56:00.812832 2026] [security2:error] [pid 67073:tid 67238] [client 49.13.134.145:25302] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rakhomed.com.br"] [uri "/index.php"] [unique_id "aoSAkPcmepr5_nHgLbNN3AAAAjU"], referer: http://rakhomed.com.br
[Tue Aug 18 12:56:00.833635 2026] [security2:error] [pid 67073:tid 67327] [client 158.23.17.4:33535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/creds.php"] [unique_id "aoSAkPcmepr5_nHgLbNN_QAAAo4"]
[Tue Aug 18 12:56:00.854332 2026] [security2:error] [pid 67073:tid 67308] [client 135.225.75.187:25653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/hello.php"] [unique_id "aoSAkPcmepr5_nHgLbNOAAAAAns"]
[Tue Aug 18 12:56:00.867701 2026] [security2:error] [pid 67073:tid 67302] [client 68.155.154.236:16368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSAkPcmepr5_nHgLbNOAQAAAnU"]
[Tue Aug 18 12:56:00.868488 2026] [security2:error] [pid 67073:tid 67205] [client 135.225.78.186:13036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/abcd.php"] [unique_id "aoSAkPcmepr5_nHgLbNOAgAAAhQ"]
[Tue Aug 18 12:56:00.886082 2026] [security2:error] [pid 67073:tid 67273] [client 20.91.215.254:12006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSAkPcmepr5_nHgLbNOAwAAAlg"]
[Tue Aug 18 12:56:00.897983 2026] [security2:error] [pid 66623:tid 66796] [client 158.158.74.177:16560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/mgrr.php"] [unique_id "aoSAkNO5rbWdOArH04KHhgAAASg"]
[Tue Aug 18 12:56:00.904463 2026] [security2:error] [pid 67073:tid 67158] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/do.php"] [unique_id "aoSAkPcmepr5_nHgLbNOBAACkVI"]
[Tue Aug 18 12:56:00.944805 2026] [security2:error] [pid 67073:tid 67250] [client 20.226.6.191:41831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSAkPcmepr5_nHgLbNOCAAAAkE"]
[Tue Aug 18 12:56:00.945834 2026] [security2:error] [pid 67073:tid 67317] [client 20.163.43.14:4384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/epinyins.php"] [unique_id "aoSAkPcmepr5_nHgLbNOCQAAAoQ"]
[Tue Aug 18 12:56:00.951087 2026] [security2:error] [pid 66623:tid 66886] [client 20.226.56.190:31673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/88.php"] [unique_id "aoSAkNO5rbWdOArH04KHhwAAAYI"]
[Tue Aug 18 12:56:00.998358 2026] [autoindex:error] [pid 67073:tid 67324] [client 43.164.190.28:57344] AH01276: Cannot serve directory /home1/olhaoreplay/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:01.013639 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:01.014079 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:01.038555 2026] [security2:error] [pid 67073:tid 67299] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/well-known/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOEAAAAnI"]
[Tue Aug 18 12:56:01.045925 2026] [security2:error] [pid 67073:tid 67287] [client 20.151.109.219:53193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/vj.php"] [unique_id "aoSAkfcmepr5_nHgLbNOEQAAAmY"]
[Tue Aug 18 12:56:01.058229 2026] [security2:error] [pid 66623:tid 66843] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSAkdO5rbWdOArH04KHiAAAAVc"]
[Tue Aug 18 12:56:01.070029 2026] [security2:error] [pid 66623:tid 66804] [client 4.223.164.152:28483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/baba.php"] [unique_id "aoSAkdO5rbWdOArH04KHiQAAATA"]
[Tue Aug 18 12:56:01.075526 2026] [security2:error] [pid 66623:tid 66882] [client 20.251.48.93:61160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAkdO5rbWdOArH04KHigAAAX4"]
[Tue Aug 18 12:56:01.078818 2026] [security2:error] [pid 66623:tid 66797] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/wj.php"] [unique_id "aoSAkdO5rbWdOArH04KHiwAAASk"]
[Tue Aug 18 12:56:01.091181 2026] [security2:error] [pid 67073:tid 67256] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOEwAAAkc"]
[Tue Aug 18 12:56:01.110347 2026] [security2:error] [pid 67073:tid 67291] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSAkfcmepr5_nHgLbNOFAAAAmo"]
[Tue Aug 18 12:56:01.112449 2026] [security2:error] [pid 67073:tid 67207] [client 132.196.61.152:60298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/php.php"] [unique_id "aoSAkfcmepr5_nHgLbNOFQAAAhY"]
[Tue Aug 18 12:56:01.130250 2026] [security2:error] [pid 67073:tid 67326] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/mt/byp.php"] [unique_id "aoSAkfcmepr5_nHgLbNOFwAAAo0"]
[Tue Aug 18 12:56:01.149284 2026] [security2:error] [pid 67073:tid 67127] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/yw.php"] [unique_id "aoSAkfcmepr5_nHgLbNOGAACTjM"]
[Tue Aug 18 12:56:01.150183 2026] [security2:error] [pid 67073:tid 67311] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSAkfcmepr5_nHgLbNOGQAAAn4"]
[Tue Aug 18 12:56:01.171894 2026] [security2:error] [pid 66623:tid 66785] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAkdO5rbWdOArH04KHjQAAAR0"]
[Tue Aug 18 12:56:01.183060 2026] [security2:error] [pid 66623:tid 66768] [client 4.223.164.152:4861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAkdO5rbWdOArH04KHjgAAAQw"]
[Tue Aug 18 12:56:01.219989 2026] [security2:error] [pid 66623:tid 66881] [client 68.155.156.252:5600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAkdO5rbWdOArH04KHjwAAAX0"]
[Tue Aug 18 12:56:01.234131 2026] [security2:error] [pid 67073:tid 67267] [client 74.248.18.37:28113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/fone1.php"] [unique_id "aoSAkfcmepr5_nHgLbNOHAAAAlI"]
[Tue Aug 18 12:56:01.238712 2026] [security2:error] [pid 67073:tid 67210] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOHQAAAhk"]
[Tue Aug 18 12:56:01.266748 2026] [security2:error] [pid 67073:tid 67226] [client 20.215.241.237:24637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/sf.php"] [unique_id "aoSAkfcmepr5_nHgLbNOHgAAAik"]
[Tue Aug 18 12:56:01.274230 2026] [security2:error] [pid 66623:tid 66840] [client 74.248.130.103:14454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-manager.php"] [unique_id "aoSAkdO5rbWdOArH04KHkAAAAVQ"]
[Tue Aug 18 12:56:01.276224 2026] [security2:error] [pid 67073:tid 67221] [client 20.163.43.14:4396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOHwAAAiQ"]
[Tue Aug 18 12:56:01.288708 2026] [security2:error] [pid 67073:tid 67306] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSAkfcmepr5_nHgLbNOIAAAAnk"]
[Tue Aug 18 12:56:01.290818 2026] [security2:error] [pid 67073:tid 67270] [client 135.225.78.186:40777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/simple.php"] [unique_id "aoSAkfcmepr5_nHgLbNOIQAAAlU"]
[Tue Aug 18 12:56:01.321993 2026] [security2:error] [pid 66623:tid 66879] [client 20.116.17.175:57436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/log.php"] [unique_id "aoSAkdO5rbWdOArH04KHkQAAAXs"]
[Tue Aug 18 12:56:01.342438 2026] [security2:error] [pid 67073:tid 67234] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/74.php"] [unique_id "aoSAkfcmepr5_nHgLbNOJgAAAjE"]
[Tue Aug 18 12:56:01.343730 2026] [security2:error] [pid 67073:tid 67276] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSAkfcmepr5_nHgLbNOJwAAAls"]
[Tue Aug 18 12:56:01.345137 2026] [security2:error] [pid 67073:tid 67301] [client 74.248.136.165:28099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/txets.php"] [unique_id "aoSAkfcmepr5_nHgLbNOKAAAAnQ"]
[Tue Aug 18 12:56:01.349084 2026] [security2:error] [pid 67073:tid 67264] [client 20.42.19.40:2637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wk/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOKQAAAk8"]
[Tue Aug 18 12:56:01.364226 2026] [security2:error] [pid 67073:tid 67332] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOKwAAApM"]
[Tue Aug 18 12:56:01.379776 2026] [security2:error] [pid 67073:tid 67316] [client 20.151.109.219:59717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/mimes.php"] [unique_id "aoSAkfcmepr5_nHgLbNOLAAAAoM"]
[Tue Aug 18 12:56:01.381433 2026] [security2:error] [pid 67073:tid 67110] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/qh.php"] [unique_id "aoSAkfcmepr5_nHgLbNOLQACfCI"]
[Tue Aug 18 12:56:01.408953 2026] [security2:error] [pid 67073:tid 67216] [client 2a02:c207:2265:4159::1:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.simetriaarquitetura.com.br"] [uri "/.git/config"] [unique_id "aoSAkfcmepr5_nHgLbNOLwAAAh8"]
[Tue Aug 18 12:56:01.421201 2026] [security2:error] [pid 66623:tid 66856] [client 68.155.154.236:16329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSAkdO5rbWdOArH04KHlQAAAWQ"]
[Tue Aug 18 12:56:01.421469 2026] [security2:error] [pid 67073:tid 67328] [client 196.12.128.158:64398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAkfcmepr5_nHgLbNOMAAAAo8"]
[Tue Aug 18 12:56:01.421595 2026] [security2:error] [pid 67073:tid 67328] [client 196.12.128.158:64398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAkfcmepr5_nHgLbNOMAAAAo8"]
[Tue Aug 18 12:56:01.424409 2026] [security2:error] [pid 67073:tid 67314] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOMQAAAoE"]
[Tue Aug 18 12:56:01.471352 2026] [security2:error] [pid 67073:tid 67217] [client 172.202.39.151:34218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAkfcmepr5_nHgLbNOMwAAAiA"]
[Tue Aug 18 12:56:01.482491 2026] [security2:error] [pid 67073:tid 67237] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/first.php"] [unique_id "aoSAkfcmepr5_nHgLbNONAAAAjQ"]
[Tue Aug 18 12:56:01.503042 2026] [security2:error] [pid 67073:tid 67232] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNONgAAAi8"]
[Tue Aug 18 12:56:01.512005 2026] [security2:error] [pid 67073:tid 67265] [client 20.65.69.59:49283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/routes.php"] [unique_id "aoSAkfcmepr5_nHgLbNOOAAAAlA"]
[Tue Aug 18 12:56:01.514253 2026] [security2:error] [pid 67073:tid 67307] [client 93.152.221.213:63376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.sindsecurpr.com.br"] [uri "/wp-login.php"] [unique_id "aoSAkfcmepr5_nHgLbNONwAAAno"], referer: https://wordpress.org/
[Tue Aug 18 12:56:01.515178 2026] [security2:error] [pid 67073:tid 67312] [client 52.173.121.69:24994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSAkfcmepr5_nHgLbNOOQAAAn8"]
[Tue Aug 18 12:56:01.519527 2026] [security2:error] [pid 67073:tid 67292] [client 20.215.241.237:49244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAkfcmepr5_nHgLbNOOgAAAms"]
[Tue Aug 18 12:56:01.521341 2026] [security2:error] [pid 66623:tid 66837] [client 158.23.17.4:38886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/mandrill.php"] [unique_id "aoSAkdO5rbWdOArH04KHlwAAAVE"]
[Tue Aug 18 12:56:01.523488 2026] [security2:error] [pid 67073:tid 67295] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOOwAAAm4"]
[Tue Aug 18 12:56:01.526401 2026] [security2:error] [pid 66623:tid 66827] [client 213.202.253.4:58067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAkdO5rbWdOArH04KHmAAAAUc"], referer: www.google.com
[Tue Aug 18 12:56:01.529935 2026] [security2:error] [pid 67073:tid 67246] [client 20.100.169.31:48080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSAkfcmepr5_nHgLbNOPAAAAj0"]
[Tue Aug 18 12:56:01.545038 2026] [security2:error] [pid 67073:tid 67275] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOPQAAAlo"]
[Tue Aug 18 12:56:01.554750 2026] [security2:error] [pid 67073:tid 67222] [client 20.226.56.190:28283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/hj.php"] [unique_id "aoSAkfcmepr5_nHgLbNOPgAAAiU"]
[Tue Aug 18 12:56:01.556849 2026] [security2:error] [pid 66623:tid 66875] [client 4.223.164.152:28500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/site.php"] [unique_id "aoSAkdO5rbWdOArH04KHmgAAAXc"]
[Tue Aug 18 12:56:01.598517 2026] [security2:error] [pid 67073:tid 67257] [client 20.91.215.254:20709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/lite.php"] [unique_id "aoSAkfcmepr5_nHgLbNOQgAAAkg"]
[Tue Aug 18 12:56:01.603872 2026] [security2:error] [pid 67073:tid 67308] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/av.php"] [unique_id "aoSAkfcmepr5_nHgLbNOQwAAAns"]
[Tue Aug 18 12:56:01.605373 2026] [security2:error] [pid 67073:tid 67320] [client 4.223.164.152:4804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAkfcmepr5_nHgLbNORAAAAoc"]
[Tue Aug 18 12:56:01.606904 2026] [security2:error] [pid 67073:tid 67293] [client 20.226.6.191:39378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNORQAAAmw"]
[Tue Aug 18 12:56:01.647428 2026] [security2:error] [pid 67073:tid 67148] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/r.php"] [unique_id "aoSAkfcmepr5_nHgLbNOSQACK0g"]
[Tue Aug 18 12:56:01.671015 2026] [security2:error] [pid 66623:tid 66838] [client 213.35.127.232:51366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAkdO5rbWdOArH04KHnQAAAVI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:01.691833 2026] [security2:error] [pid 66623:tid 66805] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/blog/byp.php"] [unique_id "aoSAkdO5rbWdOArH04KHnwAAATE"]
[Tue Aug 18 12:56:01.710477 2026] [security2:error] [pid 67073:tid 67253] [client 135.225.78.186:13015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/wp-manager.php"] [unique_id "aoSAkfcmepr5_nHgLbNOUQAAAkQ"]
[Tue Aug 18 12:56:01.715594 2026] [security2:error] [pid 67073:tid 67299] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOUwAAAnI"]
[Tue Aug 18 12:56:01.721800 2026] [security2:error] [pid 67073:tid 67248] [client 20.151.109.219:59713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ni.php"] [unique_id "aoSAkfcmepr5_nHgLbNOVAAAAj8"]
[Tue Aug 18 12:56:01.737489 2026] [security2:error] [pid 66623:tid 66776] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAkdO5rbWdOArH04KHoAAAARQ"]
[Tue Aug 18 12:56:01.788286 2026] [security2:error] [pid 67073:tid 67300] [client 68.155.156.252:4796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/av.php"] [unique_id "aoSAkfcmepr5_nHgLbNOWAAAAnM"]
[Tue Aug 18 12:56:01.800158 2026] [security2:error] [pid 67073:tid 67269] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/images/security.php"] [unique_id "aoSAkfcmepr5_nHgLbNOWQAAAlQ"]
[Tue Aug 18 12:56:01.802231 2026] [security2:error] [pid 67073:tid 67282] [client 20.163.43.14:3050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOWgAAAmE"]
[Tue Aug 18 12:56:01.811234 2026] [security2:error] [pid 66623:tid 66870] [client 78.46.190.63:1946] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "rakhomed.com.br"] [uri "/"] [unique_id "aoSAkdO5rbWdOArH04KHogAAAXI"], referer: http://rakhomed.com.br
[Tue Aug 18 12:56:01.820821 2026] [security2:error] [pid 67073:tid 67230] [client 20.226.56.190:2553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ij.php"] [unique_id "aoSAkfcmepr5_nHgLbNOWwAAAi0"]
[Tue Aug 18 12:56:01.848877 2026] [security2:error] [pid 67073:tid 67290] [client 4.232.151.198:27385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/function/function.php"] [unique_id "aoSAkfcmepr5_nHgLbNOXAAAAmk"]
[Tue Aug 18 12:56:01.849346 2026] [security2:error] [pid 67073:tid 67119] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/17.php"] [unique_id "aoSAkfcmepr5_nHgLbNOXQACTis"]
[Tue Aug 18 12:56:01.860977 2026] [security2:error] [pid 67073:tid 67268] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ag.php"] [unique_id "aoSAkfcmepr5_nHgLbNOXwAAAlM"]
[Tue Aug 18 12:56:01.862873 2026] [security2:error] [pid 67073:tid 67283] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/system/03n1hob7p03r2npdefault.php"] [unique_id "aoSAkfcmepr5_nHgLbNOYAAAAmI"]
[Tue Aug 18 12:56:01.885468 2026] [security2:error] [pid 67073:tid 67210] [client 20.171.51.14:62487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/tk.php"] [unique_id "aoSAkfcmepr5_nHgLbNOYwAAAhk"]
[Tue Aug 18 12:56:01.887674 2026] [security2:error] [pid 67073:tid 67281] [client 68.155.154.236:16350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSAkfcmepr5_nHgLbNOZAAAAmA"]
[Tue Aug 18 12:56:01.917179 2026] [security2:error] [pid 66623:tid 66885] [client 20.226.6.191:32983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAkdO5rbWdOArH04KHpAAAAYE"]
[Tue Aug 18 12:56:01.920767 2026] [security2:error] [pid 66623:tid 66892] [client 93.152.221.213:63658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.sindsecurpr.com.br"] [uri "/wp-login.php"] [unique_id "aoSAkdO5rbWdOArH04KHpQAAAYg"]
[Tue Aug 18 12:56:01.953728 2026] [security2:error] [pid 67073:tid 67220] [client 158.23.17.4:8754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/main.php"] [unique_id "aoSAkfcmepr5_nHgLbNOaAAAAiM"]
[Tue Aug 18 12:56:02.002678 2026] [security2:error] [pid 67073:tid 67325] [client 20.151.109.219:59760] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "suportesignrj.com.br"] [uri "/1.php"] [unique_id "aoSAkvcmepr5_nHgLbNOagAAAow"]
[Tue Aug 18 12:56:02.002811 2026] [security2:error] [pid 67073:tid 67325] [client 20.151.109.219:59760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/1.php"] [unique_id "aoSAkvcmepr5_nHgLbNOagAAAow"]
[Tue Aug 18 12:56:02.026717 2026] [security2:error] [pid 67073:tid 67264] [client 4.223.164.152:4823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/domvf.php"] [unique_id "aoSAkvcmepr5_nHgLbNOawAAAk8"]
[Tue Aug 18 12:56:02.065323 2026] [security2:error] [pid 67073:tid 67316] [client 4.223.164.152:46177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSAkvcmepr5_nHgLbNObwAAAoM"]
[Tue Aug 18 12:56:02.108958 2026] [security2:error] [pid 66623:tid 66781] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ig.php"] [unique_id "aoSAktO5rbWdOArH04KHpwAAARk"]
[Tue Aug 18 12:56:02.119948 2026] [security2:error] [pid 67073:tid 67174] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ev.php"] [unique_id "aoSAkvcmepr5_nHgLbNOcwACGGI"]
[Tue Aug 18 12:56:02.129235 2026] [security2:error] [pid 67073:tid 67314] [client 135.225.78.186:12997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/xiugai.php"] [unique_id "aoSAkvcmepr5_nHgLbNOdAAAAoE"]
[Tue Aug 18 12:56:02.159609 2026] [security2:error] [pid 67073:tid 67237] [client 20.163.43.14:3035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAkvcmepr5_nHgLbNOeAAAAjQ"]
[Tue Aug 18 12:56:02.166403 2026] [security2:error] [pid 66623:tid 66847] [client 74.248.130.103:15410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSAktO5rbWdOArH04KHqQAAAVs"]
[Tue Aug 18 12:56:02.209297 2026] [security2:error] [pid 67073:tid 67225] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/system/cj5ha2rah8lyiqqdefault.php"] [unique_id "aoSAkvcmepr5_nHgLbNOegAAAig"]
[Tue Aug 18 12:56:02.222671 2026] [authz_core:error] [pid 67073:tid 67184] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:02.223094 2026] [authz_core:error] [pid 67073:tid 67184] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:02.269159 2026] [security2:error] [pid 66623:tid 66863] [client 197.184.64.235:41928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAktO5rbWdOArH04KHrAAAAWs"]
[Tue Aug 18 12:56:02.269306 2026] [security2:error] [pid 66623:tid 66863] [client 197.184.64.235:41928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAktO5rbWdOArH04KHrAAAAWs"]
[Tue Aug 18 12:56:02.280695 2026] [security2:error] [pid 67073:tid 67332] [client 20.91.215.254:12021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSAkvcmepr5_nHgLbNOfQAAApM"]
[Tue Aug 18 12:56:02.295971 2026] [security2:error] [pid 66623:tid 66887] [client 20.151.109.219:21671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/88.php"] [unique_id "aoSAktO5rbWdOArH04KHrQAAAYM"]
[Tue Aug 18 12:56:02.324325 2026] [security2:error] [pid 66623:tid 66859] [client 20.100.169.31:7818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/function/function.php"] [unique_id "aoSAktO5rbWdOArH04KHtQAAAWc"]
[Tue Aug 18 12:56:02.329652 2026] [security2:error] [pid 67073:tid 67212] [client 20.226.56.190:2707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ud.php"] [unique_id "aoSAkvcmepr5_nHgLbNOfgAAAhs"]
[Tue Aug 18 12:56:02.366377 2026] [security2:error] [pid 67073:tid 67200] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/xs.php"] [unique_id "aoSAkvcmepr5_nHgLbNOgAACgHw"]
[Tue Aug 18 12:56:02.375677 2026] [security2:error] [pid 67073:tid 67229] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ta.php"] [unique_id "aoSAkvcmepr5_nHgLbNOgQAAAiw"]
[Tue Aug 18 12:56:02.401789 2026] [security2:error] [pid 66623:tid 66868] [client 37.40.227.74:56726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAktO5rbWdOArH04KHuAAAAXA"]
[Tue Aug 18 12:56:02.404093 2026] [security2:error] [pid 66623:tid 66868] [client 37.40.227.74:56726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAktO5rbWdOArH04KHuAAAAXA"]
[Tue Aug 18 12:56:02.422832 2026] [security2:error] [pid 67073:tid 67232] [client 78.46.190.63:26894] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rakhomed.com.br"] [uri "/index.php"] [unique_id "aoSAkvcmepr5_nHgLbNOggAAAi8"], referer: http://rakhomed.com.br
[Tue Aug 18 12:56:02.445641 2026] [security2:error] [pid 67073:tid 67293] [client 4.223.164.152:4820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSAkvcmepr5_nHgLbNOhAAAAmw"]
[Tue Aug 18 12:56:02.470147 2026] [security2:error] [pid 67073:tid 67261] [client 68.155.154.236:16270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSAkvcmepr5_nHgLbNOhgAAAkw"]
[Tue Aug 18 12:56:02.473418 2026] [security2:error] [pid 66623:tid 66831] [client 20.226.56.190:23747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ip.php"] [unique_id "aoSAktO5rbWdOArH04KHuwAAAUs"]
[Tue Aug 18 12:56:02.483966 2026] [autoindex:error] [pid 66623:tid 66795] [client 20.226.6.191:32286] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/images/smilies/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:02.489901 2026] [security2:error] [pid 66623:tid 66873] [client 135.225.75.187:58321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/brc.php"] [unique_id "aoSAktO5rbWdOArH04KHvAAAAXU"]
[Tue Aug 18 12:56:02.499183 2026] [security2:error] [pid 66623:tid 66786] [client 20.226.6.191:32286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSAktO5rbWdOArH04KHvQAAAR4"]
[Tue Aug 18 12:56:02.504453 2026] [security2:error] [pid 67073:tid 67331] [client 68.155.156.252:5573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/images.php"] [unique_id "aoSAkvcmepr5_nHgLbNOhwAAApI"]
[Tue Aug 18 12:56:02.515148 2026] [security2:error] [pid 67073:tid 67317] [client 4.223.164.152:54221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/cabs.php"] [unique_id "aoSAkvcmepr5_nHgLbNOiQAAAoQ"]
[Tue Aug 18 12:56:02.518779 2026] [authz_core:error] [pid 67073:tid 67194] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:02.519026 2026] [authz_core:error] [pid 67073:tid 67194] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:02.551810 2026] [security2:error] [pid 66623:tid 66861] [client 135.225.78.186:13043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/wp-load.php"] [unique_id "aoSAktO5rbWdOArH04KHvgAAAWk"]
[Tue Aug 18 12:56:02.553235 2026] [security2:error] [pid 67073:tid 67236] [client 20.163.43.14:4374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp.php"] [unique_id "aoSAkvcmepr5_nHgLbNOiwAAAjM"]
[Tue Aug 18 12:56:02.557202 2026] [security2:error] [pid 67073:tid 67253] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/system_log.php"] [unique_id "aoSAkvcmepr5_nHgLbNOjQAAAkQ"]
[Tue Aug 18 12:56:02.562809 2026] [authz_core:error] [pid 67073:tid 67173] [remote 57.141.22.100:27296] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:02.563072 2026] [authz_core:error] [pid 67073:tid 67173] [remote 57.141.22.100:27296] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:02.571631 2026] [security2:error] [pid 66623:tid 66769] [client 158.23.17.4:41921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/payout.php"] [unique_id "aoSAktO5rbWdOArH04KHvwAAAQ0"]
[Tue Aug 18 12:56:02.575542 2026] [security2:error] [pid 67073:tid 67163] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/lmfi2.php"] [unique_id "aoSAkvcmepr5_nHgLbNOjgACP1c"]
[Tue Aug 18 12:56:02.586307 2026] [security2:error] [pid 67073:tid 67278] [client 20.151.109.219:64595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/hj.php"] [unique_id "aoSAkvcmepr5_nHgLbNOjwAAAl0"]
[Tue Aug 18 12:56:02.629816 2026] [security2:error] [pid 67073:tid 67310] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/34.php"] [unique_id "aoSAkvcmepr5_nHgLbNOkQAAAn0"]
[Tue Aug 18 12:56:02.685020 2026] [security2:error] [pid 67073:tid 67238] [client 213.35.127.232:51637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAkvcmepr5_nHgLbNOkwAAAjU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:02.759769 2026] [security2:error] [pid 67073:tid 67268] [client 52.173.121.69:24768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/Cachex.php"] [unique_id "aoSAkvcmepr5_nHgLbNOlQAAAlM"]
[Tue Aug 18 12:56:02.766980 2026] [security2:error] [pid 67073:tid 67283] [client 20.79.204.6:2236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAkvcmepr5_nHgLbNOlgAAAmI"]
[Tue Aug 18 12:56:02.779608 2026] [security2:error] [pid 67073:tid 67082] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/fd.php"] [unique_id "aoSAkvcmepr5_nHgLbNOlwACUgY"]
[Tue Aug 18 12:56:02.785768 2026] [security2:error] [pid 66623:tid 66820] [client 74.248.130.103:15389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/cgi-bin/admin.php"] [unique_id "aoSAktO5rbWdOArH04KHwQAAAUA"]
[Tue Aug 18 12:56:02.820715 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:02.821129 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:02.887747 2026] [security2:error] [pid 67073:tid 67308] [client 4.232.151.198:29550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/nw.php"] [unique_id "aoSAkvcmepr5_nHgLbNOnQAAAns"]
[Tue Aug 18 12:56:02.891886 2026] [security2:error] [pid 67073:tid 67297] [client 20.104.49.167:3582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAkvcmepr5_nHgLbNOngAAAnA"]
[Tue Aug 18 12:56:02.895454 2026] [security2:error] [pid 67073:tid 67306] [client 20.163.43.14:3040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/function/function.php"] [unique_id "aoSAkvcmepr5_nHgLbNOnwAAAnk"]
[Tue Aug 18 12:56:02.905670 2026] [security2:error] [pid 66623:tid 66826] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/he.php"] [unique_id "aoSAktO5rbWdOArH04KHwwAAAUY"]
[Tue Aug 18 12:56:02.918747 2026] [security2:error] [pid 67073:tid 67218] [client 20.151.109.219:24883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ij.php"] [unique_id "aoSAkvcmepr5_nHgLbNOoAAAAiE"]
[Tue Aug 18 12:56:02.932546 2026] [security2:error] [pid 67073:tid 67234] [client 4.223.164.152:4284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/gec.php"] [unique_id "aoSAkvcmepr5_nHgLbNOoQAAAjE"]
[Tue Aug 18 12:56:02.935797 2026] [security2:error] [pid 67073:tid 67325] [client 20.42.19.40:3334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/simple.php"] [unique_id "aoSAkvcmepr5_nHgLbNOogAAAow"]
[Tue Aug 18 12:56:02.966494 2026] [security2:error] [pid 66623:tid 66813] [client 20.79.204.6:2193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/0x.php"] [unique_id "aoSAktO5rbWdOArH04KHxQAAATk"]
[Tue Aug 18 12:56:02.969353 2026] [security2:error] [pid 67073:tid 67216] [client 135.225.78.186:13026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/155.php"] [unique_id "aoSAkvcmepr5_nHgLbNOpwAAAh8"]
[Tue Aug 18 12:56:02.985250 2026] [security2:error] [pid 67073:tid 67328] [client 4.223.164.152:46205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/insc.php"] [unique_id "aoSAkvcmepr5_nHgLbNOqQAAAo8"]
[Tue Aug 18 12:56:03.018647 2026] [security2:error] [pid 67073:tid 67106] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/info2.php"] [unique_id "aoSAk_cmepr5_nHgLbNOrgACWx4"]
[Tue Aug 18 12:56:03.077315 2026] [security2:error] [pid 67073:tid 67247] [client 20.42.19.40:2191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-act.php"] [unique_id "aoSAk_cmepr5_nHgLbNOsQAAAj4"]
[Tue Aug 18 12:56:03.112716 2026] [security2:error] [pid 67073:tid 67323] [client 192.141.172.134:59521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAk_cmepr5_nHgLbNOsgAAAoo"]
[Tue Aug 18 12:56:03.112983 2026] [security2:error] [pid 67073:tid 67323] [client 192.141.172.134:59521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAk_cmepr5_nHgLbNOsgAAAoo"]
[Tue Aug 18 12:56:03.136007 2026] [security2:error] [pid 67073:tid 67296] [client 20.91.215.254:20715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/alfa-rex1.php"] [unique_id "aoSAk_cmepr5_nHgLbNOswAAAm8"]
[Tue Aug 18 12:56:03.139321 2026] [security2:error] [pid 67073:tid 67285] [client 20.29.77.16:20843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/c99shell.php"] [unique_id "aoSAk_cmepr5_nHgLbNOtAAAAmQ"]
[Tue Aug 18 12:56:03.149716 2026] [security2:error] [pid 67073:tid 67312] [client 20.65.98.162:43814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/packed.php"] [unique_id "aoSAk_cmepr5_nHgLbNOtQAAAn8"]
[Tue Aug 18 12:56:03.161633 2026] [security2:error] [pid 67073:tid 67262] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gz.php"] [unique_id "aoSAk_cmepr5_nHgLbNOtwAAAk0"]
[Tue Aug 18 12:56:03.168079 2026] [security2:error] [pid 67073:tid 67315] [client 20.226.56.190:47140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/99.php"] [unique_id "aoSAk_cmepr5_nHgLbNOuAAAAoI"]
[Tue Aug 18 12:56:03.211867 2026] [security2:error] [pid 67073:tid 67246] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/t.php"] [unique_id "aoSAk_cmepr5_nHgLbNOuQAAAj0"]
[Tue Aug 18 12:56:03.226634 2026] [security2:error] [pid 66623:tid 66782] [client 20.151.109.219:53190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ud.php"] [unique_id "aoSAk9O5rbWdOArH04KHxwAAARo"]
[Tue Aug 18 12:56:03.227674 2026] [security2:error] [pid 67073:tid 67274] [client 20.215.241.237:62712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/av.php"] [unique_id "aoSAk_cmepr5_nHgLbNOugAAAlk"]
[Tue Aug 18 12:56:03.268186 2026] [security2:error] [pid 67073:tid 67191] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/sx.php"] [unique_id "aoSAk_cmepr5_nHgLbNOvQACG3M"]
[Tue Aug 18 12:56:03.296618 2026] [security2:error] [pid 66623:tid 66882] [client 20.116.17.175:57628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/ohct.php"] [unique_id "aoSAk9O5rbWdOArH04KHyAAAAX4"]
[Tue Aug 18 12:56:03.303486 2026] [security2:error] [pid 67073:tid 67229] [client 20.163.43.14:4449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSAk_cmepr5_nHgLbNOwAAAAiw"]
[Tue Aug 18 12:56:03.312184 2026] [security2:error] [pid 67073:tid 67301] [client 68.155.154.236:16367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSAk_cmepr5_nHgLbNOwQAAAnQ"]
[Tue Aug 18 12:56:03.322096 2026] [autoindex:error] [pid 67073:tid 67222] [client 172.202.39.151:50187] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:03.325322 2026] [security2:error] [pid 67073:tid 67259] [client 79.127.164.8:38656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/lib.model.schema.sql"] [unique_id "aoSAk_cmepr5_nHgLbNOwwAAAko"], referer: https://medihub.com.br/lib.model.schema.sql
[Tue Aug 18 12:56:03.330313 2026] [security2:error] [pid 67073:tid 67232] [client 20.226.56.190:47157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/er.php"] [unique_id "aoSAk_cmepr5_nHgLbNOxAAAAi8"]
[Tue Aug 18 12:56:03.366148 2026] [security2:error] [pid 67073:tid 67205] [client 4.223.164.152:4810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/sky.php"] [unique_id "aoSAk_cmepr5_nHgLbNOxgAAAhQ"]
[Tue Aug 18 12:56:03.375600 2026] [security2:error] [pid 67073:tid 67228] [client 68.155.156.252:8313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/ops.php"] [unique_id "aoSAk_cmepr5_nHgLbNOyAAAAis"]
[Tue Aug 18 12:56:03.380416 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.56.190:20357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/qk.php"] [unique_id "aoSAk_cmepr5_nHgLbNOyQAAAlg"]
[Tue Aug 18 12:56:03.384931 2026] [security2:error] [pid 66623:tid 66888] [client 86.120.159.145:6251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAk9O5rbWdOArH04KHyQAAAYQ"]
[Tue Aug 18 12:56:03.385066 2026] [security2:error] [pid 66623:tid 66888] [client 86.120.159.145:6251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAk9O5rbWdOArH04KHyQAAAYQ"]
[Tue Aug 18 12:56:03.387141 2026] [security2:error] [pid 67073:tid 67331] [client 20.65.69.59:3749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/php5.php"] [unique_id "aoSAk_cmepr5_nHgLbNOygAAApI"]
[Tue Aug 18 12:56:03.391523 2026] [security2:error] [pid 67073:tid 67317] [client 135.225.78.186:13025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/index.php"] [unique_id "aoSAk_cmepr5_nHgLbNOywAAAoQ"]
[Tue Aug 18 12:56:03.420550 2026] [authz_core:error] [pid 67073:tid 67175] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:03.420852 2026] [authz_core:error] [pid 67073:tid 67175] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:03.423561 2026] [security2:error] [pid 66623:tid 66801] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/nf.php"] [unique_id "aoSAk9O5rbWdOArH04KHygAAAS0"]
[Tue Aug 18 12:56:03.469377 2026] [security2:error] [pid 67073:tid 67213] [client 85.208.98.55:16384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "i-databi.com.br"] [uri "/robots.txt"] [unique_id "aoSAk_cmepr5_nHgLbNOzgAAAhw"]
[Tue Aug 18 12:56:03.469509 2026] [security2:error] [pid 67073:tid 67213] [client 85.208.98.55:16384] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "i-databi.com.br"] [uri "/robots.txt"] [unique_id "aoSAk_cmepr5_nHgLbNOzgAAAhw"]
[Tue Aug 18 12:56:03.475056 2026] [security2:error] [pid 67073:tid 67255] [client 158.158.74.177:16555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/mini.php"] [unique_id "aoSAk_cmepr5_nHgLbNOzwAAAkY"]
[Tue Aug 18 12:56:03.521509 2026] [security2:error] [pid 66623:tid 66768] [client 20.226.56.190:52050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSAk9O5rbWdOArH04KHywAAAQw"]
[Tue Aug 18 12:56:03.542011 2026] [security2:error] [pid 66623:tid 66881] [client 20.226.6.191:38267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/an.php"] [unique_id "aoSAk9O5rbWdOArH04KHzAAAAX0"]
[Tue Aug 18 12:56:03.569687 2026] [security2:error] [pid 66623:tid 66880] [client 20.151.109.219:21681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ip.php"] [unique_id "aoSAk9O5rbWdOArH04KHzQAAAXw"]
[Tue Aug 18 12:56:03.571154 2026] [security2:error] [pid 67073:tid 67252] [client 20.100.169.31:7850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/nw.php"] [unique_id "aoSAk_cmepr5_nHgLbNO1QAAAkM"]
[Tue Aug 18 12:56:03.571625 2026] [security2:error] [pid 67073:tid 67261] [client 20.79.204.6:2388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/222.php"] [unique_id "aoSAk_cmepr5_nHgLbNO1gAAAkw"]
[Tue Aug 18 12:56:03.608416 2026] [security2:error] [pid 67073:tid 67326] [client 172.202.39.151:50187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/403.php"] [unique_id "aoSAk_cmepr5_nHgLbNO1wAAAo0"]
[Tue Aug 18 12:56:03.629539 2026] [security2:error] [pid 66623:tid 66817] [client 158.23.17.4:10958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/Mailgun.php"] [unique_id "aoSAk9O5rbWdOArH04KHzgAAAT0"]
[Tue Aug 18 12:56:03.664075 2026] [security2:error] [pid 67073:tid 67156] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/nu.php"] [unique_id "aoSAk_cmepr5_nHgLbNO2wACZVA"]
[Tue Aug 18 12:56:03.680027 2026] [security2:error] [pid 67073:tid 67267] [client 20.171.51.14:33699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/hp.php"] [unique_id "aoSAk_cmepr5_nHgLbNO3QAAAlI"]
[Tue Aug 18 12:56:03.684064 2026] [security2:error] [pid 67073:tid 67226] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/xv.php"] [unique_id "aoSAk_cmepr5_nHgLbNO3gAAAik"]
[Tue Aug 18 12:56:03.690651 2026] [security2:error] [pid 67073:tid 67264] [client 20.100.169.31:12962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/inputs.php"] [unique_id "aoSAk_cmepr5_nHgLbNO3wAAAk8"]
[Tue Aug 18 12:56:03.707798 2026] [security2:error] [pid 67073:tid 67302] [client 213.35.127.232:51905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAk_cmepr5_nHgLbNO4QAAAnU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:03.709037 2026] [security2:error] [pid 67073:tid 67306] [client 68.155.154.236:16336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSAk_cmepr5_nHgLbNO4gAAAnk"]
[Tue Aug 18 12:56:03.776298 2026] [security2:error] [pid 67073:tid 67325] [client 74.248.130.103:36821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/simple.php"] [unique_id "aoSAk_cmepr5_nHgLbNO5QAAAow"]
[Tue Aug 18 12:56:03.804826 2026] [security2:error] [pid 67073:tid 67240] [client 20.215.241.237:40983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/k.php"] [unique_id "aoSAk_cmepr5_nHgLbNO6AAAAjc"]
[Tue Aug 18 12:56:03.807865 2026] [security2:error] [pid 66623:tid 66778] [client 135.225.78.186:13257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/aaa.php"] [unique_id "aoSAk9O5rbWdOArH04KHzwAAARY"]
[Tue Aug 18 12:56:03.814201 2026] [security2:error] [pid 67073:tid 67316] [client 4.223.164.152:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/sixxis.php"] [unique_id "aoSAk_cmepr5_nHgLbNO6QAAAoM"]
[Tue Aug 18 12:56:03.815807 2026] [security2:error] [pid 67073:tid 67309] [client 20.163.43.14:2945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSAk_cmepr5_nHgLbNO6gAAAnw"]
[Tue Aug 18 12:56:03.835091 2026] [security2:error] [pid 66623:tid 66856] [client 4.223.164.152:28515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/file.php"] [unique_id "aoSAk9O5rbWdOArH04KH0QAAAWQ"]
[Tue Aug 18 12:56:03.870931 2026] [security2:error] [pid 66623:tid 66807] [client 103.184.169.37:41808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAk9O5rbWdOArH04KH0gAAATM"]
[Tue Aug 18 12:56:03.871052 2026] [security2:error] [pid 66623:tid 66807] [client 103.184.169.37:41808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAk9O5rbWdOArH04KH0gAAATM"]
[Tue Aug 18 12:56:03.883867 2026] [security2:error] [pid 66623:tid 66767] [client 20.151.109.219:65000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/99.php"] [unique_id "aoSAk9O5rbWdOArH04KH0wAAAQs"]
[Tue Aug 18 12:56:03.891573 2026] [security2:error] [pid 67073:tid 67114] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ko.php"] [unique_id "aoSAk_cmepr5_nHgLbNO7gACaiY"]
[Tue Aug 18 12:56:03.897293 2026] [security2:error] [pid 67073:tid 67253] [client 158.158.34.183:11512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSAk_cmepr5_nHgLbNO7wAAAkQ"]
[Tue Aug 18 12:56:03.934251 2026] [security2:error] [pid 67073:tid 67209] [client 20.104.49.167:35261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAk_cmepr5_nHgLbNO8QAAAhg"]
[Tue Aug 18 12:56:03.945951 2026] [security2:error] [pid 67073:tid 67304] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/mx.php"] [unique_id "aoSAk_cmepr5_nHgLbNO8gAAAnc"]
[Tue Aug 18 12:56:03.981163 2026] [security2:error] [pid 67073:tid 67266] [client 52.173.121.69:24774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSAk_cmepr5_nHgLbNO9AAAAlE"]
[Tue Aug 18 12:56:03.996817 2026] [security2:error] [pid 66623:tid 66810] [client 20.91.215.254:20698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSAk9O5rbWdOArH04KH1gAAATY"]
[Tue Aug 18 12:56:04.024496 2026] [authz_core:error] [pid 67073:tid 67164] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:04.024924 2026] [authz_core:error] [pid 67073:tid 67164] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:04.086319 2026] [security2:error] [pid 67073:tid 67249] [client 20.29.77.16:47802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/profiler.php"] [unique_id "aoSAlPcmepr5_nHgLbNO-QAAAkA"]
[Tue Aug 18 12:56:04.091054 2026] [security2:error] [pid 67073:tid 67227] [client 93.152.221.213:64358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sindsecurpr.com.br"] [uri "/wp-login.php"] [unique_id "aoSAlPcmepr5_nHgLbNO-gAAAio"], referer: https://t.co/
[Tue Aug 18 12:56:04.107655 2026] [security2:error] [pid 67073:tid 67303] [client 158.158.74.177:2656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/minishell.php"] [unique_id "aoSAlPcmepr5_nHgLbNO_AAAAnY"]
[Tue Aug 18 12:56:04.108615 2026] [security2:error] [pid 67073:tid 67245] [client 68.155.156.252:19061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/coffexium.php"] [unique_id "aoSAlPcmepr5_nHgLbNO_QAAAjw"]
[Tue Aug 18 12:56:04.143805 2026] [security2:error] [pid 67073:tid 67120] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/pl.php"] [unique_id "aoSAlPcmepr5_nHgLbNO_wACeCw"]
[Tue Aug 18 12:56:04.182279 2026] [security2:error] [pid 67073:tid 67257] [client 135.225.75.187:62282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/file52.php"] [unique_id "aoSAlPcmepr5_nHgLbNPAAAAAkg"]
[Tue Aug 18 12:56:04.192507 2026] [security2:error] [pid 67073:tid 67237] [client 20.79.204.6:2186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/aa.php"] [unique_id "aoSAlPcmepr5_nHgLbNPAgAAAjQ"]
[Tue Aug 18 12:56:04.200559 2026] [security2:error] [pid 67073:tid 67229] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/45.php"] [unique_id "aoSAlPcmepr5_nHgLbNPAwAAAiw"]
[Tue Aug 18 12:56:04.208291 2026] [security2:error] [pid 67073:tid 67301] [client 20.163.43.14:3029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/ok.php"] [unique_id "aoSAlPcmepr5_nHgLbNPBAAAAnQ"]
[Tue Aug 18 12:56:04.210028 2026] [security2:error] [pid 66623:tid 66792] [client 103.120.71.157:7703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAlNO5rbWdOArH04KH1wAAASQ"]
[Tue Aug 18 12:56:04.210156 2026] [security2:error] [pid 66623:tid 66792] [client 103.120.71.157:7703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAlNO5rbWdOArH04KH1wAAASQ"]
[Tue Aug 18 12:56:04.225556 2026] [security2:error] [pid 67073:tid 67259] [client 135.225.78.186:13268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/FWAZ.php"] [unique_id "aoSAlPcmepr5_nHgLbNPBgAAAko"]
[Tue Aug 18 12:56:04.239489 2026] [security2:error] [pid 66623:tid 66803] [client 4.223.164.152:4224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/yj09.php"] [unique_id "aoSAlNO5rbWdOArH04KH2AAAAS8"]
[Tue Aug 18 12:56:04.251233 2026] [security2:error] [pid 67073:tid 67205] [client 20.151.109.219:59736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/er.php"] [unique_id "aoSAlPcmepr5_nHgLbNPCAAAAhQ"]
[Tue Aug 18 12:56:04.269125 2026] [security2:error] [pid 67073:tid 67295] [client 85.208.98.55:16384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "i-databi.com.br"] [uri "/poka-yoke-exemplos-praticos-para-evitar-erros/"] [unique_id "aoSAlPcmepr5_nHgLbNPCgAAAm4"]
[Tue Aug 18 12:56:04.269226 2026] [security2:error] [pid 67073:tid 67295] [client 85.208.98.55:16384] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "i-databi.com.br"] [uri "/poka-yoke-exemplos-praticos-para-evitar-erros/"] [unique_id "aoSAlPcmepr5_nHgLbNPCgAAAm4"]
[Tue Aug 18 12:56:04.282245 2026] [security2:error] [pid 67073:tid 67230] [client 5.161.177.47:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "atekrefrigeracao.com.br"] [uri "/index.php"] [unique_id "aoSAk_cmepr5_nHgLbNO2QACLW0"], referer: https://atekrefrigeracao.com.br/
[Tue Aug 18 12:56:04.290305 2026] [autoindex:error] [pid 67073:tid 67243] [client 20.226.6.191:36354] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:04.325307 2026] [security2:error] [pid 67073:tid 67215] [client 20.226.6.191:36354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/404.php"] [unique_id "aoSAlPcmepr5_nHgLbNPDgAAAh4"]
[Tue Aug 18 12:56:04.328875 2026] [authz_core:error] [pid 67073:tid 67134] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:04.329336 2026] [authz_core:error] [pid 67073:tid 67134] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:04.343086 2026] [security2:error] [pid 67073:tid 67236] [client 4.223.164.152:28505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/dex.php"] [unique_id "aoSAlPcmepr5_nHgLbNPEAAAAjM"]
[Tue Aug 18 12:56:04.391300 2026] [security2:error] [pid 67073:tid 67135] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/env.php"] [unique_id "aoSAlPcmepr5_nHgLbNPEgACXjs"]
[Tue Aug 18 12:56:04.419004 2026] [security2:error] [pid 66623:tid 66806] [client 20.42.19.40:2938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSAlNO5rbWdOArH04KH2gAAATI"]
[Tue Aug 18 12:56:04.470751 2026] [security2:error] [pid 67073:tid 67332] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/wy.php"] [unique_id "aoSAlPcmepr5_nHgLbNPFAAAApM"]
[Tue Aug 18 12:56:04.479119 2026] [security2:error] [pid 66623:tid 66875] [client 20.100.169.31:18810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/admin.php"] [unique_id "aoSAlNO5rbWdOArH04KH2wAAAXc"]
[Tue Aug 18 12:56:04.560692 2026] [security2:error] [pid 67073:tid 67264] [client 20.151.109.219:24840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/qk.php"] [unique_id "aoSAlPcmepr5_nHgLbNPFwAAAk8"]
[Tue Aug 18 12:56:04.580828 2026] [security2:error] [pid 66623:tid 66772] [client 20.65.69.59:3764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/Black.php"] [unique_id "aoSAlNO5rbWdOArH04KH3gAAARA"]
[Tue Aug 18 12:56:04.583441 2026] [security2:error] [pid 67073:tid 67281] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/term.php"] [unique_id "aoSAlPcmepr5_nHgLbNPGQAAAmA"]
[Tue Aug 18 12:56:04.584847 2026] [security2:error] [pid 67073:tid 67320] [client 20.100.169.31:33557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/xleet.php"] [unique_id "aoSAlPcmepr5_nHgLbNPGgAAAoc"]
[Tue Aug 18 12:56:04.601191 2026] [security2:error] [pid 66623:tid 66776] [client 74.248.130.103:14434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/chosen.php"] [unique_id "aoSAlNO5rbWdOArH04KH3wAAARQ"]
[Tue Aug 18 12:56:04.602825 2026] [security2:error] [pid 67073:tid 67104] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/mz.php"] [unique_id "aoSAlPcmepr5_nHgLbNPHAACeRw"]
[Tue Aug 18 12:56:04.616983 2026] [security2:error] [pid 66623:tid 66773] [client 20.226.6.191:59948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-login.php"] [unique_id "aoSAlNO5rbWdOArH04KH4AAAARE"]
[Tue Aug 18 12:56:04.643083 2026] [security2:error] [pid 66623:tid 66836] [client 135.225.78.186:13285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/site.php"] [unique_id "aoSAlNO5rbWdOArH04KH4gAAAVA"]
[Tue Aug 18 12:56:04.647577 2026] [security2:error] [pid 67073:tid 67256] [client 138.36.100.162:43228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAlPcmepr5_nHgLbNPHgAAAkc"]
[Tue Aug 18 12:56:04.647666 2026] [security2:error] [pid 67073:tid 67256] [client 138.36.100.162:43228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAlPcmepr5_nHgLbNPHgAAAkc"]
[Tue Aug 18 12:56:04.661593 2026] [security2:error] [pid 67073:tid 67270] [client 20.163.43.14:4412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/item.php"] [unique_id "aoSAlPcmepr5_nHgLbNPIAAAAlU"]
[Tue Aug 18 12:56:04.666314 2026] [security2:error] [pid 67073:tid 67206] [client 4.223.164.152:4834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/k.php"] [unique_id "aoSAlPcmepr5_nHgLbNPIQAAAhU"]
[Tue Aug 18 12:56:04.667626 2026] [security2:error] [pid 66623:tid 66870] [client 20.226.56.190:3066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/fs.php"] [unique_id "aoSAlNO5rbWdOArH04KH4wAAAXI"]
[Tue Aug 18 12:56:04.712237 2026] [security2:error] [pid 67073:tid 67286] [client 20.91.215.254:12007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/xmrlpc.php"] [unique_id "aoSAlPcmepr5_nHgLbNPIgAAAmU"]
[Tue Aug 18 12:56:04.724171 2026] [security2:error] [pid 67073:tid 67277] [client 213.35.127.232:52164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAlPcmepr5_nHgLbNPJAAAAlw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:04.725899 2026] [security2:error] [pid 66623:tid 66871] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/f.php"] [unique_id "aoSAlNO5rbWdOArH04KH5QAAAXM"]
[Tue Aug 18 12:56:04.734109 2026] [security2:error] [pid 67073:tid 67325] [client 132.196.61.152:61000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/sf.php"] [unique_id "aoSAlPcmepr5_nHgLbNPJQAAAow"]
[Tue Aug 18 12:56:04.770492 2026] [security2:error] [pid 67073:tid 67241] [client 4.223.164.152:46144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/key.php"] [unique_id "aoSAlPcmepr5_nHgLbNPJwAAAjg"]
[Tue Aug 18 12:56:04.782123 2026] [security2:error] [pid 67073:tid 67316] [client 20.42.19.40:2902] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-admin/js/"] [unique_id "aoSAlPcmepr5_nHgLbNPKAAAAoM"]
[Tue Aug 18 12:56:04.801454 2026] [security2:error] [pid 67073:tid 67297] [client 20.79.204.6:2225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/abcd.php"] [unique_id "aoSAlPcmepr5_nHgLbNPKQAAAnA"]
[Tue Aug 18 12:56:04.812371 2026] [security2:error] [pid 67073:tid 67172] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ft.php"] [unique_id "aoSAlPcmepr5_nHgLbNPKgACH2A"]
[Tue Aug 18 12:56:04.844398 2026] [security2:error] [pid 67073:tid 67291] [client 20.116.17.175:57601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/ot.php"] [unique_id "aoSAlPcmepr5_nHgLbNPLAAAAmo"]
[Tue Aug 18 12:56:04.847085 2026] [security2:error] [pid 67073:tid 67302] [client 158.158.74.177:2644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/mm.php"] [unique_id "aoSAlPcmepr5_nHgLbNPLQAAAnU"]
[Tue Aug 18 12:56:04.847329 2026] [security2:error] [pid 66623:tid 66883] [client 20.151.109.219:24847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSAlNO5rbWdOArH04KH5wAAAX8"]
[Tue Aug 18 12:56:04.862048 2026] [security2:error] [pid 67073:tid 67219] [client 20.226.6.191:59931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAlPcmepr5_nHgLbNPLgAAAiI"]
[Tue Aug 18 12:56:04.899060 2026] [security2:error] [pid 67073:tid 67209] [client 158.23.17.4:38899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/oauth.php"] [unique_id "aoSAlPcmepr5_nHgLbNPLwAAAhg"]
[Tue Aug 18 12:56:04.997909 2026] [security2:error] [pid 66623:tid 66824] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/30.php"] [unique_id "aoSAlNO5rbWdOArH04KH6AAAAUQ"]
[Tue Aug 18 12:56:05.044993 2026] [security2:error] [pid 67073:tid 67296] [client 68.155.154.236:16371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSAlfcmepr5_nHgLbNPNAAAAm8"]
[Tue Aug 18 12:56:05.047668 2026] [security2:error] [pid 67073:tid 67089] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/h.php"] [unique_id "aoSAlfcmepr5_nHgLbNPNQACZA0"]
[Tue Aug 18 12:56:05.061554 2026] [security2:error] [pid 66623:tid 66781] [client 135.225.78.186:40819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/ccc.php"] [unique_id "aoSAldO5rbWdOArH04KH6QAAARk"]
[Tue Aug 18 12:56:05.095172 2026] [security2:error] [pid 67073:tid 67318] [client 4.223.164.152:4857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/w.php"] [unique_id "aoSAlfcmepr5_nHgLbNPNgAAAoU"]
[Tue Aug 18 12:56:05.162339 2026] [security2:error] [pid 67073:tid 67283] [client 20.151.109.219:65006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/fs.php"] [unique_id "aoSAlfcmepr5_nHgLbNPOAAAAmI"]
[Tue Aug 18 12:56:05.174771 2026] [security2:error] [pid 66623:tid 66884] [client 5.31.227.224:30445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAldO5rbWdOArH04KH6gAAAYA"]
[Tue Aug 18 12:56:05.178777 2026] [security2:error] [pid 66623:tid 66884] [client 5.31.227.224:30445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAldO5rbWdOArH04KH6gAAAYA"]
[Tue Aug 18 12:56:05.222907 2026] [security2:error] [pid 66623:tid 66848] [client 4.223.164.152:39789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/kir.php"] [unique_id "aoSAldO5rbWdOArH04KH6wAAAVw"]
[Tue Aug 18 12:56:05.227329 2026] [authz_core:error] [pid 67073:tid 67118] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:05.227610 2026] [authz_core:error] [pid 67073:tid 67118] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:05.232707 2026] [security2:error] [pid 67073:tid 67246] [client 20.51.153.15:9140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/nu.php"] [unique_id "aoSAlfcmepr5_nHgLbNPOwAAAj0"]
[Tue Aug 18 12:56:05.245495 2026] [security2:error] [pid 67073:tid 67245] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/pu.php"] [unique_id "aoSAlfcmepr5_nHgLbNPPAAAAjw"]
[Tue Aug 18 12:56:05.261931 2026] [security2:error] [pid 67073:tid 67158] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/40.php"] [unique_id "aoSAlfcmepr5_nHgLbNPPQACWVI"]
[Tue Aug 18 12:56:05.264808 2026] [security2:error] [pid 67073:tid 67305] [client 135.225.75.187:9804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/sxdfrt.php"] [unique_id "aoSAlfcmepr5_nHgLbNPPgAAAng"]
[Tue Aug 18 12:56:05.267782 2026] [security2:error] [pid 67073:tid 67313] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/test.php"] [unique_id "aoSAlfcmepr5_nHgLbNPPwAAAoA"]
[Tue Aug 18 12:56:05.296304 2026] [security2:error] [pid 66623:tid 66887] [client 20.226.56.190:45035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/rb.php"] [unique_id "aoSAldO5rbWdOArH04KH7AAAAYM"]
[Tue Aug 18 12:56:05.314457 2026] [security2:error] [pid 67073:tid 67278] [client 74.248.18.37:28831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/ncx.php"] [unique_id "aoSAlfcmepr5_nHgLbNPQgAAAl0"]
[Tue Aug 18 12:56:05.342160 2026] [security2:error] [pid 67073:tid 67292] [client 20.100.169.31:47387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp.php"] [unique_id "aoSAlfcmepr5_nHgLbNPQwAAAms"]
[Tue Aug 18 12:56:05.369200 2026] [security2:error] [pid 67073:tid 67095] [remote 115.146.125.52:43470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ihostiweb.com"] [uri "/wp-login.php"] [unique_id "aoSAlfcmepr5_nHgLbNPRAACMRM"]
[Tue Aug 18 12:56:05.396002 2026] [security2:error] [pid 67073:tid 67295] [client 20.29.77.16:52799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/findes.php"] [unique_id "aoSAlfcmepr5_nHgLbNPRwAAAm4"]
[Tue Aug 18 12:56:05.396144 2026] [security2:error] [pid 67073:tid 67205] [client 20.171.51.14:62517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/wx.php"] [unique_id "aoSAlfcmepr5_nHgLbNPRgAAAhQ"]
[Tue Aug 18 12:56:05.420488 2026] [security2:error] [pid 67073:tid 67315] [client 20.91.215.254:12113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-admin/user/12.php"] [unique_id "aoSAlfcmepr5_nHgLbNPSQAAAoI"]
[Tue Aug 18 12:56:05.442524 2026] [security2:error] [pid 67073:tid 67322] [client 20.215.241.237:45778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/82.php"] [unique_id "aoSAlfcmepr5_nHgLbNPSwAAAok"]
[Tue Aug 18 12:56:05.443622 2026] [security2:error] [pid 67073:tid 67250] [client 20.151.109.219:12913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/rb.php"] [unique_id "aoSAlfcmepr5_nHgLbNPTAAAAkE"]
[Tue Aug 18 12:56:05.451698 2026] [security2:error] [pid 67073:tid 67303] [client 20.79.204.6:2209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/admin.php"] [unique_id "aoSAlfcmepr5_nHgLbNPTQAAAnY"]
[Tue Aug 18 12:56:05.483415 2026] [security2:error] [pid 67073:tid 67215] [client 135.225.78.186:40768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/admin.php"] [unique_id "aoSAlfcmepr5_nHgLbNPTwAAAh4"]
[Tue Aug 18 12:56:05.495655 2026] [security2:error] [pid 67073:tid 67271] [client 20.104.49.167:36311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAlfcmepr5_nHgLbNPUgAAAlY"]
[Tue Aug 18 12:56:05.502691 2026] [security2:error] [pid 67073:tid 67217] [client 158.158.74.177:16556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAlfcmepr5_nHgLbNPUwAAAiA"]
[Tue Aug 18 12:56:05.503774 2026] [security2:error] [pid 67073:tid 67211] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ry.php"] [unique_id "aoSAlfcmepr5_nHgLbNPVAAAAho"]
[Tue Aug 18 12:56:05.523686 2026] [security2:error] [pid 67073:tid 67321] [client 4.223.164.152:4818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/fpwch.php"] [unique_id "aoSAlfcmepr5_nHgLbNPVgAAAog"]
[Tue Aug 18 12:56:05.531320 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:05.531628 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:05.531852 2026] [security2:error] [pid 67073:tid 67105] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ee.php"] [unique_id "aoSAlfcmepr5_nHgLbNPVwACWh0"]
[Tue Aug 18 12:56:05.531965 2026] [security2:error] [pid 67073:tid 67299] [client 74.248.130.103:36815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/als.php"] [unique_id "aoSAlfcmepr5_nHgLbNPWAAAAnI"]
[Tue Aug 18 12:56:05.543216 2026] [security2:error] [pid 67073:tid 67289] [client 68.155.156.252:8310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAlfcmepr5_nHgLbNPWQAAAmg"]
[Tue Aug 18 12:56:05.589699 2026] [security2:error] [pid 67073:tid 67222] [client 20.215.241.237:37305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/images.php"] [unique_id "aoSAlfcmepr5_nHgLbNPXAAAAiU"]
[Tue Aug 18 12:56:05.607907 2026] [security2:error] [pid 67073:tid 67207] [client 20.226.56.190:45008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/37.php"] [unique_id "aoSAlfcmepr5_nHgLbNPXQAAAhY"]
[Tue Aug 18 12:56:05.617973 2026] [security2:error] [pid 67073:tid 67212] [client 4.232.151.198:40240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/xleet.php"] [unique_id "aoSAlfcmepr5_nHgLbNPXgAAAhs"]
[Tue Aug 18 12:56:05.630062 2026] [security2:error] [pid 67073:tid 67287] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/test1.php"] [unique_id "aoSAlfcmepr5_nHgLbNPXwAAAmY"]
[Tue Aug 18 12:56:05.658418 2026] [security2:error] [pid 67073:tid 67281] [client 4.223.164.152:28503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/nofile.php"] [unique_id "aoSAlfcmepr5_nHgLbNPYAAAAmA"]
[Tue Aug 18 12:56:05.739084 2026] [security2:error] [pid 67073:tid 67206] [client 52.173.121.69:16505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-2019.php"] [unique_id "aoSAlfcmepr5_nHgLbNPZAAAAhU"]
[Tue Aug 18 12:56:05.741519 2026] [security2:error] [pid 67073:tid 67230] [client 213.35.127.232:52443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAlfcmepr5_nHgLbNPZQAAAi0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:05.745650 2026] [security2:error] [pid 67073:tid 67220] [client 20.151.109.219:21649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/37.php"] [unique_id "aoSAlfcmepr5_nHgLbNPZgAAAiM"]
[Tue Aug 18 12:56:05.755899 2026] [security2:error] [pid 67073:tid 67218] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/pm.php"] [unique_id "aoSAlfcmepr5_nHgLbNPZwAAAiE"]
[Tue Aug 18 12:56:05.804872 2026] [security2:error] [pid 67073:tid 67277] [client 68.155.154.236:16256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSAlfcmepr5_nHgLbNPaQAAAlw"]
[Tue Aug 18 12:56:05.813802 2026] [security2:error] [pid 67073:tid 67198] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ak.php"] [unique_id "aoSAlfcmepr5_nHgLbNPagACN3o"]
[Tue Aug 18 12:56:05.858995 2026] [security2:error] [pid 67073:tid 67297] [client 20.226.56.190:31642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/md.php"] [unique_id "aoSAlfcmepr5_nHgLbNPbQAAAnA"]
[Tue Aug 18 12:56:05.901856 2026] [security2:error] [pid 67073:tid 67219] [client 135.225.78.186:40828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/reviall.php"] [unique_id "aoSAlfcmepr5_nHgLbNPbwAAAiI"]
[Tue Aug 18 12:56:05.956647 2026] [security2:error] [pid 66623:tid 66873] [client 4.223.164.152:4851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/FWAZ.php"] [unique_id "aoSAldO5rbWdOArH04KH8QAAAXU"]
[Tue Aug 18 12:56:05.958616 2026] [security2:error] [pid 67073:tid 67214] [client 20.171.51.14:51797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/dj.php"] [unique_id "aoSAlfcmepr5_nHgLbNPcQAAAh0"]
[Tue Aug 18 12:56:06.022127 2026] [authz_core:error] [pid 66623:tid 66700] [remote 57.141.22.34:61818] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:06.022423 2026] [authz_core:error] [pid 66623:tid 66700] [remote 57.141.22.34:61818] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:06.061225 2026] [security2:error] [pid 67073:tid 67249] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/dr.php"] [unique_id "aoSAlvcmepr5_nHgLbNPdgAAAkA"]
[Tue Aug 18 12:56:06.071323 2026] [security2:error] [pid 67073:tid 67227] [client 20.151.109.219:53232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/md.php"] [unique_id "aoSAlvcmepr5_nHgLbNPeAAAAio"]
[Tue Aug 18 12:56:06.078661 2026] [autoindex:error] [pid 67073:tid 67282] [client 20.226.6.191:32292] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:06.087050 2026] [security2:error] [pid 67073:tid 67142] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/test_info.php"] [unique_id "aoSAlvcmepr5_nHgLbNPeQACPUI"]
[Tue Aug 18 12:56:06.097487 2026] [security2:error] [pid 67073:tid 67245] [client 20.104.49.167:35223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/av.php"] [unique_id "aoSAlvcmepr5_nHgLbNPegAAAjw"]
[Tue Aug 18 12:56:06.124324 2026] [security2:error] [pid 67073:tid 67237] [client 20.42.19.40:2216] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-admin/js/widgets/"] [unique_id "aoSAlvcmepr5_nHgLbNPfgAAAjQ"]
[Tue Aug 18 12:56:06.146289 2026] [security2:error] [pid 67073:tid 67229] [client 20.226.56.190:3054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/iy.php"] [unique_id "aoSAlvcmepr5_nHgLbNPgQAAAiw"]
[Tue Aug 18 12:56:06.146950 2026] [autoindex:error] [pid 67073:tid 67301] [client 172.202.39.151:65226] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:06.150853 2026] [security2:error] [pid 67073:tid 67327] [client 157.20.138.62:59811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAlvcmepr5_nHgLbNPggAAAo4"]
[Tue Aug 18 12:56:06.150956 2026] [security2:error] [pid 67073:tid 67327] [client 157.20.138.62:59811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAlvcmepr5_nHgLbNPggAAAo4"]
[Tue Aug 18 12:56:06.185673 2026] [security2:error] [pid 67073:tid 67259] [client 104.209.144.33:29830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSAlvcmepr5_nHgLbNPgwAAAko"]
[Tue Aug 18 12:56:06.216601 2026] [autoindex:error] [pid 67073:tid 67329] [client 20.226.6.191:32292] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:06.223220 2026] [security2:error] [pid 67073:tid 67205] [client 20.226.6.191:32292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wso.php"] [unique_id "aoSAlvcmepr5_nHgLbNPhgAAAhQ"]
[Tue Aug 18 12:56:06.241204 2026] [security2:error] [pid 67073:tid 67307] [client 158.158.74.177:2672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/ms-themes.php"] [unique_id "aoSAlvcmepr5_nHgLbNPiAAAAno"]
[Tue Aug 18 12:56:06.252259 2026] [autoindex:error] [pid 67073:tid 67234] [client 172.202.39.151:12687] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:06.289239 2026] [security2:error] [pid 67073:tid 67238] [client 20.100.169.31:7657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/155.php"] [unique_id "aoSAlvcmepr5_nHgLbNPiwAAAjU"]
[Tue Aug 18 12:56:06.290952 2026] [security2:error] [pid 67073:tid 67271] [client 20.116.17.175:57652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/v5.php"] [unique_id "aoSAlvcmepr5_nHgLbNPjAAAAlY"]
[Tue Aug 18 12:56:06.292110 2026] [security2:error] [pid 67073:tid 67217] [client 135.225.75.187:62308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/path.php"] [unique_id "aoSAlvcmepr5_nHgLbNPjQAAAiA"]
[Tue Aug 18 12:56:06.292560 2026] [security2:error] [pid 67073:tid 67211] [client 68.155.156.252:36342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/sf.php"] [unique_id "aoSAlvcmepr5_nHgLbNPjgAAAho"]
[Tue Aug 18 12:56:06.324703 2026] [security2:error] [pid 66623:tid 66846] [client 20.215.241.237:49243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/ops.php"] [unique_id "aoSAltO5rbWdOArH04KH8wAAAVo"]
[Tue Aug 18 12:56:06.326998 2026] [security2:error] [pid 67073:tid 67275] [client 4.223.164.152:54237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/fling.php"] [unique_id "aoSAlvcmepr5_nHgLbNPkAAAAlo"]
[Tue Aug 18 12:56:06.327292 2026] [security2:error] [pid 67073:tid 67299] [client 135.225.78.186:13037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/nope.php"] [unique_id "aoSAlvcmepr5_nHgLbNPkQAAAnI"]
[Tue Aug 18 12:56:06.330711 2026] [security2:error] [pid 67073:tid 67213] [client 74.248.130.103:38688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/nox.php"] [unique_id "aoSAlvcmepr5_nHgLbNPkgAAAhw"]
[Tue Aug 18 12:56:06.331197 2026] [security2:error] [pid 67073:tid 67289] [client 20.91.215.254:12017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/ku.php"] [unique_id "aoSAlvcmepr5_nHgLbNPlAAAAmg"]
[Tue Aug 18 12:56:06.331379 2026] [security2:error] [pid 67073:tid 67174] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/14.php"] [unique_id "aoSAlvcmepr5_nHgLbNPkwACP2I"]
[Tue Aug 18 12:56:06.333949 2026] [security2:error] [pid 67073:tid 67255] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ts.php"] [unique_id "aoSAlvcmepr5_nHgLbNPlQAAAkY"]
[Tue Aug 18 12:56:06.357893 2026] [security2:error] [pid 67073:tid 67244] [client 68.155.154.236:16349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSAlvcmepr5_nHgLbNPlgAAAjs"]
[Tue Aug 18 12:56:06.383713 2026] [security2:error] [pid 67073:tid 67293] [client 4.223.164.152:4836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/blurbs.php"] [unique_id "aoSAlvcmepr5_nHgLbNPmAAAAmw"]
[Tue Aug 18 12:56:06.422993 2026] [security2:error] [pid 67073:tid 67292] [client 4.232.151.198:34248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/wp.php"] [unique_id "aoSAlvcmepr5_nHgLbNPmQAAAms"]
[Tue Aug 18 12:56:06.446838 2026] [autoindex:error] [pid 67073:tid 67222] [client 172.202.39.151:65226] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:06.448609 2026] [security2:error] [pid 67073:tid 67224] [client 20.51.153.15:8727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/pl.php"] [unique_id "aoSAlvcmepr5_nHgLbNPnAAAAic"]
[Tue Aug 18 12:56:06.460629 2026] [security2:error] [pid 67073:tid 67243] [client 20.151.109.219:59768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/iy.php"] [unique_id "aoSAlvcmepr5_nHgLbNPnQAAAjo"]
[Tue Aug 18 12:56:06.462538 2026] [security2:error] [pid 67073:tid 67251] [client 20.250.13.23:19518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/u.php"] [unique_id "aoSAlvcmepr5_nHgLbNPngAAAkI"]
[Tue Aug 18 12:56:06.482482 2026] [security2:error] [pid 67073:tid 67208] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAlvcmepr5_nHgLbNPigACFw4"]
[Tue Aug 18 12:56:06.487497 2026] [security2:error] [pid 67073:tid 67247] [client 20.100.169.31:29619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/goods.php"] [unique_id "aoSAlvcmepr5_nHgLbNPoQAAAj4"]
[Tue Aug 18 12:56:06.525019 2026] [security2:error] [pid 67073:tid 67226] [client 20.42.19.40:2704] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-admin/maint/"] [unique_id "aoSAlvcmepr5_nHgLbNPowAAAik"]
[Tue Aug 18 12:56:06.530702 2026] [security2:error] [pid 67073:tid 67149] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/tk.php"] [unique_id "aoSAlvcmepr5_nHgLbNPpAACT0k"]
[Tue Aug 18 12:56:06.537062 2026] [security2:error] [pid 67073:tid 67223] [client 132.196.61.152:61043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/xx.php"] [unique_id "aoSAlvcmepr5_nHgLbNPpQAAAiY"]
[Tue Aug 18 12:56:06.562182 2026] [security2:error] [pid 67073:tid 67230] [client 172.202.39.151:12687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/404.php"] [unique_id "aoSAlvcmepr5_nHgLbNPpwAAAi0"]
[Tue Aug 18 12:56:06.595105 2026] [security2:error] [pid 67073:tid 67210] [client 172.202.39.151:65226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/gecko.php"] [unique_id "aoSAlvcmepr5_nHgLbNPqAAAAhk"]
[Tue Aug 18 12:56:06.595818 2026] [security2:error] [pid 66623:tid 66867] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/53.php"] [unique_id "aoSAltO5rbWdOArH04KH9QAAAW8"]
[Tue Aug 18 12:56:06.608633 2026] [security2:error] [pid 67073:tid 67240] [client 20.226.56.190:47114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/og.php"] [unique_id "aoSAlvcmepr5_nHgLbNPqgAAAjc"]
[Tue Aug 18 12:56:06.626116 2026] [security2:error] [pid 67073:tid 67280] [client 114.5.214.109:49808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAlvcmepr5_nHgLbNPqwAAAl8"]
[Tue Aug 18 12:56:06.626238 2026] [security2:error] [pid 67073:tid 67280] [client 114.5.214.109:49808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAlvcmepr5_nHgLbNPqwAAAl8"]
[Tue Aug 18 12:56:06.637755 2026] [security2:error] [pid 67073:tid 67276] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/tfm.php"] [unique_id "aoSAlvcmepr5_nHgLbNPrAAAAls"]
[Tue Aug 18 12:56:06.687060 2026] [security2:error] [pid 66623:tid 66874] [client 158.23.17.4:63971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/timeclock.php"] [unique_id "aoSAltO5rbWdOArH04KH9wAAAXY"]
[Tue Aug 18 12:56:06.723074 2026] [security2:error] [pid 66623:tid 66860] [client 20.226.56.190:23744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/lp.php"] [unique_id "aoSAltO5rbWdOArH04KH-QAAAWg"]
[Tue Aug 18 12:56:06.733663 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:06.734036 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:06.744392 2026] [security2:error] [pid 67073:tid 67214] [client 135.225.78.186:13020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/nope.php"] [unique_id "aoSAlvcmepr5_nHgLbNPrwAAAh0"]
[Tue Aug 18 12:56:06.758479 2026] [security2:error] [pid 66623:tid 66783] [client 213.35.127.232:52733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAltO5rbWdOArH04KH-gAAARs"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:06.762822 2026] [security2:error] [pid 67073:tid 67129] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/hp.php"] [unique_id "aoSAlvcmepr5_nHgLbNPsQACbzU"]
[Tue Aug 18 12:56:06.776794 2026] [security2:error] [pid 66623:tid 66878] [client 20.226.6.191:32301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/sf.php"] [unique_id "aoSAltO5rbWdOArH04KH-wAAAXo"]
[Tue Aug 18 12:56:06.796889 2026] [security2:error] [pid 66623:tid 66808] [client 149.34.210.141:51839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAltO5rbWdOArH04KH_QAAATQ"]
[Tue Aug 18 12:56:06.798138 2026] [security2:error] [pid 67073:tid 67283] [client 20.151.109.219:21686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/og.php"] [unique_id "aoSAlvcmepr5_nHgLbNPswAAAmI"]
[Tue Aug 18 12:56:06.816912 2026] [security2:error] [pid 66623:tid 66854] [client 4.223.164.152:4236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/100.php"] [unique_id "aoSAltO5rbWdOArH04KH_gAAAWI"]
[Tue Aug 18 12:56:06.857914 2026] [security2:error] [pid 67073:tid 67274] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/lq.php"] [unique_id "aoSAlvcmepr5_nHgLbNPtQAAAlk"]
[Tue Aug 18 12:56:06.867978 2026] [security2:error] [pid 67073:tid 67257] [client 4.223.164.152:28529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/zoo1.php"] [unique_id "aoSAlvcmepr5_nHgLbNPtwAAAkg"]
[Tue Aug 18 12:56:06.877034 2026] [security2:error] [pid 67073:tid 67278] [client 74.248.130.103:36805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/file59.php"] [unique_id "aoSAlvcmepr5_nHgLbNPuQAAAl0"]
[Tue Aug 18 12:56:06.919510 2026] [security2:error] [pid 66623:tid 66814] [client 52.238.210.254:9042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/buy.php"] [unique_id "aoSAltO5rbWdOArH04KH_wAAATo"]
[Tue Aug 18 12:56:06.926464 2026] [security2:error] [pid 67073:tid 67229] [client 20.79.204.6:2386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAlvcmepr5_nHgLbNPugAAAiw"]
[Tue Aug 18 12:56:06.928682 2026] [security2:error] [pid 66623:tid 66796] [client 104.209.144.33:33706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSAltO5rbWdOArH04KIAQAAASg"]
[Tue Aug 18 12:56:06.929227 2026] [security2:error] [pid 66623:tid 66869] [client 172.182.200.96:14092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSAltO5rbWdOArH04KIAgAAAXE"]
[Tue Aug 18 12:56:06.931868 2026] [authz_core:error] [pid 66623:tid 66644] [remote 57.141.22.127:64090] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:06.932134 2026] [authz_core:error] [pid 66623:tid 66644] [remote 57.141.22.127:64090] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:06.935569 2026] [security2:error] [pid 66623:tid 66886] [client 20.116.17.175:11215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoSAltO5rbWdOArH04KIAwAAAYI"]
[Tue Aug 18 12:56:06.942083 2026] [security2:error] [pid 67073:tid 67301] [client 20.104.49.167:19384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/images.php"] [unique_id "aoSAlvcmepr5_nHgLbNPuwAAAnQ"]
[Tue Aug 18 12:56:06.948453 2026] [security2:error] [pid 66623:tid 66784] [client 20.42.19.40:2724] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-admin/"] [unique_id "aoSAltO5rbWdOArH04KIBAAAARw"]
[Tue Aug 18 12:56:06.977653 2026] [security2:error] [pid 67073:tid 67098] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/wx.php"] [unique_id "aoSAlvcmepr5_nHgLbNPvQACKxY"]
[Tue Aug 18 12:56:06.981988 2026] [security2:error] [pid 67073:tid 67329] [client 20.171.51.14:16745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/fa.php"] [unique_id "aoSAlvcmepr5_nHgLbNPvgAAApA"]
[Tue Aug 18 12:56:07.057023 2026] [security2:error] [pid 66623:tid 66843] [client 135.225.75.187:9801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wpo.php"] [unique_id "aoSAl9O5rbWdOArH04KIBQAAAVc"]
[Tue Aug 18 12:56:07.063655 2026] [security2:error] [pid 67073:tid 67273] [client 68.155.156.252:8284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/k.php"] [unique_id "aoSAl_cmepr5_nHgLbNPxAAAAlg"]
[Tue Aug 18 12:56:07.072411 2026] [security2:error] [pid 66623:tid 66808] [client 149.34.210.141:51839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAltO5rbWdOArH04KH_QAAATQ"]
[Tue Aug 18 12:56:07.077042 2026] [security2:error] [pid 66623:tid 66785] [client 20.226.56.190:2191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ey.php"] [unique_id "aoSAl9O5rbWdOArH04KIBgAAAR0"]
[Tue Aug 18 12:56:07.089478 2026] [security2:error] [pid 67073:tid 67307] [client 20.51.153.15:8789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/mz.php"] [unique_id "aoSAl_cmepr5_nHgLbNPxgAAAno"]
[Tue Aug 18 12:56:07.089926 2026] [security2:error] [pid 67073:tid 67282] [client 158.158.74.177:2660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/my1.php"] [unique_id "aoSAl_cmepr5_nHgLbNPxwAAAmE"]
[Tue Aug 18 12:56:07.120218 2026] [security2:error] [pid 67073:tid 67238] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/you.php"] [unique_id "aoSAl_cmepr5_nHgLbNPyAAAAjU"]
[Tue Aug 18 12:56:07.123230 2026] [security2:error] [pid 67073:tid 67271] [client 20.226.6.191:64078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/index/function.php"] [unique_id "aoSAl_cmepr5_nHgLbNPyQAAAlY"]
[Tue Aug 18 12:56:07.130207 2026] [security2:error] [pid 66623:tid 66881] [client 20.151.109.219:21632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/lp.php"] [unique_id "aoSAl9O5rbWdOArH04KIBwAAAX0"]
[Tue Aug 18 12:56:07.161574 2026] [security2:error] [pid 67073:tid 67321] [client 135.225.78.186:13000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/new.php"] [unique_id "aoSAl_cmepr5_nHgLbNPzAAAAog"]
[Tue Aug 18 12:56:07.185813 2026] [security2:error] [pid 67073:tid 67275] [client 20.29.77.16:56324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/fedora.php"] [unique_id "aoSAl_cmepr5_nHgLbNPzQAAAlo"]
[Tue Aug 18 12:56:07.238559 2026] [security2:error] [pid 67073:tid 67125] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/dj.php"] [unique_id "aoSAl_cmepr5_nHgLbNP3AACTjE"]
[Tue Aug 18 12:56:07.247931 2026] [security2:error] [pid 67073:tid 67293] [client 20.91.215.254:20675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/chosen.php"] [unique_id "aoSAl_cmepr5_nHgLbNP3gAAAmw"]
[Tue Aug 18 12:56:07.257780 2026] [security2:error] [pid 66623:tid 66817] [client 4.223.164.152:4241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/ccc.php"] [unique_id "aoSAl9O5rbWdOArH04KICQAAAT0"]
[Tue Aug 18 12:56:07.267659 2026] [security2:error] [pid 66623:tid 66825] [client 20.226.56.190:3069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/lv.php"] [unique_id "aoSAl9O5rbWdOArH04KICgAAAUU"]
[Tue Aug 18 12:56:07.284044 2026] [authz_core:error] [pid 66623:tid 66753] [remote 57.141.22.42:54386] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:07.284487 2026] [authz_core:error] [pid 66623:tid 66753] [remote 57.141.22.42:54386] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:07.335565 2026] [authz_core:error] [pid 67073:tid 67194] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:07.335849 2026] [authz_core:error] [pid 67073:tid 67194] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:07.340965 2026] [security2:error] [pid 67073:tid 67326] [client 20.215.241.237:27203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/coffexium.php"] [unique_id "aoSAl_cmepr5_nHgLbNP5AAAAo0"]
[Tue Aug 18 12:56:07.361187 2026] [security2:error] [pid 67073:tid 67251] [client 20.226.56.190:47149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/51.php"] [unique_id "aoSAl_cmepr5_nHgLbNP5QAAAkI"]
[Tue Aug 18 12:56:07.365217 2026] [security2:error] [pid 67073:tid 67287] [client 158.158.34.183:25681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/o.php"] [unique_id "aoSAl_cmepr5_nHgLbNP5gAAAmY"]
[Tue Aug 18 12:56:07.366764 2026] [security2:error] [pid 67073:tid 67231] [client 20.51.153.15:9159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ft.php"] [unique_id "aoSAl_cmepr5_nHgLbNP5wAAAi4"]
[Tue Aug 18 12:56:07.373580 2026] [security2:error] [pid 66623:tid 66810] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ez.php"] [unique_id "aoSAl9O5rbWdOArH04KIGwAAATY"]
[Tue Aug 18 12:56:07.373859 2026] [security2:error] [pid 66623:tid 66872] [client 20.215.241.237:52561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/dex.php"] [unique_id "aoSAl9O5rbWdOArH04KIHAAAAXQ"]
[Tue Aug 18 12:56:07.382887 2026] [security2:error] [pid 67073:tid 67290] [client 213.202.253.4:50189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/memberfuns.php"] [unique_id "aoSAl_cmepr5_nHgLbNP6QAAAmk"], referer: www.google.com
[Tue Aug 18 12:56:07.384019 2026] [security2:error] [pid 66623:tid 66837] [client 20.226.6.191:39423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/edit.php"] [unique_id "aoSAl9O5rbWdOArH04KIHQAAAVE"]
[Tue Aug 18 12:56:07.449998 2026] [security2:error] [pid 66623:tid 66792] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/thebe.php"] [unique_id "aoSAl9O5rbWdOArH04KIHgAAASQ"]
[Tue Aug 18 12:56:07.486574 2026] [authz_core:error] [pid 66623:tid 66742] [remote 57.141.22.92:60988] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:07.486876 2026] [authz_core:error] [pid 66623:tid 66742] [remote 57.141.22.92:60988] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:07.487539 2026] [security2:error] [pid 67073:tid 67196] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/fa.php"] [unique_id "aoSAl_cmepr5_nHgLbNP7AACT3g"]
[Tue Aug 18 12:56:07.495410 2026] [security2:error] [pid 66623:tid 66819] [client 68.155.156.252:4835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/82.php"] [unique_id "aoSAl9O5rbWdOArH04KIIAAAAT8"]
[Tue Aug 18 12:56:07.499614 2026] [security2:error] [pid 67073:tid 67281] [client 20.151.109.219:12879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ey.php"] [unique_id "aoSAl_cmepr5_nHgLbNP7QAAAmA"]
[Tue Aug 18 12:56:07.510951 2026] [authz_core:error] [pid 66623:tid 66662] [remote 57.141.22.100:46124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:07.511263 2026] [authz_core:error] [pid 66623:tid 66662] [remote 57.141.22.100:46124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:07.533848 2026] [security2:error] [pid 67073:tid 67212] [client 20.79.204.6:2214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/akc.php"] [unique_id "aoSAl_cmepr5_nHgLbNP7wAAAhs"]
[Tue Aug 18 12:56:07.547338 2026] [security2:error] [pid 66623:tid 66875] [client 104.209.144.33:39346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSAl9O5rbWdOArH04KIIgAAAXc"]
[Tue Aug 18 12:56:07.562068 2026] [security2:error] [pid 66623:tid 66805] [client 158.23.17.4:33474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/email.php"] [unique_id "aoSAl9O5rbWdOArH04KIIwAAATE"]
[Tue Aug 18 12:56:07.582962 2026] [security2:error] [pid 66623:tid 66772] [client 135.225.78.186:13027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/new.php"] [unique_id "aoSAl9O5rbWdOArH04KIJAAAARA"]
[Tue Aug 18 12:56:07.606753 2026] [security2:error] [pid 67073:tid 67206] [client 4.223.164.152:46181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/zoo2.php"] [unique_id "aoSAl_cmepr5_nHgLbNP8QAAAhU"]
[Tue Aug 18 12:56:07.625052 2026] [security2:error] [pid 66623:tid 66865] [client 20.52.168.85:7814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/aged.php"] [unique_id "aoSAl9O5rbWdOArH04KIKQAAAW0"]
[Tue Aug 18 12:56:07.639683 2026] [security2:error] [pid 67073:tid 67286] [client 20.42.19.40:2696] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/themes/"] [unique_id "aoSAl_cmepr5_nHgLbNP9QAAAmU"]
[Tue Aug 18 12:56:07.641012 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:07.641486 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:07.645769 2026] [security2:error] [pid 67073:tid 67218] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/asus.php"] [unique_id "aoSAl_cmepr5_nHgLbNP9gAAAiE"]
[Tue Aug 18 12:56:07.651311 2026] [security2:error] [pid 67073:tid 67328] [client 20.116.17.175:11206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoSAl_cmepr5_nHgLbNP9wAAAo8"]
[Tue Aug 18 12:56:07.660026 2026] [security2:error] [pid 67073:tid 67277] [client 132.196.61.152:60349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/uwu.php"] [unique_id "aoSAl_cmepr5_nHgLbNP-AAAAlw"]
[Tue Aug 18 12:56:07.680714 2026] [security2:error] [pid 67073:tid 67210] [client 4.223.164.152:4807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/get.php"] [unique_id "aoSAl_cmepr5_nHgLbNP-QAAAhk"]
[Tue Aug 18 12:56:07.685422 2026] [security2:error] [pid 66623:tid 66802] [client 20.51.153.15:8784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/h.php"] [unique_id "aoSAl9O5rbWdOArH04KIMAAAAS4"]
[Tue Aug 18 12:56:07.751752 2026] [security2:error] [pid 67073:tid 67131] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/fb.php"] [unique_id "aoSAl_cmepr5_nHgLbNQBAACajc"]
[Tue Aug 18 12:56:07.773418 2026] [security2:error] [pid 66623:tid 66830] [client 213.35.127.232:53036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAl9O5rbWdOArH04KINQAAAUo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:07.786858 2026] [security2:error] [pid 67073:tid 67219] [client 74.248.130.103:14441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/admin.php"] [unique_id "aoSAl_cmepr5_nHgLbNQBgAAAiI"]
[Tue Aug 18 12:56:07.789314 2026] [security2:error] [pid 66623:tid 66829] [client 20.104.49.167:3993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/ops.php"] [unique_id "aoSAl9O5rbWdOArH04KINgAAAUk"]
[Tue Aug 18 12:56:07.822923 2026] [security2:error] [pid 67073:tid 67209] [client 20.151.109.219:64190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/lv.php"] [unique_id "aoSAl_cmepr5_nHgLbNQCAAAAhg"]
[Tue Aug 18 12:56:07.885785 2026] [security2:error] [pid 67073:tid 67325] [client 178.153.171.161:62947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAl_cmepr5_nHgLbNQCQAAAow"]
[Tue Aug 18 12:56:07.885932 2026] [security2:error] [pid 67073:tid 67325] [client 178.153.171.161:62947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAl_cmepr5_nHgLbNQCQAAAow"]
[Tue Aug 18 12:56:07.893602 2026] [security2:error] [pid 67073:tid 67279] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/22.php"] [unique_id "aoSAl_cmepr5_nHgLbNQCwAAAl4"]
[Tue Aug 18 12:56:07.937500 2026] [authz_core:error] [pid 67073:tid 67103] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:07.937805 2026] [authz_core:error] [pid 67073:tid 67103] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:07.960613 2026] [security2:error] [pid 67073:tid 67268] [client 20.91.215.254:20686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/asd.php"] [unique_id "aoSAl_cmepr5_nHgLbNQDgAAAlM"]
[Tue Aug 18 12:56:07.979566 2026] [security2:error] [pid 67073:tid 67225] [client 68.155.156.252:24923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/dex.php"] [unique_id "aoSAl_cmepr5_nHgLbNQDwAAAig"]
[Tue Aug 18 12:56:07.980696 2026] [security2:error] [pid 67073:tid 67096] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gw.php"] [unique_id "aoSAl_cmepr5_nHgLbNQEQACYhQ"]
[Tue Aug 18 12:56:08.000451 2026] [security2:error] [pid 67073:tid 67266] [client 135.225.78.186:13275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/apreset.php"] [unique_id "aoSAl_cmepr5_nHgLbNQEwAAAlE"]
[Tue Aug 18 12:56:08.028621 2026] [security2:error] [pid 66623:tid 66893] [client 20.51.153.15:8805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/40.php"] [unique_id "aoSAmNO5rbWdOArH04KIOQAAAYk"]
[Tue Aug 18 12:56:08.038556 2026] [security2:error] [pid 66623:tid 66809] [client 4.223.164.152:46204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/org.php"] [unique_id "aoSAmNO5rbWdOArH04KIOwAAATU"]
[Tue Aug 18 12:56:08.039370 2026] [security2:error] [pid 66623:tid 66887] [client 135.225.75.187:9819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/a1vx.php"] [unique_id "aoSAmNO5rbWdOArH04KIPAAAAYM"]
[Tue Aug 18 12:56:08.098304 2026] [security2:error] [pid 67073:tid 67301] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/themes.php"] [unique_id "aoSAmPcmepr5_nHgLbNQFwAAAnQ"]
[Tue Aug 18 12:56:08.098854 2026] [security2:error] [pid 67073:tid 67327] [client 4.223.164.152:4806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/images.php"] [unique_id "aoSAmPcmepr5_nHgLbNQGAAAAo4"]
[Tue Aug 18 12:56:08.132884 2026] [security2:error] [pid 67073:tid 67228] [client 20.151.109.219:45743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/51.php"] [unique_id "aoSAmPcmepr5_nHgLbNQGQAAAis"]
[Tue Aug 18 12:56:08.143516 2026] [security2:error] [pid 67073:tid 67329] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/zs.php"] [unique_id "aoSAmPcmepr5_nHgLbNQGgAAApA"]
[Tue Aug 18 12:56:08.162462 2026] [security2:error] [pid 66623:tid 66882] [client 20.100.169.31:13203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/file.php"] [unique_id "aoSAmNO5rbWdOArH04KIQQAAAX4"]
[Tue Aug 18 12:56:08.181912 2026] [security2:error] [pid 67073:tid 67233] [client 216.73.161.205:60951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-login.php"] [unique_id "aoSAmPcmepr5_nHgLbNQFAAAAjA"], referer: https://ozzyfernandesoficial.com.br/wp-login.php
[Tue Aug 18 12:56:08.193210 2026] [security2:error] [pid 67073:tid 67249] [client 20.79.204.6:2221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/buy.php"] [unique_id "aoSAmPcmepr5_nHgLbNQHQAAAkA"]
[Tue Aug 18 12:56:08.204437 2026] [security2:error] [pid 67073:tid 67323] [client 158.158.74.177:2649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/new.php"] [unique_id "aoSAmPcmepr5_nHgLbNQHwAAAoo"]
[Tue Aug 18 12:56:08.210875 2026] [security2:error] [pid 67073:tid 67113] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/sw.php"] [unique_id "aoSAmPcmepr5_nHgLbNQIAACeiU"]
[Tue Aug 18 12:56:08.229286 2026] [security2:error] [pid 67073:tid 67245] [client 20.52.168.85:7858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/essexec.php"] [unique_id "aoSAmPcmepr5_nHgLbNQIQAAAjw"]
[Tue Aug 18 12:56:08.234021 2026] [security2:error] [pid 67073:tid 67317] [client 20.226.56.190:30986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ew.php"] [unique_id "aoSAmPcmepr5_nHgLbNQIwAAAoQ"]
[Tue Aug 18 12:56:08.264780 2026] [security2:error] [pid 67073:tid 67271] [client 20.51.153.15:9109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ee.php"] [unique_id "aoSAmPcmepr5_nHgLbNQJQAAAlY"]
[Tue Aug 18 12:56:08.296506 2026] [security2:error] [pid 67073:tid 67213] [client 20.215.241.237:49257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAmPcmepr5_nHgLbNQJwAAAhw"]
[Tue Aug 18 12:56:08.350717 2026] [security2:error] [pid 66623:tid 66852] [client 20.29.77.16:20817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/path.php"] [unique_id "aoSAmNO5rbWdOArH04KIRAAAAWA"]
[Tue Aug 18 12:56:08.377004 2026] [security2:error] [pid 67073:tid 67299] [client 74.248.130.103:36823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/aa2.php"] [unique_id "aoSAmPcmepr5_nHgLbNQKQAAAnI"]
[Tue Aug 18 12:56:08.393856 2026] [security2:error] [pid 67073:tid 67207] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/iz.php"] [unique_id "aoSAmPcmepr5_nHgLbNQKgAAAhY"]
[Tue Aug 18 12:56:08.421820 2026] [security2:error] [pid 67073:tid 67232] [client 135.225.78.186:13271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/1mage.php"] [unique_id "aoSAmPcmepr5_nHgLbNQNwAAAi8"]
[Tue Aug 18 12:56:08.422426 2026] [security2:error] [pid 67073:tid 67290] [client 20.42.19.40:2177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAmPcmepr5_nHgLbNQOAAAAmk"]
[Tue Aug 18 12:56:08.426142 2026] [security2:error] [pid 66623:tid 66779] [client 68.155.156.252:21109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/puc.php"] [unique_id "aoSAmNO5rbWdOArH04KIRQAAARc"]
[Tue Aug 18 12:56:08.441539 2026] [security2:error] [pid 67073:tid 67264] [client 20.215.241.237:52581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/puc.php"] [unique_id "aoSAmPcmepr5_nHgLbNQgQAAAk8"]
[Tue Aug 18 12:56:08.481216 2026] [security2:error] [pid 67073:tid 67091] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gc.php"] [unique_id "aoSAmPcmepr5_nHgLbNQhwACJg8"]
[Tue Aug 18 12:56:08.481831 2026] [autoindex:error] [pid 67073:tid 67308] [client 20.226.6.191:38228] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:08.506596 2026] [security2:error] [pid 67073:tid 67270] [client 20.51.153.15:8762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ak.php"] [unique_id "aoSAmPcmepr5_nHgLbNQiQAAAlU"]
[Tue Aug 18 12:56:08.515174 2026] [security2:error] [pid 67073:tid 67316] [client 4.223.164.152:4233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/alls.php"] [unique_id "aoSAmPcmepr5_nHgLbNQigAAAoM"]
[Tue Aug 18 12:56:08.521706 2026] [security2:error] [pid 66623:tid 66855] [client 20.151.109.219:59725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ew.php"] [unique_id "aoSAmNO5rbWdOArH04KIRgAAAWM"]
[Tue Aug 18 12:56:08.527837 2026] [security2:error] [pid 66623:tid 66820] [client 20.116.17.175:57604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/dk.php"] [unique_id "aoSAmNO5rbWdOArH04KIRwAAAUA"]
[Tue Aug 18 12:56:08.529951 2026] [security2:error] [pid 67073:tid 67230] [client 4.223.164.152:54250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/imageskir.php"] [unique_id "aoSAmPcmepr5_nHgLbNQiwAAAi0"]
[Tue Aug 18 12:56:08.608500 2026] [security2:error] [pid 66623:tid 66791] [client 158.158.34.183:34994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/theme.php"] [unique_id "aoSAmNO5rbWdOArH04KISAAAASM"]
[Tue Aug 18 12:56:08.617039 2026] [security2:error] [pid 67073:tid 67267] [client 20.171.51.14:43350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/fb.php"] [unique_id "aoSAmPcmepr5_nHgLbNQjwAAAlI"]
[Tue Aug 18 12:56:08.622933 2026] [security2:error] [pid 67073:tid 67218] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAmPcmepr5_nHgLbNQjgACIXg"]
[Tue Aug 18 12:56:08.653939 2026] [security2:error] [pid 66623:tid 66775] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/se.php"] [unique_id "aoSAmNO5rbWdOArH04KISQAAARM"]
[Tue Aug 18 12:56:08.678646 2026] [security2:error] [pid 67073:tid 67111] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/uq.php"] [unique_id "aoSAmPcmepr5_nHgLbNQmAACOCM"]
[Tue Aug 18 12:56:08.710840 2026] [security2:error] [pid 67073:tid 67253] [client 20.226.56.190:31031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/pqr.php"] [unique_id "aoSAmPcmepr5_nHgLbNQnQAAAkQ"]
[Tue Aug 18 12:56:08.722857 2026] [security2:error] [pid 67073:tid 67205] [client 20.91.215.254:12000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/akc.php"] [unique_id "aoSAmPcmepr5_nHgLbNQngAAAhQ"]
[Tue Aug 18 12:56:08.725275 2026] [security2:error] [pid 66623:tid 66796] [client 20.104.49.167:41093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/coffexium.php"] [unique_id "aoSAmNO5rbWdOArH04KISwAAASg"]
[Tue Aug 18 12:56:08.733534 2026] [security2:error] [pid 67073:tid 67254] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/tiny.php"] [unique_id "aoSAmPcmepr5_nHgLbNQoQAAAkU"]
[Tue Aug 18 12:56:08.735161 2026] [autoindex:error] [pid 67073:tid 67272] [client 172.202.39.151:65239] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:08.795465 2026] [security2:error] [pid 66623:tid 66860] [client 20.79.204.6:2224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/cong.php"] [unique_id "aoSAmNO5rbWdOArH04KITAAAAWg"]
[Tue Aug 18 12:56:08.796185 2026] [security2:error] [pid 67073:tid 67281] [client 213.35.127.232:53316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAmPcmepr5_nHgLbNQpwAAAmA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:08.832318 2026] [security2:error] [pid 66623:tid 66783] [client 20.52.168.85:8005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/fw.php"] [unique_id "aoSAmNO5rbWdOArH04KITQAAARs"]
[Tue Aug 18 12:56:08.836843 2026] [security2:error] [pid 66623:tid 66786] [client 160.120.140.123:60714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAmNO5rbWdOArH04KITgAAAR4"]
[Tue Aug 18 12:56:08.836966 2026] [security2:error] [pid 66623:tid 66786] [client 160.120.140.123:60714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAmNO5rbWdOArH04KITgAAAR4"]
[Tue Aug 18 12:56:08.841818 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:08.842101 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:08.844677 2026] [security2:error] [pid 67073:tid 67239] [client 135.225.78.186:13287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/imsc.php"] [unique_id "aoSAmPcmepr5_nHgLbNQswAAAjY"]
[Tue Aug 18 12:56:08.857972 2026] [security2:error] [pid 67073:tid 67266] [client 20.151.109.219:64999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/pqr.php"] [unique_id "aoSAmPcmepr5_nHgLbNQtAAAAlE"]
[Tue Aug 18 12:56:08.860331 2026] [security2:error] [pid 66623:tid 66784] [client 192.141.172.134:59821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAmNO5rbWdOArH04KITwAAARw"]
[Tue Aug 18 12:56:08.860393 2026] [security2:error] [pid 66623:tid 66784] [client 192.141.172.134:59821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAmNO5rbWdOArH04KITwAAARw"]
[Tue Aug 18 12:56:08.861543 2026] [security2:error] [pid 66623:tid 66843] [client 68.155.156.252:8319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/inso.php"] [unique_id "aoSAmNO5rbWdOArH04KIUAAAAVc"]
[Tue Aug 18 12:56:08.861569 2026] [security2:error] [pid 66623:tid 66804] [client 20.51.153.15:9181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/test_info.php"] [unique_id "aoSAmNO5rbWdOArH04KIUQAAATA"]
[Tue Aug 18 12:56:08.899180 2026] [security2:error] [pid 66623:tid 66801] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/vp.php"] [unique_id "aoSAmNO5rbWdOArH04KIUgAAAS0"]
[Tue Aug 18 12:56:08.901688 2026] [security2:error] [pid 67073:tid 67319] [client 85.154.68.202:49731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAmPcmepr5_nHgLbNQtwAAAoY"]
[Tue Aug 18 12:56:08.901805 2026] [security2:error] [pid 67073:tid 67319] [client 85.154.68.202:49731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAmPcmepr5_nHgLbNQtwAAAoY"]
[Tue Aug 18 12:56:08.909212 2026] [security2:error] [pid 67073:tid 67101] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/32.php"] [unique_id "aoSAmPcmepr5_nHgLbNQuAACXRk"]
[Tue Aug 18 12:56:08.924560 2026] [security2:error] [pid 67073:tid 67229] [client 20.226.6.191:38228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSAmPcmepr5_nHgLbNQuwAAAiw"]
[Tue Aug 18 12:56:08.931586 2026] [security2:error] [pid 67073:tid 67153] [remote 191.39.149.110:7833] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "barsantajulia.com.br"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "aoSAmPcmepr5_nHgLbNQvAACdU0"], referer: https://barsantajulia.com.br/
[Tue Aug 18 12:56:08.936654 2026] [security2:error] [pid 67073:tid 67301] [client 4.223.164.152:4226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/coffexium.php"] [unique_id "aoSAmPcmepr5_nHgLbNQvgAAAnQ"]
[Tue Aug 18 12:56:08.970938 2026] [security2:error] [pid 66623:tid 66814] [client 158.158.74.177:22750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/norn.php"] [unique_id "aoSAmNO5rbWdOArH04KIUwAAATo"]
[Tue Aug 18 12:56:08.972602 2026] [security2:error] [pid 66623:tid 66768] [client 74.248.130.103:36800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/xamp.php"] [unique_id "aoSAmNO5rbWdOArH04KIVAAAAQw"]
[Tue Aug 18 12:56:08.981079 2026] [security2:error] [pid 67073:tid 67228] [client 132.196.61.152:60319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/signon.php"] [unique_id "aoSAmPcmepr5_nHgLbNQwAAAAis"]
[Tue Aug 18 12:56:09.020191 2026] [security2:error] [pid 67073:tid 67233] [client 172.202.39.151:65239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/aa.php"] [unique_id "aoSAmfcmepr5_nHgLbNQxgAAAjA"]
[Tue Aug 18 12:56:09.027943 2026] [security2:error] [pid 66623:tid 66840] [client 20.116.17.175:57622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/bal.php"] [unique_id "aoSAmdO5rbWdOArH04KIVgAAAVQ"]
[Tue Aug 18 12:56:09.043506 2026] [security2:error] [pid 67073:tid 67322] [client 4.223.164.152:64673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/indexo.php"] [unique_id "aoSAmfcmepr5_nHgLbNQxwAAAok"]
[Tue Aug 18 12:56:09.044673 2026] [security2:error] [pid 67073:tid 67249] [client 135.225.75.187:17675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ty.php"] [unique_id "aoSAmfcmepr5_nHgLbNQyAAAAkA"]
[Tue Aug 18 12:56:09.069077 2026] [security2:error] [pid 67073:tid 67323] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/tmp/byp.php"] [unique_id "aoSAmfcmepr5_nHgLbNQyQAAAoo"]
[Tue Aug 18 12:56:09.093060 2026] [security2:error] [pid 67073:tid 67317] [client 158.23.17.4:8741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/profile.php"] [unique_id "aoSAmfcmepr5_nHgLbNQywAAAoQ"]
[Tue Aug 18 12:56:09.144008 2026] [security2:error] [pid 66623:tid 66861] [client 74.248.18.37:14814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAmdO5rbWdOArH04KIZgAAAWk"]
[Tue Aug 18 12:56:09.145405 2026] [authz_core:error] [pid 67073:tid 67158] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:09.145862 2026] [authz_core:error] [pid 67073:tid 67158] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:09.163830 2026] [security2:error] [pid 66623:tid 66850] [client 20.151.109.219:24841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/an.php"] [unique_id "aoSAmdO5rbWdOArH04KIaAAAAV4"]
[Tue Aug 18 12:56:09.164377 2026] [security2:error] [pid 66623:tid 66822] [client 20.163.43.14:4196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAmdO5rbWdOArH04KIaQAAAUI"]
[Tue Aug 18 12:56:09.166712 2026] [security2:error] [pid 67073:tid 67100] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/73.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ0AACHBg"]
[Tue Aug 18 12:56:09.170094 2026] [security2:error] [pid 67073:tid 67255] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ph.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ0QAAAkY"]
[Tue Aug 18 12:56:09.171414 2026] [security2:error] [pid 67073:tid 67244] [client 20.42.19.40:2234] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/uploads/"] [unique_id "aoSAmfcmepr5_nHgLbNQ0gAAAjs"]
[Tue Aug 18 12:56:09.186468 2026] [security2:error] [pid 67073:tid 67330] [client 20.51.153.15:8708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/14.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ0wAAApE"]
[Tue Aug 18 12:56:09.210709 2026] [security2:error] [pid 67073:tid 67263] [client 20.104.85.180:18816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/system_log.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ1QAAAk4"]
[Tue Aug 18 12:56:09.210709 2026] [security2:error] [pid 66623:tid 66774] [client 79.127.164.8:37128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/localhost_backup.bak"] [unique_id "aoSAmdO5rbWdOArH04KIagAAARI"], referer: https://medihub.com.br/localhost_backup.bak
[Tue Aug 18 12:56:09.262007 2026] [security2:error] [pid 67073:tid 67251] [client 135.225.78.186:13252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/imscjpg.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ2AAAAkI"]
[Tue Aug 18 12:56:09.268929 2026] [security2:error] [pid 66623:tid 66877] [client 20.250.13.23:25705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAmdO5rbWdOArH04KIawAAAXk"]
[Tue Aug 18 12:56:09.335609 2026] [security2:error] [pid 67073:tid 67320] [client 68.155.156.252:8270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/aa.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ2wAAAoc"]
[Tue Aug 18 12:56:09.356485 2026] [security2:error] [pid 67073:tid 67174] [remote 191.39.149.110:7833] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "barsantajulia.com.br"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ4gACe2I"], referer: https://barsantajulia.com.br/happyhour/
[Tue Aug 18 12:56:09.358663 2026] [security2:error] [pid 67073:tid 67311] [client 4.223.164.152:4816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/red.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ5AAAAn4"]
[Tue Aug 18 12:56:09.374332 2026] [security2:error] [pid 66623:tid 66780] [client 104.209.144.33:25608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSAmdO5rbWdOArH04KIbQAAARg"]
[Tue Aug 18 12:56:09.376764 2026] [security2:error] [pid 67073:tid 67206] [client 20.215.241.237:19887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/sf.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ5QAAAhU"]
[Tue Aug 18 12:56:09.401965 2026] [security2:error] [pid 66623:tid 66842] [client 20.79.204.6:2226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSAmdO5rbWdOArH04KIbgAAAVY"]
[Tue Aug 18 12:56:09.408028 2026] [security2:error] [pid 67073:tid 67141] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ib.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ5wACLUE"]
[Tue Aug 18 12:56:09.419904 2026] [security2:error] [pid 66623:tid 66864] [client 20.51.153.15:9117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/tk.php"] [unique_id "aoSAmdO5rbWdOArH04KIbwAAAWw"]
[Tue Aug 18 12:56:09.425428 2026] [security2:error] [pid 67073:tid 67220] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/s.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ6AAAAiM"]
[Tue Aug 18 12:56:09.437889 2026] [security2:error] [pid 66623:tid 66806] [client 20.52.168.85:7828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/zwso.php"] [unique_id "aoSAmdO5rbWdOArH04KIcAAAATI"]
[Tue Aug 18 12:56:09.445076 2026] [security2:error] [pid 66623:tid 66819] [client 20.91.215.254:12105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/maintenance.php"] [unique_id "aoSAmdO5rbWdOArH04KIcQAAAT8"]
[Tue Aug 18 12:56:09.447564 2026] [security2:error] [pid 66623:tid 66841] [client 20.151.109.219:61395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/sy.php"] [unique_id "aoSAmdO5rbWdOArH04KIcgAAAVU"]
[Tue Aug 18 12:56:09.479945 2026] [security2:error] [pid 67073:tid 67081] [remote 103.56.163.133:44164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "holldyperfuracoes.com.br"] [uri "/wp-login.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ7gACkwU"]
[Tue Aug 18 12:56:09.485503 2026] [security2:error] [pid 67073:tid 67210] [client 20.226.56.190:28282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/an.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ8AAAAhk"]
[Tue Aug 18 12:56:09.518157 2026] [security2:error] [pid 67073:tid 67216] [client 20.226.6.191:36377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-good.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ8gAAAh8"]
[Tue Aug 18 12:56:09.528304 2026] [security2:error] [pid 67073:tid 67291] [client 20.163.43.14:4254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ8wAAAmo"]
[Tue Aug 18 12:56:09.555595 2026] [security2:error] [pid 66623:tid 66838] [client 74.248.130.103:38664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/bless.php"] [unique_id "aoSAmdO5rbWdOArH04KIdAAAAVI"]
[Tue Aug 18 12:56:09.605066 2026] [security2:error] [pid 66623:tid 66777] [client 20.215.241.237:45788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/inso.php"] [unique_id "aoSAmdO5rbWdOArH04KIdQAAARU"]
[Tue Aug 18 12:56:09.661716 2026] [security2:error] [pid 67073:tid 67086] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/xm.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ9wACRQo"]
[Tue Aug 18 12:56:09.672561 2026] [security2:error] [pid 66623:tid 66811] [client 20.116.17.175:57656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/yawa.php"] [unique_id "aoSAmdO5rbWdOArH04KIdgAAATc"]
[Tue Aug 18 12:56:09.679328 2026] [security2:error] [pid 67073:tid 67261] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/uo.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ-QAAAkw"]
[Tue Aug 18 12:56:09.680335 2026] [security2:error] [pid 66623:tid 66828] [client 135.225.78.186:13248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/qlex1.php"] [unique_id "aoSAmdO5rbWdOArH04KIdwAAAUg"]
[Tue Aug 18 12:56:09.728456 2026] [security2:error] [pid 66623:tid 66812] [client 157.51.166.53:60498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAmdO5rbWdOArH04KIfQAAATg"]
[Tue Aug 18 12:56:09.728575 2026] [security2:error] [pid 66623:tid 66812] [client 157.51.166.53:60498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAmdO5rbWdOArH04KIfQAAATg"]
[Tue Aug 18 12:56:09.731563 2026] [security2:error] [pid 67073:tid 67209] [client 20.51.153.15:8782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/hp.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ-wAAAhg"]
[Tue Aug 18 12:56:09.781803 2026] [security2:error] [pid 66623:tid 66879] [client 4.223.164.152:17651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSAmdO5rbWdOArH04KIggAAAXs"]
[Tue Aug 18 12:56:09.791462 2026] [security2:error] [pid 66623:tid 66859] [client 68.155.156.252:4555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/img.php"] [unique_id "aoSAmdO5rbWdOArH04KIgwAAAWc"]
[Tue Aug 18 12:56:09.797752 2026] [security2:error] [pid 66623:tid 66862] [client 20.104.49.167:3531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/BDKR28WP.php"] [unique_id "aoSAmdO5rbWdOArH04KIhAAAAWo"]
[Tue Aug 18 12:56:09.798849 2026] [security2:error] [pid 66623:tid 66800] [client 20.151.109.219:12917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/57.php"] [unique_id "aoSAmdO5rbWdOArH04KIhQAAASw"]
[Tue Aug 18 12:56:09.814217 2026] [security2:error] [pid 67073:tid 67218] [client 213.35.127.232:53596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ_wAAAiE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:09.867138 2026] [security2:error] [pid 67073:tid 67200] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/zy.php"] [unique_id "aoSAmfcmepr5_nHgLbNRAgAChnw"]
[Tue Aug 18 12:56:09.868930 2026] [security2:error] [pid 67073:tid 67278] [client 20.163.43.14:4188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/admin.php"] [unique_id "aoSAmfcmepr5_nHgLbNRAwAAAl0"]
[Tue Aug 18 12:56:09.940713 2026] [security2:error] [pid 66623:tid 66882] [client 132.196.61.152:61033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/file61.php"] [unique_id "aoSAmdO5rbWdOArH04KIiQAAAX4"]
[Tue Aug 18 12:56:09.942964 2026] [security2:error] [pid 66623:tid 66790] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kx.php"] [unique_id "aoSAmdO5rbWdOArH04KIigAAASI"]
[Tue Aug 18 12:56:09.949319 2026] [security2:error] [pid 66623:tid 66863] [client 135.225.75.187:17668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/vgtyu.php"] [unique_id "aoSAmdO5rbWdOArH04KIiwAAAWs"]
[Tue Aug 18 12:56:10.004705 2026] [security2:error] [pid 66623:tid 66799] [client 20.29.77.16:56331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/456.php"] [unique_id "aoSAmtO5rbWdOArH04KIjAAAASs"]
[Tue Aug 18 12:56:10.013443 2026] [security2:error] [pid 67073:tid 67281] [client 20.79.204.6:2239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/db.php"] [unique_id "aoSAmvcmepr5_nHgLbNRCAAAAmA"]
[Tue Aug 18 12:56:10.029103 2026] [security2:error] [pid 67073:tid 67325] [client 74.248.18.37:28805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wso.php"] [unique_id "aoSAmvcmepr5_nHgLbNRCQAAAow"]
[Tue Aug 18 12:56:10.044509 2026] [security2:error] [pid 67073:tid 67225] [client 20.52.168.85:7860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/term.php"] [unique_id "aoSAmvcmepr5_nHgLbNRCgAAAig"]
[Tue Aug 18 12:56:10.045083 2026] [security2:error] [pid 67073:tid 67214] [client 20.215.241.237:27234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/k.php"] [unique_id "aoSAmvcmepr5_nHgLbNRCwAAAh0"]
[Tue Aug 18 12:56:10.054765 2026] [security2:error] [pid 67073:tid 67322] [client 20.51.153.15:8730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/wx.php"] [unique_id "aoSAmvcmepr5_nHgLbNRDQAAAok"]
[Tue Aug 18 12:56:10.083419 2026] [security2:error] [pid 67073:tid 67323] [client 20.116.17.175:57471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSAmvcmepr5_nHgLbNRDgAAAoo"]
[Tue Aug 18 12:56:10.103705 2026] [security2:error] [pid 67073:tid 67314] [client 135.225.78.186:13052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/mariju.php"] [unique_id "aoSAmvcmepr5_nHgLbNRDwAAAoE"]
[Tue Aug 18 12:56:10.132195 2026] [security2:error] [pid 67073:tid 67307] [client 20.171.51.14:28812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/gw.php"] [unique_id "aoSAmvcmepr5_nHgLbNREQAAAno"]
[Tue Aug 18 12:56:10.142607 2026] [security2:error] [pid 67073:tid 67309] [client 158.158.74.177:17973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/num.php"] [unique_id "aoSAmvcmepr5_nHgLbNREgAAAnw"]
[Tue Aug 18 12:56:10.146732 2026] [security2:error] [pid 67073:tid 67282] [client 74.248.130.103:15367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/file25.php"] [unique_id "aoSAmvcmepr5_nHgLbNREwAAAmE"]
[Tue Aug 18 12:56:10.149875 2026] [security2:error] [pid 67073:tid 67245] [client 68.155.156.252:5626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/222.php"] [unique_id "aoSAmvcmepr5_nHgLbNRFAAAAjw"]
[Tue Aug 18 12:56:10.162540 2026] [security2:error] [pid 67073:tid 67157] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/q.php"] [unique_id "aoSAmvcmepr5_nHgLbNRFQACdVE"]
[Tue Aug 18 12:56:10.172564 2026] [security2:error] [pid 67073:tid 67312] [client 172.202.39.151:50196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/0x.php"] [unique_id "aoSAmvcmepr5_nHgLbNRFgAAAn8"]
[Tue Aug 18 12:56:10.184292 2026] [security2:error] [pid 67073:tid 67215] [client 20.151.109.219:24841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ah.php"] [unique_id "aoSAmvcmepr5_nHgLbNRFwAAAh4"]
[Tue Aug 18 12:56:10.194971 2026] [security2:error] [pid 67073:tid 67238] [client 20.163.43.14:4276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/public/css.php"] [unique_id "aoSAmvcmepr5_nHgLbNRGAAAAjU"]
[Tue Aug 18 12:56:10.211038 2026] [security2:error] [pid 67073:tid 67271] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/va.php"] [unique_id "aoSAmvcmepr5_nHgLbNRGQAAAlY"]
[Tue Aug 18 12:56:10.256616 2026] [security2:error] [pid 67073:tid 67289] [client 4.223.164.152:46168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSAmvcmepr5_nHgLbNRHAAAAmg"]
[Tue Aug 18 12:56:10.267772 2026] [security2:error] [pid 67073:tid 67227] [client 20.91.215.254:12100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/options-writing.php"] [unique_id "aoSAmvcmepr5_nHgLbNRHQAAAio"]
[Tue Aug 18 12:56:10.289999 2026] [security2:error] [pid 66623:tid 66815] [client 20.51.153.15:9180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/dj.php"] [unique_id "aoSAmtO5rbWdOArH04KIkQAAATs"]
[Tue Aug 18 12:56:10.348027 2026] [authz_core:error] [pid 67073:tid 67138] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:10.348289 2026] [authz_core:error] [pid 67073:tid 67138] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:10.381260 2026] [security2:error] [pid 67073:tid 67118] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/xf.php"] [unique_id "aoSAmvcmepr5_nHgLbNRIAACQio"]
[Tue Aug 18 12:56:10.391443 2026] [security2:error] [pid 66623:tid 66832] [client 20.250.13.23:24777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/h.php"] [unique_id "aoSAmtO5rbWdOArH04KIkgAAAUw"]
[Tue Aug 18 12:56:10.442028 2026] [security2:error] [pid 67073:tid 67231] [client 20.104.49.167:3544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/sf.php"] [unique_id "aoSAmvcmepr5_nHgLbNRIgAAAi4"]
[Tue Aug 18 12:56:10.470967 2026] [security2:error] [pid 66623:tid 66775] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/fo.php"] [unique_id "aoSAmtO5rbWdOArH04KIlAAAARM"]
[Tue Aug 18 12:56:10.483020 2026] [security2:error] [pid 66623:tid 66858] [client 4.223.164.152:4825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAmtO5rbWdOArH04KIlQAAAWY"]
[Tue Aug 18 12:56:10.487512 2026] [security2:error] [pid 67073:tid 67226] [client 20.151.109.219:64179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/vw.php"] [unique_id "aoSAmvcmepr5_nHgLbNRJgAAAik"]
[Tue Aug 18 12:56:10.521596 2026] [security2:error] [pid 67073:tid 67247] [client 135.225.78.186:12994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/cofbgxlk.php"] [unique_id "aoSAmvcmepr5_nHgLbNRKQAAAj4"]
[Tue Aug 18 12:56:10.545631 2026] [security2:error] [pid 67073:tid 67320] [client 20.163.43.14:4315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAmvcmepr5_nHgLbNRKgAAAoc"]
[Tue Aug 18 12:56:10.560134 2026] [security2:error] [pid 67073:tid 67212] [client 20.42.19.40:2883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSAmvcmepr5_nHgLbNRKwAAAhs"]
[Tue Aug 18 12:56:10.562557 2026] [security2:error] [pid 67073:tid 67083] [remote 178.156.200.16:35336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.200.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stremma.com.br"] [uri "/wp-login.php"] [unique_id "aoSAmvcmepr5_nHgLbNRLAACfQc"]
[Tue Aug 18 12:56:10.578013 2026] [security2:error] [pid 67073:tid 67129] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gb.php"] [unique_id "aoSAmvcmepr5_nHgLbNRLQACJjU"]
[Tue Aug 18 12:56:10.595287 2026] [security2:error] [pid 67073:tid 67206] [client 20.116.17.175:57439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/7.php"] [unique_id "aoSAmvcmepr5_nHgLbNRLwAAAhU"]
[Tue Aug 18 12:56:10.620762 2026] [security2:error] [pid 67073:tid 67287] [client 20.79.204.6:2177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/dropdown.php"] [unique_id "aoSAmvcmepr5_nHgLbNRMQAAAmY"]
[Tue Aug 18 12:56:10.648614 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:10.648934 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:10.649421 2026] [security2:error] [pid 67073:tid 67232] [client 20.52.168.85:7845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSAmvcmepr5_nHgLbNRNgAAAi8"]
[Tue Aug 18 12:56:10.716475 2026] [security2:error] [pid 66623:tid 66888] [client 20.51.153.15:9151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/fa.php"] [unique_id "aoSAmtO5rbWdOArH04KImQAAAYQ"]
[Tue Aug 18 12:56:10.732206 2026] [security2:error] [pid 67073:tid 67216] [client 68.155.156.252:5574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/key.php"] [unique_id "aoSAmvcmepr5_nHgLbNROAAAAh8"]
[Tue Aug 18 12:56:10.735021 2026] [security2:error] [pid 67073:tid 67241] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/loading.php"] [unique_id "aoSAmvcmepr5_nHgLbNROQAAAjg"]
[Tue Aug 18 12:56:10.742436 2026] [security2:error] [pid 67073:tid 67291] [client 4.223.164.152:17625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/.admin.php"] [unique_id "aoSAmvcmepr5_nHgLbNROwAAAmo"]
[Tue Aug 18 12:56:10.751778 2026] [security2:error] [pid 66623:tid 66768] [client 158.23.17.4:9375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/summary.php"] [unique_id "aoSAmtO5rbWdOArH04KImgAAAQw"]
[Tue Aug 18 12:56:10.759307 2026] [security2:error] [pid 67073:tid 67253] [client 74.248.130.103:14429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/file15.php"] [unique_id "aoSAmvcmepr5_nHgLbNRPAAAAkQ"]
[Tue Aug 18 12:56:10.779348 2026] [security2:error] [pid 67073:tid 67192] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/jp.php"] [unique_id "aoSAmvcmepr5_nHgLbNRPgACInQ"]
[Tue Aug 18 12:56:10.832090 2026] [autoindex:error] [pid 67073:tid 67242] [client 20.226.6.191:64125] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:10.836060 2026] [security2:error] [pid 66623:tid 66834] [client 213.35.127.232:53861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAmtO5rbWdOArH04KInQAAAU4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:10.842101 2026] [security2:error] [pid 66623:tid 66880] [client 20.215.241.237:17344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/aa.php"] [unique_id "aoSAmtO5rbWdOArH04KIngAAAXw"]
[Tue Aug 18 12:56:10.848711 2026] [security2:error] [pid 66623:tid 66840] [client 20.151.109.219:21636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/lj.php"] [unique_id "aoSAmtO5rbWdOArH04KInwAAAVQ"]
[Tue Aug 18 12:56:10.854027 2026] [security2:error] [pid 67073:tid 67276] [client 20.226.56.190:17893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/sy.php"] [unique_id "aoSAmvcmepr5_nHgLbNRQwAAAls"]
[Tue Aug 18 12:56:10.884134 2026] [security2:error] [pid 67073:tid 67209] [client 20.104.49.167:7836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/k.php"] [unique_id "aoSAmvcmepr5_nHgLbNRRQAAAhg"]
[Tue Aug 18 12:56:10.936368 2026] [security2:error] [pid 67073:tid 67218] [client 4.223.164.152:4850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/admin.php"] [unique_id "aoSAmvcmepr5_nHgLbNRSAAAAiE"]
[Tue Aug 18 12:56:10.938238 2026] [security2:error] [pid 66623:tid 66866] [client 172.202.39.151:50235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/zxz.php"] [unique_id "aoSAmtO5rbWdOArH04KIoAAAAW4"]
[Tue Aug 18 12:56:10.939213 2026] [security2:error] [pid 66623:tid 66778] [client 135.225.78.186:13250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/contacto.php"] [unique_id "aoSAmtO5rbWdOArH04KIoQAAARY"]
[Tue Aug 18 12:56:10.952361 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:10.952616 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:10.964832 2026] [security2:error] [pid 67073:tid 67239] [client 135.225.75.187:58323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/mans.php"] [unique_id "aoSAmvcmepr5_nHgLbNRSgAAAjY"]
[Tue Aug 18 12:56:10.971681 2026] [security2:error] [pid 67073:tid 67221] [client 20.91.215.254:22439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSAmvcmepr5_nHgLbNRTAAAAiQ"]
[Tue Aug 18 12:56:10.983104 2026] [security2:error] [pid 66623:tid 66814] [client 158.158.74.177:16564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/options-reading.php"] [unique_id "aoSAmtO5rbWdOArH04KIogAAATo"]
[Tue Aug 18 12:56:10.983963 2026] [security2:error] [pid 67073:tid 67229] [client 158.158.34.183:18838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSAmvcmepr5_nHgLbNRTQAAAiw"]
[Tue Aug 18 12:56:10.984619 2026] [security2:error] [pid 67073:tid 67278] [client 20.51.153.15:8751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/fb.php"] [unique_id "aoSAmvcmepr5_nHgLbNRTgAAAl0"]
[Tue Aug 18 12:56:10.987363 2026] [security2:error] [pid 66623:tid 66807] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ke.php"] [unique_id "aoSAmtO5rbWdOArH04KIowAAATM"]
[Tue Aug 18 12:56:11.000247 2026] [security2:error] [pid 67073:tid 67130] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/eq.php"] [unique_id "aoSAmvcmepr5_nHgLbNRUAACSjY"]
[Tue Aug 18 12:56:11.022619 2026] [security2:error] [pid 66623:tid 66798] [client 20.29.77.16:57062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/SMTP.php"] [unique_id "aoSAm9O5rbWdOArH04KIpAAAASo"]
[Tue Aug 18 12:56:11.065156 2026] [security2:error] [pid 67073:tid 67233] [client 20.163.43.14:4200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAm_cmepr5_nHgLbNRUQAAAjA"]
[Tue Aug 18 12:56:11.137885 2026] [security2:error] [pid 66623:tid 66774] [client 20.151.109.219:12887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kh.php"] [unique_id "aoSAm9O5rbWdOArH04KIpgAAARI"]
[Tue Aug 18 12:56:11.138496 2026] [security2:error] [pid 66623:tid 66785] [client 20.215.241.237:11005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/82.php"] [unique_id "aoSAm9O5rbWdOArH04KIpwAAAR0"]
[Tue Aug 18 12:56:11.139828 2026] [security2:error] [pid 67073:tid 67250] [client 172.202.39.151:45171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAm_cmepr5_nHgLbNRUwAAAkE"]
[Tue Aug 18 12:56:11.161498 2026] [security2:error] [pid 67073:tid 67311] [client 74.248.18.37:30540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/zup.php73"] [unique_id "aoSAm_cmepr5_nHgLbNRVAAAAn4"]
[Tue Aug 18 12:56:11.194629 2026] [security2:error] [pid 67073:tid 67245] [client 20.116.17.175:57428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/ws77.php"] [unique_id "aoSAm_cmepr5_nHgLbNRVgAAAjw"]
[Tue Aug 18 12:56:11.216757 2026] [autoindex:error] [pid 67073:tid 67307] [client 20.226.6.191:64125] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-admin/css/colors/midnight/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:11.218188 2026] [security2:error] [pid 66623:tid 66776] [client 20.51.153.15:9179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/gw.php"] [unique_id "aoSAm9O5rbWdOArH04KIqAAAARQ"]
[Tue Aug 18 12:56:11.220988 2026] [security2:error] [pid 67073:tid 67329] [client 20.79.204.6:2191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/file.php"] [unique_id "aoSAm_cmepr5_nHgLbNRVwAAApA"]
[Tue Aug 18 12:56:11.230450 2026] [security2:error] [pid 67073:tid 67161] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ep.php"] [unique_id "aoSAm_cmepr5_nHgLbNRWQACeFU"]
[Tue Aug 18 12:56:11.237669 2026] [security2:error] [pid 67073:tid 67327] [client 74.248.130.103:14400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/f35.php"] [unique_id "aoSAm_cmepr5_nHgLbNRWgAAAo4"]
[Tue Aug 18 12:56:11.240800 2026] [security2:error] [pid 67073:tid 67238] [client 20.226.6.191:64125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/tes.php"] [unique_id "aoSAm_cmepr5_nHgLbNRWwAAAjU"]
[Tue Aug 18 12:56:11.241802 2026] [security2:error] [pid 67073:tid 67215] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/nh.php"] [unique_id "aoSAm_cmepr5_nHgLbNRXAAAAh4"]
[Tue Aug 18 12:56:11.253130 2026] [security2:error] [pid 67073:tid 67325] [client 20.52.168.85:7847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-access.php"] [unique_id "aoSAm_cmepr5_nHgLbNRXgAAAow"]
[Tue Aug 18 12:56:11.283154 2026] [security2:error] [pid 66623:tid 66773] [client 52.173.121.69:24979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSAm9O5rbWdOArH04KIqgAAARE"]
[Tue Aug 18 12:56:11.286641 2026] [security2:error] [pid 66623:tid 66816] [client 4.223.164.152:46174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wsomini.php"] [unique_id "aoSAm9O5rbWdOArH04KIqwAAATw"]
[Tue Aug 18 12:56:11.355924 2026] [security2:error] [pid 67073:tid 67236] [client 4.223.164.152:4839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/file52.php"] [unique_id "aoSAm_cmepr5_nHgLbNRXwAAAjM"]
[Tue Aug 18 12:56:11.356300 2026] [security2:error] [pid 67073:tid 67252] [client 135.225.78.186:13039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/image2.php"] [unique_id "aoSAm_cmepr5_nHgLbNRYAAAAkM"]
[Tue Aug 18 12:56:11.387357 2026] [security2:error] [pid 66623:tid 66841] [client 104.209.144.33:33665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSAm9O5rbWdOArH04KIrQAAAVU"]
[Tue Aug 18 12:56:11.391606 2026] [security2:error] [pid 67073:tid 67213] [client 20.163.43.14:4220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/gelay.php"] [unique_id "aoSAm_cmepr5_nHgLbNRYQAAAhw"]
[Tue Aug 18 12:56:11.454482 2026] [security2:error] [pid 67073:tid 67330] [client 20.51.153.15:8761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/sw.php"] [unique_id "aoSAm_cmepr5_nHgLbNRYgAAApE"]
[Tue Aug 18 12:56:11.460242 2026] [security2:error] [pid 67073:tid 67088] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/rf.php"] [unique_id "aoSAm_cmepr5_nHgLbNRYwACSAw"]
[Tue Aug 18 12:56:11.470311 2026] [security2:error] [pid 67073:tid 67263] [client 20.151.109.219:65015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/jb.php"] [unique_id "aoSAm_cmepr5_nHgLbNRZAAAAk4"]
[Tue Aug 18 12:56:11.493493 2026] [security2:error] [pid 67073:tid 67248] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/oo.php"] [unique_id "aoSAm_cmepr5_nHgLbNRZQAAAj8"]
[Tue Aug 18 12:56:11.536401 2026] [security2:error] [pid 66623:tid 66777] [client 20.226.56.190:31645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/57.php"] [unique_id "aoSAm9O5rbWdOArH04KIrwAAARU"]
[Tue Aug 18 12:56:11.552665 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:11.552965 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:11.585790 2026] [security2:error] [pid 66623:tid 66836] [client 68.155.156.252:21056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/chosen.php"] [unique_id "aoSAm9O5rbWdOArH04KIsAAAAVA"]
[Tue Aug 18 12:56:11.587365 2026] [security2:error] [pid 67073:tid 67285] [client 132.196.61.152:34776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/copypaths.php"] [unique_id "aoSAm_cmepr5_nHgLbNRaAAAAmQ"]
[Tue Aug 18 12:56:11.628764 2026] [security2:error] [pid 66623:tid 66824] [client 20.116.17.175:11224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/read.php"] [unique_id "aoSAm9O5rbWdOArH04KIsQAAAUQ"]
[Tue Aug 18 12:56:11.643632 2026] [security2:error] [pid 67073:tid 67303] [client 20.104.49.167:30231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/82.php"] [unique_id "aoSAm_cmepr5_nHgLbNRagAAAnY"]
[Tue Aug 18 12:56:11.655437 2026] [security2:error] [pid 66623:tid 66706] [remote 157.230.98.178:49360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.98.230.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fbenevides.com.br"] [uri "/wp-login.php"] [unique_id "aoSAm9O5rbWdOArH04KIsgABLkU"]
[Tue Aug 18 12:56:11.662097 2026] [security2:error] [pid 67073:tid 67247] [client 20.226.56.190:31003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ah.php"] [unique_id "aoSAm_cmepr5_nHgLbNRawAAAj4"]
[Tue Aug 18 12:56:11.665086 2026] [security2:error] [pid 67073:tid 67104] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/xynz1.php"] [unique_id "aoSAm_cmepr5_nHgLbNRbAAChxw"]
[Tue Aug 18 12:56:11.665755 2026] [security2:error] [pid 67073:tid 67212] [client 20.171.51.14:62501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/sw.php"] [unique_id "aoSAm_cmepr5_nHgLbNRbQAAAhs"]
[Tue Aug 18 12:56:11.668221 2026] [security2:error] [pid 67073:tid 67256] [client 135.225.75.187:17700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/co.php"] [unique_id "aoSAm_cmepr5_nHgLbNRbgAAAkc"]
[Tue Aug 18 12:56:11.681798 2026] [security2:error] [pid 67073:tid 67316] [client 45.92.229.84:38599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.229.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/edit.php"] [unique_id "aoSAm_cmepr5_nHgLbNRbwAAAoM"], referer: https://ozzyfernandesoficial.com.br/wp-login.php
[Tue Aug 18 12:56:11.723182 2026] [security2:error] [pid 66623:tid 66811] [client 20.226.56.190:2730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/vw.php"] [unique_id "aoSAm9O5rbWdOArH04KIswAAATc"]
[Tue Aug 18 12:56:11.732413 2026] [security2:error] [pid 67073:tid 67328] [client 20.163.43.14:4278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAm_cmepr5_nHgLbNRcQAAAo8"]
[Tue Aug 18 12:56:11.738900 2026] [security2:error] [pid 67073:tid 67211] [client 74.248.130.103:14442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-load.php"] [unique_id "aoSAm_cmepr5_nHgLbNRcgAAAho"]
[Tue Aug 18 12:56:11.740985 2026] [security2:error] [pid 67073:tid 67267] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ja.php"] [unique_id "aoSAm_cmepr5_nHgLbNRcwAAAlI"]
[Tue Aug 18 12:56:11.752512 2026] [security2:error] [pid 67073:tid 67332] [client 20.51.153.15:8385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/gc.php"] [unique_id "aoSAm_cmepr5_nHgLbNRdAAAApM"]
[Tue Aug 18 12:56:11.756253 2026] [security2:error] [pid 66623:tid 66781] [client 20.151.109.219:65021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/do.php"] [unique_id "aoSAm9O5rbWdOArH04KItAAAARk"]
[Tue Aug 18 12:56:11.767151 2026] [security2:error] [pid 67073:tid 67326] [client 20.91.215.254:12130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/maint.php"] [unique_id "aoSAm_cmepr5_nHgLbNRdQAAAo0"]
[Tue Aug 18 12:56:11.768001 2026] [security2:error] [pid 66623:tid 66844] [client 20.226.56.190:45046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/lj.php"] [unique_id "aoSAm9O5rbWdOArH04KItQAAAVg"]
[Tue Aug 18 12:56:11.775664 2026] [security2:error] [pid 67073:tid 67208] [client 135.225.78.186:13042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/fb.php"] [unique_id "aoSAm_cmepr5_nHgLbNRdgAAAhc"]
[Tue Aug 18 12:56:11.783292 2026] [security2:error] [pid 67073:tid 67210] [client 4.223.164.152:4240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/geck.php"] [unique_id "aoSAm_cmepr5_nHgLbNRdwAAAhk"]
[Tue Aug 18 12:56:11.801062 2026] [security2:error] [pid 67073:tid 67231] [client 158.158.74.177:2645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/ors32envu.php"] [unique_id "aoSAm_cmepr5_nHgLbNReAAAAi4"]
[Tue Aug 18 12:56:11.803188 2026] [security2:error] [pid 67073:tid 67286] [client 20.226.56.190:45046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kh.php"] [unique_id "aoSAm_cmepr5_nHgLbNReQAAAmU"]
[Tue Aug 18 12:56:11.837208 2026] [security2:error] [pid 67073:tid 67297] [client 20.29.77.16:29593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/vbseo.php"] [unique_id "aoSAm_cmepr5_nHgLbNRfAAAAnA"]
[Tue Aug 18 12:56:11.851391 2026] [authz_core:error] [pid 67073:tid 67091] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:11.851648 2026] [authz_core:error] [pid 67073:tid 67091] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:11.852286 2026] [security2:error] [pid 67073:tid 67295] [client 213.35.127.232:54117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAm_cmepr5_nHgLbNRfgAAAm4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:11.854807 2026] [security2:error] [pid 67073:tid 67313] [client 20.79.204.6:2189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/goods.php"] [unique_id "aoSAm_cmepr5_nHgLbNRfwAAAoA"]
[Tue Aug 18 12:56:11.862181 2026] [security2:error] [pid 67073:tid 67224] [client 20.226.56.190:32256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/jb.php"] [unique_id "aoSAm_cmepr5_nHgLbNRgAAAAic"]
[Tue Aug 18 12:56:11.864988 2026] [security2:error] [pid 67073:tid 67279] [client 20.52.168.85:7811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/bthil.php"] [unique_id "aoSAm_cmepr5_nHgLbNRgQAAAl4"]
[Tue Aug 18 12:56:11.882322 2026] [security2:error] [pid 67073:tid 67235] [client 20.42.19.40:2717] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-includes/"] [unique_id "aoSAm_cmepr5_nHgLbNRggAAAjI"]
[Tue Aug 18 12:56:11.885738 2026] [security2:error] [pid 66623:tid 66893] [client 4.223.164.152:37248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/vr.php"] [unique_id "aoSAm9O5rbWdOArH04KItgAAAYk"]
[Tue Aug 18 12:56:11.930229 2026] [security2:error] [pid 66623:tid 66849] [client 20.250.13.23:14315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAm9O5rbWdOArH04KItwAAAV0"]
[Tue Aug 18 12:56:11.950948 2026] [security2:error] [pid 66623:tid 66833] [client 196.12.128.158:65139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAm9O5rbWdOArH04KIuAAAAU0"]
[Tue Aug 18 12:56:11.951095 2026] [security2:error] [pid 66623:tid 66833] [client 196.12.128.158:65139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAm9O5rbWdOArH04KIuAAAAU0"]
[Tue Aug 18 12:56:11.960796 2026] [security2:error] [pid 67073:tid 67278] [client 172.202.39.151:50205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/www.php"] [unique_id "aoSAm_cmepr5_nHgLbNRkQAAAl0"]
[Tue Aug 18 12:56:11.961313 2026] [security2:error] [pid 67073:tid 67076] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/vo.php"] [unique_id "aoSAm_cmepr5_nHgLbNRkgACKwA"]
[Tue Aug 18 12:56:12.020982 2026] [security2:error] [pid 67073:tid 67309] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/xx.php"] [unique_id "aoSAnPcmepr5_nHgLbNRmQAAAnw"]
[Tue Aug 18 12:56:12.025406 2026] [security2:error] [pid 67073:tid 67282] [client 20.226.56.190:17895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/do.php"] [unique_id "aoSAnPcmepr5_nHgLbNRmwAAAmE"]
[Tue Aug 18 12:56:12.041786 2026] [security2:error] [pid 67073:tid 67312] [client 20.116.17.175:57651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/albin.php"] [unique_id "aoSAnPcmepr5_nHgLbNRngAAAn8"]
[Tue Aug 18 12:56:12.057211 2026] [security2:error] [pid 67073:tid 67217] [client 20.163.43.14:4165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAnPcmepr5_nHgLbNRoQAAAiA"]
[Tue Aug 18 12:56:12.059740 2026] [security2:error] [pid 67073:tid 67280] [client 20.215.241.237:29356] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.dealermotors.com.br"] [uri "/1.php"] [unique_id "aoSAnPcmepr5_nHgLbNRogAAAl8"]
[Tue Aug 18 12:56:12.059844 2026] [security2:error] [pid 67073:tid 67280] [client 20.215.241.237:29356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/1.php"] [unique_id "aoSAnPcmepr5_nHgLbNRogAAAl8"]
[Tue Aug 18 12:56:12.068396 2026] [security2:error] [pid 67073:tid 67275] [client 20.51.153.15:8740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/uq.php"] [unique_id "aoSAnPcmepr5_nHgLbNRpQAAAlo"]
[Tue Aug 18 12:56:12.078754 2026] [security2:error] [pid 67073:tid 67213] [client 20.151.109.219:21663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/yw.php"] [unique_id "aoSAnPcmepr5_nHgLbNRqAAAAhw"]
[Tue Aug 18 12:56:12.177331 2026] [security2:error] [pid 67073:tid 67165] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/wu.php"] [unique_id "aoSAnPcmepr5_nHgLbNRuQACWFk"]
[Tue Aug 18 12:56:12.197031 2026] [security2:error] [pid 67073:tid 67320] [client 135.225.78.186:13001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/gi.php"] [unique_id "aoSAnPcmepr5_nHgLbNRxAAAAoc"]
[Tue Aug 18 12:56:12.223010 2026] [security2:error] [pid 66623:tid 66770] [client 4.223.164.152:4808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/biufile.php"] [unique_id "aoSAnNO5rbWdOArH04KIvQAAAQ4"]
[Tue Aug 18 12:56:12.229034 2026] [security2:error] [pid 67073:tid 67287] [client 20.226.56.190:31639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/yw.php"] [unique_id "aoSAnPcmepr5_nHgLbNRyAAAAmY"]
[Tue Aug 18 12:56:12.277377 2026] [security2:error] [pid 67073:tid 67208] [client 20.104.49.167:54266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/dex.php"] [unique_id "aoSAnPcmepr5_nHgLbNRzQAAAhc"]
[Tue Aug 18 12:56:12.284964 2026] [security2:error] [pid 67073:tid 67241] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/conn-test.php"] [unique_id "aoSAnPcmepr5_nHgLbNRzgAAAjg"]
[Tue Aug 18 12:56:12.292690 2026] [security2:error] [pid 67073:tid 67231] [client 74.248.136.165:64134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/fun.php"] [unique_id "aoSAnPcmepr5_nHgLbNRzwAAAi4"]
[Tue Aug 18 12:56:12.309019 2026] [security2:error] [pid 67073:tid 67272] [client 20.51.153.15:9176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/32.php"] [unique_id "aoSAnPcmepr5_nHgLbNR0AAAAlc"]
[Tue Aug 18 12:56:12.350132 2026] [security2:error] [pid 66623:tid 66845] [client 20.226.56.190:17894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/qh.php"] [unique_id "aoSAnNO5rbWdOArH04KIvgAAAVk"]
[Tue Aug 18 12:56:12.369131 2026] [authz_core:error] [pid 67073:tid 67141] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:12.369391 2026] [authz_core:error] [pid 67073:tid 67141] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:12.383708 2026] [security2:error] [pid 67073:tid 67109] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/de.php"] [unique_id "aoSAnPcmepr5_nHgLbNR1AACgCE"]
[Tue Aug 18 12:56:12.389627 2026] [security2:error] [pid 67073:tid 67224] [client 158.23.17.4:10983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/conf.php"] [unique_id "aoSAnPcmepr5_nHgLbNR1QAAAic"]
[Tue Aug 18 12:56:12.401042 2026] [security2:error] [pid 67073:tid 67306] [client 104.209.144.33:29831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSAnPcmepr5_nHgLbNR2AAAAnk"]
[Tue Aug 18 12:56:12.410034 2026] [security2:error] [pid 67073:tid 67235] [client 68.155.156.252:19013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/wpxml.php"] [unique_id "aoSAnPcmepr5_nHgLbNR2QAAAjI"]
[Tue Aug 18 12:56:12.414392 2026] [security2:error] [pid 67073:tid 67218] [client 20.151.109.219:17584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/qh.php"] [unique_id "aoSAnPcmepr5_nHgLbNR2gAAAiE"]
[Tue Aug 18 12:56:12.472747 2026] [security2:error] [pid 67073:tid 67326] [client 20.79.204.6:2190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/hplfuns.php"] [unique_id "aoSAnPcmepr5_nHgLbNR4gAAAo0"]
[Tue Aug 18 12:56:12.473083 2026] [security2:error] [pid 66623:tid 66823] [client 20.52.168.85:7815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-content/packed.php"] [unique_id "aoSAnNO5rbWdOArH04KIwAAAAUM"]
[Tue Aug 18 12:56:12.536911 2026] [security2:error] [pid 67073:tid 67292] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/fg.php"] [unique_id "aoSAnPcmepr5_nHgLbNR5QAAAms"]
[Tue Aug 18 12:56:12.557457 2026] [security2:error] [pid 67073:tid 67233] [client 135.225.75.187:17703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/btx25.php"] [unique_id "aoSAnPcmepr5_nHgLbNR5gAAAjA"]
[Tue Aug 18 12:56:12.588836 2026] [security2:error] [pid 67073:tid 67267] [client 158.158.74.177:2642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/ov-simple1.php"] [unique_id "aoSAnPcmepr5_nHgLbNR5wAAAlI"]
[Tue Aug 18 12:56:12.591243 2026] [security2:error] [pid 67073:tid 67311] [client 20.51.153.15:8721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/73.php"] [unique_id "aoSAnPcmepr5_nHgLbNR6AAAAn4"]
[Tue Aug 18 12:56:12.595004 2026] [security2:error] [pid 66623:tid 66892] [client 158.158.34.183:18872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/bi.php"] [unique_id "aoSAnNO5rbWdOArH04KIwQAAAYg"]
[Tue Aug 18 12:56:12.600946 2026] [security2:error] [pid 67073:tid 67309] [client 20.163.43.14:4148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSAnPcmepr5_nHgLbNR6gAAAnw"]
[Tue Aug 18 12:56:12.602574 2026] [security2:error] [pid 66623:tid 66795] [client 20.29.77.16:27254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/sysinfo.php"] [unique_id "aoSAnNO5rbWdOArH04KIwgAAASc"]
[Tue Aug 18 12:56:12.605656 2026] [security2:error] [pid 67073:tid 67230] [client 20.116.17.175:11221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/fw/34.php"] [unique_id "aoSAnPcmepr5_nHgLbNR7AAAAi0"]
[Tue Aug 18 12:56:12.614234 2026] [security2:error] [pid 67073:tid 67304] [client 135.225.78.186:13274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/video.php"] [unique_id "aoSAnPcmepr5_nHgLbNR7QAAAnc"]
[Tue Aug 18 12:56:12.617498 2026] [security2:error] [pid 67073:tid 67307] [client 20.42.19.40:2739] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-includes/js/crop/"] [unique_id "aoSAnPcmepr5_nHgLbNR7gAAAno"]
[Tue Aug 18 12:56:12.617753 2026] [security2:error] [pid 67073:tid 67160] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/album.php"] [unique_id "aoSAnPcmepr5_nHgLbNR7wACkFQ"]
[Tue Aug 18 12:56:12.624623 2026] [security2:error] [pid 67073:tid 67225] [client 74.248.18.37:24506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/k.php"] [unique_id "aoSAnPcmepr5_nHgLbNR8AAAAig"]
[Tue Aug 18 12:56:12.659393 2026] [security2:error] [pid 66623:tid 66769] [client 4.223.164.152:4801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/dejavu.php"] [unique_id "aoSAnNO5rbWdOArH04KIxAAAAQ0"]
[Tue Aug 18 12:56:12.659616 2026] [security2:error] [pid 67073:tid 67250] [client 103.120.71.157:50962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAnPcmepr5_nHgLbNR8gAAAkE"]
[Tue Aug 18 12:56:12.659742 2026] [security2:error] [pid 67073:tid 67250] [client 103.120.71.157:50962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAnPcmepr5_nHgLbNR8gAAAkE"]
[Tue Aug 18 12:56:12.667139 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:12.667414 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:12.669351 2026] [security2:error] [pid 66623:tid 66867] [client 172.202.39.151:65247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wicked.php"] [unique_id "aoSAnNO5rbWdOArH04KIxQAAAW8"]
[Tue Aug 18 12:56:12.684657 2026] [security2:error] [pid 67073:tid 67312] [client 74.248.130.103:14422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSAnPcmepr5_nHgLbNR9AAAAn8"]
[Tue Aug 18 12:56:12.743833 2026] [security2:error] [pid 67073:tid 67321] [client 20.151.109.219:21653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/r.php"] [unique_id "aoSAnPcmepr5_nHgLbNR9wAAAog"]
[Tue Aug 18 12:56:12.748029 2026] [security2:error] [pid 67073:tid 67281] [client 79.127.164.8:37190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/localhost_backup.sql"] [unique_id "aoSAnPcmepr5_nHgLbNR-AAAAmA"], referer: https://medihub.com.br/localhost_backup.sql
[Tue Aug 18 12:56:12.755551 2026] [security2:error] [pid 66623:tid 66839] [client 20.91.215.254:12120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/phpMailer.php"] [unique_id "aoSAnNO5rbWdOArH04KIxgAAAVM"]
[Tue Aug 18 12:56:12.771520 2026] [security2:error] [pid 66623:tid 66820] [client 20.226.56.190:19348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/r.php"] [unique_id "aoSAnNO5rbWdOArH04KIxwAAAUA"]
[Tue Aug 18 12:56:12.791938 2026] [security2:error] [pid 67073:tid 67296] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ve.php"] [unique_id "aoSAnPcmepr5_nHgLbNR-QAAAm8"]
[Tue Aug 18 12:56:12.827425 2026] [security2:error] [pid 67073:tid 67255] [client 20.171.51.14:51788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/gc.php"] [unique_id "aoSAnPcmepr5_nHgLbNR-wAAAkY"]
[Tue Aug 18 12:56:12.832538 2026] [security2:error] [pid 67073:tid 67227] [client 20.104.49.167:30256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/puc.php"] [unique_id "aoSAnPcmepr5_nHgLbNR_AAAAio"]
[Tue Aug 18 12:56:12.854047 2026] [security2:error] [pid 67073:tid 67143] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kv.php"] [unique_id "aoSAnPcmepr5_nHgLbNR_QACJUM"]
[Tue Aug 18 12:56:12.859364 2026] [security2:error] [pid 66623:tid 66775] [client 20.215.241.237:49154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAnNO5rbWdOArH04KIyAAAARM"]
[Tue Aug 18 12:56:12.864568 2026] [security2:error] [pid 67073:tid 67228] [client 213.35.127.232:54363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAnPcmepr5_nHgLbNR_gAAAis"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:12.897116 2026] [security2:error] [pid 66623:tid 66886] [client 20.51.153.15:9150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ib.php"] [unique_id "aoSAnNO5rbWdOArH04KIyQAAAYI"]
[Tue Aug 18 12:56:12.929022 2026] [security2:error] [pid 67073:tid 67248] [client 20.163.43.14:4325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/about.php"] [unique_id "aoSAnPcmepr5_nHgLbNSAAAAAj8"]
[Tue Aug 18 12:56:12.967186 2026] [security2:error] [pid 66623:tid 66860] [client 20.42.19.40:2885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-links-opml.php"] [unique_id "aoSAnNO5rbWdOArH04KIywAAAWg"]
[Tue Aug 18 12:56:12.969067 2026] [authz_core:error] [pid 67073:tid 67200] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:12.969323 2026] [authz_core:error] [pid 67073:tid 67200] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:13.010636 2026] [security2:error] [pid 67073:tid 67245] [client 20.250.13.23:52403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/a7.php"] [unique_id "aoSAnfcmepr5_nHgLbNSAwAAAjw"]
[Tue Aug 18 12:56:13.020253 2026] [security2:error] [pid 66623:tid 66818] [client 104.209.144.33:36516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSAndO5rbWdOArH04KIzQAAAT4"]
[Tue Aug 18 12:56:13.036481 2026] [security2:error] [pid 67073:tid 67251] [client 135.225.78.186:13278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/hel.php"] [unique_id "aoSAnfcmepr5_nHgLbNSBAAAAkI"]
[Tue Aug 18 12:56:13.051132 2026] [security2:error] [pid 67073:tid 67146] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/z.php"] [unique_id "aoSAnfcmepr5_nHgLbNSBQACS0Y"]
[Tue Aug 18 12:56:13.051715 2026] [security2:error] [pid 66623:tid 66768] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ia.php"] [unique_id "aoSAndO5rbWdOArH04KIzgAAAQw"]
[Tue Aug 18 12:56:13.063933 2026] [security2:error] [pid 67073:tid 67277] [client 197.184.64.235:41929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAnfcmepr5_nHgLbNSBgAAAlw"]
[Tue Aug 18 12:56:13.064031 2026] [security2:error] [pid 67073:tid 67277] [client 197.184.64.235:41929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAnfcmepr5_nHgLbNSBgAAAlw"]
[Tue Aug 18 12:56:13.079418 2026] [security2:error] [pid 66623:tid 66858] [client 20.52.168.85:7752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/admin/function.php"] [unique_id "aoSAndO5rbWdOArH04KIzwAAAWY"]
[Tue Aug 18 12:56:13.093413 2026] [security2:error] [pid 67073:tid 67247] [client 20.151.109.219:61406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/17.php"] [unique_id "aoSAnfcmepr5_nHgLbNSCAAAAj4"]
[Tue Aug 18 12:56:13.101658 2026] [security2:error] [pid 66623:tid 66834] [client 4.223.164.152:4265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/aaf.php"] [unique_id "aoSAndO5rbWdOArH04KI0AAAAU4"]
[Tue Aug 18 12:56:13.134540 2026] [security2:error] [pid 66623:tid 66840] [client 20.116.17.175:11247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp9.php"] [unique_id "aoSAndO5rbWdOArH04KI0gAAAVQ"]
[Tue Aug 18 12:56:13.141481 2026] [security2:error] [pid 67073:tid 67212] [client 172.202.39.151:65219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSAnfcmepr5_nHgLbNSCQAAAhs"]
[Tue Aug 18 12:56:13.189866 2026] [security2:error] [pid 66623:tid 66786] [client 20.79.204.6:2180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/htaccess.php"] [unique_id "aoSAndO5rbWdOArH04KI0wAAAR4"]
[Tue Aug 18 12:56:13.191239 2026] [security2:error] [pid 66623:tid 66843] [client 172.202.39.151:33696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/o.php"] [unique_id "aoSAndO5rbWdOArH04KI1AAAAVc"]
[Tue Aug 18 12:56:13.202857 2026] [security2:error] [pid 67073:tid 67206] [client 20.51.153.15:9201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/xm.php"] [unique_id "aoSAnfcmepr5_nHgLbNSDAAAAhU"]
[Tue Aug 18 12:56:13.210602 2026] [security2:error] [pid 66623:tid 66778] [client 74.248.130.103:15418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/aaa.php"] [unique_id "aoSAndO5rbWdOArH04KI1QAAARY"]
[Tue Aug 18 12:56:13.250309 2026] [security2:error] [pid 67073:tid 67144] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/xg.php"] [unique_id "aoSAnfcmepr5_nHgLbNSDQACF0Q"]
[Tue Aug 18 12:56:13.251097 2026] [security2:error] [pid 66623:tid 66888] [client 158.158.74.177:16571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/ova.php"] [unique_id "aoSAndO5rbWdOArH04KI1gAAAYQ"]
[Tue Aug 18 12:56:13.279139 2026] [security2:error] [pid 66623:tid 66872] [client 20.163.43.14:4322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSAndO5rbWdOArH04KI1wAAAXQ"]
[Tue Aug 18 12:56:13.333747 2026] [security2:error] [pid 66623:tid 66822] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kn.php"] [unique_id "aoSAndO5rbWdOArH04KI2AAAAUI"]
[Tue Aug 18 12:56:13.344385 2026] [security2:error] [pid 67073:tid 67219] [client 52.173.121.69:17929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/.cache/x.php"] [unique_id "aoSAnfcmepr5_nHgLbNSEQAAAiI"]
[Tue Aug 18 12:56:13.346477 2026] [security2:error] [pid 67073:tid 67272] [client 20.29.77.16:32963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/ppinfo.php"] [unique_id "aoSAnfcmepr5_nHgLbNSEgAAAlc"]
[Tue Aug 18 12:56:13.356733 2026] [security2:error] [pid 66623:tid 66797] [client 20.104.49.167:36351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/inso.php"] [unique_id "aoSAndO5rbWdOArH04KI2QAAASk"]
[Tue Aug 18 12:56:13.367187 2026] [security2:error] [pid 67073:tid 67295] [client 20.226.56.190:47144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/17.php"] [unique_id "aoSAnfcmepr5_nHgLbNSFQAAAm4"]
[Tue Aug 18 12:56:13.418204 2026] [security2:error] [pid 67073:tid 67279] [client 20.151.109.219:59755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ev.php"] [unique_id "aoSAnfcmepr5_nHgLbNSFwAAAl4"]
[Tue Aug 18 12:56:13.425067 2026] [security2:error] [pid 66623:tid 66877] [client 20.215.241.237:9264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/img.php"] [unique_id "aoSAndO5rbWdOArH04KI2wAAAXk"]
[Tue Aug 18 12:56:13.435086 2026] [security2:error] [pid 67073:tid 67287] [client 20.91.215.254:12004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSAnfcmepr5_nHgLbNSGAAAAmY"]
[Tue Aug 18 12:56:13.441213 2026] [security2:error] [pid 66623:tid 66780] [client 20.171.51.14:1968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/uq.php"] [unique_id "aoSAndO5rbWdOArH04KI3AAAARg"]
[Tue Aug 18 12:56:13.448223 2026] [security2:error] [pid 67073:tid 67098] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/nd.php"] [unique_id "aoSAnfcmepr5_nHgLbNSGQACFhY"]
[Tue Aug 18 12:56:13.453256 2026] [security2:error] [pid 66623:tid 66773] [client 135.225.78.186:13007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/grok.php"] [unique_id "aoSAndO5rbWdOArH04KI3QAAARE"]
[Tue Aug 18 12:56:13.455411 2026] [security2:error] [pid 67073:tid 67306] [client 20.226.56.190:47104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ev.php"] [unique_id "aoSAnfcmepr5_nHgLbNSGgAAAnk"]
[Tue Aug 18 12:56:13.483905 2026] [security2:error] [pid 67073:tid 67205] [client 20.226.6.191:64046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/files/index.php"] [unique_id "aoSAnfcmepr5_nHgLbNSHAAAAhQ"]
[Tue Aug 18 12:56:13.501125 2026] [security2:error] [pid 67073:tid 67218] [client 68.155.156.252:8267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/file1221.php"] [unique_id "aoSAnfcmepr5_nHgLbNSHQAAAiE"]
[Tue Aug 18 12:56:13.521187 2026] [security2:error] [pid 67073:tid 67291] [client 4.223.164.152:4266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSAnfcmepr5_nHgLbNSHwAAAmo"]
[Tue Aug 18 12:56:13.547485 2026] [security2:error] [pid 67073:tid 67221] [client 20.51.153.15:8715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/q.php"] [unique_id "aoSAnfcmepr5_nHgLbNSIgAAAiQ"]
[Tue Aug 18 12:56:13.571578 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:13.571851 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:13.580411 2026] [security2:error] [pid 67073:tid 67263] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/wm.php"] [unique_id "aoSAnfcmepr5_nHgLbNSJQAAAk4"]
[Tue Aug 18 12:56:13.609342 2026] [security2:error] [pid 67073:tid 67267] [client 20.163.43.14:4207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/f35.php"] [unique_id "aoSAnfcmepr5_nHgLbNSJgAAAlI"]
[Tue Aug 18 12:56:13.637962 2026] [security2:error] [pid 67073:tid 67230] [client 20.116.17.175:57637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/save.php"] [unique_id "aoSAnfcmepr5_nHgLbNSKAAAAi0"]
[Tue Aug 18 12:56:13.647731 2026] [security2:error] [pid 67073:tid 67225] [client 20.226.56.190:23765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/xs.php"] [unique_id "aoSAnfcmepr5_nHgLbNSKQAAAig"]
[Tue Aug 18 12:56:13.679608 2026] [security2:error] [pid 67073:tid 67209] [client 20.52.168.85:8019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/zoom1.php"] [unique_id "aoSAnfcmepr5_nHgLbNSKgAAAhg"]
[Tue Aug 18 12:56:13.701602 2026] [security2:error] [pid 66623:tid 66810] [client 74.248.130.103:14417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/gecko.php"] [unique_id "aoSAndO5rbWdOArH04KI3gAAATY"]
[Tue Aug 18 12:56:13.703583 2026] [security2:error] [pid 66623:tid 66819] [client 20.42.19.40:3455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAndO5rbWdOArH04KI3wAAAT8"]
[Tue Aug 18 12:56:13.704356 2026] [security2:error] [pid 67073:tid 67195] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ri.php"] [unique_id "aoSAnfcmepr5_nHgLbNSKwACjHc"]
[Tue Aug 18 12:56:13.713387 2026] [security2:error] [pid 66623:tid 66782] [client 132.196.61.152:34790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/bless6.php"] [unique_id "aoSAndO5rbWdOArH04KI4AAAARo"]
[Tue Aug 18 12:56:13.716844 2026] [security2:error] [pid 67073:tid 67231] [client 159.69.158.189:59266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.chicodareia.com.br"] [uri "/index.php"] [unique_id "aoSAnfcmepr5_nHgLbNSIAAAAi4"], referer: https://www.chicodareia.com.br/
[Tue Aug 18 12:56:13.717019 2026] [security2:error] [pid 66623:tid 66841] [client 104.209.144.33:20432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSAndO5rbWdOArH04KI4QAAAVU"]
[Tue Aug 18 12:56:13.757102 2026] [security2:error] [pid 67073:tid 67326] [client 49.13.130.29:28270] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "dadicamotors.com.br"] [uri "/index.php"] [unique_id "aoSAnfcmepr5_nHgLbNSLgAAAo0"], referer: https://dadicamotors.com.br/
[Tue Aug 18 12:56:13.778670 2026] [security2:error] [pid 67073:tid 67281] [client 20.151.109.219:17597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/xs.php"] [unique_id "aoSAnfcmepr5_nHgLbNSMQAAAmA"]
[Tue Aug 18 12:56:13.824483 2026] [security2:error] [pid 66623:tid 66890] [client 20.51.153.15:9193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/xf.php"] [unique_id "aoSAndO5rbWdOArH04KI4gAAAYY"]
[Tue Aug 18 12:56:13.828577 2026] [security2:error] [pid 66623:tid 66870] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ac.php"] [unique_id "aoSAndO5rbWdOArH04KI4wAAAXI"]
[Tue Aug 18 12:56:13.846464 2026] [security2:error] [pid 67073:tid 67304] [client 20.79.204.6:2228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/images/wso.php"] [unique_id "aoSAnfcmepr5_nHgLbNSNAAAAnc"]
[Tue Aug 18 12:56:13.869589 2026] [security2:error] [pid 66623:tid 66838] [client 172.202.39.151:55540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-login.php"] [unique_id "aoSAndO5rbWdOArH04KI5AAAAVI"]
[Tue Aug 18 12:56:13.873128 2026] [security2:error] [pid 66623:tid 66885] [client 135.225.78.186:13269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/indes.php"] [unique_id "aoSAndO5rbWdOArH04KI5QAAAYE"]
[Tue Aug 18 12:56:13.881494 2026] [security2:error] [pid 67073:tid 67285] [client 213.35.127.232:54581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAnfcmepr5_nHgLbNSNQAAAmQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:13.899035 2026] [security2:error] [pid 66623:tid 66883] [client 158.23.17.4:9377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/bala.php"] [unique_id "aoSAndO5rbWdOArH04KI5gAAAX8"]
[Tue Aug 18 12:56:13.901050 2026] [security2:error] [pid 67073:tid 67079] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/tp.php"] [unique_id "aoSAnfcmepr5_nHgLbNSNgACbwM"]
[Tue Aug 18 12:56:13.927036 2026] [security2:error] [pid 66623:tid 66836] [client 135.225.75.187:58329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/avim.php"] [unique_id "aoSAndO5rbWdOArH04KI5wAAAVA"]
[Tue Aug 18 12:56:13.970876 2026] [security2:error] [pid 66623:tid 66865] [client 4.223.164.152:4849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/155.php"] [unique_id "aoSAndO5rbWdOArH04KI6AAAAW0"]
[Tue Aug 18 12:56:13.976253 2026] [security2:error] [pid 67073:tid 67253] [client 86.120.159.145:54216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAnfcmepr5_nHgLbNSOwAAAkQ"]
[Tue Aug 18 12:56:13.976373 2026] [security2:error] [pid 67073:tid 67253] [client 86.120.159.145:54216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAnfcmepr5_nHgLbNSOwAAAkQ"]
[Tue Aug 18 12:56:13.983693 2026] [security2:error] [pid 66623:tid 66828] [client 52.173.121.69:16460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSAndO5rbWdOArH04KI6QAAAUg"]
[Tue Aug 18 12:56:14.021343 2026] [security2:error] [pid 66623:tid 66884] [client 20.226.56.190:17880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/lmfi2.php"] [unique_id "aoSAntO5rbWdOArH04KI6wAAAYA"]
[Tue Aug 18 12:56:14.057517 2026] [security2:error] [pid 66623:tid 66871] [client 20.151.109.219:21675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/lmfi2.php"] [unique_id "aoSAntO5rbWdOArH04KI7gAAAXM"]
[Tue Aug 18 12:56:14.060640 2026] [security2:error] [pid 66623:tid 66848] [client 20.104.49.167:36294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/aa.php"] [unique_id "aoSAntO5rbWdOArH04KI7wAAAVw"]
[Tue Aug 18 12:56:14.062011 2026] [security2:error] [pid 66623:tid 66809] [client 20.29.77.16:44781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/globals.php"] [unique_id "aoSAntO5rbWdOArH04KI8AAAATU"]
[Tue Aug 18 12:56:14.084708 2026] [security2:error] [pid 67073:tid 67252] [client 158.158.74.177:2633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/p.php"] [unique_id "aoSAnvcmepr5_nHgLbNSPwAAAkM"]
[Tue Aug 18 12:56:14.086122 2026] [security2:error] [pid 66623:tid 66849] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/yz.php"] [unique_id "aoSAntO5rbWdOArH04KI8QAAAV0"]
[Tue Aug 18 12:56:14.111063 2026] [security2:error] [pid 67073:tid 67283] [client 20.163.43.14:4243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/inputs.php"] [unique_id "aoSAnvcmepr5_nHgLbNSRgAAAmI"]
[Tue Aug 18 12:56:14.116224 2026] [security2:error] [pid 66623:tid 66833] [client 20.51.153.15:8750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/eq.php"] [unique_id "aoSAntO5rbWdOArH04KI8gAAAU0"]
[Tue Aug 18 12:56:14.127983 2026] [security2:error] [pid 67073:tid 67226] [client 20.116.17.175:57600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoSAnvcmepr5_nHgLbNSSgAAAik"]
[Tue Aug 18 12:56:14.175591 2026] [authz_core:error] [pid 67073:tid 67198] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:14.175870 2026] [authz_core:error] [pid 67073:tid 67198] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:14.184301 2026] [security2:error] [pid 67073:tid 67268] [client 20.100.169.31:23876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAnvcmepr5_nHgLbNSTwAAAlM"]
[Tue Aug 18 12:56:14.196576 2026] [security2:error] [pid 67073:tid 67159] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/zj.php"] [unique_id "aoSAnvcmepr5_nHgLbNSUgACG1M"]
[Tue Aug 18 12:56:14.217249 2026] [security2:error] [pid 67073:tid 67206] [client 68.155.156.252:21105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/nox.php"] [unique_id "aoSAnvcmepr5_nHgLbNSVgAAAhU"]
[Tue Aug 18 12:56:14.232822 2026] [security2:error] [pid 67073:tid 67220] [client 20.226.56.190:17871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/fd.php"] [unique_id "aoSAnvcmepr5_nHgLbNSWAAAAiM"]
[Tue Aug 18 12:56:14.282983 2026] [security2:error] [pid 66623:tid 66893] [client 20.52.168.85:7840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/about.php7"] [unique_id "aoSAntO5rbWdOArH04KI8wAAAYk"]
[Tue Aug 18 12:56:14.296840 2026] [security2:error] [pid 67073:tid 67241] [client 135.225.78.186:13253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/tTPcH.php"] [unique_id "aoSAnvcmepr5_nHgLbNSXAAAAjg"]
[Tue Aug 18 12:56:14.297935 2026] [security2:error] [pid 67073:tid 67240] [client 213.202.253.4:63721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/memberfuns.php"] [unique_id "aoSAnvcmepr5_nHgLbNSXQAAAjc"], referer: www.google.com
[Tue Aug 18 12:56:14.310332 2026] [security2:error] [pid 67073:tid 67254] [client 74.248.130.103:15403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/xiugai.php"] [unique_id "aoSAnvcmepr5_nHgLbNSXwAAAkU"]
[Tue Aug 18 12:56:14.322796 2026] [security2:error] [pid 67073:tid 67311] [client 103.184.169.37:41851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAnvcmepr5_nHgLbNSYAAAAn4"]
[Tue Aug 18 12:56:14.322903 2026] [security2:error] [pid 67073:tid 67311] [client 103.184.169.37:41851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAnvcmepr5_nHgLbNSYAAAAn4"]
[Tue Aug 18 12:56:14.334815 2026] [security2:error] [pid 67073:tid 67272] [client 20.42.19.40:2928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/ioxi-o.php"] [unique_id "aoSAnvcmepr5_nHgLbNSYQAAAlc"]
[Tue Aug 18 12:56:14.340123 2026] [security2:error] [pid 66623:tid 66811] [client 20.91.215.254:12139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/al.php"] [unique_id "aoSAntO5rbWdOArH04KI9AAAATc"]
[Tue Aug 18 12:56:14.341693 2026] [security2:error] [pid 67073:tid 67279] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kj.php"] [unique_id "aoSAnvcmepr5_nHgLbNSYwAAAl4"]
[Tue Aug 18 12:56:14.352064 2026] [security2:error] [pid 66623:tid 66790] [client 20.51.153.15:8781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ep.php"] [unique_id "aoSAntO5rbWdOArH04KI9QAAASI"]
[Tue Aug 18 12:56:14.393647 2026] [security2:error] [pid 66623:tid 66863] [client 4.223.164.152:4814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/ops.php"] [unique_id "aoSAntO5rbWdOArH04KI9gAAAWs"]
[Tue Aug 18 12:56:14.430807 2026] [security2:error] [pid 67073:tid 67310] [client 20.151.109.219:64134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/fd.php"] [unique_id "aoSAnvcmepr5_nHgLbNSZgAAAn0"]
[Tue Aug 18 12:56:14.437480 2026] [security2:error] [pid 67073:tid 67190] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/x.php"] [unique_id "aoSAnvcmepr5_nHgLbNSaAACFHI"]
[Tue Aug 18 12:56:14.456606 2026] [security2:error] [pid 66623:tid 66845] [client 20.79.204.6:2376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/index/function.php"] [unique_id "aoSAntO5rbWdOArH04KI9wAAAVk"]
[Tue Aug 18 12:56:14.530601 2026] [security2:error] [pid 67073:tid 67292] [client 52.173.121.69:17936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAnvcmepr5_nHgLbNSbAAAAms"]
[Tue Aug 18 12:56:14.573572 2026] [security2:error] [pid 67073:tid 67278] [client 20.215.241.237:65074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/dex.php"] [unique_id "aoSAnvcmepr5_nHgLbNSbwAAAl0"]
[Tue Aug 18 12:56:14.608409 2026] [security2:error] [pid 66623:tid 66789] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/vg.php"] [unique_id "aoSAntO5rbWdOArH04KI-AAAASE"]
[Tue Aug 18 12:56:14.615915 2026] [security2:error] [pid 67073:tid 67267] [client 20.163.43.14:4169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/alfa.php"] [unique_id "aoSAnvcmepr5_nHgLbNScAAAAlI"]
[Tue Aug 18 12:56:14.618386 2026] [security2:error] [pid 66623:tid 66779] [client 192.141.172.134:60081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAntO5rbWdOArH04KI-QAAARc"]
[Tue Aug 18 12:56:14.618482 2026] [security2:error] [pid 66623:tid 66779] [client 192.141.172.134:60081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAntO5rbWdOArH04KI-QAAARc"]
[Tue Aug 18 12:56:14.630775 2026] [security2:error] [pid 67073:tid 67107] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/yn.php"] [unique_id "aoSAnvcmepr5_nHgLbNScQAChh8"]
[Tue Aug 18 12:56:14.717707 2026] [security2:error] [pid 67073:tid 67239] [client 135.225.78.186:13299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/bs1.php"] [unique_id "aoSAnvcmepr5_nHgLbNScwAAAjY"]
[Tue Aug 18 12:56:14.718910 2026] [security2:error] [pid 67073:tid 67282] [client 135.225.75.187:58353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/myfile.php"] [unique_id "aoSAnvcmepr5_nHgLbNSdAAAAmE"]
[Tue Aug 18 12:56:14.721151 2026] [security2:error] [pid 67073:tid 67307] [client 20.215.241.237:9238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/222.php"] [unique_id "aoSAnvcmepr5_nHgLbNSdQAAAno"]
[Tue Aug 18 12:56:14.738661 2026] [security2:error] [pid 67073:tid 67234] [client 20.51.153.15:8736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/rf.php"] [unique_id "aoSAnvcmepr5_nHgLbNSdgAAAjE"]
[Tue Aug 18 12:56:14.741844 2026] [security2:error] [pid 67073:tid 67250] [client 20.151.109.219:21645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/info2.php"] [unique_id "aoSAnvcmepr5_nHgLbNSdwAAAkE"]
[Tue Aug 18 12:56:14.763678 2026] [security2:error] [pid 66623:tid 66844] [client 114.5.214.109:49809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAntO5rbWdOArH04KI_QAAAVg"]
[Tue Aug 18 12:56:14.763799 2026] [security2:error] [pid 66623:tid 66844] [client 114.5.214.109:49809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAntO5rbWdOArH04KI_QAAAVg"]
[Tue Aug 18 12:56:14.792772 2026] [security2:error] [pid 67073:tid 67262] [client 20.226.56.190:30993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/info2.php"] [unique_id "aoSAnvcmepr5_nHgLbNSfAAAAk0"]
[Tue Aug 18 12:56:14.792852 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:14.793283 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:14.801394 2026] [security2:error] [pid 67073:tid 67304] [client 52.238.210.254:46101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/100.php"] [unique_id "aoSAnvcmepr5_nHgLbNSfQAAAnc"]
[Tue Aug 18 12:56:14.806883 2026] [security2:error] [pid 66623:tid 66886] [client 20.116.17.175:57413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAntO5rbWdOArH04KI_wAAAYI"]
[Tue Aug 18 12:56:14.824435 2026] [security2:error] [pid 66623:tid 66846] [client 20.29.77.16:52749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/yindu.php"] [unique_id "aoSAntO5rbWdOArH04KJAAAAAVo"]
[Tue Aug 18 12:56:14.846286 2026] [security2:error] [pid 67073:tid 67314] [client 20.226.6.191:60651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAnvcmepr5_nHgLbNSgQAAAoE"]
[Tue Aug 18 12:56:14.851203 2026] [security2:error] [pid 66623:tid 66783] [client 74.248.130.103:15413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/adminner.php"] [unique_id "aoSAntO5rbWdOArH04KJAQAAARs"]
[Tue Aug 18 12:56:14.856888 2026] [security2:error] [pid 67073:tid 67131] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/11.php"] [unique_id "aoSAnvcmepr5_nHgLbNSgwACWjc"]
[Tue Aug 18 12:56:14.864838 2026] [security2:error] [pid 66623:tid 66860] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/sm.php"] [unique_id "aoSAntO5rbWdOArH04KJAgAAAWg"]
[Tue Aug 18 12:56:14.883989 2026] [security2:error] [pid 66623:tid 66852] [client 20.52.168.85:7821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/cron.php"] [unique_id "aoSAntO5rbWdOArH04KJAwAAAWA"]
[Tue Aug 18 12:56:14.896126 2026] [security2:error] [pid 66623:tid 66867] [client 213.35.127.232:54772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAntO5rbWdOArH04KJBAAAAW8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:14.930162 2026] [security2:error] [pid 67073:tid 67227] [client 20.104.49.167:3566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/img.php"] [unique_id "aoSAnvcmepr5_nHgLbNShQAAAio"]
[Tue Aug 18 12:56:14.944158 2026] [security2:error] [pid 66623:tid 66835] [client 20.163.43.14:4259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/lock360.php"] [unique_id "aoSAntO5rbWdOArH04KJBQAAAU8"]
[Tue Aug 18 12:56:14.980094 2026] [security2:error] [pid 66623:tid 66733] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAntO5rbWdOArH04KJBgABDGA"]
[Tue Aug 18 12:56:14.980211 2026] [security2:error] [pid 66623:tid 66768] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAntO5rbWdOArH04KJBgABDGA"]
[Tue Aug 18 12:56:14.987009 2026] [security2:error] [pid 66623:tid 66889] [client 104.209.144.33:34141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSAntO5rbWdOArH04KJBwAAAYU"]
[Tue Aug 18 12:56:15.039700 2026] [security2:error] [pid 66623:tid 66881] [client 172.202.39.151:15683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/bb.php"] [unique_id "aoSAn9O5rbWdOArH04KJCAAAAX0"]
[Tue Aug 18 12:56:15.041964 2026] [security2:error] [pid 67073:tid 67290] [client 20.91.215.254:12114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp.php"] [unique_id "aoSAn_cmepr5_nHgLbNSiAAAAmk"]
[Tue Aug 18 12:56:15.065531 2026] [security2:error] [pid 67073:tid 67285] [client 20.79.204.6:2377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/info.php"] [unique_id "aoSAn_cmepr5_nHgLbNSiQAAAmQ"]
[Tue Aug 18 12:56:15.073022 2026] [security2:error] [pid 67073:tid 67180] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/vm.php"] [unique_id "aoSAn_cmepr5_nHgLbNSigACWGg"]
[Tue Aug 18 12:56:15.081244 2026] [authz_core:error] [pid 67073:tid 67103] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:15.081524 2026] [authz_core:error] [pid 67073:tid 67103] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:15.105446 2026] [security2:error] [pid 67073:tid 67252] [client 20.151.109.219:64971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/sx.php"] [unique_id "aoSAn_cmepr5_nHgLbNSjAAAAkM"]
[Tue Aug 18 12:56:15.125960 2026] [security2:error] [pid 66623:tid 66778] [client 172.202.39.151:65269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAn9O5rbWdOArH04KJCQAAARY"]
[Tue Aug 18 12:56:15.138855 2026] [security2:error] [pid 66623:tid 66887] [client 135.225.78.186:13286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/hp2.php"] [unique_id "aoSAn9O5rbWdOArH04KJCgAAAYM"]
[Tue Aug 18 12:56:15.140628 2026] [security2:error] [pid 66623:tid 66888] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/28.php"] [unique_id "aoSAn9O5rbWdOArH04KJCwAAAYQ"]
[Tue Aug 18 12:56:15.174467 2026] [security2:error] [pid 66623:tid 66837] [client 20.51.153.15:8397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/album.php"] [unique_id "aoSAn9O5rbWdOArH04KJDAAAAVE"]
[Tue Aug 18 12:56:15.218385 2026] [security2:error] [pid 66623:tid 66814] [client 138.36.100.162:41604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAn9O5rbWdOArH04KJDQAAATo"]
[Tue Aug 18 12:56:15.239285 2026] [security2:error] [pid 66623:tid 66808] [client 20.226.6.191:60644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAn9O5rbWdOArH04KJDgAAATQ"]
[Tue Aug 18 12:56:15.245648 2026] [security2:error] [pid 66623:tid 66788] [client 20.226.56.190:47162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/sx.php"] [unique_id "aoSAn9O5rbWdOArH04KJDwAAASA"]
[Tue Aug 18 12:56:15.253230 2026] [security2:error] [pid 66623:tid 66784] [client 20.29.77.16:47797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/sxx.php"] [unique_id "aoSAn9O5rbWdOArH04KJEAAAARw"]
[Tue Aug 18 12:56:15.277063 2026] [security2:error] [pid 66623:tid 66773] [client 52.173.121.69:17939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAn9O5rbWdOArH04KJEQAAARE"]
[Tue Aug 18 12:56:15.315973 2026] [security2:error] [pid 66623:tid 66806] [client 20.163.43.14:4168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/flower.php"] [unique_id "aoSAn9O5rbWdOArH04KJEwAAATI"]
[Tue Aug 18 12:56:15.343937 2026] [security2:error] [pid 67073:tid 67166] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/eg.php"] [unique_id "aoSAn_cmepr5_nHgLbNSkwACXFo"]
[Tue Aug 18 12:56:15.358762 2026] [security2:error] [pid 66623:tid 66782] [client 74.248.130.103:36818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/file1221.php"] [unique_id "aoSAn9O5rbWdOArH04KJFQAAARo"]
[Tue Aug 18 12:56:15.380256 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:15.380527 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:15.394648 2026] [security2:error] [pid 66623:tid 66841] [client 20.116.17.175:57460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/df.php"] [unique_id "aoSAn9O5rbWdOArH04KJFgAAAVU"]
[Tue Aug 18 12:56:15.395485 2026] [security2:error] [pid 67073:tid 67303] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/m.php"] [unique_id "aoSAn_cmepr5_nHgLbNSlgAAAnY"]
[Tue Aug 18 12:56:15.407485 2026] [security2:error] [pid 67073:tid 67327] [client 20.171.51.14:30962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/32.php"] [unique_id "aoSAn_cmepr5_nHgLbNSmAAAAo4"]
[Tue Aug 18 12:56:15.414419 2026] [security2:error] [pid 67073:tid 67256] [client 74.248.136.165:28142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/jq.php"] [unique_id "aoSAn_cmepr5_nHgLbNSmQAAAkc"]
[Tue Aug 18 12:56:15.435025 2026] [security2:error] [pid 67073:tid 67212] [client 20.151.109.219:45754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/nu.php"] [unique_id "aoSAn_cmepr5_nHgLbNSmgAAAhs"]
[Tue Aug 18 12:56:15.483334 2026] [security2:error] [pid 66623:tid 66816] [client 20.52.168.85:8015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-2019.php"] [unique_id "aoSAn9O5rbWdOArH04KJGAAAATw"]
[Tue Aug 18 12:56:15.492419 2026] [security2:error] [pid 67073:tid 67232] [client 20.51.153.15:8755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/tp.php"] [unique_id "aoSAn_cmepr5_nHgLbNSnQAAAi8"]
[Tue Aug 18 12:56:15.556068 2026] [security2:error] [pid 67073:tid 67208] [client 135.225.78.186:40813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/yb.php"] [unique_id "aoSAn_cmepr5_nHgLbNSpAAAAhc"]
[Tue Aug 18 12:56:15.587761 2026] [security2:error] [pid 67073:tid 67171] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/uk.php"] [unique_id "aoSAn_cmepr5_nHgLbNSpgACJV8"]
[Tue Aug 18 12:56:15.631512 2026] [security2:error] [pid 66623:tid 66814] [client 138.36.100.162:41604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAn9O5rbWdOArH04KJDQAAATo"]
[Tue Aug 18 12:56:15.650139 2026] [security2:error] [pid 67073:tid 67311] [client 20.226.56.190:2513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/nu.php"] [unique_id "aoSAn_cmepr5_nHgLbNSpwAAAn4"]
[Tue Aug 18 12:56:15.654066 2026] [security2:error] [pid 67073:tid 67318] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/nl.php"] [unique_id "aoSAn_cmepr5_nHgLbNSqAAAAoU"]
[Tue Aug 18 12:56:15.679828 2026] [authz_core:error] [pid 67073:tid 67153] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:15.680094 2026] [authz_core:error] [pid 67073:tid 67153] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:15.685954 2026] [security2:error] [pid 67073:tid 67206] [client 20.79.204.6:2200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/profile.php"] [unique_id "aoSAn_cmepr5_nHgLbNSqwAAAhU"]
[Tue Aug 18 12:56:15.687738 2026] [security2:error] [pid 66623:tid 66787] [client 20.163.43.14:4191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/13.php"] [unique_id "aoSAn9O5rbWdOArH04KJGgAAAR8"]
[Tue Aug 18 12:56:15.704170 2026] [security2:error] [pid 67073:tid 67300] [client 20.226.6.191:64063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAn_cmepr5_nHgLbNSrAAAAnM"]
[Tue Aug 18 12:56:15.747440 2026] [security2:error] [pid 66623:tid 66856] [client 20.250.13.23:19456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/manager.php"] [unique_id "aoSAn9O5rbWdOArH04KJGwAAAWQ"]
[Tue Aug 18 12:56:15.776240 2026] [security2:error] [pid 67073:tid 67306] [client 20.151.109.219:17596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ko.php"] [unique_id "aoSAn_cmepr5_nHgLbNSrwAAAnk"]
[Tue Aug 18 12:56:15.784709 2026] [security2:error] [pid 67073:tid 67080] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/creds.php"] [unique_id "aoSAn_cmepr5_nHgLbNSsAACMgQ"]
[Tue Aug 18 12:56:15.803626 2026] [security2:error] [pid 67073:tid 67276] [client 20.51.153.15:8793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/eg.php"] [unique_id "aoSAn_cmepr5_nHgLbNSsQAAAls"]
[Tue Aug 18 12:56:15.819819 2026] [security2:error] [pid 67073:tid 67274] [client 20.91.215.254:12129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-activat.php"] [unique_id "aoSAn_cmepr5_nHgLbNSsgAAAlk"]
[Tue Aug 18 12:56:15.822119 2026] [security2:error] [pid 66623:tid 66865] [client 52.173.121.69:24777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSAn9O5rbWdOArH04KJHAAAAW0"]
[Tue Aug 18 12:56:15.876157 2026] [security2:error] [pid 67073:tid 67278] [client 135.225.75.187:62335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/xmy.php"] [unique_id "aoSAn_cmepr5_nHgLbNSuAAAAl0"]
[Tue Aug 18 12:56:15.877544 2026] [security2:error] [pid 67073:tid 67305] [client 5.31.227.224:29905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAn_cmepr5_nHgLbNStwAAAng"]
[Tue Aug 18 12:56:15.877678 2026] [security2:error] [pid 67073:tid 67305] [client 5.31.227.224:29905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAn_cmepr5_nHgLbNStwAAAng"]
[Tue Aug 18 12:56:15.901030 2026] [security2:error] [pid 67073:tid 67286] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/68.php"] [unique_id "aoSAn_cmepr5_nHgLbNSuwAAAmU"]
[Tue Aug 18 12:56:15.912119 2026] [security2:error] [pid 66623:tid 66767] [client 74.248.130.103:25738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/inx.php"] [unique_id "aoSAn9O5rbWdOArH04KJHQAAAQs"]
[Tue Aug 18 12:56:15.913071 2026] [security2:error] [pid 67073:tid 67240] [client 213.35.127.232:54992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAn_cmepr5_nHgLbNSwAAAAjc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:15.922333 2026] [security2:error] [pid 67073:tid 67309] [client 20.104.49.167:36318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/222.php"] [unique_id "aoSAn_cmepr5_nHgLbNSwgAAAnw"]
[Tue Aug 18 12:56:15.927133 2026] [security2:error] [pid 67073:tid 67245] [client 68.155.154.236:16343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSAn_cmepr5_nHgLbNSwwAAAjw"]
[Tue Aug 18 12:56:15.949305 2026] [security2:error] [pid 66623:tid 66809] [client 20.171.51.14:58431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/73.php"] [unique_id "aoSAn9O5rbWdOArH04KJHgAAATU"]
[Tue Aug 18 12:56:15.961140 2026] [security2:error] [pid 67073:tid 67307] [client 20.226.56.190:45029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ko.php"] [unique_id "aoSAn_cmepr5_nHgLbNSxwAAAno"]
[Tue Aug 18 12:56:15.965864 2026] [security2:error] [pid 67073:tid 67224] [client 68.155.156.252:21109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/akismet.php"] [unique_id "aoSAn_cmepr5_nHgLbNSyAAAAic"]
[Tue Aug 18 12:56:15.971634 2026] [security2:error] [pid 67073:tid 67234] [client 135.225.78.186:13004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/vc.php"] [unique_id "aoSAn_cmepr5_nHgLbNSyQAAAjE"]
[Tue Aug 18 12:56:15.981179 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:15.981330 2026] [security2:error] [pid 67073:tid 67176] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ho.php"] [unique_id "aoSAn_cmepr5_nHgLbNSywACGGQ"]
[Tue Aug 18 12:56:15.981453 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:16.019610 2026] [security2:error] [pid 67073:tid 67215] [client 158.23.17.4:9280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/222.php"] [unique_id "aoSAoPcmepr5_nHgLbNSzAAAAh4"]
[Tue Aug 18 12:56:16.030336 2026] [security2:error] [pid 66623:tid 66849] [client 20.163.43.14:4181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/cc.php"] [unique_id "aoSAoNO5rbWdOArH04KJHwAAAV0"]
[Tue Aug 18 12:56:16.044045 2026] [security2:error] [pid 67073:tid 67326] [client 20.29.77.16:27223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/settings.php"] [unique_id "aoSAoPcmepr5_nHgLbNSzgAAAo0"]
[Tue Aug 18 12:56:16.060702 2026] [security2:error] [pid 66623:tid 66876] [client 158.158.74.177:16545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/pages.php"] [unique_id "aoSAoNO5rbWdOArH04KJIAAAAXg"]
[Tue Aug 18 12:56:16.070672 2026] [security2:error] [pid 67073:tid 67248] [client 20.100.169.31:30277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/404.php"] [unique_id "aoSAoPcmepr5_nHgLbNS0AAAAj8"]
[Tue Aug 18 12:56:16.089134 2026] [security2:error] [pid 67073:tid 67231] [client 20.151.109.219:12926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/pl.php"] [unique_id "aoSAoPcmepr5_nHgLbNS0QAAAi4"]
[Tue Aug 18 12:56:16.090130 2026] [security2:error] [pid 67073:tid 67242] [client 20.52.168.85:8009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/gecko-new.php"] [unique_id "aoSAoPcmepr5_nHgLbNS0gAAAjk"]
[Tue Aug 18 12:56:16.122597 2026] [security2:error] [pid 67073:tid 67275] [client 104.209.144.33:19624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSAoPcmepr5_nHgLbNS1AAAAlo"]
[Tue Aug 18 12:56:16.136099 2026] [security2:error] [pid 67073:tid 67302] [client 20.51.153.15:9128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/uk.php"] [unique_id "aoSAoPcmepr5_nHgLbNS1gAAAnU"]
[Tue Aug 18 12:56:16.148898 2026] [security2:error] [pid 67073:tid 67296] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/jl.php"] [unique_id "aoSAoPcmepr5_nHgLbNS1wAAAm8"]
[Tue Aug 18 12:56:16.164738 2026] [security2:error] [pid 67073:tid 67271] [client 37.40.227.74:56666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAoPcmepr5_nHgLbNS2AAAAlY"]
[Tue Aug 18 12:56:16.164853 2026] [security2:error] [pid 67073:tid 67271] [client 37.40.227.74:56666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAoPcmepr5_nHgLbNS2AAAAlY"]
[Tue Aug 18 12:56:16.180383 2026] [security2:error] [pid 67073:tid 67135] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/97.php"] [unique_id "aoSAoPcmepr5_nHgLbNS2QACaDs"]
[Tue Aug 18 12:56:16.191192 2026] [security2:error] [pid 67073:tid 67217] [client 172.182.200.96:14169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSAoPcmepr5_nHgLbNS2gAAAiA"]
[Tue Aug 18 12:56:16.211123 2026] [security2:error] [pid 67073:tid 67244] [client 20.226.56.190:3014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/pl.php"] [unique_id "aoSAoPcmepr5_nHgLbNS3AAAAjs"]
[Tue Aug 18 12:56:16.290296 2026] [security2:error] [pid 67073:tid 67281] [client 20.79.204.6:2378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/sx.php"] [unique_id "aoSAoPcmepr5_nHgLbNS3wAAAmA"]
[Tue Aug 18 12:56:16.313351 2026] [security2:error] [pid 67073:tid 67329] [client 20.226.6.191:64063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/rip.php"] [unique_id "aoSAoPcmepr5_nHgLbNS4QAAApA"]
[Tue Aug 18 12:56:16.367689 2026] [security2:error] [pid 67073:tid 67313] [client 20.163.43.14:4307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAoPcmepr5_nHgLbNS4gAAAoA"]
[Tue Aug 18 12:56:16.392575 2026] [security2:error] [pid 67073:tid 67303] [client 135.225.78.186:13014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/pema.php"] [unique_id "aoSAoPcmepr5_nHgLbNS5AAAAnY"]
[Tue Aug 18 12:56:16.405641 2026] [security2:error] [pid 67073:tid 67294] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/tq.php"] [unique_id "aoSAoPcmepr5_nHgLbNS5gAAAm0"]
[Tue Aug 18 12:56:16.405781 2026] [security2:error] [pid 67073:tid 67091] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/rh.php"] [unique_id "aoSAoPcmepr5_nHgLbNS5wACIQ8"]
[Tue Aug 18 12:56:16.419512 2026] [security2:error] [pid 67073:tid 67212] [client 20.51.153.15:8792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/creds.php"] [unique_id "aoSAoPcmepr5_nHgLbNS6QAAAhs"]
[Tue Aug 18 12:56:16.443791 2026] [security2:error] [pid 67073:tid 67226] [client 20.151.109.219:24837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/env.php"] [unique_id "aoSAoPcmepr5_nHgLbNS6gAAAik"]
[Tue Aug 18 12:56:16.467642 2026] [security2:error] [pid 67073:tid 67220] [client 74.248.130.103:38679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/reviall.php"] [unique_id "aoSAoPcmepr5_nHgLbNS6wAAAiM"]
[Tue Aug 18 12:56:16.503610 2026] [security2:error] [pid 67073:tid 67222] [client 20.215.241.237:9263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/key.php"] [unique_id "aoSAoPcmepr5_nHgLbNS7QAAAiU"]
[Tue Aug 18 12:56:16.532523 2026] [security2:error] [pid 67073:tid 67317] [client 85.208.96.198:27764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754206526/1756598400/"] [unique_id "aoSAoPcmepr5_nHgLbNS7gAAAoQ"]
[Tue Aug 18 12:56:16.532649 2026] [security2:error] [pid 67073:tid 67317] [client 85.208.96.198:27764] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754206526/1756598400/"] [unique_id "aoSAoPcmepr5_nHgLbNS7gAAAoQ"]
[Tue Aug 18 12:56:16.564749 2026] [authz_core:error] [pid 67073:tid 67147] [remote 57.141.22.106:64130] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:16.565021 2026] [authz_core:error] [pid 67073:tid 67147] [remote 57.141.22.106:64130] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:16.586774 2026] [security2:error] [pid 67073:tid 67287] [client 74.248.136.165:61419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/sys.php"] [unique_id "aoSAoPcmepr5_nHgLbNS8wAAAmY"]
[Tue Aug 18 12:56:16.596373 2026] [security2:error] [pid 67073:tid 67251] [client 20.91.215.254:11922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSAoPcmepr5_nHgLbNS9AAAAkI"]
[Tue Aug 18 12:56:16.628148 2026] [security2:error] [pid 66623:tid 66831] [client 20.104.49.167:19328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/key.php"] [unique_id "aoSAoNO5rbWdOArH04KJIwAAAUs"]
[Tue Aug 18 12:56:16.636661 2026] [security2:error] [pid 67073:tid 67081] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/yg.php"] [unique_id "aoSAoPcmepr5_nHgLbNS9QACeQU"]
[Tue Aug 18 12:56:16.667377 2026] [security2:error] [pid 66623:tid 66882] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/cv.php"] [unique_id "aoSAoNO5rbWdOArH04KJJAAAAX4"]
[Tue Aug 18 12:56:16.676124 2026] [security2:error] [pid 67073:tid 67276] [client 20.51.153.15:8744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ho.php"] [unique_id "aoSAoPcmepr5_nHgLbNS-AAAAls"]
[Tue Aug 18 12:56:16.689131 2026] [security2:error] [pid 67073:tid 67264] [client 20.52.168.85:7865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/add_actualites.php"] [unique_id "aoSAoPcmepr5_nHgLbNS-QAAAk8"]
[Tue Aug 18 12:56:16.704994 2026] [security2:error] [pid 67073:tid 67332] [client 20.163.43.14:4342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSAoPcmepr5_nHgLbNS-gAAApM"]
[Tue Aug 18 12:56:16.746943 2026] [security2:error] [pid 67073:tid 67305] [client 104.209.144.33:29833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSAoPcmepr5_nHgLbNS-wAAAng"]
[Tue Aug 18 12:56:16.749797 2026] [security2:error] [pid 66623:tid 66871] [client 157.20.138.62:60411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAoNO5rbWdOArH04KJJQAAAXM"]
[Tue Aug 18 12:56:16.749911 2026] [security2:error] [pid 66623:tid 66871] [client 157.20.138.62:60411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAoNO5rbWdOArH04KJJQAAAXM"]
[Tue Aug 18 12:56:16.769361 2026] [autoindex:error] [pid 67073:tid 67263] [client 20.226.6.191:55807] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:16.809605 2026] [security2:error] [pid 67073:tid 67265] [client 135.225.78.186:13260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/sh.php"] [unique_id "aoSAoPcmepr5_nHgLbNS_wAAAlA"]
[Tue Aug 18 12:56:16.814027 2026] [security2:error] [pid 66623:tid 66868] [client 20.226.56.190:23767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/env.php"] [unique_id "aoSAoNO5rbWdOArH04KJJgAAAXA"]
[Tue Aug 18 12:56:16.815531 2026] [security2:error] [pid 67073:tid 67309] [client 20.226.6.191:55807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAoPcmepr5_nHgLbNTBQAAAnw"]
[Tue Aug 18 12:56:16.821651 2026] [security2:error] [pid 67073:tid 67310] [client 20.151.109.219:65008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/mz.php"] [unique_id "aoSAoPcmepr5_nHgLbNTBwAAAn0"]
[Tue Aug 18 12:56:16.834701 2026] [security2:error] [pid 67073:tid 67148] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/et.php"] [unique_id "aoSAoPcmepr5_nHgLbNTCQACJ0g"]
[Tue Aug 18 12:56:16.879825 2026] [security2:error] [pid 66623:tid 66863] [client 172.202.39.151:50179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/cah.php"] [unique_id "aoSAoNO5rbWdOArH04KJKAAAAWs"]
[Tue Aug 18 12:56:16.893367 2026] [security2:error] [pid 67073:tid 67221] [client 20.79.204.6:2634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSAoPcmepr5_nHgLbNTDQAAAiQ"]
[Tue Aug 18 12:56:16.901984 2026] [security2:error] [pid 66623:tid 66845] [client 52.173.121.69:17950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSAoNO5rbWdOArH04KJKQAAAVk"]
[Tue Aug 18 12:56:16.924837 2026] [security2:error] [pid 67073:tid 67261] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/un.php"] [unique_id "aoSAoPcmepr5_nHgLbNTDwAAAkw"]
[Tue Aug 18 12:56:16.928311 2026] [security2:error] [pid 67073:tid 67207] [client 213.35.127.232:55212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAoPcmepr5_nHgLbNTEAAAAhY"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:16.933116 2026] [security2:error] [pid 67073:tid 67326] [client 74.248.130.103:25761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/11.php"] [unique_id "aoSAoPcmepr5_nHgLbNTEQAAAo0"]
[Tue Aug 18 12:56:16.966790 2026] [security2:error] [pid 66623:tid 66892] [client 20.116.17.175:57433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSAoNO5rbWdOArH04KJKgAAAYg"]
[Tue Aug 18 12:56:16.967977 2026] [security2:error] [pid 67073:tid 67262] [client 20.226.56.190:28271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/mz.php"] [unique_id "aoSAoPcmepr5_nHgLbNTEwAAAk0"]
[Tue Aug 18 12:56:16.975732 2026] [security2:error] [pid 67073:tid 67321] [client 20.51.153.15:8815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/97.php"] [unique_id "aoSAoPcmepr5_nHgLbNTFAAAAog"]
[Tue Aug 18 12:56:16.994448 2026] [security2:error] [pid 66623:tid 66799] [client 20.215.241.237:27245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/puc.php"] [unique_id "aoSAoNO5rbWdOArH04KJKwAAASs"]
[Tue Aug 18 12:56:16.996967 2026] [security2:error] [pid 66623:tid 66795] [client 135.225.75.187:17716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/xda.php"] [unique_id "aoSAoNO5rbWdOArH04KJLAAAASc"]
[Tue Aug 18 12:56:17.030055 2026] [security2:error] [pid 67073:tid 67315] [client 20.250.13.23:13766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/w1.php"] [unique_id "aoSAofcmepr5_nHgLbNTFQAAAoI"]
[Tue Aug 18 12:56:17.036746 2026] [security2:error] [pid 66623:tid 66874] [client 20.163.43.14:4163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/01.php"] [unique_id "aoSAodO5rbWdOArH04KJLQAAAXY"]
[Tue Aug 18 12:56:17.088519 2026] [security2:error] [pid 67073:tid 67195] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/of.php"] [unique_id "aoSAofcmepr5_nHgLbNTFwACb3c"]
[Tue Aug 18 12:56:17.179532 2026] [security2:error] [pid 66623:tid 66839] [client 68.155.156.252:8314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/admin.php"] [unique_id "aoSAodO5rbWdOArH04KJLwAAAVM"]
[Tue Aug 18 12:56:17.181991 2026] [security2:error] [pid 67073:tid 67331] [client 20.151.109.219:21662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ft.php"] [unique_id "aoSAofcmepr5_nHgLbNTHQAAApI"]
[Tue Aug 18 12:56:17.183285 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:17.183515 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:17.186108 2026] [security2:error] [pid 67073:tid 67289] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/evil.php"] [unique_id "aoSAofcmepr5_nHgLbNTHgAAAmg"]
[Tue Aug 18 12:56:17.230876 2026] [security2:error] [pid 67073:tid 67244] [client 135.225.78.186:13295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/button.php"] [unique_id "aoSAofcmepr5_nHgLbNTHwAAAjs"]
[Tue Aug 18 12:56:17.266369 2026] [security2:error] [pid 67073:tid 67228] [client 20.215.241.237:61075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAofcmepr5_nHgLbNTIQAAAis"]
[Tue Aug 18 12:56:17.271265 2026] [security2:error] [pid 67073:tid 67225] [client 158.158.34.183:11484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/disagraeosc.php"] [unique_id "aoSAofcmepr5_nHgLbNTIgAAAig"]
[Tue Aug 18 12:56:17.283253 2026] [security2:error] [pid 66623:tid 66846] [client 20.29.77.16:57061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/spip.php"] [unique_id "aoSAodO5rbWdOArH04KJMQAAAVo"]
[Tue Aug 18 12:56:17.284933 2026] [security2:error] [pid 66623:tid 66783] [client 20.51.153.15:8802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/rh.php"] [unique_id "aoSAodO5rbWdOArH04KJMgAAARs"]
[Tue Aug 18 12:56:17.292500 2026] [security2:error] [pid 67073:tid 67170] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/bu.php"] [unique_id "aoSAofcmepr5_nHgLbNTIwACNF4"]
[Tue Aug 18 12:56:17.292858 2026] [security2:error] [pid 66623:tid 66820] [client 20.52.168.85:8004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/browse.php"] [unique_id "aoSAodO5rbWdOArH04KJMwAAAUA"]
[Tue Aug 18 12:56:17.304263 2026] [security2:error] [pid 67073:tid 67234] [client 149.34.210.141:52656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAofcmepr5_nHgLbNTJAAAAjE"]
[Tue Aug 18 12:56:17.314197 2026] [security2:error] [pid 66623:tid 66789] [client 20.91.215.254:11915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/past1.php"] [unique_id "aoSAodO5rbWdOArH04KJNAAAASE"]
[Tue Aug 18 12:56:17.352028 2026] [security2:error] [pid 67073:tid 67312] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAofcmepr5_nHgLbNTGgACfyo"]
[Tue Aug 18 12:56:17.364358 2026] [security2:error] [pid 67073:tid 67281] [client 20.163.43.14:4318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/lv.php"] [unique_id "aoSAofcmepr5_nHgLbNTKAAAAmA"]
[Tue Aug 18 12:56:17.384049 2026] [security2:error] [pid 67073:tid 67324] [client 20.226.6.191:60635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/moon.php"] [unique_id "aoSAofcmepr5_nHgLbNTKQAAAos"]
[Tue Aug 18 12:56:17.418739 2026] [security2:error] [pid 67073:tid 67329] [client 74.248.130.103:36807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/File.php"] [unique_id "aoSAofcmepr5_nHgLbNTKwAAApA"]
[Tue Aug 18 12:56:17.453409 2026] [security2:error] [pid 67073:tid 67313] [client 104.209.144.33:36489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSAofcmepr5_nHgLbNTLAAAAoA"]
[Tue Aug 18 12:56:17.453558 2026] [security2:error] [pid 67073:tid 67282] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/pw.php"] [unique_id "aoSAofcmepr5_nHgLbNTLQAAAmE"]
[Tue Aug 18 12:56:17.490776 2026] [security2:error] [pid 67073:tid 67128] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/rn.php"] [unique_id "aoSAofcmepr5_nHgLbNTMAACdjQ"]
[Tue Aug 18 12:56:17.511426 2026] [security2:error] [pid 66623:tid 66852] [client 20.79.204.6:2400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAodO5rbWdOArH04KJNwAAAWA"]
[Tue Aug 18 12:56:17.558463 2026] [security2:error] [pid 66623:tid 66834] [client 52.139.47.57:47634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/as.php"] [unique_id "aoSAodO5rbWdOArH04KJOAAAAU4"]
[Tue Aug 18 12:56:17.566365 2026] [security2:error] [pid 67073:tid 67218] [client 20.51.153.15:9088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/yg.php"] [unique_id "aoSAofcmepr5_nHgLbNTMgAAAiE"]
[Tue Aug 18 12:56:17.571117 2026] [security2:error] [pid 67073:tid 67234] [client 149.34.210.141:52656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAofcmepr5_nHgLbNTJAAAAjE"]
[Tue Aug 18 12:56:17.641861 2026] [security2:error] [pid 66623:tid 66880] [client 20.226.56.190:45048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ft.php"] [unique_id "aoSAodO5rbWdOArH04KJOgAAAXw"]
[Tue Aug 18 12:56:17.648420 2026] [security2:error] [pid 66623:tid 66840] [client 135.225.78.186:13255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/wlc.php"] [unique_id "aoSAodO5rbWdOArH04KJOwAAAVQ"]
[Tue Aug 18 12:56:17.675760 2026] [security2:error] [pid 66623:tid 66804] [client 20.104.49.167:3570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/chosen.php"] [unique_id "aoSAodO5rbWdOArH04KJPQAAATA"]
[Tue Aug 18 12:56:17.685083 2026] [security2:error] [pid 67073:tid 67219] [client 20.151.109.219:17599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/h.php"] [unique_id "aoSAofcmepr5_nHgLbNTNgAAAiI"]
[Tue Aug 18 12:56:17.709161 2026] [security2:error] [pid 67073:tid 67311] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/fn.php"] [unique_id "aoSAofcmepr5_nHgLbNTOAAAAn4"]
[Tue Aug 18 12:56:17.710072 2026] [security2:error] [pid 67073:tid 67145] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ut.php"] [unique_id "aoSAofcmepr5_nHgLbNTOQAChUU"]
[Tue Aug 18 12:56:17.714978 2026] [security2:error] [pid 67073:tid 67317] [client 20.163.43.14:4107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/new.php"] [unique_id "aoSAofcmepr5_nHgLbNTOgAAAoQ"]
[Tue Aug 18 12:56:17.740439 2026] [security2:error] [pid 67073:tid 67316] [client 132.196.61.152:60340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/special.php"] [unique_id "aoSAofcmepr5_nHgLbNTOwAAAoM"]
[Tue Aug 18 12:56:17.786419 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:17.786691 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:17.796001 2026] [security2:error] [pid 66623:tid 66866] [client 20.215.241.237:20994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/domvf.php"] [unique_id "aoSAodO5rbWdOArH04KJPgAAAW4"]
[Tue Aug 18 12:56:17.812658 2026] [security2:error] [pid 66623:tid 66887] [client 20.226.6.191:32268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/cache.php"] [unique_id "aoSAodO5rbWdOArH04KJPwAAAYM"]
[Tue Aug 18 12:56:17.818843 2026] [security2:error] [pid 66623:tid 66888] [client 74.248.136.165:64152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/pp.php"] [unique_id "aoSAodO5rbWdOArH04KJQAAAAYQ"]
[Tue Aug 18 12:56:17.829147 2026] [security2:error] [pid 67073:tid 67211] [client 158.23.17.4:9289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/routes.php"] [unique_id "aoSAofcmepr5_nHgLbNTPwAAAho"]
[Tue Aug 18 12:56:17.847119 2026] [security2:error] [pid 67073:tid 67251] [client 20.51.153.15:8768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/et.php"] [unique_id "aoSAofcmepr5_nHgLbNTQAAAAkI"]
[Tue Aug 18 12:56:17.871081 2026] [security2:error] [pid 66623:tid 66861] [client 74.248.130.103:36828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/fi22.php"] [unique_id "aoSAodO5rbWdOArH04KJQQAAAWk"]
[Tue Aug 18 12:56:17.902294 2026] [security2:error] [pid 67073:tid 67293] [client 20.52.168.85:8016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/contentloader1.php"] [unique_id "aoSAofcmepr5_nHgLbNTQgAAAmw"]
[Tue Aug 18 12:56:17.920360 2026] [security2:error] [pid 67073:tid 67299] [client 20.116.17.175:57649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/usr.php"] [unique_id "aoSAofcmepr5_nHgLbNTQwAAAnI"]
[Tue Aug 18 12:56:17.942110 2026] [security2:error] [pid 67073:tid 67230] [client 213.35.127.232:55443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAofcmepr5_nHgLbNTRAAAAi0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:17.945896 2026] [security2:error] [pid 67073:tid 67235] [client 68.155.154.236:16263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSAofcmepr5_nHgLbNTRQAAAjI"]
[Tue Aug 18 12:56:17.952305 2026] [security2:error] [pid 67073:tid 67276] [client 20.226.56.190:20352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/h.php"] [unique_id "aoSAofcmepr5_nHgLbNTRwAAAls"]
[Tue Aug 18 12:56:17.956499 2026] [security2:error] [pid 67073:tid 67082] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/eh.php"] [unique_id "aoSAofcmepr5_nHgLbNTSAACTwY"]
[Tue Aug 18 12:56:17.989566 2026] [security2:error] [pid 66623:tid 66785] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kf.php"] [unique_id "aoSAodO5rbWdOArH04KJRAAAAR0"]
[Tue Aug 18 12:56:18.007765 2026] [security2:error] [pid 66623:tid 66877] [client 172.202.39.151:55542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSAotO5rbWdOArH04KJRQAAAXk"]
[Tue Aug 18 12:56:18.054397 2026] [security2:error] [pid 66623:tid 66875] [client 20.163.43.14:4273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/222.php"] [unique_id "aoSAotO5rbWdOArH04KJRgAAAXc"]
[Tue Aug 18 12:56:18.062538 2026] [security2:error] [pid 67073:tid 67319] [client 20.29.77.16:20839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/search.php"] [unique_id "aoSAovcmepr5_nHgLbNTTQAAAoY"]
[Tue Aug 18 12:56:18.071204 2026] [security2:error] [pid 67073:tid 67295] [client 135.225.78.186:13055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/fi.php"] [unique_id "aoSAovcmepr5_nHgLbNTTwAAAm4"]
[Tue Aug 18 12:56:18.090591 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:18.091060 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:18.101576 2026] [security2:error] [pid 67073:tid 67287] [client 20.91.215.254:11905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/file61.php"] [unique_id "aoSAovcmepr5_nHgLbNTUgAAAmY"]
[Tue Aug 18 12:56:18.107710 2026] [security2:error] [pid 67073:tid 67249] [client 20.215.241.237:51464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/chosen.php"] [unique_id "aoSAovcmepr5_nHgLbNTUwAAAkA"]
[Tue Aug 18 12:56:18.118893 2026] [security2:error] [pid 66623:tid 66784] [client 104.209.144.33:35889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSAotO5rbWdOArH04KJRwAAARw"]
[Tue Aug 18 12:56:18.162433 2026] [autoindex:error] [pid 67073:tid 67306] [client 20.79.204.6:2423] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:18.177069 2026] [security2:error] [pid 67073:tid 67221] [client 135.225.75.187:29760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/zz.php"] [unique_id "aoSAovcmepr5_nHgLbNTVgAAAiQ"]
[Tue Aug 18 12:56:18.182293 2026] [security2:error] [pid 67073:tid 67261] [client 20.51.153.15:9127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/of.php"] [unique_id "aoSAovcmepr5_nHgLbNTVwAAAkw"]
[Tue Aug 18 12:56:18.188199 2026] [security2:error] [pid 67073:tid 67175] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ad.php"] [unique_id "aoSAovcmepr5_nHgLbNTWAACFmM"]
[Tue Aug 18 12:56:18.242766 2026] [security2:error] [pid 66623:tid 66810] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/su.php"] [unique_id "aoSAotO5rbWdOArH04KJSAAAATY"]
[Tue Aug 18 12:56:18.253119 2026] [autoindex:error] [pid 67073:tid 67308] [client 172.202.39.151:50193] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/js/tinymce/plugins/compat3x/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:18.271923 2026] [security2:error] [pid 67073:tid 67315] [client 20.226.56.190:31637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/40.php"] [unique_id "aoSAovcmepr5_nHgLbNTXQAAAoI"]
[Tue Aug 18 12:56:18.325403 2026] [security2:error] [pid 67073:tid 67240] [client 79.127.164.8:35640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/localhost.bak"] [unique_id "aoSAovcmepr5_nHgLbNTYAAAAjc"], referer: https://medihub.com.br/localhost.bak
[Tue Aug 18 12:56:18.331759 2026] [security2:error] [pid 67073:tid 67314] [client 20.215.241.237:44770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSAovcmepr5_nHgLbNTYQAAAoE"]
[Tue Aug 18 12:56:18.362112 2026] [security2:error] [pid 67073:tid 67301] [client 20.79.204.6:2423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAovcmepr5_nHgLbNTZQAAAnQ"]
[Tue Aug 18 12:56:18.367748 2026] [security2:error] [pid 66623:tid 66850] [client 20.151.109.219:61384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/40.php"] [unique_id "aoSAotO5rbWdOArH04KJTQAAAV4"]
[Tue Aug 18 12:56:18.381227 2026] [security2:error] [pid 67073:tid 67248] [client 20.163.43.14:4349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/chosen.php"] [unique_id "aoSAovcmepr5_nHgLbNTaQAAAj8"]
[Tue Aug 18 12:56:18.393904 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:18.394156 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:18.397224 2026] [security2:error] [pid 67073:tid 67110] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/vd.php"] [unique_id "aoSAovcmepr5_nHgLbNTawACKCI"]
[Tue Aug 18 12:56:18.431766 2026] [security2:error] [pid 66623:tid 66778] [client 178.153.171.161:58888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAotO5rbWdOArH04KJTgAAARY"]
[Tue Aug 18 12:56:18.431931 2026] [security2:error] [pid 66623:tid 66778] [client 178.153.171.161:58888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAotO5rbWdOArH04KJTgAAARY"]
[Tue Aug 18 12:56:18.453510 2026] [security2:error] [pid 67073:tid 67290] [client 20.51.153.15:8396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/bu.php"] [unique_id "aoSAovcmepr5_nHgLbNTbQAAAmk"]
[Tue Aug 18 12:56:18.482578 2026] [autoindex:error] [pid 67073:tid 67239] [client 20.226.6.191:36367] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:18.484100 2026] [security2:error] [pid 67073:tid 67198] [remote 162.241.153.188:54182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.153.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "impactads.com.br"] [uri "/wp-login.php"] [unique_id "aoSAovcmepr5_nHgLbNTbwACeHo"]
[Tue Aug 18 12:56:18.484125 2026] [security2:error] [pid 67073:tid 67256] [client 158.158.34.183:11519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/24.php"] [unique_id "aoSAovcmepr5_nHgLbNTcAAAAkc"]
[Tue Aug 18 12:56:18.489970 2026] [security2:error] [pid 67073:tid 67246] [client 135.225.78.186:40798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/chris.php"] [unique_id "aoSAovcmepr5_nHgLbNTcgAAAj0"]
[Tue Aug 18 12:56:18.490824 2026] [security2:error] [pid 66623:tid 66822] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/wp-key.php"] [unique_id "aoSAotO5rbWdOArH04KJUAAAAUI"]
[Tue Aug 18 12:56:18.491292 2026] [security2:error] [pid 67073:tid 67253] [client 68.155.156.252:38864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/ajax.php"] [unique_id "aoSAovcmepr5_nHgLbNTcwAAAkQ"]
[Tue Aug 18 12:56:18.494564 2026] [security2:error] [pid 66623:tid 66885] [client 20.226.56.190:2537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ee.php"] [unique_id "aoSAotO5rbWdOArH04KJUQAAAYE"]
[Tue Aug 18 12:56:18.503562 2026] [security2:error] [pid 66623:tid 66772] [client 20.52.168.85:8000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/upfile.php"] [unique_id "aoSAotO5rbWdOArH04KJUgAAARA"]
[Tue Aug 18 12:56:18.515837 2026] [security2:error] [pid 67073:tid 67285] [client 74.248.130.103:14403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAovcmepr5_nHgLbNTdgAAAmQ"]
[Tue Aug 18 12:56:18.545178 2026] [security2:error] [pid 67073:tid 67329] [client 172.202.39.151:50193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/system_log.php"] [unique_id "aoSAovcmepr5_nHgLbNTeAAAApA"]
[Tue Aug 18 12:56:18.594238 2026] [security2:error] [pid 67073:tid 67076] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/56.php"] [unique_id "aoSAovcmepr5_nHgLbNTewACSQA"]
[Tue Aug 18 12:56:18.627655 2026] [security2:error] [pid 67073:tid 67214] [client 20.226.6.191:36367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAovcmepr5_nHgLbNTfwAAAh0"]
[Tue Aug 18 12:56:18.660461 2026] [security2:error] [pid 66623:tid 66824] [client 20.29.77.16:32975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/build.php"] [unique_id "aoSAotO5rbWdOArH04KJVAAAAUQ"]
[Tue Aug 18 12:56:18.716592 2026] [security2:error] [pid 67073:tid 67210] [client 20.51.153.15:8801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/vd.php"] [unique_id "aoSAovcmepr5_nHgLbNThQAAAhk"]
[Tue Aug 18 12:56:18.717125 2026] [security2:error] [pid 66623:tid 66828] [client 20.104.49.167:3339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wpxml.php"] [unique_id "aoSAotO5rbWdOArH04KJVgAAAUg"]
[Tue Aug 18 12:56:18.744154 2026] [security2:error] [pid 67073:tid 67247] [client 20.163.43.14:4152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/info.php"] [unique_id "aoSAovcmepr5_nHgLbNThgAAAj4"]
[Tue Aug 18 12:56:18.749027 2026] [security2:error] [pid 67073:tid 67311] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gg.php"] [unique_id "aoSAovcmepr5_nHgLbNThwAAAn4"]
[Tue Aug 18 12:56:18.754149 2026] [security2:error] [pid 67073:tid 67237] [client 20.100.169.31:43004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/96i.php"] [unique_id "aoSAovcmepr5_nHgLbNTiAAAAjQ"]
[Tue Aug 18 12:56:18.783066 2026] [security2:error] [pid 67073:tid 67211] [client 20.151.109.219:17557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ee.php"] [unique_id "aoSAovcmepr5_nHgLbNTiwAAAho"]
[Tue Aug 18 12:56:18.791753 2026] [security2:error] [pid 67073:tid 67194] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/rx.php"] [unique_id "aoSAovcmepr5_nHgLbNTjAACQnY"]
[Tue Aug 18 12:56:18.803034 2026] [security2:error] [pid 67073:tid 67294] [client 20.215.241.237:7290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/gec.php"] [unique_id "aoSAovcmepr5_nHgLbNTjQAAAm0"]
[Tue Aug 18 12:56:18.808279 2026] [security2:error] [pid 67073:tid 67297] [client 172.202.39.151:50168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAovcmepr5_nHgLbNTjgAAAnA"]
[Tue Aug 18 12:56:18.851251 2026] [security2:error] [pid 66623:tid 66848] [client 20.226.56.190:45036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ak.php"] [unique_id "aoSAotO5rbWdOArH04KJWAAAAVw"]
[Tue Aug 18 12:56:18.873703 2026] [security2:error] [pid 66623:tid 66849] [client 68.155.154.236:16334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSAotO5rbWdOArH04KJWQAAAV0"]
[Tue Aug 18 12:56:18.908122 2026] [security2:error] [pid 66623:tid 66862] [client 135.225.78.186:13300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/doc.php"] [unique_id "aoSAotO5rbWdOArH04KJaAAAAWo"]
[Tue Aug 18 12:56:18.960698 2026] [security2:error] [pid 67073:tid 67277] [client 213.35.127.232:55666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAovcmepr5_nHgLbNTkwAAAlw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:18.990528 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:18.990802 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:18.991542 2026] [security2:error] [pid 67073:tid 67267] [client 104.209.144.33:19631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSAovcmepr5_nHgLbNTlwAAAlI"]
[Tue Aug 18 12:56:18.992093 2026] [security2:error] [pid 67073:tid 67286] [client 74.248.130.103:15409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSAovcmepr5_nHgLbNTmAAAAmU"]
[Tue Aug 18 12:56:18.997653 2026] [security2:error] [pid 67073:tid 67166] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/mandrill.php"] [unique_id "aoSAovcmepr5_nHgLbNTmgACblo"]
[Tue Aug 18 12:56:18.998546 2026] [security2:error] [pid 67073:tid 67265] [client 20.51.153.15:8401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/56.php"] [unique_id "aoSAovcmepr5_nHgLbNTmwAAAlA"]
[Tue Aug 18 12:56:19.007851 2026] [security2:error] [pid 67073:tid 67309] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gi.php"] [unique_id "aoSAo_cmepr5_nHgLbNTnAAAAnw"]
[Tue Aug 18 12:56:19.015684 2026] [security2:error] [pid 67073:tid 67245] [client 20.116.17.175:57431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSAo_cmepr5_nHgLbNTnQAAAjw"]
[Tue Aug 18 12:56:19.017827 2026] [autoindex:error] [pid 67073:tid 67300] [client 20.79.204.6:2372] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:19.020918 2026] [security2:error] [pid 67073:tid 67249] [client 158.23.17.4:29453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/php5.php"] [unique_id "aoSAo_cmepr5_nHgLbNTngAAAkA"]
[Tue Aug 18 12:56:19.021971 2026] [security2:error] [pid 66623:tid 66831] [client 52.173.121.69:24831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSAo9O5rbWdOArH04KJbAAAAUs"]
[Tue Aug 18 12:56:19.060475 2026] [security2:error] [pid 67073:tid 67227] [client 52.139.47.57:47642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/atex1.php"] [unique_id "aoSAo_cmepr5_nHgLbNToAAAAio"]
[Tue Aug 18 12:56:19.102904 2026] [security2:error] [pid 66623:tid 66871] [client 20.91.215.254:12137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/license.php"] [unique_id "aoSAo9O5rbWdOArH04KJbwAAAXM"]
[Tue Aug 18 12:56:19.109241 2026] [security2:error] [pid 67073:tid 67276] [client 20.52.168.85:7864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/form.php"] [unique_id "aoSAo_cmepr5_nHgLbNTowAAAls"]
[Tue Aug 18 12:56:19.109561 2026] [security2:error] [pid 67073:tid 67261] [client 20.215.241.237:52925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/inso.php"] [unique_id "aoSAo_cmepr5_nHgLbNTpAAAAkw"]
[Tue Aug 18 12:56:19.143883 2026] [security2:error] [pid 67073:tid 67308] [client 20.151.109.219:21679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ak.php"] [unique_id "aoSAo_cmepr5_nHgLbNTpgAAAns"]
[Tue Aug 18 12:56:19.153760 2026] [security2:error] [pid 67073:tid 67291] [client 172.202.39.151:55502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSAo_cmepr5_nHgLbNTqAAAAmo"]
[Tue Aug 18 12:56:19.177470 2026] [security2:error] [pid 67073:tid 67232] [client 20.226.56.190:20412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/test_info.php"] [unique_id "aoSAo_cmepr5_nHgLbNTqQAAAi8"]
[Tue Aug 18 12:56:19.216062 2026] [security2:error] [pid 67073:tid 67189] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/main.php"] [unique_id "aoSAo_cmepr5_nHgLbNTqgACVnE"]
[Tue Aug 18 12:56:19.218915 2026] [security2:error] [pid 67073:tid 67240] [client 20.79.204.6:2372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSAo_cmepr5_nHgLbNTqwAAAjc"]
[Tue Aug 18 12:56:19.223166 2026] [security2:error] [pid 67073:tid 67229] [client 20.104.49.167:3372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/file1221.php"] [unique_id "aoSAo_cmepr5_nHgLbNTrAAAAiw"]
[Tue Aug 18 12:56:19.228316 2026] [security2:error] [pid 66623:tid 66823] [client 20.171.51.14:15806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ib.php"] [unique_id "aoSAo9O5rbWdOArH04KJcAAAAUM"]
[Tue Aug 18 12:56:19.262175 2026] [security2:error] [pid 67073:tid 67301] [client 20.163.43.14:4302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAo_cmepr5_nHgLbNTrgAAAnQ"]
[Tue Aug 18 12:56:19.262952 2026] [security2:error] [pid 67073:tid 67275] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/pz.php"] [unique_id "aoSAo_cmepr5_nHgLbNTrwAAAlo"]
[Tue Aug 18 12:56:19.286975 2026] [security2:error] [pid 67073:tid 67290] [client 20.51.153.15:8780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/rx.php"] [unique_id "aoSAo_cmepr5_nHgLbNTsQAAAmk"]
[Tue Aug 18 12:56:19.291667 2026] [authz_core:error] [pid 67073:tid 67095] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:19.291921 2026] [authz_core:error] [pid 67073:tid 67095] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:19.307734 2026] [security2:error] [pid 67073:tid 67233] [client 158.158.74.177:22757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/past.php"] [unique_id "aoSAo_cmepr5_nHgLbNTswAAAjA"]
[Tue Aug 18 12:56:19.328071 2026] [security2:error] [pid 67073:tid 67330] [client 135.225.78.186:13301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/1337.php"] [unique_id "aoSAo_cmepr5_nHgLbNTtQAAApE"]
[Tue Aug 18 12:56:19.346191 2026] [security2:error] [pid 67073:tid 67279] [client 160.120.140.123:61282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAo_cmepr5_nHgLbNTtgAAAl4"]
[Tue Aug 18 12:56:19.346333 2026] [security2:error] [pid 67073:tid 67279] [client 160.120.140.123:61282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAo_cmepr5_nHgLbNTtgAAAl4"]
[Tue Aug 18 12:56:19.356497 2026] [security2:error] [pid 67073:tid 67253] [client 192.141.172.134:60380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAo_cmepr5_nHgLbNTtwAAAkQ"]
[Tue Aug 18 12:56:19.356610 2026] [security2:error] [pid 67073:tid 67253] [client 192.141.172.134:60380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAo_cmepr5_nHgLbNTtwAAAkQ"]
[Tue Aug 18 12:56:19.358072 2026] [security2:error] [pid 67073:tid 67217] [client 20.215.241.237:49210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/sky.php"] [unique_id "aoSAo_cmepr5_nHgLbNTuAAAAiA"]
[Tue Aug 18 12:56:19.362631 2026] [security2:error] [pid 67073:tid 67226] [client 85.154.68.202:50312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAo_cmepr5_nHgLbNTuQAAAik"]
[Tue Aug 18 12:56:19.362728 2026] [security2:error] [pid 67073:tid 67226] [client 85.154.68.202:50312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAo_cmepr5_nHgLbNTuQAAAik"]
[Tue Aug 18 12:56:19.366783 2026] [security2:error] [pid 67073:tid 67329] [client 20.226.56.190:28238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/14.php"] [unique_id "aoSAo_cmepr5_nHgLbNTugAAApA"]
[Tue Aug 18 12:56:19.387881 2026] [security2:error] [pid 66623:tid 66863] [client 20.116.17.175:11201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/css/database.php"] [unique_id "aoSAo9O5rbWdOArH04KJcwAAAWs"]
[Tue Aug 18 12:56:19.390325 2026] [security2:error] [pid 66623:tid 66860] [client 45.92.229.97:34049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.229.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAo9O5rbWdOArH04KJdAAAAWg"], referer: https://ozzyfernandesoficial.com.br/wp-login.php
[Tue Aug 18 12:56:19.431946 2026] [security2:error] [pid 67073:tid 67223] [client 20.151.109.219:61389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/test_info.php"] [unique_id "aoSAo_cmepr5_nHgLbNTvgAAAiY"]
[Tue Aug 18 12:56:19.460172 2026] [security2:error] [pid 67073:tid 67116] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ga.php"] [unique_id "aoSAo_cmepr5_nHgLbNTwAACISg"]
[Tue Aug 18 12:56:19.469644 2026] [security2:error] [pid 67073:tid 67117] [remote 129.121.103.155:40030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "konneqt.cloud"] [uri "/wp-login.php"] [unique_id "aoSAo_cmepr5_nHgLbNTwQACGyk"]
[Tue Aug 18 12:56:19.482832 2026] [security2:error] [pid 67073:tid 67256] [client 20.250.13.23:47002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-login.php"] [unique_id "aoSAo_cmepr5_nHgLbNTsgAAAkc"]
[Tue Aug 18 12:56:19.508488 2026] [security2:error] [pid 67073:tid 67208] [client 68.155.154.236:16325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSAo_cmepr5_nHgLbNTxQAAAhc"]
[Tue Aug 18 12:56:19.529090 2026] [security2:error] [pid 67073:tid 67219] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kk.php"] [unique_id "aoSAo_cmepr5_nHgLbNTxwAAAiI"]
[Tue Aug 18 12:56:19.538526 2026] [security2:error] [pid 67073:tid 67266] [client 74.248.130.103:36822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAo_cmepr5_nHgLbNTygAAAlE"]
[Tue Aug 18 12:56:19.540799 2026] [security2:error] [pid 66623:tid 66873] [client 20.51.153.15:9101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/mandrill.php"] [unique_id "aoSAo9O5rbWdOArH04KJdgAAAXU"]
[Tue Aug 18 12:56:19.556549 2026] [security2:error] [pid 67073:tid 67272] [client 20.104.49.167:3558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/nox.php"] [unique_id "aoSAo_cmepr5_nHgLbNTzAAAAlc"]
[Tue Aug 18 12:56:19.586919 2026] [security2:error] [pid 66623:tid 66839] [client 135.225.75.187:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/xa.php"] [unique_id "aoSAo9O5rbWdOArH04KJeAAAAVM"]
[Tue Aug 18 12:56:19.684921 2026] [security2:error] [pid 66623:tid 66869] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAo9O5rbWdOArH04KJeQABcQI"]
[Tue Aug 18 12:56:19.692597 2026] [security2:error] [pid 66623:tid 66783] [client 20.163.43.14:4334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSAo9O5rbWdOArH04KJegAAARs"]
[Tue Aug 18 12:56:19.696978 2026] [security2:error] [pid 67073:tid 67203] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/wb.php"] [unique_id "aoSAo_cmepr5_nHgLbNT1wACPH8"]
[Tue Aug 18 12:56:19.709451 2026] [security2:error] [pid 66623:tid 66820] [client 20.29.77.16:49264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/defaul.php"] [unique_id "aoSAo9O5rbWdOArH04KJewAAAUA"]
[Tue Aug 18 12:56:19.714876 2026] [security2:error] [pid 67073:tid 67210] [client 20.52.168.85:8043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-sigunq.php"] [unique_id "aoSAo_cmepr5_nHgLbNT2AAAAhk"]
[Tue Aug 18 12:56:19.753113 2026] [security2:error] [pid 67073:tid 67325] [client 20.215.241.237:9302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/thoms.php"] [unique_id "aoSAo_cmepr5_nHgLbNT2QAAAow"]
[Tue Aug 18 12:56:19.757633 2026] [security2:error] [pid 67073:tid 67206] [client 135.225.78.186:13266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/Njima.php"] [unique_id "aoSAo_cmepr5_nHgLbNT2gAAAhU"]
[Tue Aug 18 12:56:19.792633 2026] [security2:error] [pid 67073:tid 67262] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/phpcheck.php"] [unique_id "aoSAo_cmepr5_nHgLbNT3gAAAk0"]
[Tue Aug 18 12:56:19.802900 2026] [security2:error] [pid 67073:tid 67242] [client 20.151.109.219:64984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/14.php"] [unique_id "aoSAo_cmepr5_nHgLbNT3wAAAjk"]
[Tue Aug 18 12:56:19.822197 2026] [security2:error] [pid 66623:tid 66821] [client 20.79.204.6:2217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSAo9O5rbWdOArH04KJfgAAAUE"]
[Tue Aug 18 12:56:19.852776 2026] [security2:error] [pid 66623:tid 66852] [client 20.215.241.237:61109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/sixxis.php"] [unique_id "aoSAo9O5rbWdOArH04KJfwAAAWA"]
[Tue Aug 18 12:56:19.861926 2026] [security2:error] [pid 67073:tid 67291] [client 20.51.153.15:8775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/main.php"] [unique_id "aoSAo_cmepr5_nHgLbNT4gAAAmo"]
[Tue Aug 18 12:56:19.869517 2026] [security2:error] [pid 67073:tid 67259] [client 20.116.17.175:57468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/privdayz.php"] [unique_id "aoSAo_cmepr5_nHgLbNT4wAAAko"]
[Tue Aug 18 12:56:19.893814 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:19.894104 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:19.913314 2026] [security2:error] [pid 67073:tid 67188] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/xn.php"] [unique_id "aoSAo_cmepr5_nHgLbNT5gACb3A"]
[Tue Aug 18 12:56:19.966029 2026] [security2:error] [pid 67073:tid 67275] [client 20.104.49.167:54262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/akismet.php"] [unique_id "aoSAo_cmepr5_nHgLbNT5wAAAlo"]
[Tue Aug 18 12:56:19.974133 2026] [security2:error] [pid 66623:tid 66793] [client 213.35.127.232:55891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAo9O5rbWdOArH04KJgAAAASU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:19.978045 2026] [security2:error] [pid 67073:tid 67248] [client 68.155.154.236:16273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSAo_cmepr5_nHgLbNT6QAAAj8"]
[Tue Aug 18 12:56:20.024973 2026] [security2:error] [pid 66623:tid 66817] [client 20.163.43.14:4292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/k.php"] [unique_id "aoSApNO5rbWdOArH04KJgQAAAT0"]
[Tue Aug 18 12:56:20.046684 2026] [security2:error] [pid 67073:tid 67305] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/dg.php"] [unique_id "aoSApPcmepr5_nHgLbNT6wAAAng"]
[Tue Aug 18 12:56:20.071019 2026] [security2:error] [pid 67073:tid 67233] [client 20.226.56.190:45044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/tk.php"] [unique_id "aoSApPcmepr5_nHgLbNT7QAAAjA"]
[Tue Aug 18 12:56:20.072659 2026] [security2:error] [pid 67073:tid 67330] [client 74.248.136.165:55266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/wqqs.php"] [unique_id "aoSApPcmepr5_nHgLbNT7gAAApE"]
[Tue Aug 18 12:56:20.117009 2026] [security2:error] [pid 67073:tid 67253] [client 104.209.144.33:17225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSApPcmepr5_nHgLbNT8gAAAkQ"]
[Tue Aug 18 12:56:20.124101 2026] [security2:error] [pid 66623:tid 66825] [client 74.248.130.103:36834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSApNO5rbWdOArH04KJhAAAAUU"]
[Tue Aug 18 12:56:20.144181 2026] [security2:error] [pid 67073:tid 67167] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/47.php"] [unique_id "aoSApPcmepr5_nHgLbNT8wACKVs"]
[Tue Aug 18 12:56:20.153862 2026] [security2:error] [pid 66623:tid 66887] [client 20.151.109.219:61383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/tk.php"] [unique_id "aoSApNO5rbWdOArH04KJhgAAAYM"]
[Tue Aug 18 12:56:20.182004 2026] [security2:error] [pid 66623:tid 66807] [client 20.51.153.15:8820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ga.php"] [unique_id "aoSApNO5rbWdOArH04KJhwAAATM"]
[Tue Aug 18 12:56:20.182797 2026] [security2:error] [pid 66623:tid 66888] [client 135.225.78.186:13267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/BIBIL.php"] [unique_id "aoSApNO5rbWdOArH04KJiAAAAYQ"]
[Tue Aug 18 12:56:20.194757 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:20.195028 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:20.221905 2026] [security2:error] [pid 66623:tid 66797] [client 20.116.17.175:11208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wg459o.php"] [unique_id "aoSApNO5rbWdOArH04KJiQAAASk"]
[Tue Aug 18 12:56:20.266373 2026] [security2:error] [pid 67073:tid 67224] [client 20.29.77.16:20853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/twin.php"] [unique_id "aoSApPcmepr5_nHgLbNT-AAAAic"]
[Tue Aug 18 12:56:20.283913 2026] [security2:error] [pid 67073:tid 67273] [client 20.215.241.237:44075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/yj09.php"] [unique_id "aoSApPcmepr5_nHgLbNT-QAAAlg"]
[Tue Aug 18 12:56:20.301012 2026] [security2:error] [pid 67073:tid 67214] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/bm.php"] [unique_id "aoSApPcmepr5_nHgLbNT-gAAAh0"]
[Tue Aug 18 12:56:20.314115 2026] [security2:error] [pid 67073:tid 67327] [client 20.186.30.159:13680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSApPcmepr5_nHgLbNT-wAAAo4"]
[Tue Aug 18 12:56:20.318446 2026] [security2:error] [pid 67073:tid 67217] [client 20.52.168.85:7848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/07.php"] [unique_id "aoSApPcmepr5_nHgLbNT_AAAAiA"]
[Tue Aug 18 12:56:20.320280 2026] [security2:error] [pid 67073:tid 67246] [client 158.158.74.177:22747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/php.php"] [unique_id "aoSApPcmepr5_nHgLbNT_QAAAj0"]
[Tue Aug 18 12:56:20.348954 2026] [security2:error] [pid 66623:tid 66826] [client 20.171.51.14:65151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/xm.php"] [unique_id "aoSApNO5rbWdOArH04KJjAAAAUY"]
[Tue Aug 18 12:56:20.386784 2026] [security2:error] [pid 67073:tid 67149] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/payout.php"] [unique_id "aoSApPcmepr5_nHgLbNUAgACkkk"]
[Tue Aug 18 12:56:20.396472 2026] [security2:error] [pid 67073:tid 67220] [client 20.104.49.167:54208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/admin.php"] [unique_id "aoSApPcmepr5_nHgLbNUBQAAAiM"]
[Tue Aug 18 12:56:20.403970 2026] [autoindex:error] [pid 67073:tid 67256] [client 20.226.6.191:36426] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/js/crop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:20.428815 2026] [security2:error] [pid 67073:tid 67219] [client 20.226.6.191:36426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-mail.php"] [unique_id "aoSApPcmepr5_nHgLbNUBgAAAiI"]
[Tue Aug 18 12:56:20.429116 2026] [security2:error] [pid 66623:tid 66774] [client 20.79.204.6:2203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSApNO5rbWdOArH04KJjwAAARI"]
[Tue Aug 18 12:56:20.450961 2026] [security2:error] [pid 67073:tid 67322] [client 158.158.34.183:18822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-block.php"] [unique_id "aoSApPcmepr5_nHgLbNUCAAAAok"]
[Tue Aug 18 12:56:20.474780 2026] [security2:error] [pid 66623:tid 66832] [client 20.100.169.31:12704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wk/index.php"] [unique_id "aoSApNO5rbWdOArH04KJkAAAAUw"]
[Tue Aug 18 12:56:20.481087 2026] [security2:error] [pid 67073:tid 67211] [client 20.151.109.219:65023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/hp.php"] [unique_id "aoSApPcmepr5_nHgLbNUCQAAAho"]
[Tue Aug 18 12:56:20.496248 2026] [authz_core:error] [pid 67073:tid 67199] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:20.496512 2026] [authz_core:error] [pid 67073:tid 67199] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:20.509304 2026] [security2:error] [pid 67073:tid 67326] [client 20.226.56.190:31619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/hp.php"] [unique_id "aoSApPcmepr5_nHgLbNUCwAAAo0"]
[Tue Aug 18 12:56:20.529011 2026] [autoindex:error] [pid 67073:tid 67297] [client 172.202.39.151:65225] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:20.561031 2026] [security2:error] [pid 67073:tid 67278] [client 68.155.154.236:16301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSApPcmepr5_nHgLbNUDwAAAl0"]
[Tue Aug 18 12:56:20.561142 2026] [security2:error] [pid 67073:tid 67277] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/vu.php"] [unique_id "aoSApPcmepr5_nHgLbNUEAAAAlw"]
[Tue Aug 18 12:56:20.562762 2026] [security2:error] [pid 66623:tid 66806] [client 20.163.43.14:4272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/403.php"] [unique_id "aoSApNO5rbWdOArH04KJkgAAATI"]
[Tue Aug 18 12:56:20.572509 2026] [security2:error] [pid 67073:tid 67263] [client 74.248.130.103:25774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSApPcmepr5_nHgLbNUEQAAAk4"]
[Tue Aug 18 12:56:20.576915 2026] [security2:error] [pid 66623:tid 66803] [client 54.87.112.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tecpolorefrigeracao.com.br"] [uri "/index.php"] [unique_id "aoSAo9O5rbWdOArH04KJbQABL1k"], referer: https://tecpolorefrigeracao.com.br/
[Tue Aug 18 12:56:20.600321 2026] [security2:error] [pid 67073:tid 67247] [client 135.225.78.186:13264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/too.php"] [unique_id "aoSApPcmepr5_nHgLbNUEwAAAj4"]
[Tue Aug 18 12:56:20.606419 2026] [security2:error] [pid 67073:tid 67120] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/bh.php"] [unique_id "aoSApPcmepr5_nHgLbNUFAACYiw"]
[Tue Aug 18 12:56:20.606427 2026] [security2:error] [pid 66623:tid 66864] [client 20.51.153.15:8704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/wb.php"] [unique_id "aoSApNO5rbWdOArH04KJkwAAAWw"]
[Tue Aug 18 12:56:20.615251 2026] [security2:error] [pid 66623:tid 66768] [client 157.51.166.53:61145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSApNO5rbWdOArH04KJlAAAAQw"]
[Tue Aug 18 12:56:20.615403 2026] [security2:error] [pid 66623:tid 66768] [client 157.51.166.53:61145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSApNO5rbWdOArH04KJlAAAAQw"]
[Tue Aug 18 12:56:20.737947 2026] [security2:error] [pid 66623:tid 66814] [client 20.29.77.16:52773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/new2.php"] [unique_id "aoSApNO5rbWdOArH04KJlQAAATo"]
[Tue Aug 18 12:56:20.739381 2026] [security2:error] [pid 66623:tid 66782] [client 135.225.75.187:17710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/f6.php"] [unique_id "aoSApNO5rbWdOArH04KJlgAAARo"]
[Tue Aug 18 12:56:20.802594 2026] [security2:error] [pid 67073:tid 67249] [client 172.182.200.96:14086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSApPcmepr5_nHgLbNUGgAAAkA"]
[Tue Aug 18 12:56:20.816809 2026] [security2:error] [pid 67073:tid 67310] [client 172.202.39.151:65225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSApPcmepr5_nHgLbNUGwAAAn0"]
[Tue Aug 18 12:56:20.817981 2026] [security2:error] [pid 67073:tid 67210] [client 20.215.241.237:44093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/k.php"] [unique_id "aoSApPcmepr5_nHgLbNUHAAAAhk"]
[Tue Aug 18 12:56:20.822037 2026] [security2:error] [pid 67073:tid 67227] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ic.php"] [unique_id "aoSApPcmepr5_nHgLbNUHQAAAio"]
[Tue Aug 18 12:56:20.825587 2026] [security2:error] [pid 67073:tid 67281] [client 20.250.13.23:14307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/default.php"] [unique_id "aoSApPcmepr5_nHgLbNUHgAAAmA"]
[Tue Aug 18 12:56:20.834883 2026] [security2:error] [pid 67073:tid 67100] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ct.php"] [unique_id "aoSApPcmepr5_nHgLbNUHwACeRg"]
[Tue Aug 18 12:56:20.864808 2026] [security2:error] [pid 67073:tid 67303] [client 20.116.17.175:11232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/mifta.php"] [unique_id "aoSApPcmepr5_nHgLbNUIAAAAnY"]
[Tue Aug 18 12:56:20.880362 2026] [security2:error] [pid 67073:tid 67207] [client 20.151.109.219:12915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/wx.php"] [unique_id "aoSApPcmepr5_nHgLbNUIQAAAhY"]
[Tue Aug 18 12:56:20.890554 2026] [security2:error] [pid 66623:tid 66883] [client 20.51.153.15:8760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/xn.php"] [unique_id "aoSApNO5rbWdOArH04KJmQAAAX8"]
[Tue Aug 18 12:56:20.921303 2026] [security2:error] [pid 67073:tid 67291] [client 20.186.30.159:13651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSApPcmepr5_nHgLbNUJAAAAmo"]
[Tue Aug 18 12:56:20.923375 2026] [security2:error] [pid 66623:tid 66816] [client 20.52.168.85:7829] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.sortis.net"] [uri "/c99.php"] [unique_id "aoSApNO5rbWdOArH04KJmgAAATw"]
[Tue Aug 18 12:56:20.937614 2026] [security2:error] [pid 67073:tid 67232] [client 104.209.144.33:34136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSApPcmepr5_nHgLbNUJQAAAi8"]
[Tue Aug 18 12:56:20.986093 2026] [security2:error] [pid 67073:tid 67309] [client 213.35.127.232:56097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSApPcmepr5_nHgLbNUJwAAAnw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:21.017076 2026] [security2:error] [pid 67073:tid 67229] [client 135.225.78.186:40773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/g3.php"] [unique_id "aoSApfcmepr5_nHgLbNUKAAAAiw"]
[Tue Aug 18 12:56:21.032280 2026] [security2:error] [pid 67073:tid 67325] [client 20.79.204.6:2375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSApfcmepr5_nHgLbNUKQAAAow"]
[Tue Aug 18 12:56:21.040141 2026] [security2:error] [pid 67073:tid 67225] [client 74.248.136.165:28141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/clasa99.php"] [unique_id "aoSApfcmepr5_nHgLbNUKgAAAig"]
[Tue Aug 18 12:56:21.064750 2026] [security2:error] [pid 66623:tid 66824] [client 20.104.49.167:4013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/ajax.php"] [unique_id "aoSApdO5rbWdOArH04KJmwAAAUQ"]
[Tue Aug 18 12:56:21.077466 2026] [security2:error] [pid 67073:tid 67271] [client 20.100.169.31:28157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/as.php"] [unique_id "aoSApfcmepr5_nHgLbNULwAAAlY"]
[Tue Aug 18 12:56:21.082944 2026] [security2:error] [pid 67073:tid 67239] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ue.php"] [unique_id "aoSApfcmepr5_nHgLbNUMAAAAjY"]
[Tue Aug 18 12:56:21.108657 2026] [security2:error] [pid 67073:tid 67086] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gy.php"] [unique_id "aoSApfcmepr5_nHgLbNUMgACXwo"]
[Tue Aug 18 12:56:21.142181 2026] [security2:error] [pid 67073:tid 67262] [client 158.158.34.183:11530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wk/index.php"] [unique_id "aoSApfcmepr5_nHgLbNUNAAAAk0"]
[Tue Aug 18 12:56:21.182075 2026] [security2:error] [pid 67073:tid 67285] [client 20.215.241.237:61431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/wpxml.php"] [unique_id "aoSApfcmepr5_nHgLbNUNwAAAmQ"]
[Tue Aug 18 12:56:21.198140 2026] [security2:error] [pid 66623:tid 66838] [client 68.155.154.236:16259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSApdO5rbWdOArH04KJnQAAAVI"]
[Tue Aug 18 12:56:21.202182 2026] [security2:error] [pid 67073:tid 67253] [client 20.171.51.14:62475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/zy.php"] [unique_id "aoSApfcmepr5_nHgLbNUOAAAAkQ"]
[Tue Aug 18 12:56:21.221667 2026] [security2:error] [pid 67073:tid 67209] [client 20.51.153.15:9116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/tt.php"] [unique_id "aoSApfcmepr5_nHgLbNUOgAAAhg"]
[Tue Aug 18 12:56:21.249100 2026] [security2:error] [pid 67073:tid 67257] [client 20.163.43.14:4108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/gecko.php"] [unique_id "aoSApfcmepr5_nHgLbNUOwAAAkg"]
[Tue Aug 18 12:56:21.292008 2026] [security2:error] [pid 67073:tid 67258] [client 20.215.241.237:43630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/w.php"] [unique_id "aoSApfcmepr5_nHgLbNUPQAAAkk"]
[Tue Aug 18 12:56:21.301113 2026] [security2:error] [pid 67073:tid 67273] [client 20.151.109.219:21647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/dj.php"] [unique_id "aoSApfcmepr5_nHgLbNUPgAAAlg"]
[Tue Aug 18 12:56:21.319258 2026] [security2:error] [pid 67073:tid 67223] [client 74.248.130.103:14452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSApfcmepr5_nHgLbNUPwAAAiY"]
[Tue Aug 18 12:56:21.319535 2026] [security2:error] [pid 67073:tid 67094] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/tt.php"] [unique_id "aoSApfcmepr5_nHgLbNUQAACHhI"]
[Tue Aug 18 12:56:21.320849 2026] [security2:error] [pid 67073:tid 67214] [client 20.226.56.190:32300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/wx.php"] [unique_id "aoSApfcmepr5_nHgLbNUQQAAAh0"]
[Tue Aug 18 12:56:21.338031 2026] [security2:error] [pid 67073:tid 67246] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/lr.php"] [unique_id "aoSApfcmepr5_nHgLbNUQgAAAj0"]
[Tue Aug 18 12:56:21.401735 2026] [authz_core:error] [pid 67073:tid 67087] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:21.402013 2026] [authz_core:error] [pid 67073:tid 67087] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:21.408845 2026] [security2:error] [pid 67073:tid 67208] [client 68.155.156.252:16576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSApfcmepr5_nHgLbNURgAAAhc"]
[Tue Aug 18 12:56:21.459204 2026] [security2:error] [pid 67073:tid 67316] [client 20.226.6.191:32961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/o.php"] [unique_id "aoSApfcmepr5_nHgLbNUSwAAAoM"]
[Tue Aug 18 12:56:21.497393 2026] [security2:error] [pid 66623:tid 66781] [client 20.51.153.15:9105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/mq.php"] [unique_id "aoSApdO5rbWdOArH04KJnwAAARk"]
[Tue Aug 18 12:56:21.508026 2026] [security2:error] [pid 67073:tid 67304] [client 158.158.74.177:2648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/php8.php"] [unique_id "aoSApfcmepr5_nHgLbNUTgAAAnc"]
[Tue Aug 18 12:56:21.519937 2026] [security2:error] [pid 67073:tid 67170] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/mq.php"] [unique_id "aoSApfcmepr5_nHgLbNUTwACMl4"]
[Tue Aug 18 12:56:21.523256 2026] [security2:error] [pid 67073:tid 67327] [client 20.52.168.85:7830] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.sortis.net"] [uri "/c99.php"] [unique_id "aoSApfcmepr5_nHgLbNUUQAAAo4"]
[Tue Aug 18 12:56:21.523334 2026] [security2:error] [pid 67073:tid 67264] [client 172.202.39.151:65279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSApfcmepr5_nHgLbNUUAAAAk8"]
[Tue Aug 18 12:56:21.557954 2026] [security2:error] [pid 67073:tid 67274] [client 20.186.30.159:13599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSApfcmepr5_nHgLbNUVQAAAlk"]
[Tue Aug 18 12:56:21.575850 2026] [security2:error] [pid 67073:tid 67263] [client 52.173.121.69:17974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSApfcmepr5_nHgLbNUVgAAAk4"]
[Tue Aug 18 12:56:21.584641 2026] [security2:error] [pid 67073:tid 67272] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ka.php"] [unique_id "aoSApfcmepr5_nHgLbNUVwAAAlc"]
[Tue Aug 18 12:56:21.597212 2026] [security2:error] [pid 67073:tid 67286] [client 213.202.253.4:64946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/delpaths.php"] [unique_id "aoSApfcmepr5_nHgLbNUWAAAAmU"], referer: www.google.com
[Tue Aug 18 12:56:21.643071 2026] [security2:error] [pid 67073:tid 67205] [client 20.151.109.219:24866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/fa.php"] [unique_id "aoSApfcmepr5_nHgLbNUXAAAAhQ"]
[Tue Aug 18 12:56:21.647546 2026] [security2:error] [pid 67073:tid 67302] [client 135.225.75.187:62283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/mcs.php"] [unique_id "aoSApfcmepr5_nHgLbNUXQAAAnU"]
[Tue Aug 18 12:56:21.699226 2026] [security2:error] [pid 67073:tid 67245] [client 68.155.154.236:16324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSApfcmepr5_nHgLbNUYAAAAjw"]
[Tue Aug 18 12:56:21.701071 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:21.701336 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:21.732412 2026] [security2:error] [pid 67073:tid 67310] [client 20.215.241.237:48445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/fpwch.php"] [unique_id "aoSApfcmepr5_nHgLbNUYgAAAn0"]
[Tue Aug 18 12:56:21.740081 2026] [security2:error] [pid 67073:tid 67294] [client 20.250.13.23:21879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/i.php"] [unique_id "aoSApfcmepr5_nHgLbNUYwAAAm0"]
[Tue Aug 18 12:56:21.746015 2026] [security2:error] [pid 66623:tid 66848] [client 20.163.43.14:4217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/aa.php"] [unique_id "aoSApdO5rbWdOArH04KJogAAAVw"]
[Tue Aug 18 12:56:21.759294 2026] [security2:error] [pid 67073:tid 67227] [client 20.51.153.15:9146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/13.php"] [unique_id "aoSApfcmepr5_nHgLbNUZAAAAio"]
[Tue Aug 18 12:56:21.763209 2026] [security2:error] [pid 66623:tid 66879] [client 74.248.130.103:25736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/media.php"] [unique_id "aoSApdO5rbWdOArH04KJowAAAXs"]
[Tue Aug 18 12:56:21.764392 2026] [security2:error] [pid 67073:tid 67230] [client 20.79.204.6:2201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSApfcmepr5_nHgLbNUZQAAAi0"]
[Tue Aug 18 12:56:21.770166 2026] [security2:error] [pid 67073:tid 67181] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/13.php"] [unique_id "aoSApfcmepr5_nHgLbNUZgACYGk"]
[Tue Aug 18 12:56:21.772129 2026] [security2:error] [pid 67073:tid 67277] [client 79.127.164.8:35678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/localhost.sql"] [unique_id "aoSApfcmepr5_nHgLbNUZwAAAlw"], referer: https://medihub.com.br/localhost.sql
[Tue Aug 18 12:56:21.841402 2026] [security2:error] [pid 67073:tid 67303] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ot.php"] [unique_id "aoSApfcmepr5_nHgLbNUagAAAnY"]
[Tue Aug 18 12:56:21.872536 2026] [security2:error] [pid 67073:tid 67232] [client 104.209.144.33:19633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSApfcmepr5_nHgLbNUawAAAi8"]
[Tue Aug 18 12:56:21.912534 2026] [security2:error] [pid 67073:tid 67238] [client 20.116.17.175:57662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSApfcmepr5_nHgLbNUbQAAAjU"]
[Tue Aug 18 12:56:21.919501 2026] [security2:error] [pid 66623:tid 66800] [client 172.202.39.151:44978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSApdO5rbWdOArH04KJpQAAASw"]
[Tue Aug 18 12:56:21.997945 2026] [security2:error] [pid 66623:tid 66767] [client 213.35.127.232:56325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSApdO5rbWdOArH04KJpgAAAQs"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:22.001978 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:22.002245 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:22.002570 2026] [security2:error] [pid 67073:tid 67275] [client 20.151.109.219:21677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/fb.php"] [unique_id "aoSApvcmepr5_nHgLbNUcgAAAlo"]
[Tue Aug 18 12:56:22.009262 2026] [security2:error] [pid 67073:tid 67182] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/so.php"] [unique_id "aoSApvcmepr5_nHgLbNUcwACjGo"]
[Tue Aug 18 12:56:22.013402 2026] [security2:error] [pid 67073:tid 67228] [client 20.29.77.16:56345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/rex.php"] [unique_id "aoSApvcmepr5_nHgLbNUdAAAAis"]
[Tue Aug 18 12:56:22.067683 2026] [security2:error] [pid 67073:tid 67225] [client 68.155.154.236:16279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSApvcmepr5_nHgLbNUdQAAAig"]
[Tue Aug 18 12:56:22.078892 2026] [security2:error] [pid 67073:tid 67271] [client 20.163.43.14:4245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/0x.php"] [unique_id "aoSApvcmepr5_nHgLbNUdgAAAlY"]
[Tue Aug 18 12:56:22.092969 2026] [security2:error] [pid 67073:tid 67280] [client 20.171.51.14:61475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/q.php"] [unique_id "aoSApvcmepr5_nHgLbNUeQAAAl8"]
[Tue Aug 18 12:56:22.108578 2026] [security2:error] [pid 67073:tid 67330] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ih.php"] [unique_id "aoSApvcmepr5_nHgLbNUewAAApE"]
[Tue Aug 18 12:56:22.132059 2026] [security2:error] [pid 66623:tid 66857] [client 20.52.168.85:7863] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.sortis.net"] [uri "/c99.php"] [unique_id "aoSAptO5rbWdOArH04KJqAAAAWU"]
[Tue Aug 18 12:56:22.160761 2026] [security2:error] [pid 67073:tid 67308] [client 20.186.30.159:13669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSApvcmepr5_nHgLbNUfwAAAns"]
[Tue Aug 18 12:56:22.187354 2026] [security2:error] [pid 66623:tid 66853] [client 20.215.241.237:40475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/FWAZ.php"] [unique_id "aoSAptO5rbWdOArH04KJqQAAAWE"]
[Tue Aug 18 12:56:22.201067 2026] [security2:error] [pid 67073:tid 67324] [client 172.202.39.151:55442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/abc.php"] [unique_id "aoSApvcmepr5_nHgLbNUggAAAos"]
[Tue Aug 18 12:56:22.212061 2026] [authz_core:error] [pid 67073:tid 67132] [remote 57.141.22.94:56768] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:22.212511 2026] [authz_core:error] [pid 67073:tid 67132] [remote 57.141.22.94:56768] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:22.228914 2026] [security2:error] [pid 67073:tid 67078] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/10.php"] [unique_id "aoSApvcmepr5_nHgLbNUgwACWAI"]
[Tue Aug 18 12:56:22.231741 2026] [security2:error] [pid 67073:tid 67223] [client 20.51.153.15:8769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/so.php"] [unique_id "aoSApvcmepr5_nHgLbNUhAAAAiY"]
[Tue Aug 18 12:56:22.260341 2026] [security2:error] [pid 67073:tid 67246] [client 20.226.56.190:23773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/dj.php"] [unique_id "aoSApvcmepr5_nHgLbNUhQAAAj0"]
[Tue Aug 18 12:56:22.315875 2026] [security2:error] [pid 66623:tid 66871] [client 20.151.109.219:59746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gw.php"] [unique_id "aoSAptO5rbWdOArH04KJqgAAAXM"]
[Tue Aug 18 12:56:22.330353 2026] [security2:error] [pid 67073:tid 67311] [client 74.248.130.103:14404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/inso.php"] [unique_id "aoSApvcmepr5_nHgLbNUiAAAAn4"]
[Tue Aug 18 12:56:22.365961 2026] [security2:error] [pid 66623:tid 66868] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/k.php"] [unique_id "aoSAptO5rbWdOArH04KJqwAAAXA"]
[Tue Aug 18 12:56:22.372173 2026] [security2:error] [pid 67073:tid 67315] [client 20.79.204.6:2643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSApvcmepr5_nHgLbNUjAAAAoI"]
[Tue Aug 18 12:56:22.394650 2026] [security2:error] [pid 67073:tid 67213] [client 132.196.30.78:18675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/inputs.php"] [unique_id "aoSApvcmepr5_nHgLbNUjgAAAhw"]
[Tue Aug 18 12:56:22.423959 2026] [security2:error] [pid 67073:tid 67241] [client 20.163.43.14:4281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/zxz.php"] [unique_id "aoSApvcmepr5_nHgLbNUjwAAAjg"]
[Tue Aug 18 12:56:22.434184 2026] [security2:error] [pid 67073:tid 67326] [client 68.155.154.236:16376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSApvcmepr5_nHgLbNUkAAAAo0"]
[Tue Aug 18 12:56:22.443865 2026] [security2:error] [pid 67073:tid 67257] [client 74.248.18.37:24459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-blink.php"] [unique_id "aoSApvcmepr5_nHgLbNUkQAAAkg"]
[Tue Aug 18 12:56:22.475371 2026] [security2:error] [pid 67073:tid 67184] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/te.php"] [unique_id "aoSApvcmepr5_nHgLbNUlAACT2w"]
[Tue Aug 18 12:56:22.492414 2026] [security2:error] [pid 67073:tid 67276] [client 196.12.128.158:49500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSApvcmepr5_nHgLbNUlgAAAls"]
[Tue Aug 18 12:56:22.492546 2026] [security2:error] [pid 67073:tid 67276] [client 196.12.128.158:49500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSApvcmepr5_nHgLbNUlgAAAls"]
[Tue Aug 18 12:56:22.499621 2026] [security2:error] [pid 66623:tid 66771] [client 20.51.153.15:9172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/kc.php"] [unique_id "aoSAptO5rbWdOArH04KJrQAAAQ8"]
[Tue Aug 18 12:56:22.578998 2026] [security2:error] [pid 67073:tid 67286] [client 135.225.75.187:24662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/xleet.php"] [unique_id "aoSApvcmepr5_nHgLbNUmQAAAmU"]
[Tue Aug 18 12:56:22.611011 2026] [security2:error] [pid 67073:tid 67302] [client 20.215.241.237:49197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/blurbs.php"] [unique_id "aoSApvcmepr5_nHgLbNUmwAAAnU"]
[Tue Aug 18 12:56:22.621800 2026] [security2:error] [pid 67073:tid 67245] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/iu.php"] [unique_id "aoSApvcmepr5_nHgLbNUnQAAAjw"]
[Tue Aug 18 12:56:22.623529 2026] [security2:error] [pid 67073:tid 67287] [client 20.151.109.219:24867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/sw.php"] [unique_id "aoSApvcmepr5_nHgLbNUnwAAAmY"]
[Tue Aug 18 12:56:22.625784 2026] [security2:error] [pid 67073:tid 67290] [client 20.100.169.31:12676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/about.php"] [unique_id "aoSApvcmepr5_nHgLbNUoAAAAmk"]
[Tue Aug 18 12:56:22.662159 2026] [security2:error] [pid 67073:tid 67260] [client 158.23.17.4:63662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/Black.php"] [unique_id "aoSApvcmepr5_nHgLbNUogAAAks"]
[Tue Aug 18 12:56:22.705880 2026] [security2:error] [pid 67073:tid 67154] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kc.php"] [unique_id "aoSApvcmepr5_nHgLbNUowACRU4"]
[Tue Aug 18 12:56:22.706769 2026] [security2:error] [pid 67073:tid 67322] [client 158.158.74.177:2667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/plugins.php"] [unique_id "aoSApvcmepr5_nHgLbNUpAAAAok"]
[Tue Aug 18 12:56:22.738516 2026] [security2:error] [pid 67073:tid 67278] [client 20.52.168.85:8008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wander.php"] [unique_id "aoSApvcmepr5_nHgLbNUpwAAAl0"]
[Tue Aug 18 12:56:22.740485 2026] [security2:error] [pid 66623:tid 66830] [client 20.116.17.175:57631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/index2.php"] [unique_id "aoSAptO5rbWdOArH04KJrwAAAUo"]
[Tue Aug 18 12:56:22.772861 2026] [security2:error] [pid 67073:tid 67207] [client 20.51.153.15:8799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/bf.php"] [unique_id "aoSApvcmepr5_nHgLbNUqAAAAhY"]
[Tue Aug 18 12:56:22.832934 2026] [security2:error] [pid 66623:tid 66844] [client 20.163.43.14:4177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/www.php"] [unique_id "aoSAptO5rbWdOArH04KJsAAAAVg"]
[Tue Aug 18 12:56:22.839592 2026] [security2:error] [pid 66623:tid 66874] [client 172.182.200.96:14170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSAptO5rbWdOArH04KJsQAAAXY"]
[Tue Aug 18 12:56:22.861526 2026] [security2:error] [pid 67073:tid 67211] [client 52.139.47.57:1688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/atomlib.php"] [unique_id "aoSApvcmepr5_nHgLbNUqgAAAho"]
[Tue Aug 18 12:56:22.866474 2026] [security2:error] [pid 66623:tid 66878] [client 74.248.130.103:36831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/shiny.php"] [unique_id "aoSAptO5rbWdOArH04KJsgAAAXo"]
[Tue Aug 18 12:56:22.871037 2026] [security2:error] [pid 66623:tid 66846] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/pk.php"] [unique_id "aoSAptO5rbWdOArH04KJswAAAVo"]
[Tue Aug 18 12:56:22.877498 2026] [security2:error] [pid 66623:tid 66783] [client 68.155.154.236:16364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSAptO5rbWdOArH04KJtAAAARs"]
[Tue Aug 18 12:56:22.904549 2026] [security2:error] [pid 67073:tid 67309] [client 74.248.136.165:55245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/666.php"] [unique_id "aoSApvcmepr5_nHgLbNUrQAAAnw"]
[Tue Aug 18 12:56:22.919037 2026] [security2:error] [pid 67073:tid 67131] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/jn.php"] [unique_id "aoSApvcmepr5_nHgLbNUrwACaDc"]
[Tue Aug 18 12:56:22.919363 2026] [security2:error] [pid 67073:tid 67261] [client 132.196.30.78:18788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/admin.php"] [unique_id "aoSApvcmepr5_nHgLbNUsAAAAkw"]
[Tue Aug 18 12:56:22.962347 2026] [security2:error] [pid 67073:tid 67325] [client 20.151.109.219:17581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gc.php"] [unique_id "aoSApvcmepr5_nHgLbNUsQAAAow"]
[Tue Aug 18 12:56:22.978876 2026] [security2:error] [pid 67073:tid 67293] [client 20.79.204.6:2373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSApvcmepr5_nHgLbNUsgAAAmw"]
[Tue Aug 18 12:56:23.009595 2026] [autoindex:error] [pid 66623:tid 66815] [client 172.202.39.151:15740] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:23.013918 2026] [security2:error] [pid 66623:tid 66852] [client 20.226.56.190:45024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/fa.php"] [unique_id "aoSAp9O5rbWdOArH04KJuQAAAWA"]
[Tue Aug 18 12:56:23.017337 2026] [security2:error] [pid 67073:tid 67310] [client 213.35.127.232:56556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAp_cmepr5_nHgLbNUtAAAAn0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:23.091925 2026] [security2:error] [pid 66623:tid 66793] [client 132.196.61.152:61035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/fz.php"] [unique_id "aoSAp9O5rbWdOArH04KJugAAASU"]
[Tue Aug 18 12:56:23.099571 2026] [security2:error] [pid 67073:tid 67279] [client 20.29.77.16:27230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/verification.php"] [unique_id "aoSAp_cmepr5_nHgLbNUtgAAAl4"]
[Tue Aug 18 12:56:23.105417 2026] [security2:error] [pid 67073:tid 67308] [client 20.186.30.159:13577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/xx.php"] [unique_id "aoSAp_cmepr5_nHgLbNUtwAAAns"]
[Tue Aug 18 12:56:23.118021 2026] [security2:error] [pid 66623:tid 66881] [client 20.215.241.237:54958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/100.php"] [unique_id "aoSAp9O5rbWdOArH04KJvAAAAX0"]
[Tue Aug 18 12:56:23.126818 2026] [security2:error] [pid 66623:tid 66880] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ge.php"] [unique_id "aoSAp9O5rbWdOArH04KJvQAAAXw"]
[Tue Aug 18 12:56:23.158748 2026] [security2:error] [pid 66623:tid 66804] [client 20.163.43.14:4329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wicked.php"] [unique_id "aoSAp9O5rbWdOArH04KJvgAAATA"]
[Tue Aug 18 12:56:23.158748 2026] [security2:error] [pid 67073:tid 67076] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/bf.php"] [unique_id "aoSAp_cmepr5_nHgLbNUuAACkwA"]
[Tue Aug 18 12:56:23.195893 2026] [security2:error] [pid 67073:tid 67258] [client 20.171.51.14:45405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/xf.php"] [unique_id "aoSAp_cmepr5_nHgLbNUugAAAkk"]
[Tue Aug 18 12:56:23.205737 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:23.206001 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:23.208182 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.6.191:36357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/bb.php"] [unique_id "aoSAp_cmepr5_nHgLbNUvAAAAlg"]
[Tue Aug 18 12:56:23.225426 2026] [security2:error] [pid 66623:tid 66840] [client 20.250.13.23:24823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSAp9O5rbWdOArH04KJvwAAAVQ"]
[Tue Aug 18 12:56:23.264039 2026] [security2:error] [pid 67073:tid 67217] [client 68.155.154.236:16274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSAp_cmepr5_nHgLbNUvQAAAiA"]
[Tue Aug 18 12:56:23.274116 2026] [security2:error] [pid 67073:tid 67262] [client 20.151.109.219:12902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/uq.php"] [unique_id "aoSAp_cmepr5_nHgLbNUvgAAAk0"]
[Tue Aug 18 12:56:23.322565 2026] [autoindex:error] [pid 66623:tid 66825] [client 172.202.39.151:15740] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:23.353612 2026] [security2:error] [pid 66623:tid 66817] [client 20.52.168.85:8032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/colour.php"] [unique_id "aoSAp9O5rbWdOArH04KJwgAAAT0"]
[Tue Aug 18 12:56:23.386352 2026] [security2:error] [pid 66623:tid 66807] [client 172.202.39.151:65270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/akcc.php"] [unique_id "aoSAp9O5rbWdOArH04KJxAAAATM"]
[Tue Aug 18 12:56:23.401599 2026] [security2:error] [pid 67073:tid 67329] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kl.php"] [unique_id "aoSAp_cmepr5_nHgLbNUygAAApA"]
[Tue Aug 18 12:56:23.405743 2026] [security2:error] [pid 67073:tid 67230] [client 103.120.71.157:51558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAp_cmepr5_nHgLbNUywAAAi0"]
[Tue Aug 18 12:56:23.405932 2026] [security2:error] [pid 67073:tid 67230] [client 103.120.71.157:51558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAp_cmepr5_nHgLbNUywAAAi0"]
[Tue Aug 18 12:56:23.455395 2026] [security2:error] [pid 67073:tid 67255] [client 74.248.130.103:14456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/403dd.php"] [unique_id "aoSAp_cmepr5_nHgLbNUzAAAAkY"]
[Tue Aug 18 12:56:23.466741 2026] [security2:error] [pid 66623:tid 66791] [client 172.202.39.151:15740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wso.php"] [unique_id "aoSAp9O5rbWdOArH04KJxQAAASM"]
[Tue Aug 18 12:56:23.468727 2026] [security2:error] [pid 67073:tid 67257] [client 20.226.6.191:55782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSAp_cmepr5_nHgLbNUzQAAAkg"]
[Tue Aug 18 12:56:23.469875 2026] [security2:error] [pid 67073:tid 67234] [client 20.100.169.31:46204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/min.php"] [unique_id "aoSAp_cmepr5_nHgLbNUzwAAAjE"]
[Tue Aug 18 12:56:23.482141 2026] [security2:error] [pid 66623:tid 66866] [client 20.163.43.14:4232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSAp9O5rbWdOArH04KJxgAAAW4"]
[Tue Aug 18 12:56:23.505134 2026] [security2:error] [pid 67073:tid 67265] [client 74.7.230.22:45572] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.massagemrelax.com"] [uri "/index.php"] [unique_id "aoSApvcmepr5_nHgLbNUfgACUC4"]
[Tue Aug 18 12:56:23.534851 2026] [security2:error] [pid 67073:tid 67276] [client 135.225.75.187:51303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/fr/ms.php"] [unique_id "aoSAp_cmepr5_nHgLbNU3AAAAls"]
[Tue Aug 18 12:56:23.536359 2026] [security2:error] [pid 66623:tid 66875] [client 52.173.121.69:16456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSAp9O5rbWdOArH04KJxwAAAXc"]
[Tue Aug 18 12:56:23.579162 2026] [security2:error] [pid 66623:tid 66839] [client 197.184.64.235:41930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAp9O5rbWdOArH04KJyAAAAVM"]
[Tue Aug 18 12:56:23.579282 2026] [security2:error] [pid 66623:tid 66839] [client 197.184.64.235:41930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAp9O5rbWdOArH04KJyAAAAVM"]
[Tue Aug 18 12:56:23.580128 2026] [security2:error] [pid 67073:tid 67314] [client 20.79.204.6:2424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAp_cmepr5_nHgLbNU3gAAAoE"]
[Tue Aug 18 12:56:23.580231 2026] [security2:error] [pid 67073:tid 67307] [client 132.196.30.78:18756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/goods.php"] [unique_id "aoSAp_cmepr5_nHgLbNU4AAAAno"]
[Tue Aug 18 12:56:23.589861 2026] [security2:error] [pid 67073:tid 67163] [remote 157.230.98.178:57308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.98.230.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "orientadoraespiritualbhsp.com.br"] [uri "/wp-login.php"] [unique_id "aoSAp_cmepr5_nHgLbNU4QACO1c"]
[Tue Aug 18 12:56:23.646230 2026] [security2:error] [pid 66623:tid 66786] [client 20.151.109.219:64995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/32.php"] [unique_id "aoSAp9O5rbWdOArH04KJyQAAAR4"]
[Tue Aug 18 12:56:23.658002 2026] [security2:error] [pid 66623:tid 66773] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gs.php"] [unique_id "aoSAp9O5rbWdOArH04KJygAAARE"]
[Tue Aug 18 12:56:23.680372 2026] [security2:error] [pid 67073:tid 67316] [client 68.155.154.236:16379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSAp_cmepr5_nHgLbNU-QAAAoM"]
[Tue Aug 18 12:56:23.720665 2026] [security2:error] [pid 66623:tid 66810] [client 20.215.241.237:44036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/ccc.php"] [unique_id "aoSAp9O5rbWdOArH04KJzAAAATY"]
[Tue Aug 18 12:56:23.739765 2026] [security2:error] [pid 67073:tid 67319] [client 37.40.227.74:56882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAp_cmepr5_nHgLbNU-gAAAoY"]
[Tue Aug 18 12:56:23.739866 2026] [security2:error] [pid 67073:tid 67319] [client 37.40.227.74:56882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAp_cmepr5_nHgLbNU-gAAAoY"]
[Tue Aug 18 12:56:23.744366 2026] [security2:error] [pid 66623:tid 66861] [client 20.186.30.159:13597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/av.php"] [unique_id "aoSAp9O5rbWdOArH04KJzQAAAWk"]
[Tue Aug 18 12:56:23.762165 2026] [security2:error] [pid 67073:tid 67269] [client 74.248.136.165:46801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/thui.php"] [unique_id "aoSAp_cmepr5_nHgLbNU_AAAAlQ"]
[Tue Aug 18 12:56:23.790920 2026] [security2:error] [pid 67073:tid 67290] [client 20.171.51.14:45438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/gb.php"] [unique_id "aoSAp_cmepr5_nHgLbNU_QAAAmk"]
[Tue Aug 18 12:56:23.804531 2026] [security2:error] [pid 67073:tid 67226] [client 104.209.144.33:35875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSAp_cmepr5_nHgLbNU_wAAAik"]
[Tue Aug 18 12:56:23.820078 2026] [security2:error] [pid 66623:tid 66841] [client 20.163.43.14:4258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAp9O5rbWdOArH04KJzgAAAVU"]
[Tue Aug 18 12:56:23.840600 2026] [security2:error] [pid 66623:tid 66854] [client 158.158.74.177:2628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/post.php"] [unique_id "aoSAp9O5rbWdOArH04KJ0AAAAWI"]
[Tue Aug 18 12:56:23.867793 2026] [security2:error] [pid 67073:tid 67317] [client 172.202.39.151:50197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wk/index.php"] [unique_id "aoSAp_cmepr5_nHgLbNVBQAAAoQ"]
[Tue Aug 18 12:56:23.903172 2026] [security2:error] [pid 67073:tid 67294] [client 20.116.17.175:57619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/8.php"] [unique_id "aoSAp_cmepr5_nHgLbNVBwAAAm0"]
[Tue Aug 18 12:56:23.912134 2026] [security2:error] [pid 67073:tid 67254] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/lw.php"] [unique_id "aoSAp_cmepr5_nHgLbNVCQAAAkU"]
[Tue Aug 18 12:56:23.917139 2026] [security2:error] [pid 66623:tid 66850] [client 74.248.130.103:15365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/baba.php"] [unique_id "aoSAp9O5rbWdOArH04KJ0gAAAV4"]
[Tue Aug 18 12:56:23.925397 2026] [security2:error] [pid 66623:tid 66814] [client 20.29.77.16:52755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/smtp.php"] [unique_id "aoSAp9O5rbWdOArH04KJ0wAAATo"]
[Tue Aug 18 12:56:23.943980 2026] [security2:error] [pid 66623:tid 66864] [client 74.7.230.22:45574] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "massagemrelax.com"] [uri "/index.php"] [unique_id "aoSAp9O5rbWdOArH04KJ0QABbD8"], referer: https://www.massagemrelax.com/robots.txt
[Tue Aug 18 12:56:23.958683 2026] [security2:error] [pid 66623:tid 66768] [client 20.52.168.85:7838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/file4.php"] [unique_id "aoSAp9O5rbWdOArH04KJ1AAAAQw"]
[Tue Aug 18 12:56:23.993818 2026] [security2:error] [pid 67073:tid 67277] [client 20.151.109.219:17568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/73.php"] [unique_id "aoSAp_cmepr5_nHgLbNVDgAAAlw"]
[Tue Aug 18 12:56:24.029394 2026] [security2:error] [pid 67073:tid 67247] [client 213.35.127.232:56778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAqPcmepr5_nHgLbNVEAAAAj4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:24.035904 2026] [security2:error] [pid 67073:tid 67221] [client 68.155.154.236:16275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSAqPcmepr5_nHgLbNVEgAAAiQ"]
[Tue Aug 18 12:56:24.150708 2026] [security2:error] [pid 67073:tid 67229] [client 20.163.43.14:4160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/cah.php"] [unique_id "aoSAqPcmepr5_nHgLbNVFQAAAiw"]
[Tue Aug 18 12:56:24.158243 2026] [security2:error] [pid 67073:tid 67301] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/vj.php"] [unique_id "aoSAqPcmepr5_nHgLbNVFgAAAnQ"]
[Tue Aug 18 12:56:24.203816 2026] [security2:error] [pid 67073:tid 67281] [client 20.79.204.6:2370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSAqPcmepr5_nHgLbNVFwAAAmA"]
[Tue Aug 18 12:56:24.251298 2026] [security2:error] [pid 67073:tid 67332] [client 20.215.241.237:43623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/get.php"] [unique_id "aoSAqPcmepr5_nHgLbNVHQAAApM"]
[Tue Aug 18 12:56:24.305870 2026] [authz_core:error] [pid 67073:tid 67225] [client 192.178.4.133:65481] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:24.306173 2026] [authz_core:error] [pid 67073:tid 67225] [client 192.178.4.133:65481] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:24.312244 2026] [security2:error] [pid 67073:tid 67249] [client 20.151.109.219:12878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ib.php"] [unique_id "aoSAqPcmepr5_nHgLbNVIAAAAkA"]
[Tue Aug 18 12:56:24.344142 2026] [security2:error] [pid 67073:tid 67217] [client 20.186.30.159:13589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/media.php"] [unique_id "aoSAqPcmepr5_nHgLbNVIQAAAiA"]
[Tue Aug 18 12:56:24.351218 2026] [security2:error] [pid 67073:tid 67262] [client 20.65.69.59:49338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/filesystems.php"] [unique_id "aoSAqPcmepr5_nHgLbNVIgAAAk0"]
[Tue Aug 18 12:56:24.380379 2026] [security2:error] [pid 67073:tid 67266] [client 68.155.154.236:16332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSAqPcmepr5_nHgLbNVJwAAAlE"]
[Tue Aug 18 12:56:24.405146 2026] [security2:error] [pid 67073:tid 67282] [client 74.248.130.103:36813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/site.php"] [unique_id "aoSAqPcmepr5_nHgLbNVKwAAAmE"]
[Tue Aug 18 12:56:24.410710 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:24.410993 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:24.433735 2026] [security2:error] [pid 67073:tid 67326] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/mimes.php"] [unique_id "aoSAqPcmepr5_nHgLbNVLQAAAo0"]
[Tue Aug 18 12:56:24.442000 2026] [security2:error] [pid 66623:tid 66865] [client 158.158.34.183:35132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/w.php"] [unique_id "aoSAqNO5rbWdOArH04KJ2AAAAW0"]
[Tue Aug 18 12:56:24.483262 2026] [security2:error] [pid 67073:tid 67312] [client 135.225.75.187:17670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/gool.php"] [unique_id "aoSAqPcmepr5_nHgLbNVMAAAAn8"]
[Tue Aug 18 12:56:24.486811 2026] [security2:error] [pid 67073:tid 67242] [client 86.120.159.145:6829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAqPcmepr5_nHgLbNVMwAAAjk"]
[Tue Aug 18 12:56:24.486904 2026] [security2:error] [pid 67073:tid 67242] [client 86.120.159.145:6829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAqPcmepr5_nHgLbNVMwAAAjk"]
[Tue Aug 18 12:56:24.513370 2026] [security2:error] [pid 67073:tid 67264] [client 20.104.85.180:6977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAqPcmepr5_nHgLbNVNQAAAk8"]
[Tue Aug 18 12:56:24.536395 2026] [security2:error] [pid 67073:tid 67214] [client 132.196.30.78:22473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/file.php"] [unique_id "aoSAqPcmepr5_nHgLbNVNgAAAh0"]
[Tue Aug 18 12:56:24.562525 2026] [security2:error] [pid 67073:tid 67246] [client 20.52.168.85:7852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-includes/assets/index.php"] [unique_id "aoSAqPcmepr5_nHgLbNVNwAAAj0"]
[Tue Aug 18 12:56:24.575694 2026] [security2:error] [pid 67073:tid 67314] [client 172.182.200.96:14187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSAqPcmepr5_nHgLbNVOQAAAoE"]
[Tue Aug 18 12:56:24.581888 2026] [security2:error] [pid 67073:tid 67263] [client 20.171.51.14:31622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/jp.php"] [unique_id "aoSAqPcmepr5_nHgLbNVOgAAAk4"]
[Tue Aug 18 12:56:24.601669 2026] [security2:error] [pid 67073:tid 67226] [client 20.226.56.190:20375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/fb.php"] [unique_id "aoSAqPcmepr5_nHgLbNVPAAAAik"]
[Tue Aug 18 12:56:24.645948 2026] [security2:error] [pid 67073:tid 67322] [client 20.151.109.219:65017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/xm.php"] [unique_id "aoSAqPcmepr5_nHgLbNVPwAAAok"]
[Tue Aug 18 12:56:24.654434 2026] [security2:error] [pid 67073:tid 67256] [client 20.163.43.14:4265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/system_log.php"] [unique_id "aoSAqPcmepr5_nHgLbNVQAAAAkc"]
[Tue Aug 18 12:56:24.695949 2026] [security2:error] [pid 66623:tid 66879] [client 20.215.241.237:40450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/images.php"] [unique_id "aoSAqNO5rbWdOArH04KJ2QAAAXs"]
[Tue Aug 18 12:56:24.698055 2026] [security2:error] [pid 66623:tid 66833] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ni.php"] [unique_id "aoSAqNO5rbWdOArH04KJ2gAAAU0"]
[Tue Aug 18 12:56:24.717046 2026] [authz_core:error] [pid 67073:tid 67147] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:24.717456 2026] [authz_core:error] [pid 67073:tid 67147] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:24.725782 2026] [security2:error] [pid 67073:tid 67309] [client 68.155.154.236:16382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSAqPcmepr5_nHgLbNVRgAAAnw"]
[Tue Aug 18 12:56:24.796063 2026] [security2:error] [pid 67073:tid 67228] [client 20.104.85.180:18820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAqPcmepr5_nHgLbNVSwAAAis"]
[Tue Aug 18 12:56:24.799712 2026] [security2:error] [pid 67073:tid 67236] [client 103.184.169.37:41891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAqPcmepr5_nHgLbNVTAAAAjM"]
[Tue Aug 18 12:56:24.799866 2026] [security2:error] [pid 67073:tid 67236] [client 103.184.169.37:41891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAqPcmepr5_nHgLbNVTAAAAjM"]
[Tue Aug 18 12:56:24.821075 2026] [security2:error] [pid 67073:tid 67293] [client 20.186.30.159:13685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/images.php"] [unique_id "aoSAqPcmepr5_nHgLbNVTQAAAmw"]
[Tue Aug 18 12:56:24.826286 2026] [security2:error] [pid 66623:tid 66828] [client 20.79.204.6:2213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSAqNO5rbWdOArH04KJ3wAAAUg"]
[Tue Aug 18 12:56:24.866760 2026] [security2:error] [pid 67073:tid 67305] [client 158.158.74.177:22733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/r.php"] [unique_id "aoSAqPcmepr5_nHgLbNVTgAAAng"]
[Tue Aug 18 12:56:24.868609 2026] [security2:error] [pid 67073:tid 67280] [client 74.248.130.103:14416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSAqPcmepr5_nHgLbNVTwAAAl8"]
[Tue Aug 18 12:56:24.876037 2026] [security2:error] [pid 67073:tid 67222] [client 74.248.18.37:26813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/ww5.php"] [unique_id "aoSAqPcmepr5_nHgLbNVUQAAAiU"]
[Tue Aug 18 12:56:24.945969 2026] [security2:error] [pid 66623:tid 66767] [client 20.65.69.59:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bioclimaarcondicionado.com.br"] [uri "/1.php"] [unique_id "aoSAqNO5rbWdOArH04KJ4AAAAQs"]
[Tue Aug 18 12:56:24.946055 2026] [security2:error] [pid 66623:tid 66767] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/1.php"] [unique_id "aoSAqNO5rbWdOArH04KJ4AAAAQs"]
[Tue Aug 18 12:56:24.956753 2026] [security2:error] [pid 66623:tid 66847] [client 158.23.17.4:38885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/filesystems.php"] [unique_id "aoSAqNO5rbWdOArH04KJ4QAAAVs"]
[Tue Aug 18 12:56:24.971078 2026] [security2:error] [pid 67073:tid 67223] [client 172.202.39.151:28962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/file.php"] [unique_id "aoSAqPcmepr5_nHgLbNVVwAAAiY"]
[Tue Aug 18 12:56:25.012145 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:25.012411 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:25.015016 2026] [security2:error] [pid 67073:tid 67232] [client 20.151.109.219:24832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/zy.php"] [unique_id "aoSAqfcmepr5_nHgLbNVXAAAAi8"]
[Tue Aug 18 12:56:25.032580 2026] [security2:error] [pid 67073:tid 67220] [client 20.29.77.16:47757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/teste.php"] [unique_id "aoSAqfcmepr5_nHgLbNVXgAAAiM"]
[Tue Aug 18 12:56:25.041129 2026] [security2:error] [pid 67073:tid 67291] [client 213.35.127.232:56965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAqfcmepr5_nHgLbNVXwAAAmo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:25.066824 2026] [security2:error] [pid 67073:tid 67266] [client 68.155.154.236:16372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSAqfcmepr5_nHgLbNVYgAAAlE"]
[Tue Aug 18 12:56:25.070128 2026] [autoindex:error] [pid 67073:tid 67221] [client 20.100.169.31:42683] AH01276: Cannot serve directory /home1/lubarbosa/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:25.077298 2026] [security2:error] [pid 67073:tid 67213] [client 20.104.85.180:18835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/abc.php"] [unique_id "aoSAqfcmepr5_nHgLbNVZAAAAhw"]
[Tue Aug 18 12:56:25.126160 2026] [security2:error] [pid 67073:tid 67255] [client 20.215.241.237:61093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/alls.php"] [unique_id "aoSAqfcmepr5_nHgLbNVZQAAAkY"]
[Tue Aug 18 12:56:25.154143 2026] [security2:error] [pid 67073:tid 67304] [client 20.186.30.159:13586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/mac.php"] [unique_id "aoSAqfcmepr5_nHgLbNVZwAAAnc"]
[Tue Aug 18 12:56:25.162443 2026] [security2:error] [pid 66623:tid 66831] [client 20.52.168.85:8014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/t.php"] [unique_id "aoSAqdO5rbWdOArH04KJ4gAAAUs"]
[Tue Aug 18 12:56:25.171378 2026] [security2:error] [pid 67073:tid 67267] [client 172.202.39.151:65249] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/1.php"] [unique_id "aoSAqfcmepr5_nHgLbNVaQAAAlI"]
[Tue Aug 18 12:56:25.171461 2026] [security2:error] [pid 67073:tid 67267] [client 172.202.39.151:65249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/1.php"] [unique_id "aoSAqfcmepr5_nHgLbNVaQAAAlI"]
[Tue Aug 18 12:56:25.193547 2026] [security2:error] [pid 67073:tid 67264] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/88.php"] [unique_id "aoSAqfcmepr5_nHgLbNVagAAAk8"]
[Tue Aug 18 12:56:25.216901 2026] [security2:error] [pid 67073:tid 67214] [client 20.163.43.14:4189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAqfcmepr5_nHgLbNVawAAAh0"]
[Tue Aug 18 12:56:25.221731 2026] [security2:error] [pid 66623:tid 66811] [client 172.202.39.151:48225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/sf.php"] [unique_id "aoSAqdO5rbWdOArH04KJ4wAAATc"]
[Tue Aug 18 12:56:25.256004 2026] [security2:error] [pid 67073:tid 67164] [remote 47.86.33.52:51448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "m2mit.cloud"] [uri "/wp-login.php"] [unique_id "aoSAqfcmepr5_nHgLbNVbQACFlg"]
[Tue Aug 18 12:56:25.280102 2026] [security2:error] [pid 67073:tid 67250] [client 20.100.169.31:42683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/php8.php"] [unique_id "aoSAqfcmepr5_nHgLbNVeAAAAkE"]
[Tue Aug 18 12:56:25.333451 2026] [security2:error] [pid 66623:tid 66868] [client 20.151.109.219:59771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/q.php"] [unique_id "aoSAqdO5rbWdOArH04KJ5AAAAXA"]
[Tue Aug 18 12:56:25.355366 2026] [security2:error] [pid 67073:tid 67254] [client 20.104.85.180:6988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/akcc.php"] [unique_id "aoSAqfcmepr5_nHgLbNVfwAAAkU"]
[Tue Aug 18 12:56:25.365817 2026] [security2:error] [pid 66623:tid 66860] [client 74.248.130.103:15393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/cabs.php"] [unique_id "aoSAqdO5rbWdOArH04KJ5QAAAWg"]
[Tue Aug 18 12:56:25.381849 2026] [security2:error] [pid 67073:tid 67230] [client 158.158.34.183:34969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-admin/css/wp-login.php"] [unique_id "aoSAqfcmepr5_nHgLbNVgQAAAi0"]
[Tue Aug 18 12:56:25.385784 2026] [security2:error] [pid 67073:tid 67205] [client 74.248.136.165:61409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/agg.php"] [unique_id "aoSAqfcmepr5_nHgLbNVggAAAhQ"]
[Tue Aug 18 12:56:25.404306 2026] [security2:error] [pid 66623:tid 66863] [client 68.155.154.236:16359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSAqdO5rbWdOArH04KJ5wAAAWs"]
[Tue Aug 18 12:56:25.434112 2026] [security2:error] [pid 67073:tid 67322] [client 20.226.6.191:32987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br"] [uri "/wp-login.php"] [unique_id "aoSAqfcmepr5_nHgLbNVhQAAAok"]
[Tue Aug 18 12:56:25.439300 2026] [security2:error] [pid 67073:tid 67256] [client 20.226.6.191:32295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSAqfcmepr5_nHgLbNVhgAAAkc"]
[Tue Aug 18 12:56:25.448347 2026] [security2:error] [pid 67073:tid 67215] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/hj.php"] [unique_id "aoSAqfcmepr5_nHgLbNViAAAAh4"]
[Tue Aug 18 12:56:25.459563 2026] [security2:error] [pid 67073:tid 67257] [client 197.186.9.193:63821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.9.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intersul.ind.br"] [uri "/xmlrpc.php"] [unique_id "aoSAqfcmepr5_nHgLbNVeQAAAkg"]
[Tue Aug 18 12:56:25.459703 2026] [security2:error] [pid 67073:tid 67257] [client 197.186.9.193:63821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intersul.ind.br"] [uri "/xmlrpc.php"] [unique_id "aoSAqfcmepr5_nHgLbNVeQAAAkg"]
[Tue Aug 18 12:56:25.523827 2026] [security2:error] [pid 67073:tid 67210] [client 20.79.204.6:2202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSAqfcmepr5_nHgLbNVigAAAhk"]
[Tue Aug 18 12:56:25.543354 2026] [security2:error] [pid 66623:tid 66873] [client 20.163.43.14:4317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAqdO5rbWdOArH04KJ6AAAAXU"]
[Tue Aug 18 12:56:25.551474 2026] [security2:error] [pid 67073:tid 67131] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.env"] [unique_id "aoSAqfcmepr5_nHgLbNVjQACUzc"]
[Tue Aug 18 12:56:25.577469 2026] [security2:error] [pid 67073:tid 67293] [client 20.29.77.16:52785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/local.php"] [unique_id "aoSAqfcmepr5_nHgLbNVjwAAAmw"]
[Tue Aug 18 12:56:25.586003 2026] [security2:error] [pid 67073:tid 67248] [client 20.215.241.237:61078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/coffexium.php"] [unique_id "aoSAqfcmepr5_nHgLbNVkAAAAj8"]
[Tue Aug 18 12:56:25.614286 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:25.614541 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:25.615645 2026] [security2:error] [pid 67073:tid 67280] [client 52.173.121.69:16499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSAqfcmepr5_nHgLbNVkgAAAl8"]
[Tue Aug 18 12:56:25.617631 2026] [security2:error] [pid 67073:tid 67222] [client 20.186.30.159:13609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/ops.php"] [unique_id "aoSAqfcmepr5_nHgLbNVkwAAAiU"]
[Tue Aug 18 12:56:25.627749 2026] [security2:error] [pid 67073:tid 67285] [client 132.196.61.152:61052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/clque.php"] [unique_id "aoSAqfcmepr5_nHgLbNVlQAAAmQ"]
[Tue Aug 18 12:56:25.640247 2026] [security2:error] [pid 67073:tid 67279] [client 20.104.85.180:18842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wk/index.php"] [unique_id "aoSAqfcmepr5_nHgLbNVlwAAAl4"]
[Tue Aug 18 12:56:25.659079 2026] [security2:error] [pid 66623:tid 66846] [client 172.202.39.151:50209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSAqdO5rbWdOArH04KJ6QAAAVo"]
[Tue Aug 18 12:56:25.665763 2026] [security2:error] [pid 67073:tid 67281] [client 20.151.109.219:17545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/xf.php"] [unique_id "aoSAqfcmepr5_nHgLbNVmAAAAmA"]
[Tue Aug 18 12:56:25.682784 2026] [security2:error] [pid 67073:tid 67270] [client 135.225.75.187:25659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/maxro.php"] [unique_id "aoSAqfcmepr5_nHgLbNVmQAAAlU"]
[Tue Aug 18 12:56:25.701467 2026] [security2:error] [pid 67073:tid 67241] [client 52.139.47.57:25725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/black.php"] [unique_id "aoSAqfcmepr5_nHgLbNVmgAAAjg"]
[Tue Aug 18 12:56:25.709322 2026] [security2:error] [pid 67073:tid 67233] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ij.php"] [unique_id "aoSAqfcmepr5_nHgLbNVmwAAAjA"]
[Tue Aug 18 12:56:25.715394 2026] [security2:error] [pid 66623:tid 66790] [client 20.65.98.162:53440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/puc.php"] [unique_id "aoSAqdO5rbWdOArH04KJ6wAAASI"]
[Tue Aug 18 12:56:25.751229 2026] [security2:error] [pid 67073:tid 67206] [client 158.158.74.177:2964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/radio.php"] [unique_id "aoSAqfcmepr5_nHgLbNVnQAAAhU"]
[Tue Aug 18 12:56:25.767540 2026] [security2:error] [pid 67073:tid 67228] [client 20.52.168.85:7853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/.well-known/acme-challenge/file.php"] [unique_id "aoSAqfcmepr5_nHgLbNVoAAAAis"]
[Tue Aug 18 12:56:25.852997 2026] [security2:error] [pid 67073:tid 67077] [remote 185.118.190.176:39944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.190.118.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "latung.com.br"] [uri "/wp-login.php"] [unique_id "aoSAqfcmepr5_nHgLbNVogACIQE"]
[Tue Aug 18 12:56:25.861843 2026] [security2:error] [pid 67073:tid 67213] [client 74.248.130.103:38667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/insc.php"] [unique_id "aoSAqfcmepr5_nHgLbNVowAAAhw"]
[Tue Aug 18 12:56:25.896191 2026] [security2:error] [pid 67073:tid 67214] [client 20.163.43.14:4124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/abc.php"] [unique_id "aoSAqfcmepr5_nHgLbNVpQAAAh0"]
[Tue Aug 18 12:56:25.924101 2026] [security2:error] [pid 67073:tid 67272] [client 20.104.85.180:18830] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "certificado.numem.com.br"] [uri "/1.php"] [unique_id "aoSAqfcmepr5_nHgLbNVpwAAAlc"]
[Tue Aug 18 12:56:25.924243 2026] [security2:error] [pid 67073:tid 67272] [client 20.104.85.180:18830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/1.php"] [unique_id "aoSAqfcmepr5_nHgLbNVpwAAAlc"]
[Tue Aug 18 12:56:25.973914 2026] [security2:error] [pid 67073:tid 67245] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ud.php"] [unique_id "aoSAqfcmepr5_nHgLbNVqAAAAjw"]
[Tue Aug 18 12:56:26.003457 2026] [autoindex:error] [pid 67073:tid 67207] [client 189.5.11.234:56651] AH01276: Cannot serve directory /home4/maxtelec/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:26.034837 2026] [security2:error] [pid 67073:tid 67259] [client 172.202.39.151:55433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAqvcmepr5_nHgLbNVrAAAAko"]
[Tue Aug 18 12:56:26.037263 2026] [security2:error] [pid 67073:tid 67317] [client 20.151.109.219:21684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gb.php"] [unique_id "aoSAqvcmepr5_nHgLbNVrQAAAoQ"]
[Tue Aug 18 12:56:26.052954 2026] [security2:error] [pid 66623:tid 66889] [client 20.215.241.237:40477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/red.php"] [unique_id "aoSAqtO5rbWdOArH04KJ7AAAAYU"]
[Tue Aug 18 12:56:26.057133 2026] [security2:error] [pid 67073:tid 67332] [client 213.35.127.232:57177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAqvcmepr5_nHgLbNVrgAAApM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:26.070894 2026] [security2:error] [pid 67073:tid 67294] [client 20.226.56.190:2508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gw.php"] [unique_id "aoSAqvcmepr5_nHgLbNVrwAAAm0"]
[Tue Aug 18 12:56:26.079249 2026] [security2:error] [pid 67073:tid 67205] [client 20.215.241.237:59711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/file1221.php"] [unique_id "aoSAqvcmepr5_nHgLbNVsAAAAhQ"]
[Tue Aug 18 12:56:26.092715 2026] [security2:error] [pid 67073:tid 67212] [client 20.29.77.16:32967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/wp_sitting.php"] [unique_id "aoSAqvcmepr5_nHgLbNVsgAAAhs"]
[Tue Aug 18 12:56:26.122878 2026] [security2:error] [pid 67073:tid 67215] [client 68.155.154.236:16355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSAqvcmepr5_nHgLbNVswAAAh4"]
[Tue Aug 18 12:56:26.126395 2026] [security2:error] [pid 67073:tid 67257] [client 104.209.144.33:25656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSAqvcmepr5_nHgLbNVtQAAAkg"]
[Tue Aug 18 12:56:26.134133 2026] [security2:error] [pid 67073:tid 67316] [client 20.79.204.6:2385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAqvcmepr5_nHgLbNVtgAAAoM"]
[Tue Aug 18 12:56:26.164335 2026] [autoindex:error] [pid 67073:tid 67247] [client 189.5.11.234:34669] AH01276: Cannot serve directory /home4/maxtelec/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:26.165605 2026] [security2:error] [pid 67073:tid 67284] [client 20.186.30.159:13659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/coffexium.php"] [unique_id "aoSAqvcmepr5_nHgLbNVuQAAAmM"]
[Tue Aug 18 12:56:26.218674 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:26.219047 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:26.227163 2026] [security2:error] [pid 67073:tid 67231] [client 20.163.43.14:4336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/akcc.php"] [unique_id "aoSAqvcmepr5_nHgLbNVwAAAAi4"]
[Tue Aug 18 12:56:26.228701 2026] [security2:error] [pid 66623:tid 66834] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ip.php"] [unique_id "aoSAqtO5rbWdOArH04KJ7QAAAU4"]
[Tue Aug 18 12:56:26.242219 2026] [security2:error] [pid 67073:tid 67102] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.env.backup"] [unique_id "aoSAqvcmepr5_nHgLbNVwgACgBo"]
[Tue Aug 18 12:56:26.260490 2026] [security2:error] [pid 67073:tid 67103] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.env.bak"] [unique_id "aoSAqvcmepr5_nHgLbNVxAACgBs"]
[Tue Aug 18 12:56:26.274732 2026] [security2:error] [pid 67073:tid 67301] [client 20.104.85.180:18834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSAqvcmepr5_nHgLbNVxwAAAnQ"]
[Tue Aug 18 12:56:26.276810 2026] [security2:error] [pid 67073:tid 67327] [client 20.116.17.175:57456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/images.php"] [unique_id "aoSAqvcmepr5_nHgLbNVyAAAAo4"]
[Tue Aug 18 12:56:26.287221 2026] [security2:error] [pid 67073:tid 67190] [remote 47.86.33.52:5772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tigre.tur.br.slweb.net.br"] [uri "/wp-login.php"] [unique_id "aoSAqvcmepr5_nHgLbNVygACGHI"]
[Tue Aug 18 12:56:26.305770 2026] [autoindex:error] [pid 67073:tid 67229] [client 189.5.11.234:59663] AH01276: Cannot serve directory /home4/maxtelec/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:26.315259 2026] [security2:error] [pid 66623:tid 66881] [client 74.248.130.103:36814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/file.php"] [unique_id "aoSAqtO5rbWdOArH04KJ7gAAAX0"]
[Tue Aug 18 12:56:26.353459 2026] [security2:error] [pid 66623:tid 66789] [client 20.151.109.219:65010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/jp.php"] [unique_id "aoSAqtO5rbWdOArH04KJ7wAAASE"]
[Tue Aug 18 12:56:26.355995 2026] [security2:error] [pid 66623:tid 66840] [client 20.171.51.14:29229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/eq.php"] [unique_id "aoSAqtO5rbWdOArH04KJ8AAAAVQ"]
[Tue Aug 18 12:56:26.368266 2026] [security2:error] [pid 67073:tid 67296] [client 20.52.168.85:7867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/bgymj.php"] [unique_id "aoSAqvcmepr5_nHgLbNVzAAAAm8"]
[Tue Aug 18 12:56:26.383148 2026] [security2:error] [pid 66623:tid 66835] [client 20.226.6.191:32208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAqtO5rbWdOArH04KJ8gAAAU8"]
[Tue Aug 18 12:56:26.396048 2026] [autoindex:error] [pid 67073:tid 67287] [client 189.5.11.234:40473] AH01276: Cannot serve directory /home4/maxtelec/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:26.411897 2026] [security2:error] [pid 67073:tid 67268] [client 172.202.39.151:50211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/as.php"] [unique_id "aoSAqvcmepr5_nHgLbNVzwAAAlM"]
[Tue Aug 18 12:56:26.428279 2026] [security2:error] [pid 67073:tid 67211] [client 74.248.18.37:46683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/2.php"] [unique_id "aoSAqvcmepr5_nHgLbNV0AAAAho"]
[Tue Aug 18 12:56:26.443454 2026] [security2:error] [pid 66623:tid 66821] [client 5.31.227.224:59047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAqtO5rbWdOArH04KJ9AAAAUE"]
[Tue Aug 18 12:56:26.443564 2026] [security2:error] [pid 66623:tid 66821] [client 5.31.227.224:59047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAqtO5rbWdOArH04KJ9AAAAUE"]
[Tue Aug 18 12:56:26.480357 2026] [security2:error] [pid 67073:tid 67114] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.env.old"] [unique_id "aoSAqvcmepr5_nHgLbNV0QACJiY"]
[Tue Aug 18 12:56:26.487363 2026] [security2:error] [pid 67073:tid 67217] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/99.php"] [unique_id "aoSAqvcmepr5_nHgLbNV0gAAAiA"]
[Tue Aug 18 12:56:26.522110 2026] [authz_core:error] [pid 67073:tid 67166] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:26.522561 2026] [authz_core:error] [pid 67073:tid 67166] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:26.552275 2026] [security2:error] [pid 67073:tid 67321] [client 20.163.43.14:4112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wk/index.php"] [unique_id "aoSAqvcmepr5_nHgLbNV1QAAAog"]
[Tue Aug 18 12:56:26.556147 2026] [security2:error] [pid 66623:tid 66817] [client 20.104.85.180:43573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAqtO5rbWdOArH04KJ9QAAAT0"]
[Tue Aug 18 12:56:26.564329 2026] [security2:error] [pid 66623:tid 66880] [client 132.196.30.78:18653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAqtO5rbWdOArH04KJ9gAAAXw"]
[Tue Aug 18 12:56:26.566779 2026] [security2:error] [pid 67073:tid 67248] [client 158.158.74.177:17951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/randkeyword.php7"] [unique_id "aoSAqvcmepr5_nHgLbNV1wAAAj8"]
[Tue Aug 18 12:56:26.579860 2026] [security2:error] [pid 67073:tid 67085] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/api/.env"] [unique_id "aoSAqvcmepr5_nHgLbNV2AACUQk"]
[Tue Aug 18 12:56:26.609756 2026] [security2:error] [pid 67073:tid 67196] [remote 110.249.201.114:10208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tivinalili.com.br"] [uri "/starsue%20ever%20after%20high.pdf"] [unique_id "aoSAqvcmepr5_nHgLbNV2wACHHg"]
[Tue Aug 18 12:56:26.624390 2026] [security2:error] [pid 67073:tid 67275] [client 20.186.30.159:13642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAqvcmepr5_nHgLbNV3AAAAlo"]
[Tue Aug 18 12:56:26.636458 2026] [security2:error] [pid 66623:tid 66796] [client 158.23.17.4:63645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/showphpinfo.php"] [unique_id "aoSAqtO5rbWdOArH04KJ-wAAASg"]
[Tue Aug 18 12:56:26.677032 2026] [security2:error] [pid 67073:tid 67194] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/backend/.env"] [unique_id "aoSAqvcmepr5_nHgLbNV3gACT3Y"]
[Tue Aug 18 12:56:26.738110 2026] [security2:error] [pid 66623:tid 66776] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/er.php"] [unique_id "aoSAqtO5rbWdOArH04KJ_QAAARQ"]
[Tue Aug 18 12:56:26.746372 2026] [security2:error] [pid 67073:tid 67297] [client 20.151.109.219:21656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/eq.php"] [unique_id "aoSAqvcmepr5_nHgLbNV4wAAAnA"]
[Tue Aug 18 12:56:26.754752 2026] [security2:error] [pid 66623:tid 66839] [client 172.202.39.151:65273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAqtO5rbWdOArH04KJ_gAAAVM"]
[Tue Aug 18 12:56:26.764543 2026] [security2:error] [pid 67073:tid 67331] [client 5.161.73.160:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jlypiscinas.com.br"] [uri "/index.php"] [unique_id "aoSAqfcmepr5_nHgLbNVZgACkj4"], referer: https://jlypiscinas.com.br/
[Tue Aug 18 12:56:26.786915 2026] [security2:error] [pid 67073:tid 67281] [client 158.158.34.183:55855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-content/languages/index.php"] [unique_id "aoSAqvcmepr5_nHgLbNV5gAAAmA"]
[Tue Aug 18 12:56:26.791080 2026] [security2:error] [pid 67073:tid 67245] [client 135.225.75.187:29775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wdf.php"] [unique_id "aoSAqvcmepr5_nHgLbNV5wAAAjw"]
[Tue Aug 18 12:56:26.819654 2026] [authz_core:error] [pid 67073:tid 67165] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:26.819967 2026] [authz_core:error] [pid 67073:tid 67165] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:26.839673 2026] [security2:error] [pid 66623:tid 66842] [client 20.226.6.191:56753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/file.php"] [unique_id "aoSAqtO5rbWdOArH04KKBgAAAVY"]
[Tue Aug 18 12:56:26.839985 2026] [security2:error] [pid 67073:tid 67095] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/config/.env"] [unique_id "aoSAqvcmepr5_nHgLbNV6QACPRM"]
[Tue Aug 18 12:56:26.840474 2026] [security2:error] [pid 66623:tid 66803] [client 20.104.85.180:43546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/as.php"] [unique_id "aoSAqtO5rbWdOArH04KKBwAAAS8"]
[Tue Aug 18 12:56:26.859869 2026] [security2:error] [pid 67073:tid 67259] [client 68.155.154.236:16383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSAqvcmepr5_nHgLbNV7AAAAko"]
[Tue Aug 18 12:56:26.861786 2026] [security2:error] [pid 67073:tid 67261] [client 20.79.204.6:2176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAqvcmepr5_nHgLbNV7QAAAkw"]
[Tue Aug 18 12:56:26.912181 2026] [security2:error] [pid 67073:tid 67299] [client 20.163.43.14:4111] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.fmplast.com.br"] [uri "/1.php"] [unique_id "aoSAqvcmepr5_nHgLbNV8AAAAnI"]
[Tue Aug 18 12:56:26.912301 2026] [security2:error] [pid 67073:tid 67299] [client 20.163.43.14:4111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/1.php"] [unique_id "aoSAqvcmepr5_nHgLbNV8AAAAnI"]
[Tue Aug 18 12:56:26.936324 2026] [security2:error] [pid 66623:tid 66645] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSAqtO5rbWdOArH04KKCAABYwg"]
[Tue Aug 18 12:56:26.969066 2026] [security2:error] [pid 67073:tid 67227] [client 20.29.77.16:51374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/ninja.php"] [unique_id "aoSAqvcmepr5_nHgLbNV8wAAAio"]
[Tue Aug 18 12:56:26.992116 2026] [security2:error] [pid 67073:tid 67205] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/qk.php"] [unique_id "aoSAqvcmepr5_nHgLbNV9AAAAhQ"]
[Tue Aug 18 12:56:27.037490 2026] [security2:error] [pid 67073:tid 67309] [client 20.151.109.219:64187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ep.php"] [unique_id "aoSAq_cmepr5_nHgLbNV9gAAAnw"]
[Tue Aug 18 12:56:27.070946 2026] [security2:error] [pid 67073:tid 67282] [client 74.248.130.103:14424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/dex.php"] [unique_id "aoSAq_cmepr5_nHgLbNV9wAAAmE"]
[Tue Aug 18 12:56:27.081849 2026] [security2:error] [pid 66623:tid 66808] [client 114.5.214.109:49810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAq9O5rbWdOArH04KKCwAAATQ"]
[Tue Aug 18 12:56:27.081898 2026] [security2:error] [pid 67073:tid 67310] [client 213.35.127.232:57435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAq_cmepr5_nHgLbNV-wAAAn0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:27.087903 2026] [security2:error] [pid 67073:tid 67308] [client 172.202.39.151:50216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSAq_cmepr5_nHgLbNV_QAAAns"]
[Tue Aug 18 12:56:27.088572 2026] [security2:error] [pid 66623:tid 66808] [client 114.5.214.109:49810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAq9O5rbWdOArH04KKCwAAATQ"]
[Tue Aug 18 12:56:27.133665 2026] [security2:error] [pid 66623:tid 66778] [client 20.104.85.180:18870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAq9O5rbWdOArH04KKDAAAARY"]
[Tue Aug 18 12:56:27.137258 2026] [security2:error] [pid 66623:tid 66708] [remote 57.141.22.51:31618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSAq9O5rbWdOArH04KKDQABOkc"]
[Tue Aug 18 12:56:27.138367 2026] [security2:error] [pid 67073:tid 67229] [client 20.226.56.190:28242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/sw.php"] [unique_id "aoSAq_cmepr5_nHgLbNWAQAAAiw"]
[Tue Aug 18 12:56:27.175834 2026] [security2:error] [pid 67073:tid 67280] [client 20.52.168.85:7813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-blog.php"] [unique_id "aoSAq_cmepr5_nHgLbNWAgAAAl8"]
[Tue Aug 18 12:56:27.201746 2026] [security2:error] [pid 67073:tid 67127] [remote 162.214.205.212:38280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amp.adv.br"] [uri "/wp-login.php"] [unique_id "aoSAq_cmepr5_nHgLbNWCgACNjM"]
[Tue Aug 18 12:56:27.208978 2026] [security2:error] [pid 66623:tid 66864] [client 172.182.200.96:14094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSAq9O5rbWdOArH04KKDgAAAWw"]
[Tue Aug 18 12:56:27.222706 2026] [security2:error] [pid 67073:tid 67270] [client 74.248.136.165:61429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/erty.php"] [unique_id "aoSAq_cmepr5_nHgLbNWDQAAAlU"]
[Tue Aug 18 12:56:27.244755 2026] [security2:error] [pid 66623:tid 66768] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSAq9O5rbWdOArH04KKDwAAAQw"]
[Tue Aug 18 12:56:27.246038 2026] [security2:error] [pid 67073:tid 67233] [client 68.155.154.236:16358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSAq_cmepr5_nHgLbNWEAAAAjA"]
[Tue Aug 18 12:56:27.252460 2026] [security2:error] [pid 67073:tid 67208] [client 20.250.13.23:19702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAq_cmepr5_nHgLbNWEQAAAhc"]
[Tue Aug 18 12:56:27.264593 2026] [security2:error] [pid 66623:tid 66890] [client 20.215.241.237:7239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAq9O5rbWdOArH04KKEAAAAYY"]
[Tue Aug 18 12:56:27.284776 2026] [security2:error] [pid 67073:tid 67224] [client 158.23.17.4:29458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/phpstatus.php"] [unique_id "aoSAq_cmepr5_nHgLbNWEgAAAic"]
[Tue Aug 18 12:56:27.294594 2026] [security2:error] [pid 67073:tid 67273] [client 20.171.51.14:61447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ep.php"] [unique_id "aoSAq_cmepr5_nHgLbNWFAAAAlg"]
[Tue Aug 18 12:56:27.295689 2026] [security2:error] [pid 67073:tid 67313] [client 20.163.43.14:4262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSAq_cmepr5_nHgLbNWFQAAAoA"]
[Tue Aug 18 12:56:27.318710 2026] [security2:error] [pid 66623:tid 66824] [client 132.196.61.152:60300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/nano.php"] [unique_id "aoSAq9O5rbWdOArH04KKEQAAAUQ"]
[Tue Aug 18 12:56:27.322762 2026] [security2:error] [pid 66623:tid 66816] [client 20.151.109.219:59761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/rf.php"] [unique_id "aoSAq9O5rbWdOArH04KKEgAAATw"]
[Tue Aug 18 12:56:27.325964 2026] [security2:error] [pid 67073:tid 67247] [client 74.248.18.37:30597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSAq_cmepr5_nHgLbNWFgAAAj4"]
[Tue Aug 18 12:56:27.333628 2026] [security2:error] [pid 67073:tid 67291] [client 157.20.138.62:61004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAq_cmepr5_nHgLbNWGAAAAmo"]
[Tue Aug 18 12:56:27.333707 2026] [security2:error] [pid 67073:tid 67291] [client 157.20.138.62:61004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAq_cmepr5_nHgLbNWGAAAAmo"]
[Tue Aug 18 12:56:27.362991 2026] [security2:error] [pid 67073:tid 67271] [client 158.158.74.177:16540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/red.php"] [unique_id "aoSAq_cmepr5_nHgLbNWGgAAAlY"]
[Tue Aug 18 12:56:27.417362 2026] [security2:error] [pid 66623:tid 66865] [client 20.104.85.180:18858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSAq9O5rbWdOArH04KKFQAAAW0"]
[Tue Aug 18 12:56:27.421052 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:27.421507 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:27.427104 2026] [security2:error] [pid 67073:tid 67241] [client 79.127.164.8:46156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/mails.bak"] [unique_id "aoSAq_cmepr5_nHgLbNWHQAAAjg"], referer: https://medihub.com.br/mails.bak
[Tue Aug 18 12:56:27.441194 2026] [security2:error] [pid 67073:tid 67232] [client 20.226.6.191:54905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/epinyins.php"] [unique_id "aoSAq_cmepr5_nHgLbNWHgAAAi8"]
[Tue Aug 18 12:56:27.441194 2026] [security2:error] [pid 66623:tid 66644] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSAq9O5rbWdOArH04KKFgABcgc"]
[Tue Aug 18 12:56:27.469827 2026] [security2:error] [pid 67073:tid 67266] [client 172.202.39.151:65224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSAq_cmepr5_nHgLbNWIAAAAlE"]
[Tue Aug 18 12:56:27.479952 2026] [autoindex:error] [pid 66623:tid 66885] [client 20.79.204.6:2223] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:27.494899 2026] [security2:error] [pid 67073:tid 67279] [client 132.196.30.78:22471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/404.php"] [unique_id "aoSAq_cmepr5_nHgLbNWIQAAAl4"]
[Tue Aug 18 12:56:27.530223 2026] [security2:error] [pid 66623:tid 66848] [client 74.248.130.103:25779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/key.php"] [unique_id "aoSAq9O5rbWdOArH04KKGAAAAVw"]
[Tue Aug 18 12:56:27.560388 2026] [security2:error] [pid 67073:tid 67276] [client 172.202.39.151:36860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/index/function.php"] [unique_id "aoSAq_cmepr5_nHgLbNWIwAAAls"]
[Tue Aug 18 12:56:27.614708 2026] [security2:error] [pid 66623:tid 66747] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSAq9O5rbWdOArH04KKGQABeG4"]
[Tue Aug 18 12:56:27.621427 2026] [security2:error] [pid 66623:tid 66862] [client 20.151.109.219:17594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/xynz1.php"] [unique_id "aoSAq9O5rbWdOArH04KKGgAAAWo"]
[Tue Aug 18 12:56:27.625904 2026] [security2:error] [pid 67073:tid 67274] [client 20.163.43.14:4197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAq_cmepr5_nHgLbNWKAAAAlk"]
[Tue Aug 18 12:56:27.659011 2026] [security2:error] [pid 67073:tid 67307] [client 20.186.30.159:13650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/sf.php"] [unique_id "aoSAq_cmepr5_nHgLbNWLAAAAno"]
[Tue Aug 18 12:56:27.678063 2026] [security2:error] [pid 67073:tid 67258] [client 213.202.253.4:57505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/delpaths.php"] [unique_id "aoSAq_cmepr5_nHgLbNWLwAAAkk"], referer: www.google.com
[Tue Aug 18 12:56:27.684621 2026] [security2:error] [pid 67073:tid 67297] [client 20.116.17.175:57469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/a.php"] [unique_id "aoSAq_cmepr5_nHgLbNWMAAAAnA"]
[Tue Aug 18 12:56:27.686342 2026] [security2:error] [pid 66623:tid 66843] [client 158.158.34.183:21780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/file5.php"] [unique_id "aoSAq9O5rbWdOArH04KKHAAAAVc"]
[Tue Aug 18 12:56:27.694987 2026] [autoindex:error] [pid 66623:tid 66800] [client 20.79.204.6:2223] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-content/uploads/2025/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:27.701122 2026] [security2:error] [pid 66623:tid 66836] [client 20.104.85.180:6976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSAq9O5rbWdOArH04KKHgAAAVA"]
[Tue Aug 18 12:56:27.729262 2026] [security2:error] [pid 67073:tid 67186] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.github/.env"] [unique_id "aoSAq_cmepr5_nHgLbNWMgACP24"]
[Tue Aug 18 12:56:27.736230 2026] [security2:error] [pid 67073:tid 67263] [client 68.155.154.236:16295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSAq_cmepr5_nHgLbNWNAAAAk4"]
[Tue Aug 18 12:56:27.741126 2026] [security2:error] [pid 67073:tid 67281] [client 20.215.241.237:43618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/admin.php"] [unique_id "aoSAq_cmepr5_nHgLbNWNQAAAmA"]
[Tue Aug 18 12:56:27.779673 2026] [security2:error] [pid 67073:tid 67267] [client 20.52.168.85:7750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/tool.php"] [unique_id "aoSAq_cmepr5_nHgLbNWOQAAAlI"]
[Tue Aug 18 12:56:27.779778 2026] [security2:error] [pid 67073:tid 67260] [client 172.202.39.151:55440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAq_cmepr5_nHgLbNWOAAAAks"]
[Tue Aug 18 12:56:27.784853 2026] [security2:error] [pid 66623:tid 66641] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/st.php"] [unique_id "aoSAq9O5rbWdOArH04KKHwABfgQ"]
[Tue Aug 18 12:56:27.804503 2026] [security2:error] [pid 67073:tid 67211] [client 149.34.210.141:53508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAq_cmepr5_nHgLbNWOwAAAho"]
[Tue Aug 18 12:56:27.849340 2026] [security2:error] [pid 67073:tid 67299] [client 20.29.77.16:27260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/phpprobe.php"] [unique_id "aoSAq_cmepr5_nHgLbNWPAAAAnI"]
[Tue Aug 18 12:56:27.898320 2026] [security2:error] [pid 66623:tid 66831] [client 20.79.204.6:2223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSAq9O5rbWdOArH04KKIAAAAUs"]
[Tue Aug 18 12:56:27.955827 2026] [security2:error] [pid 67073:tid 67311] [client 20.163.43.14:4219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/as.php"] [unique_id "aoSAq_cmepr5_nHgLbNWPwAAAn4"]
[Tue Aug 18 12:56:27.955966 2026] [security2:error] [pid 67073:tid 67212] [client 135.225.75.187:24642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ff1.php"] [unique_id "aoSAq_cmepr5_nHgLbNWQAAAAhs"]
[Tue Aug 18 12:56:27.960999 2026] [security2:error] [pid 66623:tid 66698] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSAq9O5rbWdOArH04KKIQABcz0"]
[Tue Aug 18 12:56:27.983557 2026] [security2:error] [pid 67073:tid 67284] [client 20.104.85.180:43537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAq_cmepr5_nHgLbNWQgAAAmM"]
[Tue Aug 18 12:56:27.986597 2026] [security2:error] [pid 67073:tid 67318] [client 20.226.6.191:54853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAq_cmepr5_nHgLbNWQwAAAoU"]
[Tue Aug 18 12:56:27.989697 2026] [security2:error] [pid 67073:tid 67309] [client 74.248.130.103:14421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/kir.php"] [unique_id "aoSAq_cmepr5_nHgLbNWRAAAAnw"]
[Tue Aug 18 12:56:28.016176 2026] [security2:error] [pid 66623:tid 66811] [client 20.151.109.219:17572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/vo.php"] [unique_id "aoSArNO5rbWdOArH04KKIwAAATc"]
[Tue Aug 18 12:56:28.022516 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:28.022838 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:28.057190 2026] [security2:error] [pid 67073:tid 67084] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArPcmepr5_nHgLbNWRwACMwg"]
[Tue Aug 18 12:56:28.057380 2026] [security2:error] [pid 67073:tid 67236] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArPcmepr5_nHgLbNWRwACMwg"]
[Tue Aug 18 12:56:28.066021 2026] [security2:error] [pid 67073:tid 67253] [client 132.196.30.78:20189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wk/index.php"] [unique_id "aoSArPcmepr5_nHgLbNWSAAAAkQ"]
[Tue Aug 18 12:56:28.072561 2026] [security2:error] [pid 67073:tid 67229] [client 20.226.56.190:2505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gc.php"] [unique_id "aoSArPcmepr5_nHgLbNWSwAAAiw"]
[Tue Aug 18 12:56:28.082015 2026] [security2:error] [pid 67073:tid 67211] [client 149.34.210.141:53508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAq_cmepr5_nHgLbNWOwAAAho"]
[Tue Aug 18 12:56:28.095396 2026] [security2:error] [pid 66623:tid 66872] [client 213.35.127.232:57668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSArNO5rbWdOArH04KKJQAAAXQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:28.118699 2026] [security2:error] [pid 66623:tid 66860] [client 158.23.17.4:11004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/del.php"] [unique_id "aoSArNO5rbWdOArH04KKJgAAAWg"]
[Tue Aug 18 12:56:28.136088 2026] [security2:error] [pid 66623:tid 66693] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-configs.php"] [unique_id "aoSArNO5rbWdOArH04KKJwABDzg"]
[Tue Aug 18 12:56:28.147012 2026] [security2:error] [pid 66623:tid 66863] [client 172.182.200.96:14197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSArNO5rbWdOArH04KKKAAAAWs"]
[Tue Aug 18 12:56:28.163577 2026] [security2:error] [pid 66623:tid 66845] [client 20.171.51.14:62481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/rf.php"] [unique_id "aoSArNO5rbWdOArH04KKKQAAAVk"]
[Tue Aug 18 12:56:28.190697 2026] [security2:error] [pid 67073:tid 67233] [client 104.209.144.33:29838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSArPcmepr5_nHgLbNWTwAAAjA"]
[Tue Aug 18 12:56:28.227660 2026] [security2:error] [pid 67073:tid 67287] [client 20.215.241.237:40495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/file52.php"] [unique_id "aoSArPcmepr5_nHgLbNWUwAAAmY"]
[Tue Aug 18 12:56:28.259130 2026] [security2:error] [pid 67073:tid 67224] [client 20.186.30.159:13637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/k.php"] [unique_id "aoSArPcmepr5_nHgLbNWVAAAAic"]
[Tue Aug 18 12:56:28.286318 2026] [security2:error] [pid 66623:tid 66849] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArNO5rbWdOArH04KKJAABXRU"]
[Tue Aug 18 12:56:28.292520 2026] [security2:error] [pid 67073:tid 67305] [client 158.158.74.177:2663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/release.php"] [unique_id "aoSArPcmepr5_nHgLbNWWQAAAng"]
[Tue Aug 18 12:56:28.294055 2026] [autoindex:error] [pid 66623:tid 66830] [client 172.202.39.151:65248] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/images/smilies/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:28.302829 2026] [security2:error] [pid 66623:tid 66844] [client 20.163.43.14:4310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSArNO5rbWdOArH04KKLQAAAVg"]
[Tue Aug 18 12:56:28.311155 2026] [security2:error] [pid 66623:tid 66656] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-post.php"] [unique_id "aoSArNO5rbWdOArH04KKLgABWhM"]
[Tue Aug 18 12:56:28.372685 2026] [security2:error] [pid 67073:tid 67312] [client 74.248.18.37:28107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/atomlib.php"] [unique_id "aoSArPcmepr5_nHgLbNWWwAAAn8"]
[Tue Aug 18 12:56:28.379616 2026] [security2:error] [pid 66623:tid 66873] [client 20.52.168.85:7862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/ws.php"] [unique_id "aoSArNO5rbWdOArH04KKLwAAAXU"]
[Tue Aug 18 12:56:28.379667 2026] [authz_core:error] [pid 67073:tid 67168] [remote 35.197.144.252:50706] AH01630: client denied by server configuration: /home3/adobankcom/public_html/.htpasswd
[Tue Aug 18 12:56:28.387438 2026] [authz_core:error] [pid 67073:tid 67183] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:28.387707 2026] [authz_core:error] [pid 67073:tid 67183] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:28.417688 2026] [security2:error] [pid 67073:tid 67320] [client 20.151.109.219:24879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/wu.php"] [unique_id "aoSArPcmepr5_nHgLbNWYQAAAoc"]
[Tue Aug 18 12:56:28.437040 2026] [security2:error] [pid 67073:tid 67310] [client 52.139.47.57:16673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/bs1.php"] [unique_id "aoSArPcmepr5_nHgLbNWYgAAAn0"]
[Tue Aug 18 12:56:28.458444 2026] [security2:error] [pid 67073:tid 67262] [client 74.248.130.103:15411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/nofile.php"] [unique_id "aoSArPcmepr5_nHgLbNWZQAAAk0"]
[Tue Aug 18 12:56:28.481816 2026] [security2:error] [pid 67073:tid 67145] [remote 129.121.123.168:56842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.123.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wrtech.com.br"] [uri "/wp-login.php"] [unique_id "aoSArPcmepr5_nHgLbNWZwACI0U"]
[Tue Aug 18 12:56:28.484038 2026] [security2:error] [pid 66623:tid 66653] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSArNO5rbWdOArH04KKMAABOxA"]
[Tue Aug 18 12:56:28.506161 2026] [security2:error] [pid 67073:tid 67313] [client 20.79.204.6:2187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSArPcmepr5_nHgLbNWaAAAAoA"]
[Tue Aug 18 12:56:28.576107 2026] [security2:error] [pid 67073:tid 67293] [client 20.100.169.31:7753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSArPcmepr5_nHgLbNWawAAAmw"]
[Tue Aug 18 12:56:28.584528 2026] [security2:error] [pid 67073:tid 67276] [client 68.155.154.236:16284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSArPcmepr5_nHgLbNWbAAAAls"]
[Tue Aug 18 12:56:28.598210 2026] [security2:error] [pid 66623:tid 66789] [client 172.202.39.151:65248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSArNO5rbWdOArH04KKMQAAASE"]
[Tue Aug 18 12:56:28.604491 2026] [autoindex:error] [pid 67073:tid 67285] [client 20.226.6.191:48377] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:28.613827 2026] [security2:error] [pid 67073:tid 67265] [client 20.226.6.191:48377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSArPcmepr5_nHgLbNWbgAAAlA"]
[Tue Aug 18 12:56:28.625924 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:28.626185 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:28.630766 2026] [security2:error] [pid 67073:tid 67329] [client 20.163.43.14:4209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSArPcmepr5_nHgLbNWcAAAApA"]
[Tue Aug 18 12:56:28.633035 2026] [security2:error] [pid 67073:tid 67214] [client 20.186.30.159:13607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/82.php"] [unique_id "aoSArPcmepr5_nHgLbNWcQAAAh0"]
[Tue Aug 18 12:56:28.639459 2026] [security2:error] [pid 67073:tid 67307] [client 20.116.17.175:11204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSArPcmepr5_nHgLbNWcgAAAno"]
[Tue Aug 18 12:56:28.656769 2026] [security2:error] [pid 66623:tid 66650] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSArNO5rbWdOArH04KKMwABDg0"]
[Tue Aug 18 12:56:28.661338 2026] [authz_core:error] [pid 67073:tid 67184] [remote 57.141.22.1:21702] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:28.661600 2026] [authz_core:error] [pid 67073:tid 67184] [remote 57.141.22.1:21702] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:28.671336 2026] [security2:error] [pid 67073:tid 67244] [client 20.215.241.237:57762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/geck.php"] [unique_id "aoSArPcmepr5_nHgLbNWdgAAAjs"]
[Tue Aug 18 12:56:28.699714 2026] [security2:error] [pid 66623:tid 66840] [client 20.171.51.14:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/xynz1.php"] [unique_id "aoSArNO5rbWdOArH04KKNAAAAVQ"]
[Tue Aug 18 12:56:28.724747 2026] [security2:error] [pid 67073:tid 67297] [client 20.151.109.219:21682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/de.php"] [unique_id "aoSArPcmepr5_nHgLbNWeAAAAnA"]
[Tue Aug 18 12:56:28.733136 2026] [security2:error] [pid 67073:tid 67097] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSArPcmepr5_nHgLbNWewACHxU"]
[Tue Aug 18 12:56:28.749966 2026] [security2:error] [pid 67073:tid 67250] [client 40.85.222.29:13305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSArPcmepr5_nHgLbNWfQAAAkE"]
[Tue Aug 18 12:56:28.804322 2026] [security2:error] [pid 67073:tid 67237] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/fs.php"] [unique_id "aoSArPcmepr5_nHgLbNWggAAAjQ"]
[Tue Aug 18 12:56:28.828562 2026] [security2:error] [pid 66623:tid 66750] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-2019.php"] [unique_id "aoSArNO5rbWdOArH04KKNQABJ3E"]
[Tue Aug 18 12:56:28.886801 2026] [security2:error] [pid 67073:tid 67132] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSArPcmepr5_nHgLbNWhwACHzg"]
[Tue Aug 18 12:56:28.908424 2026] [security2:error] [pid 66623:tid 66775] [client 178.153.171.161:40632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArNO5rbWdOArH04KKNgAAARM"]
[Tue Aug 18 12:56:28.908550 2026] [security2:error] [pid 66623:tid 66775] [client 178.153.171.161:40632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArNO5rbWdOArH04KKNgAAARM"]
[Tue Aug 18 12:56:28.924358 2026] [security2:error] [pid 67073:tid 67215] [client 74.248.136.165:61433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/mini.php"] [unique_id "aoSArPcmepr5_nHgLbNWigAAAh4"]
[Tue Aug 18 12:56:28.926026 2026] [authz_core:error] [pid 67073:tid 67107] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:28.926425 2026] [authz_core:error] [pid 67073:tid 67107] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:28.941441 2026] [security2:error] [pid 67073:tid 67228] [client 138.36.100.162:41830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArPcmepr5_nHgLbNWiwAAAis"]
[Tue Aug 18 12:56:28.941576 2026] [security2:error] [pid 67073:tid 67228] [client 138.36.100.162:41830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArPcmepr5_nHgLbNWiwAAAis"]
[Tue Aug 18 12:56:28.982951 2026] [security2:error] [pid 67073:tid 67219] [client 20.186.30.159:13672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/dex.php"] [unique_id "aoSArPcmepr5_nHgLbNWjAAAAiI"]
[Tue Aug 18 12:56:28.985463 2026] [security2:error] [pid 67073:tid 67317] [client 20.52.168.85:8047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSArPcmepr5_nHgLbNWjQAAAoQ"]
[Tue Aug 18 12:56:28.997797 2026] [security2:error] [pid 67073:tid 67130] [remote 162.214.96.231:51512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.capecodcleaningservice.com"] [uri "/wp-login.php"] [unique_id "aoSArPcmepr5_nHgLbNWjgACkjY"]
[Tue Aug 18 12:56:29.000370 2026] [security2:error] [pid 66623:tid 66704] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/cjfuns.php"] [unique_id "aoSArNO5rbWdOArH04KKOAABg0M"]
[Tue Aug 18 12:56:29.002438 2026] [security2:error] [pid 67073:tid 67316] [client 20.151.109.219:64979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/album.php"] [unique_id "aoSArfcmepr5_nHgLbNWjwAAAoM"]
[Tue Aug 18 12:56:29.019430 2026] [security2:error] [pid 67073:tid 67295] [client 20.163.43.14:4210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSArfcmepr5_nHgLbNWkQAAAm4"]
[Tue Aug 18 12:56:29.023839 2026] [security2:error] [pid 66623:tid 66880] [client 74.248.130.103:36819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/fling.php"] [unique_id "aoSArdO5rbWdOArH04KKOgAAAXw"]
[Tue Aug 18 12:56:29.074711 2026] [security2:error] [pid 66623:tid 66794] [client 158.158.74.177:16542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/reop3.php"] [unique_id "aoSArdO5rbWdOArH04KKOwAAASY"]
[Tue Aug 18 12:56:29.085578 2026] [security2:error] [pid 66623:tid 66813] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/rb.php"] [unique_id "aoSArdO5rbWdOArH04KKPAAAATk"]
[Tue Aug 18 12:56:29.114885 2026] [security2:error] [pid 67073:tid 67267] [client 213.35.127.232:57930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSArfcmepr5_nHgLbNWlgAAAlI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:29.118737 2026] [security2:error] [pid 66623:tid 66837] [client 40.85.222.29:13304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSArdO5rbWdOArH04KKPQAAAVE"]
[Tue Aug 18 12:56:29.129920 2026] [autoindex:error] [pid 67073:tid 67212] [client 20.79.204.6:2379] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:29.132518 2026] [security2:error] [pid 66623:tid 66796] [client 172.202.39.151:50232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/an.php"] [unique_id "aoSArdO5rbWdOArH04KKPgAAASg"]
[Tue Aug 18 12:56:29.155644 2026] [security2:error] [pid 67073:tid 67229] [client 20.215.241.237:57789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/biufile.php"] [unique_id "aoSArfcmepr5_nHgLbNWlwAAAiw"]
[Tue Aug 18 12:56:29.173655 2026] [security2:error] [pid 66623:tid 66689] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSArdO5rbWdOArH04KKPwABQDQ"]
[Tue Aug 18 12:56:29.180768 2026] [security2:error] [pid 67073:tid 67222] [client 20.226.56.190:3031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/uq.php"] [unique_id "aoSArfcmepr5_nHgLbNWmAAAAiU"]
[Tue Aug 18 12:56:29.206907 2026] [security2:error] [pid 67073:tid 67324] [client 132.196.61.152:60292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/.mopj.php"] [unique_id "aoSArfcmepr5_nHgLbNWmgAAAos"]
[Tue Aug 18 12:56:29.226401 2026] [security2:error] [pid 67073:tid 67270] [client 104.209.144.33:17269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSArfcmepr5_nHgLbNWnAAAAlU"]
[Tue Aug 18 12:56:29.238028 2026] [security2:error] [pid 67073:tid 67287] [client 158.23.17.4:9346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/moderator.php"] [unique_id "aoSArfcmepr5_nHgLbNWngAAAmY"]
[Tue Aug 18 12:56:29.259045 2026] [security2:error] [pid 67073:tid 67207] [client 132.196.30.78:19407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/about.php"] [unique_id "aoSArfcmepr5_nHgLbNWoAAAAhY"]
[Tue Aug 18 12:56:29.264228 2026] [security2:error] [pid 66623:tid 66888] [client 167.235.143.113:31918] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dadicamotors.com.br"] [uri "/index.php"] [unique_id "aoSArdO5rbWdOArH04KKQAAAAYQ"], referer: https://dadicamotors.com.br/
[Tue Aug 18 12:56:29.273227 2026] [security2:error] [pid 66623:tid 66776] [client 20.29.77.16:52771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/wp-title.php"] [unique_id "aoSArdO5rbWdOArH04KKQQAAARQ"]
[Tue Aug 18 12:56:29.303897 2026] [security2:error] [pid 67073:tid 67112] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/id_rsa"] [unique_id "aoSArfcmepr5_nHgLbNWowACPiQ"]
[Tue Aug 18 12:56:29.322028 2026] [security2:error] [pid 67073:tid 67291] [client 20.151.109.219:59739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kv.php"] [unique_id "aoSArfcmepr5_nHgLbNWpAAAAmo"]
[Tue Aug 18 12:56:29.326582 2026] [security2:error] [pid 67073:tid 67271] [client 20.171.51.14:33681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/vo.php"] [unique_id "aoSArfcmepr5_nHgLbNWpQAAAlY"]
[Tue Aug 18 12:56:29.341127 2026] [security2:error] [pid 67073:tid 67308] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/37.php"] [unique_id "aoSArfcmepr5_nHgLbNWqwAAAns"]
[Tue Aug 18 12:56:29.341368 2026] [security2:error] [pid 67073:tid 67140] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/id_dsa"] [unique_id "aoSArfcmepr5_nHgLbNWqgACPkA"]
[Tue Aug 18 12:56:29.344240 2026] [security2:error] [pid 66623:tid 66753] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSArdO5rbWdOArH04KKQgABTHQ"]
[Tue Aug 18 12:56:29.346173 2026] [autoindex:error] [pid 67073:tid 67251] [client 20.79.204.6:2379] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:29.352715 2026] [security2:error] [pid 67073:tid 67320] [client 20.163.43.14:4187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSArfcmepr5_nHgLbNWrAAAAoc"]
[Tue Aug 18 12:56:29.420111 2026] [security2:error] [pid 66623:tid 66780] [client 20.116.17.175:11237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/99.php"] [unique_id "aoSArdO5rbWdOArH04KKQwAAARg"]
[Tue Aug 18 12:56:29.432202 2026] [security2:error] [pid 66623:tid 66785] [client 172.182.200.96:14137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSArdO5rbWdOArH04KKRAAAAR0"]
[Tue Aug 18 12:56:29.454599 2026] [security2:error] [pid 67073:tid 67275] [client 20.226.6.191:60608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSArfcmepr5_nHgLbNWsQAAAlo"]
[Tue Aug 18 12:56:29.460236 2026] [security2:error] [pid 67073:tid 67279] [client 20.186.30.159:8423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/puc.php"] [unique_id "aoSArfcmepr5_nHgLbNWsgAAAl4"]
[Tue Aug 18 12:56:29.465976 2026] [security2:error] [pid 67073:tid 67264] [client 172.202.39.151:28977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/edit.php"] [unique_id "aoSArfcmepr5_nHgLbNWswAAAk8"]
[Tue Aug 18 12:56:29.475183 2026] [security2:error] [pid 67073:tid 67235] [client 74.248.130.103:38709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/zoo1.php"] [unique_id "aoSArfcmepr5_nHgLbNWtQAAAjI"]
[Tue Aug 18 12:56:29.479776 2026] [security2:error] [pid 67073:tid 67274] [client 40.85.222.29:13190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/weozh.php"] [unique_id "aoSArfcmepr5_nHgLbNWtgAAAlk"]
[Tue Aug 18 12:56:29.515368 2026] [security2:error] [pid 66623:tid 66742] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/import.php"] [unique_id "aoSArdO5rbWdOArH04KKRQABL2k"]
[Tue Aug 18 12:56:29.528400 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:29.528653 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:29.551653 2026] [security2:error] [pid 67073:tid 67304] [client 20.79.204.6:2379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSArfcmepr5_nHgLbNWugAAAnc"]
[Tue Aug 18 12:56:29.589964 2026] [security2:error] [pid 67073:tid 67321] [client 20.52.168.85:8012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSArfcmepr5_nHgLbNWvAAAAog"]
[Tue Aug 18 12:56:29.597887 2026] [security2:error] [pid 67073:tid 67250] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/md.php"] [unique_id "aoSArfcmepr5_nHgLbNWvQAAAkE"]
[Tue Aug 18 12:56:29.604882 2026] [security2:error] [pid 67073:tid 67319] [client 20.215.241.237:40506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/dejavu.php"] [unique_id "aoSArfcmepr5_nHgLbNWvgAAAoY"]
[Tue Aug 18 12:56:29.621505 2026] [security2:error] [pid 67073:tid 67226] [client 20.151.109.219:21666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/z.php"] [unique_id "aoSArfcmepr5_nHgLbNWvwAAAik"]
[Tue Aug 18 12:56:29.668334 2026] [security2:error] [pid 67073:tid 67162] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/key.pem"] [unique_id "aoSArfcmepr5_nHgLbNWwQACVFY"]
[Tue Aug 18 12:56:29.677048 2026] [security2:error] [pid 67073:tid 67281] [client 20.171.51.14:65143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/wu.php"] [unique_id "aoSArfcmepr5_nHgLbNWxQAAAmA"]
[Tue Aug 18 12:56:29.682657 2026] [security2:error] [pid 66623:tid 66858] [client 74.248.18.37:35026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/rip.php"] [unique_id "aoSArdO5rbWdOArH04KKRgAAAWY"]
[Tue Aug 18 12:56:29.688737 2026] [security2:error] [pid 66623:tid 66662] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/cropper.php"] [unique_id "aoSArdO5rbWdOArH04KKRwABPxk"]
[Tue Aug 18 12:56:29.708389 2026] [security2:error] [pid 67073:tid 67233] [client 20.100.169.31:39990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/term.php"] [unique_id "aoSArfcmepr5_nHgLbNWxgAAAjA"]
[Tue Aug 18 12:56:29.711895 2026] [security2:error] [pid 66623:tid 66774] [client 20.100.169.31:17509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/222.php"] [unique_id "aoSArdO5rbWdOArH04KKSAAAARI"]
[Tue Aug 18 12:56:29.750991 2026] [security2:error] [pid 67073:tid 67311] [client 104.209.144.33:33696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSArfcmepr5_nHgLbNWyAAAAn4"]
[Tue Aug 18 12:56:29.768264 2026] [autoindex:error] [pid 67073:tid 67289] [client 172.202.39.151:55443] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:29.775828 2026] [security2:error] [pid 67073:tid 67228] [client 52.173.121.69:24966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSArfcmepr5_nHgLbNWywAAAis"]
[Tue Aug 18 12:56:29.813796 2026] [security2:error] [pid 67073:tid 67284] [client 40.85.222.29:13184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/rymmm.php"] [unique_id "aoSArfcmepr5_nHgLbNWzAAAAmM"]
[Tue Aug 18 12:56:29.826711 2026] [security2:error] [pid 67073:tid 67108] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/privatekey.key"] [unique_id "aoSArfcmepr5_nHgLbNWzQACVCA"]
[Tue Aug 18 12:56:29.850303 2026] [security2:error] [pid 67073:tid 67315] [client 20.163.43.14:4118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSArfcmepr5_nHgLbNWzgAAAoI"]
[Tue Aug 18 12:56:29.855626 2026] [security2:error] [pid 67073:tid 67260] [client 132.196.30.78:22465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/term.php"] [unique_id "aoSArfcmepr5_nHgLbNWzwAAAks"]
[Tue Aug 18 12:56:29.859162 2026] [security2:error] [pid 66623:tid 66721] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSArdO5rbWdOArH04KKSQABY1Q"]
[Tue Aug 18 12:56:29.861136 2026] [security2:error] [pid 67073:tid 67314] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/iy.php"] [unique_id "aoSArfcmepr5_nHgLbNW0AAAAoE"]
[Tue Aug 18 12:56:29.903535 2026] [security2:error] [pid 67073:tid 67240] [client 20.151.109.219:53233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/xg.php"] [unique_id "aoSArfcmepr5_nHgLbNW0gAAAjc"]
[Tue Aug 18 12:56:29.941565 2026] [security2:error] [pid 67073:tid 67280] [client 135.225.75.187:29707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/guk.php"] [unique_id "aoSArfcmepr5_nHgLbNW1gAAAl8"]
[Tue Aug 18 12:56:29.950242 2026] [security2:error] [pid 67073:tid 67232] [client 160.120.140.123:61855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArfcmepr5_nHgLbNW1wAAAi8"]
[Tue Aug 18 12:56:29.950381 2026] [security2:error] [pid 67073:tid 67232] [client 160.120.140.123:61855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArfcmepr5_nHgLbNW1wAAAi8"]
[Tue Aug 18 12:56:29.957697 2026] [security2:error] [pid 67073:tid 67296] [client 158.23.17.4:38903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/infoinfo.php"] [unique_id "aoSArfcmepr5_nHgLbNW2QAAAm8"]
[Tue Aug 18 12:56:29.959501 2026] [security2:error] [pid 67073:tid 67254] [client 85.154.68.202:50898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSArfcmepr5_nHgLbNW2AAAAkU"]
[Tue Aug 18 12:56:29.959639 2026] [security2:error] [pid 67073:tid 67254] [client 85.154.68.202:50898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSArfcmepr5_nHgLbNW2AAAAkU"]
[Tue Aug 18 12:56:29.976808 2026] [security2:error] [pid 67073:tid 67322] [client 158.158.34.183:55817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/new.php"] [unique_id "aoSArfcmepr5_nHgLbNW2wAAAok"]
[Tue Aug 18 12:56:29.988567 2026] [security2:error] [pid 67073:tid 67246] [client 74.248.130.103:36829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/zoo2.php"] [unique_id "aoSArfcmepr5_nHgLbNW3AAAAj0"]
[Tue Aug 18 12:56:29.997630 2026] [security2:error] [pid 66623:tid 66854] [client 20.186.30.159:13584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/inso.php"] [unique_id "aoSArdO5rbWdOArH04KKSgAAAWI"]
[Tue Aug 18 12:56:30.030432 2026] [security2:error] [pid 66623:tid 66691] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSArtO5rbWdOArH04KKSwABbjY"]
[Tue Aug 18 12:56:30.031929 2026] [security2:error] [pid 67073:tid 67210] [client 52.139.47.57:25710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/colors/blue/about.php"] [unique_id "aoSArvcmepr5_nHgLbNW3QAAAhk"]
[Tue Aug 18 12:56:30.054616 2026] [security2:error] [pid 67073:tid 67208] [client 172.202.39.151:55443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/404.php"] [unique_id "aoSArvcmepr5_nHgLbNW4gAAAhc"]
[Tue Aug 18 12:56:30.062895 2026] [security2:error] [pid 67073:tid 67258] [client 20.215.241.237:54933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/aaf.php"] [unique_id "aoSArvcmepr5_nHgLbNW4wAAAkk"]
[Tue Aug 18 12:56:30.121961 2026] [security2:error] [pid 66623:tid 66808] [client 20.226.6.191:45878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp.php"] [unique_id "aoSArtO5rbWdOArH04KKTAAAATQ"]
[Tue Aug 18 12:56:30.130709 2026] [security2:error] [pid 67073:tid 67295] [client 213.35.127.232:58136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSArvcmepr5_nHgLbNW5QAAAm4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:30.139686 2026] [authz_core:error] [pid 67073:tid 67201] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:30.139955 2026] [authz_core:error] [pid 67073:tid 67201] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:30.140123 2026] [security2:error] [pid 66623:tid 66778] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/og.php"] [unique_id "aoSArtO5rbWdOArH04KKTQAAARY"]
[Tue Aug 18 12:56:30.141255 2026] [security2:error] [pid 67073:tid 67278] [client 40.85.222.29:13298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/lddxs.php"] [unique_id "aoSArvcmepr5_nHgLbNW5wAAAl0"]
[Tue Aug 18 12:56:30.160687 2026] [security2:error] [pid 67073:tid 67218] [client 20.79.204.6:2222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSArvcmepr5_nHgLbNW6QAAAiE"]
[Tue Aug 18 12:56:30.167138 2026] [security2:error] [pid 67073:tid 67273] [client 156.59.198.136:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "buscacep.linkasites.com.br"] [uri "/livrocep/sp/sao-paulo/jardim-novo-santo-amaro/img/rua-caminho-particular-jardim-novo-santo-amaro-sao-paulo-sp.webp"] [unique_id "aoSArvcmepr5_nHgLbNW6wAAAlg"], referer: https://www.icep.com.br/livrocep/sp/sao-paulo/jardim-novo-santo-amaro/rua-caminho-particular-cep-05820232/
[Tue Aug 18 12:56:30.172171 2026] [security2:error] [pid 67073:tid 67291] [client 20.171.51.14:59266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/de.php"] [unique_id "aoSArvcmepr5_nHgLbNW7QAAAmo"]
[Tue Aug 18 12:56:30.181517 2026] [security2:error] [pid 67073:tid 67277] [client 20.163.43.14:4043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/an.php"] [unique_id "aoSArvcmepr5_nHgLbNW7gAAAlw"]
[Tue Aug 18 12:56:30.197317 2026] [security2:error] [pid 67073:tid 67299] [client 20.250.13.23:19686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/gecko-new.php"] [unique_id "aoSArvcmepr5_nHgLbNW8AAAAnI"]
[Tue Aug 18 12:56:30.199367 2026] [security2:error] [pid 66623:tid 66766] [client 20.52.168.85:8003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-content/file.php"] [unique_id "aoSArtO5rbWdOArH04KKTgAAAQo"]
[Tue Aug 18 12:56:30.199890 2026] [security2:error] [pid 67073:tid 67320] [client 20.151.109.219:12920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/nd.php"] [unique_id "aoSArvcmepr5_nHgLbNW8QAAAoc"]
[Tue Aug 18 12:56:30.201554 2026] [security2:error] [pid 66623:tid 66695] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/goat.php"] [unique_id "aoSArtO5rbWdOArH04KKTwABOjo"]
[Tue Aug 18 12:56:30.279329 2026] [security2:error] [pid 67073:tid 67207] [client 158.158.74.177:16575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/robots.php"] [unique_id "aoSArvcmepr5_nHgLbNW9QAAAhY"]
[Tue Aug 18 12:56:30.377764 2026] [security2:error] [pid 66623:tid 66798] [client 20.186.30.159:13590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/aa.php"] [unique_id "aoSArtO5rbWdOArH04KKUQAAASo"]
[Tue Aug 18 12:56:30.395760 2026] [security2:error] [pid 67073:tid 67235] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/lp.php"] [unique_id "aoSArvcmepr5_nHgLbNW-QAAAjI"]
[Tue Aug 18 12:56:30.415943 2026] [security2:error] [pid 67073:tid 67274] [client 74.248.136.165:46790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/sid3.php"] [unique_id "aoSArvcmepr5_nHgLbNW-gAAAlk"]
[Tue Aug 18 12:56:30.424000 2026] [security2:error] [pid 67073:tid 67329] [client 172.202.39.151:48018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/epinyins.php"] [unique_id "aoSArvcmepr5_nHgLbNW-wAAApA"]
[Tue Aug 18 12:56:30.430820 2026] [security2:error] [pid 67073:tid 67214] [client 74.248.130.103:36845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/org.php"] [unique_id "aoSArvcmepr5_nHgLbNW_QAAAh0"]
[Tue Aug 18 12:56:30.433641 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:30.433913 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:30.440186 2026] [security2:error] [pid 67073:tid 67241] [client 132.196.30.78:19397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSArvcmepr5_nHgLbNW_gAAAjg"]
[Tue Aug 18 12:56:30.455668 2026] [security2:error] [pid 67073:tid 67242] [client 40.85.222.29:13276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/zjggu.php"] [unique_id "aoSArvcmepr5_nHgLbNXAAAAAjk"]
[Tue Aug 18 12:56:30.471981 2026] [security2:error] [pid 66623:tid 66768] [client 172.182.200.96:14127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSArtO5rbWdOArH04KKUgAAAQw"]
[Tue Aug 18 12:56:30.500018 2026] [security2:error] [pid 67073:tid 67139] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSArvcmepr5_nHgLbNXAgACQT8"]
[Tue Aug 18 12:56:30.511775 2026] [security2:error] [pid 67073:tid 67234] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArvcmepr5_nHgLbNXAQACMTo"]
[Tue Aug 18 12:56:30.526856 2026] [security2:error] [pid 67073:tid 67259] [client 20.151.109.219:59743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ri.php"] [unique_id "aoSArvcmepr5_nHgLbNXBQAAAko"]
[Tue Aug 18 12:56:30.534750 2026] [security2:error] [pid 66623:tid 66772] [client 20.215.241.237:54951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSArtO5rbWdOArH04KKUwAAARA"]
[Tue Aug 18 12:56:30.587117 2026] [security2:error] [pid 66623:tid 66696] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/Session.php"] [unique_id "aoSArtO5rbWdOArH04KKVAABJDs"]
[Tue Aug 18 12:56:30.605603 2026] [security2:error] [pid 66623:tid 66870] [client 20.171.51.14:58860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/album.php"] [unique_id "aoSArtO5rbWdOArH04KKVQAAAXI"]
[Tue Aug 18 12:56:30.687286 2026] [security2:error] [pid 66623:tid 66885] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ey.php"] [unique_id "aoSArtO5rbWdOArH04KKVwAAAYE"]
[Tue Aug 18 12:56:30.693297 2026] [security2:error] [pid 67073:tid 67233] [client 201.32.74.208:56356] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "image/bmp"] [severity "WARNING"] [hostname "pensamentosimperfeitos.com.br"] [uri "/wp-json/wp/v2/media"] [unique_id "aoSArvcmepr5_nHgLbNXCAAAAjA"]
[Tue Aug 18 12:56:30.695252 2026] [security2:error] [pid 67073:tid 67230] [client 20.163.43.14:4224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/404.php"] [unique_id "aoSArvcmepr5_nHgLbNXCQAAAi0"]
[Tue Aug 18 12:56:30.736448 2026] [security2:error] [pid 67073:tid 67253] [client 172.202.39.151:50208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-login.php"] [unique_id "aoSArvcmepr5_nHgLbNXDAAAAkQ"]
[Tue Aug 18 12:56:30.738871 2026] [authz_core:error] [pid 67073:tid 67099] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:30.739323 2026] [authz_core:error] [pid 67073:tid 67099] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:30.748434 2026] [security2:error] [pid 67073:tid 67205] [client 20.116.17.175:11219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/yup.php"] [unique_id "aoSArvcmepr5_nHgLbNXDgAAAhQ"]
[Tue Aug 18 12:56:30.758521 2026] [security2:error] [pid 66623:tid 66649] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSArtO5rbWdOArH04KKWAABRgw"]
[Tue Aug 18 12:56:30.759577 2026] [security2:error] [pid 66623:tid 66809] [client 20.215.241.237:58900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/nox.php"] [unique_id "aoSArtO5rbWdOArH04KKWQAAATU"]
[Tue Aug 18 12:56:30.783588 2026] [autoindex:error] [pid 66623:tid 66865] [client 20.79.204.6:2389] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/Requests/src/Cookie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:30.799692 2026] [security2:error] [pid 66623:tid 66777] [client 20.52.168.85:7835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSArtO5rbWdOArH04KKWwAAARU"]
[Tue Aug 18 12:56:30.823048 2026] [security2:error] [pid 67073:tid 67276] [client 74.248.18.37:45886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/p.php"] [unique_id "aoSArvcmepr5_nHgLbNXEAAAAls"]
[Tue Aug 18 12:56:30.826163 2026] [security2:error] [pid 67073:tid 67257] [client 20.151.109.219:21642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/tp.php"] [unique_id "aoSArvcmepr5_nHgLbNXEQAAAkg"]
[Tue Aug 18 12:56:30.847638 2026] [security2:error] [pid 67073:tid 67219] [client 20.226.6.191:60625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/function/function.php"] [unique_id "aoSArvcmepr5_nHgLbNXEwAAAiI"]
[Tue Aug 18 12:56:30.851736 2026] [security2:error] [pid 66623:tid 66720] [remote 46.62.208.238:53274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.208.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/wp-login.php"] [unique_id "aoSArtO5rbWdOArH04KKXQABUlM"]
[Tue Aug 18 12:56:30.869809 2026] [security2:error] [pid 67073:tid 67284] [client 40.85.222.29:13242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/dlvqo.php"] [unique_id "aoSArvcmepr5_nHgLbNXFAAAAmM"]
[Tue Aug 18 12:56:30.872544 2026] [security2:error] [pid 67073:tid 67318] [client 74.248.130.103:14460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/imageskir.php"] [unique_id "aoSArvcmepr5_nHgLbNXFQAAAoU"]
[Tue Aug 18 12:56:30.920367 2026] [security2:error] [pid 67073:tid 67240] [client 20.186.30.159:13676] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/1.php"] [unique_id "aoSArvcmepr5_nHgLbNXIAAAAjc"]
[Tue Aug 18 12:56:30.920455 2026] [security2:error] [pid 67073:tid 67240] [client 20.186.30.159:13676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/1.php"] [unique_id "aoSArvcmepr5_nHgLbNXIAAAAjc"]
[Tue Aug 18 12:56:30.929154 2026] [security2:error] [pid 66623:tid 66667] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/abcd.php"] [unique_id "aoSArtO5rbWdOArH04KKYAABfh4"]
[Tue Aug 18 12:56:30.934160 2026] [security2:error] [pid 66623:tid 66856] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/lv.php"] [unique_id "aoSArtO5rbWdOArH04KKYQAAAWQ"]
[Tue Aug 18 12:56:30.957282 2026] [security2:error] [pid 66623:tid 66848] [client 79.127.164.8:46210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/mails.sql"] [unique_id "aoSArtO5rbWdOArH04KKYgAAAVw"], referer: https://medihub.com.br/mails.sql
[Tue Aug 18 12:56:30.983880 2026] [security2:error] [pid 66623:tid 66871] [client 20.79.204.6:2389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSArtO5rbWdOArH04KKZAAAAXM"]
[Tue Aug 18 12:56:31.026943 2026] [security2:error] [pid 66623:tid 66811] [client 20.163.43.14:4185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-login.php"] [unique_id "aoSAr9O5rbWdOArH04KKZQAAATc"]
[Tue Aug 18 12:56:31.044915 2026] [security2:error] [pid 67073:tid 67239] [client 20.226.56.190:47133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/32.php"] [unique_id "aoSAr_cmepr5_nHgLbNXIwAAAjY"]
[Tue Aug 18 12:56:31.073728 2026] [security2:error] [pid 67073:tid 67212] [client 74.7.241.135:59038] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gram.goptur.app.br"] [uri "/robots.txt"] [unique_id "aoSAr_cmepr5_nHgLbNXJQACGyU"]
[Tue Aug 18 12:56:31.094453 2026] [security2:error] [pid 67073:tid 67278] [client 68.155.154.236:16229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSAr_cmepr5_nHgLbNXJgAAAl0"]
[Tue Aug 18 12:56:31.106394 2026] [security2:error] [pid 67073:tid 67268] [client 20.151.109.219:32985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/zj.php"] [unique_id "aoSAr_cmepr5_nHgLbNXJwAAAlM"]
[Tue Aug 18 12:56:31.108984 2026] [security2:error] [pid 66623:tid 66716] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/kj.php"] [unique_id "aoSAr9O5rbWdOArH04KKZgABQ08"]
[Tue Aug 18 12:56:31.147173 2026] [security2:error] [pid 67073:tid 67271] [client 40.85.222.29:13296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/pkmoj.php"] [unique_id "aoSAr_cmepr5_nHgLbNXKgAAAlY"]
[Tue Aug 18 12:56:31.155399 2026] [security2:error] [pid 66623:tid 66862] [client 213.35.127.232:58390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAr9O5rbWdOArH04KKaAAAAWo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:31.170808 2026] [security2:error] [pid 67073:tid 67277] [client 20.215.241.237:44043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/155.php"] [unique_id "aoSAr_cmepr5_nHgLbNXKwAAAlw"]
[Tue Aug 18 12:56:31.170823 2026] [security2:error] [pid 67073:tid 67328] [client 20.65.98.162:8456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/19.php"] [unique_id "aoSAr_cmepr5_nHgLbNXLAAAAo8"]
[Tue Aug 18 12:56:31.181279 2026] [security2:error] [pid 67073:tid 67299] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/51.php"] [unique_id "aoSAr_cmepr5_nHgLbNXLgAAAnI"]
[Tue Aug 18 12:56:31.212100 2026] [security2:error] [pid 67073:tid 67313] [client 20.186.30.159:13574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/img.php"] [unique_id "aoSAr_cmepr5_nHgLbNXLwAAAoA"]
[Tue Aug 18 12:56:31.214109 2026] [security2:error] [pid 67073:tid 67290] [client 158.158.74.177:16515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/root.php"] [unique_id "aoSAr_cmepr5_nHgLbNXMAAAAmk"]
[Tue Aug 18 12:56:31.228909 2026] [security2:error] [pid 67073:tid 67165] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.hermes/.env"] [unique_id "aoSAr_cmepr5_nHgLbNXNAACjVk"]
[Tue Aug 18 12:56:31.233026 2026] [security2:error] [pid 67073:tid 67275] [client 158.23.17.4:33509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/c99shell.php"] [unique_id "aoSAr_cmepr5_nHgLbNXNQAAAlo"]
[Tue Aug 18 12:56:31.239868 2026] [security2:error] [pid 67073:tid 67292] [client 20.171.51.14:58816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/kv.php"] [unique_id "aoSAr_cmepr5_nHgLbNXNgAAAms"]
[Tue Aug 18 12:56:31.281799 2026] [security2:error] [pid 67073:tid 67186] [remote 135.236.141.8:20749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.141.236.135.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ondaparaty.com"] [uri "/wp-login.php"] [unique_id "aoSAr_cmepr5_nHgLbNXOgACeW4"]
[Tue Aug 18 12:56:31.282892 2026] [security2:error] [pid 66623:tid 66648] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/languages.php"] [unique_id "aoSAr9O5rbWdOArH04KKaQABWQs"]
[Tue Aug 18 12:56:31.310287 2026] [security2:error] [pid 67073:tid 67214] [client 132.196.61.152:34756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/bengi.php"] [unique_id "aoSAr_cmepr5_nHgLbNXOwAAAh0"]
[Tue Aug 18 12:56:31.311927 2026] [security2:error] [pid 66623:tid 66890] [client 157.51.166.53:61788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAr9O5rbWdOArH04KKagAAAYY"]
[Tue Aug 18 12:56:31.315660 2026] [security2:error] [pid 67073:tid 67241] [client 20.226.56.190:20405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/73.php"] [unique_id "aoSAr_cmepr5_nHgLbNXPAAAAjg"]
[Tue Aug 18 12:56:31.316205 2026] [security2:error] [pid 66623:tid 66890] [client 157.51.166.53:61788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAr9O5rbWdOArH04KKagAAAYY"]
[Tue Aug 18 12:56:31.322614 2026] [security2:error] [pid 67073:tid 67242] [client 20.215.241.237:60908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/aa.php"] [unique_id "aoSAr_cmepr5_nHgLbNXPgAAAjk"]
[Tue Aug 18 12:56:31.322613 2026] [authz_core:error] [pid 67073:tid 67153] [remote 57.141.22.101:47246] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:31.322942 2026] [authz_core:error] [pid 67073:tid 67153] [remote 57.141.22.101:47246] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:31.326884 2026] [security2:error] [pid 67073:tid 67304] [client 74.248.130.103:25780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/indexo.php"] [unique_id "aoSAr_cmepr5_nHgLbNXPwAAAnc"]
[Tue Aug 18 12:56:31.328057 2026] [security2:error] [pid 67073:tid 67225] [client 158.158.34.183:61489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/fm.php"] [unique_id "aoSAr_cmepr5_nHgLbNXQAAAAig"]
[Tue Aug 18 12:56:31.337398 2026] [security2:error] [pid 67073:tid 67331] [client 132.196.30.78:19410] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/1.php"] [unique_id "aoSAr_cmepr5_nHgLbNXQwAAApI"]
[Tue Aug 18 12:56:31.337502 2026] [security2:error] [pid 67073:tid 67331] [client 132.196.30.78:19410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/1.php"] [unique_id "aoSAr_cmepr5_nHgLbNXQwAAApI"]
[Tue Aug 18 12:56:31.345826 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:31.346263 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:31.362478 2026] [security2:error] [pid 67073:tid 67327] [client 20.163.43.14:4184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAr_cmepr5_nHgLbNXRAAAAo4"]
[Tue Aug 18 12:56:31.387430 2026] [security2:error] [pid 67073:tid 67325] [client 172.202.39.151:65255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAr_cmepr5_nHgLbNXRQAAAow"]
[Tue Aug 18 12:56:31.403328 2026] [security2:error] [pid 67073:tid 67312] [client 20.52.168.85:7808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/news.php"] [unique_id "aoSAr_cmepr5_nHgLbNXRwAAAn8"]
[Tue Aug 18 12:56:31.419046 2026] [security2:error] [pid 67073:tid 67243] [client 20.151.109.219:64626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/x.php"] [unique_id "aoSAr_cmepr5_nHgLbNXSQAAAjo"]
[Tue Aug 18 12:56:31.422578 2026] [security2:error] [pid 67073:tid 67237] [client 40.85.222.29:13287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/kopyw.php"] [unique_id "aoSAr_cmepr5_nHgLbNXSgAAAjQ"]
[Tue Aug 18 12:56:31.445792 2026] [security2:error] [pid 67073:tid 67249] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ew.php"] [unique_id "aoSAr_cmepr5_nHgLbNXSwAAAkA"]
[Tue Aug 18 12:56:31.458306 2026] [security2:error] [pid 67073:tid 67262] [client 172.202.39.151:12697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAr_cmepr5_nHgLbNXTAAAAk0"]
[Tue Aug 18 12:56:31.540953 2026] [security2:error] [pid 67073:tid 67316] [client 135.225.75.187:25605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-the.php"] [unique_id "aoSAr_cmepr5_nHgLbNXTgAAAoM"]
[Tue Aug 18 12:56:31.556357 2026] [security2:error] [pid 67073:tid 67229] [client 52.139.47.57:47639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/con7.php"] [unique_id "aoSAr_cmepr5_nHgLbNXTwAAAiw"]
[Tue Aug 18 12:56:31.616045 2026] [security2:error] [pid 67073:tid 67232] [client 20.186.30.159:13635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/222.php"] [unique_id "aoSAr_cmepr5_nHgLbNXUgAAAi8"]
[Tue Aug 18 12:56:31.665736 2026] [security2:error] [pid 66623:tid 66844] [client 20.171.51.14:29213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/z.php"] [unique_id "aoSAr9O5rbWdOArH04KKdAAAAVg"]
[Tue Aug 18 12:56:31.685537 2026] [security2:error] [pid 66623:tid 66846] [client 20.215.241.237:43600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/ops.php"] [unique_id "aoSAr9O5rbWdOArH04KKdgAAAVo"]
[Tue Aug 18 12:56:31.699466 2026] [security2:error] [pid 66623:tid 66869] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/pqr.php"] [unique_id "aoSAr9O5rbWdOArH04KKeAAAAXE"]
[Tue Aug 18 12:56:31.700453 2026] [security2:error] [pid 67073:tid 67239] [client 40.85.222.29:13212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/zznmg.php"] [unique_id "aoSAr_cmepr5_nHgLbNXVgAAAjY"]
[Tue Aug 18 12:56:31.716390 2026] [security2:error] [pid 67073:tid 67246] [client 20.215.241.237:19006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/akismet.php"] [unique_id "aoSAr_cmepr5_nHgLbNXVwAAAj0"]
[Tue Aug 18 12:56:31.720187 2026] [autoindex:error] [pid 67073:tid 67253] [client 20.79.204.6:2382] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:31.746999 2026] [security2:error] [pid 66623:tid 66867] [client 20.151.109.219:51675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/yn.php"] [unique_id "aoSAr9O5rbWdOArH04KKeQAAAW8"]
[Tue Aug 18 12:56:31.758816 2026] [security2:error] [pid 66623:tid 66801] [client 104.209.144.33:35852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSAr9O5rbWdOArH04KKegAAAS0"]
[Tue Aug 18 12:56:31.806185 2026] [security2:error] [pid 67073:tid 67268] [client 20.226.56.190:2550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ib.php"] [unique_id "aoSAr_cmepr5_nHgLbNXXgAAAlM"]
[Tue Aug 18 12:56:31.857506 2026] [security2:error] [pid 67073:tid 67151] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "adopagamentos.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSAr_cmepr5_nHgLbNXXwACYUs"]
[Tue Aug 18 12:56:31.882317 2026] [autoindex:error] [pid 67073:tid 67291] [client 172.202.39.151:48201] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:31.882411 2026] [security2:error] [pid 67073:tid 67271] [client 74.248.130.103:38656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSAr_cmepr5_nHgLbNXYgAAAlY"]
[Tue Aug 18 12:56:31.920593 2026] [security2:error] [pid 67073:tid 67299] [client 20.79.204.6:2382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSAr_cmepr5_nHgLbNXaAAAAnI"]
[Tue Aug 18 12:56:31.936224 2026] [security2:error] [pid 66623:tid 66697] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/nw.php"] [unique_id "aoSAr9O5rbWdOArH04KKgAABEzw"]
[Tue Aug 18 12:56:31.942916 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:31.943175 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:31.945169 2026] [security2:error] [pid 67073:tid 67209] [client 74.248.136.165:34196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/moon.php"] [unique_id "aoSAr_cmepr5_nHgLbNXawAAAhg"]
[Tue Aug 18 12:56:31.957237 2026] [security2:error] [pid 66623:tid 66790] [client 132.196.30.78:19421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/alfa.php"] [unique_id "aoSAr9O5rbWdOArH04KKgwAAASI"]
[Tue Aug 18 12:56:31.960786 2026] [security2:error] [pid 67073:tid 67275] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/an.php"] [unique_id "aoSAr_cmepr5_nHgLbNXbAAAAlo"]
[Tue Aug 18 12:56:31.988421 2026] [security2:error] [pid 67073:tid 67273] [client 68.155.154.236:16339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSAr_cmepr5_nHgLbNXbQAAAlg"]
[Tue Aug 18 12:56:32.046527 2026] [security2:error] [pid 66623:tid 66887] [client 20.116.17.175:57621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/222.php"] [unique_id "aoSAsNO5rbWdOArH04KKhgAAAYM"]
[Tue Aug 18 12:56:32.046544 2026] [security2:error] [pid 66623:tid 66807] [client 20.163.43.14:4037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wso.php"] [unique_id "aoSAsNO5rbWdOArH04KKhwAAATM"]
[Tue Aug 18 12:56:32.048993 2026] [security2:error] [pid 66623:tid 66817] [client 40.85.222.29:13301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/bhfnd.php"] [unique_id "aoSAsNO5rbWdOArH04KKiAAAAT0"]
[Tue Aug 18 12:56:32.061696 2026] [security2:error] [pid 66623:tid 66880] [client 172.202.39.151:55169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSAsNO5rbWdOArH04KKiQAAAXw"]
[Tue Aug 18 12:56:32.063894 2026] [security2:error] [pid 67073:tid 67264] [client 20.186.30.159:13695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/key.php"] [unique_id "aoSAsPcmepr5_nHgLbNXbwAAAk8"]
[Tue Aug 18 12:56:32.068541 2026] [security2:error] [pid 67073:tid 67306] [client 20.226.6.191:62417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSAsPcmepr5_nHgLbNXcAAAAnk"]
[Tue Aug 18 12:56:32.083629 2026] [security2:error] [pid 67073:tid 67274] [client 20.151.109.219:24875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/11.php"] [unique_id "aoSAsPcmepr5_nHgLbNXcgAAAlk"]
[Tue Aug 18 12:56:32.087367 2026] [autoindex:error] [pid 67073:tid 67265] [client 172.202.39.151:55439] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:32.108136 2026] [security2:error] [pid 66623:tid 66728] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSAsNO5rbWdOArH04KKigABKVs"]
[Tue Aug 18 12:56:32.125258 2026] [security2:error] [pid 67073:tid 67170] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "adopagamentos.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSAsPcmepr5_nHgLbNXcwACKF4"]
[Tue Aug 18 12:56:32.140885 2026] [security2:error] [pid 67073:tid 67321] [client 158.23.17.4:38911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/profiler.php"] [unique_id "aoSAsPcmepr5_nHgLbNXdQAAAog"]
[Tue Aug 18 12:56:32.169902 2026] [security2:error] [pid 67073:tid 67234] [client 172.202.39.151:48201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSAsPcmepr5_nHgLbNXdgAAAjE"]
[Tue Aug 18 12:56:32.170280 2026] [security2:error] [pid 67073:tid 67218] [client 213.35.127.232:58625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAsPcmepr5_nHgLbNXdwAAAiE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:32.207281 2026] [security2:error] [pid 67073:tid 67261] [client 201.32.74.208:56358] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "image/bmp"] [severity "WARNING"] [hostname "pensamentosimperfeitos.com.br"] [uri "/wp-json/wp/v2/media"] [unique_id "aoSAsPcmepr5_nHgLbNXeAAAAkw"]
[Tue Aug 18 12:56:32.211810 2026] [security2:error] [pid 66623:tid 66820] [client 20.52.168.85:8035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/yanz.php"] [unique_id "aoSAsNO5rbWdOArH04KKjAAAAUA"]
[Tue Aug 18 12:56:32.223315 2026] [security2:error] [pid 67073:tid 67240] [client 74.248.18.37:29844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/php.php"] [unique_id "aoSAsPcmepr5_nHgLbNXeQAAAjc"]
[Tue Aug 18 12:56:32.242738 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:32.243055 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:32.247505 2026] [security2:error] [pid 67073:tid 67206] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/sy.php"] [unique_id "aoSAsPcmepr5_nHgLbNXewAAAhU"]
[Tue Aug 18 12:56:32.249120 2026] [security2:error] [pid 67073:tid 67259] [client 20.215.241.237:61092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/mac.php"] [unique_id "aoSAsPcmepr5_nHgLbNXfAAAAko"]
[Tue Aug 18 12:56:32.275861 2026] [security2:error] [pid 67073:tid 67212] [client 20.100.169.31:29986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSAsPcmepr5_nHgLbNXfgAAAhs"]
[Tue Aug 18 12:56:32.289466 2026] [security2:error] [pid 67073:tid 67141] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/core/.env"] [unique_id "aoSAsPcmepr5_nHgLbNXgQACMEE"]
[Tue Aug 18 12:56:32.290122 2026] [autoindex:error] [pid 66623:tid 66715] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/jgbdominio/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:32.290360 2026] [authz_core:error] [pid 67073:tid 67200] [remote 57.141.22.5:35396] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:32.290599 2026] [authz_core:error] [pid 67073:tid 67200] [remote 57.141.22.5:35396] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:32.329026 2026] [security2:error] [pid 67073:tid 67303] [client 158.158.74.177:17949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/rrr.php"] [unique_id "aoSAsPcmepr5_nHgLbNXggAAAnY"]
[Tue Aug 18 12:56:32.378606 2026] [security2:error] [pid 67073:tid 67269] [client 40.85.222.29:13295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/qfvqu.php"] [unique_id "aoSAsPcmepr5_nHgLbNXhgAAAlQ"]
[Tue Aug 18 12:56:32.383707 2026] [autoindex:error] [pid 67073:tid 67229] [client 172.202.39.151:55439] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:32.407439 2026] [security2:error] [pid 66623:tid 66888] [client 20.163.43.14:4105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/sf.php"] [unique_id "aoSAsNO5rbWdOArH04KKkQAAAYQ"]
[Tue Aug 18 12:56:32.439786 2026] [security2:error] [pid 67073:tid 67232] [client 74.248.130.103:36844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/8pyceeo.php"] [unique_id "aoSAsPcmepr5_nHgLbNXiQAAAi8"]
[Tue Aug 18 12:56:32.440473 2026] [security2:error] [pid 67073:tid 67181] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.144.197.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adopagamentos.com.br"] [uri "/.env.php.bak"] [unique_id "aoSAsPcmepr5_nHgLbNXfwACMGk"]
[Tue Aug 18 12:56:32.450441 2026] [security2:error] [pid 67073:tid 67244] [client 20.151.109.219:21693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/vm.php"] [unique_id "aoSAsPcmepr5_nHgLbNXigAAAjs"]
[Tue Aug 18 12:56:32.463333 2026] [security2:error] [pid 66623:tid 66664] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSAsNO5rbWdOArH04KKkgABUxs"]
[Tue Aug 18 12:56:32.473864 2026] [security2:error] [pid 67073:tid 67124] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.144.197.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adopagamentos.com.br"] [uri "/config/.env.php"] [unique_id "aoSAsPcmepr5_nHgLbNXiwACizA"]
[Tue Aug 18 12:56:32.477560 2026] [security2:error] [pid 67073:tid 67157] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/laravel/.env"] [unique_id "aoSAsPcmepr5_nHgLbNXjAACHlE"]
[Tue Aug 18 12:56:32.511340 2026] [security2:error] [pid 67073:tid 67118] [remote 129.121.103.155:60646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnomor.com.br"] [uri "/wp-login.php"] [unique_id "aoSAsPcmepr5_nHgLbNXjwACLSo"]
[Tue Aug 18 12:56:32.513276 2026] [security2:error] [pid 66623:tid 66832] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/57.php"] [unique_id "aoSAsNO5rbWdOArH04KKlAAAAUw"]
[Tue Aug 18 12:56:32.521939 2026] [security2:error] [pid 67073:tid 67289] [client 20.79.204.6:2387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSAsPcmepr5_nHgLbNXkwAAAmg"]
[Tue Aug 18 12:56:32.530506 2026] [security2:error] [pid 67073:tid 67227] [client 172.202.39.151:55439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wso.php"] [unique_id "aoSAsPcmepr5_nHgLbNXlAAAAio"]
[Tue Aug 18 12:56:32.581943 2026] [security2:error] [pid 67073:tid 67305] [client 20.226.6.191:60669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSAsPcmepr5_nHgLbNXmAAAAng"]
[Tue Aug 18 12:56:32.617203 2026] [security2:error] [pid 67073:tid 67313] [client 20.226.6.191:48323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/ok.php"] [unique_id "aoSAsPcmepr5_nHgLbNXoAAAAoA"]
[Tue Aug 18 12:56:32.633526 2026] [security2:error] [pid 66623:tid 66734] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSAsNO5rbWdOArH04KKlwABL2E"]
[Tue Aug 18 12:56:32.640253 2026] [security2:error] [pid 67073:tid 67207] [client 20.226.6.191:56716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/item.php"] [unique_id "aoSAsPcmepr5_nHgLbNXoQAAAhY"]
[Tue Aug 18 12:56:32.646088 2026] [security2:error] [pid 67073:tid 67209] [client 132.196.61.152:61018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/file2.php"] [unique_id "aoSAsPcmepr5_nHgLbNXogAAAhg"]
[Tue Aug 18 12:56:32.657810 2026] [security2:error] [pid 67073:tid 67216] [client 52.139.47.57:47653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/contact-form-7/includes/js/jquery-ui/themes/smoothness/RxRywmgzyK.php"] [unique_id "aoSAsPcmepr5_nHgLbNXpAAAAh8"]
[Tue Aug 18 12:56:32.671733 2026] [security2:error] [pid 67073:tid 67079] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.144.197.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adopagamentos.com.br"] [uri "/config.php.bak"] [unique_id "aoSAsPcmepr5_nHgLbNXpQACIAM"]
[Tue Aug 18 12:56:32.674366 2026] [security2:error] [pid 66623:tid 66810] [client 20.116.17.175:57463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-temp.php"] [unique_id "aoSAsNO5rbWdOArH04KKmQAAATY"]
[Tue Aug 18 12:56:32.675022 2026] [security2:error] [pid 67073:tid 67264] [client 20.171.51.14:43389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/xg.php"] [unique_id "aoSAsPcmepr5_nHgLbNXpgAAAk8"]
[Tue Aug 18 12:56:32.696484 2026] [security2:error] [pid 67073:tid 67211] [client 40.85.222.29:13308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/oivcl.php"] [unique_id "aoSAsPcmepr5_nHgLbNXpwAAAho"]
[Tue Aug 18 12:56:32.733147 2026] [security2:error] [pid 66623:tid 66685] [remote 191.39.149.110:7834] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "barsantajulia.com.br"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "aoSAsNO5rbWdOArH04KKmgABgjA"], referer: https://barsantajulia.com.br/happyhour/
[Tue Aug 18 12:56:32.735535 2026] [security2:error] [pid 66623:tid 66806] [client 20.163.43.14:4099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/index/function.php"] [unique_id "aoSAsNO5rbWdOArH04KKmwAAATI"]
[Tue Aug 18 12:56:32.751616 2026] [security2:error] [pid 67073:tid 67214] [client 20.151.109.219:53186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/eg.php"] [unique_id "aoSAsPcmepr5_nHgLbNXqwAAAh0"]
[Tue Aug 18 12:56:32.763903 2026] [security2:error] [pid 67073:tid 67247] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ah.php"] [unique_id "aoSAsPcmepr5_nHgLbNXrgAAAj4"]
[Tue Aug 18 12:56:32.789217 2026] [security2:error] [pid 67073:tid 67331] [client 20.186.30.159:13683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/chosen.php"] [unique_id "aoSAsPcmepr5_nHgLbNXsAAAApI"]
[Tue Aug 18 12:56:32.804209 2026] [security2:error] [pid 66623:tid 66651] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/f7.php"] [unique_id "aoSAsNO5rbWdOArH04KKnQABPw4"]
[Tue Aug 18 12:56:32.817095 2026] [security2:error] [pid 67073:tid 67299] [client 20.52.168.85:8044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/files/index.php"] [unique_id "aoSAsPcmepr5_nHgLbNXsgAAAnI"]
[Tue Aug 18 12:56:32.836236 2026] [security2:error] [pid 67073:tid 67184] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/public/.env"] [unique_id "aoSAsPcmepr5_nHgLbNXswACIWw"]
[Tue Aug 18 12:56:32.839293 2026] [security2:error] [pid 67073:tid 67088] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.env.swp"] [unique_id "aoSAsPcmepr5_nHgLbNXtAACIQw"]
[Tue Aug 18 12:56:32.841386 2026] [security2:error] [pid 67073:tid 67226] [client 172.182.200.96:14201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSAsPcmepr5_nHgLbNXtgAAAik"]
[Tue Aug 18 12:56:32.846360 2026] [security2:error] [pid 67073:tid 67128] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.144.197.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adopagamentos.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSAsPcmepr5_nHgLbNXtwACNzQ"]
[Tue Aug 18 12:56:32.952356 2026] [security2:error] [pid 67073:tid 67302] [client 192.141.172.134:60950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAsPcmepr5_nHgLbNXugAAAnU"]
[Tue Aug 18 12:56:32.952493 2026] [security2:error] [pid 67073:tid 67302] [client 192.141.172.134:60950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAsPcmepr5_nHgLbNXugAAAnU"]
[Tue Aug 18 12:56:32.975210 2026] [security2:error] [pid 66623:tid 66669] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/photo.php"] [unique_id "aoSAsNO5rbWdOArH04KKoAABVSA"]
[Tue Aug 18 12:56:32.996734 2026] [security2:error] [pid 66623:tid 66854] [client 40.85.222.29:13290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/zugvi.php"] [unique_id "aoSAsNO5rbWdOArH04KKoQAAAWI"]
[Tue Aug 18 12:56:32.998458 2026] [security2:error] [pid 67073:tid 67316] [client 135.225.75.187:51272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/sbhu.php"] [unique_id "aoSAsPcmepr5_nHgLbNXuwAAAoM"]
[Tue Aug 18 12:56:32.999091 2026] [security2:error] [pid 67073:tid 67286] [client 74.248.130.103:38714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/.admin.php"] [unique_id "aoSAsPcmepr5_nHgLbNXvAAAAmU"]
[Tue Aug 18 12:56:33.008102 2026] [security2:error] [pid 67073:tid 67221] [client 196.12.128.158:50254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAsfcmepr5_nHgLbNXvQAAAiQ"]
[Tue Aug 18 12:56:33.008210 2026] [security2:error] [pid 67073:tid 67221] [client 196.12.128.158:50254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAsfcmepr5_nHgLbNXvQAAAiQ"]
[Tue Aug 18 12:56:33.014085 2026] [security2:error] [pid 67073:tid 67249] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/vw.php"] [unique_id "aoSAsfcmepr5_nHgLbNXvwAAAkA"]
[Tue Aug 18 12:56:33.061139 2026] [security2:error] [pid 66623:tid 66866] [client 20.163.43.14:4213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/edit.php"] [unique_id "aoSAsdO5rbWdOArH04KKpAAAAW4"]
[Tue Aug 18 12:56:33.073395 2026] [security2:error] [pid 67073:tid 67237] [client 132.196.30.78:21834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/edit.php"] [unique_id "aoSAsfcmepr5_nHgLbNXwgAAAjQ"]
[Tue Aug 18 12:56:33.088140 2026] [security2:error] [pid 67073:tid 67220] [client 74.248.136.165:28110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ms.php"] [unique_id "aoSAsfcmepr5_nHgLbNXxAAAAiM"]
[Tue Aug 18 12:56:33.096460 2026] [security2:error] [pid 67073:tid 67104] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/web/.env"] [unique_id "aoSAsfcmepr5_nHgLbNXxQACXxw"]
[Tue Aug 18 12:56:33.113872 2026] [security2:error] [pid 66623:tid 66793] [client 20.151.109.219:59723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/uk.php"] [unique_id "aoSAsdO5rbWdOArH04KKpgAAASU"]
[Tue Aug 18 12:56:33.128849 2026] [security2:error] [pid 67073:tid 67311] [client 20.79.204.6:2227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSAsfcmepr5_nHgLbNXxgAAAn4"]
[Tue Aug 18 12:56:33.150038 2026] [security2:error] [pid 66623:tid 66778] [client 172.202.39.151:50222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/sf.php"] [unique_id "aoSAsdO5rbWdOArH04KKqAAAARY"]
[Tue Aug 18 12:56:33.150909 2026] [security2:error] [pid 67073:tid 67213] [client 20.100.169.31:19909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAsfcmepr5_nHgLbNXxwAAAhw"]
[Tue Aug 18 12:56:33.151223 2026] [security2:error] [pid 67073:tid 67317] [client 20.226.56.190:19365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/xm.php"] [unique_id "aoSAsfcmepr5_nHgLbNXyAAAAoQ"]
[Tue Aug 18 12:56:33.151548 2026] [security2:error] [pid 66623:tid 66730] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-aa.php"] [unique_id "aoSAsdO5rbWdOArH04KKqQABCl0"]
[Tue Aug 18 12:56:33.173686 2026] [security2:error] [pid 67073:tid 67296] [client 20.171.51.14:29186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/nd.php"] [unique_id "aoSAsfcmepr5_nHgLbNXyQAAAm8"]
[Tue Aug 18 12:56:33.183133 2026] [security2:error] [pid 67073:tid 67261] [client 213.35.127.232:58857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAsfcmepr5_nHgLbNXywAAAkw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:33.190181 2026] [security2:error] [pid 67073:tid 67232] [client 158.23.17.4:9392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/findes.php"] [unique_id "aoSAsfcmepr5_nHgLbNXzAAAAi8"]
[Tue Aug 18 12:56:33.275401 2026] [security2:error] [pid 66623:tid 66772] [client 20.116.17.175:57626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/spadex.php"] [unique_id "aoSAsdO5rbWdOArH04KKrQAAARA"]
[Tue Aug 18 12:56:33.280168 2026] [security2:error] [pid 66623:tid 66870] [client 40.85.222.29:13294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wsrer.php"] [unique_id "aoSAsdO5rbWdOArH04KKrgAAAXI"]
[Tue Aug 18 12:56:33.308375 2026] [security2:error] [pid 67073:tid 67208] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/lj.php"] [unique_id "aoSAsfcmepr5_nHgLbNX0AAAAhc"]
[Tue Aug 18 12:56:33.371787 2026] [security2:error] [pid 66623:tid 66808] [client 20.100.169.31:33594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/info.php"] [unique_id "aoSAsdO5rbWdOArH04KKsQAAATQ"]
[Tue Aug 18 12:56:33.403589 2026] [security2:error] [pid 66623:tid 66712] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/d.php"] [unique_id "aoSAsdO5rbWdOArH04KKsgABgUs"]
[Tue Aug 18 12:56:33.417756 2026] [security2:error] [pid 66623:tid 66864] [client 20.52.168.85:7817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-admin/css/about.php"] [unique_id "aoSAsdO5rbWdOArH04KKtAAAAWw"]
[Tue Aug 18 12:56:33.418495 2026] [security2:error] [pid 66623:tid 66809] [client 20.151.109.219:24861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/creds.php"] [unique_id "aoSAsdO5rbWdOArH04KKtQAAATU"]
[Tue Aug 18 12:56:33.444805 2026] [authz_core:error] [pid 67073:tid 67117] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:33.445238 2026] [authz_core:error] [pid 67073:tid 67117] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:33.456627 2026] [security2:error] [pid 67073:tid 67271] [client 20.215.241.237:57734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSAsfcmepr5_nHgLbNX1AAAAlY"]
[Tue Aug 18 12:56:33.473444 2026] [security2:error] [pid 67073:tid 67290] [client 74.248.130.103:38715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wsomini.php"] [unique_id "aoSAsfcmepr5_nHgLbNX1QAAAmk"]
[Tue Aug 18 12:56:33.559280 2026] [security2:error] [pid 66623:tid 66768] [client 52.139.47.57:44629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/dist/alfa-rex.php"] [unique_id "aoSAsdO5rbWdOArH04KKuAAAAQw"]
[Tue Aug 18 12:56:33.568996 2026] [security2:error] [pid 66623:tid 66787] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kh.php"] [unique_id "aoSAsdO5rbWdOArH04KKuQAAAR8"]
[Tue Aug 18 12:56:33.573901 2026] [security2:error] [pid 67073:tid 67292] [client 20.163.43.14:4338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSAsfcmepr5_nHgLbNX2QAAAms"]
[Tue Aug 18 12:56:33.576196 2026] [security2:error] [pid 66623:tid 66756] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSAsdO5rbWdOArH04KKugABUnc"]
[Tue Aug 18 12:56:33.605063 2026] [security2:error] [pid 67073:tid 67216] [client 20.186.30.159:13640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/thoms.php"] [unique_id "aoSAsfcmepr5_nHgLbNX2gAAAh8"]
[Tue Aug 18 12:56:33.610293 2026] [security2:error] [pid 67073:tid 67285] [client 40.85.222.29:13281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/ucpfr.php"] [unique_id "aoSAsfcmepr5_nHgLbNX2wAAAmQ"]
[Tue Aug 18 12:56:33.641171 2026] [security2:error] [pid 67073:tid 67264] [client 20.171.51.14:28862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ri.php"] [unique_id "aoSAsfcmepr5_nHgLbNX3QAAAk8"]
[Tue Aug 18 12:56:33.682997 2026] [security2:error] [pid 67073:tid 67222] [client 20.65.69.59:3206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/showphpinfo.php"] [unique_id "aoSAsfcmepr5_nHgLbNX3gAAAiU"]
[Tue Aug 18 12:56:33.710614 2026] [security2:error] [pid 67073:tid 67321] [client 20.151.109.219:64998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ho.php"] [unique_id "aoSAsfcmepr5_nHgLbNX4AAAAog"]
[Tue Aug 18 12:56:33.729908 2026] [security2:error] [pid 67073:tid 67325] [client 172.182.200.96:14155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSAsfcmepr5_nHgLbNX4gAAAow"]
[Tue Aug 18 12:56:33.730557 2026] [security2:error] [pid 67073:tid 67250] [client 172.202.39.151:48196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-good.php"] [unique_id "aoSAsfcmepr5_nHgLbNX4wAAAkE"]
[Tue Aug 18 12:56:33.734543 2026] [security2:error] [pid 67073:tid 67330] [client 20.215.241.237:18960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/admin.php"] [unique_id "aoSAsfcmepr5_nHgLbNX5QAAApE"]
[Tue Aug 18 12:56:33.743451 2026] [authz_core:error] [pid 67073:tid 67162] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:33.743736 2026] [authz_core:error] [pid 67073:tid 67162] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:33.746451 2026] [security2:error] [pid 66623:tid 66739] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSAsdO5rbWdOArH04KKvQABV2Y"]
[Tue Aug 18 12:56:33.754568 2026] [autoindex:error] [pid 67073:tid 67293] [client 20.79.204.6:2381] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:33.795060 2026] [security2:error] [pid 66623:tid 66859] [client 172.202.39.151:65258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/index/function.php"] [unique_id "aoSAsdO5rbWdOArH04KKvwAAAWc"]
[Tue Aug 18 12:56:33.805829 2026] [security2:error] [pid 67073:tid 67082] [remote 47.128.57.62:54528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "igsautomoveis.com.br"] [uri "/veiculo/1019039/vw-volkswagen-polo-track-1-0-flex-12v-5p-2024"] [unique_id "aoSAsfcmepr5_nHgLbNX6gACXgY"]
[Tue Aug 18 12:56:33.829072 2026] [security2:error] [pid 67073:tid 67243] [client 158.158.34.183:59413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/bolt.php"] [unique_id "aoSAsfcmepr5_nHgLbNX6wAAAjo"]
[Tue Aug 18 12:56:33.829835 2026] [security2:error] [pid 67073:tid 67312] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/jb.php"] [unique_id "aoSAsfcmepr5_nHgLbNX7AAAAn8"]
[Tue Aug 18 12:56:33.831317 2026] [security2:error] [pid 67073:tid 67301] [client 104.209.144.33:21388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSAsfcmepr5_nHgLbNX7QAAAnQ"]
[Tue Aug 18 12:56:33.832305 2026] [security2:error] [pid 67073:tid 67322] [client 172.202.39.151:38629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAsfcmepr5_nHgLbNX7gAAAok"]
[Tue Aug 18 12:56:33.896852 2026] [security2:error] [pid 66623:tid 66802] [client 158.158.74.177:2978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/s.php"] [unique_id "aoSAsdO5rbWdOArH04KKwQAAAS4"]
[Tue Aug 18 12:56:33.906373 2026] [security2:error] [pid 66623:tid 66868] [client 132.196.61.152:34759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/gm.php"] [unique_id "aoSAsdO5rbWdOArH04KKwgAAAXA"]
[Tue Aug 18 12:56:33.908149 2026] [security2:error] [pid 67073:tid 67235] [client 74.248.130.103:16142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/vr.php"] [unique_id "aoSAsfcmepr5_nHgLbNX8AAAAjI"]
[Tue Aug 18 12:56:33.908836 2026] [security2:error] [pid 67073:tid 67310] [client 20.163.43.14:4248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-good.php"] [unique_id "aoSAsfcmepr5_nHgLbNX8QAAAn0"]
[Tue Aug 18 12:56:33.908885 2026] [security2:error] [pid 66623:tid 66823] [client 20.116.17.175:11250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSAsdO5rbWdOArH04KKwwAAAUM"]
[Tue Aug 18 12:56:33.913379 2026] [security2:error] [pid 67073:tid 67302] [client 40.85.222.29:13271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/yxijx.php"] [unique_id "aoSAsfcmepr5_nHgLbNX8gAAAnU"]
[Tue Aug 18 12:56:33.918790 2026] [security2:error] [pid 66623:tid 66723] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSAsdO5rbWdOArH04KKxAABalY"]
[Tue Aug 18 12:56:33.971815 2026] [security2:error] [pid 67073:tid 67328] [client 158.23.17.4:8720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/fedora.php"] [unique_id "aoSAsfcmepr5_nHgLbNX9AAAAo8"]
[Tue Aug 18 12:56:34.006216 2026] [security2:error] [pid 67073:tid 67221] [client 20.151.109.219:64993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/97.php"] [unique_id "aoSAsvcmepr5_nHgLbNX9QAAAiQ"]
[Tue Aug 18 12:56:34.024643 2026] [security2:error] [pid 66623:tid 66829] [client 20.52.168.85:7832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSAstO5rbWdOArH04KKyAAAAUk"]
[Tue Aug 18 12:56:34.073298 2026] [security2:error] [pid 66623:tid 66826] [client 103.120.71.157:52156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAstO5rbWdOArH04KKygAAAUY"]
[Tue Aug 18 12:56:34.073412 2026] [security2:error] [pid 66623:tid 66826] [client 103.120.71.157:52156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAstO5rbWdOArH04KKygAAAUY"]
[Tue Aug 18 12:56:34.074112 2026] [security2:error] [pid 67073:tid 67276] [client 197.184.64.235:41931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAsvcmepr5_nHgLbNX-AAAAls"]
[Tue Aug 18 12:56:34.074233 2026] [security2:error] [pid 67073:tid 67276] [client 197.184.64.235:41931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAsvcmepr5_nHgLbNX-AAAAls"]
[Tue Aug 18 12:56:34.087094 2026] [security2:error] [pid 67073:tid 67309] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/do.php"] [unique_id "aoSAsvcmepr5_nHgLbNX-QAAAnw"]
[Tue Aug 18 12:56:34.090264 2026] [security2:error] [pid 66623:tid 66655] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAstO5rbWdOArH04KKzQABFxI"]
[Tue Aug 18 12:56:34.115350 2026] [security2:error] [pid 67073:tid 67267] [client 20.226.56.190:31004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/zy.php"] [unique_id "aoSAsvcmepr5_nHgLbNX_AAAAlI"]
[Tue Aug 18 12:56:34.121704 2026] [security2:error] [pid 67073:tid 67213] [client 20.186.30.159:13595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/wpxml.php"] [unique_id "aoSAsvcmepr5_nHgLbNX_QAAAhw"]
[Tue Aug 18 12:56:34.191090 2026] [security2:error] [pid 67073:tid 67308] [client 52.139.47.57:9067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/elementor/wp-login.php"] [unique_id "aoSAsvcmepr5_nHgLbNYDgAAAns"]
[Tue Aug 18 12:56:34.191088 2026] [security2:error] [pid 67073:tid 67287] [client 20.79.204.6:2381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSAsvcmepr5_nHgLbNYDwAAAmY"]
[Tue Aug 18 12:56:34.203503 2026] [security2:error] [pid 67073:tid 67259] [client 213.35.127.232:59033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAsvcmepr5_nHgLbNYGgAAAko"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:34.228436 2026] [security2:error] [pid 66623:tid 66801] [client 20.215.241.237:44799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSAstO5rbWdOArH04KK0AAAAS0"]
[Tue Aug 18 12:56:34.236672 2026] [security2:error] [pid 67073:tid 67258] [client 135.225.75.187:58326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/zc-318.php"] [unique_id "aoSAsvcmepr5_nHgLbNYGwAAAkk"]
[Tue Aug 18 12:56:34.237536 2026] [security2:error] [pid 67073:tid 67289] [client 40.85.222.29:13194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/zwlsv.php"] [unique_id "aoSAsvcmepr5_nHgLbNYHAAAAmg"]
[Tue Aug 18 12:56:34.260091 2026] [security2:error] [pid 66623:tid 66670] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAstO5rbWdOArH04KK0QABPiE"]
[Tue Aug 18 12:56:34.332254 2026] [security2:error] [pid 67073:tid 67305] [client 20.151.109.219:59758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/rh.php"] [unique_id "aoSAsvcmepr5_nHgLbNYJgAAAng"]
[Tue Aug 18 12:56:34.345929 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:34.346184 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:34.364358 2026] [security2:error] [pid 67073:tid 67271] [client 20.171.51.14:16741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/tp.php"] [unique_id "aoSAsvcmepr5_nHgLbNYKAAAAlY"]
[Tue Aug 18 12:56:34.382553 2026] [security2:error] [pid 67073:tid 67231] [client 20.116.17.175:57655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/srontol.php"] [unique_id "aoSAsvcmepr5_nHgLbNYKwAAAi4"]
[Tue Aug 18 12:56:34.432966 2026] [security2:error] [pid 66623:tid 66713] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/abc.php"] [unique_id "aoSAstO5rbWdOArH04KK1QABIUw"]
[Tue Aug 18 12:56:34.458865 2026] [security2:error] [pid 66623:tid 66770] [client 20.65.98.162:8465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/133.php"] [unique_id "aoSAstO5rbWdOArH04KK1gAAAQ4"]
[Tue Aug 18 12:56:34.465665 2026] [security2:error] [pid 66623:tid 66830] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/yw.php"] [unique_id "aoSAstO5rbWdOArH04KK1wAAAUo"]
[Tue Aug 18 12:56:34.513628 2026] [security2:error] [pid 66623:tid 66821] [client 40.85.222.29:13268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/jrpga.php"] [unique_id "aoSAstO5rbWdOArH04KK2gAAAUE"]
[Tue Aug 18 12:56:34.525422 2026] [security2:error] [pid 66623:tid 66790] [client 158.23.17.4:38871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/path.php"] [unique_id "aoSAstO5rbWdOArH04KK2wAAASI"]
[Tue Aug 18 12:56:34.606317 2026] [security2:error] [pid 66623:tid 66690] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/sf.php"] [unique_id "aoSAstO5rbWdOArH04KK3QABdjU"]
[Tue Aug 18 12:56:34.630576 2026] [security2:error] [pid 66623:tid 66834] [client 20.52.168.85:8026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/num.php"] [unique_id "aoSAstO5rbWdOArH04KK3gAAAU4"]
[Tue Aug 18 12:56:34.643786 2026] [security2:error] [pid 67073:tid 67228] [client 20.250.13.23:19663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/NewFile.php"] [unique_id "aoSAsvcmepr5_nHgLbNYMQAAAis"]
[Tue Aug 18 12:56:34.648227 2026] [security2:error] [pid 67073:tid 67250] [client 20.163.43.14:4156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/tes.php"] [unique_id "aoSAsvcmepr5_nHgLbNYMgAAAkE"]
[Tue Aug 18 12:56:34.655516 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:34.656153 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:34.658414 2026] [security2:error] [pid 67073:tid 67330] [client 20.151.109.219:21640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/yg.php"] [unique_id "aoSAsvcmepr5_nHgLbNYNAAAApE"]
[Tue Aug 18 12:56:34.659691 2026] [security2:error] [pid 67073:tid 67234] [client 20.186.30.159:13624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/file1221.php"] [unique_id "aoSAsvcmepr5_nHgLbNYNQAAAjE"]
[Tue Aug 18 12:56:34.708513 2026] [security2:error] [pid 66623:tid 66796] [client 132.196.61.152:60348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/ws55.php"] [unique_id "aoSAstO5rbWdOArH04KK4AAAASg"]
[Tue Aug 18 12:56:34.730992 2026] [security2:error] [pid 66623:tid 66876] [client 132.196.30.78:19415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/elp.php"] [unique_id "aoSAstO5rbWdOArH04KK4QAAAXg"]
[Tue Aug 18 12:56:34.730991 2026] [security2:error] [pid 67073:tid 67240] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/qh.php"] [unique_id "aoSAsvcmepr5_nHgLbNYOAAAAjc"]
[Tue Aug 18 12:56:34.778303 2026] [security2:error] [pid 66623:tid 66754] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/chosen.php"] [unique_id "aoSAstO5rbWdOArH04KK4wABQHU"]
[Tue Aug 18 12:56:34.805758 2026] [security2:error] [pid 67073:tid 67243] [client 40.85.222.29:13254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSAsvcmepr5_nHgLbNYOQAAAjo"]
[Tue Aug 18 12:56:34.811950 2026] [security2:error] [pid 66623:tid 66815] [client 20.100.169.31:31878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/a.php"] [unique_id "aoSAstO5rbWdOArH04KK5AAAATs"]
[Tue Aug 18 12:56:34.836449 2026] [autoindex:error] [pid 67073:tid 67265] [client 20.79.204.6:2401] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/images/media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:34.840935 2026] [security2:error] [pid 66623:tid 66805] [client 20.65.69.59:49315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/phpstatus.php"] [unique_id "aoSAstO5rbWdOArH04KK5QAAATE"]
[Tue Aug 18 12:56:34.888536 2026] [security2:error] [pid 66623:tid 66889] [client 74.248.136.165:18041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/wsws.php"] [unique_id "aoSAstO5rbWdOArH04KK5wAAAYU"]
[Tue Aug 18 12:56:34.917015 2026] [security2:error] [pid 67073:tid 67257] [client 20.215.241.237:57783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/system_log.php"] [unique_id "aoSAsvcmepr5_nHgLbNYPgAAAkg"]
[Tue Aug 18 12:56:34.917574 2026] [security2:error] [pid 66623:tid 66776] [client 20.171.51.14:15745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/zj.php"] [unique_id "aoSAstO5rbWdOArH04KK6AAAARQ"]
[Tue Aug 18 12:56:34.960012 2026] [security2:error] [pid 66623:tid 66726] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/u.php"] [unique_id "aoSAstO5rbWdOArH04KK6gABTFk"]
[Tue Aug 18 12:56:34.960954 2026] [authz_core:error] [pid 67073:tid 67186] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:34.961429 2026] [authz_core:error] [pid 67073:tid 67186] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:34.973604 2026] [security2:error] [pid 66623:tid 66780] [client 20.163.43.14:4202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/files/index.php"] [unique_id "aoSAstO5rbWdOArH04KK6wAAARg"]
[Tue Aug 18 12:56:34.989319 2026] [security2:error] [pid 66623:tid 66842] [client 104.209.144.33:29826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSAstO5rbWdOArH04KK7AAAAVY"]
[Tue Aug 18 12:56:34.991215 2026] [security2:error] [pid 67073:tid 67245] [client 20.151.109.219:12882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/et.php"] [unique_id "aoSAsvcmepr5_nHgLbNYQwAAAjw"]
[Tue Aug 18 12:56:34.991911 2026] [security2:error] [pid 67073:tid 67219] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/r.php"] [unique_id "aoSAsvcmepr5_nHgLbNYRAAAAiI"]
[Tue Aug 18 12:56:34.998612 2026] [security2:error] [pid 66623:tid 66810] [client 20.116.17.175:57653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/file5.php"] [unique_id "aoSAstO5rbWdOArH04KK7QAAATY"]
[Tue Aug 18 12:56:35.032160 2026] [security2:error] [pid 66623:tid 66774] [client 20.215.241.237:61843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/img.php"] [unique_id "aoSAs9O5rbWdOArH04KK7gAAARI"]
[Tue Aug 18 12:56:35.038702 2026] [security2:error] [pid 67073:tid 67306] [client 20.79.204.6:2401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAs_cmepr5_nHgLbNYRQAAAnk"]
[Tue Aug 18 12:56:35.043870 2026] [security2:error] [pid 67073:tid 67214] [client 86.120.159.145:55489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAs_cmepr5_nHgLbNYRgAAAh0"]
[Tue Aug 18 12:56:35.044026 2026] [security2:error] [pid 67073:tid 67214] [client 86.120.159.145:55489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAs_cmepr5_nHgLbNYRgAAAh0"]
[Tue Aug 18 12:56:35.082677 2026] [security2:error] [pid 67073:tid 67316] [client 52.139.47.57:9069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/goat1.php"] [unique_id "aoSAs_cmepr5_nHgLbNYRwAAAoM"]
[Tue Aug 18 12:56:35.112916 2026] [security2:error] [pid 67073:tid 67286] [client 172.182.200.96:14120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSAs_cmepr5_nHgLbNYSQAAAmU"]
[Tue Aug 18 12:56:35.114905 2026] [security2:error] [pid 67073:tid 67328] [client 40.85.222.29:13195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/nwwha.php"] [unique_id "aoSAs_cmepr5_nHgLbNYSgAAAo8"]
[Tue Aug 18 12:56:35.188110 2026] [autoindex:error] [pid 66623:tid 66737] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/jgbdominio/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:35.211451 2026] [security2:error] [pid 67073:tid 67276] [client 20.65.69.59:3771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/del.php"] [unique_id "aoSAs_cmepr5_nHgLbNYTwAAAls"]
[Tue Aug 18 12:56:35.215349 2026] [security2:error] [pid 66623:tid 66788] [client 213.35.127.232:59242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAs9O5rbWdOArH04KK9wAAASA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:35.231625 2026] [security2:error] [pid 66623:tid 66819] [client 20.52.168.85:7794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSAs9O5rbWdOArH04KK-QAAAT8"]
[Tue Aug 18 12:56:35.265431 2026] [security2:error] [pid 66623:tid 66772] [client 172.202.39.151:15717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp.php"] [unique_id "aoSAs9O5rbWdOArH04KK-wAAARA"]
[Tue Aug 18 12:56:35.277477 2026] [security2:error] [pid 67073:tid 67332] [client 68.155.156.252:25568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAs_cmepr5_nHgLbNYUgAAApM"]
[Tue Aug 18 12:56:35.278106 2026] [security2:error] [pid 67073:tid 67244] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/17.php"] [unique_id "aoSAs_cmepr5_nHgLbNYUwAAAjs"]
[Tue Aug 18 12:56:35.291621 2026] [security2:error] [pid 66623:tid 66870] [client 172.202.39.151:65254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/edit.php"] [unique_id "aoSAs9O5rbWdOArH04KK_AAAAXI"]
[Tue Aug 18 12:56:35.296080 2026] [security2:error] [pid 67073:tid 67247] [client 103.184.169.37:41931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAs_cmepr5_nHgLbNYVAAAAj4"]
[Tue Aug 18 12:56:35.296203 2026] [security2:error] [pid 67073:tid 67247] [client 103.184.169.37:41931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAs_cmepr5_nHgLbNYVAAAAj4"]
[Tue Aug 18 12:56:35.316699 2026] [security2:error] [pid 67073:tid 67324] [client 158.23.17.4:63670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/456.php"] [unique_id "aoSAs_cmepr5_nHgLbNYVQAAAos"]
[Tue Aug 18 12:56:35.320654 2026] [security2:error] [pid 66623:tid 66803] [client 158.158.74.177:26169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/s93.php"] [unique_id "aoSAs9O5rbWdOArH04KK_QAAAS8"]
[Tue Aug 18 12:56:35.330745 2026] [security2:error] [pid 67073:tid 67246] [client 20.163.43.14:4137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAs_cmepr5_nHgLbNYVgAAAj0"]
[Tue Aug 18 12:56:35.346140 2026] [security2:error] [pid 67073:tid 67283] [client 20.151.109.219:64972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/of.php"] [unique_id "aoSAs_cmepr5_nHgLbNYVwAAAmI"]
[Tue Aug 18 12:56:35.357208 2026] [security2:error] [pid 66623:tid 66692] [remote 185.118.190.176:38096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.190.118.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guinchomarquette.com.br"] [uri "/wp-login.php"] [unique_id "aoSAs9O5rbWdOArH04KK_wABVTc"]
[Tue Aug 18 12:56:35.365964 2026] [security2:error] [pid 66623:tid 66707] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/customize.php"] [unique_id "aoSAs9O5rbWdOArH04KLAAABX0Y"]
[Tue Aug 18 12:56:35.408386 2026] [security2:error] [pid 67073:tid 67289] [client 40.85.222.29:13264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/opsqt.php"] [unique_id "aoSAs_cmepr5_nHgLbNYWgAAAmg"]
[Tue Aug 18 12:56:35.417422 2026] [security2:error] [pid 67073:tid 67221] [client 132.196.30.78:19442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAs_cmepr5_nHgLbNYWwAAAiQ"]
[Tue Aug 18 12:56:35.447642 2026] [security2:error] [pid 67073:tid 67232] [client 20.171.51.14:1922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/x.php"] [unique_id "aoSAs_cmepr5_nHgLbNYXAAAAi8"]
[Tue Aug 18 12:56:35.550658 2026] [security2:error] [pid 67073:tid 67314] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ev.php"] [unique_id "aoSAs_cmepr5_nHgLbNYYgAAAoE"]
[Tue Aug 18 12:56:35.561870 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:35.562294 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:35.617756 2026] [security2:error] [pid 67073:tid 67230] [client 135.225.75.187:27258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ccou.php"] [unique_id "aoSAs_cmepr5_nHgLbNYZQAAAi0"]
[Tue Aug 18 12:56:35.631787 2026] [security2:error] [pid 67073:tid 67231] [client 52.139.47.57:18368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/google-seo-rank/module.php"] [unique_id "aoSAs_cmepr5_nHgLbNYZgAAAi4"]
[Tue Aug 18 12:56:35.638666 2026] [security2:error] [pid 67073:tid 67281] [client 20.116.17.175:57421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/yup.php"] [unique_id "aoSAs_cmepr5_nHgLbNYZwAAAmA"]
[Tue Aug 18 12:56:35.646255 2026] [security2:error] [pid 67073:tid 67280] [client 20.79.204.6:2658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSAs_cmepr5_nHgLbNYaAAAAl8"]
[Tue Aug 18 12:56:35.672027 2026] [security2:error] [pid 66623:tid 66799] [client 20.100.169.31:19943] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.noise2.com.br"] [uri "/1.php"] [unique_id "aoSAs9O5rbWdOArH04KLBgAAASs"]
[Tue Aug 18 12:56:35.672150 2026] [security2:error] [pid 66623:tid 66799] [client 20.100.169.31:19943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/1.php"] [unique_id "aoSAs9O5rbWdOArH04KLBgAAASs"]
[Tue Aug 18 12:56:35.672552 2026] [security2:error] [pid 66623:tid 66828] [client 20.163.43.14:4308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAs9O5rbWdOArH04KLBwAAAUg"]
[Tue Aug 18 12:56:35.673575 2026] [security2:error] [pid 66623:tid 66768] [client 52.173.121.69:24773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSAs9O5rbWdOArH04KLCAAAAQw"]
[Tue Aug 18 12:56:35.689913 2026] [security2:error] [pid 67073:tid 67327] [client 20.151.109.219:64639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/bu.php"] [unique_id "aoSAs_cmepr5_nHgLbNYagAAAo4"]
[Tue Aug 18 12:56:35.723544 2026] [security2:error] [pid 67073:tid 67242] [client 40.85.222.29:13197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/jvcpa.php"] [unique_id "aoSAs_cmepr5_nHgLbNYawAAAjk"]
[Tue Aug 18 12:56:35.790611 2026] [autoindex:error] [pid 67073:tid 67234] [client 172.202.39.151:65254] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:35.807533 2026] [security2:error] [pid 67073:tid 67240] [client 132.196.61.152:61017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/m.php"] [unique_id "aoSAs_cmepr5_nHgLbNYbgAAAjc"]
[Tue Aug 18 12:56:35.820017 2026] [security2:error] [pid 66623:tid 66800] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/xs.php"] [unique_id "aoSAs9O5rbWdOArH04KLDQAAASw"]
[Tue Aug 18 12:56:35.836399 2026] [security2:error] [pid 67073:tid 67241] [client 20.52.168.85:7856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/css/index.php"] [unique_id "aoSAs_cmepr5_nHgLbNYbwAAAjg"]
[Tue Aug 18 12:56:35.836760 2026] [security2:error] [pid 66623:tid 66659] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/mah/function.php"] [unique_id "aoSAs9O5rbWdOArH04KLDwABWxY"]
[Tue Aug 18 12:56:35.858522 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:35.858792 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:35.870063 2026] [security2:error] [pid 67073:tid 67248] [client 20.186.30.159:13612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/nox.php"] [unique_id "aoSAs_cmepr5_nHgLbNYdQAAAj8"]
[Tue Aug 18 12:56:35.956568 2026] [security2:error] [pid 67073:tid 67273] [client 20.65.69.59:3725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/moderator.php"] [unique_id "aoSAs_cmepr5_nHgLbNYeQAAAlg"]
[Tue Aug 18 12:56:35.971376 2026] [security2:error] [pid 67073:tid 67331] [client 158.23.17.4:10946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/SMTP.php"] [unique_id "aoSAs_cmepr5_nHgLbNYegAAApI"]
[Tue Aug 18 12:56:35.979763 2026] [security2:error] [pid 67073:tid 67268] [client 20.171.51.14:43355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/yn.php"] [unique_id "aoSAs_cmepr5_nHgLbNYewAAAlM"]
[Tue Aug 18 12:56:35.999231 2026] [security2:error] [pid 66623:tid 66798] [client 40.85.222.29:13186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSAs9O5rbWdOArH04KLEgAAASo"]
[Tue Aug 18 12:56:36.001629 2026] [security2:error] [pid 66623:tid 66868] [client 20.151.109.219:64139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/rn.php"] [unique_id "aoSAtNO5rbWdOArH04KLEwAAAXA"]
[Tue Aug 18 12:56:36.002838 2026] [security2:error] [pid 67073:tid 67245] [client 172.182.200.96:14097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSAtPcmepr5_nHgLbNYfAAAAjw"]
[Tue Aug 18 12:56:36.007964 2026] [security2:error] [pid 67073:tid 67329] [client 20.163.43.14:4261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAtPcmepr5_nHgLbNYfQAAApA"]
[Tue Aug 18 12:56:36.008187 2026] [security2:error] [pid 66623:tid 66688] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/filter.php"] [unique_id "aoSAtNO5rbWdOArH04KLFAABQzM"]
[Tue Aug 18 12:56:36.096411 2026] [security2:error] [pid 66623:tid 66771] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/lmfi2.php"] [unique_id "aoSAtNO5rbWdOArH04KLGAAAAQ8"]
[Tue Aug 18 12:56:36.173260 2026] [security2:error] [pid 67073:tid 67225] [client 20.116.17.175:57654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAtPcmepr5_nHgLbNYhwAAAig"]
[Tue Aug 18 12:56:36.179316 2026] [security2:error] [pid 66623:tid 66747] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/input.php"] [unique_id "aoSAtNO5rbWdOArH04KLGgABa24"]
[Tue Aug 18 12:56:36.220586 2026] [security2:error] [pid 67073:tid 67229] [client 172.202.39.151:65254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSAtPcmepr5_nHgLbNYiQAAAiw"]
[Tue Aug 18 12:56:36.231505 2026] [security2:error] [pid 66623:tid 66859] [client 213.35.127.232:59453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAtNO5rbWdOArH04KLGwAAAWc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:36.252293 2026] [autoindex:error] [pid 67073:tid 67296] [client 172.202.39.151:42152] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:36.254073 2026] [security2:error] [pid 66623:tid 66857] [client 20.79.204.6:2638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSAtNO5rbWdOArH04KLHQAAAWU"]
[Tue Aug 18 12:56:36.258539 2026] [security2:error] [pid 66623:tid 66893] [client 52.139.47.57:16703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/h.php"] [unique_id "aoSAtNO5rbWdOArH04KLHgAAAYk"]
[Tue Aug 18 12:56:36.278959 2026] [security2:error] [pid 67073:tid 67300] [client 20.151.109.219:64603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ut.php"] [unique_id "aoSAtPcmepr5_nHgLbNYigAAAnM"]
[Tue Aug 18 12:56:36.294531 2026] [security2:error] [pid 67073:tid 67311] [client 40.85.222.29:13280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSAtPcmepr5_nHgLbNYiwAAAn4"]
[Tue Aug 18 12:56:36.345503 2026] [security2:error] [pid 66623:tid 66769] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/fd.php"] [unique_id "aoSAtNO5rbWdOArH04KLIQAAAQ0"]
[Tue Aug 18 12:56:36.370497 2026] [security2:error] [pid 67073:tid 67246] [client 20.163.43.14:4173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/rip.php"] [unique_id "aoSAtPcmepr5_nHgLbNYjgAAAj0"]
[Tue Aug 18 12:56:36.392791 2026] [security2:error] [pid 67073:tid 67294] [client 74.248.136.165:28114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/motu.php"] [unique_id "aoSAtPcmepr5_nHgLbNYjwAAAm0"]
[Tue Aug 18 12:56:36.460108 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:36.460382 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:36.465713 2026] [security2:error] [pid 66623:tid 66783] [client 20.171.51.14:29197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/11.php"] [unique_id "aoSAtNO5rbWdOArH04KLJQAAARs"]
[Tue Aug 18 12:56:36.466767 2026] [authz_core:error] [pid 67073:tid 67170] [remote 57.141.22.27:43316] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:36.467024 2026] [authz_core:error] [pid 67073:tid 67170] [remote 57.141.22.27:43316] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:36.504910 2026] [security2:error] [pid 66623:tid 66873] [client 20.215.241.237:46439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/pucci.php"] [unique_id "aoSAtNO5rbWdOArH04KLJgAAAXU"]
[Tue Aug 18 12:56:36.550476 2026] [security2:error] [pid 67073:tid 67209] [client 158.23.17.4:63999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/vbseo.php"] [unique_id "aoSAtPcmepr5_nHgLbNYmQAAAhg"]
[Tue Aug 18 12:56:36.576187 2026] [autoindex:error] [pid 67073:tid 67259] [client 172.202.39.151:42152] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-admin/css/colors/midnight/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:36.588377 2026] [security2:error] [pid 67073:tid 67295] [client 40.85.222.29:12608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSAtPcmepr5_nHgLbNYmwAAAm4"]
[Tue Aug 18 12:56:36.605329 2026] [security2:error] [pid 67073:tid 67251] [client 20.151.109.219:59750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/eh.php"] [unique_id "aoSAtPcmepr5_nHgLbNYnAAAAkI"]
[Tue Aug 18 12:56:36.617458 2026] [security2:error] [pid 67073:tid 67305] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/info2.php"] [unique_id "aoSAtPcmepr5_nHgLbNYnQAAAng"]
[Tue Aug 18 12:56:36.641884 2026] [security2:error] [pid 67073:tid 67216] [client 135.225.75.187:24670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/txets.php"] [unique_id "aoSAtPcmepr5_nHgLbNYngAAAh8"]
[Tue Aug 18 12:56:36.645586 2026] [security2:error] [pid 66623:tid 66789] [client 20.52.168.85:7857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/mini.php"] [unique_id "aoSAtNO5rbWdOArH04KLKQAAASE"]
[Tue Aug 18 12:56:36.674563 2026] [security2:error] [pid 67073:tid 67221] [client 74.7.244.23:52166] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "batlub.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSAtPcmepr5_nHgLbNYoQACJEU"]
[Tue Aug 18 12:56:36.686259 2026] [security2:error] [pid 67073:tid 67174] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/jquery.php"] [unique_id "aoSAtPcmepr5_nHgLbNYogACZmI"]
[Tue Aug 18 12:56:36.696543 2026] [security2:error] [pid 67073:tid 67232] [client 52.139.47.57:44666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/import/csv1.php"] [unique_id "aoSAtPcmepr5_nHgLbNYowAAAi8"]
[Tue Aug 18 12:56:36.715532 2026] [security2:error] [pid 67073:tid 67207] [client 172.202.39.151:42152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/tes.php"] [unique_id "aoSAtPcmepr5_nHgLbNYpAAAAhY"]
[Tue Aug 18 12:56:36.825618 2026] [security2:error] [pid 67073:tid 67290] [client 79.127.164.8:33036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/main.bak"] [unique_id "aoSAtPcmepr5_nHgLbNYpwAAAmk"], referer: https://medihub.com.br/main.bak
[Tue Aug 18 12:56:36.858357 2026] [security2:error] [pid 67073:tid 67228] [client 20.116.17.175:11259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-the.php"] [unique_id "aoSAtPcmepr5_nHgLbNYqQAAAis"]
[Tue Aug 18 12:56:36.864759 2026] [security2:error] [pid 67073:tid 67330] [client 20.65.69.59:3207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/infoinfo.php"] [unique_id "aoSAtPcmepr5_nHgLbNYqgAAApE"]
[Tue Aug 18 12:56:36.888147 2026] [security2:error] [pid 66623:tid 66790] [client 40.85.222.29:13265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSAtNO5rbWdOArH04KLLwAAASI"]
[Tue Aug 18 12:56:36.888284 2026] [security2:error] [pid 67073:tid 67195] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/media-new.php"] [unique_id "aoSAtPcmepr5_nHgLbNYrQACKXc"]
[Tue Aug 18 12:56:36.901120 2026] [security2:error] [pid 67073:tid 67332] [client 158.158.74.177:16547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/server.php"] [unique_id "aoSAtPcmepr5_nHgLbNYrgAAApM"]
[Tue Aug 18 12:56:36.901179 2026] [autoindex:error] [pid 67073:tid 67264] [client 20.79.204.6:2404] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:36.902508 2026] [security2:error] [pid 67073:tid 67279] [client 20.163.43.14:4170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtPcmepr5_nHgLbNYrwAAAl4"]
[Tue Aug 18 12:56:36.903135 2026] [security2:error] [pid 67073:tid 67240] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/sx.php"] [unique_id "aoSAtPcmepr5_nHgLbNYsAAAAjc"]
[Tue Aug 18 12:56:36.971070 2026] [authz_core:error] [pid 67073:tid 67094] [remote 57.141.22.96:55994] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:36.971351 2026] [authz_core:error] [pid 67073:tid 67094] [remote 57.141.22.96:55994] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:36.977280 2026] [security2:error] [pid 66623:tid 66817] [client 20.151.109.219:24885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ad.php"] [unique_id "aoSAtNO5rbWdOArH04KLMQAAAT0"]
[Tue Aug 18 12:56:36.981260 2026] [security2:error] [pid 66623:tid 66874] [client 20.171.51.14:51793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/vm.php"] [unique_id "aoSAtNO5rbWdOArH04KLMgAAAXY"]
[Tue Aug 18 12:56:36.993563 2026] [security2:error] [pid 67073:tid 67322] [client 68.155.156.252:2275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/media.php"] [unique_id "aoSAtPcmepr5_nHgLbNYswAAAok"]
[Tue Aug 18 12:56:36.994522 2026] [security2:error] [pid 66623:tid 66794] [client 172.202.39.151:44943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/function/function.php"] [unique_id "aoSAtNO5rbWdOArH04KLMwAAASY"]
[Tue Aug 18 12:56:37.052998 2026] [security2:error] [pid 67073:tid 67212] [client 49.13.134.145:63768] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.alcorseguros.com.br"] [uri "/index.php"] [unique_id "aoSAtPcmepr5_nHgLbNYhQAAAhs"], referer: https://www.alcorseguros.com.br
[Tue Aug 18 12:56:37.062954 2026] [authz_core:error] [pid 67073:tid 67159] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:37.063215 2026] [authz_core:error] [pid 67073:tid 67159] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:37.063844 2026] [security2:error] [pid 67073:tid 67087] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSAtfcmepr5_nHgLbNYvAACfQs"]
[Tue Aug 18 12:56:37.101491 2026] [security2:error] [pid 67073:tid 67331] [client 20.79.204.6:2404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-themes.php"] [unique_id "aoSAtfcmepr5_nHgLbNYvQAAApI"]
[Tue Aug 18 12:56:37.106487 2026] [security2:error] [pid 66623:tid 66812] [client 132.196.30.78:18631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/666.php"] [unique_id "aoSAtdO5rbWdOArH04KLNQAAATg"]
[Tue Aug 18 12:56:37.158263 2026] [security2:error] [pid 67073:tid 67208] [client 20.100.169.31:38879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/chosen.php"] [unique_id "aoSAtfcmepr5_nHgLbNYvwAAAhc"]
[Tue Aug 18 12:56:37.159600 2026] [security2:error] [pid 67073:tid 67286] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/nu.php"] [unique_id "aoSAtfcmepr5_nHgLbNYwAAAAmU"]
[Tue Aug 18 12:56:37.168581 2026] [security2:error] [pid 67073:tid 67308] [client 5.31.227.224:30431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtfcmepr5_nHgLbNYwQAAAns"]
[Tue Aug 18 12:56:37.168664 2026] [security2:error] [pid 67073:tid 67308] [client 5.31.227.224:30431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtfcmepr5_nHgLbNYwQAAAns"]
[Tue Aug 18 12:56:37.172809 2026] [security2:error] [pid 67073:tid 67278] [client 40.85.222.29:13270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSAtfcmepr5_nHgLbNYwgAAAl0"]
[Tue Aug 18 12:56:37.193614 2026] [security2:error] [pid 67073:tid 67222] [client 20.215.241.237:38843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/bajah.php"] [unique_id "aoSAtfcmepr5_nHgLbNYwwAAAiU"]
[Tue Aug 18 12:56:37.198917 2026] [security2:error] [pid 67073:tid 67328] [client 172.182.200.96:14173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/rezor.php"] [unique_id "aoSAtfcmepr5_nHgLbNYxAAAAo8"]
[Tue Aug 18 12:56:37.239129 2026] [security2:error] [pid 67073:tid 67078] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSAtfcmepr5_nHgLbNYxgACKAI"]
[Tue Aug 18 12:56:37.239162 2026] [security2:error] [pid 67073:tid 67309] [client 20.163.43.14:4301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/moon.php"] [unique_id "aoSAtfcmepr5_nHgLbNYxwAAAnw"]
[Tue Aug 18 12:56:37.246143 2026] [security2:error] [pid 66623:tid 66887] [client 213.35.127.232:59656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAtdO5rbWdOArH04KLOQAAAYM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:37.255554 2026] [security2:error] [pid 67073:tid 67272] [client 20.52.168.85:8025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAtfcmepr5_nHgLbNYyAAAAlc"]
[Tue Aug 18 12:56:37.256453 2026] [security2:error] [pid 67073:tid 67265] [client 172.202.39.151:65221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-good.php"] [unique_id "aoSAtfcmepr5_nHgLbNYyQAAAlA"]
[Tue Aug 18 12:56:37.282019 2026] [security2:error] [pid 67073:tid 67306] [client 52.139.47.57:25698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/index.bak.php"] [unique_id "aoSAtfcmepr5_nHgLbNYygAAAnk"]
[Tue Aug 18 12:56:37.320023 2026] [security2:error] [pid 67073:tid 67318] [client 20.151.109.219:12897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/vd.php"] [unique_id "aoSAtfcmepr5_nHgLbNYywAAAoU"]
[Tue Aug 18 12:56:37.361079 2026] [authz_core:error] [pid 67073:tid 67161] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:37.361340 2026] [authz_core:error] [pid 67073:tid 67161] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:37.372159 2026] [security2:error] [pid 67073:tid 67283] [client 132.196.61.152:34771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/33.php"] [unique_id "aoSAtfcmepr5_nHgLbNYzwAAAmI"]
[Tue Aug 18 12:56:37.415885 2026] [security2:error] [pid 67073:tid 67083] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-admin/import.php"] [unique_id "aoSAtfcmepr5_nHgLbNY0QACVQc"]
[Tue Aug 18 12:56:37.424302 2026] [security2:error] [pid 67073:tid 67210] [client 37.40.227.74:56818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtfcmepr5_nHgLbNY0gAAAhk"]
[Tue Aug 18 12:56:37.428637 2026] [security2:error] [pid 67073:tid 67210] [client 37.40.227.74:56818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtfcmepr5_nHgLbNY0gAAAhk"]
[Tue Aug 18 12:56:37.439114 2026] [security2:error] [pid 67073:tid 67295] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ko.php"] [unique_id "aoSAtfcmepr5_nHgLbNY0wAAAm4"]
[Tue Aug 18 12:56:37.450103 2026] [security2:error] [pid 66623:tid 66876] [client 40.85.222.29:13213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSAtdO5rbWdOArH04KLPQAAAXg"]
[Tue Aug 18 12:56:37.455303 2026] [security2:error] [pid 66623:tid 66820] [client 20.65.98.162:42893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/1xmomo.php"] [unique_id "aoSAtdO5rbWdOArH04KLPgAAAUA"]
[Tue Aug 18 12:56:37.554420 2026] [security2:error] [pid 67073:tid 67207] [client 52.173.121.69:24999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSAtfcmepr5_nHgLbNY2QAAAhY"]
[Tue Aug 18 12:56:37.574252 2026] [security2:error] [pid 67073:tid 67230] [client 20.215.241.237:7275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-temp.php"] [unique_id "aoSAtfcmepr5_nHgLbNY2gAAAi0"]
[Tue Aug 18 12:56:37.590951 2026] [security2:error] [pid 67073:tid 67184] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSAtfcmepr5_nHgLbNY2wACLmw"]
[Tue Aug 18 12:56:37.595353 2026] [security2:error] [pid 67073:tid 67281] [client 135.225.75.187:9794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/fun.php"] [unique_id "aoSAtfcmepr5_nHgLbNY3AAAAmA"]
[Tue Aug 18 12:56:37.598286 2026] [security2:error] [pid 66623:tid 66889] [client 20.171.51.14:45435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/eg.php"] [unique_id "aoSAtdO5rbWdOArH04KLQAAAAYU"]
[Tue Aug 18 12:56:37.628168 2026] [security2:error] [pid 67073:tid 67280] [client 20.163.43.14:4218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/cache.php"] [unique_id "aoSAtfcmepr5_nHgLbNY3QAAAl8"]
[Tue Aug 18 12:56:37.638485 2026] [security2:error] [pid 67073:tid 67290] [client 158.23.17.4:8760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/sysinfo.php"] [unique_id "aoSAtfcmepr5_nHgLbNY3gAAAmk"]
[Tue Aug 18 12:56:37.684384 2026] [security2:error] [pid 67073:tid 67327] [client 20.151.109.219:27971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/56.php"] [unique_id "aoSAtfcmepr5_nHgLbNY4AAAAo4"]
[Tue Aug 18 12:56:37.695521 2026] [security2:error] [pid 67073:tid 67228] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/pl.php"] [unique_id "aoSAtfcmepr5_nHgLbNY4QAAAis"]
[Tue Aug 18 12:56:37.735200 2026] [security2:error] [pid 66623:tid 66780] [client 40.85.222.29:12621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSAtdO5rbWdOArH04KLRAAAARg"]
[Tue Aug 18 12:56:37.745647 2026] [security2:error] [pid 67073:tid 67130] [remote 110.249.202.88:44466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gustavofrison.com.br"] [uri "/"] [unique_id "aoSAtfcmepr5_nHgLbNY4gACKjY"]
[Tue Aug 18 12:56:37.758700 2026] [security2:error] [pid 67073:tid 67274] [client 20.79.204.6:2220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtfcmepr5_nHgLbNY4wAAAlk"]
[Tue Aug 18 12:56:37.765042 2026] [security2:error] [pid 67073:tid 67240] [client 74.248.136.165:61391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/fff.php"] [unique_id "aoSAtfcmepr5_nHgLbNY5QAAAjc"]
[Tue Aug 18 12:56:37.765236 2026] [security2:error] [pid 67073:tid 67313] [client 192.141.172.134:61213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtfcmepr5_nHgLbNY5gAAAoA"]
[Tue Aug 18 12:56:37.765351 2026] [security2:error] [pid 67073:tid 67313] [client 192.141.172.134:61213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtfcmepr5_nHgLbNY5gAAAoA"]
[Tue Aug 18 12:56:37.766327 2026] [security2:error] [pid 67073:tid 67128] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/ebs.php7"] [unique_id "aoSAtfcmepr5_nHgLbNY5wACUTQ"]
[Tue Aug 18 12:56:37.787690 2026] [security2:error] [pid 67073:tid 67307] [client 20.206.73.37:63233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAtfcmepr5_nHgLbNY6AAAAno"]
[Tue Aug 18 12:56:37.812071 2026] [autoindex:error] [pid 67073:tid 67279] [client 172.202.39.151:50239] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:37.842235 2026] [security2:error] [pid 67073:tid 67330] [client 52.139.47.57:11772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/lite.php"] [unique_id "aoSAtfcmepr5_nHgLbNY7QAAApE"]
[Tue Aug 18 12:56:37.857852 2026] [security2:error] [pid 67073:tid 67321] [client 20.52.168.85:7759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/classwithtostring.php"] [unique_id "aoSAtfcmepr5_nHgLbNY7gAAAog"]
[Tue Aug 18 12:56:37.899907 2026] [security2:error] [pid 67073:tid 67268] [client 157.20.138.62:61650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtfcmepr5_nHgLbNY7wAAAlM"]
[Tue Aug 18 12:56:37.900059 2026] [security2:error] [pid 67073:tid 67268] [client 157.20.138.62:61650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtfcmepr5_nHgLbNY7wAAAlM"]
[Tue Aug 18 12:56:37.924825 2026] [security2:error] [pid 66623:tid 66866] [client 20.116.17.175:57423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSAtdO5rbWdOArH04KLSQAAAW4"]
[Tue Aug 18 12:56:37.940695 2026] [security2:error] [pid 67073:tid 67168] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoSAtfcmepr5_nHgLbNY8QACkFw"]
[Tue Aug 18 12:56:37.949737 2026] [security2:error] [pid 67073:tid 67282] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/env.php"] [unique_id "aoSAtfcmepr5_nHgLbNY8gAAAmE"]
[Tue Aug 18 12:56:37.969118 2026] [authz_core:error] [pid 67073:tid 67183] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:37.969577 2026] [authz_core:error] [pid 67073:tid 67183] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:38.000237 2026] [security2:error] [pid 66623:tid 66766] [client 132.196.30.78:21850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/ws54.php"] [unique_id "aoSAtdO5rbWdOArH04KLTAAAAQo"]
[Tue Aug 18 12:56:38.023984 2026] [security2:error] [pid 67073:tid 67249] [client 20.151.109.219:17571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/rx.php"] [unique_id "aoSAtvcmepr5_nHgLbNY-QAAAkA"]
[Tue Aug 18 12:56:38.043071 2026] [security2:error] [pid 67073:tid 67222] [client 40.85.222.29:13262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSAtvcmepr5_nHgLbNY_QAAAiU"]
[Tue Aug 18 12:56:38.078583 2026] [security2:error] [pid 67073:tid 67309] [client 20.186.30.159:8442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/akismet.php"] [unique_id "aoSAtvcmepr5_nHgLbNY_gAAAnw"]
[Tue Aug 18 12:56:38.099804 2026] [security2:error] [pid 66623:tid 66822] [client 20.215.241.237:54509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAttO5rbWdOArH04KLTgAAAUI"]
[Tue Aug 18 12:56:38.104666 2026] [security2:error] [pid 66623:tid 66773] [client 20.171.51.14:30913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/uk.php"] [unique_id "aoSAttO5rbWdOArH04KLTwAAARE"]
[Tue Aug 18 12:56:38.115117 2026] [security2:error] [pid 67073:tid 67076] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSAtvcmepr5_nHgLbNY_wACIwA"]
[Tue Aug 18 12:56:38.148978 2026] [security2:error] [pid 67073:tid 67229] [client 104.209.144.33:21426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSAtvcmepr5_nHgLbNZAgAAAiw"]
[Tue Aug 18 12:56:38.172015 2026] [security2:error] [pid 67073:tid 67296] [client 20.65.69.59:3203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/c99shell.php"] [unique_id "aoSAtvcmepr5_nHgLbNZBAAAAm8"]
[Tue Aug 18 12:56:38.211766 2026] [autoindex:error] [pid 67073:tid 67265] [client 172.202.39.151:50239] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-admin/css/colors/midnight/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:38.212021 2026] [security2:error] [pid 67073:tid 67311] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/mz.php"] [unique_id "aoSAtvcmepr5_nHgLbNZBgAAAn4"]
[Tue Aug 18 12:56:38.239121 2026] [security2:error] [pid 67073:tid 67285] [client 158.158.34.183:35103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "aoSAtvcmepr5_nHgLbNZBwAAAmQ"]
[Tue Aug 18 12:56:38.242714 2026] [security2:error] [pid 67073:tid 67246] [client 68.155.154.236:16241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSAtvcmepr5_nHgLbNZCAAAAj0"]
[Tue Aug 18 12:56:38.251183 2026] [security2:error] [pid 66623:tid 66819] [client 135.225.75.187:24648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/jq.php"] [unique_id "aoSAttO5rbWdOArH04KLVAAAAT8"]
[Tue Aug 18 12:56:38.261367 2026] [security2:error] [pid 67073:tid 67299] [client 213.35.127.232:59876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAtvcmepr5_nHgLbNZCgAAAnI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:38.290246 2026] [security2:error] [pid 67073:tid 67096] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/lite.php"] [unique_id "aoSAtvcmepr5_nHgLbNZCwACbRQ"]
[Tue Aug 18 12:56:38.321628 2026] [security2:error] [pid 67073:tid 67237] [client 40.85.222.29:13269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSAtvcmepr5_nHgLbNZDAAAAjQ"]
[Tue Aug 18 12:56:38.335489 2026] [security2:error] [pid 66623:tid 66806] [client 20.151.109.219:53185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/mandrill.php"] [unique_id "aoSAttO5rbWdOArH04KLVgAAATI"]
[Tue Aug 18 12:56:38.335939 2026] [security2:error] [pid 66623:tid 66782] [client 52.139.47.57:18392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/live.php"] [unique_id "aoSAttO5rbWdOArH04KLVwAAARo"]
[Tue Aug 18 12:56:38.350814 2026] [security2:error] [pid 67073:tid 67310] [client 149.34.210.141:54231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAtvcmepr5_nHgLbNZDQAAAn0"]
[Tue Aug 18 12:56:38.414166 2026] [security2:error] [pid 67073:tid 67319] [client 158.23.17.4:38860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/ppinfo.php"] [unique_id "aoSAtvcmepr5_nHgLbNZDwAAAoY"]
[Tue Aug 18 12:56:38.421125 2026] [security2:error] [pid 67073:tid 67209] [client 172.202.39.151:50239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/tes.php"] [unique_id "aoSAtvcmepr5_nHgLbNZEAAAAhg"]
[Tue Aug 18 12:56:38.459943 2026] [security2:error] [pid 66623:tid 66772] [client 20.52.168.85:7846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/404.php"] [unique_id "aoSAttO5rbWdOArH04KLXAAAARA"]
[Tue Aug 18 12:56:38.464071 2026] [security2:error] [pid 67073:tid 67107] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSAtvcmepr5_nHgLbNZEQACVB8"]
[Tue Aug 18 12:56:38.470457 2026] [security2:error] [pid 66623:tid 66788] [client 158.158.74.177:22737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/settings.php"] [unique_id "aoSAttO5rbWdOArH04KLXQAAASA"]
[Tue Aug 18 12:56:38.519043 2026] [security2:error] [pid 66623:tid 66885] [client 20.163.43.14:4286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAttO5rbWdOArH04KLXwAAAYE"]
[Tue Aug 18 12:56:38.570588 2026] [authz_core:error] [pid 67073:tid 67192] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:38.570847 2026] [authz_core:error] [pid 67073:tid 67192] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:38.577865 2026] [security2:error] [pid 67073:tid 67292] [client 20.116.17.175:11210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/xwpg.php"] [unique_id "aoSAtvcmepr5_nHgLbNZFAAAAms"]
[Tue Aug 18 12:56:38.602856 2026] [security2:error] [pid 67073:tid 67289] [client 40.85.222.29:13261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSAtvcmepr5_nHgLbNZFQAAAmg"]
[Tue Aug 18 12:56:38.620781 2026] [security2:error] [pid 67073:tid 67221] [client 132.196.61.152:60306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/packed.php"] [unique_id "aoSAtvcmepr5_nHgLbNZFgAAAiQ"]
[Tue Aug 18 12:56:38.622706 2026] [security2:error] [pid 67073:tid 67310] [client 149.34.210.141:54231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAtvcmepr5_nHgLbNZDQAAAn0"]
[Tue Aug 18 12:56:38.637739 2026] [security2:error] [pid 67073:tid 67117] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSAtvcmepr5_nHgLbNZFwACZik"]
[Tue Aug 18 12:56:38.656994 2026] [security2:error] [pid 66623:tid 66784] [client 20.151.109.219:12893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/main.php"] [unique_id "aoSAttO5rbWdOArH04KLZAAAARw"]
[Tue Aug 18 12:56:38.664162 2026] [security2:error] [pid 66623:tid 66855] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ft.php"] [unique_id "aoSAttO5rbWdOArH04KLZQAAAWM"]
[Tue Aug 18 12:56:38.676502 2026] [security2:error] [pid 67073:tid 67244] [client 20.171.51.14:29234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/creds.php"] [unique_id "aoSAtvcmepr5_nHgLbNZGQAAAjs"]
[Tue Aug 18 12:56:38.685543 2026] [security2:error] [pid 66623:tid 66799] [client 20.215.241.237:40503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/puc.php"] [unique_id "aoSAttO5rbWdOArH04KLZgAAASs"]
[Tue Aug 18 12:56:38.813972 2026] [security2:error] [pid 67073:tid 67180] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSAtvcmepr5_nHgLbNZGwACgmg"]
[Tue Aug 18 12:56:38.847540 2026] [security2:error] [pid 66623:tid 66808] [client 20.100.169.31:48608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/alfa.php"] [unique_id "aoSAttO5rbWdOArH04KLagAAATQ"]
[Tue Aug 18 12:56:38.870984 2026] [authz_core:error] [pid 66623:tid 66758] [remote 57.141.22.2:60410] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:38.871438 2026] [authz_core:error] [pid 66623:tid 66758] [remote 57.141.22.2:60410] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:38.900133 2026] [security2:error] [pid 66623:tid 66843] [client 172.202.39.151:65230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/files/index.php"] [unique_id "aoSAttO5rbWdOArH04KLbgAAAVc"]
[Tue Aug 18 12:56:38.912527 2026] [security2:error] [pid 67073:tid 67254] [client 40.85.222.29:12632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSAtvcmepr5_nHgLbNZIgAAAkU"]
[Tue Aug 18 12:56:38.921924 2026] [security2:error] [pid 67073:tid 67327] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/h.php"] [unique_id "aoSAtvcmepr5_nHgLbNZIwAAAo4"]
[Tue Aug 18 12:56:38.974841 2026] [security2:error] [pid 67073:tid 67291] [client 132.196.30.78:19447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSAtvcmepr5_nHgLbNZJQAAAmo"]
[Tue Aug 18 12:56:38.990053 2026] [security2:error] [pid 67073:tid 67101] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAtvcmepr5_nHgLbNZJwACKRk"]
[Tue Aug 18 12:56:39.026537 2026] [security2:error] [pid 67073:tid 67332] [client 20.151.109.219:53230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ga.php"] [unique_id "aoSAt_cmepr5_nHgLbNZKAAAApM"]
[Tue Aug 18 12:56:39.046689 2026] [security2:error] [pid 66623:tid 66770] [client 74.7.175.183:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.ealoggroup.com.br"] [uri "/index.php"] [unique_id "aoSAtNO5rbWdOArH04KLKwABDhM"]
[Tue Aug 18 12:56:39.065208 2026] [security2:error] [pid 66623:tid 66856] [client 20.52.168.85:8011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/shell.php"] [unique_id "aoSAt9O5rbWdOArH04KLcwAAAWQ"]
[Tue Aug 18 12:56:39.068326 2026] [security2:error] [pid 67073:tid 67325] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtvcmepr5_nHgLbNZHgACjAk"]
[Tue Aug 18 12:56:39.075443 2026] [security2:error] [pid 67073:tid 67224] [client 74.248.136.165:22494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/66.php"] [unique_id "aoSAt_cmepr5_nHgLbNZMAAAAic"]
[Tue Aug 18 12:56:39.085408 2026] [security2:error] [pid 66623:tid 66872] [client 20.163.43.14:4223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAt9O5rbWdOArH04KLdQAAAXQ"]
[Tue Aug 18 12:56:39.103619 2026] [security2:error] [pid 67073:tid 67301] [client 158.23.17.4:9382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/globals.php"] [unique_id "aoSAt_cmepr5_nHgLbNZMwAAAnQ"]
[Tue Aug 18 12:56:39.106257 2026] [security2:error] [pid 67073:tid 67218] [client 68.155.156.252:35701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/admin.php"] [unique_id "aoSAt_cmepr5_nHgLbNZNAAAAiE"]
[Tue Aug 18 12:56:39.161913 2026] [security2:error] [pid 67073:tid 67250] [client 52.139.47.57:25683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/bypass.php"] [unique_id "aoSAt_cmepr5_nHgLbNZNQAAAkE"]
[Tue Aug 18 12:56:39.165985 2026] [security2:error] [pid 67073:tid 67188] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoSAt_cmepr5_nHgLbNZNwACTXA"]
[Tue Aug 18 12:56:39.172517 2026] [authz_core:error] [pid 67073:tid 67201] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:39.172971 2026] [authz_core:error] [pid 67073:tid 67201] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:39.185135 2026] [security2:error] [pid 66623:tid 66826] [client 20.116.17.175:57444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/dex.php"] [unique_id "aoSAt9O5rbWdOArH04KLeAAAAUY"]
[Tue Aug 18 12:56:39.186220 2026] [security2:error] [pid 66623:tid 66859] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/40.php"] [unique_id "aoSAt9O5rbWdOArH04KLeQAAAWc"]
[Tue Aug 18 12:56:39.199566 2026] [security2:error] [pid 66623:tid 66893] [client 40.85.222.29:13201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSAt9O5rbWdOArH04KLegAAAYk"]
[Tue Aug 18 12:56:39.271921 2026] [security2:error] [pid 67073:tid 67242] [client 213.35.127.232:60099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAt_cmepr5_nHgLbNZOQAAAjk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:39.336175 2026] [security2:error] [pid 66623:tid 66760] [remote 47.89.174.181:63882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.dealencastroconyvidal.com.br"] [uri "/.env"] [unique_id "aoSAt9O5rbWdOArH04KLfQABF3s"]
[Tue Aug 18 12:56:39.365160 2026] [security2:error] [pid 66623:tid 66783] [client 20.151.109.219:24848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/wb.php"] [unique_id "aoSAt9O5rbWdOArH04KLfwAAARs"]
[Tue Aug 18 12:56:39.382328 2026] [security2:error] [pid 66623:tid 66873] [client 172.202.39.151:55465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAt9O5rbWdOArH04KLgAAAAXU"]
[Tue Aug 18 12:56:39.392697 2026] [autoindex:error] [pid 67073:tid 67139] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/jgbdominio/public_html/wp-admin/css/colors/ocean/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:39.397053 2026] [security2:error] [pid 67073:tid 67286] [client 52.173.121.69:25010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAt_cmepr5_nHgLbNZPAAAAmU"]
[Tue Aug 18 12:56:39.416936 2026] [security2:error] [pid 67073:tid 67222] [client 20.65.69.59:3667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/profiler.php"] [unique_id "aoSAt_cmepr5_nHgLbNZPgAAAiU"]
[Tue Aug 18 12:56:39.422515 2026] [security2:error] [pid 67073:tid 67219] [client 20.215.241.237:43620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/8.php"] [unique_id "aoSAt_cmepr5_nHgLbNZPwAAAiI"]
[Tue Aug 18 12:56:39.443739 2026] [security2:error] [pid 67073:tid 67303] [client 20.171.51.14:29235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ho.php"] [unique_id "aoSAt_cmepr5_nHgLbNZQAAAAnY"]
[Tue Aug 18 12:56:39.446919 2026] [security2:error] [pid 66623:tid 66801] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ee.php"] [unique_id "aoSAt9O5rbWdOArH04KLggAAAS0"]
[Tue Aug 18 12:56:39.449399 2026] [security2:error] [pid 67073:tid 67328] [client 20.163.43.14:4251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/o.php"] [unique_id "aoSAt_cmepr5_nHgLbNZQQAAAo8"]
[Tue Aug 18 12:56:39.450293 2026] [security2:error] [pid 66623:tid 66818] [client 20.215.241.237:31601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/222.php"] [unique_id "aoSAt9O5rbWdOArH04KLgwAAAT4"]
[Tue Aug 18 12:56:39.452925 2026] [security2:error] [pid 66623:tid 66767] [client 178.153.171.161:11914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAt9O5rbWdOArH04KLhAAAAQs"]
[Tue Aug 18 12:56:39.453015 2026] [security2:error] [pid 66623:tid 66767] [client 178.153.171.161:11914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAt9O5rbWdOArH04KLhAAAAQs"]
[Tue Aug 18 12:56:39.471642 2026] [authz_core:error] [pid 67073:tid 67166] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:39.471916 2026] [authz_core:error] [pid 67073:tid 67166] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:39.477356 2026] [security2:error] [pid 66623:tid 66789] [client 40.85.222.29:13288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSAt9O5rbWdOArH04KLhQAAASE"]
[Tue Aug 18 12:56:39.561992 2026] [security2:error] [pid 67073:tid 67211] [client 132.196.30.78:18766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/function/function.php"] [unique_id "aoSAt_cmepr5_nHgLbNZQwAAAho"]
[Tue Aug 18 12:56:39.563632 2026] [security2:error] [pid 67073:tid 67272] [client 135.225.75.187:19089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/sys.php"] [unique_id "aoSAt_cmepr5_nHgLbNZRAAAAlc"]
[Tue Aug 18 12:56:39.571920 2026] [security2:error] [pid 67073:tid 67163] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/ku.php"] [unique_id "aoSAt_cmepr5_nHgLbNZRQACeVc"]
[Tue Aug 18 12:56:39.720705 2026] [security2:error] [pid 66623:tid 66785] [client 20.151.109.219:64147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/xn.php"] [unique_id "aoSAt9O5rbWdOArH04KLiwAAAR0"]
[Tue Aug 18 12:56:39.724512 2026] [security2:error] [pid 66623:tid 66892] [client 158.158.74.177:16539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/sf.php"] [unique_id "aoSAt9O5rbWdOArH04KLjAAAAYg"]
[Tue Aug 18 12:56:39.724850 2026] [security2:error] [pid 66623:tid 66812] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ak.php"] [unique_id "aoSAt9O5rbWdOArH04KLjQAAATg"]
[Tue Aug 18 12:56:39.755391 2026] [security2:error] [pid 66623:tid 66807] [client 20.116.17.175:57415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/xyn.php"] [unique_id "aoSAt9O5rbWdOArH04KLjgAAATM"]
[Tue Aug 18 12:56:39.774414 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:39.774884 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:39.793030 2026] [security2:error] [pid 67073:tid 67210] [client 20.163.43.14:4345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/bb.php"] [unique_id "aoSAt_cmepr5_nHgLbNZUQAAAhk"]
[Tue Aug 18 12:56:39.801710 2026] [autoindex:error] [pid 67073:tid 67176] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/jgbdominio/public_html/wp-admin/css/colors/light/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:39.818660 2026] [security2:error] [pid 67073:tid 67261] [client 40.85.222.29:13263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSAt_cmepr5_nHgLbNZUgAAAkw"]
[Tue Aug 18 12:56:39.819201 2026] [security2:error] [pid 67073:tid 67281] [client 158.158.34.183:55825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/php.php"] [unique_id "aoSAt_cmepr5_nHgLbNZUwAAAmA"]
[Tue Aug 18 12:56:39.856339 2026] [security2:error] [pid 67073:tid 67209] [client 158.23.17.4:63986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/yindu.php"] [unique_id "aoSAt_cmepr5_nHgLbNZVQAAAhg"]
[Tue Aug 18 12:56:39.887048 2026] [security2:error] [pid 67073:tid 67260] [client 20.215.241.237:44765] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.borestebombordo.com.br"] [uri "/1.php"] [unique_id "aoSAt_cmepr5_nHgLbNZVwAAAks"]
[Tue Aug 18 12:56:39.887150 2026] [security2:error] [pid 67073:tid 67260] [client 20.215.241.237:44765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/1.php"] [unique_id "aoSAt_cmepr5_nHgLbNZVwAAAks"]
[Tue Aug 18 12:56:39.887975 2026] [security2:error] [pid 66623:tid 66876] [client 20.52.168.85:7818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/file.php"] [unique_id "aoSAt9O5rbWdOArH04KLkgAAAXg"]
[Tue Aug 18 12:56:39.917293 2026] [security2:error] [pid 67073:tid 67295] [client 52.139.47.57:16687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/lock360.php"] [unique_id "aoSAt_cmepr5_nHgLbNZWAAAAm4"]
[Tue Aug 18 12:56:39.978482 2026] [security2:error] [pid 67073:tid 67090] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/chosen.php"] [unique_id "aoSAt_cmepr5_nHgLbNZXAACaw4"]
[Tue Aug 18 12:56:40.004794 2026] [security2:error] [pid 66623:tid 66805] [client 172.202.39.151:28973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/files/index.php"] [unique_id "aoSAuNO5rbWdOArH04KLlQAAATE"]
[Tue Aug 18 12:56:40.025801 2026] [security2:error] [pid 67073:tid 67221] [client 20.206.73.37:20716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAuPcmepr5_nHgLbNZXwAAAiQ"]
[Tue Aug 18 12:56:40.027236 2026] [security2:error] [pid 66623:tid 66875] [client 20.171.51.14:36419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/97.php"] [unique_id "aoSAuNO5rbWdOArH04KLlgAAAXc"]
[Tue Aug 18 12:56:40.036953 2026] [security2:error] [pid 66623:tid 66888] [client 20.151.109.219:12918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/47.php"] [unique_id "aoSAuNO5rbWdOArH04KLlwAAAYQ"]
[Tue Aug 18 12:56:40.051168 2026] [security2:error] [pid 67073:tid 67287] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/test_info.php"] [unique_id "aoSAuPcmepr5_nHgLbNZYQAAAmY"]
[Tue Aug 18 12:56:40.065800 2026] [security2:error] [pid 67073:tid 67244] [client 172.202.39.151:50194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAuPcmepr5_nHgLbNZYgAAAjs"]
[Tue Aug 18 12:56:40.143861 2026] [security2:error] [pid 67073:tid 67278] [client 132.196.30.78:19399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/nw.php"] [unique_id "aoSAuPcmepr5_nHgLbNZZgAAAl0"]
[Tue Aug 18 12:56:40.153285 2026] [security2:error] [pid 67073:tid 67119] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/asd.php"] [unique_id "aoSAuPcmepr5_nHgLbNZZwACaSs"]
[Tue Aug 18 12:56:40.159503 2026] [security2:error] [pid 67073:tid 67271] [client 20.163.43.14:4295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSAuPcmepr5_nHgLbNZaAAAAlY"]
[Tue Aug 18 12:56:40.160166 2026] [security2:error] [pid 67073:tid 67238] [client 40.85.222.29:13307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSAuPcmepr5_nHgLbNZaQAAAjU"]
[Tue Aug 18 12:56:40.185702 2026] [security2:error] [pid 66623:tid 66842] [client 20.65.69.59:57066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/findes.php"] [unique_id "aoSAuNO5rbWdOArH04KLmgAAAVY"]
[Tue Aug 18 12:56:40.198079 2026] [security2:error] [pid 67073:tid 67239] [client 20.116.17.175:11236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAuPcmepr5_nHgLbNZawAAAjY"]
[Tue Aug 18 12:56:40.262766 2026] [security2:error] [pid 67073:tid 67311] [client 114.5.214.109:49811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAuPcmepr5_nHgLbNZbQAAAn4"]
[Tue Aug 18 12:56:40.275295 2026] [security2:error] [pid 67073:tid 67311] [client 114.5.214.109:49811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAuPcmepr5_nHgLbNZbQAAAn4"]
[Tue Aug 18 12:56:40.290998 2026] [security2:error] [pid 66623:tid 66877] [client 213.35.127.232:60320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAuNO5rbWdOArH04KLnAAAAXk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:40.311001 2026] [security2:error] [pid 66623:tid 66854] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/14.php"] [unique_id "aoSAuNO5rbWdOArH04KLnQAAAWI"]
[Tue Aug 18 12:56:40.327518 2026] [security2:error] [pid 67073:tid 67152] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/akc.php"] [unique_id "aoSAuPcmepr5_nHgLbNZegACWUw"]
[Tue Aug 18 12:56:40.375263 2026] [authz_core:error] [pid 67073:tid 67172] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:40.375532 2026] [authz_core:error] [pid 67073:tid 67172] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:40.380324 2026] [security2:error] [pid 67073:tid 67224] [client 20.151.109.219:64189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/payout.php"] [unique_id "aoSAuPcmepr5_nHgLbNZgQAAAic"]
[Tue Aug 18 12:56:40.396490 2026] [security2:error] [pid 67073:tid 67301] [client 158.23.17.4:38892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/sxx.php"] [unique_id "aoSAuPcmepr5_nHgLbNZggAAAnQ"]
[Tue Aug 18 12:56:40.400619 2026] [security2:error] [pid 66623:tid 66766] [client 20.215.241.237:21508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/key.php"] [unique_id "aoSAuNO5rbWdOArH04KLoQAAAQo"]
[Tue Aug 18 12:56:40.400935 2026] [security2:error] [pid 67073:tid 67218] [client 135.225.75.187:27227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/pp.php"] [unique_id "aoSAuPcmepr5_nHgLbNZgwAAAiE"]
[Tue Aug 18 12:56:40.418841 2026] [security2:error] [pid 66623:tid 66813] [client 85.154.68.202:51474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAuNO5rbWdOArH04KLogAAATk"]
[Tue Aug 18 12:56:40.418968 2026] [security2:error] [pid 66623:tid 66813] [client 85.154.68.202:51474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAuNO5rbWdOArH04KLogAAATk"]
[Tue Aug 18 12:56:40.456907 2026] [security2:error] [pid 67073:tid 67279] [client 40.85.222.29:13267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSAuPcmepr5_nHgLbNZhQAAAl4"]
[Tue Aug 18 12:56:40.469356 2026] [security2:error] [pid 66623:tid 66819] [client 20.215.241.237:20003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/ajax.php"] [unique_id "aoSAuNO5rbWdOArH04KLpQAAAT8"]
[Tue Aug 18 12:56:40.491082 2026] [security2:error] [pid 67073:tid 67291] [client 20.52.168.85:7833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/222.php"] [unique_id "aoSAuPcmepr5_nHgLbNZhgAAAmo"]
[Tue Aug 18 12:56:40.501738 2026] [security2:error] [pid 67073:tid 67120] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/maintenance.php"] [unique_id "aoSAuPcmepr5_nHgLbNZiQACFSw"]
[Tue Aug 18 12:56:40.503852 2026] [security2:error] [pid 67073:tid 67277] [client 160.120.140.123:62419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAuPcmepr5_nHgLbNZigAAAlw"]
[Tue Aug 18 12:56:40.503933 2026] [security2:error] [pid 67073:tid 67277] [client 160.120.140.123:62419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAuPcmepr5_nHgLbNZigAAAlw"]
[Tue Aug 18 12:56:40.527631 2026] [security2:error] [pid 67073:tid 67332] [client 79.127.164.8:33070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/main.sql"] [unique_id "aoSAuPcmepr5_nHgLbNZjAAAApM"], referer: https://medihub.com.br/main.sql
[Tue Aug 18 12:56:40.573171 2026] [security2:error] [pid 66623:tid 66852] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/tk.php"] [unique_id "aoSAuNO5rbWdOArH04KLqAAAAWA"]
[Tue Aug 18 12:56:40.576013 2026] [security2:error] [pid 66623:tid 66788] [client 20.215.241.237:40489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/about.php"] [unique_id "aoSAuNO5rbWdOArH04KLqgAAASA"]
[Tue Aug 18 12:56:40.604232 2026] [security2:error] [pid 67073:tid 67307] [client 158.158.74.177:26175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/shell.php"] [unique_id "aoSAuPcmepr5_nHgLbNZkAAAAno"]
[Tue Aug 18 12:56:40.620571 2026] [security2:error] [pid 66623:tid 66885] [client 20.171.51.14:51795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/rh.php"] [unique_id "aoSAuNO5rbWdOArH04KLrAAAAYE"]
[Tue Aug 18 12:56:40.675709 2026] [security2:error] [pid 67073:tid 67149] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/options-writing.php"] [unique_id "aoSAuPcmepr5_nHgLbNZkwACZUk"]
[Tue Aug 18 12:56:40.676398 2026] [authz_core:error] [pid 67073:tid 67098] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:40.676665 2026] [authz_core:error] [pid 67073:tid 67098] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:40.681569 2026] [security2:error] [pid 67073:tid 67249] [client 20.163.43.14:4125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSAuPcmepr5_nHgLbNZlAAAAkA"]
[Tue Aug 18 12:56:40.694645 2026] [security2:error] [pid 67073:tid 67303] [client 20.151.109.219:46527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/bh.php"] [unique_id "aoSAuPcmepr5_nHgLbNZlQAAAnY"]
[Tue Aug 18 12:56:40.733448 2026] [security2:error] [pid 67073:tid 67316] [client 40.85.222.29:13233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSAuPcmepr5_nHgLbNZlgAAAoM"]
[Tue Aug 18 12:56:40.760153 2026] [security2:error] [pid 66623:tid 66865] [client 20.116.17.175:11250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-good.php"] [unique_id "aoSAuNO5rbWdOArH04KLsgAAAW0"]
[Tue Aug 18 12:56:40.834632 2026] [security2:error] [pid 67073:tid 67272] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/hp.php"] [unique_id "aoSAuPcmepr5_nHgLbNZmQAAAlc"]
[Tue Aug 18 12:56:40.850685 2026] [security2:error] [pid 67073:tid 67100] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSAuPcmepr5_nHgLbNZmwACJhg"]
[Tue Aug 18 12:56:40.887179 2026] [security2:error] [pid 67073:tid 67282] [client 158.23.17.4:63648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/settings.php"] [unique_id "aoSAuPcmepr5_nHgLbNZnQAAAmE"]
[Tue Aug 18 12:56:40.892848 2026] [security2:error] [pid 67073:tid 67317] [client 20.102.65.165:8202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAuPcmepr5_nHgLbNZnwAAAoQ"]
[Tue Aug 18 12:56:40.961592 2026] [security2:error] [pid 67073:tid 67265] [client 135.225.75.187:58350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wqqs.php"] [unique_id "aoSAuPcmepr5_nHgLbNZswAAAlA"]
[Tue Aug 18 12:56:40.975896 2026] [security2:error] [pid 67073:tid 67295] [client 20.151.109.219:59714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ct.php"] [unique_id "aoSAuPcmepr5_nHgLbNZuQAAAm4"]
[Tue Aug 18 12:56:40.979560 2026] [authz_core:error] [pid 67073:tid 67178] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:40.979989 2026] [authz_core:error] [pid 67073:tid 67178] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:40.998779 2026] [ssl:error] [pid 67073:tid 67126] [remote 46.34.225.192:10695] AH02032: Hostname ondaseventos.com provided via SNI and hostname en.ondaseventos.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue Aug 18 12:56:41.002605 2026] [security2:error] [pid 67073:tid 67287] [client 74.248.136.165:61431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/g.php"] [unique_id "aoSAufcmepr5_nHgLbNZvwAAAmY"]
[Tue Aug 18 12:56:41.020552 2026] [security2:error] [pid 67073:tid 67230] [client 20.163.43.14:4208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAufcmepr5_nHgLbNZwAAAAi0"]
[Tue Aug 18 12:56:41.025333 2026] [security2:error] [pid 67073:tid 67079] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/maint.php"] [unique_id "aoSAufcmepr5_nHgLbNZwQACLgM"]
[Tue Aug 18 12:56:41.033264 2026] [security2:error] [pid 66623:tid 66800] [client 40.85.222.29:13309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSAudO5rbWdOArH04KLuAAAASw"]
[Tue Aug 18 12:56:41.060455 2026] [security2:error] [pid 66623:tid 66808] [client 52.139.47.57:18376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/majalahpro-core/lib/index.php"] [unique_id "aoSAudO5rbWdOArH04KLuQAAATQ"]
[Tue Aug 18 12:56:41.062305 2026] [security2:error] [pid 67073:tid 67271] [client 158.158.34.183:23142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-includes/wp-class.php"] [unique_id "aoSAufcmepr5_nHgLbNZxAAAAlY"]
[Tue Aug 18 12:56:41.098477 2026] [security2:error] [pid 67073:tid 67276] [client 20.52.168.85:8010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-content/admin.php"] [unique_id "aoSAufcmepr5_nHgLbNZxwAAAls"]
[Tue Aug 18 12:56:41.101535 2026] [security2:error] [pid 66623:tid 66882] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/wx.php"] [unique_id "aoSAudO5rbWdOArH04KLuwAAAX4"]
[Tue Aug 18 12:56:41.104688 2026] [security2:error] [pid 67073:tid 67254] [client 20.65.69.59:57060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/fedora.php"] [unique_id "aoSAufcmepr5_nHgLbNZyAAAAkU"]
[Tue Aug 18 12:56:41.130620 2026] [security2:error] [pid 67073:tid 67258] [client 20.102.65.165:8265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAufcmepr5_nHgLbNZygAAAkk"]
[Tue Aug 18 12:56:41.168119 2026] [security2:error] [pid 67073:tid 67232] [client 20.186.30.159:13656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/admin.php"] [unique_id "aoSAufcmepr5_nHgLbNZzAAAAi8"]
[Tue Aug 18 12:56:41.179425 2026] [security2:error] [pid 66623:tid 66843] [client 52.139.47.57:9062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/hplfuns.php"] [unique_id "aoSAudO5rbWdOArH04KLvQAAAVc"]
[Tue Aug 18 12:56:41.200755 2026] [security2:error] [pid 67073:tid 67161] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/phpMailer.php"] [unique_id "aoSAufcmepr5_nHgLbNZzgACJ1U"]
[Tue Aug 18 12:56:41.248081 2026] [security2:error] [pid 66623:tid 66868] [client 20.215.241.237:54952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/admin.php"] [unique_id "aoSAudO5rbWdOArH04KLvgAAAXA"]
[Tue Aug 18 12:56:41.271789 2026] [security2:error] [pid 67073:tid 67243] [client 172.202.39.151:65253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAufcmepr5_nHgLbNZ0wAAAjo"]
[Tue Aug 18 12:56:41.278600 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:41.278888 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:41.302356 2026] [security2:error] [pid 67073:tid 67279] [client 20.151.109.219:12908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gy.php"] [unique_id "aoSAufcmepr5_nHgLbNZ1AAAAl4"]
[Tue Aug 18 12:56:41.316726 2026] [security2:error] [pid 67073:tid 67284] [client 213.35.127.232:60540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAufcmepr5_nHgLbNZ1QAAAmM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:41.328537 2026] [security2:error] [pid 67073:tid 67256] [client 40.85.222.29:13293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSAufcmepr5_nHgLbNZ1gAAAkc"]
[Tue Aug 18 12:56:41.329769 2026] [security2:error] [pid 67073:tid 67131] [remote 162.214.96.231:49218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "humanitics.com.br"] [uri "/wp-login.php"] [unique_id "aoSAufcmepr5_nHgLbNZ1wACMjc"]
[Tue Aug 18 12:56:41.349814 2026] [security2:error] [pid 67073:tid 67206] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/dj.php"] [unique_id "aoSAufcmepr5_nHgLbNZ2gAAAhU"]
[Tue Aug 18 12:56:41.352684 2026] [security2:error] [pid 66623:tid 66871] [client 20.116.17.175:57422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wmore1.php"] [unique_id "aoSAudO5rbWdOArH04KLwAAAAXM"]
[Tue Aug 18 12:56:41.354775 2026] [security2:error] [pid 67073:tid 67330] [client 20.29.77.16:52742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/styles.php"] [unique_id "aoSAufcmepr5_nHgLbNZ2wAAApE"]
[Tue Aug 18 12:56:41.355920 2026] [security2:error] [pid 67073:tid 67277] [client 20.163.43.14:4283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/file.php"] [unique_id "aoSAufcmepr5_nHgLbNZ3AAAAlw"]
[Tue Aug 18 12:56:41.374986 2026] [security2:error] [pid 67073:tid 67110] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSAufcmepr5_nHgLbNZ3QACcCI"]
[Tue Aug 18 12:56:41.391267 2026] [security2:error] [pid 67073:tid 67312] [client 20.102.65.165:8267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/media.php"] [unique_id "aoSAufcmepr5_nHgLbNZ3gAAAn8"]
[Tue Aug 18 12:56:41.441091 2026] [security2:error] [pid 67073:tid 67242] [client 158.23.17.4:63942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/spip.php"] [unique_id "aoSAufcmepr5_nHgLbNZ4AAAAjk"]
[Tue Aug 18 12:56:41.454228 2026] [security2:error] [pid 67073:tid 67097] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAufcmepr5_nHgLbNZ4gACMRU"]
[Tue Aug 18 12:56:41.454424 2026] [security2:error] [pid 67073:tid 67234] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAufcmepr5_nHgLbNZ4gACMRU"]
[Tue Aug 18 12:56:41.519695 2026] [security2:error] [pid 67073:tid 67308] [client 68.155.154.236:16211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/rezor.php"] [unique_id "aoSAufcmepr5_nHgLbNZ5QAAAns"]
[Tue Aug 18 12:56:41.549899 2026] [security2:error] [pid 67073:tid 67140] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/al.php"] [unique_id "aoSAufcmepr5_nHgLbNZ6AACQUA"]
[Tue Aug 18 12:56:41.582885 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:41.583149 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:41.603737 2026] [security2:error] [pid 66623:tid 66771] [client 135.225.75.187:24688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/clasa99.php"] [unique_id "aoSAudO5rbWdOArH04KLxQAAAQ8"]
[Tue Aug 18 12:56:41.605423 2026] [security2:error] [pid 66623:tid 66829] [client 40.85.222.29:13202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSAudO5rbWdOArH04KLxgAAAUk"]
[Tue Aug 18 12:56:41.613908 2026] [security2:error] [pid 66623:tid 66884] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/fa.php"] [unique_id "aoSAudO5rbWdOArH04KLxwAAAYA"]
[Tue Aug 18 12:56:41.615998 2026] [security2:error] [pid 66623:tid 66826] [client 20.151.109.219:17561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/tt.php"] [unique_id "aoSAudO5rbWdOArH04KLyAAAAUY"]
[Tue Aug 18 12:56:41.628911 2026] [security2:error] [pid 67073:tid 67272] [client 20.102.65.165:8211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/admin.php"] [unique_id "aoSAufcmepr5_nHgLbNZ6wAAAlc"]
[Tue Aug 18 12:56:41.685149 2026] [security2:error] [pid 67073:tid 67296] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAufcmepr5_nHgLbNZ7AACbwE"]
[Tue Aug 18 12:56:41.704785 2026] [security2:error] [pid 67073:tid 67307] [client 52.139.47.57:18424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/hosty.php"] [unique_id "aoSAufcmepr5_nHgLbNZ8AAAAno"]
[Tue Aug 18 12:56:41.704790 2026] [security2:error] [pid 67073:tid 67222] [client 20.52.168.85:7859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-admin/a.php"] [unique_id "aoSAufcmepr5_nHgLbNZ7wAAAiU"]
[Tue Aug 18 12:56:41.714232 2026] [security2:error] [pid 67073:tid 67267] [client 20.163.43.14:4135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/epinyins.php"] [unique_id "aoSAufcmepr5_nHgLbNZ8QAAAlI"]
[Tue Aug 18 12:56:41.726616 2026] [security2:error] [pid 67073:tid 67096] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp.php"] [unique_id "aoSAufcmepr5_nHgLbNZ8gACIxQ"]
[Tue Aug 18 12:56:41.734105 2026] [security2:error] [pid 67073:tid 67324] [client 52.173.121.69:16494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSAufcmepr5_nHgLbNZ8wAAAos"]
[Tue Aug 18 12:56:41.794468 2026] [security2:error] [pid 66623:tid 66844] [client 20.171.51.14:16754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/yg.php"] [unique_id "aoSAudO5rbWdOArH04KLzQAAAVg"]
[Tue Aug 18 12:56:41.819919 2026] [security2:error] [pid 66623:tid 66869] [client 20.206.73.37:59856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/img.php"] [unique_id "aoSAudO5rbWdOArH04KLzgAAAXE"]
[Tue Aug 18 12:56:41.870696 2026] [security2:error] [pid 67073:tid 67310] [client 158.23.17.4:9320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/search.php"] [unique_id "aoSAufcmepr5_nHgLbNZ9QAAAn0"]
[Tue Aug 18 12:56:41.888316 2026] [security2:error] [pid 67073:tid 67244] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/fb.php"] [unique_id "aoSAufcmepr5_nHgLbNZ9gAAAjs"]
[Tue Aug 18 12:56:41.903312 2026] [security2:error] [pid 67073:tid 67107] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-activat.php"] [unique_id "aoSAufcmepr5_nHgLbNZ9wACdx8"]
[Tue Aug 18 12:56:41.905730 2026] [security2:error] [pid 67073:tid 67231] [client 40.85.222.29:13198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSAufcmepr5_nHgLbNZ-AAAAi4"]
[Tue Aug 18 12:56:41.929016 2026] [security2:error] [pid 67073:tid 67278] [client 20.215.241.237:7250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/edit.php"] [unique_id "aoSAufcmepr5_nHgLbNZ-gAAAl0"]
[Tue Aug 18 12:56:41.934002 2026] [security2:error] [pid 66623:tid 66824] [client 132.196.30.78:21853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/xleet.php"] [unique_id "aoSAudO5rbWdOArH04KL0wAAAUQ"]
[Tue Aug 18 12:56:41.946255 2026] [security2:error] [pid 67073:tid 67290] [client 20.102.65.165:8306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/mac.php"] [unique_id "aoSAufcmepr5_nHgLbNZ_AAAAmk"]
[Tue Aug 18 12:56:41.960676 2026] [security2:error] [pid 67073:tid 67265] [client 52.139.47.57:9064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/pwnd/as.php"] [unique_id "aoSAufcmepr5_nHgLbNZ_QAAAlA"]
[Tue Aug 18 12:56:42.002395 2026] [security2:error] [pid 66623:tid 66838] [client 20.151.109.219:51684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/mq.php"] [unique_id "aoSAutO5rbWdOArH04KL1AAAAVI"]
[Tue Aug 18 12:56:42.018649 2026] [security2:error] [pid 66623:tid 66873] [client 20.65.69.59:57043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/path.php"] [unique_id "aoSAutO5rbWdOArH04KL1gAAAXU"]
[Tue Aug 18 12:56:42.023584 2026] [security2:error] [pid 66623:tid 66851] [client 157.51.166.53:62430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAutO5rbWdOArH04KL1wAAAV8"]
[Tue Aug 18 12:56:42.023763 2026] [security2:error] [pid 66623:tid 66851] [client 157.51.166.53:62430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAutO5rbWdOArH04KL1wAAAV8"]
[Tue Aug 18 12:56:42.044224 2026] [security2:error] [pid 67073:tid 67254] [client 20.163.43.14:4129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAuvcmepr5_nHgLbNZ_gAAAkU"]
[Tue Aug 18 12:56:42.067097 2026] [security2:error] [pid 67073:tid 67311] [client 20.215.241.237:60889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/chosen.php"] [unique_id "aoSAuvcmepr5_nHgLbNaAAAAAn4"]
[Tue Aug 18 12:56:42.079834 2026] [security2:error] [pid 67073:tid 67180] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSAuvcmepr5_nHgLbNaAQACSWg"]
[Tue Aug 18 12:56:42.090423 2026] [security2:error] [pid 67073:tid 67320] [client 158.158.74.177:16541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/shiny.php"] [unique_id "aoSAuvcmepr5_nHgLbNaAgAAAoc"]
[Tue Aug 18 12:56:42.131016 2026] [security2:error] [pid 67073:tid 67232] [client 104.209.144.33:34125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSAuvcmepr5_nHgLbNaBAAAAi8"]
[Tue Aug 18 12:56:42.139120 2026] [security2:error] [pid 67073:tid 67212] [client 74.7.230.53:41242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "novosite.rota85motorshop.com.br"] [uri "/index.php"] [unique_id "aoSAufcmepr5_nHgLbNZ5wACG3w"]
[Tue Aug 18 12:56:42.154219 2026] [security2:error] [pid 66623:tid 66795] [client 20.29.77.16:51358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/server.php"] [unique_id "aoSAutO5rbWdOArH04KL2wAAASc"]
[Tue Aug 18 12:56:42.161519 2026] [security2:error] [pid 66623:tid 66817] [client 74.248.136.165:55254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/x7.php"] [unique_id "aoSAutO5rbWdOArH04KL3AAAAT0"]
[Tue Aug 18 12:56:42.189970 2026] [security2:error] [pid 67073:tid 67274] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gw.php"] [unique_id "aoSAuvcmepr5_nHgLbNaBwAAAlk"]
[Tue Aug 18 12:56:42.192171 2026] [security2:error] [pid 66623:tid 66794] [client 40.85.222.29:13256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSAutO5rbWdOArH04KL3gAAASY"]
[Tue Aug 18 12:56:42.201874 2026] [security2:error] [pid 67073:tid 67240] [client 20.102.65.165:8196] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/1.php"] [unique_id "aoSAuvcmepr5_nHgLbNaCAAAAjc"]
[Tue Aug 18 12:56:42.201998 2026] [security2:error] [pid 67073:tid 67240] [client 20.102.65.165:8196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/1.php"] [unique_id "aoSAuvcmepr5_nHgLbNaCAAAAjc"]
[Tue Aug 18 12:56:42.257531 2026] [security2:error] [pid 67073:tid 67116] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/past1.php"] [unique_id "aoSAuvcmepr5_nHgLbNaCQACPig"]
[Tue Aug 18 12:56:42.284822 2026] [security2:error] [pid 67073:tid 67269] [client 52.139.47.57:47627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/t.php"] [unique_id "aoSAuvcmepr5_nHgLbNaCwAAAlQ"]
[Tue Aug 18 12:56:42.313778 2026] [security2:error] [pid 67073:tid 67229] [client 20.52.168.85:8013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-admin.php"] [unique_id "aoSAuvcmepr5_nHgLbNaDAAAAiw"]
[Tue Aug 18 12:56:42.342317 2026] [security2:error] [pid 66623:tid 66783] [client 213.35.127.232:60783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAutO5rbWdOArH04KL4QAAARs"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:42.342421 2026] [security2:error] [pid 67073:tid 67284] [client 158.23.17.4:29495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/build.php"] [unique_id "aoSAuvcmepr5_nHgLbNaDQAAAmM"]
[Tue Aug 18 12:56:42.352046 2026] [security2:error] [pid 66623:tid 66807] [client 20.151.109.219:59722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/13.php"] [unique_id "aoSAutO5rbWdOArH04KL4gAAATM"]
[Tue Aug 18 12:56:42.388457 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:42.388706 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:42.432487 2026] [security2:error] [pid 67073:tid 67101] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/file61.php"] [unique_id "aoSAuvcmepr5_nHgLbNaEgACFRk"]
[Tue Aug 18 12:56:42.443607 2026] [security2:error] [pid 67073:tid 67330] [client 20.102.65.165:8314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/coffee.php"] [unique_id "aoSAuvcmepr5_nHgLbNaEwAAApE"]
[Tue Aug 18 12:56:42.459116 2026] [security2:error] [pid 67073:tid 67277] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/sw.php"] [unique_id "aoSAuvcmepr5_nHgLbNaFAAAAlw"]
[Tue Aug 18 12:56:42.465113 2026] [security2:error] [pid 66623:tid 66837] [client 20.171.51.14:65124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/et.php"] [unique_id "aoSAutO5rbWdOArH04KL5gAAAVE"]
[Tue Aug 18 12:56:42.465548 2026] [security2:error] [pid 67073:tid 67262] [client 40.85.222.29:13192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSAuvcmepr5_nHgLbNaFQAAAk0"]
[Tue Aug 18 12:56:42.470047 2026] [security2:error] [pid 67073:tid 67241] [client 135.225.75.187:62087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/666.php"] [unique_id "aoSAuvcmepr5_nHgLbNaFgAAAjg"]
[Tue Aug 18 12:56:42.517886 2026] [security2:error] [pid 67073:tid 67213] [client 172.202.39.151:15685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSAuvcmepr5_nHgLbNaGAAAAhw"]
[Tue Aug 18 12:56:42.534631 2026] [security2:error] [pid 67073:tid 67239] [client 132.196.30.78:18797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp.php"] [unique_id "aoSAuvcmepr5_nHgLbNaGgAAAjY"]
[Tue Aug 18 12:56:42.561425 2026] [security2:error] [pid 67073:tid 67268] [client 20.163.43.14:4238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSAuvcmepr5_nHgLbNaGwAAAlM"]
[Tue Aug 18 12:56:42.613646 2026] [security2:error] [pid 67073:tid 67208] [client 20.215.241.237:44756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAuvcmepr5_nHgLbNaHQAAAhc"]
[Tue Aug 18 12:56:42.625516 2026] [security2:error] [pid 67073:tid 67286] [client 104.209.144.33:39328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/rezor.php"] [unique_id "aoSAuvcmepr5_nHgLbNaHgAAAmU"]
[Tue Aug 18 12:56:42.642550 2026] [security2:error] [pid 66623:tid 66796] [client 20.151.109.219:64638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/so.php"] [unique_id "aoSAutO5rbWdOArH04KL6AAAASg"]
[Tue Aug 18 12:56:42.682578 2026] [security2:error] [pid 67073:tid 67205] [client 20.102.65.165:8201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAuvcmepr5_nHgLbNaHwAAAhQ"]
[Tue Aug 18 12:56:42.686121 2026] [security2:error] [pid 67073:tid 67329] [client 20.116.17.175:57437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/special.php"] [unique_id "aoSAuvcmepr5_nHgLbNaIQAAApA"]
[Tue Aug 18 12:56:42.721440 2026] [security2:error] [pid 67073:tid 67272] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gc.php"] [unique_id "aoSAuvcmepr5_nHgLbNaIwAAAlc"]
[Tue Aug 18 12:56:42.722250 2026] [security2:error] [pid 67073:tid 67300] [client 158.23.17.4:29501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/defaul.php"] [unique_id "aoSAuvcmepr5_nHgLbNaJAAAAnM"]
[Tue Aug 18 12:56:42.743402 2026] [security2:error] [pid 67073:tid 67223] [client 40.85.222.29:13278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSAuvcmepr5_nHgLbNaJQAAAiY"]
[Tue Aug 18 12:56:42.937032 2026] [security2:error] [pid 67073:tid 67292] [client 20.163.43.14:4155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAuvcmepr5_nHgLbNaMwAAAms"]
[Tue Aug 18 12:56:42.938841 2026] [security2:error] [pid 67073:tid 67233] [client 74.248.136.165:28155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/god.php"] [unique_id "aoSAuvcmepr5_nHgLbNaNAAAAjA"]
[Tue Aug 18 12:56:42.948908 2026] [security2:error] [pid 66623:tid 66805] [client 20.102.65.165:8301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSAutO5rbWdOArH04KL_QAAATE"]
[Tue Aug 18 12:56:42.990321 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:42.990614 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:43.020775 2026] [security2:error] [pid 67073:tid 67230] [client 20.151.109.219:64138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/10.php"] [unique_id "aoSAu_cmepr5_nHgLbNaNgAAAi0"]
[Tue Aug 18 12:56:43.021529 2026] [security2:error] [pid 66623:tid 66889] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/uq.php"] [unique_id "aoSAu9O5rbWdOArH04KL_wAAAYU"]
[Tue Aug 18 12:56:43.046300 2026] [security2:error] [pid 67073:tid 67315] [client 20.171.51.14:59276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/of.php"] [unique_id "aoSAu_cmepr5_nHgLbNaNwAAAoI"]
[Tue Aug 18 12:56:43.051541 2026] [security2:error] [pid 66623:tid 66780] [client 172.202.39.151:36811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAu9O5rbWdOArH04KMAQAAARg"]
[Tue Aug 18 12:56:43.057484 2026] [security2:error] [pid 67073:tid 67231] [client 40.85.222.29:13210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSAu_cmepr5_nHgLbNaOQAAAi4"]
[Tue Aug 18 12:56:43.076815 2026] [security2:error] [pid 67073:tid 67134] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/license.php"] [unique_id "aoSAu_cmepr5_nHgLbNaOgACgTo"]
[Tue Aug 18 12:56:43.085609 2026] [security2:error] [pid 67073:tid 67308] [client 52.139.47.57:44622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/rk2.php"] [unique_id "aoSAu_cmepr5_nHgLbNaPAAAAns"]
[Tue Aug 18 12:56:43.095789 2026] [security2:error] [pid 67073:tid 67211] [client 20.52.168.85:8006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "aoSAuvcmepr5_nHgLbNaMQAAAho"]
[Tue Aug 18 12:56:43.096037 2026] [security2:error] [pid 67073:tid 67332] [client 158.158.34.183:64572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-admin/includes/index.php"] [unique_id "aoSAu_cmepr5_nHgLbNaPQAAApM"]
[Tue Aug 18 12:56:43.130307 2026] [security2:error] [pid 67073:tid 67237] [client 52.139.47.57:9077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/xmlrpc.php"] [unique_id "aoSAu_cmepr5_nHgLbNaPgAAAjQ"]
[Tue Aug 18 12:56:43.136677 2026] [security2:error] [pid 67073:tid 67302] [client 20.186.30.159:13580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/bajah.php"] [unique_id "aoSAu_cmepr5_nHgLbNaPwAAAnU"]
[Tue Aug 18 12:56:43.163838 2026] [security2:error] [pid 67073:tid 67254] [client 20.215.241.237:49203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/inputs.php"] [unique_id "aoSAu_cmepr5_nHgLbNaQAAAAkU"]
[Tue Aug 18 12:56:43.211454 2026] [security2:error] [pid 67073:tid 67324] [client 132.196.30.78:21844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/155.php"] [unique_id "aoSAu_cmepr5_nHgLbNaQwAAAos"]
[Tue Aug 18 12:56:43.211518 2026] [security2:error] [pid 67073:tid 67320] [client 20.102.65.165:8285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/yj09.php"] [unique_id "aoSAu_cmepr5_nHgLbNaQgAAAoc"]
[Tue Aug 18 12:56:43.214420 2026] [security2:error] [pid 67073:tid 67260] [client 20.65.69.59:3662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/456.php"] [unique_id "aoSAu_cmepr5_nHgLbNaRAAAAks"]
[Tue Aug 18 12:56:43.263648 2026] [security2:error] [pid 67073:tid 67221] [client 20.163.43.14:4268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp.php"] [unique_id "aoSAu_cmepr5_nHgLbNaSQAAAiQ"]
[Tue Aug 18 12:56:43.269651 2026] [security2:error] [pid 67073:tid 67294] [client 20.104.85.180:43558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSAu_cmepr5_nHgLbNaSgAAAm0"]
[Tue Aug 18 12:56:43.291234 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:43.291519 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:43.331218 2026] [security2:error] [pid 67073:tid 67325] [client 40.85.222.29:13250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSAu_cmepr5_nHgLbNaTQAAAow"]
[Tue Aug 18 12:56:43.356529 2026] [security2:error] [pid 67073:tid 67243] [client 135.225.75.187:29716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/thui.php"] [unique_id "aoSAu_cmepr5_nHgLbNaTgAAAjo"]
[Tue Aug 18 12:56:43.359699 2026] [security2:error] [pid 67073:tid 67304] [client 213.35.127.232:61030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAu_cmepr5_nHgLbNaTwAAAnc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:43.369044 2026] [security2:error] [pid 67073:tid 67269] [client 20.29.77.16:32974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/xinfo.php"] [unique_id "aoSAu_cmepr5_nHgLbNaUQAAAlQ"]
[Tue Aug 18 12:56:43.410448 2026] [security2:error] [pid 66623:tid 66813] [client 20.151.109.219:24894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/te.php"] [unique_id "aoSAu9O5rbWdOArH04KMCQAAATk"]
[Tue Aug 18 12:56:43.422310 2026] [security2:error] [pid 66623:tid 66793] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/32.php"] [unique_id "aoSAu9O5rbWdOArH04KMCgAAASU"]
[Tue Aug 18 12:56:43.432542 2026] [security2:error] [pid 67073:tid 67279] [client 104.209.144.33:35878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/uploads/bypass.php"] [unique_id "aoSAu_cmepr5_nHgLbNaUgAAAl4"]
[Tue Aug 18 12:56:43.446679 2026] [security2:error] [pid 67073:tid 67305] [client 158.158.74.177:16559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/sid3.php"] [unique_id "aoSAu_cmepr5_nHgLbNaUwAAAng"]
[Tue Aug 18 12:56:43.455966 2026] [security2:error] [pid 66623:tid 66773] [client 20.102.65.165:5071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/scxy.php"] [unique_id "aoSAu9O5rbWdOArH04KMCwAAARE"]
[Tue Aug 18 12:56:43.497249 2026] [security2:error] [pid 67073:tid 67166] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/web.config"] [unique_id "aoSAu_cmepr5_nHgLbNaVgACblo"]
[Tue Aug 18 12:56:43.530038 2026] [security2:error] [pid 67073:tid 67262] [client 158.23.17.4:9380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/twin.php"] [unique_id "aoSAu_cmepr5_nHgLbNaXAAAAk0"]
[Tue Aug 18 12:56:43.547926 2026] [security2:error] [pid 67073:tid 67318] [client 20.104.85.180:43550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/an.php"] [unique_id "aoSAu_cmepr5_nHgLbNaYAAAAoU"]
[Tue Aug 18 12:56:43.582110 2026] [security2:error] [pid 66623:tid 66883] [client 192.141.172.134:61513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAu9O5rbWdOArH04KMDwAAAX8"]
[Tue Aug 18 12:56:43.582217 2026] [security2:error] [pid 66623:tid 66883] [client 192.141.172.134:61513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAu9O5rbWdOArH04KMDwAAAX8"]
[Tue Aug 18 12:56:43.587438 2026] [security2:error] [pid 67073:tid 67270] [client 196.12.128.158:50996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAu_cmepr5_nHgLbNaZAAAAlU"]
[Tue Aug 18 12:56:43.587538 2026] [security2:error] [pid 67073:tid 67270] [client 196.12.128.158:50996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAu_cmepr5_nHgLbNaZAAAAlU"]
[Tue Aug 18 12:56:43.591236 2026] [authz_core:error] [pid 67073:tid 67135] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:43.591493 2026] [authz_core:error] [pid 67073:tid 67135] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:43.591858 2026] [security2:error] [pid 67073:tid 67236] [client 20.163.43.14:4211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/function/function.php"] [unique_id "aoSAu_cmepr5_nHgLbNaZQAAAjM"]
[Tue Aug 18 12:56:43.597390 2026] [security2:error] [pid 66623:tid 66822] [client 52.139.47.57:19924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/xx.php"] [unique_id "aoSAu9O5rbWdOArH04KMEAAAAUI"]
[Tue Aug 18 12:56:43.611505 2026] [security2:error] [pid 67073:tid 67245] [client 40.85.222.29:13273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSAu_cmepr5_nHgLbNaZgAAAjw"]
[Tue Aug 18 12:56:43.687051 2026] [security2:error] [pid 67073:tid 67303] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/73.php"] [unique_id "aoSAu_cmepr5_nHgLbNabAAAAnY"]
[Tue Aug 18 12:56:43.696940 2026] [security2:error] [pid 67073:tid 67330] [client 20.52.168.85:8054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/plugins.php"] [unique_id "aoSAu_cmepr5_nHgLbNacQAAApE"]
[Tue Aug 18 12:56:43.718153 2026] [security2:error] [pid 67073:tid 67293] [client 20.171.51.14:45395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/bu.php"] [unique_id "aoSAu_cmepr5_nHgLbNacgAAAmw"]
[Tue Aug 18 12:56:43.735056 2026] [security2:error] [pid 67073:tid 67272] [client 20.102.65.165:8305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSAu_cmepr5_nHgLbNadQAAAlc"]
[Tue Aug 18 12:56:43.772548 2026] [security2:error] [pid 67073:tid 67264] [client 132.196.30.78:22519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/96i.php"] [unique_id "aoSAu_cmepr5_nHgLbNaeAAAAk8"]
[Tue Aug 18 12:56:43.802038 2026] [security2:error] [pid 67073:tid 67266] [client 20.151.109.219:45755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kc.php"] [unique_id "aoSAu_cmepr5_nHgLbNaeQAAAlE"]
[Tue Aug 18 12:56:43.815817 2026] [security2:error] [pid 67073:tid 67307] [client 20.116.17.175:11238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAu_cmepr5_nHgLbNafAAAAno"]
[Tue Aug 18 12:56:43.885796 2026] [security2:error] [pid 67073:tid 67261] [client 20.215.241.237:44054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/av.php"] [unique_id "aoSAu_cmepr5_nHgLbNafgAAAkw"]
[Tue Aug 18 12:56:43.891139 2026] [security2:error] [pid 66623:tid 66803] [client 40.85.222.29:13226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSAu9O5rbWdOArH04KMOwAAAS8"]
[Tue Aug 18 12:56:43.917182 2026] [security2:error] [pid 67073:tid 67216] [client 20.163.43.14:4139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSAu_cmepr5_nHgLbNagAAAAh8"]
[Tue Aug 18 12:56:43.947892 2026] [security2:error] [pid 66623:tid 66799] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ib.php"] [unique_id "aoSAu9O5rbWdOArH04KMRAAAASs"]
[Tue Aug 18 12:56:43.993157 2026] [security2:error] [pid 67073:tid 67332] [client 74.248.136.165:17993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ebahvhhh.php"] [unique_id "aoSAu_cmepr5_nHgLbNaggAAApM"]
[Tue Aug 18 12:56:44.017108 2026] [security2:error] [pid 67073:tid 67265] [client 20.102.65.165:8274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAvPcmepr5_nHgLbNahAAAAlA"]
[Tue Aug 18 12:56:44.035620 2026] [security2:error] [pid 67073:tid 67220] [client 52.139.47.57:19926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/storage/rip.php"] [unique_id "aoSAvPcmepr5_nHgLbNahQAAAiM"]
[Tue Aug 18 12:56:44.072623 2026] [security2:error] [pid 67073:tid 67260] [client 20.29.77.16:33023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/sym.php"] [unique_id "aoSAvPcmepr5_nHgLbNajAAAAks"]
[Tue Aug 18 12:56:44.111636 2026] [security2:error] [pid 67073:tid 67273] [client 20.100.169.31:7965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAvPcmepr5_nHgLbNajgAAAlg"]
[Tue Aug 18 12:56:44.113319 2026] [security2:error] [pid 67073:tid 67271] [client 20.151.109.219:64172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/jn.php"] [unique_id "aoSAvPcmepr5_nHgLbNajwAAAlY"]
[Tue Aug 18 12:56:44.114251 2026] [security2:error] [pid 66623:tid 66781] [client 20.215.241.237:49599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAvNO5rbWdOArH04KMRgAAARk"]
[Tue Aug 18 12:56:44.167610 2026] [security2:error] [pid 67073:tid 67226] [client 40.85.222.29:13204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSAvPcmepr5_nHgLbNakgAAAik"]
[Tue Aug 18 12:56:44.238054 2026] [security2:error] [pid 67073:tid 67321] [client 52.139.47.57:42965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/zwso.php"] [unique_id "aoSAvPcmepr5_nHgLbNalgAAAog"]
[Tue Aug 18 12:56:44.246212 2026] [security2:error] [pid 66623:tid 66847] [client 20.163.43.14:4270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSAvNO5rbWdOArH04KMSgAAAVs"]
[Tue Aug 18 12:56:44.253122 2026] [security2:error] [pid 67073:tid 67269] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/xm.php"] [unique_id "aoSAvPcmepr5_nHgLbNalwAAAlQ"]
[Tue Aug 18 12:56:44.263277 2026] [security2:error] [pid 66623:tid 66867] [client 20.100.169.31:22808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/edit.php"] [unique_id "aoSAvNO5rbWdOArH04KMSwAAAW8"]
[Tue Aug 18 12:56:44.294650 2026] [security2:error] [pid 67073:tid 67248] [client 20.186.30.159:13647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/ajax.php"] [unique_id "aoSAvPcmepr5_nHgLbNanAAAAj8"]
[Tue Aug 18 12:56:44.310537 2026] [security2:error] [pid 67073:tid 67305] [client 20.102.65.165:8317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/blurbs.php"] [unique_id "aoSAvPcmepr5_nHgLbNaoAAAAng"]
[Tue Aug 18 12:56:44.356201 2026] [security2:error] [pid 67073:tid 67218] [client 135.225.75.187:19100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/agg.php"] [unique_id "aoSAvPcmepr5_nHgLbNapgAAAiE"]
[Tue Aug 18 12:56:44.365870 2026] [ssl:error] [pid 67073:tid 67158] [remote 46.34.225.192:10695] AH02032: Hostname ondaseventos.com provided via SNI and hostname en.ondaseventos.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue Aug 18 12:56:44.369181 2026] [security2:error] [pid 67073:tid 67295] [client 20.215.241.237:54943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAvPcmepr5_nHgLbNaqAAAAm4"]
[Tue Aug 18 12:56:44.374523 2026] [security2:error] [pid 66623:tid 66768] [client 213.35.127.232:61236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAvNO5rbWdOArH04KMTQAAAQw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:44.453072 2026] [security2:error] [pid 67073:tid 67242] [client 40.85.222.29:13230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSAvPcmepr5_nHgLbNaqgAAAjk"]
[Tue Aug 18 12:56:44.459351 2026] [security2:error] [pid 67073:tid 67300] [client 158.158.34.183:55849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/go.php"] [unique_id "aoSAvPcmepr5_nHgLbNaqwAAAnM"]
[Tue Aug 18 12:56:44.461365 2026] [security2:error] [pid 67073:tid 67225] [client 68.155.154.236:16341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSAvPcmepr5_nHgLbNarAAAAig"]
[Tue Aug 18 12:56:44.472241 2026] [security2:error] [pid 66623:tid 66853] [client 20.151.109.219:21633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/bf.php"] [unique_id "aoSAvNO5rbWdOArH04KMTwAAAWE"]
[Tue Aug 18 12:56:44.488179 2026] [security2:error] [pid 66623:tid 66816] [client 132.196.30.78:19394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/as.php"] [unique_id "aoSAvNO5rbWdOArH04KMUAAAATw"]
[Tue Aug 18 12:56:44.501113 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:44.501425 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:44.503949 2026] [security2:error] [pid 67073:tid 67236] [client 20.52.168.85:8001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-includes/customize/index.php"] [unique_id "aoSAvPcmepr5_nHgLbNargAAAjM"]
[Tue Aug 18 12:56:44.509519 2026] [security2:error] [pid 67073:tid 67208] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/zy.php"] [unique_id "aoSAvPcmepr5_nHgLbNarwAAAhc"]
[Tue Aug 18 12:56:44.556911 2026] [security2:error] [pid 67073:tid 67303] [client 20.116.17.175:11257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/thoms.php"] [unique_id "aoSAvPcmepr5_nHgLbNasgAAAnY"]
[Tue Aug 18 12:56:44.557984 2026] [security2:error] [pid 67073:tid 67329] [client 20.102.65.165:8272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/bajah.php"] [unique_id "aoSAvPcmepr5_nHgLbNaswAAApA"]
[Tue Aug 18 12:56:44.559088 2026] [security2:error] [pid 67073:tid 67210] [client 20.171.51.14:58372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/rn.php"] [unique_id "aoSAvPcmepr5_nHgLbNatAAAAhk"]
[Tue Aug 18 12:56:44.619257 2026] [security2:error] [pid 67073:tid 67264] [client 20.163.43.14:4104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/ok.php"] [unique_id "aoSAvPcmepr5_nHgLbNavQAAAk8"]
[Tue Aug 18 12:56:44.628991 2026] [security2:error] [pid 67073:tid 67233] [client 197.184.64.235:41932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAvPcmepr5_nHgLbNavgAAAjA"]
[Tue Aug 18 12:56:44.629092 2026] [security2:error] [pid 67073:tid 67233] [client 197.184.64.235:41932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAvPcmepr5_nHgLbNavgAAAjA"]
[Tue Aug 18 12:56:44.673211 2026] [security2:error] [pid 67073:tid 67243] [client 84.247.146.84:47384] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "i-databi.com.br"] [uri "/"] [unique_id "aoSAvPcmepr5_nHgLbNawAAAAjo"]
[Tue Aug 18 12:56:44.701496 2026] [security2:error] [pid 67073:tid 67262] [client 158.158.74.177:26112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/sid4.php"] [unique_id "aoSAvPcmepr5_nHgLbNawQAAAk0"]
[Tue Aug 18 12:56:44.720072 2026] [security2:error] [pid 67073:tid 67286] [client 20.250.13.23:13799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSAvPcmepr5_nHgLbNawgAAAmU"]
[Tue Aug 18 12:56:44.735317 2026] [security2:error] [pid 67073:tid 67312] [client 74.248.136.165:28096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/8.php"] [unique_id "aoSAvPcmepr5_nHgLbNaxAAAAn8"]
[Tue Aug 18 12:56:44.747434 2026] [security2:error] [pid 66623:tid 66862] [client 40.85.222.29:13303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSAvNO5rbWdOArH04KMXgAAAWo"]
[Tue Aug 18 12:56:44.753167 2026] [security2:error] [pid 66623:tid 66871] [client 104.209.144.33:21435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSAvNO5rbWdOArH04KMYAAAAXM"]
[Tue Aug 18 12:56:44.770519 2026] [security2:error] [pid 67073:tid 67261] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/q.php"] [unique_id "aoSAvPcmepr5_nHgLbNaxgAAAkw"]
[Tue Aug 18 12:56:44.796039 2026] [authz_core:error] [pid 67073:tid 67181] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:44.796318 2026] [authz_core:error] [pid 67073:tid 67181] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:44.806924 2026] [security2:error] [pid 67073:tid 67244] [client 20.102.65.165:8287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/domvf.php"] [unique_id "aoSAvPcmepr5_nHgLbNayQAAAjs"]
[Tue Aug 18 12:56:44.809704 2026] [security2:error] [pid 67073:tid 67126] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/frontend/.env"] [unique_id "aoSAvPcmepr5_nHgLbNaygACLTI"]
[Tue Aug 18 12:56:44.809829 2026] [security2:error] [pid 67073:tid 67079] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/src/.env"] [unique_id "aoSAvPcmepr5_nHgLbNaywACLQM"]
[Tue Aug 18 12:56:44.834280 2026] [security2:error] [pid 67073:tid 67159] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/app/.env"] [unique_id "aoSAvPcmepr5_nHgLbNazgACgVM"]
[Tue Aug 18 12:56:44.834357 2026] [security2:error] [pid 67073:tid 67094] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/dev/.env"] [unique_id "aoSAvPcmepr5_nHgLbNazQACgRI"]
[Tue Aug 18 12:56:44.834357 2026] [security2:error] [pid 67073:tid 67083] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/production/.env"] [unique_id "aoSAvPcmepr5_nHgLbNazAACgQc"]
[Tue Aug 18 12:56:44.834631 2026] [security2:error] [pid 67073:tid 67078] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/server/.env"] [unique_id "aoSAvPcmepr5_nHgLbNazwACgQI"]
[Tue Aug 18 12:56:44.849705 2026] [security2:error] [pid 67073:tid 67308] [client 158.23.17.4:29447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/new2.php"] [unique_id "aoSAvPcmepr5_nHgLbNa0AAAAns"]
[Tue Aug 18 12:56:44.852402 2026] [security2:error] [pid 67073:tid 67235] [client 52.139.47.57:18413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/tool.php"] [unique_id "aoSAvPcmepr5_nHgLbNa0QAAAjI"]
[Tue Aug 18 12:56:44.861624 2026] [security2:error] [pid 66623:tid 66884] [client 20.65.69.59:49330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/SMTP.php"] [unique_id "aoSAvNO5rbWdOArH04KMYwAAAYA"]
[Tue Aug 18 12:56:44.883945 2026] [security2:error] [pid 66623:tid 66811] [client 20.29.77.16:47761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/ye.php"] [unique_id "aoSAvNO5rbWdOArH04KMZQAAATc"]
[Tue Aug 18 12:56:44.898757 2026] [security2:error] [pid 67073:tid 67302] [client 20.215.241.237:54922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAvPcmepr5_nHgLbNa1QAAAnU"]
[Tue Aug 18 12:56:44.957787 2026] [security2:error] [pid 67073:tid 67324] [client 52.139.47.57:44610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/x.php"] [unique_id "aoSAvPcmepr5_nHgLbNa1gAAAos"]
[Tue Aug 18 12:56:45.025849 2026] [security2:error] [pid 67073:tid 67273] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/xf.php"] [unique_id "aoSAvfcmepr5_nHgLbNa1wAAAlg"]
[Tue Aug 18 12:56:45.042363 2026] [security2:error] [pid 67073:tid 67271] [client 20.163.43.14:4180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/item.php"] [unique_id "aoSAvfcmepr5_nHgLbNa2AAAAlY"]
[Tue Aug 18 12:56:45.075000 2026] [security2:error] [pid 67073:tid 67226] [client 40.85.222.29:12668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSAvfcmepr5_nHgLbNa2QAAAik"]
[Tue Aug 18 12:56:45.079595 2026] [security2:error] [pid 67073:tid 67274] [client 20.102.65.165:8226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/fpwch.php"] [unique_id "aoSAvfcmepr5_nHgLbNa2gAAAlk"]
[Tue Aug 18 12:56:45.100624 2026] [security2:error] [pid 67073:tid 67088] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/@fs/.env"] [unique_id "aoSAvfcmepr5_nHgLbNa3AACgAw"]
[Tue Aug 18 12:56:45.105556 2026] [security2:error] [pid 67073:tid 67130] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/staging/.env"] [unique_id "aoSAvfcmepr5_nHgLbNa3gACgDY"]
[Tue Aug 18 12:56:45.112952 2026] [security2:error] [pid 67073:tid 67193] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/docker/.env"] [unique_id "aoSAvfcmepr5_nHgLbNa3wACjHU"]
[Tue Aug 18 12:56:45.114191 2026] [security2:error] [pid 67073:tid 67147] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.env.production.bak"] [unique_id "aoSAvfcmepr5_nHgLbNa4AACjEc"]
[Tue Aug 18 12:56:45.128009 2026] [security2:error] [pid 67073:tid 67131] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.env.prod.bak"] [unique_id "aoSAvfcmepr5_nHgLbNa4gACPjc"]
[Tue Aug 18 12:56:45.144917 2026] [security2:error] [pid 66623:tid 66873] [client 135.225.75.187:18783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/erty.php"] [unique_id "aoSAvdO5rbWdOArH04KMbQAAAXU"]
[Tue Aug 18 12:56:45.157211 2026] [security2:error] [pid 66623:tid 66851] [client 20.171.51.14:51802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ut.php"] [unique_id "aoSAvdO5rbWdOArH04KMbgAAAV8"]
[Tue Aug 18 12:56:45.227186 2026] [security2:error] [pid 67073:tid 67263] [client 172.202.39.151:65262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/rip.php"] [unique_id "aoSAvfcmepr5_nHgLbNa5AAAAk4"]
[Tue Aug 18 12:56:45.274373 2026] [security2:error] [pid 66623:tid 66801] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gb.php"] [unique_id "aoSAvdO5rbWdOArH04KMcQAAAS0"]
[Tue Aug 18 12:56:45.309010 2026] [security2:error] [pid 67073:tid 67277] [client 20.206.73.37:59930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/aa.php"] [unique_id "aoSAvfcmepr5_nHgLbNa6QAAAlw"]
[Tue Aug 18 12:56:45.325425 2026] [security2:error] [pid 67073:tid 67198] [remote 34.158.8.33:32976] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "alyauto.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSAvfcmepr5_nHgLbNa7gACaXo"]
[Tue Aug 18 12:56:45.334915 2026] [security2:error] [pid 66623:tid 66830] [client 20.102.65.165:8279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/adminner.php"] [unique_id "aoSAvdO5rbWdOArH04KMcwAAAUo"]
[Tue Aug 18 12:56:45.348949 2026] [security2:error] [pid 67073:tid 67213] [client 40.85.222.29:12631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSAvfcmepr5_nHgLbNa8AAAAhw"]
[Tue Aug 18 12:56:45.351759 2026] [security2:error] [pid 66623:tid 66821] [client 20.186.30.159:13678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAvdO5rbWdOArH04KMdgAAAUE"]
[Tue Aug 18 12:56:45.362245 2026] [security2:error] [pid 67073:tid 67224] [client 103.120.71.157:52786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAvfcmepr5_nHgLbNa8QAAAic"]
[Tue Aug 18 12:56:45.362340 2026] [security2:error] [pid 67073:tid 67224] [client 103.120.71.157:52786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAvfcmepr5_nHgLbNa8QAAAic"]
[Tue Aug 18 12:56:45.373257 2026] [security2:error] [pid 67073:tid 67251] [client 52.139.47.57:38991] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "whm.multiveicular.org.br"] [uri "/1.php"] [unique_id "aoSAvfcmepr5_nHgLbNa8wAAAkI"]
[Tue Aug 18 12:56:45.373343 2026] [security2:error] [pid 67073:tid 67251] [client 52.139.47.57:38991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/1.php"] [unique_id "aoSAvfcmepr5_nHgLbNa8wAAAkI"]
[Tue Aug 18 12:56:45.393241 2026] [security2:error] [pid 67073:tid 67234] [client 20.215.241.237:44742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-blog.php"] [unique_id "aoSAvfcmepr5_nHgLbNa9QAAAjE"]
[Tue Aug 18 12:56:45.395121 2026] [security2:error] [pid 66623:tid 66713] [remote 162.55.89.48:59024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "immobili.adm.br"] [uri "/wp-login.php"] [unique_id "aoSAvdO5rbWdOArH04KMdwABUkw"]
[Tue Aug 18 12:56:45.401747 2026] [authz_core:error] [pid 67073:tid 67154] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:45.402125 2026] [authz_core:error] [pid 67073:tid 67154] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:45.408833 2026] [security2:error] [pid 67073:tid 67221] [client 213.35.127.232:61430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAvfcmepr5_nHgLbNa9wAAAiQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:45.490179 2026] [security2:error] [pid 67073:tid 67305] [client 52.139.47.57:44621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/twentytwenty/functions.php"] [unique_id "aoSAvfcmepr5_nHgLbNa-QAAAng"]
[Tue Aug 18 12:56:45.528240 2026] [security2:error] [pid 67073:tid 67236] [client 20.52.168.85:8033] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.sortis.net"] [uri "/wp-content/1.php"] [unique_id "aoSAvfcmepr5_nHgLbNa-wAAAjM"]
[Tue Aug 18 12:56:45.528371 2026] [security2:error] [pid 67073:tid 67236] [client 20.52.168.85:8033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-content/1.php"] [unique_id "aoSAvfcmepr5_nHgLbNa-wAAAjM"]
[Tue Aug 18 12:56:45.528776 2026] [security2:error] [pid 67073:tid 67208] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/jp.php"] [unique_id "aoSAvfcmepr5_nHgLbNa_AAAAhc"]
[Tue Aug 18 12:56:45.582057 2026] [security2:error] [pid 66623:tid 66892] [client 20.102.65.165:8197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/abcd.php"] [unique_id "aoSAvdO5rbWdOArH04KMewAAAYg"]
[Tue Aug 18 12:56:45.609345 2026] [security2:error] [pid 66623:tid 66812] [client 20.215.241.237:17839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/wpxml.php"] [unique_id "aoSAvdO5rbWdOArH04KMfgAAATg"]
[Tue Aug 18 12:56:45.620105 2026] [security2:error] [pid 66623:tid 66783] [client 20.116.17.175:11075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSAvdO5rbWdOArH04KMfwAAARs"]
[Tue Aug 18 12:56:45.631303 2026] [security2:error] [pid 67073:tid 67328] [client 40.85.222.29:13291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSAvfcmepr5_nHgLbNbAgAAAo8"]
[Tue Aug 18 12:56:45.653379 2026] [security2:error] [pid 67073:tid 67330] [client 68.155.154.236:16312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSAvfcmepr5_nHgLbNbBAAAApE"]
[Tue Aug 18 12:56:45.701487 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:45.701808 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:45.709541 2026] [security2:error] [pid 66623:tid 66893] [client 20.100.169.31:25885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/elp.php"] [unique_id "aoSAvdO5rbWdOArH04KMgQAAAYk"]
[Tue Aug 18 12:56:45.789946 2026] [security2:error] [pid 66623:tid 66796] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/eq.php"] [unique_id "aoSAvdO5rbWdOArH04KMgwAAASg"]
[Tue Aug 18 12:56:45.802545 2026] [security2:error] [pid 66623:tid 66880] [client 52.139.47.57:19945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/z.php"] [unique_id "aoSAvdO5rbWdOArH04KMhAAAAXw"]
[Tue Aug 18 12:56:45.814837 2026] [security2:error] [pid 66623:tid 66775] [client 52.173.121.69:17930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/well-known/index.php"] [unique_id "aoSAvdO5rbWdOArH04KMhQAAARM"]
[Tue Aug 18 12:56:45.821755 2026] [security2:error] [pid 66623:tid 66785] [client 104.209.144.33:35872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/index/function.php"] [unique_id "aoSAvdO5rbWdOArH04KMhgAAAR0"]
[Tue Aug 18 12:56:45.833618 2026] [security2:error] [pid 67073:tid 67249] [client 158.158.34.183:11519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/atomlib.php"] [unique_id "aoSAvfcmepr5_nHgLbNbCgAAAkA"]
[Tue Aug 18 12:56:45.910651 2026] [security2:error] [pid 67073:tid 67209] [client 40.85.222.29:13193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSAvfcmepr5_nHgLbNbDgAAAhg"]
[Tue Aug 18 12:56:45.912790 2026] [security2:error] [pid 67073:tid 67315] [client 132.196.30.78:21703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/min.php"] [unique_id "aoSAvfcmepr5_nHgLbNbDwAAAoI"]
[Tue Aug 18 12:56:45.929960 2026] [security2:error] [pid 67073:tid 67246] [client 20.171.51.14:43340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/eh.php"] [unique_id "aoSAvfcmepr5_nHgLbNbEAAAAj0"]
[Tue Aug 18 12:56:45.953056 2026] [security2:error] [pid 67073:tid 67228] [client 103.184.169.37:41978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAvfcmepr5_nHgLbNbEQAAAis"]
[Tue Aug 18 12:56:45.953149 2026] [security2:error] [pid 67073:tid 67228] [client 103.184.169.37:41978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAvfcmepr5_nHgLbNbEQAAAis"]
[Tue Aug 18 12:56:45.958918 2026] [security2:error] [pid 67073:tid 67257] [client 158.158.74.177:2647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/size.php"] [unique_id "aoSAvfcmepr5_nHgLbNbEgAAAkg"]
[Tue Aug 18 12:56:45.961954 2026] [security2:error] [pid 67073:tid 67292] [client 172.202.39.151:42979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/images/images/about.php"] [unique_id "aoSAvfcmepr5_nHgLbNbEwAAAms"]
[Tue Aug 18 12:56:45.962074 2026] [security2:error] [pid 67073:tid 67267] [client 52.139.47.57:39039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/wp-admin.php"] [unique_id "aoSAvfcmepr5_nHgLbNbFAAAAlI"]
[Tue Aug 18 12:56:45.993056 2026] [security2:error] [pid 67073:tid 67219] [client 135.225.75.187:62133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/mini.php"] [unique_id "aoSAvfcmepr5_nHgLbNbHAAAAiI"]
[Tue Aug 18 12:56:46.023279 2026] [security2:error] [pid 67073:tid 67244] [client 68.155.154.236:7911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAvvcmepr5_nHgLbNbJwAAAjs"]
[Tue Aug 18 12:56:46.051453 2026] [security2:error] [pid 67073:tid 67231] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ep.php"] [unique_id "aoSAvvcmepr5_nHgLbNbKAAAAi4"]
[Tue Aug 18 12:56:46.149494 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.56.190:28252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/q.php"] [unique_id "aoSAvvcmepr5_nHgLbNbSQAAAlg"]
[Tue Aug 18 12:56:46.210189 2026] [security2:error] [pid 66623:tid 66842] [client 40.85.222.29:13232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSAvtO5rbWdOArH04KMjQAAAVY"]
[Tue Aug 18 12:56:46.226766 2026] [security2:error] [pid 67073:tid 67287] [client 79.127.164.8:54408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/messageinstallmysql.bak"] [unique_id "aoSAvvcmepr5_nHgLbNbUQAAAmY"], referer: https://medihub.com.br/messageinstallmysql.bak
[Tue Aug 18 12:56:46.231347 2026] [security2:error] [pid 67073:tid 67293] [client 52.139.47.57:44657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/ee.php"] [unique_id "aoSAvvcmepr5_nHgLbNbUgAAAmw"]
[Tue Aug 18 12:56:46.314795 2026] [security2:error] [pid 67073:tid 67122] [remote 47.86.33.52:6244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savvyoffshore.com.br"] [uri "/wp-login.php"] [unique_id "aoSAvvcmepr5_nHgLbNbVQACci4"]
[Tue Aug 18 12:56:46.336777 2026] [security2:error] [pid 66623:tid 66854] [client 20.52.168.85:8050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAvtO5rbWdOArH04KMkAAAAWI"]
[Tue Aug 18 12:56:46.351843 2026] [security2:error] [pid 66623:tid 66813] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/rf.php"] [unique_id "aoSAvtO5rbWdOArH04KMkQAAATk"]
[Tue Aug 18 12:56:46.363298 2026] [security2:error] [pid 66623:tid 66832] [client 20.100.169.31:7954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/vx.php"] [unique_id "aoSAvtO5rbWdOArH04KMkwAAAUw"]
[Tue Aug 18 12:56:46.368586 2026] [security2:error] [pid 66623:tid 66861] [client 74.248.136.165:22467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/koiy.php"] [unique_id "aoSAvtO5rbWdOArH04KMlAAAAWk"]
[Tue Aug 18 12:56:46.423656 2026] [security2:error] [pid 66623:tid 66839] [client 213.35.127.232:61649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAvtO5rbWdOArH04KMlgAAAVM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:46.488008 2026] [security2:error] [pid 66623:tid 66852] [client 40.85.222.29:13206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSAvtO5rbWdOArH04KMlwAAAWA"]
[Tue Aug 18 12:56:46.531653 2026] [security2:error] [pid 66623:tid 66788] [client 20.65.69.59:3242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/vbseo.php"] [unique_id "aoSAvtO5rbWdOArH04KMmgAAASA"]
[Tue Aug 18 12:56:46.572033 2026] [security2:error] [pid 67073:tid 67224] [client 52.139.47.57:44645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSAvvcmepr5_nHgLbNbjwAAAic"]
[Tue Aug 18 12:56:46.599169 2026] [security2:error] [pid 66623:tid 66786] [client 20.215.241.237:43640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAvtO5rbWdOArH04KMngAAAR4"]
[Tue Aug 18 12:56:46.606935 2026] [authz_core:error] [pid 67073:tid 67077] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:46.607336 2026] [authz_core:error] [pid 67073:tid 67077] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:46.614538 2026] [security2:error] [pid 66623:tid 66886] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/xynz1.php"] [unique_id "aoSAvtO5rbWdOArH04KMnwAAAYI"]
[Tue Aug 18 12:56:46.622531 2026] [security2:error] [pid 67073:tid 67310] [client 158.23.17.4:33482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/rex.php"] [unique_id "aoSAvvcmepr5_nHgLbNbkwAAAn0"]
[Tue Aug 18 12:56:46.685059 2026] [security2:error] [pid 67073:tid 67328] [client 68.155.154.236:16289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/index/function.php"] [unique_id "aoSAvvcmepr5_nHgLbNblwAAAo8"]
[Tue Aug 18 12:56:46.691946 2026] [security2:error] [pid 67073:tid 67253] [client 52.139.47.57:16698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/we.php"] [unique_id "aoSAvvcmepr5_nHgLbNbmAAAAkQ"]
[Tue Aug 18 12:56:46.699716 2026] [security2:error] [pid 67073:tid 67215] [client 68.155.154.236:54369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAvvcmepr5_nHgLbNbmgAAAh4"]
[Tue Aug 18 12:56:46.724546 2026] [security2:error] [pid 66623:tid 66879] [client 132.196.30.78:21902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/php8.php"] [unique_id "aoSAvtO5rbWdOArH04KMowAAAXs"]
[Tue Aug 18 12:56:46.747605 2026] [security2:error] [pid 67073:tid 67300] [client 74.7.175.162:43292] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "scaclinic.com.br"] [uri "/index.php"] [unique_id "aoSAvfcmepr5_nHgLbNa_gACcx8"]
[Tue Aug 18 12:56:46.767766 2026] [security2:error] [pid 66623:tid 66809] [client 40.85.222.29:13214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSAvtO5rbWdOArH04KMpAAAATU"]
[Tue Aug 18 12:56:46.840648 2026] [security2:error] [pid 66623:tid 66867] [client 135.225.75.187:62107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/sid3.php"] [unique_id "aoSAvtO5rbWdOArH04KMpwAAAW8"]
[Tue Aug 18 12:56:46.845469 2026] [security2:error] [pid 66623:tid 66877] [client 114.119.144.200:20913] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "designstonego.com.br"] [uri "/arquitetura-sacra/"] [unique_id "aoSAvtO5rbWdOArH04KMqAAAAXk"], referer: https://designstonego.com.br/produtos/
[Tue Aug 18 12:56:46.876427 2026] [security2:error] [pid 66623:tid 66840] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/vo.php"] [unique_id "aoSAvtO5rbWdOArH04KMqwAAAVQ"]
[Tue Aug 18 12:56:46.907829 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:46.908269 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:46.979023 2026] [security2:error] [pid 67073:tid 67216] [client 20.116.17.175:57448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/root.php"] [unique_id "aoSAvvcmepr5_nHgLbNbqgAAAh8"]
[Tue Aug 18 12:56:46.981595 2026] [security2:error] [pid 67073:tid 67244] [client 20.215.241.237:37669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/file1221.php"] [unique_id "aoSAvvcmepr5_nHgLbNbqwAAAjs"]
[Tue Aug 18 12:56:47.062697 2026] [security2:error] [pid 66623:tid 66868] [client 40.85.222.29:13284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/rezor.php"] [unique_id "aoSAv9O5rbWdOArH04KMsAAAAXA"]
[Tue Aug 18 12:56:47.109510 2026] [security2:error] [pid 67073:tid 67219] [client 52.139.47.57:47647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/to.php"] [unique_id "aoSAv_cmepr5_nHgLbNb0wAAAiI"]
[Tue Aug 18 12:56:47.132369 2026] [security2:error] [pid 67073:tid 67259] [client 20.65.98.162:50466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/mosty.php"] [unique_id "aoSAv_cmepr5_nHgLbNb1QAAAko"]
[Tue Aug 18 12:56:47.133971 2026] [security2:error] [pid 67073:tid 67294] [client 172.202.39.151:38647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSAv_cmepr5_nHgLbNb1gAAAm0"]
[Tue Aug 18 12:56:47.137527 2026] [security2:error] [pid 66623:tid 66777] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/wu.php"] [unique_id "aoSAv9O5rbWdOArH04KMswAAARU"]
[Tue Aug 18 12:56:47.158020 2026] [security2:error] [pid 67073:tid 67327] [client 20.52.168.85:7773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/adminer.php"] [unique_id "aoSAv_cmepr5_nHgLbNb2AAAAo4"]
[Tue Aug 18 12:56:47.185403 2026] [security2:error] [pid 66623:tid 66836] [client 172.202.39.151:28681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/ms-edit.php"] [unique_id "aoSAv9O5rbWdOArH04KMtAAAAVA"]
[Tue Aug 18 12:56:47.207122 2026] [authz_core:error] [pid 67073:tid 67152] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:47.207387 2026] [authz_core:error] [pid 67073:tid 67152] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:47.211537 2026] [security2:error] [pid 67073:tid 67287] [client 20.226.56.190:44998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/xf.php"] [unique_id "aoSAv_cmepr5_nHgLbNb3QAAAmY"]
[Tue Aug 18 12:56:47.220864 2026] [security2:error] [pid 67073:tid 67293] [client 20.171.51.14:33703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ad.php"] [unique_id "aoSAv_cmepr5_nHgLbNb3wAAAmw"]
[Tue Aug 18 12:56:47.263087 2026] [security2:error] [pid 67073:tid 67273] [client 132.196.30.78:18654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAv_cmepr5_nHgLbNb4gAAAlg"]
[Tue Aug 18 12:56:47.265101 2026] [security2:error] [pid 66623:tid 66826] [client 20.206.73.37:59947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/av.php"] [unique_id "aoSAv9O5rbWdOArH04KMtgAAAUY"]
[Tue Aug 18 12:56:47.269758 2026] [security2:error] [pid 67073:tid 67212] [client 158.158.34.183:23127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAv_cmepr5_nHgLbNb4wAAAhs"]
[Tue Aug 18 12:56:47.302189 2026] [security2:error] [pid 67073:tid 67275] [client 20.100.169.31:25449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAv_cmepr5_nHgLbNb5AAAAlo"]
[Tue Aug 18 12:56:47.353784 2026] [security2:error] [pid 66623:tid 66869] [client 40.85.222.29:13185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSAv9O5rbWdOArH04KMuQAAAXE"]
[Tue Aug 18 12:56:47.354914 2026] [security2:error] [pid 67073:tid 67289] [client 104.209.144.33:19610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSAv_cmepr5_nHgLbNb5gAAAmg"]
[Tue Aug 18 12:56:47.393715 2026] [security2:error] [pid 66623:tid 66824] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/de.php"] [unique_id "aoSAv9O5rbWdOArH04KMuwAAAUQ"]
[Tue Aug 18 12:56:47.415219 2026] [security2:error] [pid 66623:tid 66767] [client 20.65.69.59:3728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/sysinfo.php"] [unique_id "aoSAv9O5rbWdOArH04KMvwAAAQs"]
[Tue Aug 18 12:56:47.430022 2026] [security2:error] [pid 66623:tid 66798] [client 158.158.74.177:17954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/special.php"] [unique_id "aoSAv9O5rbWdOArH04KMwQAAASo"]
[Tue Aug 18 12:56:47.440188 2026] [security2:error] [pid 66623:tid 66848] [client 213.35.127.232:61865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAv9O5rbWdOArH04KMwgAAAVw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:47.461581 2026] [security2:error] [pid 67073:tid 67245] [client 52.173.121.69:17956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSAv_cmepr5_nHgLbNb9QAAAjw"]
[Tue Aug 18 12:56:47.491436 2026] [security2:error] [pid 66623:tid 66830] [client 20.215.241.237:44747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAv9O5rbWdOArH04KMxAAAAUo"]
[Tue Aug 18 12:56:47.510159 2026] [authz_core:error] [pid 67073:tid 67199] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:47.510451 2026] [authz_core:error] [pid 67073:tid 67199] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:47.512464 2026] [security2:error] [pid 67073:tid 67205] [client 52.139.47.57:18391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAv_cmepr5_nHgLbNb_gAAAhQ"]
[Tue Aug 18 12:56:47.533968 2026] [security2:error] [pid 66623:tid 66802] [client 52.139.47.57:44648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/ty.php"] [unique_id "aoSAv9O5rbWdOArH04KMxwAAAS4"]
[Tue Aug 18 12:56:47.608647 2026] [security2:error] [pid 67073:tid 67282] [client 74.248.136.165:34188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/iko.php"] [unique_id "aoSAv_cmepr5_nHgLbNcCAAAAmE"]
[Tue Aug 18 12:56:47.644972 2026] [security2:error] [pid 67073:tid 67228] [client 40.85.222.29:13191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSAv_cmepr5_nHgLbNcEAAAAis"]
[Tue Aug 18 12:56:47.649498 2026] [security2:error] [pid 67073:tid 67267] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/album.php"] [unique_id "aoSAv_cmepr5_nHgLbNcEgAAAlI"]
[Tue Aug 18 12:56:47.675481 2026] [security2:error] [pid 66623:tid 66837] [client 135.225.75.187:36549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/moon.php"] [unique_id "aoSAv9O5rbWdOArH04KMywAAAVE"]
[Tue Aug 18 12:56:47.713179 2026] [security2:error] [pid 67073:tid 67227] [client 68.155.154.236:39641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/weozh.php"] [unique_id "aoSAv_cmepr5_nHgLbNcIgAAAio"]
[Tue Aug 18 12:56:47.735543 2026] [security2:error] [pid 67073:tid 67214] [client 172.182.200.96:7645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/uploads/bypass.php"] [unique_id "aoSAv_cmepr5_nHgLbNcJQAAAh0"]
[Tue Aug 18 12:56:47.769449 2026] [security2:error] [pid 67073:tid 67301] [client 20.52.168.85:7823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "aoSAv_cmepr5_nHgLbNcKgAAAnQ"]
[Tue Aug 18 12:56:47.874192 2026] [security2:error] [pid 66623:tid 66796] [client 68.155.154.236:16351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSAv9O5rbWdOArH04KM0QAAASg"]
[Tue Aug 18 12:56:47.874930 2026] [security2:error] [pid 67073:tid 67327] [client 132.196.30.78:18790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/222.php"] [unique_id "aoSAv_cmepr5_nHgLbNcMAAAAo4"]
[Tue Aug 18 12:56:47.878375 2026] [security2:error] [pid 67073:tid 67325] [client 5.31.227.224:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAv_cmepr5_nHgLbNcMgAAAow"]
[Tue Aug 18 12:56:47.878481 2026] [security2:error] [pid 67073:tid 67325] [client 5.31.227.224:59012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAv_cmepr5_nHgLbNcMgAAAow"]
[Tue Aug 18 12:56:47.904141 2026] [security2:error] [pid 66623:tid 66775] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kv.php"] [unique_id "aoSAv9O5rbWdOArH04KM0gAAARM"]
[Tue Aug 18 12:56:47.953673 2026] [security2:error] [pid 67073:tid 67241] [client 145.239.69.153:38036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "siderurgiabrasil.com.br"] [uri "/robots.txt"] [unique_id "aoSAv_cmepr5_nHgLbNcPwAAAjg"]
[Tue Aug 18 12:56:47.953783 2026] [security2:error] [pid 67073:tid 67241] [client 145.239.69.153:38036] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "siderurgiabrasil.com.br"] [uri "/robots.txt"] [unique_id "aoSAv_cmepr5_nHgLbNcPwAAAjg"]
[Tue Aug 18 12:56:47.967018 2026] [security2:error] [pid 67073:tid 67280] [client 45.92.229.112:39913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.229.92.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-login.php"] [unique_id "aoSAv_cmepr5_nHgLbNcLAAAAl8"], referer: https://ozzyfernandesoficial.com.br/wp-login.php
[Tue Aug 18 12:56:47.968154 2026] [security2:error] [pid 67073:tid 67258] [client 40.85.222.29:13257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/index/function.php"] [unique_id "aoSAv_cmepr5_nHgLbNcQQAAAkk"]
[Tue Aug 18 12:56:47.972806 2026] [security2:error] [pid 67073:tid 67212] [client 52.139.47.57:38978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/ak.php"] [unique_id "aoSAv_cmepr5_nHgLbNcQwAAAhs"]
[Tue Aug 18 12:56:47.979430 2026] [security2:error] [pid 67073:tid 67268] [client 20.171.51.14:58371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/vd.php"] [unique_id "aoSAv_cmepr5_nHgLbNcRAAAAlM"]
[Tue Aug 18 12:56:47.984942 2026] [autoindex:error] [pid 67073:tid 67213] [client 172.202.39.151:50190] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:48.001355 2026] [security2:error] [pid 66623:tid 66875] [client 20.215.241.237:57751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/222.php"] [unique_id "aoSAwNO5rbWdOArH04KM1QAAAXc"]
[Tue Aug 18 12:56:48.079655 2026] [security2:error] [pid 66623:tid 66873] [client 37.40.227.74:56597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwNO5rbWdOArH04KM1wAAAXU"]
[Tue Aug 18 12:56:48.079766 2026] [security2:error] [pid 66623:tid 66873] [client 37.40.227.74:56597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwNO5rbWdOArH04KM1wAAAXU"]
[Tue Aug 18 12:56:48.098341 2026] [security2:error] [pid 66623:tid 66880] [client 20.100.169.31:48609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/666.php"] [unique_id "aoSAwNO5rbWdOArH04KM2QAAAXw"]
[Tue Aug 18 12:56:48.143500 2026] [security2:error] [pid 67073:tid 67310] [client 20.116.17.175:11209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/fpwch.php"] [unique_id "aoSAwPcmepr5_nHgLbNcSgAAAn0"]
[Tue Aug 18 12:56:48.152201 2026] [security2:error] [pid 67073:tid 67205] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/z.php"] [unique_id "aoSAwPcmepr5_nHgLbNcTAAAAhQ"]
[Tue Aug 18 12:56:48.224862 2026] [security2:error] [pid 66623:tid 66776] [client 20.100.169.31:48129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wap.php"] [unique_id "aoSAwNO5rbWdOArH04KM3gAAARQ"]
[Tue Aug 18 12:56:48.238038 2026] [security2:error] [pid 67073:tid 67207] [client 74.7.228.4:39670] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fokuss.com.br"] [uri "/index.php"] [unique_id "aoSAvfcmepr5_nHgLbNa4wACFkQ"]
[Tue Aug 18 12:56:48.245576 2026] [security2:error] [pid 67073:tid 67223] [client 168.119.96.239:26608] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.stampi.ind.br"] [uri "/index.html"] [unique_id "aoSAwPcmepr5_nHgLbNcWQAAAiY"], referer: http://www.stampi.ind.br/
[Tue Aug 18 12:56:48.254979 2026] [security2:error] [pid 66623:tid 66861] [client 40.85.222.29:13187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSAwNO5rbWdOArH04KM4gAAAWk"]
[Tue Aug 18 12:56:48.278987 2026] [security2:error] [pid 67073:tid 67315] [client 172.202.39.151:50190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwPcmepr5_nHgLbNcYQAAAoI"]
[Tue Aug 18 12:56:48.405475 2026] [security2:error] [pid 67073:tid 67264] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/xg.php"] [unique_id "aoSAwPcmepr5_nHgLbNcbAAAAk8"]
[Tue Aug 18 12:56:48.414368 2026] [authz_core:error] [pid 67073:tid 67139] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:48.414795 2026] [authz_core:error] [pid 67073:tid 67139] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:48.418106 2026] [security2:error] [pid 67073:tid 67262] [client 20.65.69.59:3407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/ppinfo.php"] [unique_id "aoSAwPcmepr5_nHgLbNcbQAAAk0"]
[Tue Aug 18 12:56:48.436022 2026] [security2:error] [pid 67073:tid 67243] [client 157.20.138.62:62282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwPcmepr5_nHgLbNcbwAAAjo"]
[Tue Aug 18 12:56:48.436111 2026] [security2:error] [pid 67073:tid 67243] [client 157.20.138.62:62282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwPcmepr5_nHgLbNcbwAAAjo"]
[Tue Aug 18 12:56:48.449240 2026] [security2:error] [pid 67073:tid 67249] [client 132.196.30.78:18801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSAwPcmepr5_nHgLbNccAAAAkA"]
[Tue Aug 18 12:56:48.452308 2026] [security2:error] [pid 66623:tid 66842] [client 213.35.127.232:62081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAwNO5rbWdOArH04KM6AAAAVY"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:48.473902 2026] [security2:error] [pid 66623:tid 66793] [client 20.206.73.37:59862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/media.php"] [unique_id "aoSAwNO5rbWdOArH04KM6QAAASU"]
[Tue Aug 18 12:56:48.488871 2026] [security2:error] [pid 66623:tid 66786] [client 135.225.75.187:58890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ms.php"] [unique_id "aoSAwNO5rbWdOArH04KM6gAAAR4"]
[Tue Aug 18 12:56:48.503529 2026] [security2:error] [pid 66623:tid 66806] [client 52.139.47.57:16661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/fm.php"] [unique_id "aoSAwNO5rbWdOArH04KM7AAAATI"]
[Tue Aug 18 12:56:48.540120 2026] [security2:error] [pid 67073:tid 67320] [client 40.85.222.29:12618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/Cachex.php"] [unique_id "aoSAwPcmepr5_nHgLbNcfAAAAoc"]
[Tue Aug 18 12:56:48.549662 2026] [security2:error] [pid 67073:tid 67220] [client 172.202.39.151:38640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/rip.php"] [unique_id "aoSAwPcmepr5_nHgLbNcfgAAAiM"]
[Tue Aug 18 12:56:48.558124 2026] [security2:error] [pid 67073:tid 67302] [client 68.155.154.236:58900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/rymmm.php"] [unique_id "aoSAwPcmepr5_nHgLbNcgAAAAnU"]
[Tue Aug 18 12:56:48.585738 2026] [security2:error] [pid 67073:tid 67227] [client 20.52.168.85:8042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wso.php"] [unique_id "aoSAwPcmepr5_nHgLbNcgwAAAio"]
[Tue Aug 18 12:56:48.637465 2026] [security2:error] [pid 67073:tid 67254] [client 68.155.156.252:19385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/mac.php"] [unique_id "aoSAwPcmepr5_nHgLbNchgAAAkU"]
[Tue Aug 18 12:56:48.651495 2026] [security2:error] [pid 66623:tid 66841] [client 52.139.47.57:47662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/wp-includes/Text/Diff/Engine.php"] [unique_id "aoSAwNO5rbWdOArH04KM9QAAAVU"]
[Tue Aug 18 12:56:48.657957 2026] [security2:error] [pid 66623:tid 66865] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/nd.php"] [unique_id "aoSAwNO5rbWdOArH04KM9wAAAW0"]
[Tue Aug 18 12:56:48.684738 2026] [security2:error] [pid 66623:tid 66781] [client 52.173.121.69:16472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAwNO5rbWdOArH04KM-QAAARk"]
[Tue Aug 18 12:56:48.709889 2026] [security2:error] [pid 67073:tid 67321] [client 20.215.241.237:61069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSAwPcmepr5_nHgLbNciQAAAog"]
[Tue Aug 18 12:56:48.716190 2026] [security2:error] [pid 67073:tid 67285] [client 20.215.241.237:36271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/nox.php"] [unique_id "aoSAwPcmepr5_nHgLbNciwAAAmQ"]
[Tue Aug 18 12:56:48.787933 2026] [security2:error] [pid 66623:tid 66808] [client 20.171.51.14:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/56.php"] [unique_id "aoSAwNO5rbWdOArH04KM-wAAATQ"]
[Tue Aug 18 12:56:48.790220 2026] [security2:error] [pid 67073:tid 67250] [client 68.155.154.236:16278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/Cachex.php"] [unique_id "aoSAwPcmepr5_nHgLbNcjQAAAkE"]
[Tue Aug 18 12:56:48.810872 2026] [security2:error] [pid 67073:tid 67279] [client 74.248.136.165:64188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/raw.php"] [unique_id "aoSAwPcmepr5_nHgLbNcjgAAAl4"]
[Tue Aug 18 12:56:48.829817 2026] [security2:error] [pid 67073:tid 67326] [client 40.85.222.29:12637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSAwPcmepr5_nHgLbNckAAAAo0"]
[Tue Aug 18 12:56:48.866910 2026] [security2:error] [pid 67073:tid 67256] [client 149.34.210.141:54938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAwPcmepr5_nHgLbNckgAAAkc"]
[Tue Aug 18 12:56:48.913390 2026] [security2:error] [pid 67073:tid 67212] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ri.php"] [unique_id "aoSAwPcmepr5_nHgLbNclAAAAhs"]
[Tue Aug 18 12:56:49.016989 2026] [authz_core:error] [pid 67073:tid 67183] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:49.017420 2026] [authz_core:error] [pid 67073:tid 67183] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:49.047857 2026] [security2:error] [pid 67073:tid 67258] [client 52.139.47.57:19923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/wp.php"] [unique_id "aoSAwfcmepr5_nHgLbNcqgAAAkk"]
[Tue Aug 18 12:56:49.048606 2026] [security2:error] [pid 67073:tid 67299] [client 132.196.30.78:21906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/info.php"] [unique_id "aoSAwfcmepr5_nHgLbNcqwAAAnI"]
[Tue Aug 18 12:56:49.057361 2026] [security2:error] [pid 67073:tid 67205] [client 20.65.69.59:3758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/globals.php"] [unique_id "aoSAwfcmepr5_nHgLbNcrAAAAhQ"]
[Tue Aug 18 12:56:49.069345 2026] [security2:error] [pid 67073:tid 67242] [client 104.209.144.33:29861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/Cachex.php"] [unique_id "aoSAwfcmepr5_nHgLbNcrQAAAjk"]
[Tue Aug 18 12:56:49.105075 2026] [security2:error] [pid 66623:tid 66888] [client 158.158.74.177:16573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/ssjpxze.php"] [unique_id "aoSAwdO5rbWdOArH04KNBwAAAYQ"]
[Tue Aug 18 12:56:49.114729 2026] [security2:error] [pid 67073:tid 67269] [client 40.85.222.29:13277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-2019.php"] [unique_id "aoSAwfcmepr5_nHgLbNcrgAAAlQ"]
[Tue Aug 18 12:56:49.140296 2026] [security2:error] [pid 67073:tid 67256] [client 149.34.210.141:54938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAwPcmepr5_nHgLbNckgAAAkc"]
[Tue Aug 18 12:56:49.176622 2026] [security2:error] [pid 67073:tid 67215] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/tp.php"] [unique_id "aoSAwfcmepr5_nHgLbNcsQAAAh4"]
[Tue Aug 18 12:56:49.193072 2026] [security2:error] [pid 67073:tid 67272] [client 20.52.168.85:8058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAwfcmepr5_nHgLbNcsgAAAlc"]
[Tue Aug 18 12:56:49.257613 2026] [security2:error] [pid 67073:tid 67281] [client 20.100.169.31:25861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/ws54.php"] [unique_id "aoSAwfcmepr5_nHgLbNcuQAAAmA"]
[Tue Aug 18 12:56:49.275682 2026] [security2:error] [pid 66623:tid 66859] [client 68.155.154.236:40358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/lddxs.php"] [unique_id "aoSAwdO5rbWdOArH04KNDAAAAWc"]
[Tue Aug 18 12:56:49.280351 2026] [security2:error] [pid 67073:tid 67255] [client 20.116.17.175:57466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/mg.php"] [unique_id "aoSAwfcmepr5_nHgLbNcugAAAkY"]
[Tue Aug 18 12:56:49.339829 2026] [security2:error] [pid 67073:tid 67228] [client 135.225.75.187:37304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wsws.php"] [unique_id "aoSAwfcmepr5_nHgLbNcuwAAAis"]
[Tue Aug 18 12:56:49.395972 2026] [security2:error] [pid 67073:tid 67331] [client 172.202.39.151:55486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/moon.php"] [unique_id "aoSAwfcmepr5_nHgLbNcvAAAApI"]
[Tue Aug 18 12:56:49.397343 2026] [security2:error] [pid 66623:tid 66846] [client 40.85.222.29:13285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSAwdO5rbWdOArH04KNDQAAAVo"]
[Tue Aug 18 12:56:49.412568 2026] [security2:error] [pid 66623:tid 66869] [client 52.173.121.69:17927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSAwdO5rbWdOArH04KNDgAAAXE"]
[Tue Aug 18 12:56:49.431981 2026] [security2:error] [pid 67073:tid 67222] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/zj.php"] [unique_id "aoSAwfcmepr5_nHgLbNcvQAAAiU"]
[Tue Aug 18 12:56:49.463302 2026] [security2:error] [pid 67073:tid 67330] [client 213.35.127.232:62301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAwfcmepr5_nHgLbNcvwAAApE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:49.464226 2026] [security2:error] [pid 67073:tid 67296] [client 52.139.47.57:18389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/33.php"] [unique_id "aoSAwfcmepr5_nHgLbNcwQAAAm8"]
[Tue Aug 18 12:56:49.512602 2026] [security2:error] [pid 66623:tid 66767] [client 20.171.51.14:21057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/rx.php"] [unique_id "aoSAwdO5rbWdOArH04KNEgAAAQs"]
[Tue Aug 18 12:56:49.600187 2026] [autoindex:error] [pid 67073:tid 67286] [client 172.202.39.151:44886] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:49.612739 2026] [authz_core:error] [pid 67073:tid 67145] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:49.612997 2026] [authz_core:error] [pid 67073:tid 67145] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:49.626285 2026] [security2:error] [pid 66623:tid 66847] [client 47.128.53.184:38906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.icemaq.com.br"] [uri "/robots.txt"] [unique_id "aoSAwdO5rbWdOArH04KNFQAAAVs"]
[Tue Aug 18 12:56:49.660532 2026] [security2:error] [pid 67073:tid 67264] [client 79.127.164.8:54454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/messageinstallmysql.sql"] [unique_id "aoSAwfcmepr5_nHgLbNcywAAAk8"], referer: https://medihub.com.br/messageinstallmysql.sql
[Tue Aug 18 12:56:49.694393 2026] [security2:error] [pid 67073:tid 67227] [client 40.85.222.29:13252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/.cache/x.php"] [unique_id "aoSAwfcmepr5_nHgLbNczgAAAio"]
[Tue Aug 18 12:56:49.717978 2026] [security2:error] [pid 67073:tid 67306] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/x.php"] [unique_id "aoSAwfcmepr5_nHgLbNc0AAAAnk"]
[Tue Aug 18 12:56:49.727455 2026] [security2:error] [pid 66623:tid 66826] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwdO5rbWdOArH04KNFAABRg8"]
[Tue Aug 18 12:56:49.738585 2026] [security2:error] [pid 67073:tid 67254] [client 20.215.241.237:49164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAwfcmepr5_nHgLbNc0QAAAkU"]
[Tue Aug 18 12:56:49.792691 2026] [security2:error] [pid 67073:tid 67220] [client 20.52.168.85:8060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/mah.php"] [unique_id "aoSAwfcmepr5_nHgLbNc0gAAAiM"]
[Tue Aug 18 12:56:49.881901 2026] [security2:error] [pid 67073:tid 67170] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alyauto.com.br"] [uri "/phpinfo.php"] [unique_id "aoSAwfcmepr5_nHgLbNc1gACIV4"]
[Tue Aug 18 12:56:49.913868 2026] [security2:error] [pid 67073:tid 67241] [client 20.116.17.175:11212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/reop3.php"] [unique_id "aoSAwfcmepr5_nHgLbNc2gAAAjg"]
[Tue Aug 18 12:56:49.936244 2026] [security2:error] [pid 67073:tid 67159] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alyauto.com.br"] [uri "/info.php"] [unique_id "aoSAwfcmepr5_nHgLbNc3AACZlM"]
[Tue Aug 18 12:56:49.943737 2026] [security2:error] [pid 67073:tid 67280] [client 68.155.154.236:54386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/zjggu.php"] [unique_id "aoSAwfcmepr5_nHgLbNc3gAAAl8"]
[Tue Aug 18 12:56:49.946159 2026] [security2:error] [pid 67073:tid 67290] [client 172.202.39.151:44886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/xmlrpc.php"] [unique_id "aoSAwfcmepr5_nHgLbNc3wAAAmk"]
[Tue Aug 18 12:56:49.974951 2026] [security2:error] [pid 67073:tid 67212] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/yn.php"] [unique_id "aoSAwfcmepr5_nHgLbNc4QAAAhs"]
[Tue Aug 18 12:56:49.982996 2026] [security2:error] [pid 66623:tid 66892] [client 40.85.222.29:13236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSAwdO5rbWdOArH04KNIQAAAYg"]
[Tue Aug 18 12:56:49.995840 2026] [security2:error] [pid 66623:tid 66769] [client 178.153.171.161:47143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwdO5rbWdOArH04KNIgAAAQ0"]
[Tue Aug 18 12:56:49.995995 2026] [security2:error] [pid 66623:tid 66769] [client 178.153.171.161:47143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwdO5rbWdOArH04KNIgAAAQ0"]
[Tue Aug 18 12:56:50.061084 2026] [security2:error] [pid 67073:tid 67297] [client 74.248.136.165:61416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/05.php"] [unique_id "aoSAwvcmepr5_nHgLbNc5AAAAnA"]
[Tue Aug 18 12:56:50.080192 2026] [security2:error] [pid 67073:tid 67235] [client 20.171.51.14:21109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/mandrill.php"] [unique_id "aoSAwvcmepr5_nHgLbNc5gAAAjI"]
[Tue Aug 18 12:56:50.087563 2026] [security2:error] [pid 67073:tid 67284] [client 52.139.47.57:47623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/az.php"] [unique_id "aoSAwvcmepr5_nHgLbNc5wAAAmM"]
[Tue Aug 18 12:56:50.116491 2026] [security2:error] [pid 67073:tid 67319] [client 138.36.100.162:42886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwvcmepr5_nHgLbNc6AAAAoY"]
[Tue Aug 18 12:56:50.177967 2026] [security2:error] [pid 67073:tid 67078] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alyauto.com.br"] [uri "/pi.php"] [unique_id "aoSAwvcmepr5_nHgLbNc6gACNAI"]
[Tue Aug 18 12:56:50.179410 2026] [security2:error] [pid 67073:tid 67157] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alyauto.com.br"] [uri "/i.php"] [unique_id "aoSAwvcmepr5_nHgLbNc6wACLFE"]
[Tue Aug 18 12:56:50.197255 2026] [security2:error] [pid 67073:tid 67214] [client 20.250.13.23:21847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSAwvcmepr5_nHgLbNc7gAAAh0"]
[Tue Aug 18 12:56:50.200456 2026] [security2:error] [pid 67073:tid 67161] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alyauto.com.br"] [uri "/test.php"] [unique_id "aoSAwvcmepr5_nHgLbNc7wACOVU"]
[Tue Aug 18 12:56:50.237215 2026] [security2:error] [pid 66623:tid 66876] [client 135.225.75.187:27210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/motu.php"] [unique_id "aoSAwtO5rbWdOArH04KNJwAAAXg"]
[Tue Aug 18 12:56:50.269558 2026] [security2:error] [pid 67073:tid 67256] [client 40.85.222.29:13219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAwvcmepr5_nHgLbNc8AAAAkc"]
[Tue Aug 18 12:56:50.302488 2026] [security2:error] [pid 67073:tid 67184] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alyauto.com.br"] [uri "/app_dev.php"] [unique_id "aoSAwvcmepr5_nHgLbNc8wACVWw"]
[Tue Aug 18 12:56:50.306868 2026] [security2:error] [pid 67073:tid 67215] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/11.php"] [unique_id "aoSAwvcmepr5_nHgLbNc9AAAAh4"]
[Tue Aug 18 12:56:50.347153 2026] [security2:error] [pid 66623:tid 66875] [client 20.65.98.162:61374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/blurbs.php"] [unique_id "aoSAwtO5rbWdOArH04KNLgAAAXc"]
[Tue Aug 18 12:56:50.376754 2026] [security2:error] [pid 67073:tid 67283] [client 114.5.214.109:49812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwvcmepr5_nHgLbNc9wAAAmI"]
[Tue Aug 18 12:56:50.376923 2026] [security2:error] [pid 67073:tid 67283] [client 114.5.214.109:49812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwvcmepr5_nHgLbNc9wAAAmI"]
[Tue Aug 18 12:56:50.384100 2026] [security2:error] [pid 67073:tid 67198] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alyauto.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "aoSAwvcmepr5_nHgLbNc-AACdno"]
[Tue Aug 18 12:56:50.397436 2026] [security2:error] [pid 67073:tid 67307] [client 20.52.168.85:7819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/about.php"] [unique_id "aoSAwvcmepr5_nHgLbNc-QAAAno"]
[Tue Aug 18 12:56:50.423171 2026] [security2:error] [pid 66623:tid 66880] [client 104.209.144.33:29839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSAwtO5rbWdOArH04KNNAAAAXw"]
[Tue Aug 18 12:56:50.478189 2026] [security2:error] [pid 67073:tid 67310] [client 213.35.127.232:62525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAwvcmepr5_nHgLbNc_gAAAn0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:50.493974 2026] [security2:error] [pid 67073:tid 67319] [client 138.36.100.162:42886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwvcmepr5_nHgLbNc6AAAAoY"]
[Tue Aug 18 12:56:50.513311 2026] [security2:error] [pid 66623:tid 66890] [client 20.116.17.175:11248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/php5.php"] [unique_id "aoSAwtO5rbWdOArH04KNOwAAAYY"]
[Tue Aug 18 12:56:50.519301 2026] [security2:error] [pid 67073:tid 67228] [client 20.65.69.59:3761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/yindu.php"] [unique_id "aoSAwvcmepr5_nHgLbNdAgAAAis"]
[Tue Aug 18 12:56:50.520317 2026] [authz_core:error] [pid 67073:tid 67088] [remote 57.141.22.56:29018] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:50.520701 2026] [authz_core:error] [pid 67073:tid 67088] [remote 57.141.22.56:29018] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:50.556752 2026] [security2:error] [pid 66623:tid 66839] [client 40.85.222.29:12626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAwtO5rbWdOArH04KNPgAAAVM"]
[Tue Aug 18 12:56:50.562578 2026] [security2:error] [pid 67073:tid 67267] [client 68.155.154.236:16340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSAwvcmepr5_nHgLbNdBwAAAlI"]
[Tue Aug 18 12:56:50.573328 2026] [security2:error] [pid 66623:tid 66805] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/vm.php"] [unique_id "aoSAwtO5rbWdOArH04KNQQAAATE"]
[Tue Aug 18 12:56:50.578442 2026] [security2:error] [pid 66623:tid 66819] [client 68.155.154.236:54366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/dlvqo.php"] [unique_id "aoSAwtO5rbWdOArH04KNQwAAAT8"]
[Tue Aug 18 12:56:50.631994 2026] [security2:error] [pid 66623:tid 66889] [client 132.196.30.78:21947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/a.php"] [unique_id "aoSAwtO5rbWdOArH04KNRAAAAYU"]
[Tue Aug 18 12:56:50.726750 2026] [security2:error] [pid 67073:tid 67292] [client 52.139.47.57:9048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/sx.php"] [unique_id "aoSAwvcmepr5_nHgLbNdDwAAAms"]
[Tue Aug 18 12:56:50.736662 2026] [security2:error] [pid 66623:tid 66786] [client 40.74.65.169:28168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAwtO5rbWdOArH04KNSgAAAR4"]
[Tue Aug 18 12:56:50.817798 2026] [security2:error] [pid 67073:tid 67231] [client 52.139.47.57:44652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/wp-mail.php"] [unique_id "aoSAwvcmepr5_nHgLbNdEAAAAi4"]
[Tue Aug 18 12:56:50.820196 2026] [security2:error] [pid 66623:tid 66845] [client 84.247.146.84:53430] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "i-databi.com.br"] [uri "/wp-json/batch/v1"] [unique_id "aoSAwtO5rbWdOArH04KNUAAAAVk"]
[Tue Aug 18 12:56:50.832629 2026] [security2:error] [pid 67073:tid 67314] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/eg.php"] [unique_id "aoSAwvcmepr5_nHgLbNdEgAAAoE"]
[Tue Aug 18 12:56:50.842069 2026] [security2:error] [pid 67073:tid 67112] [remote 103.56.163.133:38562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "paciolli.com.br"] [uri "/wp-login.php"] [unique_id "aoSAwvcmepr5_nHgLbNdEwACdSQ"]
[Tue Aug 18 12:56:50.845436 2026] [security2:error] [pid 67073:tid 67318] [client 40.85.222.29:13241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSAwvcmepr5_nHgLbNdFAAAAoU"]
[Tue Aug 18 12:56:50.849676 2026] [security2:error] [pid 67073:tid 67321] [client 20.100.169.31:48595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSAwvcmepr5_nHgLbNdFQAAAog"]
[Tue Aug 18 12:56:50.866475 2026] [security2:error] [pid 67073:tid 67227] [client 158.23.17.4:63656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/verification.php"] [unique_id "aoSAwvcmepr5_nHgLbNdGAAAAio"]
[Tue Aug 18 12:56:50.912830 2026] [security2:error] [pid 67073:tid 67199] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/api/.env"] [unique_id "aoSAwvcmepr5_nHgLbNdGQACRXs"]
[Tue Aug 18 12:56:50.925868 2026] [access_compat:error] [pid 67073:tid 67106] [remote 34.158.8.33:32992] AH01797: client denied by server configuration: /home3/alyautocom/public_html/server-status
[Tue Aug 18 12:56:50.931558 2026] [security2:error] [pid 66623:tid 66809] [client 172.202.39.151:55475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/cache.php"] [unique_id "aoSAwtO5rbWdOArH04KNVwAAATU"]
[Tue Aug 18 12:56:50.935301 2026] [security2:error] [pid 66623:tid 66883] [client 20.171.51.14:15775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/main.php"] [unique_id "aoSAwtO5rbWdOArH04KNWAAAAX8"]
[Tue Aug 18 12:56:51.006679 2026] [security2:error] [pid 67073:tid 67277] [client 85.154.68.202:52046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAw_cmepr5_nHgLbNdHAAAAlw"]
[Tue Aug 18 12:56:51.006847 2026] [security2:error] [pid 67073:tid 67277] [client 85.154.68.202:52046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAw_cmepr5_nHgLbNdHAAAAlw"]
[Tue Aug 18 12:56:51.013214 2026] [security2:error] [pid 66623:tid 66855] [client 20.52.168.85:7827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/sid3.php"] [unique_id "aoSAw9O5rbWdOArH04KNXAAAAWM"]
[Tue Aug 18 12:56:51.042756 2026] [security2:error] [pid 67073:tid 67250] [client 192.141.172.134:62073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAw_cmepr5_nHgLbNdHgAAAkE"]
[Tue Aug 18 12:56:51.042869 2026] [security2:error] [pid 67073:tid 67250] [client 192.141.172.134:62073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAw_cmepr5_nHgLbNdHgAAAkE"]
[Tue Aug 18 12:56:51.049678 2026] [security2:error] [pid 67073:tid 67241] [client 20.116.17.175:11258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/acp.php"] [unique_id "aoSAw_cmepr5_nHgLbNdHwAAAjg"]
[Tue Aug 18 12:56:51.053878 2026] [security2:error] [pid 67073:tid 67326] [client 20.215.241.237:31591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/akismet.php"] [unique_id "aoSAw_cmepr5_nHgLbNdIAAAAo0"]
[Tue Aug 18 12:56:51.069792 2026] [security2:error] [pid 66623:tid 66832] [client 160.120.140.123:62982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAw9O5rbWdOArH04KNZQAAAUw"]
[Tue Aug 18 12:56:51.069883 2026] [security2:error] [pid 66623:tid 66832] [client 160.120.140.123:62982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAw9O5rbWdOArH04KNZQAAAUw"]
[Tue Aug 18 12:56:51.137407 2026] [security2:error] [pid 66623:tid 66823] [client 40.85.222.29:13209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSAw9O5rbWdOArH04KNaAAAAUM"]
[Tue Aug 18 12:56:51.143122 2026] [security2:error] [pid 67073:tid 67101] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/backend/.env"] [unique_id "aoSAw_cmepr5_nHgLbNdKwAChxk"]
[Tue Aug 18 12:56:51.150372 2026] [security2:error] [pid 67073:tid 67102] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/config/.env"] [unique_id "aoSAw_cmepr5_nHgLbNdLgAChxo"]
[Tue Aug 18 12:56:51.161016 2026] [security2:error] [pid 67073:tid 67325] [client 52.139.47.57:44627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/tfm.php"] [unique_id "aoSAw_cmepr5_nHgLbNdLwAAAow"]
[Tue Aug 18 12:56:51.210551 2026] [security2:error] [pid 67073:tid 67279] [client 132.196.30.78:19398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/chosen.php"] [unique_id "aoSAw_cmepr5_nHgLbNdMQAAAl4"]
[Tue Aug 18 12:56:51.250369 2026] [security2:error] [pid 67073:tid 67234] [client 20.65.69.59:57025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/sxx.php"] [unique_id "aoSAw_cmepr5_nHgLbNdMgAAAjE"]
[Tue Aug 18 12:56:51.251942 2026] [security2:error] [pid 67073:tid 67235] [client 20.226.56.190:30990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gb.php"] [unique_id "aoSAw_cmepr5_nHgLbNdMwAAAjI"]
[Tue Aug 18 12:56:51.310097 2026] [security2:error] [pid 66623:tid 66824] [client 20.206.73.37:20689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/images.php"] [unique_id "aoSAw9O5rbWdOArH04KNcgAAAUQ"]
[Tue Aug 18 12:56:51.419078 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:51.419347 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:51.421411 2026] [security2:error] [pid 66623:tid 66847] [client 74.248.136.165:22509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/public/hi.php"] [unique_id "aoSAw9O5rbWdOArH04KNdgAAAVs"]
[Tue Aug 18 12:56:51.426246 2026] [security2:error] [pid 67073:tid 67329] [client 158.23.17.4:9298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/smtp.php"] [unique_id "aoSAw_cmepr5_nHgLbNdPQAAApA"]
[Tue Aug 18 12:56:51.430320 2026] [security2:error] [pid 67073:tid 67246] [client 40.85.222.29:12609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSAw_cmepr5_nHgLbNdPgAAAj0"]
[Tue Aug 18 12:56:51.435545 2026] [security2:error] [pid 67073:tid 67208] [client 40.74.65.169:28202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAw_cmepr5_nHgLbNdPwAAAhc"]
[Tue Aug 18 12:56:51.459560 2026] [security2:error] [pid 67073:tid 67266] [client 135.225.75.187:37306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/fff.php"] [unique_id "aoSAw_cmepr5_nHgLbNdQQAAAlE"]
[Tue Aug 18 12:56:51.498978 2026] [security2:error] [pid 66623:tid 66862] [client 213.35.127.232:62745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAw9O5rbWdOArH04KNgAAAAWo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:51.532782 2026] [security2:error] [pid 67073:tid 67300] [client 52.139.47.57:18409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/wp-the.php"] [unique_id "aoSAw_cmepr5_nHgLbNdQwAAAnM"]
[Tue Aug 18 12:56:51.564147 2026] [security2:error] [pid 66623:tid 66794] [client 20.226.56.190:45049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/jp.php"] [unique_id "aoSAw9O5rbWdOArH04KNgwAAASY"]
[Tue Aug 18 12:56:51.576911 2026] [security2:error] [pid 67073:tid 67294] [client 20.250.13.23:14286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/themes.php"] [unique_id "aoSAw_cmepr5_nHgLbNdRwAAAm0"]
[Tue Aug 18 12:56:51.604306 2026] [authz_core:error] [pid 67073:tid 67187] [remote 57.141.0.37:48816] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:51.604594 2026] [authz_core:error] [pid 67073:tid 67187] [remote 57.141.0.37:48816] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:51.611876 2026] [security2:error] [pid 66623:tid 66892] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/uk.php"] [unique_id "aoSAw9O5rbWdOArH04KNhQAAAYg"]
[Tue Aug 18 12:56:51.614084 2026] [security2:error] [pid 66623:tid 66798] [client 20.52.168.85:7766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/blog.php7"] [unique_id "aoSAw9O5rbWdOArH04KNhgAAASo"]
[Tue Aug 18 12:56:51.655081 2026] [security2:error] [pid 67073:tid 67216] [client 52.139.47.57:38987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/asd.php"] [unique_id "aoSAw_cmepr5_nHgLbNdUQAAAh8"]
[Tue Aug 18 12:56:51.666000 2026] [security2:error] [pid 66623:tid 66640] [remote 97.74.87.194:43536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centraldasvariedades.com.br"] [uri "/wp-login.php"] [unique_id "aoSAw9O5rbWdOArH04KNiQABewM"]
[Tue Aug 18 12:56:51.701060 2026] [security2:error] [pid 67073:tid 67225] [client 20.65.69.59:49336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/settings.php"] [unique_id "aoSAw_cmepr5_nHgLbNdVAAAAig"]
[Tue Aug 18 12:56:51.708611 2026] [security2:error] [pid 66623:tid 66802] [client 132.196.30.78:21896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAw9O5rbWdOArH04KNigAAAS4"]
[Tue Aug 18 12:56:51.713934 2026] [security2:error] [pid 67073:tid 67230] [client 40.85.222.29:13196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSAw_cmepr5_nHgLbNdVgAAAi0"]
[Tue Aug 18 12:56:51.715815 2026] [security2:error] [pid 67073:tid 67275] [client 20.215.241.237:61102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp.php"] [unique_id "aoSAw_cmepr5_nHgLbNdWAAAAlo"]
[Tue Aug 18 12:56:51.725646 2026] [authz_core:error] [pid 67073:tid 67202] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:51.725935 2026] [authz_core:error] [pid 67073:tid 67202] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:51.743263 2026] [security2:error] [pid 66623:tid 66831] [client 68.155.154.236:7914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/pkmoj.php"] [unique_id "aoSAw9O5rbWdOArH04KNkAAAAUs"]
[Tue Aug 18 12:56:51.794538 2026] [fcgid:warn] [pid 67073:tid 67286] (70014)End of file found: [client 66.132.186.168:16060] mod_fcgid: can't get data from http client
[Tue Aug 18 12:56:51.859859 2026] [security2:error] [pid 66623:tid 66857] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/creds.php"] [unique_id "aoSAw9O5rbWdOArH04KNlAAAAWU"]
[Tue Aug 18 12:56:51.902416 2026] [security2:error] [pid 67073:tid 67227] [client 20.171.51.14:62470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ga.php"] [unique_id "aoSAw_cmepr5_nHgLbNdYAAAAio"]
[Tue Aug 18 12:56:52.009303 2026] [security2:error] [pid 67073:tid 67263] [client 40.85.222.29:13207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSAxPcmepr5_nHgLbNdZgAAAk4"]
[Tue Aug 18 12:56:52.051924 2026] [security2:error] [pid 67073:tid 67304] [client 172.182.200.96:14198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSAxPcmepr5_nHgLbNdaAAAAnc"]
[Tue Aug 18 12:56:52.054410 2026] [security2:error] [pid 67073:tid 67250] [client 20.116.17.175:57633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/yas.php"] [unique_id "aoSAxPcmepr5_nHgLbNdaQAAAkE"]
[Tue Aug 18 12:56:52.082328 2026] [security2:error] [pid 67073:tid 67125] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.env"] [unique_id "aoSAxPcmepr5_nHgLbNdawACODE"]
[Tue Aug 18 12:56:52.118220 2026] [security2:error] [pid 67073:tid 67280] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ho.php"] [unique_id "aoSAxPcmepr5_nHgLbNdbAAAAl8"]
[Tue Aug 18 12:56:52.133852 2026] [security2:error] [pid 67073:tid 67268] [client 40.74.65.169:27772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/domvf.php"] [unique_id "aoSAxPcmepr5_nHgLbNdbwAAAlM"]
[Tue Aug 18 12:56:52.147173 2026] [security2:error] [pid 67073:tid 67243] [client 20.100.169.31:43919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSAxPcmepr5_nHgLbNdcAAAAjo"]
[Tue Aug 18 12:56:52.218867 2026] [security2:error] [pid 66623:tid 66780] [client 20.52.168.85:8020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/GOD.php"] [unique_id "aoSAxNO5rbWdOArH04KNmwAAARg"]
[Tue Aug 18 12:56:52.240358 2026] [security2:error] [pid 67073:tid 67218] [client 52.139.47.57:16677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/wp.php"] [unique_id "aoSAxPcmepr5_nHgLbNddAAAAiE"]
[Tue Aug 18 12:56:52.251053 2026] [security2:error] [pid 67073:tid 67287] [client 132.196.30.78:21900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/vx.php"] [unique_id "aoSAxPcmepr5_nHgLbNddgAAAmY"]
[Tue Aug 18 12:56:52.272946 2026] [security2:error] [pid 67073:tid 67229] [client 20.65.69.59:49295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/spip.php"] [unique_id "aoSAxPcmepr5_nHgLbNddwAAAiw"]
[Tue Aug 18 12:56:52.320465 2026] [authz_core:error] [pid 67073:tid 67085] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:52.320735 2026] [authz_core:error] [pid 67073:tid 67085] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:52.335535 2026] [security2:error] [pid 67073:tid 67200] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.github/.env"] [unique_id "aoSAxPcmepr5_nHgLbNdegACFnw"]
[Tue Aug 18 12:56:52.338347 2026] [security2:error] [pid 67073:tid 67309] [client 40.85.222.29:13275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSAxPcmepr5_nHgLbNdfAAAAnw"]
[Tue Aug 18 12:56:52.340112 2026] [security2:error] [pid 67073:tid 67283] [client 172.202.39.151:43249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/ok.php"] [unique_id "aoSAxPcmepr5_nHgLbNdfQAAAmI"]
[Tue Aug 18 12:56:52.345767 2026] [security2:error] [pid 67073:tid 67226] [client 158.158.34.183:55823] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "aesexaustores.com.br"] [uri "/1.php"] [unique_id "aoSAxPcmepr5_nHgLbNdfgAAAik"]
[Tue Aug 18 12:56:52.345877 2026] [security2:error] [pid 67073:tid 67226] [client 158.158.34.183:55823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/1.php"] [unique_id "aoSAxPcmepr5_nHgLbNdfgAAAik"]
[Tue Aug 18 12:56:52.386410 2026] [security2:error] [pid 67073:tid 67259] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/97.php"] [unique_id "aoSAxPcmepr5_nHgLbNdfwAAAko"]
[Tue Aug 18 12:56:52.388996 2026] [security2:error] [pid 67073:tid 67209] [client 74.248.136.165:28126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/get.php"] [unique_id "aoSAxPcmepr5_nHgLbNdgAAAAhg"]
[Tue Aug 18 12:56:52.408307 2026] [security2:error] [pid 67073:tid 67203] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.env.backup"] [unique_id "aoSAxPcmepr5_nHgLbNdggACfX8"]
[Tue Aug 18 12:56:52.427991 2026] [autoindex:error] [pid 67073:tid 67251] [client 172.202.39.151:55448] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:52.429153 2026] [security2:error] [pid 67073:tid 67319] [client 135.225.75.187:47220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/66.php"] [unique_id "aoSAxPcmepr5_nHgLbNdhQAAAoY"]
[Tue Aug 18 12:56:52.432615 2026] [security2:error] [pid 67073:tid 67332] [client 158.158.74.177:2653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/storage/index.php"] [unique_id "aoSAxPcmepr5_nHgLbNdhgAAApM"]
[Tue Aug 18 12:56:52.456022 2026] [security2:error] [pid 67073:tid 67208] [client 172.202.39.151:30105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/moon.php"] [unique_id "aoSAxPcmepr5_nHgLbNdhwAAAhc"]
[Tue Aug 18 12:56:52.481269 2026] [security2:error] [pid 67073:tid 67210] [client 20.215.241.237:21542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/admin.php"] [unique_id "aoSAxPcmepr5_nHgLbNdiAAAAhk"]
[Tue Aug 18 12:56:52.500263 2026] [security2:error] [pid 67073:tid 67253] [client 104.209.144.33:34148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-2019.php"] [unique_id "aoSAxPcmepr5_nHgLbNdiQAAAkQ"]
[Tue Aug 18 12:56:52.513957 2026] [security2:error] [pid 67073:tid 67325] [client 213.35.127.232:62963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAxPcmepr5_nHgLbNdigAAAow"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:52.541761 2026] [security2:error] [pid 66623:tid 66889] [client 20.206.73.37:20705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/admin.php"] [unique_id "aoSAxNO5rbWdOArH04KNpAAAAYU"]
[Tue Aug 18 12:56:52.602378 2026] [security2:error] [pid 67073:tid 67222] [client 158.23.17.4:38907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/teste.php"] [unique_id "aoSAxPcmepr5_nHgLbNdjwAAAiU"]
[Tue Aug 18 12:56:52.610766 2026] [security2:error] [pid 66623:tid 66785] [client 52.139.47.57:18200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/nij.php"] [unique_id "aoSAxNO5rbWdOArH04KNpgAAAR0"]
[Tue Aug 18 12:56:52.615622 2026] [security2:error] [pid 67073:tid 67282] [client 20.215.241.237:59472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/i.php"] [unique_id "aoSAxPcmepr5_nHgLbNdkAAAAmE"]
[Tue Aug 18 12:56:52.622937 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:52.623193 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:52.624394 2026] [security2:error] [pid 67073:tid 67248] [client 40.85.222.29:12634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSAxPcmepr5_nHgLbNdkgAAAj8"]
[Tue Aug 18 12:56:52.644751 2026] [security2:error] [pid 67073:tid 67153] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.env.bak"] [unique_id "aoSAxPcmepr5_nHgLbNdlAACLU0"]
[Tue Aug 18 12:56:52.644752 2026] [security2:error] [pid 67073:tid 67155] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.env.old"] [unique_id "aoSAxPcmepr5_nHgLbNdlQACLU8"]
[Tue Aug 18 12:56:52.698915 2026] [security2:error] [pid 66623:tid 66796] [client 157.51.166.53:63083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAxNO5rbWdOArH04KNqgAAASg"]
[Tue Aug 18 12:56:52.699058 2026] [security2:error] [pid 66623:tid 66796] [client 157.51.166.53:63083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAxNO5rbWdOArH04KNqgAAASg"]
[Tue Aug 18 12:56:52.699979 2026] [security2:error] [pid 66623:tid 66858] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/rh.php"] [unique_id "aoSAxNO5rbWdOArH04KNqwAAAWY"]
[Tue Aug 18 12:56:52.709837 2026] [security2:error] [pid 67073:tid 67249] [client 20.100.169.31:35378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/function/function.php"] [unique_id "aoSAxPcmepr5_nHgLbNdnQAAAkA"]
[Tue Aug 18 12:56:52.786153 2026] [security2:error] [pid 67073:tid 67291] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAxPcmepr5_nHgLbNdoAACaj8"]
[Tue Aug 18 12:56:52.817244 2026] [security2:error] [pid 67073:tid 67296] [client 20.52.168.85:7682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/alumni_reg.php"] [unique_id "aoSAxPcmepr5_nHgLbNdogAAAm8"]
[Tue Aug 18 12:56:52.837586 2026] [security2:error] [pid 66623:tid 66814] [client 40.74.65.169:7391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSAxNO5rbWdOArH04KNrgAAATo"]
[Tue Aug 18 12:56:52.837710 2026] [security2:error] [pid 66623:tid 66799] [client 68.155.154.236:58894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/kopyw.php"] [unique_id "aoSAxNO5rbWdOArH04KNrwAAASs"]
[Tue Aug 18 12:56:52.893933 2026] [security2:error] [pid 67073:tid 67317] [client 20.116.17.175:11239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/ah25.php"] [unique_id "aoSAxPcmepr5_nHgLbNdpQAAAoQ"]
[Tue Aug 18 12:56:52.920499 2026] [security2:error] [pid 67073:tid 67232] [client 40.85.222.29:13258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSAxPcmepr5_nHgLbNdqAAAAi8"]
[Tue Aug 18 12:56:52.927067 2026] [security2:error] [pid 67073:tid 67263] [client 20.65.69.59:49309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/search.php"] [unique_id "aoSAxPcmepr5_nHgLbNdqQAAAk4"]
[Tue Aug 18 12:56:52.929679 2026] [authz_core:error] [pid 67073:tid 67183] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:52.930114 2026] [authz_core:error] [pid 67073:tid 67183] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:52.965846 2026] [security2:error] [pid 67073:tid 67304] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/yg.php"] [unique_id "aoSAxPcmepr5_nHgLbNdqgAAAnc"]
[Tue Aug 18 12:56:52.978025 2026] [security2:error] [pid 67073:tid 67225] [client 20.100.169.31:7714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/bgymj.php"] [unique_id "aoSAxPcmepr5_nHgLbNdqwAAAig"]
[Tue Aug 18 12:56:52.987801 2026] [authz_core:error] [pid 67073:tid 67194] [remote 34.158.8.33:32992] AH01630: client denied by server configuration: /home3/alyautocom/public_html/.htpasswd
[Tue Aug 18 12:56:52.987893 2026] [security2:error] [pid 67073:tid 67276] [client 52.139.47.57:44647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/wso.php"] [unique_id "aoSAxPcmepr5_nHgLbNdrwAAAls"]
[Tue Aug 18 12:56:53.010264 2026] [security2:error] [pid 66623:tid 66867] [client 68.155.156.252:40229] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "email.domcoworking.com.br"] [uri "/1.php"] [unique_id "aoSAxdO5rbWdOArH04KNtAAAAW8"]
[Tue Aug 18 12:56:53.010378 2026] [security2:error] [pid 66623:tid 66867] [client 68.155.156.252:40229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/1.php"] [unique_id "aoSAxdO5rbWdOArH04KNtAAAAW8"]
[Tue Aug 18 12:56:53.027741 2026] [security2:error] [pid 67073:tid 67212] [client 172.202.39.151:55448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAxfcmepr5_nHgLbNdsQAAAhs"]
[Tue Aug 18 12:56:53.035788 2026] [security2:error] [pid 67073:tid 67100] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSAxfcmepr5_nHgLbNdswACUxg"]
[Tue Aug 18 12:56:53.118882 2026] [security2:error] [pid 66623:tid 66832] [client 158.23.17.4:29493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/local.php"] [unique_id "aoSAxdO5rbWdOArH04KNuAAAAUw"]
[Tue Aug 18 12:56:53.179777 2026] [security2:error] [pid 67073:tid 67305] [client 49.13.134.145:6936] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.melocorretordeimoveis.com.br"] [uri "/"] [unique_id "aoSAxfcmepr5_nHgLbNdtwAAAng"], referer: http://www.melocorretordeimoveis.com.br
[Tue Aug 18 12:56:53.201432 2026] [security2:error] [pid 66623:tid 66793] [client 40.85.222.29:13231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSAxdO5rbWdOArH04KNugAAASU"]
[Tue Aug 18 12:56:53.212188 2026] [security2:error] [pid 67073:tid 67320] [client 52.139.47.57:63055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/404.php"] [unique_id "aoSAxfcmepr5_nHgLbNduQAAAoc"]
[Tue Aug 18 12:56:53.215041 2026] [security2:error] [pid 66623:tid 66816] [client 132.196.30.78:19436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wap.php"] [unique_id "aoSAxdO5rbWdOArH04KNvAAAATw"]
[Tue Aug 18 12:56:53.243389 2026] [security2:error] [pid 67073:tid 67226] [client 20.171.51.14:58871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/wb.php"] [unique_id "aoSAxfcmepr5_nHgLbNduwAAAik"]
[Tue Aug 18 12:56:53.293695 2026] [security2:error] [pid 67073:tid 67281] [client 20.215.241.237:59481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/abcd.php"] [unique_id "aoSAxfcmepr5_nHgLbNdvwAAAmA"]
[Tue Aug 18 12:56:53.299486 2026] [security2:error] [pid 67073:tid 67209] [client 52.173.121.69:16467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/mt/byp.php"] [unique_id "aoSAxfcmepr5_nHgLbNdwAAAAhg"]
[Tue Aug 18 12:56:53.405765 2026] [security2:error] [pid 67073:tid 67242] [client 104.209.144.33:36509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSAxfcmepr5_nHgLbNdxQAAAjk"]
[Tue Aug 18 12:56:53.424583 2026] [security2:error] [pid 67073:tid 67287] [client 20.52.168.85:7824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/depotcv.php"] [unique_id "aoSAxfcmepr5_nHgLbNdxgAAAmY"]
[Tue Aug 18 12:56:53.428508 2026] [security2:error] [pid 67073:tid 67315] [client 20.250.13.23:39632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/cv.php"] [unique_id "aoSAxfcmepr5_nHgLbNdyAAAAoI"]
[Tue Aug 18 12:56:53.505039 2026] [security2:error] [pid 67073:tid 67098] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSAxfcmepr5_nHgLbNdywACjxY"]
[Tue Aug 18 12:56:53.526944 2026] [authz_core:error] [pid 67073:tid 67159] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:53.527212 2026] [authz_core:error] [pid 67073:tid 67159] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:53.535312 2026] [security2:error] [pid 67073:tid 67236] [client 213.35.127.232:63192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAxfcmepr5_nHgLbNdzQAAAjM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:53.537547 2026] [security2:error] [pid 67073:tid 67221] [client 40.74.65.169:27038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/gec.php"] [unique_id "aoSAxfcmepr5_nHgLbNdzgAAAiQ"]
[Tue Aug 18 12:56:53.548064 2026] [security2:error] [pid 67073:tid 67330] [client 40.85.222.29:12612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAxfcmepr5_nHgLbNd0AAAApE"]
[Tue Aug 18 12:56:53.574999 2026] [security2:error] [pid 67073:tid 67294] [client 20.65.69.59:3205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/build.php"] [unique_id "aoSAxfcmepr5_nHgLbNd0QAAAm0"]
[Tue Aug 18 12:56:53.586682 2026] [security2:error] [pid 66623:tid 66884] [client 68.155.154.236:46620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/zznmg.php"] [unique_id "aoSAxdO5rbWdOArH04KN0wAAAYA"]
[Tue Aug 18 12:56:53.610573 2026] [security2:error] [pid 66623:tid 66803] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/et.php"] [unique_id "aoSAxdO5rbWdOArH04KN1AAAAS8"]
[Tue Aug 18 12:56:53.619178 2026] [security2:error] [pid 66623:tid 66829] [client 172.202.39.151:54717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/item.php"] [unique_id "aoSAxdO5rbWdOArH04KN1QAAAUk"]
[Tue Aug 18 12:56:53.633403 2026] [security2:error] [pid 67073:tid 67273] [client 52.139.47.57:1501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/mah.php"] [unique_id "aoSAxfcmepr5_nHgLbNd1AAAAlg"]
[Tue Aug 18 12:56:53.682375 2026] [security2:error] [pid 67073:tid 67275] [client 20.116.17.175:11223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/ano.php"] [unique_id "aoSAxfcmepr5_nHgLbNd2AAAAlo"]
[Tue Aug 18 12:56:53.682416 2026] [security2:error] [pid 66623:tid 66782] [client 47.128.36.158:65518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "reservamatadapraia.com.br"] [uri "/robots.txt"] [unique_id "aoSAxdO5rbWdOArH04KN2gAAARo"]
[Tue Aug 18 12:56:53.721870 2026] [security2:error] [pid 66623:tid 66767] [client 20.226.56.190:47118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/eq.php"] [unique_id "aoSAxdO5rbWdOArH04KN2wAAAQs"]
[Tue Aug 18 12:56:53.734819 2026] [security2:error] [pid 66623:tid 66888] [client 52.139.47.57:11762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/www.php"] [unique_id "aoSAxdO5rbWdOArH04KN3AAAAYQ"]
[Tue Aug 18 12:56:53.752268 2026] [security2:error] [pid 67073:tid 67205] [client 158.158.74.177:17947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/storage/rip.php"] [unique_id "aoSAxfcmepr5_nHgLbNd2wAAAhQ"]
[Tue Aug 18 12:56:53.768907 2026] [security2:error] [pid 67073:tid 67219] [client 172.202.39.151:61396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/cache.php"] [unique_id "aoSAxfcmepr5_nHgLbNd3gAAAiI"]
[Tue Aug 18 12:56:53.825127 2026] [security2:error] [pid 67073:tid 67296] [client 20.171.51.14:29238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/xn.php"] [unique_id "aoSAxfcmepr5_nHgLbNd4wAAAm8"]
[Tue Aug 18 12:56:53.830059 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:53.830320 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:53.853063 2026] [security2:error] [pid 67073:tid 67185] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSAxfcmepr5_nHgLbNd5QACZG0"]
[Tue Aug 18 12:56:53.854882 2026] [security2:error] [pid 67073:tid 67228] [client 40.85.222.29:13300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSAxfcmepr5_nHgLbNd5gAAAis"]
[Tue Aug 18 12:56:53.887255 2026] [security2:error] [pid 66623:tid 66843] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/of.php"] [unique_id "aoSAxdO5rbWdOArH04KOFwAAAVc"]
[Tue Aug 18 12:56:53.913079 2026] [security2:error] [pid 67073:tid 67238] [client 74.248.136.165:18006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/rpk.php"] [unique_id "aoSAxfcmepr5_nHgLbNd5wAAAjU"]
[Tue Aug 18 12:56:53.954775 2026] [security2:error] [pid 67073:tid 67304] [client 20.206.73.37:63237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/222.php"] [unique_id "aoSAxfcmepr5_nHgLbNd6AAAAnc"]
[Tue Aug 18 12:56:53.988924 2026] [security2:error] [pid 66623:tid 66824] [client 132.196.30.78:21914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSAxdO5rbWdOArH04KOGQAAAUQ"]
[Tue Aug 18 12:56:53.996542 2026] [security2:error] [pid 66623:tid 66769] [client 158.23.17.4:29475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/wp_sitting.php"] [unique_id "aoSAxdO5rbWdOArH04KOGwAAAQ0"]
[Tue Aug 18 12:56:54.025917 2026] [security2:error] [pid 67073:tid 67254] [client 20.52.168.85:7804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/admin.php7"] [unique_id "aoSAxvcmepr5_nHgLbNd6gAAAkU"]
[Tue Aug 18 12:56:54.084342 2026] [security2:error] [pid 67073:tid 67311] [client 196.12.128.158:51736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAxvcmepr5_nHgLbNd7AAAAn4"]
[Tue Aug 18 12:56:54.084441 2026] [security2:error] [pid 67073:tid 67311] [client 196.12.128.158:51736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAxvcmepr5_nHgLbNd7AAAAn4"]
[Tue Aug 18 12:56:54.087514 2026] [security2:error] [pid 67073:tid 67118] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/id_rsa"] [unique_id "aoSAxvcmepr5_nHgLbNd7QACICo"]
[Tue Aug 18 12:56:54.129933 2026] [authz_core:error] [pid 67073:tid 67110] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:54.130198 2026] [authz_core:error] [pid 67073:tid 67110] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:54.131771 2026] [security2:error] [pid 67073:tid 67271] [client 20.215.241.237:43600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-manager.php"] [unique_id "aoSAxvcmepr5_nHgLbNd8QAAAlY"]
[Tue Aug 18 12:56:54.137886 2026] [security2:error] [pid 66623:tid 66848] [client 52.139.47.57:47643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/ws.php7"] [unique_id "aoSAxtO5rbWdOArH04KOJwAAAVw"]
[Tue Aug 18 12:56:54.142515 2026] [security2:error] [pid 67073:tid 67261] [client 40.85.222.29:13310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/well-known/index.php"] [unique_id "aoSAxvcmepr5_nHgLbNd8gAAAkw"]
[Tue Aug 18 12:56:54.171811 2026] [security2:error] [pid 67073:tid 67211] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/bu.php"] [unique_id "aoSAxvcmepr5_nHgLbNd8wAAAho"]
[Tue Aug 18 12:56:54.176189 2026] [security2:error] [pid 67073:tid 67239] [client 20.215.241.237:31607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/ajax.php"] [unique_id "aoSAxvcmepr5_nHgLbNd9AAAAjY"]
[Tue Aug 18 12:56:54.179323 2026] [security2:error] [pid 67073:tid 67279] [client 20.116.17.175:57452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/nwflm.php"] [unique_id "aoSAxvcmepr5_nHgLbNd9QAAAl4"]
[Tue Aug 18 12:56:54.193742 2026] [security2:error] [pid 67073:tid 67227] [client 20.100.169.31:45609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/aa.php"] [unique_id "aoSAxvcmepr5_nHgLbNd9wAAAio"]
[Tue Aug 18 12:56:54.221128 2026] [security2:error] [pid 66623:tid 66802] [client 20.226.56.190:2186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ep.php"] [unique_id "aoSAxtO5rbWdOArH04KOPgAAAS4"]
[Tue Aug 18 12:56:54.230429 2026] [security2:error] [pid 66623:tid 66887] [client 104.209.144.33:25648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/.cache/x.php"] [unique_id "aoSAxtO5rbWdOArH04KOPwAAAYM"]
[Tue Aug 18 12:56:54.235394 2026] [security2:error] [pid 66623:tid 66825] [client 40.74.65.169:26747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/sky.php"] [unique_id "aoSAxtO5rbWdOArH04KOQAAAAUU"]
[Tue Aug 18 12:56:54.434150 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:54.434599 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:54.445493 2026] [security2:error] [pid 67073:tid 67259] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/rn.php"] [unique_id "aoSAxvcmepr5_nHgLbNd-wAAAko"]
[Tue Aug 18 12:56:54.452871 2026] [security2:error] [pid 67073:tid 67281] [client 40.85.222.29:13292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSAxvcmepr5_nHgLbNd_AAAAmA"]
[Tue Aug 18 12:56:54.484552 2026] [security2:error] [pid 67073:tid 67164] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/id_dsa"] [unique_id "aoSAxvcmepr5_nHgLbNd_wACXVg"]
[Tue Aug 18 12:56:54.512357 2026] [security2:error] [pid 67073:tid 67237] [client 158.158.74.177:26122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/sts.php"] [unique_id "aoSAxvcmepr5_nHgLbNeAAAAAjQ"]
[Tue Aug 18 12:56:54.548881 2026] [security2:error] [pid 66623:tid 66844] [client 213.35.127.232:63398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAxtO5rbWdOArH04KOaAAAAVg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:54.567188 2026] [security2:error] [pid 66623:tid 66873] [client 52.139.47.57:47652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/jga.php"] [unique_id "aoSAxtO5rbWdOArH04KOaQAAAXU"]
[Tue Aug 18 12:56:54.586518 2026] [security2:error] [pid 66623:tid 66890] [client 158.23.17.4:63619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/ninja.php"] [unique_id "aoSAxtO5rbWdOArH04KOawAAAYY"]
[Tue Aug 18 12:56:54.592610 2026] [security2:error] [pid 67073:tid 67283] [client 132.196.30.78:20161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/bgymj.php"] [unique_id "aoSAxvcmepr5_nHgLbNeAQAAAmI"]
[Tue Aug 18 12:56:54.644553 2026] [security2:error] [pid 66623:tid 66780] [client 20.52.168.85:8053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/f.php"] [unique_id "aoSAxtO5rbWdOArH04KObgAAARg"]
[Tue Aug 18 12:56:54.721086 2026] [security2:error] [pid 66623:tid 66789] [client 135.225.75.187:56771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/g.php"] [unique_id "aoSAxtO5rbWdOArH04KOcAAAASE"]
[Tue Aug 18 12:56:54.729230 2026] [security2:error] [pid 67073:tid 67280] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ut.php"] [unique_id "aoSAxvcmepr5_nHgLbNeBAAAAl8"]
[Tue Aug 18 12:56:54.741679 2026] [security2:error] [pid 67073:tid 67210] [client 20.215.241.237:40511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSAxvcmepr5_nHgLbNeBQAAAhk"]
[Tue Aug 18 12:56:54.744842 2026] [security2:error] [pid 67073:tid 67269] [client 20.65.69.59:49340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/defaul.php"] [unique_id "aoSAxvcmepr5_nHgLbNeBgAAAlQ"]
[Tue Aug 18 12:56:54.770845 2026] [security2:error] [pid 67073:tid 67310] [client 52.139.47.57:47630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/x.php"] [unique_id "aoSAxvcmepr5_nHgLbNeCAAAAn0"]
[Tue Aug 18 12:56:54.771363 2026] [security2:error] [pid 66623:tid 66822] [client 40.85.222.29:13225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAxtO5rbWdOArH04KOcgAAAUI"]
[Tue Aug 18 12:56:54.790400 2026] [security2:error] [pid 67073:tid 67256] [client 20.171.51.14:51787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/47.php"] [unique_id "aoSAxvcmepr5_nHgLbNeCgAAAkc"]
[Tue Aug 18 12:56:54.858999 2026] [security2:error] [pid 67073:tid 67328] [client 68.155.154.236:16264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-2019.php"] [unique_id "aoSAxvcmepr5_nHgLbNeEQAAAo8"]
[Tue Aug 18 12:56:54.879763 2026] [security2:error] [pid 66623:tid 66858] [client 20.116.17.175:57464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-load.php"] [unique_id "aoSAxtO5rbWdOArH04KOegAAAWY"]
[Tue Aug 18 12:56:54.929535 2026] [security2:error] [pid 67073:tid 67221] [client 40.74.65.169:30068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/sixxis.php"] [unique_id "aoSAxvcmepr5_nHgLbNeFAAAAiQ"]
[Tue Aug 18 12:56:54.983894 2026] [security2:error] [pid 67073:tid 67213] [client 52.139.47.57:17919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/166.php"] [unique_id "aoSAxvcmepr5_nHgLbNeFgAAAhw"]
[Tue Aug 18 12:56:55.002383 2026] [security2:error] [pid 67073:tid 67248] [client 20.250.13.23:21857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAx_cmepr5_nHgLbNeFwAAAj8"]
[Tue Aug 18 12:56:55.014081 2026] [security2:error] [pid 66623:tid 66814] [client 104.209.144.33:25642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSAx9O5rbWdOArH04KOfgAAATo"]
[Tue Aug 18 12:56:55.031150 2026] [security2:error] [pid 67073:tid 67230] [client 68.155.154.236:40326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/bhfnd.php"] [unique_id "aoSAx_cmepr5_nHgLbNeHQAAAi0"]
[Tue Aug 18 12:56:55.043706 2026] [security2:error] [pid 66623:tid 66804] [client 197.184.64.235:41933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAx9O5rbWdOArH04KOggAAATA"]
[Tue Aug 18 12:56:55.043835 2026] [security2:error] [pid 66623:tid 66804] [client 197.184.64.235:41933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAx9O5rbWdOArH04KOggAAATA"]
[Tue Aug 18 12:56:55.052507 2026] [security2:error] [pid 67073:tid 67222] [client 49.13.134.145:40024] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.melocorretordeimoveis.com.br"] [uri "/index.php"] [unique_id "aoSAxfcmepr5_nHgLbNd3wAAAiU"], referer: http://www.melocorretordeimoveis.com.br
[Tue Aug 18 12:56:55.052548 2026] [security2:error] [pid 66623:tid 66886] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/eh.php"] [unique_id "aoSAx9O5rbWdOArH04KOgwAAAYI"]
[Tue Aug 18 12:56:55.064454 2026] [security2:error] [pid 67073:tid 67231] [client 40.85.222.29:12652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSAx_cmepr5_nHgLbNeHgAAAi4"]
[Tue Aug 18 12:56:55.071349 2026] [security2:error] [pid 67073:tid 67234] [client 20.100.169.31:48603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/nw.php"] [unique_id "aoSAx_cmepr5_nHgLbNeHwAAAjE"]
[Tue Aug 18 12:56:55.090957 2026] [security2:error] [pid 67073:tid 67132] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.hermes/.env"] [unique_id "aoSAx_cmepr5_nHgLbNeIgACgTg"]
[Tue Aug 18 12:56:55.130674 2026] [security2:error] [pid 67073:tid 67286] [client 52.173.121.69:16487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSAx_cmepr5_nHgLbNeJAAAAmU"]
[Tue Aug 18 12:56:55.155666 2026] [security2:error] [pid 66623:tid 66784] [client 20.65.98.162:50884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/bajah.php"] [unique_id "aoSAx9O5rbWdOArH04KOhQAAARw"]
[Tue Aug 18 12:56:55.188908 2026] [security2:error] [pid 67073:tid 67182] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/key.pem"] [unique_id "aoSAx_cmepr5_nHgLbNeJwACTWo"]
[Tue Aug 18 12:56:55.231491 2026] [security2:error] [pid 66623:tid 66787] [client 132.196.30.78:18789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/aa.php"] [unique_id "aoSAx9O5rbWdOArH04KOigAAAR8"]
[Tue Aug 18 12:56:55.241032 2026] [security2:error] [pid 67073:tid 67263] [client 20.226.56.190:47120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/rf.php"] [unique_id "aoSAx_cmepr5_nHgLbNeKgAAAk4"]
[Tue Aug 18 12:56:55.244763 2026] [security2:error] [pid 67073:tid 67275] [client 20.52.168.85:7836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/c.php"] [unique_id "aoSAx_cmepr5_nHgLbNeKwAAAlo"]
[Tue Aug 18 12:56:55.270587 2026] [security2:error] [pid 66623:tid 66685] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAx9O5rbWdOArH04KOiwABJTA"]
[Tue Aug 18 12:56:55.270762 2026] [security2:error] [pid 66623:tid 66793] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAx9O5rbWdOArH04KOiwABJTA"]
[Tue Aug 18 12:56:55.289435 2026] [security2:error] [pid 67073:tid 67327] [client 20.116.17.175:57412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/jj.php"] [unique_id "aoSAx_cmepr5_nHgLbNeLgAAAo4"]
[Tue Aug 18 12:56:55.292931 2026] [security2:error] [pid 66623:tid 66838] [client 20.215.241.237:7524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSAx9O5rbWdOArH04KOjAAAAVI"]
[Tue Aug 18 12:56:55.329562 2026] [security2:error] [pid 67073:tid 67241] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ad.php"] [unique_id "aoSAx_cmepr5_nHgLbNeMQAAAjg"]
[Tue Aug 18 12:56:55.335561 2026] [authz_core:error] [pid 67073:tid 67116] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:55.335843 2026] [authz_core:error] [pid 67073:tid 67116] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:55.336992 2026] [security2:error] [pid 67073:tid 67158] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alyauto.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSAx_cmepr5_nHgLbNeMgAChFI"]
[Tue Aug 18 12:56:55.392790 2026] [security2:error] [pid 67073:tid 67217] [client 40.85.222.29:13274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/mt/byp.php"] [unique_id "aoSAx_cmepr5_nHgLbNeMwAAAiA"]
[Tue Aug 18 12:56:55.401747 2026] [security2:error] [pid 66623:tid 66800] [client 74.248.136.165:61413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/wp-blog.php"] [unique_id "aoSAx9O5rbWdOArH04KOjwAAASw"]
[Tue Aug 18 12:56:55.455975 2026] [security2:error] [pid 66623:tid 66778] [client 52.139.47.57:11773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/log.php"] [unique_id "aoSAx9O5rbWdOArH04KOkgAAARY"]
[Tue Aug 18 12:56:55.465363 2026] [security2:error] [pid 66623:tid 66884] [client 135.225.75.187:62912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/x7.php"] [unique_id "aoSAx9O5rbWdOArH04KOkwAAAYA"]
[Tue Aug 18 12:56:55.489543 2026] [security2:error] [pid 67073:tid 67107] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/privatekey.key"] [unique_id "aoSAx_cmepr5_nHgLbNeOQACeB8"]
[Tue Aug 18 12:56:55.528095 2026] [security2:error] [pid 66623:tid 66767] [client 20.65.69.59:40531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/twin.php"] [unique_id "aoSAx9O5rbWdOArH04KOlwAAAQs"]
[Tue Aug 18 12:56:55.542375 2026] [security2:error] [pid 67073:tid 67254] [client 79.127.164.8:54518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/moduleinfoincludemysql/phpcms_info.bak"] [unique_id "aoSAx_cmepr5_nHgLbNeOgAAAkU"], referer: https://medihub.com.br/moduleinfoincludemysql/phpcms_info.bak
[Tue Aug 18 12:56:55.560406 2026] [security2:error] [pid 67073:tid 67316] [client 213.35.127.232:63576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAx_cmepr5_nHgLbNeOwAAAoM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:55.585930 2026] [security2:error] [pid 66623:tid 66851] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/vd.php"] [unique_id "aoSAx9O5rbWdOArH04KOmQAAAV8"]
[Tue Aug 18 12:56:55.618198 2026] [security2:error] [pid 66623:tid 66770] [client 20.171.51.14:21062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/payout.php"] [unique_id "aoSAx9O5rbWdOArH04KOmwAAAQ4"]
[Tue Aug 18 12:56:55.622574 2026] [security2:error] [pid 66623:tid 66843] [client 40.74.65.169:44777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/yj09.php"] [unique_id "aoSAx9O5rbWdOArH04KOnQAAAVc"]
[Tue Aug 18 12:56:55.628456 2026] [security2:error] [pid 67073:tid 67322] [client 158.158.74.177:16549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/system_log.php"] [unique_id "aoSAx_cmepr5_nHgLbNePQAAAok"]
[Tue Aug 18 12:56:55.679767 2026] [security2:error] [pid 67073:tid 67282] [client 37.40.227.74:57006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAx_cmepr5_nHgLbNePwAAAmE"]
[Tue Aug 18 12:56:55.679898 2026] [security2:error] [pid 67073:tid 67282] [client 37.40.227.74:57006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAx_cmepr5_nHgLbNePwAAAmE"]
[Tue Aug 18 12:56:55.706471 2026] [security2:error] [pid 66623:tid 66798] [client 40.85.222.29:12642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSAx9O5rbWdOArH04KOogAAASo"]
[Tue Aug 18 12:56:55.815800 2026] [security2:error] [pid 67073:tid 67220] [client 158.158.34.183:42599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-includes/blocks/about.php"] [unique_id "aoSAx_cmepr5_nHgLbNeRAAAAiM"]
[Tue Aug 18 12:56:55.821064 2026] [security2:error] [pid 67073:tid 67278] [client 20.116.17.175:57451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/img.php"] [unique_id "aoSAx_cmepr5_nHgLbNeRQAAAl0"]
[Tue Aug 18 12:56:55.833299 2026] [security2:error] [pid 66623:tid 66818] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/56.php"] [unique_id "aoSAx9O5rbWdOArH04KOpgAAAT4"]
[Tue Aug 18 12:56:55.853701 2026] [security2:error] [pid 67073:tid 67249] [client 20.52.168.85:8024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/ini.php"] [unique_id "aoSAx_cmepr5_nHgLbNeRwAAAkA"]
[Tue Aug 18 12:56:55.892690 2026] [security2:error] [pid 67073:tid 67259] [client 52.139.47.57:18390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/file.php"] [unique_id "aoSAx_cmepr5_nHgLbNeSAAAAko"]
[Tue Aug 18 12:56:55.922360 2026] [security2:error] [pid 66623:tid 66879] [client 158.23.17.4:10977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/phpprobe.php"] [unique_id "aoSAx9O5rbWdOArH04KOqQAAAXs"]
[Tue Aug 18 12:56:56.001796 2026] [security2:error] [pid 66623:tid 66893] [client 40.85.222.29:13259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAyNO5rbWdOArH04KOqwAAAYk"]
[Tue Aug 18 12:56:56.017952 2026] [authz_core:error] [pid 67073:tid 67206] [client 192.178.4.134:54606] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:56.018214 2026] [authz_core:error] [pid 67073:tid 67206] [client 192.178.4.134:54606] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:56.057373 2026] [security2:error] [pid 67073:tid 67319] [client 68.155.154.236:16313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSAyPcmepr5_nHgLbNeTAAAAoY"]
[Tue Aug 18 12:56:56.057666 2026] [security2:error] [pid 67073:tid 67332] [client 132.196.30.78:26243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAyPcmepr5_nHgLbNeTQAAApM"]
[Tue Aug 18 12:56:56.074216 2026] [security2:error] [pid 66623:tid 66825] [client 135.225.75.187:56365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/god.php"] [unique_id "aoSAyNO5rbWdOArH04KOrQAAAUU"]
[Tue Aug 18 12:56:56.086084 2026] [security2:error] [pid 67073:tid 67331] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/rx.php"] [unique_id "aoSAyPcmepr5_nHgLbNeTgAAApI"]
[Tue Aug 18 12:56:56.189753 2026] [security2:error] [pid 67073:tid 67221] [client 20.171.51.14:59311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/bh.php"] [unique_id "aoSAyPcmepr5_nHgLbNeUQAAAiQ"]
[Tue Aug 18 12:56:56.297879 2026] [security2:error] [pid 66623:tid 66880] [client 40.85.222.29:13203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAyNO5rbWdOArH04KOtQAAAXw"]
[Tue Aug 18 12:56:56.301262 2026] [security2:error] [pid 67073:tid 67222] [client 40.74.65.169:27794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/k.php"] [unique_id "aoSAyPcmepr5_nHgLbNeVgAAAiU"]
[Tue Aug 18 12:56:56.341342 2026] [security2:error] [pid 66623:tid 66852] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/mandrill.php"] [unique_id "aoSAyNO5rbWdOArH04KOtwAAAWA"]
[Tue Aug 18 12:56:56.357681 2026] [security2:error] [pid 67073:tid 67236] [client 52.139.47.57:17905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/bolt.php"] [unique_id "aoSAyPcmepr5_nHgLbNeXAAAAjM"]
[Tue Aug 18 12:56:56.364018 2026] [autoindex:error] [pid 67073:tid 67314] [client 172.202.39.151:65222] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/js/crop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:56.369145 2026] [security2:error] [pid 66623:tid 66856] [client 20.116.17.175:57462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/we.php"] [unique_id "aoSAyNO5rbWdOArH04KOuAAAAWQ"]
[Tue Aug 18 12:56:56.446360 2026] [security2:error] [pid 67073:tid 67270] [client 20.215.241.237:54966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/simple.php"] [unique_id "aoSAyPcmepr5_nHgLbNeYAAAAlU"]
[Tue Aug 18 12:56:56.450142 2026] [security2:error] [pid 66623:tid 66827] [client 158.23.17.4:8743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/wp-title.php"] [unique_id "aoSAyNO5rbWdOArH04KOvgAAAUc"]
[Tue Aug 18 12:56:56.459303 2026] [security2:error] [pid 67073:tid 67255] [client 20.52.168.85:7837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/nf.php"] [unique_id "aoSAyPcmepr5_nHgLbNeYQAAAkY"]
[Tue Aug 18 12:56:56.486048 2026] [security2:error] [pid 66623:tid 66797] [client 158.158.74.177:16525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/t.php"] [unique_id "aoSAyNO5rbWdOArH04KOvwAAASk"]
[Tue Aug 18 12:56:56.517618 2026] [security2:error] [pid 67073:tid 67251] [client 103.184.169.37:42029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAyPcmepr5_nHgLbNeYwAAAkI"]
[Tue Aug 18 12:56:56.517711 2026] [security2:error] [pid 67073:tid 67251] [client 103.184.169.37:42029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAyPcmepr5_nHgLbNeYwAAAkI"]
[Tue Aug 18 12:56:56.539454 2026] [authz_core:error] [pid 67073:tid 67108] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:56.539707 2026] [authz_core:error] [pid 67073:tid 67108] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:56.557667 2026] [security2:error] [pid 67073:tid 67285] [client 20.65.69.59:3676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/new2.php"] [unique_id "aoSAyPcmepr5_nHgLbNeZQAAAmQ"]
[Tue Aug 18 12:56:56.571694 2026] [security2:error] [pid 67073:tid 67244] [client 213.35.127.232:63755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAyPcmepr5_nHgLbNeZgAAAjs"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:56.578142 2026] [security2:error] [pid 67073:tid 67277] [client 68.155.154.236:16266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/.cache/x.php"] [unique_id "aoSAyPcmepr5_nHgLbNeaAAAAlw"]
[Tue Aug 18 12:56:56.582259 2026] [security2:error] [pid 67073:tid 67229] [client 20.100.169.31:25914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/xleet.php"] [unique_id "aoSAyPcmepr5_nHgLbNeaQAAAiw"]
[Tue Aug 18 12:56:56.587098 2026] [autoindex:error] [pid 67073:tid 67293] [client 172.202.39.151:44980] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:56.597034 2026] [security2:error] [pid 67073:tid 67238] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/main.php"] [unique_id "aoSAyPcmepr5_nHgLbNebAAAAjU"]
[Tue Aug 18 12:56:56.653849 2026] [security2:error] [pid 66623:tid 66842] [client 52.173.121.69:17931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAyNO5rbWdOArH04KOwgAAAVY"]
[Tue Aug 18 12:56:56.659885 2026] [security2:error] [pid 67073:tid 67225] [client 40.85.222.29:13223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSAyPcmepr5_nHgLbNebgAAAig"]
[Tue Aug 18 12:56:56.662320 2026] [security2:error] [pid 67073:tid 67327] [client 172.202.39.151:65222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAyPcmepr5_nHgLbNebwAAAo4"]
[Tue Aug 18 12:56:56.728002 2026] [security2:error] [pid 67073:tid 67212] [client 68.155.156.252:2701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/coffee.php"] [unique_id "aoSAyPcmepr5_nHgLbNecAAAAhs"]
[Tue Aug 18 12:56:56.770963 2026] [security2:error] [pid 67073:tid 67328] [client 103.120.71.157:10841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAyPcmepr5_nHgLbNecQAAAo8"]
[Tue Aug 18 12:56:56.771076 2026] [security2:error] [pid 67073:tid 67328] [client 103.120.71.157:10841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAyPcmepr5_nHgLbNecQAAAo8"]
[Tue Aug 18 12:56:56.812998 2026] [security2:error] [pid 67073:tid 67311] [client 192.141.172.134:62330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAyPcmepr5_nHgLbNecgAAAn4"]
[Tue Aug 18 12:56:56.813131 2026] [security2:error] [pid 67073:tid 67311] [client 192.141.172.134:62330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAyPcmepr5_nHgLbNecgAAAn4"]
[Tue Aug 18 12:56:56.834223 2026] [security2:error] [pid 67073:tid 67317] [client 52.139.47.57:11754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/item.php"] [unique_id "aoSAyPcmepr5_nHgLbNecwAAAoQ"]
[Tue Aug 18 12:56:56.847190 2026] [security2:error] [pid 67073:tid 67211] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ga.php"] [unique_id "aoSAyPcmepr5_nHgLbNedAAAAho"]
[Tue Aug 18 12:56:56.850404 2026] [security2:error] [pid 67073:tid 67239] [client 20.206.73.37:20699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/mac.php"] [unique_id "aoSAyPcmepr5_nHgLbNedQAAAjY"]
[Tue Aug 18 12:56:56.942305 2026] [security2:error] [pid 67073:tid 67299] [client 40.85.222.29:12638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSAyPcmepr5_nHgLbNedgAAAnI"]
[Tue Aug 18 12:56:56.954612 2026] [security2:error] [pid 66623:tid 66809] [client 68.155.154.236:16354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSAyNO5rbWdOArH04KOzgAAATU"]
[Tue Aug 18 12:56:56.989091 2026] [security2:error] [pid 66623:tid 66883] [client 135.225.75.187:62056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ebahvhhh.php"] [unique_id "aoSAyNO5rbWdOArH04KO0AAAAX8"]
[Tue Aug 18 12:56:56.996063 2026] [security2:error] [pid 66623:tid 66875] [client 132.196.30.78:19395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/bolt.php"] [unique_id "aoSAyNO5rbWdOArH04KO0QAAAXc"]
[Tue Aug 18 12:56:57.003055 2026] [security2:error] [pid 67073:tid 67267] [client 40.74.65.169:44749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/w.php"] [unique_id "aoSAyfcmepr5_nHgLbNeegAAAlI"]
[Tue Aug 18 12:56:57.065869 2026] [security2:error] [pid 67073:tid 67235] [client 20.52.168.85:7776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/room.php"] [unique_id "aoSAyfcmepr5_nHgLbNefAAAAjI"]
[Tue Aug 18 12:56:57.100557 2026] [security2:error] [pid 66623:tid 66877] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/wb.php"] [unique_id "aoSAydO5rbWdOArH04KO1QAAAXk"]
[Tue Aug 18 12:56:57.143637 2026] [security2:error] [pid 66623:tid 66788] [client 104.209.144.33:21432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-content/index.php"] [unique_id "aoSAydO5rbWdOArH04KO2AAAASA"]
[Tue Aug 18 12:56:57.217977 2026] [security2:error] [pid 66623:tid 66793] [client 20.171.51.14:29212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ct.php"] [unique_id "aoSAydO5rbWdOArH04KO2gAAASU"]
[Tue Aug 18 12:56:57.218988 2026] [security2:error] [pid 67073:tid 67329] [client 40.85.222.29:12629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSAyfcmepr5_nHgLbNefwAAApA"]
[Tue Aug 18 12:56:57.245996 2026] [security2:error] [pid 66623:tid 66823] [client 74.248.136.165:28113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/mga.php"] [unique_id "aoSAydO5rbWdOArH04KO3AAAAUM"]
[Tue Aug 18 12:56:57.250631 2026] [security2:error] [pid 67073:tid 67320] [client 20.215.241.237:40504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/chosen.php"] [unique_id "aoSAyfcmepr5_nHgLbNegAAAAoc"]
[Tue Aug 18 12:56:57.261901 2026] [security2:error] [pid 66623:tid 66832] [client 52.139.47.57:39004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/sid3.php"] [unique_id "aoSAydO5rbWdOArH04KO3QAAAUw"]
[Tue Aug 18 12:56:57.265753 2026] [security2:error] [pid 67073:tid 67268] [client 172.182.200.96:14203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/index/function.php"] [unique_id "aoSAyfcmepr5_nHgLbNegQAAAlM"]
[Tue Aug 18 12:56:57.356177 2026] [security2:error] [pid 67073:tid 67290] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/xn.php"] [unique_id "aoSAyfcmepr5_nHgLbNeggAAAmk"]
[Tue Aug 18 12:56:57.396253 2026] [security2:error] [pid 67073:tid 67256] [client 68.155.154.236:16283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAyfcmepr5_nHgLbNegwAAAkc"]
[Tue Aug 18 12:56:57.401382 2026] [security2:error] [pid 66623:tid 66784] [client 158.158.74.177:2634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/templates.php"] [unique_id "aoSAydO5rbWdOArH04KO4AAAARw"]
[Tue Aug 18 12:56:57.433864 2026] [security2:error] [pid 67073:tid 67332] [client 158.23.17.4:9367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/styles.php"] [unique_id "aoSAyfcmepr5_nHgLbNehAAAApM"]
[Tue Aug 18 12:56:57.435652 2026] [security2:error] [pid 67073:tid 67331] [client 20.65.98.162:8451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/h.php"] [unique_id "aoSAyfcmepr5_nHgLbNehgAAApI"]
[Tue Aug 18 12:56:57.441644 2026] [authz_core:error] [pid 67073:tid 67174] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:57.441950 2026] [authz_core:error] [pid 67073:tid 67174] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:57.451965 2026] [security2:error] [pid 66623:tid 66884] [client 68.155.154.236:8013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/qfvqu.php"] [unique_id "aoSAydO5rbWdOArH04KO4gAAAYA"]
[Tue Aug 18 12:56:57.463118 2026] [security2:error] [pid 66623:tid 66792] [client 20.65.69.59:3680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/rex.php"] [unique_id "aoSAydO5rbWdOArH04KO4wAAASQ"]
[Tue Aug 18 12:56:57.477799 2026] [security2:error] [pid 67073:tid 67283] [client 20.100.169.31:7978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAyfcmepr5_nHgLbNehwAAAmI"]
[Tue Aug 18 12:56:57.486751 2026] [security2:error] [pid 66623:tid 66882] [client 132.196.30.78:19470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/bthil.php"] [unique_id "aoSAydO5rbWdOArH04KO5AAAAX4"]
[Tue Aug 18 12:56:57.495144 2026] [security2:error] [pid 67073:tid 67266] [client 40.85.222.29:12610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSAyfcmepr5_nHgLbNeiAAAAlE"]
[Tue Aug 18 12:56:57.584227 2026] [security2:error] [pid 66623:tid 66838] [client 213.35.127.232:63946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAydO5rbWdOArH04KO6AAAAVI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:57.595691 2026] [security2:error] [pid 66623:tid 66851] [client 20.226.56.190:45020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/xynz1.php"] [unique_id "aoSAydO5rbWdOArH04KO6QAAAV8"]
[Tue Aug 18 12:56:57.626201 2026] [security2:error] [pid 67073:tid 67231] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/47.php"] [unique_id "aoSAyfcmepr5_nHgLbNeiwAAAi4"]
[Tue Aug 18 12:56:57.666897 2026] [security2:error] [pid 67073:tid 67233] [client 20.52.168.85:7870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-contentt.php"] [unique_id "aoSAyfcmepr5_nHgLbNejAAAAjA"]
[Tue Aug 18 12:56:57.676559 2026] [security2:error] [pid 66623:tid 66864] [client 52.139.47.57:47664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/size.php"] [unique_id "aoSAydO5rbWdOArH04KO7AAAAWw"]
[Tue Aug 18 12:56:57.707016 2026] [security2:error] [pid 67073:tid 67270] [client 135.225.75.187:37228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/8.php"] [unique_id "aoSAyfcmepr5_nHgLbNejwAAAlU"]
[Tue Aug 18 12:56:57.710200 2026] [security2:error] [pid 67073:tid 67262] [client 40.74.65.169:42573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/fpwch.php"] [unique_id "aoSAyfcmepr5_nHgLbNekAAAAk0"]
[Tue Aug 18 12:56:57.719581 2026] [security2:error] [pid 66623:tid 66835] [client 20.118.172.148:54910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAydO5rbWdOArH04KO7QAAAU8"]
[Tue Aug 18 12:56:57.742222 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:57.742504 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:57.746554 2026] [security2:error] [pid 67073:tid 67323] [client 68.155.154.236:16213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAyfcmepr5_nHgLbNekgAAAoo"]
[Tue Aug 18 12:56:57.775061 2026] [security2:error] [pid 67073:tid 67274] [client 40.85.222.29:13299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/first.php"] [unique_id "aoSAyfcmepr5_nHgLbNekwAAAlk"]
[Tue Aug 18 12:56:57.816660 2026] [security2:error] [pid 67073:tid 67209] [client 20.100.169.31:25891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp.php"] [unique_id "aoSAyfcmepr5_nHgLbNelQAAAhg"]
[Tue Aug 18 12:56:57.826402 2026] [security2:error] [pid 67073:tid 67251] [client 20.171.51.14:16705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/gy.php"] [unique_id "aoSAyfcmepr5_nHgLbNelgAAAkI"]
[Tue Aug 18 12:56:57.837616 2026] [security2:error] [pid 66623:tid 66766] [client 158.158.34.183:42615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "aoSAydO5rbWdOArH04KO8gAAAQo"]
[Tue Aug 18 12:56:57.891175 2026] [security2:error] [pid 66623:tid 66848] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/payout.php"] [unique_id "aoSAydO5rbWdOArH04KO9QAAAVw"]
[Tue Aug 18 12:56:58.100537 2026] [security2:error] [pid 67073:tid 67241] [client 40.85.222.29:13266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSAyvcmepr5_nHgLbNenAAAAjg"]
[Tue Aug 18 12:56:58.144457 2026] [security2:error] [pid 66623:tid 66892] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/bh.php"] [unique_id "aoSAytO5rbWdOArH04KO_QAAAYg"]
[Tue Aug 18 12:56:58.181828 2026] [security2:error] [pid 66623:tid 66826] [client 52.139.47.57:18375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/tgrs.php"] [unique_id "aoSAytO5rbWdOArH04KO_gAAAUY"]
[Tue Aug 18 12:56:58.188568 2026] [security2:error] [pid 67073:tid 67223] [client 132.196.30.78:21888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/x.php"] [unique_id "aoSAyvcmepr5_nHgLbNengAAAiY"]
[Tue Aug 18 12:56:58.190090 2026] [security2:error] [pid 67073:tid 67330] [client 68.155.154.236:16198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSAyvcmepr5_nHgLbNenwAAApE"]
[Tue Aug 18 12:56:58.204887 2026] [security2:error] [pid 66623:tid 66779] [client 20.65.69.59:39230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/verification.php"] [unique_id "aoSAytO5rbWdOArH04KO_wAAARc"]
[Tue Aug 18 12:56:58.226057 2026] [security2:error] [pid 67073:tid 67212] [client 20.118.172.148:62454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAyvcmepr5_nHgLbNeoQAAAhs"]
[Tue Aug 18 12:56:58.236219 2026] [security2:error] [pid 66623:tid 66885] [client 52.139.47.57:18122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSAytO5rbWdOArH04KPAQAAAYE"]
[Tue Aug 18 12:56:58.241750 2026] [security2:error] [pid 66623:tid 66782] [client 158.158.74.177:16552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/term.php"] [unique_id "aoSAytO5rbWdOArH04KPAgAAARo"]
[Tue Aug 18 12:56:58.259754 2026] [security2:error] [pid 67073:tid 67245] [client 20.215.241.237:7548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/als.php"] [unique_id "aoSAyvcmepr5_nHgLbNeogAAAjw"]
[Tue Aug 18 12:56:58.263545 2026] [security2:error] [pid 67073:tid 67217] [client 158.23.17.4:63633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/server.php"] [unique_id "aoSAyvcmepr5_nHgLbNeowAAAiA"]
[Tue Aug 18 12:56:58.270188 2026] [security2:error] [pid 66623:tid 66830] [client 20.52.168.85:7850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/input.php"] [unique_id "aoSAytO5rbWdOArH04KPAwAAAUo"]
[Tue Aug 18 12:56:58.300262 2026] [security2:error] [pid 67073:tid 67326] [client 68.155.155.199:5029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/chosen.php"] [unique_id "aoSAyvcmepr5_nHgLbNepQAAAo0"]
[Tue Aug 18 12:56:58.315094 2026] [security2:error] [pid 67073:tid 67211] [client 52.173.121.69:6094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAyvcmepr5_nHgLbNepgAAAho"]
[Tue Aug 18 12:56:58.348131 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:58.348530 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:58.370151 2026] [security2:error] [pid 67073:tid 67286] [client 138.36.100.162:43044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAyvcmepr5_nHgLbNeqAAAAmU"]
[Tue Aug 18 12:56:58.370246 2026] [security2:error] [pid 67073:tid 67286] [client 138.36.100.162:43044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAyvcmepr5_nHgLbNeqAAAAmU"]
[Tue Aug 18 12:56:58.394297 2026] [security2:error] [pid 67073:tid 67305] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ct.php"] [unique_id "aoSAyvcmepr5_nHgLbNeqQAAAng"]
[Tue Aug 18 12:56:58.399222 2026] [security2:error] [pid 66623:tid 66817] [client 130.89.144.165:51409] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "culinariaemporio.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSAytO5rbWdOArH04KPCAAAAT0"]
[Tue Aug 18 12:56:58.415472 2026] [security2:error] [pid 66623:tid 66880] [client 40.85.222.29:12617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSAytO5rbWdOArH04KPCgAAAXw"]
[Tue Aug 18 12:56:58.439424 2026] [security2:error] [pid 66623:tid 66815] [client 20.171.51.14:62484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/tt.php"] [unique_id "aoSAytO5rbWdOArH04KPDAAAATs"]
[Tue Aug 18 12:56:58.441644 2026] [security2:error] [pid 66623:tid 66852] [client 40.74.65.169:11220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/FWAZ.php"] [unique_id "aoSAytO5rbWdOArH04KPDQAAAWA"]
[Tue Aug 18 12:56:58.525659 2026] [security2:error] [pid 66623:tid 66769] [client 5.31.227.224:30446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAytO5rbWdOArH04KPEAAAAQ0"]
[Tue Aug 18 12:56:58.532566 2026] [security2:error] [pid 66623:tid 66769] [client 5.31.227.224:30446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAytO5rbWdOArH04KPEAAAAQ0"]
[Tue Aug 18 12:56:58.599592 2026] [security2:error] [pid 66623:tid 66775] [client 213.35.127.232:64149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAytO5rbWdOArH04KPFAAAARM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:58.646220 2026] [authz_core:error] [pid 67073:tid 67167] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:58.646496 2026] [authz_core:error] [pid 67073:tid 67167] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:58.656018 2026] [security2:error] [pid 67073:tid 67289] [client 52.139.47.57:18382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/ws83.php"] [unique_id "aoSAyvcmepr5_nHgLbNerwAAAmg"]
[Tue Aug 18 12:56:58.697568 2026] [security2:error] [pid 67073:tid 67272] [client 20.65.69.59:49284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/smtp.php"] [unique_id "aoSAyvcmepr5_nHgLbNesAAAAlc"]
[Tue Aug 18 12:56:58.701289 2026] [security2:error] [pid 66623:tid 66791] [client 135.225.75.187:37234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/koiy.php"] [unique_id "aoSAytO5rbWdOArH04KPFgAAASM"]
[Tue Aug 18 12:56:58.704474 2026] [security2:error] [pid 67073:tid 67303] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gy.php"] [unique_id "aoSAyvcmepr5_nHgLbNesQAAAnY"]
[Tue Aug 18 12:56:58.712052 2026] [security2:error] [pid 67073:tid 67220] [client 40.85.222.29:12640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAyvcmepr5_nHgLbNesgAAAiM"]
[Tue Aug 18 12:56:58.734677 2026] [security2:error] [pid 67073:tid 67307] [client 172.202.39.151:44980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAyvcmepr5_nHgLbNeswAAAno"]
[Tue Aug 18 12:56:58.772908 2026] [autoindex:error] [pid 66623:tid 66861] [client 3.210.118.109:9003] AH01276: Cannot serve directory /home4/adf/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:56:58.781491 2026] [security2:error] [pid 66623:tid 66811] [client 158.158.34.183:39503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/aaa.php"] [unique_id "aoSAytO5rbWdOArH04KPGAAAATc"]
[Tue Aug 18 12:56:58.804235 2026] [security2:error] [pid 66623:tid 66839] [client 130.89.144.165:35405] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "304"] [hostname "culinariaemporio.com.br"] [uri "/index.html"] [unique_id "aoSAytO5rbWdOArH04KPGgAAAVM"]
[Tue Aug 18 12:56:58.841453 2026] [security2:error] [pid 67073:tid 67320] [client 20.104.85.180:18832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/404.php"] [unique_id "aoSAyvcmepr5_nHgLbNetAAAAoc"]
[Tue Aug 18 12:56:58.874372 2026] [security2:error] [pid 67073:tid 67226] [client 20.52.168.85:7757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/disagreed.php"] [unique_id "aoSAyvcmepr5_nHgLbNetQAAAik"]
[Tue Aug 18 12:56:58.879271 2026] [security2:error] [pid 66623:tid 66814] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAytO5rbWdOArH04KPHAAAATo"]
[Tue Aug 18 12:56:58.923227 2026] [security2:error] [pid 67073:tid 67235] [client 132.196.30.78:21919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/index/function.php"] [unique_id "aoSAyvcmepr5_nHgLbNetgAAAjI"]
[Tue Aug 18 12:56:58.952104 2026] [security2:error] [pid 67073:tid 67315] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/tt.php"] [unique_id "aoSAyvcmepr5_nHgLbNeuQAAAoI"]
[Tue Aug 18 12:56:58.965318 2026] [security2:error] [pid 66623:tid 66809] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAytO5rbWdOArH04KPHgAAATU"]
[Tue Aug 18 12:56:58.990558 2026] [security2:error] [pid 67073:tid 67310] [client 40.85.222.29:13218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/blog/byp.php"] [unique_id "aoSAyvcmepr5_nHgLbNeugAAAn0"]
[Tue Aug 18 12:56:59.018386 2026] [security2:error] [pid 66623:tid 66807] [client 157.20.138.62:62917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAy9O5rbWdOArH04KPIAAAATM"]
[Tue Aug 18 12:56:59.018501 2026] [security2:error] [pid 66623:tid 66807] [client 157.20.138.62:62917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAy9O5rbWdOArH04KPIAAAATM"]
[Tue Aug 18 12:56:59.052058 2026] [security2:error] [pid 66623:tid 66805] [client 20.171.51.14:16760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/mq.php"] [unique_id "aoSAy9O5rbWdOArH04KPIgAAATE"]
[Tue Aug 18 12:56:59.053583 2026] [security2:error] [pid 67073:tid 67290] [client 158.23.17.4:8736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/xinfo.php"] [unique_id "aoSAy_cmepr5_nHgLbNeuwAAAmk"]
[Tue Aug 18 12:56:59.054055 2026] [security2:error] [pid 66623:tid 66786] [client 158.158.74.177:26160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/test.php"] [unique_id "aoSAy9O5rbWdOArH04KPIwAAAR4"]
[Tue Aug 18 12:56:59.072778 2026] [security2:error] [pid 67073:tid 67287] [client 52.139.47.57:18134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/style.php"] [unique_id "aoSAy_cmepr5_nHgLbNevAAAAmY"]
[Tue Aug 18 12:56:59.086816 2026] [security2:error] [pid 67073:tid 67246] [client 79.127.164.8:60442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/moduleinfoincludemysql/phpcms_info.sql"] [unique_id "aoSAy_cmepr5_nHgLbNevQAAAj0"], referer: https://medihub.com.br/moduleinfoincludemysql/phpcms_info.sql
[Tue Aug 18 12:56:59.118030 2026] [security2:error] [pid 66623:tid 66855] [client 20.215.241.237:43621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/nox.php"] [unique_id "aoSAy9O5rbWdOArH04KPJQAAAWM"]
[Tue Aug 18 12:56:59.149320 2026] [security2:error] [pid 67073:tid 67266] [client 40.74.65.169:44774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/blurbs.php"] [unique_id "aoSAy_cmepr5_nHgLbNevwAAAlE"]
[Tue Aug 18 12:56:59.157237 2026] [security2:error] [pid 67073:tid 67312] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/admin.php"] [unique_id "aoSAy_cmepr5_nHgLbNewAAAAn8"]
[Tue Aug 18 12:56:59.203615 2026] [security2:error] [pid 66623:tid 66829] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/mq.php"] [unique_id "aoSAy9O5rbWdOArH04KPKQAAAUk"]
[Tue Aug 18 12:56:59.224878 2026] [security2:error] [pid 67073:tid 67216] [client 74.248.136.165:18021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/fs.php"] [unique_id "aoSAy_cmepr5_nHgLbNewgAAAh8"]
[Tue Aug 18 12:56:59.239750 2026] [security2:error] [pid 67073:tid 67231] [client 20.65.69.59:49342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/teste.php"] [unique_id "aoSAy_cmepr5_nHgLbNexAAAAi4"]
[Tue Aug 18 12:56:59.272298 2026] [security2:error] [pid 67073:tid 67222] [client 20.226.56.190:52070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/vo.php"] [unique_id "aoSAy_cmepr5_nHgLbNexQAAAiU"]
[Tue Aug 18 12:56:59.279773 2026] [security2:error] [pid 67073:tid 67236] [client 40.85.222.29:13282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSAy_cmepr5_nHgLbNexgAAAjM"]
[Tue Aug 18 12:56:59.298101 2026] [security2:error] [pid 66623:tid 66787] [client 52.173.121.69:17962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSAy9O5rbWdOArH04KPLAAAAR8"]
[Tue Aug 18 12:56:59.299354 2026] [security2:error] [pid 66623:tid 66774] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/edit.php"] [unique_id "aoSAy9O5rbWdOArH04KPLQAAARI"]
[Tue Aug 18 12:56:59.314504 2026] [security2:error] [pid 66623:tid 66793] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/w.php"] [unique_id "aoSAy9O5rbWdOArH04KPLgAAASU"]
[Tue Aug 18 12:56:59.328389 2026] [security2:error] [pid 66623:tid 66832] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/file.php"] [unique_id "aoSAy9O5rbWdOArH04KPMAAAAUw"]
[Tue Aug 18 12:56:59.346616 2026] [security2:error] [pid 66623:tid 66772] [client 20.104.85.180:18855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-login.php"] [unique_id "aoSAy9O5rbWdOArH04KPJwAAARA"]
[Tue Aug 18 12:56:59.369934 2026] [security2:error] [pid 66623:tid 66836] [client 84.247.146.84:53436] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "i-databi.com.br"] [uri "/index.php"] [unique_id "aoSAy9O5rbWdOArH04KPKAAAAVA"]
[Tue Aug 18 12:56:59.378971 2026] [security2:error] [pid 67073:tid 67242] [client 149.34.210.141:55646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAy_cmepr5_nHgLbNexwAAAjk"]
[Tue Aug 18 12:56:59.384946 2026] [security2:error] [pid 67073:tid 67293] [client 20.100.169.31:43003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/bolt.php"] [unique_id "aoSAy_cmepr5_nHgLbNeyAAAAmw"]
[Tue Aug 18 12:56:59.393349 2026] [security2:error] [pid 66623:tid 66784] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAy9O5rbWdOArH04KPMQAAARw"]
[Tue Aug 18 12:56:59.445461 2026] [security2:error] [pid 66623:tid 66767] [client 68.155.154.236:40361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/oivcl.php"] [unique_id "aoSAy9O5rbWdOArH04KPMwAAAQs"]
[Tue Aug 18 12:56:59.457794 2026] [security2:error] [pid 66623:tid 66888] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/13.php"] [unique_id "aoSAy9O5rbWdOArH04KPNAAAAYQ"]
[Tue Aug 18 12:56:59.479018 2026] [security2:error] [pid 67073:tid 67313] [client 20.52.168.85:7760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/defaults.php"] [unique_id "aoSAy_cmepr5_nHgLbNeyQAAAoA"]
[Tue Aug 18 12:56:59.514525 2026] [security2:error] [pid 66623:tid 66801] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/aa.php"] [unique_id "aoSAy9O5rbWdOArH04KPNgAAAS0"]
[Tue Aug 18 12:56:59.519387 2026] [security2:error] [pid 66623:tid 66835] [client 68.155.154.236:16199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSAy9O5rbWdOArH04KPNwAAAU8"]
[Tue Aug 18 12:56:59.525441 2026] [authz_core:error] [pid 66623:tid 66778] [client 192.178.4.133:53183] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:59.525695 2026] [authz_core:error] [pid 66623:tid 66778] [client 192.178.4.133:53183] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:59.537618 2026] [security2:error] [pid 66623:tid 66872] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAy9O5rbWdOArH04KPOQAAAXQ"]
[Tue Aug 18 12:56:59.539823 2026] [security2:error] [pid 67073:tid 67323] [client 20.118.172.148:62135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/admin.php"] [unique_id "aoSAy_cmepr5_nHgLbNeygAAAoo"]
[Tue Aug 18 12:56:59.547847 2026] [authz_core:error] [pid 67073:tid 67144] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:59.548115 2026] [authz_core:error] [pid 67073:tid 67144] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:59.576063 2026] [security2:error] [pid 67073:tid 67291] [client 40.85.222.29:13237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAy_cmepr5_nHgLbNezQAAAmo"]
[Tue Aug 18 12:56:59.587476 2026] [security2:error] [pid 66623:tid 66794] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/about.php"] [unique_id "aoSAy9O5rbWdOArH04KPPAAAASY"]
[Tue Aug 18 12:56:59.598156 2026] [security2:error] [pid 67073:tid 67250] [client 135.225.75.187:9320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/iko.php"] [unique_id "aoSAy_cmepr5_nHgLbNezgAAAkE"]
[Tue Aug 18 12:56:59.613059 2026] [security2:error] [pid 66623:tid 66788] [client 213.35.127.232:64342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAy9O5rbWdOArH04KPPgAAASA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:56:59.619047 2026] [security2:error] [pid 66623:tid 66851] [client 52.139.47.57:17903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/wp-the.php"] [unique_id "aoSAy9O5rbWdOArH04KPPwAAAV8"]
[Tue Aug 18 12:56:59.645220 2026] [security2:error] [pid 67073:tid 67242] [client 149.34.210.141:55646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAy_cmepr5_nHgLbNexwAAAjk"]
[Tue Aug 18 12:56:59.647784 2026] [security2:error] [pid 67073:tid 67206] [client 20.104.85.180:43575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAy_cmepr5_nHgLbNezwAAAhU"]
[Tue Aug 18 12:56:59.652706 2026] [security2:error] [pid 66623:tid 66790] [client 132.196.30.78:21932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/aaa.php"] [unique_id "aoSAy9O5rbWdOArH04KPQAAAASI"]
[Tue Aug 18 12:56:59.684297 2026] [security2:error] [pid 67073:tid 67257] [client 172.202.39.151:65252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/o.php"] [unique_id "aoSAy_cmepr5_nHgLbNe0AAAAkg"]
[Tue Aug 18 12:56:59.746401 2026] [security2:error] [pid 67073:tid 67230] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/so.php"] [unique_id "aoSAy_cmepr5_nHgLbNe0QAAAi0"]
[Tue Aug 18 12:56:59.774332 2026] [security2:error] [pid 66623:tid 66825] [client 158.23.17.4:9281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/sym.php"] [unique_id "aoSAy9O5rbWdOArH04KPSAAAAUU"]
[Tue Aug 18 12:56:59.779790 2026] [security2:error] [pid 67073:tid 67208] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/goods.php"] [unique_id "aoSAy_cmepr5_nHgLbNe0wAAAhc"]
[Tue Aug 18 12:56:59.818785 2026] [security2:error] [pid 66623:tid 66885] [client 20.171.51.14:62511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/13.php"] [unique_id "aoSAy9O5rbWdOArH04KPSQAAAYE"]
[Tue Aug 18 12:56:59.848187 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:56:59.848447 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:56:59.871919 2026] [security2:error] [pid 66623:tid 66830] [client 40.74.65.169:30075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/100.php"] [unique_id "aoSAy9O5rbWdOArH04KPTQAAAUo"]
[Tue Aug 18 12:56:59.882920 2026] [security2:error] [pid 66623:tid 66849] [client 40.85.222.29:12659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/images/security.php"] [unique_id "aoSAy9O5rbWdOArH04KPTgAAAV0"]
[Tue Aug 18 12:56:59.895644 2026] [security2:error] [pid 66623:tid 66892] [client 52.139.47.57:1483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/aaa.php"] [unique_id "aoSAy9O5rbWdOArH04KPTwAAAYg"]
[Tue Aug 18 12:56:59.903761 2026] [security2:error] [pid 67073:tid 67245] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/php8.php"] [unique_id "aoSAy_cmepr5_nHgLbNe1wAAAjw"]
[Tue Aug 18 12:56:59.936319 2026] [security2:error] [pid 67073:tid 67217] [client 20.65.69.59:3719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/local.php"] [unique_id "aoSAy_cmepr5_nHgLbNe2AAAAiA"]
[Tue Aug 18 12:56:59.999988 2026] [security2:error] [pid 67073:tid 67286] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/10.php"] [unique_id "aoSAy_cmepr5_nHgLbNe2wAAAmU"]
[Tue Aug 18 12:57:00.042263 2026] [security2:error] [pid 67073:tid 67276] [client 20.65.98.162:52093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/ano.php"] [unique_id "aoSAzPcmepr5_nHgLbNe3QAAAls"]
[Tue Aug 18 12:57:00.063261 2026] [security2:error] [pid 67073:tid 67224] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/info.php"] [unique_id "aoSAzPcmepr5_nHgLbNe3gAAAic"]
[Tue Aug 18 12:57:00.087222 2026] [security2:error] [pid 66623:tid 66863] [client 20.52.168.85:7780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/kyami.php"] [unique_id "aoSAzNO5rbWdOArH04KPVAAAAWs"]
[Tue Aug 18 12:57:00.090409 2026] [security2:error] [pid 66623:tid 66873] [client 52.139.47.57:3131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/plugin.php"] [unique_id "aoSAzNO5rbWdOArH04KPVQAAAXU"]
[Tue Aug 18 12:57:00.201145 2026] [security2:error] [pid 67073:tid 67260] [client 158.158.74.177:2657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/test1.php"] [unique_id "aoSAzPcmepr5_nHgLbNe4gAAAks"]
[Tue Aug 18 12:57:00.252691 2026] [security2:error] [pid 67073:tid 67309] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/te.php"] [unique_id "aoSAzPcmepr5_nHgLbNe4wAAAnw"]
[Tue Aug 18 12:57:00.253959 2026] [security2:error] [pid 66623:tid 66861] [client 20.226.56.190:31640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/wu.php"] [unique_id "aoSAzNO5rbWdOArH04KPWgAAAWk"]
[Tue Aug 18 12:57:00.255601 2026] [security2:error] [pid 67073:tid 67254] [client 51.68.236.91:15707] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autocompanymultimarcas.com.br"] [uri "/robots.txt"] [unique_id "aoSAzPcmepr5_nHgLbNe5AAAAkU"]
[Tue Aug 18 12:57:00.255756 2026] [security2:error] [pid 67073:tid 67254] [client 51.68.236.91:15707] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autocompanymultimarcas.com.br"] [uri "/robots.txt"] [unique_id "aoSAzPcmepr5_nHgLbNe5AAAAkU"]
[Tue Aug 18 12:57:00.271321 2026] [security2:error] [pid 66623:tid 66811] [client 135.225.75.187:45886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/raw.php"] [unique_id "aoSAzNO5rbWdOArH04KPWwAAATc"]
[Tue Aug 18 12:57:00.288898 2026] [security2:error] [pid 66623:tid 66839] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/chosen.php"] [unique_id "aoSAzNO5rbWdOArH04KPXAAAAVM"]
[Tue Aug 18 12:57:00.294401 2026] [security2:error] [pid 66623:tid 66828] [client 20.215.241.237:35248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/file59.php"] [unique_id "aoSAzNO5rbWdOArH04KPXQAAAUg"]
[Tue Aug 18 12:57:00.301788 2026] [security2:error] [pid 67073:tid 67282] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/simple.php"] [unique_id "aoSAzPcmepr5_nHgLbNe5QAAAmE"]
[Tue Aug 18 12:57:00.318102 2026] [security2:error] [pid 67073:tid 67214] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAzPcmepr5_nHgLbNe5gAAAh0"]
[Tue Aug 18 12:57:00.381092 2026] [security2:error] [pid 67073:tid 67324] [client 20.171.51.14:36429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/so.php"] [unique_id "aoSAzPcmepr5_nHgLbNe6AAAAos"]
[Tue Aug 18 12:57:00.386788 2026] [authz_core:error] [pid 66623:tid 66760] [remote 57.141.22.121:32396] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:00.387051 2026] [authz_core:error] [pid 66623:tid 66760] [remote 57.141.22.121:32396] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:00.415404 2026] [security2:error] [pid 67073:tid 67207] [client 20.250.13.23:25708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/ws83.php"] [unique_id "aoSAzPcmepr5_nHgLbNe6QAAAhY"]
[Tue Aug 18 12:57:00.445188 2026] [authz_core:error] [pid 66623:tid 66709] [remote 57.141.22.12:24200] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:00.445467 2026] [authz_core:error] [pid 66623:tid 66709] [remote 57.141.22.12:24200] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:00.450627 2026] [authz_core:error] [pid 67073:tid 67111] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:00.450898 2026] [authz_core:error] [pid 67073:tid 67111] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:00.497551 2026] [security2:error] [pid 67073:tid 67305] [client 158.158.34.183:28877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/alfa.php"] [unique_id "aoSAzPcmepr5_nHgLbNe7QAAAng"]
[Tue Aug 18 12:57:00.506769 2026] [security2:error] [pid 66623:tid 66829] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kc.php"] [unique_id "aoSAzNO5rbWdOArH04KPaQAAAUk"]
[Tue Aug 18 12:57:00.526417 2026] [security2:error] [pid 67073:tid 67328] [client 178.153.171.161:46480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAzPcmepr5_nHgLbNe7gAAAo8"]
[Tue Aug 18 12:57:00.526551 2026] [security2:error] [pid 67073:tid 67328] [client 178.153.171.161:46480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAzPcmepr5_nHgLbNe7gAAAo8"]
[Tue Aug 18 12:57:00.543857 2026] [security2:error] [pid 67073:tid 67303] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAzPcmepr5_nHgLbNe5wACdnI"]
[Tue Aug 18 12:57:00.573667 2026] [security2:error] [pid 66623:tid 66853] [client 40.74.65.169:27021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/ccc.php"] [unique_id "aoSAzNO5rbWdOArH04KPbAAAAWE"]
[Tue Aug 18 12:57:00.609664 2026] [security2:error] [pid 67073:tid 67315] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/av.php"] [unique_id "aoSAzPcmepr5_nHgLbNe8AAAAoI"]
[Tue Aug 18 12:57:00.631498 2026] [security2:error] [pid 66623:tid 66833] [client 213.35.127.232:64541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAzNO5rbWdOArH04KPbwAAAU0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:00.660390 2026] [security2:error] [pid 67073:tid 67319] [client 20.118.172.148:56512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/edit.php"] [unique_id "aoSAzPcmepr5_nHgLbNe8gAAAoY"]
[Tue Aug 18 12:57:00.692644 2026] [security2:error] [pid 66623:tid 66855] [client 20.52.168.85:8059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/DxHhVcy2bmJ.php"] [unique_id "aoSAzNO5rbWdOArH04KPcgAAAWM"]
[Tue Aug 18 12:57:00.746335 2026] [autoindex:error] [pid 67073:tid 67280] [client 20.119.58.187:7951] AH01276: Cannot serve directory /home1/gfrison965/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:00.751879 2026] [authz_core:error] [pid 67073:tid 67176] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:00.752126 2026] [authz_core:error] [pid 67073:tid 67176] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:00.753856 2026] [security2:error] [pid 67073:tid 67269] [client 52.139.47.57:18159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/readme.php"] [unique_id "aoSAzPcmepr5_nHgLbNe9wAAAlQ"]
[Tue Aug 18 12:57:00.765934 2026] [security2:error] [pid 67073:tid 67216] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/jn.php"] [unique_id "aoSAzPcmepr5_nHgLbNe-AAAAh8"]
[Tue Aug 18 12:57:00.781641 2026] [security2:error] [pid 67073:tid 67213] [client 74.248.136.165:61359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/wp-tem.php"] [unique_id "aoSAzPcmepr5_nHgLbNe-QAAAhw"]
[Tue Aug 18 12:57:00.829555 2026] [security2:error] [pid 67073:tid 67236] [client 104.209.144.33:35867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAzPcmepr5_nHgLbNe-wAAAjM"]
[Tue Aug 18 12:57:00.835097 2026] [security2:error] [pid 67073:tid 67314] [client 20.215.241.237:7514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/admin.php"] [unique_id "aoSAzPcmepr5_nHgLbNe_AAAAoE"]
[Tue Aug 18 12:57:00.973519 2026] [security2:error] [pid 66623:tid 66792] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp.php"] [unique_id "aoSAzNO5rbWdOArH04KPeAAAASQ"]
[Tue Aug 18 12:57:00.980457 2026] [security2:error] [pid 66623:tid 66838] [client 20.171.51.14:15752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/10.php"] [unique_id "aoSAzNO5rbWdOArH04KPeQAAAVI"]
[Tue Aug 18 12:57:01.036794 2026] [security2:error] [pid 67073:tid 67242] [client 68.155.154.236:48952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/zugvi.php"] [unique_id "aoSAzfcmepr5_nHgLbNe_wAAAjk"]
[Tue Aug 18 12:57:01.039450 2026] [security2:error] [pid 67073:tid 67206] [client 20.65.69.59:3768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/wp_sitting.php"] [unique_id "aoSAzfcmepr5_nHgLbNfAAAAAhU"]
[Tue Aug 18 12:57:01.042187 2026] [security2:error] [pid 66623:tid 66888] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/bf.php"] [unique_id "aoSAzdO5rbWdOArH04KPegAAAYQ"]
[Tue Aug 18 12:57:01.054949 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:01.055211 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:01.066325 2026] [security2:error] [pid 66623:tid 66872] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/file2.php"] [unique_id "aoSAzdO5rbWdOArH04KPfAAAAXQ"]
[Tue Aug 18 12:57:01.080450 2026] [security2:error] [pid 67073:tid 67257] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/images/class-config.php"] [unique_id "aoSAzfcmepr5_nHgLbNfAwAAAkg"]
[Tue Aug 18 12:57:01.085898 2026] [autoindex:error] [pid 67073:tid 67219] [client 172.202.39.151:43206] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/js/crop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:01.094294 2026] [security2:error] [pid 67073:tid 67263] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/alfa.php"] [unique_id "aoSAzfcmepr5_nHgLbNfBAAAAk4"]
[Tue Aug 18 12:57:01.106798 2026] [security2:error] [pid 66623:tid 66859] [client 20.197.195.76:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/1.php"] [unique_id "aoSAzdO5rbWdOArH04KPfQAAAWc"]
[Tue Aug 18 12:57:01.106900 2026] [security2:error] [pid 66623:tid 66859] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/1.php"] [unique_id "aoSAzdO5rbWdOArH04KPfQAAAWc"]
[Tue Aug 18 12:57:01.117229 2026] [security2:error] [pid 66623:tid 66794] [client 20.206.73.37:59938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/ops.php"] [unique_id "aoSAzdO5rbWdOArH04KPfgAAASY"]
[Tue Aug 18 12:57:01.127496 2026] [security2:error] [pid 67073:tid 67270] [client 158.158.74.177:16526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/thoms.php"] [unique_id "aoSAzfcmepr5_nHgLbNfBQAAAlU"]
[Tue Aug 18 12:57:01.221699 2026] [security2:error] [pid 67073:tid 67228] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/222.php"] [unique_id "aoSAzfcmepr5_nHgLbNfBwAAAis"]
[Tue Aug 18 12:57:01.235641 2026] [security2:error] [pid 67073:tid 67253] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/asasx.php"] [unique_id "aoSAzfcmepr5_nHgLbNfCAAAAkQ"]
[Tue Aug 18 12:57:01.249357 2026] [security2:error] [pid 66623:tid 66869] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/filemanager.php"] [unique_id "aoSAzdO5rbWdOArH04KPgQAAAXE"]
[Tue Aug 18 12:57:01.262245 2026] [security2:error] [pid 66623:tid 66795] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/themes.php"] [unique_id "aoSAzdO5rbWdOArH04KPgwAAASc"]
[Tue Aug 18 12:57:01.268756 2026] [security2:error] [pid 66623:tid 66782] [client 40.74.65.169:27787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/get.php"] [unique_id "aoSAzdO5rbWdOArH04KPhQAAARo"]
[Tue Aug 18 12:57:01.274828 2026] [security2:error] [pid 66623:tid 66881] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAzdO5rbWdOArH04KPhgAAAX0"]
[Tue Aug 18 12:57:01.296226 2026] [security2:error] [pid 66623:tid 66803] [client 20.52.168.85:7746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/amaxx.php"] [unique_id "aoSAzdO5rbWdOArH04KPhwAAAS8"]
[Tue Aug 18 12:57:01.303995 2026] [security2:error] [pid 67073:tid 67262] [client 20.250.13.23:14010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/atex1.php"] [unique_id "aoSAzfcmepr5_nHgLbNfCgAAAk0"]
[Tue Aug 18 12:57:01.359319 2026] [security2:error] [pid 67073:tid 67223] [client 20.215.241.237:61100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/aa2.php"] [unique_id "aoSAzfcmepr5_nHgLbNfCwAAAiY"]
[Tue Aug 18 12:57:01.364081 2026] [security2:error] [pid 66623:tid 66892] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/buy.php"] [unique_id "aoSAzdO5rbWdOArH04KPigAAAYg"]
[Tue Aug 18 12:57:01.373927 2026] [security2:error] [pid 67073:tid 67240] [client 172.202.39.151:43206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-mail.php"] [unique_id "aoSAzfcmepr5_nHgLbNfDAAAAjc"]
[Tue Aug 18 12:57:01.384048 2026] [security2:error] [pid 67073:tid 67245] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/dropdown.php"] [unique_id "aoSAzfcmepr5_nHgLbNfDQAAAjw"]
[Tue Aug 18 12:57:01.393680 2026] [security2:error] [pid 67073:tid 67296] [client 52.139.47.57:48722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/chosen.php"] [unique_id "aoSAzfcmepr5_nHgLbNfDgAAAm8"]
[Tue Aug 18 12:57:01.481352 2026] [security2:error] [pid 67073:tid 67224] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/inputs.php"] [unique_id "aoSAzfcmepr5_nHgLbNfEAAAAic"]
[Tue Aug 18 12:57:01.482906 2026] [security2:error] [pid 67073:tid 67271] [client 52.173.121.69:16459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSAzfcmepr5_nHgLbNfEQAAAlY"]
[Tue Aug 18 12:57:01.489550 2026] [security2:error] [pid 67073:tid 67312] [client 85.154.68.202:52620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAzfcmepr5_nHgLbNfEgAAAn8"]
[Tue Aug 18 12:57:01.489676 2026] [security2:error] [pid 67073:tid 67312] [client 85.154.68.202:52620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAzfcmepr5_nHgLbNfEgAAAn8"]
[Tue Aug 18 12:57:01.514030 2026] [security2:error] [pid 67073:tid 67232] [client 172.182.200.96:14164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSAzfcmepr5_nHgLbNfEwAAAi8"]
[Tue Aug 18 12:57:01.521097 2026] [security2:error] [pid 67073:tid 67267] [client 135.225.75.187:20254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/05.php"] [unique_id "aoSAzfcmepr5_nHgLbNfFAAAAlI"]
[Tue Aug 18 12:57:01.526927 2026] [security2:error] [pid 67073:tid 67209] [client 68.155.154.236:16280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSAzfcmepr5_nHgLbNfFQAAAhg"]
[Tue Aug 18 12:57:01.543363 2026] [security2:error] [pid 67073:tid 67317] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/100.php"] [unique_id "aoSAzfcmepr5_nHgLbNfFgAAAoQ"]
[Tue Aug 18 12:57:01.557432 2026] [security2:error] [pid 67073:tid 67261] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/akc.php"] [unique_id "aoSAzfcmepr5_nHgLbNfFwAAAkw"]
[Tue Aug 18 12:57:01.573354 2026] [security2:error] [pid 66623:tid 66890] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSAzdO5rbWdOArH04KPkQAAAYY"]
[Tue Aug 18 12:57:01.583694 2026] [security2:error] [pid 67073:tid 67239] [client 20.100.169.31:7785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/bthil.php"] [unique_id "aoSAzfcmepr5_nHgLbNfGAAAAjY"]
[Tue Aug 18 12:57:01.598702 2026] [security2:error] [pid 67073:tid 67274] [client 160.120.140.123:63702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAzfcmepr5_nHgLbNfGQAAAlk"]
[Tue Aug 18 12:57:01.598867 2026] [security2:error] [pid 67073:tid 67274] [client 160.120.140.123:63702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAzfcmepr5_nHgLbNfGQAAAlk"]
[Tue Aug 18 12:57:01.635444 2026] [security2:error] [pid 66623:tid 66871] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/php.php"] [unique_id "aoSAzdO5rbWdOArH04KPlAAAAXM"]
[Tue Aug 18 12:57:01.642750 2026] [security2:error] [pid 66623:tid 66778] [client 20.171.51.14:62506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/te.php"] [unique_id "aoSAzdO5rbWdOArH04KPlQAAARY"]
[Tue Aug 18 12:57:01.645299 2026] [security2:error] [pid 66623:tid 66830] [client 213.35.127.232:64754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAzdO5rbWdOArH04KPlgAAAUo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:01.678021 2026] [security2:error] [pid 66623:tid 66798] [client 119.93.171.138:61139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.171.93.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imbeg.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAzdO5rbWdOArH04KPjAAAASo"]
[Tue Aug 18 12:57:01.678216 2026] [security2:error] [pid 66623:tid 66798] [client 119.93.171.138:61139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "imbeg.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAzdO5rbWdOArH04KPjAAAASo"]
[Tue Aug 18 12:57:01.686506 2026] [security2:error] [pid 66623:tid 66887] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/t.php"] [unique_id "aoSAzdO5rbWdOArH04KPlwAAAYM"]
[Tue Aug 18 12:57:01.753992 2026] [security2:error] [pid 67073:tid 67278] [client 158.158.34.183:64530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "aoSAzfcmepr5_nHgLbNfGwAAAl0"]
[Tue Aug 18 12:57:01.774354 2026] [security2:error] [pid 66623:tid 66856] [client 68.155.155.199:9362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/simple.php"] [unique_id "aoSAzdO5rbWdOArH04KPmQAAAWQ"]
[Tue Aug 18 12:57:01.781970 2026] [security2:error] [pid 66623:tid 66773] [client 132.196.30.78:18658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/abcd.php"] [unique_id "aoSAzdO5rbWdOArH04KPmwAAARE"]
[Tue Aug 18 12:57:01.781953 2026] [security2:error] [pid 66623:tid 66873] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/index/function.php"] [unique_id "aoSAzdO5rbWdOArH04KPmgAAAXU"]
[Tue Aug 18 12:57:01.836350 2026] [security2:error] [pid 67073:tid 67281] [client 158.23.17.4:63672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/ye.php"] [unique_id "aoSAzfcmepr5_nHgLbNfHQAAAmA"]
[Tue Aug 18 12:57:01.856189 2026] [security2:error] [pid 67073:tid 67217] [client 114.5.214.109:49813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAzfcmepr5_nHgLbNfHgAAAiA"]
[Tue Aug 18 12:57:01.863191 2026] [security2:error] [pid 67073:tid 67303] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wk/index.php"] [unique_id "aoSAzfcmepr5_nHgLbNfIAAAAnY"]
[Tue Aug 18 12:57:01.871898 2026] [security2:error] [pid 67073:tid 67235] [client 20.206.73.37:20729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/8.php"] [unique_id "aoSAzfcmepr5_nHgLbNfIQAAAjI"]
[Tue Aug 18 12:57:01.873370 2026] [security2:error] [pid 67073:tid 67217] [client 114.5.214.109:49813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAzfcmepr5_nHgLbNfHgAAAiA"]
[Tue Aug 18 12:57:01.880389 2026] [security2:error] [pid 67073:tid 67290] [client 20.215.241.237:43169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/xamp.php"] [unique_id "aoSAzfcmepr5_nHgLbNfIwAAAmk"]
[Tue Aug 18 12:57:01.897306 2026] [security2:error] [pid 67073:tid 67307] [client 20.52.168.85:7855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/BIBIL0DAY.php"] [unique_id "aoSAzfcmepr5_nHgLbNfJAAAAno"]
[Tue Aug 18 12:57:01.936144 2026] [security2:error] [pid 67073:tid 67331] [client 68.155.154.236:8022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wsrer.php"] [unique_id "aoSAzfcmepr5_nHgLbNfJQAAApI"]
[Tue Aug 18 12:57:01.959054 2026] [security2:error] [pid 67073:tid 67283] [client 40.74.65.169:43139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/images.php"] [unique_id "aoSAzfcmepr5_nHgLbNfJgAAAmI"]
[Tue Aug 18 12:57:02.002990 2026] [security2:error] [pid 67073:tid 67266] [client 20.171.51.14:15756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/kc.php"] [unique_id "aoSAzvcmepr5_nHgLbNfKAAAAlE"]
[Tue Aug 18 12:57:02.031133 2026] [security2:error] [pid 67073:tid 67258] [client 158.158.74.177:26143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/tool.php"] [unique_id "aoSAzvcmepr5_nHgLbNfKwAAAkk"]
[Tue Aug 18 12:57:02.090762 2026] [security2:error] [pid 67073:tid 67221] [client 52.139.47.57:48745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/system.php"] [unique_id "aoSAzvcmepr5_nHgLbNfLQAAAiQ"]
[Tue Aug 18 12:57:02.120055 2026] [security2:error] [pid 66623:tid 66822] [client 20.65.69.59:40539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/ninja.php"] [unique_id "aoSAztO5rbWdOArH04KPpAAAAUI"]
[Tue Aug 18 12:57:02.174951 2026] [security2:error] [pid 66623:tid 66849] [client 20.100.169.31:25869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/155.php"] [unique_id "aoSAztO5rbWdOArH04KPpgAAAV0"]
[Tue Aug 18 12:57:02.184483 2026] [security2:error] [pid 67073:tid 67301] [client 172.202.39.151:54695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/o.php"] [unique_id "aoSAzvcmepr5_nHgLbNfLwAAAnQ"]
[Tue Aug 18 12:57:02.246098 2026] [security2:error] [pid 66623:tid 66811] [client 52.173.121.69:24776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSAztO5rbWdOArH04KPqAAAATc"]
[Tue Aug 18 12:57:02.294135 2026] [security2:error] [pid 66623:tid 66821] [client 114.119.131.235:55543] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "site.paulocardosoimoveis.com"] [uri "/imoveis/venda/casa-itaipu"] [unique_id "aoSAztO5rbWdOArH04KPqQAAAUE"], referer: https://site.paulocardosoimoveis.com/imoveis/venda/casa-itaipu
[Tue Aug 18 12:57:02.419955 2026] [security2:error] [pid 66623:tid 66861] [client 132.196.30.78:21912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-good.php"] [unique_id "aoSAztO5rbWdOArH04KPrQAAAWk"]
[Tue Aug 18 12:57:02.427150 2026] [security2:error] [pid 66623:tid 66886] [client 74.248.136.165:46809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/sadd.php"] [unique_id "aoSAztO5rbWdOArH04KPrwAAAYI"]
[Tue Aug 18 12:57:02.442518 2026] [security2:error] [pid 66623:tid 66805] [client 20.171.51.14:58853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/jn.php"] [unique_id "aoSAztO5rbWdOArH04KPsAAAATE"]
[Tue Aug 18 12:57:02.497844 2026] [security2:error] [pid 67073:tid 67291] [client 20.52.168.85:8018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/functions.php"] [unique_id "aoSAzvcmepr5_nHgLbNfNAAAAmo"]
[Tue Aug 18 12:57:02.505838 2026] [security2:error] [pid 67073:tid 67270] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-blink.php"] [unique_id "aoSAzvcmepr5_nHgLbNfNQAAAlU"]
[Tue Aug 18 12:57:02.515514 2026] [security2:error] [pid 67073:tid 67230] [client 20.226.56.190:23772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/de.php"] [unique_id "aoSAzvcmepr5_nHgLbNfNgAAAi0"]
[Tue Aug 18 12:57:02.525793 2026] [security2:error] [pid 66623:tid 66883] [client 52.139.47.57:18141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/wp-load.php"] [unique_id "aoSAztO5rbWdOArH04KPtAAAAX8"]
[Tue Aug 18 12:57:02.549053 2026] [security2:error] [pid 67073:tid 67225] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/xfun.php"] [unique_id "aoSAzvcmepr5_nHgLbNfNwAAAig"]
[Tue Aug 18 12:57:02.562067 2026] [security2:error] [pid 67073:tid 67284] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/p.php"] [unique_id "aoSAzvcmepr5_nHgLbNfOAAAAmM"]
[Tue Aug 18 12:57:02.573086 2026] [security2:error] [pid 66623:tid 66844] [client 20.215.241.237:59486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/bless.php"] [unique_id "aoSAztO5rbWdOArH04KPtQAAAVg"]
[Tue Aug 18 12:57:02.576111 2026] [security2:error] [pid 67073:tid 67212] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAzvcmepr5_nHgLbNfOQAAAhs"]
[Tue Aug 18 12:57:02.595547 2026] [authz_core:error] [pid 67073:tid 67200] [remote 57.141.22.27:46640] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:02.595836 2026] [authz_core:error] [pid 67073:tid 67200] [remote 57.141.22.27:46640] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:02.618170 2026] [security2:error] [pid 66623:tid 66870] [client 20.206.73.37:59845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/biufile.php"] [unique_id "aoSAztO5rbWdOArH04KPuQAAAXI"]
[Tue Aug 18 12:57:02.657198 2026] [security2:error] [pid 66623:tid 66776] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/aaa.php"] [unique_id "aoSAztO5rbWdOArH04KPugAAARQ"]
[Tue Aug 18 12:57:02.659885 2026] [security2:error] [pid 66623:tid 66839] [client 213.35.127.232:64980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAztO5rbWdOArH04KPuwAAAVM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:02.660285 2026] [security2:error] [pid 67073:tid 67296] [client 40.74.65.169:27818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/alls.php"] [unique_id "aoSAzvcmepr5_nHgLbNfPAAAAm8"]
[Tue Aug 18 12:57:02.674716 2026] [security2:error] [pid 67073:tid 67318] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/term.php"] [unique_id "aoSAzvcmepr5_nHgLbNfPQAAAoU"]
[Tue Aug 18 12:57:02.679695 2026] [security2:error] [pid 66623:tid 66808] [client 20.118.172.148:62430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/w.php"] [unique_id "aoSAztO5rbWdOArH04KPvAAAATQ"]
[Tue Aug 18 12:57:02.689302 2026] [security2:error] [pid 67073:tid 67211] [client 135.225.75.187:20224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/public/hi.php"] [unique_id "aoSAzvcmepr5_nHgLbNfPwAAAho"]
[Tue Aug 18 12:57:02.725782 2026] [security2:error] [pid 67073:tid 67271] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/7.php"] [unique_id "aoSAzvcmepr5_nHgLbNfQQAAAlY"]
[Tue Aug 18 12:57:02.740187 2026] [security2:error] [pid 67073:tid 67312] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/file5.php"] [unique_id "aoSAzvcmepr5_nHgLbNfQgAAAn8"]
[Tue Aug 18 12:57:02.742833 2026] [security2:error] [pid 67073:tid 67322] [client 20.65.98.162:53495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/ai.php"] [unique_id "aoSAzvcmepr5_nHgLbNfQwAAAok"]
[Tue Aug 18 12:57:02.752849 2026] [security2:error] [pid 67073:tid 67267] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSAzvcmepr5_nHgLbNfRwAAAlI"]
[Tue Aug 18 12:57:02.757328 2026] [security2:error] [pid 67073:tid 67317] [client 20.226.56.190:31630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/album.php"] [unique_id "aoSAzvcmepr5_nHgLbNfSAAAAoQ"]
[Tue Aug 18 12:57:02.759461 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:02.759736 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:02.762168 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:02.762353 2026] [authz_core:error] [pid 67073:tid 67188] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:02.762603 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:02.762809 2026] [authz_core:error] [pid 67073:tid 67188] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:02.763416 2026] [security2:error] [pid 67073:tid 67243] [client 52.173.121.69:16462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSAzvcmepr5_nHgLbNfSQAAAjo"]
[Tue Aug 18 12:57:02.765239 2026] [security2:error] [pid 67073:tid 67261] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAzvcmepr5_nHgLbNfSgAAAkw"]
[Tue Aug 18 12:57:02.779359 2026] [security2:error] [pid 67073:tid 67260] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSAzvcmepr5_nHgLbNfSwAAAks"]
[Tue Aug 18 12:57:02.779555 2026] [security2:error] [pid 67073:tid 67297] [client 104.209.144.33:21383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSAzvcmepr5_nHgLbNfTAAAAnA"]
[Tue Aug 18 12:57:02.791609 2026] [security2:error] [pid 66623:tid 66813] [client 68.155.154.236:48953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/ucpfr.php"] [unique_id "aoSAztO5rbWdOArH04KPvwAAATk"]
[Tue Aug 18 12:57:02.847021 2026] [security2:error] [pid 66623:tid 66793] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/atomlib.php"] [unique_id "aoSAztO5rbWdOArH04KPwAAAASU"]
[Tue Aug 18 12:57:02.852689 2026] [security2:error] [pid 67073:tid 67319] [client 20.250.13.23:38922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/class-t.api.php"] [unique_id "aoSAzvcmepr5_nHgLbNfTgAAAoY"]
[Tue Aug 18 12:57:02.875135 2026] [security2:error] [pid 67073:tid 67324] [client 20.65.69.59:49321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/phpprobe.php"] [unique_id "aoSAzvcmepr5_nHgLbNfTwAAAos"]
[Tue Aug 18 12:57:02.878311 2026] [security2:error] [pid 67073:tid 67207] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/min.php"] [unique_id "aoSAzvcmepr5_nHgLbNfUAAAAhY"]
[Tue Aug 18 12:57:02.880245 2026] [security2:error] [pid 67073:tid 67117] [remote 192.250.229.214:42450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.229.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nadianobre.com.br"] [uri "/wp-login.php"] [unique_id "aoSAzvcmepr5_nHgLbNfUQACXSk"]
[Tue Aug 18 12:57:02.914048 2026] [security2:error] [pid 67073:tid 67305] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/mac.php"] [unique_id "aoSAzvcmepr5_nHgLbNfUgAAAng"]
[Tue Aug 18 12:57:02.928889 2026] [security2:error] [pid 66623:tid 66877] [client 52.139.47.57:3076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/fpwch.php"] [unique_id "aoSAztO5rbWdOArH04KPwgAAAXk"]
[Tue Aug 18 12:57:02.930741 2026] [security2:error] [pid 67073:tid 67259] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/nc4.php"] [unique_id "aoSAzvcmepr5_nHgLbNfUwAAAko"]
[Tue Aug 18 12:57:02.944833 2026] [security2:error] [pid 66623:tid 66874] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/as.php"] [unique_id "aoSAztO5rbWdOArH04KPwwAAAXY"]
[Tue Aug 18 12:57:02.949389 2026] [security2:error] [pid 66623:tid 66772] [client 20.226.56.190:17904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kv.php"] [unique_id "aoSAztO5rbWdOArH04KPxAAAARA"]
[Tue Aug 18 12:57:02.956644 2026] [security2:error] [pid 66623:tid 66889] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/k.php"] [unique_id "aoSAztO5rbWdOArH04KPxQAAAYU"]
[Tue Aug 18 12:57:02.974130 2026] [security2:error] [pid 66623:tid 66857] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSAztO5rbWdOArH04KPyAAAAWU"]
[Tue Aug 18 12:57:02.986295 2026] [security2:error] [pid 67073:tid 67235] [client 20.171.51.14:36452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/bf.php"] [unique_id "aoSAzvcmepr5_nHgLbNfVAAAAjI"]
[Tue Aug 18 12:57:03.013999 2026] [security2:error] [pid 67073:tid 67306] [client 132.196.30.78:18755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/simple.php"] [unique_id "aoSAz_cmepr5_nHgLbNfVQAAAnk"]
[Tue Aug 18 12:57:03.060915 2026] [security2:error] [pid 66623:tid 66767] [client 68.155.155.199:3554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAz9O5rbWdOArH04KPyQAAAQs"]
[Tue Aug 18 12:57:03.062011 2026] [security2:error] [pid 67073:tid 67325] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/system_log.php"] [unique_id "aoSAz_cmepr5_nHgLbNfWAAAAow"]
[Tue Aug 18 12:57:03.100563 2026] [security2:error] [pid 66623:tid 66865] [client 52.139.47.57:17918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/files/8.php"] [unique_id "aoSAz9O5rbWdOArH04KPywAAAW0"]
[Tue Aug 18 12:57:03.103788 2026] [security2:error] [pid 67073:tid 67220] [client 20.52.168.85:7868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-comments-post.php"] [unique_id "aoSAz_cmepr5_nHgLbNfWQAAAiM"]
[Tue Aug 18 12:57:03.118970 2026] [security2:error] [pid 66623:tid 66855] [client 20.100.169.31:12570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/96i.php"] [unique_id "aoSAz9O5rbWdOArH04KPzQAAAWM"]
[Tue Aug 18 12:57:03.205754 2026] [security2:error] [pid 67073:tid 67191] [remote 129.121.103.155:38692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/wp-login.php"] [unique_id "aoSAz_cmepr5_nHgLbNfWgACZ3M"]
[Tue Aug 18 12:57:03.282568 2026] [security2:error] [pid 67073:tid 67266] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/x.php"] [unique_id "aoSAz_cmepr5_nHgLbNfXAAAAlE"]
[Tue Aug 18 12:57:03.337938 2026] [security2:error] [pid 66623:tid 66801] [client 20.226.56.190:20410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/z.php"] [unique_id "aoSAz9O5rbWdOArH04KP0QAAAS0"]
[Tue Aug 18 12:57:03.353181 2026] [security2:error] [pid 67073:tid 67332] [client 40.74.65.169:27768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/coffexium.php"] [unique_id "aoSAz_cmepr5_nHgLbNfXgAAApM"]
[Tue Aug 18 12:57:03.369053 2026] [security2:error] [pid 67073:tid 67221] [client 20.118.172.148:62444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/file.php"] [unique_id "aoSAz_cmepr5_nHgLbNfYAAAAiQ"]
[Tue Aug 18 12:57:03.398432 2026] [security2:error] [pid 66623:tid 66824] [client 104.209.144.33:34112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/help/crnpwfiu.php"] [unique_id "aoSAz9O5rbWdOArH04KP0gAAAUQ"]
[Tue Aug 18 12:57:03.478100 2026] [security2:error] [pid 66623:tid 66829] [client 157.51.166.53:63748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAz9O5rbWdOArH04KP1gAAAUk"]
[Tue Aug 18 12:57:03.478202 2026] [security2:error] [pid 66623:tid 66829] [client 157.51.166.53:63748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAz9O5rbWdOArH04KP1gAAAUk"]
[Tue Aug 18 12:57:03.504561 2026] [security2:error] [pid 66623:tid 66825] [client 135.225.75.187:33047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/get.php"] [unique_id "aoSAz9O5rbWdOArH04KP2QAAAUU"]
[Tue Aug 18 12:57:03.630292 2026] [security2:error] [pid 67073:tid 67222] [client 132.196.30.78:21892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/edit-tags.php"] [unique_id "aoSAz_cmepr5_nHgLbNfZgAAAiU"]
[Tue Aug 18 12:57:03.649497 2026] [security2:error] [pid 67073:tid 67242] [client 20.215.241.237:35249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/file25.php"] [unique_id "aoSAz_cmepr5_nHgLbNfZwAAAjk"]
[Tue Aug 18 12:57:03.678357 2026] [security2:error] [pid 67073:tid 67210] [client 213.35.127.232:65233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAz_cmepr5_nHgLbNfaAAAAhk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:03.707508 2026] [security2:error] [pid 66623:tid 66771] [client 20.52.168.85:7854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/conf_upload.php"] [unique_id "aoSAz9O5rbWdOArH04KP4QAAAQ8"]
[Tue Aug 18 12:57:03.710686 2026] [security2:error] [pid 67073:tid 67219] [client 20.65.69.59:49281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/wp-title.php"] [unique_id "aoSAz_cmepr5_nHgLbNfagAAAiI"]
[Tue Aug 18 12:57:03.794194 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:03.794638 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:03.894031 2026] [security2:error] [pid 66623:tid 66677] [remote 34.176.82.226:40370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.82.176.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "site.supercarconsulting.com.br"] [uri "/wp-login.php"] [unique_id "aoSAz9O5rbWdOArH04KP8QABdCg"]
[Tue Aug 18 12:57:03.909829 2026] [security2:error] [pid 66623:tid 66848] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAz9O5rbWdOArH04KP7wABXD4"]
[Tue Aug 18 12:57:03.917743 2026] [security2:error] [pid 67073:tid 67286] [client 172.202.39.151:55514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/bb.php"] [unique_id "aoSAz_cmepr5_nHgLbNfcQAAAmU"]
[Tue Aug 18 12:57:03.935339 2026] [security2:error] [pid 67073:tid 67099] [remote 162.214.96.231:44850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gvc.eng.br"] [uri "/wp-login.php"] [unique_id "aoSAz_cmepr5_nHgLbNfcwACKRc"]
[Tue Aug 18 12:57:03.942447 2026] [security2:error] [pid 67073:tid 67253] [client 20.118.172.148:62133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAz_cmepr5_nHgLbNfdAAAAkQ"]
[Tue Aug 18 12:57:04.027535 2026] [security2:error] [pid 66623:tid 66782] [client 20.250.13.23:25687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/w.php"] [unique_id "aoSA0NO5rbWdOArH04KP9gAAARo"]
[Tue Aug 18 12:57:04.053601 2026] [security2:error] [pid 66623:tid 66769] [client 40.74.65.169:27785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/red.php"] [unique_id "aoSA0NO5rbWdOArH04KP-QAAAQ0"]
[Tue Aug 18 12:57:04.120439 2026] [security2:error] [pid 67073:tid 67276] [client 132.196.30.78:18752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/u.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfdQAAAls"]
[Tue Aug 18 12:57:04.208200 2026] [security2:error] [pid 67073:tid 67267] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfeAAAAlI"]
[Tue Aug 18 12:57:04.225429 2026] [security2:error] [pid 67073:tid 67209] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/hosty.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfeQAAAhg"]
[Tue Aug 18 12:57:04.227670 2026] [security2:error] [pid 67073:tid 67317] [client 68.155.154.236:65483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/yxijx.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfegAAAoQ"]
[Tue Aug 18 12:57:04.234433 2026] [security2:error] [pid 66623:tid 66827] [client 74.248.136.165:22465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ex.php"] [unique_id "aoSA0NO5rbWdOArH04KQOAAAAUc"]
[Tue Aug 18 12:57:04.239768 2026] [security2:error] [pid 66623:tid 66850] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/test1.php"] [unique_id "aoSA0NO5rbWdOArH04KQOQAAAV4"]
[Tue Aug 18 12:57:04.276020 2026] [security2:error] [pid 67073:tid 67260] [client 104.209.144.33:35898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfewAAAks"]
[Tue Aug 18 12:57:04.310069 2026] [security2:error] [pid 66623:tid 66785] [client 20.52.168.85:8057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/content.php888"] [unique_id "aoSA0NO5rbWdOArH04KQPQAAAR0"]
[Tue Aug 18 12:57:04.331503 2026] [security2:error] [pid 67073:tid 67218] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/zwso.php"] [unique_id "aoSA0Pcmepr5_nHgLbNffAAAAiE"]
[Tue Aug 18 12:57:04.340637 2026] [security2:error] [pid 67073:tid 67254] [client 68.155.156.252:20767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSA0Pcmepr5_nHgLbNffQAAAkU"]
[Tue Aug 18 12:57:04.344179 2026] [security2:error] [pid 67073:tid 67282] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/Geforce.php"] [unique_id "aoSA0Pcmepr5_nHgLbNffgAAAmE"]
[Tue Aug 18 12:57:04.353021 2026] [security2:error] [pid 66623:tid 66807] [client 20.118.172.148:62113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/aa.php"] [unique_id "aoSA0NO5rbWdOArH04KQQAAAATM"]
[Tue Aug 18 12:57:04.358980 2026] [security2:error] [pid 67073:tid 67309] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/fpwch.php"] [unique_id "aoSA0Pcmepr5_nHgLbNffwAAAnw"]
[Tue Aug 18 12:57:04.447178 2026] [security2:error] [pid 67073:tid 67324] [client 68.155.155.199:2297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/av.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfhAAAAos"]
[Tue Aug 18 12:57:04.492129 2026] [security2:error] [pid 66623:tid 66870] [client 20.65.69.59:3767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/styles.php"] [unique_id "aoSA0NO5rbWdOArH04KQQwAAAXI"]
[Tue Aug 18 12:57:04.630613 2026] [security2:error] [pid 67073:tid 67294] [client 196.12.128.158:52482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfiAAAAm0"]
[Tue Aug 18 12:57:04.630811 2026] [security2:error] [pid 67073:tid 67294] [client 196.12.128.158:52482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfiAAAAm0"]
[Tue Aug 18 12:57:04.634327 2026] [authz_core:error] [pid 67073:tid 67160] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:04.634588 2026] [authz_core:error] [pid 67073:tid 67160] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:04.694938 2026] [security2:error] [pid 67073:tid 67272] [client 213.35.127.232:65437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfigAAAlc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:04.698737 2026] [security2:error] [pid 66623:tid 66793] [client 135.225.75.187:26540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/rpk.php"] [unique_id "aoSA0NO5rbWdOArH04KQUAAAASU"]
[Tue Aug 18 12:57:04.702230 2026] [security2:error] [pid 66623:tid 66774] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSA0NO5rbWdOArH04KQUQAAARI"]
[Tue Aug 18 12:57:04.714677 2026] [cgid:error] [pid 67073:tid 67327] [client 20.100.169.31:43813] AH01265: stderr from /home1/lubarbosa/public_html/cgi-bin/: attempt to invoke directory as script
[Tue Aug 18 12:57:04.725815 2026] [security2:error] [pid 67073:tid 67279] [client 20.226.56.190:20414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/xg.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfjAAAAl4"]
[Tue Aug 18 12:57:04.748920 2026] [security2:error] [pid 67073:tid 67329] [client 79.127.164.8:60518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/my.bak"] [unique_id "aoSA0Pcmepr5_nHgLbNfjQAAApA"], referer: https://medihub.com.br/my.bak
[Tue Aug 18 12:57:04.850953 2026] [security2:error] [pid 67073:tid 67308] [client 20.118.172.148:62111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfjwAAAns"]
[Tue Aug 18 12:57:04.855858 2026] [security2:error] [pid 67073:tid 67325] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/about/function.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfkAAAAow"]
[Tue Aug 18 12:57:04.908564 2026] [security2:error] [pid 66623:tid 66776] [client 158.158.74.177:26172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/tools.php"] [unique_id "aoSA0NO5rbWdOArH04KQWgAAARQ"]
[Tue Aug 18 12:57:04.921132 2026] [security2:error] [pid 67073:tid 67248] [client 20.52.168.85:8063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/gecko-new.php.1"] [unique_id "aoSA0Pcmepr5_nHgLbNfkwAAAj8"]
[Tue Aug 18 12:57:04.922316 2026] [security2:error] [pid 67073:tid 67283] [client 20.100.169.31:43813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/x.php"] [unique_id "aoSA0Pcmepr5_nHgLbNflAAAAmI"]
[Tue Aug 18 12:57:04.933795 2026] [security2:error] [pid 66623:tid 66768] [client 132.196.30.78:21883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSA0NO5rbWdOArH04KQXgAAAQw"]
[Tue Aug 18 12:57:04.935041 2026] [security2:error] [pid 67073:tid 67288] [client 20.215.241.237:43149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/file15.php"] [unique_id "aoSA0Pcmepr5_nHgLbNflQAAAmc"]
[Tue Aug 18 12:57:05.068014 2026] [security2:error] [pid 67073:tid 67301] [client 68.155.154.236:7621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/zwlsv.php"] [unique_id "aoSA0fcmepr5_nHgLbNfnwAAAnQ"]
[Tue Aug 18 12:57:05.111152 2026] [authz_core:error] [pid 67073:tid 67118] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:05.111444 2026] [authz_core:error] [pid 67073:tid 67118] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:05.196077 2026] [security2:error] [pid 67073:tid 67222] [client 20.118.172.148:62452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/about.php"] [unique_id "aoSA0fcmepr5_nHgLbNfsgAAAiU"]
[Tue Aug 18 12:57:05.208063 2026] [security2:error] [pid 67073:tid 67332] [client 20.100.169.31:16055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/as.php"] [unique_id "aoSA0fcmepr5_nHgLbNfswAAApM"]
[Tue Aug 18 12:57:05.238774 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:05.239049 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:05.259604 2026] [security2:error] [pid 67073:tid 67206] [client 20.65.69.59:49292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/server.php"] [unique_id "aoSA0fcmepr5_nHgLbNftQAAAhU"]
[Tue Aug 18 12:57:05.280170 2026] [security2:error] [pid 67073:tid 67210] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/function/function.php"] [unique_id "aoSA0fcmepr5_nHgLbNftgAAAhk"]
[Tue Aug 18 12:57:05.299901 2026] [security2:error] [pid 67073:tid 67257] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-signin.php"] [unique_id "aoSA0fcmepr5_nHgLbNftwAAAkg"]
[Tue Aug 18 12:57:05.305482 2026] [security2:error] [pid 67073:tid 67293] [client 20.250.13.23:41603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/archive.php"] [unique_id "aoSA0fcmepr5_nHgLbNfuAAAAmw"]
[Tue Aug 18 12:57:05.339511 2026] [security2:error] [pid 67073:tid 67213] [client 172.202.39.151:55550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSA0fcmepr5_nHgLbNfuQAAAhw"]
[Tue Aug 18 12:57:05.367207 2026] [security2:error] [pid 66623:tid 66812] [client 172.202.39.151:65264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/bb.php"] [unique_id "aoSA0dO5rbWdOArH04KQbgAAATg"]
[Tue Aug 18 12:57:05.411242 2026] [security2:error] [pid 67073:tid 67291] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/f35.php"] [unique_id "aoSA0fcmepr5_nHgLbNfvAAAAmo"]
[Tue Aug 18 12:57:05.427759 2026] [security2:error] [pid 67073:tid 67238] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/gg.php"] [unique_id "aoSA0fcmepr5_nHgLbNfvQAAAjU"]
[Tue Aug 18 12:57:05.472297 2026] [security2:error] [pid 67073:tid 67223] [client 135.225.75.187:9347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-blog.php"] [unique_id "aoSA0fcmepr5_nHgLbNfvwAAAiY"]
[Tue Aug 18 12:57:05.519263 2026] [security2:error] [pid 67073:tid 67296] [client 114.119.144.176:64321] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "eccellenzaconsultoria.com.br"] [uri "/robots.txt"] [unique_id "aoSA0fcmepr5_nHgLbNfwwAAAm8"], referer: http://eccellenzaconsultoria.com.br/robots.txt
[Tue Aug 18 12:57:05.520563 2026] [security2:error] [pid 66623:tid 66840] [client 20.52.168.85:8045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/OthioNDwMEK.php"] [unique_id "aoSA0dO5rbWdOArH04KQdAAAAVQ"]
[Tue Aug 18 12:57:05.539633 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:05.540029 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:05.544826 2026] [security2:error] [pid 66623:tid 66864] [client 20.118.172.148:62143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/goods.php"] [unique_id "aoSA0dO5rbWdOArH04KQdgAAAWw"]
[Tue Aug 18 12:57:05.550343 2026] [security2:error] [pid 66623:tid 66804] [client 132.196.30.78:18678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/h.php"] [unique_id "aoSA0dO5rbWdOArH04KQeAAAATA"]
[Tue Aug 18 12:57:05.571328 2026] [security2:error] [pid 67073:tid 67211] [client 104.209.144.33:17253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSA0fcmepr5_nHgLbNfxgAAAho"]
[Tue Aug 18 12:57:05.571342 2026] [security2:error] [pid 67073:tid 67286] [client 20.226.56.190:52033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/nd.php"] [unique_id "aoSA0fcmepr5_nHgLbNfxQAAAmU"]
[Tue Aug 18 12:57:05.598371 2026] [security2:error] [pid 66623:tid 66790] [client 68.155.154.236:51401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/jrpga.php"] [unique_id "aoSA0dO5rbWdOArH04KQeQAAASI"]
[Tue Aug 18 12:57:05.599243 2026] [security2:error] [pid 67073:tid 67220] [client 197.184.64.235:41934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0fcmepr5_nHgLbNfyAAAAiM"]
[Tue Aug 18 12:57:05.599366 2026] [security2:error] [pid 67073:tid 67220] [client 197.184.64.235:41934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0fcmepr5_nHgLbNfyAAAAiM"]
[Tue Aug 18 12:57:05.707239 2026] [security2:error] [pid 67073:tid 67264] [client 52.173.121.69:16458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/first.php"] [unique_id "aoSA0fcmepr5_nHgLbNfygAAAk8"]
[Tue Aug 18 12:57:05.711103 2026] [security2:error] [pid 67073:tid 67244] [client 213.35.127.232:49269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA0fcmepr5_nHgLbNfywAAAjs"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:05.774416 2026] [security2:error] [pid 67073:tid 67317] [client 20.65.69.59:40519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/xinfo.php"] [unique_id "aoSA0fcmepr5_nHgLbNfzQAAAoQ"]
[Tue Aug 18 12:57:05.780614 2026] [security2:error] [pid 67073:tid 67230] [client 158.158.34.183:28870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/sf.php"] [unique_id "aoSA0fcmepr5_nHgLbNfzgAAAi0"]
[Tue Aug 18 12:57:05.790153 2026] [security2:error] [pid 66623:tid 66834] [client 68.155.155.199:13317] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-admin"] [unique_id "aoSA0dO5rbWdOArH04KQnwAAAU4"]
[Tue Aug 18 12:57:05.821975 2026] [security2:error] [pid 67073:tid 67261] [client 40.74.65.169:11209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-content/index.php"] [unique_id "aoSA0fcmepr5_nHgLbNfzwAAAkw"]
[Tue Aug 18 12:57:05.840591 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:05.841055 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:05.920132 2026] [security2:error] [pid 66623:tid 66885] [client 5.161.73.160:55124] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ealoggroup.com.br"] [uri "/index.php"] [unique_id "aoSAz9O5rbWdOArH04KP3wAAAYE"], referer: https://ealoggroup.com.br/
[Tue Aug 18 12:57:05.960552 2026] [security2:error] [pid 67073:tid 67324] [client 172.182.200.96:14103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/Cachex.php"] [unique_id "aoSA0fcmepr5_nHgLbNf1gAAAos"]
[Tue Aug 18 12:57:06.093789 2026] [security2:error] [pid 67073:tid 67259] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/class.php"] [unique_id "aoSA0vcmepr5_nHgLbNf3QAAAko"]
[Tue Aug 18 12:57:06.105457 2026] [security2:error] [pid 67073:tid 67272] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/flower.php"] [unique_id "aoSA0vcmepr5_nHgLbNf3wAAAlc"]
[Tue Aug 18 12:57:06.117466 2026] [security2:error] [pid 67073:tid 67235] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/motu.php"] [unique_id "aoSA0vcmepr5_nHgLbNf4QAAAjI"]
[Tue Aug 18 12:57:06.122514 2026] [security2:error] [pid 67073:tid 67237] [client 20.52.168.85:8007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/sim.php"] [unique_id "aoSA0vcmepr5_nHgLbNf4gAAAjQ"]
[Tue Aug 18 12:57:06.129520 2026] [security2:error] [pid 67073:tid 67329] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/404.php"] [unique_id "aoSA0vcmepr5_nHgLbNf4wAAApA"]
[Tue Aug 18 12:57:06.140673 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:06.140947 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:06.141287 2026] [security2:error] [pid 67073:tid 67315] [client 68.155.154.236:50411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSA0vcmepr5_nHgLbNf5QAAAoI"]
[Tue Aug 18 12:57:06.179495 2026] [security2:error] [pid 66623:tid 66880] [client 132.196.30.78:21922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/ms-edit.php"] [unique_id "aoSA0tO5rbWdOArH04KQuAAAAXw"]
[Tue Aug 18 12:57:06.216901 2026] [security2:error] [pid 67073:tid 67248] [client 20.206.73.37:11961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/coffexium.php"] [unique_id "aoSA0vcmepr5_nHgLbNf5gAAAj8"]
[Tue Aug 18 12:57:06.304264 2026] [security2:error] [pid 67073:tid 67280] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/lite.php"] [unique_id "aoSA0vcmepr5_nHgLbNf6AAAAl8"]
[Tue Aug 18 12:57:06.316340 2026] [security2:error] [pid 67073:tid 67266] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/lock360.php"] [unique_id "aoSA0vcmepr5_nHgLbNf6QAAAlE"]
[Tue Aug 18 12:57:06.328794 2026] [security2:error] [pid 67073:tid 67233] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSA0vcmepr5_nHgLbNf6wAAAjA"]
[Tue Aug 18 12:57:06.342748 2026] [security2:error] [pid 67073:tid 67330] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSA0vcmepr5_nHgLbNf7AAAApE"]
[Tue Aug 18 12:57:06.347971 2026] [security2:error] [pid 66623:tid 66893] [client 68.155.155.199:9405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp.php"] [unique_id "aoSA0tO5rbWdOArH04KQvAAAAYk"]
[Tue Aug 18 12:57:06.354440 2026] [security2:error] [pid 66623:tid 66843] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/.alf.php"] [unique_id "aoSA0tO5rbWdOArH04KQvwAAAVc"]
[Tue Aug 18 12:57:06.366816 2026] [security2:error] [pid 67073:tid 67331] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/.trash7206/index.php"] [unique_id "aoSA0vcmepr5_nHgLbNf7wAAApI"]
[Tue Aug 18 12:57:06.372529 2026] [security2:error] [pid 67073:tid 67216] [client 192.141.172.134:62891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0vcmepr5_nHgLbNf8AAAAh8"]
[Tue Aug 18 12:57:06.372649 2026] [security2:error] [pid 67073:tid 67216] [client 192.141.172.134:62891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0vcmepr5_nHgLbNf8AAAAh8"]
[Tue Aug 18 12:57:06.394554 2026] [security2:error] [pid 67073:tid 67332] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSA0vcmepr5_nHgLbNf8gAAApM"]
[Tue Aug 18 12:57:06.403675 2026] [security2:error] [pid 67073:tid 67320] [client 20.100.169.31:13273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/min.php"] [unique_id "aoSA0vcmepr5_nHgLbNf8wAAAoc"]
[Tue Aug 18 12:57:06.406744 2026] [security2:error] [pid 67073:tid 67206] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSA0vcmepr5_nHgLbNf9AAAAhU"]
[Tue Aug 18 12:57:06.419019 2026] [security2:error] [pid 67073:tid 67210] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSA0vcmepr5_nHgLbNf9QAAAhk"]
[Tue Aug 18 12:57:06.432881 2026] [security2:error] [pid 67073:tid 67257] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSA0vcmepr5_nHgLbNf9gAAAkg"]
[Tue Aug 18 12:57:06.444303 2026] [security2:error] [pid 67073:tid 67293] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/xmr.php"] [unique_id "aoSA0vcmepr5_nHgLbNf9wAAAmw"]
[Tue Aug 18 12:57:06.456335 2026] [security2:error] [pid 67073:tid 67213] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/about.php"] [unique_id "aoSA0vcmepr5_nHgLbNf-AAAAhw"]
[Tue Aug 18 12:57:06.467310 2026] [security2:error] [pid 66623:tid 66876] [client 20.65.69.59:39217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/sym.php"] [unique_id "aoSA0tO5rbWdOArH04KQwgAAAXg"]
[Tue Aug 18 12:57:06.541922 2026] [security2:error] [pid 66623:tid 66850] [client 40.74.65.169:26712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/admin.php"] [unique_id "aoSA0tO5rbWdOArH04KQyAAAAV4"]
[Tue Aug 18 12:57:06.557965 2026] [security2:error] [pid 66623:tid 66797] [client 20.215.241.237:45963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/f35.php"] [unique_id "aoSA0tO5rbWdOArH04KQygAAASk"]
[Tue Aug 18 12:57:06.632777 2026] [security2:error] [pid 66623:tid 66807] [client 74.248.136.165:55289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/tax.php"] [unique_id "aoSA0tO5rbWdOArH04KQzgAAATM"]
[Tue Aug 18 12:57:06.718416 2026] [security2:error] [pid 66623:tid 66786] [client 172.202.39.151:50201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSA0tO5rbWdOArH04KQ0QAAAR4"]
[Tue Aug 18 12:57:06.721880 2026] [security2:error] [pid 66623:tid 66821] [client 20.52.168.85:7869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/y.php"] [unique_id "aoSA0tO5rbWdOArH04KQ0gAAAUE"]
[Tue Aug 18 12:57:06.730241 2026] [security2:error] [pid 67073:tid 67270] [client 132.196.30.78:21897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/a7.php"] [unique_id "aoSA0vcmepr5_nHgLbNf_AAAAlU"]
[Tue Aug 18 12:57:06.739627 2026] [security2:error] [pid 67073:tid 67286] [client 104.209.144.33:20458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSA0vcmepr5_nHgLbNf_gAAAmU"]
[Tue Aug 18 12:57:06.742921 2026] [authz_core:error] [pid 67073:tid 67076] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:06.743170 2026] [authz_core:error] [pid 67073:tid 67076] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:06.745645 2026] [security2:error] [pid 67073:tid 67231] [client 213.35.127.232:49473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSA0vcmepr5_nHgLbNf_wAAAi4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:06.763297 2026] [security2:error] [pid 67073:tid 67226] [client 135.225.75.187:63960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/mga.php"] [unique_id "aoSA0vcmepr5_nHgLbNgAQAAAik"]
[Tue Aug 18 12:57:06.789675 2026] [security2:error] [pid 66623:tid 66870] [client 20.65.98.162:54069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/sf.php"] [unique_id "aoSA0tO5rbWdOArH04KQ0wAAAXI"]
[Tue Aug 18 12:57:06.822348 2026] [security2:error] [pid 67073:tid 67244] [client 68.155.154.236:48905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/nwwha.php"] [unique_id "aoSA0vcmepr5_nHgLbNgAwAAAjs"]
[Tue Aug 18 12:57:06.925144 2026] [security2:error] [pid 67073:tid 67328] [client 158.158.74.177:16531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/txets.php"] [unique_id "aoSA0vcmepr5_nHgLbNgBQAAAo8"]
[Tue Aug 18 12:57:07.048777 2026] [authz_core:error] [pid 67073:tid 67088] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:07.049040 2026] [authz_core:error] [pid 67073:tid 67088] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:07.221324 2026] [security2:error] [pid 67073:tid 67292] [client 103.184.169.37:42074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0_cmepr5_nHgLbNgEAAAAms"]
[Tue Aug 18 12:57:07.221440 2026] [security2:error] [pid 67073:tid 67292] [client 103.184.169.37:42074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0_cmepr5_nHgLbNgEAAAAms"]
[Tue Aug 18 12:57:07.253062 2026] [security2:error] [pid 67073:tid 67274] [client 40.74.65.169:44781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/file52.php"] [unique_id "aoSA0_cmepr5_nHgLbNgEgAAAlk"]
[Tue Aug 18 12:57:07.324868 2026] [security2:error] [pid 66623:tid 66774] [client 20.52.168.85:7765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/xleet.php"] [unique_id "aoSA09O5rbWdOArH04KQ3gAAARI"]
[Tue Aug 18 12:57:07.350051 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:07.350481 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:07.366703 2026] [security2:error] [pid 67073:tid 67235] [client 20.226.56.190:28228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ri.php"] [unique_id "aoSA0_cmepr5_nHgLbNgIgAAAjI"]
[Tue Aug 18 12:57:07.442231 2026] [security2:error] [pid 67073:tid 67237] [client 68.155.155.199:11344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/file2.php"] [unique_id "aoSA0_cmepr5_nHgLbNgJAAAAjQ"]
[Tue Aug 18 12:57:07.467783 2026] [security2:error] [pid 67073:tid 67302] [client 103.120.71.157:11443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0_cmepr5_nHgLbNgJQAAAnU"]
[Tue Aug 18 12:57:07.467901 2026] [security2:error] [pid 67073:tid 67302] [client 103.120.71.157:11443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0_cmepr5_nHgLbNgJQAAAnU"]
[Tue Aug 18 12:57:07.487069 2026] [security2:error] [pid 67073:tid 67306] [client 20.215.241.237:45274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-load.php"] [unique_id "aoSA0_cmepr5_nHgLbNgJwAAAnk"]
[Tue Aug 18 12:57:07.581938 2026] [security2:error] [pid 67073:tid 67167] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0_cmepr5_nHgLbNgKgACXls"]
[Tue Aug 18 12:57:07.582075 2026] [security2:error] [pid 67073:tid 67279] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0_cmepr5_nHgLbNgKgACXls"]
[Tue Aug 18 12:57:07.597470 2026] [security2:error] [pid 67073:tid 67248] [client 104.209.144.33:29843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSA0_cmepr5_nHgLbNgLAAAAj8"]
[Tue Aug 18 12:57:07.639240 2026] [security2:error] [pid 66623:tid 66857] [client 135.225.75.187:63955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/fs.php"] [unique_id "aoSA09O5rbWdOArH04KQ6gAAAWU"]
[Tue Aug 18 12:57:07.640884 2026] [security2:error] [pid 67073:tid 67263] [client 20.118.172.148:62439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/php8.php"] [unique_id "aoSA0_cmepr5_nHgLbNgLQAAAk4"]
[Tue Aug 18 12:57:07.642433 2026] [security2:error] [pid 67073:tid 67305] [client 158.158.34.183:39496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/file56.php"] [unique_id "aoSA0_cmepr5_nHgLbNgMQAAAng"]
[Tue Aug 18 12:57:07.648695 2026] [authz_core:error] [pid 67073:tid 67127] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:07.648974 2026] [authz_core:error] [pid 67073:tid 67127] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:07.691480 2026] [security2:error] [pid 67073:tid 67266] [client 68.155.154.236:40303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/opsqt.php"] [unique_id "aoSA0_cmepr5_nHgLbNgMgAAAlE"]
[Tue Aug 18 12:57:07.716146 2026] [security2:error] [pid 67073:tid 67214] [client 74.248.18.37:8032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/g.php"] [unique_id "aoSA0_cmepr5_nHgLbNgMwAAAh0"]
[Tue Aug 18 12:57:07.757623 2026] [security2:error] [pid 67073:tid 67224] [client 213.35.127.232:49679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSA0_cmepr5_nHgLbNgNAAAAic"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:07.842630 2026] [security2:error] [pid 67073:tid 67216] [client 20.100.169.31:40535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/php8.php"] [unique_id "aoSA0_cmepr5_nHgLbNgNgAAAh8"]
[Tue Aug 18 12:57:07.898481 2026] [security2:error] [pid 66623:tid 66832] [client 86.120.159.145:56482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA09O5rbWdOArH04KQ7AAAAUw"]
[Tue Aug 18 12:57:07.898642 2026] [security2:error] [pid 66623:tid 66832] [client 86.120.159.145:56482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA09O5rbWdOArH04KQ7AAAAUw"]
[Tue Aug 18 12:57:07.901945 2026] [security2:error] [pid 66623:tid 66838] [client 20.65.69.59:40514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/ye.php"] [unique_id "aoSA09O5rbWdOArH04KQ8AAAAVI"]
[Tue Aug 18 12:57:07.927261 2026] [security2:error] [pid 66623:tid 66868] [client 20.52.168.85:7755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/1index.php"] [unique_id "aoSA09O5rbWdOArH04KQ9AAAAXA"]
[Tue Aug 18 12:57:08.009955 2026] [security2:error] [pid 66623:tid 66824] [client 40.74.65.169:43150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/geck.php"] [unique_id "aoSA1NO5rbWdOArH04KQ9wAAAUQ"]
[Tue Aug 18 12:57:08.051688 2026] [security2:error] [pid 67073:tid 67257] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/admin.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgOQAAAkg"]
[Tue Aug 18 12:57:08.073508 2026] [security2:error] [pid 66623:tid 66796] [client 20.118.172.148:62409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/info.php"] [unique_id "aoSA1NO5rbWdOArH04KQ-QAAASg"]
[Tue Aug 18 12:57:08.135576 2026] [security2:error] [pid 67073:tid 67247] [client 20.250.13.23:47026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/bless.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgOwAAAj4"]
[Tue Aug 18 12:57:08.190362 2026] [security2:error] [pid 66623:tid 66795] [client 68.155.155.199:9636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/images/class-config.php"] [unique_id "aoSA1NO5rbWdOArH04KQ_QAAASc"]
[Tue Aug 18 12:57:08.205965 2026] [security2:error] [pid 67073:tid 67285] [client 158.158.74.177:26146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/u.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgPAAAAmQ"]
[Tue Aug 18 12:57:08.222709 2026] [security2:error] [pid 67073:tid 67300] [client 79.127.164.8:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/my.sql"] [unique_id "aoSA1Pcmepr5_nHgLbNgPQAAAnM"], referer: https://medihub.com.br/my.sql
[Tue Aug 18 12:57:08.250932 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:08.251232 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:08.354121 2026] [security2:error] [pid 66623:tid 66826] [client 74.248.18.37:62118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/gecko.php"] [unique_id "aoSA1NO5rbWdOArH04KRAAAAAUY"]
[Tue Aug 18 12:57:08.408206 2026] [security2:error] [pid 66623:tid 66847] [client 20.118.172.148:62431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/chosen.php"] [unique_id "aoSA1NO5rbWdOArH04KRAwAAAVs"]
[Tue Aug 18 12:57:08.430594 2026] [security2:error] [pid 67073:tid 67319] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/adminfuns.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgQAAAAoY"]
[Tue Aug 18 12:57:08.447245 2026] [security2:error] [pid 67073:tid 67250] [client 138.36.100.162:42980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgQQAAAkE"]
[Tue Aug 18 12:57:08.451153 2026] [security2:error] [pid 67073:tid 67242] [client 104.209.144.33:21431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/update/wpupex.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgQgAAAjk"]
[Tue Aug 18 12:57:08.454954 2026] [fcgid:warn] [pid 66623:tid 66829] (70014)End of file found: [client 66.132.195.33:2782] mod_fcgid: can't get data from http client
[Tue Aug 18 12:57:08.460462 2026] [security2:error] [pid 67073:tid 67238] [client 52.173.121.69:16476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgQwAAAjU"]
[Tue Aug 18 12:57:08.470971 2026] [security2:error] [pid 66623:tid 66882] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/as.php"] [unique_id "aoSA1NO5rbWdOArH04KRCgAAAX4"]
[Tue Aug 18 12:57:08.484256 2026] [security2:error] [pid 67073:tid 67223] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/bolt.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgRgAAAiY"]
[Tue Aug 18 12:57:08.505732 2026] [cgid:error] [pid 67073:tid 67258] [client 20.197.195.76:0] AH01265: stderr from /home3/cp36imobibrasil/public_html/cgi-bin/: attempt to invoke directory as script
[Tue Aug 18 12:57:08.517567 2026] [security2:error] [pid 67073:tid 67284] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/class-t.api.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgTAAAAmM"]
[Tue Aug 18 12:57:08.531369 2026] [security2:error] [pid 67073:tid 67256] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/edit.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgTgAAAkc"]
[Tue Aug 18 12:57:08.532927 2026] [security2:error] [pid 66623:tid 66834] [client 20.52.168.85:8062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/admin.php1"] [unique_id "aoSA1NO5rbWdOArH04KRDAAAAU4"]
[Tue Aug 18 12:57:08.543656 2026] [security2:error] [pid 67073:tid 67286] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/ff1.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgTwAAAmU"]
[Tue Aug 18 12:57:08.545234 2026] [security2:error] [pid 66623:tid 66664] [remote 89.185.225.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.225.185.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fabispinazolapilates.com.br"] [uri "/wp-login.php"] [unique_id "aoSA1NO5rbWdOArH04KRDQABdBs"]
[Tue Aug 18 12:57:08.552223 2026] [authz_core:error] [pid 67073:tid 67133] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:08.552524 2026] [authz_core:error] [pid 67073:tid 67133] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:08.579820 2026] [security2:error] [pid 66623:tid 66881] [client 158.158.34.183:45721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/2.php"] [unique_id "aoSA1NO5rbWdOArH04KRDwAAAX0"]
[Tue Aug 18 12:57:08.656599 2026] [security2:error] [pid 66623:tid 66789] [client 135.225.75.187:58997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-tem.php"] [unique_id "aoSA1NO5rbWdOArH04KREwAAASE"]
[Tue Aug 18 12:57:08.704072 2026] [security2:error] [pid 67073:tid 67264] [client 40.74.65.169:27717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/biufile.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgXQAAAk8"]
[Tue Aug 18 12:57:08.730850 2026] [security2:error] [pid 67073:tid 67276] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/fff.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgXgAAAls"]
[Tue Aug 18 12:57:08.766690 2026] [security2:error] [pid 66623:tid 66769] [client 20.118.172.148:62088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/simple.php"] [unique_id "aoSA1NO5rbWdOArH04KRFgAAAQ0"]
[Tue Aug 18 12:57:08.770841 2026] [security2:error] [pid 66623:tid 66876] [client 68.155.155.199:5043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/alfa.php"] [unique_id "aoSA1NO5rbWdOArH04KRFwAAAXg"]
[Tue Aug 18 12:57:08.775775 2026] [security2:error] [pid 66623:tid 66825] [client 213.35.127.232:49891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSA1NO5rbWdOArH04KRGAAAAUU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:08.804086 2026] [security2:error] [pid 67073:tid 67232] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/inputs.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgXwAAAi8"]
[Tue Aug 18 12:57:08.822336 2026] [security2:error] [pid 67073:tid 67312] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgYAAAAn8"]
[Tue Aug 18 12:57:08.825626 2026] [security2:error] [pid 67073:tid 67250] [client 138.36.100.162:42980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgQQAAAkE"]
[Tue Aug 18 12:57:08.826143 2026] [security2:error] [pid 67073:tid 67209] [client 68.155.154.236:7620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/jvcpa.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgYQAAAhg"]
[Tue Aug 18 12:57:08.851555 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:08.851842 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:08.852147 2026] [security2:error] [pid 67073:tid 67230] [client 172.202.39.151:52035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-login.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgZQAAAi0"]
[Tue Aug 18 12:57:08.893618 2026] [security2:error] [pid 67073:tid 67260] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/lite.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgZgAAAks"]
[Tue Aug 18 12:57:09.000240 2026] [security2:error] [pid 67073:tid 67251] [client 172.202.39.151:43210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgZwAAAkI"]
[Tue Aug 18 12:57:09.038347 2026] [security2:error] [pid 66623:tid 66849] [client 74.248.18.37:26554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/gettest.php"] [unique_id "aoSA1dO5rbWdOArH04KRIwAAAV0"]
[Tue Aug 18 12:57:09.084839 2026] [security2:error] [pid 67073:tid 67322] [client 68.155.154.236:16250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSA1fcmepr5_nHgLbNgaQAAAok"]
[Tue Aug 18 12:57:09.135497 2026] [security2:error] [pid 66623:tid 66821] [client 20.52.168.85:7720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/M1.php"] [unique_id "aoSA1dO5rbWdOArH04KRJgAAAUE"]
[Tue Aug 18 12:57:09.135524 2026] [security2:error] [pid 67073:tid 67317] [client 20.118.172.148:54897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSA1fcmepr5_nHgLbNgagAAAoQ"]
[Tue Aug 18 12:57:09.151716 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:09.151982 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:09.153074 2026] [security2:error] [pid 66623:tid 66778] [client 5.31.227.224:30417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1dO5rbWdOArH04KRKAAAARY"]
[Tue Aug 18 12:57:09.153160 2026] [security2:error] [pid 66623:tid 66778] [client 5.31.227.224:30417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1dO5rbWdOArH04KRKAAAARY"]
[Tue Aug 18 12:57:09.210755 2026] [security2:error] [pid 66623:tid 66813] [client 20.215.241.237:25146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSA1dO5rbWdOArH04KRKwAAATk"]
[Tue Aug 18 12:57:09.226095 2026] [security2:error] [pid 66623:tid 66866] [client 20.100.169.31:27744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSA1dO5rbWdOArH04KRLAAAAW4"]
[Tue Aug 18 12:57:09.228081 2026] [security2:error] [pid 66623:tid 66866] [client 68.155.155.199:6598] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/1.php"] [unique_id "aoSA1dO5rbWdOArH04KRLQAAAW4"]
[Tue Aug 18 12:57:09.228140 2026] [security2:error] [pid 66623:tid 66866] [client 68.155.155.199:6598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/1.php"] [unique_id "aoSA1dO5rbWdOArH04KRLQAAAW4"]
[Tue Aug 18 12:57:09.302614 2026] [security2:error] [pid 67073:tid 67229] [client 132.196.30.78:18773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/manager.php"] [unique_id "aoSA1fcmepr5_nHgLbNgcQAAAiw"]
[Tue Aug 18 12:57:09.355699 2026] [security2:error] [pid 67073:tid 67308] [client 52.173.121.69:24812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSA1fcmepr5_nHgLbNgdQAAAns"]
[Tue Aug 18 12:57:09.419323 2026] [security2:error] [pid 66623:tid 66874] [client 40.74.65.169:26718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/dejavu.php"] [unique_id "aoSA1dO5rbWdOArH04KRMQAAAXY"]
[Tue Aug 18 12:57:09.453980 2026] [authz_core:error] [pid 67073:tid 67191] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:09.454230 2026] [authz_core:error] [pid 67073:tid 67191] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:09.467907 2026] [security2:error] [pid 67073:tid 67290] [client 20.118.172.148:54855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/av.php"] [unique_id "aoSA1fcmepr5_nHgLbNgeQAAAmk"]
[Tue Aug 18 12:57:09.569743 2026] [security2:error] [pid 67073:tid 67315] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/ms-edit.php"] [unique_id "aoSA1fcmepr5_nHgLbNgewAAAoI"]
[Tue Aug 18 12:57:09.586659 2026] [security2:error] [pid 67073:tid 67295] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/rip.php"] [unique_id "aoSA1fcmepr5_nHgLbNgfQAAAm4"]
[Tue Aug 18 12:57:09.598870 2026] [security2:error] [pid 67073:tid 67252] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/update/da222.php"] [unique_id "aoSA1fcmepr5_nHgLbNgfgAAAkM"]
[Tue Aug 18 12:57:09.608162 2026] [security2:error] [pid 66623:tid 66811] [client 157.20.138.62:63555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1dO5rbWdOArH04KRNAAAATc"]
[Tue Aug 18 12:57:09.608264 2026] [security2:error] [pid 66623:tid 66811] [client 157.20.138.62:63555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1dO5rbWdOArH04KRNAAAATc"]
[Tue Aug 18 12:57:09.611781 2026] [security2:error] [pid 67073:tid 67214] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/upload.php"] [unique_id "aoSA1fcmepr5_nHgLbNgfwAAAh0"]
[Tue Aug 18 12:57:09.658302 2026] [security2:error] [pid 67073:tid 67294] [client 158.158.74.177:2635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/ultra.php"] [unique_id "aoSA1fcmepr5_nHgLbNggQAAAm0"]
[Tue Aug 18 12:57:09.690901 2026] [security2:error] [pid 67073:tid 67248] [client 74.248.18.37:62116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/goods.php"] [unique_id "aoSA1fcmepr5_nHgLbNgggAAAj8"]
[Tue Aug 18 12:57:09.698775 2026] [security2:error] [pid 67073:tid 67241] [client 172.202.39.151:65265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teste.advocaciacriminalgo.com.br"] [uri "/wp-login.php"] [unique_id "aoSA1fcmepr5_nHgLbNggwAAAjg"]
[Tue Aug 18 12:57:09.713548 2026] [security2:error] [pid 67073:tid 67207] [client 68.155.154.236:7930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSA1fcmepr5_nHgLbNghAAAAhY"]
[Tue Aug 18 12:57:09.733357 2026] [security2:error] [pid 66623:tid 66863] [client 37.40.227.74:56756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1dO5rbWdOArH04KRNgAAAWs"]
[Tue Aug 18 12:57:09.733472 2026] [security2:error] [pid 66623:tid 66863] [client 37.40.227.74:56756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1dO5rbWdOArH04KRNgAAAWs"]
[Tue Aug 18 12:57:09.740872 2026] [security2:error] [pid 66623:tid 66784] [client 20.52.168.85:7758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/ds.php"] [unique_id "aoSA1dO5rbWdOArH04KRNwAAARw"]
[Tue Aug 18 12:57:09.782495 2026] [security2:error] [pid 67073:tid 67288] [client 52.173.121.69:17934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSA1fcmepr5_nHgLbNghwAAAmc"]
[Tue Aug 18 12:57:09.788822 2026] [security2:error] [pid 67073:tid 67272] [client 213.35.127.232:50109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA1fcmepr5_nHgLbNgiAAAAlc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:09.790993 2026] [security2:error] [pid 67073:tid 67268] [client 135.225.75.187:19225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/sadd.php"] [unique_id "aoSA1fcmepr5_nHgLbNgiQAAAlM"]
[Tue Aug 18 12:57:09.820902 2026] [security2:error] [pid 67073:tid 67269] [client 68.155.156.252:6242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSA1fcmepr5_nHgLbNgiwAAAlQ"]
[Tue Aug 18 12:57:09.842002 2026] [security2:error] [pid 67073:tid 67326] [client 172.202.39.151:50180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSA1fcmepr5_nHgLbNgjAAAAo0"]
[Tue Aug 18 12:57:09.854989 2026] [security2:error] [pid 67073:tid 67249] [client 74.248.136.165:61369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/X7x.php"] [unique_id "aoSA1fcmepr5_nHgLbNgkAAAAkA"]
[Tue Aug 18 12:57:09.929895 2026] [security2:error] [pid 66623:tid 66823] [client 149.34.210.141:56357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSA1dO5rbWdOArH04KROAAAAUM"]
[Tue Aug 18 12:57:10.017553 2026] [security2:error] [pid 67073:tid 67273] [client 20.118.172.148:62095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp.php"] [unique_id "aoSA1vcmepr5_nHgLbNgmAAAAlg"]
[Tue Aug 18 12:57:10.037384 2026] [security2:error] [pid 66623:tid 66770] [client 104.209.144.33:20422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-admin/install.php"] [unique_id "aoSA1tO5rbWdOArH04KROgAAAQ4"]
[Tue Aug 18 12:57:10.046421 2026] [security2:error] [pid 67073:tid 67284] [client 20.226.56.190:28263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/tp.php"] [unique_id "aoSA1vcmepr5_nHgLbNgmQAAAmM"]
[Tue Aug 18 12:57:10.055906 2026] [authz_core:error] [pid 67073:tid 67149] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:10.056151 2026] [authz_core:error] [pid 67073:tid 67149] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:10.070438 2026] [security2:error] [pid 67073:tid 67323] [client 20.215.241.237:43261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/aaa.php"] [unique_id "aoSA1vcmepr5_nHgLbNgmwAAAoo"]
[Tue Aug 18 12:57:10.095313 2026] [security2:error] [pid 67073:tid 67080] [remote 162.241.152.27:46970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ancavisi.com.br"] [uri "/wp-login.php"] [unique_id "aoSA1vcmepr5_nHgLbNgnQACRgQ"]
[Tue Aug 18 12:57:10.103597 2026] [security2:error] [pid 67073:tid 67286] [client 172.182.200.96:14133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSA1vcmepr5_nHgLbNgngAAAmU"]
[Tue Aug 18 12:57:10.105751 2026] [security2:error] [pid 66623:tid 66820] [client 40.74.65.169:26703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/aaf.php"] [unique_id "aoSA1tO5rbWdOArH04KROwAAAUA"]
[Tue Aug 18 12:57:10.138675 2026] [security2:error] [pid 67073:tid 67228] [client 68.155.155.199:7384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/222.php"] [unique_id "aoSA1vcmepr5_nHgLbNgoAAAAis"]
[Tue Aug 18 12:57:10.196890 2026] [security2:error] [pid 66623:tid 66823] [client 149.34.210.141:56357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSA1dO5rbWdOArH04KROAAAAUM"]
[Tue Aug 18 12:57:10.214614 2026] [security2:error] [pid 66623:tid 66864] [client 52.173.121.69:24992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/blog/byp.php"] [unique_id "aoSA1tO5rbWdOArH04KRPQAAAWw"]
[Tue Aug 18 12:57:10.239087 2026] [security2:error] [pid 66623:tid 66878] [client 172.202.39.151:50215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSA1tO5rbWdOArH04KRPgAAAXo"]
[Tue Aug 18 12:57:10.357173 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:10.357450 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:10.370800 2026] [security2:error] [pid 66623:tid 66796] [client 74.248.18.37:62109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/gulu.php"] [unique_id "aoSA1tO5rbWdOArH04KRQQAAASg"]
[Tue Aug 18 12:57:10.475091 2026] [security2:error] [pid 67073:tid 67264] [client 158.158.74.177:2636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/un.php"] [unique_id "aoSA1vcmepr5_nHgLbNgsQAAAk8"]
[Tue Aug 18 12:57:10.483456 2026] [security2:error] [pid 67073:tid 67215] [client 20.118.172.148:62091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/file2.php"] [unique_id "aoSA1vcmepr5_nHgLbNgsgAAAh4"]
[Tue Aug 18 12:57:10.548757 2026] [security2:error] [pid 66623:tid 66800] [client 20.250.13.23:21849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/sagax1.php"] [unique_id "aoSA1tO5rbWdOArH04KRQgAAASw"]
[Tue Aug 18 12:57:10.566571 2026] [security2:error] [pid 67073:tid 67281] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wk/index.php"] [unique_id "aoSA1vcmepr5_nHgLbNgtQAAAmA"]
[Tue Aug 18 12:57:10.579879 2026] [security2:error] [pid 67073:tid 67236] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-act.php"] [unique_id "aoSA1vcmepr5_nHgLbNgtgAAAjM"]
[Tue Aug 18 12:57:10.658216 2026] [authz_core:error] [pid 67073:tid 67092] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:10.658482 2026] [authz_core:error] [pid 67073:tid 67092] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:10.811007 2026] [security2:error] [pid 67073:tid 67317] [client 213.35.127.232:50354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA1vcmepr5_nHgLbNgxQAAAoQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:10.816809 2026] [security2:error] [pid 67073:tid 67252] [client 40.74.65.169:27815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/h02ugyh.php"] [unique_id "aoSA1vcmepr5_nHgLbNgxgAAAkM"]
[Tue Aug 18 12:57:10.855321 2026] [security2:error] [pid 67073:tid 67321] [client 20.118.172.148:62418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/images/class-config.php"] [unique_id "aoSA1vcmepr5_nHgLbNgxwAAAog"]
[Tue Aug 18 12:57:10.939955 2026] [security2:error] [pid 67073:tid 67248] [client 20.215.241.237:25091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/gecko.php"] [unique_id "aoSA1vcmepr5_nHgLbNgyQAAAj8"]
[Tue Aug 18 12:57:10.956876 2026] [security2:error] [pid 67073:tid 67282] [client 178.153.171.161:4196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1vcmepr5_nHgLbNgywAAAmE"]
[Tue Aug 18 12:57:10.957059 2026] [security2:error] [pid 67073:tid 67282] [client 178.153.171.161:4196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1vcmepr5_nHgLbNgywAAAmE"]
[Tue Aug 18 12:57:10.959267 2026] [authz_core:error] [pid 67073:tid 67084] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:10.959624 2026] [authz_core:error] [pid 67073:tid 67084] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:10.963809 2026] [security2:error] [pid 66623:tid 66831] [client 68.155.155.199:8561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/asasx.php"] [unique_id "aoSA1tO5rbWdOArH04KRTwAAAUs"]
[Tue Aug 18 12:57:11.012373 2026] [security2:error] [pid 66623:tid 66798] [client 52.173.121.69:24962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSA19O5rbWdOArH04KRUAAAASo"]
[Tue Aug 18 12:57:11.016286 2026] [security2:error] [pid 67073:tid 67266] [client 74.248.18.37:8034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/h.php"] [unique_id "aoSA1_cmepr5_nHgLbNgzQAAAlE"]
[Tue Aug 18 12:57:11.064978 2026] [security2:error] [pid 66623:tid 66841] [client 104.209.144.33:17227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSA19O5rbWdOArH04KRUwAAAVU"]
[Tue Aug 18 12:57:11.086755 2026] [security2:error] [pid 66623:tid 66769] [client 68.155.156.252:29031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/yj09.php"] [unique_id "aoSA19O5rbWdOArH04KRVQAAAQ0"]
[Tue Aug 18 12:57:11.102911 2026] [security2:error] [pid 67073:tid 67207] [client 172.202.39.151:49629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/xmrlpc.php"] [unique_id "aoSA1_cmepr5_nHgLbNg0QAAAhY"]
[Tue Aug 18 12:57:11.113096 2026] [security2:error] [pid 67073:tid 67216] [client 132.196.30.78:18628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/w1.php"] [unique_id "aoSA1_cmepr5_nHgLbNg0wAAAh8"]
[Tue Aug 18 12:57:11.125265 2026] [security2:error] [pid 66623:tid 66847] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1tO5rbWdOArH04KRTAABWyE"]
[Tue Aug 18 12:57:11.180646 2026] [security2:error] [pid 66623:tid 66850] [client 68.155.154.236:50409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSA19O5rbWdOArH04KRWQAAAV4"]
[Tue Aug 18 12:57:11.254542 2026] [security2:error] [pid 66623:tid 66871] [client 158.158.74.177:2976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/up.php"] [unique_id "aoSA19O5rbWdOArH04KRWgAAAXM"]
[Tue Aug 18 12:57:11.262794 2026] [security2:error] [pid 67073:tid 67214] [client 20.100.169.31:27959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/index/function.php"] [unique_id "aoSA1_cmepr5_nHgLbNg1gAAAh0"]
[Tue Aug 18 12:57:11.288160 2026] [security2:error] [pid 67073:tid 67250] [client 20.100.169.31:12591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/222.php"] [unique_id "aoSA1_cmepr5_nHgLbNg2AAAAkE"]
[Tue Aug 18 12:57:11.364124 2026] [security2:error] [pid 66623:tid 66802] [client 20.119.58.187:11291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/666.php"] [unique_id "aoSA19O5rbWdOArH04KRWwAAAS4"]
[Tue Aug 18 12:57:11.435140 2026] [security2:error] [pid 67073:tid 67265] [client 52.173.121.69:16465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSA1_cmepr5_nHgLbNg3QAAAlA"]
[Tue Aug 18 12:57:11.435597 2026] [security2:error] [pid 66623:tid 66734] [remote 194.163.162.96:49106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.162.163.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caminhosdaregiao.com.br"] [uri "/wp-login.php"] [unique_id "aoSA19O5rbWdOArH04KRXQABZmE"]
[Tue Aug 18 12:57:11.453985 2026] [security2:error] [pid 67073:tid 67223] [client 20.118.172.148:62416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/alfa.php"] [unique_id "aoSA1_cmepr5_nHgLbNg4AAAAiY"]
[Tue Aug 18 12:57:11.489424 2026] [security2:error] [pid 67073:tid 67283] [client 20.119.58.187:11316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/bgymj.php"] [unique_id "aoSA1_cmepr5_nHgLbNg4QAAAmI"]
[Tue Aug 18 12:57:11.535227 2026] [security2:error] [pid 67073:tid 67258] [client 135.225.75.187:25667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ex.php"] [unique_id "aoSA1_cmepr5_nHgLbNg4wAAAkk"]
[Tue Aug 18 12:57:11.564368 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:11.564630 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:11.571411 2026] [security2:error] [pid 67073:tid 67256] [client 40.74.65.169:30055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/155.php"] [unique_id "aoSA1_cmepr5_nHgLbNg5gAAAkc"]
[Tue Aug 18 12:57:11.592192 2026] [security2:error] [pid 67073:tid 67270] [client 20.206.73.37:59853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/dex.php"] [unique_id "aoSA1_cmepr5_nHgLbNg5wAAAlU"]
[Tue Aug 18 12:57:11.602199 2026] [security2:error] [pid 67073:tid 67286] [client 68.155.154.236:50371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSA1_cmepr5_nHgLbNg6AAAAmU"]
[Tue Aug 18 12:57:11.625863 2026] [security2:error] [pid 67073:tid 67297] [client 158.158.34.183:12106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "aoSA1_cmepr5_nHgLbNg6QAAAnA"]
[Tue Aug 18 12:57:11.661036 2026] [security2:error] [pid 66623:tid 66718] [remote 156.59.198.136:34156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "devota.com.br"] [uri "/img/about/sunset.svg"] [unique_id "aoSA19O5rbWdOArH04KRYAABFlE"], referer: https://devota.com.br/
[Tue Aug 18 12:57:11.669442 2026] [security2:error] [pid 67073:tid 67262] [client 74.248.18.37:62115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/hello.php"] [unique_id "aoSA1_cmepr5_nHgLbNg7AAAAk0"]
[Tue Aug 18 12:57:11.674607 2026] [security2:error] [pid 66623:tid 66867] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSA19O5rbWdOArH04KRYgAAAW8"]
[Tue Aug 18 12:57:11.827207 2026] [security2:error] [pid 66623:tid 66849] [client 213.35.127.232:50601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSA19O5rbWdOArH04KRZAAAAV0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:11.843534 2026] [security2:error] [pid 67073:tid 67232] [client 20.119.58.187:11279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/bthil.php"] [unique_id "aoSA1_cmepr5_nHgLbNg9wAAAi8"]
[Tue Aug 18 12:57:11.846922 2026] [security2:error] [pid 66623:tid 66833] [client 20.215.241.237:25126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/xiugai.php"] [unique_id "aoSA19O5rbWdOArH04KRZQAAAU0"]
[Tue Aug 18 12:57:11.862506 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:11.862797 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:11.865053 2026] [security2:error] [pid 67073:tid 67318] [client 20.250.13.23:39679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wpc.php"] [unique_id "aoSA1_cmepr5_nHgLbNg-QAAAoU"]
[Tue Aug 18 12:57:11.881818 2026] [security2:error] [pid 67073:tid 67205] [client 132.196.30.78:26266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-login.php"] [unique_id "aoSA1_cmepr5_nHgLbNg-gAAAhQ"]
[Tue Aug 18 12:57:11.926284 2026] [security2:error] [pid 67073:tid 67320] [client 95.108.213.173:50864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.213.108.95.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentaclehost.com.br"] [uri "/index.php"] [unique_id "aoSA1_cmepr5_nHgLbNg8AAAAoc"]
[Tue Aug 18 12:57:11.932911 2026] [security2:error] [pid 66623:tid 66807] [client 85.154.68.202:53188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSA19O5rbWdOArH04KRaQAAATM"]
[Tue Aug 18 12:57:11.933036 2026] [security2:error] [pid 66623:tid 66807] [client 85.154.68.202:53188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSA19O5rbWdOArH04KRaQAAATM"]
[Tue Aug 18 12:57:11.977156 2026] [authz_core:error] [pid 66623:tid 66754] [remote 57.141.22.115:38394] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:11.977637 2026] [authz_core:error] [pid 66623:tid 66754] [remote 57.141.22.115:38394] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:12.007208 2026] [security2:error] [pid 67073:tid 67281] [client 20.65.98.162:25818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/xx.php"] [unique_id "aoSA2Pcmepr5_nHgLbNg_gAAAmA"]
[Tue Aug 18 12:57:12.026265 2026] [security2:error] [pid 67073:tid 67217] [client 52.173.121.69:24810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/images/security.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhAAAAAiA"]
[Tue Aug 18 12:57:12.127770 2026] [security2:error] [pid 67073:tid 67237] [client 20.118.172.148:62457] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.bluelord.com.br"] [uri "/1.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhAwAAAjQ"]
[Tue Aug 18 12:57:12.127880 2026] [security2:error] [pid 67073:tid 67237] [client 20.118.172.148:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/1.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhAwAAAjQ"]
[Tue Aug 18 12:57:12.135404 2026] [security2:error] [pid 67073:tid 67293] [client 160.120.140.123:64352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhBAAAAmw"]
[Tue Aug 18 12:57:12.135547 2026] [security2:error] [pid 67073:tid 67293] [client 160.120.140.123:64352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhBAAAAmw"]
[Tue Aug 18 12:57:12.163308 2026] [authz_core:error] [pid 67073:tid 67158] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:12.163572 2026] [authz_core:error] [pid 67073:tid 67158] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:12.196397 2026] [security2:error] [pid 67073:tid 67254] [client 20.119.58.187:11264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/xp.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhCAAAAkU"]
[Tue Aug 18 12:57:12.204559 2026] [security2:error] [pid 66623:tid 66793] [client 68.155.155.199:5081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/filemanager.php"] [unique_id "aoSA2NO5rbWdOArH04KRawAAASU"]
[Tue Aug 18 12:57:12.212284 2026] [security2:error] [pid 67073:tid 67327] [client 172.182.200.96:14204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhCQAAAo4"]
[Tue Aug 18 12:57:12.241086 2026] [security2:error] [pid 67073:tid 67308] [client 68.155.154.236:65514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhCgAAAns"]
[Tue Aug 18 12:57:12.248482 2026] [security2:error] [pid 66623:tid 66768] [client 172.202.39.151:55424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/file.php"] [unique_id "aoSA2NO5rbWdOArH04KRbAAAAQw"]
[Tue Aug 18 12:57:12.262886 2026] [security2:error] [pid 67073:tid 67226] [client 40.74.65.169:44778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/ops.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhDQAAAik"]
[Tue Aug 18 12:57:12.320636 2026] [security2:error] [pid 66623:tid 66874] [client 74.248.18.37:8018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/images/index.php"] [unique_id "aoSA2NO5rbWdOArH04KRbgAAAXY"]
[Tue Aug 18 12:57:12.406658 2026] [security2:error] [pid 67073:tid 67324] [client 20.100.169.31:16033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhEgAAAos"]
[Tue Aug 18 12:57:12.463822 2026] [authz_core:error] [pid 67073:tid 67116] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:12.464076 2026] [authz_core:error] [pid 67073:tid 67116] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:12.485891 2026] [security2:error] [pid 67073:tid 67282] [client 135.225.75.187:31402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/tax.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhFQAAAmE"]
[Tue Aug 18 12:57:12.533385 2026] [security2:error] [pid 67073:tid 67330] [client 158.158.74.177:16535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/users.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhFgAAApE"]
[Tue Aug 18 12:57:12.539555 2026] [security2:error] [pid 67073:tid 67227] [client 104.209.144.33:36534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhGAAAAio"]
[Tue Aug 18 12:57:12.548181 2026] [security2:error] [pid 67073:tid 67295] [client 20.119.58.187:11311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/reze.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhGQAAAm4"]
[Tue Aug 18 12:57:12.656211 2026] [security2:error] [pid 66623:tid 66888] [client 20.215.241.237:48028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/adminner.php"] [unique_id "aoSA2NO5rbWdOArH04KRcwAAAYQ"]
[Tue Aug 18 12:57:12.698267 2026] [security2:error] [pid 67073:tid 67269] [client 20.118.172.148:54902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/222.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhHQAAAlQ"]
[Tue Aug 18 12:57:12.726141 2026] [security2:error] [pid 66623:tid 66820] [client 68.155.156.252:19795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/scxy.php"] [unique_id "aoSA2NO5rbWdOArH04KRdgAAAUA"]
[Tue Aug 18 12:57:12.748406 2026] [security2:error] [pid 67073:tid 67278] [client 172.202.39.151:30127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/file.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhIAAAAl0"]
[Tue Aug 18 12:57:12.766017 2026] [authz_core:error] [pid 67073:tid 67101] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:12.766284 2026] [authz_core:error] [pid 67073:tid 67101] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:12.822817 2026] [security2:error] [pid 67073:tid 67266] [client 158.158.34.183:12124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhIwAAAlE"]
[Tue Aug 18 12:57:12.832064 2026] [security2:error] [pid 67073:tid 67331] [client 132.196.30.78:21890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/default.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhJAAAApI"]
[Tue Aug 18 12:57:12.843607 2026] [security2:error] [pid 67073:tid 67241] [client 213.35.127.232:50853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhJwAAAjg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:12.905342 2026] [security2:error] [pid 66623:tid 66795] [client 20.119.58.187:11327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/2026w.php"] [unique_id "aoSA2NO5rbWdOArH04KReQAAASc"]
[Tue Aug 18 12:57:12.950781 2026] [security2:error] [pid 66623:tid 66794] [client 40.74.65.169:27025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/mac.php"] [unique_id "aoSA2NO5rbWdOArH04KRewAAASY"]
[Tue Aug 18 12:57:12.963530 2026] [security2:error] [pid 67073:tid 67275] [client 68.155.154.236:45593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhKQAAAlo"]
[Tue Aug 18 12:57:13.021299 2026] [security2:error] [pid 67073:tid 67265] [client 20.226.56.190:2549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/zj.php"] [unique_id "aoSA2fcmepr5_nHgLbNhLAAAAlA"]
[Tue Aug 18 12:57:13.065359 2026] [authz_core:error] [pid 67073:tid 67162] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:13.065625 2026] [authz_core:error] [pid 67073:tid 67162] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:13.097484 2026] [security2:error] [pid 67073:tid 67300] [client 74.248.18.37:8016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/index.bak.php"] [unique_id "aoSA2fcmepr5_nHgLbNhLgAAAnM"]
[Tue Aug 18 12:57:13.144653 2026] [security2:error] [pid 66623:tid 66783] [client 68.155.155.199:6635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/themes.php"] [unique_id "aoSA2dO5rbWdOArH04KRgQAAARs"]
[Tue Aug 18 12:57:13.191033 2026] [security2:error] [pid 66623:tid 66767] [client 20.250.13.23:25718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/fone1.php"] [unique_id "aoSA2dO5rbWdOArH04KRggAAAQs"]
[Tue Aug 18 12:57:13.258034 2026] [security2:error] [pid 66623:tid 66892] [client 20.119.58.187:11456] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.telesaopedro.com.br"] [uri "/1.php"] [unique_id "aoSA2dO5rbWdOArH04KRhgAAAYg"]
[Tue Aug 18 12:57:13.258149 2026] [security2:error] [pid 66623:tid 66892] [client 20.119.58.187:11456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/1.php"] [unique_id "aoSA2dO5rbWdOArH04KRhgAAAYg"]
[Tue Aug 18 12:57:13.263252 2026] [security2:error] [pid 66623:tid 66834] [client 68.155.154.236:16265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSA2dO5rbWdOArH04KRhwAAAU4"]
[Tue Aug 18 12:57:13.338127 2026] [security2:error] [pid 66623:tid 66818] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSA2dO5rbWdOArH04KRiAAAAT4"]
[Tue Aug 18 12:57:13.388916 2026] [security2:error] [pid 67073:tid 67208] [client 158.158.74.177:26164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/v.php"] [unique_id "aoSA2fcmepr5_nHgLbNhQwAAAhc"]
[Tue Aug 18 12:57:13.413309 2026] [security2:error] [pid 67073:tid 67310] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSA2fcmepr5_nHgLbNhRQAAAn0"]
[Tue Aug 18 12:57:13.583196 2026] [security2:error] [pid 67073:tid 67261] [client 172.202.39.151:54697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/epinyins.php"] [unique_id "aoSA2fcmepr5_nHgLbNhSgAAAkw"]
[Tue Aug 18 12:57:13.610454 2026] [security2:error] [pid 67073:tid 67212] [client 20.119.58.187:11220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/2.php"] [unique_id "aoSA2fcmepr5_nHgLbNhTQAAAhs"]
[Tue Aug 18 12:57:13.619215 2026] [security2:error] [pid 66623:tid 66788] [client 20.215.241.237:37908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/file1221.php"] [unique_id "aoSA2dO5rbWdOArH04KRjAAAASA"]
[Tue Aug 18 12:57:13.623701 2026] [security2:error] [pid 66623:tid 66825] [client 20.226.56.190:17868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/x.php"] [unique_id "aoSA2dO5rbWdOArH04KRjQAAAUU"]
[Tue Aug 18 12:57:13.670508 2026] [authz_core:error] [pid 67073:tid 67176] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:13.670965 2026] [authz_core:error] [pid 67073:tid 67176] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:13.757074 2026] [security2:error] [pid 67073:tid 67230] [client 20.118.172.148:62427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/asasx.php"] [unique_id "aoSA2fcmepr5_nHgLbNhUgAAAi0"]
[Tue Aug 18 12:57:13.757597 2026] [security2:error] [pid 66623:tid 66859] [client 20.65.98.162:8956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/uwu.php"] [unique_id "aoSA2dO5rbWdOArH04KRjwAAAWc"]
[Tue Aug 18 12:57:13.768226 2026] [security2:error] [pid 67073:tid 67253] [client 79.127.164.8:39702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/mysql_basic.bak"] [unique_id "aoSA2fcmepr5_nHgLbNhVAAAAkQ"], referer: https://medihub.com.br/mysql_basic.bak
[Tue Aug 18 12:57:13.775253 2026] [security2:error] [pid 66623:tid 66882] [client 132.196.30.78:18779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/i.php"] [unique_id "aoSA2dO5rbWdOArH04KRkAAAAX4"]
[Tue Aug 18 12:57:13.781364 2026] [security2:error] [pid 67073:tid 67309] [client 104.209.144.33:36506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSA2fcmepr5_nHgLbNhVQAAAnw"]
[Tue Aug 18 12:57:13.820273 2026] [security2:error] [pid 67073:tid 67313] [client 135.225.75.187:31370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/X7x.php"] [unique_id "aoSA2fcmepr5_nHgLbNhVgAAAoA"]
[Tue Aug 18 12:57:13.855835 2026] [authz_core:error] [pid 67073:tid 67267] [client 192.178.4.133:57249] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:13.856105 2026] [authz_core:error] [pid 67073:tid 67267] [client 192.178.4.133:57249] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:13.860446 2026] [security2:error] [pid 67073:tid 67246] [client 74.248.18.37:31868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/index/function.php"] [unique_id "aoSA2fcmepr5_nHgLbNhWQAAAj0"]
[Tue Aug 18 12:57:13.861730 2026] [security2:error] [pid 66623:tid 66668] [remote 129.121.103.155:44390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "historiasparadormir.top"] [uri "/wp-login.php"] [unique_id "aoSA2dO5rbWdOArH04KRkQABiR8"]
[Tue Aug 18 12:57:13.868189 2026] [security2:error] [pid 67073:tid 67312] [client 213.35.127.232:51096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSA2fcmepr5_nHgLbNhWgAAAn8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:13.891187 2026] [security2:error] [pid 67073:tid 67243] [client 68.155.155.199:20182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSA2fcmepr5_nHgLbNhWwAAAjo"]
[Tue Aug 18 12:57:13.897580 2026] [security2:error] [pid 67073:tid 67238] [client 20.100.169.31:32897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/aaa.php"] [unique_id "aoSA2fcmepr5_nHgLbNhXAAAAjU"]
[Tue Aug 18 12:57:13.912517 2026] [security2:error] [pid 67073:tid 67262] [client 114.5.214.109:49814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA2fcmepr5_nHgLbNhXQAAAk0"]
[Tue Aug 18 12:57:13.912660 2026] [security2:error] [pid 67073:tid 67262] [client 114.5.214.109:49814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA2fcmepr5_nHgLbNhXQAAAk0"]
[Tue Aug 18 12:57:13.969266 2026] [authz_core:error] [pid 67073:tid 67114] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:13.969569 2026] [authz_core:error] [pid 67073:tid 67114] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:13.973966 2026] [security2:error] [pid 67073:tid 67235] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSA2fcmepr5_nHgLbNhYQAAAjI"]
[Tue Aug 18 12:57:13.978067 2026] [security2:error] [pid 67073:tid 67304] [client 20.119.58.187:11216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/7.php"] [unique_id "aoSA2fcmepr5_nHgLbNhYgAAAnc"]
[Tue Aug 18 12:57:13.986237 2026] [security2:error] [pid 67073:tid 67293] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSA2fcmepr5_nHgLbNhZAAAAmw"]
[Tue Aug 18 12:57:14.011436 2026] [security2:error] [pid 67073:tid 67234] [client 68.155.154.236:45575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSA2vcmepr5_nHgLbNhZgAAAjE"]
[Tue Aug 18 12:57:14.067149 2026] [security2:error] [pid 67073:tid 67287] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/0x.php"] [unique_id "aoSA2vcmepr5_nHgLbNhagAAAmY"]
[Tue Aug 18 12:57:14.085376 2026] [security2:error] [pid 67073:tid 67255] [client 157.51.166.53:64392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA2vcmepr5_nHgLbNhbAAAAkY"]
[Tue Aug 18 12:57:14.085480 2026] [security2:error] [pid 67073:tid 67255] [client 157.51.166.53:64392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA2vcmepr5_nHgLbNhbAAAAkY"]
[Tue Aug 18 12:57:14.146582 2026] [security2:error] [pid 67073:tid 67274] [client 158.158.74.177:16530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/v5.php"] [unique_id "aoSA2vcmepr5_nHgLbNhbgAAAlk"]
[Tue Aug 18 12:57:14.183948 2026] [authz_core:error] [pid 67073:tid 67200] [remote 57.141.22.26:43774] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:14.184404 2026] [authz_core:error] [pid 67073:tid 67200] [remote 57.141.22.26:43774] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:14.270793 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:14.271117 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:14.331308 2026] [security2:error] [pid 66623:tid 66827] [client 20.119.58.187:11306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/10.php"] [unique_id "aoSA2tO5rbWdOArH04KRlQAAAUc"]
[Tue Aug 18 12:57:14.348061 2026] [authz_core:error] [pid 66623:tid 66819] [client 192.178.4.133:54432] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:14.348388 2026] [authz_core:error] [pid 66623:tid 66819] [client 192.178.4.133:54432] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:14.392052 2026] [security2:error] [pid 67073:tid 67251] [client 74.248.136.165:64172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ocxla.php"] [unique_id "aoSA2vcmepr5_nHgLbNhdAAAAkI"]
[Tue Aug 18 12:57:14.402467 2026] [security2:error] [pid 67073:tid 67282] [client 40.74.65.169:28203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/makeasmtp.php"] [unique_id "aoSA2vcmepr5_nHgLbNhdwAAAmE"]
[Tue Aug 18 12:57:14.458913 2026] [authz_core:error] [pid 66623:tid 66739] [remote 57.141.22.3:27164] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:14.459176 2026] [authz_core:error] [pid 66623:tid 66739] [remote 57.141.22.3:27164] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:14.462564 2026] [security2:error] [pid 67073:tid 67227] [client 20.118.172.148:62414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/filemanager.php"] [unique_id "aoSA2vcmepr5_nHgLbNheAAAAio"]
[Tue Aug 18 12:57:14.503060 2026] [security2:error] [pid 67073:tid 67221] [client 74.248.18.37:8002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/info.php"] [unique_id "aoSA2vcmepr5_nHgLbNhewAAAiQ"]
[Tue Aug 18 12:57:14.573212 2026] [security2:error] [pid 66623:tid 66865] [client 5.161.113.195:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "amigosdoronron.com.br"] [uri "/index.php"] [unique_id "aoSA2dO5rbWdOArH04KRfwABbWg"], referer: https://amigosdoronron.com.br/
[Tue Aug 18 12:57:14.574272 2026] [authz_core:error] [pid 67073:tid 67139] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:14.574698 2026] [authz_core:error] [pid 67073:tid 67139] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:14.601642 2026] [security2:error] [pid 66623:tid 66866] [client 132.196.30.78:21827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSA2tO5rbWdOArH04KRmwAAAW4"]
[Tue Aug 18 12:57:14.624790 2026] [security2:error] [pid 67073:tid 67272] [client 68.155.154.236:16216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSA2vcmepr5_nHgLbNhfwAAAlc"]
[Tue Aug 18 12:57:14.625187 2026] [security2:error] [pid 67073:tid 67307] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/222.php"] [unique_id "aoSA2vcmepr5_nHgLbNhgAAAAno"]
[Tue Aug 18 12:57:14.636545 2026] [security2:error] [pid 67073:tid 67332] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/aa.php"] [unique_id "aoSA2vcmepr5_nHgLbNhgQAAApM"]
[Tue Aug 18 12:57:14.677634 2026] [security2:error] [pid 66623:tid 66775] [client 68.155.156.252:29051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSA2tO5rbWdOArH04KRnQAAARM"]
[Tue Aug 18 12:57:14.686078 2026] [security2:error] [pid 67073:tid 67288] [client 20.119.58.187:11296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/13.php"] [unique_id "aoSA2vcmepr5_nHgLbNhgwAAAmc"]
[Tue Aug 18 12:57:14.735076 2026] [security2:error] [pid 67073:tid 67241] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/abcd.php"] [unique_id "aoSA2vcmepr5_nHgLbNhhAAAAjg"]
[Tue Aug 18 12:57:14.771760 2026] [security2:error] [pid 67073:tid 67319] [client 68.155.155.199:2257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/buy.php"] [unique_id "aoSA2vcmepr5_nHgLbNhhgAAAoY"]
[Tue Aug 18 12:57:14.872798 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:14.873063 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:14.881889 2026] [security2:error] [pid 66623:tid 66862] [client 213.35.127.232:51335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA2tO5rbWdOArH04KRogAAAWo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:14.901224 2026] [security2:error] [pid 67073:tid 67258] [client 172.202.39.151:31525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-admin/css/index.php"] [unique_id "aoSA2vcmepr5_nHgLbNhkAAAAkk"]
[Tue Aug 18 12:57:14.902843 2026] [security2:error] [pid 67073:tid 67257] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA2vcmepr5_nHgLbNhjgACSEk"]
[Tue Aug 18 12:57:14.952949 2026] [security2:error] [pid 66623:tid 66781] [client 20.100.169.31:40546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/info.php"] [unique_id "aoSA2tO5rbWdOArH04KRpQAAARk"]
[Tue Aug 18 12:57:14.974620 2026] [security2:error] [pid 67073:tid 67210] [client 20.215.241.237:22703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/inx.php"] [unique_id "aoSA2vcmepr5_nHgLbNhkwAAAhk"]
[Tue Aug 18 12:57:14.983472 2026] [security2:error] [pid 67073:tid 67273] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/admin.php"] [unique_id "aoSA2vcmepr5_nHgLbNhlAAAAlg"]
[Tue Aug 18 12:57:14.988301 2026] [security2:error] [pid 67073:tid 67279] [client 20.118.172.148:54875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/themes.php"] [unique_id "aoSA2vcmepr5_nHgLbNhlQAAAl4"]
[Tue Aug 18 12:57:14.993363 2026] [security2:error] [pid 67073:tid 67250] [client 158.158.74.177:22765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/we.php"] [unique_id "aoSA2vcmepr5_nHgLbNhlgAAAkE"]
[Tue Aug 18 12:57:15.061020 2026] [security2:error] [pid 66623:tid 66808] [client 68.155.154.236:50370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSA29O5rbWdOArH04KRpgAAATQ"]
[Tue Aug 18 12:57:15.067304 2026] [security2:error] [pid 66623:tid 66768] [client 20.119.58.187:11320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/100.php"] [unique_id "aoSA29O5rbWdOArH04KRpwAAAQw"]
[Tue Aug 18 12:57:15.130925 2026] [security2:error] [pid 67073:tid 67314] [client 132.196.30.78:21855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSA2_cmepr5_nHgLbNhnAAAAoE"]
[Tue Aug 18 12:57:15.133240 2026] [security2:error] [pid 67073:tid 67309] [client 40.74.65.169:43147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSA2_cmepr5_nHgLbNhnQAAAnw"]
[Tue Aug 18 12:57:15.146120 2026] [security2:error] [pid 66623:tid 66857] [client 192.141.172.134:63203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSA29O5rbWdOArH04KRqgAAAWU"]
[Tue Aug 18 12:57:15.146292 2026] [security2:error] [pid 66623:tid 66857] [client 192.141.172.134:63203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSA29O5rbWdOArH04KRqgAAAWU"]
[Tue Aug 18 12:57:15.162501 2026] [security2:error] [pid 67073:tid 67294] [client 196.12.128.158:53225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA2_cmepr5_nHgLbNhngAAAm0"]
[Tue Aug 18 12:57:15.162630 2026] [security2:error] [pid 67073:tid 67294] [client 196.12.128.158:53225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA2_cmepr5_nHgLbNhngAAAm0"]
[Tue Aug 18 12:57:15.168328 2026] [security2:error] [pid 67073:tid 67243] [client 135.225.75.187:24753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ocxla.php"] [unique_id "aoSA2_cmepr5_nHgLbNhnwAAAjo"]
[Tue Aug 18 12:57:15.270700 2026] [security2:error] [pid 67073:tid 67286] [client 74.248.18.37:8017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/inputs.php"] [unique_id "aoSA2_cmepr5_nHgLbNhowAAAmU"]
[Tue Aug 18 12:57:15.294203 2026] [security2:error] [pid 67073:tid 67237] [client 104.209.144.33:36515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/well-known/index.php"] [unique_id "aoSA2_cmepr5_nHgLbNhpAAAAjQ"]
[Tue Aug 18 12:57:15.367555 2026] [security2:error] [pid 67073:tid 67229] [client 20.65.98.162:42483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/signon.php"] [unique_id "aoSA2_cmepr5_nHgLbNhpwAAAiw"]
[Tue Aug 18 12:57:15.418499 2026] [security2:error] [pid 66623:tid 66770] [client 20.119.58.187:11326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/222.php"] [unique_id "aoSA29O5rbWdOArH04KRsgAAAQ4"]
[Tue Aug 18 12:57:15.418689 2026] [security2:error] [pid 67073:tid 67305] [client 172.182.200.96:14080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA2_cmepr5_nHgLbNhqwAAAng"]
[Tue Aug 18 12:57:15.429404 2026] [authz_core:error] [pid 67073:tid 67183] [remote 57.141.22.98:32294] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:15.429655 2026] [authz_core:error] [pid 67073:tid 67183] [remote 57.141.22.98:32294] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:15.478151 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:15.478610 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:15.558263 2026] [security2:error] [pid 67073:tid 67267] [client 20.215.241.237:37928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/reviall.php"] [unique_id "aoSA2_cmepr5_nHgLbNhsQAAAlI"]
[Tue Aug 18 12:57:15.560373 2026] [security2:error] [pid 67073:tid 67321] [client 68.155.154.236:16201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSA2_cmepr5_nHgLbNhsgAAAog"]
[Tue Aug 18 12:57:15.665776 2026] [security2:error] [pid 67073:tid 67325] [client 20.118.172.148:62451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSA2_cmepr5_nHgLbNhtAAAAow"]
[Tue Aug 18 12:57:15.720593 2026] [security2:error] [pid 67073:tid 67317] [client 132.196.30.78:21945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/gecko-new.php"] [unique_id "aoSA2_cmepr5_nHgLbNhtgAAAoQ"]
[Tue Aug 18 12:57:15.770764 2026] [security2:error] [pid 66623:tid 66795] [client 20.119.58.187:11324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/adminfuns.php"] [unique_id "aoSA29O5rbWdOArH04KRtQAAASc"]
[Tue Aug 18 12:57:15.775989 2026] [authz_core:error] [pid 67073:tid 67195] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:15.776261 2026] [authz_core:error] [pid 67073:tid 67195] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:15.808680 2026] [security2:error] [pid 66623:tid 66803] [client 158.158.74.177:16536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wkl.php"] [unique_id "aoSA29O5rbWdOArH04KRtgAAAS8"]
[Tue Aug 18 12:57:15.841233 2026] [security2:error] [pid 66623:tid 66826] [client 40.74.65.169:11245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/system_log.php"] [unique_id "aoSA29O5rbWdOArH04KRtwAAAUY"]
[Tue Aug 18 12:57:15.888918 2026] [security2:error] [pid 67073:tid 67302] [client 197.184.64.235:41935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA2_cmepr5_nHgLbNhvAAAAnU"]
[Tue Aug 18 12:57:15.889040 2026] [security2:error] [pid 67073:tid 67302] [client 197.184.64.235:41935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA2_cmepr5_nHgLbNhvAAAAnU"]
[Tue Aug 18 12:57:15.892025 2026] [security2:error] [pid 66623:tid 66783] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/adminfuns.php"] [unique_id "aoSA29O5rbWdOArH04KRuAAAARs"]
[Tue Aug 18 12:57:15.894189 2026] [security2:error] [pid 66623:tid 66836] [client 213.35.127.232:51603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA29O5rbWdOArH04KRuQAAAVA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:15.920773 2026] [security2:error] [pid 67073:tid 67330] [client 74.248.18.37:62084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/install.php"] [unique_id "aoSA2_cmepr5_nHgLbNhvQAAApE"]
[Tue Aug 18 12:57:15.980467 2026] [security2:error] [pid 66623:tid 66815] [client 68.155.155.199:6646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/dropdown.php"] [unique_id "aoSA29O5rbWdOArH04KRvgAAATs"]
[Tue Aug 18 12:57:16.010132 2026] [security2:error] [pid 66623:tid 66766] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/akc.php"] [unique_id "aoSA3NO5rbWdOArH04KRvwAAAQo"]
[Tue Aug 18 12:57:16.025975 2026] [security2:error] [pid 66623:tid 66834] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/buy.php"] [unique_id "aoSA3NO5rbWdOArH04KRwAAAAU4"]
[Tue Aug 18 12:57:16.044922 2026] [security2:error] [pid 66623:tid 66818] [client 20.118.133.132:27455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA3NO5rbWdOArH04KRwQAAAT4"]
[Tue Aug 18 12:57:16.079241 2026] [authz_core:error] [pid 67073:tid 67105] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:16.079519 2026] [authz_core:error] [pid 67073:tid 67105] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:16.124383 2026] [security2:error] [pid 67073:tid 67249] [client 135.225.75.187:33044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/post.php"] [unique_id "aoSA3Pcmepr5_nHgLbNhxQAAAkA"]
[Tue Aug 18 12:57:16.165965 2026] [security2:error] [pid 66623:tid 66856] [client 20.215.241.237:20383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/11.php"] [unique_id "aoSA3NO5rbWdOArH04KRwgAAAWQ"]
[Tue Aug 18 12:57:16.167202 2026] [security2:error] [pid 67073:tid 67272] [client 20.119.58.187:11215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/abcd.php"] [unique_id "aoSA3Pcmepr5_nHgLbNhxwAAAlc"]
[Tue Aug 18 12:57:16.216118 2026] [security2:error] [pid 67073:tid 67291] [client 158.158.34.183:57357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/dav.php"] [unique_id "aoSA3Pcmepr5_nHgLbNhyQAAAmo"]
[Tue Aug 18 12:57:16.350507 2026] [security2:error] [pid 67073:tid 67223] [client 172.182.200.96:14123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/weozh.php"] [unique_id "aoSA3Pcmepr5_nHgLbNhzQAAAiY"]
[Tue Aug 18 12:57:16.364897 2026] [security2:error] [pid 67073:tid 67241] [client 132.196.30.78:19449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/NewFile.php"] [unique_id "aoSA3Pcmepr5_nHgLbNhzgAAAjg"]
[Tue Aug 18 12:57:16.378491 2026] [authz_core:error] [pid 67073:tid 67198] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:16.378755 2026] [authz_core:error] [pid 67073:tid 67198] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:16.411000 2026] [security2:error] [pid 67073:tid 67303] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/cong.php"] [unique_id "aoSA3Pcmepr5_nHgLbNh0QAAAnY"]
[Tue Aug 18 12:57:16.411054 2026] [security2:error] [pid 67073:tid 67269] [client 20.100.169.31:40290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/abcd.php"] [unique_id "aoSA3Pcmepr5_nHgLbNh0AAAAlQ"]
[Tue Aug 18 12:57:16.418238 2026] [security2:error] [pid 67073:tid 67300] [client 20.206.73.37:11919] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "villasgarage.com.br"] [uri "/1.php"] [unique_id "aoSA3Pcmepr5_nHgLbNh0gAAAnM"]
[Tue Aug 18 12:57:16.418323 2026] [security2:error] [pid 67073:tid 67300] [client 20.206.73.37:11919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/1.php"] [unique_id "aoSA3Pcmepr5_nHgLbNh0gAAAnM"]
[Tue Aug 18 12:57:16.468983 2026] [security2:error] [pid 67073:tid 67257] [client 20.118.172.148:54858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/buy.php"] [unique_id "aoSA3Pcmepr5_nHgLbNh1QAAAkg"]
[Tue Aug 18 12:57:16.494391 2026] [security2:error] [pid 67073:tid 67311] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSA3Pcmepr5_nHgLbNh2AAAAn4"]
[Tue Aug 18 12:57:16.519678 2026] [security2:error] [pid 66623:tid 66882] [client 20.119.58.187:11323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/al.php"] [unique_id "aoSA3NO5rbWdOArH04KRxwAAAX4"]
[Tue Aug 18 12:57:16.562034 2026] [security2:error] [pid 66623:tid 66843] [client 74.248.18.37:8019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSA3NO5rbWdOArH04KRyQAAAVc"]
[Tue Aug 18 12:57:16.677070 2026] [authz_core:error] [pid 67073:tid 67108] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:16.677397 2026] [authz_core:error] [pid 67073:tid 67108] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:16.680501 2026] [security2:error] [pid 67073:tid 67253] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/db.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiAgAAAkQ"]
[Tue Aug 18 12:57:16.705175 2026] [security2:error] [pid 67073:tid 67309] [client 104.209.144.33:19588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiBAAAAnw"]
[Tue Aug 18 12:57:16.758485 2026] [security2:error] [pid 66623:tid 66782] [client 68.155.154.236:16360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSA3NO5rbWdOArH04KRzAAAARo"]
[Tue Aug 18 12:57:16.835463 2026] [security2:error] [pid 66623:tid 66850] [client 20.250.13.23:39662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/ncx.php"] [unique_id "aoSA3NO5rbWdOArH04KRzQAAAV4"]
[Tue Aug 18 12:57:16.872244 2026] [security2:error] [pid 67073:tid 67312] [client 20.119.58.187:11210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/alfa.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiCAAAAn8"]
[Tue Aug 18 12:57:16.876591 2026] [security2:error] [pid 67073:tid 67304] [client 135.225.75.187:24718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/nhr.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiCwAAAnc"]
[Tue Aug 18 12:57:16.916380 2026] [security2:error] [pid 67073:tid 67218] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/dropdown.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiDAAAAiE"]
[Tue Aug 18 12:57:16.922650 2026] [security2:error] [pid 67073:tid 67240] [client 213.35.127.232:51868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiDQAAAjc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:16.926656 2026] [security2:error] [pid 67073:tid 67286] [client 192.141.172.134:63465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiDgAAAmU"]
[Tue Aug 18 12:57:16.926755 2026] [security2:error] [pid 67073:tid 67286] [client 192.141.172.134:63465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiDgAAAmU"]
[Tue Aug 18 12:57:16.929007 2026] [security2:error] [pid 67073:tid 67255] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/file.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiDwAAAkY"]
[Tue Aug 18 12:57:16.930152 2026] [security2:error] [pid 67073:tid 67290] [client 20.215.241.237:43210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/File.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiEAAAAmk"]
[Tue Aug 18 12:57:16.941559 2026] [security2:error] [pid 67073:tid 67305] [client 68.155.154.236:50403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiEQAAAng"]
[Tue Aug 18 12:57:16.944013 2026] [security2:error] [pid 67073:tid 67299] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/goods.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiEgAAAnI"]
[Tue Aug 18 12:57:16.956906 2026] [security2:error] [pid 66623:tid 66797] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/hplfuns.php"] [unique_id "aoSA3NO5rbWdOArH04KRzwAAASk"]
[Tue Aug 18 12:57:16.976222 2026] [security2:error] [pid 67073:tid 67280] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/htaccess.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiFwAAAl8"]
[Tue Aug 18 12:57:16.996712 2026] [security2:error] [pid 67073:tid 67267] [client 158.158.74.177:26123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/work.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiGgAAAlI"]
[Tue Aug 18 12:57:17.032606 2026] [security2:error] [pid 66623:tid 66809] [client 85.208.96.201:30028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/2025/06/14/hoot-loot-status-trial-in-the-high-5-game-neteller-casino-dragonz-5-deposit-95-rtp-2025-pt-sil/"] [unique_id "aoSA3dO5rbWdOArH04KR0QAAATU"]
[Tue Aug 18 12:57:17.032734 2026] [security2:error] [pid 66623:tid 66809] [client 85.208.96.201:30028] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/2025/06/14/hoot-loot-status-trial-in-the-high-5-game-neteller-casino-dragonz-5-deposit-95-rtp-2025-pt-sil/"] [unique_id "aoSA3dO5rbWdOArH04KR0QAAATU"]
[Tue Aug 18 12:57:17.040566 2026] [security2:error] [pid 67073:tid 67251] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/images/wso.php"] [unique_id "aoSA3fcmepr5_nHgLbNiHQAAAkI"]
[Tue Aug 18 12:57:17.076472 2026] [autoindex:error] [pid 66623:tid 66807] [client 172.202.39.151:43213] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:17.078857 2026] [security2:error] [pid 66623:tid 66774] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/index/function.php"] [unique_id "aoSA3dO5rbWdOArH04KR0wAAARI"]
[Tue Aug 18 12:57:17.085674 2026] [security2:error] [pid 66623:tid 66853] [client 68.155.155.199:4361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/inputs.php"] [unique_id "aoSA3dO5rbWdOArH04KR1AAAAWE"]
[Tue Aug 18 12:57:17.103445 2026] [security2:error] [pid 67073:tid 67227] [client 20.118.172.148:62087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/dropdown.php"] [unique_id "aoSA3fcmepr5_nHgLbNiIQAAAio"]
[Tue Aug 18 12:57:17.194660 2026] [security2:error] [pid 66623:tid 66866] [client 49.13.164.148:17962] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agrimotor.com.br"] [uri "/index.php"] [unique_id "aoSA3dO5rbWdOArH04KR0AAAAW4"], referer: https://agrimotor.com.br
[Tue Aug 18 12:57:17.198930 2026] [security2:error] [pid 67073:tid 67324] [client 74.248.18.37:62132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/item.php"] [unique_id "aoSA3fcmepr5_nHgLbNiJQAAAos"]
[Tue Aug 18 12:57:17.251025 2026] [security2:error] [pid 67073:tid 67313] [client 158.158.34.183:28885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp_wol.php"] [unique_id "aoSA3fcmepr5_nHgLbNiKAAAAoA"]
[Tue Aug 18 12:57:17.272589 2026] [security2:error] [pid 67073:tid 67326] [client 172.182.200.96:14145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-2019.php"] [unique_id "aoSA3fcmepr5_nHgLbNiKgAAAo0"]
[Tue Aug 18 12:57:17.283463 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:17.283928 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:17.284525 2026] [security2:error] [pid 66623:tid 66819] [client 20.119.58.187:11205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/as.php"] [unique_id "aoSA3dO5rbWdOArH04KR1wAAAT8"]
[Tue Aug 18 12:57:17.335644 2026] [security2:error] [pid 66623:tid 66816] [client 74.7.228.11:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.adobank.com.br"] [uri "/index.php"] [unique_id "aoSA3dO5rbWdOArH04KR1QABPHA"]
[Tue Aug 18 12:57:17.345746 2026] [security2:error] [pid 67073:tid 67331] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/info.php"] [unique_id "aoSA3fcmepr5_nHgLbNiLAAAApI"]
[Tue Aug 18 12:57:17.346485 2026] [security2:error] [pid 66623:tid 66885] [client 20.100.169.31:43832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-good.php"] [unique_id "aoSA3dO5rbWdOArH04KR2AAAAYE"]
[Tue Aug 18 12:57:17.349099 2026] [security2:error] [pid 67073:tid 67214] [client 40.74.65.169:27026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/pucci.php"] [unique_id "aoSA3fcmepr5_nHgLbNiLQAAAh0"]
[Tue Aug 18 12:57:17.429468 2026] [security2:error] [pid 67073:tid 67230] [client 37.40.227.74:56756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3fcmepr5_nHgLbNiMgAAAi0"]
[Tue Aug 18 12:57:17.429589 2026] [security2:error] [pid 67073:tid 67230] [client 37.40.227.74:56756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3fcmepr5_nHgLbNiMgAAAi0"]
[Tue Aug 18 12:57:17.444369 2026] [security2:error] [pid 66623:tid 66872] [client 172.202.39.151:43213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSA3dO5rbWdOArH04KR2gAAAXQ"]
[Tue Aug 18 12:57:17.463089 2026] [security2:error] [pid 67073:tid 67269] [client 20.215.241.237:20363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/fi22.php"] [unique_id "aoSA3fcmepr5_nHgLbNiMwAAAlQ"]
[Tue Aug 18 12:57:17.578703 2026] [authz_core:error] [pid 67073:tid 67119] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:17.578968 2026] [authz_core:error] [pid 67073:tid 67119] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:17.579335 2026] [authz_core:error] [pid 67073:tid 67133] [remote 57.141.22.85:40878] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:17.579713 2026] [authz_core:error] [pid 67073:tid 67133] [remote 57.141.22.85:40878] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:17.618331 2026] [security2:error] [pid 66623:tid 66845] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/profile.php"] [unique_id "aoSA3dO5rbWdOArH04KR4AAAAVk"]
[Tue Aug 18 12:57:17.625300 2026] [security2:error] [pid 67073:tid 67271] [client 135.225.75.187:25709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ms-edit.php"] [unique_id "aoSA3fcmepr5_nHgLbNiPAAAAlY"]
[Tue Aug 18 12:57:17.636480 2026] [security2:error] [pid 67073:tid 67323] [client 20.119.58.187:11298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/aa.php"] [unique_id "aoSA3fcmepr5_nHgLbNiPQAAAoo"]
[Tue Aug 18 12:57:17.645690 2026] [security2:error] [pid 67073:tid 67261] [client 68.155.155.199:1917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/100.php"] [unique_id "aoSA3fcmepr5_nHgLbNiPwAAAkw"]
[Tue Aug 18 12:57:17.763843 2026] [security2:error] [pid 67073:tid 67243] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/sx.php"] [unique_id "aoSA3fcmepr5_nHgLbNiRwAAAjo"]
[Tue Aug 18 12:57:17.770609 2026] [security2:error] [pid 67073:tid 67296] [client 158.158.74.177:17923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/worksec.php"] [unique_id "aoSA3fcmepr5_nHgLbNiSAAAAm8"]
[Tue Aug 18 12:57:17.785429 2026] [security2:error] [pid 67073:tid 67238] [client 74.248.136.165:22473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/post.php"] [unique_id "aoSA3fcmepr5_nHgLbNiSQAAAjU"]
[Tue Aug 18 12:57:17.786614 2026] [security2:error] [pid 66623:tid 66832] [client 68.155.154.236:16306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSA3dO5rbWdOArH04KR4QAAAUw"]
[Tue Aug 18 12:57:17.789751 2026] [security2:error] [pid 67073:tid 67260] [client 170.81.43.147:40146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.43.81.170.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.fbenevides.com.br"] [uri "/include/plugin/payment/alipay/pay.php"] [unique_id "aoSA3fcmepr5_nHgLbNiSgAAAks"]
[Tue Aug 18 12:57:17.838399 2026] [security2:error] [pid 67073:tid 67211] [client 103.184.169.37:42114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3fcmepr5_nHgLbNiTwAAAho"]
[Tue Aug 18 12:57:17.838764 2026] [security2:error] [pid 67073:tid 67211] [client 103.184.169.37:42114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3fcmepr5_nHgLbNiTwAAAho"]
[Tue Aug 18 12:57:17.840938 2026] [security2:error] [pid 67073:tid 67304] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSA3fcmepr5_nHgLbNiUAAAAnc"]
[Tue Aug 18 12:57:17.846426 2026] [security2:error] [pid 67073:tid 67217] [client 132.196.30.78:21891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSA3fcmepr5_nHgLbNiUQAAAiA"]
[Tue Aug 18 12:57:17.870215 2026] [security2:error] [pid 66623:tid 66863] [client 74.248.18.37:31838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/js.php"] [unique_id "aoSA3dO5rbWdOArH04KR4gAAAWs"]
[Tue Aug 18 12:57:17.884965 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:17.885396 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:17.936392 2026] [security2:error] [pid 67073:tid 67310] [client 213.35.127.232:52099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSA3fcmepr5_nHgLbNiWgAAAn0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:17.964770 2026] [security2:error] [pid 67073:tid 67306] [client 68.155.156.252:51574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSA3fcmepr5_nHgLbNiXAAAAnk"]
[Tue Aug 18 12:57:17.977943 2026] [security2:error] [pid 67073:tid 67263] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSA3fcmepr5_nHgLbNiXgAAAk4"]
[Tue Aug 18 12:57:17.993827 2026] [security2:error] [pid 67073:tid 67255] [client 20.119.58.187:11266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/abc.php"] [unique_id "aoSA3fcmepr5_nHgLbNiXwAAAkY"]
[Tue Aug 18 12:57:18.049664 2026] [security2:error] [pid 66623:tid 66801] [client 20.215.241.237:37913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSA3tO5rbWdOArH04KR5QAAAS0"]
[Tue Aug 18 12:57:18.056182 2026] [security2:error] [pid 66623:tid 66770] [client 68.155.154.236:45573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSA3tO5rbWdOArH04KR5wAAAQ4"]
[Tue Aug 18 12:57:18.068561 2026] [security2:error] [pid 66623:tid 66875] [client 20.118.172.148:62453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/inputs.php"] [unique_id "aoSA3tO5rbWdOArH04KR6QAAAXc"]
[Tue Aug 18 12:57:18.181576 2026] [authz_core:error] [pid 67073:tid 67081] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:18.181890 2026] [authz_core:error] [pid 67073:tid 67081] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:18.213739 2026] [security2:error] [pid 66623:tid 66874] [client 103.120.71.157:54636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3tO5rbWdOArH04KR8gAAAXY"]
[Tue Aug 18 12:57:18.213847 2026] [security2:error] [pid 66623:tid 66874] [client 103.120.71.157:54636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3tO5rbWdOArH04KR8gAAAXY"]
[Tue Aug 18 12:57:18.255286 2026] [security2:error] [pid 66623:tid 66829] [client 68.155.155.199:7119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/akc.php"] [unique_id "aoSA3tO5rbWdOArH04KR9AAAAUk"]
[Tue Aug 18 12:57:18.270936 2026] [security2:error] [pid 67073:tid 67221] [client 20.206.73.37:59868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/coffee.php"] [unique_id "aoSA3vcmepr5_nHgLbNiZgAAAiQ"]
[Tue Aug 18 12:57:18.281111 2026] [security2:error] [pid 67073:tid 67321] [client 20.100.169.31:40275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/simple.php"] [unique_id "aoSA3vcmepr5_nHgLbNiZwAAAog"]
[Tue Aug 18 12:57:18.388792 2026] [security2:error] [pid 67073:tid 67320] [client 20.119.58.187:11307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/av.php"] [unique_id "aoSA3vcmepr5_nHgLbNibQAAAoc"]
[Tue Aug 18 12:57:18.401498 2026] [security2:error] [pid 67073:tid 67227] [client 79.127.164.8:52192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/mysql_basic.sql"] [unique_id "aoSA3vcmepr5_nHgLbNibgAAAio"], referer: https://medihub.com.br/mysql_basic.sql
[Tue Aug 18 12:57:18.455388 2026] [security2:error] [pid 67073:tid 67272] [client 20.65.98.162:52150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/file61.php"] [unique_id "aoSA3vcmepr5_nHgLbNicgAAAlc"]
[Tue Aug 18 12:57:18.465767 2026] [security2:error] [pid 66623:tid 66892] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA3tO5rbWdOArH04KR_AAAAYg"]
[Tue Aug 18 12:57:18.523670 2026] [security2:error] [pid 67073:tid 67207] [client 74.248.18.37:8007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/k.php"] [unique_id "aoSA3vcmepr5_nHgLbNidQAAAhY"]
[Tue Aug 18 12:57:18.602959 2026] [security2:error] [pid 67073:tid 67247] [client 20.226.56.190:23752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/yn.php"] [unique_id "aoSA3vcmepr5_nHgLbNidgAAAj4"]
[Tue Aug 18 12:57:18.624392 2026] [security2:error] [pid 67073:tid 67283] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA3vcmepr5_nHgLbNieAAAAmI"]
[Tue Aug 18 12:57:18.633102 2026] [security2:error] [pid 67073:tid 67277] [client 104.209.144.33:36497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoSA3vcmepr5_nHgLbNieQAAAlw"]
[Tue Aug 18 12:57:18.646533 2026] [security2:error] [pid 67073:tid 67257] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/weozh.php"] [unique_id "aoSA3vcmepr5_nHgLbNiegAAAkg"]
[Tue Aug 18 12:57:18.658178 2026] [security2:error] [pid 67073:tid 67311] [client 172.202.39.151:57336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSA3vcmepr5_nHgLbNiewAAAn4"]
[Tue Aug 18 12:57:18.704772 2026] [security2:error] [pid 67073:tid 67268] [client 111.221.44.12:62411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.44.221.111.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jic.org.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSA3vcmepr5_nHgLbNifQAAAlM"]
[Tue Aug 18 12:57:18.757008 2026] [security2:error] [pid 67073:tid 67245] [client 20.119.58.187:11287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSA3vcmepr5_nHgLbNifwAAAjw"]
[Tue Aug 18 12:57:18.781979 2026] [authz_core:error] [pid 67073:tid 67145] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:18.782237 2026] [authz_core:error] [pid 67073:tid 67145] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:18.793884 2026] [security2:error] [pid 67073:tid 67284] [client 135.225.75.187:36573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ws79.php"] [unique_id "aoSA3vcmepr5_nHgLbNigwAAAmM"]
[Tue Aug 18 12:57:18.807119 2026] [security2:error] [pid 66623:tid 66890] [client 40.74.65.169:27831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-temp.php"] [unique_id "aoSA3tO5rbWdOArH04KSCgAAAYY"]
[Tue Aug 18 12:57:18.853205 2026] [security2:error] [pid 67073:tid 67258] [client 20.118.172.148:52237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/100.php"] [unique_id "aoSA3vcmepr5_nHgLbNihAAAAkk"]
[Tue Aug 18 12:57:18.861119 2026] [security2:error] [pid 67073:tid 67209] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/rymmm.php"] [unique_id "aoSA3vcmepr5_nHgLbNihQAAAhg"]
[Tue Aug 18 12:57:18.931995 2026] [security2:error] [pid 67073:tid 67238] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/lddxs.php"] [unique_id "aoSA3vcmepr5_nHgLbNiiAAAAjU"]
[Tue Aug 18 12:57:18.941111 2026] [security2:error] [pid 67073:tid 67260] [client 172.182.200.96:7621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/rymmm.php"] [unique_id "aoSA3vcmepr5_nHgLbNiiQAAAks"]
[Tue Aug 18 12:57:18.941730 2026] [security2:error] [pid 67073:tid 67262] [client 20.118.133.132:1171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA3vcmepr5_nHgLbNiigAAAk0"]
[Tue Aug 18 12:57:18.950193 2026] [security2:error] [pid 67073:tid 67269] [client 213.35.127.232:52329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSA3vcmepr5_nHgLbNijAAAAlQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:19.084705 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:19.084978 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:19.108787 2026] [security2:error] [pid 67073:tid 67266] [client 20.119.58.187:11309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/asus.php"] [unique_id "aoSA3_cmepr5_nHgLbNikwAAAlE"]
[Tue Aug 18 12:57:19.122617 2026] [security2:error] [pid 67073:tid 67273] [client 20.100.169.31:43800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/edit-tags.php"] [unique_id "aoSA3_cmepr5_nHgLbNilQAAAlg"]
[Tue Aug 18 12:57:19.175661 2026] [security2:error] [pid 67073:tid 67288] [client 20.100.169.31:12561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/a.php"] [unique_id "aoSA3_cmepr5_nHgLbNimAAAAmc"]
[Tue Aug 18 12:57:19.265344 2026] [security2:error] [pid 67073:tid 67292] [client 74.248.18.37:62112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/media/index.php"] [unique_id "aoSA3_cmepr5_nHgLbNinAAAAms"]
[Tue Aug 18 12:57:19.294259 2026] [security2:error] [pid 67073:tid 67276] [client 20.118.172.148:56541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/akc.php"] [unique_id "aoSA3_cmepr5_nHgLbNingAAAls"]
[Tue Aug 18 12:57:19.308848 2026] [security2:error] [pid 67073:tid 67252] [client 20.215.241.237:22667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSA3_cmepr5_nHgLbNinwAAAkM"]
[Tue Aug 18 12:57:19.355057 2026] [security2:error] [pid 67073:tid 67233] [client 68.155.155.199:5983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSA3_cmepr5_nHgLbNiogAAAjA"]
[Tue Aug 18 12:57:19.356633 2026] [security2:error] [pid 67073:tid 67295] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/zjggu.php"] [unique_id "aoSA3_cmepr5_nHgLbNiowAAAm4"]
[Tue Aug 18 12:57:19.358425 2026] [fcgid:warn] [pid 67073:tid 67303] (70014)End of file found: [client 199.45.154.71:57014] mod_fcgid: can't get data from http client
[Tue Aug 18 12:57:19.384919 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:19.385182 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:19.385761 2026] [security2:error] [pid 66623:tid 66855] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/dlvqo.php"] [unique_id "aoSA39O5rbWdOArH04KSEAAAAWM"]
[Tue Aug 18 12:57:19.412770 2026] [security2:error] [pid 67073:tid 67315] [client 68.155.154.236:16218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSA3_cmepr5_nHgLbNipgAAAoI"]
[Tue Aug 18 12:57:19.486150 2026] [security2:error] [pid 67073:tid 67282] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/pkmoj.php"] [unique_id "aoSA3_cmepr5_nHgLbNiqwAAAmE"]
[Tue Aug 18 12:57:19.496692 2026] [security2:error] [pid 66623:tid 66844] [client 74.248.136.165:17988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/nhr.php"] [unique_id "aoSA39O5rbWdOArH04KSEgAAAVg"]
[Tue Aug 18 12:57:19.499244 2026] [security2:error] [pid 67073:tid 67294] [client 20.119.58.187:11301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/about.php"] [unique_id "aoSA3_cmepr5_nHgLbNirAAAAm0"]
[Tue Aug 18 12:57:19.525088 2026] [security2:error] [pid 67073:tid 67332] [client 68.155.154.236:40285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSA3_cmepr5_nHgLbNirgAAApM"]
[Tue Aug 18 12:57:19.546911 2026] [security2:error] [pid 66623:tid 66858] [client 20.226.56.190:31656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/11.php"] [unique_id "aoSA39O5rbWdOArH04KSFAAAAWY"]
[Tue Aug 18 12:57:19.574363 2026] [security2:error] [pid 66623:tid 66810] [client 40.74.65.169:42611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSA39O5rbWdOArH04KSFQAAATY"]
[Tue Aug 18 12:57:19.608813 2026] [authz_core:error] [pid 66623:tid 66696] [remote 57.141.22.107:35194] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:19.609096 2026] [authz_core:error] [pid 66623:tid 66696] [remote 57.141.22.107:35194] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:19.639468 2026] [security2:error] [pid 67073:tid 67275] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/kopyw.php"] [unique_id "aoSA3_cmepr5_nHgLbNiswAAAlo"]
[Tue Aug 18 12:57:19.682373 2026] [security2:error] [pid 66623:tid 66775] [client 20.118.172.148:62086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSA39O5rbWdOArH04KSGQAAARM"]
[Tue Aug 18 12:57:19.689098 2026] [authz_core:error] [pid 67073:tid 67193] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:19.689352 2026] [authz_core:error] [pid 67073:tid 67193] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:19.698989 2026] [security2:error] [pid 67073:tid 67239] [client 68.155.156.252:14997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/blurbs.php"] [unique_id "aoSA3_cmepr5_nHgLbNitQAAAjY"]
[Tue Aug 18 12:57:19.730968 2026] [security2:error] [pid 67073:tid 67304] [client 5.31.227.224:7859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3_cmepr5_nHgLbNiuAAAAnc"]
[Tue Aug 18 12:57:19.738876 2026] [security2:error] [pid 67073:tid 67304] [client 5.31.227.224:7859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3_cmepr5_nHgLbNiuAAAAnc"]
[Tue Aug 18 12:57:19.764843 2026] [security2:error] [pid 67073:tid 67305] [client 158.158.34.183:60364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/fm2.php"] [unique_id "aoSA3_cmepr5_nHgLbNiuQAAAng"]
[Tue Aug 18 12:57:19.774272 2026] [security2:error] [pid 67073:tid 67277] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/zznmg.php"] [unique_id "aoSA3_cmepr5_nHgLbNiuwAAAlw"]
[Tue Aug 18 12:57:19.798567 2026] [security2:error] [pid 67073:tid 67249] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/bhfnd.php"] [unique_id "aoSA3_cmepr5_nHgLbNivgAAAkA"]
[Tue Aug 18 12:57:19.803680 2026] [security2:error] [pid 67073:tid 67271] [client 135.225.75.187:36567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/rtx.php"] [unique_id "aoSA3_cmepr5_nHgLbNivwAAAlY"]
[Tue Aug 18 12:57:19.820835 2026] [security2:error] [pid 67073:tid 67208] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/qfvqu.php"] [unique_id "aoSA3_cmepr5_nHgLbNiwAAAAhc"]
[Tue Aug 18 12:57:19.822759 2026] [security2:error] [pid 67073:tid 67245] [client 172.202.39.151:31491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp.php"] [unique_id "aoSA3_cmepr5_nHgLbNiwQAAAjw"]
[Tue Aug 18 12:57:19.834590 2026] [security2:error] [pid 67073:tid 67293] [client 111.221.44.12:62630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.44.221.111.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jic.org.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSA3_cmepr5_nHgLbNiwgAAAmw"]
[Tue Aug 18 12:57:19.842434 2026] [security2:error] [pid 66623:tid 66806] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/oivcl.php"] [unique_id "aoSA39O5rbWdOArH04KSHgAAATI"]
[Tue Aug 18 12:57:19.853590 2026] [security2:error] [pid 66623:tid 66777] [client 20.119.58.187:11295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/atomlib.php"] [unique_id "aoSA39O5rbWdOArH04KSHwAAARU"]
[Tue Aug 18 12:57:19.858819 2026] [security2:error] [pid 67073:tid 67279] [client 68.155.154.236:16260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSA3_cmepr5_nHgLbNiwwAAAl4"]
[Tue Aug 18 12:57:19.877333 2026] [security2:error] [pid 67073:tid 67253] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/zugvi.php"] [unique_id "aoSA3_cmepr5_nHgLbNixAAAAkQ"]
[Tue Aug 18 12:57:19.900643 2026] [security2:error] [pid 66623:tid 66809] [client 74.248.18.37:62090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/memberfuns.php"] [unique_id "aoSA39O5rbWdOArH04KSIAAAATU"]
[Tue Aug 18 12:57:19.967562 2026] [security2:error] [pid 67073:tid 67287] [client 213.35.127.232:52549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA3_cmepr5_nHgLbNixwAAAmY"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:19.986378 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:19.986651 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:20.042958 2026] [security2:error] [pid 66623:tid 66792] [client 20.206.73.37:63258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSA4NO5rbWdOArH04KSIgAAASQ"]
[Tue Aug 18 12:57:20.046435 2026] [security2:error] [pid 66623:tid 66845] [client 20.226.56.190:2558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/vm.php"] [unique_id "aoSA4NO5rbWdOArH04KSIwAAAVk"]
[Tue Aug 18 12:57:20.125233 2026] [security2:error] [pid 66623:tid 66801] [client 68.155.155.199:5990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/php.php"] [unique_id "aoSA4NO5rbWdOArH04KSJgAAAS0"]
[Tue Aug 18 12:57:20.131729 2026] [security2:error] [pid 67073:tid 67308] [client 132.196.30.78:21847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSA4Pcmepr5_nHgLbNizAAAAns"]
[Tue Aug 18 12:57:20.142569 2026] [security2:error] [pid 67073:tid 67205] [client 157.20.138.62:64175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4Pcmepr5_nHgLbNizQAAAhQ"]
[Tue Aug 18 12:57:20.142745 2026] [security2:error] [pid 67073:tid 67205] [client 157.20.138.62:64175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4Pcmepr5_nHgLbNizQAAAhQ"]
[Tue Aug 18 12:57:20.148894 2026] [security2:error] [pid 66623:tid 66864] [client 20.118.172.148:54873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/php.php"] [unique_id "aoSA4NO5rbWdOArH04KSJwAAAWw"]
[Tue Aug 18 12:57:20.159862 2026] [security2:error] [pid 66623:tid 66878] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wsrer.php"] [unique_id "aoSA4NO5rbWdOArH04KSKQAAAXo"]
[Tue Aug 18 12:57:20.208553 2026] [security2:error] [pid 66623:tid 66784] [client 20.119.58.187:11200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSA4NO5rbWdOArH04KSKwAAARw"]
[Tue Aug 18 12:57:20.227831 2026] [security2:error] [pid 66623:tid 66839] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/ucpfr.php"] [unique_id "aoSA4NO5rbWdOArH04KSLQAAAVM"]
[Tue Aug 18 12:57:20.246403 2026] [security2:error] [pid 66623:tid 66793] [client 68.155.154.236:16363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/well-known/index.php"] [unique_id "aoSA4NO5rbWdOArH04KSLgAAASU"]
[Tue Aug 18 12:57:20.269478 2026] [security2:error] [pid 66623:tid 66874] [client 40.74.65.169:26694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/puc.php"] [unique_id "aoSA4NO5rbWdOArH04KSLwAAAXY"]
[Tue Aug 18 12:57:20.371961 2026] [security2:error] [pid 67073:tid 67312] [client 20.226.56.190:52085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/eg.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi0wAAAn8"]
[Tue Aug 18 12:57:20.406039 2026] [security2:error] [pid 67073:tid 67310] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/yxijx.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi1QAAAn0"]
[Tue Aug 18 12:57:20.417587 2026] [security2:error] [pid 67073:tid 67278] [client 149.34.210.141:57066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi1gAAAl0"]
[Tue Aug 18 12:57:20.459783 2026] [security2:error] [pid 66623:tid 66840] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/zwlsv.php"] [unique_id "aoSA4NO5rbWdOArH04KSMQAAAVQ"]
[Tue Aug 18 12:57:20.517201 2026] [security2:error] [pid 67073:tid 67263] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/jrpga.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi2QAAAk4"]
[Tue Aug 18 12:57:20.546172 2026] [security2:error] [pid 66623:tid 66879] [client 158.158.34.183:19931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/xmlrpc.php0"] [unique_id "aoSA4NO5rbWdOArH04KSMwAAAXs"]
[Tue Aug 18 12:57:20.555995 2026] [security2:error] [pid 66623:tid 66794] [client 172.182.200.96:7619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSA4NO5rbWdOArH04KSNAAAASY"]
[Tue Aug 18 12:57:20.570957 2026] [security2:error] [pid 67073:tid 67299] [client 172.202.39.151:44977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/function/function.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi2wAAAnI"]
[Tue Aug 18 12:57:20.590995 2026] [security2:error] [pid 66623:tid 66835] [client 74.248.18.37:31846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/mgrr.php"] [unique_id "aoSA4NO5rbWdOArH04KSNQAAAU8"]
[Tue Aug 18 12:57:20.598205 2026] [security2:error] [pid 66623:tid 66887] [client 20.118.172.148:62463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/t.php"] [unique_id "aoSA4NO5rbWdOArH04KSNgAAAYM"]
[Tue Aug 18 12:57:20.602415 2026] [security2:error] [pid 66623:tid 66892] [client 20.119.58.187:11207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/b.php"] [unique_id "aoSA4NO5rbWdOArH04KSNwAAAYg"]
[Tue Aug 18 12:57:20.646615 2026] [security2:error] [pid 67073:tid 67212] [client 68.155.154.236:16342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi3QAAAhs"]
[Tue Aug 18 12:57:20.672389 2026] [security2:error] [pid 66623:tid 66856] [client 20.215.241.237:44136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSA4NO5rbWdOArH04KSOAAAAWQ"]
[Tue Aug 18 12:57:20.686687 2026] [security2:error] [pid 67073:tid 67278] [client 149.34.210.141:57066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi1gAAAl0"]
[Tue Aug 18 12:57:20.718284 2026] [security2:error] [pid 66623:tid 66880] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSA4NO5rbWdOArH04KSOQAAAXw"]
[Tue Aug 18 12:57:20.831192 2026] [security2:error] [pid 66623:tid 66881] [client 135.225.75.187:48262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/end.php"] [unique_id "aoSA4NO5rbWdOArH04KSOwAAAX0"]
[Tue Aug 18 12:57:20.845962 2026] [security2:error] [pid 66623:tid 66859] [client 20.118.133.132:26814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/img.php"] [unique_id "aoSA4NO5rbWdOArH04KSPAAAAWc"]
[Tue Aug 18 12:57:20.857143 2026] [security2:error] [pid 67073:tid 67317] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/nwwha.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi7QAAAoQ"]
[Tue Aug 18 12:57:20.890802 2026] [authz_core:error] [pid 67073:tid 67084] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:20.891055 2026] [authz_core:error] [pid 67073:tid 67084] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:20.963286 2026] [security2:error] [pid 66623:tid 66780] [client 20.119.58.187:11206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/buy.php"] [unique_id "aoSA4NO5rbWdOArH04KSPQAAARg"]
[Tue Aug 18 12:57:20.963539 2026] [security2:error] [pid 67073:tid 67313] [client 20.226.56.190:31022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/uk.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi8AAAAoA"]
[Tue Aug 18 12:57:20.986570 2026] [security2:error] [pid 67073:tid 67255] [client 213.35.127.232:52767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi8wAAAkY"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:21.013978 2026] [security2:error] [pid 66623:tid 66814] [client 68.155.154.236:16377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSA4dO5rbWdOArH04KSTQAAATo"]
[Tue Aug 18 12:57:21.019301 2026] [security2:error] [pid 66623:tid 66822] [client 68.155.154.236:7898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSA4dO5rbWdOArH04KSTgAAAUI"]
[Tue Aug 18 12:57:21.020106 2026] [security2:error] [pid 67073:tid 67252] [client 132.196.30.78:19406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/themes.php"] [unique_id "aoSA4fcmepr5_nHgLbNi9QAAAkM"]
[Tue Aug 18 12:57:21.028552 2026] [security2:error] [pid 67073:tid 67198] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4fcmepr5_nHgLbNi9gACNHo"]
[Tue Aug 18 12:57:21.028699 2026] [security2:error] [pid 67073:tid 67237] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4fcmepr5_nHgLbNi9gACNHo"]
[Tue Aug 18 12:57:21.050155 2026] [security2:error] [pid 67073:tid 67332] [client 20.118.172.148:54860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/index/function.php"] [unique_id "aoSA4fcmepr5_nHgLbNi9wAAApM"]
[Tue Aug 18 12:57:21.101196 2026] [security2:error] [pid 66623:tid 66789] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/opsqt.php"] [unique_id "aoSA4dO5rbWdOArH04KSYAAAASE"]
[Tue Aug 18 12:57:21.109586 2026] [security2:error] [pid 67073:tid 67220] [client 68.155.155.199:1861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/t.php"] [unique_id "aoSA4fcmepr5_nHgLbNi-QAAAiM"]
[Tue Aug 18 12:57:21.131620 2026] [security2:error] [pid 67073:tid 67256] [client 20.100.169.31:14567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/chosen.php"] [unique_id "aoSA4fcmepr5_nHgLbNi-wAAAkc"]
[Tue Aug 18 12:57:21.189959 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:21.190212 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:21.214008 2026] [security2:error] [pid 67073:tid 67302] [client 172.182.200.96:14090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/lddxs.php"] [unique_id "aoSA4fcmepr5_nHgLbNjAQAAAnU"]
[Tue Aug 18 12:57:21.314821 2026] [security2:error] [pid 67073:tid 67226] [client 20.100.169.31:42195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/u.php"] [unique_id "aoSA4fcmepr5_nHgLbNjBgAAAik"]
[Tue Aug 18 12:57:21.319201 2026] [security2:error] [pid 66623:tid 66883] [client 20.119.58.187:11293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/bless.php"] [unique_id "aoSA4dO5rbWdOArH04KSZAAAAX8"]
[Tue Aug 18 12:57:21.336241 2026] [security2:error] [pid 66623:tid 66813] [client 40.74.65.169:27796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/8.php"] [unique_id "aoSA4dO5rbWdOArH04KSZQAAATk"]
[Tue Aug 18 12:57:21.397833 2026] [security2:error] [pid 66623:tid 66833] [client 74.248.18.37:57308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/ioxi-o.php"] [unique_id "aoSA4dO5rbWdOArH04KSZwAAAU0"]
[Tue Aug 18 12:57:21.421923 2026] [security2:error] [pid 66623:tid 66669] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4dO5rbWdOArH04KSaAABZiA"]
[Tue Aug 18 12:57:21.422121 2026] [security2:error] [pid 66623:tid 66858] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4dO5rbWdOArH04KSaAABZiA"]
[Tue Aug 18 12:57:21.435878 2026] [security2:error] [pid 67073:tid 67326] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/jvcpa.php"] [unique_id "aoSA4fcmepr5_nHgLbNjCgAAAo0"]
[Tue Aug 18 12:57:21.462367 2026] [security2:error] [pid 67073:tid 67285] [client 74.248.18.37:8052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/mini.php"] [unique_id "aoSA4fcmepr5_nHgLbNjDAAAAmQ"]
[Tue Aug 18 12:57:21.494680 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:21.494987 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:21.503041 2026] [security2:error] [pid 67073:tid 67221] [client 178.153.171.161:41402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4fcmepr5_nHgLbNjDgAAAiQ"]
[Tue Aug 18 12:57:21.503194 2026] [security2:error] [pid 67073:tid 67221] [client 178.153.171.161:41402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4fcmepr5_nHgLbNjDgAAAiQ"]
[Tue Aug 18 12:57:21.507303 2026] [security2:error] [pid 67073:tid 67283] [client 20.215.241.237:20380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSA4fcmepr5_nHgLbNjDwAAAmI"]
[Tue Aug 18 12:57:21.531507 2026] [security2:error] [pid 67073:tid 67268] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSA4fcmepr5_nHgLbNjEQAAAlM"]
[Tue Aug 18 12:57:21.541026 2026] [security2:error] [pid 67073:tid 67271] [client 20.65.98.162:58053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/copypaths.php"] [unique_id "aoSA4fcmepr5_nHgLbNjEgAAAlY"]
[Tue Aug 18 12:57:21.573292 2026] [security2:error] [pid 67073:tid 67323] [client 20.118.172.148:62460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wk/index.php"] [unique_id "aoSA4fcmepr5_nHgLbNjFAAAAoo"]
[Tue Aug 18 12:57:21.601644 2026] [security2:error] [pid 67073:tid 67261] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSA4fcmepr5_nHgLbNjFQAAAkw"]
[Tue Aug 18 12:57:21.629599 2026] [security2:error] [pid 67073:tid 67314] [client 68.155.154.236:46599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSA4fcmepr5_nHgLbNjGAAAAoE"]
[Tue Aug 18 12:57:21.630048 2026] [security2:error] [pid 66623:tid 66870] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSA4dO5rbWdOArH04KSawAAAXI"]
[Tue Aug 18 12:57:21.661344 2026] [security2:error] [pid 67073:tid 67210] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSA4fcmepr5_nHgLbNjGQAAAhk"]
[Tue Aug 18 12:57:21.721050 2026] [security2:error] [pid 66623:tid 66799] [client 68.155.154.236:16248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSA4dO5rbWdOArH04KSbQAAASs"]
[Tue Aug 18 12:57:21.730054 2026] [security2:error] [pid 67073:tid 67284] [client 20.119.58.187:11292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/class-t.api.php"] [unique_id "aoSA4fcmepr5_nHgLbNjHAAAAmM"]
[Tue Aug 18 12:57:21.755094 2026] [autoindex:error] [pid 67073:tid 67253] [client 20.1.169.243:5774] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:21.766533 2026] [security2:error] [pid 66623:tid 66866] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSA4dO5rbWdOArH04KSbgAAAW4"]
[Tue Aug 18 12:57:21.772955 2026] [security2:error] [pid 66623:tid 66889] [client 104.209.144.33:36543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSA4dO5rbWdOArH04KSbwAAAYU"]
[Tue Aug 18 12:57:21.874378 2026] [security2:error] [pid 66623:tid 66886] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSA4dO5rbWdOArH04KScAAAAYI"]
[Tue Aug 18 12:57:21.918791 2026] [security2:error] [pid 67073:tid 67205] [client 20.226.56.190:17909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/creds.php"] [unique_id "aoSA4fcmepr5_nHgLbNjIgAAAhQ"]
[Tue Aug 18 12:57:21.958212 2026] [security2:error] [pid 67073:tid 67235] [client 68.155.155.199:5070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/index/function.php"] [unique_id "aoSA4fcmepr5_nHgLbNjKwAAAjI"]
[Tue Aug 18 12:57:21.962009 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSA4fcmepr5_nHgLbNjLAAAAlg"]
[Tue Aug 18 12:57:21.986729 2026] [security2:error] [pid 67073:tid 67206] [client 135.225.75.187:45327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ae.php"] [unique_id "aoSA4fcmepr5_nHgLbNjLgAAAhU"]
[Tue Aug 18 12:57:22.000593 2026] [security2:error] [pid 67073:tid 67311] [client 213.35.127.232:53006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSA4fcmepr5_nHgLbNjLwAAAn4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:22.029976 2026] [security2:error] [pid 67073:tid 67299] [client 20.118.172.148:62114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-blink.php"] [unique_id "aoSA4vcmepr5_nHgLbNjMQAAAnI"]
[Tue Aug 18 12:57:22.072684 2026] [security2:error] [pid 67073:tid 67320] [client 132.196.30.78:18813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/cv.php"] [unique_id "aoSA4vcmepr5_nHgLbNjMgAAAoc"]
[Tue Aug 18 12:57:22.079358 2026] [security2:error] [pid 66623:tid 66777] [client 40.74.65.169:27822] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/1.php"] [unique_id "aoSA4tO5rbWdOArH04KScQAAARU"]
[Tue Aug 18 12:57:22.079480 2026] [security2:error] [pid 66623:tid 66777] [client 40.74.65.169:27822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/1.php"] [unique_id "aoSA4tO5rbWdOArH04KScQAAARU"]
[Tue Aug 18 12:57:22.081465 2026] [security2:error] [pid 67073:tid 67312] [client 20.119.58.187:11300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/cache.php"] [unique_id "aoSA4vcmepr5_nHgLbNjNAAAAn8"]
[Tue Aug 18 12:57:22.087159 2026] [security2:error] [pid 67073:tid 67309] [client 68.155.156.252:55664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/bajah.php"] [unique_id "aoSA4vcmepr5_nHgLbNjNQAAAnw"]
[Tue Aug 18 12:57:22.095514 2026] [authz_core:error] [pid 67073:tid 67089] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:22.095774 2026] [authz_core:error] [pid 67073:tid 67089] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:22.096081 2026] [security2:error] [pid 67073:tid 67217] [client 20.100.169.31:27957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSA4vcmepr5_nHgLbNjNwAAAiA"]
[Tue Aug 18 12:57:22.127333 2026] [security2:error] [pid 66623:tid 66816] [client 158.158.74.177:22738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-activate.php"] [unique_id "aoSA4tO5rbWdOArH04KScwAAATw"]
[Tue Aug 18 12:57:22.142857 2026] [security2:error] [pid 67073:tid 67240] [client 74.248.18.37:62080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/minishell.php"] [unique_id "aoSA4vcmepr5_nHgLbNjOQAAAjc"]
[Tue Aug 18 12:57:22.169855 2026] [security2:error] [pid 67073:tid 67251] [client 172.202.39.151:28680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSA4vcmepr5_nHgLbNjPAAAAkI"]
[Tue Aug 18 12:57:22.207467 2026] [security2:error] [pid 67073:tid 67327] [client 68.155.154.236:16286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/mt/byp.php"] [unique_id "aoSA4vcmepr5_nHgLbNjPgAAAo4"]
[Tue Aug 18 12:57:22.218341 2026] [security2:error] [pid 67073:tid 67306] [client 74.248.18.37:3700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/0x.php"] [unique_id "aoSA4vcmepr5_nHgLbNjPwAAAnk"]
[Tue Aug 18 12:57:22.218356 2026] [security2:error] [pid 67073:tid 67315] [client 20.215.241.237:28316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSA4vcmepr5_nHgLbNjQAAAAoI"]
[Tue Aug 18 12:57:22.271494 2026] [security2:error] [pid 67073:tid 67255] [client 20.226.56.190:20394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ho.php"] [unique_id "aoSA4vcmepr5_nHgLbNjQwAAAkY"]
[Tue Aug 18 12:57:22.335199 2026] [security2:error] [pid 67073:tid 67209] [client 85.154.68.202:53779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSA4vcmepr5_nHgLbNjRAAAAhg"]
[Tue Aug 18 12:57:22.335328 2026] [security2:error] [pid 67073:tid 67209] [client 85.154.68.202:53779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSA4vcmepr5_nHgLbNjRAAAAhg"]
[Tue Aug 18 12:57:22.373289 2026] [security2:error] [pid 67073:tid 67332] [client 104.209.144.33:34158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/mt/byp.php"] [unique_id "aoSA4vcmepr5_nHgLbNjRgAAApM"]
[Tue Aug 18 12:57:22.375785 2026] [security2:error] [pid 67073:tid 67214] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSA4vcmepr5_nHgLbNjRwAAAh0"]
[Tue Aug 18 12:57:22.398239 2026] [authz_core:error] [pid 67073:tid 67201] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:22.398499 2026] [authz_core:error] [pid 67073:tid 67201] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:22.434932 2026] [security2:error] [pid 67073:tid 67252] [client 20.119.58.187:11286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/content.php"] [unique_id "aoSA4vcmepr5_nHgLbNjSQAAAkM"]
[Tue Aug 18 12:57:22.474715 2026] [security2:error] [pid 67073:tid 67226] [client 20.118.172.148:56557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/xfun.php"] [unique_id "aoSA4vcmepr5_nHgLbNjSwAAAik"]
[Tue Aug 18 12:57:22.512854 2026] [security2:error] [pid 67073:tid 67247] [client 74.248.136.165:61398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ms-edit.php"] [unique_id "aoSA4vcmepr5_nHgLbNjTAAAAj4"]
[Tue Aug 18 12:57:22.530309 2026] [security2:error] [pid 66623:tid 66675] [remote 45.167.52.147:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.52.167.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imoveisbase.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4tO5rbWdOArH04KSdgABJCY"]
[Tue Aug 18 12:57:22.530474 2026] [security2:error] [pid 66623:tid 66792] [client 45.167.52.147:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "imoveisbase.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4tO5rbWdOArH04KSdgABJCY"]
[Tue Aug 18 12:57:22.544794 2026] [security2:error] [pid 67073:tid 67326] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSA4vcmepr5_nHgLbNjTwAAAo0"]
[Tue Aug 18 12:57:22.568957 2026] [security2:error] [pid 67073:tid 67133] [remote 57.141.22.101:49330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSA4vcmepr5_nHgLbNjUAAChjk"]
[Tue Aug 18 12:57:22.578620 2026] [security2:error] [pid 67073:tid 67270] [client 138.36.100.162:43238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4vcmepr5_nHgLbNjUQAAAlU"]
[Tue Aug 18 12:57:22.578716 2026] [security2:error] [pid 67073:tid 67270] [client 138.36.100.162:43238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4vcmepr5_nHgLbNjUQAAAlU"]
[Tue Aug 18 12:57:22.591867 2026] [security2:error] [pid 67073:tid 67221] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSA4vcmepr5_nHgLbNjUgAAAiQ"]
[Tue Aug 18 12:57:22.604683 2026] [security2:error] [pid 67073:tid 67323] [client 68.155.154.236:65527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSA4vcmepr5_nHgLbNjVgAAAoo"]
[Tue Aug 18 12:57:22.609430 2026] [security2:error] [pid 67073:tid 67331] [client 160.120.140.123:64949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4vcmepr5_nHgLbNjVwAAApI"]
[Tue Aug 18 12:57:22.609517 2026] [security2:error] [pid 67073:tid 67331] [client 160.120.140.123:64949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4vcmepr5_nHgLbNjVwAAApI"]
[Tue Aug 18 12:57:22.655321 2026] [security2:error] [pid 67073:tid 67293] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSA4vcmepr5_nHgLbNjWQAAAmw"]
[Tue Aug 18 12:57:22.722538 2026] [security2:error] [pid 67073:tid 67260] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSA4vcmepr5_nHgLbNjXgAAAks"]
[Tue Aug 18 12:57:22.748353 2026] [security2:error] [pid 66623:tid 66875] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSA4tO5rbWdOArH04KSegAAAXc"]
[Tue Aug 18 12:57:22.784172 2026] [security2:error] [pid 66623:tid 66868] [client 68.155.154.236:16262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSA4tO5rbWdOArH04KSfAAAAXA"]
[Tue Aug 18 12:57:22.795119 2026] [security2:error] [pid 67073:tid 67285] [client 74.248.18.37:8035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/mm.php"] [unique_id "aoSA4vcmepr5_nHgLbNjYwAAAmQ"]
[Tue Aug 18 12:57:22.811219 2026] [security2:error] [pid 67073:tid 67219] [client 40.74.65.169:7413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/about.php"] [unique_id "aoSA4vcmepr5_nHgLbNjZAAAAiI"]
[Tue Aug 18 12:57:22.822445 2026] [security2:error] [pid 67073:tid 67284] [client 20.119.58.187:11223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSA4vcmepr5_nHgLbNjZgAAAmM"]
[Tue Aug 18 12:57:22.832617 2026] [security2:error] [pid 67073:tid 67308] [client 20.206.73.37:11958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSA4vcmepr5_nHgLbNjZwAAAns"]
[Tue Aug 18 12:57:22.858078 2026] [security2:error] [pid 66623:tid 66770] [client 74.248.18.37:3079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/222.php"] [unique_id "aoSA4tO5rbWdOArH04KSfwAAAQ4"]
[Tue Aug 18 12:57:22.866967 2026] [security2:error] [pid 66623:tid 66803] [client 132.196.30.78:21829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSA4tO5rbWdOArH04KSgAAAAS8"]
[Tue Aug 18 12:57:22.877810 2026] [security2:error] [pid 67073:tid 67300] [client 68.155.155.199:3568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wk/index.php"] [unique_id "aoSA4vcmepr5_nHgLbNjaAAAAnM"]
[Tue Aug 18 12:57:22.894979 2026] [security2:error] [pid 67073:tid 67206] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSA4vcmepr5_nHgLbNjawAAAhU"]
[Tue Aug 18 12:57:22.962537 2026] [security2:error] [pid 67073:tid 67280] [client 20.226.56.190:3009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/97.php"] [unique_id "aoSA4vcmepr5_nHgLbNjbgAAAl8"]
[Tue Aug 18 12:57:22.981863 2026] [security2:error] [pid 66623:tid 66869] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSA4tO5rbWdOArH04KShAAAAXE"]
[Tue Aug 18 12:57:22.998007 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:22.998259 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:22.999407 2026] [security2:error] [pid 67073:tid 67320] [client 20.215.241.237:43393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSA4vcmepr5_nHgLbNjcgAAAoc"]
[Tue Aug 18 12:57:23.014499 2026] [security2:error] [pid 67073:tid 67243] [client 213.35.127.232:53253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSA4_cmepr5_nHgLbNjdAAAAjo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:23.024902 2026] [security2:error] [pid 67073:tid 67259] [client 158.158.74.177:2629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin.php"] [unique_id "aoSA4_cmepr5_nHgLbNjdQAAAko"]
[Tue Aug 18 12:57:23.148476 2026] [security2:error] [pid 67073:tid 67216] [client 172.202.39.151:50191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/epinyins.php"] [unique_id "aoSA4_cmepr5_nHgLbNjeQAAAh8"]
[Tue Aug 18 12:57:23.176432 2026] [security2:error] [pid 67073:tid 67240] [client 20.119.58.187:11270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/css.php"] [unique_id "aoSA4_cmepr5_nHgLbNjewAAAjc"]
[Tue Aug 18 12:57:23.281604 2026] [security2:error] [pid 67073:tid 67211] [client 20.250.13.23:25678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSA4_cmepr5_nHgLbNjggAAAho"]
[Tue Aug 18 12:57:23.290320 2026] [security2:error] [pid 67073:tid 67276] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSA4_cmepr5_nHgLbNjhAAAAls"]
[Tue Aug 18 12:57:23.343305 2026] [security2:error] [pid 66623:tid 66835] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSA49O5rbWdOArH04KSiwAAAU8"]
[Tue Aug 18 12:57:23.422887 2026] [security2:error] [pid 67073:tid 67332] [client 20.118.172.148:54894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/p.php"] [unique_id "aoSA4_cmepr5_nHgLbNjiAAAApM"]
[Tue Aug 18 12:57:23.429671 2026] [security2:error] [pid 67073:tid 67214] [client 20.65.98.162:9097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/bless6.php"] [unique_id "aoSA4_cmepr5_nHgLbNjiwAAAh0"]
[Tue Aug 18 12:57:23.429898 2026] [security2:error] [pid 67073:tid 67322] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSA4_cmepr5_nHgLbNjjAAAAok"]
[Tue Aug 18 12:57:23.491559 2026] [security2:error] [pid 66623:tid 66879] [client 74.248.18.37:3085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/aa.php"] [unique_id "aoSA49O5rbWdOArH04KSjQAAAXs"]
[Tue Aug 18 12:57:23.530892 2026] [security2:error] [pid 67073:tid 67252] [client 20.226.56.190:31010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/rh.php"] [unique_id "aoSA4_cmepr5_nHgLbNjlAAAAkM"]
[Tue Aug 18 12:57:23.531131 2026] [security2:error] [pid 66623:tid 66802] [client 20.119.58.187:11214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/chosen.php"] [unique_id "aoSA49O5rbWdOArH04KSjwAAAS4"]
[Tue Aug 18 12:57:23.561022 2026] [security2:error] [pid 67073:tid 67224] [client 74.248.18.37:8053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/ms-edit.php"] [unique_id "aoSA4_cmepr5_nHgLbNjmAAAAic"]
[Tue Aug 18 12:57:23.599391 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:23.599651 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:23.632264 2026] [security2:error] [pid 66623:tid 66769] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSA49O5rbWdOArH04KSkQAAAQ0"]
[Tue Aug 18 12:57:23.650113 2026] [security2:error] [pid 67073:tid 67326] [client 40.74.65.169:42566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/admin.php"] [unique_id "aoSA4_cmepr5_nHgLbNjnAAAAo0"]
[Tue Aug 18 12:57:23.660997 2026] [security2:error] [pid 66623:tid 66852] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSA49O5rbWdOArH04KSlQAAAWA"]
[Tue Aug 18 12:57:23.687414 2026] [security2:error] [pid 67073:tid 67328] [client 20.48.236.86:40694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA4_cmepr5_nHgLbNjnQAAAo8"]
[Tue Aug 18 12:57:23.722600 2026] [security2:error] [pid 66623:tid 66776] [client 20.215.241.237:20395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/media.php"] [unique_id "aoSA49O5rbWdOArH04KSlwAAARQ"]
[Tue Aug 18 12:57:23.799787 2026] [security2:error] [pid 67073:tid 67241] [client 68.155.154.236:65515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSA4_cmepr5_nHgLbNjoAAAAjg"]
[Tue Aug 18 12:57:23.808354 2026] [security2:error] [pid 67073:tid 67323] [client 68.155.154.236:16251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSA4_cmepr5_nHgLbNjogAAAoo"]
[Tue Aug 18 12:57:23.815346 2026] [security2:error] [pid 66623:tid 66822] [client 68.155.155.199:7375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-blink.php"] [unique_id "aoSA49O5rbWdOArH04KSmAAAAUI"]
[Tue Aug 18 12:57:23.829140 2026] [security2:error] [pid 67073:tid 67319] [client 192.141.172.134:63781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSA4_cmepr5_nHgLbNjowAAAoY"]
[Tue Aug 18 12:57:23.829292 2026] [security2:error] [pid 67073:tid 67319] [client 192.141.172.134:63781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSA4_cmepr5_nHgLbNjowAAAoY"]
[Tue Aug 18 12:57:23.874661 2026] [security2:error] [pid 67073:tid 67314] [client 20.118.172.148:52255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSA4_cmepr5_nHgLbNjpQAAAoE"]
[Tue Aug 18 12:57:23.878334 2026] [security2:error] [pid 67073:tid 67207] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSA4_cmepr5_nHgLbNjpgAAAhY"]
[Tue Aug 18 12:57:23.900075 2026] [authz_core:error] [pid 67073:tid 67199] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:23.900479 2026] [authz_core:error] [pid 67073:tid 67199] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:23.941678 2026] [security2:error] [pid 66623:tid 66785] [client 74.248.136.165:22485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ws79.php"] [unique_id "aoSA49O5rbWdOArH04KSmQAAAR0"]
[Tue Aug 18 12:57:23.960544 2026] [security2:error] [pid 67073:tid 67261] [client 20.119.58.187:11212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/doc.php"] [unique_id "aoSA4_cmepr5_nHgLbNjrQAAAkw"]
[Tue Aug 18 12:57:23.989991 2026] [security2:error] [pid 67073:tid 67221] [client 79.127.164.8:52274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/mysql.bak"] [unique_id "aoSA4_cmepr5_nHgLbNjrgAAAiQ"], referer: https://medihub.com.br/mysql.bak
[Tue Aug 18 12:57:23.990233 2026] [security2:error] [pid 67073:tid 67242] [client 20.100.169.31:16144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSA4_cmepr5_nHgLbNjrwAAAjk"]
[Tue Aug 18 12:57:24.029190 2026] [security2:error] [pid 67073:tid 67305] [client 213.35.127.232:53456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjsgAAAng"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:24.041461 2026] [security2:error] [pid 67073:tid 67235] [client 68.155.156.252:51514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/domvf.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjswAAAjI"]
[Tue Aug 18 12:57:24.045001 2026] [security2:error] [pid 67073:tid 67258] [client 172.182.200.96:14111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/zjggu.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjtAAAAkk"]
[Tue Aug 18 12:57:24.137078 2026] [security2:error] [pid 67073:tid 67260] [client 132.196.30.78:22518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/ws83.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjugAAAks"]
[Tue Aug 18 12:57:24.144570 2026] [authz_core:error] [pid 67073:tid 67151] [remote 57.141.22.37:59990] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:24.144991 2026] [authz_core:error] [pid 67073:tid 67151] [remote 57.141.22.37:59990] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:24.186344 2026] [security2:error] [pid 67073:tid 67257] [client 74.248.18.37:27501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/abcd.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjvQAAAkg"]
[Tue Aug 18 12:57:24.199706 2026] [authz_core:error] [pid 67073:tid 67193] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:24.199969 2026] [authz_core:error] [pid 67073:tid 67193] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:24.203519 2026] [security2:error] [pid 66623:tid 66789] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSA5NO5rbWdOArH04KSnAAAASE"]
[Tue Aug 18 12:57:24.230945 2026] [security2:error] [pid 67073:tid 67262] [client 74.248.18.37:31844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/ms-themes.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjwgAAAk0"]
[Tue Aug 18 12:57:24.292287 2026] [security2:error] [pid 67073:tid 67236] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjxAAAAjM"]
[Tue Aug 18 12:57:24.314312 2026] [security2:error] [pid 67073:tid 67309] [client 20.119.58.187:11305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/elp.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjxgAAAnw"]
[Tue Aug 18 12:57:24.368449 2026] [security2:error] [pid 67073:tid 67267] [client 20.206.73.37:59848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/mgrr.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjyAAAAlI"]
[Tue Aug 18 12:57:24.449953 2026] [security2:error] [pid 67073:tid 67282] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjzQAAAmE"]
[Tue Aug 18 12:57:24.463842 2026] [security2:error] [pid 67073:tid 67255] [client 68.155.155.199:13312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/xfun.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjzgAAAkY"]
[Tue Aug 18 12:57:24.466109 2026] [security2:error] [pid 67073:tid 67294] [client 20.215.241.237:28300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/inso.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjzwAAAm0"]
[Tue Aug 18 12:57:24.502775 2026] [security2:error] [pid 67073:tid 67215] [client 68.155.154.236:40263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj0wAAAh4"]
[Tue Aug 18 12:57:24.503553 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:24.503817 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:24.507568 2026] [security2:error] [pid 67073:tid 67286] [client 40.74.65.169:43161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/edit.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj1QAAAmU"]
[Tue Aug 18 12:57:24.534853 2026] [security2:error] [pid 67073:tid 67248] [client 20.118.172.148:62138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/aaa.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj1wAAAj8"]
[Tue Aug 18 12:57:24.549868 2026] [security2:error] [pid 66623:tid 66858] [client 20.226.56.190:45020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/yg.php"] [unique_id "aoSA5NO5rbWdOArH04KSnwAAAWY"]
[Tue Aug 18 12:57:24.571948 2026] [security2:error] [pid 66623:tid 66850] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSA5NO5rbWdOArH04KSoAAAAV4"]
[Tue Aug 18 12:57:24.588152 2026] [security2:error] [pid 66623:tid 66817] [client 40.85.222.29:44790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA5NO5rbWdOArH04KSowAAAT0"]
[Tue Aug 18 12:57:24.591889 2026] [security2:error] [pid 67073:tid 67213] [client 202.63.210.218:56299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.210.63.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "icemaq.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjygAAAhw"]
[Tue Aug 18 12:57:24.591989 2026] [security2:error] [pid 67073:tid 67213] [client 202.63.210.218:56299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "icemaq.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjygAAAhw"]
[Tue Aug 18 12:57:24.594123 2026] [security2:error] [pid 67073:tid 67290] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj2gAAAmk"]
[Tue Aug 18 12:57:24.614846 2026] [security2:error] [pid 67073:tid 67212] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj3AAAAhs"]
[Tue Aug 18 12:57:24.637996 2026] [security2:error] [pid 66623:tid 66786] [client 172.202.39.151:48243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSA5NO5rbWdOArH04KSpAAAAR4"]
[Tue Aug 18 12:57:24.665473 2026] [security2:error] [pid 66623:tid 66833] [client 20.119.58.187:11261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/Exception-class.php"] [unique_id "aoSA5NO5rbWdOArH04KSpgAAAU0"]
[Tue Aug 18 12:57:24.686315 2026] [security2:error] [pid 66623:tid 66799] [client 68.155.154.236:16277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSA5NO5rbWdOArH04KSqQAAASs"]
[Tue Aug 18 12:57:24.714577 2026] [security2:error] [pid 67073:tid 67223] [client 158.158.34.183:57391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/gebase.php69"] [unique_id "aoSA5Pcmepr5_nHgLbNj3wAAAiY"]
[Tue Aug 18 12:57:24.717148 2026] [security2:error] [pid 67073:tid 67304] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj4AAAAnc"]
[Tue Aug 18 12:57:24.743317 2026] [security2:error] [pid 67073:tid 67270] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj4wAAAlU"]
[Tue Aug 18 12:57:24.754883 2026] [security2:error] [pid 67073:tid 67214] [client 132.196.30.78:21913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/atex1.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj5AAAAh0"]
[Tue Aug 18 12:57:24.763054 2026] [security2:error] [pid 67073:tid 67231] [client 157.51.166.53:65039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj5wAAAi4"]
[Tue Aug 18 12:57:24.772566 2026] [security2:error] [pid 67073:tid 67231] [client 157.51.166.53:65039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj5wAAAi4"]
[Tue Aug 18 12:57:24.804872 2026] [authz_core:error] [pid 67073:tid 67132] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:24.805209 2026] [authz_core:error] [pid 67073:tid 67132] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:24.817905 2026] [security2:error] [pid 66623:tid 66827] [client 74.248.18.37:3124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/admin.php"] [unique_id "aoSA5NO5rbWdOArH04KSqgAAAUc"]
[Tue Aug 18 12:57:24.851408 2026] [security2:error] [pid 67073:tid 67293] [client 20.118.133.132:1236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/aa.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj6wAAAmw"]
[Tue Aug 18 12:57:24.880146 2026] [security2:error] [pid 66623:tid 66807] [client 74.248.18.37:62100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/my1.php"] [unique_id "aoSA5NO5rbWdOArH04KSqwAAATM"]
[Tue Aug 18 12:57:24.882157 2026] [security2:error] [pid 66623:tid 66781] [client 20.118.172.148:54857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/term.php"] [unique_id "aoSA5NO5rbWdOArH04KSrAAAARk"]
[Tue Aug 18 12:57:24.954471 2026] [security2:error] [pid 66623:tid 66816] [client 40.85.222.29:44761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA5NO5rbWdOArH04KSrwAAATw"]
[Tue Aug 18 12:57:24.967118 2026] [security2:error] [pid 67073:tid 67261] [client 104.209.144.33:17238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/MTOS/byp.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj9gAAAkw"]
[Tue Aug 18 12:57:24.999961 2026] [security2:error] [pid 67073:tid 67227] [client 213.202.253.4:56311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/schallfuns.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj9wAAAio"], referer: www.google.com
[Tue Aug 18 12:57:25.000791 2026] [security2:error] [pid 67073:tid 67326] [client 20.100.169.31:39848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/vx.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj-AAAAo0"]
[Tue Aug 18 12:57:25.015373 2026] [security2:error] [pid 66623:tid 66811] [client 5.188.86.234:57388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.86.188.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.maxxbox.ind.br"] [uri "/wp-login.php"] [unique_id "aoSA5dO5rbWdOArH04KSsAAAATc"]
[Tue Aug 18 12:57:25.018596 2026] [security2:error] [pid 66623:tid 66857] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSA5dO5rbWdOArH04KSsQAAAWU"]
[Tue Aug 18 12:57:25.034608 2026] [security2:error] [pid 66623:tid 66777] [client 20.119.58.187:11460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/ee.php"] [unique_id "aoSA5dO5rbWdOArH04KSsgAAARU"]
[Tue Aug 18 12:57:25.041702 2026] [security2:error] [pid 67073:tid 67239] [client 213.35.127.232:53688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA5fcmepr5_nHgLbNj_AAAAjY"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:25.047024 2026] [security2:error] [pid 66623:tid 66845] [client 68.155.155.199:6630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/p.php"] [unique_id "aoSA5dO5rbWdOArH04KSswAAAVk"]
[Tue Aug 18 12:57:25.156730 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSA5fcmepr5_nHgLbNkCwAAAlg"]
[Tue Aug 18 12:57:25.168986 2026] [security2:error] [pid 66623:tid 66801] [client 68.155.154.236:8043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSA5dO5rbWdOArH04KStgAAAS0"]
[Tue Aug 18 12:57:25.187010 2026] [security2:error] [pid 67073:tid 67206] [client 74.248.136.165:55233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/rtx.php"] [unique_id "aoSA5fcmepr5_nHgLbNkDAAAAhU"]
[Tue Aug 18 12:57:25.187030 2026] [security2:error] [pid 66623:tid 66832] [client 172.182.200.96:7636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/.cache/x.php"] [unique_id "aoSA5dO5rbWdOArH04KStwAAAUw"]
[Tue Aug 18 12:57:25.187894 2026] [security2:error] [pid 67073:tid 67289] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSA5fcmepr5_nHgLbNkDQAAAmg"]
[Tue Aug 18 12:57:25.189421 2026] [security2:error] [pid 66623:tid 66875] [client 20.226.56.190:3024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/et.php"] [unique_id "aoSA5dO5rbWdOArH04KSuAAAAXc"]
[Tue Aug 18 12:57:25.228560 2026] [security2:error] [pid 67073:tid 67244] [client 40.74.65.169:27744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-content/admin.php"] [unique_id "aoSA5fcmepr5_nHgLbNkDwAAAjs"]
[Tue Aug 18 12:57:25.244019 2026] [security2:error] [pid 67073:tid 67260] [client 68.155.154.236:16362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSA5fcmepr5_nHgLbNkEAAAAks"]
[Tue Aug 18 12:57:25.254658 2026] [security2:error] [pid 67073:tid 67301] [client 40.85.222.29:44239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/weozh.php"] [unique_id "aoSA5fcmepr5_nHgLbNkEQAAAnQ"]
[Tue Aug 18 12:57:25.395414 2026] [security2:error] [pid 66623:tid 66784] [client 20.119.58.187:11249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/edit.php"] [unique_id "aoSA5dO5rbWdOArH04KSuwAAARw"]
[Tue Aug 18 12:57:25.432745 2026] [security2:error] [pid 67073:tid 67234] [client 20.215.241.237:8012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/shiny.php"] [unique_id "aoSA5fcmepr5_nHgLbNkHAAAAjE"]
[Tue Aug 18 12:57:25.449251 2026] [security2:error] [pid 67073:tid 67230] [client 20.100.169.31:37653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/h.php"] [unique_id "aoSA5fcmepr5_nHgLbNkHgAAAi0"]
[Tue Aug 18 12:57:25.516733 2026] [security2:error] [pid 66623:tid 66829] [client 20.118.172.148:62082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/7.php"] [unique_id "aoSA5dO5rbWdOArH04KSvwAAAUk"]
[Tue Aug 18 12:57:25.524763 2026] [security2:error] [pid 67073:tid 67306] [client 158.158.74.177:16538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/about.php"] [unique_id "aoSA5fcmepr5_nHgLbNkIQAAAnk"]
[Tue Aug 18 12:57:25.530484 2026] [security2:error] [pid 67073:tid 67324] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSA5fcmepr5_nHgLbNkIgAAAos"]
[Tue Aug 18 12:57:25.531178 2026] [security2:error] [pid 67073:tid 67211] [client 40.85.222.29:44228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/rymmm.php"] [unique_id "aoSA5fcmepr5_nHgLbNkIwAAAho"]
[Tue Aug 18 12:57:25.541791 2026] [security2:error] [pid 67073:tid 67317] [client 172.202.39.151:44919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/ok.php"] [unique_id "aoSA5fcmepr5_nHgLbNkJAAAAoQ"]
[Tue Aug 18 12:57:25.553709 2026] [security2:error] [pid 66623:tid 66767] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSA5dO5rbWdOArH04KSwwAAAQs"]
[Tue Aug 18 12:57:25.569106 2026] [security2:error] [pid 66623:tid 66840] [client 68.155.154.236:48936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSA5dO5rbWdOArH04KSxAAAAVQ"]
[Tue Aug 18 12:57:25.576333 2026] [security2:error] [pid 67073:tid 67320] [client 74.248.18.37:62097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/new.php"] [unique_id "aoSA5fcmepr5_nHgLbNkJQAAAoc"]
[Tue Aug 18 12:57:25.668941 2026] [security2:error] [pid 67073:tid 67256] [client 74.248.18.37:27476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/adminfuns.php"] [unique_id "aoSA5fcmepr5_nHgLbNkKAAAAkc"]
[Tue Aug 18 12:57:25.680138 2026] [security2:error] [pid 66623:tid 66830] [client 20.206.73.37:59885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/55.php"] [unique_id "aoSA5dO5rbWdOArH04KSxgAAAUo"]
[Tue Aug 18 12:57:25.693238 2026] [security2:error] [pid 67073:tid 67251] [client 132.196.30.78:19405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/class-t.api.php"] [unique_id "aoSA5fcmepr5_nHgLbNkKgAAAkI"]
[Tue Aug 18 12:57:25.706531 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:25.706804 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:25.741527 2026] [security2:error] [pid 66623:tid 66772] [client 196.12.128.158:53968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA5dO5rbWdOArH04KSyQAAARA"]
[Tue Aug 18 12:57:25.741639 2026] [security2:error] [pid 66623:tid 66772] [client 196.12.128.158:53968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA5dO5rbWdOArH04KSyQAAARA"]
[Tue Aug 18 12:57:25.748521 2026] [security2:error] [pid 67073:tid 67295] [client 20.119.58.187:11250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/f35.php"] [unique_id "aoSA5fcmepr5_nHgLbNkLAAAAm4"]
[Tue Aug 18 12:57:25.823487 2026] [security2:error] [pid 66623:tid 66769] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSA5dO5rbWdOArH04KSygAAAQ0"]
[Tue Aug 18 12:57:25.851709 2026] [security2:error] [pid 66623:tid 66848] [client 68.155.154.236:16326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSA5dO5rbWdOArH04KSzAAAAVw"]
[Tue Aug 18 12:57:25.914890 2026] [security2:error] [pid 67073:tid 67223] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5fcmepr5_nHgLbNkNQACJhI"]
[Tue Aug 18 12:57:25.937544 2026] [security2:error] [pid 66623:tid 66852] [client 20.118.172.148:54890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/file5.php"] [unique_id "aoSA5dO5rbWdOArH04KS0AAAAWA"]
[Tue Aug 18 12:57:25.958926 2026] [security2:error] [pid 67073:tid 67307] [client 40.74.65.169:27022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/inputs.php"] [unique_id "aoSA5fcmepr5_nHgLbNkPAAAAno"]
[Tue Aug 18 12:57:26.008371 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:26.008637 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:26.055095 2026] [security2:error] [pid 66623:tid 66860] [client 213.35.127.232:53908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA5tO5rbWdOArH04KS0gAAAWg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:26.061158 2026] [security2:error] [pid 66623:tid 66805] [client 20.226.56.190:19367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/of.php"] [unique_id "aoSA5tO5rbWdOArH04KS0wAAATE"]
[Tue Aug 18 12:57:26.078342 2026] [security2:error] [pid 66623:tid 66837] [client 68.155.155.199:7402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSA5tO5rbWdOArH04KS1AAAAVE"]
[Tue Aug 18 12:57:26.081439 2026] [security2:error] [pid 66623:tid 66841] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSA5tO5rbWdOArH04KS1QAAAVU"]
[Tue Aug 18 12:57:26.108270 2026] [security2:error] [pid 66623:tid 66882] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSA5tO5rbWdOArH04KS1wAAAX4"]
[Tue Aug 18 12:57:26.132863 2026] [security2:error] [pid 66623:tid 66855] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSA5tO5rbWdOArH04KS2AAAAWM"]
[Tue Aug 18 12:57:26.150918 2026] [security2:error] [pid 66623:tid 66779] [client 20.119.58.187:11246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/fff.php"] [unique_id "aoSA5tO5rbWdOArH04KS2QAAARc"]
[Tue Aug 18 12:57:26.157992 2026] [security2:error] [pid 67073:tid 67245] [client 68.155.154.236:51393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSA5vcmepr5_nHgLbNkQwAAAjw"]
[Tue Aug 18 12:57:26.181048 2026] [security2:error] [pid 66623:tid 66844] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/rezor.php"] [unique_id "aoSA5tO5rbWdOArH04KS2gAAAVg"]
[Tue Aug 18 12:57:26.185472 2026] [security2:error] [pid 67073:tid 67319] [client 20.206.73.37:63242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/ajax.php"] [unique_id "aoSA5vcmepr5_nHgLbNkRAAAAoY"]
[Tue Aug 18 12:57:26.208030 2026] [authz_core:error] [pid 67073:tid 67179] [remote 57.141.22.92:28164] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:26.208319 2026] [authz_core:error] [pid 67073:tid 67179] [remote 57.141.22.92:28164] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:26.241263 2026] [security2:error] [pid 67073:tid 67231] [client 74.248.18.37:8033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/norn.php"] [unique_id "aoSA5vcmepr5_nHgLbNkSQAAAi4"]
[Tue Aug 18 12:57:26.258826 2026] [security2:error] [pid 67073:tid 67287] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSA5vcmepr5_nHgLbNkSwAAAmY"]
[Tue Aug 18 12:57:26.298140 2026] [security2:error] [pid 66623:tid 66873] [client 74.248.18.37:3106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/akc.php"] [unique_id "aoSA5tO5rbWdOArH04KS3AAAAXU"]
[Tue Aug 18 12:57:26.399917 2026] [security2:error] [pid 66623:tid 66877] [client 158.158.74.177:22727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSA5tO5rbWdOArH04KS4AAAAXk"]
[Tue Aug 18 12:57:26.413998 2026] [security2:error] [pid 66623:tid 66810] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSA5tO5rbWdOArH04KS4QAAATY"]
[Tue Aug 18 12:57:26.426545 2026] [security2:error] [pid 66623:tid 66774] [client 20.118.172.148:54892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSA5tO5rbWdOArH04KS4wAAARI"]
[Tue Aug 18 12:57:26.428035 2026] [security2:error] [pid 66623:tid 66799] [client 40.74.65.169:4418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA5tO5rbWdOArH04KS5AAAASs"]
[Tue Aug 18 12:57:26.440294 2026] [security2:error] [pid 67073:tid 67321] [client 158.158.34.183:42593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/akcc.php"] [unique_id "aoSA5vcmepr5_nHgLbNkUQAAAog"]
[Tue Aug 18 12:57:26.493314 2026] [security2:error] [pid 66623:tid 66819] [client 20.215.241.237:38231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/403dd.php"] [unique_id "aoSA5tO5rbWdOArH04KS5gAAAT8"]
[Tue Aug 18 12:57:26.502112 2026] [security2:error] [pid 66623:tid 66889] [client 172.202.39.151:30090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/item.php"] [unique_id "aoSA5tO5rbWdOArH04KS5wAAAYU"]
[Tue Aug 18 12:57:26.507109 2026] [security2:error] [pid 66623:tid 66876] [client 20.119.58.187:11231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/ff1.php"] [unique_id "aoSA5tO5rbWdOArH04KS6AAAAXg"]
[Tue Aug 18 12:57:26.553886 2026] [security2:error] [pid 66623:tid 66806] [client 20.226.56.190:31027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/bu.php"] [unique_id "aoSA5tO5rbWdOArH04KS6QAAATI"]
[Tue Aug 18 12:57:26.570964 2026] [security2:error] [pid 66623:tid 66807] [client 68.155.154.236:16375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSA5tO5rbWdOArH04KS6gAAATM"]
[Tue Aug 18 12:57:26.595405 2026] [security2:error] [pid 67073:tid 67305] [client 68.155.154.236:7668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSA5vcmepr5_nHgLbNkVAAAAng"]
[Tue Aug 18 12:57:26.612393 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:26.612661 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:26.622351 2026] [security2:error] [pid 67073:tid 67081] [remote 5.188.86.234:54814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.86.188.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.maxxbox.ind.br"] [uri "/wp-login.php"] [unique_id "aoSA5vcmepr5_nHgLbNkVwACJAU"]
[Tue Aug 18 12:57:26.659105 2026] [security2:error] [pid 67073:tid 67311] [client 40.74.65.169:30021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/av.php"] [unique_id "aoSA5vcmepr5_nHgLbNkWQAAAn4"]
[Tue Aug 18 12:57:26.701502 2026] [security2:error] [pid 67073:tid 67260] [client 20.206.73.37:11445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/yj09.php"] [unique_id "aoSA5vcmepr5_nHgLbNkWwAAAks"]
[Tue Aug 18 12:57:26.708661 2026] [security2:error] [pid 67073:tid 67328] [client 197.184.64.235:41936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5vcmepr5_nHgLbNkXQAAAo8"]
[Tue Aug 18 12:57:26.708747 2026] [security2:error] [pid 67073:tid 67328] [client 197.184.64.235:41936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5vcmepr5_nHgLbNkXQAAAo8"]
[Tue Aug 18 12:57:26.721500 2026] [security2:error] [pid 67073:tid 67257] [client 40.85.222.29:44769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/lddxs.php"] [unique_id "aoSA5vcmepr5_nHgLbNkXgAAAkg"]
[Tue Aug 18 12:57:26.742265 2026] [security2:error] [pid 67073:tid 67217] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/index/function.php"] [unique_id "aoSA5vcmepr5_nHgLbNkYAAAAiA"]
[Tue Aug 18 12:57:26.782002 2026] [security2:error] [pid 67073:tid 67309] [client 20.118.172.148:62436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSA5vcmepr5_nHgLbNkYwAAAnw"]
[Tue Aug 18 12:57:26.811208 2026] [security2:error] [pid 67073:tid 67234] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSA5vcmepr5_nHgLbNkaAAAAjE"]
[Tue Aug 18 12:57:26.820974 2026] [security2:error] [pid 67073:tid 67310] [client 132.196.30.78:21866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/w.php"] [unique_id "aoSA5vcmepr5_nHgLbNkaQAAAn0"]
[Tue Aug 18 12:57:26.863038 2026] [security2:error] [pid 67073:tid 67259] [client 20.119.58.187:11211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/flower.php"] [unique_id "aoSA5vcmepr5_nHgLbNkagAAAko"]
[Tue Aug 18 12:57:26.878126 2026] [security2:error] [pid 67073:tid 67228] [client 74.248.18.37:20492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/num.php"] [unique_id "aoSA5vcmepr5_nHgLbNkbAAAAis"]
[Tue Aug 18 12:57:26.878638 2026] [security2:error] [pid 67073:tid 67250] [client 20.226.56.190:52092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/rn.php"] [unique_id "aoSA5vcmepr5_nHgLbNkbQAAAkE"]
[Tue Aug 18 12:57:26.967542 2026] [security2:error] [pid 67073:tid 67215] [client 74.248.136.165:61392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/end.php"] [unique_id "aoSA5vcmepr5_nHgLbNkcwAAAh4"]
[Tue Aug 18 12:57:26.974706 2026] [security2:error] [pid 67073:tid 67327] [client 114.119.142.14:56999] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mudancassilvano.com.br"] [uri "/orcamento-m%C2%B3"] [unique_id "aoSA5vcmepr5_nHgLbNkdAAAAo4"], referer: https://mudancassilvano.com.br/orcamento-m%C2%B3?gclid=EAIaIQobChMI75mKzIb66gIVQweRCh28GwN-EAAYASACEgK8NfD_BwE&cf_pg=6
[Tue Aug 18 12:57:26.976027 2026] [security2:error] [pid 67073:tid 67264] [client 20.250.13.23:47032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wso.php"] [unique_id "aoSA5vcmepr5_nHgLbNkdQAAAk8"]
[Tue Aug 18 12:57:27.001514 2026] [security2:error] [pid 67073:tid 67332] [client 40.85.222.29:44244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/zjggu.php"] [unique_id "aoSA5_cmepr5_nHgLbNkdgAAApM"]
[Tue Aug 18 12:57:27.027833 2026] [security2:error] [pid 67073:tid 67216] [client 68.155.154.236:8036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSA5_cmepr5_nHgLbNkdwAAAh8"]
[Tue Aug 18 12:57:27.056311 2026] [security2:error] [pid 66623:tid 66875] [client 20.100.169.31:16437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wap.php"] [unique_id "aoSA59O5rbWdOArH04KS8wAAAXc"]
[Tue Aug 18 12:57:27.057354 2026] [security2:error] [pid 67073:tid 67296] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/Cachex.php"] [unique_id "aoSA5_cmepr5_nHgLbNkeQAAAm8"]
[Tue Aug 18 12:57:27.069132 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:27.069416 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:27.072615 2026] [security2:error] [pid 67073:tid 67288] [client 213.35.127.232:54164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSA5_cmepr5_nHgLbNkewAAAmc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:27.101650 2026] [security2:error] [pid 67073:tid 67306] [client 74.248.18.37:27494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/buy.php"] [unique_id "aoSA5_cmepr5_nHgLbNkfAAAAnk"]
[Tue Aug 18 12:57:27.117815 2026] [security2:error] [pid 66623:tid 66771] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSA59O5rbWdOArH04KS9AAAAQ8"]
[Tue Aug 18 12:57:27.122625 2026] [security2:error] [pid 66623:tid 66868] [client 40.74.65.169:4804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA59O5rbWdOArH04KS9gAAAXA"]
[Tue Aug 18 12:57:27.144196 2026] [security2:error] [pid 67073:tid 67263] [client 20.118.172.148:62437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSA5_cmepr5_nHgLbNkgAAAAk4"]
[Tue Aug 18 12:57:27.231355 2026] [security2:error] [pid 67073:tid 67308] [client 168.119.123.75:22692] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.petceu.com.br"] [uri "/index.php"] [unique_id "aoSA5vcmepr5_nHgLbNkZAAAAns"], referer: https://www.petceu.com.br
[Tue Aug 18 12:57:27.247364 2026] [security2:error] [pid 66623:tid 66784] [client 20.119.58.187:11271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/file.php"] [unique_id "aoSA59O5rbWdOArH04KS-AAAARw"]
[Tue Aug 18 12:57:27.254552 2026] [security2:error] [pid 66623:tid 66851] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-2019.php"] [unique_id "aoSA59O5rbWdOArH04KS-QAAAV8"]
[Tue Aug 18 12:57:27.354965 2026] [security2:error] [pid 67073:tid 67247] [client 40.85.222.29:44231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/dlvqo.php"] [unique_id "aoSA5_cmepr5_nHgLbNkhgAAAj4"]
[Tue Aug 18 12:57:27.378596 2026] [security2:error] [pid 67073:tid 67283] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSA5_cmepr5_nHgLbNkhwAAAmI"]
[Tue Aug 18 12:57:27.409946 2026] [security2:error] [pid 67073:tid 67172] [remote 203.99.146.53:51426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/wp-login.php"] [unique_id "aoSA5_cmepr5_nHgLbNkiAACL2A"]
[Tue Aug 18 12:57:27.410348 2026] [security2:error] [pid 67073:tid 67231] [client 40.74.65.169:11204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/classwithtostring.php"] [unique_id "aoSA5_cmepr5_nHgLbNkiQAAAi4"]
[Tue Aug 18 12:57:27.439692 2026] [security2:error] [pid 67073:tid 67238] [client 68.155.154.236:7627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSA5_cmepr5_nHgLbNkiwAAAjU"]
[Tue Aug 18 12:57:27.444875 2026] [security2:error] [pid 67073:tid 67224] [client 132.196.30.78:21831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/archive.php"] [unique_id "aoSA5_cmepr5_nHgLbNkjAAAAic"]
[Tue Aug 18 12:57:27.455030 2026] [security2:error] [pid 67073:tid 67318] [client 104.209.144.33:20465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSA5_cmepr5_nHgLbNkjQAAAoU"]
[Tue Aug 18 12:57:27.473154 2026] [security2:error] [pid 67073:tid 67240] [client 20.118.172.148:62130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/atomlib.php"] [unique_id "aoSA5_cmepr5_nHgLbNkjgAAAjc"]
[Tue Aug 18 12:57:27.483573 2026] [security2:error] [pid 67073:tid 67148] [remote 129.121.103.155:49258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "serviplascomercio.com.br"] [uri "/wp-login.php"] [unique_id "aoSA5_cmepr5_nHgLbNkjwACV0g"]
[Tue Aug 18 12:57:27.485284 2026] [security2:error] [pid 67073:tid 67253] [client 20.48.236.86:48725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA5_cmepr5_nHgLbNkkAAAAkQ"]
[Tue Aug 18 12:57:27.515040 2026] [authz_core:error] [pid 67073:tid 67112] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:27.515309 2026] [authz_core:error] [pid 67073:tid 67112] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:27.526116 2026] [security2:error] [pid 67073:tid 67214] [client 74.248.18.37:62131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/options-reading.php"] [unique_id "aoSA5_cmepr5_nHgLbNkkwAAAh0"]
[Tue Aug 18 12:57:27.527204 2026] [security2:error] [pid 67073:tid 67208] [client 79.127.164.8:47078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/mysql.sql"] [unique_id "aoSA5_cmepr5_nHgLbNklAAAAhc"], referer: https://medihub.com.br/mysql.sql
[Tue Aug 18 12:57:27.571872 2026] [security2:error] [pid 66623:tid 66766] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/.cache/x.php"] [unique_id "aoSA59O5rbWdOArH04KS_gAAAQo"]
[Tue Aug 18 12:57:27.596589 2026] [security2:error] [pid 67073:tid 67254] [client 20.206.73.37:59890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/scxy.php"] [unique_id "aoSA5_cmepr5_nHgLbNklQAAAkU"]
[Tue Aug 18 12:57:27.599392 2026] [security2:error] [pid 67073:tid 67261] [client 20.119.58.187:11294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/goods.php"] [unique_id "aoSA5_cmepr5_nHgLbNklwAAAkw"]
[Tue Aug 18 12:57:27.604984 2026] [security2:error] [pid 67073:tid 67222] [client 192.141.172.134:64039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5_cmepr5_nHgLbNkmAAAAiU"]
[Tue Aug 18 12:57:27.605057 2026] [security2:error] [pid 67073:tid 67222] [client 192.141.172.134:64039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5_cmepr5_nHgLbNkmAAAAiU"]
[Tue Aug 18 12:57:27.609004 2026] [security2:error] [pid 67073:tid 67314] [client 172.182.200.96:14146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/dlvqo.php"] [unique_id "aoSA5_cmepr5_nHgLbNkmQAAAoE"]
[Tue Aug 18 12:57:27.621883 2026] [security2:error] [pid 67073:tid 67311] [client 172.202.39.151:50231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSA5_cmepr5_nHgLbNkmgAAAn4"]
[Tue Aug 18 12:57:27.638252 2026] [security2:error] [pid 67073:tid 67297] [client 20.215.241.237:48215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/baba.php"] [unique_id "aoSA5_cmepr5_nHgLbNknAAAAnA"]
[Tue Aug 18 12:57:27.677738 2026] [security2:error] [pid 67073:tid 67323] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSA5_cmepr5_nHgLbNknQAAAoo"]
[Tue Aug 18 12:57:27.722024 2026] [security2:error] [pid 67073:tid 67270] [client 86.120.159.145:7881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5_cmepr5_nHgLbNkoAAAAlU"]
[Tue Aug 18 12:57:27.722155 2026] [security2:error] [pid 67073:tid 67270] [client 86.120.159.145:7881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5_cmepr5_nHgLbNkoAAAAlU"]
[Tue Aug 18 12:57:27.735918 2026] [security2:error] [pid 67073:tid 67219] [client 74.248.18.37:27486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/cong.php"] [unique_id "aoSA5_cmepr5_nHgLbNkogAAAiI"]
[Tue Aug 18 12:57:27.759361 2026] [security2:error] [pid 66623:tid 66798] [client 68.155.154.236:16319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSA59O5rbWdOArH04KS_wAAASo"]
[Tue Aug 18 12:57:27.798746 2026] [security2:error] [pid 67073:tid 67234] [client 40.74.65.169:4569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/media.php"] [unique_id "aoSA5_cmepr5_nHgLbNkpAAAAjE"]
[Tue Aug 18 12:57:27.815411 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:27.815666 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:27.817162 2026] [security2:error] [pid 67073:tid 67307] [client 158.158.74.177:2662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/admin.php"] [unique_id "aoSA5_cmepr5_nHgLbNkpgAAAno"]
[Tue Aug 18 12:57:27.821406 2026] [security2:error] [pid 67073:tid 67269] [client 40.85.222.29:44762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/pkmoj.php"] [unique_id "aoSA5_cmepr5_nHgLbNkpwAAAlQ"]
[Tue Aug 18 12:57:27.834299 2026] [security2:error] [pid 67073:tid 67310] [client 20.118.172.148:52227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/min.php"] [unique_id "aoSA5_cmepr5_nHgLbNkqAAAAn0"]
[Tue Aug 18 12:57:27.871601 2026] [security2:error] [pid 67073:tid 67250] [client 68.155.154.236:65525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSA5_cmepr5_nHgLbNkqgAAAkE"]
[Tue Aug 18 12:57:27.937291 2026] [security2:error] [pid 67073:tid 67262] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA5_cmepr5_nHgLbNkrQAAAk0"]
[Tue Aug 18 12:57:27.953077 2026] [security2:error] [pid 67073:tid 67274] [client 20.119.58.187:11315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/g.php"] [unique_id "aoSA5_cmepr5_nHgLbNkrgAAAlk"]
[Tue Aug 18 12:57:27.958753 2026] [security2:error] [pid 67073:tid 67313] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSA5_cmepr5_nHgLbNkrwAAAoA"]
[Tue Aug 18 12:57:28.017509 2026] [security2:error] [pid 67073:tid 67210] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSA6Pcmepr5_nHgLbNktAAAAhk"]
[Tue Aug 18 12:57:28.033244 2026] [security2:error] [pid 67073:tid 67235] [client 20.250.13.23:47034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/zup.php73"] [unique_id "aoSA6Pcmepr5_nHgLbNktQAAAjI"]
[Tue Aug 18 12:57:28.086087 2026] [security2:error] [pid 66623:tid 66887] [client 213.35.127.232:54362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSA6NO5rbWdOArH04KTAQAAAYM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:28.103912 2026] [security2:error] [pid 67073:tid 67296] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkuAAAAm8"]
[Tue Aug 18 12:57:28.119340 2026] [authz_core:error] [pid 67073:tid 67164] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:28.119615 2026] [authz_core:error] [pid 67073:tid 67164] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:28.120219 2026] [security2:error] [pid 67073:tid 67213] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/admin.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkugAAAhw"]
[Tue Aug 18 12:57:28.134210 2026] [security2:error] [pid 67073:tid 67295] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/biufile.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkuwAAAm4"]
[Tue Aug 18 12:57:28.137498 2026] [security2:error] [pid 67073:tid 67244] [client 40.74.65.169:28189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkvAAAAjs"]
[Tue Aug 18 12:57:28.156667 2026] [security2:error] [pid 67073:tid 67291] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkvwAAAmo"]
[Tue Aug 18 12:57:28.168903 2026] [security2:error] [pid 67073:tid 67304] [client 172.182.200.96:7620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/pkmoj.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkwAAAAnc"]
[Tue Aug 18 12:57:28.177026 2026] [security2:error] [pid 67073:tid 67275] [client 20.118.172.148:52236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/mac.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkwQAAAlo"]
[Tue Aug 18 12:57:28.179576 2026] [security2:error] [pid 67073:tid 67308] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkwgAAAns"]
[Tue Aug 18 12:57:28.187788 2026] [security2:error] [pid 67073:tid 67259] [client 68.155.155.199:5982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/aaa.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkwwAAAko"]
[Tue Aug 18 12:57:28.221094 2026] [security2:error] [pid 67073:tid 67283] [client 68.155.154.236:16373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/first.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkxgAAAmI"]
[Tue Aug 18 12:57:28.231517 2026] [security2:error] [pid 66623:tid 66847] [client 40.85.222.29:44270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/kopyw.php"] [unique_id "aoSA6NO5rbWdOArH04KTAwAAAVs"]
[Tue Aug 18 12:57:28.244455 2026] [security2:error] [pid 67073:tid 67237] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkxwAAAjQ"]
[Tue Aug 18 12:57:28.257689 2026] [security2:error] [pid 67073:tid 67232] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/coffexium.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkyAAAAi8"]
[Tue Aug 18 12:57:28.258684 2026] [security2:error] [pid 67073:tid 67332] [client 74.248.18.37:62081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/ors32envu.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkyQAAApM"]
[Tue Aug 18 12:57:28.277217 2026] [security2:error] [pid 67073:tid 67277] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/dex.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkygAAAlw"]
[Tue Aug 18 12:57:28.290963 2026] [security2:error] [pid 67073:tid 67224] [client 20.206.73.37:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/1.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkywAAAic"]
[Tue Aug 18 12:57:28.291085 2026] [security2:error] [pid 67073:tid 67224] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/1.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkywAAAic"]
[Tue Aug 18 12:57:28.307233 2026] [security2:error] [pid 67073:tid 67253] [client 20.119.58.187:12036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkzQAAAkQ"]
[Tue Aug 18 12:57:28.307421 2026] [security2:error] [pid 67073:tid 67220] [client 20.119.58.187:11314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/hplfuns.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkzgAAAiM"]
[Tue Aug 18 12:57:28.326287 2026] [security2:error] [pid 66623:tid 66859] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/coffee.php"] [unique_id "aoSA6NO5rbWdOArH04KTBQAAAWc"]
[Tue Aug 18 12:57:28.339693 2026] [security2:error] [pid 66623:tid 66780] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSA6NO5rbWdOArH04KTBgAAARg"]
[Tue Aug 18 12:57:28.353568 2026] [security2:error] [pid 67073:tid 67214] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk0QAAAh0"]
[Tue Aug 18 12:57:28.368920 2026] [security2:error] [pid 67073:tid 67255] [client 74.248.18.37:3078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk0wAAAkY"]
[Tue Aug 18 12:57:28.373648 2026] [security2:error] [pid 67073:tid 67218] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/mgrr.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk1AAAAiE"]
[Tue Aug 18 12:57:28.386523 2026] [security2:error] [pid 67073:tid 67305] [client 68.155.154.236:7890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk1QAAAng"]
[Tue Aug 18 12:57:28.463643 2026] [security2:error] [pid 66623:tid 66815] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSA6NO5rbWdOArH04KTCAAAATs"]
[Tue Aug 18 12:57:28.472431 2026] [security2:error] [pid 67073:tid 67289] [client 40.74.65.169:4479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/admin.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk2AAAAmg"]
[Tue Aug 18 12:57:28.513916 2026] [security2:error] [pid 67073:tid 67323] [client 20.118.172.148:62093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/nc4.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk2QAAAoo"]
[Tue Aug 18 12:57:28.518818 2026] [security2:error] [pid 67073:tid 67246] [client 103.184.169.37:42151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk2gAAAj0"]
[Tue Aug 18 12:57:28.518909 2026] [security2:error] [pid 67073:tid 67246] [client 103.184.169.37:42151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk2gAAAj0"]
[Tue Aug 18 12:57:28.529413 2026] [security2:error] [pid 67073:tid 67312] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk2wAAAn8"]
[Tue Aug 18 12:57:28.533462 2026] [security2:error] [pid 67073:tid 67270] [client 40.85.222.29:44249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/zznmg.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk3QAAAlU"]
[Tue Aug 18 12:57:28.579609 2026] [security2:error] [pid 67073:tid 67279] [client 172.182.200.96:7665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk3gAAAl4"]
[Tue Aug 18 12:57:28.660584 2026] [security2:error] [pid 67073:tid 67299] [client 20.119.58.187:11252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk3wAAAnI"]
[Tue Aug 18 12:57:28.660802 2026] [security2:error] [pid 66623:tid 66800] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSA6NO5rbWdOArH04KTCgAAASw"]
[Tue Aug 18 12:57:28.664133 2026] [security2:error] [pid 66623:tid 66822] [client 20.119.58.187:12087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/index.php"] [unique_id "aoSA6NO5rbWdOArH04KTCwAAAUI"]
[Tue Aug 18 12:57:28.668242 2026] [security2:error] [pid 66623:tid 66773] [client 172.182.200.96:14105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/kopyw.php"] [unique_id "aoSA6NO5rbWdOArH04KTDAAAARE"]
[Tue Aug 18 12:57:28.672197 2026] [security2:error] [pid 67073:tid 67260] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/55.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk4AAAAks"]
[Tue Aug 18 12:57:28.684128 2026] [security2:error] [pid 67073:tid 67321] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/ajax.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk4gAAAog"]
[Tue Aug 18 12:57:28.704953 2026] [security2:error] [pid 67073:tid 67097] [remote 47.128.31.157:14370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "maxxbox.ind.br"] [uri "/"] [unique_id "aoSA6Pcmepr5_nHgLbNk4wACNhU"]
[Tue Aug 18 12:57:28.709920 2026] [security2:error] [pid 67073:tid 67233] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/yj09.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk5AAAAjA"]
[Tue Aug 18 12:57:28.722171 2026] [security2:error] [pid 67073:tid 67313] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/scxy.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk5gAAAoA"]
[Tue Aug 18 12:57:28.724842 2026] [authz_core:error] [pid 67073:tid 67107] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:28.725090 2026] [authz_core:error] [pid 67073:tid 67107] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:28.752555 2026] [security2:error] [pid 67073:tid 67235] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/ws13.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk6AAAAjI"]
[Tue Aug 18 12:57:28.758532 2026] [autoindex:error] [pid 67073:tid 67209] [client 205.210.31.192:0] AH01276: Cannot serve directory /home2/le7f15nb/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:28.765192 2026] [security2:error] [pid 67073:tid 67271] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/btx25.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk6gAAAlY"]
[Tue Aug 18 12:57:28.774942 2026] [security2:error] [pid 67073:tid 67213] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk6wAAAhw"]
[Tue Aug 18 12:57:28.781662 2026] [security2:error] [pid 67073:tid 67263] [client 103.120.71.157:12648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk7AAAAk4"]
[Tue Aug 18 12:57:28.781766 2026] [security2:error] [pid 67073:tid 67263] [client 103.120.71.157:12648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk7AAAAk4"]
[Tue Aug 18 12:57:28.791391 2026] [security2:error] [pid 67073:tid 67244] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk7wAAAjs"]
[Tue Aug 18 12:57:28.804496 2026] [security2:error] [pid 66623:tid 66883] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSA6NO5rbWdOArH04KTDQAAAX8"]
[Tue Aug 18 12:57:28.817955 2026] [security2:error] [pid 67073:tid 67304] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk9gAAAnc"]
[Tue Aug 18 12:57:28.831087 2026] [security2:error] [pid 67073:tid 67308] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/sky.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk9wAAAns"]
[Tue Aug 18 12:57:28.841908 2026] [security2:error] [pid 66623:tid 66858] [client 40.74.65.169:31877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-blog.php"] [unique_id "aoSA6NO5rbWdOArH04KTDgAAAWY"]
[Tue Aug 18 12:57:28.843303 2026] [security2:error] [pid 66623:tid 66813] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/file5.php"] [unique_id "aoSA6NO5rbWdOArH04KTDwAAATk"]
[Tue Aug 18 12:57:28.857248 2026] [security2:error] [pid 66623:tid 66817] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/xyn.php"] [unique_id "aoSA6NO5rbWdOArH04KTEAAAAT0"]
[Tue Aug 18 12:57:28.862336 2026] [security2:error] [pid 66623:tid 66810] [client 20.118.172.148:62412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/as.php"] [unique_id "aoSA6NO5rbWdOArH04KTEQAAATY"]
[Tue Aug 18 12:57:28.870475 2026] [security2:error] [pid 66623:tid 66870] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/inso.php"] [unique_id "aoSA6NO5rbWdOArH04KTEgAAAXI"]
[Tue Aug 18 12:57:28.879606 2026] [security2:error] [pid 67073:tid 67217] [client 20.100.169.31:16178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk-wAAAiA"]
[Tue Aug 18 12:57:28.898183 2026] [security2:error] [pid 67073:tid 67245] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/puc.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk_AAAAjw"]
[Tue Aug 18 12:57:28.906162 2026] [security2:error] [pid 67073:tid 67276] [client 74.248.18.37:20528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/ov-simple1.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk_QAAAls"]
[Tue Aug 18 12:57:28.925165 2026] [security2:error] [pid 66623:tid 66799] [client 40.85.222.29:44760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/bhfnd.php"] [unique_id "aoSA6NO5rbWdOArH04KTEwAAASs"]
[Tue Aug 18 12:57:28.926894 2026] [security2:error] [pid 67073:tid 67287] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/19.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk_gAAAmY"]
[Tue Aug 18 12:57:28.943947 2026] [security2:error] [pid 66623:tid 66848] [client 49.13.167.123:61146] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.capecodcleaningservice.com"] [uri "/index.php"] [unique_id "aoSA6NO5rbWdOArH04KTBAAAAVw"], referer: https://www.capecodcleaningservice.com
[Tue Aug 18 12:57:28.953189 2026] [security2:error] [pid 66623:tid 66819] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/133.php"] [unique_id "aoSA6NO5rbWdOArH04KTFAAAAT8"]
[Tue Aug 18 12:57:28.959439 2026] [security2:error] [pid 66623:tid 66876] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSA6NO5rbWdOArH04KTFQAAAXg"]
[Tue Aug 18 12:57:28.969225 2026] [security2:error] [pid 66623:tid 66807] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/1xmomo.php"] [unique_id "aoSA6NO5rbWdOArH04KTFwAAATM"]
[Tue Aug 18 12:57:28.983686 2026] [security2:error] [pid 66623:tid 66853] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/mosty.php"] [unique_id "aoSA6NO5rbWdOArH04KTGAAAAWE"]
[Tue Aug 18 12:57:28.997224 2026] [security2:error] [pid 66623:tid 66776] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/blurbs.php"] [unique_id "aoSA6NO5rbWdOArH04KTGQAAARQ"]
[Tue Aug 18 12:57:29.003244 2026] [security2:error] [pid 67073:tid 67205] [client 74.248.18.37:3649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/db.php"] [unique_id "aoSA6fcmepr5_nHgLbNk_wAAAhQ"]
[Tue Aug 18 12:57:29.014632 2026] [security2:error] [pid 67073:tid 67241] [client 37.40.227.74:56815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6fcmepr5_nHgLbNlAAAAAjg"]
[Tue Aug 18 12:57:29.014751 2026] [security2:error] [pid 67073:tid 67241] [client 37.40.227.74:56815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6fcmepr5_nHgLbNlAAAAAjg"]
[Tue Aug 18 12:57:29.016096 2026] [security2:error] [pid 67073:tid 67283] [client 20.119.58.187:11201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/in.php"] [unique_id "aoSA6fcmepr5_nHgLbNlAQAAAmI"]
[Tue Aug 18 12:57:29.017326 2026] [security2:error] [pid 67073:tid 67237] [client 20.119.58.187:12065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/pomo/user-new.php"] [unique_id "aoSA6fcmepr5_nHgLbNlAgAAAjQ"]
[Tue Aug 18 12:57:29.032050 2026] [authz_core:error] [pid 67073:tid 67110] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:29.032504 2026] [authz_core:error] [pid 67073:tid 67110] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:29.054001 2026] [security2:error] [pid 67073:tid 67238] [client 20.203.183.135:37144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA6fcmepr5_nHgLbNlBQAAAjU"]
[Tue Aug 18 12:57:29.068654 2026] [security2:error] [pid 66623:tid 66886] [client 68.155.154.236:16192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSA6dO5rbWdOArH04KTGgAAAYI"]
[Tue Aug 18 12:57:29.079762 2026] [security2:error] [pid 66623:tid 66862] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSA6dO5rbWdOArH04KTGwAAAWo"]
[Tue Aug 18 12:57:29.089149 2026] [security2:error] [pid 66623:tid 66827] [client 172.182.200.96:7637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/zznmg.php"] [unique_id "aoSA6dO5rbWdOArH04KTHAAAAUc"]
[Tue Aug 18 12:57:29.099197 2026] [security2:error] [pid 67073:tid 67216] [client 213.35.127.232:54567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSA6fcmepr5_nHgLbNlCgAAAh8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:29.106514 2026] [security2:error] [pid 67073:tid 67220] [client 20.226.56.190:45052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ut.php"] [unique_id "aoSA6fcmepr5_nHgLbNlCwAAAiM"]
[Tue Aug 18 12:57:29.109913 2026] [security2:error] [pid 66623:tid 66888] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSA6dO5rbWdOArH04KTHQAAAYQ"]
[Tue Aug 18 12:57:29.117718 2026] [security2:error] [pid 66623:tid 66845] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/bajah.php"] [unique_id "aoSA6dO5rbWdOArH04KTHwAAAVk"]
[Tue Aug 18 12:57:29.132124 2026] [security2:error] [pid 67073:tid 67227] [client 104.209.144.33:19616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSA6fcmepr5_nHgLbNlDQAAAio"]
[Tue Aug 18 12:57:29.132956 2026] [security2:error] [pid 67073:tid 67214] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/h.php"] [unique_id "aoSA6fcmepr5_nHgLbNlDgAAAh0"]
[Tue Aug 18 12:57:29.148568 2026] [security2:error] [pid 67073:tid 67248] [client 40.74.65.169:4449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/mac.php"] [unique_id "aoSA6fcmepr5_nHgLbNlDwAAAj8"]
[Tue Aug 18 12:57:29.160323 2026] [security2:error] [pid 67073:tid 67315] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/ano.php"] [unique_id "aoSA6fcmepr5_nHgLbNlEAAAAoI"]
[Tue Aug 18 12:57:29.175501 2026] [security2:error] [pid 67073:tid 67225] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/ai.php"] [unique_id "aoSA6fcmepr5_nHgLbNlEQAAAig"]
[Tue Aug 18 12:57:29.200189 2026] [security2:error] [pid 67073:tid 67258] [client 68.155.154.236:65511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSA6fcmepr5_nHgLbNlEgAAAkk"]
[Tue Aug 18 12:57:29.207104 2026] [security2:error] [pid 67073:tid 67221] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/sf.php"] [unique_id "aoSA6fcmepr5_nHgLbNlEwAAAiQ"]
[Tue Aug 18 12:57:29.222514 2026] [security2:error] [pid 67073:tid 67297] [client 20.118.172.148:62416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/k.php"] [unique_id "aoSA6fcmepr5_nHgLbNlFQAAAnA"]
[Tue Aug 18 12:57:29.237990 2026] [security2:error] [pid 67073:tid 67301] [client 40.85.222.29:44792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/qfvqu.php"] [unique_id "aoSA6fcmepr5_nHgLbNlFwAAAnQ"]
[Tue Aug 18 12:57:29.238635 2026] [security2:error] [pid 66623:tid 66771] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/xx.php"] [unique_id "aoSA6dO5rbWdOArH04KTJAAAAQ8"]
[Tue Aug 18 12:57:29.251940 2026] [security2:error] [pid 66623:tid 66795] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/uwu.php"] [unique_id "aoSA6dO5rbWdOArH04KTJQAAASc"]
[Tue Aug 18 12:57:29.265841 2026] [security2:error] [pid 67073:tid 67319] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/signon.php"] [unique_id "aoSA6fcmepr5_nHgLbNlGQAAAoY"]
[Tue Aug 18 12:57:29.279964 2026] [security2:error] [pid 67073:tid 67278] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/file61.php"] [unique_id "aoSA6fcmepr5_nHgLbNlGwAAAl0"]
[Tue Aug 18 12:57:29.293678 2026] [security2:error] [pid 67073:tid 67279] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/copypaths.php"] [unique_id "aoSA6fcmepr5_nHgLbNlHAAAAl4"]
[Tue Aug 18 12:57:29.321116 2026] [security2:error] [pid 67073:tid 67236] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/bless6.php"] [unique_id "aoSA6fcmepr5_nHgLbNlHQAAAjM"]
[Tue Aug 18 12:57:29.321751 2026] [security2:error] [pid 66623:tid 66838] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSA6dO5rbWdOArH04KTJgAAAVI"]
[Tue Aug 18 12:57:29.334244 2026] [security2:error] [pid 67073:tid 67226] [client 168.119.96.239:51582] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.rhsolucionar.com.br"] [uri "/index.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk0AAAAik"], referer: https://www.rhsolucionar.com.br/
[Tue Aug 18 12:57:29.336238 2026] [security2:error] [pid 67073:tid 67260] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/special.php"] [unique_id "aoSA6fcmepr5_nHgLbNlHwAAAks"]
[Tue Aug 18 12:57:29.351171 2026] [security2:error] [pid 67073:tid 67321] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/fz.php"] [unique_id "aoSA6fcmepr5_nHgLbNlIQAAAog"]
[Tue Aug 18 12:57:29.365220 2026] [security2:error] [pid 66623:tid 66864] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/clque.php"] [unique_id "aoSA6dO5rbWdOArH04KTKAAAAWw"]
[Tue Aug 18 12:57:29.367311 2026] [security2:error] [pid 67073:tid 67233] [client 68.155.155.199:22800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/term.php"] [unique_id "aoSA6fcmepr5_nHgLbNlIgAAAjA"]
[Tue Aug 18 12:57:29.369123 2026] [security2:error] [pid 67073:tid 67246] [client 20.119.58.187:11313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/info.php"] [unique_id "aoSA6fcmepr5_nHgLbNlIwAAAj0"]
[Tue Aug 18 12:57:29.372240 2026] [security2:error] [pid 66623:tid 66851] [client 68.155.156.252:19809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/fpwch.php"] [unique_id "aoSA6dO5rbWdOArH04KTKQAAAV8"]
[Tue Aug 18 12:57:29.378524 2026] [security2:error] [pid 67073:tid 67235] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/nano.php"] [unique_id "aoSA6fcmepr5_nHgLbNlJAAAAjI"]
[Tue Aug 18 12:57:29.391803 2026] [security2:error] [pid 67073:tid 67296] [client 20.206.73.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/.mopj.php"] [unique_id "aoSA6fcmepr5_nHgLbNlJQAAAm8"]
[Tue Aug 18 12:57:29.401981 2026] [security2:error] [pid 67073:tid 67213] [client 20.48.236.86:48708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/img.php"] [unique_id "aoSA6fcmepr5_nHgLbNlJgAAAhw"]
[Tue Aug 18 12:57:29.405261 2026] [security2:error] [pid 67073:tid 67251] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/bengi.php"] [unique_id "aoSA6fcmepr5_nHgLbNlJwAAAkI"]
[Tue Aug 18 12:57:29.410371 2026] [security2:error] [pid 67073:tid 67212] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/well-known/index.php"] [unique_id "aoSA6fcmepr5_nHgLbNlKAAAAhs"]
[Tue Aug 18 12:57:29.418903 2026] [security2:error] [pid 67073:tid 67281] [client 20.119.58.187:12045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/sodium_compat/src/about.php"] [unique_id "aoSA6fcmepr5_nHgLbNlKgAAAmA"]
[Tue Aug 18 12:57:29.470796 2026] [security2:error] [pid 67073:tid 67329] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSA6fcmepr5_nHgLbNlLQAAApA"]
[Tue Aug 18 12:57:29.497555 2026] [security2:error] [pid 67073:tid 67295] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSA6fcmepr5_nHgLbNlLgAAAm4"]
[Tue Aug 18 12:57:29.500454 2026] [security2:error] [pid 67073:tid 67274] [client 20.65.98.162:9095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/special.php"] [unique_id "aoSA6fcmepr5_nHgLbNlLwAAAlk"]
[Tue Aug 18 12:57:29.513984 2026] [security2:error] [pid 67073:tid 67207] [client 20.250.13.23:60438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/k.php"] [unique_id "aoSA6fcmepr5_nHgLbNlMAAAAhY"]
[Tue Aug 18 12:57:29.536963 2026] [security2:error] [pid 67073:tid 67272] [client 172.182.200.96:14180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/bhfnd.php"] [unique_id "aoSA6fcmepr5_nHgLbNlMQAAAlc"]
[Tue Aug 18 12:57:29.565982 2026] [security2:error] [pid 66623:tid 66826] [client 20.118.172.148:62139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSA6dO5rbWdOArH04KTKgAAAUY"]
[Tue Aug 18 12:57:29.588562 2026] [security2:error] [pid 66623:tid 66793] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSA6dO5rbWdOArH04KTKwAAASU"]
[Tue Aug 18 12:57:29.603441 2026] [security2:error] [pid 66623:tid 66846] [client 20.215.241.237:48249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/site.php"] [unique_id "aoSA6dO5rbWdOArH04KTLAAAAVo"]
[Tue Aug 18 12:57:29.607150 2026] [security2:error] [pid 67073:tid 67269] [client 74.248.18.37:20522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/ova.php"] [unique_id "aoSA6fcmepr5_nHgLbNlNAAAAlQ"]
[Tue Aug 18 12:57:29.616671 2026] [security2:error] [pid 66623:tid 66820] [client 74.248.136.165:22489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ae.php"] [unique_id "aoSA6dO5rbWdOArH04KTLQAAAUA"]
[Tue Aug 18 12:57:29.623271 2026] [security2:error] [pid 67073:tid 67249] [client 40.85.222.29:44796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/oivcl.php"] [unique_id "aoSA6fcmepr5_nHgLbNlNwAAAkA"]
[Tue Aug 18 12:57:29.627094 2026] [security2:error] [pid 66623:tid 66841] [client 74.7.244.13:45790] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "andradesales.com.br"] [uri "/index.php"] [unique_id "aoSA6NO5rbWdOArH04KTCQABVXA"]
[Tue Aug 18 12:57:29.634138 2026] [security2:error] [pid 67073:tid 67263] [client 74.248.18.37:27489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/dropdown.php"] [unique_id "aoSA6fcmepr5_nHgLbNlOQAAAk4"]
[Tue Aug 18 12:57:29.675244 2026] [security2:error] [pid 67073:tid 67231] [client 20.118.133.132:1260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/av.php"] [unique_id "aoSA6fcmepr5_nHgLbNlQwAAAi4"]
[Tue Aug 18 12:57:29.712150 2026] [security2:error] [pid 67073:tid 67224] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/file2.php"] [unique_id "aoSA6fcmepr5_nHgLbNlSwAAAic"]
[Tue Aug 18 12:57:29.721157 2026] [security2:error] [pid 67073:tid 67232] [client 20.119.58.187:11222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/inputs.php"] [unique_id "aoSA6fcmepr5_nHgLbNlTAAAAi8"]
[Tue Aug 18 12:57:29.731918 2026] [security2:error] [pid 67073:tid 67220] [client 20.226.56.190:52054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/eh.php"] [unique_id "aoSA6fcmepr5_nHgLbNlTgAAAiM"]
[Tue Aug 18 12:57:29.741518 2026] [security2:error] [pid 67073:tid 67285] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/gm.php"] [unique_id "aoSA6fcmepr5_nHgLbNlTwAAAmQ"]
[Tue Aug 18 12:57:29.760931 2026] [security2:error] [pid 67073:tid 67208] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/ws55.php"] [unique_id "aoSA6fcmepr5_nHgLbNlUAAAAhc"]
[Tue Aug 18 12:57:29.763740 2026] [security2:error] [pid 67073:tid 67214] [client 68.155.154.236:50375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSA6fcmepr5_nHgLbNlUQAAAh0"]
[Tue Aug 18 12:57:29.775770 2026] [security2:error] [pid 66623:tid 66836] [client 20.119.58.187:12053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSA6dO5rbWdOArH04KTLwAAAVA"]
[Tue Aug 18 12:57:29.782973 2026] [security2:error] [pid 67073:tid 67290] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/mt/byp.php"] [unique_id "aoSA6fcmepr5_nHgLbNlUgAAAmk"]
[Tue Aug 18 12:57:29.789783 2026] [security2:error] [pid 67073:tid 67248] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/m.php"] [unique_id "aoSA6fcmepr5_nHgLbNlUwAAAj8"]
[Tue Aug 18 12:57:29.802396 2026] [security2:error] [pid 67073:tid 67280] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/33.php"] [unique_id "aoSA6fcmepr5_nHgLbNlVAAAAl8"]
[Tue Aug 18 12:57:29.813211 2026] [security2:error] [pid 67073:tid 67254] [client 20.206.73.37:20675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/ws13.php"] [unique_id "aoSA6fcmepr5_nHgLbNlVgAAAkU"]
[Tue Aug 18 12:57:29.818193 2026] [security2:error] [pid 67073:tid 67261] [client 68.155.154.236:16308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSA6fcmepr5_nHgLbNlVwAAAkw"]
[Tue Aug 18 12:57:29.827570 2026] [security2:error] [pid 67073:tid 67314] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/packed.php"] [unique_id "aoSA6fcmepr5_nHgLbNlWAAAAoE"]
[Tue Aug 18 12:57:29.830297 2026] [security2:error] [pid 67073:tid 67311] [client 40.74.65.169:4556] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/1.php"] [unique_id "aoSA6fcmepr5_nHgLbNlWQAAAn4"]
[Tue Aug 18 12:57:29.830365 2026] [security2:error] [pid 67073:tid 67311] [client 40.74.65.169:4556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/1.php"] [unique_id "aoSA6fcmepr5_nHgLbNlWQAAAn4"]
[Tue Aug 18 12:57:29.859176 2026] [security2:error] [pid 67073:tid 67312] [client 172.182.200.96:14195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-content/index.php"] [unique_id "aoSA6fcmepr5_nHgLbNlWgAAAn8"]
[Tue Aug 18 12:57:29.892933 2026] [security2:error] [pid 66623:tid 66785] [client 20.100.169.31:34744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/ms-edit.php"] [unique_id "aoSA6dO5rbWdOArH04KTMAAAAR0"]
[Tue Aug 18 12:57:29.897737 2026] [security2:error] [pid 67073:tid 67257] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSA6fcmepr5_nHgLbNlXgAAAkg"]
[Tue Aug 18 12:57:29.914515 2026] [security2:error] [pid 66623:tid 66767] [client 20.100.169.31:16422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/bgymj.php"] [unique_id "aoSA6dO5rbWdOArH04KTMQAAAQs"]
[Tue Aug 18 12:57:29.930139 2026] [security2:error] [pid 67073:tid 67278] [client 40.85.222.29:44739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/zugvi.php"] [unique_id "aoSA6fcmepr5_nHgLbNlYQAAAl0"]
[Tue Aug 18 12:57:29.974751 2026] [security2:error] [pid 67073:tid 67227] [client 4.232.151.198:4311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSA6fcmepr5_nHgLbNlYgAAAio"]
[Tue Aug 18 12:57:29.982121 2026] [security2:error] [pid 66623:tid 66834] [client 20.104.85.180:7041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wso.php"] [unique_id "aoSA6dO5rbWdOArH04KTMgAAAU4"]
[Tue Aug 18 12:57:30.019380 2026] [security2:error] [pid 67073:tid 67330] [client 132.196.30.78:21852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/bless.php"] [unique_id "aoSA6vcmepr5_nHgLbNlcgAAApE"]
[Tue Aug 18 12:57:30.042164 2026] [security2:error] [pid 67073:tid 67302] [client 138.36.100.162:41662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6vcmepr5_nHgLbNlcwAAAnU"]
[Tue Aug 18 12:57:30.042268 2026] [security2:error] [pid 67073:tid 67302] [client 138.36.100.162:41662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6vcmepr5_nHgLbNlcwAAAnU"]
[Tue Aug 18 12:57:30.057345 2026] [security2:error] [pid 67073:tid 67324] [client 40.74.65.169:43146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/adminfuns.php"] [unique_id "aoSA6vcmepr5_nHgLbNldAAAAos"]
[Tue Aug 18 12:57:30.099275 2026] [security2:error] [pid 66623:tid 66770] [client 20.119.58.187:11218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/item.php"] [unique_id "aoSA6tO5rbWdOArH04KTNAAAAQ4"]
[Tue Aug 18 12:57:30.101753 2026] [security2:error] [pid 67073:tid 67256] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSA6vcmepr5_nHgLbNldwAAAkc"]
[Tue Aug 18 12:57:30.110951 2026] [security2:error] [pid 66623:tid 66863] [client 213.35.127.232:54780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA6tO5rbWdOArH04KTNQAAAWs"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:30.133970 2026] [security2:error] [pid 67073:tid 67317] [client 20.119.58.187:12066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSA6vcmepr5_nHgLbNleAAAAoQ"]
[Tue Aug 18 12:57:30.181347 2026] [security2:error] [pid 67073:tid 67281] [client 4.232.151.198:4331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/0x.php"] [unique_id "aoSA6vcmepr5_nHgLbNligAAAmA"]
[Tue Aug 18 12:57:30.195624 2026] [security2:error] [pid 67073:tid 67291] [client 172.182.200.96:14124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/qfvqu.php"] [unique_id "aoSA6vcmepr5_nHgLbNliwAAAmo"]
[Tue Aug 18 12:57:30.228849 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:30.229103 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:30.236822 2026] [security2:error] [pid 67073:tid 67247] [client 40.85.222.29:44751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wsrer.php"] [unique_id "aoSA6vcmepr5_nHgLbNllgAAAj4"]
[Tue Aug 18 12:57:30.249528 2026] [security2:error] [pid 67073:tid 67206] [client 20.118.172.148:62408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/system_log.php"] [unique_id "aoSA6vcmepr5_nHgLbNllwAAAhU"]
[Tue Aug 18 12:57:30.272882 2026] [security2:error] [pid 67073:tid 67215] [client 74.248.18.37:31850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/p.php"] [unique_id "aoSA6vcmepr5_nHgLbNlmgAAAh4"]
[Tue Aug 18 12:57:30.274837 2026] [security2:error] [pid 67073:tid 67264] [client 74.248.18.37:27475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/file.php"] [unique_id "aoSA6vcmepr5_nHgLbNlmwAAAk8"]
[Tue Aug 18 12:57:30.278996 2026] [security2:error] [pid 67073:tid 67223] [client 68.155.154.236:46634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSA6vcmepr5_nHgLbNlnAAAAiY"]
[Tue Aug 18 12:57:30.304444 2026] [security2:error] [pid 66623:tid 66802] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSA6tO5rbWdOArH04KTNgAAAS4"]
[Tue Aug 18 12:57:30.307442 2026] [security2:error] [pid 67073:tid 67322] [client 20.104.85.180:7007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/sf.php"] [unique_id "aoSA6vcmepr5_nHgLbNlngAAAok"]
[Tue Aug 18 12:57:30.340848 2026] [security2:error] [pid 67073:tid 67295] [client 20.215.241.237:25273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSA6vcmepr5_nHgLbNloQAAAm4"]
[Tue Aug 18 12:57:30.367426 2026] [security2:error] [pid 67073:tid 67217] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSA6vcmepr5_nHgLbNlowAAAiA"]
[Tue Aug 18 12:57:30.393340 2026] [security2:error] [pid 66623:tid 66859] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSA6tO5rbWdOArH04KTOgAAAWc"]
[Tue Aug 18 12:57:30.410031 2026] [security2:error] [pid 67073:tid 67242] [client 5.31.227.224:1439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6vcmepr5_nHgLbNlpAAAAjk"]
[Tue Aug 18 12:57:30.410168 2026] [security2:error] [pid 67073:tid 67242] [client 5.31.227.224:1439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6vcmepr5_nHgLbNlpAAAAjk"]
[Tue Aug 18 12:57:30.452697 2026] [security2:error] [pid 66623:tid 66879] [client 20.119.58.187:11244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/k.php"] [unique_id "aoSA6tO5rbWdOArH04KTPAAAAXs"]
[Tue Aug 18 12:57:30.487530 2026] [security2:error] [pid 66623:tid 66847] [client 20.119.58.187:12085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/wp-class.php"] [unique_id "aoSA6tO5rbWdOArH04KTPgAAAVs"]
[Tue Aug 18 12:57:30.523698 2026] [security2:error] [pid 67073:tid 67263] [client 40.74.65.169:4465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/coffee.php"] [unique_id "aoSA6vcmepr5_nHgLbNlpgAAAk4"]
[Tue Aug 18 12:57:30.531520 2026] [authz_core:error] [pid 67073:tid 67152] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:30.531795 2026] [authz_core:error] [pid 67073:tid 67152] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:30.555303 2026] [security2:error] [pid 66623:tid 66773] [client 68.155.155.199:22839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/7.php"] [unique_id "aoSA6tO5rbWdOArH04KTQwAAARE"]
[Tue Aug 18 12:57:30.592436 2026] [security2:error] [pid 66623:tid 66789] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSA6tO5rbWdOArH04KTRAAAASE"]
[Tue Aug 18 12:57:30.593781 2026] [security2:error] [pid 67073:tid 67277] [client 20.104.85.180:6994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/index/function.php"] [unique_id "aoSA6vcmepr5_nHgLbNlqQAAAlw"]
[Tue Aug 18 12:57:30.609535 2026] [security2:error] [pid 67073:tid 67237] [client 40.85.222.29:44773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/ucpfr.php"] [unique_id "aoSA6vcmepr5_nHgLbNlqgAAAjQ"]
[Tue Aug 18 12:57:30.646291 2026] [security2:error] [pid 67073:tid 67224] [client 20.118.172.148:62417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/x.php"] [unique_id "aoSA6vcmepr5_nHgLbNlrAAAAic"]
[Tue Aug 18 12:57:30.657014 2026] [security2:error] [pid 67073:tid 67259] [client 158.158.74.177:26154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSA6vcmepr5_nHgLbNlrQAAAko"]
[Tue Aug 18 12:57:30.718333 2026] [security2:error] [pid 67073:tid 67253] [client 172.182.200.96:7632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/oivcl.php"] [unique_id "aoSA6vcmepr5_nHgLbNlrwAAAkQ"]
[Tue Aug 18 12:57:30.741442 2026] [security2:error] [pid 67073:tid 67320] [client 104.209.144.33:36520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSA6vcmepr5_nHgLbNlsgAAAoc"]
[Tue Aug 18 12:57:30.771449 2026] [security2:error] [pid 66623:tid 66867] [client 40.74.65.169:26727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/ms-edit.php"] [unique_id "aoSA6tO5rbWdOArH04KTRQAAAW8"]
[Tue Aug 18 12:57:30.772232 2026] [security2:error] [pid 67073:tid 67299] [client 157.20.138.62:64811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6vcmepr5_nHgLbNlswAAAnI"]
[Tue Aug 18 12:57:30.772323 2026] [security2:error] [pid 67073:tid 67299] [client 157.20.138.62:64811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6vcmepr5_nHgLbNlswAAAnI"]
[Tue Aug 18 12:57:30.804225 2026] [security2:error] [pid 67073:tid 67255] [client 20.203.183.135:37133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA6vcmepr5_nHgLbNltAAAAkY"]
[Tue Aug 18 12:57:30.806197 2026] [security2:error] [pid 67073:tid 67287] [client 132.196.30.78:21901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/sagax1.php"] [unique_id "aoSA6vcmepr5_nHgLbNltQAAAmY"]
[Tue Aug 18 12:57:30.810064 2026] [security2:error] [pid 66623:tid 66856] [client 20.119.58.187:11254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/license.php"] [unique_id "aoSA6tO5rbWdOArH04KTRgAAAWQ"]
[Tue Aug 18 12:57:30.816466 2026] [security2:error] [pid 67073:tid 67283] [client 20.100.169.31:13257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/aa.php"] [unique_id "aoSA6vcmepr5_nHgLbNltgAAAmI"]
[Tue Aug 18 12:57:30.816711 2026] [security2:error] [pid 66623:tid 66850] [client 68.155.154.236:7892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSA6tO5rbWdOArH04KTRwAAAV4"]
[Tue Aug 18 12:57:30.826294 2026] [security2:error] [pid 67073:tid 67238] [client 4.232.151.198:4332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/222.php"] [unique_id "aoSA6vcmepr5_nHgLbNluAAAAjU"]
[Tue Aug 18 12:57:30.835392 2026] [authz_core:error] [pid 67073:tid 67172] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:30.835643 2026] [authz_core:error] [pid 67073:tid 67172] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:30.874631 2026] [security2:error] [pid 66623:tid 66818] [client 20.119.58.187:12067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/wp-widgets.php"] [unique_id "aoSA6tO5rbWdOArH04KTSAAAAT4"]
[Tue Aug 18 12:57:30.875372 2026] [security2:error] [pid 67073:tid 67280] [client 68.155.154.236:16238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSA6vcmepr5_nHgLbNluwAAAl8"]
[Tue Aug 18 12:57:30.880188 2026] [security2:error] [pid 66623:tid 66817] [client 20.104.85.180:43570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/edit.php"] [unique_id "aoSA6tO5rbWdOArH04KTSQAAAT0"]
[Tue Aug 18 12:57:30.886212 2026] [security2:error] [pid 67073:tid 67221] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSA6vcmepr5_nHgLbNlvwAAAiQ"]
[Tue Aug 18 12:57:30.903994 2026] [security2:error] [pid 67073:tid 67216] [client 74.248.18.37:3105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/goods.php"] [unique_id "aoSA6vcmepr5_nHgLbNlwQAAAh8"]
[Tue Aug 18 12:57:30.908367 2026] [security2:error] [pid 66623:tid 66883] [client 74.248.18.37:8042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/pages.php"] [unique_id "aoSA6tO5rbWdOArH04KTSgAAAX8"]
[Tue Aug 18 12:57:30.924969 2026] [security2:error] [pid 67073:tid 67312] [client 20.100.185.105:25160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/fxcexgle.php"] [unique_id "aoSA6vcmepr5_nHgLbNlwwAAAn8"]
[Tue Aug 18 12:57:30.930927 2026] [security2:error] [pid 66623:tid 66824] [client 149.34.210.141:57778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSA6tO5rbWdOArH04KTSwAAAUQ"]
[Tue Aug 18 12:57:30.946461 2026] [security2:error] [pid 67073:tid 67270] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/first.php"] [unique_id "aoSA6vcmepr5_nHgLbNlxAAAAlU"]
[Tue Aug 18 12:57:30.956639 2026] [security2:error] [pid 67073:tid 67266] [client 40.85.222.29:44799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/yxijx.php"] [unique_id "aoSA6vcmepr5_nHgLbNlxQAAAlE"]
[Tue Aug 18 12:57:31.007004 2026] [security2:error] [pid 66623:tid 66848] [client 172.182.200.96:14095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoSA69O5rbWdOArH04KTTgAAAVw"]
[Tue Aug 18 12:57:31.052789 2026] [security2:error] [pid 67073:tid 67268] [client 20.226.56.190:45043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ad.php"] [unique_id "aoSA6_cmepr5_nHgLbNlyQAAAlM"]
[Tue Aug 18 12:57:31.060069 2026] [security2:error] [pid 67073:tid 67321] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSA6_cmepr5_nHgLbNlzAAAAog"]
[Tue Aug 18 12:57:31.085450 2026] [security2:error] [pid 67073:tid 67324] [client 20.118.172.148:62122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSA6_cmepr5_nHgLbNlzgAAAos"]
[Tue Aug 18 12:57:31.087886 2026] [security2:error] [pid 67073:tid 67184] [remote 216.194.122.158:56050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.122.194.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melocorretordeimoveis.com.br"] [uri "/wp-login.php"] [unique_id "aoSA6_cmepr5_nHgLbNlzwACF2w"]
[Tue Aug 18 12:57:31.115324 2026] [security2:error] [pid 66623:tid 66781] [client 172.182.200.96:14193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/zugvi.php"] [unique_id "aoSA69O5rbWdOArH04KTUQAAARk"]
[Tue Aug 18 12:57:31.125941 2026] [security2:error] [pid 66623:tid 66813] [client 213.35.127.232:54973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA69O5rbWdOArH04KTUgAAATk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:31.130990 2026] [security2:error] [pid 67073:tid 67213] [client 213.202.253.4:53155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/schallfuns.php"] [unique_id "aoSA6_cmepr5_nHgLbNl0QAAAhw"], referer: www.google.com
[Tue Aug 18 12:57:31.165693 2026] [security2:error] [pid 66623:tid 66797] [client 20.119.58.187:11268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/load.php"] [unique_id "aoSA69O5rbWdOArH04KTVAAAASk"]
[Tue Aug 18 12:57:31.184424 2026] [security2:error] [pid 66623:tid 66674] [remote 95.111.251.70:53832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.251.111.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/wp-login.php"] [unique_id "aoSA69O5rbWdOArH04KTVgABPCU"]
[Tue Aug 18 12:57:31.194352 2026] [security2:error] [pid 66623:tid 66886] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSA69O5rbWdOArH04KTVwAAAYI"]
[Tue Aug 18 12:57:31.196847 2026] [security2:error] [pid 66623:tid 66824] [client 149.34.210.141:57778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSA6tO5rbWdOArH04KTSwAAAUQ"]
[Tue Aug 18 12:57:31.207525 2026] [security2:error] [pid 66623:tid 66811] [client 40.74.65.169:4824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/classwithtostring.php"] [unique_id "aoSA69O5rbWdOArH04KTWAAAATc"]
[Tue Aug 18 12:57:31.228537 2026] [security2:error] [pid 67073:tid 67256] [client 20.119.58.187:12058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-signup.php"] [unique_id "aoSA6_cmepr5_nHgLbNl1gAAAkc"]
[Tue Aug 18 12:57:31.256648 2026] [security2:error] [pid 66623:tid 66873] [client 20.100.169.31:41654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/a7.php"] [unique_id "aoSA69O5rbWdOArH04KTWgAAAXU"]
[Tue Aug 18 12:57:31.260961 2026] [security2:error] [pid 67073:tid 67291] [client 20.226.56.190:32280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/vd.php"] [unique_id "aoSA6_cmepr5_nHgLbNl1wAAAmo"]
[Tue Aug 18 12:57:31.269109 2026] [security2:error] [pid 66623:tid 66888] [client 40.85.222.29:44797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/zwlsv.php"] [unique_id "aoSA69O5rbWdOArH04KTWwAAAYQ"]
[Tue Aug 18 12:57:31.273791 2026] [security2:error] [pid 67073:tid 67264] [client 68.155.154.236:8015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSA6_cmepr5_nHgLbNl2gAAAk8"]
[Tue Aug 18 12:57:31.330506 2026] [security2:error] [pid 67073:tid 67295] [client 20.206.73.37:11393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/btx25.php"] [unique_id "aoSA6_cmepr5_nHgLbNl2wAAAm4"]
[Tue Aug 18 12:57:31.348672 2026] [security2:error] [pid 66623:tid 66871] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSA69O5rbWdOArH04KTXQAAAXM"]
[Tue Aug 18 12:57:31.418862 2026] [security2:error] [pid 66623:tid 66771] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/blog/byp.php"] [unique_id "aoSA69O5rbWdOArH04KTXwAAAQ8"]
[Tue Aug 18 12:57:31.466042 2026] [security2:error] [pid 66623:tid 66857] [client 4.232.151.198:4340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/aa.php"] [unique_id "aoSA69O5rbWdOArH04KTYgAAAWU"]
[Tue Aug 18 12:57:31.476528 2026] [security2:error] [pid 66623:tid 66842] [client 172.182.200.96:7662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wsrer.php"] [unique_id "aoSA69O5rbWdOArH04KTYwAAAVY"]
[Tue Aug 18 12:57:31.525181 2026] [security2:error] [pid 67073:tid 67219] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSA6_cmepr5_nHgLbNl5AAAAiI"]
[Tue Aug 18 12:57:31.533019 2026] [security2:error] [pid 67073:tid 67253] [client 40.74.65.169:27800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/222.php"] [unique_id "aoSA6_cmepr5_nHgLbNl5gAAAkQ"]
[Tue Aug 18 12:57:31.536404 2026] [security2:error] [pid 67073:tid 67232] [client 68.155.155.199:9377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/file5.php"] [unique_id "aoSA6_cmepr5_nHgLbNl6AAAAi8"]
[Tue Aug 18 12:57:31.536432 2026] [security2:error] [pid 67073:tid 67230] [client 74.248.18.37:3098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/hplfuns.php"] [unique_id "aoSA6_cmepr5_nHgLbNl5wAAAi0"]
[Tue Aug 18 12:57:31.536944 2026] [security2:error] [pid 66623:tid 66875] [client 20.119.58.187:11283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/manager.php"] [unique_id "aoSA69O5rbWdOArH04KTZQAAAXc"]
[Tue Aug 18 12:57:31.546067 2026] [security2:error] [pid 67073:tid 67274] [client 20.100.185.105:6200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/locale.php"] [unique_id "aoSA6_cmepr5_nHgLbNl6gAAAlk"]
[Tue Aug 18 12:57:31.549963 2026] [security2:error] [pid 66623:tid 66812] [client 40.85.222.29:26882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/jrpga.php"] [unique_id "aoSA69O5rbWdOArH04KTZgAAATg"]
[Tue Aug 18 12:57:31.587538 2026] [security2:error] [pid 67073:tid 67263] [client 20.119.58.187:12084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-trackback.php"] [unique_id "aoSA6_cmepr5_nHgLbNl7gAAAk4"]
[Tue Aug 18 12:57:31.596358 2026] [autoindex:error] [pid 66623:tid 66809] [client 158.158.74.177:26147] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:31.599413 2026] [security2:error] [pid 67073:tid 67283] [client 20.226.56.190:23788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/56.php"] [unique_id "aoSA6_cmepr5_nHgLbNl7wAAAmI"]
[Tue Aug 18 12:57:31.608091 2026] [security2:error] [pid 67073:tid 67238] [client 20.118.172.148:62096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/hosty.php"] [unique_id "aoSA6_cmepr5_nHgLbNl8AAAAjU"]
[Tue Aug 18 12:57:31.640320 2026] [security2:error] [pid 67073:tid 67280] [client 20.215.241.237:48200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/cabs.php"] [unique_id "aoSA6_cmepr5_nHgLbNl8gAAAl8"]
[Tue Aug 18 12:57:31.696065 2026] [security2:error] [pid 67073:tid 67314] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSA6_cmepr5_nHgLbNl9AAAAoE"]
[Tue Aug 18 12:57:31.731821 2026] [security2:error] [pid 67073:tid 67216] [client 20.48.236.86:50751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/aa.php"] [unique_id "aoSA6_cmepr5_nHgLbNl9gAAAh8"]
[Tue Aug 18 12:57:31.775004 2026] [security2:error] [pid 67073:tid 67331] [client 68.155.154.236:16298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/blog/byp.php"] [unique_id "aoSA6_cmepr5_nHgLbNl-QAAApI"]
[Tue Aug 18 12:57:31.781731 2026] [security2:error] [pid 66623:tid 66835] [client 74.7.175.188:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bn2s.com.br"] [uri "/index.php"] [unique_id "aoSA6tO5rbWdOArH04KTOQAAAU8"]
[Tue Aug 18 12:57:31.794247 2026] [security2:error] [pid 67073:tid 67287] [client 74.248.18.37:31858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/past.php"] [unique_id "aoSA6_cmepr5_nHgLbNl-gAAAmY"]
[Tue Aug 18 12:57:31.833196 2026] [security2:error] [pid 67073:tid 67326] [client 40.85.222.29:44764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSA6_cmepr5_nHgLbNl_wAAAo0"]
[Tue Aug 18 12:57:31.834960 2026] [security2:error] [pid 66623:tid 66820] [client 158.158.74.177:26147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/about.php"] [unique_id "aoSA69O5rbWdOArH04KTaQAAAUA"]
[Tue Aug 18 12:57:31.851484 2026] [security2:error] [pid 67073:tid 67310] [client 20.203.183.135:12402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/media.php"] [unique_id "aoSA6_cmepr5_nHgLbNmAAAAAn0"]
[Tue Aug 18 12:57:31.860996 2026] [security2:error] [pid 67073:tid 67268] [client 68.155.154.236:39647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSA6_cmepr5_nHgLbNmAQAAAlM"]
[Tue Aug 18 12:57:31.889585 2026] [security2:error] [pid 67073:tid 67211] [client 20.119.58.187:11239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/media.php"] [unique_id "aoSA6_cmepr5_nHgLbNmAgAAAho"]
[Tue Aug 18 12:57:31.901943 2026] [security2:error] [pid 67073:tid 67233] [client 172.182.200.96:7655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/ucpfr.php"] [unique_id "aoSA6_cmepr5_nHgLbNmAwAAAjA"]
[Tue Aug 18 12:57:31.905963 2026] [security2:error] [pid 67073:tid 67246] [client 40.74.65.169:4823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/wp-ws68.php"] [unique_id "aoSA6_cmepr5_nHgLbNmBAAAAj0"]
[Tue Aug 18 12:57:31.921100 2026] [security2:error] [pid 67073:tid 67324] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/images/security.php"] [unique_id "aoSA6_cmepr5_nHgLbNmBgAAAos"]
[Tue Aug 18 12:57:31.946626 2026] [security2:error] [pid 67073:tid 67102] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6_cmepr5_nHgLbNmBwACbBo"]
[Tue Aug 18 12:57:31.946805 2026] [security2:error] [pid 67073:tid 67293] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6_cmepr5_nHgLbNmBwACbBo"]
[Tue Aug 18 12:57:31.965994 2026] [security2:error] [pid 67073:tid 67317] [client 20.118.172.148:62401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/test1.php"] [unique_id "aoSA6_cmepr5_nHgLbNmCAAAAoQ"]
[Tue Aug 18 12:57:31.972212 2026] [security2:error] [pid 67073:tid 67217] [client 178.153.171.161:45638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6_cmepr5_nHgLbNmCQAAAiA"]
[Tue Aug 18 12:57:31.972321 2026] [security2:error] [pid 67073:tid 67217] [client 178.153.171.161:45638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6_cmepr5_nHgLbNmCQAAAiA"]
[Tue Aug 18 12:57:32.044681 2026] [security2:error] [pid 67073:tid 67236] [client 20.119.58.187:12032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/ws.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmDQAAAjM"]
[Tue Aug 18 12:57:32.076124 2026] [security2:error] [pid 67073:tid 67223] [client 20.118.133.132:14861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/media.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmDgAAAiY"]
[Tue Aug 18 12:57:32.113333 2026] [security2:error] [pid 67073:tid 67260] [client 4.232.151.198:4300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/abcd.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmEAAAAks"]
[Tue Aug 18 12:57:32.121789 2026] [security2:error] [pid 67073:tid 67271] [client 20.226.56.190:52076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/rx.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmEQAAAlY"]
[Tue Aug 18 12:57:32.131054 2026] [security2:error] [pid 67073:tid 67239] [client 40.85.222.29:44252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/nwwha.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmEgAAAjY"]
[Tue Aug 18 12:57:32.138994 2026] [security2:error] [pid 67073:tid 67279] [client 213.35.127.232:55183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmEwAAAl4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:32.167507 2026] [security2:error] [pid 67073:tid 67240] [client 74.248.18.37:3076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/htaccess.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmFAAAAjc"]
[Tue Aug 18 12:57:32.182469 2026] [security2:error] [pid 67073:tid 67251] [client 20.100.185.105:58834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/cache-base.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmFgAAAkI"]
[Tue Aug 18 12:57:32.184477 2026] [security2:error] [pid 67073:tid 67302] [client 132.196.30.78:21861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wpc.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmGQAAAnU"]
[Tue Aug 18 12:57:32.240468 2026] [security2:error] [pid 66623:tid 66878] [client 20.119.58.187:11478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/mar.php"] [unique_id "aoSA7NO5rbWdOArH04KTbAAAAXo"]
[Tue Aug 18 12:57:32.247015 2026] [autoindex:error] [pid 67073:tid 67247] [client 20.79.204.6:4807] AH01276: Cannot serve directory /home1/xsolutions/pagazul.3xsolutions.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:32.273443 2026] [security2:error] [pid 66623:tid 66841] [client 20.100.169.31:41610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/manager.php"] [unique_id "aoSA7NO5rbWdOArH04KTbQAAAVU"]
[Tue Aug 18 12:57:32.286648 2026] [security2:error] [pid 67073:tid 67219] [client 172.182.200.96:14091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/yxijx.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmIgAAAiI"]
[Tue Aug 18 12:57:32.360321 2026] [security2:error] [pid 67073:tid 67285] [client 20.226.56.190:23790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/mandrill.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmJAAAAmQ"]
[Tue Aug 18 12:57:32.383800 2026] [security2:error] [pid 66623:tid 66834] [client 40.74.65.169:28160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSA7NO5rbWdOArH04KTbwAAAU4"]
[Tue Aug 18 12:57:32.400493 2026] [security2:error] [pid 67073:tid 67238] [client 20.118.172.148:62131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/zwso.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmJwAAAjU"]
[Tue Aug 18 12:57:32.421906 2026] [security2:error] [pid 67073:tid 67241] [client 20.119.58.187:12486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wso.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmKAAAAjg"]
[Tue Aug 18 12:57:32.466238 2026] [authz_core:error] [pid 67073:tid 67274] [client 192.178.4.133:46321] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:32.466516 2026] [authz_core:error] [pid 67073:tid 67274] [client 192.178.4.133:46321] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:32.478686 2026] [security2:error] [pid 67073:tid 67250] [client 40.85.222.29:44267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/opsqt.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmLAAAAkE"]
[Tue Aug 18 12:57:32.492819 2026] [security2:error] [pid 67073:tid 67314] [client 68.155.155.199:2258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmLQAAAoE"]
[Tue Aug 18 12:57:32.512901 2026] [security2:error] [pid 67073:tid 67300] [client 74.248.18.37:62126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/php.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmLgAAAnM"]
[Tue Aug 18 12:57:32.541519 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.56.190:31030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/main.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmLwAAAlg"]
[Tue Aug 18 12:57:32.541693 2026] [security2:error] [pid 67073:tid 67297] [client 20.215.241.237:25293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/insc.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmMAAAAnA"]
[Tue Aug 18 12:57:32.577309 2026] [security2:error] [pid 66623:tid 66802] [client 68.155.156.252:18405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/adminner.php"] [unique_id "aoSA7NO5rbWdOArH04KTcgAAAS4"]
[Tue Aug 18 12:57:32.585586 2026] [security2:error] [pid 67073:tid 67301] [client 40.74.65.169:4470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/yj09.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmMgAAAnQ"]
[Tue Aug 18 12:57:32.601951 2026] [security2:error] [pid 67073:tid 67254] [client 223.185.37.47:9065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmKQAAAkU"]
[Tue Aug 18 12:57:32.602116 2026] [security2:error] [pid 67073:tid 67254] [client 223.185.37.47:9065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmKQAAAkU"]
[Tue Aug 18 12:57:32.603189 2026] [security2:error] [pid 67073:tid 67280] [client 20.119.58.187:11290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/my1.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmMwAAAl8"]
[Tue Aug 18 12:57:32.612357 2026] [security2:error] [pid 66623:tid 66852] [client 172.182.200.96:7588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/zwlsv.php"] [unique_id "aoSA7NO5rbWdOArH04KTcwAAAWA"]
[Tue Aug 18 12:57:32.638293 2026] [security2:error] [pid 66623:tid 66772] [client 68.155.154.236:46638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSA7NO5rbWdOArH04KTdAAAARA"]
[Tue Aug 18 12:57:32.739490 2026] [security2:error] [pid 66623:tid 66880] [client 4.232.151.198:4341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/admin.php"] [unique_id "aoSA7NO5rbWdOArH04KTdgAAAXw"]
[Tue Aug 18 12:57:32.784863 2026] [security2:error] [pid 67073:tid 67226] [client 20.119.58.187:12081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/meta.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmOwAAAik"]
[Tue Aug 18 12:57:32.799588 2026] [security2:error] [pid 67073:tid 67323] [client 74.248.18.37:3084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/images/wso.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmPAAAAoo"]
[Tue Aug 18 12:57:32.799600 2026] [security2:error] [pid 67073:tid 67312] [client 20.100.185.105:29241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/lite.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmPQAAAn8"]
[Tue Aug 18 12:57:32.799983 2026] [security2:error] [pid 67073:tid 67208] [client 40.85.222.29:44265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/jvcpa.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmPgAAAhc"]
[Tue Aug 18 12:57:32.860156 2026] [security2:error] [pid 67073:tid 67242] [client 20.100.169.31:31274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-mail.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmQgAAAjk"]
[Tue Aug 18 12:57:32.872618 2026] [security2:error] [pid 67073:tid 67287] [client 132.196.30.78:21825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/fone1.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmQwAAAmY"]
[Tue Aug 18 12:57:32.877474 2026] [autoindex:error] [pid 66623:tid 66855] [client 172.202.39.151:50182] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:32.957516 2026] [security2:error] [pid 67073:tid 67293] [client 20.119.58.187:11310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/mm.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmRgAAAmw"]
[Tue Aug 18 12:57:32.973128 2026] [security2:error] [pid 67073:tid 67244] [client 172.182.200.96:14176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/jrpga.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmRwAAAjs"]
[Tue Aug 18 12:57:32.994767 2026] [security2:error] [pid 67073:tid 67269] [client 85.154.68.202:54350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmSAAAAlQ"]
[Tue Aug 18 12:57:32.994898 2026] [security2:error] [pid 67073:tid 67269] [client 85.154.68.202:54350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmSAAAAlQ"]
[Tue Aug 18 12:57:33.061506 2026] [security2:error] [pid 67073:tid 67260] [client 20.118.172.148:62108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/Geforce.php"] [unique_id "aoSA7fcmepr5_nHgLbNmTAAAAks"]
[Tue Aug 18 12:57:33.077127 2026] [security2:error] [pid 67073:tid 67257] [client 40.85.222.29:44748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSA7fcmepr5_nHgLbNmTQAAAkg"]
[Tue Aug 18 12:57:33.089871 2026] [security2:error] [pid 67073:tid 67259] [client 79.127.164.8:47150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/mysqldump.bak"] [unique_id "aoSA7fcmepr5_nHgLbNmTgAAAko"], referer: https://medihub.com.br/mysqldump.bak
[Tue Aug 18 12:57:33.135482 2026] [security2:error] [pid 66623:tid 66874] [client 160.120.140.123:49182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA7dO5rbWdOArH04KTegAAAXY"]
[Tue Aug 18 12:57:33.135589 2026] [security2:error] [pid 66623:tid 66874] [client 160.120.140.123:49182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA7dO5rbWdOArH04KTegAAAXY"]
[Tue Aug 18 12:57:33.149205 2026] [security2:error] [pid 67073:tid 67209] [client 213.35.127.232:55416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSA7fcmepr5_nHgLbNmUAAAAhg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:33.150270 2026] [security2:error] [pid 67073:tid 67264] [client 20.119.58.187:12092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/hehe.php"] [unique_id "aoSA7fcmepr5_nHgLbNmUQAAAk8"]
[Tue Aug 18 12:57:33.159367 2026] [security2:error] [pid 67073:tid 67302] [client 40.74.65.169:27756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/BDKR28WP.php"] [unique_id "aoSA7fcmepr5_nHgLbNmUgAAAnU"]
[Tue Aug 18 12:57:33.174999 2026] [security2:error] [pid 67073:tid 67245] [client 20.226.56.190:31678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ga.php"] [unique_id "aoSA7fcmepr5_nHgLbNmVAAAAjw"]
[Tue Aug 18 12:57:33.194334 2026] [security2:error] [pid 66623:tid 66867] [client 172.202.39.151:50182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSA7dO5rbWdOArH04KTewAAAW8"]
[Tue Aug 18 12:57:33.213988 2026] [autoindex:error] [pid 67073:tid 67325] [client 82.102.18.182:33894] AH01276: Cannot serve directory /home4/ctrrefrigeracao/public_html/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:33.217389 2026] [security2:error] [pid 66623:tid 66791] [client 74.248.18.37:31851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/php8.php"] [unique_id "aoSA7dO5rbWdOArH04KTfAAAASM"]
[Tue Aug 18 12:57:33.218018 2026] [security2:error] [pid 66623:tid 66850] [client 20.203.183.135:62163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/admin.php"] [unique_id "aoSA7dO5rbWdOArH04KTfQAAAV4"]
[Tue Aug 18 12:57:33.230295 2026] [security2:error] [pid 67073:tid 67303] [client 68.155.154.236:45605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSA7fcmepr5_nHgLbNmWAAAAnY"]
[Tue Aug 18 12:57:33.232453 2026] [security2:error] [pid 67073:tid 67276] [client 68.155.154.236:16269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSA7fcmepr5_nHgLbNmWQAAAls"]
[Tue Aug 18 12:57:33.274006 2026] [security2:error] [pid 67073:tid 67309] [client 40.74.65.169:4550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/scxy.php"] [unique_id "aoSA7fcmepr5_nHgLbNmWgAAAnw"]
[Tue Aug 18 12:57:33.279440 2026] [security2:error] [pid 67073:tid 67294] [client 104.209.144.33:33694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSA7fcmepr5_nHgLbNmXAAAAm0"]
[Tue Aug 18 12:57:33.311072 2026] [security2:error] [pid 66623:tid 66822] [client 20.119.58.187:11257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/network.php"] [unique_id "aoSA7dO5rbWdOArH04KTfwAAAUI"]
[Tue Aug 18 12:57:33.314849 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:33.315115 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:33.315554 2026] [authz_core:error] [pid 67073:tid 67110] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:33.315817 2026] [authz_core:error] [pid 67073:tid 67110] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:33.315902 2026] [authz_core:error] [pid 67073:tid 67174] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:33.316192 2026] [authz_core:error] [pid 67073:tid 67174] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:33.318741 2026] [security2:error] [pid 67073:tid 67237] [client 20.215.241.237:38211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/file.php"] [unique_id "aoSA7fcmepr5_nHgLbNmYAAAAjQ"]
[Tue Aug 18 12:57:33.396599 2026] [security2:error] [pid 66623:tid 66858] [client 20.100.185.105:6380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-good.php"] [unique_id "aoSA7dO5rbWdOArH04KTgAAAAWY"]
[Tue Aug 18 12:57:33.428181 2026] [security2:error] [pid 66623:tid 66856] [client 158.158.74.177:16566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSA7dO5rbWdOArH04KTggAAAWQ"]
[Tue Aug 18 12:57:33.441093 2026] [security2:error] [pid 66623:tid 66818] [client 74.248.18.37:3075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/index/function.php"] [unique_id "aoSA7dO5rbWdOArH04KTgwAAAT4"]
[Tue Aug 18 12:57:33.448014 2026] [security2:error] [pid 66623:tid 66877] [client 192.141.172.134:64362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSA7dO5rbWdOArH04KThAAAAXk"]
[Tue Aug 18 12:57:33.454729 2026] [security2:error] [pid 66623:tid 66877] [client 192.141.172.134:64362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSA7dO5rbWdOArH04KThAAAAXk"]
[Tue Aug 18 12:57:33.471751 2026] [security2:error] [pid 67073:tid 67238] [client 40.85.222.29:44262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSA7fcmepr5_nHgLbNmZwAAAjU"]
[Tue Aug 18 12:57:33.477338 2026] [security2:error] [pid 67073:tid 67247] [client 132.196.30.78:21894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/ncx.php"] [unique_id "aoSA7fcmepr5_nHgLbNmaAAAAj4"]
[Tue Aug 18 12:57:33.507311 2026] [security2:error] [pid 67073:tid 67219] [client 20.119.58.187:12490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/yindu.php"] [unique_id "aoSA7fcmepr5_nHgLbNmaQAAAiI"]
[Tue Aug 18 12:57:33.516843 2026] [security2:error] [pid 67073:tid 67315] [client 68.155.155.199:10403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSA7fcmepr5_nHgLbNmagAAAoI"]
[Tue Aug 18 12:57:33.530291 2026] [autoindex:error] [pid 67073:tid 67320] [client 20.119.58.187:2643] AH01276: Cannot serve directory /home3/slwebn28/portopreguicasresort.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:33.551753 2026] [security2:error] [pid 67073:tid 67082] [remote 162.55.89.48:51652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "polimentodemarmore.com.br"] [uri "/wp-login.php"] [unique_id "aoSA7fcmepr5_nHgLbNmbQACQAY"]
[Tue Aug 18 12:57:33.585475 2026] [security2:error] [pid 67073:tid 67300] [client 68.155.154.236:16255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSA7fcmepr5_nHgLbNmbgAAAnM"]
[Tue Aug 18 12:57:33.639101 2026] [security2:error] [pid 67073:tid 67216] [client 20.118.172.148:54861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/fpwch.php"] [unique_id "aoSA7fcmepr5_nHgLbNmbwAAAh8"]
[Tue Aug 18 12:57:33.664211 2026] [security2:error] [pid 67073:tid 67222] [client 20.119.58.187:11516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/new.php"] [unique_id "aoSA7fcmepr5_nHgLbNmcQAAAiU"]
[Tue Aug 18 12:57:33.707339 2026] [security2:error] [pid 67073:tid 67285] [client 20.100.169.31:48035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/w1.php"] [unique_id "aoSA7fcmepr5_nHgLbNmcgAAAmQ"]
[Tue Aug 18 12:57:33.710811 2026] [security2:error] [pid 67073:tid 67331] [client 172.182.200.96:14206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSA7fcmepr5_nHgLbNmcwAAApI"]
[Tue Aug 18 12:57:33.785290 2026] [security2:error] [pid 67073:tid 67229] [client 114.5.214.109:49815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA7fcmepr5_nHgLbNmdgAAAiw"]
[Tue Aug 18 12:57:33.791276 2026] [security2:error] [pid 67073:tid 67229] [client 114.5.214.109:49815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA7fcmepr5_nHgLbNmdgAAAiw"]
[Tue Aug 18 12:57:33.818967 2026] [security2:error] [pid 66623:tid 66806] [client 40.85.222.29:44251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSA7dO5rbWdOArH04KThwAAATI"]
[Tue Aug 18 12:57:33.838920 2026] [security2:error] [pid 66623:tid 66859] [client 74.7.228.16:41404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.coffeestationbrasil.com.br.culinariaemporio.com.br"] [uri "/index.php"] [unique_id "aoSA7NO5rbWdOArH04KTdQABZ0Q"]
[Tue Aug 18 12:57:33.862576 2026] [security2:error] [pid 67073:tid 67292] [client 20.119.58.187:12042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/class-db.php"] [unique_id "aoSA7fcmepr5_nHgLbNmegAAAms"]
[Tue Aug 18 12:57:33.868108 2026] [security2:error] [pid 67073:tid 67321] [client 20.215.241.237:8009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/dex.php"] [unique_id "aoSA7fcmepr5_nHgLbNmewAAAog"]
[Tue Aug 18 12:57:33.943969 2026] [security2:error] [pid 66623:tid 66876] [client 74.248.18.37:20497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/plugins.php"] [unique_id "aoSA7dO5rbWdOArH04KTigAAAXg"]
[Tue Aug 18 12:57:33.978634 2026] [security2:error] [pid 66623:tid 66886] [client 40.74.65.169:4551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSA7dO5rbWdOArH04KTiwAAAYI"]
[Tue Aug 18 12:57:34.019791 2026] [security2:error] [pid 67073:tid 67319] [client 20.100.185.105:25194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/goods.php"] [unique_id "aoSA7vcmepr5_nHgLbNmgwAAAoY"]
[Tue Aug 18 12:57:34.023046 2026] [security2:error] [pid 66623:tid 66776] [client 20.119.58.187:11285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/0x.php"] [unique_id "aoSA7tO5rbWdOArH04KTjQAAARQ"]
[Tue Aug 18 12:57:34.074610 2026] [security2:error] [pid 66623:tid 66853] [client 74.248.18.37:3657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/info.php"] [unique_id "aoSA7tO5rbWdOArH04KTjgAAAWE"]
[Tue Aug 18 12:57:34.099450 2026] [security2:error] [pid 67073:tid 67228] [client 40.85.222.29:44745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSA7vcmepr5_nHgLbNmhQAAAis"]
[Tue Aug 18 12:57:34.144457 2026] [security2:error] [pid 67073:tid 67154] [remote 216.194.122.158:56066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.122.194.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carnescapellari.top"] [uri "/wp-login.php"] [unique_id "aoSA7vcmepr5_nHgLbNmiQACjU4"]
[Tue Aug 18 12:57:34.144599 2026] [security2:error] [pid 67073:tid 67244] [client 104.209.144.33:19627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSA7vcmepr5_nHgLbNmiAAAAjs"]
[Tue Aug 18 12:57:34.165412 2026] [security2:error] [pid 67073:tid 67231] [client 213.35.127.232:55662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSA7vcmepr5_nHgLbNmigAAAi4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:34.215053 2026] [security2:error] [pid 67073:tid 67328] [client 68.155.154.236:40282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSA7vcmepr5_nHgLbNmjQAAAo8"]
[Tue Aug 18 12:57:34.225710 2026] [security2:error] [pid 67073:tid 67206] [client 4.232.151.198:4336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSA7vcmepr5_nHgLbNmjwAAAhU"]
[Tue Aug 18 12:57:34.242559 2026] [security2:error] [pid 67073:tid 67260] [client 40.74.65.169:43159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp.php"] [unique_id "aoSA7vcmepr5_nHgLbNmkAAAAks"]
[Tue Aug 18 12:57:34.274265 2026] [authz_core:error] [pid 67073:tid 67168] [remote 57.141.22.1:49298] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:34.274537 2026] [authz_core:error] [pid 67073:tid 67168] [remote 57.141.22.1:49298] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:34.279419 2026] [security2:error] [pid 67073:tid 67257] [client 20.48.236.86:48745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/av.php"] [unique_id "aoSA7vcmepr5_nHgLbNmkgAAAkg"]
[Tue Aug 18 12:57:34.326532 2026] [security2:error] [pid 67073:tid 67226] [client 132.196.30.78:21903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSA7vcmepr5_nHgLbNmlAAAAik"]
[Tue Aug 18 12:57:34.343585 2026] [security2:error] [pid 67073:tid 67276] [client 20.119.58.187:12037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known//index.php"] [unique_id "aoSA7vcmepr5_nHgLbNmlQAAAls"]
[Tue Aug 18 12:57:34.376225 2026] [security2:error] [pid 67073:tid 67239] [client 20.119.58.187:11217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/0.php"] [unique_id "aoSA7vcmepr5_nHgLbNmmAAAAjY"]
[Tue Aug 18 12:57:34.385060 2026] [security2:error] [pid 67073:tid 67294] [client 172.182.200.96:14177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSA7vcmepr5_nHgLbNmmQAAAm0"]
[Tue Aug 18 12:57:34.402515 2026] [security2:error] [pid 66623:tid 66777] [client 40.85.222.29:44778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSA7tO5rbWdOArH04KTkAAAARU"]
[Tue Aug 18 12:57:34.413743 2026] [security2:error] [pid 66623:tid 66771] [client 20.118.172.148:62140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSA7tO5rbWdOArH04KTkQAAAQ8"]
[Tue Aug 18 12:57:34.428299 2026] [security2:error] [pid 67073:tid 67306] [client 158.158.74.177:26163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/colors.php"] [unique_id "aoSA7vcmepr5_nHgLbNmnQAAAnk"]
[Tue Aug 18 12:57:34.434300 2026] [security2:error] [pid 67073:tid 67265] [client 20.215.241.237:8013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/key.php"] [unique_id "aoSA7vcmepr5_nHgLbNmngAAAlA"]
[Tue Aug 18 12:57:34.558372 2026] [security2:error] [pid 67073:tid 67329] [client 104.209.144.33:20471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSA7vcmepr5_nHgLbNmoAAAApA"]
[Tue Aug 18 12:57:34.592065 2026] [security2:error] [pid 67073:tid 67309] [client 74.248.18.37:35365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/post.php"] [unique_id "aoSA7vcmepr5_nHgLbNmogAAAnw"]
[Tue Aug 18 12:57:34.623427 2026] [security2:error] [pid 67073:tid 67213] [client 20.100.169.31:16136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/bolt.php"] [unique_id "aoSA7vcmepr5_nHgLbNmowAAAhw"]
[Tue Aug 18 12:57:34.647981 2026] [security2:error] [pid 67073:tid 67205] [client 20.100.185.105:6369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSA7vcmepr5_nHgLbNmqAAAAhQ"]
[Tue Aug 18 12:57:34.657227 2026] [security2:error] [pid 67073:tid 67315] [client 40.74.65.169:4866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSA7vcmepr5_nHgLbNmqQAAAoI"]
[Tue Aug 18 12:57:34.697880 2026] [security2:error] [pid 66623:tid 66842] [client 68.155.154.236:16209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/images/security.php"] [unique_id "aoSA7tO5rbWdOArH04KTlAAAAVY"]
[Tue Aug 18 12:57:34.707391 2026] [security2:error] [pid 67073:tid 67263] [client 74.248.18.37:27504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/profile.php"] [unique_id "aoSA7vcmepr5_nHgLbNmqwAAAk4"]
[Tue Aug 18 12:57:34.729336 2026] [security2:error] [pid 67073:tid 67238] [client 20.119.58.187:12494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/libraries/phpmailer//index.php"] [unique_id "aoSA7vcmepr5_nHgLbNmrAAAAjU"]
[Tue Aug 18 12:57:34.729341 2026] [security2:error] [pid 66623:tid 66795] [client 20.119.58.187:11208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/oxshell.php"] [unique_id "aoSA7tO5rbWdOArH04KTlgAAASc"]
[Tue Aug 18 12:57:34.775753 2026] [security2:error] [pid 67073:tid 67221] [client 40.85.222.29:44782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSA7vcmepr5_nHgLbNmsAAAAiQ"]
[Tue Aug 18 12:57:34.817214 2026] [security2:error] [pid 67073:tid 67251] [client 68.155.154.236:8001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSA7vcmepr5_nHgLbNmswAAAkI"]
[Tue Aug 18 12:57:34.878102 2026] [authz_core:error] [pid 66623:tid 66648] [remote 57.141.22.37:61138] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:34.878378 2026] [authz_core:error] [pid 66623:tid 66648] [remote 57.141.22.37:61138] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:34.920580 2026] [security2:error] [pid 67073:tid 67322] [client 4.232.151.198:4339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/akc.php"] [unique_id "aoSA7vcmepr5_nHgLbNmtgAAAok"]
[Tue Aug 18 12:57:34.942219 2026] [security2:error] [pid 67073:tid 67250] [client 132.196.30.78:18625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wso.php"] [unique_id "aoSA7vcmepr5_nHgLbNmuAAAAkE"]
[Tue Aug 18 12:57:35.034546 2026] [security2:error] [pid 66623:tid 66787] [client 68.155.155.199:7108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSA79O5rbWdOArH04KTmgAAAR8"]
[Tue Aug 18 12:57:35.060160 2026] [security2:error] [pid 67073:tid 67312] [client 40.74.65.169:11219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/i.php"] [unique_id "aoSA7_cmepr5_nHgLbNmwgAAAn8"]
[Tue Aug 18 12:57:35.079939 2026] [security2:error] [pid 67073:tid 67313] [client 20.65.98.162:39956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/fz.php"] [unique_id "aoSA7_cmepr5_nHgLbNmxAAAAoA"]
[Tue Aug 18 12:57:35.083594 2026] [authz_core:error] [pid 67073:tid 67139] [remote 57.141.22.25:57326] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:35.083862 2026] [authz_core:error] [pid 67073:tid 67139] [remote 57.141.22.25:57326] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:35.089256 2026] [security2:error] [pid 67073:tid 67268] [client 20.119.58.187:12485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "aoSA7_cmepr5_nHgLbNmxgAAAlM"]
[Tue Aug 18 12:57:35.095408 2026] [security2:error] [pid 67073:tid 67288] [client 20.119.58.187:11213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/php8.php"] [unique_id "aoSA7_cmepr5_nHgLbNmyQAAAmc"]
[Tue Aug 18 12:57:35.135694 2026] [security2:error] [pid 67073:tid 67319] [client 40.85.222.29:44271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSA7_cmepr5_nHgLbNmzAAAAoY"]
[Tue Aug 18 12:57:35.144013 2026] [security2:error] [pid 67073:tid 67287] [client 20.206.73.37:59958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSA7_cmepr5_nHgLbNmzQAAAmY"]
[Tue Aug 18 12:57:35.149259 2026] [security2:error] [pid 66623:tid 66865] [client 20.250.13.23:39668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-blink.php"] [unique_id "aoSA79O5rbWdOArH04KTmwAAAW0"]
[Tue Aug 18 12:57:35.168549 2026] [security2:error] [pid 66623:tid 66803] [client 20.118.172.148:54903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/about/function.php"] [unique_id "aoSA79O5rbWdOArH04KTnAAAAS8"]
[Tue Aug 18 12:57:35.176769 2026] [security2:error] [pid 67073:tid 67284] [client 213.35.127.232:55864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA7_cmepr5_nHgLbNmzwAAAmM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:35.233228 2026] [security2:error] [pid 67073:tid 67266] [client 158.158.34.183:11377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/BIBIL_0DAY.php/global.php"] [unique_id "aoSA7_cmepr5_nHgLbNm2AAAAlE"]
[Tue Aug 18 12:57:35.253886 2026] [autoindex:error] [pid 67073:tid 67227] [client 158.158.74.177:26131] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:35.265704 2026] [security2:error] [pid 67073:tid 67208] [client 20.100.185.105:42640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/cv.php"] [unique_id "aoSA7_cmepr5_nHgLbNm2QAAAhc"]
[Tue Aug 18 12:57:35.293401 2026] [security2:error] [pid 66623:tid 66829] [client 74.248.18.37:7213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/r.php"] [unique_id "aoSA79O5rbWdOArH04KTngAAAUk"]
[Tue Aug 18 12:57:35.346507 2026] [security2:error] [pid 66623:tid 66835] [client 40.74.65.169:4462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/blurbs.php"] [unique_id "aoSA79O5rbWdOArH04KTnwAAAU8"]
[Tue Aug 18 12:57:35.347476 2026] [security2:error] [pid 67073:tid 67087] [remote 151.240.45.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.45.240.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-login.php"] [unique_id "aoSA7_cmepr5_nHgLbNm4QACVAs"]
[Tue Aug 18 12:57:35.388110 2026] [security2:error] [pid 66623:tid 66793] [client 74.248.18.37:27515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/sx.php"] [unique_id "aoSA79O5rbWdOArH04KToAAAASU"]
[Tue Aug 18 12:57:35.440922 2026] [security2:error] [pid 67073:tid 67295] [client 20.215.241.237:55386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/kir.php"] [unique_id "aoSA7_cmepr5_nHgLbNm5gAAAm4"]
[Tue Aug 18 12:57:35.449355 2026] [security2:error] [pid 67073:tid 67236] [client 20.119.58.187:11232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/p.php"] [unique_id "aoSA7_cmepr5_nHgLbNm5wAAAjM"]
[Tue Aug 18 12:57:35.462192 2026] [security2:error] [pid 67073:tid 67264] [client 40.85.222.29:25036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSA7_cmepr5_nHgLbNm6AAAAk8"]
[Tue Aug 18 12:57:35.465998 2026] [security2:error] [pid 66623:tid 66820] [client 20.119.58.187:12492] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/blue//1.php"] [unique_id "aoSA79O5rbWdOArH04KToQAAAUA"]
[Tue Aug 18 12:57:35.466085 2026] [security2:error] [pid 66623:tid 66820] [client 20.119.58.187:12492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/blue//1.php"] [unique_id "aoSA79O5rbWdOArH04KToQAAAUA"]
[Tue Aug 18 12:57:35.468102 2026] [security2:error] [pid 67073:tid 67302] [client 158.158.74.177:26131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSA7_cmepr5_nHgLbNm6QAAAnU"]
[Tue Aug 18 12:57:35.529080 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:35.529541 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:35.563380 2026] [security2:error] [pid 66623:tid 66840] [client 4.232.151.198:24937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/buy.php"] [unique_id "aoSA79O5rbWdOArH04KTogAAAVQ"]
[Tue Aug 18 12:57:35.607511 2026] [security2:error] [pid 67073:tid 67306] [client 104.209.144.33:19585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/first.php"] [unique_id "aoSA7_cmepr5_nHgLbNm7wAAAnk"]
[Tue Aug 18 12:57:35.629416 2026] [security2:error] [pid 67073:tid 67265] [client 52.173.121.69:17928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA7_cmepr5_nHgLbNm8AAAAlA"]
[Tue Aug 18 12:57:35.679893 2026] [security2:error] [pid 67073:tid 67222] [client 157.51.166.53:49311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA7_cmepr5_nHgLbNm9AAAAiU"]
[Tue Aug 18 12:57:35.680010 2026] [security2:error] [pid 67073:tid 67222] [client 157.51.166.53:49311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA7_cmepr5_nHgLbNm9AAAAiU"]
[Tue Aug 18 12:57:35.741119 2026] [security2:error] [pid 67073:tid 67283] [client 40.85.222.29:26913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSA7_cmepr5_nHgLbNm9wAAAmI"]
[Tue Aug 18 12:57:35.788429 2026] [security2:error] [pid 66623:tid 66863] [client 20.203.183.135:60884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/mac.php"] [unique_id "aoSA79O5rbWdOArH04KTowAAAWs"]
[Tue Aug 18 12:57:35.801112 2026] [security2:error] [pid 67073:tid 67232] [client 20.119.58.187:11318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/php.php"] [unique_id "aoSA7_cmepr5_nHgLbNm-QAAAi8"]
[Tue Aug 18 12:57:35.804057 2026] [security2:error] [pid 66623:tid 66802] [client 40.74.65.169:11252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/abcd.php"] [unique_id "aoSA79O5rbWdOArH04KTpAAAAS4"]
[Tue Aug 18 12:57:35.821765 2026] [security2:error] [pid 67073:tid 67230] [client 20.119.58.187:12489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/BbUMY/flower.php"] [unique_id "aoSA7_cmepr5_nHgLbNm_AAAAi0"]
[Tue Aug 18 12:57:35.828568 2026] [authz_core:error] [pid 67073:tid 67126] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:35.828841 2026] [authz_core:error] [pid 67073:tid 67126] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:35.853969 2026] [security2:error] [pid 66623:tid 66798] [client 172.202.39.151:63106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSA79O5rbWdOArH04KTpQAAASo"]
[Tue Aug 18 12:57:35.866852 2026] [security2:error] [pid 66623:tid 66780] [client 20.118.172.148:62438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/function/function.php"] [unique_id "aoSA79O5rbWdOArH04KTpgAAARg"]
[Tue Aug 18 12:57:35.879339 2026] [security2:error] [pid 66623:tid 66830] [client 68.155.154.236:48921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSA79O5rbWdOArH04KTpwAAAUo"]
[Tue Aug 18 12:57:35.883695 2026] [security2:error] [pid 67073:tid 67253] [client 20.100.185.105:58290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/core.php"] [unique_id "aoSA7_cmepr5_nHgLbNm_gAAAkQ"]
[Tue Aug 18 12:57:35.920827 2026] [security2:error] [pid 66623:tid 66801] [client 132.196.30.78:21904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/zup.php73"] [unique_id "aoSA79O5rbWdOArH04KTqgAAAS0"]
[Tue Aug 18 12:57:35.987635 2026] [authz_core:error] [pid 67073:tid 67263] [client 192.178.4.133:46321] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:35.987917 2026] [authz_core:error] [pid 67073:tid 67263] [client 192.178.4.133:46321] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:35.995074 2026] [security2:error] [pid 67073:tid 67329] [client 74.248.18.37:20534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/radio.php"] [unique_id "aoSA7_cmepr5_nHgLbNnAgAAApA"]
[Tue Aug 18 12:57:36.020486 2026] [security2:error] [pid 67073:tid 67309] [client 74.248.18.37:3080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnBAAAAnw"]
[Tue Aug 18 12:57:36.020823 2026] [security2:error] [pid 67073:tid 67320] [client 40.85.222.29:26934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnBQAAAoc"]
[Tue Aug 18 12:57:36.047082 2026] [security2:error] [pid 67073:tid 67314] [client 40.74.65.169:4594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/bajah.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnBwAAAoE"]
[Tue Aug 18 12:57:36.189745 2026] [security2:error] [pid 66623:tid 66772] [client 213.35.127.232:56086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA8NO5rbWdOArH04KTrgAAARA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:36.191406 2026] [security2:error] [pid 67073:tid 67221] [client 20.119.58.187:12493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/ID3//file.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnCgAAAiQ"]
[Tue Aug 18 12:57:36.211119 2026] [security2:error] [pid 67073:tid 67251] [client 20.119.58.187:11322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/past.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnCwAAAkI"]
[Tue Aug 18 12:57:36.227362 2026] [security2:error] [pid 66623:tid 66667] [remote 129.121.123.168:60424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.123.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sprintlimp.com.br"] [uri "/wp-login.php"] [unique_id "aoSA8NO5rbWdOArH04KTrwABOB4"]
[Tue Aug 18 12:57:36.234684 2026] [security2:error] [pid 67073:tid 67262] [client 196.12.128.158:54714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnDQAAAk0"]
[Tue Aug 18 12:57:36.234783 2026] [security2:error] [pid 67073:tid 67262] [client 196.12.128.158:54714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnDQAAAk0"]
[Tue Aug 18 12:57:36.239610 2026] [security2:error] [pid 67073:tid 67238] [client 4.232.151.198:4350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/cong.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnDgAAAjU"]
[Tue Aug 18 12:57:36.259185 2026] [security2:error] [pid 67073:tid 67299] [client 158.158.74.177:16557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnDwAAAnI"]
[Tue Aug 18 12:57:36.270181 2026] [security2:error] [pid 67073:tid 67285] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnEAAAAmQ"]
[Tue Aug 18 12:57:36.300920 2026] [security2:error] [pid 67073:tid 67278] [client 40.85.222.29:26929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnEQAAAl0"]
[Tue Aug 18 12:57:36.318371 2026] [security2:error] [pid 67073:tid 67259] [client 158.158.34.183:19941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/updates.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnEwAAAko"]
[Tue Aug 18 12:57:36.383563 2026] [security2:error] [pid 67073:tid 67330] [client 52.173.121.69:25015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnFQAAApE"]
[Tue Aug 18 12:57:36.444038 2026] [authz_core:error] [pid 67073:tid 67115] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:36.444329 2026] [authz_core:error] [pid 67073:tid 67115] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:36.455335 2026] [security2:error] [pid 67073:tid 67242] [client 20.118.172.148:62127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-signin.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnGQAAAjk"]
[Tue Aug 18 12:57:36.503101 2026] [security2:error] [pid 67073:tid 67252] [client 20.100.185.105:29238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/ahax.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnHAAAAkM"]
[Tue Aug 18 12:57:36.539884 2026] [security2:error] [pid 66623:tid 66850] [client 40.74.65.169:30056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-manager.php"] [unique_id "aoSA8NO5rbWdOArH04KTsgAAAV4"]
[Tue Aug 18 12:57:36.557351 2026] [security2:error] [pid 67073:tid 67313] [client 20.119.58.187:12089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/Text/Diff/Engine//about.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnHQAAAoA"]
[Tue Aug 18 12:57:36.562267 2026] [security2:error] [pid 67073:tid 67288] [client 20.119.58.187:11477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/root.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnHgAAAmc"]
[Tue Aug 18 12:57:36.604875 2026] [security2:error] [pid 67073:tid 67326] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnIAAAAo0"]
[Tue Aug 18 12:57:36.606220 2026] [security2:error] [pid 67073:tid 67244] [client 68.155.155.199:4383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/atomlib.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnIQAAAjs"]
[Tue Aug 18 12:57:36.621717 2026] [security2:error] [pid 67073:tid 67256] [client 40.85.222.29:26896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnIgAAAkc"]
[Tue Aug 18 12:57:36.625958 2026] [security2:error] [pid 67073:tid 67266] [client 20.226.7.189:17671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/bthil.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnIwAAAlE"]
[Tue Aug 18 12:57:36.645351 2026] [security2:error] [pid 66623:tid 66815] [client 20.226.7.189:17664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/index/function.php"] [unique_id "aoSA8NO5rbWdOArH04KTswAAATs"]
[Tue Aug 18 12:57:36.671558 2026] [security2:error] [pid 67073:tid 67287] [client 74.248.18.37:27517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnJQAAAmY"]
[Tue Aug 18 12:57:36.674272 2026] [security2:error] [pid 67073:tid 67331] [client 20.118.133.132:16807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/images.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnJgAAApI"]
[Tue Aug 18 12:57:36.675942 2026] [security2:error] [pid 67073:tid 67258] [client 20.226.7.189:5517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnJwAAAkk"]
[Tue Aug 18 12:57:36.678413 2026] [security2:error] [pid 67073:tid 67090] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnKQACjw4"]
[Tue Aug 18 12:57:36.678516 2026] [security2:error] [pid 67073:tid 67328] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnKQACjw4"]
[Tue Aug 18 12:57:36.698979 2026] [security2:error] [pid 67073:tid 67310] [client 20.226.7.189:5530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/file5.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnKgAAAn0"]
[Tue Aug 18 12:57:36.718420 2026] [security2:error] [pid 67073:tid 67257] [client 20.226.7.189:1777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnKwAAAkg"]
[Tue Aug 18 12:57:36.720822 2026] [security2:error] [pid 67073:tid 67209] [client 40.74.65.169:4425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/domvf.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnLQAAAhg"]
[Tue Aug 18 12:57:36.737385 2026] [security2:error] [pid 67073:tid 67245] [client 20.226.7.189:1739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-includes/blocks/search/index.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnLgAAAjw"]
[Tue Aug 18 12:57:36.737387 2026] [security2:error] [pid 66623:tid 66779] [client 20.250.13.23:25719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/ww5.php"] [unique_id "aoSA8NO5rbWdOArH04KTtQAAARc"]
[Tue Aug 18 12:57:36.745808 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:36.746099 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:36.753466 2026] [security2:error] [pid 66623:tid 66775] [client 20.226.7.189:17675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/edit.php"] [unique_id "aoSA8NO5rbWdOArH04KTtwAAARM"]
[Tue Aug 18 12:57:36.763884 2026] [security2:error] [pid 66623:tid 66822] [client 79.127.164.8:45388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/mysqldump.sql"] [unique_id "aoSA8NO5rbWdOArH04KTuAAAAUI"], referer: https://medihub.com.br/mysqldump.sql
[Tue Aug 18 12:57:36.782780 2026] [security2:error] [pid 67073:tid 67224] [client 20.226.7.189:5526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/a.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnMgAAAic"]
[Tue Aug 18 12:57:36.803394 2026] [security2:error] [pid 67073:tid 67318] [client 20.226.7.189:5549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/w.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnMwAAAoU"]
[Tue Aug 18 12:57:36.818314 2026] [security2:error] [pid 67073:tid 67271] [client 20.215.241.237:25280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/nofile.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnNAAAAlY"]
[Tue Aug 18 12:57:36.841956 2026] [security2:error] [pid 67073:tid 67230] [client 20.226.7.189:1732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnNgAAAi0"]
[Tue Aug 18 12:57:36.842796 2026] [security2:error] [pid 67073:tid 67305] [client 74.248.18.37:20500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/randkeyword.php7"] [unique_id "aoSA8Pcmepr5_nHgLbNnNwAAAng"]
[Tue Aug 18 12:57:36.848308 2026] [security2:error] [pid 67073:tid 67220] [client 52.173.121.69:24983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/weozh.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnOAAAAiM"]
[Tue Aug 18 12:57:36.880268 2026] [security2:error] [pid 67073:tid 67329] [client 20.48.236.86:23289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/media.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnPgAAApA"]
[Tue Aug 18 12:57:36.882298 2026] [security2:error] [pid 67073:tid 67320] [client 20.226.7.189:17699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/0x.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnPwAAAoc"]
[Tue Aug 18 12:57:36.902382 2026] [security2:error] [pid 66623:tid 66877] [client 20.226.7.189:5506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/file.php"] [unique_id "aoSA8NO5rbWdOArH04KTuQAAAXk"]
[Tue Aug 18 12:57:36.913306 2026] [security2:error] [pid 67073:tid 67261] [client 132.196.30.78:18634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/k.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnQAAAAkw"]
[Tue Aug 18 12:57:36.913426 2026] [security2:error] [pid 67073:tid 67222] [client 20.119.58.187:11480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/r.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnQQAAAiU"]
[Tue Aug 18 12:57:36.919813 2026] [security2:error] [pid 67073:tid 67300] [client 20.226.7.189:5556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnQwAAAnM"]
[Tue Aug 18 12:57:36.936004 2026] [security2:error] [pid 67073:tid 67235] [client 20.119.58.187:12043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/Text/Diff/Engine//index.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnRAAAAjI"]
[Tue Aug 18 12:57:36.944494 2026] [security2:error] [pid 67073:tid 67325] [client 4.232.151.198:4296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnRQAAAow"]
[Tue Aug 18 12:57:36.946572 2026] [security2:error] [pid 67073:tid 67211] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnQgACGjo"]
[Tue Aug 18 12:57:36.953474 2026] [security2:error] [pid 67073:tid 67221] [client 104.209.144.33:29862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnSAAAAiQ"]
[Tue Aug 18 12:57:36.965222 2026] [security2:error] [pid 67073:tid 67216] [client 20.226.7.189:17703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnSQAAAh8"]
[Tue Aug 18 12:57:36.984147 2026] [security2:error] [pid 67073:tid 67312] [client 197.184.64.235:41937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnSwAAAn8"]
[Tue Aug 18 12:57:36.986229 2026] [security2:error] [pid 67073:tid 67254] [client 20.226.7.189:1783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnTAAAAkU"]
[Tue Aug 18 12:57:36.988294 2026] [security2:error] [pid 67073:tid 67312] [client 197.184.64.235:41937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnSwAAAn8"]
[Tue Aug 18 12:57:37.005891 2026] [security2:error] [pid 66623:tid 66890] [client 20.226.7.189:5564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/3.php"] [unique_id "aoSA8dO5rbWdOArH04KTugAAAYY"]
[Tue Aug 18 12:57:37.020428 2026] [security2:error] [pid 67073:tid 67259] [client 40.85.222.29:26890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSA8fcmepr5_nHgLbNnTwAAAko"]
[Tue Aug 18 12:57:37.028868 2026] [security2:error] [pid 67073:tid 67231] [client 20.226.7.189:17703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/config.php"] [unique_id "aoSA8fcmepr5_nHgLbNnUAAAAi4"]
[Tue Aug 18 12:57:37.047187 2026] [authz_core:error] [pid 67073:tid 67198] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:37.047444 2026] [authz_core:error] [pid 67073:tid 67198] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:37.049508 2026] [security2:error] [pid 67073:tid 67319] [client 20.226.7.189:1072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/simple.php"] [unique_id "aoSA8fcmepr5_nHgLbNnUwAAAoY"]
[Tue Aug 18 12:57:37.057872 2026] [security2:error] [pid 67073:tid 67107] [remote 216.194.122.158:33534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.122.194.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qriarfood.com"] [uri "/wp-login.php"] [unique_id "aoSA8fcmepr5_nHgLbNnVAACKR8"]
[Tue Aug 18 12:57:37.076254 2026] [security2:error] [pid 67073:tid 67313] [client 20.226.7.189:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/storage/index.php"] [unique_id "aoSA8fcmepr5_nHgLbNnVQAAAoA"]
[Tue Aug 18 12:57:37.097967 2026] [security2:error] [pid 67073:tid 67217] [client 20.226.7.189:17667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/themes.php"] [unique_id "aoSA8fcmepr5_nHgLbNnVgAAAiA"]
[Tue Aug 18 12:57:37.136089 2026] [security2:error] [pid 67073:tid 67323] [client 20.118.172.148:62098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/f35.php"] [unique_id "aoSA8fcmepr5_nHgLbNnWwAAAoo"]
[Tue Aug 18 12:57:37.146963 2026] [security2:error] [pid 67073:tid 67266] [client 20.226.7.189:17687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-content/packed.php"] [unique_id "aoSA8fcmepr5_nHgLbNnXQAAAlE"]
[Tue Aug 18 12:57:37.166843 2026] [security2:error] [pid 67073:tid 67287] [client 20.226.7.189:17672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSA8fcmepr5_nHgLbNnXgAAAmY"]
[Tue Aug 18 12:57:37.199132 2026] [security2:error] [pid 66623:tid 66813] [client 20.226.7.189:5504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-themes.php"] [unique_id "aoSA8dO5rbWdOArH04KTvQAAATk"]
[Tue Aug 18 12:57:37.202222 2026] [security2:error] [pid 67073:tid 67219] [client 213.35.127.232:56316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSA8fcmepr5_nHgLbNnXwAAAiI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:37.220833 2026] [security2:error] [pid 67073:tid 67206] [client 20.226.7.189:5507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/xda.php"] [unique_id "aoSA8fcmepr5_nHgLbNnYAAAAhU"]
[Tue Aug 18 12:57:37.240890 2026] [security2:error] [pid 66623:tid 66816] [client 20.226.7.189:1788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSA8dO5rbWdOArH04KTvgAAATw"]
[Tue Aug 18 12:57:37.245781 2026] [security2:error] [pid 67073:tid 67280] [client 158.158.74.177:22743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "aoSA8fcmepr5_nHgLbNnYgAAAl8"]
[Tue Aug 18 12:57:37.248649 2026] [security2:error] [pid 66623:tid 66810] [client 142.111.55.8:16122] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSA8NO5rbWdOArH04KTtgAAATY"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/
[Tue Aug 18 12:57:37.270026 2026] [security2:error] [pid 67073:tid 67260] [client 20.226.7.189:5532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/15.php"] [unique_id "aoSA8fcmepr5_nHgLbNnYwAAAks"]
[Tue Aug 18 12:57:37.292650 2026] [security2:error] [pid 67073:tid 67258] [client 20.119.58.187:12052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/css//index.php"] [unique_id "aoSA8fcmepr5_nHgLbNnZAAAAkk"]
[Tue Aug 18 12:57:37.294566 2026] [security2:error] [pid 66623:tid 66776] [client 20.226.7.189:1735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/403.php"] [unique_id "aoSA8dO5rbWdOArH04KTvwAAARQ"]
[Tue Aug 18 12:57:37.316552 2026] [security2:error] [pid 67073:tid 67257] [client 20.226.7.189:1757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/404webshell.php"] [unique_id "aoSA8fcmepr5_nHgLbNnaAAAAkg"]
[Tue Aug 18 12:57:37.323329 2026] [security2:error] [pid 67073:tid 67324] [client 40.74.65.169:11215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSA8fcmepr5_nHgLbNnaQAAAos"]
[Tue Aug 18 12:57:37.332126 2026] [security2:error] [pid 67073:tid 67302] [client 20.100.185.105:58873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/contact_tpl.php"] [unique_id "aoSA8fcmepr5_nHgLbNnagAAAnU"]
[Tue Aug 18 12:57:37.334965 2026] [security2:error] [pid 67073:tid 67269] [client 20.119.58.187:11317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/sid3.php"] [unique_id "aoSA8fcmepr5_nHgLbNnawAAAlQ"]
[Tue Aug 18 12:57:37.336669 2026] [security2:error] [pid 67073:tid 67264] [client 20.226.7.189:5540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/666.php"] [unique_id "aoSA8fcmepr5_nHgLbNnbAAAAk8"]
[Tue Aug 18 12:57:37.350147 2026] [authz_core:error] [pid 67073:tid 67171] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:37.350613 2026] [authz_core:error] [pid 67073:tid 67171] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:37.357125 2026] [security2:error] [pid 67073:tid 67303] [client 20.226.7.189:1734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/7.php"] [unique_id "aoSA8fcmepr5_nHgLbNnbgAAAnY"]
[Tue Aug 18 12:57:37.379296 2026] [security2:error] [pid 67073:tid 67237] [client 20.226.7.189:1753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/a7.php"] [unique_id "aoSA8fcmepr5_nHgLbNncAAAAjQ"]
[Tue Aug 18 12:57:37.382872 2026] [security2:error] [pid 66623:tid 66811] [client 20.215.241.237:38254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/fling.php"] [unique_id "aoSA8dO5rbWdOArH04KTwQAAATc"]
[Tue Aug 18 12:57:37.400860 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.7.189:1745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/alfadheat.php"] [unique_id "aoSA8fcmepr5_nHgLbNncQAAAlg"]
[Tue Aug 18 12:57:37.411518 2026] [security2:error] [pid 67073:tid 67318] [client 40.74.65.169:4456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/fpwch.php"] [unique_id "aoSA8fcmepr5_nHgLbNncwAAAoU"]
[Tue Aug 18 12:57:37.420176 2026] [security2:error] [pid 67073:tid 67255] [client 20.226.7.189:1747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/apikey/mar.php"] [unique_id "aoSA8fcmepr5_nHgLbNndAAAAkY"]
[Tue Aug 18 12:57:37.431122 2026] [security2:error] [pid 67073:tid 67230] [client 68.155.155.199:5075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/min.php"] [unique_id "aoSA8fcmepr5_nHgLbNndQAAAi0"]
[Tue Aug 18 12:57:37.439218 2026] [security2:error] [pid 67073:tid 67305] [client 20.226.7.189:17693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/assetsalfa.php"] [unique_id "aoSA8fcmepr5_nHgLbNndgAAAng"]
[Tue Aug 18 12:57:37.463535 2026] [security2:error] [pid 67073:tid 67205] [client 20.226.7.189:1743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/init.php"] [unique_id "aoSA8fcmepr5_nHgLbNndwAAAhQ"]
[Tue Aug 18 12:57:37.482551 2026] [security2:error] [pid 67073:tid 67309] [client 20.226.7.189:5509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/bak.php"] [unique_id "aoSA8fcmepr5_nHgLbNneQAAAnw"]
[Tue Aug 18 12:57:37.490922 2026] [security2:error] [pid 67073:tid 67279] [client 74.248.18.37:35372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/red.php"] [unique_id "aoSA8fcmepr5_nHgLbNnegAAAl4"]
[Tue Aug 18 12:57:37.501599 2026] [security2:error] [pid 67073:tid 67249] [client 20.226.7.189:5534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/bgymj.php"] [unique_id "aoSA8fcmepr5_nHgLbNnfAAAAkA"]
[Tue Aug 18 12:57:37.521801 2026] [security2:error] [pid 67073:tid 67300] [client 74.248.18.37:27508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSA8fcmepr5_nHgLbNnfQAAAnM"]
[Tue Aug 18 12:57:37.529193 2026] [security2:error] [pid 67073:tid 67310] [client 132.196.30.78:18753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-blink.php"] [unique_id "aoSA8fcmepr5_nHgLbNnfwAAAn0"]
[Tue Aug 18 12:57:37.535141 2026] [security2:error] [pid 67073:tid 67248] [client 20.226.7.189:5544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/class-t.api.php"] [unique_id "aoSA8fcmepr5_nHgLbNngAAAAj8"]
[Tue Aug 18 12:57:37.555497 2026] [security2:error] [pid 67073:tid 67297] [client 20.226.7.189:17680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/class.php"] [unique_id "aoSA8fcmepr5_nHgLbNngQAAAnA"]
[Tue Aug 18 12:57:37.592879 2026] [security2:error] [pid 66623:tid 66884] [client 20.118.172.148:62441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/gg.php"] [unique_id "aoSA8dO5rbWdOArH04KTxQAAAYA"]
[Tue Aug 18 12:57:37.643995 2026] [security2:error] [pid 67073:tid 67265] [client 4.232.151.198:4319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/db.php"] [unique_id "aoSA8fcmepr5_nHgLbNnhQAAAlA"]
[Tue Aug 18 12:57:37.649554 2026] [authz_core:error] [pid 67073:tid 67095] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:37.649818 2026] [authz_core:error] [pid 67073:tid 67095] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:37.679688 2026] [security2:error] [pid 67073:tid 67290] [client 52.173.121.69:17952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/rymmm.php"] [unique_id "aoSA8fcmepr5_nHgLbNnhwAAAmk"]
[Tue Aug 18 12:57:37.688011 2026] [security2:error] [pid 66623:tid 66849] [client 20.119.58.187:11203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/ss.php"] [unique_id "aoSA8dO5rbWdOArH04KTxwAAAV0"]
[Tue Aug 18 12:57:37.689828 2026] [security2:error] [pid 67073:tid 67251] [client 20.119.58.187:12048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/css//xc.php"] [unique_id "aoSA8fcmepr5_nHgLbNniQAAAkI"]
[Tue Aug 18 12:57:37.882030 2026] [security2:error] [pid 66623:tid 66769] [client 40.85.222.29:44257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSA8dO5rbWdOArH04KTzAAAAQ0"]
[Tue Aug 18 12:57:37.943641 2026] [security2:error] [pid 66623:tid 66810] [client 142.111.55.8:16122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSA8NO5rbWdOArH04KTtgAAATY"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/
[Tue Aug 18 12:57:37.951997 2026] [security2:error] [pid 67073:tid 67234] [client 20.100.185.105:40001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/alfa-rex.php"] [unique_id "aoSA8fcmepr5_nHgLbNnnwAAAjE"]
[Tue Aug 18 12:57:37.960323 2026] [autoindex:error] [pid 66623:tid 66842] [client 158.158.74.177:22736] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:38.046399 2026] [security2:error] [pid 67073:tid 67256] [client 20.119.58.187:12054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/images//about.php"] [unique_id "aoSA8vcmepr5_nHgLbNnowAAAkc"]
[Tue Aug 18 12:57:38.059682 2026] [security2:error] [pid 67073:tid 67291] [client 20.119.58.187:11242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/sts.php"] [unique_id "aoSA8vcmepr5_nHgLbNnpAAAAmo"]
[Tue Aug 18 12:57:38.085105 2026] [security2:error] [pid 67073:tid 67212] [client 40.74.65.169:4128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/adminner.php"] [unique_id "aoSA8vcmepr5_nHgLbNnpQAAAhs"]
[Tue Aug 18 12:57:38.091057 2026] [security2:error] [pid 67073:tid 67328] [client 40.74.65.169:11208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSA8vcmepr5_nHgLbNnpwAAAo8"]
[Tue Aug 18 12:57:38.091616 2026] [security2:error] [pid 67073:tid 67331] [client 192.141.172.134:64614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8vcmepr5_nHgLbNnqAAAApI"]
[Tue Aug 18 12:57:38.091703 2026] [security2:error] [pid 67073:tid 67331] [client 192.141.172.134:64614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8vcmepr5_nHgLbNnqAAAApI"]
[Tue Aug 18 12:57:38.109499 2026] [security2:error] [pid 67073:tid 67280] [client 52.173.121.69:17968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/lddxs.php"] [unique_id "aoSA8vcmepr5_nHgLbNnqgAAAl8"]
[Tue Aug 18 12:57:38.111359 2026] [security2:error] [pid 67073:tid 67292] [client 172.182.200.96:14185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/nwwha.php"] [unique_id "aoSA8vcmepr5_nHgLbNnqwAAAms"]
[Tue Aug 18 12:57:38.158654 2026] [security2:error] [pid 67073:tid 67266] [client 74.248.18.37:35390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/release.php"] [unique_id "aoSA8vcmepr5_nHgLbNnrgAAAlE"]
[Tue Aug 18 12:57:38.161310 2026] [autoindex:error] [pid 67073:tid 67308] [client 20.100.169.31:42185] AH01276: Cannot serve directory /home1/lubarbosa/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:38.165355 2026] [security2:error] [pid 66623:tid 66839] [client 158.158.74.177:22736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/colors/ectoplasm/about.php"] [unique_id "aoSA8tO5rbWdOArH04KTzwAAAVM"]
[Tue Aug 18 12:57:38.186388 2026] [security2:error] [pid 66623:tid 66783] [client 20.118.172.148:56515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/class.php"] [unique_id "aoSA8tO5rbWdOArH04KT0AAAARs"]
[Tue Aug 18 12:57:38.206798 2026] [security2:error] [pid 66623:tid 66820] [client 40.85.222.29:26889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSA8tO5rbWdOArH04KT0QAAAUA"]
[Tue Aug 18 12:57:38.207649 2026] [security2:error] [pid 66623:tid 66892] [client 20.206.73.37:59900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSA8tO5rbWdOArH04KT0gAAAYg"]
[Tue Aug 18 12:57:38.217369 2026] [security2:error] [pid 67073:tid 67217] [client 213.35.127.232:56543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSA8vcmepr5_nHgLbNnsAAAAiA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:38.242061 2026] [security2:error] [pid 66623:tid 66848] [client 213.202.253.4:54342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/wp-content/schallfuns.php"] [unique_id "aoSA8tO5rbWdOArH04KT0wAAAVw"], referer: www.google.com
[Tue Aug 18 12:57:38.284014 2026] [security2:error] [pid 66623:tid 66846] [client 4.232.151.198:4310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/dropdown.php"] [unique_id "aoSA8tO5rbWdOArH04KT1AAAAVo"]
[Tue Aug 18 12:57:38.303786 2026] [security2:error] [pid 67073:tid 67245] [client 68.155.155.199:7370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/mac.php"] [unique_id "aoSA8vcmepr5_nHgLbNntQAAAjw"]
[Tue Aug 18 12:57:38.357727 2026] [security2:error] [pid 67073:tid 67277] [client 20.215.241.237:25301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/zoo1.php"] [unique_id "aoSA8vcmepr5_nHgLbNnuAAAAlw"]
[Tue Aug 18 12:57:38.377769 2026] [security2:error] [pid 67073:tid 67224] [client 74.248.18.37:27496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/about.php"] [unique_id "aoSA8vcmepr5_nHgLbNnuQAAAic"]
[Tue Aug 18 12:57:38.410888 2026] [security2:error] [pid 66623:tid 66823] [client 20.119.58.187:12484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/images/crystal//index.php"] [unique_id "aoSA8tO5rbWdOArH04KT1gAAAUM"]
[Tue Aug 18 12:57:38.426934 2026] [security2:error] [pid 67073:tid 67303] [client 20.119.58.187:11459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/shell.php"] [unique_id "aoSA8vcmepr5_nHgLbNnvAAAAnY"]
[Tue Aug 18 12:57:38.466136 2026] [security2:error] [pid 66623:tid 66841] [client 20.65.98.162:45896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/clque.php"] [unique_id "aoSA8tO5rbWdOArH04KT2AAAAVU"]
[Tue Aug 18 12:57:38.507911 2026] [security2:error] [pid 67073:tid 67230] [client 40.85.222.29:44241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSA8vcmepr5_nHgLbNnvwAAAi0"]
[Tue Aug 18 12:57:38.527013 2026] [security2:error] [pid 67073:tid 67240] [client 52.173.121.69:24984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/zjggu.php"] [unique_id "aoSA8vcmepr5_nHgLbNnygAAAjc"]
[Tue Aug 18 12:57:38.553806 2026] [authz_core:error] [pid 67073:tid 67166] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:38.554081 2026] [authz_core:error] [pid 67073:tid 67166] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:38.576523 2026] [security2:error] [pid 66623:tid 66863] [client 20.203.183.135:58262] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.amigosdoronron.com.br"] [uri "/1.php"] [unique_id "aoSA8tO5rbWdOArH04KT2QAAAWs"]
[Tue Aug 18 12:57:38.576614 2026] [security2:error] [pid 66623:tid 66863] [client 20.203.183.135:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/1.php"] [unique_id "aoSA8tO5rbWdOArH04KT2QAAAWs"]
[Tue Aug 18 12:57:38.586955 2026] [security2:error] [pid 67073:tid 67281] [client 20.100.169.31:42185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-login.php"] [unique_id "aoSA8vcmepr5_nHgLbNnuwAAAmA"]
[Tue Aug 18 12:57:38.652072 2026] [security2:error] [pid 67073:tid 67279] [client 132.196.30.78:21872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/ww5.php"] [unique_id "aoSA8vcmepr5_nHgLbNnzgAAAl4"]
[Tue Aug 18 12:57:38.691443 2026] [security2:error] [pid 66623:tid 66831] [client 20.118.172.148:62410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/flower.php"] [unique_id "aoSA8tO5rbWdOArH04KT2gAAAUs"]
[Tue Aug 18 12:57:38.738123 2026] [security2:error] [pid 67073:tid 67237] [client 20.100.185.105:29232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-login.php"] [unique_id "aoSA8vcmepr5_nHgLbNnzAAAAjQ"]
[Tue Aug 18 12:57:38.766757 2026] [security2:error] [pid 67073:tid 67213] [client 20.119.58.187:12498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp//index.php"] [unique_id "aoSA8vcmepr5_nHgLbNn1QAAAhw"]
[Tue Aug 18 12:57:38.767956 2026] [security2:error] [pid 67073:tid 67310] [client 40.74.65.169:4548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/abcd.php"] [unique_id "aoSA8vcmepr5_nHgLbNn1gAAAn0"]
[Tue Aug 18 12:57:38.777071 2026] [security2:error] [pid 67073:tid 67320] [client 20.119.58.187:11273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/setup-config.php"] [unique_id "aoSA8vcmepr5_nHgLbNn2AAAAoc"]
[Tue Aug 18 12:57:38.789359 2026] [security2:error] [pid 67073:tid 67248] [client 40.85.222.29:26880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSA8vcmepr5_nHgLbNn2QAAAj8"]
[Tue Aug 18 12:57:38.859985 2026] [security2:error] [pid 67073:tid 67309] [client 74.248.18.37:31823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/reop3.php"] [unique_id "aoSA8vcmepr5_nHgLbNn3QAAAnw"]
[Tue Aug 18 12:57:38.913671 2026] [security2:error] [pid 67073:tid 67299] [client 52.173.121.69:17944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/dlvqo.php"] [unique_id "aoSA8vcmepr5_nHgLbNn4AAAAnI"]
[Tue Aug 18 12:57:38.917755 2026] [security2:error] [pid 67073:tid 67290] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSA8vcmepr5_nHgLbNn4QAAAmk"]
[Tue Aug 18 12:57:38.918860 2026] [authz_core:error] [pid 67073:tid 67146] [remote 57.141.22.25:57342] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:38.919231 2026] [authz_core:error] [pid 67073:tid 67146] [remote 57.141.22.25:57342] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:38.923232 2026] [security2:error] [pid 67073:tid 67261] [client 4.232.151.198:4468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/file.php"] [unique_id "aoSA8vcmepr5_nHgLbNn4gAAAkw"]
[Tue Aug 18 12:57:38.963326 2026] [security2:error] [pid 67073:tid 67272] [client 68.155.156.252:18403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/abcd.php"] [unique_id "aoSA8vcmepr5_nHgLbNn6QAAAlc"]
[Tue Aug 18 12:57:39.009221 2026] [security2:error] [pid 67073:tid 67330] [client 20.215.241.237:38235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/zoo2.php"] [unique_id "aoSA8_cmepr5_nHgLbNn9gAAApE"]
[Tue Aug 18 12:57:39.023587 2026] [security2:error] [pid 67073:tid 67236] [client 158.158.74.177:26167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/colors/ectoplasm/wp-login.php"] [unique_id "aoSA8vcmepr5_nHgLbNn2wAAAjM"]
[Tue Aug 18 12:57:39.023593 2026] [security2:error] [pid 66623:tid 66830] [client 74.248.18.37:3083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSA89O5rbWdOArH04KT2wAAAUo"]
[Tue Aug 18 12:57:39.066128 2026] [security2:error] [pid 67073:tid 67216] [client 20.250.13.23:47033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/2.php"] [unique_id "aoSA8_cmepr5_nHgLbNn-AAAAh8"]
[Tue Aug 18 12:57:39.095874 2026] [security2:error] [pid 67073:tid 67252] [client 40.85.222.29:44236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSA8_cmepr5_nHgLbNn-QAAAkM"]
[Tue Aug 18 12:57:39.124396 2026] [security2:error] [pid 67073:tid 67231] [client 20.119.58.187:12487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/user.php"] [unique_id "aoSA8_cmepr5_nHgLbNn-wAAAi4"]
[Tue Aug 18 12:57:39.129434 2026] [security2:error] [pid 67073:tid 67233] [client 20.119.58.187:11284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/t.php"] [unique_id "aoSA8_cmepr5_nHgLbNn_AAAAjA"]
[Tue Aug 18 12:57:39.195370 2026] [security2:error] [pid 67073:tid 67226] [client 40.74.65.169:44757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/simple.php"] [unique_id "aoSA8_cmepr5_nHgLbNoAAAAAik"]
[Tue Aug 18 12:57:39.209609 2026] [security2:error] [pid 67073:tid 67246] [client 68.155.155.199:13332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/nc4.php"] [unique_id "aoSA8_cmepr5_nHgLbNoBAAAAj0"]
[Tue Aug 18 12:57:39.219337 2026] [security2:error] [pid 66623:tid 66774] [client 178.156.184.20:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jlyclimatizacao.com.br"] [uri "/index.php"] [unique_id "aoSA8dO5rbWdOArH04KTxgABEgw"], referer: https://jlyclimatizacao.com.br/
[Tue Aug 18 12:57:39.232600 2026] [security2:error] [pid 67073:tid 67312] [client 213.35.127.232:56773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSA8_cmepr5_nHgLbNoBgAAAn8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:39.264021 2026] [security2:error] [pid 67073:tid 67219] [client 20.118.172.148:62126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/motu.php"] [unique_id "aoSA8_cmepr5_nHgLbNoBwAAAiI"]
[Tue Aug 18 12:57:39.308354 2026] [security2:error] [pid 67073:tid 67212] [client 52.173.121.69:16471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/pkmoj.php"] [unique_id "aoSA8_cmepr5_nHgLbNoCAAAAhs"]
[Tue Aug 18 12:57:39.332863 2026] [security2:error] [pid 67073:tid 67315] [client 103.184.169.37:42195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8_cmepr5_nHgLbNoCgAAAoI"]
[Tue Aug 18 12:57:39.332997 2026] [security2:error] [pid 67073:tid 67315] [client 103.184.169.37:42195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8_cmepr5_nHgLbNoCgAAAoI"]
[Tue Aug 18 12:57:39.363714 2026] [security2:error] [pid 67073:tid 67285] [client 20.100.185.105:6382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/Auth.php"] [unique_id "aoSA8_cmepr5_nHgLbNoDAAAAmQ"]
[Tue Aug 18 12:57:39.411434 2026] [security2:error] [pid 67073:tid 67289] [client 40.85.222.29:44775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSA8_cmepr5_nHgLbNoDwAAAmg"]
[Tue Aug 18 12:57:39.462276 2026] [security2:error] [pid 67073:tid 67210] [client 104.209.144.33:25606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSA8_cmepr5_nHgLbNoEAAAAhk"]
[Tue Aug 18 12:57:39.482923 2026] [security2:error] [pid 67073:tid 67280] [client 20.119.58.187:12070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-2019.php"] [unique_id "aoSA8_cmepr5_nHgLbNoEQAAAl8"]
[Tue Aug 18 12:57:39.518951 2026] [security2:error] [pid 67073:tid 67292] [client 20.119.58.187:11321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/up.php"] [unique_id "aoSA8_cmepr5_nHgLbNoEwAAAms"]
[Tue Aug 18 12:57:39.525451 2026] [security2:error] [pid 67073:tid 67243] [client 103.120.71.157:13277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8_cmepr5_nHgLbNoFAAAAjo"]
[Tue Aug 18 12:57:39.525550 2026] [security2:error] [pid 67073:tid 67243] [client 103.120.71.157:13277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8_cmepr5_nHgLbNoFAAAAjo"]
[Tue Aug 18 12:57:39.563952 2026] [security2:error] [pid 67073:tid 67275] [client 4.232.151.198:24950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/goods.php"] [unique_id "aoSA8_cmepr5_nHgLbNoFQAAAlo"]
[Tue Aug 18 12:57:39.597593 2026] [security2:error] [pid 67073:tid 67254] [client 20.100.169.31:14570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/bthil.php"] [unique_id "aoSA8_cmepr5_nHgLbNoGAAAAkU"]
[Tue Aug 18 12:57:39.600388 2026] [security2:error] [pid 67073:tid 67291] [client 74.248.18.37:20516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/robots.php"] [unique_id "aoSA8_cmepr5_nHgLbNoGQAAAmo"]
[Tue Aug 18 12:57:39.623333 2026] [security2:error] [pid 67073:tid 67318] [client 172.202.39.151:65257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp.php"] [unique_id "aoSA8_cmepr5_nHgLbNoGwAAAoU"]
[Tue Aug 18 12:57:39.651931 2026] [security2:error] [pid 67073:tid 67227] [client 74.248.18.37:3101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/admin.php"] [unique_id "aoSA8_cmepr5_nHgLbNoHAAAAio"]
[Tue Aug 18 12:57:39.653793 2026] [security2:error] [pid 67073:tid 67232] [client 52.173.121.69:17923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/kopyw.php"] [unique_id "aoSA8_cmepr5_nHgLbNoHgAAAi8"]
[Tue Aug 18 12:57:39.666927 2026] [security2:error] [pid 66623:tid 66844] [client 20.203.183.135:60866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/coffee.php"] [unique_id "aoSA89O5rbWdOArH04KT3wAAAVg"]
[Tue Aug 18 12:57:39.698001 2026] [security2:error] [pid 67073:tid 67217] [client 158.158.74.177:2624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSA8_cmepr5_nHgLbNoIAAAAiA"]
[Tue Aug 18 12:57:39.702151 2026] [security2:error] [pid 66623:tid 66852] [client 40.85.222.29:44259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSA89O5rbWdOArH04KT4AAAAWA"]
[Tue Aug 18 12:57:39.741618 2026] [security2:error] [pid 67073:tid 67247] [client 20.215.241.237:38216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/org.php"] [unique_id "aoSA8_cmepr5_nHgLbNoIwAAAj4"]
[Tue Aug 18 12:57:39.744378 2026] [security2:error] [pid 66623:tid 66893] [client 20.118.172.148:54864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/404.php"] [unique_id "aoSA89O5rbWdOArH04KT4gAAAYk"]
[Tue Aug 18 12:57:39.745312 2026] [security2:error] [pid 67073:tid 67253] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/av.php"] [unique_id "aoSA8_cmepr5_nHgLbNoJAAAAkQ"]
[Tue Aug 18 12:57:39.759205 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:39.759468 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:39.819494 2026] [security2:error] [pid 67073:tid 67249] [client 68.155.154.236:40259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSA8_cmepr5_nHgLbNoLgAAAkA"]
[Tue Aug 18 12:57:39.847346 2026] [security2:error] [pid 66623:tid 66837] [client 20.119.58.187:12093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/functions.php"] [unique_id "aoSA89O5rbWdOArH04KT5AAAAVE"]
[Tue Aug 18 12:57:39.871618 2026] [security2:error] [pid 67073:tid 67208] [client 20.119.58.187:11464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/ultra.php"] [unique_id "aoSA8_cmepr5_nHgLbNoMAAAAhc"]
[Tue Aug 18 12:57:39.989600 2026] [security2:error] [pid 67073:tid 67329] [client 20.100.185.105:43339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/axx.php"] [unique_id "aoSA8_cmepr5_nHgLbNoNAAAApA"]
[Tue Aug 18 12:57:40.013651 2026] [security2:error] [pid 67073:tid 67251] [client 52.173.121.69:16452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/zznmg.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoNgAAAkI"]
[Tue Aug 18 12:57:40.017610 2026] [security2:error] [pid 67073:tid 67259] [client 40.85.222.29:26895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoOQAAAko"]
[Tue Aug 18 12:57:40.058270 2026] [authz_core:error] [pid 67073:tid 67118] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:40.058543 2026] [authz_core:error] [pid 67073:tid 67118] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:40.107788 2026] [security2:error] [pid 67073:tid 67313] [client 132.196.30.78:21878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/2.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoPAAAAoA"]
[Tue Aug 18 12:57:40.115539 2026] [security2:error] [pid 67073:tid 67216] [client 20.118.172.148:56533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/lite.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoPwAAAh8"]
[Tue Aug 18 12:57:40.138158 2026] [security2:error] [pid 67073:tid 67319] [client 68.155.155.199:4409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/as.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoQQAAAoY"]
[Tue Aug 18 12:57:40.173791 2026] [security2:error] [pid 66623:tid 66773] [client 20.100.169.31:41650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/default.php"] [unique_id "aoSA9NO5rbWdOArH04KT5wAAARE"]
[Tue Aug 18 12:57:40.198270 2026] [security2:error] [pid 67073:tid 67330] [client 20.119.58.187:12528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cron.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoRAAAApE"]
[Tue Aug 18 12:57:40.209759 2026] [security2:error] [pid 67073:tid 67309] [client 4.232.151.198:4326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/hplfuns.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoSAAAAnw"]
[Tue Aug 18 12:57:40.214386 2026] [security2:error] [pid 66623:tid 66772] [client 86.120.159.145:57734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9NO5rbWdOArH04KT6AAAARA"]
[Tue Aug 18 12:57:40.214471 2026] [security2:error] [pid 66623:tid 66772] [client 86.120.159.145:57734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9NO5rbWdOArH04KT6AAAARA"]
[Tue Aug 18 12:57:40.226362 2026] [security2:error] [pid 67073:tid 67317] [client 20.119.58.187:11472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/vv.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoSQAAAoQ"]
[Tue Aug 18 12:57:40.238492 2026] [security2:error] [pid 67073:tid 67207] [client 40.74.65.169:30073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/chosen.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoSwAAAhY"]
[Tue Aug 18 12:57:40.242916 2026] [security2:error] [pid 67073:tid 67221] [client 213.35.127.232:56972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoTAAAAiQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:40.257464 2026] [security2:error] [pid 66623:tid 66882] [client 20.215.241.237:25314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/imageskir.php"] [unique_id "aoSA9NO5rbWdOArH04KT6QAAAX4"]
[Tue Aug 18 12:57:40.260991 2026] [security2:error] [pid 66623:tid 66791] [client 74.248.18.37:20542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/root.php"] [unique_id "aoSA9NO5rbWdOArH04KT6gAAASM"]
[Tue Aug 18 12:57:40.282005 2026] [security2:error] [pid 67073:tid 67238] [client 74.248.18.37:3653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/content.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoTgAAAjU"]
[Tue Aug 18 12:57:40.312119 2026] [security2:error] [pid 67073:tid 67326] [client 40.85.222.29:44774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoTwAAAo0"]
[Tue Aug 18 12:57:40.362363 2026] [authz_core:error] [pid 67073:tid 67137] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:40.362734 2026] [authz_core:error] [pid 67073:tid 67137] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:40.387205 2026] [security2:error] [pid 67073:tid 67212] [client 52.173.121.69:17943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/bhfnd.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoVQAAAhs"]
[Tue Aug 18 12:57:40.434712 2026] [security2:error] [pid 67073:tid 67267] [client 158.158.74.177:26145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/colors/light/wp-login.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoWgAAAlI"]
[Tue Aug 18 12:57:40.456065 2026] [security2:error] [pid 67073:tid 67308] [client 20.118.172.148:54850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/lock360.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoWwAAAns"]
[Tue Aug 18 12:57:40.510539 2026] [security2:error] [pid 66623:tid 66870] [client 172.202.39.151:65235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/function/function.php"] [unique_id "aoSA9NO5rbWdOArH04KT6wAAAXI"]
[Tue Aug 18 12:57:40.551796 2026] [security2:error] [pid 67073:tid 67266] [client 20.119.58.187:12095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/gecko-new.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoXwAAAlE"]
[Tue Aug 18 12:57:40.616148 2026] [security2:error] [pid 67073:tid 67211] [client 20.100.185.105:43387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/disagraeed.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoYgAAAho"]
[Tue Aug 18 12:57:40.650107 2026] [security2:error] [pid 67073:tid 67245] [client 20.119.58.187:11263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/V5.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoYwAAAjw"]
[Tue Aug 18 12:57:40.655049 2026] [security2:error] [pid 67073:tid 67224] [client 40.85.222.29:44225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoZAAAAic"]
[Tue Aug 18 12:57:40.711142 2026] [security2:error] [pid 67073:tid 67303] [client 68.155.155.199:6614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/k.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoZgAAAnY"]
[Tue Aug 18 12:57:40.726199 2026] [security2:error] [pid 67073:tid 67324] [client 52.173.121.69:24995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/qfvqu.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoZwAAAos"]
[Tue Aug 18 12:57:40.726689 2026] [security2:error] [pid 66623:tid 66869] [client 216.73.160.243:49363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hotelvipunai.com.br"] [uri "/wp-login.php"] [unique_id "aoSA9NO5rbWdOArH04KT8AAAAXE"]
[Tue Aug 18 12:57:40.738863 2026] [autoindex:error] [pid 66623:tid 66776] [client 83.171.202.64:29800] AH01276: Cannot serve directory /home3/qs3e8j7ytlrlm8h9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:40.751129 2026] [security2:error] [pid 67073:tid 67220] [client 20.215.241.237:20649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/indexo.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoaQAAAiM"]
[Tue Aug 18 12:57:40.802242 2026] [security2:error] [pid 67073:tid 67323] [client 132.196.30.78:21839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoawAAAoo"]
[Tue Aug 18 12:57:40.838700 2026] [security2:error] [pid 66623:tid 66876] [client 4.232.151.198:4416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/htaccess.php"] [unique_id "aoSA9NO5rbWdOArH04KT8gAAAXg"]
[Tue Aug 18 12:57:40.918674 2026] [security2:error] [pid 67073:tid 67274] [client 74.248.18.37:3077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/index.php"] [unique_id "aoSA9Pcmepr5_nHgLbNobgAAAlk"]
[Tue Aug 18 12:57:40.924433 2026] [security2:error] [pid 66623:tid 66853] [client 20.119.58.187:12497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cookie.php"] [unique_id "aoSA9NO5rbWdOArH04KT8wAAAWE"]
[Tue Aug 18 12:57:40.924833 2026] [security2:error] [pid 67073:tid 67237] [client 20.206.73.37:63235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSA9Pcmepr5_nHgLbNocAAAAjQ"]
[Tue Aug 18 12:57:40.949136 2026] [security2:error] [pid 67073:tid 67300] [client 20.100.169.31:41187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/x.php"] [unique_id "aoSA9Pcmepr5_nHgLbNocQAAAnM"]
[Tue Aug 18 12:57:40.949437 2026] [security2:error] [pid 67073:tid 67311] [client 20.48.236.86:32833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/images.php"] [unique_id "aoSA9Pcmepr5_nHgLbNocgAAAn4"]
[Tue Aug 18 12:57:40.950956 2026] [security2:error] [pid 67073:tid 67208] [client 40.85.222.29:44237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSA9Pcmepr5_nHgLbNocwAAAhc"]
[Tue Aug 18 12:57:40.955714 2026] [security2:error] [pid 66623:tid 66886] [client 74.248.18.37:20511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/rrr.php"] [unique_id "aoSA9NO5rbWdOArH04KT9AAAAYI"]
[Tue Aug 18 12:57:40.963942 2026] [authz_core:error] [pid 67073:tid 67111] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:40.964194 2026] [authz_core:error] [pid 67073:tid 67111] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:41.000920 2026] [security2:error] [pid 67073:tid 67279] [client 20.119.58.187:11290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/wp-user.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoeQAAAl4"]
[Tue Aug 18 12:57:41.030749 2026] [security2:error] [pid 67073:tid 67261] [client 20.118.133.132:16255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/admin.php"] [unique_id "aoSA9fcmepr5_nHgLbNofAAAAkw"]
[Tue Aug 18 12:57:41.032581 2026] [security2:error] [pid 67073:tid 67248] [client 20.226.56.190:2506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/wb.php"] [unique_id "aoSA9fcmepr5_nHgLbNofgAAAj8"]
[Tue Aug 18 12:57:41.058556 2026] [security2:error] [pid 67073:tid 67284] [client 5.31.227.224:59013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9fcmepr5_nHgLbNogAAAAmM"]
[Tue Aug 18 12:57:41.064921 2026] [security2:error] [pid 67073:tid 67284] [client 5.31.227.224:59013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9fcmepr5_nHgLbNogAAAAmM"]
[Tue Aug 18 12:57:41.095652 2026] [security2:error] [pid 67073:tid 67242] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/images.php"] [unique_id "aoSA9fcmepr5_nHgLbNoggAAAjk"]
[Tue Aug 18 12:57:41.106762 2026] [security2:error] [pid 67073:tid 67222] [client 68.221.73.131:21124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.velasmagica.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA9fcmepr5_nHgLbNogwAAAiU"]
[Tue Aug 18 12:57:41.128346 2026] [security2:error] [pid 67073:tid 67317] [client 52.173.121.69:17976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/oivcl.php"] [unique_id "aoSA9fcmepr5_nHgLbNohAAAAoQ"]
[Tue Aug 18 12:57:41.151686 2026] [security2:error] [pid 67073:tid 67239] [client 20.100.169.31:42184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/i.php"] [unique_id "aoSA9fcmepr5_nHgLbNohgAAAjY"]
[Tue Aug 18 12:57:41.241120 2026] [security2:error] [pid 67073:tid 67205] [client 20.100.185.105:52187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/e69ovfsr.php"] [unique_id "aoSA9fcmepr5_nHgLbNoiQAAAhQ"]
[Tue Aug 18 12:57:41.255109 2026] [security2:error] [pid 67073:tid 67249] [client 213.35.127.232:57179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA9fcmepr5_nHgLbNoigAAAkA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:41.287648 2026] [security2:error] [pid 67073:tid 67332] [client 40.85.222.29:44269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSA9fcmepr5_nHgLbNojQAAApM"]
[Tue Aug 18 12:57:41.297392 2026] [security2:error] [pid 66623:tid 66808] [client 20.119.58.187:12072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/xleet.php"] [unique_id "aoSA9dO5rbWdOArH04KT-QAAATQ"]
[Tue Aug 18 12:57:41.348264 2026] [security2:error] [pid 67073:tid 67326] [client 20.215.241.237:55367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSA9fcmepr5_nHgLbNojwAAAo0"]
[Tue Aug 18 12:57:41.353588 2026] [security2:error] [pid 67073:tid 67228] [client 40.74.65.169:27791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/als.php"] [unique_id "aoSA9fcmepr5_nHgLbNokAAAAis"]
[Tue Aug 18 12:57:41.354089 2026] [security2:error] [pid 67073:tid 67246] [client 20.119.58.187:11235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/wp-blog.php"] [unique_id "aoSA9fcmepr5_nHgLbNokQAAAj0"]
[Tue Aug 18 12:57:41.406183 2026] [autoindex:error] [pid 66623:tid 66797] [client 158.158.74.177:16558] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/css/colors/midnight/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:41.486656 2026] [security2:error] [pid 66623:tid 66811] [client 149.34.210.141:58483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSA9dO5rbWdOArH04KT_AAAATc"]
[Tue Aug 18 12:57:41.490144 2026] [security2:error] [pid 67073:tid 67236] [client 172.182.200.96:14153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/opsqt.php"] [unique_id "aoSA9fcmepr5_nHgLbNolgAAAjM"]
[Tue Aug 18 12:57:41.506633 2026] [security2:error] [pid 67073:tid 67225] [client 52.173.121.69:17959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/zugvi.php"] [unique_id "aoSA9fcmepr5_nHgLbNomQAAAig"]
[Tue Aug 18 12:57:41.526753 2026] [security2:error] [pid 66623:tid 66868] [client 4.232.151.198:4466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/images/wso.php"] [unique_id "aoSA9dO5rbWdOArH04KT_QAAAXA"]
[Tue Aug 18 12:57:41.567953 2026] [security2:error] [pid 67073:tid 67214] [client 157.20.138.62:65455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9fcmepr5_nHgLbNomwAAAh0"]
[Tue Aug 18 12:57:41.568062 2026] [security2:error] [pid 67073:tid 67214] [client 157.20.138.62:65455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9fcmepr5_nHgLbNomwAAAh0"]
[Tue Aug 18 12:57:41.569410 2026] [authz_core:error] [pid 67073:tid 67117] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:41.569657 2026] [authz_core:error] [pid 67073:tid 67117] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:41.572291 2026] [security2:error] [pid 67073:tid 67272] [client 20.118.172.148:54891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSA9fcmepr5_nHgLbNonAAAAlc"]
[Tue Aug 18 12:57:41.602304 2026] [security2:error] [pid 67073:tid 67258] [client 40.85.222.29:44243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSA9fcmepr5_nHgLbNongAAAkk"]
[Tue Aug 18 12:57:41.614449 2026] [security2:error] [pid 67073:tid 67287] [client 74.248.18.37:35355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/s.php"] [unique_id "aoSA9fcmepr5_nHgLbNonwAAAmY"]
[Tue Aug 18 12:57:41.626600 2026] [security2:error] [pid 67073:tid 67210] [client 104.209.144.33:29848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSA9fcmepr5_nHgLbNooAAAAhk"]
[Tue Aug 18 12:57:41.643580 2026] [security2:error] [pid 67073:tid 67270] [client 74.248.18.37:3125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSA9fcmepr5_nHgLbNooQAAAlU"]
[Tue Aug 18 12:57:41.656948 2026] [security2:error] [pid 67073:tid 67294] [client 20.226.56.190:19384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/xn.php"] [unique_id "aoSA9fcmepr5_nHgLbNoowAAAm0"]
[Tue Aug 18 12:57:41.661574 2026] [security2:error] [pid 67073:tid 67267] [client 20.119.58.187:12537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/spip.php"] [unique_id "aoSA9fcmepr5_nHgLbNopAAAAlI"]
[Tue Aug 18 12:57:41.699689 2026] [autoindex:error] [pid 66623:tid 66849] [client 158.158.74.177:16558] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:41.736454 2026] [security2:error] [pid 66623:tid 66875] [client 20.226.56.190:17867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/47.php"] [unique_id "aoSA9dO5rbWdOArH04KT_wAAAXc"]
[Tue Aug 18 12:57:41.743315 2026] [security2:error] [pid 67073:tid 67302] [client 20.250.13.23:38944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSA9fcmepr5_nHgLbNopgAAAnU"]
[Tue Aug 18 12:57:41.754059 2026] [security2:error] [pid 66623:tid 66811] [client 149.34.210.141:58483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSA9dO5rbWdOArH04KT_AAAATc"]
[Tue Aug 18 12:57:41.771643 2026] [security2:error] [pid 67073:tid 67209] [client 20.119.58.187:11325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/wp.php"] [unique_id "aoSA9fcmepr5_nHgLbNopwAAAhg"]
[Tue Aug 18 12:57:41.789859 2026] [security2:error] [pid 67073:tid 67241] [client 37.40.227.74:56749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9fcmepr5_nHgLbNoqQAAAjg"]
[Tue Aug 18 12:57:41.793705 2026] [security2:error] [pid 67073:tid 67241] [client 37.40.227.74:56749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9fcmepr5_nHgLbNoqQAAAjg"]
[Tue Aug 18 12:57:41.821746 2026] [security2:error] [pid 67073:tid 67273] [client 172.202.39.151:50207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSA9fcmepr5_nHgLbNoqgAAAlg"]
[Tue Aug 18 12:57:41.866550 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:41.866865 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:41.884573 2026] [security2:error] [pid 67073:tid 67220] [client 52.173.121.69:16463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wsrer.php"] [unique_id "aoSA9fcmepr5_nHgLbNorwAAAiM"]
[Tue Aug 18 12:57:41.898513 2026] [security2:error] [pid 67073:tid 67324] [client 157.90.155.240:16348] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.idealquimica.com"] [uri "/index.php"] [unique_id "aoSA9fcmepr5_nHgLbNoqwAAAos"], referer: http://www.idealquimica.com
[Tue Aug 18 12:57:41.899534 2026] [security2:error] [pid 67073:tid 67266] [client 20.100.185.105:43346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSA9fcmepr5_nHgLbNosAAAAlE"]
[Tue Aug 18 12:57:41.909922 2026] [autoindex:error] [pid 66623:tid 66865] [client 129.211.229.121:43178] AH01276: Cannot serve directory /home4/patiojardinsma/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:41.925812 2026] [security2:error] [pid 66623:tid 66769] [client 40.85.222.29:26919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSA9dO5rbWdOArH04KUAwAAAQ0"]
[Tue Aug 18 12:57:41.940623 2026] [security2:error] [pid 66623:tid 66768] [client 172.182.200.96:7638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/help/crnpwfiu.php"] [unique_id "aoSA9dO5rbWdOArH04KUBAAAAQw"]
[Tue Aug 18 12:57:42.014453 2026] [security2:error] [pid 67073:tid 67274] [client 68.155.155.199:10396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSA9vcmepr5_nHgLbNoswAAAlk"]
[Tue Aug 18 12:57:42.019701 2026] [security2:error] [pid 67073:tid 67232] [client 20.119.58.187:11841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/22.php"] [unique_id "aoSA9vcmepr5_nHgLbNotAAAAi8"]
[Tue Aug 18 12:57:42.081303 2026] [security2:error] [pid 67073:tid 67293] [client 158.158.34.183:17541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/cnzcsfwm.php"] [unique_id "aoSA9vcmepr5_nHgLbNotwAAAmw"]
[Tue Aug 18 12:57:42.090217 2026] [autoindex:error] [pid 67073:tid 67211] [client 20.100.169.31:37680] AH01276: Cannot serve directory /home1/lubarbosa/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:42.094507 2026] [security2:error] [pid 67073:tid 67215] [client 45.92.229.99:53407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.229.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/edit.php"] [unique_id "aoSA9vcmepr5_nHgLbNouAAAAh4"], referer: https://ozzyfernandesoficial.com.br/wp-login.php
[Tue Aug 18 12:57:42.102801 2026] [security2:error] [pid 67073:tid 67230] [client 114.119.137.122:32443] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.advocaciasc.com"] [uri "/wp-content/uploads/2021/04/cartao-de-credito-02.jpg"] [unique_id "aoSA9vcmepr5_nHgLbNouQAAAi0"], referer: https://www.advocaciasc.com/direito-bancario-cartao-de-credito/
[Tue Aug 18 12:57:42.119438 2026] [security2:error] [pid 67073:tid 67320] [client 40.74.65.169:26750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/nox.php"] [unique_id "aoSA9vcmepr5_nHgLbNougAAAoc"]
[Tue Aug 18 12:57:42.123081 2026] [security2:error] [pid 67073:tid 67276] [client 20.119.58.187:11297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/worksec.php"] [unique_id "aoSA9vcmepr5_nHgLbNouwAAAls"]
[Tue Aug 18 12:57:42.134030 2026] [security2:error] [pid 67073:tid 67265] [client 68.155.154.236:65506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSA9vcmepr5_nHgLbNovQAAAlA"]
[Tue Aug 18 12:57:42.187243 2026] [security2:error] [pid 66623:tid 66771] [client 20.100.169.31:39123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/index/function.php"] [unique_id "aoSA9tO5rbWdOArH04KUBwAAAQ8"]
[Tue Aug 18 12:57:42.195934 2026] [security2:error] [pid 66623:tid 66810] [client 4.232.151.198:4305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/index/function.php"] [unique_id "aoSA9tO5rbWdOArH04KUCAAAATY"]
[Tue Aug 18 12:57:42.211383 2026] [security2:error] [pid 67073:tid 67154] [remote 84.205.178.135:26582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.178.205.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "becacao.us"] [uri "/wp-login.php"] [unique_id "aoSA9vcmepr5_nHgLbNowAACRE4"]
[Tue Aug 18 12:57:42.213132 2026] [security2:error] [pid 67073:tid 67257] [client 40.85.222.29:44765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSA9vcmepr5_nHgLbNowQAAAkg"]
[Tue Aug 18 12:57:42.218261 2026] [security2:error] [pid 66623:tid 66792] [client 20.215.241.237:25298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSA9tO5rbWdOArH04KUCgAAASQ"]
[Tue Aug 18 12:57:42.237150 2026] [security2:error] [pid 66623:tid 66840] [client 20.118.172.148:54904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSA9tO5rbWdOArH04KUDAAAAVQ"]
[Tue Aug 18 12:57:42.268390 2026] [security2:error] [pid 66623:tid 66795] [client 213.35.127.232:57399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSA9tO5rbWdOArH04KUDQAAASc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:42.271848 2026] [security2:error] [pid 67073:tid 67322] [client 52.173.121.69:25007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/ucpfr.php"] [unique_id "aoSA9vcmepr5_nHgLbNowwAAAok"]
[Tue Aug 18 12:57:42.274901 2026] [security2:error] [pid 67073:tid 67311] [client 74.248.18.37:3314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSA9vcmepr5_nHgLbNoxAAAAn4"]
[Tue Aug 18 12:57:42.277310 2026] [autoindex:error] [pid 66623:tid 66846] [client 158.158.74.177:16558] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/css/colors/ocean/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:42.296106 2026] [security2:error] [pid 67073:tid 67231] [client 20.100.169.31:37680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSA9vcmepr5_nHgLbNoxQAAAi4"]
[Tue Aug 18 12:57:42.299455 2026] [security2:error] [pid 66623:tid 66841] [client 20.48.236.86:36121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/admin.php"] [unique_id "aoSA9tO5rbWdOArH04KUDgAAAVU"]
[Tue Aug 18 12:57:42.303437 2026] [security2:error] [pid 67073:tid 67310] [client 74.248.18.37:20526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/s93.php"] [unique_id "aoSA9vcmepr5_nHgLbNoxgAAAn0"]
[Tue Aug 18 12:57:42.379070 2026] [security2:error] [pid 67073:tid 67319] [client 20.119.58.187:12047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/room.php"] [unique_id "aoSA9vcmepr5_nHgLbNoyAAAAoY"]
[Tue Aug 18 12:57:42.393731 2026] [security2:error] [pid 66623:tid 66848] [client 132.196.30.78:21930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/atomlib.php"] [unique_id "aoSA9tO5rbWdOArH04KUEAAAAVw"]
[Tue Aug 18 12:57:42.438820 2026] [security2:error] [pid 67073:tid 67318] [client 178.153.171.161:59476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9vcmepr5_nHgLbNoygAAAoU"]
[Tue Aug 18 12:57:42.438926 2026] [security2:error] [pid 67073:tid 67318] [client 178.153.171.161:59476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9vcmepr5_nHgLbNoygAAAoU"]
[Tue Aug 18 12:57:42.475111 2026] [security2:error] [pid 66623:tid 66887] [client 20.119.58.187:11312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/wp-themes.php"] [unique_id "aoSA9tO5rbWdOArH04KUEQAAAYM"]
[Tue Aug 18 12:57:42.483075 2026] [security2:error] [pid 66623:tid 66802] [client 158.158.74.177:16558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSA9tO5rbWdOArH04KUEgAAAS4"]
[Tue Aug 18 12:57:42.511998 2026] [security2:error] [pid 66623:tid 66742] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9tO5rbWdOArH04KUFAABQGk"]
[Tue Aug 18 12:57:42.512140 2026] [security2:error] [pid 66623:tid 66820] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9tO5rbWdOArH04KUFAABQGk"]
[Tue Aug 18 12:57:42.533240 2026] [security2:error] [pid 66623:tid 66858] [client 40.85.222.29:44282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSA9tO5rbWdOArH04KUFQAAAWY"]
[Tue Aug 18 12:57:42.558616 2026] [security2:error] [pid 67073:tid 67250] [client 79.127.164.8:45456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/old.bak"] [unique_id "aoSA9vcmepr5_nHgLbNo1AAAAkE"], referer: https://medihub.com.br/old.bak
[Tue Aug 18 12:57:42.577027 2026] [security2:error] [pid 67073:tid 67233] [client 20.100.185.105:52174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/cd.php"] [unique_id "aoSA9vcmepr5_nHgLbNo1wAAAjA"]
[Tue Aug 18 12:57:42.657613 2026] [security2:error] [pid 67073:tid 67272] [client 68.155.155.199:7390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/system_log.php"] [unique_id "aoSA9vcmepr5_nHgLbNo3AAAAlc"]
[Tue Aug 18 12:57:42.686372 2026] [security2:error] [pid 67073:tid 67222] [client 157.90.155.240:1298] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.idealquimica.com"] [uri "/index.php"] [unique_id "aoSA9vcmepr5_nHgLbNo0gAAAiU"], referer: http://www.idealquimica.com
[Tue Aug 18 12:57:42.744785 2026] [security2:error] [pid 66623:tid 66852] [client 20.119.58.187:12483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/disagreed.php"] [unique_id "aoSA9tO5rbWdOArH04KUGQAAAWA"]
[Tue Aug 18 12:57:42.746912 2026] [security2:error] [pid 67073:tid 67303] [client 20.226.56.190:28226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/payout.php"] [unique_id "aoSA9vcmepr5_nHgLbNo5AAAAnY"]
[Tue Aug 18 12:57:42.761487 2026] [security2:error] [pid 67073:tid 67252] [client 167.235.143.113:5590] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.idealquimica.com"] [uri "/index.php"] [unique_id "aoSA9vcmepr5_nHgLbNoywAAAkM"], referer: https://www.idealquimica.com
[Tue Aug 18 12:57:42.777226 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:42.777494 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:42.829343 2026] [security2:error] [pid 67073:tid 67315] [client 4.232.151.198:24955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/info.php"] [unique_id "aoSA9vcmepr5_nHgLbNo6QAAAoI"]
[Tue Aug 18 12:57:42.835167 2026] [security2:error] [pid 66623:tid 66850] [client 40.85.222.29:44240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSA9tO5rbWdOArH04KUHAAAAV4"]
[Tue Aug 18 12:57:42.836312 2026] [security2:error] [pid 67073:tid 67206] [client 20.119.58.187:11471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/wp-signin.php"] [unique_id "aoSA9vcmepr5_nHgLbNo6wAAAhU"]
[Tue Aug 18 12:57:42.870091 2026] [security2:error] [pid 67073:tid 67283] [client 20.118.172.148:54899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/.alf.php"] [unique_id "aoSA9vcmepr5_nHgLbNo7AAAAmI"]
[Tue Aug 18 12:57:42.896605 2026] [security2:error] [pid 66623:tid 66805] [client 20.215.241.237:54696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/.admin.php"] [unique_id "aoSA9tO5rbWdOArH04KUHQAAATE"]
[Tue Aug 18 12:57:42.904499 2026] [security2:error] [pid 67073:tid 67305] [client 40.74.65.169:11229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/file59.php"] [unique_id "aoSA9vcmepr5_nHgLbNo7gAAAng"]
[Tue Aug 18 12:57:42.919795 2026] [security2:error] [pid 67073:tid 67292] [client 74.248.18.37:3131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSA9vcmepr5_nHgLbNo7wAAAms"]
[Tue Aug 18 12:57:42.943666 2026] [security2:error] [pid 67073:tid 67263] [client 52.173.121.69:17926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/yxijx.php"] [unique_id "aoSA9vcmepr5_nHgLbNo8AAAAk4"]
[Tue Aug 18 12:57:42.953031 2026] [security2:error] [pid 67073:tid 67243] [client 74.248.18.37:62098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/server.php"] [unique_id "aoSA9vcmepr5_nHgLbNo8QAAAjo"]
[Tue Aug 18 12:57:43.079753 2026] [authz_core:error] [pid 67073:tid 67085] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:43.080203 2026] [authz_core:error] [pid 67073:tid 67085] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:43.104441 2026] [security2:error] [pid 66623:tid 66775] [client 20.119.58.187:12080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/alfa-rex.php"] [unique_id "aoSA99O5rbWdOArH04KUIAAAARM"]
[Tue Aug 18 12:57:43.109823 2026] [security2:error] [pid 67073:tid 67322] [client 40.85.222.29:44767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSA9_cmepr5_nHgLbNo_AAAAok"]
[Tue Aug 18 12:57:43.189571 2026] [security2:error] [pid 67073:tid 67251] [client 20.119.58.187:11251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSA9_cmepr5_nHgLbNo_gAAAkI"]
[Tue Aug 18 12:57:43.199084 2026] [security2:error] [pid 67073:tid 67300] [client 20.100.185.105:62352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/dropdown.php"] [unique_id "aoSA9_cmepr5_nHgLbNo_wAAAnM"]
[Tue Aug 18 12:57:43.237396 2026] [security2:error] [pid 67073:tid 67310] [client 172.182.200.96:14196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/jvcpa.php"] [unique_id "aoSA9_cmepr5_nHgLbNpAgAAAn0"]
[Tue Aug 18 12:57:43.242027 2026] [security2:error] [pid 67073:tid 67314] [client 20.118.172.148:52238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/.trash7206/index.php"] [unique_id "aoSA9_cmepr5_nHgLbNpBAAAAoE"]
[Tue Aug 18 12:57:43.281861 2026] [security2:error] [pid 66623:tid 66882] [client 213.35.127.232:57626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSA99O5rbWdOArH04KUIgAAAX4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:43.301083 2026] [security2:error] [pid 66623:tid 66870] [client 20.48.236.86:2118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/222.php"] [unique_id "aoSA99O5rbWdOArH04KUIwAAAXI"]
[Tue Aug 18 12:57:43.310813 2026] [security2:error] [pid 67073:tid 67247] [client 132.196.30.78:21757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/rip.php"] [unique_id "aoSA9_cmepr5_nHgLbNpBQAAAj4"]
[Tue Aug 18 12:57:43.361459 2026] [security2:error] [pid 67073:tid 67281] [client 158.158.34.183:31663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/MYK4TJEfFvO.php"] [unique_id "aoSA9_cmepr5_nHgLbNpBwAAAmA"]
[Tue Aug 18 12:57:43.378095 2026] [security2:error] [pid 67073:tid 67240] [client 20.100.169.31:42200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSA9_cmepr5_nHgLbNpCQAAAjc"]
[Tue Aug 18 12:57:43.378833 2026] [authz_core:error] [pid 67073:tid 67185] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:43.379096 2026] [authz_core:error] [pid 67073:tid 67185] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:43.385819 2026] [security2:error] [pid 66623:tid 66817] [client 40.85.222.29:26906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSA99O5rbWdOArH04KUJAAAAT0"]
[Tue Aug 18 12:57:43.472526 2026] [security2:error] [pid 67073:tid 67254] [client 85.154.68.202:54921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSA9_cmepr5_nHgLbNpDQAAAkU"]
[Tue Aug 18 12:57:43.472695 2026] [security2:error] [pid 67073:tid 67254] [client 85.154.68.202:54921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSA9_cmepr5_nHgLbNpDQAAAkU"]
[Tue Aug 18 12:57:43.480256 2026] [security2:error] [pid 67073:tid 67239] [client 4.232.151.198:24934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/profile.php"] [unique_id "aoSA9_cmepr5_nHgLbNpDgAAAjY"]
[Tue Aug 18 12:57:43.516757 2026] [security2:error] [pid 66623:tid 66889] [client 20.119.58.187:12509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSA99O5rbWdOArH04KUJgAAAYU"]
[Tue Aug 18 12:57:43.532506 2026] [security2:error] [pid 67073:tid 67238] [client 20.118.133.132:15369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/222.php"] [unique_id "aoSA9_cmepr5_nHgLbNpEAAAAjU"]
[Tue Aug 18 12:57:43.537279 2026] [security2:error] [pid 67073:tid 67332] [client 68.155.154.236:65499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSA9_cmepr5_nHgLbNpEQAAApM"]
[Tue Aug 18 12:57:43.573973 2026] [security2:error] [pid 67073:tid 67312] [client 20.215.241.237:25320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wsomini.php"] [unique_id "aoSA9_cmepr5_nHgLbNpEwAAAn8"]
[Tue Aug 18 12:57:43.597813 2026] [security2:error] [pid 67073:tid 67268] [client 74.248.18.37:35376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/settings.php"] [unique_id "aoSA9_cmepr5_nHgLbNpFAAAAlM"]
[Tue Aug 18 12:57:43.648643 2026] [security2:error] [pid 66623:tid 66799] [client 40.74.65.169:43138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/admin.php"] [unique_id "aoSA99O5rbWdOArH04KUKAAAASs"]
[Tue Aug 18 12:57:43.664740 2026] [security2:error] [pid 67073:tid 67285] [client 20.119.58.187:11224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/ws.php"] [unique_id "aoSA9_cmepr5_nHgLbNpFgAAAmQ"]
[Tue Aug 18 12:57:43.720086 2026] [security2:error] [pid 66623:tid 66877] [client 74.248.18.37:3102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSA99O5rbWdOArH04KUJwAAAXk"]
[Tue Aug 18 12:57:43.726022 2026] [security2:error] [pid 66623:tid 66869] [client 40.85.222.29:44248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSA99O5rbWdOArH04KUKQAAAXE"]
[Tue Aug 18 12:57:43.747602 2026] [security2:error] [pid 67073:tid 67330] [client 160.120.140.123:49752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9_cmepr5_nHgLbNpGgAAApE"]
[Tue Aug 18 12:57:43.747735 2026] [security2:error] [pid 67073:tid 67330] [client 160.120.140.123:49752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9_cmepr5_nHgLbNpGgAAApE"]
[Tue Aug 18 12:57:43.816594 2026] [security2:error] [pid 67073:tid 67233] [client 20.100.185.105:58293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/22.php"] [unique_id "aoSA9_cmepr5_nHgLbNpHQAAAjA"]
[Tue Aug 18 12:57:43.825999 2026] [security2:error] [pid 67073:tid 67270] [client 104.209.144.33:36500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/blog/byp.php"] [unique_id "aoSA9_cmepr5_nHgLbNpHgAAAlU"]
[Tue Aug 18 12:57:43.863124 2026] [security2:error] [pid 67073:tid 67327] [client 20.118.172.148:62097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSA9_cmepr5_nHgLbNpHwAAAo4"]
[Tue Aug 18 12:57:43.873102 2026] [security2:error] [pid 67073:tid 67280] [client 52.173.121.69:16455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/zwlsv.php"] [unique_id "aoSA9_cmepr5_nHgLbNpIAAAAl8"]
[Tue Aug 18 12:57:43.884960 2026] [security2:error] [pid 66623:tid 66816] [client 20.119.58.187:12035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/feeds.php"] [unique_id "aoSA99O5rbWdOArH04KUKwAAATw"]
[Tue Aug 18 12:57:43.933147 2026] [security2:error] [pid 66623:tid 66827] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/ops.php"] [unique_id "aoSA99O5rbWdOArH04KULQAAAUc"]
[Tue Aug 18 12:57:43.977962 2026] [authz_core:error] [pid 67073:tid 67148] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:43.978232 2026] [authz_core:error] [pid 67073:tid 67148] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:43.997624 2026] [security2:error] [pid 67073:tid 67269] [client 158.158.74.177:26120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/data.php"] [unique_id "aoSA9_cmepr5_nHgLbNpLwAAAlQ"]
[Tue Aug 18 12:57:44.006589 2026] [security2:error] [pid 67073:tid 67241] [client 40.85.222.29:44770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpMAAAAjg"]
[Tue Aug 18 12:57:44.011855 2026] [security2:error] [pid 67073:tid 67277] [client 192.141.172.134:64928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpMQAAAlw"]
[Tue Aug 18 12:57:44.011961 2026] [security2:error] [pid 67073:tid 67277] [client 192.141.172.134:64928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpMQAAAlw"]
[Tue Aug 18 12:57:44.019244 2026] [security2:error] [pid 67073:tid 67267] [client 20.119.58.187:11507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/wsa.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpMgAAAlI"]
[Tue Aug 18 12:57:44.091000 2026] [security2:error] [pid 67073:tid 67323] [client 20.215.241.237:36785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/vr.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpOgAAAoo"]
[Tue Aug 18 12:57:44.107626 2026] [security2:error] [pid 67073:tid 67275] [client 4.232.151.198:24925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/sx.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpPAAAAlo"]
[Tue Aug 18 12:57:44.156257 2026] [security2:error] [pid 67073:tid 67274] [client 68.155.154.236:50377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpPwAAAlk"]
[Tue Aug 18 12:57:44.241090 2026] [security2:error] [pid 67073:tid 67264] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/coffexium.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpQgAAAk8"]
[Tue Aug 18 12:57:44.243601 2026] [security2:error] [pid 67073:tid 67205] [client 20.119.58.187:12535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/defaults.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpQwAAAhQ"]
[Tue Aug 18 12:57:44.250528 2026] [security2:error] [pid 66623:tid 66833] [client 74.248.18.37:35369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/sf.php"] [unique_id "aoSA-NO5rbWdOArH04KULgAAAU0"]
[Tue Aug 18 12:57:44.275767 2026] [security2:error] [pid 67073:tid 67208] [client 172.202.39.151:65277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpRQAAAhc"]
[Tue Aug 18 12:57:44.294237 2026] [security2:error] [pid 67073:tid 67306] [client 213.35.127.232:57855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpRgAAAnk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:44.309538 2026] [security2:error] [pid 66623:tid 66857] [client 40.85.222.29:25034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSA-NO5rbWdOArH04KULwAAAWU"]
[Tue Aug 18 12:57:44.345997 2026] [security2:error] [pid 66623:tid 66868] [client 68.155.155.199:5954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/x.php"] [unique_id "aoSA-NO5rbWdOArH04KUMAAAAXA"]
[Tue Aug 18 12:57:44.350825 2026] [security2:error] [pid 67073:tid 67292] [client 74.248.18.37:3293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpSQAAAms"]
[Tue Aug 18 12:57:44.353736 2026] [security2:error] [pid 66623:tid 66808] [client 74.7.228.44:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "leandroxavier1753363671494.0201157.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "aoSA-NO5rbWdOArH04KUMgABNCw"]
[Tue Aug 18 12:57:44.370954 2026] [security2:error] [pid 67073:tid 67215] [client 20.119.58.187:11248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/w.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpSgAAAh4"]
[Tue Aug 18 12:57:44.385470 2026] [security2:error] [pid 66623:tid 66864] [client 40.74.65.169:44761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/aa2.php"] [unique_id "aoSA-NO5rbWdOArH04KUNAAAAWw"]
[Tue Aug 18 12:57:44.393454 2026] [security2:error] [pid 66623:tid 66861] [client 132.196.30.78:21877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/p.php"] [unique_id "aoSA-NO5rbWdOArH04KUNQAAAWk"]
[Tue Aug 18 12:57:44.409119 2026] [security2:error] [pid 67073:tid 67237] [client 20.203.183.135:31320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpTAAAAjQ"]
[Tue Aug 18 12:57:44.447737 2026] [security2:error] [pid 66623:tid 66801] [client 20.100.185.105:42651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/hkvkjguw.php"] [unique_id "aoSA-NO5rbWdOArH04KUNwAAAS0"]
[Tue Aug 18 12:57:44.511748 2026] [security2:error] [pid 67073:tid 67320] [client 20.100.169.31:43821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/gecko-new.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpTwAAAoc"]
[Tue Aug 18 12:57:44.531186 2026] [security2:error] [pid 67073:tid 67310] [client 20.206.73.37:20712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/sky.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpUAAAAn0"]
[Tue Aug 18 12:57:44.552739 2026] [security2:error] [pid 67073:tid 67314] [client 172.182.200.96:14129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpUwAAAoE"]
[Tue Aug 18 12:57:44.584819 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:44.585088 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:44.594691 2026] [security2:error] [pid 66623:tid 66885] [client 40.85.222.29:44263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSA-NO5rbWdOArH04KUPAAAAYE"]
[Tue Aug 18 12:57:44.604879 2026] [security2:error] [pid 67073:tid 67311] [client 20.119.58.187:12086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/system.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpVgAAAn4"]
[Tue Aug 18 12:57:44.722237 2026] [security2:error] [pid 67073:tid 67319] [client 20.119.58.187:11256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/x.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpXAAAAoY"]
[Tue Aug 18 12:57:44.733625 2026] [security2:error] [pid 67073:tid 67300] [client 4.232.151.198:4297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpXQAAAnM"]
[Tue Aug 18 12:57:44.792178 2026] [security2:error] [pid 66623:tid 66770] [client 68.155.154.236:8052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/rezor.php"] [unique_id "aoSA-NO5rbWdOArH04KUTQAAAQ4"]
[Tue Aug 18 12:57:44.861926 2026] [security2:error] [pid 67073:tid 67235] [client 52.173.121.69:24971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/jrpga.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpZAAAAjI"]
[Tue Aug 18 12:57:44.869111 2026] [security2:error] [pid 66623:tid 66793] [client 104.209.144.33:20419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSA-NO5rbWdOArH04KUTgAAASU"]
[Tue Aug 18 12:57:44.884370 2026] [authz_core:error] [pid 67073:tid 67192] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:44.884665 2026] [authz_core:error] [pid 67073:tid 67192] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:44.911200 2026] [security2:error] [pid 66623:tid 66887] [client 40.85.222.29:44781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSA-NO5rbWdOArH04KUUAAAAYM"]
[Tue Aug 18 12:57:44.919816 2026] [security2:error] [pid 67073:tid 67254] [client 74.248.18.37:20509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/shell.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpZwAAAkU"]
[Tue Aug 18 12:57:44.921162 2026] [security2:error] [pid 66623:tid 66845] [client 158.158.34.183:43696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/Casper.php"] [unique_id "aoSA-NO5rbWdOArH04KUUQAAAVk"]
[Tue Aug 18 12:57:44.986460 2026] [security2:error] [pid 66623:tid 66794] [client 74.248.18.37:3275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSA-NO5rbWdOArH04KUUwAAASY"]
[Tue Aug 18 12:57:44.997107 2026] [security2:error] [pid 67073:tid 67207] [client 158.158.74.177:16553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/disagrsxr.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpagAAAhY"]
[Tue Aug 18 12:57:45.003953 2026] [security2:error] [pid 67073:tid 67328] [client 20.119.58.187:12491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA-fcmepr5_nHgLbNpawAAAo8"]
[Tue Aug 18 12:57:45.066478 2026] [security2:error] [pid 67073:tid 67284] [client 20.100.185.105:42687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/cadastro-2.php"] [unique_id "aoSA-fcmepr5_nHgLbNpbQAAAmM"]
[Tue Aug 18 12:57:45.080118 2026] [security2:error] [pid 66623:tid 66783] [client 20.119.58.187:11468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/xx.php"] [unique_id "aoSA-dO5rbWdOArH04KUVQAAARs"]
[Tue Aug 18 12:57:45.102778 2026] [security2:error] [pid 67073:tid 67295] [client 172.182.217.32:15582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/666.php"] [unique_id "aoSA-fcmepr5_nHgLbNpbwAAAm4"]
[Tue Aug 18 12:57:45.108498 2026] [security2:error] [pid 66623:tid 66780] [client 20.118.172.148:62421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSA-dO5rbWdOArH04KUVwAAARg"]
[Tue Aug 18 12:57:45.132522 2026] [security2:error] [pid 67073:tid 67270] [client 40.74.65.169:27795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/xamp.php"] [unique_id "aoSA-fcmepr5_nHgLbNpcQAAAlU"]
[Tue Aug 18 12:57:45.225535 2026] [security2:error] [pid 67073:tid 67280] [client 20.226.56.190:2077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/bh.php"] [unique_id "aoSA-fcmepr5_nHgLbNpcwAAAl8"]
[Tue Aug 18 12:57:45.243535 2026] [security2:error] [pid 66623:tid 66848] [client 132.196.30.78:18796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/php.php"] [unique_id "aoSA-dO5rbWdOArH04KUWQAAAVw"]
[Tue Aug 18 12:57:45.254569 2026] [security2:error] [pid 67073:tid 67277] [client 40.85.222.29:44253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSA-fcmepr5_nHgLbNpdQAAAlw"]
[Tue Aug 18 12:57:45.265862 2026] [security2:error] [pid 67073:tid 67321] [client 172.182.217.32:15596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/bgymj.php"] [unique_id "aoSA-fcmepr5_nHgLbNpdgAAAog"]
[Tue Aug 18 12:57:45.308431 2026] [security2:error] [pid 67073:tid 67289] [client 213.35.127.232:58075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA-fcmepr5_nHgLbNpdwAAAmg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:45.359487 2026] [security2:error] [pid 67073:tid 67269] [client 20.119.58.187:11884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/xmlrpc.php0"] [unique_id "aoSA-fcmepr5_nHgLbNpeQAAAlQ"]
[Tue Aug 18 12:57:45.369028 2026] [security2:error] [pid 67073:tid 67217] [client 68.155.155.199:6611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSA-fcmepr5_nHgLbNpegAAAiA"]
[Tue Aug 18 12:57:45.406067 2026] [security2:error] [pid 67073:tid 67222] [client 4.232.151.198:4314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSA-fcmepr5_nHgLbNpewAAAiU"]
[Tue Aug 18 12:57:45.426966 2026] [security2:error] [pid 67073:tid 67209] [client 20.65.98.162:44221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/nano.php"] [unique_id "aoSA-fcmepr5_nHgLbNpfQAAAhg"]
[Tue Aug 18 12:57:45.433396 2026] [security2:error] [pid 66623:tid 66879] [client 20.119.58.187:11469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA-dO5rbWdOArH04KUXQAAAXs"]
[Tue Aug 18 12:57:45.497777 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:45.498074 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:45.501834 2026] [security2:error] [pid 67073:tid 67266] [client 5.161.117.52:12650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rota85motorshop.com.br"] [uri "/index.php"] [unique_id "aoSA-fcmepr5_nHgLbNpfwAAAlE"], referer: https://rota85motorshop.com.br/
[Tue Aug 18 12:57:45.528777 2026] [security2:error] [pid 67073:tid 67264] [client 172.182.200.96:7663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSA-fcmepr5_nHgLbNpggAAAk8"]
[Tue Aug 18 12:57:45.562471 2026] [security2:error] [pid 67073:tid 67252] [client 40.85.222.29:44234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/rezor.php"] [unique_id "aoSA-fcmepr5_nHgLbNpgwAAAkM"]
[Tue Aug 18 12:57:45.586974 2026] [security2:error] [pid 67073:tid 67248] [client 114.119.157.158:25355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vidracariafroesbox.com.br"] [uri "/servicos/fechamento-de-varandas-em-vidro"] [unique_id "aoSA-fcmepr5_nHgLbNphAAAAj8"], referer: https://vidracariafroesbox.com.br/servicos/fechamento-de-varandas-em-vidro
[Tue Aug 18 12:57:45.607073 2026] [security2:error] [pid 67073:tid 67292] [client 20.206.73.37:20722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/file5.php"] [unique_id "aoSA-fcmepr5_nHgLbNphwAAAms"]
[Tue Aug 18 12:57:45.615258 2026] [security2:error] [pid 66623:tid 66778] [client 20.250.13.23:41606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/atomlib.php"] [unique_id "aoSA-dO5rbWdOArH04KUXgAAARY"]
[Tue Aug 18 12:57:45.639873 2026] [security2:error] [pid 67073:tid 67305] [client 74.248.18.37:3128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSA-fcmepr5_nHgLbNpiAAAAng"]
[Tue Aug 18 12:57:45.677267 2026] [security2:error] [pid 66623:tid 66782] [client 20.118.133.132:17383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/mac.php"] [unique_id "aoSA-dO5rbWdOArH04KUXwAAARo"]
[Tue Aug 18 12:57:45.685331 2026] [security2:error] [pid 67073:tid 67244] [client 20.100.185.105:58256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/backup.php"] [unique_id "aoSA-fcmepr5_nHgLbNpigAAAjs"]
[Tue Aug 18 12:57:45.713519 2026] [security2:error] [pid 67073:tid 67329] [client 20.119.58.187:12506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/colors.php"] [unique_id "aoSA-fcmepr5_nHgLbNpjQAAApA"]
[Tue Aug 18 12:57:45.716412 2026] [security2:error] [pid 67073:tid 67293] [client 74.248.18.37:21540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/shiny.php"] [unique_id "aoSA-fcmepr5_nHgLbNpjgAAAmw"]
[Tue Aug 18 12:57:45.754852 2026] [security2:error] [pid 67073:tid 67279] [client 172.182.217.32:15764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/bthil.php"] [unique_id "aoSA-fcmepr5_nHgLbNpjwAAAl4"]
[Tue Aug 18 12:57:45.767103 2026] [security2:error] [pid 67073:tid 67243] [client 20.48.236.86:2187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/mac.php"] [unique_id "aoSA-fcmepr5_nHgLbNpkAAAAjo"]
[Tue Aug 18 12:57:45.784487 2026] [security2:error] [pid 66623:tid 66850] [client 20.118.172.148:63066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA-dO5rbWdOArH04KUYAAAAV4"]
[Tue Aug 18 12:57:45.786966 2026] [security2:error] [pid 67073:tid 67242] [client 20.119.58.187:11101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/y.php"] [unique_id "aoSA-fcmepr5_nHgLbNpkQAAAjk"]
[Tue Aug 18 12:57:45.807630 2026] [authz_core:error] [pid 67073:tid 67175] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:45.807897 2026] [authz_core:error] [pid 67073:tid 67175] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:45.853653 2026] [security2:error] [pid 67073:tid 67309] [client 104.222.31.70:37637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.31.222.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fioplastic.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSA-fcmepr5_nHgLbNplQAAAnw"]
[Tue Aug 18 12:57:45.861294 2026] [security2:error] [pid 66623:tid 66836] [client 223.185.37.47:3374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSA-dO5rbWdOArH04KUYwAAAVA"]
[Tue Aug 18 12:57:45.861431 2026] [security2:error] [pid 66623:tid 66836] [client 223.185.37.47:3374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSA-dO5rbWdOArH04KUYwAAAVA"]
[Tue Aug 18 12:57:45.873817 2026] [security2:error] [pid 67073:tid 67205] [client 158.158.74.177:2632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/dropdown.php"] [unique_id "aoSA-fcmepr5_nHgLbNplgAAAhQ"]
[Tue Aug 18 12:57:45.874135 2026] [security2:error] [pid 66623:tid 66642] [remote 108.167.161.33:15518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.161.167.108.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guelraott.com"] [uri "/wp-login.php"] [unique_id "aoSA-dO5rbWdOArH04KUZAABRgU"]
[Tue Aug 18 12:57:45.905670 2026] [security2:error] [pid 67073:tid 67213] [client 68.155.154.236:7909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSA-fcmepr5_nHgLbNpmQAAAhw"]
[Tue Aug 18 12:57:45.936552 2026] [security2:error] [pid 67073:tid 67256] [client 213.202.253.4:63331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/wp-content/schallfuns.php"] [unique_id "aoSA-fcmepr5_nHgLbNpmwAAAkc"], referer: www.google.com
[Tue Aug 18 12:57:45.987009 2026] [security2:error] [pid 66623:tid 66856] [client 40.74.65.169:28191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/bless.php"] [unique_id "aoSA-dO5rbWdOArH04KUZQAAAWQ"]
[Tue Aug 18 12:57:46.034842 2026] [security2:error] [pid 67073:tid 67319] [client 104.209.144.33:34132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSA-vcmepr5_nHgLbNpngAAAoY"]
[Tue Aug 18 12:57:46.053848 2026] [security2:error] [pid 66623:tid 66775] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSA-tO5rbWdOArH04KUZwAAARM"]
[Tue Aug 18 12:57:46.058740 2026] [security2:error] [pid 66623:tid 66832] [client 20.118.172.148:62425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSA-tO5rbWdOArH04KUaAAAAUw"]
[Tue Aug 18 12:57:46.069821 2026] [security2:error] [pid 67073:tid 67332] [client 52.173.121.69:24961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSA-vcmepr5_nHgLbNpoAAAApM"]
[Tue Aug 18 12:57:46.079534 2026] [autoindex:error] [pid 66623:tid 66815] [client 4.232.151.198:4342] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:46.090018 2026] [security2:error] [pid 66623:tid 66779] [client 20.119.58.187:12071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/updates.php"] [unique_id "aoSA-tO5rbWdOArH04KUagAAARc"]
[Tue Aug 18 12:57:46.105263 2026] [security2:error] [pid 67073:tid 67278] [client 40.85.222.29:44768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSA-vcmepr5_nHgLbNpoQAAAl0"]
[Tue Aug 18 12:57:46.111426 2026] [security2:error] [pid 67073:tid 67213] [client 79.127.164.8:57786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/old.sql"] [unique_id "aoSA-vcmepr5_nHgLbNppwAAAhw"], referer: https://medihub.com.br/old.sql
[Tue Aug 18 12:57:46.116124 2026] [security2:error] [pid 67073:tid 67297] [client 20.226.56.190:47139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ct.php"] [unique_id "aoSA-vcmepr5_nHgLbNprQAAAnA"]
[Tue Aug 18 12:57:46.117829 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:46.118262 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:46.234418 2026] [security2:error] [pid 66623:tid 66812] [client 20.118.172.148:33525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA-tO5rbWdOArH04KUbQAAATg"]
[Tue Aug 18 12:57:46.246616 2026] [security2:error] [pid 66623:tid 66843] [client 20.104.85.180:7040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSA-tO5rbWdOArH04KUbgAAAVc"]
[Tue Aug 18 12:57:46.255196 2026] [security2:error] [pid 67073:tid 67268] [client 172.182.217.32:15588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/xp.php"] [unique_id "aoSA-vcmepr5_nHgLbNpswAAAlM"]
[Tue Aug 18 12:57:46.273354 2026] [security2:error] [pid 66623:tid 66877] [client 68.155.155.199:13352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/hosty.php"] [unique_id "aoSA-tO5rbWdOArH04KUbwAAAXk"]
[Tue Aug 18 12:57:46.309240 2026] [security2:error] [pid 66623:tid 66710] [remote 110.249.202.110:17212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gustavofrison.com.br"] [uri "/wp-content/uploads/2018/06/GF-com-Luiz-Schmidt-Caio-Almeida-e-Artur-da-Matta-400x284.jpg"] [unique_id "aoSA-tO5rbWdOArH04KUcAABUkk"]
[Tue Aug 18 12:57:46.312924 2026] [security2:error] [pid 66623:tid 66886] [client 4.232.151.198:4342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSA-tO5rbWdOArH04KUcQAAAYI"]
[Tue Aug 18 12:57:46.313333 2026] [security2:error] [pid 67073:tid 67219] [client 74.248.18.37:3270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSA-vcmepr5_nHgLbNpuwAAAiI"]
[Tue Aug 18 12:57:46.320064 2026] [security2:error] [pid 67073:tid 67261] [client 20.100.185.105:43351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSA-vcmepr5_nHgLbNpvAAAAkw"]
[Tue Aug 18 12:57:46.320463 2026] [security2:error] [pid 66623:tid 66772] [client 213.35.127.232:58293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA-tO5rbWdOArH04KUcgAAARA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:46.390905 2026] [security2:error] [pid 67073:tid 67230] [client 157.51.166.53:50240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA-vcmepr5_nHgLbNpwAAAAi0"]
[Tue Aug 18 12:57:46.391097 2026] [security2:error] [pid 67073:tid 67230] [client 157.51.166.53:50240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA-vcmepr5_nHgLbNpwAAAAi0"]
[Tue Aug 18 12:57:46.414447 2026] [security2:error] [pid 67073:tid 67318] [client 74.248.18.37:21513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/sid3.php"] [unique_id "aoSA-vcmepr5_nHgLbNpwQAAAoU"]
[Tue Aug 18 12:57:46.430781 2026] [authz_core:error] [pid 67073:tid 67135] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:46.431225 2026] [authz_core:error] [pid 67073:tid 67135] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:46.444921 2026] [security2:error] [pid 66623:tid 66816] [client 20.119.58.187:12034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSA-tO5rbWdOArH04KUcwAAATw"]
[Tue Aug 18 12:57:46.451460 2026] [security2:error] [pid 66623:tid 66884] [client 68.155.154.236:45574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSA-tO5rbWdOArH04KUdAAAAYA"]
[Tue Aug 18 12:57:46.465713 2026] [security2:error] [pid 66623:tid 66857] [client 40.85.222.29:44788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSA-tO5rbWdOArH04KUdQAAAWU"]
[Tue Aug 18 12:57:46.612360 2026] [security2:error] [pid 66623:tid 66875] [client 104.209.144.33:20465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/images/security.php"] [unique_id "aoSA-tO5rbWdOArH04KUdwAAAXc"]
[Tue Aug 18 12:57:46.688795 2026] [security2:error] [pid 67073:tid 67206] [client 20.118.172.148:33500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/admin.php"] [unique_id "aoSA-vcmepr5_nHgLbNpyAAAAhU"]
[Tue Aug 18 12:57:46.689896 2026] [security2:error] [pid 67073:tid 67294] [client 20.104.85.180:43544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-good.php"] [unique_id "aoSA-vcmepr5_nHgLbNpyQAAAm0"]
[Tue Aug 18 12:57:46.750237 2026] [security2:error] [pid 66623:tid 66804] [client 172.182.217.32:15748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/reze.php"] [unique_id "aoSA-tO5rbWdOArH04KUewAAATA"]
[Tue Aug 18 12:57:46.766882 2026] [security2:error] [pid 67073:tid 67285] [client 196.12.128.158:55458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA-vcmepr5_nHgLbNpywAAAmQ"]
[Tue Aug 18 12:57:46.766991 2026] [security2:error] [pid 67073:tid 67285] [client 196.12.128.158:55458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA-vcmepr5_nHgLbNpywAAAmQ"]
[Tue Aug 18 12:57:46.801987 2026] [security2:error] [pid 66623:tid 66865] [client 20.119.58.187:12046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-index.php"] [unique_id "aoSA-tO5rbWdOArH04KUfAAAAW0"]
[Tue Aug 18 12:57:46.839299 2026] [security2:error] [pid 67073:tid 67262] [client 40.74.65.169:43193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/file25.php"] [unique_id "aoSA-vcmepr5_nHgLbNpzgAAAk0"]
[Tue Aug 18 12:57:46.868683 2026] [security2:error] [pid 66623:tid 66771] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/sf.php"] [unique_id "aoSA-tO5rbWdOArH04KUfQAAAQ8"]
[Tue Aug 18 12:57:46.887492 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:46.887755 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:46.902273 2026] [authz_core:error] [pid 67073:tid 67142] [remote 57.141.22.29:54220] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:46.902532 2026] [authz_core:error] [pid 67073:tid 67142] [remote 57.141.22.29:54220] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:46.906551 2026] [security2:error] [pid 66623:tid 66841] [client 20.1.169.243:3395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/as.php"] [unique_id "aoSA-tO5rbWdOArH04KUgQAAAVU"]
[Tue Aug 18 12:57:46.940514 2026] [security2:error] [pid 66623:tid 66846] [client 172.202.39.151:65265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/ok.php"] [unique_id "aoSA-tO5rbWdOArH04KUgwAAAVo"]
[Tue Aug 18 12:57:46.958112 2026] [security2:error] [pid 66623:tid 66845] [client 40.85.222.29:44791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/index/function.php"] [unique_id "aoSA-tO5rbWdOArH04KUhgAAAVk"]
[Tue Aug 18 12:57:46.958435 2026] [security2:error] [pid 66623:tid 66842] [client 20.100.185.105:29220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/item.php"] [unique_id "aoSA-tO5rbWdOArH04KUhwAAAVY"]
[Tue Aug 18 12:57:47.026601 2026] [security2:error] [pid 66623:tid 66885] [client 20.1.169.243:3670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/atex1.php"] [unique_id "aoSA-9O5rbWdOArH04KUiQAAAYE"]
[Tue Aug 18 12:57:47.048826 2026] [security2:error] [pid 67073:tid 67296] [client 68.155.154.236:50396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/index/function.php"] [unique_id "aoSA-_cmepr5_nHgLbNp4wAAAm8"]
[Tue Aug 18 12:57:47.082522 2026] [autoindex:error] [pid 67073:tid 67323] [client 158.158.74.177:26133] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:47.089403 2026] [security2:error] [pid 66623:tid 66892] [client 74.248.18.37:35332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/sid4.php"] [unique_id "aoSA-9O5rbWdOArH04KUiwAAAYg"]
[Tue Aug 18 12:57:47.116489 2026] [security2:error] [pid 67073:tid 67243] [client 20.118.172.148:53104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/edit.php"] [unique_id "aoSA-_cmepr5_nHgLbNp5QAAAjo"]
[Tue Aug 18 12:57:47.121158 2026] [autoindex:error] [pid 67073:tid 67264] [client 4.232.151.198:24913] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:47.150890 2026] [security2:error] [pid 66623:tid 66647] [remote 66.102.134.13:56966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.134.102.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-login.php"] [unique_id "aoSA-9O5rbWdOArH04KUjAABVAo"]
[Tue Aug 18 12:57:47.172931 2026] [security2:error] [pid 66623:tid 66794] [client 20.119.58.187:12038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/alfanew.php7"] [unique_id "aoSA-9O5rbWdOArH04KUjgAAASY"]
[Tue Aug 18 12:57:47.184295 2026] [security2:error] [pid 67073:tid 67310] [client 52.173.121.69:16466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/nwwha.php"] [unique_id "aoSA-_cmepr5_nHgLbNp5wAAAn0"]
[Tue Aug 18 12:57:47.197973 2026] [security2:error] [pid 67073:tid 67317] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/k.php"] [unique_id "aoSA-_cmepr5_nHgLbNp6AAAAoQ"]
[Tue Aug 18 12:57:47.241426 2026] [security2:error] [pid 67073:tid 67293] [client 172.182.217.32:15582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/2026w.php"] [unique_id "aoSA-_cmepr5_nHgLbNp6gAAAmw"]
[Tue Aug 18 12:57:47.287708 2026] [security2:error] [pid 67073:tid 67234] [client 158.158.74.177:26133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/images/about.php"] [unique_id "aoSA-_cmepr5_nHgLbNp7gAAAjE"]
[Tue Aug 18 12:57:47.321217 2026] [security2:error] [pid 66623:tid 66813] [client 20.118.172.148:62426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSA-9O5rbWdOArH04KUlQAAATk"]
[Tue Aug 18 12:57:47.327198 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:47.327468 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:47.330326 2026] [security2:error] [pid 67073:tid 67253] [client 213.35.127.232:58518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSA-_cmepr5_nHgLbNp8QAAAkQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:47.330366 2026] [security2:error] [pid 67073:tid 67240] [client 4.232.151.198:24913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSA-_cmepr5_nHgLbNp8AAAAjc"]
[Tue Aug 18 12:57:47.371607 2026] [security2:error] [pid 67073:tid 67291] [client 20.100.169.31:16412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/aaa.php"] [unique_id "aoSA-_cmepr5_nHgLbNp8gAAAmo"]
[Tue Aug 18 12:57:47.372502 2026] [security2:error] [pid 66623:tid 66855] [client 40.85.222.29:44246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSA-9O5rbWdOArH04KUlwAAAWM"]
[Tue Aug 18 12:57:47.382847 2026] [security2:error] [pid 66623:tid 66782] [client 74.248.18.37:3661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSA-9O5rbWdOArH04KUmQAAARo"]
[Tue Aug 18 12:57:47.387148 2026] [security2:error] [pid 67073:tid 67319] [client 20.206.73.37:59895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/xyn.php"] [unique_id "aoSA-_cmepr5_nHgLbNp8wAAAoY"]
[Tue Aug 18 12:57:47.389537 2026] [security2:error] [pid 67073:tid 67247] [client 20.1.169.243:3656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/atomlib.php"] [unique_id "aoSA-_cmepr5_nHgLbNp9AAAAj4"]
[Tue Aug 18 12:57:47.421083 2026] [core:error] [pid 67073:tid 67278] [client 52.167.144.146:33154] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 12:57:47.421099 2026] [core:error] [pid 67073:tid 67278] [client 52.167.144.146:33154] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 12:57:47.465029 2026] [security2:error] [pid 67073:tid 67236] [client 68.155.155.199:10426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/test1.php"] [unique_id "aoSA-_cmepr5_nHgLbNp-AAAAjM"]
[Tue Aug 18 12:57:47.524916 2026] [security2:error] [pid 67073:tid 67295] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/82.php"] [unique_id "aoSA-_cmepr5_nHgLbNp-wAAAm4"]
[Tue Aug 18 12:57:47.529900 2026] [security2:error] [pid 67073:tid 67250] [client 20.119.58.187:12500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/locale.php"] [unique_id "aoSA-_cmepr5_nHgLbNp_AAAAkE"]
[Tue Aug 18 12:57:47.552900 2026] [security2:error] [pid 67073:tid 67268] [client 68.155.154.236:7670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSA-_cmepr5_nHgLbNp_QAAAlM"]
[Tue Aug 18 12:57:47.631292 2026] [authz_core:error] [pid 67073:tid 67184] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:47.631589 2026] [authz_core:error] [pid 67073:tid 67184] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:47.633041 2026] [security2:error] [pid 67073:tid 67261] [client 40.74.65.169:44779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/file15.php"] [unique_id "aoSA-_cmepr5_nHgLbNqBQAAAkw"]
[Tue Aug 18 12:57:47.643974 2026] [security2:error] [pid 67073:tid 67245] [client 20.118.172.148:43503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/w.php"] [unique_id "aoSA-_cmepr5_nHgLbNqBgAAAjw"]
[Tue Aug 18 12:57:47.691614 2026] [security2:error] [pid 67073:tid 67177] [remote 72.167.40.62:35812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.40.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/wp-login.php"] [unique_id "aoSA-_cmepr5_nHgLbNqBwACOGU"]
[Tue Aug 18 12:57:47.749093 2026] [security2:error] [pid 67073:tid 67215] [client 197.184.64.235:41938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA-_cmepr5_nHgLbNqCgAAAh4"]
[Tue Aug 18 12:57:47.749240 2026] [security2:error] [pid 67073:tid 67215] [client 197.184.64.235:41938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA-_cmepr5_nHgLbNqCgAAAh4"]
[Tue Aug 18 12:57:47.751079 2026] [security2:error] [pid 67073:tid 67327] [client 172.182.217.32:15600] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "invictambiental.com.br"] [uri "/1.php"] [unique_id "aoSA-_cmepr5_nHgLbNqCwAAAo4"]
[Tue Aug 18 12:57:47.751220 2026] [security2:error] [pid 67073:tid 67327] [client 172.182.217.32:15600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/1.php"] [unique_id "aoSA-_cmepr5_nHgLbNqCwAAAo4"]
[Tue Aug 18 12:57:47.754754 2026] [security2:error] [pid 67073:tid 67306] [client 20.1.169.243:3392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/black.php"] [unique_id "aoSA-_cmepr5_nHgLbNqDAAAAnk"]
[Tue Aug 18 12:57:47.804375 2026] [security2:error] [pid 67073:tid 67220] [client 20.100.185.105:43333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/assets/images/doc.php"] [unique_id "aoSA-_cmepr5_nHgLbNqDwAAAiM"]
[Tue Aug 18 12:57:47.844452 2026] [security2:error] [pid 67073:tid 67269] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/dex.php"] [unique_id "aoSA-_cmepr5_nHgLbNqEAAAAlQ"]
[Tue Aug 18 12:57:47.887342 2026] [security2:error] [pid 67073:tid 67217] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA-_cmepr5_nHgLbNqEgACIBY"]
[Tue Aug 18 12:57:47.888182 2026] [security2:error] [pid 67073:tid 67273] [client 20.119.58.187:11875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wxo.php"] [unique_id "aoSA-_cmepr5_nHgLbNqHAAAAlg"]
[Tue Aug 18 12:57:47.929432 2026] [security2:error] [pid 67073:tid 67152] [remote 165.227.132.137:55216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.132.227.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/wp-login.php"] [unique_id "aoSA-_cmepr5_nHgLbNqHwACPUw"]
[Tue Aug 18 12:57:47.930823 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:47.931092 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:47.995837 2026] [security2:error] [pid 67073:tid 67321] [client 4.232.151.198:4312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSA-_cmepr5_nHgLbNqIgAAAog"]
[Tue Aug 18 12:57:47.998565 2026] [security2:error] [pid 67073:tid 67211] [client 74.248.18.37:21523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/size.php"] [unique_id "aoSA-_cmepr5_nHgLbNqIwAAAho"]
[Tue Aug 18 12:57:48.013202 2026] [security2:error] [pid 67073:tid 67289] [client 74.248.18.37:3289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-fclass.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqJAAAAmg"]
[Tue Aug 18 12:57:48.036619 2026] [security2:error] [pid 67073:tid 67218] [client 103.139.191.60:64585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ctrrefrigeracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqKgAAAiE"]
[Tue Aug 18 12:57:48.036741 2026] [security2:error] [pid 67073:tid 67218] [client 103.139.191.60:64585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ctrrefrigeracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqKgAAAiE"]
[Tue Aug 18 12:57:48.096464 2026] [security2:error] [pid 67073:tid 67243] [client 40.85.222.29:44758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/Cachex.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqPwAAAjo"]
[Tue Aug 18 12:57:48.101673 2026] [security2:error] [pid 67073:tid 67301] [client 20.118.172.148:53061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/file.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqVAAAAnQ"]
[Tue Aug 18 12:57:48.114005 2026] [security2:error] [pid 66623:tid 66822] [client 20.250.13.23:47815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/rip.php"] [unique_id "aoSA_NO5rbWdOArH04KUpAAAAUI"]
[Tue Aug 18 12:57:48.123439 2026] [security2:error] [pid 67073:tid 67208] [client 20.1.169.243:3704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/bs1.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqVgAAAhc"]
[Tue Aug 18 12:57:48.124361 2026] [security2:error] [pid 66623:tid 66870] [client 68.155.154.236:46622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/Cachex.php"] [unique_id "aoSA_NO5rbWdOArH04KUpQAAAXI"]
[Tue Aug 18 12:57:48.135265 2026] [autoindex:error] [pid 66623:tid 66703] [remote 40.77.167.224:43784] AH01276: Cannot serve directory /home1/sergiopontes/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:48.164349 2026] [security2:error] [pid 67073:tid 67212] [client 68.155.155.199:8146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/zwso.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqYAAAAhs"]
[Tue Aug 18 12:57:48.165200 2026] [security2:error] [pid 67073:tid 67226] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/puc.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqYQAAAik"]
[Tue Aug 18 12:57:48.180712 2026] [security2:error] [pid 66623:tid 66789] [client 158.158.34.183:43692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/beence.php"] [unique_id "aoSA_NO5rbWdOArH04KUpwAAASE"]
[Tue Aug 18 12:57:48.243672 2026] [security2:error] [pid 67073:tid 67317] [client 20.119.58.187:12502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/colour.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqegAAAoQ"]
[Tue Aug 18 12:57:48.249750 2026] [security2:error] [pid 67073:tid 67329] [client 172.182.217.32:15611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/2.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqewAAApA"]
[Tue Aug 18 12:57:48.257304 2026] [security2:error] [pid 67073:tid 67322] [client 20.118.172.148:56514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/xmr.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqfwAAAok"]
[Tue Aug 18 12:57:48.345350 2026] [security2:error] [pid 67073:tid 67331] [client 213.35.127.232:58738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqhwAAApI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:48.346941 2026] [security2:error] [pid 67073:tid 67279] [client 20.226.56.190:20376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gy.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqiAAAAl4"]
[Tue Aug 18 12:57:48.423994 2026] [security2:error] [pid 67073:tid 67253] [client 20.100.185.105:62343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-load.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqkgAAAkQ"]
[Tue Aug 18 12:57:48.454986 2026] [security2:error] [pid 67073:tid 67318] [client 20.186.30.159:1961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqqAAAAoU"]
[Tue Aug 18 12:57:48.510981 2026] [security2:error] [pid 66623:tid 66838] [client 20.1.169.243:3668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/colors/blue/about.php"] [unique_id "aoSA_NO5rbWdOArH04KUrAAAAVI"]
[Tue Aug 18 12:57:48.516743 2026] [security2:error] [pid 67073:tid 67215] [client 20.203.183.135:24618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqrAAAAh4"]
[Tue Aug 18 12:57:48.530777 2026] [authz_core:error] [pid 67073:tid 67116] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:48.531026 2026] [authz_core:error] [pid 67073:tid 67116] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:48.556932 2026] [core:error] [pid 66623:tid 66733] [remote 52.167.144.146:47566] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 12:57:48.556946 2026] [core:error] [pid 66623:tid 66733] [remote 52.167.144.146:47566] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 12:57:48.575893 2026] [security2:error] [pid 67073:tid 67308] [client 52.173.121.69:25018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/opsqt.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqsAAAAns"]
[Tue Aug 18 12:57:48.613761 2026] [security2:error] [pid 67073:tid 67217] [client 20.118.172.148:19702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqswAAAiA"]
[Tue Aug 18 12:57:48.619491 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.56.190:3057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/tt.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqtQAAAlg"]
[Tue Aug 18 12:57:48.639056 2026] [security2:error] [pid 67073:tid 67327] [client 20.119.58.187:12523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-contentt.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqugAAAo4"]
[Tue Aug 18 12:57:48.655069 2026] [security2:error] [pid 67073:tid 67265] [client 4.232.151.198:24896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqvAAAAlA"]
[Tue Aug 18 12:57:48.678981 2026] [security2:error] [pid 67073:tid 67230] [client 74.248.18.37:35373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/special.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqvQAAAi0"]
[Tue Aug 18 12:57:48.723300 2026] [security2:error] [pid 67073:tid 67296] [client 68.155.154.236:50389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqyQAAAm8"]
[Tue Aug 18 12:57:48.748420 2026] [security2:error] [pid 67073:tid 67294] [client 172.182.217.32:15579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/7.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqygAAAm0"]
[Tue Aug 18 12:57:48.749200 2026] [security2:error] [pid 66623:tid 66857] [client 40.74.65.169:26723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/f35.php"] [unique_id "aoSA_NO5rbWdOArH04KUswAAAWU"]
[Tue Aug 18 12:57:48.772150 2026] [security2:error] [pid 67073:tid 67243] [client 20.186.30.159:1667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqywAAAjo"]
[Tue Aug 18 12:57:48.784559 2026] [security2:error] [pid 67073:tid 67301] [client 68.155.155.199:8170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/Geforce.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqzAAAAnQ"]
[Tue Aug 18 12:57:48.859676 2026] [security2:error] [pid 67073:tid 67219] [client 40.85.222.29:44266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSA_Pcmepr5_nHgLbNq1gAAAiI"]
[Tue Aug 18 12:57:48.877981 2026] [security2:error] [pid 66623:tid 66862] [client 20.1.169.243:3681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/con7.php"] [unique_id "aoSA_NO5rbWdOArH04KUtQAAAWo"]
[Tue Aug 18 12:57:48.981986 2026] [security2:error] [pid 67073:tid 67326] [client 20.226.56.190:32307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/mq.php"] [unique_id "aoSA_Pcmepr5_nHgLbNq4wAAAo0"]
[Tue Aug 18 12:57:48.985938 2026] [security2:error] [pid 67073:tid 67306] [client 20.100.169.31:16428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/abcd.php"] [unique_id "aoSA_Pcmepr5_nHgLbNq5AAAAnk"]
[Tue Aug 18 12:57:48.994356 2026] [security2:error] [pid 66623:tid 66808] [client 20.119.58.187:12078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/config.php7"] [unique_id "aoSA_NO5rbWdOArH04KUtgAAATQ"]
[Tue Aug 18 12:57:49.030700 2026] [security2:error] [pid 67073:tid 67285] [client 158.158.74.177:2665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSA_fcmepr5_nHgLbNq7AAAAmQ"]
[Tue Aug 18 12:57:49.066161 2026] [security2:error] [pid 67073:tid 67311] [client 20.100.185.105:42637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/r.php"] [unique_id "aoSA_fcmepr5_nHgLbNq7QAAAn4"]
[Tue Aug 18 12:57:49.088915 2026] [security2:error] [pid 66623:tid 66764] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_dO5rbWdOArH04KUtwABd38"]
[Tue Aug 18 12:57:49.089102 2026] [security2:error] [pid 66623:tid 66875] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_dO5rbWdOArH04KUtwABd38"]
[Tue Aug 18 12:57:49.133737 2026] [security2:error] [pid 67073:tid 67270] [client 74.248.18.37:3682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSA_fcmepr5_nHgLbNq8wAAAlU"]
[Tue Aug 18 12:57:49.138443 2026] [security2:error] [pid 66623:tid 66787] [client 20.118.172.148:43504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/aa.php"] [unique_id "aoSA_dO5rbWdOArH04KUuAAAAR8"]
[Tue Aug 18 12:57:49.142855 2026] [authz_core:error] [pid 67073:tid 67186] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:49.143113 2026] [authz_core:error] [pid 67073:tid 67186] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:49.155937 2026] [security2:error] [pid 67073:tid 67229] [client 20.186.30.159:1957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/media.php"] [unique_id "aoSA_fcmepr5_nHgLbNq-AAAAiw"]
[Tue Aug 18 12:57:49.165873 2026] [security2:error] [pid 67073:tid 67244] [client 20.118.172.148:62080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/about.php"] [unique_id "aoSA_fcmepr5_nHgLbNq-gAAAjs"]
[Tue Aug 18 12:57:49.179077 2026] [security2:error] [pid 67073:tid 67261] [client 20.118.133.132:1663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/ops.php"] [unique_id "aoSA_fcmepr5_nHgLbNq_AAAAkw"]
[Tue Aug 18 12:57:49.229213 2026] [security2:error] [pid 67073:tid 67318] [client 52.173.121.69:16480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/jvcpa.php"] [unique_id "aoSA_fcmepr5_nHgLbNrAAAAAoU"]
[Tue Aug 18 12:57:49.232036 2026] [security2:error] [pid 66623:tid 66827] [client 172.182.200.96:7629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSA_dO5rbWdOArH04KUugAAAUc"]
[Tue Aug 18 12:57:49.240203 2026] [security2:error] [pid 67073:tid 67330] [client 172.182.217.32:15601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/10.php"] [unique_id "aoSA_fcmepr5_nHgLbNrAQAAApE"]
[Tue Aug 18 12:57:49.243441 2026] [security2:error] [pid 67073:tid 67268] [client 20.1.169.243:3687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/contact-form-7/includes/js/jquery-ui/themes/smoothness/RxRywmgzyK.php"] [unique_id "aoSA_fcmepr5_nHgLbNrAgAAAlM"]
[Tue Aug 18 12:57:49.244281 2026] [security2:error] [pid 67073:tid 67254] [client 20.226.56.190:45041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/13.php"] [unique_id "aoSA_fcmepr5_nHgLbNrAwAAAkU"]
[Tue Aug 18 12:57:49.257464 2026] [security2:error] [pid 67073:tid 67281] [client 20.250.13.23:25707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/p.php"] [unique_id "aoSA_fcmepr5_nHgLbNrBAAAAmA"]
[Tue Aug 18 12:57:49.303073 2026] [security2:error] [pid 67073:tid 67250] [client 4.232.151.198:4299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSA_fcmepr5_nHgLbNrBgAAAkE"]
[Tue Aug 18 12:57:49.347943 2026] [security2:error] [pid 67073:tid 67312] [client 20.119.58.187:12524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/config.php"] [unique_id "aoSA_fcmepr5_nHgLbNrCQAAAn8"]
[Tue Aug 18 12:57:49.362678 2026] [security2:error] [pid 66623:tid 66851] [client 68.155.155.199:4353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/fpwch.php"] [unique_id "aoSA_dO5rbWdOArH04KUuwAAAV8"]
[Tue Aug 18 12:57:49.363073 2026] [security2:error] [pid 67073:tid 67214] [client 213.35.127.232:58960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSA_fcmepr5_nHgLbNrDAAAAh0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:49.419708 2026] [security2:error] [pid 67073:tid 67253] [client 74.248.18.37:54933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/ssjpxze.php"] [unique_id "aoSA_fcmepr5_nHgLbNrDQAAAkQ"]
[Tue Aug 18 12:57:49.426145 2026] [security2:error] [pid 66623:tid 66810] [client 20.48.236.86:32857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/ops.php"] [unique_id "aoSA_dO5rbWdOArH04KUvQAAATY"]
[Tue Aug 18 12:57:49.466498 2026] [security2:error] [pid 67073:tid 67255] [client 40.85.222.29:44789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-2019.php"] [unique_id "aoSA_fcmepr5_nHgLbNrEAAAAkY"]
[Tue Aug 18 12:57:49.500270 2026] [security2:error] [pid 66623:tid 66839] [client 68.155.154.236:40316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-2019.php"] [unique_id "aoSA_dO5rbWdOArH04KUvgAAAVM"]
[Tue Aug 18 12:57:49.583955 2026] [security2:error] [pid 67073:tid 67252] [client 20.186.30.159:1670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/admin.php"] [unique_id "aoSA_fcmepr5_nHgLbNrGgAAAkM"]
[Tue Aug 18 12:57:49.615541 2026] [security2:error] [pid 67073:tid 67274] [client 20.1.169.243:3654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/dist/alfa-rex.php"] [unique_id "aoSA_fcmepr5_nHgLbNrGwAAAlk"]
[Tue Aug 18 12:57:49.632669 2026] [security2:error] [pid 66623:tid 66885] [client 20.118.172.148:43468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSA_dO5rbWdOArH04KUwAAAAYE"]
[Tue Aug 18 12:57:49.633494 2026] [security2:error] [pid 66623:tid 66860] [client 192.141.172.134:65184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_dO5rbWdOArH04KUwQAAAWg"]
[Tue Aug 18 12:57:49.633635 2026] [security2:error] [pid 66623:tid 66860] [client 192.141.172.134:65184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_dO5rbWdOArH04KUwQAAAWg"]
[Tue Aug 18 12:57:49.640815 2026] [security2:error] [pid 67073:tid 67216] [client 40.74.65.169:43190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-load.php"] [unique_id "aoSA_fcmepr5_nHgLbNrHQAAAh8"]
[Tue Aug 18 12:57:49.679947 2026] [security2:error] [pid 66623:tid 66849] [client 37.40.227.74:56921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_dO5rbWdOArH04KUwgAAAV0"]
[Tue Aug 18 12:57:49.680060 2026] [security2:error] [pid 66623:tid 66849] [client 37.40.227.74:56921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_dO5rbWdOArH04KUwgAAAV0"]
[Tue Aug 18 12:57:49.710638 2026] [security2:error] [pid 66623:tid 66825] [client 20.119.58.187:11880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/theme.php"] [unique_id "aoSA_dO5rbWdOArH04KUwwAAAUU"]
[Tue Aug 18 12:57:49.725863 2026] [security2:error] [pid 67073:tid 67314] [client 20.226.56.190:20392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/so.php"] [unique_id "aoSA_fcmepr5_nHgLbNrJgAAAoE"]
[Tue Aug 18 12:57:49.729154 2026] [security2:error] [pid 67073:tid 67289] [client 172.182.217.32:15747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/13.php"] [unique_id "aoSA_fcmepr5_nHgLbNrJwAAAmg"]
[Tue Aug 18 12:57:49.738435 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:49.738694 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:49.777848 2026] [security2:error] [pid 67073:tid 67259] [client 74.248.18.37:3324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSA_fcmepr5_nHgLbNrMAAAAko"]
[Tue Aug 18 12:57:49.797933 2026] [security2:error] [pid 66623:tid 66793] [client 172.202.39.151:55427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/item.php"] [unique_id "aoSA_dO5rbWdOArH04KUxgAAASU"]
[Tue Aug 18 12:57:49.836059 2026] [security2:error] [pid 66623:tid 66809] [client 86.120.159.145:58124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_dO5rbWdOArH04KUxwAAATU"]
[Tue Aug 18 12:57:49.836194 2026] [security2:error] [pid 66623:tid 66809] [client 86.120.159.145:58124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_dO5rbWdOArH04KUxwAAATU"]
[Tue Aug 18 12:57:49.892491 2026] [security2:error] [pid 67073:tid 67329] [client 20.100.185.105:6375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/root.php"] [unique_id "aoSA_fcmepr5_nHgLbNrMgAAApA"]
[Tue Aug 18 12:57:49.908021 2026] [security2:error] [pid 67073:tid 67313] [client 40.85.222.29:44242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSA_fcmepr5_nHgLbNrNAAAAoA"]
[Tue Aug 18 12:57:49.931261 2026] [security2:error] [pid 67073:tid 67275] [client 4.232.151.198:4347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSA_fcmepr5_nHgLbNrNgAAAlo"]
[Tue Aug 18 12:57:49.978590 2026] [security2:error] [pid 66623:tid 66848] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/inso.php"] [unique_id "aoSA_dO5rbWdOArH04KUyQAAAVw"]
[Tue Aug 18 12:57:50.040705 2026] [authz_core:error] [pid 67073:tid 67196] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:50.040977 2026] [authz_core:error] [pid 67073:tid 67196] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:50.041623 2026] [security2:error] [pid 67073:tid 67249] [client 20.186.30.159:1689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/mac.php"] [unique_id "aoSA_vcmepr5_nHgLbNrOwAAAkA"]
[Tue Aug 18 12:57:50.054234 2026] [security2:error] [pid 66623:tid 66792] [client 158.158.34.183:27972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/configs.php"] [unique_id "aoSA_tO5rbWdOArH04KUzgAAASQ"]
[Tue Aug 18 12:57:50.065350 2026] [security2:error] [pid 67073:tid 67238] [client 20.119.58.187:12056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/block-bindings.php"] [unique_id "aoSA_vcmepr5_nHgLbNrPAAAAjU"]
[Tue Aug 18 12:57:50.068391 2026] [security2:error] [pid 67073:tid 67207] [client 172.182.200.96:7672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSA_vcmepr5_nHgLbNrPgAAAhY"]
[Tue Aug 18 12:57:50.082980 2026] [security2:error] [pid 67073:tid 67282] [client 74.248.18.37:21541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/storage/index.php"] [unique_id "aoSA_vcmepr5_nHgLbNrQQAAAmE"]
[Tue Aug 18 12:57:50.109147 2026] [security2:error] [pid 67073:tid 67233] [client 103.184.169.37:42234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_vcmepr5_nHgLbNrQgAAAjA"]
[Tue Aug 18 12:57:50.109255 2026] [security2:error] [pid 67073:tid 67233] [client 103.184.169.37:42234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_vcmepr5_nHgLbNrQgAAAjA"]
[Tue Aug 18 12:57:50.117566 2026] [security2:error] [pid 67073:tid 67264] [client 68.155.155.199:13353] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/mini"] [unique_id "aoSA_vcmepr5_nHgLbNrQwAAAk8"]
[Tue Aug 18 12:57:50.142349 2026] [security2:error] [pid 66623:tid 66847] [client 20.118.172.148:62099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/admin.php"] [unique_id "aoSA_tO5rbWdOArH04KU0AAAAVs"]
[Tue Aug 18 12:57:50.146261 2026] [security2:error] [pid 66623:tid 66794] [client 20.1.169.243:3403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/elementor/wp-login.php"] [unique_id "aoSA_dO5rbWdOArH04KUygAAASY"]
[Tue Aug 18 12:57:50.224407 2026] [security2:error] [pid 66623:tid 66893] [client 172.182.217.32:15569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/100.php"] [unique_id "aoSA_tO5rbWdOArH04KU0gAAAYk"]
[Tue Aug 18 12:57:50.285403 2026] [security2:error] [pid 67073:tid 67300] [client 20.118.172.148:63082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/about.php"] [unique_id "aoSA_vcmepr5_nHgLbNrSwAAAnM"]
[Tue Aug 18 12:57:50.293378 2026] [security2:error] [pid 67073:tid 67319] [client 40.85.222.29:44247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/.cache/x.php"] [unique_id "aoSA_vcmepr5_nHgLbNrTAAAAoY"]
[Tue Aug 18 12:57:50.297606 2026] [security2:error] [pid 67073:tid 67268] [client 20.186.30.159:1674] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/1.php"] [unique_id "aoSA_vcmepr5_nHgLbNrTQAAAlM"]
[Tue Aug 18 12:57:50.297739 2026] [security2:error] [pid 67073:tid 67268] [client 20.186.30.159:1674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/1.php"] [unique_id "aoSA_vcmepr5_nHgLbNrTQAAAlM"]
[Tue Aug 18 12:57:50.306595 2026] [security2:error] [pid 67073:tid 67281] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/aa.php"] [unique_id "aoSA_vcmepr5_nHgLbNrTwAAAmA"]
[Tue Aug 18 12:57:50.320765 2026] [security2:error] [pid 67073:tid 67296] [client 103.120.71.157:56448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_vcmepr5_nHgLbNrUAAAAm8"]
[Tue Aug 18 12:57:50.320919 2026] [security2:error] [pid 67073:tid 67296] [client 103.120.71.157:56448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_vcmepr5_nHgLbNrUAAAAm8"]
[Tue Aug 18 12:57:50.340177 2026] [authz_core:error] [pid 67073:tid 67127] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:50.340507 2026] [authz_core:error] [pid 67073:tid 67127] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:50.355942 2026] [security2:error] [pid 67073:tid 67266] [client 114.119.135.217:37437] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.trokarautomoveis.com.br"] [uri "/photo-resize/2026/975883/gb-b656418.jpg"] [unique_id "aoSA_vcmepr5_nHgLbNrVAAAAlE"], referer: https://www.trokarautomoveis.com.br/veiculo/975883/saveiro-cross-1-6-mi-total-flex-8v-ce
[Tue Aug 18 12:57:50.360977 2026] [security2:error] [pid 66623:tid 66788] [client 172.182.200.96:7624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSA_tO5rbWdOArH04KU1AAAASA"]
[Tue Aug 18 12:57:50.377336 2026] [security2:error] [pid 67073:tid 67218] [client 213.35.127.232:59162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA_vcmepr5_nHgLbNrVQAAAiE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:50.419492 2026] [security2:error] [pid 67073:tid 67325] [client 20.119.58.187:12522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/class_api.php"] [unique_id "aoSA_vcmepr5_nHgLbNrVwAAAow"]
[Tue Aug 18 12:57:50.444626 2026] [authz_core:error] [pid 67073:tid 67138] [remote 57.141.22.25:35336] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:50.445041 2026] [authz_core:error] [pid 67073:tid 67138] [remote 57.141.22.25:35336] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:50.462383 2026] [security2:error] [pid 67073:tid 67253] [client 20.226.56.190:45021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/10.php"] [unique_id "aoSA_vcmepr5_nHgLbNrWwAAAkQ"]
[Tue Aug 18 12:57:50.474583 2026] [security2:error] [pid 67073:tid 67213] [client 52.173.121.69:17960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSA_vcmepr5_nHgLbNrXAAAAhw"]
[Tue Aug 18 12:57:50.550716 2026] [security2:error] [pid 66623:tid 66887] [client 20.100.185.105:52162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/a1.php"] [unique_id "aoSA_tO5rbWdOArH04KU4gAAAYM"]
[Tue Aug 18 12:57:50.603468 2026] [security2:error] [pid 67073:tid 67324] [client 68.155.154.236:8003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSA_vcmepr5_nHgLbNraAAAAos"]
[Tue Aug 18 12:57:50.606312 2026] [security2:error] [pid 66623:tid 66820] [client 4.232.151.198:4418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSA_tO5rbWdOArH04KU5AAAAUA"]
[Tue Aug 18 12:57:50.635838 2026] [security2:error] [pid 66623:tid 66828] [client 74.248.18.37:3321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSA_tO5rbWdOArH04KU5QAAAUg"]
[Tue Aug 18 12:57:50.641175 2026] [authz_core:error] [pid 67073:tid 67145] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:50.641471 2026] [authz_core:error] [pid 67073:tid 67145] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:50.646527 2026] [security2:error] [pid 67073:tid 67243] [client 40.85.222.29:26887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSA_vcmepr5_nHgLbNrbQAAAjo"]
[Tue Aug 18 12:57:50.679673 2026] [security2:error] [pid 66623:tid 66773] [client 158.158.74.177:16518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSA_tO5rbWdOArH04KU5wAAARE"]
[Tue Aug 18 12:57:50.685845 2026] [security2:error] [pid 66623:tid 66870] [client 20.203.138.185:39940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA_tO5rbWdOArH04KU6AAAAXI"]
[Tue Aug 18 12:57:50.717515 2026] [security2:error] [pid 67073:tid 67274] [client 172.182.217.32:15580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/222.php"] [unique_id "aoSA_vcmepr5_nHgLbNrbwAAAlk"]
[Tue Aug 18 12:57:50.742359 2026] [security2:error] [pid 67073:tid 67297] [client 20.100.169.31:48544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/NewFile.php"] [unique_id "aoSA_vcmepr5_nHgLbNrcgAAAnA"]
[Tue Aug 18 12:57:50.759949 2026] [security2:error] [pid 67073:tid 67248] [client 20.186.30.159:1931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/coffee.php"] [unique_id "aoSA_vcmepr5_nHgLbNrdAAAAj8"]
[Tue Aug 18 12:57:50.770633 2026] [security2:error] [pid 67073:tid 67272] [client 74.248.18.37:35330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/storage/rip.php"] [unique_id "aoSA_vcmepr5_nHgLbNrdQAAAlc"]
[Tue Aug 18 12:57:50.774156 2026] [security2:error] [pid 67073:tid 67242] [client 20.119.58.187:12510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/root.php"] [unique_id "aoSA_vcmepr5_nHgLbNrdgAAAjk"]
[Tue Aug 18 12:57:50.804681 2026] [security2:error] [pid 67073:tid 67219] [client 68.155.155.199:5018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSA_vcmepr5_nHgLbNrdwAAAiI"]
[Tue Aug 18 12:57:50.945257 2026] [security2:error] [pid 67073:tid 67275] [client 20.118.172.148:62106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/adminfuns.php"] [unique_id "aoSA_vcmepr5_nHgLbNrfQAAAlo"]
[Tue Aug 18 12:57:50.948773 2026] [security2:error] [pid 67073:tid 67320] [client 40.85.222.29:25032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSA_vcmepr5_nHgLbNrfgAAAoc"]
[Tue Aug 18 12:57:50.971994 2026] [security2:error] [pid 66623:tid 66886] [client 138.36.100.162:41368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_tO5rbWdOArH04KU6gAAAYI"]
[Tue Aug 18 12:57:50.972122 2026] [security2:error] [pid 66623:tid 66886] [client 138.36.100.162:41368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_tO5rbWdOArH04KU6gAAAYI"]
[Tue Aug 18 12:57:50.997216 2026] [security2:error] [pid 66623:tid 66863] [client 20.1.169.243:3421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/goat1.php"] [unique_id "aoSA_tO5rbWdOArH04KU6wAAAWs"]
[Tue Aug 18 12:57:51.001375 2026] [security2:error] [pid 67073:tid 67222] [client 119.93.171.138:62115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.171.93.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imbe.eng.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_vcmepr5_nHgLbNrgQAAAiU"]
[Tue Aug 18 12:57:51.001496 2026] [security2:error] [pid 67073:tid 67222] [client 119.93.171.138:62115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "imbe.eng.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_vcmepr5_nHgLbNrgQAAAiU"]
[Tue Aug 18 12:57:51.033433 2026] [security2:error] [pid 67073:tid 67236] [client 52.173.121.69:24980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSA__cmepr5_nHgLbNrigAAAjM"]
[Tue Aug 18 12:57:51.117507 2026] [security2:error] [pid 67073:tid 67237] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/img.php"] [unique_id "aoSA__cmepr5_nHgLbNrjgAAAjQ"]
[Tue Aug 18 12:57:51.122862 2026] [security2:error] [pid 66623:tid 66884] [client 20.186.30.159:1677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSA_9O5rbWdOArH04KU7AAAAYA"]
[Tue Aug 18 12:57:51.130944 2026] [security2:error] [pid 67073:tid 67299] [client 20.119.58.187:12059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/menu.php"] [unique_id "aoSA__cmepr5_nHgLbNrjwAAAnI"]
[Tue Aug 18 12:57:51.153882 2026] [security2:error] [pid 67073:tid 67239] [client 20.226.56.190:28244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/te.php"] [unique_id "aoSA__cmepr5_nHgLbNrkAAAAjY"]
[Tue Aug 18 12:57:51.171498 2026] [security2:error] [pid 66623:tid 66772] [client 20.100.185.105:29231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/install.php"] [unique_id "aoSA_9O5rbWdOArH04KU7gAAARA"]
[Tue Aug 18 12:57:51.203914 2026] [security2:error] [pid 66623:tid 66824] [client 172.182.217.32:15555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/adminfuns.php"] [unique_id "aoSA_9O5rbWdOArH04KU7wAAAUQ"]
[Tue Aug 18 12:57:51.235969 2026] [security2:error] [pid 67073:tid 67300] [client 68.155.154.236:48900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/.cache/x.php"] [unique_id "aoSA__cmepr5_nHgLbNrkwAAAnM"]
[Tue Aug 18 12:57:51.246900 2026] [authz_core:error] [pid 67073:tid 67140] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:51.247165 2026] [authz_core:error] [pid 67073:tid 67140] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:51.261545 2026] [security2:error] [pid 67073:tid 67215] [client 20.206.73.37:63241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSA__cmepr5_nHgLbNrlQAAAh4"]
[Tue Aug 18 12:57:51.265686 2026] [security2:error] [pid 67073:tid 67207] [client 4.232.151.198:4348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSA__cmepr5_nHgLbNrlwAAAhY"]
[Tue Aug 18 12:57:51.275613 2026] [security2:error] [pid 67073:tid 67235] [client 40.74.65.169:43151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSA__cmepr5_nHgLbNrmQAAAjI"]
[Tue Aug 18 12:57:51.321326 2026] [security2:error] [pid 66623:tid 66777] [client 40.85.222.29:44277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSA_9O5rbWdOArH04KU8AAAARU"]
[Tue Aug 18 12:57:51.366731 2026] [security2:error] [pid 66623:tid 66786] [client 20.1.169.243:3404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/google-seo-rank/module.php"] [unique_id "aoSA_9O5rbWdOArH04KU8QAAAR4"]
[Tue Aug 18 12:57:51.392634 2026] [security2:error] [pid 67073:tid 67221] [client 213.35.127.232:59364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA__cmepr5_nHgLbNrmwAAAiQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:51.473245 2026] [security2:error] [pid 67073:tid 67326] [client 68.155.155.199:11863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/about/function.php"] [unique_id "aoSA__cmepr5_nHgLbNroAAAAo0"]
[Tue Aug 18 12:57:51.479581 2026] [security2:error] [pid 67073:tid 67280] [client 74.248.18.37:3327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSA__cmepr5_nHgLbNroQAAAl8"]
[Tue Aug 18 12:57:51.484425 2026] [security2:error] [pid 66623:tid 66868] [client 20.119.58.187:12532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/plugin.php"] [unique_id "aoSA_9O5rbWdOArH04KU9QAAAXA"]
[Tue Aug 18 12:57:51.491608 2026] [security2:error] [pid 67073:tid 67283] [client 20.118.133.132:15220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/8.php"] [unique_id "aoSA__cmepr5_nHgLbNrpAAAAmI"]
[Tue Aug 18 12:57:51.491817 2026] [security2:error] [pid 67073:tid 67250] [client 74.248.18.37:35339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/sts.php"] [unique_id "aoSA__cmepr5_nHgLbNrowAAAkE"]
[Tue Aug 18 12:57:51.547301 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:51.547556 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:51.553807 2026] [security2:error] [pid 67073:tid 67295] [client 20.186.30.159:1958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSA__cmepr5_nHgLbNrqAAAAm4"]
[Tue Aug 18 12:57:51.555470 2026] [security2:error] [pid 66623:tid 66835] [client 20.118.172.148:2744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/goods.php"] [unique_id "aoSA_9O5rbWdOArH04KU9gAAAU8"]
[Tue Aug 18 12:57:51.575268 2026] [security2:error] [pid 67073:tid 67234] [client 78.46.190.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.pousadadoreiarthur.com.br"] [uri "/index.php"] [unique_id "aoSA_fcmepr5_nHgLbNrNwACMXY"], referer: https://www.pousadadoreiarthur.com.br/
[Tue Aug 18 12:57:51.653495 2026] [security2:error] [pid 66623:tid 66804] [client 40.85.222.29:25035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSA_9O5rbWdOArH04KU-QAAATA"]
[Tue Aug 18 12:57:51.693128 2026] [security2:error] [pid 67073:tid 67332] [client 172.182.217.32:15784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/abcd.php"] [unique_id "aoSA__cmepr5_nHgLbNrqQAAApM"]
[Tue Aug 18 12:57:51.728486 2026] [security2:error] [pid 66623:tid 66841] [client 20.1.169.243:3649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/h.php"] [unique_id "aoSA_9O5rbWdOArH04KU_AAAAVU"]
[Tue Aug 18 12:57:51.732268 2026] [security2:error] [pid 66623:tid 66823] [client 20.203.138.185:45320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA_9O5rbWdOArH04KU_gAAAUM"]
[Tue Aug 18 12:57:51.754235 2026] [security2:error] [pid 66623:tid 66860] [client 20.226.56.190:28249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kc.php"] [unique_id "aoSA_9O5rbWdOArH04KU_wAAAWg"]
[Tue Aug 18 12:57:51.769298 2026] [security2:error] [pid 66623:tid 66849] [client 20.118.172.148:62420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/as.php"] [unique_id "aoSA_9O5rbWdOArH04KVAQAAAV0"]
[Tue Aug 18 12:57:51.779860 2026] [security2:error] [pid 66623:tid 66816] [client 5.31.227.224:30411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_9O5rbWdOArH04KVAgAAATw"]
[Tue Aug 18 12:57:51.784238 2026] [security2:error] [pid 66623:tid 66816] [client 5.31.227.224:30411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_9O5rbWdOArH04KVAgAAATw"]
[Tue Aug 18 12:57:51.849635 2026] [security2:error] [pid 66623:tid 66805] [client 20.119.58.187:11872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cloud.php"] [unique_id "aoSA_9O5rbWdOArH04KVBAAAATE"]
[Tue Aug 18 12:57:51.894828 2026] [security2:error] [pid 66623:tid 66845] [client 4.232.151.198:4313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSA_9O5rbWdOArH04KVBwAAAVk"]
[Tue Aug 18 12:57:51.933095 2026] [security2:error] [pid 66623:tid 66848] [client 68.155.155.199:5004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/function/function.php"] [unique_id "aoSA_9O5rbWdOArH04KVCAAAAVw"]
[Tue Aug 18 12:57:51.936495 2026] [security2:error] [pid 66623:tid 66774] [client 52.173.121.69:17922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSA_9O5rbWdOArH04KVCQAAARI"]
[Tue Aug 18 12:57:51.943399 2026] [security2:error] [pid 66623:tid 66885] [client 79.127.164.8:57864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/phpbb_db_backup_data.bak"] [unique_id "aoSA_9O5rbWdOArH04KVCgAAAYE"], referer: https://medihub.com.br/phpbb_db_backup_data.bak
[Tue Aug 18 12:57:51.989422 2026] [security2:error] [pid 66623:tid 66878] [client 20.203.183.135:13092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/yj09.php"] [unique_id "aoSA_9O5rbWdOArH04KVDAAAAXo"]
[Tue Aug 18 12:57:51.999950 2026] [security2:error] [pid 66623:tid 66782] [client 40.85.222.29:25073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSA_9O5rbWdOArH04KVDQAAARo"]
[Tue Aug 18 12:57:52.017650 2026] [security2:error] [pid 67073:tid 67296] [client 223.185.37.47:17912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBAPcmepr5_nHgLbNrqgAAAm8"]
[Tue Aug 18 12:57:52.017831 2026] [security2:error] [pid 67073:tid 67296] [client 223.185.37.47:17912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBAPcmepr5_nHgLbNrqgAAAm8"]
[Tue Aug 18 12:57:52.056088 2026] [security2:error] [pid 66623:tid 66836] [client 68.155.154.236:46643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSBANO5rbWdOArH04KVEgAAAVA"]
[Tue Aug 18 12:57:52.056087 2026] [security2:error] [pid 66623:tid 66865] [client 149.34.210.141:59186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBANO5rbWdOArH04KVEwAAAW0"]
[Tue Aug 18 12:57:52.072280 2026] [security2:error] [pid 66623:tid 66862] [client 157.20.138.62:49730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBANO5rbWdOArH04KVFAAAAWo"]
[Tue Aug 18 12:57:52.072422 2026] [security2:error] [pid 66623:tid 66862] [client 157.20.138.62:49730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBANO5rbWdOArH04KVFAAAAWo"]
[Tue Aug 18 12:57:52.080371 2026] [security2:error] [pid 66623:tid 66837] [client 20.100.185.105:29226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/file2.php"] [unique_id "aoSBANO5rbWdOArH04KVFgAAAVE"]
[Tue Aug 18 12:57:52.086866 2026] [security2:error] [pid 67073:tid 67321] [client 20.250.13.23:52380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/php.php"] [unique_id "aoSBAPcmepr5_nHgLbNrqwAAAog"]
[Tue Aug 18 12:57:52.092364 2026] [security2:error] [pid 66623:tid 66844] [client 20.1.169.243:3664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/import/csv1.php"] [unique_id "aoSBANO5rbWdOArH04KVGAAAAVg"]
[Tue Aug 18 12:57:52.104892 2026] [security2:error] [pid 66623:tid 66881] [client 20.226.56.190:47136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/jn.php"] [unique_id "aoSBANO5rbWdOArH04KVGgAAAX0"]
[Tue Aug 18 12:57:52.106238 2026] [security2:error] [pid 66623:tid 66796] [client 40.74.65.169:26688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/aaa.php"] [unique_id "aoSBANO5rbWdOArH04KVGwAAASg"]
[Tue Aug 18 12:57:52.114597 2026] [security2:error] [pid 66623:tid 66802] [client 74.248.18.37:3316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSBANO5rbWdOArH04KVHAAAAS4"]
[Tue Aug 18 12:57:52.137289 2026] [security2:error] [pid 66623:tid 66828] [client 20.186.30.159:1797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/yj09.php"] [unique_id "aoSBANO5rbWdOArH04KVHQAAAUg"]
[Tue Aug 18 12:57:52.146859 2026] [security2:error] [pid 66623:tid 66858] [client 74.248.18.37:26514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/system_log.php"] [unique_id "aoSBANO5rbWdOArH04KVHgAAAWY"]
[Tue Aug 18 12:57:52.214208 2026] [security2:error] [pid 66623:tid 66794] [client 172.182.217.32:15605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/al.php"] [unique_id "aoSBANO5rbWdOArH04KVIQAAASY"]
[Tue Aug 18 12:57:52.215516 2026] [security2:error] [pid 66623:tid 66800] [client 20.119.58.187:12526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/configs.php"] [unique_id "aoSBANO5rbWdOArH04KVIgAAASw"]
[Tue Aug 18 12:57:52.274564 2026] [authz_core:error] [pid 66623:tid 66684] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:52.274833 2026] [authz_core:error] [pid 66623:tid 66684] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:52.278784 2026] [security2:error] [pid 66623:tid 66886] [client 40.85.222.29:26914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBANO5rbWdOArH04KVJQAAAYI"]
[Tue Aug 18 12:57:52.279421 2026] [authz_core:error] [pid 66623:tid 66663] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:52.279879 2026] [authz_core:error] [pid 66623:tid 66663] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:52.335898 2026] [security2:error] [pid 66623:tid 66865] [client 149.34.210.141:59186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBANO5rbWdOArH04KVEwAAAW0"]
[Tue Aug 18 12:57:52.368822 2026] [security2:error] [pid 66623:tid 66871] [client 20.118.172.148:2705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/php8.php"] [unique_id "aoSBANO5rbWdOArH04KVKAAAAXM"]
[Tue Aug 18 12:57:52.407707 2026] [security2:error] [pid 66623:tid 66893] [client 213.35.127.232:59590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBANO5rbWdOArH04KVKwAAAYk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:52.410334 2026] [security2:error] [pid 66623:tid 66838] [client 20.118.172.148:62101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/bolt.php"] [unique_id "aoSBANO5rbWdOArH04KVLAAAAVI"]
[Tue Aug 18 12:57:52.417995 2026] [security2:error] [pid 66623:tid 66793] [client 20.100.169.31:48424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSBANO5rbWdOArH04KVLgAAASU"]
[Tue Aug 18 12:57:52.422847 2026] [autoindex:error] [pid 66623:tid 66824] [client 82.102.18.182:58610] AH01276: Cannot serve directory /home4/ctrrefrigeracao/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:52.456772 2026] [security2:error] [pid 66623:tid 66790] [client 20.1.169.243:3679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/index.bak.php"] [unique_id "aoSBANO5rbWdOArH04KVLwAAASI"]
[Tue Aug 18 12:57:52.473489 2026] [authz_core:error] [pid 66623:tid 66755] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:52.473743 2026] [authz_core:error] [pid 66623:tid 66755] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:52.537252 2026] [security2:error] [pid 66623:tid 66803] [client 68.155.155.199:6638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-signin.php"] [unique_id "aoSBANO5rbWdOArH04KVNQAAAS8"]
[Tue Aug 18 12:57:52.567976 2026] [security2:error] [pid 66623:tid 66770] [client 20.226.56.190:2089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/bf.php"] [unique_id "aoSBANO5rbWdOArH04KVOAAAAQ4"]
[Tue Aug 18 12:57:52.568238 2026] [security2:error] [pid 66623:tid 66786] [client 20.119.58.187:12055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-configs.php"] [unique_id "aoSBANO5rbWdOArH04KVOQAAAR4"]
[Tue Aug 18 12:57:52.568372 2026] [security2:error] [pid 66623:tid 66841] [client 40.85.222.29:26924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSBANO5rbWdOArH04KVOgAAAVU"]
[Tue Aug 18 12:57:52.663281 2026] [security2:error] [pid 66623:tid 66785] [client 20.48.236.86:50731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/8.php"] [unique_id "aoSBANO5rbWdOArH04KVSAAAAR0"]
[Tue Aug 18 12:57:52.683855 2026] [security2:error] [pid 66623:tid 66889] [client 4.232.151.198:4291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSBANO5rbWdOArH04KVMwAAAYU"]
[Tue Aug 18 12:57:52.697868 2026] [security2:error] [pid 66623:tid 66795] [client 20.186.30.159:1954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/scxy.php"] [unique_id "aoSBANO5rbWdOArH04KVSQAAASc"]
[Tue Aug 18 12:57:52.705144 2026] [security2:error] [pid 66623:tid 66787] [client 172.182.217.32:15760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/alfa.php"] [unique_id "aoSBANO5rbWdOArH04KVSgAAAR8"]
[Tue Aug 18 12:57:52.710798 2026] [security2:error] [pid 66623:tid 66848] [client 68.155.154.236:46611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBANO5rbWdOArH04KVSwAAAVw"]
[Tue Aug 18 12:57:52.711480 2026] [security2:error] [pid 66623:tid 66784] [client 20.100.185.105:41015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBANO5rbWdOArH04KVTAAAARw"]
[Tue Aug 18 12:57:52.718990 2026] [security2:error] [pid 66623:tid 66853] [client 172.182.200.96:14121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBANO5rbWdOArH04KVUQAAAWE"]
[Tue Aug 18 12:57:52.752623 2026] [security2:error] [pid 66623:tid 66813] [client 20.203.138.185:35049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ws61.php"] [unique_id "aoSBANO5rbWdOArH04KVVAAAATk"]
[Tue Aug 18 12:57:52.752831 2026] [security2:error] [pid 66623:tid 66804] [client 74.248.18.37:55791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSBANO5rbWdOArH04KVVQAAATA"]
[Tue Aug 18 12:57:52.799824 2026] [security2:error] [pid 66623:tid 66819] [client 20.118.172.148:63068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/info.php"] [unique_id "aoSBANO5rbWdOArH04KVVwAAAT8"]
[Tue Aug 18 12:57:52.820370 2026] [security2:error] [pid 66623:tid 66798] [client 74.248.18.37:21508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/t.php"] [unique_id "aoSBANO5rbWdOArH04KVWQAAASo"]
[Tue Aug 18 12:57:52.821889 2026] [security2:error] [pid 66623:tid 66880] [client 20.1.169.243:3655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/lite.php"] [unique_id "aoSBANO5rbWdOArH04KVWgAAAXw"]
[Tue Aug 18 12:57:52.875746 2026] [autoindex:error] [pid 66623:tid 66823] [client 158.158.74.177:2687] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:52.915668 2026] [security2:error] [pid 66623:tid 66852] [client 40.85.222.29:25046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSBANO5rbWdOArH04KVYQAAAWA"]
[Tue Aug 18 12:57:52.921949 2026] [security2:error] [pid 66623:tid 66836] [client 20.119.58.187:12481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/update.php"] [unique_id "aoSBANO5rbWdOArH04KVYwAAAVA"]
[Tue Aug 18 12:57:52.966538 2026] [security2:error] [pid 66623:tid 66828] [client 40.74.65.169:28175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/gecko.php"] [unique_id "aoSBANO5rbWdOArH04KVaAAAAUg"]
[Tue Aug 18 12:57:52.982432 2026] [security2:error] [pid 66623:tid 66825] [client 20.186.30.159:1971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSBANO5rbWdOArH04KVaQAAAUU"]
[Tue Aug 18 12:57:52.991901 2026] [security2:error] [pid 66623:tid 66834] [client 213.202.253.4:58186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/txets.php"] [unique_id "aoSBANO5rbWdOArH04KVagAAAU4"], referer: www.google.com
[Tue Aug 18 12:57:53.026845 2026] [security2:error] [pid 66623:tid 66864] [client 178.153.171.161:47335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBAdO5rbWdOArH04KVbQAAAWw"]
[Tue Aug 18 12:57:53.026987 2026] [security2:error] [pid 66623:tid 66864] [client 178.153.171.161:47335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBAdO5rbWdOArH04KVbQAAAWw"]
[Tue Aug 18 12:57:53.107602 2026] [security2:error] [pid 66623:tid 66649] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBAdO5rbWdOArH04KVcQABGww"]
[Tue Aug 18 12:57:53.107754 2026] [security2:error] [pid 66623:tid 66783] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBAdO5rbWdOArH04KVcQABGww"]
[Tue Aug 18 12:57:53.125166 2026] [security2:error] [pid 66623:tid 66874] [client 68.155.155.199:7138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/f35.php"] [unique_id "aoSBAdO5rbWdOArH04KVdgAAAXY"]
[Tue Aug 18 12:57:53.151425 2026] [security2:error] [pid 66623:tid 66871] [client 68.155.154.236:50390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBAdO5rbWdOArH04KVdwAAAXM"]
[Tue Aug 18 12:57:53.183935 2026] [security2:error] [pid 66623:tid 66877] [client 20.1.169.243:3396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/live.php"] [unique_id "aoSBAdO5rbWdOArH04KVewAAAXk"]
[Tue Aug 18 12:57:53.192899 2026] [security2:error] [pid 66623:tid 66838] [client 52.173.121.69:17925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSBAdO5rbWdOArH04KVfQAAAVI"]
[Tue Aug 18 12:57:53.196241 2026] [security2:error] [pid 66623:tid 66794] [client 172.182.217.32:15591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/as.php"] [unique_id "aoSBAdO5rbWdOArH04KVfgAAASY"]
[Tue Aug 18 12:57:53.242597 2026] [security2:error] [pid 66623:tid 66793] [client 40.85.222.29:44779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBAdO5rbWdOArH04KVfwAAASU"]
[Tue Aug 18 12:57:53.269210 2026] [security2:error] [pid 66623:tid 66861] [client 92.222.108.115:56024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "kuringacomunicacao.com.br"] [uri "/robots.txt"] [unique_id "aoSBAdO5rbWdOArH04KVggAAAWk"]
[Tue Aug 18 12:57:53.269316 2026] [security2:error] [pid 66623:tid 66861] [client 92.222.108.115:56024] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kuringacomunicacao.com.br"] [uri "/robots.txt"] [unique_id "aoSBAdO5rbWdOArH04KVggAAAWk"]
[Tue Aug 18 12:57:53.277982 2026] [security2:error] [pid 66623:tid 66773] [client 158.158.34.183:43663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/delpaths.php"] [unique_id "aoSBAdO5rbWdOArH04KVgwAAARE"]
[Tue Aug 18 12:57:53.283982 2026] [security2:error] [pid 66623:tid 66790] [client 20.118.133.132:15397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/biufile.php"] [unique_id "aoSBAdO5rbWdOArH04KVhQAAASI"]
[Tue Aug 18 12:57:53.292966 2026] [security2:error] [pid 66623:tid 66811] [client 20.118.172.148:54848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBAdO5rbWdOArH04KVhgAAATc"]
[Tue Aug 18 12:57:53.301492 2026] [security2:error] [pid 66623:tid 66810] [client 172.182.200.96:14182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/update/wpupex.php"] [unique_id "aoSBAdO5rbWdOArH04KViAAAATY"]
[Tue Aug 18 12:57:53.304202 2026] [security2:error] [pid 66623:tid 66829] [client 4.232.151.198:4437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSBAdO5rbWdOArH04KViQAAAUk"]
[Tue Aug 18 12:57:53.318971 2026] [security2:error] [pid 66623:tid 66797] [client 20.119.58.187:12069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/input.php"] [unique_id "aoSBAdO5rbWdOArH04KVigAAASk"]
[Tue Aug 18 12:57:53.329408 2026] [security2:error] [pid 66623:tid 66850] [client 20.100.185.105:52194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-includes/admin.php"] [unique_id "aoSBAdO5rbWdOArH04KViwAAAV4"]
[Tue Aug 18 12:57:53.350184 2026] [security2:error] [pid 66623:tid 66807] [client 20.186.30.159:1719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBAdO5rbWdOArH04KVjgAAATM"]
[Tue Aug 18 12:57:53.420603 2026] [security2:error] [pid 66623:tid 66869] [client 213.35.127.232:59830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBAdO5rbWdOArH04KVkgAAAXE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:53.446613 2026] [security2:error] [pid 66623:tid 66814] [client 20.118.172.148:43488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/chosen.php"] [unique_id "aoSBAdO5rbWdOArH04KVlAAAATo"]
[Tue Aug 18 12:57:53.461648 2026] [security2:error] [pid 66623:tid 66804] [client 20.65.98.162:8372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "gruposchopan.com.br"] [uri "/.mopj.php"] [unique_id "aoSBAdO5rbWdOArH04KVlgAAATA"]
[Tue Aug 18 12:57:53.527344 2026] [security2:error] [pid 66623:tid 66837] [client 40.85.222.29:44798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSBAdO5rbWdOArH04KVmgAAAVE"]
[Tue Aug 18 12:57:53.542163 2026] [security2:error] [pid 66623:tid 66769] [client 74.248.18.37:20543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/templates.php"] [unique_id "aoSBAdO5rbWdOArH04KVmwAAAQ0"]
[Tue Aug 18 12:57:53.551828 2026] [security2:error] [pid 66623:tid 66795] [client 20.1.169.243:3417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/bypass.php"] [unique_id "aoSBAdO5rbWdOArH04KVnQAAASc"]
[Tue Aug 18 12:57:53.646891 2026] [security2:error] [pid 66623:tid 66796] [client 20.203.138.185:50290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/rum.php"] [unique_id "aoSBAdO5rbWdOArH04KVogAAASg"]
[Tue Aug 18 12:57:53.671029 2026] [security2:error] [pid 66623:tid 66791] [client 20.119.58.187:12075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/geju.php"] [unique_id "aoSBAdO5rbWdOArH04KVpAAAASM"]
[Tue Aug 18 12:57:53.684817 2026] [authz_core:error] [pid 66623:tid 66695] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:53.685080 2026] [authz_core:error] [pid 66623:tid 66695] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:53.686078 2026] [security2:error] [pid 66623:tid 66867] [client 172.182.217.32:15612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/aa.php"] [unique_id "aoSBAdO5rbWdOArH04KVpgAAAW8"]
[Tue Aug 18 12:57:53.723506 2026] [security2:error] [pid 66623:tid 66834] [client 158.158.74.177:2687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/includes/about.php"] [unique_id "aoSBAdO5rbWdOArH04KVqAAAAU4"]
[Tue Aug 18 12:57:53.750748 2026] [security2:error] [pid 66623:tid 66851] [client 40.74.65.169:43137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/xiugai.php"] [unique_id "aoSBAdO5rbWdOArH04KVrAAAAV8"]
[Tue Aug 18 12:57:53.804388 2026] [security2:error] [pid 66623:tid 66871] [client 20.226.6.191:3984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBAdO5rbWdOArH04KVtgAAAXM"]
[Tue Aug 18 12:57:53.817044 2026] [security2:error] [pid 66623:tid 66838] [client 172.182.200.96:14107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSBAdO5rbWdOArH04KVvAAAAVI"]
[Tue Aug 18 12:57:53.817147 2026] [security2:error] [pid 66623:tid 66794] [client 74.248.18.37:3104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSBAdO5rbWdOArH04KVvQAAASY"]
[Tue Aug 18 12:57:53.837267 2026] [security2:error] [pid 66623:tid 66862] [client 20.226.6.191:4053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBAdO5rbWdOArH04KVzQAAAWo"]
[Tue Aug 18 12:57:53.853166 2026] [security2:error] [pid 66623:tid 66824] [client 20.226.6.191:4046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/admin.php"] [unique_id "aoSBAdO5rbWdOArH04KVzgAAAUQ"]
[Tue Aug 18 12:57:53.854966 2026] [security2:error] [pid 66623:tid 66861] [client 40.85.222.29:44264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSBAdO5rbWdOArH04KVzwAAAWk"]
[Tue Aug 18 12:57:53.865203 2026] [security2:error] [pid 66623:tid 66811] [client 68.155.155.199:9370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/gg.php"] [unique_id "aoSBAdO5rbWdOArH04KV0AAAATc"]
[Tue Aug 18 12:57:53.881242 2026] [security2:error] [pid 66623:tid 66827] [client 20.206.73.37:59923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/inso.php"] [unique_id "aoSBAdO5rbWdOArH04KV0QAAAUc"]
[Tue Aug 18 12:57:53.885131 2026] [security2:error] [pid 66623:tid 66803] [client 20.226.6.191:4075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/public/css.php"] [unique_id "aoSBAdO5rbWdOArH04KV0wAAAS8"]
[Tue Aug 18 12:57:53.895799 2026] [security2:error] [pid 66623:tid 66770] [client 74.248.18.37:21514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/g.php"] [unique_id "aoSBAdO5rbWdOArH04KV1AAAAQ4"]
[Tue Aug 18 12:57:53.906491 2026] [access_compat:error] [pid 66623:tid 66874] [client 192.178.4.34:61666] AH01797: client denied by server configuration: /home1/classea/public_html/robots.txt
[Tue Aug 18 12:57:53.910415 2026] [security2:error] [pid 66623:tid 66860] [client 20.226.6.191:4093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBAdO5rbWdOArH04KV1gAAAWg"]
[Tue Aug 18 12:57:53.926168 2026] [security2:error] [pid 66623:tid 66781] [client 68.155.154.236:7895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSBAdO5rbWdOArH04KV2gAAARk"]
[Tue Aug 18 12:57:53.944243 2026] [security2:error] [pid 66623:tid 66768] [client 4.232.151.198:24956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSBAdO5rbWdOArH04KV3AAAAQw"]
[Tue Aug 18 12:57:53.954611 2026] [security2:error] [pid 66623:tid 66832] [client 20.100.185.105:58250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/123.php"] [unique_id "aoSBAdO5rbWdOArH04KV3gAAAUw"]
[Tue Aug 18 12:57:53.968195 2026] [security2:error] [pid 66623:tid 66888] [client 170.81.43.147:43550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.43.81.170.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.fbenevides.com.br"] [uri "/include/plugin/payment/alipay/pay.php"] [unique_id "aoSBAdO5rbWdOArH04KV4AAAAYQ"]
[Tue Aug 18 12:57:53.999318 2026] [security2:error] [pid 66623:tid 66845] [client 20.226.6.191:3975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBAdO5rbWdOArH04KV4gAAAVk"]
[Tue Aug 18 12:57:54.007933 2026] [security2:error] [pid 66623:tid 66808] [client 85.154.68.202:55496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBAtO5rbWdOArH04KV4wAAATQ"]
[Tue Aug 18 12:57:54.008092 2026] [security2:error] [pid 66623:tid 66808] [client 85.154.68.202:55496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBAtO5rbWdOArH04KV4wAAATQ"]
[Tue Aug 18 12:57:54.015532 2026] [security2:error] [pid 67073:tid 67301] [client 107.150.61.58:37542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.61.150.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.h6.com.br"] [uri "/wp-includes/admin.php"] [unique_id "aoSBAvcmepr5_nHgLbNrrAAAAnQ"], referer: https://mail.h6.com.br/wp-includes/admin.php
[Tue Aug 18 12:57:54.035896 2026] [security2:error] [pid 66623:tid 66892] [client 20.119.58.187:12068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp.php"] [unique_id "aoSBAtO5rbWdOArH04KV5QAAAYg"]
[Tue Aug 18 12:57:54.065619 2026] [security2:error] [pid 66623:tid 66876] [client 20.186.30.159:1942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/blurbs.php"] [unique_id "aoSBAtO5rbWdOArH04KV5gAAAXg"]
[Tue Aug 18 12:57:54.079052 2026] [security2:error] [pid 66623:tid 66819] [client 20.226.6.191:4070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/gelay.php"] [unique_id "aoSBAtO5rbWdOArH04KV6QAAAT8"]
[Tue Aug 18 12:57:54.121353 2026] [security2:error] [pid 66623:tid 66841] [client 74.248.18.37:21536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/gecko.php"] [unique_id "aoSBAtO5rbWdOArH04KV6wAAAVU"]
[Tue Aug 18 12:57:54.156868 2026] [security2:error] [pid 66623:tid 66801] [client 20.118.172.148:63097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/simple.php"] [unique_id "aoSBAtO5rbWdOArH04KV7QAAAS0"]
[Tue Aug 18 12:57:54.158308 2026] [security2:error] [pid 66623:tid 66779] [client 40.85.222.29:44784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBAtO5rbWdOArH04KV7gAAARc"]
[Tue Aug 18 12:57:54.176254 2026] [security2:error] [pid 66623:tid 66835] [client 172.182.217.32:15583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/abc.php"] [unique_id "aoSBAtO5rbWdOArH04KV8AAAAU8"]
[Tue Aug 18 12:57:54.176402 2026] [security2:error] [pid 66623:tid 66795] [client 20.226.6.191:4045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBAtO5rbWdOArH04KV8QAAASc"]
[Tue Aug 18 12:57:54.208126 2026] [security2:error] [pid 66623:tid 66774] [client 114.5.214.109:49817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBAtO5rbWdOArH04KV8wAAARI"]
[Tue Aug 18 12:57:54.212209 2026] [security2:error] [pid 66623:tid 66774] [client 114.5.214.109:49817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBAtO5rbWdOArH04KV8wAAARI"]
[Tue Aug 18 12:57:54.215586 2026] [security2:error] [pid 66623:tid 66805] [client 74.248.18.37:35341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/term.php"] [unique_id "aoSBAtO5rbWdOArH04KV9AAAATE"]
[Tue Aug 18 12:57:54.283360 2026] [security2:error] [pid 66623:tid 66856] [client 20.226.6.191:4062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBAtO5rbWdOArH04KV-gAAAWQ"]
[Tue Aug 18 12:57:54.284196 2026] [authz_core:error] [pid 66623:tid 66703] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:54.284479 2026] [authz_core:error] [pid 66623:tid 66703] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:54.325411 2026] [security2:error] [pid 66623:tid 66821] [client 160.120.140.123:50314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBAtO5rbWdOArH04KV-wAAAUE"]
[Tue Aug 18 12:57:54.325547 2026] [security2:error] [pid 66623:tid 66821] [client 160.120.140.123:50314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBAtO5rbWdOArH04KV-wAAAUE"]
[Tue Aug 18 12:57:54.339953 2026] [security2:error] [pid 66623:tid 66764] [remote 135.236.141.8:6443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.141.236.135.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ondaseventos.com"] [uri "/wp-login.php"] [unique_id "aoSBAtO5rbWdOArH04KV_wABIX8"]
[Tue Aug 18 12:57:54.369592 2026] [security2:error] [pid 66623:tid 66886] [client 20.1.169.243:3684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/lock360.php"] [unique_id "aoSBAtO5rbWdOArH04KWBAAAAYI"]
[Tue Aug 18 12:57:54.370835 2026] [security2:error] [pid 66623:tid 66863] [client 20.226.6.191:4005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSBAtO5rbWdOArH04KWBQAAAWs"]
[Tue Aug 18 12:57:54.390521 2026] [security2:error] [pid 66623:tid 66796] [client 20.119.58.187:12050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/hoot.php"] [unique_id "aoSBAtO5rbWdOArH04KWBwAAASg"]
[Tue Aug 18 12:57:54.391112 2026] [security2:error] [pid 66623:tid 66893] [client 20.226.6.191:4058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/about.php"] [unique_id "aoSBAtO5rbWdOArH04KWCAAAAYk"]
[Tue Aug 18 12:57:54.419727 2026] [security2:error] [pid 66623:tid 66794] [client 20.226.6.191:4082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBAtO5rbWdOArH04KWCQAAASY"]
[Tue Aug 18 12:57:54.421005 2026] [security2:error] [pid 66623:tid 66833] [client 20.118.172.148:54886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/edit.php"] [unique_id "aoSBAtO5rbWdOArH04KWCgAAAU0"]
[Tue Aug 18 12:57:54.429104 2026] [security2:error] [pid 66623:tid 66862] [client 52.173.121.69:6081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSBAtO5rbWdOArH04KWDAAAAWo"]
[Tue Aug 18 12:57:54.437357 2026] [security2:error] [pid 66623:tid 66846] [client 213.35.127.232:60041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBAtO5rbWdOArH04KWDgAAAVo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:54.438961 2026] [security2:error] [pid 66623:tid 66773] [client 172.182.200.96:7616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-admin/install.php"] [unique_id "aoSBAtO5rbWdOArH04KWDwAAARE"]
[Tue Aug 18 12:57:54.450186 2026] [security2:error] [pid 66623:tid 66790] [client 68.155.154.236:7658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSBAtO5rbWdOArH04KWEQAAASI"]
[Tue Aug 18 12:57:54.480907 2026] [security2:error] [pid 66623:tid 66812] [client 40.85.222.29:44274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBAtO5rbWdOArH04KWFAAAATg"]
[Tue Aug 18 12:57:54.539233 2026] [security2:error] [pid 66623:tid 66807] [client 20.186.30.159:1669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/bajah.php"] [unique_id "aoSBAtO5rbWdOArH04KWGQAAATM"]
[Tue Aug 18 12:57:54.548486 2026] [security2:error] [pid 66623:tid 66854] [client 40.74.65.169:27745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/adminner.php"] [unique_id "aoSBAtO5rbWdOArH04KWGwAAAWI"]
[Tue Aug 18 12:57:54.572954 2026] [security2:error] [pid 66623:tid 66806] [client 20.100.185.105:40023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/cc.php"] [unique_id "aoSBAtO5rbWdOArH04KWHQAAATI"]
[Tue Aug 18 12:57:54.589365 2026] [authz_core:error] [pid 66623:tid 66676] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:54.589787 2026] [authz_core:error] [pid 66623:tid 66676] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:54.602237 2026] [security2:error] [pid 66623:tid 66785] [client 20.203.138.185:11244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ze.php"] [unique_id "aoSBAtO5rbWdOArH04KWIAAAAR0"]
[Tue Aug 18 12:57:54.603153 2026] [security2:error] [pid 66623:tid 66809] [client 20.226.6.191:4038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/f35.php"] [unique_id "aoSBAtO5rbWdOArH04KWIQAAATU"]
[Tue Aug 18 12:57:54.624340 2026] [security2:error] [pid 66623:tid 66661] [remote 47.86.33.52:31798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rtvsolucoes.com.br"] [uri "/wp-login.php"] [unique_id "aoSBAtO5rbWdOArH04KWIwABFRg"]
[Tue Aug 18 12:57:54.647379 2026] [security2:error] [pid 66623:tid 66853] [client 158.158.74.177:2630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/index.php"] [unique_id "aoSBAtO5rbWdOArH04KWKwAAAWE"]
[Tue Aug 18 12:57:54.654974 2026] [security2:error] [pid 66623:tid 66844] [client 68.155.155.199:11875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/class.php"] [unique_id "aoSBAtO5rbWdOArH04KWLAAAAVg"]
[Tue Aug 18 12:57:54.667380 2026] [security2:error] [pid 66623:tid 66890] [client 74.248.18.37:3844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBAtO5rbWdOArH04KWLgAAAYY"]
[Tue Aug 18 12:57:54.668969 2026] [security2:error] [pid 66623:tid 66811] [client 4.232.151.198:4329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBAtO5rbWdOArH04KWLwAAATc"]
[Tue Aug 18 12:57:54.671569 2026] [security2:error] [pid 66623:tid 66786] [client 172.182.217.32:15756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/av.php"] [unique_id "aoSBAtO5rbWdOArH04KWMAAAAR4"]
[Tue Aug 18 12:57:54.683645 2026] [security2:error] [pid 66623:tid 66855] [client 192.141.172.134:65514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBAtO5rbWdOArH04KWMQAAAWM"]
[Tue Aug 18 12:57:54.683777 2026] [security2:error] [pid 66623:tid 66855] [client 192.141.172.134:65514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBAtO5rbWdOArH04KWMQAAAWM"]
[Tue Aug 18 12:57:54.718826 2026] [security2:error] [pid 66623:tid 66837] [client 54.39.0.186:62924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "kuringacomunicacao.com.br"] [uri "/"] [unique_id "aoSBAtO5rbWdOArH04KWNQAAAVE"]
[Tue Aug 18 12:57:54.718933 2026] [security2:error] [pid 66623:tid 66837] [client 54.39.0.186:62924] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kuringacomunicacao.com.br"] [uri "/"] [unique_id "aoSBAtO5rbWdOArH04KWNQAAAVE"]
[Tue Aug 18 12:57:54.722740 2026] [security2:error] [pid 66623:tid 66797] [client 158.158.34.183:29805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/NewFile.php"] [unique_id "aoSBAtO5rbWdOArH04KWNgAAASk"]
[Tue Aug 18 12:57:54.745592 2026] [security2:error] [pid 66623:tid 66848] [client 20.119.58.187:11843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBAtO5rbWdOArH04KWPQAAAVw"]
[Tue Aug 18 12:57:54.753893 2026] [security2:error] [pid 66623:tid 66852] [client 20.118.172.148:53057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBAtO5rbWdOArH04KWQAAAAWA"]
[Tue Aug 18 12:57:54.762294 2026] [security2:error] [pid 66623:tid 66774] [client 20.226.6.191:4040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/inputs.php"] [unique_id "aoSBAtO5rbWdOArH04KWQgAAARI"]
[Tue Aug 18 12:57:54.774442 2026] [security2:error] [pid 66623:tid 66798] [client 20.215.241.237:53477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBAtO5rbWdOArH04KWQwAAASo"]
[Tue Aug 18 12:57:54.792619 2026] [security2:error] [pid 66623:tid 66827] [client 20.100.169.31:31255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-good.php"] [unique_id "aoSBAtO5rbWdOArH04KWRQAAAUc"]
[Tue Aug 18 12:57:54.793580 2026] [security2:error] [pid 66623:tid 66783] [client 74.248.18.37:21530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/gettest.php"] [unique_id "aoSBAtO5rbWdOArH04KWRwAAARs"]
[Tue Aug 18 12:57:54.805677 2026] [security2:error] [pid 66623:tid 66887] [client 40.85.222.29:25048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBAtO5rbWdOArH04KWSAAAAYM"]
[Tue Aug 18 12:57:54.836547 2026] [security2:error] [pid 66623:tid 66834] [client 68.155.154.236:50369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBAtO5rbWdOArH04KWTgAAAU4"]
[Tue Aug 18 12:57:54.864570 2026] [security2:error] [pid 66623:tid 66851] [client 20.226.6.191:3983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/alfa.php"] [unique_id "aoSBAtO5rbWdOArH04KWTwAAAV8"]
[Tue Aug 18 12:57:54.883004 2026] [security2:error] [pid 66623:tid 66884] [client 20.226.6.191:4069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/lock360.php"] [unique_id "aoSBAtO5rbWdOArH04KWUAAAAYA"]
[Tue Aug 18 12:57:54.901579 2026] [security2:error] [pid 66623:tid 66892] [client 74.248.18.37:54964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/test.php"] [unique_id "aoSBAtO5rbWdOArH04KWUQAAAYg"]
[Tue Aug 18 12:57:54.904093 2026] [security2:error] [pid 66623:tid 66893] [client 20.226.6.191:4041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/flower.php"] [unique_id "aoSBAtO5rbWdOArH04KWUgAAAYk"]
[Tue Aug 18 12:57:54.928120 2026] [security2:error] [pid 66623:tid 66838] [client 20.226.6.191:3980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/13.php"] [unique_id "aoSBAtO5rbWdOArH04KWVAAAAVI"]
[Tue Aug 18 12:57:54.941557 2026] [security2:error] [pid 66623:tid 66833] [client 20.226.6.191:4047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/cc.php"] [unique_id "aoSBAtO5rbWdOArH04KWVgAAAU0"]
[Tue Aug 18 12:57:54.969432 2026] [security2:error] [pid 66623:tid 66773] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/222.php"] [unique_id "aoSBAtO5rbWdOArH04KWVwAAARE"]
[Tue Aug 18 12:57:55.012472 2026] [security2:error] [pid 66623:tid 66807] [client 20.226.6.191:3978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBA9O5rbWdOArH04KWWgAAATM"]
[Tue Aug 18 12:57:55.036518 2026] [security2:error] [pid 66623:tid 66806] [client 20.226.6.191:4073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSBA9O5rbWdOArH04KWWwAAATI"]
[Tue Aug 18 12:57:55.061333 2026] [security2:error] [pid 66623:tid 66830] [client 20.226.6.191:4095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/01.php"] [unique_id "aoSBA9O5rbWdOArH04KWXAAAAUo"]
[Tue Aug 18 12:57:55.080281 2026] [security2:error] [pid 66623:tid 66847] [client 20.226.6.191:4095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/lv.php"] [unique_id "aoSBA9O5rbWdOArH04KWXQAAAVs"]
[Tue Aug 18 12:57:55.103230 2026] [security2:error] [pid 66623:tid 66861] [client 20.119.58.187:12074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/db-cache.php"] [unique_id "aoSBA9O5rbWdOArH04KWXwAAAWk"]
[Tue Aug 18 12:57:55.104465 2026] [security2:error] [pid 66623:tid 66792] [client 40.85.222.29:26942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/well-known/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWYAAAASQ"]
[Tue Aug 18 12:57:55.104620 2026] [security2:error] [pid 66623:tid 66879] [client 20.226.6.191:4042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/new.php"] [unique_id "aoSBA9O5rbWdOArH04KWYQAAAXs"]
[Tue Aug 18 12:57:55.105896 2026] [security2:error] [pid 66623:tid 66853] [client 172.182.200.96:14143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWYgAAAWE"]
[Tue Aug 18 12:57:55.125168 2026] [security2:error] [pid 66623:tid 66811] [client 20.226.6.191:4077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/222.php"] [unique_id "aoSBA9O5rbWdOArH04KWZAAAATc"]
[Tue Aug 18 12:57:55.148470 2026] [security2:error] [pid 66623:tid 66845] [client 20.1.169.243:3697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/majalahpro-core/lib/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWZQAAAVk"]
[Tue Aug 18 12:57:55.157901 2026] [security2:error] [pid 66623:tid 66819] [client 20.186.30.159:1935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/domvf.php"] [unique_id "aoSBA9O5rbWdOArH04KWawAAAT8"]
[Tue Aug 18 12:57:55.159546 2026] [security2:error] [pid 66623:tid 66803] [client 172.182.217.32:15576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSBA9O5rbWdOArH04KWbAAAAS8"]
[Tue Aug 18 12:57:55.175679 2026] [security2:error] [pid 66623:tid 66842] [client 20.226.6.191:4083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/chosen.php"] [unique_id "aoSBA9O5rbWdOArH04KWcQAAAVY"]
[Tue Aug 18 12:57:55.187995 2026] [authz_core:error] [pid 66623:tid 66715] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:55.188266 2026] [authz_core:error] [pid 66623:tid 66715] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:55.190877 2026] [security2:error] [pid 66623:tid 66880] [client 20.226.6.191:4043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/info.php"] [unique_id "aoSBA9O5rbWdOArH04KWdAAAAXw"]
[Tue Aug 18 12:57:55.196954 2026] [security2:error] [pid 66623:tid 66817] [client 20.118.172.148:38955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/av.php"] [unique_id "aoSBA9O5rbWdOArH04KWdgAAAT0"]
[Tue Aug 18 12:57:55.211002 2026] [security2:error] [pid 66623:tid 66820] [client 68.155.155.199:10431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/flower.php"] [unique_id "aoSBA9O5rbWdOArH04KWdwAAAUA"]
[Tue Aug 18 12:57:55.211016 2026] [security2:error] [pid 66623:tid 66874] [client 20.100.185.105:56387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-logs.php"] [unique_id "aoSBA9O5rbWdOArH04KWeAAAAXY"]
[Tue Aug 18 12:57:55.246884 2026] [security2:error] [pid 66623:tid 66775] [client 20.226.6.191:3987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWhAAAARM"]
[Tue Aug 18 12:57:55.277759 2026] [security2:error] [pid 66623:tid 66783] [client 20.226.6.191:3969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWhgAAARs"]
[Tue Aug 18 12:57:55.286441 2026] [security2:error] [pid 66623:tid 66887] [client 172.182.200.96:14125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSBA9O5rbWdOArH04KWiAAAAYM"]
[Tue Aug 18 12:57:55.292989 2026] [security2:error] [pid 66623:tid 66839] [client 4.232.151.198:4334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWiQAAAVM"]
[Tue Aug 18 12:57:55.304590 2026] [security2:error] [pid 66623:tid 66858] [client 68.155.154.236:7912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWigAAAWY"]
[Tue Aug 18 12:57:55.310842 2026] [security2:error] [pid 66623:tid 66860] [client 20.226.6.191:4067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/k.php"] [unique_id "aoSBA9O5rbWdOArH04KWiwAAAWg"]
[Tue Aug 18 12:57:55.321487 2026] [security2:error] [pid 66623:tid 66784] [client 74.248.18.37:55804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSBA9O5rbWdOArH04KWjAAAARw"]
[Tue Aug 18 12:57:55.327390 2026] [security2:error] [pid 66623:tid 66883] [client 20.203.138.185:10612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/gjm.php"] [unique_id "aoSBA9O5rbWdOArH04KWjQAAAX8"]
[Tue Aug 18 12:57:55.369448 2026] [security2:error] [pid 66623:tid 66893] [client 20.118.133.132:15373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/coffexium.php"] [unique_id "aoSBA9O5rbWdOArH04KWkgAAAYk"]
[Tue Aug 18 12:57:55.375396 2026] [security2:error] [pid 66623:tid 66843] [client 20.226.6.191:4087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/403.php"] [unique_id "aoSBA9O5rbWdOArH04KWkwAAAVc"]
[Tue Aug 18 12:57:55.386440 2026] [security2:error] [pid 66623:tid 66837] [client 79.127.164.8:57896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/phpbb_db_backup_data.sql"] [unique_id "aoSBA9O5rbWdOArH04KWlQAAAVE"], referer: https://medihub.com.br/phpbb_db_backup_data.sql
[Tue Aug 18 12:57:55.450889 2026] [security2:error] [pid 66623:tid 66890] [client 213.35.127.232:60263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWmgAAAYY"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:55.458735 2026] [security2:error] [pid 66623:tid 66776] [client 20.119.58.187:12082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "aoSBA9O5rbWdOArH04KWnAAAARQ"]
[Tue Aug 18 12:57:55.463887 2026] [security2:error] [pid 66623:tid 66773] [client 40.74.65.169:7379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/file1221.php"] [unique_id "aoSBA9O5rbWdOArH04KWnQAAARE"]
[Tue Aug 18 12:57:55.474522 2026] [security2:error] [pid 66623:tid 66771] [client 74.248.18.37:21557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/goods.php"] [unique_id "aoSBA9O5rbWdOArH04KWogAAAQ8"]
[Tue Aug 18 12:57:55.488378 2026] [security2:error] [pid 66623:tid 66829] [client 20.226.6.191:4086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/gecko.php"] [unique_id "aoSBA9O5rbWdOArH04KWqQAAAUk"]
[Tue Aug 18 12:57:55.492922 2026] [authz_core:error] [pid 66623:tid 66649] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:55.493334 2026] [authz_core:error] [pid 66623:tid 66649] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:55.499823 2026] [security2:error] [pid 66623:tid 66866] [client 40.85.222.29:44747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBA9O5rbWdOArH04KWqgAAAW4"]
[Tue Aug 18 12:57:55.515586 2026] [security2:error] [pid 66623:tid 66877] [client 20.1.169.243:3416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/pwnd/as.php"] [unique_id "aoSBA9O5rbWdOArH04KWrQAAAXk"]
[Tue Aug 18 12:57:55.530093 2026] [security2:error] [pid 66623:tid 66830] [client 20.226.6.191:4086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/aa.php"] [unique_id "aoSBA9O5rbWdOArH04KWrgAAAUo"]
[Tue Aug 18 12:57:55.551065 2026] [security2:error] [pid 66623:tid 66789] [client 74.248.18.37:31850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/test1.php"] [unique_id "aoSBA9O5rbWdOArH04KWrwAAASE"]
[Tue Aug 18 12:57:55.594194 2026] [security2:error] [pid 66623:tid 66808] [client 20.226.6.191:3972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/0x.php"] [unique_id "aoSBA9O5rbWdOArH04KWsQAAATQ"]
[Tue Aug 18 12:57:55.597528 2026] [security2:error] [pid 66623:tid 66861] [client 20.118.172.148:62413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/ff1.php"] [unique_id "aoSBA9O5rbWdOArH04KWsgAAAWk"]
[Tue Aug 18 12:57:55.632549 2026] [security2:error] [pid 66623:tid 66840] [client 20.226.6.191:3981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/zxz.php"] [unique_id "aoSBA9O5rbWdOArH04KWtAAAAVQ"]
[Tue Aug 18 12:57:55.647266 2026] [security2:error] [pid 66623:tid 66786] [client 20.226.6.191:4032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/www.php"] [unique_id "aoSBA9O5rbWdOArH04KWtQAAAR4"]
[Tue Aug 18 12:57:55.648769 2026] [security2:error] [pid 66623:tid 66812] [client 172.182.217.32:15575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/asus.php"] [unique_id "aoSBA9O5rbWdOArH04KWtgAAATg"]
[Tue Aug 18 12:57:55.656423 2026] [security2:error] [pid 66623:tid 66855] [client 20.206.73.37:59954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/puc.php"] [unique_id "aoSBA9O5rbWdOArH04KWuQAAAWM"]
[Tue Aug 18 12:57:55.670630 2026] [security2:error] [pid 66623:tid 66760] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.info.php"] [unique_id "aoSBA9O5rbWdOArH04KWugABWXs"]
[Tue Aug 18 12:57:55.725836 2026] [security2:error] [pid 66623:tid 66797] [client 20.226.6.191:4059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wicked.php"] [unique_id "aoSBA9O5rbWdOArH04KWvwAAASk"]
[Tue Aug 18 12:57:55.770356 2026] [security2:error] [pid 66623:tid 66870] [client 20.226.6.191:4033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSBA9O5rbWdOArH04KWwwAAAXI"]
[Tue Aug 18 12:57:55.779925 2026] [security2:error] [pid 66623:tid 66848] [client 40.85.222.29:44749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWxAAAAVw"]
[Tue Aug 18 12:57:55.790714 2026] [security2:error] [pid 66623:tid 66774] [client 20.226.6.191:4015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWxgAAARI"]
[Tue Aug 18 12:57:55.794407 2026] [authz_core:error] [pid 66623:tid 66717] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:55.794843 2026] [authz_core:error] [pid 66623:tid 66717] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:55.795447 2026] [autoindex:error] [pid 66623:tid 66828] [client 158.158.74.177:26157] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:55.813839 2026] [security2:error] [pid 66623:tid 66841] [client 20.119.58.187:12063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "aoSBA9O5rbWdOArH04KWyAAAAVU"]
[Tue Aug 18 12:57:55.843494 2026] [security2:error] [pid 66623:tid 66802] [client 20.226.6.191:3986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/cah.php"] [unique_id "aoSBA9O5rbWdOArH04KWywAAAS4"]
[Tue Aug 18 12:57:55.849873 2026] [security2:error] [pid 66623:tid 66720] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/about.php"] [unique_id "aoSBA9O5rbWdOArH04KWzQABG1M"]
[Tue Aug 18 12:57:55.883034 2026] [security2:error] [pid 66623:tid 66874] [client 20.1.169.243:1055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/rk2.php"] [unique_id "aoSBA9O5rbWdOArH04KW0AAAAXY"]
[Tue Aug 18 12:57:55.953954 2026] [security2:error] [pid 66623:tid 66859] [client 74.248.18.37:55769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSBA9O5rbWdOArH04KW1QAAAWc"]
[Tue Aug 18 12:57:55.962047 2026] [autoindex:error] [pid 66623:tid 66817] [client 4.232.151.198:24957] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:55.971024 2026] [security2:error] [pid 66623:tid 66834] [client 172.182.200.96:14110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBA9O5rbWdOArH04KW1gAAAU4"]
[Tue Aug 18 12:57:56.002447 2026] [security2:error] [pid 66623:tid 66825] [client 168.119.96.239:12218] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pan.com.br"] [uri "/server.php"] [unique_id "aoSBA9O5rbWdOArH04KWswAAAUU"], referer: https://pan.com.br/?lang=pt-br
[Tue Aug 18 12:57:56.010119 2026] [security2:error] [pid 66623:tid 66785] [client 158.158.74.177:26157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/js/about.php"] [unique_id "aoSBBNO5rbWdOArH04KW2AAAAR0"]
[Tue Aug 18 12:57:56.031342 2026] [security2:error] [pid 66623:tid 66864] [client 20.226.6.191:4079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/system_log.php"] [unique_id "aoSBBNO5rbWdOArH04KW3QAAAWw"]
[Tue Aug 18 12:57:56.032819 2026] [security2:error] [pid 66623:tid 66892] [client 20.186.30.159:1699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/fpwch.php"] [unique_id "aoSBBNO5rbWdOArH04KW3gAAAYg"]
[Tue Aug 18 12:57:56.039348 2026] [autoindex:error] [pid 66623:tid 66708] [remote 68.155.154.146:0] AH01276: Cannot serve directory /home4/bioclimaarcondic/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:56.041699 2026] [security2:error] [pid 66623:tid 66867] [client 68.155.154.236:48920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSBBNO5rbWdOArH04KW3wAAAW8"]
[Tue Aug 18 12:57:56.053758 2026] [security2:error] [pid 66623:tid 66794] [client 20.100.185.105:42685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSBBNO5rbWdOArH04KW4AAAASY"]
[Tue Aug 18 12:57:56.063854 2026] [security2:error] [pid 66623:tid 66862] [client 20.118.172.148:50082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp.php"] [unique_id "aoSBBNO5rbWdOArH04KW4QAAAWo"]
[Tue Aug 18 12:57:56.071511 2026] [security2:error] [pid 66623:tid 66846] [client 40.85.222.29:26899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBBNO5rbWdOArH04KW4wAAAVo"]
[Tue Aug 18 12:57:56.075643 2026] [security2:error] [pid 66623:tid 66776] [client 172.182.200.96:7639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSBBNO5rbWdOArH04KW5AAAARQ"]
[Tue Aug 18 12:57:56.136744 2026] [security2:error] [pid 66623:tid 66791] [client 74.248.18.37:21527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/gulu.php"] [unique_id "aoSBBNO5rbWdOArH04KW5wAAASM"]
[Tue Aug 18 12:57:56.136974 2026] [security2:error] [pid 66623:tid 66883] [client 172.182.217.32:15753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/about.php"] [unique_id "aoSBBNO5rbWdOArH04KW6AAAAX8"]
[Tue Aug 18 12:57:56.167416 2026] [security2:error] [pid 66623:tid 66873] [client 20.119.58.187:12511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "aoSBBNO5rbWdOArH04KW6wAAAXU"]
[Tue Aug 18 12:57:56.182804 2026] [autoindex:error] [pid 66623:tid 66854] [client 4.232.151.198:24957] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-content/uploads/2025/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:56.197590 2026] [security2:error] [pid 66623:tid 66807] [client 20.203.183.135:13059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/scxy.php"] [unique_id "aoSBBNO5rbWdOArH04KW7gAAATM"]
[Tue Aug 18 12:57:56.220667 2026] [security2:error] [pid 66623:tid 66851] [client 74.248.18.37:26513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/thoms.php"] [unique_id "aoSBBNO5rbWdOArH04KW8QAAAV8"]
[Tue Aug 18 12:57:56.229164 2026] [security2:error] [pid 66623:tid 66711] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "aoSBBNO5rbWdOArH04KW8gABhEo"]
[Tue Aug 18 12:57:56.237856 2026] [security2:error] [pid 66623:tid 66847] [client 40.74.65.169:44755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/inx.php"] [unique_id "aoSBBNO5rbWdOArH04KW9AAAAVs"]
[Tue Aug 18 12:57:56.239493 2026] [security2:error] [pid 66623:tid 66777] [client 52.173.121.69:25013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSBBNO5rbWdOArH04KW9gAAARU"]
[Tue Aug 18 12:57:56.251462 2026] [security2:error] [pid 66623:tid 66772] [client 20.1.169.243:3425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/storage/rip.php"] [unique_id "aoSBBNO5rbWdOArH04KW-gAAARA"]
[Tue Aug 18 12:57:56.256755 2026] [security2:error] [pid 66623:tid 66792] [client 20.65.98.162:44188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/bengi.php"] [unique_id "aoSBBNO5rbWdOArH04KW-wAAASQ"]
[Tue Aug 18 12:57:56.256785 2026] [security2:error] [pid 66623:tid 66840] [client 20.226.6.191:4016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSBBNO5rbWdOArH04KW_QAAAVQ"]
[Tue Aug 18 12:57:56.355250 2026] [security2:error] [pid 66623:tid 66797] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/key.php"] [unique_id "aoSBBNO5rbWdOArH04KXEgAAASk"]
[Tue Aug 18 12:57:56.357637 2026] [security2:error] [pid 66623:tid 66884] [client 20.226.6.191:4074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBBNO5rbWdOArH04KXEwAAAYA"]
[Tue Aug 18 12:57:56.365681 2026] [security2:error] [pid 66623:tid 66820] [client 68.155.155.199:2138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/motu.php"] [unique_id "aoSBBNO5rbWdOArH04KXFQAAAUA"]
[Tue Aug 18 12:57:56.387973 2026] [security2:error] [pid 66623:tid 66774] [client 4.232.151.198:24957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSBBNO5rbWdOArH04KXGAAAARI"]
[Tue Aug 18 12:57:56.393559 2026] [security2:error] [pid 66623:tid 66828] [client 20.203.138.185:35008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/new4.php"] [unique_id "aoSBBNO5rbWdOArH04KXGQAAAUg"]
[Tue Aug 18 12:57:56.393984 2026] [authz_core:error] [pid 66623:tid 66647] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:56.394237 2026] [authz_core:error] [pid 66623:tid 66647] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:56.421233 2026] [security2:error] [pid 66623:tid 66835] [client 20.118.172.148:53119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/file2.php"] [unique_id "aoSBBNO5rbWdOArH04KXGgAAAU8"]
[Tue Aug 18 12:57:56.424219 2026] [security2:error] [pid 66623:tid 66841] [client 20.118.172.148:62445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/fff.php"] [unique_id "aoSBBNO5rbWdOArH04KXGwAAAVU"]
[Tue Aug 18 12:57:56.440220 2026] [security2:error] [pid 66623:tid 66823] [client 40.85.222.29:44776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/mt/byp.php"] [unique_id "aoSBBNO5rbWdOArH04KXHQAAAUM"]
[Tue Aug 18 12:57:56.464073 2026] [security2:error] [pid 66623:tid 66871] [client 213.35.127.232:60491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBBNO5rbWdOArH04KXHgAAAXM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:56.521771 2026] [security2:error] [pid 66623:tid 66856] [client 20.119.58.187:12517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "aoSBBNO5rbWdOArH04KXJgAAAWQ"]
[Tue Aug 18 12:57:56.534646 2026] [security2:error] [pid 66623:tid 66778] [client 20.226.6.191:4036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/abc.php"] [unique_id "aoSBBNO5rbWdOArH04KXJwAAARY"]
[Tue Aug 18 12:57:56.546385 2026] [security2:error] [pid 66623:tid 66825] [client 172.182.200.96:14132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSBBNO5rbWdOArH04KXKAAAAUU"]
[Tue Aug 18 12:57:56.558301 2026] [security2:error] [pid 66623:tid 66865] [client 20.186.30.159:1922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/adminner.php"] [unique_id "aoSBBNO5rbWdOArH04KXKgAAAW0"]
[Tue Aug 18 12:57:56.580677 2026] [security2:error] [pid 66623:tid 66805] [client 20.100.169.31:15279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/simple.php"] [unique_id "aoSBBNO5rbWdOArH04KXLAAAATE"]
[Tue Aug 18 12:57:56.593161 2026] [security2:error] [pid 66623:tid 66837] [client 172.182.200.96:7555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBBNO5rbWdOArH04KXLQAAAVE"]
[Tue Aug 18 12:57:56.618667 2026] [security2:error] [pid 66623:tid 66821] [client 20.1.169.243:3410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/tool.php"] [unique_id "aoSBBNO5rbWdOArH04KXLgAAAUE"]
[Tue Aug 18 12:57:56.651282 2026] [security2:error] [pid 66623:tid 66783] [client 172.182.217.32:15749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/atomlib.php"] [unique_id "aoSBBNO5rbWdOArH04KXMAAAARs"]
[Tue Aug 18 12:57:56.686005 2026] [security2:error] [pid 66623:tid 66854] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/chosen.php"] [unique_id "aoSBBNO5rbWdOArH04KXMgAAAWI"]
[Tue Aug 18 12:57:56.687339 2026] [security2:error] [pid 66623:tid 66879] [client 20.100.185.105:42675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBBNO5rbWdOArH04KXMwAAAXs"]
[Tue Aug 18 12:57:56.697384 2026] [authz_core:error] [pid 66623:tid 66732] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:56.697804 2026] [authz_core:error] [pid 66623:tid 66732] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:56.710089 2026] [security2:error] [pid 66623:tid 66679] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "aoSBBNO5rbWdOArH04KXOgABbCo"]
[Tue Aug 18 12:57:56.776511 2026] [security2:error] [pid 66623:tid 66809] [client 20.48.236.86:37064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/biufile.php"] [unique_id "aoSBBNO5rbWdOArH04KXQQAAATU"]
[Tue Aug 18 12:57:56.778516 2026] [security2:error] [pid 66623:tid 66847] [client 68.155.154.236:46609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBBNO5rbWdOArH04KXQgAAAVs"]
[Tue Aug 18 12:57:56.785830 2026] [security2:error] [pid 66623:tid 66796] [client 74.248.18.37:54929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/h.php"] [unique_id "aoSBBNO5rbWdOArH04KXQwAAASg"]
[Tue Aug 18 12:57:56.788749 2026] [security2:error] [pid 66623:tid 66861] [client 40.85.222.29:44233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSBBNO5rbWdOArH04KXRAAAAWk"]
[Tue Aug 18 12:57:56.849563 2026] [security2:error] [pid 66623:tid 66842] [client 20.226.6.191:3982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/akcc.php"] [unique_id "aoSBBNO5rbWdOArH04KXSQAAAVY"]
[Tue Aug 18 12:57:56.866202 2026] [security2:error] [pid 66623:tid 66820] [client 20.118.172.148:33494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/images/class-config.php"] [unique_id "aoSBBNO5rbWdOArH04KXSwAAAUA"]
[Tue Aug 18 12:57:56.876200 2026] [security2:error] [pid 66623:tid 66824] [client 20.119.58.187:12503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "aoSBBNO5rbWdOArH04KXTAAAAUQ"]
[Tue Aug 18 12:57:56.886516 2026] [security2:error] [pid 66623:tid 66848] [client 52.173.121.69:25008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSBBNO5rbWdOArH04KXTwAAAVw"]
[Tue Aug 18 12:57:56.907491 2026] [security2:error] [pid 66623:tid 66773] [client 157.51.166.53:50880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBBNO5rbWdOArH04KXUwAAARE"]
[Tue Aug 18 12:57:56.907607 2026] [security2:error] [pid 66623:tid 66773] [client 157.51.166.53:50880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBBNO5rbWdOArH04KXUwAAARE"]
[Tue Aug 18 12:57:56.919453 2026] [security2:error] [pid 66623:tid 66807] [client 74.248.18.37:20484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/tool.php"] [unique_id "aoSBBNO5rbWdOArH04KXVQAAATM"]
[Tue Aug 18 12:57:56.943409 2026] [security2:error] [pid 66623:tid 66768] [client 20.226.6.191:3928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wk/index.php"] [unique_id "aoSBBNO5rbWdOArH04KXWgAAAQw"]
[Tue Aug 18 12:57:56.973181 2026] [security2:error] [pid 66623:tid 66834] [client 74.248.18.37:55795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-themes.php"] [unique_id "aoSBBNO5rbWdOArH04KXXgAAAU4"]
[Tue Aug 18 12:57:56.985360 2026] [security2:error] [pid 66623:tid 66880] [client 20.1.169.243:1044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/twentytwenty/functions.php"] [unique_id "aoSBBNO5rbWdOArH04KXYAAAAXw"]
[Tue Aug 18 12:57:57.000403 2026] [security2:error] [pid 66623:tid 66772] [client 158.158.74.177:2641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBBNO5rbWdOArH04KXYwAAARA"]
[Tue Aug 18 12:57:57.004603 2026] [security2:error] [pid 66623:tid 66886] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/wpxml.php"] [unique_id "aoSBBdO5rbWdOArH04KXZQAAAYI"]
[Tue Aug 18 12:57:57.008358 2026] [authz_core:error] [pid 66623:tid 66707] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:57.008797 2026] [authz_core:error] [pid 66623:tid 66707] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:57.049202 2026] [security2:error] [pid 66623:tid 66876] [client 4.232.151.198:4294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSBBdO5rbWdOArH04KXcQAAAXg"]
[Tue Aug 18 12:57:57.068578 2026] [security2:error] [pid 66623:tid 66794] [client 20.186.30.159:1922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/abcd.php"] [unique_id "aoSBBdO5rbWdOArH04KXcwAAASY"]
[Tue Aug 18 12:57:57.081520 2026] [security2:error] [pid 66623:tid 66789] [client 40.74.65.169:35750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/reviall.php"] [unique_id "aoSBBdO5rbWdOArH04KXdAAAASE"]
[Tue Aug 18 12:57:57.088269 2026] [security2:error] [pid 66623:tid 66795] [client 158.158.34.183:32477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/system.php"] [unique_id "aoSBBdO5rbWdOArH04KXeAAAASc"]
[Tue Aug 18 12:57:57.092591 2026] [security2:error] [pid 66623:tid 66791] [client 40.85.222.29:26928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBBdO5rbWdOArH04KXeQAAASM"]
[Tue Aug 18 12:57:57.144780 2026] [security2:error] [pid 66623:tid 66856] [client 172.182.217.32:15757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSBBdO5rbWdOArH04KXfAAAAWQ"]
[Tue Aug 18 12:57:57.177091 2026] [security2:error] [pid 66623:tid 66692] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/acme-challenge/makeasmtp.php"] [unique_id "aoSBBdO5rbWdOArH04KXfwABHTc"]
[Tue Aug 18 12:57:57.232425 2026] [security2:error] [pid 66623:tid 66847] [client 20.118.172.148:50068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/alfa.php"] [unique_id "aoSBBdO5rbWdOArH04KXgQAAAVs"]
[Tue Aug 18 12:57:57.238853 2026] [security2:error] [pid 66623:tid 66822] [client 20.226.6.191:3921] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "riovacinas.com.br"] [uri "/1.php"] [unique_id "aoSBBdO5rbWdOArH04KXggAAAUI"]
[Tue Aug 18 12:57:57.238979 2026] [security2:error] [pid 66623:tid 66822] [client 20.226.6.191:3921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/1.php"] [unique_id "aoSBBdO5rbWdOArH04KXggAAAUI"]
[Tue Aug 18 12:57:57.251582 2026] [security2:error] [pid 66623:tid 66819] [client 20.119.58.187:12504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "aoSBBdO5rbWdOArH04KXhAAAAT8"]
[Tue Aug 18 12:57:57.284992 2026] [security2:error] [pid 66623:tid 66810] [client 20.206.73.37:20725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/19.php"] [unique_id "aoSBBdO5rbWdOArH04KXhQAAATY"]
[Tue Aug 18 12:57:57.285609 2026] [security2:error] [pid 66623:tid 66769] [client 68.155.154.236:40276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSBBdO5rbWdOArH04KXhgAAAQ0"]
[Tue Aug 18 12:57:57.298571 2026] [security2:error] [pid 66623:tid 66790] [client 196.12.128.158:56207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBBdO5rbWdOArH04KXiAAAASI"]
[Tue Aug 18 12:57:57.298749 2026] [security2:error] [pid 66623:tid 66790] [client 196.12.128.158:56207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBBdO5rbWdOArH04KXiAAAASI"]
[Tue Aug 18 12:57:57.311636 2026] [security2:error] [pid 66623:tid 66873] [client 20.100.185.105:29824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBBdO5rbWdOArH04KXiwAAAXU"]
[Tue Aug 18 12:57:57.326069 2026] [security2:error] [pid 66623:tid 66803] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/file1221.php"] [unique_id "aoSBBdO5rbWdOArH04KXjAAAAS8"]
[Tue Aug 18 12:57:57.353247 2026] [security2:error] [pid 66623:tid 66809] [client 20.1.169.243:1031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/wp-admin.php"] [unique_id "aoSBBdO5rbWdOArH04KXlwAAATU"]
[Tue Aug 18 12:57:57.371669 2026] [security2:error] [pid 66623:tid 66816] [client 40.85.222.29:44786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBBdO5rbWdOArH04KXmQAAATw"]
[Tue Aug 18 12:57:57.372396 2026] [security2:error] [pid 66623:tid 66660] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/admin.php"] [unique_id "aoSBBdO5rbWdOArH04KXmgABKRc"]
[Tue Aug 18 12:57:57.401941 2026] [security2:error] [pid 66623:tid 66820] [client 68.155.155.199:9345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/404.php"] [unique_id "aoSBBdO5rbWdOArH04KXnQAAAUA"]
[Tue Aug 18 12:57:57.423498 2026] [security2:error] [pid 66623:tid 66877] [client 74.248.18.37:35335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/hello.php"] [unique_id "aoSBBdO5rbWdOArH04KXoQAAAXk"]
[Tue Aug 18 12:57:57.431675 2026] [security2:error] [pid 66623:tid 66775] [client 20.118.172.148:62117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/inputs.php"] [unique_id "aoSBBdO5rbWdOArH04KXowAAARM"]
[Tue Aug 18 12:57:57.452989 2026] [security2:error] [pid 66623:tid 66868] [client 172.182.200.96:14149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSBBdO5rbWdOArH04KXpAAAAXA"]
[Tue Aug 18 12:57:57.469641 2026] [security2:error] [pid 66623:tid 66823] [client 20.186.30.159:1678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/simple.php"] [unique_id "aoSBBdO5rbWdOArH04KXpQAAAUM"]
[Tue Aug 18 12:57:57.476369 2026] [security2:error] [pid 66623:tid 66773] [client 52.173.121.69:24976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSBBdO5rbWdOArH04KXpgAAARE"]
[Tue Aug 18 12:57:57.476861 2026] [security2:error] [pid 66623:tid 66864] [client 213.35.127.232:60706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBBdO5rbWdOArH04KXpwAAAWw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:57.554331 2026] [security2:error] [pid 66623:tid 66723] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/core.php"] [unique_id "aoSBBdO5rbWdOArH04KXwgABfVY"]
[Tue Aug 18 12:57:57.568042 2026] [security2:error] [pid 66623:tid 66866] [client 74.248.18.37:21519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/tools.php"] [unique_id "aoSBBdO5rbWdOArH04KXxAAAAW4"]
[Tue Aug 18 12:57:57.604996 2026] [authz_core:error] [pid 66623:tid 66677] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:57.605249 2026] [authz_core:error] [pid 66623:tid 66677] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:57.615584 2026] [security2:error] [pid 66623:tid 66884] [client 74.248.18.37:3322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/xmlrpc.php"] [unique_id "aoSBBdO5rbWdOArH04KXzQAAAYA"]
[Tue Aug 18 12:57:57.622896 2026] [security2:error] [pid 66623:tid 66871] [client 20.119.58.187:12538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "aoSBBdO5rbWdOArH04KXzwAAAXM"]
[Tue Aug 18 12:57:57.632195 2026] [security2:error] [pid 66623:tid 66800] [client 172.182.217.32:15777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/b.php"] [unique_id "aoSBBdO5rbWdOArH04KX0AAAASw"]
[Tue Aug 18 12:57:57.672356 2026] [security2:error] [pid 66623:tid 66893] [client 20.118.172.148:2691] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/1.php"] [unique_id "aoSBBdO5rbWdOArH04KX1gAAAYk"]
[Tue Aug 18 12:57:57.672453 2026] [security2:error] [pid 66623:tid 66893] [client 20.118.172.148:2691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/1.php"] [unique_id "aoSBBdO5rbWdOArH04KX1gAAAYk"]
[Tue Aug 18 12:57:57.676056 2026] [security2:error] [pid 66623:tid 66837] [client 158.23.17.4:34150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBBdO5rbWdOArH04KX1wAAAVE"]
[Tue Aug 18 12:57:57.678685 2026] [security2:error] [pid 66623:tid 66876] [client 20.203.138.185:50269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-act.php"] [unique_id "aoSBBdO5rbWdOArH04KX2AAAAXg"]
[Tue Aug 18 12:57:57.679397 2026] [autoindex:error] [pid 66623:tid 66841] [client 4.232.151.198:51268] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:57.717688 2026] [security2:error] [pid 66623:tid 66882] [client 20.1.169.243:3394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSBBdO5rbWdOArH04KX2gAAAX4"]
[Tue Aug 18 12:57:57.734485 2026] [security2:error] [pid 66623:tid 66794] [client 20.226.6.191:4068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSBBdO5rbWdOArH04KX2wAAASY"]
[Tue Aug 18 12:57:57.740608 2026] [security2:error] [pid 66623:tid 66835] [client 172.182.200.96:7675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/well-known/index.php"] [unique_id "aoSBBdO5rbWdOArH04KX3AAAAU8"]
[Tue Aug 18 12:57:57.750346 2026] [security2:error] [pid 66623:tid 66735] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/db-status.php"] [unique_id "aoSBBdO5rbWdOArH04KX3QABQWI"]
[Tue Aug 18 12:57:57.771827 2026] [security2:error] [pid 66623:tid 66890] [client 40.85.222.29:26938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBBdO5rbWdOArH04KX4gAAAYY"]
[Tue Aug 18 12:57:57.795604 2026] [security2:error] [pid 66623:tid 66854] [client 20.118.133.132:15178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/dex.php"] [unique_id "aoSBBdO5rbWdOArH04KX5QAAAWI"]
[Tue Aug 18 12:57:57.801059 2026] [security2:error] [pid 66623:tid 66850] [client 40.74.65.169:43154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/11.php"] [unique_id "aoSBBdO5rbWdOArH04KX5gAAAV4"]
[Tue Aug 18 12:57:57.909386 2026] [autoindex:error] [pid 66623:tid 66819] [client 4.232.151.198:51268] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:57.910717 2026] [authz_core:error] [pid 66623:tid 66755] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:57.911151 2026] [authz_core:error] [pid 66623:tid 66755] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:57.911877 2026] [security2:error] [pid 66623:tid 66853] [client 68.155.154.236:8027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSBBdO5rbWdOArH04KX7wAAAWE"]
[Tue Aug 18 12:57:57.932122 2026] [security2:error] [pid 66623:tid 66838] [client 20.100.185.105:40069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-includes/fonts/admin.php"] [unique_id "aoSBBdO5rbWdOArH04KX8gAAAVI"]
[Tue Aug 18 12:57:57.968334 2026] [security2:error] [pid 66623:tid 66661] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSBBdO5rbWdOArH04KX9gABdRg"]
[Tue Aug 18 12:57:57.971106 2026] [security2:error] [pid 66623:tid 66804] [client 20.118.172.148:54877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBBdO5rbWdOArH04KX9wAAATA"]
[Tue Aug 18 12:57:57.982351 2026] [security2:error] [pid 66623:tid 66822] [client 20.119.58.187:12482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "aoSBBdO5rbWdOArH04KX-AAAAUI"]
[Tue Aug 18 12:57:58.012864 2026] [security2:error] [pid 66623:tid 66774] [client 197.184.64.235:41939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBBtO5rbWdOArH04KX-QAAARI"]
[Tue Aug 18 12:57:58.012971 2026] [security2:error] [pid 66623:tid 66774] [client 197.184.64.235:41939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBBtO5rbWdOArH04KX-QAAARI"]
[Tue Aug 18 12:57:58.017199 2026] [security2:error] [pid 66623:tid 66783] [client 20.100.169.31:29052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/edit-tags.php"] [unique_id "aoSBBtO5rbWdOArH04KX-gAAARs"]
[Tue Aug 18 12:57:58.018322 2026] [security2:error] [pid 66623:tid 66803] [client 52.173.121.69:17947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSBBtO5rbWdOArH04KX-wAAAS8"]
[Tue Aug 18 12:57:58.054534 2026] [security2:error] [pid 66623:tid 66808] [client 20.48.236.86:36124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/coffexium.php"] [unique_id "aoSBBtO5rbWdOArH04KX_QAAATQ"]
[Tue Aug 18 12:57:58.061274 2026] [security2:error] [pid 66623:tid 66809] [client 20.226.6.191:4081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBBtO5rbWdOArH04KX_gAAATU"]
[Tue Aug 18 12:57:58.103972 2026] [security2:error] [pid 66623:tid 66812] [client 74.248.18.37:21505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/images/index.php"] [unique_id "aoSBBtO5rbWdOArH04KYAwAAATg"]
[Tue Aug 18 12:57:58.104606 2026] [authz_core:error] [pid 66623:tid 66686] [remote 57.141.22.23:40622] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:58.104874 2026] [authz_core:error] [pid 66623:tid 66686] [remote 57.141.22.23:40622] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:58.113090 2026] [security2:error] [pid 66623:tid 66801] [client 40.85.222.29:26931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBBtO5rbWdOArH04KYBAAAAS0"]
[Tue Aug 18 12:57:58.114351 2026] [security2:error] [pid 66623:tid 66848] [client 4.232.151.198:51268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBBtO5rbWdOArH04KYDwAAAVw"]
[Tue Aug 18 12:57:58.121207 2026] [security2:error] [pid 66623:tid 66781] [client 172.182.217.32:15772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/buy.php"] [unique_id "aoSBBtO5rbWdOArH04KYFgAAARk"]
[Tue Aug 18 12:57:58.133379 2026] [security2:error] [pid 66623:tid 66793] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/nox.php"] [unique_id "aoSBBtO5rbWdOArH04KYGgAAASU"]
[Tue Aug 18 12:57:58.148236 2026] [security2:error] [pid 66623:tid 66700] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/index.php"] [unique_id "aoSBBtO5rbWdOArH04KYGwABET8"]
[Tue Aug 18 12:57:58.152832 2026] [security2:error] [pid 66623:tid 66864] [client 20.186.30.159:1692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/wp-manager.php"] [unique_id "aoSBBtO5rbWdOArH04KYHAAAAWw"]
[Tue Aug 18 12:57:58.186472 2026] [security2:error] [pid 66623:tid 66814] [client 20.203.183.135:42445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSBBtO5rbWdOArH04KYHgAAATo"]
[Tue Aug 18 12:57:58.213228 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:58.213680 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:58.278877 2026] [security2:error] [pid 66623:tid 66825] [client 20.118.172.148:63052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/222.php"] [unique_id "aoSBBtO5rbWdOArH04KYKgAAAUU"]
[Tue Aug 18 12:57:58.332157 2026] [security2:error] [pid 66623:tid 66841] [client 20.226.6.191:4025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/as.php"] [unique_id "aoSBBtO5rbWdOArH04KYLgAAAVU"]
[Tue Aug 18 12:57:58.336632 2026] [security2:error] [pid 66623:tid 66829] [client 74.248.18.37:21561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/txets.php"] [unique_id "aoSBBtO5rbWdOArH04KYLwAAAUk"]
[Tue Aug 18 12:57:58.350692 2026] [security2:error] [pid 66623:tid 66859] [client 20.119.58.187:12496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "aoSBBtO5rbWdOArH04KYMQAAAWc"]
[Tue Aug 18 12:57:58.355539 2026] [security2:error] [pid 66623:tid 66691] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSBBtO5rbWdOArH04KYMgABhjY"]
[Tue Aug 18 12:57:58.436153 2026] [security2:error] [pid 66623:tid 66817] [client 40.85.222.29:44256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBBtO5rbWdOArH04KYNwAAAT0"]
[Tue Aug 18 12:57:58.455704 2026] [security2:error] [pid 66623:tid 66843] [client 20.203.138.185:54976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/grsiuk.php"] [unique_id "aoSBBtO5rbWdOArH04KYOgAAAVc"]
[Tue Aug 18 12:57:58.468777 2026] [security2:error] [pid 66623:tid 66875] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/akismet.php"] [unique_id "aoSBBtO5rbWdOArH04KYPwAAAXc"]
[Tue Aug 18 12:57:58.490377 2026] [security2:error] [pid 66623:tid 66839] [client 213.35.127.232:60915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBBtO5rbWdOArH04KYRwAAAVM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:58.528739 2026] [security2:error] [pid 66623:tid 66769] [client 20.186.30.159:1696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/xiugai.php"] [unique_id "aoSBBtO5rbWdOArH04KYSQAAAQ0"]
[Tue Aug 18 12:57:58.539245 2026] [security2:error] [pid 66623:tid 66804] [client 172.182.200.96:14135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSBBtO5rbWdOArH04KYSgAAATA"]
[Tue Aug 18 12:57:58.547802 2026] [security2:error] [pid 66623:tid 66658] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/logs233/x.php"] [unique_id "aoSBBtO5rbWdOArH04KYSwABEhU"]
[Tue Aug 18 12:57:58.554213 2026] [security2:error] [pid 66623:tid 66805] [client 20.100.185.105:62863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/av.php"] [unique_id "aoSBBtO5rbWdOArH04KYTQAAATE"]
[Tue Aug 18 12:57:58.554928 2026] [security2:error] [pid 66623:tid 66803] [client 20.226.6.191:4037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBBtO5rbWdOArH04KYTgAAAS8"]
[Tue Aug 18 12:57:58.575016 2026] [security2:error] [pid 66623:tid 66808] [client 40.74.65.169:43197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/File.php"] [unique_id "aoSBBtO5rbWdOArH04KYUAAAATQ"]
[Tue Aug 18 12:57:58.577396 2026] [security2:error] [pid 66623:tid 66842] [client 68.155.155.199:4355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/lite.php"] [unique_id "aoSBBtO5rbWdOArH04KYUgAAAVY"]
[Tue Aug 18 12:57:58.615098 2026] [security2:error] [pid 66623:tid 66785] [client 172.182.217.32:12250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/bless.php"] [unique_id "aoSBBtO5rbWdOArH04KYVQAAAR0"]
[Tue Aug 18 12:57:58.623053 2026] [security2:error] [pid 66623:tid 66812] [client 172.182.200.96:14089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBBtO5rbWdOArH04KYVgAAATg"]
[Tue Aug 18 12:57:58.639185 2026] [security2:error] [pid 66623:tid 66848] [client 20.118.172.148:62083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/lite.php"] [unique_id "aoSBBtO5rbWdOArH04KYWAAAAVw"]
[Tue Aug 18 12:57:58.679589 2026] [security2:error] [pid 66623:tid 66773] [client 20.118.133.132:15194] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "agrimotor.com.br"] [uri "/1.php"] [unique_id "aoSBBtO5rbWdOArH04KYXQAAARE"]
[Tue Aug 18 12:57:58.679712 2026] [security2:error] [pid 66623:tid 66773] [client 20.118.133.132:15194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/1.php"] [unique_id "aoSBBtO5rbWdOArH04KYXQAAARE"]
[Tue Aug 18 12:57:58.681539 2026] [security2:error] [pid 66623:tid 66864] [client 68.155.154.236:40269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBBtO5rbWdOArH04KYXgAAAWw"]
[Tue Aug 18 12:57:58.710216 2026] [autoindex:error] [pid 66623:tid 66849] [client 158.158.74.177:16513] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:58.721592 2026] [security2:error] [pid 66623:tid 66784] [client 20.119.58.187:12073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "aoSBBtO5rbWdOArH04KYYQAAARw"]
[Tue Aug 18 12:57:58.727812 2026] [security2:error] [pid 66623:tid 66855] [client 40.85.222.29:44227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBBtO5rbWdOArH04KYYgAAAWM"]
[Tue Aug 18 12:57:58.735481 2026] [security2:error] [pid 66623:tid 66716] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/ms-files.php"] [unique_id "aoSBBtO5rbWdOArH04KYYwABYE8"]
[Tue Aug 18 12:57:58.738026 2026] [security2:error] [pid 66623:tid 66838] [client 4.232.151.198:24898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSBBtO5rbWdOArH04KYZAAAAVI"]
[Tue Aug 18 12:57:58.750561 2026] [security2:error] [pid 66623:tid 66790] [client 74.248.18.37:54965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/index.bak.php"] [unique_id "aoSBBtO5rbWdOArH04KYZQAAASI"]
[Tue Aug 18 12:57:58.785657 2026] [security2:error] [pid 66623:tid 66888] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBBtO5rbWdOArH04KYZgABhGo"]
[Tue Aug 18 12:57:58.812178 2026] [security2:error] [pid 66623:tid 66886] [client 20.226.6.191:4091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSBBtO5rbWdOArH04KYagAAAYI"]
[Tue Aug 18 12:57:58.813430 2026] [authz_core:error] [pid 66623:tid 66667] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:58.813892 2026] [authz_core:error] [pid 66623:tid 66667] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:58.873736 2026] [security2:error] [pid 66623:tid 66859] [client 20.186.30.159:1982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/wp-load.php"] [unique_id "aoSBBtO5rbWdOArH04KYbQAAAWc"]
[Tue Aug 18 12:57:58.915059 2026] [security2:error] [pid 66623:tid 66846] [client 158.158.74.177:16513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoSBBtO5rbWdOArH04KYcQAAAVo"]
[Tue Aug 18 12:57:58.924698 2026] [security2:error] [pid 66623:tid 66757] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/options.php"] [unique_id "aoSBBtO5rbWdOArH04KYcwABf3g"]
[Tue Aug 18 12:57:58.978494 2026] [security2:error] [pid 66623:tid 66778] [client 74.248.18.37:20493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/u.php"] [unique_id "aoSBBtO5rbWdOArH04KYdwAAARY"]
[Tue Aug 18 12:57:59.036159 2026] [security2:error] [pid 66623:tid 66792] [client 40.85.222.29:26915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/first.php"] [unique_id "aoSBB9O5rbWdOArH04KYegAAASQ"]
[Tue Aug 18 12:57:59.054313 2026] [security2:error] [pid 66623:tid 66819] [client 20.48.236.86:48753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/dex.php"] [unique_id "aoSBB9O5rbWdOArH04KYewAAAT8"]
[Tue Aug 18 12:57:59.076335 2026] [security2:error] [pid 66623:tid 66850] [client 20.119.58.187:12541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "aoSBB9O5rbWdOArH04KYfAAAAV4"]
[Tue Aug 18 12:57:59.104184 2026] [security2:error] [pid 66623:tid 66862] [client 172.182.217.32:15593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBB9O5rbWdOArH04KYfgAAAWo"]
[Tue Aug 18 12:57:59.109805 2026] [security2:error] [pid 66623:tid 66711] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/panel.php"] [unique_id "aoSBB9O5rbWdOArH04KYgAABF0o"]
[Tue Aug 18 12:57:59.113459 2026] [security2:error] [pid 66623:tid 66813] [client 52.173.121.69:16448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSBB9O5rbWdOArH04KYgQAAATk"]
[Tue Aug 18 12:57:59.116306 2026] [security2:error] [pid 66623:tid 66791] [client 158.158.34.183:43742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/IDhrIlrLb.php"] [unique_id "aoSBB9O5rbWdOArH04KYggAAASM"]
[Tue Aug 18 12:57:59.149891 2026] [security2:error] [pid 66623:tid 66770] [client 216.244.66.243:40156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.jclareteimoveis.com.br"] [uri "/5522bet-2/"] [unique_id "aoSBB9O5rbWdOArH04KYhQAAAQ4"]
[Tue Aug 18 12:57:59.149918 2026] [security2:error] [pid 66623:tid 66818] [client 68.155.154.236:40267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBB9O5rbWdOArH04KYhAAAAT4"]
[Tue Aug 18 12:57:59.150000 2026] [security2:error] [pid 66623:tid 66770] [client 216.244.66.243:40156] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.jclareteimoveis.com.br"] [uri "/5522bet-2/"] [unique_id "aoSBB9O5rbWdOArH04KYhQAAAQ4"]
[Tue Aug 18 12:57:59.155736 2026] [security2:error] [pid 66623:tid 66786] [client 158.23.17.4:44850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBB9O5rbWdOArH04KYiAAAAR4"]
[Tue Aug 18 12:57:59.156787 2026] [security2:error] [pid 66623:tid 66769] [client 20.226.6.191:4008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSBB9O5rbWdOArH04KYiQAAAQ0"]
[Tue Aug 18 12:57:59.172679 2026] [security2:error] [pid 66623:tid 66806] [client 68.155.155.199:1862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/lock360.php"] [unique_id "aoSBB9O5rbWdOArH04KYigAAATI"]
[Tue Aug 18 12:57:59.172791 2026] [security2:error] [pid 66623:tid 66885] [client 20.100.185.105:29845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/admin.php"] [unique_id "aoSBB9O5rbWdOArH04KYiwAAAYE"]
[Tue Aug 18 12:57:59.180219 2026] [security2:error] [pid 66623:tid 66643] [remote 185.118.190.176:59876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.190.118.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brandaoesa.com"] [uri "/wp-login.php"] [unique_id "aoSBB9O5rbWdOArH04KYjAABQgY"]
[Tue Aug 18 12:57:59.225125 2026] [security2:error] [pid 66623:tid 66808] [client 20.1.169.243:3398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBB9O5rbWdOArH04KYjgAAATQ"]
[Tue Aug 18 12:57:59.227323 2026] [security2:error] [pid 66623:tid 66816] [client 20.118.172.148:46772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/asasx.php"] [unique_id "aoSBB9O5rbWdOArH04KYjwAAATw"]
[Tue Aug 18 12:57:59.229826 2026] [security2:error] [pid 66623:tid 66861] [client 20.118.172.148:62115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBB9O5rbWdOArH04KYkAAAAWk"]
[Tue Aug 18 12:57:59.261110 2026] [security2:error] [pid 66623:tid 66809] [client 192.141.172.134:49377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBB9O5rbWdOArH04KYkgAAATU"]
[Tue Aug 18 12:57:59.261204 2026] [security2:error] [pid 66623:tid 66809] [client 192.141.172.134:49377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBB9O5rbWdOArH04KYkgAAATU"]
[Tue Aug 18 12:57:59.279430 2026] [security2:error] [pid 66623:tid 66851] [client 40.74.65.169:27778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/fi22.php"] [unique_id "aoSBB9O5rbWdOArH04KYkwAAAV8"]
[Tue Aug 18 12:57:59.306628 2026] [security2:error] [pid 66623:tid 66728] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "aoSBB9O5rbWdOArH04KYlAABeVs"]
[Tue Aug 18 12:57:59.355765 2026] [security2:error] [pid 66623:tid 66814] [client 40.85.222.29:44766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBB9O5rbWdOArH04KYmQAAATo"]
[Tue Aug 18 12:57:59.372611 2026] [security2:error] [pid 66623:tid 66881] [client 20.226.6.191:4034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBB9O5rbWdOArH04KYmwAAAX0"]
[Tue Aug 18 12:57:59.390639 2026] [security2:error] [pid 66623:tid 66879] [client 20.186.30.159:1691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/155.php"] [unique_id "aoSBB9O5rbWdOArH04KYnQAAAXs"]
[Tue Aug 18 12:57:59.394430 2026] [autoindex:error] [pid 66623:tid 66777] [client 4.232.151.198:24919] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/Requests/src/Cookie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:59.412427 2026] [authz_core:error] [pid 66623:tid 66725] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:57:59.412672 2026] [authz_core:error] [pid 66623:tid 66725] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:57:59.431475 2026] [security2:error] [pid 66623:tid 66888] [client 20.226.6.191:3938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSBB9O5rbWdOArH04KYpQAAAYQ"]
[Tue Aug 18 12:57:59.438050 2026] [security2:error] [pid 66623:tid 66775] [client 20.119.58.187:11864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/rest-api/about.php"] [unique_id "aoSBB9O5rbWdOArH04KYpgAAARM"]
[Tue Aug 18 12:57:59.480855 2026] [security2:error] [pid 66623:tid 66876] [client 172.182.200.96:14156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBB9O5rbWdOArH04KYrgAAAXg"]
[Tue Aug 18 12:57:59.481986 2026] [security2:error] [pid 66623:tid 66785] [client 74.248.18.37:21543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/index/function.php"] [unique_id "aoSBB9O5rbWdOArH04KYrwAAAR0"]
[Tue Aug 18 12:57:59.485411 2026] [security2:error] [pid 66623:tid 66867] [client 213.202.253.4:52694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/txets.php"] [unique_id "aoSBB9O5rbWdOArH04KYsAAAAW8"], referer: www.google.com
[Tue Aug 18 12:57:59.495382 2026] [security2:error] [pid 66623:tid 66710] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/pki-validation/min.php"] [unique_id "aoSBB9O5rbWdOArH04KYswABfkk"]
[Tue Aug 18 12:57:59.503234 2026] [security2:error] [pid 66623:tid 66873] [client 213.35.127.232:61137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBB9O5rbWdOArH04KYtQAAAXU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:57:59.505049 2026] [security2:error] [pid 66623:tid 66794] [client 20.226.6.191:4089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/an.php"] [unique_id "aoSBB9O5rbWdOArH04KYtgAAASY"]
[Tue Aug 18 12:57:59.540934 2026] [security2:error] [pid 66623:tid 66776] [client 103.139.191.60:49328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ctrrefrigeracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBB9O5rbWdOArH04KYugAAARQ"]
[Tue Aug 18 12:57:59.541058 2026] [security2:error] [pid 66623:tid 66776] [client 103.139.191.60:49328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ctrrefrigeracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBB9O5rbWdOArH04KYugAAARQ"]
[Tue Aug 18 12:57:59.587344 2026] [security2:error] [pid 66623:tid 66766] [client 20.226.6.191:4010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/404.php"] [unique_id "aoSBB9O5rbWdOArH04KYwgAAAQo"]
[Tue Aug 18 12:57:59.600903 2026] [security2:error] [pid 66623:tid 66828] [client 172.182.217.32:15761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/cache.php"] [unique_id "aoSBB9O5rbWdOArH04KYxgAAAUg"]
[Tue Aug 18 12:57:59.602276 2026] [security2:error] [pid 66623:tid 66836] [client 4.232.151.198:24919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSBB9O5rbWdOArH04KYxwAAAVA"]
[Tue Aug 18 12:57:59.631844 2026] [security2:error] [pid 66623:tid 66857] [client 20.226.6.191:4094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-login.php"] [unique_id "aoSBB9O5rbWdOArH04KYyAAAAWU"]
[Tue Aug 18 12:57:59.633847 2026] [security2:error] [pid 66623:tid 66875] [client 20.203.138.185:35014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/h.php"] [unique_id "aoSBB9O5rbWdOArH04KYygAAAXc"]
[Tue Aug 18 12:57:59.657696 2026] [security2:error] [pid 66623:tid 66850] [client 20.118.172.148:53115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/filemanager.php"] [unique_id "aoSBB9O5rbWdOArH04KYywAAAV4"]
[Tue Aug 18 12:57:59.662092 2026] [security2:error] [pid 66623:tid 66853] [client 68.155.154.236:40308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBB9O5rbWdOArH04KYzAAAAWE"]
[Tue Aug 18 12:57:59.665915 2026] [security2:error] [pid 66623:tid 66860] [client 20.48.236.86:48724] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cabeceiragrandemg.com.br"] [uri "/1.php"] [unique_id "aoSBB9O5rbWdOArH04KYzQAAAWg"]
[Tue Aug 18 12:57:59.666028 2026] [security2:error] [pid 66623:tid 66860] [client 20.48.236.86:48724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/1.php"] [unique_id "aoSBB9O5rbWdOArH04KYzQAAAWg"]
[Tue Aug 18 12:57:59.674084 2026] [security2:error] [pid 66623:tid 66825] [client 74.248.18.37:7226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/ultra.php"] [unique_id "aoSBB9O5rbWdOArH04KY0gAAAUU"]
[Tue Aug 18 12:57:59.674090 2026] [security2:error] [pid 66623:tid 66818] [client 20.226.6.191:4094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSBB9O5rbWdOArH04KY0QAAAT4"]
[Tue Aug 18 12:57:59.681777 2026] [security2:error] [pid 66623:tid 66729] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/plugin-install.php"] [unique_id "aoSBB9O5rbWdOArH04KY0wABHlw"]
[Tue Aug 18 12:57:59.727183 2026] [security2:error] [pid 66623:tid 66885] [client 40.85.222.29:26935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBB9O5rbWdOArH04KY1QAAAYE"]
[Tue Aug 18 12:57:59.740242 2026] [security2:error] [pid 66623:tid 66774] [client 20.118.172.148:56564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/rip.php"] [unique_id "aoSBB9O5rbWdOArH04KY2AAAARI"]
[Tue Aug 18 12:57:59.756110 2026] [security2:error] [pid 66623:tid 66799] [client 52.173.121.69:16454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSBB9O5rbWdOArH04KY2gAAASs"]
[Tue Aug 18 12:57:59.760693 2026] [autoindex:error] [pid 66623:tid 66798] [client 20.226.6.191:4027] AH01276: Cannot serve directory /home1/agencialkx/riovacinas.com.br/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:57:59.766471 2026] [security2:error] [pid 66623:tid 66816] [client 20.226.6.191:4027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wso.php"] [unique_id "aoSBB9O5rbWdOArH04KY3AAAATw"]
[Tue Aug 18 12:57:59.772234 2026] [security2:error] [pid 66623:tid 66831] [client 20.79.204.6:11679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBB9O5rbWdOArH04KY3gAAAUs"]
[Tue Aug 18 12:57:59.775516 2026] [security2:error] [pid 66623:tid 66820] [client 20.186.30.159:1685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/index.php"] [unique_id "aoSBB9O5rbWdOArH04KY3wAAAUA"]
[Tue Aug 18 12:57:59.783483 2026] [security2:error] [pid 66623:tid 66812] [client 20.226.6.191:3991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/sf.php"] [unique_id "aoSBB9O5rbWdOArH04KY4AAAATg"]
[Tue Aug 18 12:57:59.794660 2026] [security2:error] [pid 66623:tid 66770] [client 20.119.58.187:12041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "aoSBB9O5rbWdOArH04KY5AAAAQ4"]
[Tue Aug 18 12:57:59.804088 2026] [security2:error] [pid 66623:tid 66823] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/admin.php"] [unique_id "aoSBB9O5rbWdOArH04KY5QAAAUM"]
[Tue Aug 18 12:57:59.824184 2026] [security2:error] [pid 66623:tid 66783] [client 20.226.6.191:3922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/index/function.php"] [unique_id "aoSBB9O5rbWdOArH04KY6QAAARs"]
[Tue Aug 18 12:57:59.861278 2026] [security2:error] [pid 66623:tid 66764] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/test.php"] [unique_id "aoSBB9O5rbWdOArH04KY7wABhH8"]
[Tue Aug 18 12:57:59.889253 2026] [security2:error] [pid 66623:tid 66865] [client 20.203.183.135:50101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBB9O5rbWdOArH04KY8QAAAW0"]
[Tue Aug 18 12:57:59.915490 2026] [security2:error] [pid 66623:tid 66873] [client 68.155.155.199:19421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSBB9O5rbWdOArH04KY8wAAAXU"]
[Tue Aug 18 12:57:59.927976 2026] [security2:error] [pid 66623:tid 66834] [client 20.226.6.191:4007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/edit.php"] [unique_id "aoSBB9O5rbWdOArH04KY9AAAAU4"]
[Tue Aug 18 12:57:59.987550 2026] [security2:error] [pid 66623:tid 66772] [client 62.197.45.62:64803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.45.197.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exatarc.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSBB9O5rbWdOArH04KY6AAAARA"], referer: https://exatarc.com.br/
[Tue Aug 18 12:57:59.999183 2026] [security2:error] [pid 66623:tid 66835] [client 20.100.185.105:52169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-the.php"] [unique_id "aoSBB9O5rbWdOArH04KY-AAAAU8"]
[Tue Aug 18 12:58:00.016325 2026] [security2:error] [pid 66623:tid 66840] [client 158.158.34.183:55388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/cJLGqzB.php"] [unique_id "aoSBCNO5rbWdOArH04KY-wAAAVQ"]
[Tue Aug 18 12:58:00.017979 2026] [security2:error] [pid 66623:tid 66771] [client 20.118.172.148:33496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/themes.php"] [unique_id "aoSBCNO5rbWdOArH04KY_AAAAQ8"]
[Tue Aug 18 12:58:00.042488 2026] [security2:error] [pid 66623:tid 66678] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/wp-blog-header.php"] [unique_id "aoSBCNO5rbWdOArH04KY_wABMyk"]
[Tue Aug 18 12:58:00.045323 2026] [security2:error] [pid 66623:tid 66828] [client 20.226.6.191:3907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSBCNO5rbWdOArH04KZAAAAAUg"]
[Tue Aug 18 12:58:00.064603 2026] [security2:error] [pid 66623:tid 66843] [client 20.65.98.162:8629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/file2.php"] [unique_id "aoSBCNO5rbWdOArH04KZAQAAAVc"]
[Tue Aug 18 12:58:00.081158 2026] [security2:error] [pid 66623:tid 66792] [client 40.85.222.29:44756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBCNO5rbWdOArH04KZAgAAASQ"]
[Tue Aug 18 12:58:00.095610 2026] [security2:error] [pid 66623:tid 66875] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/ajax.php"] [unique_id "aoSBCNO5rbWdOArH04KZAwAAAXc"]
[Tue Aug 18 12:58:00.097588 2026] [security2:error] [pid 66623:tid 66841] [client 172.182.217.32:15594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/content.php"] [unique_id "aoSBCNO5rbWdOArH04KZBAAAAVU"]
[Tue Aug 18 12:58:00.119644 2026] [security2:error] [pid 66623:tid 66810] [client 40.74.65.169:43184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBCNO5rbWdOArH04KZBQAAATY"]
[Tue Aug 18 12:58:00.137000 2026] [security2:error] [pid 66623:tid 66800] [client 74.248.18.37:7185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/info.php"] [unique_id "aoSBCNO5rbWdOArH04KZCAAAASw"]
[Tue Aug 18 12:58:00.153796 2026] [security2:error] [pid 66623:tid 66817] [client 20.119.58.187:11853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/banners/about.php"] [unique_id "aoSBCNO5rbWdOArH04KZCQAAAT0"]
[Tue Aug 18 12:58:00.178499 2026] [security2:error] [pid 66623:tid 66860] [client 20.226.6.191:4044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-good.php"] [unique_id "aoSBCNO5rbWdOArH04KZCwAAAWg"]
[Tue Aug 18 12:58:00.185291 2026] [security2:error] [pid 66623:tid 66791] [client 114.119.131.253:48291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "renatomultimarcas.com.br"] [uri "/veiculo/136148/idea-elx-1-4-mpi-fire-flex-8v-5p"] [unique_id "aoSBCNO5rbWdOArH04KZDAAAASM"], referer: http://renatomultimarcas.com.br/veiculo/136148/idea-elx-1-4-mpi-fire-flex-8v-5p
[Tue Aug 18 12:58:00.225612 2026] [security2:error] [pid 66623:tid 66671] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/wp-cron.php"] [unique_id "aoSBCNO5rbWdOArH04KZDwABQiI"]
[Tue Aug 18 12:58:00.243416 2026] [security2:error] [pid 66623:tid 66799] [client 20.186.30.159:1962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/aaa.php"] [unique_id "aoSBCNO5rbWdOArH04KZEgAAASs"]
[Tue Aug 18 12:58:00.248266 2026] [autoindex:error] [pid 66623:tid 66811] [client 4.232.151.198:24905] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:00.254060 2026] [security2:error] [pid 66623:tid 66808] [client 20.1.169.243:3428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/wp-includes/Text/Diff/Engine.php"] [unique_id "aoSBCNO5rbWdOArH04KZEwAAATQ"]
[Tue Aug 18 12:58:00.264894 2026] [security2:error] [pid 66623:tid 66778] [client 37.40.227.74:56638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCNO5rbWdOArH04KZFgAAARY"]
[Tue Aug 18 12:58:00.269040 2026] [security2:error] [pid 66623:tid 66778] [client 37.40.227.74:56638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCNO5rbWdOArH04KZFgAAARY"]
[Tue Aug 18 12:58:00.273332 2026] [security2:error] [pid 66623:tid 66812] [client 68.155.154.236:7923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/well-known/index.php"] [unique_id "aoSBCNO5rbWdOArH04KZGAAAATg"]
[Tue Aug 18 12:58:00.312014 2026] [security2:error] [pid 66623:tid 66877] [client 20.226.6.191:4031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/tes.php"] [unique_id "aoSBCNO5rbWdOArH04KZHAAAAXk"]
[Tue Aug 18 12:58:00.321055 2026] [authz_core:error] [pid 66623:tid 66655] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:00.321326 2026] [authz_core:error] [pid 66623:tid 66655] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:00.326873 2026] [security2:error] [pid 66623:tid 66770] [client 20.203.138.185:55020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/koiy.php"] [unique_id "aoSBCNO5rbWdOArH04KZHgAAAQ4"]
[Tue Aug 18 12:58:00.364820 2026] [security2:error] [pid 66623:tid 66827] [client 74.248.18.37:54970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/un.php"] [unique_id "aoSBCNO5rbWdOArH04KZHwAAAUc"]
[Tue Aug 18 12:58:00.370333 2026] [security2:error] [pid 66623:tid 66881] [client 20.118.172.148:2704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBCNO5rbWdOArH04KZIAAAAX0"]
[Tue Aug 18 12:58:00.377023 2026] [security2:error] [pid 66623:tid 66849] [client 20.226.6.191:4057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/files/index.php"] [unique_id "aoSBCNO5rbWdOArH04KZIQAAAV0"]
[Tue Aug 18 12:58:00.387875 2026] [security2:error] [pid 66623:tid 66825] [client 20.79.204.6:11659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/0x.php"] [unique_id "aoSBCNO5rbWdOArH04KZIgAAAUU"]
[Tue Aug 18 12:58:00.406806 2026] [security2:error] [pid 66623:tid 66759] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/wp-links-opml.php"] [unique_id "aoSBCNO5rbWdOArH04KZJAABYHo"]
[Tue Aug 18 12:58:00.413131 2026] [security2:error] [pid 66623:tid 66871] [client 20.226.6.191:4018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBCNO5rbWdOArH04KZJgAAAXM"]
[Tue Aug 18 12:58:00.457051 2026] [security2:error] [pid 66623:tid 66865] [client 4.232.151.198:24905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSBCNO5rbWdOArH04KZKQAAAW0"]
[Tue Aug 18 12:58:00.462701 2026] [security2:error] [pid 66623:tid 66876] [client 20.226.6.191:3988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/images/images/about.php"] [unique_id "aoSBCNO5rbWdOArH04KZKgAAAXg"]
[Tue Aug 18 12:58:00.475521 2026] [security2:error] [pid 66623:tid 66834] [client 20.118.172.148:62400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/update/da222.php"] [unique_id "aoSBCNO5rbWdOArH04KZLAAAAU4"]
[Tue Aug 18 12:58:00.485076 2026] [security2:error] [pid 66623:tid 66878] [client 40.85.222.29:44763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/blog/byp.php"] [unique_id "aoSBCNO5rbWdOArH04KZMgAAAXo"]
[Tue Aug 18 12:58:00.487407 2026] [security2:error] [pid 66623:tid 66829] [client 20.226.6.191:3909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBCNO5rbWdOArH04KZMwAAAUk"]
[Tue Aug 18 12:58:00.499799 2026] [security2:error] [pid 66623:tid 66772] [client 20.226.6.191:4024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/rip.php"] [unique_id "aoSBCNO5rbWdOArH04KZNQAAARA"]
[Tue Aug 18 12:58:00.507007 2026] [security2:error] [pid 66623:tid 66783] [client 20.119.58.187:12488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSBCNO5rbWdOArH04KZNwAAARs"]
[Tue Aug 18 12:58:00.525767 2026] [security2:error] [pid 66623:tid 66766] [client 20.186.30.159:1948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/FWAZ.php"] [unique_id "aoSBCNO5rbWdOArH04KZPgAAAQo"]
[Tue Aug 18 12:58:00.530315 2026] [security2:error] [pid 66623:tid 66828] [client 20.226.6.191:3937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCNO5rbWdOArH04KZPwAAAUg"]
[Tue Aug 18 12:58:00.531981 2026] [security2:error] [pid 66623:tid 66786] [client 213.35.127.232:61341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBCNO5rbWdOArH04KZQAAAAR4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:00.533796 2026] [security2:error] [pid 66623:tid 66870] [client 20.100.169.31:20231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/u.php"] [unique_id "aoSBCNO5rbWdOArH04KZQQAAAXI"]
[Tue Aug 18 12:58:00.586340 2026] [security2:error] [pid 66623:tid 66790] [client 172.182.217.32:15562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBCNO5rbWdOArH04KZSQAAASI"]
[Tue Aug 18 12:58:00.587485 2026] [security2:error] [pid 66623:tid 66792] [client 20.226.6.191:3851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/moon.php"] [unique_id "aoSBCNO5rbWdOArH04KZSwAAASQ"]
[Tue Aug 18 12:58:00.602229 2026] [security2:error] [pid 66623:tid 66800] [client 20.226.6.191:3910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/cache.php"] [unique_id "aoSBCNO5rbWdOArH04KZTgAAASw"]
[Tue Aug 18 12:58:00.625997 2026] [security2:error] [pid 66623:tid 66838] [client 20.100.185.105:29874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSBCNO5rbWdOArH04KZUgAAAVI"]
[Tue Aug 18 12:58:00.629281 2026] [security2:error] [pid 66623:tid 66789] [client 20.118.133.132:23183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/coffee.php"] [unique_id "aoSBCNO5rbWdOArH04KZUwAAASE"]
[Tue Aug 18 12:58:00.636526 2026] [security2:error] [pid 66623:tid 66822] [client 68.155.155.199:20169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSBCNO5rbWdOArH04KZVQAAAUI"]
[Tue Aug 18 12:58:00.703597 2026] [security2:error] [pid 66623:tid 66812] [client 20.226.6.191:3905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBCNO5rbWdOArH04KZXwAAATg"]
[Tue Aug 18 12:58:00.719198 2026] [security2:error] [pid 66623:tid 66856] [client 103.184.169.37:42271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCNO5rbWdOArH04KZYgAAAWQ"]
[Tue Aug 18 12:58:00.719466 2026] [security2:error] [pid 66623:tid 66856] [client 103.184.169.37:42271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCNO5rbWdOArH04KZYgAAAWQ"]
[Tue Aug 18 12:58:00.756093 2026] [security2:error] [pid 66623:tid 66747] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/wp-login.php"] [unique_id "aoSBCNO5rbWdOArH04KZTAABP24"]
[Tue Aug 18 12:58:00.780358 2026] [security2:error] [pid 66623:tid 66823] [client 68.155.154.236:50412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBCNO5rbWdOArH04KZZgAAAUM"]
[Tue Aug 18 12:58:00.809597 2026] [security2:error] [pid 66623:tid 66827] [client 20.118.172.148:63055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/buy.php"] [unique_id "aoSBCNO5rbWdOArH04KZaAAAAUc"]
[Tue Aug 18 12:58:00.824879 2026] [security2:error] [pid 66623:tid 66887] [client 40.85.222.29:26941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBCNO5rbWdOArH04KZagAAAYM"]
[Tue Aug 18 12:58:00.851965 2026] [security2:error] [pid 66623:tid 66885] [client 74.248.18.37:7227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/inputs.php"] [unique_id "aoSBCNO5rbWdOArH04KZawAAAYE"]
[Tue Aug 18 12:58:00.863950 2026] [security2:error] [pid 66623:tid 66888] [client 20.118.172.148:62406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/upload.php"] [unique_id "aoSBCNO5rbWdOArH04KZbgAAAYQ"]
[Tue Aug 18 12:58:00.867949 2026] [security2:error] [pid 66623:tid 66877] [client 20.119.58.187:11860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/img/about.php"] [unique_id "aoSBCNO5rbWdOArH04KZbwAAAXk"]
[Tue Aug 18 12:58:00.912385 2026] [security2:error] [pid 66623:tid 66873] [client 20.226.6.191:4052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBCNO5rbWdOArH04KZcgAAAXU"]
[Tue Aug 18 12:58:00.951943 2026] [security2:error] [pid 66623:tid 66839] [client 20.203.138.185:22981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/fff.php"] [unique_id "aoSBCNO5rbWdOArH04KZdgAAAVM"]
[Tue Aug 18 12:58:00.953726 2026] [security2:error] [pid 66623:tid 66701] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/wp-settings.php"] [unique_id "aoSBCNO5rbWdOArH04KZeAABH0A"]
[Tue Aug 18 12:58:00.966348 2026] [security2:error] [pid 66623:tid 66844] [client 103.120.71.157:57050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCNO5rbWdOArH04KZeQAAAVg"]
[Tue Aug 18 12:58:00.966470 2026] [security2:error] [pid 66623:tid 66844] [client 103.120.71.157:57050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCNO5rbWdOArH04KZeQAAAVg"]
[Tue Aug 18 12:58:00.986841 2026] [security2:error] [pid 66623:tid 66840] [client 20.1.169.243:1038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/wp-mail.php"] [unique_id "aoSBCNO5rbWdOArH04KZfAAAAVQ"]
[Tue Aug 18 12:58:00.988801 2026] [security2:error] [pid 66623:tid 66770] [client 20.79.204.6:11662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/222.php"] [unique_id "aoSBCNO5rbWdOArH04KZfQAAAQ4"]
[Tue Aug 18 12:58:00.999815 2026] [security2:error] [pid 66623:tid 66773] [client 79.127.164.8:52338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/phpmyadmin.bak"] [unique_id "aoSBCNO5rbWdOArH04KZfgAAARE"], referer: https://medihub.com.br/phpmyadmin.bak
[Tue Aug 18 12:58:01.048995 2026] [security2:error] [pid 66623:tid 66833] [client 20.48.236.86:37069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/coffee.php"] [unique_id "aoSBCdO5rbWdOArH04KZggAAAU0"]
[Tue Aug 18 12:58:01.072767 2026] [security2:error] [pid 66623:tid 66825] [client 74.248.18.37:7177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/up.php"] [unique_id "aoSBCdO5rbWdOArH04KZhAAAAUU"]
[Tue Aug 18 12:58:01.075113 2026] [security2:error] [pid 66623:tid 66882] [client 172.182.217.32:15599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/css.php"] [unique_id "aoSBCdO5rbWdOArH04KZhQAAAX4"]
[Tue Aug 18 12:58:01.081532 2026] [security2:error] [pid 66623:tid 66782] [client 4.232.151.198:24947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSBCdO5rbWdOArH04KZhgAAARo"]
[Tue Aug 18 12:58:01.108161 2026] [security2:error] [pid 66623:tid 66858] [client 20.186.30.159:1953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/site.php"] [unique_id "aoSBCdO5rbWdOArH04KZiQAAAWY"]
[Tue Aug 18 12:58:01.111474 2026] [security2:error] [pid 66623:tid 66779] [client 40.74.65.169:27773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSBCdO5rbWdOArH04KZigAAARc"]
[Tue Aug 18 12:58:01.124344 2026] [security2:error] [pid 66623:tid 66777] [client 52.173.121.69:17966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSBCdO5rbWdOArH04KZiwAAARU"]
[Tue Aug 18 12:58:01.146332 2026] [security2:error] [pid 66623:tid 66697] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/wp-signup.php"] [unique_id "aoSBCdO5rbWdOArH04KZjQABIzw"]
[Tue Aug 18 12:58:01.147052 2026] [security2:error] [pid 66623:tid 66892] [client 20.118.172.148:43499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/dropdown.php"] [unique_id "aoSBCdO5rbWdOArH04KZjgAAAYg"]
[Tue Aug 18 12:58:01.171746 2026] [security2:error] [pid 66623:tid 66860] [client 20.226.6.191:3960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/o.php"] [unique_id "aoSBCdO5rbWdOArH04KZjwAAAWg"]
[Tue Aug 18 12:58:01.173442 2026] [security2:error] [pid 66623:tid 66866] [client 40.85.222.29:44273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBCdO5rbWdOArH04KZkAAAAW4"]
[Tue Aug 18 12:58:01.198077 2026] [security2:error] [pid 66623:tid 66886] [client 68.155.154.236:7908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBCdO5rbWdOArH04KZkgAAAYI"]
[Tue Aug 18 12:58:01.223592 2026] [security2:error] [pid 66623:tid 66809] [client 20.226.6.191:4020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/bb.php"] [unique_id "aoSBCdO5rbWdOArH04KZlAAAATU"]
[Tue Aug 18 12:58:01.224830 2026] [security2:error] [pid 66623:tid 66848] [client 20.119.58.187:11870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/languages/about.php"] [unique_id "aoSBCdO5rbWdOArH04KZlQAAAVw"]
[Tue Aug 18 12:58:01.249977 2026] [security2:error] [pid 66623:tid 66820] [client 20.219.2.203:7297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/tmp/index.php"] [unique_id "aoSBCdO5rbWdOArH04KZlgAAAUA"]
[Tue Aug 18 12:58:01.265136 2026] [security2:error] [pid 66623:tid 66824] [client 20.100.185.105:56443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBCdO5rbWdOArH04KZlwAAAUQ"]
[Tue Aug 18 12:58:01.274359 2026] [security2:error] [pid 66623:tid 66856] [client 20.118.172.148:62459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wk/index.php"] [unique_id "aoSBCdO5rbWdOArH04KZmAAAAWQ"]
[Tue Aug 18 12:58:01.335506 2026] [security2:error] [pid 66623:tid 66716] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/002.php"] [unique_id "aoSBCdO5rbWdOArH04KZmwABOk8"]
[Tue Aug 18 12:58:01.351453 2026] [security2:error] [pid 66623:tid 66797] [client 20.1.169.243:3411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/wp-the.php"] [unique_id "aoSBCdO5rbWdOArH04KZnAAAASk"]
[Tue Aug 18 12:58:01.367667 2026] [security2:error] [pid 66623:tid 66827] [client 20.226.6.191:3985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSBCdO5rbWdOArH04KZnQAAAUc"]
[Tue Aug 18 12:58:01.399990 2026] [security2:error] [pid 66623:tid 66877] [client 20.186.30.159:1949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/ccc.php"] [unique_id "aoSBCdO5rbWdOArH04KZngAAAXk"]
[Tue Aug 18 12:58:01.443364 2026] [security2:error] [pid 66623:tid 66864] [client 158.158.74.177:16572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/link-add.php"] [unique_id "aoSBCdO5rbWdOArH04KZoQAAAWw"]
[Tue Aug 18 12:58:01.477970 2026] [security2:error] [pid 66623:tid 66829] [client 40.85.222.29:44281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/images/security.php"] [unique_id "aoSBCdO5rbWdOArH04KZogAAAUk"]
[Tue Aug 18 12:58:01.505974 2026] [security2:error] [pid 66623:tid 66835] [client 20.226.6.191:4029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSBCdO5rbWdOArH04KZpwAAAU8"]
[Tue Aug 18 12:58:01.507142 2026] [security2:error] [pid 66623:tid 66796] [client 74.248.18.37:7208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/install.php"] [unique_id "aoSBCdO5rbWdOArH04KZqAAAASg"]
[Tue Aug 18 12:58:01.518773 2026] [security2:error] [pid 66623:tid 66757] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/0x.php"] [unique_id "aoSBCdO5rbWdOArH04KZqQABSng"]
[Tue Aug 18 12:58:01.550752 2026] [security2:error] [pid 66623:tid 66816] [client 213.35.127.232:61539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBCdO5rbWdOArH04KZqwAAATw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:01.559834 2026] [security2:error] [pid 66623:tid 66788] [client 172.182.217.32:15577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/chosen.php"] [unique_id "aoSBCdO5rbWdOArH04KZrAAAASA"]
[Tue Aug 18 12:58:01.571254 2026] [security2:error] [pid 66623:tid 66770] [client 20.226.6.191:4080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSBCdO5rbWdOArH04KZsAAAAQ4"]
[Tue Aug 18 12:58:01.580394 2026] [security2:error] [pid 66623:tid 66893] [client 20.119.58.187:11977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "aoSBCdO5rbWdOArH04KZsQAAAYk"]
[Tue Aug 18 12:58:01.580526 2026] [security2:error] [pid 66623:tid 66805] [client 20.219.2.203:7302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/tmpls.php"] [unique_id "aoSBCdO5rbWdOArH04KZsgAAATE"]
[Tue Aug 18 12:58:01.590616 2026] [security2:error] [pid 66623:tid 66852] [client 20.79.204.6:11526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/aa.php"] [unique_id "aoSBCdO5rbWdOArH04KZtAAAAWA"]
[Tue Aug 18 12:58:01.617911 2026] [security2:error] [pid 66623:tid 66786] [client 68.155.154.236:7646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBCdO5rbWdOArH04KZtwAAAR4"]
[Tue Aug 18 12:58:01.618969 2026] [security2:error] [pid 66623:tid 66853] [client 20.118.172.148:2688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/inputs.php"] [unique_id "aoSBCdO5rbWdOArH04KZuQAAAWE"]
[Tue Aug 18 12:58:01.624812 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:01.625066 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:01.631874 2026] [security2:error] [pid 66623:tid 66870] [client 20.226.6.191:4063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/file.php"] [unique_id "aoSBCdO5rbWdOArH04KZugAAAXI"]
[Tue Aug 18 12:58:01.661669 2026] [security2:error] [pid 66623:tid 66875] [client 20.226.6.191:3868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/epinyins.php"] [unique_id "aoSBCdO5rbWdOArH04KZvgAAAXc"]
[Tue Aug 18 12:58:01.681039 2026] [security2:error] [pid 66623:tid 66831] [client 20.226.6.191:3911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBCdO5rbWdOArH04KZwgAAAUs"]
[Tue Aug 18 12:58:01.700557 2026] [security2:error] [pid 66623:tid 66665] [remote 68.155.154.146:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/1.php"] [unique_id "aoSBCdO5rbWdOArH04KZxQABFxw"]
[Tue Aug 18 12:58:01.700644 2026] [security2:error] [pid 66623:tid 66665] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/1.php"] [unique_id "aoSBCdO5rbWdOArH04KZxQABFxw"]
[Tue Aug 18 12:58:01.708795 2026] [security2:error] [pid 66623:tid 66802] [client 4.232.151.198:24938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSBCdO5rbWdOArH04KZxwAAAS4"]
[Tue Aug 18 12:58:01.715443 2026] [security2:error] [pid 66623:tid 66857] [client 20.1.169.243:3408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/wp.php"] [unique_id "aoSBCdO5rbWdOArH04KZywAAAWU"]
[Tue Aug 18 12:58:01.719007 2026] [security2:error] [pid 66623:tid 66776] [client 172.182.200.96:14158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSBCdO5rbWdOArH04KZzAAAARQ"]
[Tue Aug 18 12:58:01.721328 2026] [security2:error] [pid 66623:tid 66769] [client 20.226.6.191:3964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSBCdO5rbWdOArH04KZzQAAAQ0"]
[Tue Aug 18 12:58:01.722604 2026] [security2:error] [pid 66623:tid 66769] [client 158.23.17.4:20189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/st.php"] [unique_id "aoSBCdO5rbWdOArH04KZzgAAAQ0"]
[Tue Aug 18 12:58:01.763023 2026] [security2:error] [pid 66623:tid 66796] [client 20.226.6.191:3977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBCdO5rbWdOArH04KZ1QAAASg"]
[Tue Aug 18 12:58:01.794997 2026] [security2:error] [pid 66623:tid 66816] [client 20.226.6.191:3976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp.php"] [unique_id "aoSBCdO5rbWdOArH04KZ1wAAATw"]
[Tue Aug 18 12:58:01.800970 2026] [security2:error] [pid 66623:tid 66890] [client 172.182.200.96:7641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBCdO5rbWdOArH04KZ2AAAAYY"]
[Tue Aug 18 12:58:01.830029 2026] [security2:error] [pid 66623:tid 66852] [client 20.226.6.191:3932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/function/function.php"] [unique_id "aoSBCdO5rbWdOArH04KZ2gAAAWA"]
[Tue Aug 18 12:58:01.841383 2026] [security2:error] [pid 66623:tid 66773] [client 20.186.30.159:1701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/admin.php"] [unique_id "aoSBCdO5rbWdOArH04KZ2wAAARE"]
[Tue Aug 18 12:58:01.848142 2026] [security2:error] [pid 66623:tid 66853] [client 20.226.6.191:3973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSBCdO5rbWdOArH04KZ3QAAAWE"]
[Tue Aug 18 12:58:01.849954 2026] [security2:error] [pid 66623:tid 66807] [client 158.158.34.183:25420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/akc.php"] [unique_id "aoSBCdO5rbWdOArH04KZ3gAAATM"]
[Tue Aug 18 12:58:01.854515 2026] [security2:error] [pid 66623:tid 66843] [client 68.155.155.199:11550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/.alf.php"] [unique_id "aoSBCdO5rbWdOArH04KZ3wAAAVc"]
[Tue Aug 18 12:58:01.861816 2026] [security2:error] [pid 66623:tid 66837] [client 20.226.6.191:3958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSBCdO5rbWdOArH04KZ4QAAAVE"]
[Tue Aug 18 12:58:01.876815 2026] [security2:error] [pid 66623:tid 66785] [client 40.74.65.169:35731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBCdO5rbWdOArH04KZ4wAAAR0"]
[Tue Aug 18 12:58:01.894059 2026] [security2:error] [pid 66623:tid 66831] [client 20.118.133.132:23210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBCdO5rbWdOArH04KZ5QAAAUs"]
[Tue Aug 18 12:58:01.896599 2026] [security2:error] [pid 66623:tid 66749] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/100.php"] [unique_id "aoSBCdO5rbWdOArH04KZ5gABfnA"]
[Tue Aug 18 12:58:01.901245 2026] [security2:error] [pid 66623:tid 66800] [client 52.173.121.69:24803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSBCdO5rbWdOArH04KZ5wAAASw"]
[Tue Aug 18 12:58:01.921470 2026] [security2:error] [pid 66623:tid 66866] [client 34.86.30.230:41898] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/proc/1/environ"] [unique_id "aoSBCdO5rbWdOArH04KZ7QAAAW4"]
[Tue Aug 18 12:58:01.921939 2026] [security2:error] [pid 66623:tid 66860] [client 34.86.30.230:41872] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBCdO5rbWdOArH04KZ7gAAAWg"]
[Tue Aug 18 12:58:01.926048 2026] [authz_core:error] [pid 66623:tid 66758] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:01.926308 2026] [authz_core:error] [pid 66623:tid 66758] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:01.926930 2026] [proxy_http:error] [pid 66623:tid 66774] (20014)Internal error (specific information not available): [client 34.86.30.230:41844] AH01102: error reading status line from remote server 127.0.0.1:2095, referer: https://webmail.nightblue.com.br
[Tue Aug 18 12:58:01.926941 2026] [proxy:error] [pid 66623:tid 66774] [client 34.86.30.230:41844] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/graphql, referer: https://webmail.nightblue.com.br
[Tue Aug 18 12:58:01.934642 2026] [security2:error] [pid 66623:tid 66776] [client 20.226.6.191:3865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/ok.php"] [unique_id "aoSBCdO5rbWdOArH04KZ8QAAARQ"]
[Tue Aug 18 12:58:01.935166 2026] [proxy_http:error] [pid 66623:tid 66860] (20014)Internal error (specific information not available): [client 34.86.30.230:41872] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:01.935182 2026] [proxy:error] [pid 66623:tid 66860] [client 34.86.30.230:41872] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/cgi-sys/403.html
[Tue Aug 18 12:58:01.936394 2026] [security2:error] [pid 66623:tid 66770] [client 20.119.58.187:11888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/widgets/about.php"] [unique_id "aoSBCdO5rbWdOArH04KZ8wAAAQ4"]
[Tue Aug 18 12:58:01.943644 2026] [proxy_http:error] [pid 66623:tid 66774] (20014)Internal error (specific information not available): [client 34.86.30.230:41844] AH01102: error reading status line from remote server 127.0.0.1:2095, referer: https://webmail.nightblue.com.br
[Tue Aug 18 12:58:01.943662 2026] [proxy:error] [pid 66623:tid 66774] [client 34.86.30.230:41844] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml, referer: https://webmail.nightblue.com.br
[Tue Aug 18 12:58:01.948757 2026] [security2:error] [pid 66623:tid 66892] [client 20.226.6.191:4088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/item.php"] [unique_id "aoSBCdO5rbWdOArH04KZ9QAAAYg"]
[Tue Aug 18 12:58:01.949205 2026] [security2:error] [pid 66623:tid 66789] [client 74.248.18.37:54966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/users.php"] [unique_id "aoSBCdO5rbWdOArH04KZ9gAAASE"]
[Tue Aug 18 12:58:01.950050 2026] [security2:error] [pid 66623:tid 66836] [client 20.118.172.148:63077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/100.php"] [unique_id "aoSBCdO5rbWdOArH04KZ9wAAAVA"]
[Tue Aug 18 12:58:01.950639 2026] [proxy_http:error] [pid 66623:tid 66878] (20014)Internal error (specific information not available): [client 34.86.30.230:42236] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:01.950652 2026] [proxy:error] [pid 66623:tid 66878] [client 34.86.30.230:42236] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/@fs/home/ec2-user/.aws/credentials
[Tue Aug 18 12:58:01.958886 2026] [security2:error] [pid 66623:tid 66864] [client 34.86.30.230:41858] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/media../.env"] [unique_id "aoSBCdO5rbWdOArH04KZ_QAAAWw"]
[Tue Aug 18 12:58:01.958948 2026] [security2:error] [pid 66623:tid 66868] [client 34.86.30.230:41956] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/static../etc/passwd"] [unique_id "aoSBCdO5rbWdOArH04KZ-gAAAXA"]
[Tue Aug 18 12:58:01.959209 2026] [security2:error] [pid 66623:tid 66842] [client 34.86.30.230:41884] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBCdO5rbWdOArH04KZ-QAAAVY"]
[Tue Aug 18 12:58:01.962683 2026] [security2:error] [pid 66623:tid 66848] [client 20.118.172.148:62121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-act.php"] [unique_id "aoSBCdO5rbWdOArH04KaAgAAAVw"]
[Tue Aug 18 12:58:01.966461 2026] [security2:error] [pid 66623:tid 66821] [client 20.203.138.185:45366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/pouhg.php"] [unique_id "aoSBCdO5rbWdOArH04KaAwAAAUE"]
[Tue Aug 18 12:58:01.970563 2026] [security2:error] [pid 66623:tid 66797] [client 34.86.30.230:42038] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/proc/self/environ"] [unique_id "aoSBCdO5rbWdOArH04KaBgAAASk"]
[Tue Aug 18 12:58:01.970598 2026] [security2:error] [pid 66623:tid 66879] [client 34.86.30.230:42052] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/api/config"] [unique_id "aoSBCdO5rbWdOArH04KaCQAAAXs"]
[Tue Aug 18 12:58:01.972080 2026] [proxy_http:error] [pid 66623:tid 66874] (20014)Internal error (specific information not available): [client 34.86.30.230:42012] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:01.972097 2026] [proxy:error] [pid 66623:tid 66874] [client 34.86.30.230:42012] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/app/.env
[Tue Aug 18 12:58:01.973313 2026] [security2:error] [pid 66623:tid 66850] [client 34.86.30.230:42178] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/fetch"] [unique_id "aoSBCdO5rbWdOArH04KaDAAAAV4"]
[Tue Aug 18 12:58:01.973425 2026] [security2:error] [pid 66623:tid 66869] [client 34.86.30.230:42212] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/api/graphql"] [unique_id "aoSBCdO5rbWdOArH04KaDwAAAXE"], referer: https://webmail.nightblue.com.br
[Tue Aug 18 12:58:01.974237 2026] [security2:error] [pid 66623:tid 66798] [client 34.86.30.230:42152] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/read"] [unique_id "aoSBCdO5rbWdOArH04KaFQAAASo"]
[Tue Aug 18 12:58:01.974449 2026] [core:error] [pid 66623:tid 66856] [client 34.86.30.230:41982] AH10244: invalid URI path (/assets../../../etc/passwd)
[Tue Aug 18 12:58:01.975895 2026] [security2:error] [pid 66623:tid 66827] [client 34.86.30.230:41984] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/files../etc/passwd"] [unique_id "aoSBCdO5rbWdOArH04KaHgAAAUc"]
[Tue Aug 18 12:58:02.050698 2026] [security2:error] [pid 66623:tid 66638] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaJQABJQE"]
[Tue Aug 18 12:58:02.050931 2026] [security2:error] [pid 66623:tid 66793] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaJQABJQE"]
[Tue Aug 18 12:58:02.078363 2026] [security2:error] [pid 66623:tid 66689] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/2.php"] [unique_id "aoSBCtO5rbWdOArH04KaKAABETQ"]
[Tue Aug 18 12:58:02.080198 2026] [security2:error] [pid 66623:tid 66838] [client 20.1.169.243:3399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/wso.php"] [unique_id "aoSBCtO5rbWdOArH04KaKQAAAVI"]
[Tue Aug 18 12:58:02.094258 2026] [security2:error] [pid 66623:tid 66863] [client 172.182.217.32:15752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/doc.php"] [unique_id "aoSBCtO5rbWdOArH04KaKwAAAWs"]
[Tue Aug 18 12:58:02.098983 2026] [security2:error] [pid 66623:tid 66870] [client 20.100.185.105:53284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/3.php"] [unique_id "aoSBCtO5rbWdOArH04KaLAAAAXI"]
[Tue Aug 18 12:58:02.108649 2026] [proxy_http:error] [pid 66623:tid 66814] (20014)Internal error (specific information not available): [client 34.86.30.230:42090] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.108672 2026] [proxy:error] [pid 66623:tid 66814] [client 34.86.30.230:42090] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.mcp.json
[Tue Aug 18 12:58:02.114255 2026] [security2:error] [pid 66623:tid 66790] [client 20.186.30.159:1944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/reviall.php"] [unique_id "aoSBCtO5rbWdOArH04KaLQAAASI"]
[Tue Aug 18 12:58:02.116833 2026] [proxy_http:error] [pid 66623:tid 66797] (20014)Internal error (specific information not available): [client 34.86.30.230:42038] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.116849 2026] [proxy:error] [pid 66623:tid 66797] [client 34.86.30.230:42038] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/cgi-sys/403.html
[Tue Aug 18 12:58:02.124125 2026] [proxy_http:error] [pid 66623:tid 66851] (20014)Internal error (specific information not available): [client 34.86.30.230:42028] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.124139 2026] [proxy:error] [pid 66623:tid 66851] [client 34.86.30.230:42028] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/aws/credentials
[Tue Aug 18 12:58:02.138849 2026] [proxy_http:error] [pid 66623:tid 66778] (20014)Internal error (specific information not available): [client 34.86.30.230:42064] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.138865 2026] [proxy:error] [pid 66623:tid 66778] [client 34.86.30.230:42064] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.git/HEAD
[Tue Aug 18 12:58:02.144225 2026] [security2:error] [pid 66623:tid 66841] [client 68.155.154.236:51415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/mt/byp.php"] [unique_id "aoSBCtO5rbWdOArH04KaLwAAAVU"]
[Tue Aug 18 12:58:02.146695 2026] [proxy_http:error] [pid 66623:tid 66824] (20014)Internal error (specific information not available): [client 34.86.30.230:42022] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.147452 2026] [proxy:error] [pid 66623:tid 66824] [client 34.86.30.230:42022] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.aws/credentials
[Tue Aug 18 12:58:02.151612 2026] [security2:error] [pid 66623:tid 66815] [client 158.23.17.4:34035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/le.php"] [unique_id "aoSBCtO5rbWdOArH04KaMAAAATs"]
[Tue Aug 18 12:58:02.154997 2026] [proxy_http:error] [pid 66623:tid 66810] (20014)Internal error (specific information not available): [client 34.86.30.230:41922] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.155014 2026] [proxy:error] [pid 66623:tid 66810] [client 34.86.30.230:41922] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env
[Tue Aug 18 12:58:02.163532 2026] [security2:error] [pid 66623:tid 66876] [client 138.36.100.162:42581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaMQAAAXg"]
[Tue Aug 18 12:58:02.163666 2026] [security2:error] [pid 66623:tid 66876] [client 138.36.100.162:42581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaMQAAAXg"]
[Tue Aug 18 12:58:02.209392 2026] [security2:error] [pid 66623:tid 66844] [client 20.79.204.6:11687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/abcd.php"] [unique_id "aoSBCtO5rbWdOArH04KaNwAAAVg"]
[Tue Aug 18 12:58:02.228846 2026] [authz_core:error] [pid 66623:tid 66735] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:02.229109 2026] [authz_core:error] [pid 66623:tid 66735] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:02.261153 2026] [security2:error] [pid 66623:tid 66744] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/222.php"] [unique_id "aoSBCtO5rbWdOArH04KaPQABUGs"]
[Tue Aug 18 12:58:02.269015 2026] [security2:error] [pid 66623:tid 66788] [client 74.248.18.37:21547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBCtO5rbWdOArH04KaPgAAASA"]
[Tue Aug 18 12:58:02.270138 2026] [proxy_http:error] [pid 66623:tid 66886] (20014)Internal error (specific information not available): [client 34.86.30.230:42220] AH01102: error reading status line from remote server 127.0.0.1:2095, referer: https://webmail.nightblue.com.br
[Tue Aug 18 12:58:02.270158 2026] [proxy:error] [pid 66623:tid 66886] [client 34.86.30.230:42220] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/v1/graphql, referer: https://webmail.nightblue.com.br
[Tue Aug 18 12:58:02.271334 2026] [security2:error] [pid 66623:tid 66787] [client 20.206.73.37:59843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/133.php"] [unique_id "aoSBCtO5rbWdOArH04KaPwAAAR8"]
[Tue Aug 18 12:58:02.276686 2026] [proxy_http:error] [pid 66623:tid 66889] (20014)Internal error (specific information not available): [client 34.86.30.230:42156] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.276707 2026] [proxy:error] [pid 66623:tid 66889] [client 34.86.30.230:42156] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/fetch
[Tue Aug 18 12:58:02.283437 2026] [proxy_http:error] [pid 66623:tid 66808] (20014)Internal error (specific information not available): [client 34.86.30.230:42040] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.283450 2026] [proxy:error] [pid 66623:tid 66808] [client 34.86.30.230:42040] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/actuator/env
[Tue Aug 18 12:58:02.289467 2026] [security2:error] [pid 66623:tid 66845] [client 20.119.58.187:11975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/IXR/about.php"] [unique_id "aoSBCtO5rbWdOArH04KaQAAAAVk"]
[Tue Aug 18 12:58:02.290380 2026] [proxy_http:error] [pid 66623:tid 66818] (20014)Internal error (specific information not available): [client 34.86.30.230:42138] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.290391 2026] [proxy:error] [pid 66623:tid 66818] [client 34.86.30.230:42138] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/
[Tue Aug 18 12:58:02.297215 2026] [proxy_http:error] [pid 66623:tid 66826] (20014)Internal error (specific information not available): [client 34.86.30.230:41840] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.320414 2026] [proxy_http:error] [pid 66623:tid 66886] (20014)Internal error (specific information not available): [client 34.86.30.230:42220] AH01102: error reading status line from remote server 127.0.0.1:2095, referer: https://webmail.nightblue.com.br
[Tue Aug 18 12:58:02.320433 2026] [proxy:error] [pid 66623:tid 66886] [client 34.86.30.230:42220] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml, referer: https://webmail.nightblue.com.br
[Tue Aug 18 12:58:02.337806 2026] [security2:error] [pid 66623:tid 66879] [client 20.118.172.148:46762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/akc.php"] [unique_id "aoSBCtO5rbWdOArH04KaRQAAAXs"]
[Tue Aug 18 12:58:02.351818 2026] [security2:error] [pid 66623:tid 66667] [remote 57.141.22.9:50662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siderurgiabrasil.com.br"] [uri "/wp-content/ajax-handler.php"] [unique_id "aoSBCtO5rbWdOArH04KaRgABDh4"], referer: https://siderurgiabrasil.com.br/2023/02/27/cresceu-a-producao-de-aco-em-janeiro/
[Tue Aug 18 12:58:02.374037 2026] [autoindex:error] [pid 66623:tid 66875] [client 4.232.151.198:4449] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:02.384301 2026] [security2:error] [pid 66623:tid 66784] [client 20.186.30.159:1941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/nope.php"] [unique_id "aoSBCtO5rbWdOArH04KaSQAAARw"]
[Tue Aug 18 12:58:02.386035 2026] [security2:error] [pid 66623:tid 66857] [client 5.31.227.224:7816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaSgAAAWU"]
[Tue Aug 18 12:58:02.390642 2026] [security2:error] [pid 66623:tid 66857] [client 5.31.227.224:7816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaSgAAAWU"]
[Tue Aug 18 12:58:02.427681 2026] [security2:error] [pid 66623:tid 66830] [client 52.173.121.69:24784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSBCtO5rbWdOArH04KaUAAAAUo"]
[Tue Aug 18 12:58:02.442169 2026] [security2:error] [pid 66623:tid 66644] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/3pjcpmfsd8b.php"] [unique_id "aoSBCtO5rbWdOArH04KaUQABPAc"]
[Tue Aug 18 12:58:02.455309 2026] [security2:error] [pid 66623:tid 66821] [client 20.1.169.243:3673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/www.php"] [unique_id "aoSBCtO5rbWdOArH04KaVAAAAUE"]
[Tue Aug 18 12:58:02.493446 2026] [security2:error] [pid 66623:tid 66853] [client 20.118.172.148:54883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSBCtO5rbWdOArH04KaWAAAAWE"]
[Tue Aug 18 12:58:02.500933 2026] [security2:error] [pid 66623:tid 66657] [remote 52.167.144.230:24617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sindsecurpr.com.br"] [uri "/buy/kitte-letter/inshi/s_list.php"] [unique_id "aoSBCtO5rbWdOArH04KaWwABMxQ"]
[Tue Aug 18 12:58:02.524146 2026] [security2:error] [pid 66623:tid 66802] [client 20.219.2.203:8594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/tool.php"] [unique_id "aoSBCtO5rbWdOArH04KaYQAAAS4"]
[Tue Aug 18 12:58:02.539596 2026] [security2:error] [pid 66623:tid 66772] [client 68.155.154.236:40284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSBCtO5rbWdOArH04KaZQAAARA"]
[Tue Aug 18 12:58:02.554919 2026] [security2:error] [pid 66623:tid 66849] [client 78.46.190.63:10168] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.anzenblindados.com.br"] [uri "/index.php"] [unique_id "aoSBCdO5rbWdOArH04KZrwAAAV0"], referer: https://www.anzenblindados.com.br/
[Tue Aug 18 12:58:02.574577 2026] [security2:error] [pid 66623:tid 66822] [client 213.35.127.232:61763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBCtO5rbWdOArH04KaaQAAAUI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:02.584245 2026] [security2:error] [pid 66623:tid 66811] [client 172.182.217.32:15610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/elp.php"] [unique_id "aoSBCtO5rbWdOArH04KaawAAATc"]
[Tue Aug 18 12:58:02.584748 2026] [security2:error] [pid 66623:tid 66869] [client 74.248.18.37:21555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/v.php"] [unique_id "aoSBCtO5rbWdOArH04KabAAAAXE"]
[Tue Aug 18 12:58:02.586212 2026] [security2:error] [pid 66623:tid 66837] [client 149.34.210.141:59896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KabQAAAVE"]
[Tue Aug 18 12:58:02.588952 2026] [security2:error] [pid 66623:tid 66785] [client 40.74.65.169:29579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSBCtO5rbWdOArH04KabwAAAR0"]
[Tue Aug 18 12:58:02.606457 2026] [security2:error] [pid 66623:tid 66819] [client 34.86.30.230:41922] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/.env.bak"] [unique_id "aoSBCtO5rbWdOArH04KacQAAAT8"]
[Tue Aug 18 12:58:02.607017 2026] [security2:error] [pid 66623:tid 66844] [client 34.86.30.230:41812] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/server/.env"] [unique_id "aoSBCtO5rbWdOArH04KaeQAAAVg"]
[Tue Aug 18 12:58:02.607565 2026] [security2:error] [pid 66623:tid 66844] [client 34.86.30.230:41930] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/admin/.env"] [unique_id "aoSBCtO5rbWdOArH04KafwAAAVg"]
[Tue Aug 18 12:58:02.609134 2026] [security2:error] [pid 66623:tid 66854] [client 34.86.30.230:42004] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/.env.production"] [unique_id "aoSBCtO5rbWdOArH04KagAAAAWI"]
[Tue Aug 18 12:58:02.617574 2026] [proxy_http:error] [pid 66623:tid 66876] (20014)Internal error (specific information not available): [client 34.86.30.230:42116] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.619711 2026] [security2:error] [pid 66623:tid 66805] [client 157.20.138.62:50593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaiAAAATE"]
[Tue Aug 18 12:58:02.619835 2026] [security2:error] [pid 66623:tid 66805] [client 157.20.138.62:50593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaiAAAATE"]
[Tue Aug 18 12:58:02.622770 2026] [security2:error] [pid 66623:tid 66681] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/403.php"] [unique_id "aoSBCtO5rbWdOArH04KaiQABKiw"]
[Tue Aug 18 12:58:02.624411 2026] [proxy_http:error] [pid 66623:tid 66815] (20014)Internal error (specific information not available): [client 34.86.30.230:42064] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.631761 2026] [proxy_http:error] [pid 66623:tid 66775] (20014)Internal error (specific information not available): [client 34.86.30.230:42124] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.637762 2026] [proxy_http:error] [pid 66623:tid 66792] (20014)Internal error (specific information not available): [client 34.86.30.230:41996] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.644847 2026] [proxy_http:error] [pid 66623:tid 66882] (20014)Internal error (specific information not available): [client 34.86.30.230:41824] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.651553 2026] [proxy_http:error] [pid 66623:tid 66858] (20014)Internal error (specific information not available): [client 34.86.30.230:41972] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.659118 2026] [security2:error] [pid 66623:tid 66861] [client 20.119.58.187:12060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/pomo/about.php"] [unique_id "aoSBCtO5rbWdOArH04KaigAAAWk"]
[Tue Aug 18 12:58:02.659170 2026] [proxy_http:error] [pid 66623:tid 66866] (20014)Internal error (specific information not available): [client 34.86.30.230:42236] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.665873 2026] [proxy_http:error] [pid 66623:tid 66832] (20014)Internal error (specific information not available): [client 34.86.30.230:42028] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.672075 2026] [security2:error] [pid 66623:tid 66787] [client 40.74.65.169:49086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBCtO5rbWdOArH04KaiwAAAR8"]
[Tue Aug 18 12:58:02.672386 2026] [proxy_http:error] [pid 66623:tid 66892] (20014)Internal error (specific information not available): [client 34.86.30.230:41948] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.672464 2026] [security2:error] [pid 66623:tid 66864] [client 20.48.236.86:25981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBCtO5rbWdOArH04KajAAAAWw"]
[Tue Aug 18 12:58:02.679565 2026] [proxy_http:error] [pid 66623:tid 66836] (20014)Internal error (specific information not available): [client 34.86.30.230:41942] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.687787 2026] [security2:error] [pid 66623:tid 66881] [client 34.86.30.230:41906] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/aws/credentials.json"] [unique_id "aoSBCtO5rbWdOArH04KajQAAAX0"]
[Tue Aug 18 12:58:02.730605 2026] [security2:error] [pid 66623:tid 66820] [client 20.118.172.148:19696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSBCtO5rbWdOArH04KakQAAAUA"]
[Tue Aug 18 12:58:02.751769 2026] [security2:error] [pid 66623:tid 66810] [client 20.203.138.185:11218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/moon3.php"] [unique_id "aoSBCtO5rbWdOArH04KalAAAATY"]
[Tue Aug 18 12:58:02.765054 2026] [autoindex:error] [pid 66623:tid 66828] [client 158.158.74.177:26135] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:02.802735 2026] [security2:error] [pid 66623:tid 66668] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/404.php"] [unique_id "aoSBCtO5rbWdOArH04KalwABRx8"]
[Tue Aug 18 12:58:02.812704 2026] [security2:error] [pid 66623:tid 66804] [client 20.79.204.6:11683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/admin.php"] [unique_id "aoSBCtO5rbWdOArH04KamAAAATA"]
[Tue Aug 18 12:58:02.820981 2026] [security2:error] [pid 66623:tid 66795] [client 20.1.169.243:3397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/x.php"] [unique_id "aoSBCtO5rbWdOArH04KamQAAASc"]
[Tue Aug 18 12:58:02.835204 2026] [security2:error] [pid 66623:tid 66849] [client 4.232.151.198:4449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSBCtO5rbWdOArH04KamwAAAV0"]
[Tue Aug 18 12:58:02.835517 2026] [authz_core:error] [pid 66623:tid 66733] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:02.835772 2026] [authz_core:error] [pid 66623:tid 66733] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:02.858292 2026] [security2:error] [pid 66623:tid 66837] [client 149.34.210.141:59896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KabQAAAVE"]
[Tue Aug 18 12:58:02.892632 2026] [security2:error] [pid 66623:tid 66808] [client 34.86.30.230:31158] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/home/node/.aws/credentials"] [unique_id "aoSBCtO5rbWdOArH04KaoQAAATQ"]
[Tue Aug 18 12:58:02.899791 2026] [proxy_http:error] [pid 66623:tid 66818] (20014)Internal error (specific information not available): [client 34.86.30.230:31174] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.899809 2026] [proxy:error] [pid 66623:tid 66818] [client 34.86.30.230:31174] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/root/.aws/credentials
[Tue Aug 18 12:58:02.906745 2026] [proxy_http:error] [pid 66623:tid 66886] (20014)Internal error (specific information not available): [client 34.86.30.230:31144] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.906764 2026] [proxy:error] [pid 66623:tid 66886] [client 34.86.30.230:31144] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/@fs/home/ec2-user/.aws/credentials
[Tue Aug 18 12:58:02.907007 2026] [core:error] [pid 66623:tid 66839] [client 34.86.30.230:31104] AH10244: invalid URI path (/assets../../../.env)
[Tue Aug 18 12:58:02.907383 2026] [security2:error] [pid 66623:tid 66813] [client 20.100.185.105:60274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-includes/index.php"] [unique_id "aoSBCtO5rbWdOArH04KapwAAATk"]
[Tue Aug 18 12:58:02.907906 2026] [security2:error] [pid 66623:tid 66843] [client 223.185.37.47:21916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaqAAAAVc"]
[Tue Aug 18 12:58:02.908107 2026] [security2:error] [pid 66623:tid 66843] [client 223.185.37.47:21916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaqAAAAVc"]
[Tue Aug 18 12:58:02.909233 2026] [security2:error] [pid 66623:tid 66789] [client 34.86.30.230:31130] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/root/.aws/credentials"] [unique_id "aoSBCtO5rbWdOArH04KaqQAAASE"]
[Tue Aug 18 12:58:02.910106 2026] [security2:error] [pid 66623:tid 66840] [client 34.86.30.230:31054] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/backend/.aws/credentials"] [unique_id "aoSBCtO5rbWdOArH04KarQAAAVQ"]
[Tue Aug 18 12:58:02.913525 2026] [proxy_http:error] [pid 66623:tid 66818] (20014)Internal error (specific information not available): [client 34.86.30.230:31174] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.913538 2026] [proxy:error] [pid 66623:tid 66818] [client 34.86.30.230:31174] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml
[Tue Aug 18 12:58:02.920710 2026] [proxy_http:error] [pid 66623:tid 66886] (20014)Internal error (specific information not available): [client 34.86.30.230:31144] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.920838 2026] [proxy:error] [pid 66623:tid 66886] [client 34.86.30.230:31144] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml
[Tue Aug 18 12:58:02.921279 2026] [security2:error] [pid 66623:tid 66876] [client 20.186.30.159:1693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/nope.php"] [unique_id "aoSBCtO5rbWdOArH04KatAAAAXg"]
[Tue Aug 18 12:58:02.928389 2026] [proxy_http:error] [pid 66623:tid 66893] (20014)Internal error (specific information not available): [client 34.86.30.230:31066] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.928405 2026] [proxy:error] [pid 66623:tid 66893] [client 34.86.30.230:31066] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/home/ubuntu/.aws/credentials
[Tue Aug 18 12:58:02.934544 2026] [proxy_http:error] [pid 66623:tid 66821] (20014)Internal error (specific information not available): [client 34.86.30.230:31102] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.934560 2026] [proxy:error] [pid 66623:tid 66821] [client 34.86.30.230:31102] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/_next/.env
[Tue Aug 18 12:58:02.940630 2026] [proxy_http:error] [pid 66623:tid 66859] (20014)Internal error (specific information not available): [client 34.86.30.230:31080] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.940666 2026] [proxy:error] [pid 66623:tid 66859] [client 34.86.30.230:31080] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env
[Tue Aug 18 12:58:02.947585 2026] [proxy_http:error] [pid 66623:tid 66781] (20014)Internal error (specific information not available): [client 34.86.30.230:31042] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.947608 2026] [proxy:error] [pid 66623:tid 66781] [client 34.86.30.230:31042] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/home/node/.aws/credentials
[Tue Aug 18 12:58:02.952461 2026] [security2:error] [pid 66623:tid 66841] [client 34.86.30.230:42194] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBCtO5rbWdOArH04KauQAAAVU"]
[Tue Aug 18 12:58:02.954322 2026] [proxy_http:error] [pid 66623:tid 66893] (20014)Internal error (specific information not available): [client 34.86.30.230:31066] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.954336 2026] [proxy:error] [pid 66623:tid 66893] [client 34.86.30.230:31066] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml
[Tue Aug 18 12:58:02.958402 2026] [security2:error] [pid 66623:tid 66882] [client 52.173.121.69:17932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSBCtO5rbWdOArH04KaugAAAX4"]
[Tue Aug 18 12:58:02.960236 2026] [security2:error] [pid 66623:tid 66814] [client 74.248.18.37:7221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/item.php"] [unique_id "aoSBCtO5rbWdOArH04KavAAAATo"]
[Tue Aug 18 12:58:02.973167 2026] [proxy_http:error] [pid 66623:tid 66858] (20014)Internal error (specific information not available): [client 34.86.30.230:42156] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:02.984636 2026] [security2:error] [pid 66623:tid 66675] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/4mosan.php"] [unique_id "aoSBCtO5rbWdOArH04KavgABFyY"]
[Tue Aug 18 12:58:03.015420 2026] [security2:error] [pid 66623:tid 66785] [client 20.119.58.187:11852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/updraft/about.php"] [unique_id "aoSBC9O5rbWdOArH04KawQAAAR0"]
[Tue Aug 18 12:58:03.017405 2026] [security2:error] [pid 66623:tid 66872] [client 158.158.74.177:26135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSBC9O5rbWdOArH04KawgAAAXQ"]
[Tue Aug 18 12:58:03.025176 2026] [proxy_http:error] [pid 66623:tid 66881] (20014)Internal error (specific information not available): [client 34.86.30.230:42012] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.033461 2026] [proxy_http:error] [pid 66623:tid 66833] (20014)Internal error (specific information not available): [client 34.86.30.230:31088] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.033480 2026] [proxy:error] [pid 66623:tid 66833] [client 34.86.30.230:31088] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/fetch
[Tue Aug 18 12:58:03.040703 2026] [proxy_http:error] [pid 66623:tid 66833] (20014)Internal error (specific information not available): [client 34.86.30.230:31088] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.040732 2026] [proxy:error] [pid 66623:tid 66833] [client 34.86.30.230:31088] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml
[Tue Aug 18 12:58:03.044855 2026] [security2:error] [pid 66623:tid 66770] [client 68.155.154.236:8006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBC9O5rbWdOArH04KaygAAAQ4"]
[Tue Aug 18 12:58:03.047498 2026] [security2:error] [pid 66623:tid 66856] [client 3.77.67.4:52986] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "siderurgiabrasil.com.br"] [uri "/index.php"] [unique_id "aoSBCtO5rbWdOArH04KanQAAAWQ"], referer: https://siderurgiabrasil.com.br
[Tue Aug 18 12:58:03.048007 2026] [proxy_http:error] [pid 66623:tid 66824] (20014)Internal error (specific information not available): [client 34.86.30.230:42210] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.055480 2026] [proxy_http:error] [pid 66623:tid 66887] (20014)Internal error (specific information not available): [client 34.86.30.230:42104] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.061936 2026] [proxy_http:error] [pid 66623:tid 66875] (20014)Internal error (specific information not available): [client 34.86.30.230:42220] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.068369 2026] [proxy_http:error] [pid 66623:tid 66852] (20014)Internal error (specific information not available): [client 34.86.30.230:42040] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.091997 2026] [security2:error] [pid 66623:tid 66829] [client 158.23.17.4:57230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/hr.php"] [unique_id "aoSBC9O5rbWdOArH04Ka0gAAAUk"]
[Tue Aug 18 12:58:03.094880 2026] [security2:error] [pid 66623:tid 66788] [client 172.182.217.32:15766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/Exception-class.php"] [unique_id "aoSBC9O5rbWdOArH04Ka0wAAASA"]
[Tue Aug 18 12:58:03.100061 2026] [security2:error] [pid 66623:tid 66804] [client 68.155.155.199:4366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/.trash7206/index.php"] [unique_id "aoSBC9O5rbWdOArH04Ka1AAAATA"]
[Tue Aug 18 12:58:03.140196 2026] [security2:error] [pid 66623:tid 66793] [client 34.86.30.230:31172] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/google-services.json"] [unique_id "aoSBC9O5rbWdOArH04Ka2AAAASU"]
[Tue Aug 18 12:58:03.140483 2026] [security2:error] [pid 66623:tid 66786] [client 34.86.30.230:31120] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/fetch"] [unique_id "aoSBC9O5rbWdOArH04Ka2QAAAR4"]
[Tue Aug 18 12:58:03.141061 2026] [authz_core:error] [pid 66623:tid 66713] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:03.141344 2026] [authz_core:error] [pid 66623:tid 66713] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:03.161734 2026] [security2:error] [pid 66623:tid 66682] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/504.php"] [unique_id "aoSBC9O5rbWdOArH04Ka4QABNy0"]
[Tue Aug 18 12:58:03.163212 2026] [proxy_http:error] [pid 66623:tid 66799] (20014)Internal error (specific information not available): [client 34.86.30.230:31058] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.169879 2026] [proxy_http:error] [pid 66623:tid 66822] (20014)Internal error (specific information not available): [client 34.86.30.230:31174] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.171151 2026] [security2:error] [pid 66623:tid 66831] [client 34.86.30.230:31102] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/__env.js"] [unique_id "aoSBC9O5rbWdOArH04Ka5AAAAUs"]
[Tue Aug 18 12:58:03.177212 2026] [proxy_http:error] [pid 66623:tid 66869] (20014)Internal error (specific information not available): [client 34.86.30.230:31066] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.184233 2026] [proxy_http:error] [pid 66623:tid 66813] (20014)Internal error (specific information not available): [client 34.86.30.230:42170] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.186101 2026] [security2:error] [pid 66623:tid 66816] [client 20.1.169.243:3415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSBC9O5rbWdOArH04Ka5wAAATw"]
[Tue Aug 18 12:58:03.190953 2026] [proxy_http:error] [pid 66623:tid 66789] (20014)Internal error (specific information not available): [client 34.86.30.230:42138] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.210311 2026] [security2:error] [pid 66623:tid 66839] [client 34.86.30.230:31088] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/actuator/logfile"] [unique_id "aoSBC9O5rbWdOArH04Ka7AAAAVM"]
[Tue Aug 18 12:58:03.212613 2026] [proxy_http:error] [pid 66623:tid 66889] (20014)Internal error (specific information not available): [client 34.86.30.230:42090] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.240045 2026] [security2:error] [pid 66623:tid 66893] [client 34.86.30.230:41844] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/fetch"] [unique_id "aoSBC9O5rbWdOArH04Ka7gAAAYk"]
[Tue Aug 18 12:58:03.241995 2026] [security2:error] [pid 66623:tid 66825] [client 34.86.30.230:42224] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBC9O5rbWdOArH04Ka7wAAAUU"]
[Tue Aug 18 12:58:03.271676 2026] [security2:error] [pid 66623:tid 66871] [client 20.65.98.162:58106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/gm.php"] [unique_id "aoSBC9O5rbWdOArH04Ka8wAAAXM"]
[Tue Aug 18 12:58:03.277463 2026] [security2:error] [pid 66623:tid 66878] [client 74.248.18.37:21550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/v5.php"] [unique_id "aoSBC9O5rbWdOArH04Ka9AAAAXo"]
[Tue Aug 18 12:58:03.287352 2026] [security2:error] [pid 66623:tid 66785] [client 20.118.172.148:43472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/php.php"] [unique_id "aoSBC9O5rbWdOArH04Ka9wAAAR0"]
[Tue Aug 18 12:58:03.338673 2026] [security2:error] [pid 66623:tid 66853] [client 35.219.242.23:42896] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "andradesalescarregamentos.com.br"] [uri "/index.php"] [unique_id "aoSBC9O5rbWdOArH04Ka9gAAAWE"]
[Tue Aug 18 12:58:03.339469 2026] [security2:error] [pid 66623:tid 66688] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/7.php"] [unique_id "aoSBC9O5rbWdOArH04Ka-AABdTM"]
[Tue Aug 18 12:58:03.345086 2026] [security2:error] [pid 66623:tid 66777] [client 34.86.30.230:31036] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/.github/workflows/ci.yml"] [unique_id "aoSBC9O5rbWdOArH04Ka-gAAARU"]
[Tue Aug 18 12:58:03.348044 2026] [security2:error] [pid 66623:tid 66850] [client 40.74.65.169:49049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBC9O5rbWdOArH04Ka-wAAAV4"]
[Tue Aug 18 12:58:03.359227 2026] [proxy_http:error] [pid 66623:tid 66841] (20014)Internal error (specific information not available): [client 34.86.30.230:31168] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.367619 2026] [proxy_http:error] [pid 66623:tid 66772] (20014)Internal error (specific information not available): [client 34.86.30.230:31156] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.377862 2026] [proxy_http:error] [pid 66623:tid 66766] (20014)Internal error (specific information not available): [client 34.86.30.230:31080] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.388904 2026] [security2:error] [pid 66623:tid 66822] [client 34.86.30.230:31052] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/api/file"] [unique_id "aoSBC9O5rbWdOArH04KbAwAAAUI"]
[Tue Aug 18 12:58:03.412399 2026] [security2:error] [pid 66623:tid 66769] [client 20.119.58.187:11842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "aoSBC9O5rbWdOArH04KbBgAAAQ0"]
[Tue Aug 18 12:58:03.412526 2026] [proxy_http:error] [pid 66623:tid 66818] (20014)Internal error (specific information not available): [client 34.86.30.230:31190] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.412542 2026] [proxy:error] [pid 66623:tid 66818] [client 34.86.30.230:31190] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env.old
[Tue Aug 18 12:58:03.414613 2026] [security2:error] [pid 66623:tid 66789] [client 40.74.65.169:11255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSBC9O5rbWdOArH04KbBwAAASE"]
[Tue Aug 18 12:58:03.441989 2026] [authz_core:error] [pid 66623:tid 66738] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:03.442241 2026] [authz_core:error] [pid 66623:tid 66738] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:03.447865 2026] [security2:error] [pid 66623:tid 66779] [client 34.86.30.230:31208] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/fetch"] [unique_id "aoSBC9O5rbWdOArH04KbDgAAARc"]
[Tue Aug 18 12:58:03.458053 2026] [security2:error] [pid 66623:tid 66883] [client 20.118.133.132:14805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBC9O5rbWdOArH04KbEAAAAX8"]
[Tue Aug 18 12:58:03.461727 2026] [security2:error] [pid 66623:tid 66790] [client 20.219.2.203:7307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/up.php"] [unique_id "aoSBC9O5rbWdOArH04KbEgAAASI"]
[Tue Aug 18 12:58:03.468293 2026] [proxy_http:error] [pid 66623:tid 66775] (20014)Internal error (specific information not available): [client 34.86.30.230:31220] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.468309 2026] [proxy:error] [pid 66623:tid 66775] [client 34.86.30.230:31220] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/web/.env
[Tue Aug 18 12:58:03.474134 2026] [security2:error] [pid 66623:tid 66882] [client 20.203.138.185:35010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/opts.php"] [unique_id "aoSBC9O5rbWdOArH04KbFgAAAX4"]
[Tue Aug 18 12:58:03.475323 2026] [proxy_http:error] [pid 66623:tid 66775] (20014)Internal error (specific information not available): [client 34.86.30.230:31220] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.475336 2026] [proxy:error] [pid 66623:tid 66775] [client 34.86.30.230:31220] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml
[Tue Aug 18 12:58:03.477194 2026] [security2:error] [pid 66623:tid 66781] [client 20.186.30.159:1978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/new.php"] [unique_id "aoSBC9O5rbWdOArH04KbFwAAARk"]
[Tue Aug 18 12:58:03.481643 2026] [autoindex:error] [pid 66623:tid 66814] [client 4.232.151.198:24933] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/images/media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:03.497497 2026] [security2:error] [pid 66623:tid 66872] [client 34.86.30.230:31272] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/fetch"] [unique_id "aoSBC9O5rbWdOArH04KbIgAAAXQ"]
[Tue Aug 18 12:58:03.503938 2026] [security2:error] [pid 66623:tid 66810] [client 34.86.30.230:31340] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBC9O5rbWdOArH04KbIwAAATY"]
[Tue Aug 18 12:58:03.520005 2026] [security2:error] [pid 66623:tid 66819] [client 68.155.154.236:7637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBC9O5rbWdOArH04KbJAAAAT8"]
[Tue Aug 18 12:58:03.520278 2026] [security2:error] [pid 66623:tid 66712] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/8.php"] [unique_id "aoSBC9O5rbWdOArH04KbJQABg0s"]
[Tue Aug 18 12:58:03.520446 2026] [security2:error] [pid 66623:tid 66884] [client 178.153.171.161:23814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBC9O5rbWdOArH04KbJgAAAYA"]
[Tue Aug 18 12:58:03.520572 2026] [security2:error] [pid 66623:tid 66884] [client 178.153.171.161:23814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBC9O5rbWdOArH04KbJgAAAYA"]
[Tue Aug 18 12:58:03.551127 2026] [security2:error] [pid 66623:tid 66805] [client 20.1.169.243:3652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/aaa.php"] [unique_id "aoSBC9O5rbWdOArH04KbLgAAATE"]
[Tue Aug 18 12:58:03.558177 2026] [security2:error] [pid 66623:tid 66888] [client 20.100.185.105:60280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-includes/Text/about.php"] [unique_id "aoSBC9O5rbWdOArH04KbMAAAAYQ"]
[Tue Aug 18 12:58:03.586566 2026] [security2:error] [pid 66623:tid 66830] [client 172.182.217.32:15590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/ee.php"] [unique_id "aoSBC9O5rbWdOArH04KbNgAAAUo"]
[Tue Aug 18 12:58:03.592691 2026] [security2:error] [pid 66623:tid 66821] [client 213.35.127.232:61974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBC9O5rbWdOArH04KbNwAAAUE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:03.595926 2026] [proxy_http:error] [pid 66623:tid 66881] (20014)Internal error (specific information not available): [client 34.86.30.230:31312] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.595941 2026] [proxy:error] [pid 66623:tid 66881] [client 34.86.30.230:31312] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/fetch
[Tue Aug 18 12:58:03.603322 2026] [proxy_http:error] [pid 66623:tid 66832] (20014)Internal error (specific information not available): [client 34.86.30.230:31298] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.603358 2026] [proxy:error] [pid 66623:tid 66832] [client 34.86.30.230:31298] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/debug/default/view
[Tue Aug 18 12:58:03.604792 2026] [security2:error] [pid 66623:tid 66677] [remote 173.252.70.12:44088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.70.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hotelvipempresas.com.br"] [uri "/site/
Warning:%20%20Undefined%20variable%20$onde%20in%20/home1/hotelvip/public_html/site/includes/menu.php%20on%20line%205
conteudo/hoteis"] [unique_id "aoSBC9O5rbWdOArH04KbDQABcig"]
[Tue Aug 18 12:58:03.607961 2026] [security2:error] [pid 66623:tid 66701] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBC9O5rbWdOArH04KbOgABQEA"]
[Tue Aug 18 12:58:03.608120 2026] [security2:error] [pid 66623:tid 66820] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBC9O5rbWdOArH04KbOgABQEA"]
[Tue Aug 18 12:58:03.608876 2026] [security2:error] [pid 66623:tid 66877] [client 158.158.34.183:34344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/flower.php"] [unique_id "aoSBC9O5rbWdOArH04KbOwAAAXk"]
[Tue Aug 18 12:58:03.610541 2026] [proxy_http:error] [pid 66623:tid 66845] (20014)Internal error (specific information not available): [client 34.86.30.230:31242] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.610560 2026] [proxy:error] [pid 66623:tid 66845] [client 34.86.30.230:31242] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/runtime-config.js
[Tue Aug 18 12:58:03.617043 2026] [proxy_http:error] [pid 66623:tid 66810] (20014)Internal error (specific information not available): [client 34.86.30.230:31340] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.617065 2026] [proxy:error] [pid 66623:tid 66810] [client 34.86.30.230:31340] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/cgi-sys/403.html
[Tue Aug 18 12:58:03.618332 2026] [security2:error] [pid 66623:tid 66789] [client 20.118.172.148:63052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/t.php"] [unique_id "aoSBC9O5rbWdOArH04KbPgAAASE"]
[Tue Aug 18 12:58:03.624916 2026] [proxy_http:error] [pid 66623:tid 66849] (20014)Internal error (specific information not available): [client 34.86.30.230:31452] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.624933 2026] [proxy:error] [pid 66623:tid 66849] [client 34.86.30.230:31452] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/read
[Tue Aug 18 12:58:03.633047 2026] [proxy_http:error] [pid 66623:tid 66862] (20014)Internal error (specific information not available): [client 34.86.30.230:31474] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.633072 2026] [proxy:error] [pid 66623:tid 66862] [client 34.86.30.230:31474] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/fetch
[Tue Aug 18 12:58:03.661422 2026] [security2:error] [pid 66623:tid 66773] [client 74.248.18.37:54975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/js.php"] [unique_id "aoSBC9O5rbWdOArH04KbQQAAARE"]
[Tue Aug 18 12:58:03.689843 2026] [security2:error] [pid 66623:tid 66783] [client 4.232.151.198:24933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBC9O5rbWdOArH04KbQwAAARs"]
[Tue Aug 18 12:58:03.697956 2026] [security2:error] [pid 66623:tid 66779] [client 20.48.236.86:2362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBC9O5rbWdOArH04KbRAAAARc"]
[Tue Aug 18 12:58:03.698687 2026] [security2:error] [pid 66623:tid 66687] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/82.php"] [unique_id "aoSBC9O5rbWdOArH04KbRQABhjI"]
[Tue Aug 18 12:58:03.781864 2026] [security2:error] [pid 66623:tid 66886] [client 20.119.58.187:11846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/images/about.php"] [unique_id "aoSBC9O5rbWdOArH04KbSwAAAYI"]
[Tue Aug 18 12:58:03.788068 2026] [security2:error] [pid 66623:tid 66794] [client 34.86.30.230:31518] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBC9O5rbWdOArH04KbTAAAASY"]
[Tue Aug 18 12:58:03.824184 2026] [proxy_http:error] [pid 66623:tid 66816] (20014)Internal error (specific information not available): [client 34.86.30.230:31478] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:03.824201 2026] [proxy:error] [pid 66623:tid 66816] [client 34.86.30.230:31478] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/proxy
[Tue Aug 18 12:58:03.876052 2026] [security2:error] [pid 66623:tid 66719] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/a.php"] [unique_id "aoSBC9O5rbWdOArH04KbWAABI1I"]
[Tue Aug 18 12:58:03.908939 2026] [security2:error] [pid 66623:tid 66789] [client 158.23.17.4:12495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/kt.php"] [unique_id "aoSBC9O5rbWdOArH04KbXwAAASE"]
[Tue Aug 18 12:58:03.914840 2026] [security2:error] [pid 66623:tid 66825] [client 20.1.169.243:3705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/fpwch.php"] [unique_id "aoSBC9O5rbWdOArH04KbYAAAAUU"]
[Tue Aug 18 12:58:03.916054 2026] [security2:error] [pid 66623:tid 66874] [client 20.203.183.135:42481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/blurbs.php"] [unique_id "aoSBC9O5rbWdOArH04KbYgAAAXY"]
[Tue Aug 18 12:58:03.932322 2026] [security2:error] [pid 66623:tid 66885] [client 34.86.30.230:31678] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBC9O5rbWdOArH04KbZAAAAYE"]
[Tue Aug 18 12:58:03.952317 2026] [security2:error] [pid 66623:tid 66849] [client 20.118.172.148:50062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/index/function.php"] [unique_id "aoSBC9O5rbWdOArH04KbZgAAAV0"]
[Tue Aug 18 12:58:03.956163 2026] [security2:error] [pid 66623:tid 66775] [client 74.248.18.37:54924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/we.php"] [unique_id "aoSBC9O5rbWdOArH04KbaAAAARM"]
[Tue Aug 18 12:58:04.026762 2026] [security2:error] [pid 66623:tid 66882] [client 34.86.30.230:31226] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/api/fetch"] [unique_id "aoSBDNO5rbWdOArH04KbcQAAAX4"]
[Tue Aug 18 12:58:04.029042 2026] [security2:error] [pid 66623:tid 66873] [client 158.158.74.177:22745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSBDNO5rbWdOArH04KbcgAAAXU"]
[Tue Aug 18 12:58:04.039171 2026] [authz_core:error] [pid 66623:tid 66694] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:04.039439 2026] [authz_core:error] [pid 66623:tid 66694] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:04.048149 2026] [security2:error] [pid 66623:tid 66781] [client 40.74.65.169:64254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/media.php"] [unique_id "aoSBDNO5rbWdOArH04KbdQAAARk"]
[Tue Aug 18 12:58:04.049179 2026] [security2:error] [pid 66623:tid 66814] [client 20.186.30.159:1700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/new.php"] [unique_id "aoSBDNO5rbWdOArH04KbdgAAATo"]
[Tue Aug 18 12:58:04.049201 2026] [proxy_http:error] [pid 66623:tid 66802] (20014)Internal error (specific information not available): [client 34.86.30.230:31312] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:04.059434 2026] [security2:error] [pid 66623:tid 66643] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/aa.php"] [unique_id "aoSBDNO5rbWdOArH04KbeAABHQY"]
[Tue Aug 18 12:58:04.061766 2026] [security2:error] [pid 66623:tid 66720] [remote 138.68.158.60:45432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.158.68.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viniciushartl.com.br"] [uri "/wp-login.php"] [unique_id "aoSBDNO5rbWdOArH04KbdwABc1M"]
[Tue Aug 18 12:58:04.092480 2026] [security2:error] [pid 66623:tid 66811] [client 172.182.217.32:12243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/edit.php"] [unique_id "aoSBDNO5rbWdOArH04KbfQAAATc"]
[Tue Aug 18 12:58:04.117001 2026] [security2:error] [pid 66623:tid 66884] [client 68.155.155.199:13345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSBDNO5rbWdOArH04KbfwAAAYA"]
[Tue Aug 18 12:58:04.118800 2026] [security2:error] [pid 66623:tid 66794] [client 68.155.154.236:46617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBDNO5rbWdOArH04KbgAAAASY"]
[Tue Aug 18 12:58:04.140675 2026] [security2:error] [pid 66623:tid 66779] [client 20.119.58.187:11851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "aoSBDNO5rbWdOArH04KbgQAAARc"]
[Tue Aug 18 12:58:04.155331 2026] [security2:error] [pid 66623:tid 66862] [client 20.100.185.105:63291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/403.php"] [unique_id "aoSBDNO5rbWdOArH04KbggAAAWo"]
[Tue Aug 18 12:58:04.218572 2026] [security2:error] [pid 66623:tid 66816] [client 34.86.30.230:31478] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/api/proxy"] [unique_id "aoSBDNO5rbWdOArH04KbiQAAATw"]
[Tue Aug 18 12:58:04.238846 2026] [security2:error] [pid 66623:tid 66676] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/aaa.php"] [unique_id "aoSBDNO5rbWdOArH04KbigABECc"]
[Tue Aug 18 12:58:04.256705 2026] [security2:error] [pid 66623:tid 66791] [client 20.118.172.148:62402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBDNO5rbWdOArH04KbjQAAASM"]
[Tue Aug 18 12:58:04.284355 2026] [security2:error] [pid 66623:tid 66722] [remote 136.110.27.48:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.martinmadeireira.com.br"] [uri "/config/.env.php"] [unique_id "aoSBDNO5rbWdOArH04KbjwABeVU"]
[Tue Aug 18 12:58:04.284581 2026] [security2:error] [pid 66623:tid 66789] [client 34.86.30.230:31200] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBDNO5rbWdOArH04KbkQAAASE"]
[Tue Aug 18 12:58:04.291388 2026] [security2:error] [pid 66623:tid 66833] [client 34.86.30.230:31438] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/api/v1/fetch"] [unique_id "aoSBDNO5rbWdOArH04KbkgAAAU0"]
[Tue Aug 18 12:58:04.307968 2026] [security2:error] [pid 66623:tid 66887] [client 4.232.151.198:24946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSBDNO5rbWdOArH04KblwAAAYM"]
[Tue Aug 18 12:58:04.310879 2026] [security2:error] [pid 66623:tid 66886] [client 74.248.18.37:54962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/k.php"] [unique_id "aoSBDNO5rbWdOArH04KbmAAAAYI"]
[Tue Aug 18 12:58:04.340402 2026] [authz_core:error] [pid 66623:tid 66751] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:04.340665 2026] [authz_core:error] [pid 66623:tid 66751] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:04.344419 2026] [security2:error] [pid 66623:tid 66775] [client 40.74.65.169:35723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSBDNO5rbWdOArH04KbnAAAARM"]
[Tue Aug 18 12:58:04.375913 2026] [security2:error] [pid 66623:tid 66810] [client 20.186.30.159:1983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/apreset.php"] [unique_id "aoSBDNO5rbWdOArH04KboAAAATY"]
[Tue Aug 18 12:58:04.381545 2026] [security2:error] [pid 66623:tid 66742] [remote 136.110.27.48:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.martinmadeireira.com.br"] [uri "/.env.php.bak"] [unique_id "aoSBDNO5rbWdOArH04KboQABUmk"]
[Tue Aug 18 12:58:04.388710 2026] [security2:error] [pid 66623:tid 66858] [client 85.154.68.202:56068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBDNO5rbWdOArH04KbowAAAWY"]
[Tue Aug 18 12:58:04.388830 2026] [security2:error] [pid 66623:tid 66858] [client 85.154.68.202:56068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBDNO5rbWdOArH04KbowAAAWY"]
[Tue Aug 18 12:58:04.391920 2026] [security2:error] [pid 66623:tid 66771] [client 20.219.2.203:7309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/w.php"] [unique_id "aoSBDNO5rbWdOArH04KbpAAAAQ8"]
[Tue Aug 18 12:58:04.400457 2026] [proxy_http:error] [pid 66623:tid 66800] (20014)Internal error (specific information not available): [client 34.86.30.230:31598] AH01102: error reading status line from remote server 127.0.0.1:2095, referer: https://webmail.nightblue.com.br/proxy?url=http%3A%2F%2F169.254.169.254%2Flatest%2Fmeta-data%2F
[Tue Aug 18 12:58:04.400471 2026] [proxy:error] [pid 66623:tid 66800] [client 34.86.30.230:31598] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/proxy, referer: https://webmail.nightblue.com.br/proxy?url=http%3A%2F%2F169.254.169.254%2Flatest%2Fmeta-data%2F
[Tue Aug 18 12:58:04.406897 2026] [proxy_http:error] [pid 66623:tid 66796] (20014)Internal error (specific information not available): [client 34.86.30.230:31614] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:04.406914 2026] [proxy:error] [pid 66623:tid 66796] [client 34.86.30.230:31614] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/api/download
[Tue Aug 18 12:58:04.413863 2026] [proxy_http:error] [pid 66623:tid 66800] (20014)Internal error (specific information not available): [client 34.86.30.230:31598] AH01102: error reading status line from remote server 127.0.0.1:2095, referer: https://webmail.nightblue.com.br/proxy?url=http%3A%2F%2F169.254.169.254%2Flatest%2Fmeta-data%2F
[Tue Aug 18 12:58:04.413889 2026] [proxy:error] [pid 66623:tid 66800] [client 34.86.30.230:31598] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml, referer: https://webmail.nightblue.com.br/proxy?url=http%3A%2F%2F169.254.169.254%2Flatest%2Fmeta-data%2F
[Tue Aug 18 12:58:04.416830 2026] [security2:error] [pid 66623:tid 66745] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/aar.php"] [unique_id "aoSBDNO5rbWdOArH04KbpQABImw"]
[Tue Aug 18 12:58:04.420096 2026] [security2:error] [pid 66623:tid 66861] [client 20.118.172.148:43500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wk/index.php"] [unique_id "aoSBDNO5rbWdOArH04KbpgAAAWk"]
[Tue Aug 18 12:58:04.455695 2026] [security2:error] [pid 66623:tid 66788] [client 34.86.30.230:31600] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBDNO5rbWdOArH04KbqgAAASA"]
[Tue Aug 18 12:58:04.498066 2026] [security2:error] [pid 66623:tid 66818] [client 20.119.58.187:12090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/about.php"] [unique_id "aoSBDNO5rbWdOArH04KbrwAAAT4"]
[Tue Aug 18 12:58:04.540859 2026] [security2:error] [pid 66623:tid 66843] [client 79.127.164.8:52390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/phpmyadmin.sql"] [unique_id "aoSBDNO5rbWdOArH04KbtAAAAVc"], referer: https://medihub.com.br/phpmyadmin.sql
[Tue Aug 18 12:58:04.555327 2026] [security2:error] [pid 66623:tid 66804] [client 34.86.30.230:31254] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/preview"] [unique_id "aoSBDNO5rbWdOArH04KbtQAAATA"]
[Tue Aug 18 12:58:04.563841 2026] [proxy_http:error] [pid 66623:tid 66829] (20014)Internal error (specific information not available): [client 34.86.30.230:31474] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:04.582477 2026] [security2:error] [pid 66623:tid 66873] [client 172.182.217.32:15795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/f35.php"] [unique_id "aoSBDNO5rbWdOArH04KbuwAAAXU"]
[Tue Aug 18 12:58:04.604216 2026] [security2:error] [pid 66623:tid 66766] [client 213.35.127.232:62178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBDNO5rbWdOArH04KbvQAAAQo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:04.609266 2026] [security2:error] [pid 66623:tid 66888] [client 20.203.138.185:50247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/zwq13.php"] [unique_id "aoSBDNO5rbWdOArH04KbvgAAAYQ"]
[Tue Aug 18 12:58:04.609768 2026] [security2:error] [pid 66623:tid 66815] [client 74.248.18.37:7169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wkl.php"] [unique_id "aoSBDNO5rbWdOArH04KbwAAAATs"]
[Tue Aug 18 12:58:04.609875 2026] [security2:error] [pid 66623:tid 66710] [remote 136.110.27.48:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.martinmadeireira.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSBDNO5rbWdOArH04KbvwABEEk"]
[Tue Aug 18 12:58:04.628182 2026] [security2:error] [pid 66623:tid 66732] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/ab.php"] [unique_id "aoSBDNO5rbWdOArH04KbxQABZV8"]
[Tue Aug 18 12:58:04.633088 2026] [security2:error] [pid 66623:tid 66856] [client 68.155.154.236:8031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBDNO5rbWdOArH04KbxgAAAWQ"]
[Tue Aug 18 12:58:04.636157 2026] [security2:error] [pid 66623:tid 66841] [client 34.86.30.230:31642] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBDNO5rbWdOArH04KbxwAAAVU"]
[Tue Aug 18 12:58:04.641587 2026] [security2:error] [pid 66623:tid 66826] [client 20.186.30.159:1968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/1mage.php"] [unique_id "aoSBDNO5rbWdOArH04KbygAAAUY"]
[Tue Aug 18 12:58:04.644316 2026] [security2:error] [pid 66623:tid 66764] [remote 136.110.27.48:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.martinmadeireira.com.br"] [uri "/config.php.bak"] [unique_id "aoSBDNO5rbWdOArH04KbzAABbX8"]
[Tue Aug 18 12:58:04.647614 2026] [authz_core:error] [pid 66623:tid 66644] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:04.647895 2026] [authz_core:error] [pid 66623:tid 66644] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:04.652133 2026] [security2:error] [pid 66623:tid 66791] [client 34.86.30.230:31586] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/image"] [unique_id "aoSBDNO5rbWdOArH04KbzQAAASM"]
[Tue Aug 18 12:58:04.681911 2026] [security2:error] [pid 66623:tid 66769] [client 158.158.34.183:31101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/class-IXR-encryption.php"] [unique_id "aoSBDNO5rbWdOArH04Kb0gAAAQ0"]
[Tue Aug 18 12:58:04.722799 2026] [security2:error] [pid 66623:tid 66887] [client 40.74.65.169:49109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/admin.php"] [unique_id "aoSBDNO5rbWdOArH04Kb2QAAAYM"]
[Tue Aug 18 12:58:04.731109 2026] [security2:error] [pid 66623:tid 66810] [client 158.23.17.4:34043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ww.php"] [unique_id "aoSBDNO5rbWdOArH04Kb3QAAATY"]
[Tue Aug 18 12:58:04.753295 2026] [proxy_http:error] [pid 66623:tid 66774] (20014)Internal error (specific information not available): [client 34.86.30.230:31598] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:04.780478 2026] [security2:error] [pid 66623:tid 66837] [client 20.100.185.105:18295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "aoSBDNO5rbWdOArH04Kb3gAAAVE"]
[Tue Aug 18 12:58:04.811525 2026] [security2:error] [pid 66623:tid 66845] [client 20.118.172.148:19670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBDNO5rbWdOArH04Kb4wAAAVk"]
[Tue Aug 18 12:58:04.811870 2026] [security2:error] [pid 66623:tid 66659] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/abc.php"] [unique_id "aoSBDNO5rbWdOArH04Kb5AABLhY"]
[Tue Aug 18 12:58:04.846961 2026] [security2:error] [pid 66623:tid 66867] [client 160.120.140.123:50738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBDNO5rbWdOArH04Kb5QAAAW8"]
[Tue Aug 18 12:58:04.847074 2026] [security2:error] [pid 66623:tid 66867] [client 160.120.140.123:50738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBDNO5rbWdOArH04Kb5QAAAW8"]
[Tue Aug 18 12:58:04.865482 2026] [security2:error] [pid 66623:tid 66773] [client 20.119.58.187:12480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/about.php"] [unique_id "aoSBDNO5rbWdOArH04Kb8AAAARE"]
[Tue Aug 18 12:58:04.886742 2026] [security2:error] [pid 66623:tid 66821] [client 158.158.74.177:26136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/maint/wpxml.php"] [unique_id "aoSBDNO5rbWdOArH04Kb9wAAAUE"]
[Tue Aug 18 12:58:04.935622 2026] [security2:error] [pid 66623:tid 66881] [client 4.232.151.198:4325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSBDNO5rbWdOArH04Kb_QAAAX0"]
[Tue Aug 18 12:58:04.948564 2026] [authz_core:error] [pid 66623:tid 66639] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:04.948829 2026] [authz_core:error] [pid 66623:tid 66639] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:04.964192 2026] [security2:error] [pid 66623:tid 66858] [client 74.248.18.37:54963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/media/index.php"] [unique_id "aoSBDNO5rbWdOArH04KcAAAAAWY"]
[Tue Aug 18 12:58:04.965334 2026] [security2:error] [pid 66623:tid 66879] [client 20.186.30.159:1679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/imsc.php"] [unique_id "aoSBDNO5rbWdOArH04KcAQAAAXs"]
[Tue Aug 18 12:58:04.995440 2026] [security2:error] [pid 66623:tid 66673] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/abcd.php"] [unique_id "aoSBDNO5rbWdOArH04KcBAABaCQ"]
[Tue Aug 18 12:58:05.012613 2026] [security2:error] [pid 66623:tid 66786] [client 20.215.241.237:46255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBDdO5rbWdOArH04KcCQAAAR4"]
[Tue Aug 18 12:58:05.016742 2026] [security2:error] [pid 66623:tid 66823] [client 68.155.154.236:50414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBDdO5rbWdOArH04KcCgAAAUM"]
[Tue Aug 18 12:58:05.058736 2026] [security2:error] [pid 66623:tid 66772] [client 52.173.121.69:25005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSBDdO5rbWdOArH04KcDQAAARA"]
[Tue Aug 18 12:58:05.071764 2026] [security2:error] [pid 66623:tid 66819] [client 172.182.217.32:15806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/fff.php"] [unique_id "aoSBDdO5rbWdOArH04KcDgAAAT8"]
[Tue Aug 18 12:58:05.072736 2026] [security2:error] [pid 66623:tid 66824] [client 20.48.236.86:2355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/mgrr.php"] [unique_id "aoSBDdO5rbWdOArH04KcDwAAAUQ"]
[Tue Aug 18 12:58:05.131851 2026] [security2:error] [pid 66623:tid 66883] [client 40.74.65.169:43188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/media.php"] [unique_id "aoSBDdO5rbWdOArH04KcEwAAAX8"]
[Tue Aug 18 12:58:05.167539 2026] [security2:error] [pid 66623:tid 66830] [client 20.118.172.148:43461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/xfun.php"] [unique_id "aoSBDdO5rbWdOArH04KcFgAAAUo"]
[Tue Aug 18 12:58:05.178171 2026] [security2:error] [pid 66623:tid 66753] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/about.php"] [unique_id "aoSBDdO5rbWdOArH04KcFwABI3Q"]
[Tue Aug 18 12:58:05.215404 2026] [security2:error] [pid 66623:tid 66808] [client 20.118.172.148:56571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSBDdO5rbWdOArH04KcHAAAATQ"]
[Tue Aug 18 12:58:05.219152 2026] [security2:error] [pid 66623:tid 66856] [client 20.119.58.187:12076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/gallery/about.php"] [unique_id "aoSBDdO5rbWdOArH04KcHQAAAWQ"]
[Tue Aug 18 12:58:05.247655 2026] [authz_core:error] [pid 66623:tid 66761] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:05.248096 2026] [authz_core:error] [pid 66623:tid 66761] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:05.267882 2026] [security2:error] [pid 66623:tid 66812] [client 158.23.17.4:44842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/mo.php"] [unique_id "aoSBDdO5rbWdOArH04KcJQAAATg"]
[Tue Aug 18 12:58:05.271184 2026] [security2:error] [pid 66623:tid 66774] [client 20.186.30.159:1673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/imscjpg.php"] [unique_id "aoSBDdO5rbWdOArH04KcJgAAARI"]
[Tue Aug 18 12:58:05.339279 2026] [security2:error] [pid 66623:tid 66864] [client 20.219.2.203:7308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/wp-admin/css/about.php"] [unique_id "aoSBDdO5rbWdOArH04KcKwAAAWw"]
[Tue Aug 18 12:58:05.371628 2026] [security2:error] [pid 66623:tid 66697] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/about/function.php"] [unique_id "aoSBDdO5rbWdOArH04KcLgABLjw"]
[Tue Aug 18 12:58:05.375688 2026] [security2:error] [pid 66623:tid 66796] [client 34.86.30.230:31614] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBDdO5rbWdOArH04KcLwAAASg"]
[Tue Aug 18 12:58:05.417740 2026] [security2:error] [pid 66623:tid 66821] [client 40.74.65.169:49043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/mac.php"] [unique_id "aoSBDdO5rbWdOArH04KcNAAAAUE"]
[Tue Aug 18 12:58:05.419698 2026] [security2:error] [pid 66623:tid 66776] [client 20.100.185.105:7054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/test1.php"] [unique_id "aoSBDdO5rbWdOArH04KcNgAAARQ"]
[Tue Aug 18 12:58:05.444122 2026] [security2:error] [pid 66623:tid 66832] [client 192.141.172.134:49707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBDdO5rbWdOArH04KcOQAAAUw"]
[Tue Aug 18 12:58:05.444235 2026] [security2:error] [pid 66623:tid 66832] [client 192.141.172.134:49707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBDdO5rbWdOArH04KcOQAAAUw"]
[Tue Aug 18 12:58:05.485809 2026] [security2:error] [pid 66623:tid 66798] [client 34.86.30.230:31696] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/fetch"] [unique_id "aoSBDdO5rbWdOArH04KcOwAAASo"]
[Tue Aug 18 12:58:05.493073 2026] [proxy_http:error] [pid 66623:tid 66805] (20014)Internal error (specific information not available): [client 34.86.30.230:31680] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:05.493091 2026] [proxy:error] [pid 66623:tid 66805] [client 34.86.30.230:31680] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/fetch
[Tue Aug 18 12:58:05.501241 2026] [proxy_http:error] [pid 66623:tid 66853] (20014)Internal error (specific information not available): [client 34.86.30.230:31424] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:05.510312 2026] [proxy_http:error] [pid 66623:tid 66798] (20014)Internal error (specific information not available): [client 34.86.30.230:31696] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:05.518890 2026] [security2:error] [pid 66623:tid 66779] [client 20.118.133.132:1605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/mgrr.php"] [unique_id "aoSBDdO5rbWdOArH04KcPwAAARc"]
[Tue Aug 18 12:58:05.519023 2026] [security2:error] [pid 66623:tid 66845] [client 34.86.30.230:31744] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBDdO5rbWdOArH04KcQAAAAVk"]
[Tue Aug 18 12:58:05.531591 2026] [security2:error] [pid 66623:tid 66862] [client 74.248.18.37:54955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/work.php"] [unique_id "aoSBDdO5rbWdOArH04KcQQAAAWo"]
[Tue Aug 18 12:58:05.548200 2026] [authz_core:error] [pid 66623:tid 66719] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:05.548495 2026] [authz_core:error] [pid 66623:tid 66719] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:05.555874 2026] [security2:error] [pid 66623:tid 66674] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/admin/admin.php"] [unique_id "aoSBDdO5rbWdOArH04KcRAABYCU"]
[Tue Aug 18 12:58:05.558862 2026] [security2:error] [pid 66623:tid 66773] [client 172.182.217.32:15769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/ff1.php"] [unique_id "aoSBDdO5rbWdOArH04KcRQAAARE"]
[Tue Aug 18 12:58:05.583061 2026] [security2:error] [pid 66623:tid 66878] [client 20.119.58.187:12527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/about.php"] [unique_id "aoSBDdO5rbWdOArH04KcRgAAAXo"]
[Tue Aug 18 12:58:05.599297 2026] [autoindex:error] [pid 66623:tid 66885] [client 4.232.151.198:24899] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:05.606823 2026] [security2:error] [pid 66623:tid 66854] [client 68.155.154.236:40312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBDdO5rbWdOArH04KcSQAAAWI"]
[Tue Aug 18 12:58:05.618570 2026] [security2:error] [pid 66623:tid 66778] [client 34.86.30.230:31714] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/proxy"] [unique_id "aoSBDdO5rbWdOArH04KcSgAAARY"]
[Tue Aug 18 12:58:05.619329 2026] [security2:error] [pid 66623:tid 66806] [client 213.35.127.232:62381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBDdO5rbWdOArH04KcSwAAATI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:05.636417 2026] [security2:error] [pid 66623:tid 66888] [client 20.186.30.159:1683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/qlex1.php"] [unique_id "aoSBDdO5rbWdOArH04KcTwAAAYQ"]
[Tue Aug 18 12:58:05.643235 2026] [security2:error] [pid 66623:tid 66783] [client 34.86.30.230:31770] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/fetch"] [unique_id "aoSBDdO5rbWdOArH04KcUQAAARs"]
[Tue Aug 18 12:58:05.648779 2026] [security2:error] [pid 66623:tid 66861] [client 34.86.30.230:31742] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBDdO5rbWdOArH04KcUgAAAWk"]
[Tue Aug 18 12:58:05.653734 2026] [security2:error] [pid 66623:tid 66770] [client 114.5.214.109:49818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBDdO5rbWdOArH04KcVAAAAQ4"]
[Tue Aug 18 12:58:05.656280 2026] [security2:error] [pid 66623:tid 66772] [client 20.203.138.185:10580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/Okxob.php"] [unique_id "aoSBDdO5rbWdOArH04KcVQAAARA"]
[Tue Aug 18 12:58:05.658412 2026] [security2:error] [pid 66623:tid 66770] [client 114.5.214.109:49818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBDdO5rbWdOArH04KcVAAAAQ4"]
[Tue Aug 18 12:58:05.682772 2026] [security2:error] [pid 66623:tid 66881] [client 74.248.18.37:7223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/memberfuns.php"] [unique_id "aoSBDdO5rbWdOArH04KcVwAAAX0"]
[Tue Aug 18 12:58:05.733972 2026] [proxy_http:error] [pid 66623:tid 66873] (20014)Internal error (specific information not available): [client 34.86.30.230:31702] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:05.740595 2026] [security2:error] [pid 66623:tid 66738] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/admin/function.php"] [unique_id "aoSBDdO5rbWdOArH04KcWgABHGU"]
[Tue Aug 18 12:58:05.768923 2026] [security2:error] [pid 66623:tid 66844] [client 34.86.30.230:31726] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBDdO5rbWdOArH04KcXQAAAVg"]
[Tue Aug 18 12:58:05.802202 2026] [security2:error] [pid 66623:tid 66830] [client 20.118.172.148:63096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/p.php"] [unique_id "aoSBDdO5rbWdOArH04KcYQAAAUo"]
[Tue Aug 18 12:58:05.807241 2026] [security2:error] [pid 66623:tid 66828] [client 4.232.151.198:24899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-themes.php"] [unique_id "aoSBDdO5rbWdOArH04KcYgAAAUg"]
[Tue Aug 18 12:58:05.817322 2026] [security2:error] [pid 66623:tid 66871] [client 52.173.121.69:16482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSBDdO5rbWdOArH04KcZAAAAXM"]
[Tue Aug 18 12:58:05.848041 2026] [proxy_http:error] [pid 66623:tid 66861] (20014)Internal error (specific information not available): [client 34.86.30.230:31742] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:05.848058 2026] [proxy:error] [pid 66623:tid 66861] [client 34.86.30.230:31742] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/cgi-sys/403.html
[Tue Aug 18 12:58:05.854619 2026] [proxy_http:error] [pid 66623:tid 66844] (20014)Internal error (specific information not available): [client 34.86.30.230:31726] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:05.854636 2026] [proxy:error] [pid 66623:tid 66844] [client 34.86.30.230:31726] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/cgi-sys/403.html
[Tue Aug 18 12:58:05.869455 2026] [security2:error] [pid 66623:tid 66786] [client 158.158.74.177:16533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/maintenance.php"] [unique_id "aoSBDdO5rbWdOArH04KcZgAAAR4"]
[Tue Aug 18 12:58:05.893511 2026] [security2:error] [pid 66623:tid 66849] [client 213.202.253.4:50828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/wp-content/txets.php"] [unique_id "aoSBDdO5rbWdOArH04KcZwAAAV0"], referer: www.google.com
[Tue Aug 18 12:58:05.896169 2026] [security2:error] [pid 66623:tid 66850] [client 158.158.34.183:53283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/OK.php"] [unique_id "aoSBDdO5rbWdOArH04KcaAAAAV4"]
[Tue Aug 18 12:58:05.913090 2026] [security2:error] [pid 66623:tid 66831] [client 20.79.204.6:11666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBDdO5rbWdOArH04KcawAAAUs"]
[Tue Aug 18 12:58:05.924583 2026] [security2:error] [pid 66623:tid 66808] [client 20.48.236.86:50724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/55.php"] [unique_id "aoSBDdO5rbWdOArH04KcbQAAATQ"]
[Tue Aug 18 12:58:05.927852 2026] [security2:error] [pid 66623:tid 66856] [client 158.23.17.4:31874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/qr.php"] [unique_id "aoSBDdO5rbWdOArH04KcbgAAAWQ"]
[Tue Aug 18 12:58:05.929383 2026] [security2:error] [pid 66623:tid 66877] [client 40.74.65.169:11238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/inso.php"] [unique_id "aoSBDdO5rbWdOArH04KcbwAAAXk"]
[Tue Aug 18 12:58:05.935762 2026] [security2:error] [pid 66623:tid 66643] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBDdO5rbWdOArH04KccAABeAY"]
[Tue Aug 18 12:58:05.945278 2026] [security2:error] [pid 66623:tid 66791] [client 20.119.58.187:12515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "aoSBDdO5rbWdOArH04KccQAAASM"]
[Tue Aug 18 12:58:05.950995 2026] [security2:error] [pid 66623:tid 66836] [client 68.155.155.199:5327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSBDdO5rbWdOArH04KccgAAAVA"]
[Tue Aug 18 12:58:06.031048 2026] [security2:error] [pid 66623:tid 66882] [client 20.186.30.159:1960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/mariju.php"] [unique_id "aoSBDtO5rbWdOArH04KcdgAAAX4"]
[Tue Aug 18 12:58:06.039794 2026] [security2:error] [pid 66623:tid 66801] [client 20.100.185.105:53298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/asd.php"] [unique_id "aoSBDtO5rbWdOArH04KcdwAAAS0"]
[Tue Aug 18 12:58:06.046203 2026] [security2:error] [pid 66623:tid 66813] [client 172.182.217.32:15758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/flower.php"] [unique_id "aoSBDtO5rbWdOArH04KceAAAATk"]
[Tue Aug 18 12:58:06.096542 2026] [security2:error] [pid 66623:tid 66866] [client 68.155.154.236:48957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/first.php"] [unique_id "aoSBDtO5rbWdOArH04KcfAAAAW4"]
[Tue Aug 18 12:58:06.108326 2026] [security2:error] [pid 66623:tid 66799] [client 40.74.65.169:49065] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.compratec.com.br"] [uri "/1.php"] [unique_id "aoSBDtO5rbWdOArH04KcfQAAASs"]
[Tue Aug 18 12:58:06.108446 2026] [security2:error] [pid 66623:tid 66799] [client 40.74.65.169:49065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/1.php"] [unique_id "aoSBDtO5rbWdOArH04KcfQAAASs"]
[Tue Aug 18 12:58:06.118928 2026] [security2:error] [pid 66623:tid 66706] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/administrator/templates/hathor/html/layouts/plugins/db-status.php"] [unique_id "aoSBDtO5rbWdOArH04KcfgABTEU"]
[Tue Aug 18 12:58:06.137179 2026] [security2:error] [pid 66623:tid 66886] [client 34.86.30.230:31774] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/proxy"] [unique_id "aoSBDtO5rbWdOArH04KcfwAAAYI"]
[Tue Aug 18 12:58:06.150441 2026] [authz_core:error] [pid 66623:tid 66743] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:06.150688 2026] [authz_core:error] [pid 66623:tid 66743] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:06.163798 2026] [security2:error] [pid 66623:tid 66777] [client 20.118.172.148:50058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBDtO5rbWdOArH04KchAAAARU"]
[Tue Aug 18 12:58:06.187871 2026] [security2:error] [pid 66623:tid 66810] [client 35.219.242.23:42908] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "andradesalescarregamentos.com.br"] [uri "/index.php"] [unique_id "aoSBDtO5rbWdOArH04KchQAAATY"]
[Tue Aug 18 12:58:06.201087 2026] [security2:error] [pid 66623:tid 66845] [client 34.86.30.230:31754] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/fetch"] [unique_id "aoSBDtO5rbWdOArH04KchwAAAVk"]
[Tue Aug 18 12:58:06.301580 2026] [security2:error] [pid 66623:tid 66749] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/ahax.php"] [unique_id "aoSBDtO5rbWdOArH04KcjAABPHA"]
[Tue Aug 18 12:58:06.304939 2026] [security2:error] [pid 66623:tid 66789] [client 20.119.58.187:12518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "aoSBDtO5rbWdOArH04KcjQAAASE"]
[Tue Aug 18 12:58:06.311818 2026] [security2:error] [pid 66623:tid 66867] [client 74.248.18.37:21542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/worksec.php"] [unique_id "aoSBDtO5rbWdOArH04KcjgAAAW8"]
[Tue Aug 18 12:58:06.364869 2026] [security2:error] [pid 66623:tid 66864] [client 20.219.2.203:8616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSBDtO5rbWdOArH04KckwAAAWw"]
[Tue Aug 18 12:58:06.390878 2026] [security2:error] [pid 66623:tid 66858] [client 34.86.30.230:31792] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBDtO5rbWdOArH04KclAAAAWY"]
[Tue Aug 18 12:58:06.413931 2026] [security2:error] [pid 66623:tid 66881] [client 20.186.30.159:1686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSBDtO5rbWdOArH04KclQAAAX0"]
[Tue Aug 18 12:58:06.418036 2026] [security2:error] [pid 66623:tid 66889] [client 74.248.18.37:35389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/mgrr.php"] [unique_id "aoSBDtO5rbWdOArH04KclwAAAYU"]
[Tue Aug 18 12:58:06.443908 2026] [security2:error] [pid 66623:tid 66778] [client 20.118.172.148:62104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSBDtO5rbWdOArH04KcmwAAARY"]
[Tue Aug 18 12:58:06.446582 2026] [security2:error] [pid 66623:tid 66852] [client 4.232.151.198:24952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBDtO5rbWdOArH04KcnAAAAWA"]
[Tue Aug 18 12:58:06.458971 2026] [security2:error] [pid 66623:tid 66824] [client 35.219.242.23:42908] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "andradesalescarregamentos.com.br"] [uri "/index.php"] [unique_id "aoSBDtO5rbWdOArH04KclgAAAUQ"]
[Tue Aug 18 12:58:06.468316 2026] [security2:error] [pid 66623:tid 66863] [client 68.155.155.199:8497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSBDtO5rbWdOArH04KcoAAAAWs"]
[Tue Aug 18 12:58:06.485062 2026] [security2:error] [pid 66623:tid 66646] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/alfa.php"] [unique_id "aoSBDtO5rbWdOArH04KcogABXwk"]
[Tue Aug 18 12:58:06.497177 2026] [security2:error] [pid 66623:tid 66835] [client 3.212.128.62:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "joanagaspar.com.br"] [uri "/"] [unique_id "aoSBDtO5rbWdOArH04KcpQABT3E"], referer: https://joanagaspar.com.br/
[Tue Aug 18 12:58:06.499227 2026] [security2:error] [pid 66623:tid 66787] [client 20.118.172.148:46753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/aaa.php"] [unique_id "aoSBDtO5rbWdOArH04KcpgAAAR8"]
[Tue Aug 18 12:58:06.531171 2026] [security2:error] [pid 66623:tid 66823] [client 20.79.204.6:11709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/akc.php"] [unique_id "aoSBDtO5rbWdOArH04KcqgAAAUM"]
[Tue Aug 18 12:58:06.570621 2026] [security2:error] [pid 66623:tid 66846] [client 172.182.217.32:15571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/file.php"] [unique_id "aoSBDtO5rbWdOArH04KcrAAAAVo"]
[Tue Aug 18 12:58:06.582758 2026] [security2:error] [pid 66623:tid 66786] [client 52.173.121.69:48263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBDtO5rbWdOArH04KcrQAAAR4"]
[Tue Aug 18 12:58:06.614937 2026] [security2:error] [pid 66623:tid 66850] [client 20.203.138.185:10560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/file59.php"] [unique_id "aoSBDtO5rbWdOArH04KcrwAAAV4"]
[Tue Aug 18 12:58:06.628825 2026] [security2:error] [pid 66623:tid 66808] [client 20.118.133.132:21723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/55.php"] [unique_id "aoSBDtO5rbWdOArH04KcsAAAATQ"]
[Tue Aug 18 12:58:06.639117 2026] [security2:error] [pid 66623:tid 66860] [client 213.35.127.232:62602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBDtO5rbWdOArH04KcsQAAAWg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:06.658858 2026] [security2:error] [pid 66623:tid 66868] [client 20.186.30.159:1937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/contacto.php"] [unique_id "aoSBDtO5rbWdOArH04KcsgAAAXA"]
[Tue Aug 18 12:58:06.660829 2026] [security2:error] [pid 66623:tid 66771] [client 34.86.30.230:31780] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/fetch"] [unique_id "aoSBDtO5rbWdOArH04KcswAAAQ8"]
[Tue Aug 18 12:58:06.662762 2026] [security2:error] [pid 66623:tid 66704] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/alfax.php"] [unique_id "aoSBDtO5rbWdOArH04KctAABUEM"]
[Tue Aug 18 12:58:06.669608 2026] [security2:error] [pid 66623:tid 66880] [client 20.119.58.187:12094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/network/cloud.php"] [unique_id "aoSBDtO5rbWdOArH04KctQAAAXw"]
[Tue Aug 18 12:58:06.688514 2026] [security2:error] [pid 66623:tid 66774] [client 40.74.65.169:7372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/shiny.php"] [unique_id "aoSBDtO5rbWdOArH04KctgAAARI"]
[Tue Aug 18 12:58:06.696691 2026] [autoindex:error] [pid 66623:tid 66838] [client 205.210.31.149:64762] AH01276: Cannot serve directory /home2/rj9727inseozcb1z/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:06.723166 2026] [security2:error] [pid 66623:tid 66801] [client 52.173.121.69:24970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSBDtO5rbWdOArH04KcugAAAS0"]
[Tue Aug 18 12:58:06.742811 2026] [security2:error] [pid 66623:tid 66872] [client 20.206.73.37:59956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/1xmomo.php"] [unique_id "aoSBDtO5rbWdOArH04KcuwAAAXQ"]
[Tue Aug 18 12:58:06.757497 2026] [authz_core:error] [pid 66623:tid 66710] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:06.757946 2026] [authz_core:error] [pid 66623:tid 66710] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:06.784206 2026] [security2:error] [pid 66623:tid 66796] [client 40.74.65.169:49076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/coffee.php"] [unique_id "aoSBDtO5rbWdOArH04KcwAAAASg"]
[Tue Aug 18 12:58:06.839377 2026] [security2:error] [pid 66623:tid 66842] [client 34.86.30.230:31808] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/proxy"] [unique_id "aoSBDtO5rbWdOArH04KcxQAAAVY"]
[Tue Aug 18 12:58:06.840993 2026] [security2:error] [pid 66623:tid 66667] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/ant.php"] [unique_id "aoSBDtO5rbWdOArH04KcxgABah4"]
[Tue Aug 18 12:58:06.866120 2026] [security2:error] [pid 66623:tid 66877] [client 35.219.242.23:42920] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "andradesalescarregamentos.com.br"] [uri "/index.php"] [unique_id "aoSBDtO5rbWdOArH04KcxwAAAXk"]
[Tue Aug 18 12:58:06.882486 2026] [security2:error] [pid 66623:tid 66886] [client 172.182.200.96:14161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSBDtO5rbWdOArH04KcyQAAAYI"]
[Tue Aug 18 12:58:06.891999 2026] [security2:error] [pid 66623:tid 66885] [client 20.65.98.162:44177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/ws55.php"] [unique_id "aoSBDtO5rbWdOArH04KczQAAAYE"]
[Tue Aug 18 12:58:06.906382 2026] [security2:error] [pid 66623:tid 66789] [client 20.48.236.86:32885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/ajax.php"] [unique_id "aoSBDtO5rbWdOArH04Kc0gAAASE"]
[Tue Aug 18 12:58:06.910009 2026] [security2:error] [pid 66623:tid 66867] [client 68.155.154.236:48928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBDtO5rbWdOArH04Kc0wAAAW8"]
[Tue Aug 18 12:58:06.924167 2026] [security2:error] [pid 66623:tid 66892] [client 20.118.172.148:43476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/term.php"] [unique_id "aoSBDtO5rbWdOArH04Kc1gAAAYg"]
[Tue Aug 18 12:58:06.956363 2026] [security2:error] [pid 66623:tid 66814] [client 3.212.128.62:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "joanagaspar.com.br"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aoSBDtO5rbWdOArH04Kc0QABOhQ"], referer: https://joanagaspar.com.br/
[Tue Aug 18 12:58:06.972347 2026] [security2:error] [pid 66623:tid 66887] [client 158.158.34.183:31053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/config.php7"] [unique_id "aoSBDtO5rbWdOArH04Kc2QAAAYM"]
[Tue Aug 18 12:58:06.986315 2026] [security2:error] [pid 66623:tid 66776] [client 74.248.18.37:54938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-activate.php"] [unique_id "aoSBDtO5rbWdOArH04Kc2gAAARQ"]
[Tue Aug 18 12:58:07.027694 2026] [security2:error] [pid 66623:tid 66715] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/app.php"] [unique_id "aoSBD9O5rbWdOArH04Kc3AABiU4"]
[Tue Aug 18 12:58:07.047486 2026] [security2:error] [pid 66623:tid 66834] [client 20.119.58.187:11859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/cloud.php"] [unique_id "aoSBD9O5rbWdOArH04Kc3gAAAU4"]
[Tue Aug 18 12:58:07.054886 2026] [authz_core:error] [pid 66623:tid 66735] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:07.055151 2026] [authz_core:error] [pid 66623:tid 66735] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:07.060346 2026] [security2:error] [pid 66623:tid 66816] [client 172.182.217.32:15584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/goods.php"] [unique_id "aoSBD9O5rbWdOArH04Kc4QAAATw"]
[Tue Aug 18 12:58:07.091433 2026] [security2:error] [pid 66623:tid 66850] [client 158.23.17.4:44838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/dirs.php"] [unique_id "aoSBD9O5rbWdOArH04Kc5AAAAV4"]
[Tue Aug 18 12:58:07.092710 2026] [security2:error] [pid 66623:tid 66831] [client 20.100.185.105:63271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBD9O5rbWdOArH04Kc5QAAAUs"]
[Tue Aug 18 12:58:07.103105 2026] [security2:error] [pid 66623:tid 66808] [client 20.118.172.148:56427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBD9O5rbWdOArH04Kc5gAAATQ"]
[Tue Aug 18 12:58:07.108820 2026] [security2:error] [pid 66623:tid 66833] [client 35.219.242.23:42908] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "andradesalescarregamentos.com.br"] [uri "/index.php"] [unique_id "aoSBD9O5rbWdOArH04Kc4gAAAU0"]
[Tue Aug 18 12:58:07.118084 2026] [security2:error] [pid 66623:tid 66860] [client 20.186.30.159:1924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/image2.php"] [unique_id "aoSBD9O5rbWdOArH04Kc6wAAAWg"]
[Tue Aug 18 12:58:07.136193 2026] [security2:error] [pid 66623:tid 66845] [client 20.79.204.6:11558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/buy.php"] [unique_id "aoSBD9O5rbWdOArH04Kc7AAAAVk"]
[Tue Aug 18 12:58:07.184539 2026] [security2:error] [pid 66623:tid 66826] [client 34.86.30.230:31680] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/azure-pipelines.yml"] [unique_id "aoSBD9O5rbWdOArH04Kc8AAAAUY"]
[Tue Aug 18 12:58:07.191822 2026] [security2:error] [pid 66623:tid 66890] [client 68.155.155.199:7279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSBD9O5rbWdOArH04Kc8gAAAYY"]
[Tue Aug 18 12:58:07.248087 2026] [security2:error] [pid 66623:tid 66696] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/archive.php"] [unique_id "aoSBD9O5rbWdOArH04Kc9AABJTs"]
[Tue Aug 18 12:58:07.259024 2026] [authz_core:error] [pid 66623:tid 66659] [remote 57.141.22.86:63388] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:07.259280 2026] [authz_core:error] [pid 66623:tid 66659] [remote 57.141.22.86:63388] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:07.277097 2026] [security2:error] [pid 66623:tid 66830] [client 34.86.30.230:31924] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/.vercel/.env.production.local"] [unique_id "aoSBD9O5rbWdOArH04Kc_gAAAUo"]
[Tue Aug 18 12:58:07.282239 2026] [proxy_http:error] [pid 66623:tid 66794] (20014)Internal error (specific information not available): [client 34.86.30.230:31946] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:07.282257 2026] [proxy:error] [pid 66623:tid 66794] [client 34.86.30.230:31946] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.vercel/.env.development.local
[Tue Aug 18 12:58:07.290159 2026] [proxy_http:error] [pid 66623:tid 66870] (20014)Internal error (specific information not available): [client 34.86.30.230:31828] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:07.290182 2026] [proxy:error] [pid 66623:tid 66870] [client 34.86.30.230:31828] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/jenkins/Jenkinsfile
[Tue Aug 18 12:58:07.290219 2026] [security2:error] [pid 66623:tid 66771] [client 20.203.138.185:38101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/eauu.php"] [unique_id "aoSBD9O5rbWdOArH04KdAgAAAQ8"]
[Tue Aug 18 12:58:07.293127 2026] [security2:error] [pid 66623:tid 66832] [client 20.203.183.135:52383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/bajah.php"] [unique_id "aoSBD9O5rbWdOArH04KdCAAAAUw"]
[Tue Aug 18 12:58:07.296517 2026] [security2:error] [pid 66623:tid 66796] [client 20.118.172.148:2741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/7.php"] [unique_id "aoSBD9O5rbWdOArH04KdCQAAASg"]
[Tue Aug 18 12:58:07.298557 2026] [proxy_http:error] [pid 66623:tid 66835] (20014)Internal error (specific information not available): [client 34.86.30.230:31890] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:07.298572 2026] [proxy:error] [pid 66623:tid 66835] [client 34.86.30.230:31890] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.travis.yml
[Tue Aug 18 12:58:07.299654 2026] [security2:error] [pid 66623:tid 66783] [client 34.86.30.230:31852] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/.env.ci"] [unique_id "aoSBD9O5rbWdOArH04KdCgAAARs"]
[Tue Aug 18 12:58:07.305818 2026] [proxy_http:error] [pid 66623:tid 66787] (20014)Internal error (specific information not available): [client 34.86.30.230:31888] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:07.305838 2026] [proxy:error] [pid 66623:tid 66787] [client 34.86.30.230:31888] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.circleci/config.yml
[Tue Aug 18 12:58:07.325180 2026] [proxy_http:error] [pid 66623:tid 66822] (20014)Internal error (specific information not available): [client 34.86.30.230:31904] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:07.325199 2026] [proxy:error] [pid 66623:tid 66822] [client 34.86.30.230:31904] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.drone.yml
[Tue Aug 18 12:58:07.332626 2026] [proxy_http:error] [pid 66623:tid 66824] (20014)Internal error (specific information not available): [client 34.86.30.230:31922] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:07.332643 2026] [proxy:error] [pid 66623:tid 66824] [client 34.86.30.230:31922] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/cloudbuild.yaml
[Tue Aug 18 12:58:07.352119 2026] [proxy_http:error] [pid 66623:tid 66787] (20014)Internal error (specific information not available): [client 34.86.30.230:31888] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:07.352140 2026] [proxy:error] [pid 66623:tid 66787] [client 34.86.30.230:31888] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml
[Tue Aug 18 12:58:07.358562 2026] [authz_core:error] [pid 66623:tid 66759] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:07.358959 2026] [authz_core:error] [pid 66623:tid 66759] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:07.372379 2026] [security2:error] [pid 66623:tid 66785] [client 35.219.242.23:42908] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "andradesalescarregamentos.com.br"] [uri "/index.php"] [unique_id "aoSBD9O5rbWdOArH04KdEgAAAR0"]
[Tue Aug 18 12:58:07.373678 2026] [security2:error] [pid 66623:tid 66878] [client 20.186.30.159:1965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/fb.php"] [unique_id "aoSBD9O5rbWdOArH04KdFgAAAXo"]
[Tue Aug 18 12:58:07.382087 2026] [security2:error] [pid 66623:tid 66855] [client 74.248.18.37:21562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/mini.php"] [unique_id "aoSBD9O5rbWdOArH04KdGAAAAWM"]
[Tue Aug 18 12:58:07.385050 2026] [security2:error] [pid 66623:tid 66853] [client 35.219.242.23:42920] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "andradesalescarregamentos.com.br"] [uri "/index.php"] [unique_id "aoSBD9O5rbWdOArH04KdEwAAAWE"]
[Tue Aug 18 12:58:07.390560 2026] [security2:error] [pid 66623:tid 66854] [client 34.86.30.230:31826] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/.github/workflows/test.yml"] [unique_id "aoSBD9O5rbWdOArH04KdGQAAAWI"]
[Tue Aug 18 12:58:07.391320 2026] [autoindex:error] [pid 66623:tid 66778] [client 20.219.2.203:10410] AH01276: Cannot serve directory /home2/cropman/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:07.401299 2026] [security2:error] [pid 66623:tid 66815] [client 188.82.68.190:40376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoSBDtO5rbWdOArH04KcvwABO00"], referer: https://bioarquitetar.com/xmlrpc.php
[Tue Aug 18 12:58:07.405893 2026] [security2:error] [pid 66623:tid 66821] [client 20.119.58.187:11983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/updates.php"] [unique_id "aoSBD9O5rbWdOArH04KdHQAAAUE"]
[Tue Aug 18 12:58:07.428895 2026] [security2:error] [pid 66623:tid 66661] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/as.php"] [unique_id "aoSBD9O5rbWdOArH04KdHgABUxg"]
[Tue Aug 18 12:58:07.438363 2026] [security2:error] [pid 66623:tid 66797] [client 20.48.236.86:25952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/yj09.php"] [unique_id "aoSBD9O5rbWdOArH04KdHwAAASk"]
[Tue Aug 18 12:58:07.465942 2026] [security2:error] [pid 66623:tid 66887] [client 34.86.30.230:31946] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/.github/secrets.env"] [unique_id "aoSBD9O5rbWdOArH04KdIgAAAYM"]
[Tue Aug 18 12:58:07.482706 2026] [security2:error] [pid 66623:tid 66864] [client 40.74.65.169:49096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBD9O5rbWdOArH04KdJAAAAWw"]
[Tue Aug 18 12:58:07.489034 2026] [security2:error] [pid 66623:tid 66881] [client 20.206.73.37:24285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBD9O5rbWdOArH04KdJQAAAX0"]
[Tue Aug 18 12:58:07.490282 2026] [security2:error] [pid 66623:tid 66859] [client 20.206.73.37:11916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/mosty.php"] [unique_id "aoSBD9O5rbWdOArH04KdJgAAAWc"]
[Tue Aug 18 12:58:07.498443 2026] [security2:error] [pid 66623:tid 66800] [client 52.173.121.69:12200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBD9O5rbWdOArH04KdJwAAASw"]
[Tue Aug 18 12:58:07.533763 2026] [security2:error] [pid 66623:tid 66769] [client 158.158.74.177:22760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/network/about.php"] [unique_id "aoSBD9O5rbWdOArH04KdLwAAAQ0"]
[Tue Aug 18 12:58:07.540543 2026] [proxy_http:error] [pid 66623:tid 66786] (20014)Internal error (specific information not available): [client 34.86.30.230:31892] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:07.544202 2026] [security2:error] [pid 66623:tid 66831] [client 52.173.121.69:25022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSBD9O5rbWdOArH04KdNAAAAUs"]
[Tue Aug 18 12:58:07.547914 2026] [security2:error] [pid 66623:tid 66885] [client 172.182.217.32:15751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/g.php"] [unique_id "aoSBD9O5rbWdOArH04KdNQAAAYE"]
[Tue Aug 18 12:58:07.560874 2026] [security2:error] [pid 66623:tid 66856] [client 34.86.30.230:31922] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/.env.production.bak"] [unique_id "aoSBD9O5rbWdOArH04KdNwAAAWQ"]
[Tue Aug 18 12:58:07.563744 2026] [security2:error] [pid 66623:tid 66860] [client 34.86.30.230:31844] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/var/www/html/.env"] [unique_id "aoSBD9O5rbWdOArH04KdOAAAAWg"]
[Tue Aug 18 12:58:07.567825 2026] [proxy_http:error] [pid 66623:tid 66833] (20014)Internal error (specific information not available): [client 34.86.30.230:31904] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:07.570854 2026] [security2:error] [pid 66623:tid 66883] [client 157.51.166.53:51525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBD9O5rbWdOArH04KdOgAAAX8"]
[Tue Aug 18 12:58:07.581203 2026] [security2:error] [pid 66623:tid 66883] [client 157.51.166.53:51525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBD9O5rbWdOArH04KdOgAAAX8"]
[Tue Aug 18 12:58:07.588145 2026] [security2:error] [pid 66623:tid 66880] [client 20.118.172.148:56438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/0x.php"] [unique_id "aoSBD9O5rbWdOArH04KdPgAAAXw"]
[Tue Aug 18 12:58:07.608700 2026] [security2:error] [pid 66623:tid 66838] [client 40.74.65.169:43187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/403dd.php"] [unique_id "aoSBD9O5rbWdOArH04KdRgAAAVI"]
[Tue Aug 18 12:58:07.630234 2026] [security2:error] [pid 66623:tid 66688] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/assets/images/doc.php"] [unique_id "aoSBD9O5rbWdOArH04KdSQABRjM"]
[Tue Aug 18 12:58:07.651283 2026] [authz_core:error] [pid 66623:tid 66748] [remote 57.141.22.20:20924] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:07.651548 2026] [authz_core:error] [pid 66623:tid 66748] [remote 57.141.22.20:20924] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:07.653947 2026] [security2:error] [pid 66623:tid 66775] [client 213.35.127.232:62828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBD9O5rbWdOArH04KdSwAAARM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:07.661485 2026] [security2:error] [pid 66623:tid 66814] [client 74.248.18.37:7179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin.php"] [unique_id "aoSBD9O5rbWdOArH04KdTQAAATo"]
[Tue Aug 18 12:58:07.697786 2026] [security2:error] [pid 66623:tid 66866] [client 20.186.30.159:1698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/gi.php"] [unique_id "aoSBD9O5rbWdOArH04KdUAAAAW4"]
[Tue Aug 18 12:58:07.708277 2026] [security2:error] [pid 66623:tid 66780] [client 20.219.2.203:10410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBD9O5rbWdOArH04KdUwAAARg"]
[Tue Aug 18 12:58:07.720795 2026] [security2:error] [pid 66623:tid 66893] [client 20.100.185.105:35292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/gg.php"] [unique_id "aoSBD9O5rbWdOArH04KdVAAAAYk"]
[Tue Aug 18 12:58:07.729834 2026] [security2:error] [pid 66623:tid 66851] [client 20.118.172.148:53070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/file5.php"] [unique_id "aoSBD9O5rbWdOArH04KdVwAAAV8"]
[Tue Aug 18 12:58:07.732509 2026] [security2:error] [pid 66623:tid 66781] [client 20.206.73.37:24270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBD9O5rbWdOArH04KdWAAAARk"]
[Tue Aug 18 12:58:07.741830 2026] [security2:error] [pid 66623:tid 66849] [client 20.79.204.6:11682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/cong.php"] [unique_id "aoSBD9O5rbWdOArH04KdXAAAAV0"]
[Tue Aug 18 12:58:07.749777 2026] [security2:error] [pid 66623:tid 66836] [client 34.86.30.230:31822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.30.86.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nightblue.com.br"] [uri "/.env.local.php"] [unique_id "aoSBD9O5rbWdOArH04KdPQAAAVA"]
[Tue Aug 18 12:58:07.758615 2026] [security2:error] [pid 66623:tid 66890] [client 20.119.58.187:11903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/css/cloud.php"] [unique_id "aoSBD9O5rbWdOArH04KdXgAAAYY"]
[Tue Aug 18 12:58:07.819188 2026] [security2:error] [pid 66623:tid 66740] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/atomlib.php"] [unique_id "aoSBD9O5rbWdOArH04KdZQABVGc"]
[Tue Aug 18 12:58:07.906673 2026] [security2:error] [pid 66623:tid 66884] [client 196.12.128.158:56957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBD9O5rbWdOArH04KdaAAAAYA"]
[Tue Aug 18 12:58:07.906812 2026] [security2:error] [pid 66623:tid 66884] [client 196.12.128.158:56957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBD9O5rbWdOArH04KdaAAAAYA"]
[Tue Aug 18 12:58:07.959064 2026] [authz_core:error] [pid 66623:tid 66670] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:07.959332 2026] [authz_core:error] [pid 66623:tid 66670] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:07.960963 2026] [security2:error] [pid 66623:tid 66872] [client 103.139.191.60:50084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ctrrefrigeracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBD9O5rbWdOArH04KdbAAAAXQ"]
[Tue Aug 18 12:58:07.961085 2026] [security2:error] [pid 66623:tid 66872] [client 103.139.191.60:50084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ctrrefrigeracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBD9O5rbWdOArH04KdbAAAAXQ"]
[Tue Aug 18 12:58:07.970132 2026] [security2:error] [pid 66623:tid 66846] [client 47.128.62.10:43782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acqualereformadepiscina.com.br"] [uri "/robots.txt"] [unique_id "aoSBD9O5rbWdOArH04KdbQAAAVo"]
[Tue Aug 18 12:58:07.997426 2026] [security2:error] [pid 66623:tid 66662] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/b.php"] [unique_id "aoSBD9O5rbWdOArH04KdbwABbBk"]
[Tue Aug 18 12:58:08.002133 2026] [security2:error] [pid 66623:tid 66881] [client 20.206.73.37:50089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/domvf.php"] [unique_id "aoSBENO5rbWdOArH04KdcAAAAX0"]
[Tue Aug 18 12:58:08.035919 2026] [security2:error] [pid 66623:tid 66824] [client 172.182.217.32:15581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBENO5rbWdOArH04KddAAAAUQ"]
[Tue Aug 18 12:58:08.088775 2026] [security2:error] [pid 66623:tid 66861] [client 172.182.200.96:7631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/mt/byp.php"] [unique_id "aoSBENO5rbWdOArH04KddgAAAWk"]
[Tue Aug 18 12:58:08.097235 2026] [security2:error] [pid 66623:tid 66855] [client 74.248.18.37:54914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/minishell.php"] [unique_id "aoSBENO5rbWdOArH04KddwAAAWM"]
[Tue Aug 18 12:58:08.105145 2026] [security2:error] [pid 66623:tid 66737] [remote 103.82.26.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.26.82.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yycc.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSBENO5rbWdOArH04KdeQABd2Q"]
[Tue Aug 18 12:58:08.112827 2026] [security2:error] [pid 66623:tid 66879] [client 20.119.58.187:12039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/user/cloud.php"] [unique_id "aoSBENO5rbWdOArH04KdegAAAXs"]
[Tue Aug 18 12:58:08.113337 2026] [security2:error] [pid 66623:tid 66844] [client 20.186.30.159:1964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/video.php"] [unique_id "aoSBENO5rbWdOArH04KdewAAAVg"]
[Tue Aug 18 12:58:08.123224 2026] [security2:error] [pid 66623:tid 66769] [client 68.155.155.199:19454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/xmr.php"] [unique_id "aoSBENO5rbWdOArH04KdfAAAAQ0"]
[Tue Aug 18 12:58:08.138641 2026] [security2:error] [pid 66623:tid 66843] [client 20.48.236.86:2176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/scxy.php"] [unique_id "aoSBENO5rbWdOArH04KdfgAAAVc"]
[Tue Aug 18 12:58:08.149074 2026] [security2:error] [pid 66623:tid 66850] [client 20.206.73.37:52534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSBENO5rbWdOArH04KdgAAAAV4"]
[Tue Aug 18 12:58:08.165369 2026] [security2:error] [pid 66623:tid 66856] [client 40.74.65.169:49074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBENO5rbWdOArH04KdggAAAWQ"]
[Tue Aug 18 12:58:08.177917 2026] [security2:error] [pid 66623:tid 66709] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/backup.php"] [unique_id "aoSBENO5rbWdOArH04KdhgABTUg"]
[Tue Aug 18 12:58:08.235471 2026] [security2:error] [pid 66623:tid 66775] [client 34.86.30.230:31828] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/www/.env"] [unique_id "aoSBENO5rbWdOArH04KdiwAAARM"]
[Tue Aug 18 12:58:08.257020 2026] [authz_core:error] [pid 66623:tid 66724] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:08.257278 2026] [authz_core:error] [pid 66623:tid 66724] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:08.260476 2026] [security2:error] [pid 66623:tid 66793] [client 20.206.73.37:28010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/gec.php"] [unique_id "aoSBENO5rbWdOArH04KdjQAAASU"]
[Tue Aug 18 12:58:08.265349 2026] [security2:error] [pid 66623:tid 66827] [client 20.203.138.185:45321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/dsd.php"] [unique_id "aoSBENO5rbWdOArH04KdjgAAAUc"]
[Tue Aug 18 12:58:08.277324 2026] [security2:error] [pid 66623:tid 66802] [client 20.118.172.148:63068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBENO5rbWdOArH04KdjwAAAS4"]
[Tue Aug 18 12:58:08.288051 2026] [security2:error] [pid 66623:tid 66893] [client 20.206.73.37:52047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/sky.php"] [unique_id "aoSBENO5rbWdOArH04KdkQAAAYk"]
[Tue Aug 18 12:58:08.312310 2026] [authz_core:error] [pid 66623:tid 66761] [remote 57.141.22.109:47760] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:08.312663 2026] [authz_core:error] [pid 66623:tid 66761] [remote 57.141.22.109:47760] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:08.316596 2026] [security2:error] [pid 66623:tid 66794] [client 34.86.30.230:31890] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/.netlify/.env"] [unique_id "aoSBENO5rbWdOArH04KdlAAAASY"]
[Tue Aug 18 12:58:08.321875 2026] [security2:error] [pid 66623:tid 66870] [client 52.173.121.69:48297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/weozh.php"] [unique_id "aoSBENO5rbWdOArH04KdlQAAAXI"]
[Tue Aug 18 12:58:08.322611 2026] [security2:error] [pid 66623:tid 66848] [client 20.206.73.37:50058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/sixxis.php"] [unique_id "aoSBENO5rbWdOArH04KdlgAAAVw"]
[Tue Aug 18 12:58:08.335105 2026] [security2:error] [pid 66623:tid 66852] [client 34.86.30.230:31740] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/%2eenv"] [unique_id "aoSBENO5rbWdOArH04KdmQAAAWA"]
[Tue Aug 18 12:58:08.337176 2026] [security2:error] [pid 66623:tid 66810] [client 20.206.73.37:59813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/yj09.php"] [unique_id "aoSBENO5rbWdOArH04KdmwAAATY"]
[Tue Aug 18 12:58:08.338401 2026] [security2:error] [pid 66623:tid 66840] [client 34.86.30.230:31888] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/supabase/.env"] [unique_id "aoSBENO5rbWdOArH04KdnQAAAVQ"]
[Tue Aug 18 12:58:08.338633 2026] [security2:error] [pid 66623:tid 66786] [client 20.100.185.105:58359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-admin/file.php"] [unique_id "aoSBENO5rbWdOArH04KdnAAAAR4"]
[Tue Aug 18 12:58:08.348167 2026] [security2:error] [pid 66623:tid 66837] [client 40.74.65.169:28165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/baba.php"] [unique_id "aoSBENO5rbWdOArH04KdngAAAVE"]
[Tue Aug 18 12:58:08.350001 2026] [security2:error] [pid 66623:tid 66885] [client 20.79.204.6:11530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSBENO5rbWdOArH04KdnwAAAYE"]
[Tue Aug 18 12:58:08.359684 2026] [security2:error] [pid 66623:tid 66787] [client 20.206.73.37:6101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/k.php"] [unique_id "aoSBENO5rbWdOArH04KdoQAAAR8"]
[Tue Aug 18 12:58:08.359734 2026] [security2:error] [pid 66623:tid 66674] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/bak.php"] [unique_id "aoSBENO5rbWdOArH04KdoAABFSU"]
[Tue Aug 18 12:58:08.396654 2026] [core:error] [pid 66623:tid 66806] [client 34.86.30.230:31908] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.env)
[Tue Aug 18 12:58:08.406217 2026] [security2:error] [pid 66623:tid 66854] [client 20.118.172.148:62107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/222.php"] [unique_id "aoSBENO5rbWdOArH04KdpgAAAWI"]
[Tue Aug 18 12:58:08.417124 2026] [security2:error] [pid 66623:tid 66886] [client 34.86.30.230:31880] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "aoSBENO5rbWdOArH04KdqAAAAYI"]
[Tue Aug 18 12:58:08.429294 2026] [security2:error] [pid 66623:tid 66822] [client 158.158.34.183:31054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/hyIPpxWDQ.php"] [unique_id "aoSBENO5rbWdOArH04KdqQAAAUI"]
[Tue Aug 18 12:58:08.435897 2026] [security2:error] [pid 66623:tid 66815] [client 20.206.73.37:52033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/w.php"] [unique_id "aoSBENO5rbWdOArH04KdqgAAATs"]
[Tue Aug 18 12:58:08.471155 2026] [security2:error] [pid 66623:tid 66862] [client 20.119.58.187:12534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/img/cloud.php"] [unique_id "aoSBENO5rbWdOArH04KdrwAAAWo"]
[Tue Aug 18 12:58:08.481948 2026] [core:error] [pid 66623:tid 66881] [client 34.86.30.230:31824] AH10244: invalid URI path (/public/plugins/grafana-clock-panel/../../../../../../../../.env)
[Tue Aug 18 12:58:08.482115 2026] [security2:error] [pid 66623:tid 66859] [client 20.186.30.159:1671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/hel.php"] [unique_id "aoSBENO5rbWdOArH04KdsQAAAWc"]
[Tue Aug 18 12:58:08.529060 2026] [security2:error] [pid 66623:tid 66805] [client 197.184.64.235:41942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBENO5rbWdOArH04KdtQAAATE"]
[Tue Aug 18 12:58:08.529154 2026] [security2:error] [pid 66623:tid 66805] [client 197.184.64.235:41942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBENO5rbWdOArH04KdtQAAATE"]
[Tue Aug 18 12:58:08.541147 2026] [security2:error] [pid 66623:tid 66878] [client 172.182.217.32:15767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBENO5rbWdOArH04KdtwAAAXo"]
[Tue Aug 18 12:58:08.558480 2026] [security2:error] [pid 66623:tid 66869] [client 74.248.18.37:35384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/about.php"] [unique_id "aoSBENO5rbWdOArH04KdugAAAXE"]
[Tue Aug 18 12:58:08.559807 2026] [security2:error] [pid 66623:tid 66703] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/bgymj.php"] [unique_id "aoSBENO5rbWdOArH04KduwABaUI"]
[Tue Aug 18 12:58:08.564596 2026] [authz_core:error] [pid 66623:tid 66656] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:08.565008 2026] [authz_core:error] [pid 66623:tid 66656] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:08.574160 2026] [core:error] [pid 66623:tid 66797] [client 34.86.30.230:31832] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.env)
[Tue Aug 18 12:58:08.582614 2026] [proxy_http:error] [pid 66623:tid 66782] (20014)Internal error (specific information not available): [client 34.86.30.230:31866] AH01102: error reading status line from remote server 127.0.0.1:2095
[Tue Aug 18 12:58:08.585374 2026] [security2:error] [pid 66623:tid 66855] [client 20.206.73.37:5517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/fpwch.php"] [unique_id "aoSBENO5rbWdOArH04KdvgAAAWM"]
[Tue Aug 18 12:58:08.633901 2026] [security2:error] [pid 66623:tid 66844] [client 68.155.155.199:8104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/about.php"] [unique_id "aoSBENO5rbWdOArH04KdvwAAAVg"]
[Tue Aug 18 12:58:08.676630 2026] [security2:error] [pid 66623:tid 66835] [client 213.35.127.232:63040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBENO5rbWdOArH04KdwwAAAU8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:08.679010 2026] [security2:error] [pid 66623:tid 66801] [client 20.219.2.203:8577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBENO5rbWdOArH04KdxAAAAS0"]
[Tue Aug 18 12:58:08.716383 2026] [security2:error] [pid 66623:tid 66880] [client 20.206.73.37:24306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/FWAZ.php"] [unique_id "aoSBENO5rbWdOArH04KdxgAAAXw"]
[Tue Aug 18 12:58:08.728982 2026] [security2:error] [pid 66623:tid 66829] [client 20.48.236.86:25930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/ws13.php"] [unique_id "aoSBENO5rbWdOArH04KdyAAAAUk"]
[Tue Aug 18 12:58:08.740465 2026] [security2:error] [pid 66623:tid 66774] [client 158.23.17.4:38305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/sn.php"] [unique_id "aoSBENO5rbWdOArH04KdyQAAARI"]
[Tue Aug 18 12:58:08.745492 2026] [security2:error] [pid 66623:tid 66665] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/bi.php"] [unique_id "aoSBENO5rbWdOArH04KdygABChw"]
[Tue Aug 18 12:58:08.771557 2026] [security2:error] [pid 66623:tid 66868] [client 20.206.73.37:40647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/blurbs.php"] [unique_id "aoSBENO5rbWdOArH04KdzgAAAXA"]
[Tue Aug 18 12:58:08.801488 2026] [security2:error] [pid 66623:tid 66781] [client 20.118.133.132:21726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/ajax.php"] [unique_id "aoSBENO5rbWdOArH04Kd0AAAARk"]
[Tue Aug 18 12:58:08.813956 2026] [security2:error] [pid 66623:tid 66842] [client 74.248.18.37:20488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/mm.php"] [unique_id "aoSBENO5rbWdOArH04Kd0QAAAVY"]
[Tue Aug 18 12:58:08.815149 2026] [security2:error] [pid 66623:tid 66799] [client 172.182.200.96:7599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSBENO5rbWdOArH04Kd0gAAASs"]
[Tue Aug 18 12:58:08.820567 2026] [security2:error] [pid 66623:tid 66832] [client 20.186.30.159:1923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/grok.php"] [unique_id "aoSBENO5rbWdOArH04Kd0wAAAUw"]
[Tue Aug 18 12:58:08.828769 2026] [security2:error] [pid 66623:tid 66876] [client 20.119.58.187:11857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "aoSBENO5rbWdOArH04Kd1QAAAXg"]
[Tue Aug 18 12:58:08.830406 2026] [security2:error] [pid 66623:tid 66875] [client 158.158.74.177:26127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBENO5rbWdOArH04Kd1gAAAXc"]
[Tue Aug 18 12:58:08.835796 2026] [security2:error] [pid 66623:tid 66791] [client 20.206.73.37:52521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/100.php"] [unique_id "aoSBENO5rbWdOArH04Kd2QAAASM"]
[Tue Aug 18 12:58:08.858167 2026] [authz_core:error] [pid 66623:tid 66676] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:08.858495 2026] [authz_core:error] [pid 66623:tid 66676] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:08.860320 2026] [security2:error] [pid 66623:tid 66858] [client 40.74.65.169:64165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/yj09.php"] [unique_id "aoSBENO5rbWdOArH04Kd3AAAAWY"]
[Tue Aug 18 12:58:08.889498 2026] [security2:error] [pid 66623:tid 66874] [client 216.73.160.245:59469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaquimlirio333.com.br"] [uri "/wp-login.php"] [unique_id "aoSBENO5rbWdOArH04Kd3gAAAXY"]
[Tue Aug 18 12:58:08.926342 2026] [security2:error] [pid 66623:tid 66749] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/blog.php"] [unique_id "aoSBENO5rbWdOArH04Kd4QABNnA"]
[Tue Aug 18 12:58:08.957051 2026] [security2:error] [pid 66623:tid 66775] [client 20.79.204.6:11700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/db.php"] [unique_id "aoSBENO5rbWdOArH04Kd5AAAARM"]
[Tue Aug 18 12:58:08.969179 2026] [security2:error] [pid 66623:tid 66826] [client 20.100.185.105:35288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/index/function.php"] [unique_id "aoSBENO5rbWdOArH04Kd5QAAAUY"]
[Tue Aug 18 12:58:08.976410 2026] [security2:error] [pid 66623:tid 66777] [client 20.65.98.162:58055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/m.php"] [unique_id "aoSBENO5rbWdOArH04Kd5gAAARU"]
[Tue Aug 18 12:58:08.984172 2026] [security2:error] [pid 66623:tid 66854] [client 20.206.73.37:40694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/ccc.php"] [unique_id "aoSBENO5rbWdOArH04Kd5wAAAWI"]
[Tue Aug 18 12:58:09.000435 2026] [security2:error] [pid 66623:tid 66778] [client 20.203.138.185:19796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/c4.php"] [unique_id "aoSBENO5rbWdOArH04Kd6AAAARY"]
[Tue Aug 18 12:58:09.048097 2026] [security2:error] [pid 66623:tid 66887] [client 20.118.172.148:63049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBEdO5rbWdOArH04Kd6gAAAYM"]
[Tue Aug 18 12:58:09.048162 2026] [security2:error] [pid 66623:tid 66792] [client 172.182.217.32:12242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/in.php"] [unique_id "aoSBEdO5rbWdOArH04Kd6wAAASQ"]
[Tue Aug 18 12:58:09.080204 2026] [security2:error] [pid 66623:tid 66686] [remote 136.110.27.48:36776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nadianobre.com.br"] [uri "/phpinfo.php"] [unique_id "aoSBEdO5rbWdOArH04Kd7gABUzE"]
[Tue Aug 18 12:58:09.101596 2026] [security2:error] [pid 66623:tid 66859] [client 20.206.73.37:52083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/get.php"] [unique_id "aoSBEdO5rbWdOArH04Kd8AAAAWc"]
[Tue Aug 18 12:58:09.102241 2026] [security2:error] [pid 66623:tid 66857] [client 20.186.30.159:1967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/indes.php"] [unique_id "aoSBEdO5rbWdOArH04Kd8QAAAWU"]
[Tue Aug 18 12:58:09.102255 2026] [security2:error] [pid 66623:tid 66649] [remote 136.110.27.48:36776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nadianobre.com.br"] [uri "/info.php"] [unique_id "aoSBEdO5rbWdOArH04Kd8gABMAw"]
[Tue Aug 18 12:58:09.107658 2026] [security2:error] [pid 66623:tid 66723] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/bs1.php"] [unique_id "aoSBEdO5rbWdOArH04Kd9AABLFY"]
[Tue Aug 18 12:58:09.158916 2026] [authz_core:error] [pid 66623:tid 66750] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:09.159174 2026] [authz_core:error] [pid 66623:tid 66750] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:09.176761 2026] [security2:error] [pid 66623:tid 66823] [client 40.74.65.169:44769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/site.php"] [unique_id "aoSBEdO5rbWdOArH04Kd_gAAAUM"]
[Tue Aug 18 12:58:09.187748 2026] [security2:error] [pid 66623:tid 66796] [client 20.119.58.187:12083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/images/cloud.php"] [unique_id "aoSBEdO5rbWdOArH04KeAgAAASg"]
[Tue Aug 18 12:58:09.227750 2026] [security2:error] [pid 66623:tid 66834] [client 20.206.73.37:45799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/images.php"] [unique_id "aoSBEdO5rbWdOArH04KeBQAAAU4"]
[Tue Aug 18 12:58:09.273492 2026] [security2:error] [pid 66623:tid 66745] [remote 136.110.27.48:36776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nadianobre.com.br"] [uri "/i.php"] [unique_id "aoSBEdO5rbWdOArH04KeCAABQGw"]
[Tue Aug 18 12:58:09.282615 2026] [security2:error] [pid 66623:tid 66835] [client 20.206.73.37:40676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/alls.php"] [unique_id "aoSBEdO5rbWdOArH04KeCwAAAU8"]
[Tue Aug 18 12:58:09.286728 2026] [security2:error] [pid 66623:tid 66638] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/bthil.php"] [unique_id "aoSBEdO5rbWdOArH04KeDQABLQE"]
[Tue Aug 18 12:58:09.313085 2026] [security2:error] [pid 66623:tid 66880] [client 20.206.73.37:45813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/coffexium.php"] [unique_id "aoSBEdO5rbWdOArH04KeEwAAAXw"]
[Tue Aug 18 12:58:09.316552 2026] [authz_core:error] [pid 66623:tid 66657] [remote 89.124.86.18:55130] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:09.317018 2026] [authz_core:error] [pid 66623:tid 66657] [remote 89.124.86.18:55130] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:09.343387 2026] [security2:error] [pid 66623:tid 66774] [client 20.206.73.37:52051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/red.php"] [unique_id "aoSBEdO5rbWdOArH04KeFAAAARI"]
[Tue Aug 18 12:58:09.356948 2026] [security2:error] [pid 66623:tid 66878] [client 74.248.18.37:7210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSBEdO5rbWdOArH04KeFgAAAXo"]
[Tue Aug 18 12:58:09.394526 2026] [security2:error] [pid 66623:tid 66893] [client 20.186.30.159:1930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/tTPcH.php"] [unique_id "aoSBEdO5rbWdOArH04KeGwAAAYk"]
[Tue Aug 18 12:58:09.395943 2026] [security2:error] [pid 66623:tid 66798] [client 158.23.17.4:12520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/43.php"] [unique_id "aoSBEdO5rbWdOArH04KeHAAAASo"]
[Tue Aug 18 12:58:09.425714 2026] [security2:error] [pid 66623:tid 66817] [client 20.118.172.148:63044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSBEdO5rbWdOArH04KeHwAAAT0"]
[Tue Aug 18 12:58:09.431803 2026] [security2:error] [pid 66623:tid 66876] [client 20.206.73.37:52489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBEdO5rbWdOArH04KeIAAAAXg"]
[Tue Aug 18 12:58:09.452264 2026] [security2:error] [pid 66623:tid 66803] [client 20.118.172.148:56408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/aa.php"] [unique_id "aoSBEdO5rbWdOArH04KeIwAAAS8"]
[Tue Aug 18 12:58:09.476801 2026] [security2:error] [pid 66623:tid 66708] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/bypass.php"] [unique_id "aoSBEdO5rbWdOArH04KeJwABJkc"]
[Tue Aug 18 12:58:09.479040 2026] [security2:error] [pid 66623:tid 66890] [client 20.206.73.37:21705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/admin.php"] [unique_id "aoSBEdO5rbWdOArH04KeKQAAAYY"]
[Tue Aug 18 12:58:09.488468 2026] [security2:error] [pid 66623:tid 66874] [client 68.155.154.236:50427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBEdO5rbWdOArH04KeKgAAAXY"]
[Tue Aug 18 12:58:09.507662 2026] [security2:error] [pid 66623:tid 66811] [client 20.206.73.37:59791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/file52.php"] [unique_id "aoSBEdO5rbWdOArH04KeKwAAATc"]
[Tue Aug 18 12:58:09.510544 2026] [security2:error] [pid 66623:tid 66892] [client 68.155.155.199:13848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/admin.php"] [unique_id "aoSBEdO5rbWdOArH04KeLAAAAYg"]
[Tue Aug 18 12:58:09.533117 2026] [security2:error] [pid 66623:tid 66840] [client 40.74.65.169:49095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/scxy.php"] [unique_id "aoSBEdO5rbWdOArH04KeLQAAAVQ"]
[Tue Aug 18 12:58:09.536082 2026] [security2:error] [pid 66623:tid 66818] [client 20.206.73.37:52035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/geck.php"] [unique_id "aoSBEdO5rbWdOArH04KeLgAAAT4"]
[Tue Aug 18 12:58:09.538600 2026] [security2:error] [pid 66623:tid 66883] [client 74.248.18.37:54943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBEdO5rbWdOArH04KeLwAAAX8"]
[Tue Aug 18 12:58:09.542011 2026] [security2:error] [pid 66623:tid 66868] [client 172.182.217.32:15598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/info.php"] [unique_id "aoSBEdO5rbWdOArH04KeMAAAAXA"]
[Tue Aug 18 12:58:09.544847 2026] [security2:error] [pid 66623:tid 66841] [client 20.119.58.187:12516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/avaa.php"] [unique_id "aoSBEdO5rbWdOArH04KeMQAAAVU"]
[Tue Aug 18 12:58:09.565099 2026] [security2:error] [pid 66623:tid 66814] [client 20.79.204.6:11704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/dropdown.php"] [unique_id "aoSBEdO5rbWdOArH04KeMgAAATo"]
[Tue Aug 18 12:58:09.576284 2026] [security2:error] [pid 66623:tid 66786] [client 20.206.73.37:52087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/biufile.php"] [unique_id "aoSBEdO5rbWdOArH04KeNAAAAR4"]
[Tue Aug 18 12:58:09.587103 2026] [security2:error] [pid 66623:tid 66780] [client 20.100.185.105:6255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/getid3-core.php"] [unique_id "aoSBEdO5rbWdOArH04KeNQAAARg"]
[Tue Aug 18 12:58:09.607790 2026] [security2:error] [pid 66623:tid 66785] [client 20.206.73.37:59779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/dejavu.php"] [unique_id "aoSBEdO5rbWdOArH04KeNwAAAR0"]
[Tue Aug 18 12:58:09.627411 2026] [security2:error] [pid 66623:tid 66833] [client 20.219.2.203:8582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSBEdO5rbWdOArH04KeOQAAAU0"]
[Tue Aug 18 12:58:09.640327 2026] [security2:error] [pid 66623:tid 66777] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBEdO5rbWdOArH04KeOAABFWE"]
[Tue Aug 18 12:58:09.665857 2026] [security2:error] [pid 66623:tid 66815] [client 20.186.30.159:1802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/bs1.php"] [unique_id "aoSBEdO5rbWdOArH04KePAAAATs"]
[Tue Aug 18 12:58:09.698757 2026] [security2:error] [pid 66623:tid 66836] [client 158.158.74.177:26165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/options-privacy.php"] [unique_id "aoSBEdO5rbWdOArH04KePgAAAVA"]
[Tue Aug 18 12:58:09.698838 2026] [security2:error] [pid 66623:tid 66888] [client 213.35.127.232:63240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBEdO5rbWdOArH04KePQAAAYQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:09.700266 2026] [security2:error] [pid 66623:tid 66779] [client 20.203.138.185:38091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/an7.php"] [unique_id "aoSBEdO5rbWdOArH04KePwAAARc"]
[Tue Aug 18 12:58:09.704803 2026] [security2:error] [pid 66623:tid 66714] [remote 103.82.26.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.26.82.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yycc.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSBEdO5rbWdOArH04KeQAABS00"]
[Tue Aug 18 12:58:09.710985 2026] [security2:error] [pid 66623:tid 66792] [client 20.206.73.37:50088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/aaf.php"] [unique_id "aoSBEdO5rbWdOArH04KeQQAAASQ"]
[Tue Aug 18 12:58:09.755117 2026] [security2:error] [pid 66623:tid 66839] [client 20.118.172.148:2751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/atomlib.php"] [unique_id "aoSBEdO5rbWdOArH04KeQwAAAVM"]
[Tue Aug 18 12:58:09.779705 2026] [security2:error] [pid 66623:tid 66770] [client 20.48.236.86:32890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/btx25.php"] [unique_id "aoSBEdO5rbWdOArH04KeRgAAAQ4"]
[Tue Aug 18 12:58:09.862509 2026] [security2:error] [pid 66623:tid 66869] [client 20.65.98.162:60286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/33.php"] [unique_id "aoSBEdO5rbWdOArH04KeTAAAAXE"]
[Tue Aug 18 12:58:09.888831 2026] [security2:error] [pid 66623:tid 66819] [client 192.141.172.134:49955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBEdO5rbWdOArH04KeTgAAAT8"]
[Tue Aug 18 12:58:09.891301 2026] [security2:error] [pid 66623:tid 66819] [client 192.141.172.134:49955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBEdO5rbWdOArH04KeTgAAAT8"]
[Tue Aug 18 12:58:09.895021 2026] [security2:error] [pid 66623:tid 66783] [client 86.120.159.145:59156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBEdO5rbWdOArH04KeTwAAARs"]
[Tue Aug 18 12:58:09.895146 2026] [security2:error] [pid 66623:tid 66783] [client 86.120.159.145:59156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBEdO5rbWdOArH04KeTwAAARs"]
[Tue Aug 18 12:58:09.900834 2026] [security2:error] [pid 66623:tid 66825] [client 20.119.58.187:12501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/images/cloud.php"] [unique_id "aoSBEdO5rbWdOArH04KeUAAAAUU"]
[Tue Aug 18 12:58:09.911890 2026] [security2:error] [pid 66623:tid 66782] [client 20.186.30.159:1921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/hp2.php"] [unique_id "aoSBEdO5rbWdOArH04KeUQAAARo"]
[Tue Aug 18 12:58:09.914634 2026] [security2:error] [pid 66623:tid 66877] [client 20.118.172.148:54887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/abcd.php"] [unique_id "aoSBEdO5rbWdOArH04KeUgAAAXk"]
[Tue Aug 18 12:58:09.941697 2026] [security2:error] [pid 66623:tid 66754] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cc.php"] [unique_id "aoSBEdO5rbWdOArH04KeVQABWHU"]
[Tue Aug 18 12:58:09.994137 2026] [security2:error] [pid 66623:tid 66847] [client 20.206.73.37:20680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/blurbs.php"] [unique_id "aoSBEdO5rbWdOArH04KeVwAAAVs"]
[Tue Aug 18 12:58:09.994199 2026] [security2:error] [pid 66623:tid 66867] [client 20.206.73.37:59839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSBEdO5rbWdOArH04KeWAAAAW8"]
[Tue Aug 18 12:58:10.001545 2026] [security2:error] [pid 66623:tid 66812] [client 40.74.65.169:29626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSBEtO5rbWdOArH04KeWQAAATg"]
[Tue Aug 18 12:58:10.020619 2026] [security2:error] [pid 66623:tid 66838] [client 158.23.17.4:8952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/fresh.php"] [unique_id "aoSBEtO5rbWdOArH04KeWwAAAVI"]
[Tue Aug 18 12:58:10.030570 2026] [security2:error] [pid 66623:tid 66870] [client 172.182.217.32:15553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/inputs.php"] [unique_id "aoSBEtO5rbWdOArH04KeXQAAAXI"]
[Tue Aug 18 12:58:10.044852 2026] [security2:error] [pid 66623:tid 66781] [client 34.86.30.230:31870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.30.86.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nightblue.com.br"] [uri "/.env.php"] [unique_id "aoSBEtO5rbWdOArH04KeXgAAARk"]
[Tue Aug 18 12:58:10.055912 2026] [security2:error] [pid 66623:tid 66851] [client 74.248.18.37:31838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/admin.php"] [unique_id "aoSBEtO5rbWdOArH04KeYAAAAV8"]
[Tue Aug 18 12:58:10.062603 2026] [authz_core:error] [pid 66623:tid 66637] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:10.062878 2026] [authz_core:error] [pid 66623:tid 66637] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:10.121105 2026] [security2:error] [pid 66623:tid 66675] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSBEtO5rbWdOArH04KeYwABdyY"]
[Tue Aug 18 12:58:10.153603 2026] [security2:error] [pid 66623:tid 66803] [client 20.186.30.159:1951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/yb.php"] [unique_id "aoSBEtO5rbWdOArH04KeZQAAAS8"]
[Tue Aug 18 12:58:10.171696 2026] [security2:error] [pid 66623:tid 66801] [client 20.79.204.6:11675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/file.php"] [unique_id "aoSBEtO5rbWdOArH04KeZgAAAS0"]
[Tue Aug 18 12:58:10.228647 2026] [security2:error] [pid 66623:tid 66840] [client 40.74.65.169:49063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSBEtO5rbWdOArH04KebQAAAVQ"]
[Tue Aug 18 12:58:10.256349 2026] [security2:error] [pid 66623:tid 66791] [client 20.119.58.187:11849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "aoSBEtO5rbWdOArH04KebgAAASM"]
[Tue Aug 18 12:58:10.325838 2026] [security2:error] [pid 66623:tid 66786] [client 20.118.172.148:53066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/min.php"] [unique_id "aoSBEtO5rbWdOArH04KecwAAAR4"]
[Tue Aug 18 12:58:10.352409 2026] [security2:error] [pid 66623:tid 66872] [client 74.248.18.37:7201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ms-themes.php"] [unique_id "aoSBEtO5rbWdOArH04KedAAAAXQ"]
[Tue Aug 18 12:58:10.405541 2026] [security2:error] [pid 66623:tid 66853] [client 20.186.30.159:1665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/vc.php"] [unique_id "aoSBEtO5rbWdOArH04KedwAAAWE"]
[Tue Aug 18 12:58:10.425197 2026] [security2:error] [pid 66623:tid 66884] [client 68.155.155.199:1306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBEtO5rbWdOArH04KeeAAAAYA"]
[Tue Aug 18 12:58:10.440654 2026] [security2:error] [pid 66623:tid 66871] [client 20.100.185.105:58320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/edit.php"] [unique_id "aoSBEtO5rbWdOArH04KeegAAAXM"]
[Tue Aug 18 12:58:10.520812 2026] [security2:error] [pid 66623:tid 66785] [client 172.182.217.32:15604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/item.php"] [unique_id "aoSBEtO5rbWdOArH04KehAAAAR0"]
[Tue Aug 18 12:58:10.520877 2026] [security2:error] [pid 66623:tid 66767] [client 158.158.34.183:31073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/randkeyword.php"] [unique_id "aoSBEtO5rbWdOArH04KehQAAAQs"]
[Tue Aug 18 12:58:10.523425 2026] [security2:error] [pid 66623:tid 66857] [client 20.118.172.148:56540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/admin.php"] [unique_id "aoSBEtO5rbWdOArH04KehgAAAWU"]
[Tue Aug 18 12:58:10.532996 2026] [security2:error] [pid 66623:tid 66841] [client 79.127.164.8:40180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/pma.bak"] [unique_id "aoSBEtO5rbWdOArH04KehwAAAVU"], referer: https://medihub.com.br/pma.bak
[Tue Aug 18 12:58:10.534712 2026] [security2:error] [pid 66623:tid 66886] [client 20.206.73.37:24265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/155.php"] [unique_id "aoSBEtO5rbWdOArH04KeiAAAAYI"]
[Tue Aug 18 12:58:10.602530 2026] [security2:error] [pid 66623:tid 66819] [client 20.203.138.185:54986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/bsg-management/php.php"] [unique_id "aoSBEtO5rbWdOArH04KejAAAAT8"]
[Tue Aug 18 12:58:10.621542 2026] [security2:error] [pid 66623:tid 66864] [client 20.119.58.187:12495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "aoSBEtO5rbWdOArH04KejwAAAWw"]
[Tue Aug 18 12:58:10.665214 2026] [authz_core:error] [pid 66623:tid 66748] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:10.665486 2026] [authz_core:error] [pid 66623:tid 66748] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:10.670988 2026] [security2:error] [pid 66623:tid 66807] [client 20.186.30.159:1981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/pema.php"] [unique_id "aoSBEtO5rbWdOArH04KelQAAATM"]
[Tue Aug 18 12:58:10.687015 2026] [security2:error] [pid 66623:tid 66834] [client 52.173.121.69:24771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSBEtO5rbWdOArH04KelgAAAU4"]
[Tue Aug 18 12:58:10.703414 2026] [security2:error] [pid 66623:tid 66850] [client 20.104.85.180:45984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBEtO5rbWdOArH04KelwAAAV4"]
[Tue Aug 18 12:58:10.710971 2026] [security2:error] [pid 66623:tid 66843] [client 20.118.172.148:46771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/mac.php"] [unique_id "aoSBEtO5rbWdOArH04KemAAAAVc"]
[Tue Aug 18 12:58:10.723871 2026] [security2:error] [pid 66623:tid 66777] [client 213.35.127.232:63451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBEtO5rbWdOArH04KemQAAARU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:10.732864 2026] [security2:error] [pid 66623:tid 66820] [client 20.118.133.132:1916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/yj09.php"] [unique_id "aoSBEtO5rbWdOArH04KemgAAAUA"]
[Tue Aug 18 12:58:10.736044 2026] [security2:error] [pid 66623:tid 66823] [client 40.74.65.169:7405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/cabs.php"] [unique_id "aoSBEtO5rbWdOArH04KemwAAAUM"]
[Tue Aug 18 12:58:10.739412 2026] [security2:error] [pid 66623:tid 66845] [client 158.23.17.4:8958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/gj.php"] [unique_id "aoSBEtO5rbWdOArH04KenAAAAVk"]
[Tue Aug 18 12:58:10.774973 2026] [security2:error] [pid 66623:tid 66805] [client 20.79.204.6:11698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/goods.php"] [unique_id "aoSBEtO5rbWdOArH04KengAAATE"]
[Tue Aug 18 12:58:10.788892 2026] [security2:error] [pid 66623:tid 66880] [client 20.48.236.86:32838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSBEtO5rbWdOArH04KeoQAAAXw"]
[Tue Aug 18 12:58:10.863801 2026] [security2:error] [pid 66623:tid 66759] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "aoSBEtO5rbWdOArH04KepAABeHo"]
[Tue Aug 18 12:58:10.886421 2026] [security2:error] [pid 66623:tid 66877] [client 74.248.18.37:54932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBEtO5rbWdOArH04KepQAAAXk"]
[Tue Aug 18 12:58:10.900491 2026] [security2:error] [pid 66623:tid 66859] [client 68.155.154.236:7905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBEtO5rbWdOArH04KepgAAAWc"]
[Tue Aug 18 12:58:10.907459 2026] [security2:error] [pid 66623:tid 66801] [client 40.74.65.169:49078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBEtO5rbWdOArH04KepwAAAS0"]
[Tue Aug 18 12:58:10.920165 2026] [security2:error] [pid 66623:tid 66794] [client 20.186.30.159:1938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/sh.php"] [unique_id "aoSBEtO5rbWdOArH04KeqAAAASY"]
[Tue Aug 18 12:58:10.929916 2026] [security2:error] [pid 66623:tid 66881] [client 158.158.74.177:26149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/options.php"] [unique_id "aoSBEtO5rbWdOArH04KeqQAAAX0"]
[Tue Aug 18 12:58:10.965513 2026] [authz_core:error] [pid 66623:tid 66663] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:10.965804 2026] [authz_core:error] [pid 66623:tid 66663] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:10.974656 2026] [security2:error] [pid 66623:tid 66771] [client 20.119.58.187:11874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "aoSBEtO5rbWdOArH04KerQAAAQ8"]
[Tue Aug 18 12:58:11.017259 2026] [security2:error] [pid 66623:tid 66829] [client 172.182.217.32:15597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/k.php"] [unique_id "aoSBE9O5rbWdOArH04KergAAAUk"]
[Tue Aug 18 12:58:11.046004 2026] [security2:error] [pid 66623:tid 66827] [client 74.248.18.37:21544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/my1.php"] [unique_id "aoSBE9O5rbWdOArH04KesAAAAUc"]
[Tue Aug 18 12:58:11.089331 2026] [security2:error] [pid 66623:tid 66883] [client 20.118.172.148:46741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/nc4.php"] [unique_id "aoSBE9O5rbWdOArH04KetAAAAX8"]
[Tue Aug 18 12:58:11.200143 2026] [security2:error] [pid 66623:tid 66854] [client 172.182.200.96:14151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/MTOS/byp.php"] [unique_id "aoSBE9O5rbWdOArH04KeuAAAAWI"]
[Tue Aug 18 12:58:11.267530 2026] [authz_core:error] [pid 66623:tid 66716] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:11.267815 2026] [authz_core:error] [pid 66623:tid 66716] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:11.283850 2026] [security2:error] [pid 66623:tid 66846] [client 20.100.185.105:59767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "aoSBE9O5rbWdOArH04KewAAAAVo"]
[Tue Aug 18 12:58:11.302757 2026] [security2:error] [pid 66623:tid 66766] [client 158.23.17.4:6339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/pd.php"] [unique_id "aoSBE9O5rbWdOArH04KewQAAAQo"]
[Tue Aug 18 12:58:11.336452 2026] [security2:error] [pid 66623:tid 66853] [client 20.119.58.187:12064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/includes/cloud.php"] [unique_id "aoSBE9O5rbWdOArH04KewwAAAWE"]
[Tue Aug 18 12:58:11.337842 2026] [security2:error] [pid 66623:tid 66839] [client 20.206.73.37:59785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/ops.php"] [unique_id "aoSBE9O5rbWdOArH04KexAAAAVM"]
[Tue Aug 18 12:58:11.343784 2026] [security2:error] [pid 66623:tid 66813] [client 20.186.30.159:1847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/button.php"] [unique_id "aoSBE9O5rbWdOArH04KexQAAATk"]
[Tue Aug 18 12:58:11.348552 2026] [security2:error] [pid 66623:tid 66757] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "aoSBE9O5rbWdOArH04KexwABTXg"]
[Tue Aug 18 12:58:11.350996 2026] [security2:error] [pid 66623:tid 66855] [client 103.184.169.37:42308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBE9O5rbWdOArH04KeyAAAAWM"]
[Tue Aug 18 12:58:11.351088 2026] [security2:error] [pid 66623:tid 66855] [client 103.184.169.37:42308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBE9O5rbWdOArH04KeyAAAAWM"]
[Tue Aug 18 12:58:11.370279 2026] [security2:error] [pid 66623:tid 66804] [client 20.104.85.180:26285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBE9O5rbWdOArH04KeyQAAATA"]
[Tue Aug 18 12:58:11.376172 2026] [security2:error] [pid 66623:tid 66787] [client 20.79.204.6:11564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBE9O5rbWdOArH04KeywAAAR8"]
[Tue Aug 18 12:58:11.385622 2026] [security2:error] [pid 66623:tid 66784] [client 68.155.154.236:65492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/blog/byp.php"] [unique_id "aoSBE9O5rbWdOArH04KezAAAARw"]
[Tue Aug 18 12:58:11.400135 2026] [security2:error] [pid 66623:tid 66800] [client 20.203.138.185:38136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/byp8.php"] [unique_id "aoSBE9O5rbWdOArH04KezgAAASw"]
[Tue Aug 18 12:58:11.406637 2026] [security2:error] [pid 66623:tid 66796] [client 20.118.172.148:62116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBE9O5rbWdOArH04Ke0AAAASg"]
[Tue Aug 18 12:58:11.435686 2026] [security2:error] [pid 66623:tid 66797] [client 40.74.65.169:35774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/insc.php"] [unique_id "aoSBE9O5rbWdOArH04Ke0QAAASk"]
[Tue Aug 18 12:58:11.441469 2026] [security2:error] [pid 66623:tid 66786] [client 158.158.34.183:53253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/ewywe1dg.php"] [unique_id "aoSBE9O5rbWdOArH04Ke0gAAAR4"]
[Tue Aug 18 12:58:11.451315 2026] [security2:error] [pid 66623:tid 66819] [client 20.118.172.148:53067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/as.php"] [unique_id "aoSBE9O5rbWdOArH04Ke0wAAAT8"]
[Tue Aug 18 12:58:11.479348 2026] [security2:error] [pid 66623:tid 66781] [client 188.82.68.190:35278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoSBE9O5rbWdOArH04KevQABGW4"], referer: https://bioarquitetar.com/xmlrpc.php
[Tue Aug 18 12:58:11.500330 2026] [security2:error] [pid 66623:tid 66822] [client 172.182.217.32:15776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/license.php"] [unique_id "aoSBE9O5rbWdOArH04Ke1QAAAUI"]
[Tue Aug 18 12:58:11.522073 2026] [security2:error] [pid 66623:tid 66843] [client 52.173.121.69:16489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSBE9O5rbWdOArH04Ke1gAAAVc"]
[Tue Aug 18 12:58:11.530041 2026] [security2:error] [pid 66623:tid 66693] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/wp-settings.php"] [unique_id "aoSBE9O5rbWdOArH04Ke1wABQDg"]
[Tue Aug 18 12:58:11.550172 2026] [security2:error] [pid 66623:tid 66821] [client 20.100.169.31:32721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBE9O5rbWdOArH04Ke2QAAAUE"]
[Tue Aug 18 12:58:11.590082 2026] [security2:error] [pid 66623:tid 66812] [client 40.74.65.169:49138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/blurbs.php"] [unique_id "aoSBE9O5rbWdOArH04Ke3QAAATg"]
[Tue Aug 18 12:58:11.591772 2026] [security2:error] [pid 66623:tid 66808] [client 68.155.155.199:7253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/as.php"] [unique_id "aoSBE9O5rbWdOArH04Ke3gAAATQ"]
[Tue Aug 18 12:58:11.600852 2026] [security2:error] [pid 66623:tid 66882] [client 20.186.30.159:1939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/wlc.php"] [unique_id "aoSBE9O5rbWdOArH04Ke3wAAAX4"]
[Tue Aug 18 12:58:11.615179 2026] [security2:error] [pid 66623:tid 66890] [client 103.120.71.157:57646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBE9O5rbWdOArH04Ke4AAAAYY"]
[Tue Aug 18 12:58:11.615313 2026] [security2:error] [pid 66623:tid 66890] [client 103.120.71.157:57646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBE9O5rbWdOArH04Ke4AAAAYY"]
[Tue Aug 18 12:58:11.692186 2026] [security2:error] [pid 66623:tid 66867] [client 20.119.58.187:12525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "aoSBE9O5rbWdOArH04Ke5AAAAW8"]
[Tue Aug 18 12:58:11.711166 2026] [security2:error] [pid 66623:tid 66865] [client 74.248.18.37:54972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/new.php"] [unique_id "aoSBE9O5rbWdOArH04Ke5QAAAW0"]
[Tue Aug 18 12:58:11.715275 2026] [security2:error] [pid 66623:tid 66724] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "aoSBE9O5rbWdOArH04Ke5gABfVc"]
[Tue Aug 18 12:58:11.734421 2026] [security2:error] [pid 66623:tid 66790] [client 172.182.200.96:7668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSBE9O5rbWdOArH04Ke5wAAASI"]
[Tue Aug 18 12:58:11.741193 2026] [security2:error] [pid 66623:tid 66873] [client 213.35.127.232:63650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBE9O5rbWdOArH04Ke6AAAAXU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:11.813270 2026] [security2:error] [pid 66623:tid 66878] [client 20.118.172.148:43496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/k.php"] [unique_id "aoSBE9O5rbWdOArH04Ke7AAAAXo"]
[Tue Aug 18 12:58:11.815545 2026] [security2:error] [pid 66623:tid 66802] [client 158.158.74.177:2625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/plugin-install.php"] [unique_id "aoSBE9O5rbWdOArH04Ke7QAAAS4"]
[Tue Aug 18 12:58:11.857543 2026] [security2:error] [pid 66623:tid 66818] [client 20.186.30.159:1946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/fi.php"] [unique_id "aoSBE9O5rbWdOArH04Ke8AAAAT4"]
[Tue Aug 18 12:58:11.879158 2026] [security2:error] [pid 66623:tid 66816] [client 20.118.172.148:56526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/akc.php"] [unique_id "aoSBE9O5rbWdOArH04Ke8gAAATw"]
[Tue Aug 18 12:58:11.892077 2026] [security2:error] [pid 66623:tid 66761] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/config.php"] [unique_id "aoSBE9O5rbWdOArH04Ke8wABNnw"]
[Tue Aug 18 12:58:11.894424 2026] [security2:error] [pid 66623:tid 66817] [client 74.248.18.37:7215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/about.php"] [unique_id "aoSBE9O5rbWdOArH04Ke9AAAAT0"]
[Tue Aug 18 12:58:11.903682 2026] [security2:error] [pid 66623:tid 66803] [client 20.100.185.105:59745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSBE9O5rbWdOArH04Ke9QAAAS8"]
[Tue Aug 18 12:58:11.906100 2026] [security2:error] [pid 66623:tid 66780] [client 20.215.241.237:52676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBE9O5rbWdOArH04Ke9gAAARg"]
[Tue Aug 18 12:58:11.929870 2026] [security2:error] [pid 66623:tid 66854] [client 20.48.236.86:48715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBE9O5rbWdOArH04Ke9wAAAWI"]
[Tue Aug 18 12:58:11.977103 2026] [security2:error] [pid 66623:tid 66827] [client 20.79.204.6:11652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/htaccess.php"] [unique_id "aoSBE9O5rbWdOArH04Ke-QAAAUc"]
[Tue Aug 18 12:58:11.993820 2026] [security2:error] [pid 66623:tid 66791] [client 172.182.217.32:15755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/load.php"] [unique_id "aoSBE9O5rbWdOArH04Ke-gAAASM"]
[Tue Aug 18 12:58:12.005151 2026] [security2:error] [pid 66623:tid 66792] [client 20.118.133.132:16368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/scxy.php"] [unique_id "aoSBFNO5rbWdOArH04Ke-wAAASQ"]
[Tue Aug 18 12:58:12.044009 2026] [security2:error] [pid 66623:tid 66853] [client 20.203.138.185:10599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/plugins.php"] [unique_id "aoSBFNO5rbWdOArH04Ke_QAAAWE"]
[Tue Aug 18 12:58:12.053587 2026] [security2:error] [pid 66623:tid 66839] [client 68.155.154.236:51424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBFNO5rbWdOArH04Ke_gAAAVM"]
[Tue Aug 18 12:58:12.054567 2026] [security2:error] [pid 66623:tid 66785] [client 52.173.121.69:16502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSBFNO5rbWdOArH04Ke_wAAAR0"]
[Tue Aug 18 12:58:12.064638 2026] [security2:error] [pid 66623:tid 66789] [client 20.206.73.37:45811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/mac.php"] [unique_id "aoSBFNO5rbWdOArH04KfAAAAASE"]
[Tue Aug 18 12:58:12.067016 2026] [security2:error] [pid 66623:tid 66683] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSBFNO5rbWdOArH04KfAQABCy4"]
[Tue Aug 18 12:58:12.073535 2026] [security2:error] [pid 66623:tid 66795] [client 20.104.85.180:42261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/admin.php"] [unique_id "aoSBFNO5rbWdOArH04KfAwAAASc"]
[Tue Aug 18 12:58:12.099701 2026] [security2:error] [pid 66623:tid 66779] [client 20.119.58.187:12521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/cloud.php"] [unique_id "aoSBFNO5rbWdOArH04KfBgAAARc"]
[Tue Aug 18 12:58:12.106877 2026] [security2:error] [pid 66623:tid 66787] [client 20.186.30.159:1975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/chris.php"] [unique_id "aoSBFNO5rbWdOArH04KfBwAAAR8"]
[Tue Aug 18 12:58:12.167643 2026] [security2:error] [pid 66623:tid 66834] [client 40.74.65.169:44771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/file.php"] [unique_id "aoSBFNO5rbWdOArH04KfCwAAAU4"]
[Tue Aug 18 12:58:12.170491 2026] [authz_core:error] [pid 66623:tid 66749] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:12.171002 2026] [authz_core:error] [pid 66623:tid 66749] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:12.214439 2026] [security2:error] [pid 66623:tid 66769] [client 37.40.227.74:56528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFNO5rbWdOArH04KfDQAAAQ0"]
[Tue Aug 18 12:58:12.214540 2026] [security2:error] [pid 66623:tid 66769] [client 37.40.227.74:56528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFNO5rbWdOArH04KfDQAAAQ0"]
[Tue Aug 18 12:58:12.231244 2026] [security2:error] [pid 66623:tid 66832] [client 20.118.172.148:53100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSBFNO5rbWdOArH04KfDwAAAUw"]
[Tue Aug 18 12:58:12.272191 2026] [security2:error] [pid 66623:tid 66778] [client 213.202.253.4:52498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/wp-content/txets.php"] [unique_id "aoSBFNO5rbWdOArH04KfEQAAARY"], referer: www.google.com
[Tue Aug 18 12:58:12.273167 2026] [security2:error] [pid 66623:tid 66686] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/module.php"] [unique_id "aoSBFNO5rbWdOArH04KfEgABgjE"]
[Tue Aug 18 12:58:12.274958 2026] [security2:error] [pid 66623:tid 66847] [client 20.118.172.148:56436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/buy.php"] [unique_id "aoSBFNO5rbWdOArH04KfEwAAAVs"]
[Tue Aug 18 12:58:12.289615 2026] [security2:error] [pid 66623:tid 66885] [client 40.74.65.169:49151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/bajah.php"] [unique_id "aoSBFNO5rbWdOArH04KfFgAAAYE"]
[Tue Aug 18 12:58:12.336861 2026] [security2:error] [pid 66623:tid 66893] [client 158.23.17.4:34002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/th.php"] [unique_id "aoSBFNO5rbWdOArH04KfGQAAAYk"]
[Tue Aug 18 12:58:12.370254 2026] [security2:error] [pid 66623:tid 66819] [client 74.248.18.37:21549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/norn.php"] [unique_id "aoSBFNO5rbWdOArH04KfGgAAAT8"]
[Tue Aug 18 12:58:12.387233 2026] [security2:error] [pid 66623:tid 66857] [client 20.186.30.159:1928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/doc.php"] [unique_id "aoSBFNO5rbWdOArH04KfGwAAAWU"]
[Tue Aug 18 12:58:12.411607 2026] [security2:error] [pid 66623:tid 66763] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBFNO5rbWdOArH04KfHQABLX4"]
[Tue Aug 18 12:58:12.426108 2026] [security2:error] [pid 66623:tid 66728] [remote 162.214.205.212:48562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tersaudefitness.com.br.elizangelabrito.com.br"] [uri "/wp-login.php"] [unique_id "aoSBFNO5rbWdOArH04KfHwABS1s"]
[Tue Aug 18 12:58:12.430501 2026] [security2:error] [pid 66623:tid 66874] [client 68.155.155.199:4981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/bolt.php"] [unique_id "aoSBFNO5rbWdOArH04KfIAAAAXY"]
[Tue Aug 18 12:58:12.451785 2026] [security2:error] [pid 66623:tid 66646] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/options.php"] [unique_id "aoSBFNO5rbWdOArH04KfIgABIgk"]
[Tue Aug 18 12:58:12.458073 2026] [security2:error] [pid 66623:tid 66890] [client 20.119.58.187:11894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/libraries/legacy/updates.php"] [unique_id "aoSBFNO5rbWdOArH04KfIwAAAYY"]
[Tue Aug 18 12:58:12.471911 2026] [security2:error] [pid 66623:tid 66797] [client 20.100.169.31:32730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/h.php"] [unique_id "aoSBFNO5rbWdOArH04KfJQAAASk"]
[Tue Aug 18 12:58:12.476251 2026] [authz_core:error] [pid 66623:tid 66698] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:12.476665 2026] [authz_core:error] [pid 66623:tid 66698] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:12.482496 2026] [security2:error] [pid 66623:tid 66838] [client 172.182.217.32:15746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/manager.php"] [unique_id "aoSBFNO5rbWdOArH04KfJgAAAVI"]
[Tue Aug 18 12:58:12.528792 2026] [security2:error] [pid 66623:tid 66830] [client 68.155.154.236:46647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBFNO5rbWdOArH04KfKgAAAUo"]
[Tue Aug 18 12:58:12.580038 2026] [security2:error] [pid 66623:tid 66859] [client 20.79.204.6:11708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/images/wso.php"] [unique_id "aoSBFNO5rbWdOArH04KfMAAAAWc"]
[Tue Aug 18 12:58:12.603537 2026] [security2:error] [pid 66623:tid 66810] [client 20.206.73.37:6080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBFNO5rbWdOArH04KfMgAAATY"]
[Tue Aug 18 12:58:12.605509 2026] [security2:error] [pid 66623:tid 66875] [client 74.248.18.37:21510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSBFNO5rbWdOArH04KfMwAAAXc"]
[Tue Aug 18 12:58:12.630057 2026] [security2:error] [pid 66623:tid 66694] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/panel.php"] [unique_id "aoSBFNO5rbWdOArH04KfNAABRDk"]
[Tue Aug 18 12:58:12.639291 2026] [security2:error] [pid 66623:tid 66872] [client 20.118.172.148:54907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/cong.php"] [unique_id "aoSBFNO5rbWdOArH04KfNQAAAXQ"]
[Tue Aug 18 12:58:12.666756 2026] [security2:error] [pid 66623:tid 66814] [client 20.186.30.159:1945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/1337.php"] [unique_id "aoSBFNO5rbWdOArH04KfOAAAATo"]
[Tue Aug 18 12:58:12.705892 2026] [security2:error] [pid 66623:tid 66836] [client 20.118.172.148:2728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/system_log.php"] [unique_id "aoSBFNO5rbWdOArH04KfOwAAAVA"]
[Tue Aug 18 12:58:12.730499 2026] [security2:error] [pid 66623:tid 66888] [client 20.100.185.105:6211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-file.php"] [unique_id "aoSBFNO5rbWdOArH04KfPAAAAYQ"]
[Tue Aug 18 12:58:12.754075 2026] [security2:error] [pid 66623:tid 66792] [client 20.104.85.180:14075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/public/css.php"] [unique_id "aoSBFNO5rbWdOArH04KfPQAAASQ"]
[Tue Aug 18 12:58:12.754270 2026] [security2:error] [pid 66623:tid 66823] [client 213.35.127.232:63853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBFNO5rbWdOArH04KfPgAAAUM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:12.770487 2026] [authz_core:error] [pid 66623:tid 66745] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:12.770878 2026] [authz_core:error] [pid 66623:tid 66745] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:12.808210 2026] [security2:error] [pid 66623:tid 66667] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/wp-activate.php"] [unique_id "aoSBFNO5rbWdOArH04KfRAABCx4"]
[Tue Aug 18 12:58:12.814020 2026] [security2:error] [pid 66623:tid 66871] [client 20.119.58.187:12505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/libraries/phpmailer/updates.php"] [unique_id "aoSBFNO5rbWdOArH04KfRQAAAXM"]
[Tue Aug 18 12:58:12.831685 2026] [security2:error] [pid 66623:tid 66804] [client 158.23.17.4:12537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/admin404.php"] [unique_id "aoSBFNO5rbWdOArH04KfRgAAATA"]
[Tue Aug 18 12:58:12.836809 2026] [security2:error] [pid 66623:tid 66779] [client 20.203.138.185:39035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/100.kb.php"] [unique_id "aoSBFNO5rbWdOArH04KfRwAAARc"]
[Tue Aug 18 12:58:12.855758 2026] [security2:error] [pid 66623:tid 66787] [client 20.48.236.86:32849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBFNO5rbWdOArH04KfSAAAAR8"]
[Tue Aug 18 12:58:12.925104 2026] [security2:error] [pid 66623:tid 66826] [client 40.74.65.169:31908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/dex.php"] [unique_id "aoSBFNO5rbWdOArH04KfSwAAAUY"]
[Tue Aug 18 12:58:12.944233 2026] [security2:error] [pid 66623:tid 66776] [client 20.186.30.159:1674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/Njima.php"] [unique_id "aoSBFNO5rbWdOArH04KfTQAAARQ"]
[Tue Aug 18 12:58:12.968455 2026] [security2:error] [pid 66623:tid 66833] [client 172.182.217.32:15781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/media.php"] [unique_id "aoSBFNO5rbWdOArH04KfTwAAAU0"]
[Tue Aug 18 12:58:12.976972 2026] [security2:error] [pid 66623:tid 66866] [client 158.158.74.177:16550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/wp-cron.php"] [unique_id "aoSBFNO5rbWdOArH04KfUAAAAW4"]
[Tue Aug 18 12:58:12.986914 2026] [security2:error] [pid 66623:tid 66732] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/wp-blog-header.php"] [unique_id "aoSBFNO5rbWdOArH04KfUQABDV8"]
[Tue Aug 18 12:58:12.987839 2026] [security2:error] [pid 66623:tid 66822] [client 40.74.65.169:49071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/domvf.php"] [unique_id "aoSBFNO5rbWdOArH04KfUgAAAUI"]
[Tue Aug 18 12:58:12.992704 2026] [security2:error] [pid 66623:tid 66820] [client 20.206.73.37:21707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSBFNO5rbWdOArH04KfUwAAAUA"]
[Tue Aug 18 12:58:13.005658 2026] [security2:error] [pid 66623:tid 66764] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBFdO5rbWdOArH04KfVAABLH8"]
[Tue Aug 18 12:58:13.016559 2026] [security2:error] [pid 66623:tid 66835] [client 68.155.154.236:7665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/images/security.php"] [unique_id "aoSBFdO5rbWdOArH04KfVQAAAU8"]
[Tue Aug 18 12:58:13.032772 2026] [security2:error] [pid 66623:tid 66856] [client 20.118.172.148:33528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/x.php"] [unique_id "aoSBFdO5rbWdOArH04KfVwAAAWQ"]
[Tue Aug 18 12:58:13.059084 2026] [authz_core:error] [pid 66623:tid 66864] [client 192.178.4.134:64604] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:13.059358 2026] [authz_core:error] [pid 66623:tid 66864] [client 192.178.4.134:64604] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:13.061629 2026] [security2:error] [pid 66623:tid 66847] [client 20.118.172.148:54896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSBFdO5rbWdOArH04KfWgAAAVs"]
[Tue Aug 18 12:58:13.077428 2026] [authz_core:error] [pid 66623:tid 66756] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:13.077868 2026] [authz_core:error] [pid 66623:tid 66756] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:13.095144 2026] [security2:error] [pid 66623:tid 66803] [client 149.34.210.141:60605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfXAAAAS8"]
[Tue Aug 18 12:58:13.100060 2026] [security2:error] [pid 66623:tid 66865] [client 5.31.227.224:7846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfXgAAAW0"]
[Tue Aug 18 12:58:13.100154 2026] [security2:error] [pid 66623:tid 66865] [client 5.31.227.224:7846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfXgAAAW0"]
[Tue Aug 18 12:58:13.104278 2026] [security2:error] [pid 66623:tid 66808] [client 157.20.138.62:51307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfXwAAATQ"]
[Tue Aug 18 12:58:13.104385 2026] [security2:error] [pid 66623:tid 66808] [client 157.20.138.62:51307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfXwAAATQ"]
[Tue Aug 18 12:58:13.154537 2026] [security2:error] [pid 66623:tid 66784] [client 74.248.18.37:7220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/num.php"] [unique_id "aoSBFdO5rbWdOArH04KfYwAAARw"]
[Tue Aug 18 12:58:13.164936 2026] [security2:error] [pid 66623:tid 66778] [client 20.119.58.187:11885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/libraries/vendor/updates.php"] [unique_id "aoSBFdO5rbWdOArH04KfZAAAARY"]
[Tue Aug 18 12:58:13.169325 2026] [security2:error] [pid 66623:tid 66743] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfZQABEmo"]
[Tue Aug 18 12:58:13.177946 2026] [security2:error] [pid 66623:tid 66831] [client 68.155.155.199:3112] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/cgi-bin/"] [unique_id "aoSBFdO5rbWdOArH04KfZgAAAUs"]
[Tue Aug 18 12:58:13.180686 2026] [security2:error] [pid 66623:tid 66874] [client 20.206.73.37:55643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/system_log.php"] [unique_id "aoSBFdO5rbWdOArH04KfZwAAAXY"]
[Tue Aug 18 12:58:13.186302 2026] [security2:error] [pid 66623:tid 66850] [client 20.79.204.6:11653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/index/function.php"] [unique_id "aoSBFdO5rbWdOArH04KfaAAAAV4"]
[Tue Aug 18 12:58:13.186801 2026] [security2:error] [pid 66623:tid 66793] [client 20.186.30.159:1934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/BIBIL.php"] [unique_id "aoSBFdO5rbWdOArH04KfaQAAASU"]
[Tue Aug 18 12:58:13.238245 2026] [security2:error] [pid 66623:tid 66680] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/st.php"] [unique_id "aoSBFdO5rbWdOArH04KfawABJis"]
[Tue Aug 18 12:58:13.266745 2026] [security2:error] [pid 66623:tid 66886] [client 74.248.18.37:21518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/colors.php"] [unique_id "aoSBFdO5rbWdOArH04KfbQAAAYI"]
[Tue Aug 18 12:58:13.345857 2026] [security2:error] [pid 66623:tid 66714] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/chosen.php"] [unique_id "aoSBFdO5rbWdOArH04KfdQABPU0"]
[Tue Aug 18 12:58:13.352623 2026] [security2:error] [pid 66623:tid 66801] [client 20.100.185.105:7016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/checkbox.php"] [unique_id "aoSBFdO5rbWdOArH04KfdwAAAS0"]
[Tue Aug 18 12:58:13.353570 2026] [security2:error] [pid 66623:tid 66780] [client 172.202.39.151:40380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBFdO5rbWdOArH04KfeAAAARg"]
[Tue Aug 18 12:58:13.360683 2026] [security2:error] [pid 66623:tid 66803] [client 149.34.210.141:60605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfXAAAAS8"]
[Tue Aug 18 12:58:13.392598 2026] [security2:error] [pid 66623:tid 66811] [client 20.118.172.148:46745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSBFdO5rbWdOArH04KfewAAATc"]
[Tue Aug 18 12:58:13.419865 2026] [security2:error] [pid 66623:tid 66651] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/le.php"] [unique_id "aoSBFdO5rbWdOArH04KffgABVg4"]
[Tue Aug 18 12:58:13.428505 2026] [security2:error] [pid 66623:tid 66791] [client 20.206.73.37:46982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/pucci.php"] [unique_id "aoSBFdO5rbWdOArH04KffwAAASM"]
[Tue Aug 18 12:58:13.435614 2026] [security2:error] [pid 66623:tid 66827] [client 223.185.37.47:28000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfhgAAAUc"]
[Tue Aug 18 12:58:13.435771 2026] [security2:error] [pid 66623:tid 66827] [client 223.185.37.47:28000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfhgAAAUc"]
[Tue Aug 18 12:58:13.437449 2026] [security2:error] [pid 66623:tid 66823] [client 20.104.85.180:27318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBFdO5rbWdOArH04KfhwAAAUM"]
[Tue Aug 18 12:58:13.445420 2026] [security2:error] [pid 66623:tid 66789] [client 20.186.30.159:1963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/too.php"] [unique_id "aoSBFdO5rbWdOArH04KfiQAAASE"]
[Tue Aug 18 12:58:13.462072 2026] [security2:error] [pid 66623:tid 66830] [client 172.182.217.32:15603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/mar.php"] [unique_id "aoSBFdO5rbWdOArH04KfiwAAAUo"]
[Tue Aug 18 12:58:13.521639 2026] [security2:error] [pid 66623:tid 66887] [client 20.119.58.187:12062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/alfanew.php"] [unique_id "aoSBFdO5rbWdOArH04KfjgAAAYM"]
[Tue Aug 18 12:58:13.554920 2026] [security2:error] [pid 66623:tid 66869] [client 20.203.138.185:38133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/mamzi.php"] [unique_id "aoSBFdO5rbWdOArH04KfkgAAAXE"]
[Tue Aug 18 12:58:13.599958 2026] [security2:error] [pid 66623:tid 66843] [client 20.206.73.37:40674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-temp.php"] [unique_id "aoSBFdO5rbWdOArH04KflgAAAVc"]
[Tue Aug 18 12:58:13.624708 2026] [security2:error] [pid 66623:tid 66851] [client 20.215.241.237:54549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/av.php"] [unique_id "aoSBFdO5rbWdOArH04KfmAAAAV8"]
[Tue Aug 18 12:58:13.650574 2026] [security2:error] [pid 66623:tid 66847] [client 40.74.65.169:29603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/key.php"] [unique_id "aoSBFdO5rbWdOArH04KfmQAAAVs"]
[Tue Aug 18 12:58:13.653613 2026] [security2:error] [pid 66623:tid 66840] [client 52.173.121.69:24800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSBFdO5rbWdOArH04KfmgAAAVQ"]
[Tue Aug 18 12:58:13.662902 2026] [security2:error] [pid 66623:tid 66812] [client 158.23.17.4:20168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/qo.php"] [unique_id "aoSBFdO5rbWdOArH04KfmwAAATg"]
[Tue Aug 18 12:58:13.674196 2026] [authz_core:error] [pid 66623:tid 66672] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:13.674457 2026] [authz_core:error] [pid 66623:tid 66672] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:13.683309 2026] [security2:error] [pid 66623:tid 66819] [client 40.74.65.169:49030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/fpwch.php"] [unique_id "aoSBFdO5rbWdOArH04KfoAAAAT8"]
[Tue Aug 18 12:58:13.692585 2026] [security2:error] [pid 66623:tid 66642] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/hr.php"] [unique_id "aoSBFdO5rbWdOArH04KfogABbwU"]
[Tue Aug 18 12:58:13.711190 2026] [security2:error] [pid 66623:tid 66784] [client 40.74.65.169:55849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBFdO5rbWdOArH04KfowAAARw"]
[Tue Aug 18 12:58:13.729350 2026] [security2:error] [pid 66623:tid 66778] [client 20.186.30.159:1811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/g3.php"] [unique_id "aoSBFdO5rbWdOArH04KfpAAAARY"]
[Tue Aug 18 12:58:13.745456 2026] [security2:error] [pid 66623:tid 66831] [client 20.206.73.37:52075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBFdO5rbWdOArH04KfpQAAAUs"]
[Tue Aug 18 12:58:13.770179 2026] [security2:error] [pid 66623:tid 66797] [client 20.48.236.86:50727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/sky.php"] [unique_id "aoSBFdO5rbWdOArH04KfqQAAASk"]
[Tue Aug 18 12:58:13.775861 2026] [security2:error] [pid 66623:tid 66893] [client 20.118.172.148:62132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/db.php"] [unique_id "aoSBFdO5rbWdOArH04KfqgAAAYk"]
[Tue Aug 18 12:58:13.778796 2026] [security2:error] [pid 66623:tid 66805] [client 213.35.127.232:64046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBFdO5rbWdOArH04KfqwAAATE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:13.798507 2026] [security2:error] [pid 66623:tid 66671] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/class-protect-uploads.php"] [unique_id "aoSBFdO5rbWdOArH04KfrQABdSI"]
[Tue Aug 18 12:58:13.807627 2026] [security2:error] [pid 66623:tid 66877] [client 138.36.100.162:41464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfrgAAAXk"]
[Tue Aug 18 12:58:13.807752 2026] [security2:error] [pid 66623:tid 66877] [client 138.36.100.162:41464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfrgAAAXk"]
[Tue Aug 18 12:58:13.811440 2026] [security2:error] [pid 66623:tid 66809] [client 74.248.18.37:7180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/options-reading.php"] [unique_id "aoSBFdO5rbWdOArH04KfrwAAATU"]
[Tue Aug 18 12:58:13.813003 2026] [security2:error] [pid 66623:tid 66800] [client 20.79.204.6:12238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/info.php"] [unique_id "aoSBFdO5rbWdOArH04KfsAAAASw"]
[Tue Aug 18 12:58:13.847756 2026] [security2:error] [pid 66623:tid 66868] [client 20.118.172.148:46775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/hosty.php"] [unique_id "aoSBFdO5rbWdOArH04KfsgAAAXA"]
[Tue Aug 18 12:58:13.865412 2026] [security2:error] [pid 66623:tid 66644] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kt.php"] [unique_id "aoSBFdO5rbWdOArH04KfswABawc"]
[Tue Aug 18 12:58:13.867331 2026] [security2:error] [pid 66623:tid 66804] [client 158.158.74.177:26139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/wp-settings.php"] [unique_id "aoSBFdO5rbWdOArH04KftQAAATA"]
[Tue Aug 18 12:58:13.883965 2026] [security2:error] [pid 66623:tid 66890] [client 20.119.58.187:11994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "aoSBFdO5rbWdOArH04KftwAAAYY"]
[Tue Aug 18 12:58:13.929922 2026] [security2:error] [pid 66623:tid 66818] [client 20.206.73.37:59817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/puc.php"] [unique_id "aoSBFdO5rbWdOArH04KfuAAAAT4"]
[Tue Aug 18 12:58:13.943956 2026] [security2:error] [pid 66623:tid 66859] [client 20.206.73.37:11954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/bajah.php"] [unique_id "aoSBFdO5rbWdOArH04KfuQAAAWc"]
[Tue Aug 18 12:58:13.950502 2026] [security2:error] [pid 66623:tid 66794] [client 172.182.217.32:15554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/my1.php"] [unique_id "aoSBFdO5rbWdOArH04KfugAAASY"]
[Tue Aug 18 12:58:13.976424 2026] [security2:error] [pid 66623:tid 66762] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/class.uncode-6wixr9.php"] [unique_id "aoSBFdO5rbWdOArH04KfvQABPX0"]
[Tue Aug 18 12:58:14.012826 2026] [security2:error] [pid 66623:tid 66886] [client 79.127.164.8:40236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/pma.sql"] [unique_id "aoSBFtO5rbWdOArH04KfvwAAAYI"], referer: https://medihub.com.br/pma.sql
[Tue Aug 18 12:58:14.021297 2026] [security2:error] [pid 66623:tid 66811] [client 172.182.200.96:7499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBFtO5rbWdOArH04KfwQAAATc"]
[Tue Aug 18 12:58:14.038856 2026] [security2:error] [pid 66623:tid 66836] [client 178.153.171.161:14979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFtO5rbWdOArH04KfxAAAAVA"]
[Tue Aug 18 12:58:14.038999 2026] [security2:error] [pid 66623:tid 66836] [client 178.153.171.161:14979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFtO5rbWdOArH04KfxAAAAVA"]
[Tue Aug 18 12:58:14.040777 2026] [security2:error] [pid 66623:tid 66844] [client 20.100.185.105:58343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wso112233.php"] [unique_id "aoSBFtO5rbWdOArH04KfxQAAAVg"]
[Tue Aug 18 12:58:14.064326 2026] [security2:error] [pid 66623:tid 66842] [client 68.155.155.199:13650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBFtO5rbWdOArH04KfxwAAAVY"]
[Tue Aug 18 12:58:14.099941 2026] [security2:error] [pid 66623:tid 66701] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ww.php"] [unique_id "aoSBFtO5rbWdOArH04KfyAABR0A"]
[Tue Aug 18 12:58:14.157808 2026] [security2:error] [pid 66623:tid 66717] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/content.php"] [unique_id "aoSBFtO5rbWdOArH04KfzQABc1A"]
[Tue Aug 18 12:58:14.162370 2026] [security2:error] [pid 66623:tid 66779] [client 20.104.85.180:15690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBFtO5rbWdOArH04KfzgAAARc"]
[Tue Aug 18 12:58:14.166495 2026] [security2:error] [pid 66623:tid 66864] [client 172.182.200.96:7670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSBFtO5rbWdOArH04Kf1gAAAWw"]
[Tue Aug 18 12:58:14.169437 2026] [security2:error] [pid 66623:tid 66737] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFtO5rbWdOArH04Kf1wABHmQ"]
[Tue Aug 18 12:58:14.169613 2026] [security2:error] [pid 66623:tid 66786] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFtO5rbWdOArH04Kf1wABHmQ"]
[Tue Aug 18 12:58:14.180338 2026] [security2:error] [pid 66623:tid 66782] [client 20.206.73.37:45776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/8.php"] [unique_id "aoSBFtO5rbWdOArH04Kf4QAAARo"]
[Tue Aug 18 12:58:14.185134 2026] [security2:error] [pid 66623:tid 66733] [remote 104.43.48.106:31860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.48.43.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "i-databi.com.br"] [uri "/wp-login.php"] [unique_id "aoSBFtO5rbWdOArH04Kf4AABbmA"]
[Tue Aug 18 12:58:14.190249 2026] [security2:error] [pid 66623:tid 66861] [client 20.203.138.185:38992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ms.php"] [unique_id "aoSBFtO5rbWdOArH04Kf4gAAAWk"]
[Tue Aug 18 12:58:14.207252 2026] [security2:error] [pid 66623:tid 66776] [client 20.206.73.37:28018] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/1.php"] [unique_id "aoSBFtO5rbWdOArH04Kf4wAAARQ"]
[Tue Aug 18 12:58:14.207374 2026] [security2:error] [pid 66623:tid 66776] [client 20.206.73.37:28018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/1.php"] [unique_id "aoSBFtO5rbWdOArH04Kf4wAAARQ"]
[Tue Aug 18 12:58:14.224115 2026] [security2:error] [pid 66623:tid 66777] [client 74.248.18.37:7172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBFtO5rbWdOArH04Kf5gAAARU"]
[Tue Aug 18 12:58:14.232205 2026] [security2:error] [pid 66623:tid 66856] [client 20.118.172.148:62447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/dropdown.php"] [unique_id "aoSBFtO5rbWdOArH04Kf6gAAAWQ"]
[Tue Aug 18 12:58:14.241218 2026] [security2:error] [pid 66623:tid 66783] [client 20.118.172.148:50095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/test1.php"] [unique_id "aoSBFtO5rbWdOArH04Kf6wAAARs"]
[Tue Aug 18 12:58:14.275718 2026] [authz_core:error] [pid 66623:tid 66711] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:14.275985 2026] [authz_core:error] [pid 66623:tid 66711] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:14.291270 2026] [security2:error] [pid 66623:tid 66867] [client 158.23.17.4:34034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/sd.php"] [unique_id "aoSBFtO5rbWdOArH04Kf9QAAAW8"]
[Tue Aug 18 12:58:14.292638 2026] [security2:error] [pid 66623:tid 66830] [client 20.119.58.187:12520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-p.php7"] [unique_id "aoSBFtO5rbWdOArH04Kf9wAAAUo"]
[Tue Aug 18 12:58:14.293965 2026] [security2:error] [pid 66623:tid 66755] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/mo.php"] [unique_id "aoSBFtO5rbWdOArH04Kf-AABHHY"]
[Tue Aug 18 12:58:14.320320 2026] [security2:error] [pid 66623:tid 66815] [client 20.206.73.37:39001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/about.php"] [unique_id "aoSBFtO5rbWdOArH04Kf-QAAATs"]
[Tue Aug 18 12:58:14.335150 2026] [security2:error] [pid 66623:tid 66643] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/database.php"] [unique_id "aoSBFtO5rbWdOArH04Kf_QABIgY"]
[Tue Aug 18 12:58:14.372202 2026] [security2:error] [pid 66623:tid 66873] [client 40.74.65.169:49119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/adminner.php"] [unique_id "aoSBFtO5rbWdOArH04KgAQAAAXU"]
[Tue Aug 18 12:58:14.393811 2026] [security2:error] [pid 66623:tid 66771] [client 20.206.73.37:40684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/admin.php"] [unique_id "aoSBFtO5rbWdOArH04KgAwAAAQ8"]
[Tue Aug 18 12:58:14.416870 2026] [security2:error] [pid 66623:tid 66858] [client 20.79.204.6:11661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/profile.php"] [unique_id "aoSBFtO5rbWdOArH04KgCgAAAWY"]
[Tue Aug 18 12:58:14.426323 2026] [security2:error] [pid 66623:tid 66802] [client 40.74.65.169:28169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/kir.php"] [unique_id "aoSBFtO5rbWdOArH04KgDAAAAS4"]
[Tue Aug 18 12:58:14.437278 2026] [security2:error] [pid 66623:tid 66808] [client 172.182.217.32:12228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/mm.php"] [unique_id "aoSBFtO5rbWdOArH04KgDgAAATQ"]
[Tue Aug 18 12:58:14.499426 2026] [security2:error] [pid 66623:tid 66692] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/qr.php"] [unique_id "aoSBFtO5rbWdOArH04KgEgABiDc"]
[Tue Aug 18 12:58:14.523539 2026] [security2:error] [pid 66623:tid 66713] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/db.php"] [unique_id "aoSBFtO5rbWdOArH04KgFgABL0w"]
[Tue Aug 18 12:58:14.537386 2026] [security2:error] [pid 66623:tid 66860] [client 74.248.18.37:40966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ors32envu.php"] [unique_id "aoSBFtO5rbWdOArH04KgGQAAAWg"]
[Tue Aug 18 12:58:14.577334 2026] [authz_core:error] [pid 66623:tid 66667] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:14.577616 2026] [authz_core:error] [pid 66623:tid 66667] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:14.594810 2026] [security2:error] [pid 66623:tid 66885] [client 20.118.172.148:53099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/zwso.php"] [unique_id "aoSBFtO5rbWdOArH04KgIwAAAYE"]
[Tue Aug 18 12:58:14.612430 2026] [security2:error] [pid 66623:tid 66844] [client 40.74.65.169:56414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBFtO5rbWdOArH04KgJQAAAVg"]
[Tue Aug 18 12:58:14.630662 2026] [security2:error] [pid 66623:tid 66868] [client 158.158.74.177:16520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/wp-signup.php"] [unique_id "aoSBFtO5rbWdOArH04KgJwAAAXA"]
[Tue Aug 18 12:58:14.648507 2026] [security2:error] [pid 66623:tid 66839] [client 20.119.58.187:12530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/repeater.php"] [unique_id "aoSBFtO5rbWdOArH04KgKQAAAVM"]
[Tue Aug 18 12:58:14.661585 2026] [security2:error] [pid 66623:tid 66817] [client 20.100.185.105:7029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBFtO5rbWdOArH04KgKgAAAT0"]
[Tue Aug 18 12:58:14.677311 2026] [security2:error] [pid 66623:tid 66722] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/dirs.php"] [unique_id "aoSBFtO5rbWdOArH04KgLQABXlU"]
[Tue Aug 18 12:58:14.685579 2026] [security2:error] [pid 66623:tid 66715] [remote 72.167.40.62:56626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.40.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centrodosorrisosobral.com.br"] [uri "/wp-login.php"] [unique_id "aoSBFtO5rbWdOArH04KgLgABIE4"]
[Tue Aug 18 12:58:14.702465 2026] [security2:error] [pid 66623:tid 66743] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/default.php"] [unique_id "aoSBFtO5rbWdOArH04KgMAABg2o"]
[Tue Aug 18 12:58:14.712149 2026] [security2:error] [pid 66623:tid 66828] [client 20.118.172.148:62119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/file.php"] [unique_id "aoSBFtO5rbWdOArH04KgMQAAAUg"]
[Tue Aug 18 12:58:14.769811 2026] [security2:error] [pid 66623:tid 66855] [client 68.155.155.199:7708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/edit.php"] [unique_id "aoSBFtO5rbWdOArH04KgMgAAAWM"]
[Tue Aug 18 12:58:14.775281 2026] [security2:error] [pid 66623:tid 66833] [client 20.206.73.37:59795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/edit.php"] [unique_id "aoSBFtO5rbWdOArH04KgMwAAAU0"]
[Tue Aug 18 12:58:14.776955 2026] [security2:error] [pid 66623:tid 66843] [client 20.203.183.135:24650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/domvf.php"] [unique_id "aoSBFtO5rbWdOArH04KgNAAAAVc"]
[Tue Aug 18 12:58:14.790224 2026] [security2:error] [pid 66623:tid 66875] [client 213.35.127.232:64262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBFtO5rbWdOArH04KgNwAAAXc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:14.853027 2026] [security2:error] [pid 66623:tid 66826] [client 85.154.68.202:16881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBFtO5rbWdOArH04KgOgAAAUY"]
[Tue Aug 18 12:58:14.853152 2026] [security2:error] [pid 66623:tid 66826] [client 85.154.68.202:16881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBFtO5rbWdOArH04KgOgAAAUY"]
[Tue Aug 18 12:58:14.914662 2026] [security2:error] [pid 66623:tid 66835] [client 20.206.73.37:52065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBFtO5rbWdOArH04KgPwAAAU8"]
[Tue Aug 18 12:58:14.926872 2026] [security2:error] [pid 66623:tid 66807] [client 172.182.217.32:12246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/network.php"] [unique_id "aoSBFtO5rbWdOArH04KgQAAAATM"]
[Tue Aug 18 12:58:14.931982 2026] [security2:error] [pid 66623:tid 66730] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/sn.php"] [unique_id "aoSBFtO5rbWdOArH04KgQQABEV0"]
[Tue Aug 18 12:58:14.941503 2026] [security2:error] [pid 66623:tid 66678] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/dex.php"] [unique_id "aoSBFtO5rbWdOArH04KgQgABSik"]
[Tue Aug 18 12:58:14.963071 2026] [security2:error] [pid 66623:tid 66815] [client 20.104.85.180:19166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/gelay.php"] [unique_id "aoSBFtO5rbWdOArH04KgRQAAATs"]
[Tue Aug 18 12:58:14.972785 2026] [security2:error] [pid 66623:tid 66837] [client 20.100.169.31:29094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBFtO5rbWdOArH04KgRgAAAVE"]
[Tue Aug 18 12:58:14.988949 2026] [security2:error] [pid 66623:tid 66881] [client 20.65.98.162:39442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/packed.php"] [unique_id "aoSBFtO5rbWdOArH04KgRwAAAX0"]
[Tue Aug 18 12:58:14.994310 2026] [security2:error] [pid 66623:tid 66870] [client 20.206.73.37:50054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/inputs.php"] [unique_id "aoSBFtO5rbWdOArH04KgSAAAAXI"]
[Tue Aug 18 12:58:15.002011 2026] [security2:error] [pid 66623:tid 66847] [client 20.119.58.187:11897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/repeater.php"] [unique_id "aoSBF9O5rbWdOArH04KgSQAAAVs"]
[Tue Aug 18 12:58:15.023079 2026] [security2:error] [pid 66623:tid 66893] [client 20.206.73.37:52493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/av.php"] [unique_id "aoSBF9O5rbWdOArH04KgSwAAAYk"]
[Tue Aug 18 12:58:15.023702 2026] [security2:error] [pid 66623:tid 66871] [client 20.250.13.23:7809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/inputs.php"] [unique_id "aoSBF9O5rbWdOArH04KgTAAAAXM"]
[Tue Aug 18 12:58:15.068210 2026] [security2:error] [pid 66623:tid 66879] [client 40.74.65.169:49100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/abcd.php"] [unique_id "aoSBF9O5rbWdOArH04KgTwAAAXs"]
[Tue Aug 18 12:58:15.084965 2026] [security2:error] [pid 66623:tid 66783] [client 74.248.18.37:41007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "aoSBF9O5rbWdOArH04KgUAAAARs"]
[Tue Aug 18 12:58:15.085762 2026] [security2:error] [pid 66623:tid 66863] [client 20.118.172.148:56393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/goods.php"] [unique_id "aoSBF9O5rbWdOArH04KgUQAAAWs"]
[Tue Aug 18 12:58:15.092627 2026] [security2:error] [pid 66623:tid 66858] [client 172.182.200.96:7669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBF9O5rbWdOArH04KgUgAAAWY"]
[Tue Aug 18 12:58:15.094403 2026] [security2:error] [pid 66623:tid 66821] [client 20.79.204.6:11701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/sx.php"] [unique_id "aoSBF9O5rbWdOArH04KgUwAAAUE"]
[Tue Aug 18 12:58:15.117395 2026] [security2:error] [pid 66623:tid 66664] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/df.php"] [unique_id "aoSBF9O5rbWdOArH04KgVQABLhs"]
[Tue Aug 18 12:58:15.125295 2026] [security2:error] [pid 66623:tid 66889] [client 158.158.34.183:34340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/class-wp-cmd.php/fied.php"] [unique_id "aoSBF9O5rbWdOArH04KgVwAAAYU"]
[Tue Aug 18 12:58:15.137357 2026] [security2:error] [pid 66623:tid 66780] [client 40.74.65.169:27720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/nofile.php"] [unique_id "aoSBF9O5rbWdOArH04KgWQAAARg"]
[Tue Aug 18 12:58:15.139818 2026] [security2:error] [pid 66623:tid 66892] [client 20.206.73.37:28001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBF9O5rbWdOArH04KgWgAAAYg"]
[Tue Aug 18 12:58:15.179607 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:15.179864 2026] [security2:error] [pid 66623:tid 66784] [client 74.248.18.37:7173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ov-simple1.php"] [unique_id "aoSBF9O5rbWdOArH04KgXgAAARw"]
[Tue Aug 18 12:58:15.179870 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:15.233259 2026] [security2:error] [pid 66623:tid 66775] [client 20.118.172.148:43486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/Geforce.php"] [unique_id "aoSBF9O5rbWdOArH04KgYAAAARM"]
[Tue Aug 18 12:58:15.241866 2026] [security2:error] [pid 66623:tid 66844] [client 20.203.138.185:39994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/gfile.php"] [unique_id "aoSBF9O5rbWdOArH04KgYQAAAVg"]
[Tue Aug 18 12:58:15.245319 2026] [security2:error] [pid 66623:tid 66708] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/43.php"] [unique_id "aoSBF9O5rbWdOArH04KgYgABhEc"]
[Tue Aug 18 12:58:15.265696 2026] [security2:error] [pid 66623:tid 66827] [client 20.206.73.37:6090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBF9O5rbWdOArH04KgYwAAAUc"]
[Tue Aug 18 12:58:15.283888 2026] [security2:error] [pid 66623:tid 66768] [client 20.100.185.105:6612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/gecko.php"] [unique_id "aoSBF9O5rbWdOArH04KgZQAAAQw"]
[Tue Aug 18 12:58:15.298739 2026] [security2:error] [pid 66623:tid 66745] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/disagrsxr.php"] [unique_id "aoSBF9O5rbWdOArH04KgZgABHWw"]
[Tue Aug 18 12:58:15.348630 2026] [security2:error] [pid 66623:tid 66862] [client 20.206.73.37:24272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-blog.php"] [unique_id "aoSBF9O5rbWdOArH04KgagAAAWo"]
[Tue Aug 18 12:58:15.357380 2026] [security2:error] [pid 66623:tid 66836] [client 20.119.58.187:11871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/repeater.php"] [unique_id "aoSBF9O5rbWdOArH04KgawAAAVA"]
[Tue Aug 18 12:58:15.405762 2026] [security2:error] [pid 66623:tid 66866] [client 20.104.85.180:57702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBF9O5rbWdOArH04KgbwAAAW4"]
[Tue Aug 18 12:58:15.420514 2026] [security2:error] [pid 66623:tid 66791] [client 172.182.217.32:15770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/new.php"] [unique_id "aoSBF9O5rbWdOArH04KgcgAAASM"]
[Tue Aug 18 12:58:15.481822 2026] [authz_core:error] [pid 66623:tid 66690] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:15.482093 2026] [authz_core:error] [pid 66623:tid 66690] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:15.483654 2026] [security2:error] [pid 66623:tid 66642] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/domvf.php"] [unique_id "aoSBF9O5rbWdOArH04KgdQABegU"]
[Tue Aug 18 12:58:15.489771 2026] [security2:error] [pid 66623:tid 66868] [client 158.158.74.177:2953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBF9O5rbWdOArH04KgdgAAAXA"]
[Tue Aug 18 12:58:15.523825 2026] [security2:error] [pid 66623:tid 66832] [client 20.206.73.37:63256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/h.php"] [unique_id "aoSBF9O5rbWdOArH04KgeQAAAUw"]
[Tue Aug 18 12:58:15.552470 2026] [security2:error] [pid 66623:tid 66777] [client 158.23.17.4:20178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/km.php"] [unique_id "aoSBF9O5rbWdOArH04KgewAAARU"]
[Tue Aug 18 12:58:15.560044 2026] [security2:error] [pid 66623:tid 66829] [client 40.74.65.169:55810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBF9O5rbWdOArH04KgfAAAAUk"]
[Tue Aug 18 12:58:15.563549 2026] [security2:error] [pid 66623:tid 66754] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/fresh.php"] [unique_id "aoSBF9O5rbWdOArH04KgfQABVHU"]
[Tue Aug 18 12:58:15.643788 2026] [security2:error] [pid 66623:tid 66881] [client 51.68.111.203:24049] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ferreirafreitas.com.br"] [uri "/robots.txt"] [unique_id "aoSBF9O5rbWdOArH04KghAAAAX0"]
[Tue Aug 18 12:58:15.643903 2026] [security2:error] [pid 66623:tid 66881] [client 51.68.111.203:24049] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ferreirafreitas.com.br"] [uri "/robots.txt"] [unique_id "aoSBF9O5rbWdOArH04KghAAAAX0"]
[Tue Aug 18 12:58:15.663419 2026] [security2:error] [pid 66623:tid 66644] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/dropdown.php"] [unique_id "aoSBF9O5rbWdOArH04KghQABcgc"]
[Tue Aug 18 12:58:15.701107 2026] [security2:error] [pid 66623:tid 66787] [client 20.79.204.6:12228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBF9O5rbWdOArH04KgiAAAAR8"]
[Tue Aug 18 12:58:15.709144 2026] [security2:error] [pid 66623:tid 66830] [client 20.119.58.187:12529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wsoyanz.php"] [unique_id "aoSBF9O5rbWdOArH04KgiQAAAUo"]
[Tue Aug 18 12:58:15.778647 2026] [security2:error] [pid 66623:tid 66879] [client 20.48.236.86:50730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/file5.php"] [unique_id "aoSBF9O5rbWdOArH04KgjQAAAXs"]
[Tue Aug 18 12:58:15.783008 2026] [security2:error] [pid 66623:tid 66783] [client 20.206.73.37:35164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBF9O5rbWdOArH04KgjgAAARs"]
[Tue Aug 18 12:58:15.783572 2026] [authz_core:error] [pid 66623:tid 66762] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:15.783849 2026] [authz_core:error] [pid 66623:tid 66762] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:15.792989 2026] [security2:error] [pid 66623:tid 66890] [client 20.215.241.237:57578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/images.php"] [unique_id "aoSBF9O5rbWdOArH04KgkAAAAYY"]
[Tue Aug 18 12:58:15.802235 2026] [security2:error] [pid 66623:tid 66833] [client 213.35.127.232:64469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBF9O5rbWdOArH04KgkQAAAU0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:15.803009 2026] [security2:error] [pid 66623:tid 66820] [client 20.100.169.31:40543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/a7.php"] [unique_id "aoSBF9O5rbWdOArH04KgkgAAAUA"]
[Tue Aug 18 12:58:15.803497 2026] [security2:error] [pid 66623:tid 66819] [client 74.248.18.37:40995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "aoSBF9O5rbWdOArH04KgkwAAAT8"]
[Tue Aug 18 12:58:15.816236 2026] [security2:error] [pid 66623:tid 66858] [client 172.182.200.96:7647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBF9O5rbWdOArH04KglAAAAWY"]
[Tue Aug 18 12:58:15.837117 2026] [security2:error] [pid 66623:tid 66771] [client 68.155.155.199:21583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/ff1.php"] [unique_id "aoSBF9O5rbWdOArH04KglQAAAQ8"]
[Tue Aug 18 12:58:15.841309 2026] [security2:error] [pid 66623:tid 66688] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/dxb/.well-known/options.php"] [unique_id "aoSBF9O5rbWdOArH04KglgABgDM"]
[Tue Aug 18 12:58:15.860164 2026] [security2:error] [pid 66623:tid 66802] [client 52.173.121.69:24965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSBF9O5rbWdOArH04KglwAAAS4"]
[Tue Aug 18 12:58:15.860180 2026] [security2:error] [pid 66623:tid 66682] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gj.php"] [unique_id "aoSBF9O5rbWdOArH04KgmAABZy0"]
[Tue Aug 18 12:58:15.911456 2026] [security2:error] [pid 66623:tid 66793] [client 172.182.217.32:15563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/0x.php"] [unique_id "aoSBF9O5rbWdOArH04KgnQAAASU"]
[Tue Aug 18 12:58:15.925674 2026] [security2:error] [pid 66623:tid 66845] [client 20.127.136.245:22128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBF9O5rbWdOArH04KgnwAAAVk"]
[Tue Aug 18 12:58:15.938976 2026] [security2:error] [pid 66623:tid 66874] [client 20.100.185.105:6231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/catuploadcsv.php"] [unique_id "aoSBF9O5rbWdOArH04KgoQAAAXY"]
[Tue Aug 18 12:58:15.940065 2026] [security2:error] [pid 66623:tid 66803] [client 20.104.85.180:42301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBF9O5rbWdOArH04KgogAAAS8"]
[Tue Aug 18 12:58:15.942059 2026] [security2:error] [pid 66623:tid 66784] [client 20.118.172.148:56407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBF9O5rbWdOArH04KgowAAARw"]
[Tue Aug 18 12:58:15.974427 2026] [security2:error] [pid 66623:tid 66770] [client 40.74.65.169:44742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/fling.php"] [unique_id "aoSBF9O5rbWdOArH04KgpwAAAQ4"]
[Tue Aug 18 12:58:16.016402 2026] [security2:error] [pid 66623:tid 66831] [client 74.248.18.37:40973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ova.php"] [unique_id "aoSBGNO5rbWdOArH04KgqAAAAUs"]
[Tue Aug 18 12:58:16.017626 2026] [security2:error] [pid 66623:tid 66823] [client 20.203.138.185:40924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/public/wp-blog.php"] [unique_id "aoSBGNO5rbWdOArH04KgqQAAAUM"]
[Tue Aug 18 12:58:16.021274 2026] [security2:error] [pid 66623:tid 66710] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/edit.php"] [unique_id "aoSBGNO5rbWdOArH04KgqgABXUk"]
[Tue Aug 18 12:58:16.042886 2026] [security2:error] [pid 66623:tid 66817] [client 20.206.73.37:50064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBGNO5rbWdOArH04KgrAAAAT0"]
[Tue Aug 18 12:58:16.065469 2026] [security2:error] [pid 66623:tid 66814] [client 20.119.58.187:11886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/yanz.php"] [unique_id "aoSBGNO5rbWdOArH04KgrgAAATo"]
[Tue Aug 18 12:58:16.080123 2026] [security2:error] [pid 66623:tid 66737] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/pd.php"] [unique_id "aoSBGNO5rbWdOArH04KgrwABIGQ"]
[Tue Aug 18 12:58:16.080180 2026] [security2:error] [pid 66623:tid 66850] [client 20.118.172.148:33513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/fpwch.php"] [unique_id "aoSBGNO5rbWdOArH04KgsAAAAV4"]
[Tue Aug 18 12:58:16.130714 2026] [security2:error] [pid 66623:tid 66805] [client 158.158.34.183:18898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/manager.php"] [unique_id "aoSBGNO5rbWdOArH04KgsgAAATE"]
[Tue Aug 18 12:58:16.183082 2026] [security2:error] [pid 66623:tid 66776] [client 20.206.73.37:52481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/222.php"] [unique_id "aoSBGNO5rbWdOArH04KgtQAAARQ"]
[Tue Aug 18 12:58:16.197503 2026] [security2:error] [pid 66623:tid 66712] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/elp.php"] [unique_id "aoSBGNO5rbWdOArH04KgtwABY0s"]
[Tue Aug 18 12:58:16.266971 2026] [security2:error] [pid 66623:tid 66799] [client 20.206.73.37:21750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSBGNO5rbWdOArH04KguwAAASs"]
[Tue Aug 18 12:58:16.277040 2026] [security2:error] [pid 66623:tid 66672] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/th.php"] [unique_id "aoSBGNO5rbWdOArH04KgvAABSSM"]
[Tue Aug 18 12:58:16.285767 2026] [security2:error] [pid 66623:tid 66835] [client 20.206.73.37:55621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBGNO5rbWdOArH04KgvgAAAU8"]
[Tue Aug 18 12:58:16.286822 2026] [security2:error] [pid 66623:tid 66812] [client 172.182.200.96:7579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBGNO5rbWdOArH04KgvwAAATg"]
[Tue Aug 18 12:58:16.339645 2026] [security2:error] [pid 66623:tid 66836] [client 20.79.204.6:11697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBGNO5rbWdOArH04KgwwAAAVA"]
[Tue Aug 18 12:58:16.345647 2026] [security2:error] [pid 66623:tid 66870] [client 20.206.73.37:5525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp.php"] [unique_id "aoSBGNO5rbWdOArH04KgxAAAAXI"]
[Tue Aug 18 12:58:16.362756 2026] [security2:error] [pid 66623:tid 66880] [client 20.206.73.37:55675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/i.php"] [unique_id "aoSBGNO5rbWdOArH04KgxwAAAXw"]
[Tue Aug 18 12:58:16.374166 2026] [security2:error] [pid 66623:tid 66674] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/email.php"] [unique_id "aoSBGNO5rbWdOArH04KgyAABSiU"]
[Tue Aug 18 12:58:16.383739 2026] [security2:error] [pid 66623:tid 66887] [client 20.118.172.148:56552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/htaccess.php"] [unique_id "aoSBGNO5rbWdOArH04KgygAAAYM"]
[Tue Aug 18 12:58:16.384639 2026] [authz_core:error] [pid 66623:tid 66721] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:16.384938 2026] [authz_core:error] [pid 66623:tid 66721] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:16.387829 2026] [security2:error] [pid 66623:tid 66873] [client 20.206.73.37:52086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/abcd.php"] [unique_id "aoSBGNO5rbWdOArH04KgywAAAXU"]
[Tue Aug 18 12:58:16.390843 2026] [security2:error] [pid 66623:tid 66662] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBGNO5rbWdOArH04KgzAABNRk"]
[Tue Aug 18 12:58:16.390974 2026] [security2:error] [pid 66623:tid 66809] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBGNO5rbWdOArH04KgzAABNRk"]
[Tue Aug 18 12:58:16.397820 2026] [security2:error] [pid 66623:tid 66856] [client 172.182.217.32:15609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/0.php"] [unique_id "aoSBGNO5rbWdOArH04KgzQAAAWQ"]
[Tue Aug 18 12:58:16.418485 2026] [security2:error] [pid 66623:tid 66852] [client 20.119.58.187:11869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/seoo/wsoyanz.php"] [unique_id "aoSBGNO5rbWdOArH04Kg0QAAAWA"]
[Tue Aug 18 12:58:16.418616 2026] [security2:error] [pid 66623:tid 66804] [client 20.206.73.37:52056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-manager.php"] [unique_id "aoSBGNO5rbWdOArH04Kg0AAAATA"]
[Tue Aug 18 12:58:16.428608 2026] [security2:error] [pid 66623:tid 66819] [client 20.127.136.245:10562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBGNO5rbWdOArH04Kg0wAAAT8"]
[Tue Aug 18 12:58:16.430159 2026] [security2:error] [pid 66623:tid 66858] [client 20.206.73.37:40699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSBGNO5rbWdOArH04Kg1AAAAWY"]
[Tue Aug 18 12:58:16.447788 2026] [security2:error] [pid 66623:tid 66771] [client 20.206.73.37:52502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSBGNO5rbWdOArH04Kg1QAAAQ8"]
[Tue Aug 18 12:58:16.473783 2026] [security2:error] [pid 66623:tid 66744] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/admin404.php"] [unique_id "aoSBGNO5rbWdOArH04Kg2AABbWs"]
[Tue Aug 18 12:58:16.485392 2026] [security2:error] [pid 66623:tid 66780] [client 20.206.73.37:52526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/simple.php"] [unique_id "aoSBGNO5rbWdOArH04Kg2QAAARg"]
[Tue Aug 18 12:58:16.515313 2026] [security2:error] [pid 66623:tid 66803] [client 20.206.73.37:6138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/chosen.php"] [unique_id "aoSBGNO5rbWdOArH04Kg3QAAAS8"]
[Tue Aug 18 12:58:16.556654 2026] [security2:error] [pid 66623:tid 66703] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/error.php"] [unique_id "aoSBGNO5rbWdOArH04Kg3wABhEI"]
[Tue Aug 18 12:58:16.557747 2026] [security2:error] [pid 66623:tid 66847] [client 20.100.185.105:6844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/info.php"] [unique_id "aoSBGNO5rbWdOArH04Kg4AAAAVs"]
[Tue Aug 18 12:58:16.559975 2026] [security2:error] [pid 66623:tid 66775] [client 20.250.13.23:20488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/admin.php"] [unique_id "aoSBGNO5rbWdOArH04Kg4QAAARM"]
[Tue Aug 18 12:58:16.560175 2026] [security2:error] [pid 66623:tid 66827] [client 20.206.73.37:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/als.php"] [unique_id "aoSBGNO5rbWdOArH04Kg4gAAAUc"]
[Tue Aug 18 12:58:16.568777 2026] [security2:error] [pid 66623:tid 66663] [remote 129.121.48.235:51764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.48.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "proj.vitimarketing.com.br"] [uri "/wp-login.php"] [unique_id "aoSBGNO5rbWdOArH04Kg4wABQho"]
[Tue Aug 18 12:58:16.569957 2026] [security2:error] [pid 66623:tid 66807] [client 158.158.74.177:26115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSBGNO5rbWdOArH04Kg5AAAATM"]
[Tue Aug 18 12:58:16.609668 2026] [security2:error] [pid 66623:tid 66848] [client 20.206.73.37:21708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/nox.php"] [unique_id "aoSBGNO5rbWdOArH04Kg5gAAAVw"]
[Tue Aug 18 12:58:16.629942 2026] [security2:error] [pid 66623:tid 66796] [client 114.5.214.109:50408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBGNO5rbWdOArH04Kg5wAAASg"]
[Tue Aug 18 12:58:16.630444 2026] [security2:error] [pid 66623:tid 66796] [client 114.5.214.109:50408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBGNO5rbWdOArH04Kg5wAAASg"]
[Tue Aug 18 12:58:16.645641 2026] [security2:error] [pid 66623:tid 66801] [client 20.206.73.37:5500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/file59.php"] [unique_id "aoSBGNO5rbWdOArH04Kg6QAAAS0"]
[Tue Aug 18 12:58:16.657849 2026] [security2:error] [pid 66623:tid 66794] [client 20.206.73.37:5447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/admin.php"] [unique_id "aoSBGNO5rbWdOArH04Kg6wAAASY"]
[Tue Aug 18 12:58:16.675564 2026] [security2:error] [pid 66623:tid 66786] [client 74.248.18.37:35339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/colors/ectoplasm/about.php"] [unique_id "aoSBGNO5rbWdOArH04Kg7QAAAR4"]
[Tue Aug 18 12:58:16.675827 2026] [security2:error] [pid 66623:tid 66779] [client 20.206.73.37:21716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/aa2.php"] [unique_id "aoSBGNO5rbWdOArH04Kg7gAAARc"]
[Tue Aug 18 12:58:16.678305 2026] [security2:error] [pid 66623:tid 66866] [client 20.203.138.185:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/cu.php"] [unique_id "aoSBGNO5rbWdOArH04Kg8AAAAW4"]
[Tue Aug 18 12:58:16.683742 2026] [security2:error] [pid 66623:tid 66791] [client 158.23.17.4:32575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/mf.php"] [unique_id "aoSBGNO5rbWdOArH04Kg8QAAASM"]
[Tue Aug 18 12:58:16.684669 2026] [authz_core:error] [pid 66623:tid 66695] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:16.684943 2026] [authz_core:error] [pid 66623:tid 66695] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:16.694959 2026] [security2:error] [pid 66623:tid 66859] [client 74.248.18.37:7191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/p.php"] [unique_id "aoSBGNO5rbWdOArH04Kg8wAAAWc"]
[Tue Aug 18 12:58:16.715666 2026] [security2:error] [pid 66623:tid 66716] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/qo.php"] [unique_id "aoSBGNO5rbWdOArH04Kg9QABek8"]
[Tue Aug 18 12:58:16.718607 2026] [security2:error] [pid 66623:tid 66868] [client 20.118.133.132:1877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/ws13.php"] [unique_id "aoSBGNO5rbWdOArH04Kg9wAAAXA"]
[Tue Aug 18 12:58:16.718626 2026] [security2:error] [pid 66623:tid 66792] [client 40.74.65.169:27035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/zoo1.php"] [unique_id "aoSBGNO5rbWdOArH04Kg9gAAASQ"]
[Tue Aug 18 12:58:16.735504 2026] [security2:error] [pid 66623:tid 66683] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/f35.php"] [unique_id "aoSBGNO5rbWdOArH04Kg-AABTC4"]
[Tue Aug 18 12:58:16.772271 2026] [security2:error] [pid 66623:tid 66808] [client 20.119.58.187:12519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/seoo/wsoyanz1.php"] [unique_id "aoSBGNO5rbWdOArH04Kg-wAAATQ"]
[Tue Aug 18 12:58:16.780467 2026] [security2:error] [pid 66623:tid 66869] [client 172.182.200.96:7677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBGNO5rbWdOArH04Kg_AAAAXE"]
[Tue Aug 18 12:58:16.781829 2026] [security2:error] [pid 66623:tid 66835] [client 20.118.172.148:62085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/images/wso.php"] [unique_id "aoSBGNO5rbWdOArH04Kg_QAAAU8"]
[Tue Aug 18 12:58:16.790349 2026] [security2:error] [pid 66623:tid 66812] [client 20.206.73.37:6108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/xamp.php"] [unique_id "aoSBGNO5rbWdOArH04Kg_wAAATg"]
[Tue Aug 18 12:58:16.812137 2026] [security2:error] [pid 66623:tid 66793] [client 213.35.127.232:64697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBGNO5rbWdOArH04KhAQAAASU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:16.819199 2026] [security2:error] [pid 66623:tid 66846] [client 20.48.236.86:25933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/xyn.php"] [unique_id "aoSBGNO5rbWdOArH04KhAgAAAVo"]
[Tue Aug 18 12:58:16.823351 2026] [security2:error] [pid 66623:tid 66810] [client 40.74.65.169:56425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBGNO5rbWdOArH04KhAwAAATY"]
[Tue Aug 18 12:58:16.834983 2026] [security2:error] [pid 66623:tid 66837] [client 68.155.155.199:13162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/fff.php"] [unique_id "aoSBGNO5rbWdOArH04KhBAAAAVE"]
[Tue Aug 18 12:58:16.839918 2026] [security2:error] [pid 66623:tid 66836] [client 20.104.85.180:31281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSBGNO5rbWdOArH04KhBQAAAVA"]
[Tue Aug 18 12:58:16.860017 2026] [security2:error] [pid 66623:tid 66839] [client 20.206.73.37:35152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/bless.php"] [unique_id "aoSBGNO5rbWdOArH04KhCAAAAVM"]
[Tue Aug 18 12:58:16.885855 2026] [security2:error] [pid 66623:tid 66854] [client 172.182.217.32:15750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/oxshell.php"] [unique_id "aoSBGNO5rbWdOArH04KhCQAAAWI"]
[Tue Aug 18 12:58:16.920417 2026] [security2:error] [pid 66623:tid 66640] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/f35.update.php"] [unique_id "aoSBGNO5rbWdOArH04KhCwABeQM"]
[Tue Aug 18 12:58:16.936039 2026] [security2:error] [pid 66623:tid 66809] [client 20.206.73.37:40664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/file25.php"] [unique_id "aoSBGNO5rbWdOArH04KhDAAAATU"]
[Tue Aug 18 12:58:16.938052 2026] [security2:error] [pid 66623:tid 66706] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/sd.php"] [unique_id "aoSBGNO5rbWdOArH04KhDQABe0U"]
[Tue Aug 18 12:58:16.946851 2026] [security2:error] [pid 66623:tid 66863] [client 20.127.136.245:22117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/admin.php"] [unique_id "aoSBGNO5rbWdOArH04KhDgAAAWs"]
[Tue Aug 18 12:58:16.974911 2026] [security2:error] [pid 66623:tid 66819] [client 20.206.73.37:6115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/file15.php"] [unique_id "aoSBGNO5rbWdOArH04KhEgAAAT8"]
[Tue Aug 18 12:58:16.985368 2026] [authz_core:error] [pid 66623:tid 66684] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:16.985627 2026] [authz_core:error] [pid 66623:tid 66684] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:17.009584 2026] [security2:error] [pid 66623:tid 66884] [client 20.104.85.180:18826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/tes.php"] [unique_id "aoSBGdO5rbWdOArH04KhFAAAAYA"]
[Tue Aug 18 12:58:17.022159 2026] [autoindex:error] [pid 66623:tid 66851] [client 20.79.204.6:12229] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:17.028690 2026] [security2:error] [pid 66623:tid 66802] [client 20.206.73.37:5506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/f35.php"] [unique_id "aoSBGdO5rbWdOArH04KhFgAAAS4"]
[Tue Aug 18 12:58:17.106548 2026] [security2:error] [pid 66623:tid 66692] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/file.php"] [unique_id "aoSBGdO5rbWdOArH04KhGwABiDc"]
[Tue Aug 18 12:58:17.114807 2026] [security2:error] [pid 66623:tid 66747] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/km.php"] [unique_id "aoSBGdO5rbWdOArH04KhHAABHG4"]
[Tue Aug 18 12:58:17.129947 2026] [security2:error] [pid 66623:tid 66875] [client 20.119.58.187:11890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cache-compat.php"] [unique_id "aoSBGdO5rbWdOArH04KhHQAAAXc"]
[Tue Aug 18 12:58:17.135481 2026] [security2:error] [pid 66623:tid 66649] [remote 46.62.208.238:50276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.208.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naorar.com.br"] [uri "/wp-login.php"] [unique_id "aoSBGdO5rbWdOArH04KhHgABMgw"]
[Tue Aug 18 12:58:17.144347 2026] [security2:error] [pid 66623:tid 66811] [client 20.206.73.37:59789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-load.php"] [unique_id "aoSBGdO5rbWdOArH04KhHwAAATc"]
[Tue Aug 18 12:58:17.163273 2026] [security2:error] [pid 66623:tid 66804] [client 20.100.185.105:58364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/jquery.php"] [unique_id "aoSBGdO5rbWdOArH04KhIAAAATA"]
[Tue Aug 18 12:58:17.224476 2026] [security2:error] [pid 66623:tid 66831] [client 20.79.204.6:12229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBGdO5rbWdOArH04KhIgAAAUs"]
[Tue Aug 18 12:58:17.281815 2026] [security2:error] [pid 66623:tid 66838] [client 20.118.172.148:52264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/index/function.php"] [unique_id "aoSBGdO5rbWdOArH04KhJgAAAVI"]
[Tue Aug 18 12:58:17.283866 2026] [security2:error] [pid 66623:tid 66749] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/file2.php"] [unique_id "aoSBGdO5rbWdOArH04KhJwABPXA"]
[Tue Aug 18 12:58:17.285810 2026] [security2:error] [pid 66623:tid 66742] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/mf.php"] [unique_id "aoSBGdO5rbWdOArH04KhKAABOmk"]
[Tue Aug 18 12:58:17.295572 2026] [security2:error] [pid 66623:tid 66785] [client 20.104.85.180:43525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/files/index.php"] [unique_id "aoSBGdO5rbWdOArH04KhKQAAAR0"]
[Tue Aug 18 12:58:17.316381 2026] [security2:error] [pid 66623:tid 66796] [client 20.203.138.185:54982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/X57.php"] [unique_id "aoSBGdO5rbWdOArH04KhKgAAASg"]
[Tue Aug 18 12:58:17.342185 2026] [security2:error] [pid 66623:tid 66699] [remote 103.56.163.133:38658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocionais.com.br"] [uri "/wp-login.php"] [unique_id "aoSBGdO5rbWdOArH04KhKwABcz4"]
[Tue Aug 18 12:58:17.344388 2026] [security2:error] [pid 66623:tid 66788] [client 20.104.85.180:23978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/about.php"] [unique_id "aoSBGdO5rbWdOArH04KhLAAAASA"]
[Tue Aug 18 12:58:17.349088 2026] [security2:error] [pid 66623:tid 66801] [client 172.182.200.96:7623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBGdO5rbWdOArH04KhLQAAAS0"]
[Tue Aug 18 12:58:17.371012 2026] [security2:error] [pid 66623:tid 66789] [client 52.173.121.69:24791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSBGdO5rbWdOArH04KhMAAAASE"]
[Tue Aug 18 12:58:17.398756 2026] [security2:error] [pid 66623:tid 66823] [client 172.182.217.32:15570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/php8.php"] [unique_id "aoSBGdO5rbWdOArH04KhMQAAAUM"]
[Tue Aug 18 12:58:17.418495 2026] [security2:error] [pid 66623:tid 66866] [client 40.74.65.169:27782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/zoo2.php"] [unique_id "aoSBGdO5rbWdOArH04KhMwAAAW4"]
[Tue Aug 18 12:58:17.483782 2026] [security2:error] [pid 66623:tid 66794] [client 20.119.58.187:11865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/ajax-actions.php"] [unique_id "aoSBGdO5rbWdOArH04KhOQAAASY"]
[Tue Aug 18 12:58:17.490314 2026] [security2:error] [pid 66623:tid 66647] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/files.php"] [unique_id "aoSBGdO5rbWdOArH04KhOgABFAo"]
[Tue Aug 18 12:58:17.496665 2026] [security2:error] [pid 66623:tid 66761] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ie.php"] [unique_id "aoSBGdO5rbWdOArH04KhOwABSXw"]
[Tue Aug 18 12:58:17.529223 2026] [security2:error] [pid 66623:tid 66874] [client 144.86.18.243:62358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.18.86.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "impactads.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBGdO5rbWdOArH04KhLwAAAXY"]
[Tue Aug 18 12:58:17.529381 2026] [security2:error] [pid 66623:tid 66874] [client 144.86.18.243:62358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "impactads.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBGdO5rbWdOArH04KhLwAAAXY"]
[Tue Aug 18 12:58:17.529698 2026] [security2:error] [pid 66623:tid 66773] [client 158.23.17.4:34021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ie.php"] [unique_id "aoSBGdO5rbWdOArH04KhPQAAARE"]
[Tue Aug 18 12:58:17.571932 2026] [security2:error] [pid 66623:tid 66837] [client 20.104.85.180:18874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBGdO5rbWdOArH04KhQQAAAVE"]
[Tue Aug 18 12:58:17.588928 2026] [security2:error] [pid 66623:tid 66824] [client 39.194.1.247:9576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "usa.lifetreemarketing.com"] [uri "/"] [unique_id "aoSBGNO5rbWdOArH04KgtgAAAUQ"]
[Tue Aug 18 12:58:17.590599 2026] [authz_core:error] [pid 66623:tid 66727] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:17.591033 2026] [authz_core:error] [pid 66623:tid 66727] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:17.592524 2026] [security2:error] [pid 66623:tid 66839] [client 20.127.136.245:4063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/edit.php"] [unique_id "aoSBGdO5rbWdOArH04KhRAAAAVM"]
[Tue Aug 18 12:58:17.597280 2026] [security2:error] [pid 66623:tid 66825] [client 20.206.73.37:6094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSBGdO5rbWdOArH04KhRQAAAUU"]
[Tue Aug 18 12:58:17.613705 2026] [security2:error] [pid 66623:tid 66842] [client 74.248.18.37:40965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/pages.php"] [unique_id "aoSBGdO5rbWdOArH04KhRwAAAVY"]
[Tue Aug 18 12:58:17.615785 2026] [security2:error] [pid 66623:tid 66786] [client 185.191.171.9:16866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754246636/1756598400/"] [unique_id "aoSBGdO5rbWdOArH04KhSQAAAR4"]
[Tue Aug 18 12:58:17.615884 2026] [security2:error] [pid 66623:tid 66786] [client 185.191.171.9:16866] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754246636/1756598400/"] [unique_id "aoSBGdO5rbWdOArH04KhSQAAAR4"]
[Tue Aug 18 12:58:17.672801 2026] [security2:error] [pid 66623:tid 66859] [client 74.248.18.37:40981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/colors/ectoplasm/wp-login.php"] [unique_id "aoSBGdO5rbWdOArH04KhTAAAAWc"]
[Tue Aug 18 12:58:17.679076 2026] [security2:error] [pid 66623:tid 66743] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/fix.php"] [unique_id "aoSBGdO5rbWdOArH04KhTQABe2o"]
[Tue Aug 18 12:58:17.690995 2026] [security2:error] [pid 66623:tid 66656] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/nw.php"] [unique_id "aoSBGdO5rbWdOArH04KhTgABfxM"]
[Tue Aug 18 12:58:17.721976 2026] [security2:error] [pid 66623:tid 66819] [client 20.206.73.37:52508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/aaa.php"] [unique_id "aoSBGdO5rbWdOArH04KhUAAAAT8"]
[Tue Aug 18 12:58:17.757350 2026] [security2:error] [pid 66623:tid 66828] [client 158.158.74.177:16517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-blog.php"] [unique_id "aoSBGdO5rbWdOArH04KhUgAAAUg"]
[Tue Aug 18 12:58:17.783200 2026] [security2:error] [pid 66623:tid 66836] [client 20.100.185.105:18299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/5173e.php"] [unique_id "aoSBGdO5rbWdOArH04KhUwAAAVA"]
[Tue Aug 18 12:58:17.793709 2026] [security2:error] [pid 66623:tid 66795] [client 68.155.155.199:13014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/inputs.php"] [unique_id "aoSBGdO5rbWdOArH04KhVAAAASc"]
[Tue Aug 18 12:58:17.825183 2026] [security2:error] [pid 66623:tid 66777] [client 213.35.127.232:64896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBGdO5rbWdOArH04KhWAAAARU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:17.837503 2026] [security2:error] [pid 66623:tid 66820] [client 20.119.58.187:12049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/ajax-actions.php"] [unique_id "aoSBGdO5rbWdOArH04KhWgAAAUA"]
[Tue Aug 18 12:58:17.864919 2026] [security2:error] [pid 66623:tid 66698] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/fm.php"] [unique_id "aoSBGdO5rbWdOArH04KhWwABgj0"]
[Tue Aug 18 12:58:17.866299 2026] [security2:error] [pid 66623:tid 66784] [client 20.118.172.148:62089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/info.php"] [unique_id "aoSBGdO5rbWdOArH04KhXAAAARw"]
[Tue Aug 18 12:58:17.871012 2026] [security2:error] [pid 66623:tid 66875] [client 20.104.85.180:7046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/images/images/about.php"] [unique_id "aoSBGdO5rbWdOArH04KhXQAAAXc"]
[Tue Aug 18 12:58:17.872967 2026] [security2:error] [pid 66623:tid 66732] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/sb.php"] [unique_id "aoSBGdO5rbWdOArH04KhXgABDl8"]
[Tue Aug 18 12:58:17.878441 2026] [autoindex:error] [pid 66623:tid 66873] [client 20.79.204.6:11674] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:17.889096 2026] [security2:error] [pid 66623:tid 66858] [client 172.182.217.32:15786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/p.php"] [unique_id "aoSBGdO5rbWdOArH04KhYAAAAWY"]
[Tue Aug 18 12:58:17.917430 2026] [security2:error] [pid 66623:tid 66804] [client 20.206.73.37:40696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/gecko.php"] [unique_id "aoSBGdO5rbWdOArH04KhYwAAATA"]
[Tue Aug 18 12:58:17.956373 2026] [security2:error] [pid 66623:tid 66775] [client 20.206.73.37:40645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/xiugai.php"] [unique_id "aoSBGdO5rbWdOArH04KhZAAAARM"]
[Tue Aug 18 12:58:17.989947 2026] [security2:error] [pid 66623:tid 66807] [client 172.182.200.96:14202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/first.php"] [unique_id "aoSBGdO5rbWdOArH04KhZgAAATM"]
[Tue Aug 18 12:58:17.994579 2026] [security2:error] [pid 66623:tid 66817] [client 20.104.85.180:47164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBGdO5rbWdOArH04KhZwAAAT0"]
[Tue Aug 18 12:58:18.008756 2026] [authz_core:error] [pid 66623:tid 66680] [remote 57.141.22.102:39006] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:18.009026 2026] [authz_core:error] [pid 66623:tid 66680] [remote 57.141.22.102:39006] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:18.013578 2026] [security2:error] [pid 66623:tid 66785] [client 20.206.73.37:45771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/adminner.php"] [unique_id "aoSBGtO5rbWdOArH04KhawAAAR0"]
[Tue Aug 18 12:58:18.047049 2026] [security2:error] [pid 66623:tid 66711] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/footer.php"] [unique_id "aoSBGtO5rbWdOArH04KhbAABLUo"]
[Tue Aug 18 12:58:18.053506 2026] [security2:error] [pid 66623:tid 66864] [client 20.127.136.245:4041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/w.php"] [unique_id "aoSBGtO5rbWdOArH04KhbgAAAWw"]
[Tue Aug 18 12:58:18.053512 2026] [security2:error] [pid 66623:tid 66789] [client 158.23.17.4:57223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/nw.php"] [unique_id "aoSBGtO5rbWdOArH04KhbQAAASE"]
[Tue Aug 18 12:58:18.080269 2026] [security2:error] [pid 66623:tid 66791] [client 20.79.204.6:11674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSBGtO5rbWdOArH04KhcQAAASM"]
[Tue Aug 18 12:58:18.095353 2026] [security2:error] [pid 66623:tid 66685] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/xj.php"] [unique_id "aoSBGtO5rbWdOArH04KhcwABVzA"]
[Tue Aug 18 12:58:18.097859 2026] [security2:error] [pid 66623:tid 66868] [client 20.206.73.37:52061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/file1221.php"] [unique_id "aoSBGtO5rbWdOArH04KhdQAAAXA"]
[Tue Aug 18 12:58:18.117447 2026] [security2:error] [pid 66623:tid 66826] [client 20.206.73.37:11960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/ano.php"] [unique_id "aoSBGtO5rbWdOArH04KhdgAAAUY"]
[Tue Aug 18 12:58:18.133988 2026] [security2:error] [pid 66623:tid 66832] [client 40.74.65.169:35763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/org.php"] [unique_id "aoSBGtO5rbWdOArH04KhdwAAAUw"]
[Tue Aug 18 12:58:18.139755 2026] [security2:error] [pid 66623:tid 66776] [client 20.206.73.37:5557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/inx.php"] [unique_id "aoSBGtO5rbWdOArH04KheAAAARQ"]
[Tue Aug 18 12:58:18.157797 2026] [security2:error] [pid 66623:tid 66783] [client 20.104.85.180:7004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBGtO5rbWdOArH04KhegAAARs"]
[Tue Aug 18 12:58:18.190297 2026] [authz_core:error] [pid 66623:tid 66657] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:18.190567 2026] [authz_core:error] [pid 66623:tid 66657] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:18.191654 2026] [security2:error] [pid 66623:tid 66812] [client 20.206.73.37:42666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/reviall.php"] [unique_id "aoSBGtO5rbWdOArH04KhgAAAATg"]
[Tue Aug 18 12:58:18.206944 2026] [security2:error] [pid 66623:tid 66878] [client 20.119.58.187:12507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-consar.php"] [unique_id "aoSBGtO5rbWdOArH04KhggAAAXo"]
[Tue Aug 18 12:58:18.233663 2026] [security2:error] [pid 66623:tid 66651] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/form.php"] [unique_id "aoSBGtO5rbWdOArH04KhgwABFg4"]
[Tue Aug 18 12:58:18.278956 2026] [security2:error] [pid 66623:tid 66877] [client 20.206.73.37:55657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/11.php"] [unique_id "aoSBGtO5rbWdOArH04KhiQAAAXk"]
[Tue Aug 18 12:58:18.289543 2026] [security2:error] [pid 66623:tid 66731] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ns.php"] [unique_id "aoSBGtO5rbWdOArH04KhigABe14"]
[Tue Aug 18 12:58:18.363486 2026] [security2:error] [pid 66623:tid 66857] [client 20.206.73.37:5488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/File.php"] [unique_id "aoSBGtO5rbWdOArH04KhjgAAAWU"]
[Tue Aug 18 12:58:18.371179 2026] [security2:error] [pid 66623:tid 66869] [client 74.248.18.37:7192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/past.php"] [unique_id "aoSBGtO5rbWdOArH04KhkAAAAXE"]
[Tue Aug 18 12:58:18.371686 2026] [security2:error] [pid 66623:tid 66800] [client 20.118.172.148:62458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/profile.php"] [unique_id "aoSBGtO5rbWdOArH04KhkQAAASw"]
[Tue Aug 18 12:58:18.389379 2026] [security2:error] [pid 66623:tid 66880] [client 172.182.217.32:15803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/php.php"] [unique_id "aoSBGtO5rbWdOArH04KhkwAAAXw"]
[Tue Aug 18 12:58:18.392808 2026] [security2:error] [pid 66623:tid 66793] [client 74.248.18.37:41011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBGtO5rbWdOArH04KhlAAAASU"]
[Tue Aug 18 12:58:18.404395 2026] [security2:error] [pid 66623:tid 66851] [client 20.206.73.37:52488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/fi22.php"] [unique_id "aoSBGtO5rbWdOArH04KhlwAAAV8"]
[Tue Aug 18 12:58:18.426283 2026] [security2:error] [pid 66623:tid 66798] [client 20.206.73.37:5459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBGtO5rbWdOArH04KhmAAAASo"]
[Tue Aug 18 12:58:18.429807 2026] [security2:error] [pid 66623:tid 66669] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/fpwch.php"] [unique_id "aoSBGtO5rbWdOArH04KhmQABhSA"]
[Tue Aug 18 12:58:18.433258 2026] [security2:error] [pid 66623:tid 66777] [client 20.104.85.180:18847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/rip.php"] [unique_id "aoSBGtO5rbWdOArH04KhmgAAARU"]
[Tue Aug 18 12:58:18.433597 2026] [security2:error] [pid 66623:tid 66802] [client 196.12.128.158:57694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBGtO5rbWdOArH04KhmwAAAS4"]
[Tue Aug 18 12:58:18.433696 2026] [security2:error] [pid 66623:tid 66802] [client 196.12.128.158:57694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBGtO5rbWdOArH04KhmwAAAS4"]
[Tue Aug 18 12:58:18.448646 2026] [security2:error] [pid 66623:tid 66855] [client 20.100.185.105:34569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/class_api.php"] [unique_id "aoSBGtO5rbWdOArH04KhnQAAAWM"]
[Tue Aug 18 12:58:18.464211 2026] [security2:error] [pid 66623:tid 66875] [client 40.74.65.169:55809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/xx.php"] [unique_id "aoSBGtO5rbWdOArH04KhoAAAAXc"]
[Tue Aug 18 12:58:18.470433 2026] [security2:error] [pid 66623:tid 66770] [client 20.206.73.37:52090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSBGtO5rbWdOArH04KhoQAAAQ4"]
[Tue Aug 18 12:58:18.482974 2026] [security2:error] [pid 66623:tid 66750] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gk.php"] [unique_id "aoSBGtO5rbWdOArH04KhogABgXE"]
[Tue Aug 18 12:58:18.492775 2026] [authz_core:error] [pid 66623:tid 66673] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:18.493074 2026] [authz_core:error] [pid 66623:tid 66673] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:18.522139 2026] [security2:error] [pid 66623:tid 66815] [client 157.51.166.53:52181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBGtO5rbWdOArH04KhpAAAATs"]
[Tue Aug 18 12:58:18.522279 2026] [security2:error] [pid 66623:tid 66815] [client 157.51.166.53:52181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBGtO5rbWdOArH04KhpAAAATs"]
[Tue Aug 18 12:58:18.559045 2026] [security2:error] [pid 66623:tid 66775] [client 172.182.200.96:7635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBGtO5rbWdOArH04KhpgAAARM"]
[Tue Aug 18 12:58:18.561882 2026] [security2:error] [pid 66623:tid 66803] [client 20.119.58.187:11900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/repeater.php"] [unique_id "aoSBGtO5rbWdOArH04KhpwAAAS8"]
[Tue Aug 18 12:58:18.584793 2026] [security2:error] [pid 66623:tid 66768] [client 68.155.155.199:7551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBGtO5rbWdOArH04KhqQAAAQw"]
[Tue Aug 18 12:58:18.594464 2026] [security2:error] [pid 66623:tid 66822] [client 20.206.73.37:59830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBGtO5rbWdOArH04KhqgAAAUI"]
[Tue Aug 18 12:58:18.607388 2026] [security2:error] [pid 66623:tid 66814] [client 20.206.73.37:6128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSBGtO5rbWdOArH04KhrAAAATo"]
[Tue Aug 18 12:58:18.611174 2026] [security2:error] [pid 66623:tid 66739] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/function.php"] [unique_id "aoSBGtO5rbWdOArH04KhrQABKGY"]
[Tue Aug 18 12:58:18.632041 2026] [security2:error] [pid 66623:tid 66788] [client 20.206.73.37:52536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSBGtO5rbWdOArH04KhrgAAASA"]
[Tue Aug 18 12:58:18.635600 2026] [security2:error] [pid 66623:tid 66801] [client 52.173.121.69:24783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSBGtO5rbWdOArH04KhsAAAAS0"]
[Tue Aug 18 12:58:18.661912 2026] [security2:error] [pid 66623:tid 66843] [client 20.203.138.185:39031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/forbidals.php"] [unique_id "aoSBGtO5rbWdOArH04KhsgAAAVc"]
[Tue Aug 18 12:58:18.663556 2026] [security2:error] [pid 66623:tid 66756] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/wn.php"] [unique_id "aoSBGtO5rbWdOArH04KhswABcHc"]
[Tue Aug 18 12:58:18.672949 2026] [security2:error] [pid 66623:tid 66769] [client 20.127.136.245:1794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/file.php"] [unique_id "aoSBGtO5rbWdOArH04KhtAAAAQ0"]
[Tue Aug 18 12:58:18.681217 2026] [security2:error] [pid 66623:tid 66867] [client 158.158.34.183:11718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/csv.php"] [unique_id "aoSBGtO5rbWdOArH04KhtQAAAW8"]
[Tue Aug 18 12:58:18.685395 2026] [security2:error] [pid 66623:tid 66776] [client 20.206.73.37:50101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSBGtO5rbWdOArH04KhtgAAARQ"]
[Tue Aug 18 12:58:18.687484 2026] [security2:error] [pid 66623:tid 66858] [client 20.79.204.6:11650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSBGtO5rbWdOArH04KhtwAAAWY"]
[Tue Aug 18 12:58:18.705544 2026] [security2:error] [pid 66623:tid 66773] [client 158.23.17.4:44805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/sb.php"] [unique_id "aoSBGtO5rbWdOArH04KhuAAAARE"]
[Tue Aug 18 12:58:18.714082 2026] [security2:error] [pid 66623:tid 66816] [client 20.104.85.180:27268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/f35.php"] [unique_id "aoSBGtO5rbWdOArH04KhuQAAATw"]
[Tue Aug 18 12:58:18.714748 2026] [security2:error] [pid 66623:tid 66810] [client 20.206.73.37:59808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/media.php"] [unique_id "aoSBGtO5rbWdOArH04KhugAAATY"]
[Tue Aug 18 12:58:18.776780 2026] [security2:error] [pid 66623:tid 66767] [client 20.206.73.37:50066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/inso.php"] [unique_id "aoSBGtO5rbWdOArH04KhwQAAAQs"]
[Tue Aug 18 12:58:18.780597 2026] [autoindex:error] [pid 66623:tid 66688] [remote 136.110.27.48:37542] AH01276: Cannot serve directory /home4/gueirosadv/_wildcard_.gueirosadvocacia.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:18.793369 2026] [security2:error] [pid 66623:tid 66753] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/g.php"] [unique_id "aoSBGtO5rbWdOArH04KhwwABZ3Q"]
[Tue Aug 18 12:58:18.803984 2026] [security2:error] [pid 66623:tid 66842] [client 20.206.73.37:45777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/shiny.php"] [unique_id "aoSBGtO5rbWdOArH04KhxAAAAVY"]
[Tue Aug 18 12:58:18.824090 2026] [security2:error] [pid 66623:tid 66787] [client 20.206.73.37:45781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/403dd.php"] [unique_id "aoSBGtO5rbWdOArH04KhxgAAAR8"]
[Tue Aug 18 12:58:18.835336 2026] [security2:error] [pid 66623:tid 66823] [client 40.74.65.169:26728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/imageskir.php"] [unique_id "aoSBGtO5rbWdOArH04KhxwAAAUM"]
[Tue Aug 18 12:58:18.842144 2026] [security2:error] [pid 66623:tid 66882] [client 213.35.127.232:65129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBGtO5rbWdOArH04KhzgAAAX4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:18.866425 2026] [security2:error] [pid 66623:tid 66710] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/app.php"] [unique_id "aoSBGtO5rbWdOArH04KhzwABbUk"]
[Tue Aug 18 12:58:18.873271 2026] [security2:error] [pid 66623:tid 66798] [client 20.118.172.148:62446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/sx.php"] [unique_id "aoSBGtO5rbWdOArH04Kh0AAAASo"]
[Tue Aug 18 12:58:18.880078 2026] [security2:error] [pid 66623:tid 66846] [client 172.182.217.32:15789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/past.php"] [unique_id "aoSBGtO5rbWdOArH04Kh0QAAAVo"]
[Tue Aug 18 12:58:18.911730 2026] [security2:error] [pid 66623:tid 66802] [client 20.206.73.37:52517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/baba.php"] [unique_id "aoSBGtO5rbWdOArH04Kh1AAAAS4"]
[Tue Aug 18 12:58:18.916204 2026] [security2:error] [pid 66623:tid 66861] [client 20.119.58.187:11993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/admin-post.php"] [unique_id "aoSBGtO5rbWdOArH04Kh1QAAAWk"]
[Tue Aug 18 12:58:18.938587 2026] [security2:error] [pid 66623:tid 66875] [client 20.48.236.86:36145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBGtO5rbWdOArH04Kh1wAAAXc"]
[Tue Aug 18 12:58:18.969822 2026] [security2:error] [pid 66623:tid 66808] [client 20.206.73.37:40679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/site.php"] [unique_id "aoSBGtO5rbWdOArH04Kh2AAAATQ"]
[Tue Aug 18 12:58:18.970130 2026] [security2:error] [pid 66623:tid 66855] [client 192.141.172.134:50278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBGtO5rbWdOArH04Kh2QAAAWM"]
[Tue Aug 18 12:58:18.970235 2026] [security2:error] [pid 66623:tid 66855] [client 192.141.172.134:50278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBGtO5rbWdOArH04Kh2QAAAWM"]
[Tue Aug 18 12:58:18.984637 2026] [security2:error] [pid 66623:tid 66717] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/goods.php"] [unique_id "aoSBGtO5rbWdOArH04Kh2gABMFA"]
[Tue Aug 18 12:58:18.985902 2026] [security2:error] [pid 66623:tid 66815] [client 20.206.73.37:5509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSBGtO5rbWdOArH04Kh2wAAATs"]
[Tue Aug 18 12:58:19.017202 2026] [security2:error] [pid 66623:tid 66847] [client 20.118.172.148:46773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSBG9O5rbWdOArH04Kh3wAAAVs"]
[Tue Aug 18 12:58:19.018297 2026] [security2:error] [pid 66623:tid 66884] [client 172.202.39.151:44550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBG9O5rbWdOArH04Kh4AAAAYA"]
[Tue Aug 18 12:58:19.025431 2026] [security2:error] [pid 66623:tid 66775] [client 20.206.73.37:59818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/cabs.php"] [unique_id "aoSBG9O5rbWdOArH04Kh4QAAARM"]
[Tue Aug 18 12:58:19.038487 2026] [security2:error] [pid 66623:tid 66844] [client 197.184.64.235:41943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBG9O5rbWdOArH04Kh4gAAAVg"]
[Tue Aug 18 12:58:19.038557 2026] [security2:error] [pid 66623:tid 66844] [client 197.184.64.235:41943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBG9O5rbWdOArH04Kh4gAAAVg"]
[Tue Aug 18 12:58:19.069099 2026] [security2:error] [pid 66623:tid 66849] [client 20.206.73.37:50065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/insc.php"] [unique_id "aoSBG9O5rbWdOArH04Kh4wAAAV0"]
[Tue Aug 18 12:58:19.071890 2026] [security2:error] [pid 66623:tid 66841] [client 74.248.18.37:7229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/php.php"] [unique_id "aoSBG9O5rbWdOArH04Kh5QAAAVU"]
[Tue Aug 18 12:58:19.071912 2026] [security2:error] [pid 66623:tid 66807] [client 172.182.200.96:14136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBG9O5rbWdOArH04Kh5gAAATM"]
[Tue Aug 18 12:58:19.086825 2026] [security2:error] [pid 66623:tid 66709] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/87.php"] [unique_id "aoSBG9O5rbWdOArH04Kh6AABK0g"]
[Tue Aug 18 12:58:19.089235 2026] [security2:error] [pid 66623:tid 66889] [client 20.100.185.105:6228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/word.php"] [unique_id "aoSBG9O5rbWdOArH04Kh6QAAAYU"]
[Tue Aug 18 12:58:19.093479 2026] [authz_core:error] [pid 66623:tid 66637] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:19.093753 2026] [authz_core:error] [pid 66623:tid 66637] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:19.099428 2026] [security2:error] [pid 66623:tid 66789] [client 20.206.73.37:5486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/file.php"] [unique_id "aoSBG9O5rbWdOArH04Kh7QAAASE"]
[Tue Aug 18 12:58:19.139016 2026] [security2:error] [pid 66623:tid 66791] [client 68.155.155.199:3846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/lite.php"] [unique_id "aoSBG9O5rbWdOArH04Kh7gAAASM"]
[Tue Aug 18 12:58:19.170566 2026] [security2:error] [pid 66623:tid 66758] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/gtt.php"] [unique_id "aoSBG9O5rbWdOArH04Kh7wABDXk"]
[Tue Aug 18 12:58:19.209703 2026] [security2:error] [pid 66623:tid 66888] [client 74.248.18.37:40974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/colors/light/wp-login.php"] [unique_id "aoSBG9O5rbWdOArH04Kh8gAAAYQ"]
[Tue Aug 18 12:58:19.224077 2026] [security2:error] [pid 66623:tid 66874] [client 20.206.73.37:11922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/ai.php"] [unique_id "aoSBG9O5rbWdOArH04Kh8wAAAXY"]
[Tue Aug 18 12:58:19.276818 2026] [security2:error] [pid 66623:tid 66868] [client 20.119.58.187:12229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/maint/maint/ajax-actions.php"] [unique_id "aoSBG9O5rbWdOArH04Kh9gAAAXA"]
[Tue Aug 18 12:58:19.304045 2026] [security2:error] [pid 66623:tid 66662] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/zi.php"] [unique_id "aoSBG9O5rbWdOArH04Kh-QABFhk"]
[Tue Aug 18 12:58:19.305852 2026] [security2:error] [pid 66623:tid 66788] [client 20.79.204.6:11668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBG9O5rbWdOArH04Kh-gAAASA"]
[Tue Aug 18 12:58:19.312551 2026] [security2:error] [pid 66623:tid 66779] [client 20.118.172.148:52230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBG9O5rbWdOArH04Kh_QAAARc"]
[Tue Aug 18 12:58:19.315568 2026] [security2:error] [pid 66623:tid 66825] [client 40.74.65.169:55834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/av.php"] [unique_id "aoSBG9O5rbWdOArH04Kh_wAAAUU"]
[Tue Aug 18 12:58:19.341485 2026] [security2:error] [pid 66623:tid 66767] [client 20.206.73.37:45819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/dex.php"] [unique_id "aoSBG9O5rbWdOArH04KiBgAAAQs"]
[Tue Aug 18 12:58:19.353832 2026] [security2:error] [pid 66623:tid 66762] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/gulu.php"] [unique_id "aoSBG9O5rbWdOArH04KiBwABf30"]
[Tue Aug 18 12:58:19.369631 2026] [security2:error] [pid 66623:tid 66776] [client 172.182.217.32:15439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/root.php"] [unique_id "aoSBG9O5rbWdOArH04KiCQAAARQ"]
[Tue Aug 18 12:58:19.386496 2026] [security2:error] [pid 66623:tid 66859] [client 20.127.136.245:6080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBG9O5rbWdOArH04KiCgAAAWc"]
[Tue Aug 18 12:58:19.393025 2026] [authz_core:error] [pid 66623:tid 66643] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:19.393305 2026] [authz_core:error] [pid 66623:tid 66643] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:19.463529 2026] [security2:error] [pid 66623:tid 66850] [client 4.232.151.198:62711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/uploads/backwpup-restore/uploads/users.php"] [unique_id "aoSBG9O5rbWdOArH04KiDQAAAV4"]
[Tue Aug 18 12:58:19.480910 2026] [security2:error] [pid 66623:tid 66853] [client 20.250.13.23:52068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/goods.php"] [unique_id "aoSBG9O5rbWdOArH04KiDgAAAWE"]
[Tue Aug 18 12:58:19.504968 2026] [security2:error] [pid 66623:tid 66780] [client 213.202.253.4:63644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/filefuns.php"] [unique_id "aoSBG9O5rbWdOArH04KiDwAAARg"], referer: www.google.com
[Tue Aug 18 12:58:19.533080 2026] [security2:error] [pid 66623:tid 66686] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/hello.php"] [unique_id "aoSBG9O5rbWdOArH04KiFQABfDE"]
[Tue Aug 18 12:58:19.534358 2026] [security2:error] [pid 66623:tid 66798] [client 40.74.65.169:11246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/indexo.php"] [unique_id "aoSBG9O5rbWdOArH04KiFgAAASo"]
[Tue Aug 18 12:58:19.629092 2026] [security2:error] [pid 66623:tid 66882] [client 20.119.58.187:12542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/dropdown.php"] [unique_id "aoSBG9O5rbWdOArH04KiGgAAAX4"]
[Tue Aug 18 12:58:19.702373 2026] [security2:error] [pid 66623:tid 66775] [client 20.206.73.37:6112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/key.php"] [unique_id "aoSBG9O5rbWdOArH04KiIAAAARM"]
[Tue Aug 18 12:58:19.708633 2026] [security2:error] [pid 66623:tid 66869] [client 79.127.164.8:33078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/scriptsacplibinserts.bak"] [unique_id "aoSBG9O5rbWdOArH04KiIQAAAXE"], referer: https://medihub.com.br/scriptsacplibinserts.bak
[Tue Aug 18 12:58:19.710103 2026] [security2:error] [pid 66623:tid 66783] [client 20.100.185.105:58319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-index.php"] [unique_id "aoSBG9O5rbWdOArH04KiIgAAARs"]
[Tue Aug 18 12:58:19.723790 2026] [security2:error] [pid 66623:tid 66827] [client 172.182.200.96:14183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBG9O5rbWdOArH04KiJAAAAUc"]
[Tue Aug 18 12:58:19.723862 2026] [security2:error] [pid 66623:tid 66747] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/html/plugins/plugins/config.php"] [unique_id "aoSBG9O5rbWdOArH04KiIwABS24"]
[Tue Aug 18 12:58:19.757736 2026] [security2:error] [pid 66623:tid 66881] [client 20.118.172.148:52225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBG9O5rbWdOArH04KiJwAAAX0"]
[Tue Aug 18 12:58:19.774108 2026] [security2:error] [pid 66623:tid 66841] [client 52.173.121.69:24993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBG9O5rbWdOArH04KiKAAAAVU"]
[Tue Aug 18 12:58:19.779415 2026] [security2:error] [pid 66623:tid 66695] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/92.php"] [unique_id "aoSBG9O5rbWdOArH04KiKgABajo"]
[Tue Aug 18 12:58:19.780685 2026] [security2:error] [pid 66623:tid 66876] [client 20.100.169.31:15252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/manager.php"] [unique_id "aoSBG9O5rbWdOArH04KiKwAAAXg"]
[Tue Aug 18 12:58:19.792118 2026] [security2:error] [pid 66623:tid 66796] [client 20.203.138.185:44086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/edit.php"] [unique_id "aoSBG9O5rbWdOArH04KiLQAAASg"]
[Tue Aug 18 12:58:19.822065 2026] [security2:error] [pid 66623:tid 66878] [client 74.248.18.37:54916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/php8.php"] [unique_id "aoSBG9O5rbWdOArH04KiLwAAAXo"]
[Tue Aug 18 12:58:19.853240 2026] [security2:error] [pid 66623:tid 66797] [client 213.35.127.232:65345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBG9O5rbWdOArH04KiMQAAASk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:19.857197 2026] [security2:error] [pid 66623:tid 66821] [client 172.182.217.32:15780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/r.php"] [unique_id "aoSBG9O5rbWdOArH04KiMgAAAUE"]
[Tue Aug 18 12:58:19.898421 2026] [security2:error] [pid 66623:tid 66832] [client 20.215.241.237:57544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/ops.php"] [unique_id "aoSBG9O5rbWdOArH04KiNQAAAUw"]
[Tue Aug 18 12:58:19.901494 2026] [security2:error] [pid 66623:tid 66749] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/images/class-config.php"] [unique_id "aoSBG9O5rbWdOArH04KiNgABSXA"]
[Tue Aug 18 12:58:19.910018 2026] [security2:error] [pid 66623:tid 66803] [client 20.79.204.6:11649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSBG9O5rbWdOArH04KiNwAAAS8"]
[Tue Aug 18 12:58:19.925599 2026] [security2:error] [pid 66623:tid 66816] [client 20.206.73.37:52538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/kir.php"] [unique_id "aoSBG9O5rbWdOArH04KiOQAAATw"]
[Tue Aug 18 12:58:19.932967 2026] [security2:error] [pid 66623:tid 66852] [client 20.127.136.245:4270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/aa.php"] [unique_id "aoSBG9O5rbWdOArH04KiPAAAAWA"]
[Tue Aug 18 12:58:19.961413 2026] [security2:error] [pid 66623:tid 66699] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/jm.php"] [unique_id "aoSBG9O5rbWdOArH04KiPwABIj4"]
[Tue Aug 18 12:58:19.983778 2026] [security2:error] [pid 66623:tid 66789] [client 20.119.58.187:11861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBG9O5rbWdOArH04KiQQAAASE"]
[Tue Aug 18 12:58:19.986912 2026] [security2:error] [pid 66623:tid 66825] [client 20.206.73.37:38993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/nofile.php"] [unique_id "aoSBG9O5rbWdOArH04KiQgAAAUU"]
[Tue Aug 18 12:58:19.996707 2026] [authz_core:error] [pid 66623:tid 66646] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:19.996967 2026] [authz_core:error] [pid 66623:tid 66646] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:20.020151 2026] [security2:error] [pid 66623:tid 66776] [client 20.206.73.37:52532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/fling.php"] [unique_id "aoSBHNO5rbWdOArH04KiSAAAARQ"]
[Tue Aug 18 12:58:20.025530 2026] [security2:error] [pid 66623:tid 66859] [client 20.104.85.180:59567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/inputs.php"] [unique_id "aoSBHNO5rbWdOArH04KiTAAAAWc"]
[Tue Aug 18 12:58:20.028355 2026] [security2:error] [pid 66623:tid 66648] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.env"] [unique_id "aoSBHNO5rbWdOArH04KiTgABLQs"]
[Tue Aug 18 12:58:20.037871 2026] [security2:error] [pid 66623:tid 66848] [client 158.23.17.4:44803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/xj.php"] [unique_id "aoSBHNO5rbWdOArH04KiTwAAAVw"]
[Tue Aug 18 12:58:20.065651 2026] [security2:error] [pid 66623:tid 66819] [client 68.155.155.199:1496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBHNO5rbWdOArH04KiUwAAAT8"]
[Tue Aug 18 12:58:20.093462 2026] [security2:error] [pid 66623:tid 66843] [client 4.232.151.198:5298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/gxirhnercs.php"] [unique_id "aoSBHNO5rbWdOArH04KiVgAAAVc"]
[Tue Aug 18 12:58:20.124130 2026] [security2:error] [pid 66623:tid 66795] [client 20.206.73.37:52032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/zoo1.php"] [unique_id "aoSBHNO5rbWdOArH04KiVwAAASc"]
[Tue Aug 18 12:58:20.155495 2026] [security2:error] [pid 66623:tid 66846] [client 20.48.236.86:36137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/inso.php"] [unique_id "aoSBHNO5rbWdOArH04KiWQAAAVo"]
[Tue Aug 18 12:58:20.183893 2026] [security2:error] [pid 66623:tid 66676] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/wj.php"] [unique_id "aoSBHNO5rbWdOArH04KiWgABaSc"]
[Tue Aug 18 12:58:20.205895 2026] [security2:error] [pid 66623:tid 66811] [client 20.206.73.37:50106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/zoo2.php"] [unique_id "aoSBHNO5rbWdOArH04KiXQAAATc"]
[Tue Aug 18 12:58:20.219484 2026] [security2:error] [pid 66623:tid 66877] [client 20.206.73.37:40691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/org.php"] [unique_id "aoSBHNO5rbWdOArH04KiXgAAAXk"]
[Tue Aug 18 12:58:20.221599 2026] [security2:error] [pid 66623:tid 66855] [client 40.74.65.169:27071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSBHNO5rbWdOArH04KiXwAAAWM"]
[Tue Aug 18 12:58:20.248402 2026] [security2:error] [pid 66623:tid 66869] [client 20.206.73.37:50090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/imageskir.php"] [unique_id "aoSBHNO5rbWdOArH04KiYQAAAXE"]
[Tue Aug 18 12:58:20.296932 2026] [security2:error] [pid 66623:tid 66849] [client 20.206.73.37:5555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/indexo.php"] [unique_id "aoSBHNO5rbWdOArH04KiZwAAAV0"]
[Tue Aug 18 12:58:20.297088 2026] [authz_core:error] [pid 66623:tid 66720] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:20.297338 2026] [authz_core:error] [pid 66623:tid 66720] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:20.334323 2026] [security2:error] [pid 66623:tid 66836] [client 20.100.185.105:58339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/bypass.php"] [unique_id "aoSBHNO5rbWdOArH04KiagAAAVA"]
[Tue Aug 18 12:58:20.343307 2026] [security2:error] [pid 66623:tid 66845] [client 172.182.217.32:15765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/sid3.php"] [unique_id "aoSBHNO5rbWdOArH04KiawAAAVk"]
[Tue Aug 18 12:58:20.347936 2026] [security2:error] [pid 66623:tid 66785] [client 20.206.73.37:5487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSBHNO5rbWdOArH04KibAAAAR0"]
[Tue Aug 18 12:58:20.352484 2026] [security2:error] [pid 66623:tid 66808] [client 20.119.58.187:11980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/about.php7"] [unique_id "aoSBHNO5rbWdOArH04KibQAAATQ"]
[Tue Aug 18 12:58:20.385758 2026] [security2:error] [pid 66623:tid 66805] [client 40.74.65.169:55811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/media.php"] [unique_id "aoSBHNO5rbWdOArH04KidAAAATE"]
[Tue Aug 18 12:58:20.390383 2026] [security2:error] [pid 66623:tid 66729] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/images/index.php"] [unique_id "aoSBHNO5rbWdOArH04KidwABa1w"]
[Tue Aug 18 12:58:20.401754 2026] [security2:error] [pid 66623:tid 66769] [client 172.182.200.96:7559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/blog/byp.php"] [unique_id "aoSBHNO5rbWdOArH04KifAAAAQ0"]
[Tue Aug 18 12:58:20.405468 2026] [security2:error] [pid 66623:tid 66812] [client 86.120.159.145:59678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHNO5rbWdOArH04KiewAAATg"]
[Tue Aug 18 12:58:20.405568 2026] [security2:error] [pid 66623:tid 66812] [client 86.120.159.145:59678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHNO5rbWdOArH04KiewAAATg"]
[Tue Aug 18 12:58:20.414262 2026] [security2:error] [pid 66623:tid 66651] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/74.php"] [unique_id "aoSBHNO5rbWdOArH04KifQABJg4"]
[Tue Aug 18 12:58:20.425500 2026] [security2:error] [pid 66623:tid 66802] [client 216.73.160.240:52131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "twgestaoemarcas.com.br"] [uri "/wp-login.php"] [unique_id "aoSBHNO5rbWdOArH04KiZAAAAS4"]
[Tue Aug 18 12:58:20.514046 2026] [security2:error] [pid 66623:tid 66826] [client 158.158.74.177:2673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-blogs.php"] [unique_id "aoSBHNO5rbWdOArH04KigwAAAUY"]
[Tue Aug 18 12:58:20.515166 2026] [security2:error] [pid 66623:tid 66814] [client 20.79.204.6:11705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBHNO5rbWdOArH04KihAAAATo"]
[Tue Aug 18 12:58:20.532947 2026] [security2:error] [pid 66623:tid 66868] [client 20.118.172.148:19672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/about/function.php"] [unique_id "aoSBHNO5rbWdOArH04KihwAAAXA"]
[Tue Aug 18 12:58:20.568818 2026] [security2:error] [pid 66623:tid 66668] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/index/function.php"] [unique_id "aoSBHNO5rbWdOArH04KiiwABiR8"]
[Tue Aug 18 12:58:20.585717 2026] [security2:error] [pid 66623:tid 66839] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHNO5rbWdOArH04KiigABUyA"]
[Tue Aug 18 12:58:20.590800 2026] [security2:error] [pid 66623:tid 66714] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/av.php"] [unique_id "aoSBHNO5rbWdOArH04KijAABIU0"]
[Tue Aug 18 12:58:20.598970 2026] [authz_core:error] [pid 66623:tid 66671] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:20.599250 2026] [authz_core:error] [pid 66623:tid 66671] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:20.611623 2026] [security2:error] [pid 66623:tid 66797] [client 74.248.18.37:54940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/plugins.php"] [unique_id "aoSBHNO5rbWdOArH04KijgAAASk"]
[Tue Aug 18 12:58:20.614687 2026] [security2:error] [pid 66623:tid 66825] [client 52.173.121.69:24990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSBHNO5rbWdOArH04KijwAAAUU"]
[Tue Aug 18 12:58:20.635735 2026] [security2:error] [pid 66623:tid 66781] [client 74.248.18.37:7202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBHNO5rbWdOArH04KikAAAARk"]
[Tue Aug 18 12:58:20.683267 2026] [security2:error] [pid 66623:tid 66776] [client 20.206.73.37:59950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/w1px.php"] [unique_id "aoSBHNO5rbWdOArH04KilQAAARQ"]
[Tue Aug 18 12:58:20.696673 2026] [security2:error] [pid 66623:tid 66848] [client 20.206.73.37:52072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSBHNO5rbWdOArH04KilgAAAVw"]
[Tue Aug 18 12:58:20.705549 2026] [security2:error] [pid 66623:tid 66788] [client 20.119.58.187:11901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/adminfuns.php7"] [unique_id "aoSBHNO5rbWdOArH04KilwAAASA"]
[Tue Aug 18 12:58:20.710518 2026] [security2:error] [pid 66623:tid 66642] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.env.bak"] [unique_id "aoSBHNO5rbWdOArH04KimQABXgU"]
[Tue Aug 18 12:58:20.712030 2026] [security2:error] [pid 66623:tid 66739] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.env.old"] [unique_id "aoSBHNO5rbWdOArH04KimgABXmY"]
[Tue Aug 18 12:58:20.715425 2026] [security2:error] [pid 66623:tid 66864] [client 4.232.151.198:5261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/plugins/data.php"] [unique_id "aoSBHNO5rbWdOArH04KimwAAAWw"]
[Tue Aug 18 12:58:20.725766 2026] [security2:error] [pid 66623:tid 66870] [client 158.158.34.183:22985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/404.php123123"] [unique_id "aoSBHNO5rbWdOArH04KinAAAAXI"]
[Tue Aug 18 12:58:20.749368 2026] [security2:error] [pid 66623:tid 66866] [client 20.206.73.37:6087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/.admin.php"] [unique_id "aoSBHNO5rbWdOArH04KingAAAW4"]
[Tue Aug 18 12:58:20.752598 2026] [security2:error] [pid 66623:tid 66666] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.env.backup"] [unique_id "aoSBHNO5rbWdOArH04KinwABEh0"]
[Tue Aug 18 12:58:20.759156 2026] [security2:error] [pid 66623:tid 66681] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/api/.env"] [unique_id "aoSBHNO5rbWdOArH04KioAABbSw"]
[Tue Aug 18 12:58:20.778356 2026] [security2:error] [pid 66623:tid 66756] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/info.php"] [unique_id "aoSBHNO5rbWdOArH04KiogABWnc"]
[Tue Aug 18 12:58:20.791792 2026] [security2:error] [pid 66623:tid 66657] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ag.php"] [unique_id "aoSBHNO5rbWdOArH04KipAABaRQ"]
[Tue Aug 18 12:58:20.831958 2026] [security2:error] [pid 66623:tid 66885] [client 20.206.73.37:5445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wsomini.php"] [unique_id "aoSBHNO5rbWdOArH04KipwAAAYE"]
[Tue Aug 18 12:58:20.866937 2026] [security2:error] [pid 66623:tid 66852] [client 213.35.127.232:49160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBHNO5rbWdOArH04KiqwAAAWA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:20.879204 2026] [security2:error] [pid 66623:tid 66830] [client 20.206.73.37:55644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/vr.php"] [unique_id "aoSBHNO5rbWdOArH04KirAAAAUo"]
[Tue Aug 18 12:58:20.893387 2026] [security2:error] [pid 66623:tid 66869] [client 20.203.183.135:41537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/fpwch.php"] [unique_id "aoSBHNO5rbWdOArH04KirgAAAXE"]
[Tue Aug 18 12:58:20.901967 2026] [security2:error] [pid 66623:tid 66827] [client 20.48.236.86:31085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/puc.php"] [unique_id "aoSBHNO5rbWdOArH04KirwAAAUc"]
[Tue Aug 18 12:58:20.902559 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:20.902980 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:20.907282 2026] [security2:error] [pid 66623:tid 66828] [client 172.182.217.32:15578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/ss.php"] [unique_id "aoSBHNO5rbWdOArH04KisAAAAUg"]
[Tue Aug 18 12:58:20.933209 2026] [security2:error] [pid 66623:tid 66768] [client 20.104.85.180:14045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/alfa.php"] [unique_id "aoSBHNO5rbWdOArH04KisgAAAQw"]
[Tue Aug 18 12:58:20.950686 2026] [security2:error] [pid 66623:tid 66890] [client 172.182.200.96:14190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBHNO5rbWdOArH04KiswAAAYY"]
[Tue Aug 18 12:58:20.952688 2026] [security2:error] [pid 66623:tid 66849] [client 20.127.136.245:3211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBHNO5rbWdOArH04KitAAAAV0"]
[Tue Aug 18 12:58:20.953654 2026] [security2:error] [pid 66623:tid 66807] [client 40.74.65.169:7397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/8pyceeo.php"] [unique_id "aoSBHNO5rbWdOArH04KitQAAATM"]
[Tue Aug 18 12:58:20.958650 2026] [security2:error] [pid 66623:tid 66795] [client 20.100.185.105:16780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/alfanew.php7"] [unique_id "aoSBHNO5rbWdOArH04KitgAAASc"]
[Tue Aug 18 12:58:20.963430 2026] [security2:error] [pid 66623:tid 66688] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/install.php"] [unique_id "aoSBHNO5rbWdOArH04KitwABdzM"]
[Tue Aug 18 12:58:20.989688 2026] [security2:error] [pid 66623:tid 66753] [remote 108.167.161.148:20190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.161.167.108.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/wp-login.php"] [unique_id "aoSBHNO5rbWdOArH04KiuAABLHQ"]
[Tue Aug 18 12:58:21.014585 2026] [security2:error] [pid 66623:tid 66641] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ig.php"] [unique_id "aoSBHdO5rbWdOArH04KiugABewQ"]
[Tue Aug 18 12:58:21.038279 2026] [security2:error] [pid 66623:tid 66726] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/backend/.env"] [unique_id "aoSBHdO5rbWdOArH04KivAABelk"]
[Tue Aug 18 12:58:21.059132 2026] [security2:error] [pid 66623:tid 66881] [client 20.119.58.187:11896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/ebs.php7"] [unique_id "aoSBHdO5rbWdOArH04KivgAAAX0"]
[Tue Aug 18 12:58:21.115936 2026] [security2:error] [pid 66623:tid 66751] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/config/.env"] [unique_id "aoSBHdO5rbWdOArH04KiwwABQnI"]
[Tue Aug 18 12:58:21.116584 2026] [security2:error] [pid 66623:tid 66831] [client 20.79.204.6:11667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSBHdO5rbWdOArH04KixAAAAUs"]
[Tue Aug 18 12:58:21.148314 2026] [security2:error] [pid 66623:tid 66717] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/item.php"] [unique_id "aoSBHdO5rbWdOArH04KixgABVFA"]
[Tue Aug 18 12:58:21.184510 2026] [security2:error] [pid 66623:tid 66872] [client 68.155.155.199:10029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/rip.php"] [unique_id "aoSBHdO5rbWdOArH04KixwAAAXQ"]
[Tue Aug 18 12:58:21.191212 2026] [security2:error] [pid 66623:tid 66697] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ta.php"] [unique_id "aoSBHdO5rbWdOArH04KiyQABdjw"]
[Tue Aug 18 12:58:21.247199 2026] [security2:error] [pid 66623:tid 66808] [client 20.100.169.31:15277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/w1.php"] [unique_id "aoSBHdO5rbWdOArH04KiywAAATQ"]
[Tue Aug 18 12:58:21.268430 2026] [security2:error] [pid 66623:tid 66790] [client 20.118.133.132:14111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/btx25.php"] [unique_id "aoSBHdO5rbWdOArH04KizAAAASI"]
[Tue Aug 18 12:58:21.277027 2026] [security2:error] [pid 66623:tid 66799] [client 74.248.18.37:7217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/post.php"] [unique_id "aoSBHdO5rbWdOArH04KizgAAASs"]
[Tue Aug 18 12:58:21.286308 2026] [security2:error] [pid 66623:tid 66818] [client 52.173.121.69:17967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSBHdO5rbWdOArH04KizwAAAT4"]
[Tue Aug 18 12:58:21.328229 2026] [security2:error] [pid 66623:tid 66839] [client 172.182.200.96:14188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBHdO5rbWdOArH04Ki0AAAAVM"]
[Tue Aug 18 12:58:21.329529 2026] [security2:error] [pid 66623:tid 66746] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/kir.php"] [unique_id "aoSBHdO5rbWdOArH04Ki0QABIW0"]
[Tue Aug 18 12:58:21.330694 2026] [security2:error] [pid 66623:tid 66779] [client 20.104.85.180:18769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBHdO5rbWdOArH04Ki0wAAARc"]
[Tue Aug 18 12:58:21.330883 2026] [security2:error] [pid 66623:tid 66793] [client 74.248.18.37:21515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/data.php"] [unique_id "aoSBHdO5rbWdOArH04Ki0gAAASU"]
[Tue Aug 18 12:58:21.355184 2026] [security2:error] [pid 66623:tid 66834] [client 20.203.138.185:54985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/kj.php"] [unique_id "aoSBHdO5rbWdOArH04Ki1AAAAU4"]
[Tue Aug 18 12:58:21.405245 2026] [security2:error] [pid 66623:tid 66781] [client 40.74.65.169:56408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/images.php"] [unique_id "aoSBHdO5rbWdOArH04Ki1gAAARk"]
[Tue Aug 18 12:58:21.408379 2026] [security2:error] [pid 66623:tid 66737] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/34.php"] [unique_id "aoSBHdO5rbWdOArH04Ki1wABf2Q"]
[Tue Aug 18 12:58:21.409128 2026] [security2:error] [pid 66623:tid 66782] [client 172.182.217.32:15615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/sts.php"] [unique_id "aoSBHdO5rbWdOArH04Ki2AAAARo"]
[Tue Aug 18 12:58:21.410531 2026] [security2:error] [pid 66623:tid 66778] [client 20.119.58.187:12040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/ws.php7"] [unique_id "aoSBHdO5rbWdOArH04Ki2QAAARY"]
[Tue Aug 18 12:58:21.433622 2026] [security2:error] [pid 66623:tid 66802] [client 4.232.151.198:5287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/options.php"] [unique_id "aoSBHdO5rbWdOArH04Ki2gAAAS4"]
[Tue Aug 18 12:58:21.500950 2026] [security2:error] [pid 66623:tid 66801] [client 192.141.172.134:50522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHdO5rbWdOArH04Ki4QAAAS0"]
[Tue Aug 18 12:58:21.501139 2026] [security2:error] [pid 66623:tid 66801] [client 192.141.172.134:50522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHdO5rbWdOArH04Ki4QAAAS0"]
[Tue Aug 18 12:58:21.501170 2026] [authz_core:error] [pid 66623:tid 66662] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:21.501487 2026] [authz_core:error] [pid 66623:tid 66662] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:21.513926 2026] [security2:error] [pid 66623:tid 66796] [client 20.250.13.23:53865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/file.php"] [unique_id "aoSBHdO5rbWdOArH04Ki4wAAASg"]
[Tue Aug 18 12:58:21.575580 2026] [security2:error] [pid 66623:tid 66767] [client 20.100.185.105:34615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/admin-header.php"] [unique_id "aoSBHdO5rbWdOArH04Ki5QAAAQs"]
[Tue Aug 18 12:58:21.587417 2026] [security2:error] [pid 66623:tid 66861] [client 20.104.85.180:27933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/lock360.php"] [unique_id "aoSBHdO5rbWdOArH04Ki5gAAAWk"]
[Tue Aug 18 12:58:21.598350 2026] [security2:error] [pid 66623:tid 66806] [client 20.118.172.148:63087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/function/function.php"] [unique_id "aoSBHdO5rbWdOArH04Ki5wAAATI"]
[Tue Aug 18 12:58:21.612000 2026] [security2:error] [pid 66623:tid 66744] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/he.php"] [unique_id "aoSBHdO5rbWdOArH04Ki6AABN2s"]
[Tue Aug 18 12:58:21.642460 2026] [security2:error] [pid 66623:tid 66873] [client 20.127.136.245:13482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/about.php"] [unique_id "aoSBHdO5rbWdOArH04Ki6QAAAXU"]
[Tue Aug 18 12:58:21.654760 2026] [security2:error] [pid 66623:tid 66855] [client 40.74.65.169:27748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/.admin.php"] [unique_id "aoSBHdO5rbWdOArH04Ki6wAAAWM"]
[Tue Aug 18 12:58:21.723508 2026] [security2:error] [pid 66623:tid 66870] [client 20.79.204.6:11678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSBHdO5rbWdOArH04Ki8AAAAXI"]
[Tue Aug 18 12:58:21.780073 2026] [security2:error] [pid 66623:tid 66735] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/log.php"] [unique_id "aoSBHdO5rbWdOArH04Ki9AABe2I"]
[Tue Aug 18 12:58:21.780087 2026] [security2:error] [pid 66623:tid 66869] [client 20.119.58.187:11881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/alfanew2.php7"] [unique_id "aoSBHdO5rbWdOArH04Ki9QAAAXE"]
[Tue Aug 18 12:58:21.790826 2026] [security2:error] [pid 66623:tid 66672] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gz.php"] [unique_id "aoSBHdO5rbWdOArH04Ki9gABHSM"]
[Tue Aug 18 12:58:21.803497 2026] [authz_core:error] [pid 66623:tid 66748] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:21.803772 2026] [authz_core:error] [pid 66623:tid 66748] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:21.819561 2026] [security2:error] [pid 66623:tid 66871] [client 158.158.74.177:26173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-config.php"] [unique_id "aoSBHdO5rbWdOArH04Ki-AAAAXM"]
[Tue Aug 18 12:58:21.869419 2026] [security2:error] [pid 66623:tid 66766] [client 158.23.17.4:32514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ns.php"] [unique_id "aoSBHdO5rbWdOArH04Ki_gAAAQo"]
[Tue Aug 18 12:58:21.891002 2026] [security2:error] [pid 66623:tid 66866] [client 213.35.127.232:49391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBHdO5rbWdOArH04KjAAAAAW4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:21.897091 2026] [security2:error] [pid 66623:tid 66849] [client 172.182.217.32:15778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/shell.php"] [unique_id "aoSBHdO5rbWdOArH04KjAQAAAV0"]
[Tue Aug 18 12:58:21.898581 2026] [security2:error] [pid 66623:tid 66826] [client 37.40.227.74:57044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHdO5rbWdOArH04Ki_wAAAUY"]
[Tue Aug 18 12:58:21.898707 2026] [security2:error] [pid 66623:tid 66826] [client 37.40.227.74:57044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHdO5rbWdOArH04Ki_wAAAUY"]
[Tue Aug 18 12:58:21.936515 2026] [security2:error] [pid 66623:tid 66822] [client 52.173.121.69:6116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSBHdO5rbWdOArH04KjAwAAAUI"]
[Tue Aug 18 12:58:21.940044 2026] [security2:error] [pid 66623:tid 66890] [client 74.248.18.37:40963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/r.php"] [unique_id "aoSBHdO5rbWdOArH04KjBAAAAYY"]
[Tue Aug 18 12:58:21.956559 2026] [security2:error] [pid 66623:tid 66738] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/logins.php"] [unique_id "aoSBHdO5rbWdOArH04KjBQABJmU"]
[Tue Aug 18 12:58:21.959123 2026] [security2:error] [pid 66623:tid 66832] [client 20.104.85.180:15742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/flower.php"] [unique_id "aoSBHdO5rbWdOArH04KjBgAAAUw"]
[Tue Aug 18 12:58:21.967398 2026] [security2:error] [pid 66623:tid 66840] [client 172.182.200.96:14106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/images/security.php"] [unique_id "aoSBHdO5rbWdOArH04KjCAAAAVQ"]
[Tue Aug 18 12:58:21.968940 2026] [authz_core:error] [pid 66623:tid 66640] [remote 57.141.22.16:28110] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:21.969200 2026] [authz_core:error] [pid 66623:tid 66640] [remote 57.141.22.16:28110] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:21.982601 2026] [security2:error] [pid 66623:tid 66701] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/nf.php"] [unique_id "aoSBHdO5rbWdOArH04KjCQABO0A"]
[Tue Aug 18 12:58:22.073576 2026] [security2:error] [pid 66623:tid 66821] [client 4.232.151.198:5301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/js/new.php"] [unique_id "aoSBHtO5rbWdOArH04KjDQAAAUE"]
[Tue Aug 18 12:58:22.085711 2026] [security2:error] [pid 66623:tid 66863] [client 74.248.18.37:7743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/disagrsxr.php"] [unique_id "aoSBHtO5rbWdOArH04KjDgAAAWs"]
[Tue Aug 18 12:58:22.101190 2026] [security2:error] [pid 66623:tid 66893] [client 20.118.172.148:50086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-signin.php"] [unique_id "aoSBHtO5rbWdOArH04KjEAAAAYk"]
[Tue Aug 18 12:58:22.104171 2026] [authz_core:error] [pid 66623:tid 66687] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:22.104448 2026] [authz_core:error] [pid 66623:tid 66687] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:22.137032 2026] [security2:error] [pid 66623:tid 66747] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/mailer.php"] [unique_id "aoSBHtO5rbWdOArH04KjEwABOW4"]
[Tue Aug 18 12:58:22.139556 2026] [security2:error] [pid 66623:tid 66874] [client 20.119.58.187:11866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/alfa-rex2.php7"] [unique_id "aoSBHtO5rbWdOArH04KjFAAAAXY"]
[Tue Aug 18 12:58:22.150482 2026] [security2:error] [pid 66623:tid 66706] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.github/.env"] [unique_id "aoSBHtO5rbWdOArH04KjFgABQEU"]
[Tue Aug 18 12:58:22.184842 2026] [security2:error] [pid 66623:tid 66782] [client 68.155.155.199:14209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/update/da222.php"] [unique_id "aoSBHtO5rbWdOArH04KjGQAAARo"]
[Tue Aug 18 12:58:22.193980 2026] [security2:error] [pid 66623:tid 66888] [client 20.100.185.105:6769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/83064.php"] [unique_id "aoSBHtO5rbWdOArH04KjGgAAAYQ"]
[Tue Aug 18 12:58:22.194754 2026] [security2:error] [pid 66623:tid 66778] [client 20.104.85.180:19765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBHtO5rbWdOArH04KjGwAAARY"]
[Tue Aug 18 12:58:22.249062 2026] [authz_core:error] [pid 66623:tid 66721] [remote 57.141.22.85:32532] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:22.249372 2026] [authz_core:error] [pid 66623:tid 66721] [remote 57.141.22.85:32532] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:22.249802 2026] [security2:error] [pid 66623:tid 66802] [client 40.74.65.169:56442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/mac.php"] [unique_id "aoSBHtO5rbWdOArH04KjHgAAAS4"]
[Tue Aug 18 12:58:22.251402 2026] [security2:error] [pid 66623:tid 66713] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/xv.php"] [unique_id "aoSBHtO5rbWdOArH04KjHwABZ0w"]
[Tue Aug 18 12:58:22.316652 2026] [security2:error] [pid 66623:tid 66637] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/min.php"] [unique_id "aoSBHtO5rbWdOArH04KjIQABLQA"]
[Tue Aug 18 12:58:22.329211 2026] [security2:error] [pid 66623:tid 66789] [client 20.79.204.6:11658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBHtO5rbWdOArH04KjIgAAASE"]
[Tue Aug 18 12:58:22.352505 2026] [security2:error] [pid 66623:tid 66844] [client 103.120.71.157:58257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHtO5rbWdOArH04KjIwAAAVg"]
[Tue Aug 18 12:58:22.352653 2026] [security2:error] [pid 66623:tid 66844] [client 103.120.71.157:58257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHtO5rbWdOArH04KjIwAAAVg"]
[Tue Aug 18 12:58:22.356224 2026] [security2:error] [pid 66623:tid 66780] [client 40.74.65.169:43198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wsomini.php"] [unique_id "aoSBHtO5rbWdOArH04KjJAAAARg"]
[Tue Aug 18 12:58:22.362590 2026] [security2:error] [pid 66623:tid 66852] [client 103.184.169.37:42343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHtO5rbWdOArH04KjJQAAAWA"]
[Tue Aug 18 12:58:22.362678 2026] [security2:error] [pid 66623:tid 66852] [client 103.184.169.37:42343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHtO5rbWdOArH04KjJQAAAWA"]
[Tue Aug 18 12:58:22.384806 2026] [security2:error] [pid 66623:tid 66816] [client 172.182.217.32:15744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/setup-config.php"] [unique_id "aoSBHtO5rbWdOArH04KjKgAAATw"]
[Tue Aug 18 12:58:22.400219 2026] [security2:error] [pid 66623:tid 66787] [client 172.202.39.151:44603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/admin.php"] [unique_id "aoSBHtO5rbWdOArH04KjLAAAAR8"]
[Tue Aug 18 12:58:22.463797 2026] [security2:error] [pid 66623:tid 66835] [client 20.203.138.185:50715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/bes.php"] [unique_id "aoSBHtO5rbWdOArH04KjLQAAAU8"]
[Tue Aug 18 12:58:22.474810 2026] [security2:error] [pid 66623:tid 66647] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/mx.php"] [unique_id "aoSBHtO5rbWdOArH04KjMAABFQo"]
[Tue Aug 18 12:58:22.494238 2026] [security2:error] [pid 66623:tid 66838] [client 20.119.58.187:12540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "aoSBHtO5rbWdOArH04KjMwAAAVI"]
[Tue Aug 18 12:58:22.508229 2026] [authz_core:error] [pid 66623:tid 66728] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:22.508567 2026] [authz_core:error] [pid 66623:tid 66728] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:22.521890 2026] [security2:error] [pid 66623:tid 66864] [client 20.118.172.148:53118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/f35.php"] [unique_id "aoSBHtO5rbWdOArH04KjNgAAAWw"]
[Tue Aug 18 12:58:22.546455 2026] [security2:error] [pid 66623:tid 66855] [client 158.23.17.4:33409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/gk.php"] [unique_id "aoSBHtO5rbWdOArH04KjNwAAAWM"]
[Tue Aug 18 12:58:22.555067 2026] [security2:error] [pid 66623:tid 66865] [client 20.104.85.180:31236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/13.php"] [unique_id "aoSBHtO5rbWdOArH04KjOAAAAW0"]
[Tue Aug 18 12:58:22.601111 2026] [authz_core:error] [pid 66623:tid 66648] [remote 136.110.27.48:37542] AH01630: client denied by server configuration: /home4/gueirosadv/_wildcard_.gueirosadvocacia.com.br/.htpasswd
[Tue Aug 18 12:58:22.632123 2026] [security2:error] [pid 66623:tid 66892] [client 74.248.18.37:7705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/radio.php"] [unique_id "aoSBHtO5rbWdOArH04KjPQAAAYg"]
[Tue Aug 18 12:58:22.650572 2026] [security2:error] [pid 66623:tid 66869] [client 20.48.236.86:2773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/19.php"] [unique_id "aoSBHtO5rbWdOArH04KjQAAAAXE"]
[Tue Aug 18 12:58:22.659407 2026] [security2:error] [pid 66623:tid 66878] [client 52.173.121.69:16450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSBHtO5rbWdOArH04KjQgAAAXo"]
[Tue Aug 18 12:58:22.703490 2026] [security2:error] [pid 66623:tid 66696] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/45.php"] [unique_id "aoSBHtO5rbWdOArH04KjRAABDTs"]
[Tue Aug 18 12:58:22.710595 2026] [security2:error] [pid 66623:tid 66843] [client 4.232.151.198:5872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/themes/petz/inc/plugins/wp-links-opml.php"] [unique_id "aoSBHtO5rbWdOArH04KjRgAAAVc"]
[Tue Aug 18 12:58:22.760852 2026] [authz_core:error] [pid 66623:tid 66707] [remote 57.141.22.105:48902] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:22.761113 2026] [authz_core:error] [pid 66623:tid 66707] [remote 57.141.22.105:48902] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:22.768873 2026] [security2:error] [pid 66623:tid 66684] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/mini.php"] [unique_id "aoSBHtO5rbWdOArH04KjSQABJi8"]
[Tue Aug 18 12:58:22.775659 2026] [security2:error] [pid 66623:tid 66815] [client 20.127.136.245:14516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/goods.php"] [unique_id "aoSBHtO5rbWdOArH04KjSgAAATs"]
[Tue Aug 18 12:58:22.776561 2026] [security2:error] [pid 66623:tid 66828] [client 74.248.18.37:40994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/dropdown.php"] [unique_id "aoSBHtO5rbWdOArH04KjSwAAAUg"]
[Tue Aug 18 12:58:22.812381 2026] [security2:error] [pid 66623:tid 66786] [client 20.100.185.105:21690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-trackback.php"] [unique_id "aoSBHtO5rbWdOArH04KjTQAAAR4"]
[Tue Aug 18 12:58:22.864973 2026] [security2:error] [pid 66623:tid 66890] [client 20.119.58.187:12536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "aoSBHtO5rbWdOArH04KjUgAAAYY"]
[Tue Aug 18 12:58:22.876476 2026] [security2:error] [pid 66623:tid 66849] [client 172.182.217.32:15566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/t.php"] [unique_id "aoSBHtO5rbWdOArH04KjUwAAAV0"]
[Tue Aug 18 12:58:22.878434 2026] [security2:error] [pid 66623:tid 66702] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSBHtO5rbWdOArH04KjVAABQUE"]
[Tue Aug 18 12:58:22.892908 2026] [security2:error] [pid 66623:tid 66863] [client 20.206.73.37:11907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/zi-936.php"] [unique_id "aoSBHtO5rbWdOArH04KjVgAAAWs"]
[Tue Aug 18 12:58:22.903163 2026] [security2:error] [pid 66623:tid 66837] [client 213.35.127.232:49590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBHtO5rbWdOArH04KjVwAAAVE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:22.929107 2026] [security2:error] [pid 66623:tid 66694] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/wy.php"] [unique_id "aoSBHtO5rbWdOArH04KjWQABWTk"]
[Tue Aug 18 12:58:22.937628 2026] [security2:error] [pid 66623:tid 66822] [client 20.79.204.6:11686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSBHtO5rbWdOArH04KjWwAAAUI"]
[Tue Aug 18 12:58:22.942117 2026] [security2:error] [pid 66623:tid 66820] [client 40.74.65.169:56435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/ops.php"] [unique_id "aoSBHtO5rbWdOArH04KjXAAAAUA"]
[Tue Aug 18 12:58:22.958366 2026] [security2:error] [pid 66623:tid 66856] [client 68.155.155.199:6956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/upload.php"] [unique_id "aoSBHtO5rbWdOArH04KjXgAAAWQ"]
[Tue Aug 18 12:58:22.960184 2026] [security2:error] [pid 66623:tid 66740] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/moddofuns.php"] [unique_id "aoSBHtO5rbWdOArH04KjXwABf2c"]
[Tue Aug 18 12:58:22.973834 2026] [security2:error] [pid 66623:tid 66679] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSBHtO5rbWdOArH04KjYQABNSo"]
[Tue Aug 18 12:58:22.993249 2026] [security2:error] [pid 66623:tid 66825] [client 20.118.172.148:33509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/gg.php"] [unique_id "aoSBHtO5rbWdOArH04KjZAAAAUU"]
[Tue Aug 18 12:58:23.006401 2026] [authz_core:error] [pid 66623:tid 66734] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:23.006662 2026] [authz_core:error] [pid 66623:tid 66734] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:23.065821 2026] [security2:error] [pid 66623:tid 66796] [client 40.74.65.169:35747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/vr.php"] [unique_id "aoSBH9O5rbWdOArH04KjaAAAASg"]
[Tue Aug 18 12:58:23.067333 2026] [security2:error] [pid 66623:tid 66844] [client 20.203.138.185:54979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ws60.php"] [unique_id "aoSBH9O5rbWdOArH04KjaQAAAVg"]
[Tue Aug 18 12:58:23.080213 2026] [security2:error] [pid 66623:tid 66780] [client 20.100.169.31:29030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-login.php"] [unique_id "aoSBH9O5rbWdOArH04KjagAAARg"]
[Tue Aug 18 12:58:23.104765 2026] [security2:error] [pid 66623:tid 66787] [client 20.104.85.180:27959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/cc.php"] [unique_id "aoSBH9O5rbWdOArH04KjbQAAAR8"]
[Tue Aug 18 12:58:23.111707 2026] [security2:error] [pid 66623:tid 66791] [client 158.23.17.4:34149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/wn.php"] [unique_id "aoSBH9O5rbWdOArH04KjbgAAASM"]
[Tue Aug 18 12:58:23.141585 2026] [security2:error] [pid 66623:tid 66651] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/f.php"] [unique_id "aoSBH9O5rbWdOArH04KjcAABDg4"]
[Tue Aug 18 12:58:23.145406 2026] [security2:error] [pid 66623:tid 66638] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/modules/hrm/assets/plugins/db-status.php"] [unique_id "aoSBH9O5rbWdOArH04KjcQABNwE"]
[Tue Aug 18 12:58:23.182367 2026] [security2:error] [pid 66623:tid 66859] [client 79.127.164.8:33122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/scriptsacplibinserts.sql"] [unique_id "aoSBH9O5rbWdOArH04KjdAAAAWc"], referer: https://medihub.com.br/scriptsacplibinserts.sql
[Tue Aug 18 12:58:23.218112 2026] [security2:error] [pid 66623:tid 66846] [client 20.119.58.187:12077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/linkpreview/db.php"] [unique_id "aoSBH9O5rbWdOArH04KjdQAAAVo"]
[Tue Aug 18 12:58:23.267009 2026] [security2:error] [pid 66623:tid 66806] [client 20.104.85.180:19731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/admin.php"] [unique_id "aoSBH9O5rbWdOArH04KjeQAAATI"]
[Tue Aug 18 12:58:23.307535 2026] [authz_core:error] [pid 66623:tid 66714] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:23.307802 2026] [authz_core:error] [pid 66623:tid 66714] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:23.323297 2026] [security2:error] [pid 66623:tid 66711] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/moduless.php"] [unique_id "aoSBH9O5rbWdOArH04KjfQABiEo"]
[Tue Aug 18 12:58:23.337311 2026] [security2:error] [pid 66623:tid 66785] [client 20.118.172.148:46752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/class.php"] [unique_id "aoSBH9O5rbWdOArH04KjfwAAAR0"]
[Tue Aug 18 12:58:23.348784 2026] [security2:error] [pid 66623:tid 66871] [client 68.155.155.199:13477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wk/index.php"] [unique_id "aoSBH9O5rbWdOArH04KjgAAAAXM"]
[Tue Aug 18 12:58:23.358450 2026] [security2:error] [pid 66623:tid 66680] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/30.php"] [unique_id "aoSBH9O5rbWdOArH04KjgQABeSs"]
[Tue Aug 18 12:58:23.369064 2026] [security2:error] [pid 66623:tid 66855] [client 172.182.217.32:15773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/up.php"] [unique_id "aoSBH9O5rbWdOArH04KjgwAAAWM"]
[Tue Aug 18 12:58:23.392037 2026] [security2:error] [pid 66623:tid 66722] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/id_rsa"] [unique_id "aoSBH9O5rbWdOArH04KjhQABRlU"]
[Tue Aug 18 12:58:23.433339 2026] [security2:error] [pid 66623:tid 66739] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/id_dsa"] [unique_id "aoSBH9O5rbWdOArH04KjhwABaWY"]
[Tue Aug 18 12:58:23.489249 2026] [security2:error] [pid 66623:tid 66786] [client 52.173.121.69:24801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSBH9O5rbWdOArH04KjigAAAR4"]
[Tue Aug 18 12:58:23.493976 2026] [security2:error] [pid 66623:tid 66798] [client 20.100.185.105:6841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/dxc.php"] [unique_id "aoSBH9O5rbWdOArH04KjiwAAASo"]
[Tue Aug 18 12:58:23.528740 2026] [security2:error] [pid 66623:tid 66681] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBH9O5rbWdOArH04KjjgABcCw"]
[Tue Aug 18 12:58:23.557307 2026] [security2:error] [pid 66623:tid 66849] [client 20.118.133.132:16868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSBH9O5rbWdOArH04KjkAAAAV0"]
[Tue Aug 18 12:58:23.560986 2026] [security2:error] [pid 66623:tid 66766] [client 20.79.204.6:11685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSBH9O5rbWdOArH04KjkQAAAQo"]
[Tue Aug 18 12:58:23.571078 2026] [security2:error] [pid 66623:tid 66794] [client 20.119.58.187:12033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSBH9O5rbWdOArH04KjkgAAASY"]
[Tue Aug 18 12:58:23.581096 2026] [security2:error] [pid 66623:tid 66858] [client 20.48.236.86:36139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/133.php"] [unique_id "aoSBH9O5rbWdOArH04KjlAAAAWY"]
[Tue Aug 18 12:58:23.585386 2026] [security2:error] [pid 66623:tid 66664] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/pu.php"] [unique_id "aoSBH9O5rbWdOArH04KjlQABdhs"]
[Tue Aug 18 12:58:23.589600 2026] [security2:error] [pid 66623:tid 66797] [client 4.232.151.198:62663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/Cap.php"] [unique_id "aoSBH9O5rbWdOArH04KjlgAAASk"]
[Tue Aug 18 12:58:23.595956 2026] [security2:error] [pid 66623:tid 66800] [client 158.158.74.177:2652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSBH9O5rbWdOArH04KjlwAAASw"]
[Tue Aug 18 12:58:23.598802 2026] [security2:error] [pid 66623:tid 66769] [client 74.248.18.37:7206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/randkeyword.php7"] [unique_id "aoSBH9O5rbWdOArH04KjmAAAAQ0"]
[Tue Aug 18 12:58:23.612302 2026] [authz_core:error] [pid 66623:tid 66750] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:23.612588 2026] [authz_core:error] [pid 66623:tid 66750] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:23.679733 2026] [security2:error] [pid 66623:tid 66883] [client 20.118.172.148:19664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/flower.php"] [unique_id "aoSBH9O5rbWdOArH04KjnQAAAX8"]
[Tue Aug 18 12:58:23.691846 2026] [security2:error] [pid 66623:tid 66829] [client 149.34.210.141:61315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBH9O5rbWdOArH04KjngAAAUk"]
[Tue Aug 18 12:58:23.705982 2026] [security2:error] [pid 66623:tid 66753] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/new.php"] [unique_id "aoSBH9O5rbWdOArH04KjnwABW3Q"]
[Tue Aug 18 12:58:23.724061 2026] [security2:error] [pid 66623:tid 66893] [client 157.20.138.62:51948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBH9O5rbWdOArH04KjoAAAAYk"]
[Tue Aug 18 12:58:23.724157 2026] [security2:error] [pid 66623:tid 66893] [client 157.20.138.62:51948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBH9O5rbWdOArH04KjoAAAAYk"]
[Tue Aug 18 12:58:23.748691 2026] [security2:error] [pid 66623:tid 66801] [client 5.31.227.224:7809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBH9O5rbWdOArH04KjogAAAS0"]
[Tue Aug 18 12:58:23.748892 2026] [security2:error] [pid 66623:tid 66801] [client 5.31.227.224:7809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBH9O5rbWdOArH04KjogAAAS0"]
[Tue Aug 18 12:58:23.755429 2026] [security2:error] [pid 66623:tid 66774] [client 20.203.138.185:45377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/olfclass.php"] [unique_id "aoSBH9O5rbWdOArH04KjpAAAARI"]
[Tue Aug 18 12:58:23.771483 2026] [security2:error] [pid 66623:tid 66641] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ry.php"] [unique_id "aoSBH9O5rbWdOArH04KjpQABPAQ"]
[Tue Aug 18 12:58:23.781059 2026] [security2:error] [pid 66623:tid 66852] [client 20.104.85.180:26735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBH9O5rbWdOArH04KjpgAAAWA"]
[Tue Aug 18 12:58:23.832367 2026] [autoindex:error] [pid 66623:tid 66811] [client 85.204.70.114:46956] AH01276: Cannot serve directory /home2/combrazilcoa/intersul.ind.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:23.862883 2026] [security2:error] [pid 66623:tid 66825] [client 172.182.217.32:15552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/ultra.php"] [unique_id "aoSBH9O5rbWdOArH04KjrAAAAUU"]
[Tue Aug 18 12:58:23.882365 2026] [security2:error] [pid 66623:tid 66652] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/node_modules/@babel/preset-modules/lib/plugins/system.php"] [unique_id "aoSBH9O5rbWdOArH04KjrgABZw8"]
[Tue Aug 18 12:58:23.921466 2026] [security2:error] [pid 66623:tid 66793] [client 213.35.127.232:49805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBH9O5rbWdOArH04KjsAAAASU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:23.926523 2026] [security2:error] [pid 66623:tid 66848] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBH9O5rbWdOArH04KjsQAAAVw"]
[Tue Aug 18 12:58:23.943167 2026] [security2:error] [pid 66623:tid 66720] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/pm.php"] [unique_id "aoSBH9O5rbWdOArH04KjswABZVM"]
[Tue Aug 18 12:58:23.951068 2026] [security2:error] [pid 66623:tid 66768] [client 68.155.155.199:10124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-act.php"] [unique_id "aoSBH9O5rbWdOArH04KjtQAAAQw"]
[Tue Aug 18 12:58:23.958690 2026] [security2:error] [pid 66623:tid 66829] [client 149.34.210.141:61315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBH9O5rbWdOArH04KjngAAAUk"]
[Tue Aug 18 12:58:23.960967 2026] [security2:error] [pid 66623:tid 66795] [client 40.74.65.169:56429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/coffexium.php"] [unique_id "aoSBH9O5rbWdOArH04KjtgAAASc"]
[Tue Aug 18 12:58:23.978244 2026] [security2:error] [pid 66623:tid 66869] [client 158.23.17.4:12513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/app.php"] [unique_id "aoSBH9O5rbWdOArH04KjuQAAAXE"]
[Tue Aug 18 12:58:23.994743 2026] [security2:error] [pid 66623:tid 66777] [client 20.119.58.187:11847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/seoplugins/db.php"] [unique_id "aoSBH9O5rbWdOArH04KjugAAARU"]
[Tue Aug 18 12:58:24.009218 2026] [security2:error] [pid 66623:tid 66876] [client 20.127.136.245:21472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/php8.php"] [unique_id "aoSBINO5rbWdOArH04KjuwAAAXg"]
[Tue Aug 18 12:58:24.059891 2026] [security2:error] [pid 66623:tid 66835] [client 20.104.85.180:14576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/public/css.php"] [unique_id "aoSBINO5rbWdOArH04KjvQAAAU8"]
[Tue Aug 18 12:58:24.075469 2026] [security2:error] [pid 66623:tid 66717] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/num.php"] [unique_id "aoSBINO5rbWdOArH04KjvgABblA"]
[Tue Aug 18 12:58:24.085038 2026] [security2:error] [pid 66623:tid 66826] [client 74.248.18.37:7704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/images/about.php"] [unique_id "aoSBINO5rbWdOArH04KjvwAAAUY"]
[Tue Aug 18 12:58:24.093165 2026] [security2:error] [pid 66623:tid 66827] [client 20.118.172.148:33479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/motu.php"] [unique_id "aoSBINO5rbWdOArH04KjwAAAAUc"]
[Tue Aug 18 12:58:24.113105 2026] [security2:error] [pid 66623:tid 66865] [client 20.100.185.105:6810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/v4.php"] [unique_id "aoSBINO5rbWdOArH04KjwQAAAW0"]
[Tue Aug 18 12:58:24.142168 2026] [security2:error] [pid 66623:tid 66798] [client 20.206.73.37:20728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/dcsgumnm.php"] [unique_id "aoSBINO5rbWdOArH04KjxAAAASo"]
[Tue Aug 18 12:58:24.145621 2026] [security2:error] [pid 66623:tid 66709] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/key.pem"] [unique_id "aoSBINO5rbWdOArH04KjxQABVkg"]
[Tue Aug 18 12:58:24.145625 2026] [security2:error] [pid 66623:tid 66718] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/privatekey.key"] [unique_id "aoSBINO5rbWdOArH04KjxwABVlE"]
[Tue Aug 18 12:58:24.162154 2026] [security2:error] [pid 66623:tid 66862] [client 20.79.204.6:11524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSBINO5rbWdOArH04KjyQAAAWo"]
[Tue Aug 18 12:58:24.184613 2026] [security2:error] [pid 66623:tid 66754] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/dr.php"] [unique_id "aoSBINO5rbWdOArH04KjzAABhnU"]
[Tue Aug 18 12:58:24.185937 2026] [authz_core:error] [pid 66623:tid 66690] [remote 57.141.22.51:42726] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:24.186191 2026] [authz_core:error] [pid 66623:tid 66690] [remote 57.141.22.51:42726] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:24.186781 2026] [security2:error] [pid 66623:tid 66878] [client 223.185.37.47:21759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBINO5rbWdOArH04KjzQAAAXo"]
[Tue Aug 18 12:58:24.186903 2026] [security2:error] [pid 66623:tid 66878] [client 223.185.37.47:21759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBINO5rbWdOArH04KjzQAAAXo"]
[Tue Aug 18 12:58:24.233649 2026] [autoindex:error] [pid 66623:tid 66794] [client 85.204.70.114:46956] AH01276: Cannot serve directory /home2/combrazilcoa/intersul.ind.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:24.244959 2026] [security2:error] [pid 66623:tid 66830] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBINO5rbWdOArH04Kj0QAAAUo"]
[Tue Aug 18 12:58:24.259587 2026] [security2:error] [pid 66623:tid 66660] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/php.php"] [unique_id "aoSBINO5rbWdOArH04Kj0wABLBc"]
[Tue Aug 18 12:58:24.273894 2026] [security2:error] [pid 66623:tid 66783] [client 158.158.34.183:52681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/log.php"] [unique_id "aoSBINO5rbWdOArH04Kj1AAAARs"]
[Tue Aug 18 12:58:24.348776 2026] [security2:error] [pid 66623:tid 66872] [client 4.232.151.198:62665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-includes/sodium_compat/index.php"] [unique_id "aoSBINO5rbWdOArH04Kj1wAAAXQ"]
[Tue Aug 18 12:58:24.351740 2026] [security2:error] [pid 66623:tid 66863] [client 20.119.58.187:11989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/seoplugins/mar.php"] [unique_id "aoSBINO5rbWdOArH04Kj2AAAAWs"]
[Tue Aug 18 12:58:24.369093 2026] [security2:error] [pid 66623:tid 66766] [client 172.182.217.32:15790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/vv.php"] [unique_id "aoSBINO5rbWdOArH04Kj2gAAAQo"]
[Tue Aug 18 12:58:24.398817 2026] [security2:error] [pid 66623:tid 66847] [client 20.104.85.180:23993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSBINO5rbWdOArH04Kj3QAAAVs"]
[Tue Aug 18 12:58:24.410241 2026] [security2:error] [pid 66623:tid 66758] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ts.php"] [unique_id "aoSBINO5rbWdOArH04Kj3gABD3k"]
[Tue Aug 18 12:58:24.422883 2026] [security2:error] [pid 66623:tid 66796] [client 85.204.70.114:46956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aoSBINO5rbWdOArH04Kj3wAAASg"]
[Tue Aug 18 12:58:24.422946 2026] [security2:error] [pid 66623:tid 66789] [client 20.215.241.237:62531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/coffexium.php"] [unique_id "aoSBINO5rbWdOArH04Kj4AAAASE"]
[Tue Aug 18 12:58:24.430454 2026] [security2:error] [pid 66623:tid 66893] [client 68.155.155.199:6067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSBINO5rbWdOArH04Kj4QAAAYk"]
[Tue Aug 18 12:58:24.441881 2026] [security2:error] [pid 66623:tid 66663] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/php/eval-stdin.php"] [unique_id "aoSBINO5rbWdOArH04Kj4gABLRo"]
[Tue Aug 18 12:58:24.477529 2026] [security2:error] [pid 66623:tid 66846] [client 178.153.171.161:20542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBINO5rbWdOArH04Kj5QAAAVo"]
[Tue Aug 18 12:58:24.477633 2026] [security2:error] [pid 66623:tid 66846] [client 178.153.171.161:20542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBINO5rbWdOArH04Kj5QAAAVo"]
[Tue Aug 18 12:58:24.485145 2026] [security2:error] [pid 66623:tid 66791] [client 158.23.17.4:38326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/87.php"] [unique_id "aoSBINO5rbWdOArH04Kj6AAAASM"]
[Tue Aug 18 12:58:24.512917 2026] [authz_core:error] [pid 66623:tid 66672] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:24.513180 2026] [authz_core:error] [pid 66623:tid 66672] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:24.549452 2026] [security2:error] [pid 66623:tid 66825] [client 52.173.121.69:24805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSBINO5rbWdOArH04Kj9wAAAUU"]
[Tue Aug 18 12:58:24.559142 2026] [security2:error] [pid 66623:tid 66889] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/img.php"] [unique_id "aoSBINO5rbWdOArH04Kj-AAAAYU"]
[Tue Aug 18 12:58:24.564612 2026] [security2:error] [pid 66623:tid 66848] [client 20.104.85.180:20239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBINO5rbWdOArH04Kj-QAAAVw"]
[Tue Aug 18 12:58:24.569984 2026] [security2:error] [pid 66623:tid 66857] [client 20.118.172.148:58753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/404.php"] [unique_id "aoSBINO5rbWdOArH04Kj-gAAAWU"]
[Tue Aug 18 12:58:24.583192 2026] [security2:error] [pid 66623:tid 66870] [client 74.248.18.37:7207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/red.php"] [unique_id "aoSBINO5rbWdOArH04Kj_AAAAXI"]
[Tue Aug 18 12:58:24.593223 2026] [security2:error] [pid 66623:tid 66762] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/53.php"] [unique_id "aoSBINO5rbWdOArH04Kj_gABUH0"]
[Tue Aug 18 12:58:24.621337 2026] [security2:error] [pid 66623:tid 66654] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/php8.php"] [unique_id "aoSBINO5rbWdOArH04Kj_wABcRE"]
[Tue Aug 18 12:58:24.654497 2026] [security2:error] [pid 66623:tid 66876] [client 20.48.236.86:25955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/1xmomo.php"] [unique_id "aoSBINO5rbWdOArH04KkAwAAAXg"]
[Tue Aug 18 12:58:24.673384 2026] [security2:error] [pid 66623:tid 66686] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBINO5rbWdOArH04KkBQABfTE"]
[Tue Aug 18 12:58:24.673597 2026] [security2:error] [pid 66623:tid 66881] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBINO5rbWdOArH04KkBQABfTE"]
[Tue Aug 18 12:58:24.682939 2026] [security2:error] [pid 66623:tid 66826] [client 172.202.39.151:44560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/public/css.php"] [unique_id "aoSBINO5rbWdOArH04KkBwAAAUY"]
[Tue Aug 18 12:58:24.705298 2026] [security2:error] [pid 66623:tid 66829] [client 20.119.58.187:11873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSBINO5rbWdOArH04KkCAAAAUk"]
[Tue Aug 18 12:58:24.735977 2026] [security2:error] [pid 66623:tid 66811] [client 20.100.185.105:6732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/error.php"] [unique_id "aoSBINO5rbWdOArH04KkCgAAATc"]
[Tue Aug 18 12:58:24.763905 2026] [security2:error] [pid 66623:tid 66793] [client 20.79.204.6:11648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBINO5rbWdOArH04KkCwAAASU"]
[Tue Aug 18 12:58:24.777935 2026] [security2:error] [pid 66623:tid 66842] [client 20.203.138.185:44077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wpver.php"] [unique_id "aoSBINO5rbWdOArH04KkDQAAAVY"]
[Tue Aug 18 12:58:24.793503 2026] [security2:error] [pid 66623:tid 66665] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/lq.php"] [unique_id "aoSBINO5rbWdOArH04KkDwABNhw"]
[Tue Aug 18 12:58:24.812818 2026] [security2:error] [pid 66623:tid 66804] [client 40.74.65.169:56389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBINO5rbWdOArH04KkEQAAATA"]
[Tue Aug 18 12:58:24.814866 2026] [authz_core:error] [pid 66623:tid 66763] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:24.815138 2026] [authz_core:error] [pid 66623:tid 66763] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:24.823161 2026] [security2:error] [pid 66623:tid 66890] [client 85.204.70.114:46966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intersul.ind.br"] [uri "/xmlrpc.php"] [unique_id "aoSBINO5rbWdOArH04KkEgAAAYY"]
[Tue Aug 18 12:58:24.833196 2026] [security2:error] [pid 66623:tid 66768] [client 74.248.18.37:40969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBINO5rbWdOArH04KkEwAAAQw"]
[Tue Aug 18 12:58:24.834161 2026] [security2:error] [pid 66623:tid 66849] [client 20.118.133.132:14126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBINO5rbWdOArH04KkFAAAAV0"]
[Tue Aug 18 12:58:24.857396 2026] [security2:error] [pid 66623:tid 66833] [client 172.182.217.32:12237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/V5.php"] [unique_id "aoSBINO5rbWdOArH04KkFgAAAU0"]
[Tue Aug 18 12:58:24.892851 2026] [security2:error] [pid 66623:tid 66799] [client 201.32.74.208:56519] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "image/bmp"] [severity "WARNING"] [hostname "pensamentosimperfeitos.com.br"] [uri "/wp-json/wp/v2/media"] [unique_id "aoSBINO5rbWdOArH04KkGAAAASs"]
[Tue Aug 18 12:58:24.894338 2026] [security2:error] [pid 66623:tid 66814] [client 68.155.155.199:5695] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-admin/js/"] [unique_id "aoSBINO5rbWdOArH04KkGQAAATo"]
[Tue Aug 18 12:58:24.900041 2026] [security2:error] [pid 66623:tid 66840] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/aa.php"] [unique_id "aoSBINO5rbWdOArH04KkGgAAAVQ"]
[Tue Aug 18 12:58:24.908199 2026] [security2:error] [pid 66623:tid 66640] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSBINO5rbWdOArH04KkGwABQAM"]
[Tue Aug 18 12:58:24.920322 2026] [security2:error] [pid 66623:tid 66830] [client 138.36.100.162:41700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBINO5rbWdOArH04KkIAAAAUo"]
[Tue Aug 18 12:58:24.938946 2026] [security2:error] [pid 66623:tid 66795] [client 213.35.127.232:50015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBINO5rbWdOArH04KkIQAAASc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:24.941166 2026] [security2:error] [pid 66623:tid 66838] [client 20.100.169.31:38653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/default.php"] [unique_id "aoSBINO5rbWdOArH04KkIgAAAVI"]
[Tue Aug 18 12:58:24.975780 2026] [security2:error] [pid 66623:tid 66798] [client 4.232.151.198:62664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/.tmb/dropdown.php"] [unique_id "aoSBINO5rbWdOArH04KkJgAAASo"]
[Tue Aug 18 12:58:24.980519 2026] [security2:error] [pid 66623:tid 66893] [client 172.182.200.96:7563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSBINO5rbWdOArH04KkJwAAAYk"]
[Tue Aug 18 12:58:24.986088 2026] [security2:error] [pid 66623:tid 66648] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/you.php"] [unique_id "aoSBINO5rbWdOArH04KkKAABPAs"]
[Tue Aug 18 12:58:24.987640 2026] [security2:error] [pid 66623:tid 66767] [client 20.118.172.148:33493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/lite.php"] [unique_id "aoSBINO5rbWdOArH04KkKQAAAQs"]
[Tue Aug 18 12:58:24.987665 2026] [security2:error] [pid 66623:tid 66805] [client 20.104.85.180:42284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/01.php"] [unique_id "aoSBINO5rbWdOArH04KkKgAAATE"]
[Tue Aug 18 12:58:25.079439 2026] [security2:error] [pid 66623:tid 66778] [client 20.119.58.187:11854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/acme-challenge/xmrlpc.php"] [unique_id "aoSBIdO5rbWdOArH04KkQwAAARY"]
[Tue Aug 18 12:58:25.104576 2026] [security2:error] [pid 66623:tid 66824] [client 158.23.17.4:31877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/zi.php"] [unique_id "aoSBIdO5rbWdOArH04KkRQAAAUQ"]
[Tue Aug 18 12:58:25.114669 2026] [security2:error] [pid 66623:tid 66839] [client 20.104.85.180:18770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBIdO5rbWdOArH04KkRwAAAVM"]
[Tue Aug 18 12:58:25.116261 2026] [authz_core:error] [pid 66623:tid 66689] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:25.116526 2026] [authz_core:error] [pid 66623:tid 66689] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:25.128150 2026] [security2:error] [pid 66623:tid 66812] [client 20.250.13.23:51635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBIdO5rbWdOArH04KkSAAAATg"]
[Tue Aug 18 12:58:25.142938 2026] [security2:error] [pid 66623:tid 66880] [client 132.196.30.78:32072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pinceisroma.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSBIdO5rbWdOArH04KkTAAAAXw"], referer: www.google.com
[Tue Aug 18 12:58:25.143106 2026] [security2:error] [pid 66623:tid 66810] [client 132.196.30.78:32069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pinceisroma.com.br"] [uri "/wp-plain.php"] [unique_id "aoSBIdO5rbWdOArH04KkTQAAATY"], referer: www.google.com
[Tue Aug 18 12:58:25.178240 2026] [security2:error] [pid 66623:tid 66821] [client 20.127.136.245:4229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/info.php"] [unique_id "aoSBIdO5rbWdOArH04KkUAAAAUE"]
[Tue Aug 18 12:58:25.225458 2026] [security2:error] [pid 66623:tid 66651] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ez.php"] [unique_id "aoSBIdO5rbWdOArH04KkUgABKQ4"]
[Tue Aug 18 12:58:25.245872 2026] [autoindex:error] [pid 66623:tid 66800] [client 85.204.70.114:46970] AH01276: Cannot serve directory /home2/combrazilcoa/intersul.ind.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:25.250432 2026] [security2:error] [pid 66623:tid 66730] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.hermes/.env"] [unique_id "aoSBIdO5rbWdOArH04KkVQABOl0"]
[Tue Aug 18 12:58:25.255916 2026] [authz_core:error] [pid 66623:tid 66638] [remote 57.141.22.89:64074] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:25.256319 2026] [authz_core:error] [pid 66623:tid 66638] [remote 57.141.22.89:64074] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:25.264166 2026] [security2:error] [pid 66623:tid 66820] [client 172.202.39.151:4720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBIdO5rbWdOArH04KkVgAAAUA"]
[Tue Aug 18 12:58:25.291403 2026] [security2:error] [pid 66623:tid 66830] [client 138.36.100.162:41700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBINO5rbWdOArH04KkIAAAAUo"]
[Tue Aug 18 12:58:25.305912 2026] [security2:error] [pid 66623:tid 66803] [client 158.23.17.4:15752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBIdO5rbWdOArH04KkWgAAAS8"]
[Tue Aug 18 12:58:25.319985 2026] [security2:error] [pid 66623:tid 66801] [client 20.118.172.148:19658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/lock360.php"] [unique_id "aoSBIdO5rbWdOArH04KkXAAAAS0"]
[Tue Aug 18 12:58:25.348050 2026] [security2:error] [pid 66623:tid 66794] [client 172.182.217.32:15445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/wp-user.php"] [unique_id "aoSBIdO5rbWdOArH04KkZgAAASY"]
[Tue Aug 18 12:58:25.357878 2026] [security2:error] [pid 66623:tid 66786] [client 74.248.18.37:7691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/release.php"] [unique_id "aoSBIdO5rbWdOArH04KkagAAAR4"]
[Tue Aug 18 12:58:25.359036 2026] [security2:error] [pid 66623:tid 66804] [client 20.100.185.105:6796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/disagrsod.php"] [unique_id "aoSBIdO5rbWdOArH04KkawAAATA"]
[Tue Aug 18 12:58:25.367667 2026] [security2:error] [pid 66623:tid 66849] [client 20.79.204.6:11534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBIdO5rbWdOArH04KkbAAAAV0"]
[Tue Aug 18 12:58:25.409160 2026] [security2:error] [pid 66623:tid 66760] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/asus.php"] [unique_id "aoSBIdO5rbWdOArH04KkcwABTns"]
[Tue Aug 18 12:58:25.427762 2026] [security2:error] [pid 66623:tid 66876] [client 132.196.30.78:32090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pinceisroma.com.br"] [uri "/ambjerfi.php"] [unique_id "aoSBIdO5rbWdOArH04KkdQAAAXg"], referer: www.google.com
[Tue Aug 18 12:58:25.436240 2026] [security2:error] [pid 66623:tid 66877] [client 20.119.58.187:11863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "aoSBIdO5rbWdOArH04KkdwAAAXk"]
[Tue Aug 18 12:58:25.437754 2026] [security2:error] [pid 66623:tid 66835] [client 85.154.68.202:57224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBIdO5rbWdOArH04KkeAAAAU8"]
[Tue Aug 18 12:58:25.437842 2026] [security2:error] [pid 66623:tid 66835] [client 85.154.68.202:57224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBIdO5rbWdOArH04KkeAAAAU8"]
[Tue Aug 18 12:58:25.495520 2026] [security2:error] [pid 66623:tid 66826] [client 20.48.236.86:2802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/mosty.php"] [unique_id "aoSBIdO5rbWdOArH04KkeQAAAUY"]
[Tue Aug 18 12:58:25.547056 2026] [security2:error] [pid 66623:tid 66855] [client 68.155.155.199:5682] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-admin/js/widgets/"] [unique_id "aoSBIdO5rbWdOArH04KkegAAAWM"]
[Tue Aug 18 12:58:25.573882 2026] [security2:error] [pid 66623:tid 66809] [client 132.196.30.78:32075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pinceisroma.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSBIdO5rbWdOArH04KkewAAATU"], referer: www.google.com
[Tue Aug 18 12:58:25.582075 2026] [security2:error] [pid 66623:tid 66798] [client 74.248.18.37:7733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSBIdO5rbWdOArH04KkfAAAASo"]
[Tue Aug 18 12:58:25.585655 2026] [security2:error] [pid 66623:tid 66666] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/22.php"] [unique_id "aoSBIdO5rbWdOArH04KkfQABQx0"]
[Tue Aug 18 12:58:25.605422 2026] [security2:error] [pid 66623:tid 66773] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/av.php"] [unique_id "aoSBIdO5rbWdOArH04KkfgAAARE"]
[Tue Aug 18 12:58:25.618194 2026] [security2:error] [pid 66623:tid 66880] [client 85.204.70.114:46970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aoSBIdO5rbWdOArH04KkfwAAAXw"]
[Tue Aug 18 12:58:25.620122 2026] [security2:error] [pid 66623:tid 66810] [client 20.104.85.180:14547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/gelay.php"] [unique_id "aoSBIdO5rbWdOArH04KkgAAAATY"]
[Tue Aug 18 12:58:25.656952 2026] [security2:error] [pid 66623:tid 66768] [client 20.203.138.185:50735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/thui.php"] [unique_id "aoSBIdO5rbWdOArH04KkgwAAAQw"]
[Tue Aug 18 12:58:25.682995 2026] [security2:error] [pid 66623:tid 66821] [client 20.118.172.148:64309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSBIdO5rbWdOArH04KkhQAAAUE"]
[Tue Aug 18 12:58:25.703404 2026] [security2:error] [pid 66623:tid 66657] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/plugins.php"] [unique_id "aoSBIdO5rbWdOArH04KkhgABURQ"]
[Tue Aug 18 12:58:25.722660 2026] [authz_core:error] [pid 66623:tid 66652] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:25.723112 2026] [authz_core:error] [pid 66623:tid 66652] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:25.738911 2026] [security2:error] [pid 66623:tid 66772] [client 40.74.65.169:56422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/sf.php"] [unique_id "aoSBIdO5rbWdOArH04KkiAAAARA"]
[Tue Aug 18 12:58:25.793578 2026] [security2:error] [pid 66623:tid 66793] [client 20.119.58.187:11876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSBIdO5rbWdOArH04KkjgAAASU"]
[Tue Aug 18 12:58:25.794842 2026] [security2:error] [pid 66623:tid 66726] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/zs.php"] [unique_id "aoSBIdO5rbWdOArH04KkjwABOlk"]
[Tue Aug 18 12:58:25.833155 2026] [security2:error] [pid 66623:tid 66854] [client 172.182.217.32:12276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/wp-blog.php"] [unique_id "aoSBIdO5rbWdOArH04KkkQAAAWI"]
[Tue Aug 18 12:58:25.847154 2026] [security2:error] [pid 66623:tid 66881] [client 4.232.151.198:30016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-includes/SimplePie/Parse/about.php"] [unique_id "aoSBIdO5rbWdOArH04KkkgAAAX0"]
[Tue Aug 18 12:58:25.853139 2026] [security2:error] [pid 66623:tid 66803] [client 52.173.121.69:24989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSBIdO5rbWdOArH04KkkwAAAS8"]
[Tue Aug 18 12:58:25.857761 2026] [security2:error] [pid 66623:tid 66833] [client 132.196.30.78:32078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pinceisroma.com.br"] [uri "/wp-plain.php"] [unique_id "aoSBIdO5rbWdOArH04KklAAAAU0"], referer: www.google.com
[Tue Aug 18 12:58:25.860870 2026] [security2:error] [pid 66623:tid 66771] [client 20.104.85.180:50333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/lv.php"] [unique_id "aoSBIdO5rbWdOArH04KklQAAAQ8"]
[Tue Aug 18 12:58:25.887279 2026] [security2:error] [pid 66623:tid 66736] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/radio.php"] [unique_id "aoSBIdO5rbWdOArH04KklgABLWM"]
[Tue Aug 18 12:58:25.914124 2026] [security2:error] [pid 66623:tid 66865] [client 213.202.253.4:64949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/filefuns.php"] [unique_id "aoSBIdO5rbWdOArH04KkmQAAAW0"], referer: www.google.com
[Tue Aug 18 12:58:25.928842 2026] [security2:error] [pid 66623:tid 66816] [client 68.155.155.199:6957] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-admin/maint/"] [unique_id "aoSBIdO5rbWdOArH04KknAAAATw"]
[Tue Aug 18 12:58:25.937508 2026] [security2:error] [pid 66623:tid 66825] [client 20.104.85.180:18713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBIdO5rbWdOArH04KknQAAAUU"]
[Tue Aug 18 12:58:25.953966 2026] [security2:error] [pid 66623:tid 66879] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/media.php"] [unique_id "aoSBIdO5rbWdOArH04KkngAAAXs"]
[Tue Aug 18 12:58:25.955136 2026] [security2:error] [pid 66623:tid 66868] [client 213.35.127.232:50234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBIdO5rbWdOArH04KknwAAAXA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:25.978114 2026] [security2:error] [pid 66623:tid 66800] [client 20.100.185.105:6843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/eNtnKM.php"] [unique_id "aoSBIdO5rbWdOArH04KkogAAASw"]
[Tue Aug 18 12:58:25.988787 2026] [autoindex:error] [pid 66623:tid 66832] [client 20.79.204.6:11660] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:26.000049 2026] [security2:error] [pid 66623:tid 66710] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/iz.php"] [unique_id "aoSBIdO5rbWdOArH04KkowABMUk"]
[Tue Aug 18 12:58:26.019855 2026] [security2:error] [pid 66623:tid 66848] [client 85.204.70.114:46984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aoSBItO5rbWdOArH04KkpQAAAVw"]
[Tue Aug 18 12:58:26.019922 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:26.020233 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:26.026972 2026] [security2:error] [pid 66623:tid 66794] [client 20.118.172.148:46731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSBItO5rbWdOArH04KkpgAAASY"]
[Tue Aug 18 12:58:26.065978 2026] [security2:error] [pid 66623:tid 66644] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/rem.php"] [unique_id "aoSBItO5rbWdOArH04KkqQABZwc"]
[Tue Aug 18 12:58:26.110090 2026] [security2:error] [pid 66623:tid 66813] [client 74.248.18.37:40979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/reop3.php"] [unique_id "aoSBItO5rbWdOArH04KkrgAAATk"]
[Tue Aug 18 12:58:26.146226 2026] [security2:error] [pid 66623:tid 66857] [client 20.119.58.187:12079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "aoSBItO5rbWdOArH04KkrwAAAWU"]
[Tue Aug 18 12:58:26.192384 2026] [security2:error] [pid 66623:tid 66746] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/se.php"] [unique_id "aoSBItO5rbWdOArH04KkswABc20"]
[Tue Aug 18 12:58:26.201652 2026] [autoindex:error] [pid 66623:tid 66888] [client 20.79.204.6:11660] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-content/uploads/2025/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:26.227836 2026] [security2:error] [pid 66623:tid 66663] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSBItO5rbWdOArH04KktQABExo"]
[Tue Aug 18 12:58:26.248680 2026] [security2:error] [pid 66623:tid 66671] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/server.php"] [unique_id "aoSBItO5rbWdOArH04KkuAABYyI"]
[Tue Aug 18 12:58:26.283438 2026] [security2:error] [pid 66623:tid 66869] [client 132.196.30.78:32082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pinceisroma.com.br"] [uri "/kigpfegm.php"] [unique_id "aoSBItO5rbWdOArH04KkuQAAAXE"], referer: www.google.com
[Tue Aug 18 12:58:26.284512 2026] [security2:error] [pid 66623:tid 66811] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/images.php"] [unique_id "aoSBItO5rbWdOArH04KkvgAAATc"]
[Tue Aug 18 12:58:26.314180 2026] [security2:error] [pid 66623:tid 66778] [client 201.32.74.208:56527] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "image/bmp"] [severity "WARNING"] [hostname "pensamentosimperfeitos.com.br"] [uri "/wp-json/wp/v2/media"] [unique_id "aoSBItO5rbWdOArH04KkwAAAARY"]
[Tue Aug 18 12:58:26.326746 2026] [authz_core:error] [pid 66623:tid 66705] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:26.327207 2026] [authz_core:error] [pid 66623:tid 66705] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:26.339341 2026] [security2:error] [pid 66623:tid 66659] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSBItO5rbWdOArH04KkwwABKhY"]
[Tue Aug 18 12:58:26.353047 2026] [security2:error] [pid 66623:tid 66823] [client 20.104.85.180:15125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/new.php"] [unique_id "aoSBItO5rbWdOArH04KkxAAAAUM"]
[Tue Aug 18 12:58:26.356892 2026] [security2:error] [pid 66623:tid 66835] [client 172.182.217.32:12235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/wp.php"] [unique_id "aoSBItO5rbWdOArH04KkxQAAAU8"]
[Tue Aug 18 12:58:26.380321 2026] [security2:error] [pid 66623:tid 66716] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/vp.php"] [unique_id "aoSBItO5rbWdOArH04KkxgABOE8"]
[Tue Aug 18 12:58:26.401544 2026] [security2:error] [pid 66623:tid 66810] [client 20.79.204.6:11660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSBItO5rbWdOArH04KkyQAAATY"]
[Tue Aug 18 12:58:26.410086 2026] [security2:error] [pid 66623:tid 66790] [client 20.104.85.180:52585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBItO5rbWdOArH04KkygAAASI"]
[Tue Aug 18 12:58:26.415015 2026] [security2:error] [pid 66623:tid 66831] [client 85.204.70.114:46992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aoSBItO5rbWdOArH04KkzAAAAUs"]
[Tue Aug 18 12:58:26.426333 2026] [security2:error] [pid 66623:tid 66701] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/settings.php"] [unique_id "aoSBItO5rbWdOArH04KkzgABd0A"]
[Tue Aug 18 12:58:26.466929 2026] [security2:error] [pid 66623:tid 66828] [client 20.48.236.86:25921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/blurbs.php"] [unique_id "aoSBItO5rbWdOArH04Kk0AAAAUg"]
[Tue Aug 18 12:58:26.495696 2026] [security2:error] [pid 66623:tid 66829] [client 4.232.151.198:30056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/network/file.php"] [unique_id "aoSBItO5rbWdOArH04Kk0gAAAUk"]
[Tue Aug 18 12:58:26.504096 2026] [security2:error] [pid 66623:tid 66773] [client 20.119.58.187:11973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/css/xmrlpc.php"] [unique_id "aoSBItO5rbWdOArH04Kk0wAAARE"]
[Tue Aug 18 12:58:26.517228 2026] [security2:error] [pid 66623:tid 66772] [client 68.155.155.199:12375] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-admin/"] [unique_id "aoSBItO5rbWdOArH04Kk1QAAARA"]
[Tue Aug 18 12:58:26.524776 2026] [security2:error] [pid 66623:tid 66814] [client 20.118.172.148:46730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/.alf.php"] [unique_id "aoSBItO5rbWdOArH04Kk1gAAATo"]
[Tue Aug 18 12:58:26.537903 2026] [security2:error] [pid 66623:tid 66820] [client 20.203.138.185:47668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/tmpls.php"] [unique_id "aoSBItO5rbWdOArH04Kk1wAAAUA"]
[Tue Aug 18 12:58:26.546769 2026] [security2:error] [pid 66623:tid 66882] [client 20.215.241.237:54531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBItO5rbWdOArH04Kk2AAAAX4"]
[Tue Aug 18 12:58:26.593045 2026] [security2:error] [pid 66623:tid 66747] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ph.php"] [unique_id "aoSBItO5rbWdOArH04Kk3AABa24"]
[Tue Aug 18 12:58:26.593115 2026] [security2:error] [pid 66623:tid 66795] [client 40.74.65.169:56405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/k.php"] [unique_id "aoSBItO5rbWdOArH04Kk2wAAASc"]
[Tue Aug 18 12:58:26.596790 2026] [security2:error] [pid 66623:tid 66880] [client 20.100.185.105:43130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/buy.php"] [unique_id "aoSBItO5rbWdOArH04Kk3QAAAXw"]
[Tue Aug 18 12:58:26.609412 2026] [security2:error] [pid 66623:tid 66706] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/sf.php"] [unique_id "aoSBItO5rbWdOArH04Kk3gABSkU"]
[Tue Aug 18 12:58:26.622769 2026] [security2:error] [pid 66623:tid 66833] [client 158.23.17.4:33456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/92.php"] [unique_id "aoSBItO5rbWdOArH04Kk4AAAAU0"]
[Tue Aug 18 12:58:26.639971 2026] [security2:error] [pid 66623:tid 66841] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/admin.php"] [unique_id "aoSBItO5rbWdOArH04Kk4gAAAVU"]
[Tue Aug 18 12:58:26.648698 2026] [security2:error] [pid 66623:tid 66838] [client 192.141.172.134:50851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBItO5rbWdOArH04Kk4wAAAVI"]
[Tue Aug 18 12:58:26.648818 2026] [security2:error] [pid 66623:tid 66838] [client 192.141.172.134:50851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBItO5rbWdOArH04Kk4wAAAVI"]
[Tue Aug 18 12:58:26.674794 2026] [security2:error] [pid 66623:tid 66840] [client 74.248.18.37:7732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/includes/about.php"] [unique_id "aoSBItO5rbWdOArH04Kk5QAAAVQ"]
[Tue Aug 18 12:58:26.779187 2026] [security2:error] [pid 66623:tid 66712] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/s.php"] [unique_id "aoSBItO5rbWdOArH04Kk6QABJks"]
[Tue Aug 18 12:58:26.780822 2026] [security2:error] [pid 66623:tid 66665] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/laravel/.env"] [unique_id "aoSBItO5rbWdOArH04Kk6wABQhw"]
[Tue Aug 18 12:58:26.817897 2026] [security2:error] [pid 66623:tid 66832] [client 5.161.215.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "graices.com.br"] [uri "/"] [unique_id "aoSBItO5rbWdOArH04Kk7wABTAo"], referer: https://graices.com.br/
[Tue Aug 18 12:58:26.824138 2026] [security2:error] [pid 66623:tid 66786] [client 85.204.70.114:47006] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "aoSBItO5rbWdOArH04Kk8QAAAR4"]
[Tue Aug 18 12:58:26.836052 2026] [security2:error] [pid 66623:tid 66713] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/size.php"] [unique_id "aoSBItO5rbWdOArH04Kk8wABXUw"]
[Tue Aug 18 12:58:26.843579 2026] [security2:error] [pid 66623:tid 66761] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/config/.env.php"] [unique_id "aoSBItO5rbWdOArH04Kk9QABaHw"]
[Tue Aug 18 12:58:26.844765 2026] [security2:error] [pid 66623:tid 66725] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/core/.env"] [unique_id "aoSBItO5rbWdOArH04Kk9AABaFg"]
[Tue Aug 18 12:58:26.850274 2026] [security2:error] [pid 66623:tid 66776] [client 172.182.217.32:12261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/worksec.php"] [unique_id "aoSBItO5rbWdOArH04Kk9gAAARQ"]
[Tue Aug 18 12:58:26.858711 2026] [security2:error] [pid 66623:tid 66780] [client 20.119.58.187:12257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSBItO5rbWdOArH04Kk-AAAARg"]
[Tue Aug 18 12:58:26.869154 2026] [security2:error] [pid 66623:tid 66723] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.env.php.bak"] [unique_id "aoSBItO5rbWdOArH04Kk-gABZVY"]
[Tue Aug 18 12:58:26.888928 2026] [security2:error] [pid 66623:tid 66815] [client 161.118.247.229:51558] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "mail.hsinfinity.com.br"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "aoSBItO5rbWdOArH04Kk_AAAATs"]
[Tue Aug 18 12:58:26.892062 2026] [security2:error] [pid 66623:tid 66877] [client 52.173.121.69:24816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSBItO5rbWdOArH04Kk_QAAAXk"]
[Tue Aug 18 12:58:26.928779 2026] [security2:error] [pid 66623:tid 66801] [client 74.248.18.37:41015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/robots.php"] [unique_id "aoSBItO5rbWdOArH04KlAAAAAS0"]
[Tue Aug 18 12:58:26.937952 2026] [authz_core:error] [pid 66623:tid 66655] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:26.938208 2026] [authz_core:error] [pid 66623:tid 66655] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:26.956774 2026] [security2:error] [pid 66623:tid 66853] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/222.php"] [unique_id "aoSBItO5rbWdOArH04KlAgAAAWE"]
[Tue Aug 18 12:58:26.964315 2026] [security2:error] [pid 66623:tid 66656] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/uo.php"] [unique_id "aoSBItO5rbWdOArH04KlAwABcRM"]
[Tue Aug 18 12:58:26.970410 2026] [security2:error] [pid 66623:tid 66811] [client 172.202.39.151:4724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBItO5rbWdOArH04KlBAAAATc"]
[Tue Aug 18 12:58:26.991997 2026] [security2:error] [pid 66623:tid 66844] [client 213.35.127.232:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBItO5rbWdOArH04KlBQAAAVg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:27.005503 2026] [security2:error] [pid 66623:tid 66781] [client 20.79.204.6:11531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSBI9O5rbWdOArH04KlBgAAARk"]
[Tue Aug 18 12:58:27.005545 2026] [security2:error] [pid 66623:tid 66778] [client 20.118.172.148:2708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/.trash7206/index.php"] [unique_id "aoSBI9O5rbWdOArH04KlBwAAARY"]
[Tue Aug 18 12:58:27.012826 2026] [security2:error] [pid 66623:tid 66721] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/staging/wp-content/test.php"] [unique_id "aoSBI9O5rbWdOArH04KlCAABQ1Q"]
[Tue Aug 18 12:58:27.024751 2026] [security2:error] [pid 66623:tid 66812] [client 68.155.155.199:1550] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/themes/"] [unique_id "aoSBI9O5rbWdOArH04KlCgAAATg"]
[Tue Aug 18 12:58:27.054137 2026] [security2:error] [pid 66623:tid 66890] [client 20.118.133.132:1730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBI9O5rbWdOArH04KlCwAAAYY"]
[Tue Aug 18 12:58:27.104892 2026] [security2:error] [pid 66623:tid 66797] [client 20.104.85.180:14570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSBI9O5rbWdOArH04KlFAAAASk"]
[Tue Aug 18 12:58:27.124340 2026] [security2:error] [pid 66623:tid 66783] [client 20.104.85.180:45980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/222.php"] [unique_id "aoSBI9O5rbWdOArH04KlFgAAARs"]
[Tue Aug 18 12:58:27.124635 2026] [security2:error] [pid 66623:tid 66871] [client 4.232.151.198:30052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/upgrade/alfa.php"] [unique_id "aoSBI9O5rbWdOArH04KlFwAAAXM"]
[Tue Aug 18 12:58:27.188849 2026] [security2:error] [pid 66623:tid 66643] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/storage/index.php"] [unique_id "aoSBI9O5rbWdOArH04KlGgABJwY"]
[Tue Aug 18 12:58:27.206950 2026] [security2:error] [pid 66623:tid 66698] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kx.php"] [unique_id "aoSBI9O5rbWdOArH04KlHgABfT0"]
[Tue Aug 18 12:58:27.213281 2026] [security2:error] [pid 66623:tid 66828] [client 20.119.58.187:12007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/img/xmrlpc.php"] [unique_id "aoSBI9O5rbWdOArH04KlIAAAAUg"]
[Tue Aug 18 12:58:27.218186 2026] [security2:error] [pid 66623:tid 66798] [client 20.100.185.105:20622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/ae.php"] [unique_id "aoSBI9O5rbWdOArH04KlIgAAASo"]
[Tue Aug 18 12:58:27.222927 2026] [authz_core:error] [pid 66623:tid 66637] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:27.223465 2026] [authz_core:error] [pid 66623:tid 66637] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:27.239807 2026] [security2:error] [pid 66623:tid 66833] [client 85.204.70.114:51398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aoSBI9O5rbWdOArH04KlIwAAAU0"]
[Tue Aug 18 12:58:27.264306 2026] [security2:error] [pid 66623:tid 66821] [client 5.161.215.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "graices.com.br"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aoSBI9O5rbWdOArH04KlHwABQS0"], referer: https://graices.com.br/
[Tue Aug 18 12:58:27.268865 2026] [security2:error] [pid 66623:tid 66840] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/mac.php"] [unique_id "aoSBI9O5rbWdOArH04KlJQAAAVQ"]
[Tue Aug 18 12:58:27.276826 2026] [security2:error] [pid 66623:tid 66816] [client 158.23.17.4:56743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBI9O5rbWdOArH04KlJgAAATw"]
[Tue Aug 18 12:58:27.290105 2026] [security2:error] [pid 66623:tid 66791] [client 158.23.17.4:44807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/jm.php"] [unique_id "aoSBI9O5rbWdOArH04KlJwAAASM"]
[Tue Aug 18 12:58:27.352198 2026] [security2:error] [pid 66623:tid 66802] [client 172.182.217.32:15762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/wp-themes.php"] [unique_id "aoSBI9O5rbWdOArH04KlKwAAAS4"]
[Tue Aug 18 12:58:27.356432 2026] [security2:error] [pid 66623:tid 66676] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSBI9O5rbWdOArH04KlLQABKCc"]
[Tue Aug 18 12:58:27.366337 2026] [security2:error] [pid 66623:tid 66819] [client 20.118.172.148:43514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSBI9O5rbWdOArH04KlLgAAAT8"]
[Tue Aug 18 12:58:27.378177 2026] [security2:error] [pid 66623:tid 66678] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/storage/min.php"] [unique_id "aoSBI9O5rbWdOArH04KlLwABISk"]
[Tue Aug 18 12:58:27.384247 2026] [security2:error] [pid 66623:tid 66651] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/public/.env"] [unique_id "aoSBI9O5rbWdOArH04KlMgABJg4"]
[Tue Aug 18 12:58:27.384538 2026] [security2:error] [pid 66623:tid 66749] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.env.swp"] [unique_id "aoSBI9O5rbWdOArH04KlMQABJnA"]
[Tue Aug 18 12:58:27.387956 2026] [security2:error] [pid 66623:tid 66707] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/va.php"] [unique_id "aoSBI9O5rbWdOArH04KlNAABQkY"]
[Tue Aug 18 12:58:27.436114 2026] [security2:error] [pid 66623:tid 66763] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/web/.env"] [unique_id "aoSBI9O5rbWdOArH04KlNQABHn4"]
[Tue Aug 18 12:58:27.449459 2026] [security2:error] [pid 66623:tid 66727] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/config.php.bak"] [unique_id "aoSBI9O5rbWdOArH04KlNgABaFo"]
[Tue Aug 18 12:58:27.495426 2026] [security2:error] [pid 66623:tid 66867] [client 20.48.236.86:25983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/bajah.php"] [unique_id "aoSBI9O5rbWdOArH04KlOAAAAW8"]
[Tue Aug 18 12:58:27.500467 2026] [security2:error] [pid 66623:tid 66852] [client 20.203.138.185:10789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/nzv.php"] [unique_id "aoSBI9O5rbWdOArH04KlOgAAAWA"]
[Tue Aug 18 12:58:27.514693 2026] [security2:error] [pid 66623:tid 66892] [client 74.248.18.37:7197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/index.php"] [unique_id "aoSBI9O5rbWdOArH04KlOwAAAYg"]
[Tue Aug 18 12:58:27.524913 2026] [authz_core:error] [pid 66623:tid 66711] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:27.525163 2026] [authz_core:error] [pid 66623:tid 66711] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:27.550189 2026] [security2:error] [pid 66623:tid 66877] [client 68.155.155.199:6728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBI9O5rbWdOArH04KlPgAAAXk"]
[Tue Aug 18 12:58:27.551547 2026] [security2:error] [pid 66623:tid 66793] [client 40.74.65.169:55847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/82.php"] [unique_id "aoSBI9O5rbWdOArH04KlPwAAASU"]
[Tue Aug 18 12:58:27.554693 2026] [security2:error] [pid 66623:tid 66888] [client 20.104.85.180:27932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/chosen.php"] [unique_id "aoSBI9O5rbWdOArH04KlQAAAAYQ"]
[Tue Aug 18 12:58:27.568861 2026] [security2:error] [pid 66623:tid 66849] [client 20.119.58.187:11981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/coffee/xmrlpc.php"] [unique_id "aoSBI9O5rbWdOArH04KlQwAAAV0"]
[Tue Aug 18 12:58:27.570585 2026] [security2:error] [pid 66623:tid 66771] [client 20.100.169.31:29028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/i.php"] [unique_id "aoSBI9O5rbWdOArH04KlRAAAAQ8"]
[Tue Aug 18 12:58:27.624995 2026] [autoindex:error] [pid 66623:tid 66825] [client 20.79.204.6:11693] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:27.634161 2026] [security2:error] [pid 66623:tid 66869] [client 85.204.70.114:51402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aoSBI9O5rbWdOArH04KlSgAAAXE"]
[Tue Aug 18 12:58:27.648091 2026] [security2:error] [pid 66623:tid 66672] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/fo.php"] [unique_id "aoSBI9O5rbWdOArH04KlSwABNSM"]
[Tue Aug 18 12:58:27.651972 2026] [security2:error] [pid 66623:tid 66844] [client 52.173.121.69:25016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSBI9O5rbWdOArH04KlTQAAAVg"]
[Tue Aug 18 12:58:27.652044 2026] [security2:error] [pid 66623:tid 66804] [client 74.248.18.37:54951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/root.php"] [unique_id "aoSBI9O5rbWdOArH04KlTgAAATA"]
[Tue Aug 18 12:58:27.776308 2026] [security2:error] [pid 66623:tid 66856] [client 4.232.151.198:6101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/xmlrpc.php"] [unique_id "aoSBI9O5rbWdOArH04KlVAAAAWQ"]
[Tue Aug 18 12:58:27.808907 2026] [security2:error] [pid 66623:tid 66783] [client 20.104.85.180:1592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/about.php"] [unique_id "aoSBI9O5rbWdOArH04KlVwAAARs"]
[Tue Aug 18 12:58:27.837066 2026] [autoindex:error] [pid 66623:tid 66814] [client 20.79.204.6:11693] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:27.837081 2026] [security2:error] [pid 66623:tid 66668] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/test.php"] [unique_id "aoSBI9O5rbWdOArH04KlXAABJx8"]
[Tue Aug 18 12:58:27.842286 2026] [security2:error] [pid 66623:tid 66834] [client 172.182.217.32:12239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/wp-signin.php"] [unique_id "aoSBI9O5rbWdOArH04KlXgAAAU4"]
[Tue Aug 18 12:58:27.847007 2026] [security2:error] [pid 66623:tid 66853] [client 20.100.185.105:19748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/raf.php"] [unique_id "aoSBI9O5rbWdOArH04KlXwAAAWE"]
[Tue Aug 18 12:58:27.856554 2026] [security2:error] [pid 66623:tid 66669] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/loading.php"] [unique_id "aoSBI9O5rbWdOArH04KlYAABgiA"]
[Tue Aug 18 12:58:27.926651 2026] [security2:error] [pid 66623:tid 66842] [client 20.119.58.187:11858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/images/xmrlpc.php"] [unique_id "aoSBI9O5rbWdOArH04KlaQAAAVY"]
[Tue Aug 18 12:58:27.935777 2026] [security2:error] [pid 66623:tid 66838] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/ops.php"] [unique_id "aoSBI9O5rbWdOArH04KlawAAAVI"]
[Tue Aug 18 12:58:27.941878 2026] [security2:error] [pid 66623:tid 66883] [client 161.118.247.229:51954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.247.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hsinfinity.com.br"] [uri "/wp-content/plugins/pods/init.php"] [unique_id "aoSBI9O5rbWdOArH04KlbAAAAX8"]
[Tue Aug 18 12:58:27.945864 2026] [security2:error] [pid 66623:tid 66841] [client 158.23.17.4:34157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/wj.php"] [unique_id "aoSBI9O5rbWdOArH04KlbQAAAVU"]
[Tue Aug 18 12:58:27.949271 2026] [security2:error] [pid 66623:tid 66879] [client 20.203.183.135:45463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/adminner.php"] [unique_id "aoSBI9O5rbWdOArH04KlbgAAAXs"]
[Tue Aug 18 12:58:28.002736 2026] [security2:error] [pid 66623:tid 66779] [client 3.20.63.178:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "1ba.com.br"] [uri "/index.php"] [unique_id "aoSBI9O5rbWdOArH04KlaAABFzc"], referer: https://1ba.com.br/
[Tue Aug 18 12:58:28.014028 2026] [security2:error] [pid 66623:tid 66689] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/test1.php"] [unique_id "aoSBJNO5rbWdOArH04KlbwABDjQ"]
[Tue Aug 18 12:58:28.020526 2026] [security2:error] [pid 66623:tid 66823] [client 213.35.127.232:50684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBJNO5rbWdOArH04KlcQAAAUM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:28.038084 2026] [security2:error] [pid 66623:tid 66846] [client 20.79.204.6:11693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBJNO5rbWdOArH04KlcgAAAVo"]
[Tue Aug 18 12:58:28.056367 2026] [security2:error] [pid 66623:tid 66819] [client 85.204.70.114:51416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJNO5rbWdOArH04KlcwAAAT8"]
[Tue Aug 18 12:58:28.057649 2026] [security2:error] [pid 66623:tid 66806] [client 20.118.172.148:53063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSBJNO5rbWdOArH04KldAAAATI"]
[Tue Aug 18 12:58:28.059096 2026] [security2:error] [pid 66623:tid 66794] [client 20.104.85.180:31285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/info.php"] [unique_id "aoSBJNO5rbWdOArH04KldQAAASY"]
[Tue Aug 18 12:58:28.059221 2026] [security2:error] [pid 66623:tid 66788] [client 158.158.74.177:16574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-content.php"] [unique_id "aoSBJNO5rbWdOArH04KldgAAASA"]
[Tue Aug 18 12:58:28.111225 2026] [security2:error] [pid 66623:tid 66858] [client 172.182.200.96:7649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSBJNO5rbWdOArH04KlegAAAWY"]
[Tue Aug 18 12:58:28.114971 2026] [security2:error] [pid 66623:tid 66638] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ke.php"] [unique_id "aoSBJNO5rbWdOArH04KlfAABbwE"]
[Tue Aug 18 12:58:28.194957 2026] [security2:error] [pid 66623:tid 66641] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/thoms.php"] [unique_id "aoSBJNO5rbWdOArH04KlgAABMwQ"]
[Tue Aug 18 12:58:28.212339 2026] [security2:error] [pid 66623:tid 66864] [client 5.161.117.52:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alsconsultoria.com.br"] [uri "/index.php"] [unique_id "aoSBItO5rbWdOArH04Kk8AABbBU"], referer: https://alsconsultoria.com.br/
[Tue Aug 18 12:58:28.279336 2026] [security2:error] [pid 66623:tid 66876] [client 20.119.58.187:11878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSBJNO5rbWdOArH04KlhAAAAXg"]
[Tue Aug 18 12:58:28.286641 2026] [security2:error] [pid 66623:tid 66827] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/8.php"] [unique_id "aoSBJNO5rbWdOArH04KlhQAAAUc"]
[Tue Aug 18 12:58:28.328701 2026] [security2:error] [pid 66623:tid 66852] [client 74.248.18.37:7182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/rrr.php"] [unique_id "aoSBJNO5rbWdOArH04KlhwAAAWA"]
[Tue Aug 18 12:58:28.331090 2026] [security2:error] [pid 66623:tid 66776] [client 172.182.217.32:12260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSBJNO5rbWdOArH04KliAAAARQ"]
[Tue Aug 18 12:58:28.344219 2026] [security2:error] [pid 66623:tid 66810] [client 40.74.65.169:56393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/dex.php"] [unique_id "aoSBJNO5rbWdOArH04KliQAAATY"]
[Tue Aug 18 12:58:28.371550 2026] [security2:error] [pid 66623:tid 66717] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/tiny.php"] [unique_id "aoSBJNO5rbWdOArH04KliwABUFA"]
[Tue Aug 18 12:58:28.377662 2026] [security2:error] [pid 66623:tid 66720] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/nh.php"] [unique_id "aoSBJNO5rbWdOArH04KljAABYlM"]
[Tue Aug 18 12:58:28.384610 2026] [security2:error] [pid 66623:tid 66856] [client 20.203.138.185:47229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/error1.php"] [unique_id "aoSBJNO5rbWdOArH04KljgAAAWQ"]
[Tue Aug 18 12:58:28.395153 2026] [security2:error] [pid 66623:tid 66773] [client 68.155.155.199:12063] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/uploads/"] [unique_id "aoSBJNO5rbWdOArH04KlkAAAARE"]
[Tue Aug 18 12:58:28.407491 2026] [security2:error] [pid 66623:tid 66783] [client 20.206.73.37:11913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/php.php"] [unique_id "aoSBJNO5rbWdOArH04KlkQAAARs"]
[Tue Aug 18 12:58:28.427632 2026] [authz_core:error] [pid 66623:tid 66644] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:28.427918 2026] [authz_core:error] [pid 66623:tid 66644] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:28.434879 2026] [security2:error] [pid 66623:tid 66880] [client 74.248.18.37:41012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/js/about.php"] [unique_id "aoSBJNO5rbWdOArH04KlkwAAAXw"]
[Tue Aug 18 12:58:28.440739 2026] [autoindex:error] [pid 66623:tid 66829] [client 169.58.72.248:63638] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:28.442891 2026] [security2:error] [pid 66623:tid 66814] [client 85.204.70.114:51418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJNO5rbWdOArH04KllAAAATo"]
[Tue Aug 18 12:58:28.449966 2026] [security2:error] [pid 66623:tid 66885] [client 4.232.151.198:30027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/.tmb/cloud.php"] [unique_id "aoSBJNO5rbWdOArH04KllQAAAYE"]
[Tue Aug 18 12:58:28.466356 2026] [security2:error] [pid 66623:tid 66801] [client 20.100.185.105:59232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/cloud.php"] [unique_id "aoSBJNO5rbWdOArH04KlmAAAAS0"]
[Tue Aug 18 12:58:28.567060 2026] [security2:error] [pid 66623:tid 66697] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/tool.php"] [unique_id "aoSBJNO5rbWdOArH04KlnAABTTw"]
[Tue Aug 18 12:58:28.604544 2026] [security2:error] [pid 66623:tid 66821] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/biufile.php"] [unique_id "aoSBJNO5rbWdOArH04KlogAAAUE"]
[Tue Aug 18 12:58:28.612975 2026] [security2:error] [pid 66623:tid 66840] [client 161.118.247.229:52386] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "mail.hsinfinity.com.br"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "aoSBJNO5rbWdOArH04KlowAAAVQ"]
[Tue Aug 18 12:58:28.613282 2026] [security2:error] [pid 66623:tid 66677] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/oo.php"] [unique_id "aoSBJNO5rbWdOArH04KlpAABVSg"]
[Tue Aug 18 12:58:28.631155 2026] [security2:error] [pid 66623:tid 66816] [client 20.118.172.148:50094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSBJNO5rbWdOArH04KlpgAAATw"]
[Tue Aug 18 12:58:28.635830 2026] [security2:error] [pid 66623:tid 66872] [client 20.119.58.187:12030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoSBJNO5rbWdOArH04KlpwAAAXQ"]
[Tue Aug 18 12:58:28.651701 2026] [security2:error] [pid 66623:tid 66795] [client 20.79.204.6:11676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSBJNO5rbWdOArH04KlqAAAASc"]
[Tue Aug 18 12:58:28.733088 2026] [security2:error] [pid 66623:tid 66806] [client 158.23.17.4:8915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/74.php"] [unique_id "aoSBJNO5rbWdOArH04KlrAAAATI"]
[Tue Aug 18 12:58:28.742711 2026] [security2:error] [pid 66623:tid 66667] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/top.php"] [unique_id "aoSBJNO5rbWdOArH04KlrQABJh4"]
[Tue Aug 18 12:58:28.779207 2026] [security2:error] [pid 66623:tid 66766] [client 79.127.164.8:40836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/server.bak"] [unique_id "aoSBJNO5rbWdOArH04KlsQAAAQo"], referer: https://medihub.com.br/server.bak
[Tue Aug 18 12:58:28.800312 2026] [security2:error] [pid 66623:tid 66659] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ja.php"] [unique_id "aoSBJNO5rbWdOArH04KlswABQBY"]
[Tue Aug 18 12:58:28.805787 2026] [security2:error] [pid 66623:tid 66875] [client 20.118.133.132:17330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/sky.php"] [unique_id "aoSBJNO5rbWdOArH04KltQAAAXc"]
[Tue Aug 18 12:58:28.917303 2026] [security2:error] [pid 66623:tid 66750] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/txets.php"] [unique_id "aoSBJNO5rbWdOArH04KlvAABbHE"]
[Tue Aug 18 12:58:28.917953 2026] [security2:error] [pid 66623:tid 66793] [client 20.127.136.245:17893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/chosen.php"] [unique_id "aoSBJNO5rbWdOArH04KlvQAAASU"]
[Tue Aug 18 12:58:28.920866 2026] [security2:error] [pid 66623:tid 66865] [client 68.155.155.199:12691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSBJNO5rbWdOArH04KlvgAAAW0"]
[Tue Aug 18 12:58:28.922611 2026] [security2:error] [pid 66623:tid 66771] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/coffexium.php"] [unique_id "aoSBJNO5rbWdOArH04KlvwAAAQ8"]
[Tue Aug 18 12:58:28.946407 2026] [authz_core:error] [pid 66623:tid 66738] [remote 57.141.22.8:43226] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:28.946663 2026] [authz_core:error] [pid 66623:tid 66738] [remote 57.141.22.8:43226] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:28.966192 2026] [security2:error] [pid 66623:tid 66778] [client 196.12.128.158:58443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBJNO5rbWdOArH04KlxgAAARY"]
[Tue Aug 18 12:58:28.966329 2026] [security2:error] [pid 66623:tid 66778] [client 196.12.128.158:58443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBJNO5rbWdOArH04KlxgAAARY"]
[Tue Aug 18 12:58:28.971428 2026] [security2:error] [pid 66623:tid 66703] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/xx.php"] [unique_id "aoSBJNO5rbWdOArH04KlxwABcUI"]
[Tue Aug 18 12:58:28.971936 2026] [security2:error] [pid 66623:tid 66809] [client 52.173.121.69:6136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSBJNO5rbWdOArH04KlyAAAATU"]
[Tue Aug 18 12:58:28.982129 2026] [security2:error] [pid 66623:tid 66785] [client 20.104.85.180:47104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBJNO5rbWdOArH04KlyQAAAR0"]
[Tue Aug 18 12:58:28.990100 2026] [security2:error] [pid 66623:tid 66782] [client 20.119.58.187:12015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/xmrlpc.php"] [unique_id "aoSBJNO5rbWdOArH04KlygAAARo"]
[Tue Aug 18 12:58:29.004512 2026] [security2:error] [pid 66623:tid 66887] [client 20.118.172.148:50073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSBJdO5rbWdOArH04KlzwAAAYM"]
[Tue Aug 18 12:58:29.014685 2026] [security2:error] [pid 66623:tid 66776] [client 85.204.70.114:51420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJdO5rbWdOArH04Kl0AAAARQ"]
[Tue Aug 18 12:58:29.031458 2026] [authz_core:error] [pid 66623:tid 66762] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:29.031740 2026] [authz_core:error] [pid 66623:tid 66762] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:29.042370 2026] [security2:error] [pid 66623:tid 66882] [client 213.35.127.232:50897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBJdO5rbWdOArH04Kl1QAAAX4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:29.084583 2026] [security2:error] [pid 66623:tid 66857] [client 20.100.185.105:43107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/cookie.php"] [unique_id "aoSBJdO5rbWdOArH04Kl1gAAAWU"]
[Tue Aug 18 12:58:29.085475 2026] [security2:error] [pid 66623:tid 66780] [client 4.232.151.198:30035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-includes/certificates/wp-login.php"] [unique_id "aoSBJdO5rbWdOArH04Kl1wAAARg"]
[Tue Aug 18 12:58:29.100364 2026] [security2:error] [pid 66623:tid 66884] [client 74.248.18.37:31809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/s.php"] [unique_id "aoSBJdO5rbWdOArH04Kl2QAAAYA"]
[Tue Aug 18 12:58:29.104145 2026] [security2:error] [pid 66623:tid 66662] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/virus.php"] [unique_id "aoSBJdO5rbWdOArH04Kl2wABSRk"]
[Tue Aug 18 12:58:29.162043 2026] [security2:error] [pid 66623:tid 66654] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/conn-test.php"] [unique_id "aoSBJdO5rbWdOArH04Kl4AABShE"]
[Tue Aug 18 12:58:29.177937 2026] [security2:error] [pid 66623:tid 66828] [client 20.203.138.185:60948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/155.php"] [unique_id "aoSBJdO5rbWdOArH04Kl4QAAAUg"]
[Tue Aug 18 12:58:29.187710 2026] [security2:error] [pid 66623:tid 66833] [client 172.182.217.32:12272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/ws.php"] [unique_id "aoSBJdO5rbWdOArH04Kl4gAAAU0"]
[Tue Aug 18 12:58:29.214384 2026] [security2:error] [pid 66623:tid 66883] [client 20.250.13.23:1834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBJdO5rbWdOArH04Kl5AAAAX8"]
[Tue Aug 18 12:58:29.231180 2026] [security2:error] [pid 66623:tid 66841] [client 40.74.65.169:56394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/puc.php"] [unique_id "aoSBJdO5rbWdOArH04Kl5gAAAVU"]
[Tue Aug 18 12:58:29.234508 2026] [security2:error] [pid 66623:tid 66799] [client 157.51.166.53:52840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJdO5rbWdOArH04Kl5wAAASs"]
[Tue Aug 18 12:58:29.234588 2026] [security2:error] [pid 66623:tid 66799] [client 157.51.166.53:52840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJdO5rbWdOArH04Kl5wAAASs"]
[Tue Aug 18 12:58:29.275835 2026] [autoindex:error] [pid 66623:tid 66836] [client 20.79.204.6:12245] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-includes/Requests/src/Cookie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:29.281501 2026] [security2:error] [pid 66623:tid 66725] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/we.php"] [unique_id "aoSBJdO5rbWdOArH04Kl6gABJ1g"]
[Tue Aug 18 12:58:29.291910 2026] [security2:error] [pid 66623:tid 66846] [client 161.118.247.229:52645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.247.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hsinfinity.com.br"] [uri "/wp-content/plugins/pods/init.php"] [unique_id "aoSBJdO5rbWdOArH04Kl6wAAAVo"]
[Tue Aug 18 12:58:29.343110 2026] [security2:error] [pid 66623:tid 66773] [client 74.248.18.37:7715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBJdO5rbWdOArH04Kl8wAAARE"]
[Tue Aug 18 12:58:29.344586 2026] [security2:error] [pid 66623:tid 66840] [client 20.119.58.187:12539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/includes/xmrlpc.php"] [unique_id "aoSBJdO5rbWdOArH04Kl9AAAAVQ"]
[Tue Aug 18 12:58:29.370351 2026] [security2:error] [pid 66623:tid 66822] [client 158.158.74.177:22734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSBJdO5rbWdOArH04Kl9gAAAUI"]
[Tue Aug 18 12:58:29.375926 2026] [security2:error] [pid 66623:tid 66786] [client 20.118.172.148:64303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/xmr.php"] [unique_id "aoSBJdO5rbWdOArH04Kl9wAAAR4"]
[Tue Aug 18 12:58:29.377703 2026] [security2:error] [pid 66623:tid 66721] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/fg.php"] [unique_id "aoSBJdO5rbWdOArH04Kl-AABClQ"]
[Tue Aug 18 12:58:29.407856 2026] [security2:error] [pid 66623:tid 66860] [client 85.204.70.114:51430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJdO5rbWdOArH04Kl_AAAAWg"]
[Tue Aug 18 12:58:29.460264 2026] [security2:error] [pid 66623:tid 66868] [client 158.23.17.4:57278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/av.php"] [unique_id "aoSBJdO5rbWdOArH04Kl_wAAAXA"]
[Tue Aug 18 12:58:29.473672 2026] [security2:error] [pid 66623:tid 66881] [client 68.155.155.199:4327] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-includes/"] [unique_id "aoSBJdO5rbWdOArH04KmAAAAAX0"]
[Tue Aug 18 12:58:29.474737 2026] [security2:error] [pid 66623:tid 66807] [client 20.100.169.31:29054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSBJdO5rbWdOArH04KmAQAAATM"]
[Tue Aug 18 12:58:29.477867 2026] [security2:error] [pid 66623:tid 66864] [client 20.79.204.6:12245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSBJdO5rbWdOArH04KmBAAAAWw"]
[Tue Aug 18 12:58:29.521245 2026] [security2:error] [pid 66623:tid 66815] [client 20.250.13.23:52070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/404.php"] [unique_id "aoSBJdO5rbWdOArH04KmBQAAATs"]
[Tue Aug 18 12:58:29.550021 2026] [security2:error] [pid 66623:tid 66876] [client 172.202.39.151:4712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/admin.php"] [unique_id "aoSBJdO5rbWdOArH04KmBwAAAXg"]
[Tue Aug 18 12:58:29.633913 2026] [authz_core:error] [pid 66623:tid 66748] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:29.634258 2026] [authz_core:error] [pid 66623:tid 66748] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:29.645167 2026] [security2:error] [pid 66623:tid 66743] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ve.php"] [unique_id "aoSBJdO5rbWdOArH04KmDAABfmo"]
[Tue Aug 18 12:58:29.678139 2026] [security2:error] [pid 66623:tid 66790] [client 114.5.214.109:50409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJdO5rbWdOArH04KmEAAAASI"]
[Tue Aug 18 12:58:29.688704 2026] [security2:error] [pid 66623:tid 66790] [client 114.5.214.109:50409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJdO5rbWdOArH04KmEAAAASI"]
[Tue Aug 18 12:58:29.699792 2026] [security2:error] [pid 66623:tid 66782] [client 20.119.58.187:11848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/blue/xmrlpc.php"] [unique_id "aoSBJdO5rbWdOArH04KmEwAAARo"]
[Tue Aug 18 12:58:29.701875 2026] [security2:error] [pid 66623:tid 66793] [client 20.100.185.105:21670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/aleXus.php"] [unique_id "aoSBJdO5rbWdOArH04KmFAAAASU"]
[Tue Aug 18 12:58:29.710950 2026] [security2:error] [pid 66623:tid 66825] [client 172.182.217.32:15759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/wsa.php"] [unique_id "aoSBJdO5rbWdOArH04KmFQAAAUU"]
[Tue Aug 18 12:58:29.747098 2026] [security2:error] [pid 66623:tid 66779] [client 4.232.151.198:30021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/gettest.php"] [unique_id "aoSBJdO5rbWdOArH04KmFgAAARc"]
[Tue Aug 18 12:58:29.766328 2026] [security2:error] [pid 66623:tid 66861] [client 158.23.17.4:7218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/st.php"] [unique_id "aoSBJdO5rbWdOArH04KmGgAAAWk"]
[Tue Aug 18 12:58:29.771795 2026] [security2:error] [pid 66623:tid 66883] [client 20.118.172.148:50085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/about.php"] [unique_id "aoSBJdO5rbWdOArH04KmGwAAAX8"]
[Tue Aug 18 12:58:29.792054 2026] [security2:error] [pid 66623:tid 66804] [client 85.204.70.114:51442] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJdO5rbWdOArH04KmHAAAATA"]
[Tue Aug 18 12:58:29.818759 2026] [security2:error] [pid 66623:tid 66890] [client 197.184.64.235:41944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJdO5rbWdOArH04KmHQAAAYY"]
[Tue Aug 18 12:58:29.821044 2026] [security2:error] [pid 66623:tid 66682] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ia.php"] [unique_id "aoSBJdO5rbWdOArH04KmHgABXy0"]
[Tue Aug 18 12:58:29.823467 2026] [security2:error] [pid 66623:tid 66890] [client 197.184.64.235:41944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJdO5rbWdOArH04KmHQAAAYY"]
[Tue Aug 18 12:58:29.849383 2026] [security2:error] [pid 66623:tid 66764] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJdO5rbWdOArH04KmIQABUH8"]
[Tue Aug 18 12:58:29.849524 2026] [security2:error] [pid 66623:tid 66836] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJdO5rbWdOArH04KmIQABUH8"]
[Tue Aug 18 12:58:29.857275 2026] [security2:error] [pid 66623:tid 66795] [client 172.182.200.96:14081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSBJdO5rbWdOArH04KmIgAAASc"]
[Tue Aug 18 12:58:29.872013 2026] [security2:error] [pid 66623:tid 66824] [client 20.250.13.23:53677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/0x.php"] [unique_id "aoSBJdO5rbWdOArH04KmIwAAAUQ"]
[Tue Aug 18 12:58:29.898573 2026] [security2:error] [pid 66623:tid 66797] [client 74.248.18.37:47259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/s93.php"] [unique_id "aoSBJdO5rbWdOArH04KmJQAAASk"]
[Tue Aug 18 12:58:29.933178 2026] [authz_core:error] [pid 66623:tid 66651] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:29.933446 2026] [authz_core:error] [pid 66623:tid 66651] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:29.953783 2026] [security2:error] [pid 66623:tid 66773] [client 20.203.138.185:10795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/fasx.php"] [unique_id "aoSBJdO5rbWdOArH04KmKgAAARE"]
[Tue Aug 18 12:58:29.987426 2026] [security2:error] [pid 66623:tid 66786] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/dex.php"] [unique_id "aoSBJdO5rbWdOArH04KmLQAAAR4"]
[Tue Aug 18 12:58:29.988705 2026] [security2:error] [pid 66623:tid 66766] [client 20.48.236.86:25982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/h.php"] [unique_id "aoSBJdO5rbWdOArH04KmLgAAAQo"]
[Tue Aug 18 12:58:29.991859 2026] [security2:error] [pid 66623:tid 66707] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kn.php"] [unique_id "aoSBJdO5rbWdOArH04KmLwABTkY"]
[Tue Aug 18 12:58:30.006276 2026] [security2:error] [pid 66623:tid 66785] [client 40.74.65.169:56439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/inso.php"] [unique_id "aoSBJtO5rbWdOArH04KmMAAAAR0"]
[Tue Aug 18 12:58:30.012393 2026] [security2:error] [pid 66623:tid 66776] [client 68.155.155.199:5678] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-includes/js/crop/"] [unique_id "aoSBJtO5rbWdOArH04KmMQAAARQ"]
[Tue Aug 18 12:58:30.020855 2026] [security2:error] [pid 66623:tid 66829] [client 158.23.17.4:31924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ag.php"] [unique_id "aoSBJtO5rbWdOArH04KmMgAAAUk"]
[Tue Aug 18 12:58:30.056241 2026] [security2:error] [pid 66623:tid 66796] [client 20.119.58.187:11892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/xmrlpc.php"] [unique_id "aoSBJtO5rbWdOArH04KmNgAAASg"]
[Tue Aug 18 12:58:30.067403 2026] [security2:error] [pid 66623:tid 66792] [client 213.35.127.232:51121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBJtO5rbWdOArH04KmNwAAASQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:30.076994 2026] [security2:error] [pid 66623:tid 66775] [client 20.118.133.132:21636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/file5.php"] [unique_id "aoSBJtO5rbWdOArH04KmOQAAARM"]
[Tue Aug 18 12:58:30.100953 2026] [security2:error] [pid 66623:tid 66869] [client 20.104.85.180:27954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBJtO5rbWdOArH04KmPAAAAXE"]
[Tue Aug 18 12:58:30.104699 2026] [autoindex:error] [pid 66623:tid 66803] [client 20.79.204.6:11579] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:30.137047 2026] [security2:error] [pid 66623:tid 66821] [client 20.118.172.148:2712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/admin.php"] [unique_id "aoSBJtO5rbWdOArH04KmPgAAAUE"]
[Tue Aug 18 12:58:30.169256 2026] [security2:error] [pid 66623:tid 66704] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/wm.php"] [unique_id "aoSBJtO5rbWdOArH04KmQwABY0M"]
[Tue Aug 18 12:58:30.175526 2026] [security2:error] [pid 66623:tid 66770] [client 85.204.70.114:51450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJtO5rbWdOArH04KmRAAAAQ4"]
[Tue Aug 18 12:58:30.201774 2026] [security2:error] [pid 66623:tid 66889] [client 172.182.217.32:15607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/w.php"] [unique_id "aoSBJtO5rbWdOArH04KmRwAAAYU"]
[Tue Aug 18 12:58:30.207659 2026] [security2:error] [pid 66623:tid 66840] [client 20.206.73.37:11926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/sf.php"] [unique_id "aoSBJtO5rbWdOArH04KmSQAAAVQ"]
[Tue Aug 18 12:58:30.239840 2026] [authz_core:error] [pid 66623:tid 66685] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:30.240272 2026] [authz_core:error] [pid 66623:tid 66685] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:30.307654 2026] [security2:error] [pid 66623:tid 66815] [client 20.79.204.6:11579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSBJtO5rbWdOArH04KmUAAAATs"]
[Tue Aug 18 12:58:30.319628 2026] [security2:error] [pid 66623:tid 66847] [client 68.155.153.139:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cnascimentoassessoria.com"] [uri "/1.php"] [unique_id "aoSBJtO5rbWdOArH04KmUwAAAVs"]
[Tue Aug 18 12:58:30.319748 2026] [security2:error] [pid 66623:tid 66847] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/1.php"] [unique_id "aoSBJtO5rbWdOArH04KmUwAAAVs"]
[Tue Aug 18 12:58:30.330196 2026] [security2:error] [pid 66623:tid 66833] [client 20.100.185.105:59222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-signup.php"] [unique_id "aoSBJtO5rbWdOArH04KmVAAAAU0"]
[Tue Aug 18 12:58:30.365076 2026] [security2:error] [pid 66623:tid 66680] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/work.php"] [unique_id "aoSBJtO5rbWdOArH04KmVgABYSs"]
[Tue Aug 18 12:58:30.374354 2026] [security2:error] [pid 66623:tid 66861] [client 158.158.74.177:22763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-content/ad4599c5/admin.php"] [unique_id "aoSBJtO5rbWdOArH04KmVwAAAWk"]
[Tue Aug 18 12:58:30.387445 2026] [security2:error] [pid 66623:tid 66791] [client 4.232.151.198:6126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/void.php"] [unique_id "aoSBJtO5rbWdOArH04KmWgAAASM"]
[Tue Aug 18 12:58:30.410748 2026] [security2:error] [pid 66623:tid 66881] [client 20.119.58.187:12061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/mail.php"] [unique_id "aoSBJtO5rbWdOArH04KmWwAAAX0"]
[Tue Aug 18 12:58:30.424376 2026] [security2:error] [pid 66623:tid 66661] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ac.php"] [unique_id "aoSBJtO5rbWdOArH04KmXAABJRg"]
[Tue Aug 18 12:58:30.487882 2026] [security2:error] [pid 66623:tid 66828] [client 20.127.136.245:4220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/simple.php"] [unique_id "aoSBJtO5rbWdOArH04KmXgAAAUg"]
[Tue Aug 18 12:58:30.489767 2026] [security2:error] [pid 66623:tid 66869] [client 68.155.155.199:9472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSBJtO5rbWdOArH04KmXwAAAXE"]
[Tue Aug 18 12:58:30.498353 2026] [security2:error] [pid 66623:tid 66831] [client 20.118.172.148:50053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBJtO5rbWdOArH04KmYQAAAUs"]
[Tue Aug 18 12:58:30.498969 2026] [security2:error] [pid 66623:tid 66807] [client 20.250.13.23:45714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/222.php"] [unique_id "aoSBJtO5rbWdOArH04KmYgAAATM"]
[Tue Aug 18 12:58:30.534699 2026] [authz_core:error] [pid 66623:tid 66753] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:30.534967 2026] [authz_core:error] [pid 66623:tid 66753] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:30.544759 2026] [security2:error] [pid 66623:tid 66722] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin.php"] [unique_id "aoSBJtO5rbWdOArH04KmZwABZ1U"]
[Tue Aug 18 12:58:30.562357 2026] [security2:error] [pid 66623:tid 66799] [client 85.204.70.114:51452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJtO5rbWdOArH04KmaAAAASs"]
[Tue Aug 18 12:58:30.614148 2026] [security2:error] [pid 66623:tid 66826] [client 74.248.18.37:54923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/server.php"] [unique_id "aoSBJtO5rbWdOArH04KmawAAAUY"]
[Tue Aug 18 12:58:30.637396 2026] [security2:error] [pid 66623:tid 66711] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/yz.php"] [unique_id "aoSBJtO5rbWdOArH04KmbAABREo"]
[Tue Aug 18 12:58:30.644421 2026] [security2:error] [pid 66623:tid 66797] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/coffee.php"] [unique_id "aoSBJtO5rbWdOArH04KmbQAAASk"]
[Tue Aug 18 12:58:30.688284 2026] [security2:error] [pid 66623:tid 66892] [client 172.182.217.32:12231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/x.php"] [unique_id "aoSBJtO5rbWdOArH04KmcAAAAYg"]
[Tue Aug 18 12:58:30.747075 2026] [security2:error] [pid 66623:tid 66778] [client 20.48.236.86:32839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/ano.php"] [unique_id "aoSBJtO5rbWdOArH04KmdgAAARY"]
[Tue Aug 18 12:58:30.768303 2026] [security2:error] [pid 66623:tid 66850] [client 20.119.58.187:11892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/upfile.php"] [unique_id "aoSBJtO5rbWdOArH04KmeAAAAV4"]
[Tue Aug 18 12:58:30.800843 2026] [security2:error] [pid 66623:tid 66845] [client 40.74.65.169:56390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/aa.php"] [unique_id "aoSBJtO5rbWdOArH04KmeQAAAVk"]
[Tue Aug 18 12:58:30.818683 2026] [security2:error] [pid 66623:tid 66832] [client 4.232.94.69:49348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/f5.php"] [unique_id "aoSBJtO5rbWdOArH04KmewAAAUw"]
[Tue Aug 18 12:58:30.837876 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:30.838178 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:30.838286 2026] [security2:error] [pid 66623:tid 66666] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kj.php"] [unique_id "aoSBJtO5rbWdOArH04KmfQABbR0"]
[Tue Aug 18 12:58:30.851645 2026] [security2:error] [pid 66623:tid 66876] [client 20.118.172.148:31292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/as.php"] [unique_id "aoSBJtO5rbWdOArH04KmgAAAAXg"]
[Tue Aug 18 12:58:30.902910 2026] [security2:error] [pid 66623:tid 66812] [client 74.248.18.37:47284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoSBJtO5rbWdOArH04KmiAAAATg"]
[Tue Aug 18 12:58:30.910134 2026] [security2:error] [pid 66623:tid 66806] [client 20.79.204.6:11560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSBJtO5rbWdOArH04KmiQAAATI"]
[Tue Aug 18 12:58:30.947861 2026] [security2:error] [pid 66623:tid 66839] [client 86.120.159.145:60196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJtO5rbWdOArH04KmiwAAAVM"]
[Tue Aug 18 12:58:30.947983 2026] [security2:error] [pid 66623:tid 66839] [client 86.120.159.145:60196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJtO5rbWdOArH04KmiwAAAVM"]
[Tue Aug 18 12:58:30.949029 2026] [security2:error] [pid 66623:tid 66878] [client 20.100.185.105:43117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/moon.php"] [unique_id "aoSBJtO5rbWdOArH04KmjAAAAXo"]
[Tue Aug 18 12:58:30.977457 2026] [security2:error] [pid 66623:tid 66856] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/classwithtostring.php"] [unique_id "aoSBJtO5rbWdOArH04KmjQAAAWQ"]
[Tue Aug 18 12:58:30.986763 2026] [security2:error] [pid 66623:tid 66817] [client 85.204.70.114:51460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJtO5rbWdOArH04KmjgAAAT0"]
[Tue Aug 18 12:58:31.013052 2026] [security2:error] [pid 66623:tid 66829] [client 20.104.85.180:47124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/k.php"] [unique_id "aoSBJ9O5rbWdOArH04KmkAAAAUk"]
[Tue Aug 18 12:58:31.013163 2026] [security2:error] [pid 66623:tid 66720] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/vg.php"] [unique_id "aoSBJ9O5rbWdOArH04KmkQABaVM"]
[Tue Aug 18 12:58:31.054394 2026] [security2:error] [pid 66623:tid 66709] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/about.php"] [unique_id "aoSBJ9O5rbWdOArH04KmlAABRUg"]
[Tue Aug 18 12:58:31.054624 2026] [security2:error] [pid 66623:tid 66745] [remote 162.55.89.48:53396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/wp-login.php"] [unique_id "aoSBJ9O5rbWdOArH04KmkwABcmw"]
[Tue Aug 18 12:58:31.061902 2026] [security2:error] [pid 66623:tid 66789] [client 158.23.17.4:15757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/le.php"] [unique_id "aoSBJ9O5rbWdOArH04KmlQAAASE"]
[Tue Aug 18 12:58:31.064038 2026] [security2:error] [pid 66623:tid 66847] [client 158.158.74.177:16569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBJ9O5rbWdOArH04KmlgAAAVs"]
[Tue Aug 18 12:58:31.071461 2026] [security2:error] [pid 66623:tid 66790] [client 192.141.172.134:51087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJ9O5rbWdOArH04KmmAAAASI"]
[Tue Aug 18 12:58:31.071579 2026] [security2:error] [pid 66623:tid 66790] [client 192.141.172.134:51087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJ9O5rbWdOArH04KmmAAAASI"]
[Tue Aug 18 12:58:31.075646 2026] [security2:error] [pid 66623:tid 66769] [client 20.215.241.237:41263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/sf.php"] [unique_id "aoSBJ9O5rbWdOArH04KmmgAAAQ0"]
[Tue Aug 18 12:58:31.079436 2026] [security2:error] [pid 66623:tid 66863] [client 213.35.127.232:51328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBJ9O5rbWdOArH04KmnAAAAWs"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:31.085211 2026] [security2:error] [pid 66623:tid 66849] [client 4.232.151.198:6098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wpsml-sys.php"] [unique_id "aoSBJ9O5rbWdOArH04KmnQAAAV0"]
[Tue Aug 18 12:58:31.113444 2026] [security2:error] [pid 66623:tid 66697] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/phpinfo.php"] [unique_id "aoSBJ9O5rbWdOArH04KmoAABFzw"]
[Tue Aug 18 12:58:31.134582 2026] [security2:error] [pid 66623:tid 66774] [client 20.119.58.187:11887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSBJ9O5rbWdOArH04KmogAAARI"]
[Tue Aug 18 12:58:31.141985 2026] [security2:error] [pid 66623:tid 66777] [client 114.119.157.196:50113] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "abrilbranco.org"] [uri "/tipos_de_cancer/tumores-neuroendocrinos"] [unique_id "aoSBJ9O5rbWdOArH04KmowAAARU"], referer: http://abrilbranco.org/?pid=129085669
[Tue Aug 18 12:58:31.148440 2026] [security2:error] [pid 66623:tid 66874] [client 20.250.13.23:1819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/aa.php"] [unique_id "aoSBJ9O5rbWdOArH04KmpAAAAXY"]
[Tue Aug 18 12:58:31.171578 2026] [security2:error] [pid 66623:tid 66821] [client 20.203.138.185:60944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-good.php"] [unique_id "aoSBJ9O5rbWdOArH04KmpQAAAUE"]
[Tue Aug 18 12:58:31.176744 2026] [security2:error] [pid 66623:tid 66853] [client 172.182.217.32:2691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/xx.php"] [unique_id "aoSBJ9O5rbWdOArH04KmpgAAAWE"]
[Tue Aug 18 12:58:31.190794 2026] [security2:error] [pid 66623:tid 66795] [client 20.118.172.148:46737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/bolt.php"] [unique_id "aoSBJ9O5rbWdOArH04KmpwAAASc"]
[Tue Aug 18 12:58:31.193313 2026] [security2:error] [pid 66623:tid 66663] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/sm.php"] [unique_id "aoSBJ9O5rbWdOArH04KmqAABRho"]
[Tue Aug 18 12:58:31.219380 2026] [security2:error] [pid 66623:tid 66885] [client 114.119.152.142:62277] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "telesaopedro.com.br"] [uri "/cvc-sao-pedro-agencia-de-turismo/"] [unique_id "aoSBJ9O5rbWdOArH04KmqgAAAYE"], referer: https://telesaopedro.com.br/empresa/page/35
[Tue Aug 18 12:58:31.238080 2026] [security2:error] [pid 66623:tid 66671] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/admin.php"] [unique_id "aoSBJ9O5rbWdOArH04KmqwABRCI"]
[Tue Aug 18 12:58:31.294765 2026] [security2:error] [pid 66623:tid 66889] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/wp-ws68.php"] [unique_id "aoSBJ9O5rbWdOArH04KmrgAAAYU"]
[Tue Aug 18 12:58:31.297331 2026] [security2:error] [pid 66623:tid 66871] [client 74.248.18.37:7703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/settings.php"] [unique_id "aoSBJ9O5rbWdOArH04KmrwAAAXM"]
[Tue Aug 18 12:58:31.312117 2026] [security2:error] [pid 66623:tid 66844] [client 158.23.17.4:34143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ig.php"] [unique_id "aoSBJ9O5rbWdOArH04KmsQAAAVg"]
[Tue Aug 18 12:58:31.344997 2026] [security2:error] [pid 66623:tid 66868] [client 68.155.155.199:7015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBJ9O5rbWdOArH04KmswAAAXA"]
[Tue Aug 18 12:58:31.389028 2026] [security2:error] [pid 66623:tid 66822] [client 172.182.200.96:7640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSBJ9O5rbWdOArH04KmtgAAAUI"]
[Tue Aug 18 12:58:31.397696 2026] [security2:error] [pid 66623:tid 66781] [client 85.204.70.114:51462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJ9O5rbWdOArH04KmuQAAARk"]
[Tue Aug 18 12:58:31.404789 2026] [security2:error] [pid 66623:tid 66708] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/28.php"] [unique_id "aoSBJ9O5rbWdOArH04KmugABYEc"]
[Tue Aug 18 12:58:31.466839 2026] [security2:error] [pid 66623:tid 66867] [client 52.173.121.69:27893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/lddxs.php"] [unique_id "aoSBJ9O5rbWdOArH04KmvAAAAW8"]
[Tue Aug 18 12:58:31.471892 2026] [autoindex:error] [pid 66623:tid 66701] [remote 68.155.154.146:0] AH01276: Cannot serve directory /home4/bioclimaarcondic/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:31.518345 2026] [security2:error] [pid 66623:tid 66851] [client 20.79.204.6:11656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSBJ9O5rbWdOArH04KmvgAAAV8"]
[Tue Aug 18 12:58:31.519736 2026] [security2:error] [pid 66623:tid 66887] [client 20.119.58.187:11999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSBJ9O5rbWdOArH04KmvwAAAYM"]
[Tue Aug 18 12:58:31.563369 2026] [security2:error] [pid 66623:tid 66829] [client 20.118.133.132:1750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/xyn.php"] [unique_id "aoSBJ9O5rbWdOArH04KmwQAAAUk"]
[Tue Aug 18 12:58:31.591745 2026] [security2:error] [pid 66623:tid 66846] [client 20.100.169.31:29060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBJ9O5rbWdOArH04KmwwAAAVo"]
[Tue Aug 18 12:58:31.606477 2026] [security2:error] [pid 66623:tid 66712] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/m.php"] [unique_id "aoSBJ9O5rbWdOArH04KmygABSks"]
[Tue Aug 18 12:58:31.609238 2026] [security2:error] [pid 66623:tid 66823] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/mgrr.php"] [unique_id "aoSBJ9O5rbWdOArH04KmywAAAUM"]
[Tue Aug 18 12:58:31.616150 2026] [security2:error] [pid 66623:tid 66833] [client 20.100.185.105:6768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/exif.php"] [unique_id "aoSBJ9O5rbWdOArH04KmzgAAAU0"]
[Tue Aug 18 12:58:31.656661 2026] [authz_core:error] [pid 66623:tid 66654] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:31.656937 2026] [authz_core:error] [pid 66623:tid 66654] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:31.657992 2026] [security2:error] [pid 66623:tid 66800] [client 74.248.18.37:40997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/link-add.php"] [unique_id "aoSBJ9O5rbWdOArH04Km0gAAASw"]
[Tue Aug 18 12:58:31.658027 2026] [security2:error] [pid 66623:tid 66757] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSBJ9O5rbWdOArH04Km0QABfHg"]
[Tue Aug 18 12:58:31.675055 2026] [security2:error] [pid 66623:tid 66881] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJ9O5rbWdOArH04KmzwABfU8"]
[Tue Aug 18 12:58:31.680328 2026] [security2:error] [pid 66623:tid 66857] [client 172.182.217.32:15459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJ9O5rbWdOArH04Km1QAAAWU"]
[Tue Aug 18 12:58:31.711584 2026] [security2:error] [pid 66623:tid 66831] [client 52.173.121.69:17982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSBJ9O5rbWdOArH04Km1wAAAUs"]
[Tue Aug 18 12:58:31.717084 2026] [security2:error] [pid 66623:tid 66854] [client 4.232.151.198:6086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/l.php"] [unique_id "aoSBJ9O5rbWdOArH04Km2AAAAWI"]
[Tue Aug 18 12:58:31.794362 2026] [security2:error] [pid 66623:tid 66777] [client 85.204.70.114:51472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJ9O5rbWdOArH04Km3gAAARU"]
[Tue Aug 18 12:58:31.802345 2026] [security2:error] [pid 66623:tid 66776] [client 4.232.94.69:20775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/al.php"] [unique_id "aoSBJ9O5rbWdOArH04Km3wAAARQ"]
[Tue Aug 18 12:58:31.816065 2026] [security2:error] [pid 66623:tid 66770] [client 20.250.13.23:32702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wk/index.php"] [unique_id "aoSBJ9O5rbWdOArH04Km4QAAAQ4"]
[Tue Aug 18 12:58:31.820680 2026] [security2:error] [pid 66623:tid 66644] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/nl.php"] [unique_id "aoSBJ9O5rbWdOArH04Km4gABdgc"]
[Tue Aug 18 12:58:31.831628 2026] [security2:error] [pid 66623:tid 66825] [client 20.250.13.23:45756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/abcd.php"] [unique_id "aoSBJ9O5rbWdOArH04Km4wAAAUU"]
[Tue Aug 18 12:58:31.844567 2026] [security2:error] [pid 66623:tid 66804] [client 20.118.172.148:2709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBJ9O5rbWdOArH04Km5QAAATA"]
[Tue Aug 18 12:58:31.868803 2026] [security2:error] [pid 66623:tid 66795] [client 20.48.236.86:31043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/ai.php"] [unique_id "aoSBJ9O5rbWdOArH04Km5wAAASc"]
[Tue Aug 18 12:58:31.878164 2026] [security2:error] [pid 66623:tid 66886] [client 20.119.58.187:12543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/ae.php"] [unique_id "aoSBJ9O5rbWdOArH04Km6AAAAYI"]
[Tue Aug 18 12:58:31.881766 2026] [autoindex:error] [pid 66623:tid 66648] [remote 68.155.154.146:0] AH01276: Cannot serve directory /home4/bioclimaarcondic/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:31.900690 2026] [security2:error] [pid 66623:tid 66824] [client 158.23.17.4:15786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/hr.php"] [unique_id "aoSBJ9O5rbWdOArH04Km6QAAAUQ"]
[Tue Aug 18 12:58:31.948037 2026] [security2:error] [pid 66623:tid 66840] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/55.php"] [unique_id "aoSBJ9O5rbWdOArH04Km7AAAAVQ"]
[Tue Aug 18 12:58:31.957064 2026] [authz_core:error] [pid 66623:tid 66762] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:31.957320 2026] [authz_core:error] [pid 66623:tid 66762] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:31.961611 2026] [security2:error] [pid 66623:tid 66773] [client 68.155.155.199:6746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/0x.php"] [unique_id "aoSBJ9O5rbWdOArH04Km7wAAARE"]
[Tue Aug 18 12:58:31.969674 2026] [security2:error] [pid 66623:tid 66771] [client 74.248.18.37:7209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/sf.php"] [unique_id "aoSBJ9O5rbWdOArH04Km8QAAAQ8"]
[Tue Aug 18 12:58:31.976051 2026] [security2:error] [pid 66623:tid 66848] [client 20.203.183.135:49668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/abcd.php"] [unique_id "aoSBJ9O5rbWdOArH04Km8gAAAVw"]
[Tue Aug 18 12:58:32.001406 2026] [security2:error] [pid 66623:tid 66744] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/68.php"] [unique_id "aoSBKNO5rbWdOArH04Km8wABKms"]
[Tue Aug 18 12:58:32.008428 2026] [security2:error] [pid 66623:tid 66686] [remote 66.249.74.227:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "donfalconebarbearia.com.br"] [uri "/robots.txt"] [unique_id "aoSBKNO5rbWdOArH04Km9AABWDE"]
[Tue Aug 18 12:58:32.017949 2026] [security2:error] [pid 66623:tid 66820] [client 40.74.65.169:45400] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/1.php"] [unique_id "aoSBKNO5rbWdOArH04Km9QAAAUA"]
[Tue Aug 18 12:58:32.018070 2026] [security2:error] [pid 66623:tid 66820] [client 40.74.65.169:45400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/1.php"] [unique_id "aoSBKNO5rbWdOArH04Km9QAAAUA"]
[Tue Aug 18 12:58:32.020919 2026] [security2:error] [pid 66623:tid 66884] [client 52.173.121.69:47306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/zjggu.php"] [unique_id "aoSBKNO5rbWdOArH04Km9gAAAYA"]
[Tue Aug 18 12:58:32.066119 2026] [security2:error] [pid 66623:tid 66647] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/css/colors/blue/min.php"] [unique_id "aoSBKNO5rbWdOArH04Km-QABOwo"]
[Tue Aug 18 12:58:32.089307 2026] [security2:error] [pid 66623:tid 66842] [client 213.35.127.232:51540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBKNO5rbWdOArH04Km-gAAAVY"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:32.113463 2026] [security2:error] [pid 66623:tid 66893] [client 20.104.85.180:45974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/403.php"] [unique_id "aoSBKNO5rbWdOArH04Km-wAAAYk"]
[Tue Aug 18 12:58:32.141801 2026] [autoindex:error] [pid 66623:tid 66797] [client 20.79.204.6:11533] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:32.159018 2026] [security2:error] [pid 66623:tid 66786] [client 158.23.17.4:32520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ta.php"] [unique_id "aoSBKNO5rbWdOArH04Km_gAAAR4"]
[Tue Aug 18 12:58:32.160581 2026] [security2:error] [pid 66623:tid 66890] [client 172.202.39.151:4702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/public/css.php"] [unique_id "aoSBKNO5rbWdOArH04Km_wAAAYY"]
[Tue Aug 18 12:58:32.168243 2026] [security2:error] [pid 66623:tid 66766] [client 172.182.217.32:15586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/y.php"] [unique_id "aoSBKNO5rbWdOArH04KnAAAAAQo"]
[Tue Aug 18 12:58:32.196604 2026] [security2:error] [pid 66623:tid 66656] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/jl.php"] [unique_id "aoSBKNO5rbWdOArH04KnAgABXxM"]
[Tue Aug 18 12:58:32.235232 2026] [security2:error] [pid 66623:tid 66808] [client 20.100.185.105:21652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/0.php"] [unique_id "aoSBKNO5rbWdOArH04KnBQAAATQ"]
[Tue Aug 18 12:58:32.238251 2026] [security2:error] [pid 66623:tid 66852] [client 20.119.58.187:11974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/moon.php"] [unique_id "aoSBKNO5rbWdOArH04KnBgAAAWA"]
[Tue Aug 18 12:58:32.249603 2026] [security2:error] [pid 66623:tid 66761] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/css/colors/blue/xmrlpc.php"] [unique_id "aoSBKNO5rbWdOArH04KnCAABC3w"]
[Tue Aug 18 12:58:32.265265 2026] [security2:error] [pid 66623:tid 66837] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/ajax.php"] [unique_id "aoSBKNO5rbWdOArH04KnCwAAAVE"]
[Tue Aug 18 12:58:32.313479 2026] [security2:error] [pid 66623:tid 66781] [client 79.127.164.8:40880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/server.sql"] [unique_id "aoSBKNO5rbWdOArH04KnDwAAARk"], referer: https://medihub.com.br/server.sql
[Tue Aug 18 12:58:32.351757 2026] [security2:error] [pid 66623:tid 66737] [remote 72.167.40.62:55648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.40.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/wp-login.php"] [unique_id "aoSBKNO5rbWdOArH04KnEgABZmQ"]
[Tue Aug 18 12:58:32.378021 2026] [security2:error] [pid 66623:tid 66755] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/tq.php"] [unique_id "aoSBKNO5rbWdOArH04KnEwABPnY"]
[Tue Aug 18 12:58:32.379909 2026] [security2:error] [pid 66623:tid 66785] [client 4.232.151.198:30030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/file.php"] [unique_id "aoSBKNO5rbWdOArH04KnFAAAAR0"]
[Tue Aug 18 12:58:32.381891 2026] [security2:error] [pid 66623:tid 66835] [client 20.203.138.185:47213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/zxin.php"] [unique_id "aoSBKNO5rbWdOArH04KnFQAAAU8"]
[Tue Aug 18 12:58:32.417214 2026] [security2:error] [pid 66623:tid 66831] [client 52.173.121.69:17946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/rezor.php"] [unique_id "aoSBKNO5rbWdOArH04KnGAAAAUs"]
[Tue Aug 18 12:58:32.421369 2026] [security2:error] [pid 66623:tid 66854] [client 20.118.172.148:50060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/edit.php"] [unique_id "aoSBKNO5rbWdOArH04KnGQAAAWI"]
[Tue Aug 18 12:58:32.439049 2026] [security2:error] [pid 66623:tid 66705] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/css/colors/ectoplasm/about.php"] [unique_id "aoSBKNO5rbWdOArH04KnGgABM0Q"]
[Tue Aug 18 12:58:32.456966 2026] [security2:error] [pid 66623:tid 66814] [client 20.250.13.23:53632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/admin.php"] [unique_id "aoSBKNO5rbWdOArH04KnGwAAATo"]
[Tue Aug 18 12:58:32.556450 2026] [security2:error] [pid 66623:tid 66804] [client 52.173.121.69:14544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/dlvqo.php"] [unique_id "aoSBKNO5rbWdOArH04KnMgAAATA"]
[Tue Aug 18 12:58:32.565040 2026] [security2:error] [pid 66623:tid 66660] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/cv.php"] [unique_id "aoSBKNO5rbWdOArH04KnMwABYRc"]
[Tue Aug 18 12:58:32.575004 2026] [security2:error] [pid 66623:tid 66836] [client 20.79.204.6:11533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSBKNO5rbWdOArH04KnNQAAAVA"]
[Tue Aug 18 12:58:32.581415 2026] [security2:error] [pid 66623:tid 66795] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/yj09.php"] [unique_id "aoSBKNO5rbWdOArH04KnNwAAASc"]
[Tue Aug 18 12:58:32.583434 2026] [authz_core:error] [pid 66623:tid 66752] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:32.583703 2026] [authz_core:error] [pid 66623:tid 66752] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:32.599486 2026] [security2:error] [pid 66623:tid 66769] [client 4.232.94.69:44546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/inc.php"] [unique_id "aoSBKNO5rbWdOArH04KnOAAAAQ0"]
[Tue Aug 18 12:58:32.599628 2026] [security2:error] [pid 66623:tid 66777] [client 20.119.58.187:12531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/ini.php"] [unique_id "aoSBKNO5rbWdOArH04KnOQAAARU"]
[Tue Aug 18 12:58:32.602756 2026] [security2:error] [pid 66623:tid 66881] [client 74.248.18.37:40982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/shell.php"] [unique_id "aoSBKNO5rbWdOArH04KnOgAAAX0"]
[Tue Aug 18 12:58:32.610022 2026] [security2:error] [pid 66623:tid 66805] [client 74.248.18.37:47275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSBKNO5rbWdOArH04KnPQAAATE"]
[Tue Aug 18 12:58:32.628106 2026] [security2:error] [pid 66623:tid 66680] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBKNO5rbWdOArH04KnPwABESs"]
[Tue Aug 18 12:58:32.648856 2026] [security2:error] [pid 66623:tid 66778] [client 20.127.136.245:13467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBKNO5rbWdOArH04KnRQAAARY"]
[Tue Aug 18 12:58:32.676532 2026] [security2:error] [pid 66623:tid 66860] [client 68.155.155.199:4924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/222.php"] [unique_id "aoSBKNO5rbWdOArH04KnSAAAAWg"]
[Tue Aug 18 12:58:32.716048 2026] [security2:error] [pid 66623:tid 66847] [client 20.118.133.132:19636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBKNO5rbWdOArH04KnSQAAAVs"]
[Tue Aug 18 12:58:32.734549 2026] [security2:error] [pid 66623:tid 66801] [client 158.23.17.4:8935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/34.php"] [unique_id "aoSBKNO5rbWdOArH04KnTQAAAS0"]
[Tue Aug 18 12:58:32.737696 2026] [security2:error] [pid 66623:tid 66751] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/un.php"] [unique_id "aoSBKNO5rbWdOArH04KnTgABcXI"]
[Tue Aug 18 12:58:32.823549 2026] [security2:error] [pid 66623:tid 66740] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/css/colors/light/flower.php"] [unique_id "aoSBKNO5rbWdOArH04KnUgABYGc"]
[Tue Aug 18 12:58:32.852707 2026] [security2:error] [pid 66623:tid 66798] [client 20.100.185.105:59250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/embed.php"] [unique_id "aoSBKNO5rbWdOArH04KnVgAAASo"]
[Tue Aug 18 12:58:32.858908 2026] [authz_core:error] [pid 66623:tid 66711] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:32.859164 2026] [authz_core:error] [pid 66623:tid 66711] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:32.868129 2026] [security2:error] [pid 66623:tid 66809] [client 158.23.17.4:7229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/kt.php"] [unique_id "aoSBKNO5rbWdOArH04KnWAAAATU"]
[Tue Aug 18 12:58:32.913335 2026] [security2:error] [pid 66623:tid 66739] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/evil.php"] [unique_id "aoSBKNO5rbWdOArH04KnWgABGWY"]
[Tue Aug 18 12:58:32.933827 2026] [security2:error] [pid 66623:tid 66887] [client 103.184.169.37:42385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKNO5rbWdOArH04KnXQAAAYM"]
[Tue Aug 18 12:58:32.933969 2026] [security2:error] [pid 66623:tid 66887] [client 103.184.169.37:42385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKNO5rbWdOArH04KnXQAAAYM"]
[Tue Aug 18 12:58:32.954752 2026] [security2:error] [pid 66623:tid 66791] [client 20.119.58.187:11988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/shell.php"] [unique_id "aoSBKNO5rbWdOArH04KnXwAAASM"]
[Tue Aug 18 12:58:32.984409 2026] [security2:error] [pid 66623:tid 66789] [client 20.118.172.148:2717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/ff1.php"] [unique_id "aoSBKNO5rbWdOArH04KnYAAAASE"]
[Tue Aug 18 12:58:33.007212 2026] [security2:error] [pid 66623:tid 66856] [client 4.232.151.198:6110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-comments-post.php"] [unique_id "aoSBKdO5rbWdOArH04KnYgAAAWQ"]
[Tue Aug 18 12:58:33.009057 2026] [security2:error] [pid 66623:tid 66692] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/css/colors/light/min.php"] [unique_id "aoSBKdO5rbWdOArH04KnZAABTzc"]
[Tue Aug 18 12:58:33.022058 2026] [security2:error] [pid 66623:tid 66880] [client 103.120.71.157:58854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKdO5rbWdOArH04KnZQAAAXw"]
[Tue Aug 18 12:58:33.022171 2026] [security2:error] [pid 66623:tid 66880] [client 103.120.71.157:58854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKdO5rbWdOArH04KnZQAAAXw"]
[Tue Aug 18 12:58:33.026403 2026] [security2:error] [pid 66623:tid 66857] [client 40.74.65.169:56402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/img.php"] [unique_id "aoSBKdO5rbWdOArH04KnZgAAAWU"]
[Tue Aug 18 12:58:33.037553 2026] [security2:error] [pid 66623:tid 66831] [client 20.48.236.86:2771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/w1px.php"] [unique_id "aoSBKdO5rbWdOArH04KnaAAAAUs"]
[Tue Aug 18 12:58:33.049729 2026] [security2:error] [pid 66623:tid 66779] [client 52.173.121.69:24790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSBKdO5rbWdOArH04KnagAAARc"]
[Tue Aug 18 12:58:33.059171 2026] [security2:error] [pid 66623:tid 66807] [client 20.104.85.180:50311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/gecko.php"] [unique_id "aoSBKdO5rbWdOArH04KnawAAATM"]
[Tue Aug 18 12:58:33.086483 2026] [security2:error] [pid 66623:tid 66638] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/pw.php"] [unique_id "aoSBKdO5rbWdOArH04KnbQABSAE"]
[Tue Aug 18 12:58:33.103952 2026] [security2:error] [pid 66623:tid 66786] [client 213.35.127.232:51762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBKdO5rbWdOArH04KncAAAAR4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:33.159552 2026] [authz_core:error] [pid 66623:tid 66690] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:33.159835 2026] [authz_core:error] [pid 66623:tid 66690] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:33.163391 2026] [security2:error] [pid 66623:tid 66870] [client 20.250.13.23:32699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/about.php"] [unique_id "aoSBKdO5rbWdOArH04KndAAAAXI"]
[Tue Aug 18 12:58:33.187248 2026] [security2:error] [pid 66623:tid 66753] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/css/colors/ocean/min.php"] [unique_id "aoSBKdO5rbWdOArH04KndgABUHQ"]
[Tue Aug 18 12:58:33.197495 2026] [autoindex:error] [pid 66623:tid 66800] [client 20.79.204.6:11670] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-includes/images/media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:33.201504 2026] [security2:error] [pid 66623:tid 66799] [client 52.173.121.69:27867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/pkmoj.php"] [unique_id "aoSBKdO5rbWdOArH04KndwAAASs"]
[Tue Aug 18 12:58:33.216052 2026] [security2:error] [pid 66623:tid 66805] [client 172.202.39.151:40329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBKdO5rbWdOArH04KneQAAATE"]
[Tue Aug 18 12:58:33.260623 2026] [security2:error] [pid 66623:tid 66854] [client 74.248.18.37:7693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSBKdO5rbWdOArH04KnfAAAAWI"]
[Tue Aug 18 12:58:33.276524 2026] [security2:error] [pid 66623:tid 66861] [client 74.248.18.37:47290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/shiny.php"] [unique_id "aoSBKdO5rbWdOArH04KnfQAAAWk"]
[Tue Aug 18 12:58:33.286139 2026] [security2:error] [pid 66623:tid 66745] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/fn.php"] [unique_id "aoSBKdO5rbWdOArH04KnfwABXmw"]
[Tue Aug 18 12:58:33.310125 2026] [security2:error] [pid 66623:tid 66768] [client 20.250.13.23:1814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBKdO5rbWdOArH04KnhAAAAQw"]
[Tue Aug 18 12:58:33.310412 2026] [security2:error] [pid 66623:tid 66795] [client 20.119.58.187:12512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBKdO5rbWdOArH04KngwAAASc"]
[Tue Aug 18 12:58:33.322480 2026] [security2:error] [pid 66623:tid 66788] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/scxy.php"] [unique_id "aoSBKdO5rbWdOArH04KnhgAAASA"]
[Tue Aug 18 12:58:33.366014 2026] [security2:error] [pid 66623:tid 66713] [remote 115.146.125.52:46118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "docurso.com"] [uri "/wp-login.php"] [unique_id "aoSBKdO5rbWdOArH04KniAABQEw"]
[Tue Aug 18 12:58:33.376986 2026] [security2:error] [pid 66623:tid 66658] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/css/min.php"] [unique_id "aoSBKdO5rbWdOArH04KniQABRRU"]
[Tue Aug 18 12:58:33.399233 2026] [security2:error] [pid 66623:tid 66893] [client 20.79.204.6:11670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBKdO5rbWdOArH04KniwAAAYk"]
[Tue Aug 18 12:58:33.433792 2026] [security2:error] [pid 66623:tid 66822] [client 158.23.17.4:34138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/he.php"] [unique_id "aoSBKdO5rbWdOArH04KnjwAAAUI"]
[Tue Aug 18 12:58:33.493540 2026] [security2:error] [pid 66623:tid 66671] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kf.php"] [unique_id "aoSBKdO5rbWdOArH04KnkgABbyI"]
[Tue Aug 18 12:58:33.562192 2026] [security2:error] [pid 66623:tid 66741] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/data.php"] [unique_id "aoSBKdO5rbWdOArH04KnlAABhGg"]
[Tue Aug 18 12:58:33.589330 2026] [security2:error] [pid 66623:tid 66736] [remote 165.173.18.124:57776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.18.173.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-login.php"] [unique_id "aoSBKdO5rbWdOArH04KnlwABHWM"]
[Tue Aug 18 12:58:33.604516 2026] [security2:error] [pid 66623:tid 66856] [client 20.104.85.180:54573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/aa.php"] [unique_id "aoSBKdO5rbWdOArH04KnmAAAAWQ"]
[Tue Aug 18 12:58:33.612810 2026] [security2:error] [pid 66623:tid 66835] [client 20.215.241.237:53253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/k.php"] [unique_id "aoSBKdO5rbWdOArH04KnmQAAAU8"]
[Tue Aug 18 12:58:33.624437 2026] [security2:error] [pid 66623:tid 66872] [client 37.40.227.74:57206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKdO5rbWdOArH04KnmwAAAXQ"]
[Tue Aug 18 12:58:33.624552 2026] [security2:error] [pid 66623:tid 66872] [client 37.40.227.74:57206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKdO5rbWdOArH04KnmwAAAXQ"]
[Tue Aug 18 12:58:33.646315 2026] [security2:error] [pid 66623:tid 66857] [client 52.173.121.69:32593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/kopyw.php"] [unique_id "aoSBKdO5rbWdOArH04KnnQAAAWU"]
[Tue Aug 18 12:58:33.650515 2026] [security2:error] [pid 66623:tid 66808] [client 4.232.151.198:62685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/xmrlpc.php"] [unique_id "aoSBKdO5rbWdOArH04KnngAAATQ"]
[Tue Aug 18 12:58:33.665351 2026] [security2:error] [pid 66623:tid 66791] [client 20.119.58.187:11976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-sigunq.php"] [unique_id "aoSBKdO5rbWdOArH04KnnwAAASM"]
[Tue Aug 18 12:58:33.669704 2026] [security2:error] [pid 66623:tid 66837] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/ws13.php"] [unique_id "aoSBKdO5rbWdOArH04KnoQAAAVE"]
[Tue Aug 18 12:58:33.678150 2026] [security2:error] [pid 66623:tid 66734] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/su.php"] [unique_id "aoSBKdO5rbWdOArH04KnogABE2E"]
[Tue Aug 18 12:58:33.698393 2026] [security2:error] [pid 66623:tid 66871] [client 213.202.253.4:55783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/wp-content/postnews.php"] [unique_id "aoSBKdO5rbWdOArH04KnowAAAXM"], referer: www.google.com
[Tue Aug 18 12:58:33.725332 2026] [security2:error] [pid 66623:tid 66828] [client 40.74.65.169:55837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/222.php"] [unique_id "aoSBKdO5rbWdOArH04KnpAAAAUg"]
[Tue Aug 18 12:58:33.751797 2026] [security2:error] [pid 66623:tid 66758] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/home.php"] [unique_id "aoSBKdO5rbWdOArH04KnpQABf3k"]
[Tue Aug 18 12:58:33.760776 2026] [authz_core:error] [pid 66623:tid 66659] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:33.761196 2026] [authz_core:error] [pid 66623:tid 66659] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:33.776790 2026] [security2:error] [pid 66623:tid 66833] [client 20.104.85.180:18864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKdO5rbWdOArH04KnqAAAAU0"]
[Tue Aug 18 12:58:33.786755 2026] [security2:error] [pid 66623:tid 66882] [client 20.206.73.37:59880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/xx.php"] [unique_id "aoSBKdO5rbWdOArH04KnqQAAAX4"]
[Tue Aug 18 12:58:33.789685 2026] [security2:error] [pid 66623:tid 66701] [remote 162.214.96.231:36390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-login.php"] [unique_id "aoSBKdO5rbWdOArH04KnqgABeUA"]
[Tue Aug 18 12:58:33.816950 2026] [security2:error] [pid 66623:tid 66796] [client 20.118.133.132:20217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/inso.php"] [unique_id "aoSBKdO5rbWdOArH04KnqwAAASg"]
[Tue Aug 18 12:58:33.887439 2026] [security2:error] [pid 66623:tid 66673] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/wp-key.php"] [unique_id "aoSBKdO5rbWdOArH04KnsAABdSQ"]
[Tue Aug 18 12:58:33.916436 2026] [security2:error] [pid 66623:tid 66840] [client 20.48.236.86:2217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/zi-936.php"] [unique_id "aoSBKdO5rbWdOArH04KnsgAAAVQ"]
[Tue Aug 18 12:58:33.917322 2026] [security2:error] [pid 66623:tid 66831] [client 74.248.18.37:7718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/maint/wpxml.php"] [unique_id "aoSBKdO5rbWdOArH04KnswAAAUs"]
[Tue Aug 18 12:58:33.938832 2026] [security2:error] [pid 66623:tid 66813] [client 52.173.121.69:6096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSBKdO5rbWdOArH04KntAAAATk"]
[Tue Aug 18 12:58:33.939423 2026] [security2:error] [pid 66623:tid 66816] [client 20.250.13.23:45743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/akc.php"] [unique_id "aoSBKdO5rbWdOArH04KntQAAATw"]
[Tue Aug 18 12:58:33.944862 2026] [security2:error] [pid 66623:tid 66848] [client 158.23.17.4:20403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ww.php"] [unique_id "aoSBKdO5rbWdOArH04KntwAAAVw"]
[Tue Aug 18 12:58:33.949812 2026] [security2:error] [pid 66623:tid 66807] [client 74.248.18.37:7681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/sid3.php"] [unique_id "aoSBKdO5rbWdOArH04KnuAAAATM"]
[Tue Aug 18 12:58:33.985523 2026] [security2:error] [pid 66623:tid 66788] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/btx25.php"] [unique_id "aoSBKdO5rbWdOArH04KnugAAASA"]
[Tue Aug 18 12:58:34.000210 2026] [security2:error] [pid 66623:tid 66853] [client 20.79.204.6:11539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSBKdO5rbWdOArH04KnuwAAAWE"]
[Tue Aug 18 12:58:34.022274 2026] [autoindex:error] [pid 66623:tid 66724] [remote 68.155.154.146:0] AH01276: Cannot serve directory /home4/bioclimaarcondic/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:34.033054 2026] [security2:error] [pid 66623:tid 66805] [client 20.119.58.187:12088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wso112233.php"] [unique_id "aoSBKtO5rbWdOArH04KnvgAAATE"]
[Tue Aug 18 12:58:34.058824 2026] [security2:error] [pid 66623:tid 66889] [client 20.104.85.180:6984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/moon.php"] [unique_id "aoSBKtO5rbWdOArH04KnwAAAAYU"]
[Tue Aug 18 12:58:34.064116 2026] [authz_core:error] [pid 66623:tid 66691] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:34.064378 2026] [authz_core:error] [pid 66623:tid 66691] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:34.069647 2026] [security2:error] [pid 66623:tid 66793] [client 172.202.39.151:4687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/classwithtostring.php"] [unique_id "aoSBKtO5rbWdOArH04KnwgAAASU"]
[Tue Aug 18 12:58:34.089457 2026] [security2:error] [pid 66623:tid 66662] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gg.php"] [unique_id "aoSBKtO5rbWdOArH04KnwwABQBk"]
[Tue Aug 18 12:58:34.105396 2026] [security2:error] [pid 66623:tid 66790] [client 158.23.17.4:34156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/gz.php"] [unique_id "aoSBKtO5rbWdOArH04KnxAAAASI"]
[Tue Aug 18 12:58:34.118386 2026] [security2:error] [pid 66623:tid 66841] [client 213.35.127.232:51944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBKtO5rbWdOArH04KnxQAAAVU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:34.126250 2026] [security2:error] [pid 66623:tid 66757] [remote 165.173.18.124:57776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.18.173.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-login.php"] [unique_id "aoSBKtO5rbWdOArH04KnxwABeng"], referer: https://eccellenzaconsultoria.com.br/wp-login.php
[Tue Aug 18 12:58:34.126540 2026] [security2:error] [pid 66623:tid 66825] [client 52.173.121.69:14854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/zznmg.php"] [unique_id "aoSBKtO5rbWdOArH04KnyAAAAUU"]
[Tue Aug 18 12:58:34.143337 2026] [security2:error] [pid 66623:tid 66832] [client 172.182.200.96:14088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSBKtO5rbWdOArH04KnyQAAAUw"]
[Tue Aug 18 12:58:34.149494 2026] [security2:error] [pid 66623:tid 66780] [client 20.118.172.148:2743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/fff.php"] [unique_id "aoSBKtO5rbWdOArH04KnywAAARg"]
[Tue Aug 18 12:58:34.203319 2026] [security2:error] [pid 66623:tid 66667] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/images/min.php"] [unique_id "aoSBKtO5rbWdOArH04KnzQABQx4"]
[Tue Aug 18 12:58:34.208082 2026] [security2:error] [pid 66623:tid 66794] [client 20.250.13.23:51643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/term.php"] [unique_id "aoSBKtO5rbWdOArH04KnzgAAASY"]
[Tue Aug 18 12:58:34.236685 2026] [security2:error] [pid 66623:tid 66783] [client 68.155.155.199:23081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/aa.php"] [unique_id "aoSBKtO5rbWdOArH04Kn0QAAARs"]
[Tue Aug 18 12:58:34.243119 2026] [security2:error] [pid 66623:tid 66786] [client 149.34.210.141:62026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBKtO5rbWdOArH04Kn0gAAAR4"]
[Tue Aug 18 12:58:34.264867 2026] [security2:error] [pid 66623:tid 66879] [client 20.104.85.180:15224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/0x.php"] [unique_id "aoSBKtO5rbWdOArH04Kn0wAAAXs"]
[Tue Aug 18 12:58:34.295446 2026] [security2:error] [pid 66623:tid 66842] [client 4.232.151.198:30044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/aj.php"] [unique_id "aoSBKtO5rbWdOArH04Kn1AAAAVY"]
[Tue Aug 18 12:58:34.300856 2026] [security2:error] [pid 66623:tid 66835] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/SDsadqwrf.php"] [unique_id "aoSBKtO5rbWdOArH04Kn1QAAAU8"]
[Tue Aug 18 12:58:34.306388 2026] [security2:error] [pid 66623:tid 66641] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gi.php"] [unique_id "aoSBKtO5rbWdOArH04Kn1gABdAQ"]
[Tue Aug 18 12:58:34.340738 2026] [security2:error] [pid 66623:tid 66775] [client 20.104.85.180:43541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/cache.php"] [unique_id "aoSBKtO5rbWdOArH04Kn2AAAARM"]
[Tue Aug 18 12:58:34.365209 2026] [authz_core:error] [pid 66623:tid 66756] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:34.365484 2026] [authz_core:error] [pid 66623:tid 66756] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:34.393991 2026] [security2:error] [pid 66623:tid 66789] [client 20.119.58.187:11990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/fw.php"] [unique_id "aoSBKtO5rbWdOArH04Kn-QAAASE"]
[Tue Aug 18 12:58:34.396583 2026] [security2:error] [pid 66623:tid 66811] [client 5.31.227.224:59070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKtO5rbWdOArH04Kn-gAAATc"]
[Tue Aug 18 12:58:34.411953 2026] [security2:error] [pid 66623:tid 66811] [client 5.31.227.224:59070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKtO5rbWdOArH04Kn-gAAATc"]
[Tue Aug 18 12:58:34.415981 2026] [security2:error] [pid 66623:tid 66849] [client 157.20.138.62:52576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKtO5rbWdOArH04KoBwAAAV0"]
[Tue Aug 18 12:58:34.416133 2026] [security2:error] [pid 66623:tid 66849] [client 157.20.138.62:52576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKtO5rbWdOArH04KoBwAAAV0"]
[Tue Aug 18 12:58:34.434434 2026] [autoindex:error] [pid 66623:tid 66732] [remote 68.155.154.146:0] AH01276: Cannot serve directory /home4/bioclimaarcondic/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:34.478332 2026] [security2:error] [pid 66623:tid 66796] [client 20.203.138.185:10763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/pass4.php"] [unique_id "aoSBKtO5rbWdOArH04KoDAAAASg"]
[Tue Aug 18 12:58:34.503771 2026] [security2:error] [pid 66623:tid 66738] [remote 103.56.163.133:53702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalinox.pt.cesarinox.com"] [uri "/wp-login.php"] [unique_id "aoSBKtO5rbWdOArH04KoEAABDWU"]
[Tue Aug 18 12:58:34.520185 2026] [security2:error] [pid 66623:tid 66786] [client 149.34.210.141:62026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBKtO5rbWdOArH04Kn0gAAAR4"]
[Tue Aug 18 12:58:34.543015 2026] [security2:error] [pid 66623:tid 66718] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/pz.php"] [unique_id "aoSBKtO5rbWdOArH04KoEwABS1E"]
[Tue Aug 18 12:58:34.545213 2026] [security2:error] [pid 66623:tid 66813] [client 40.74.65.169:45379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/key.php"] [unique_id "aoSBKtO5rbWdOArH04KoFAAAATk"]
[Tue Aug 18 12:58:34.583865 2026] [security2:error] [pid 66623:tid 66814] [client 20.250.13.23:53660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/buy.php"] [unique_id "aoSBKtO5rbWdOArH04KoLgAAATo"]
[Tue Aug 18 12:58:34.601467 2026] [security2:error] [pid 66623:tid 66883] [client 20.79.204.6:12236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSBKtO5rbWdOArH04KoOAAAAX8"]
[Tue Aug 18 12:58:34.614414 2026] [security2:error] [pid 66623:tid 66788] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBKtO5rbWdOArH04KoOQAAASA"]
[Tue Aug 18 12:58:34.623466 2026] [security2:error] [pid 66623:tid 66806] [client 138.36.100.162:42094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKtO5rbWdOArH04KoPAAAATI"]
[Tue Aug 18 12:58:34.623572 2026] [security2:error] [pid 66623:tid 66806] [client 138.36.100.162:42094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKtO5rbWdOArH04KoPAAAATI"]
[Tue Aug 18 12:58:34.631075 2026] [security2:error] [pid 66623:tid 66815] [client 40.74.65.169:20320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBKtO5rbWdOArH04KoPQAAATs"]
[Tue Aug 18 12:58:34.637053 2026] [security2:error] [pid 66623:tid 66658] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/includes/header.php"] [unique_id "aoSBKtO5rbWdOArH04KoPgABWBU"]
[Tue Aug 18 12:58:34.645128 2026] [security2:error] [pid 66623:tid 66863] [client 52.173.121.69:42732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/bhfnd.php"] [unique_id "aoSBKtO5rbWdOArH04KoPwAAAWs"]
[Tue Aug 18 12:58:34.669559 2026] [authz_core:error] [pid 66623:tid 66729] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:34.669836 2026] [authz_core:error] [pid 66623:tid 66729] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:34.686672 2026] [security2:error] [pid 66623:tid 66875] [client 74.248.18.37:8116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/maintenance.php"] [unique_id "aoSBKtO5rbWdOArH04KoQwAAAXc"]
[Tue Aug 18 12:58:34.686689 2026] [security2:error] [pid 66623:tid 66877] [client 74.248.18.37:7692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/sid4.php"] [unique_id "aoSBKtO5rbWdOArH04KoRAAAAXk"]
[Tue Aug 18 12:58:34.704697 2026] [security2:error] [pid 66623:tid 66820] [client 20.104.85.180:42269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/zxz.php"] [unique_id "aoSBKtO5rbWdOArH04KoRgAAAUA"]
[Tue Aug 18 12:58:34.706798 2026] [security2:error] [pid 66623:tid 66869] [client 20.118.172.148:19662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/inputs.php"] [unique_id "aoSBKtO5rbWdOArH04KoRwAAAXE"]
[Tue Aug 18 12:58:34.764780 2026] [security2:error] [pid 66623:tid 66805] [client 20.119.58.187:11986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "aoSBKtO5rbWdOArH04KoSQAAATE"]
[Tue Aug 18 12:58:34.806976 2026] [security2:error] [pid 66623:tid 66697] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kk.php"] [unique_id "aoSBKtO5rbWdOArH04KoUgABGDw"]
[Tue Aug 18 12:58:34.815442 2026] [security2:error] [pid 66623:tid 66711] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/index.php"] [unique_id "aoSBKtO5rbWdOArH04KoVAABaEo"]
[Tue Aug 18 12:58:34.859105 2026] [security2:error] [pid 66623:tid 66781] [client 158.23.17.4:34020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/nf.php"] [unique_id "aoSBKtO5rbWdOArH04KoWQAAARk"]
[Tue Aug 18 12:58:34.939917 2026] [security2:error] [pid 66623:tid 66773] [client 4.232.151.198:30020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/themes/sky-pro/js.php"] [unique_id "aoSBKtO5rbWdOArH04KoWgAAARE"]
[Tue Aug 18 12:58:34.970345 2026] [authz_core:error] [pid 66623:tid 66758] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:34.970624 2026] [authz_core:error] [pid 66623:tid 66758] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:34.980048 2026] [security2:error] [pid 66623:tid 66827] [client 20.118.133.132:26302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/puc.php"] [unique_id "aoSBKtO5rbWdOArH04KoXQAAAUc"]
[Tue Aug 18 12:58:35.000385 2026] [security2:error] [pid 66623:tid 66701] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/phpcheck.php"] [unique_id "aoSBKtO5rbWdOArH04KoXwABdEA"]
[Tue Aug 18 12:58:35.012617 2026] [security2:error] [pid 66623:tid 66880] [client 68.155.155.199:3150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/abcd.php"] [unique_id "aoSBK9O5rbWdOArH04KoYAAAAXw"]
[Tue Aug 18 12:58:35.043307 2026] [autoindex:error] [pid 66623:tid 66717] [remote 68.155.154.146:0] AH01276: Cannot serve directory /home4/bioclimaarcondic/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:35.088566 2026] [security2:error] [pid 66623:tid 66828] [client 52.173.121.69:50189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/qfvqu.php"] [unique_id "aoSBK9O5rbWdOArH04KoZgAAAUg"]
[Tue Aug 18 12:58:35.099622 2026] [security2:error] [pid 66623:tid 66774] [client 20.127.136.245:17301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/av.php"] [unique_id "aoSBK9O5rbWdOArH04KoZwAAARI"]
[Tue Aug 18 12:58:35.114631 2026] [security2:error] [pid 66623:tid 66803] [client 178.153.171.161:9936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBK9O5rbWdOArH04KoaQAAAS8"]
[Tue Aug 18 12:58:35.114936 2026] [security2:error] [pid 66623:tid 66803] [client 178.153.171.161:9936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBK9O5rbWdOArH04KoaQAAAS8"]
[Tue Aug 18 12:58:35.128961 2026] [security2:error] [pid 66623:tid 66893] [client 213.35.127.232:52136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBK9O5rbWdOArH04KoawAAAYk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:35.182462 2026] [security2:error] [pid 66623:tid 66847] [client 20.119.58.187:12017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/classsmtps.php"] [unique_id "aoSBK9O5rbWdOArH04KobAAAAVs"]
[Tue Aug 18 12:58:35.204391 2026] [security2:error] [pid 66623:tid 66675] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBK9O5rbWdOArH04KobQABhCY"]
[Tue Aug 18 12:58:35.204539 2026] [security2:error] [pid 66623:tid 66888] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBK9O5rbWdOArH04KobQABhCY"]
[Tue Aug 18 12:58:35.207275 2026] [security2:error] [pid 66623:tid 66688] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/dg.php"] [unique_id "aoSBK9O5rbWdOArH04KocAABUDM"]
[Tue Aug 18 12:58:35.219262 2026] [autoindex:error] [pid 66623:tid 66808] [client 20.79.204.6:11688] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:35.247190 2026] [security2:error] [pid 66623:tid 66835] [client 20.250.13.23:1812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/cong.php"] [unique_id "aoSBK9O5rbWdOArH04KodQAAAU8"]
[Tue Aug 18 12:58:35.267833 2026] [authz_core:error] [pid 66623:tid 66746] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:35.268107 2026] [authz_core:error] [pid 66623:tid 66746] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:35.285502 2026] [security2:error] [pid 66623:tid 66816] [client 20.104.85.180:54563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/www.php"] [unique_id "aoSBK9O5rbWdOArH04KoeQAAATw"]
[Tue Aug 18 12:58:35.294951 2026] [security2:error] [pid 66623:tid 66814] [client 40.74.65.169:56423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/chosen.php"] [unique_id "aoSBK9O5rbWdOArH04KoegAAATo"]
[Tue Aug 18 12:58:35.296575 2026] [autoindex:error] [pid 66623:tid 66757] [remote 68.155.154.146:0] AH01276: Cannot serve directory /home4/bioclimaarcondic/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:35.336197 2026] [security2:error] [pid 66623:tid 66853] [client 40.74.65.169:19460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBK9O5rbWdOArH04KofAAAAWE"]
[Tue Aug 18 12:58:35.349096 2026] [security2:error] [pid 66623:tid 66815] [client 52.173.121.69:16473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/index/function.php"] [unique_id "aoSBK9O5rbWdOArH04KofQAAATs"]
[Tue Aug 18 12:58:35.367534 2026] [security2:error] [pid 66623:tid 66770] [client 20.118.172.148:63079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBK9O5rbWdOArH04KofwAAAQ4"]
[Tue Aug 18 12:58:35.420339 2026] [security2:error] [pid 66623:tid 66807] [client 20.79.204.6:11688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-themes.php"] [unique_id "aoSBK9O5rbWdOArH04KogQAAATM"]
[Tue Aug 18 12:58:35.436032 2026] [security2:error] [pid 66623:tid 66708] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/bm.php"] [unique_id "aoSBK9O5rbWdOArH04KohAABgkc"]
[Tue Aug 18 12:58:35.487149 2026] [security2:error] [pid 66623:tid 66750] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/link-add.php"] [unique_id "aoSBK9O5rbWdOArH04KoiAABP3E"]
[Tue Aug 18 12:58:35.535904 2026] [security2:error] [pid 66623:tid 66820] [client 20.119.58.187:11877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSBK9O5rbWdOArH04KojAAAAUA"]
[Tue Aug 18 12:58:35.538212 2026] [security2:error] [pid 66623:tid 66829] [client 52.173.121.69:49021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/oivcl.php"] [unique_id "aoSBK9O5rbWdOArH04KojQAAAUk"]
[Tue Aug 18 12:58:35.572816 2026] [authz_core:error] [pid 66623:tid 66761] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:35.573253 2026] [authz_core:error] [pid 66623:tid 66761] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:35.578915 2026] [security2:error] [pid 66623:tid 66801] [client 20.48.236.86:36116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/dcsgumnm.php"] [unique_id "aoSBK9O5rbWdOArH04KokAAAAS0"]
[Tue Aug 18 12:58:35.605272 2026] [security2:error] [pid 66623:tid 66879] [client 158.23.17.4:44857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/xv.php"] [unique_id "aoSBK9O5rbWdOArH04KomAAAAXs"]
[Tue Aug 18 12:58:35.624083 2026] [security2:error] [pid 66623:tid 66810] [client 20.100.169.31:32767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBK9O5rbWdOArH04KonQAAATY"]
[Tue Aug 18 12:58:35.633733 2026] [security2:error] [pid 66623:tid 66773] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/BDKR28WP.php"] [unique_id "aoSBK9O5rbWdOArH04KongAAARE"]
[Tue Aug 18 12:58:35.637397 2026] [security2:error] [pid 66623:tid 66648] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/vu.php"] [unique_id "aoSBK9O5rbWdOArH04KonwABWgs"]
[Tue Aug 18 12:58:35.669197 2026] [security2:error] [pid 66623:tid 66775] [client 74.248.18.37:47288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/size.php"] [unique_id "aoSBK9O5rbWdOArH04KooQAAARM"]
[Tue Aug 18 12:58:35.670739 2026] [security2:error] [pid 66623:tid 66686] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/login.php"] [unique_id "aoSBK9O5rbWdOArH04KoogABUzE"]
[Tue Aug 18 12:58:35.692429 2026] [security2:error] [pid 66623:tid 66864] [client 74.248.18.37:47238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/network/about.php"] [unique_id "aoSBK9O5rbWdOArH04KopAAAAWw"]
[Tue Aug 18 12:58:35.706983 2026] [security2:error] [pid 66623:tid 66774] [client 20.104.85.180:50341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wicked.php"] [unique_id "aoSBK9O5rbWdOArH04KopQAAARI"]
[Tue Aug 18 12:58:35.765459 2026] [security2:error] [pid 66623:tid 66849] [client 20.206.73.37:59919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/uwu.php"] [unique_id "aoSBK9O5rbWdOArH04KopwAAAV0"]
[Tue Aug 18 12:58:35.789460 2026] [security2:error] [pid 66623:tid 66851] [client 223.185.37.47:3937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBK9O5rbWdOArH04KoqAAAAV8"]
[Tue Aug 18 12:58:35.789564 2026] [security2:error] [pid 66623:tid 66851] [client 223.185.37.47:3937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBK9O5rbWdOArH04KoqAAAAV8"]
[Tue Aug 18 12:58:35.793257 2026] [security2:error] [pid 66623:tid 66882] [client 4.232.151.198:6104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/images/Mhbgf.php"] [unique_id "aoSBK9O5rbWdOArH04KoqQAAAX4"]
[Tue Aug 18 12:58:35.815669 2026] [security2:error] [pid 66623:tid 66653] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ic.php"] [unique_id "aoSBK9O5rbWdOArH04KorQABhBA"]
[Tue Aug 18 12:58:35.821752 2026] [security2:error] [pid 66623:tid 66811] [client 85.154.68.202:57796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBK9O5rbWdOArH04KorwAAATc"]
[Tue Aug 18 12:58:35.821894 2026] [security2:error] [pid 66623:tid 66811] [client 85.154.68.202:57796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBK9O5rbWdOArH04KorwAAATc"]
[Tue Aug 18 12:58:35.833265 2026] [security2:error] [pid 66623:tid 66737] [remote 172.238.58.237:50604] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "cargaedescargatiofe.com.br"] [uri "/"] [unique_id "aoSBK9O5rbWdOArH04KosAABdGQ"]
[Tue Aug 18 12:58:35.853175 2026] [security2:error] [pid 66623:tid 66755] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/min.php"] [unique_id "aoSBK9O5rbWdOArH04KosQABKHY"]
[Tue Aug 18 12:58:35.863141 2026] [security2:error] [pid 66623:tid 66837] [client 20.250.13.23:45753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSBK9O5rbWdOArH04KotAAAAVE"]
[Tue Aug 18 12:58:35.869089 2026] [authz_core:error] [pid 66623:tid 66647] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:35.869380 2026] [authz_core:error] [pid 66623:tid 66647] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:35.887979 2026] [security2:error] [pid 66623:tid 66868] [client 20.119.58.187:11879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSBK9O5rbWdOArH04KotgAAAXA"]
[Tue Aug 18 12:58:35.901601 2026] [security2:error] [pid 66623:tid 66771] [client 20.203.138.185:27979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSBK9O5rbWdOArH04KouQAAAQ8"]
[Tue Aug 18 12:58:35.970186 2026] [security2:error] [pid 66623:tid 66856] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/sky.php"] [unique_id "aoSBK9O5rbWdOArH04KovAAAAWQ"]
[Tue Aug 18 12:58:35.989944 2026] [security2:error] [pid 66623:tid 66853] [client 40.74.65.169:55812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/thoms.php"] [unique_id "aoSBK9O5rbWdOArH04KovgAAAWE"]
[Tue Aug 18 12:58:36.003796 2026] [security2:error] [pid 66623:tid 66763] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ue.php"] [unique_id "aoSBLNO5rbWdOArH04KovwABa34"]
[Tue Aug 18 12:58:36.036332 2026] [security2:error] [pid 66623:tid 66776] [client 40.74.65.169:20102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/domvf.php"] [unique_id "aoSBLNO5rbWdOArH04KowgAAARQ"]
[Tue Aug 18 12:58:36.043898 2026] [security2:error] [pid 66623:tid 66639] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBLNO5rbWdOArH04KowwABTQI"]
[Tue Aug 18 12:58:36.048398 2026] [access_compat:error] [pid 66623:tid 66881] [client 173.252.70.82:41546] AH01797: client denied by server configuration: /home1/canabarro/public_html/meta.json
[Tue Aug 18 12:58:36.094841 2026] [security2:error] [pid 66623:tid 66854] [client 20.79.204.6:11702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBLNO5rbWdOArH04KoyQAAAWI"]
[Tue Aug 18 12:58:36.144848 2026] [security2:error] [pid 66623:tid 66817] [client 213.35.127.232:52316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBLNO5rbWdOArH04KoywAAAT0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:36.168073 2026] [security2:error] [pid 66623:tid 66820] [client 172.202.39.151:40338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBLNO5rbWdOArH04KozwAAAUA"]
[Tue Aug 18 12:58:36.171525 2026] [authz_core:error] [pid 66623:tid 66704] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:36.171798 2026] [authz_core:error] [pid 66623:tid 66704] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:36.174763 2026] [security2:error] [pid 66623:tid 66702] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/lr.php"] [unique_id "aoSBLNO5rbWdOArH04Ko0AABLUE"]
[Tue Aug 18 12:58:36.223887 2026] [security2:error] [pid 66623:tid 66714] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/network/post.php"] [unique_id "aoSBLNO5rbWdOArH04Ko1AABNk0"]
[Tue Aug 18 12:58:36.242770 2026] [security2:error] [pid 66623:tid 66825] [client 20.119.58.187:12508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-cron.php"] [unique_id "aoSBLNO5rbWdOArH04Ko1gAAAUU"]
[Tue Aug 18 12:58:36.265683 2026] [security2:error] [pid 66623:tid 66827] [client 52.173.121.69:35569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/zugvi.php"] [unique_id "aoSBLNO5rbWdOArH04Ko2AAAAUc"]
[Tue Aug 18 12:58:36.277490 2026] [security2:error] [pid 66623:tid 66839] [client 20.104.85.180:50320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSBLNO5rbWdOArH04Ko2QAAAVM"]
[Tue Aug 18 12:58:36.283068 2026] [security2:error] [pid 66623:tid 66850] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/file5.php"] [unique_id "aoSBLNO5rbWdOArH04Ko2gAAAV4"]
[Tue Aug 18 12:58:36.285437 2026] [security2:error] [pid 66623:tid 66823] [client 20.250.13.23:52081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBLNO5rbWdOArH04Ko2wAAAUM"]
[Tue Aug 18 12:58:36.324035 2026] [security2:error] [pid 66623:tid 66806] [client 20.104.85.180:1586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBLNO5rbWdOArH04Ko3QAAATI"]
[Tue Aug 18 12:58:36.331532 2026] [security2:error] [pid 66623:tid 66774] [client 4.232.94.69:54131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBLNO5rbWdOArH04Ko3gAAARI"]
[Tue Aug 18 12:58:36.351317 2026] [security2:error] [pid 66623:tid 66660] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ka.php"] [unique_id "aoSBLNO5rbWdOArH04Ko3wABLxc"]
[Tue Aug 18 12:58:36.363859 2026] [security2:error] [pid 66623:tid 66851] [client 68.155.155.199:11984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/admin.php"] [unique_id "aoSBLNO5rbWdOArH04Ko4QAAAV8"]
[Tue Aug 18 12:58:36.403613 2026] [security2:error] [pid 66623:tid 66718] [remote 172.238.58.237:50620] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "cargaedescargatiofe.com.br"] [uri "/"] [unique_id "aoSBLNO5rbWdOArH04Ko4wABW1E"]
[Tue Aug 18 12:58:36.413188 2026] [security2:error] [pid 66623:tid 66668] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/test.php"] [unique_id "aoSBLNO5rbWdOArH04Ko5QABhB8"]
[Tue Aug 18 12:58:36.414902 2026] [security2:error] [pid 66623:tid 66811] [client 20.215.241.237:62802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/82.php"] [unique_id "aoSBLNO5rbWdOArH04Ko5gAAATc"]
[Tue Aug 18 12:58:36.426243 2026] [security2:error] [pid 66623:tid 66819] [client 74.248.18.37:7696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/special.php"] [unique_id "aoSBLNO5rbWdOArH04Ko5wAAAT8"]
[Tue Aug 18 12:58:36.432460 2026] [security2:error] [pid 66623:tid 66780] [client 74.248.18.37:47261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBLNO5rbWdOArH04Ko6AAAARg"]
[Tue Aug 18 12:58:36.473510 2026] [authz_core:error] [pid 66623:tid 66680] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:36.473804 2026] [authz_core:error] [pid 66623:tid 66680] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:36.489361 2026] [security2:error] [pid 66623:tid 66876] [client 20.100.169.31:12296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/NewFile.php"] [unique_id "aoSBLNO5rbWdOArH04Ko6wAAAXg"]
[Tue Aug 18 12:58:36.525085 2026] [security2:error] [pid 66623:tid 66791] [client 20.250.13.23:1807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/db.php"] [unique_id "aoSBLNO5rbWdOArH04Ko7wAAASM"]
[Tue Aug 18 12:58:36.533675 2026] [security2:error] [pid 66623:tid 66638] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ot.php"] [unique_id "aoSBLNO5rbWdOArH04Ko8QABbwE"]
[Tue Aug 18 12:58:36.592841 2026] [security2:error] [pid 66623:tid 66642] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/themes/themes/wp-cron.php"] [unique_id "aoSBLNO5rbWdOArH04Ko9AABbgU"]
[Tue Aug 18 12:58:36.596365 2026] [security2:error] [pid 66623:tid 66824] [client 52.173.121.69:6111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSBLNO5rbWdOArH04Ko9QAAAUQ"]
[Tue Aug 18 12:58:36.600022 2026] [security2:error] [pid 66623:tid 66769] [client 20.119.58.187:11899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-load.php"] [unique_id "aoSBLNO5rbWdOArH04Ko9gAAAQ0"]
[Tue Aug 18 12:58:36.600119 2026] [security2:error] [pid 66623:tid 66856] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/xyn.php"] [unique_id "aoSBLNO5rbWdOArH04Ko9wAAAWQ"]
[Tue Aug 18 12:58:36.656761 2026] [security2:error] [pid 66623:tid 66840] [client 4.232.151.198:6090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/images/cloud.php"] [unique_id "aoSBLNO5rbWdOArH04Ko-gAAAVQ"]
[Tue Aug 18 12:58:36.706158 2026] [security2:error] [pid 66623:tid 66783] [client 20.104.85.180:47138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBLNO5rbWdOArH04Ko_AAAARs"]
[Tue Aug 18 12:58:36.725299 2026] [security2:error] [pid 66623:tid 66804] [client 40.74.65.169:20300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSBLNO5rbWdOArH04Ko_QAAATA"]
[Tue Aug 18 12:58:36.732709 2026] [security2:error] [pid 66623:tid 66859] [client 158.23.17.4:8908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/mx.php"] [unique_id "aoSBLNO5rbWdOArH04Ko_gAAAWc"]
[Tue Aug 18 12:58:36.754257 2026] [security2:error] [pid 66623:tid 66852] [client 40.74.65.169:56386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/wpxml.php"] [unique_id "aoSBLNO5rbWdOArH04KpAQAAAWA"]
[Tue Aug 18 12:58:36.777619 2026] [security2:error] [pid 66623:tid 66820] [client 20.48.236.86:2791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/php.php"] [unique_id "aoSBLNO5rbWdOArH04KpAwAAAUA"]
[Tue Aug 18 12:58:36.780191 2026] [security2:error] [pid 66623:tid 66728] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ih.php"] [unique_id "aoSBLNO5rbWdOArH04KpBAABg1s"]
[Tue Aug 18 12:58:36.841898 2026] [security2:error] [pid 66623:tid 66879] [client 20.127.136.245:7631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp.php"] [unique_id "aoSBLNO5rbWdOArH04KpBgAAAXs"]
[Tue Aug 18 12:58:36.923153 2026] [security2:error] [pid 66623:tid 66839] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBLNO5rbWdOArH04KpCgAAAVM"]
[Tue Aug 18 12:58:36.941219 2026] [security2:error] [pid 66623:tid 66864] [client 52.173.121.69:32607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wsrer.php"] [unique_id "aoSBLNO5rbWdOArH04KpDgAAAWw"]
[Tue Aug 18 12:58:36.952274 2026] [security2:error] [pid 66623:tid 66678] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/k.php"] [unique_id "aoSBLNO5rbWdOArH04KpEAABICk"]
[Tue Aug 18 12:58:36.962487 2026] [security2:error] [pid 66623:tid 66719] [remote 172.238.58.237:50626] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "cargaedescargatiofe.com.br"] [uri "/"] [unique_id "aoSBLNO5rbWdOArH04KpEQABGVI"]
[Tue Aug 18 12:58:36.969280 2026] [security2:error] [pid 66623:tid 66860] [client 20.119.58.187:12242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-activate.php"] [unique_id "aoSBLNO5rbWdOArH04KpEgAAAWg"]
[Tue Aug 18 12:58:37.023597 2026] [security2:error] [pid 66623:tid 66803] [client 20.118.172.148:43485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/lite.php"] [unique_id "aoSBLdO5rbWdOArH04KpEwAAAS8"]
[Tue Aug 18 12:58:37.078473 2026] [authz_core:error] [pid 66623:tid 66646] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:37.078760 2026] [authz_core:error] [pid 66623:tid 66646] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:37.084440 2026] [security2:error] [pid 66623:tid 66689] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/user/min.php"] [unique_id "aoSBLdO5rbWdOArH04KpFwABfjQ"]
[Tue Aug 18 12:58:37.105483 2026] [security2:error] [pid 66623:tid 66825] [client 74.248.18.37:8127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/options-privacy.php"] [unique_id "aoSBLdO5rbWdOArH04KpGAAAAUU"]
[Tue Aug 18 12:58:37.137322 2026] [security2:error] [pid 66623:tid 66823] [client 20.250.13.23:1822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/dropdown.php"] [unique_id "aoSBLdO5rbWdOArH04KpGgAAAUM"]
[Tue Aug 18 12:58:37.155655 2026] [security2:error] [pid 66623:tid 66807] [client 213.35.127.232:52544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBLdO5rbWdOArH04KpHgAAATM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:37.158884 2026] [authz_core:error] [pid 66623:tid 66745] [remote 57.141.22.95:45588] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:37.159158 2026] [authz_core:error] [pid 66623:tid 66745] [remote 57.141.22.95:45588] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:37.160336 2026] [security2:error] [pid 66623:tid 66797] [client 68.155.155.199:7036] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/admin/controller/extension/extension/"] [unique_id "aoSBLdO5rbWdOArH04KpHwAAASk"]
[Tue Aug 18 12:58:37.162711 2026] [security2:error] [pid 66623:tid 66731] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/iu.php"] [unique_id "aoSBLdO5rbWdOArH04KpIAABRl4"]
[Tue Aug 18 12:58:37.178696 2026] [security2:error] [pid 66623:tid 66780] [client 20.203.138.185:10812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/z.php"] [unique_id "aoSBLdO5rbWdOArH04KpIQAAARg"]
[Tue Aug 18 12:58:37.185229 2026] [security2:error] [pid 66623:tid 66846] [client 74.248.18.37:7690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ssjpxze.php"] [unique_id "aoSBLdO5rbWdOArH04KpIgAAAVo"]
[Tue Aug 18 12:58:37.187417 2026] [security2:error] [pid 66623:tid 66811] [client 192.141.172.134:51411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBLdO5rbWdOArH04KpIwAAATc"]
[Tue Aug 18 12:58:37.187496 2026] [security2:error] [pid 66623:tid 66811] [client 192.141.172.134:51411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBLdO5rbWdOArH04KpIwAAATc"]
[Tue Aug 18 12:58:37.231551 2026] [security2:error] [pid 66623:tid 66873] [client 20.104.85.180:14053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/cah.php"] [unique_id "aoSBLdO5rbWdOArH04KpJwAAAXU"]
[Tue Aug 18 12:58:37.263574 2026] [security2:error] [pid 66623:tid 66733] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/users.php"] [unique_id "aoSBLdO5rbWdOArH04KpKAABQmA"]
[Tue Aug 18 12:58:37.286752 2026] [security2:error] [pid 66623:tid 66851] [client 4.232.151.198:62677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/router.php"] [unique_id "aoSBLdO5rbWdOArH04KpKQAAAV8"]
[Tue Aug 18 12:58:37.322677 2026] [security2:error] [pid 66623:tid 66796] [client 20.119.58.187:11979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/berlin.php"] [unique_id "aoSBLdO5rbWdOArH04KpKwAAASg"]
[Tue Aug 18 12:58:37.347858 2026] [security2:error] [pid 66623:tid 66756] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/pk.php"] [unique_id "aoSBLdO5rbWdOArH04KpLAABaXc"]
[Tue Aug 18 12:58:37.375071 2026] [authz_core:error] [pid 66623:tid 66694] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:37.375354 2026] [authz_core:error] [pid 66623:tid 66694] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:37.404746 2026] [security2:error] [pid 66623:tid 66842] [client 40.74.65.169:42467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/gec.php"] [unique_id "aoSBLdO5rbWdOArH04KpNQAAAVY"]
[Tue Aug 18 12:58:37.444557 2026] [security2:error] [pid 66623:tid 66645] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/wp-activate.php"] [unique_id "aoSBLdO5rbWdOArH04KpNgABRAg"]
[Tue Aug 18 12:58:37.521656 2026] [security2:error] [pid 66623:tid 66799] [client 20.100.169.31:29059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSBLdO5rbWdOArH04KpOgAAASs"]
[Tue Aug 18 12:58:37.552531 2026] [security2:error] [pid 66623:tid 66710] [remote 172.238.58.237:50634] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "cargaedescargatiofe.com.br"] [uri "/"] [unique_id "aoSBLdO5rbWdOArH04KpPAABhkk"]
[Tue Aug 18 12:58:37.556682 2026] [security2:error] [pid 66623:tid 66685] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ge.php"] [unique_id "aoSBLdO5rbWdOArH04KpPwABiDA"]
[Tue Aug 18 12:58:37.590992 2026] [security2:error] [pid 66623:tid 66783] [client 40.74.65.169:56421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/file1221.php"] [unique_id "aoSBLdO5rbWdOArH04KpQgAAARs"]
[Tue Aug 18 12:58:37.633874 2026] [security2:error] [pid 66623:tid 66726] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/wp-load.php"] [unique_id "aoSBLdO5rbWdOArH04KpRAABV1k"]
[Tue Aug 18 12:58:37.679131 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:37.679579 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:37.709843 2026] [security2:error] [pid 66623:tid 66854] [client 20.48.236.86:2753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/sf.php"] [unique_id "aoSBLdO5rbWdOArH04KpSAAAAWI"]
[Tue Aug 18 12:58:37.710962 2026] [security2:error] [pid 66623:tid 66848] [client 20.206.73.37:59940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/signon.php"] [unique_id "aoSBLdO5rbWdOArH04KpSQAAAVw"]
[Tue Aug 18 12:58:37.743108 2026] [security2:error] [pid 66623:tid 66790] [client 20.119.58.187:12014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/not/includes/php8.php"] [unique_id "aoSBLdO5rbWdOArH04KpTAAAASI"]
[Tue Aug 18 12:58:37.751584 2026] [security2:error] [pid 66623:tid 66840] [client 20.250.13.23:45698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/file.php"] [unique_id "aoSBLdO5rbWdOArH04KpTgAAAVQ"]
[Tue Aug 18 12:58:37.768137 2026] [security2:error] [pid 66623:tid 66818] [client 52.173.121.69:50205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/ucpfr.php"] [unique_id "aoSBLdO5rbWdOArH04KpTwAAAT4"]
[Tue Aug 18 12:58:37.782524 2026] [security2:error] [pid 66623:tid 66752] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kl.php"] [unique_id "aoSBLdO5rbWdOArH04KpUQABNnM"]
[Tue Aug 18 12:58:37.805880 2026] [security2:error] [pid 66623:tid 66877] [client 74.248.18.37:7695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/options.php"] [unique_id "aoSBLdO5rbWdOArH04KpUwAAAXk"]
[Tue Aug 18 12:58:37.811089 2026] [security2:error] [pid 66623:tid 66777] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/inso.php"] [unique_id "aoSBLdO5rbWdOArH04KpVAAAARU"]
[Tue Aug 18 12:58:37.816455 2026] [security2:error] [pid 66623:tid 66717] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/wp-login.php"] [unique_id "aoSBLdO5rbWdOArH04KpVgABZVA"]
[Tue Aug 18 12:58:37.877856 2026] [security2:error] [pid 66623:tid 66886] [client 74.248.18.37:7171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/storage/index.php"] [unique_id "aoSBLdO5rbWdOArH04KpWgAAAYI"]
[Tue Aug 18 12:58:37.928381 2026] [security2:error] [pid 66623:tid 66882] [client 20.104.85.180:50357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/system_log.php"] [unique_id "aoSBLdO5rbWdOArH04KpXQAAAX4"]
[Tue Aug 18 12:58:37.928863 2026] [security2:error] [pid 66623:tid 66767] [client 79.127.164.8:45708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/sessions.bak"] [unique_id "aoSBLdO5rbWdOArH04KpXAAAAQs"], referer: https://medihub.com.br/sessions.bak
[Tue Aug 18 12:58:37.978226 2026] [authz_core:error] [pid 66623:tid 66663] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:37.978494 2026] [authz_core:error] [pid 66623:tid 66663] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:37.991999 2026] [security2:error] [pid 66623:tid 66661] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/wp-mail.php"] [unique_id "aoSBLdO5rbWdOArH04KpYgABKRg"]
[Tue Aug 18 12:58:38.008566 2026] [security2:error] [pid 66623:tid 66677] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gs.php"] [unique_id "aoSBLtO5rbWdOArH04KpZAABRig"]
[Tue Aug 18 12:58:38.038794 2026] [security2:error] [pid 66623:tid 66839] [client 4.232.151.198:6139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/shop.php"] [unique_id "aoSBLtO5rbWdOArH04KpZgAAAVM"]
[Tue Aug 18 12:58:38.060106 2026] [security2:error] [pid 66623:tid 66812] [client 216.73.161.209:45265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-login.php"] [unique_id "aoSBLtO5rbWdOArH04KpaAAAATg"], referer: https://ozzyfernandesoficial.com.br/wp-login.php
[Tue Aug 18 12:58:38.089677 2026] [security2:error] [pid 66623:tid 66837] [client 40.74.65.169:42490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/sky.php"] [unique_id "aoSBLtO5rbWdOArH04KpagAAAVE"]
[Tue Aug 18 12:58:38.100784 2026] [security2:error] [pid 66623:tid 66830] [client 20.119.58.187:12499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/wp-theme-editor/php8.php/wp-content/themes/aahana/json.php"] [unique_id "aoSBLtO5rbWdOArH04KpbAAAAUo"]
[Tue Aug 18 12:58:38.131915 2026] [security2:error] [pid 66623:tid 66789] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/puc.php"] [unique_id "aoSBLtO5rbWdOArH04KpbQAAASE"]
[Tue Aug 18 12:58:38.168991 2026] [security2:error] [pid 66623:tid 66871] [client 213.35.127.232:52755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBLtO5rbWdOArH04KpcQAAAXM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:38.171931 2026] [security2:error] [pid 66623:tid 66736] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/wp-settings.php"] [unique_id "aoSBLtO5rbWdOArH04KpcgABD2M"]
[Tue Aug 18 12:58:38.172945 2026] [security2:error] [pid 66623:tid 66893] [client 172.202.39.151:44491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/gelay.php"] [unique_id "aoSBLtO5rbWdOArH04KpcwAAAYk"]
[Tue Aug 18 12:58:38.186115 2026] [security2:error] [pid 66623:tid 66758] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/lw.php"] [unique_id "aoSBLtO5rbWdOArH04KpdAABJ3k"]
[Tue Aug 18 12:58:38.245706 2026] [security2:error] [pid 66623:tid 66884] [client 4.232.94.69:44571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/x.php"] [unique_id "aoSBLtO5rbWdOArH04KpdwAAAYA"]
[Tue Aug 18 12:58:38.282409 2026] [security2:error] [pid 66623:tid 66799] [client 40.74.65.169:56410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/nox.php"] [unique_id "aoSBLtO5rbWdOArH04KpfAAAASs"]
[Tue Aug 18 12:58:38.342547 2026] [authz_core:error] [pid 66623:tid 66656] [remote 57.141.22.123:20168] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:38.342830 2026] [authz_core:error] [pid 66623:tid 66656] [remote 57.141.22.123:20168] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:38.354420 2026] [security2:error] [pid 66623:tid 66831] [client 52.173.121.69:51281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/yxijx.php"] [unique_id "aoSBLtO5rbWdOArH04KpgQAAAUs"]
[Tue Aug 18 12:58:38.355222 2026] [security2:error] [pid 66623:tid 66648] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/x.php"] [unique_id "aoSBLtO5rbWdOArH04KpggABfQs"]
[Tue Aug 18 12:58:38.364356 2026] [security2:error] [pid 66623:tid 66869] [client 158.23.17.4:33418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/45.php"] [unique_id "aoSBLtO5rbWdOArH04KpgwAAAXE"]
[Tue Aug 18 12:58:38.365212 2026] [security2:error] [pid 66623:tid 66867] [client 20.250.13.23:17835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/goods.php"] [unique_id "aoSBLtO5rbWdOArH04KphAAAAW8"]
[Tue Aug 18 12:58:38.443676 2026] [security2:error] [pid 66623:tid 66848] [client 20.104.85.180:28658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/f35.php"] [unique_id "aoSBLtO5rbWdOArH04KpjgAAAVw"]
[Tue Aug 18 12:58:38.443886 2026] [security2:error] [pid 66623:tid 66859] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/19.php"] [unique_id "aoSBLtO5rbWdOArH04KpjwAAAWc"]
[Tue Aug 18 12:58:38.445021 2026] [security2:error] [pid 66623:tid 66737] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/vj.php"] [unique_id "aoSBLtO5rbWdOArH04KpkAABZ2Q"]
[Tue Aug 18 12:58:38.454688 2026] [security2:error] [pid 66623:tid 66809] [client 20.119.58.187:11893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/Requests/php8.php"] [unique_id "aoSBLtO5rbWdOArH04KpkQAAATU"]
[Tue Aug 18 12:58:38.485993 2026] [security2:error] [pid 66623:tid 66820] [client 20.203.138.185:24300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/222.php"] [unique_id "aoSBLtO5rbWdOArH04KpkwAAAUA"]
[Tue Aug 18 12:58:38.504779 2026] [security2:error] [pid 66623:tid 66793] [client 68.155.155.199:6207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBLtO5rbWdOArH04KplQAAASU"]
[Tue Aug 18 12:58:38.534080 2026] [security2:error] [pid 66623:tid 66676] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-blogs.php"] [unique_id "aoSBLtO5rbWdOArH04KplgABNic"]
[Tue Aug 18 12:58:38.591168 2026] [security2:error] [pid 66623:tid 66838] [client 172.182.200.96:7674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSBLtO5rbWdOArH04KpmQAAAVI"]
[Tue Aug 18 12:58:38.604161 2026] [security2:error] [pid 66623:tid 66864] [client 20.48.236.86:2359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/xx.php"] [unique_id "aoSBLtO5rbWdOArH04KpmgAAAWw"]
[Tue Aug 18 12:58:38.631429 2026] [security2:error] [pid 66623:tid 66804] [client 74.248.18.37:47232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/plugin-install.php"] [unique_id "aoSBLtO5rbWdOArH04KpmwAAATA"]
[Tue Aug 18 12:58:38.662904 2026] [security2:error] [pid 66623:tid 66643] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/mimes.php"] [unique_id "aoSBLtO5rbWdOArH04KpnAABLwY"]
[Tue Aug 18 12:58:38.668986 2026] [security2:error] [pid 66623:tid 66889] [client 20.104.85.180:15163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSBLtO5rbWdOArH04KpogAAAYU"]
[Tue Aug 18 12:58:38.671028 2026] [security2:error] [pid 66623:tid 66790] [client 4.232.151.198:30064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-info.php"] [unique_id "aoSBLtO5rbWdOArH04KpowAAASI"]
[Tue Aug 18 12:58:38.703147 2026] [security2:error] [pid 66623:tid 66882] [client 20.118.133.132:26254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/19.php"] [unique_id "aoSBLtO5rbWdOArH04KppQAAAX4"]
[Tue Aug 18 12:58:38.726024 2026] [security2:error] [pid 66623:tid 66847] [client 52.173.121.69:24994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/Cachex.php"] [unique_id "aoSBLtO5rbWdOArH04KppwAAAVs"]
[Tue Aug 18 12:58:38.736407 2026] [security2:error] [pid 66623:tid 66700] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-content.attacker-decoy/themes/test.php"] [unique_id "aoSBLtO5rbWdOArH04KpqQABGj8"]
[Tue Aug 18 12:58:38.743671 2026] [security2:error] [pid 66623:tid 66780] [client 20.206.73.37:11959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/file61.php"] [unique_id "aoSBLtO5rbWdOArH04KpqwAAARg"]
[Tue Aug 18 12:58:38.776874 2026] [security2:error] [pid 66623:tid 66873] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/133.php"] [unique_id "aoSBLtO5rbWdOArH04KpswAAAXU"]
[Tue Aug 18 12:58:38.783945 2026] [security2:error] [pid 66623:tid 66851] [client 40.74.65.169:20125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/sixxis.php"] [unique_id "aoSBLtO5rbWdOArH04KptAAAAV8"]
[Tue Aug 18 12:58:38.822142 2026] [security2:error] [pid 66623:tid 66767] [client 20.119.58.187:11995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/SimplePie/php8.php"] [unique_id "aoSBLtO5rbWdOArH04KpuQAAAQs"]
[Tue Aug 18 12:58:38.834765 2026] [security2:error] [pid 66623:tid 66879] [client 74.248.18.37:7711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/storage/rip.php"] [unique_id "aoSBLtO5rbWdOArH04KpugAAAXs"]
[Tue Aug 18 12:58:38.873131 2026] [security2:error] [pid 66623:tid 66825] [client 20.25.139.174:4645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/inputs.php"] [unique_id "aoSBLtO5rbWdOArH04KpwAAAAUU"]
[Tue Aug 18 12:58:38.927132 2026] [security2:error] [pid 66623:tid 66702] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ni.php"] [unique_id "aoSBLtO5rbWdOArH04KpwgABFEE"]
[Tue Aug 18 12:58:38.946536 2026] [security2:error] [pid 66623:tid 66831] [client 52.173.121.69:48992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/zwlsv.php"] [unique_id "aoSBLtO5rbWdOArH04KpxAAAAUs"]
[Tue Aug 18 12:58:38.979549 2026] [security2:error] [pid 66623:tid 66778] [client 20.250.13.23:45748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBLtO5rbWdOArH04KpyAAAARY"]
[Tue Aug 18 12:58:39.038037 2026] [security2:error] [pid 66623:tid 66764] [remote 162.43.94.44:53492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.94.43.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "holldyperfuracoes.com.br"] [uri "/wp-login.php"] [unique_id "aoSBL9O5rbWdOArH04KpygABYn8"]
[Tue Aug 18 12:58:39.126377 2026] [security2:error] [pid 66623:tid 66638] [remote 20.29.77.16:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "suporte.automasantos.com.br"] [uri "/1.php"] [unique_id "aoSBL9O5rbWdOArH04Kp1QABSQE"]
[Tue Aug 18 12:58:39.126493 2026] [security2:error] [pid 66623:tid 66638] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/1.php"] [unique_id "aoSBL9O5rbWdOArH04Kp1QABSQE"]
[Tue Aug 18 12:58:39.161214 2026] [security2:error] [pid 66623:tid 66868] [client 158.23.17.4:56716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/mo.php"] [unique_id "aoSBL9O5rbWdOArH04Kp2QAAAXA"]
[Tue Aug 18 12:58:39.165556 2026] [security2:error] [pid 66623:tid 66715] [remote 68.155.154.146:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-content/1.php"] [unique_id "aoSBL9O5rbWdOArH04Kp2gABKE4"]
[Tue Aug 18 12:58:39.165641 2026] [security2:error] [pid 66623:tid 66715] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-content/1.php"] [unique_id "aoSBL9O5rbWdOArH04Kp2gABKE4"]
[Tue Aug 18 12:58:39.174695 2026] [security2:error] [pid 66623:tid 66852] [client 20.119.58.187:11991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/banners/php8.php"] [unique_id "aoSBL9O5rbWdOArH04Kp2wAAAWA"]
[Tue Aug 18 12:58:39.183112 2026] [authz_core:error] [pid 66623:tid 66647] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:39.183393 2026] [authz_core:error] [pid 66623:tid 66647] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:39.184669 2026] [security2:error] [pid 66623:tid 66787] [client 213.35.127.232:52954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBL9O5rbWdOArH04Kp3QAAAR8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:39.243122 2026] [security2:error] [pid 66623:tid 66803] [client 20.104.85.180:31259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBL9O5rbWdOArH04Kp4gAAAS8"]
[Tue Aug 18 12:58:39.253636 2026] [security2:error] [pid 66623:tid 66889] [client 172.202.39.151:44576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBL9O5rbWdOArH04Kp4wAAAYU"]
[Tue Aug 18 12:58:39.254016 2026] [security2:error] [pid 66623:tid 66874] [client 40.74.65.169:56443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/akismet.php"] [unique_id "aoSBL9O5rbWdOArH04Kp5AAAAXY"]
[Tue Aug 18 12:58:39.279221 2026] [security2:error] [pid 66623:tid 66878] [client 4.232.94.69:43563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/filemanager.php"] [unique_id "aoSBL9O5rbWdOArH04Kp5gAAAXo"]
[Tue Aug 18 12:58:39.306396 2026] [security2:error] [pid 66623:tid 66672] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/88.php"] [unique_id "aoSBL9O5rbWdOArH04Kp6AABhCM"]
[Tue Aug 18 12:58:39.342539 2026] [security2:error] [pid 66623:tid 66742] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBL9O5rbWdOArH04Kp6wABGGk"]
[Tue Aug 18 12:58:39.354570 2026] [security2:error] [pid 66623:tid 66826] [client 52.173.121.69:42688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/jrpga.php"] [unique_id "aoSBL9O5rbWdOArH04Kp7QAAAUY"]
[Tue Aug 18 12:58:39.389517 2026] [security2:error] [pid 66623:tid 66887] [client 74.248.18.37:8065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/wp-cron.php"] [unique_id "aoSBL9O5rbWdOArH04Kp7wAAAYM"]
[Tue Aug 18 12:58:39.393933 2026] [security2:error] [pid 66623:tid 66860] [client 20.25.139.174:4632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/admin.php"] [unique_id "aoSBL9O5rbWdOArH04Kp8AAAAWg"]
[Tue Aug 18 12:58:39.397038 2026] [security2:error] [pid 66623:tid 66769] [client 4.232.151.198:62672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/public_html/wp-content/uploads/users.php"] [unique_id "aoSBL9O5rbWdOArH04Kp8QAAAQ0"]
[Tue Aug 18 12:58:39.440973 2026] [security2:error] [pid 66623:tid 66830] [client 20.127.136.245:1567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/file2.php"] [unique_id "aoSBL9O5rbWdOArH04Kp9AAAAUo"]
[Tue Aug 18 12:58:39.472783 2026] [security2:error] [pid 66623:tid 66792] [client 40.74.65.169:20106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/yj09.php"] [unique_id "aoSBL9O5rbWdOArH04Kp9QAAASQ"]
[Tue Aug 18 12:58:39.484343 2026] [authz_core:error] [pid 66623:tid 66704] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:39.484611 2026] [authz_core:error] [pid 66623:tid 66704] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:39.492456 2026] [security2:error] [pid 66623:tid 66824] [client 196.12.128.158:59191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBL9O5rbWdOArH04Kp9wAAAUQ"]
[Tue Aug 18 12:58:39.492552 2026] [security2:error] [pid 66623:tid 66824] [client 196.12.128.158:59191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBL9O5rbWdOArH04Kp9wAAAUQ"]
[Tue Aug 18 12:58:39.496420 2026] [security2:error] [pid 66623:tid 66882] [client 74.248.18.37:47253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/sts.php"] [unique_id "aoSBL9O5rbWdOArH04Kp-AAAAX4"]
[Tue Aug 18 12:58:39.520368 2026] [security2:error] [pid 66623:tid 66649] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-content/api.php"] [unique_id "aoSBL9O5rbWdOArH04Kp-wABcgw"]
[Tue Aug 18 12:58:39.528618 2026] [security2:error] [pid 66623:tid 66785] [client 20.119.58.187:12005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/php8.php"] [unique_id "aoSBL9O5rbWdOArH04Kp_AAAAR0"]
[Tue Aug 18 12:58:39.565310 2026] [security2:error] [pid 66623:tid 66893] [client 20.104.85.180:14549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/inputs.php"] [unique_id "aoSBL9O5rbWdOArH04Kp_gAAAYk"]
[Tue Aug 18 12:58:39.565777 2026] [security2:error] [pid 66623:tid 66692] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/hj.php"] [unique_id "aoSBL9O5rbWdOArH04Kp_wABLDc"]
[Tue Aug 18 12:58:39.595617 2026] [security2:error] [pid 66623:tid 66866] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/1xmomo.php"] [unique_id "aoSBL9O5rbWdOArH04KqBAAAAW4"]
[Tue Aug 18 12:58:39.614258 2026] [security2:error] [pid 66623:tid 66812] [client 20.250.13.23:53661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/htaccess.php"] [unique_id "aoSBL9O5rbWdOArH04KqBQAAATg"]
[Tue Aug 18 12:58:39.720064 2026] [security2:error] [pid 66623:tid 66658] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-content/ccx/index.php"] [unique_id "aoSBL9O5rbWdOArH04KqGgABfRU"]
[Tue Aug 18 12:58:39.736646 2026] [authz_core:error] [pid 66623:tid 66734] [remote 57.141.22.114:31732] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:39.736924 2026] [authz_core:error] [pid 66623:tid 66734] [remote 57.141.22.114:31732] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:39.756934 2026] [security2:error] [pid 66623:tid 66801] [client 52.173.121.69:14860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/museu/yhweq.php"] [unique_id "aoSBL9O5rbWdOArH04KqHQAAAS0"]
[Tue Aug 18 12:58:39.788624 2026] [authz_core:error] [pid 66623:tid 66696] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:39.789065 2026] [authz_core:error] [pid 66623:tid 66696] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:39.809429 2026] [security2:error] [pid 66623:tid 66690] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ij.php"] [unique_id "aoSBL9O5rbWdOArH04KqIQABZzU"]
[Tue Aug 18 12:58:39.881626 2026] [security2:error] [pid 66623:tid 66828] [client 20.119.58.187:11867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/php8.php"] [unique_id "aoSBL9O5rbWdOArH04KqJgAAAUg"]
[Tue Aug 18 12:58:39.902387 2026] [security2:error] [pid 66623:tid 66717] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-content/db-status.php"] [unique_id "aoSBL9O5rbWdOArH04KqJwABFVA"]
[Tue Aug 18 12:58:39.908874 2026] [security2:error] [pid 66623:tid 66857] [client 68.155.155.199:6137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/akc.php"] [unique_id "aoSBL9O5rbWdOArH04KqKAAAAWU"]
[Tue Aug 18 12:58:39.909742 2026] [security2:error] [pid 66623:tid 66841] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/mosty.php"] [unique_id "aoSBL9O5rbWdOArH04KqKQAAAVU"]
[Tue Aug 18 12:58:39.943935 2026] [security2:error] [pid 66623:tid 66854] [client 20.25.139.174:4560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/goods.php"] [unique_id "aoSBL9O5rbWdOArH04KqKgAAAWI"]
[Tue Aug 18 12:58:39.950488 2026] [security2:error] [pid 66623:tid 66787] [client 20.203.138.185:15943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/G-in.php"] [unique_id "aoSBL9O5rbWdOArH04KqLAAAAR8"]
[Tue Aug 18 12:58:39.981945 2026] [security2:error] [pid 66623:tid 66766] [client 157.51.166.53:53483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBL9O5rbWdOArH04KqLgAAAQo"]
[Tue Aug 18 12:58:39.982119 2026] [security2:error] [pid 66623:tid 66766] [client 157.51.166.53:53483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBL9O5rbWdOArH04KqLgAAAQo"]
[Tue Aug 18 12:58:40.003756 2026] [security2:error] [pid 66623:tid 66805] [client 197.184.64.235:41945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBMNO5rbWdOArH04KqNQAAATE"]
[Tue Aug 18 12:58:40.003860 2026] [security2:error] [pid 66623:tid 66805] [client 197.184.64.235:41945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBMNO5rbWdOArH04KqNQAAATE"]
[Tue Aug 18 12:58:40.010844 2026] [security2:error] [pid 66623:tid 66809] [client 40.74.65.169:56430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/admin.php"] [unique_id "aoSBMNO5rbWdOArH04KqOAAAATU"]
[Tue Aug 18 12:58:40.027295 2026] [security2:error] [pid 66623:tid 66674] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ud.php"] [unique_id "aoSBMNO5rbWdOArH04KqOgABWyU"]
[Tue Aug 18 12:58:40.058098 2026] [security2:error] [pid 66623:tid 66840] [client 4.232.151.198:6130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/x.php"] [unique_id "aoSBMNO5rbWdOArH04KqPAAAAVQ"]
[Tue Aug 18 12:58:40.080879 2026] [security2:error] [pid 66623:tid 66713] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-content/endurance-page-cache/wp-content/module.php"] [unique_id "aoSBMNO5rbWdOArH04KqPgABGkw"]
[Tue Aug 18 12:58:40.132315 2026] [security2:error] [pid 66623:tid 66883] [client 20.104.85.180:27924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/abc.php"] [unique_id "aoSBMNO5rbWdOArH04KqPwAAAX8"]
[Tue Aug 18 12:58:40.161671 2026] [security2:error] [pid 66623:tid 66885] [client 40.74.65.169:43060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/k.php"] [unique_id "aoSBMNO5rbWdOArH04KqQwAAAYE"]
[Tue Aug 18 12:58:40.175216 2026] [security2:error] [pid 66623:tid 66830] [client 20.104.85.180:20259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/alfa.php"] [unique_id "aoSBMNO5rbWdOArH04KqRAAAAUo"]
[Tue Aug 18 12:58:40.198338 2026] [security2:error] [pid 66623:tid 66793] [client 213.35.127.232:53154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBMNO5rbWdOArH04KqRwAAASU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:40.226672 2026] [security2:error] [pid 66623:tid 66886] [client 20.250.13.23:45715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/images/wso.php"] [unique_id "aoSBMNO5rbWdOArH04KqSAAAAYI"]
[Tue Aug 18 12:58:40.226988 2026] [security2:error] [pid 66623:tid 66768] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/blurbs.php"] [unique_id "aoSBMNO5rbWdOArH04KqSQAAAQw"]
[Tue Aug 18 12:58:40.233903 2026] [security2:error] [pid 66623:tid 66870] [client 52.173.121.69:12163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/nwwha.php"] [unique_id "aoSBMNO5rbWdOArH04KqSwAAAXI"]
[Tue Aug 18 12:58:40.236651 2026] [security2:error] [pid 66623:tid 66846] [client 20.119.58.187:11850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/Text/php8.php"] [unique_id "aoSBMNO5rbWdOArH04KqTAAAAVo"]
[Tue Aug 18 12:58:40.254078 2026] [security2:error] [pid 66623:tid 66798] [client 74.248.18.37:8110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/wp-settings.php"] [unique_id "aoSBMNO5rbWdOArH04KqTQAAASo"]
[Tue Aug 18 12:58:40.255792 2026] [security2:error] [pid 66623:tid 66803] [client 74.248.18.37:47276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/system_log.php"] [unique_id "aoSBMNO5rbWdOArH04KqTgAAAS8"]
[Tue Aug 18 12:58:40.258336 2026] [security2:error] [pid 66623:tid 66708] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-content/home.php"] [unique_id "aoSBMNO5rbWdOArH04KqTwABHUc"]
[Tue Aug 18 12:58:40.265859 2026] [security2:error] [pid 66623:tid 66641] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ip.php"] [unique_id "aoSBMNO5rbWdOArH04KqUAABTwQ"]
[Tue Aug 18 12:58:40.274860 2026] [security2:error] [pid 66623:tid 66838] [client 213.202.253.4:51055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/wp-content/postnews.php"] [unique_id "aoSBMNO5rbWdOArH04KqUQAAAVI"], referer: www.google.com
[Tue Aug 18 12:58:40.293676 2026] [security2:error] [pid 66623:tid 66771] [client 20.48.236.86:36126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/uwu.php"] [unique_id "aoSBMNO5rbWdOArH04KqUwAAAQ8"]
[Tue Aug 18 12:58:40.386593 2026] [authz_core:error] [pid 66623:tid 66750] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:40.386877 2026] [authz_core:error] [pid 66623:tid 66750] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:40.413586 2026] [security2:error] [pid 66623:tid 66836] [client 172.182.200.96:7648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSBMNO5rbWdOArH04KqWQAAAVA"]
[Tue Aug 18 12:58:40.475507 2026] [security2:error] [pid 66623:tid 66747] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/99.php"] [unique_id "aoSBMNO5rbWdOArH04KqWgABQW4"]
[Tue Aug 18 12:58:40.511273 2026] [security2:error] [pid 66623:tid 66893] [client 20.25.139.174:4641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/file.php"] [unique_id "aoSBMNO5rbWdOArH04KqXQAAAYk"]
[Tue Aug 18 12:58:40.540894 2026] [autoindex:error] [pid 66623:tid 66887] [client 4.232.94.69:57478] AH01276: Cannot serve directory /home2/vfunnelcrmcom/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:40.541370 2026] [security2:error] [pid 66623:tid 66845] [client 20.206.73.37:59881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/copypaths.php"] [unique_id "aoSBMNO5rbWdOArH04KqXwAAAVk"]
[Tue Aug 18 12:58:40.556552 2026] [security2:error] [pid 66623:tid 66832] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/bajah.php"] [unique_id "aoSBMNO5rbWdOArH04KqYAAAAUw"]
[Tue Aug 18 12:58:40.597629 2026] [security2:error] [pid 66623:tid 66831] [client 20.119.58.187:12023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/ID3/php8.php"] [unique_id "aoSBMNO5rbWdOArH04KqYwAAAUs"]
[Tue Aug 18 12:58:40.622178 2026] [security2:error] [pid 66623:tid 66852] [client 158.23.17.4:56716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/qr.php"] [unique_id "aoSBMNO5rbWdOArH04KqZAAAAWA"]
[Tue Aug 18 12:58:40.675363 2026] [security2:error] [pid 66623:tid 66746] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/er.php"] [unique_id "aoSBMNO5rbWdOArH04KqZgABVW0"]
[Tue Aug 18 12:58:40.685985 2026] [authz_core:error] [pid 66623:tid 66686] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:40.686235 2026] [authz_core:error] [pid 66623:tid 66686] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:40.690280 2026] [security2:error] [pid 66623:tid 66775] [client 4.232.151.198:30033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/stem.php"] [unique_id "aoSBMNO5rbWdOArH04KqaQAAARM"]
[Tue Aug 18 12:58:40.749255 2026] [authz_core:error] [pid 66623:tid 66662] [remote 57.141.22.95:45606] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:40.749536 2026] [authz_core:error] [pid 66623:tid 66662] [remote 57.141.22.95:45606] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:40.750183 2026] [security2:error] [pid 66623:tid 66805] [client 4.232.94.69:57478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBMNO5rbWdOArH04KqbgAAATE"]
[Tue Aug 18 12:58:40.767394 2026] [security2:error] [pid 66623:tid 66806] [client 20.104.85.180:54542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/akcc.php"] [unique_id "aoSBMNO5rbWdOArH04KqbwAAATI"]
[Tue Aug 18 12:58:40.811512 2026] [security2:error] [pid 66623:tid 66840] [client 20.118.133.132:15903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/133.php"] [unique_id "aoSBMNO5rbWdOArH04KqcQAAAVQ"]
[Tue Aug 18 12:58:40.844062 2026] [security2:error] [pid 66623:tid 66849] [client 20.250.13.23:53639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/index/function.php"] [unique_id "aoSBMNO5rbWdOArH04KqcwAAAV0"]
[Tue Aug 18 12:58:40.851637 2026] [security2:error] [pid 66623:tid 66780] [client 52.173.121.69:17972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSBMNO5rbWdOArH04KqdAAAARg"]
[Tue Aug 18 12:58:40.863250 2026] [security2:error] [pid 66623:tid 66827] [client 40.74.65.169:20358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/w.php"] [unique_id "aoSBMNO5rbWdOArH04KqdwAAAUc"]
[Tue Aug 18 12:58:40.887414 2026] [security2:error] [pid 66623:tid 66773] [client 52.173.121.69:35566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/opsqt.php"] [unique_id "aoSBMNO5rbWdOArH04KqegAAARE"]
[Tue Aug 18 12:58:40.896458 2026] [security2:error] [pid 66623:tid 66769] [client 20.203.138.185:17852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/xxx.php"] [unique_id "aoSBMNO5rbWdOArH04KqewAAAQ0"]
[Tue Aug 18 12:58:40.898154 2026] [security2:error] [pid 66623:tid 66885] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/h.php"] [unique_id "aoSBMNO5rbWdOArH04KqfAAAAYE"]
[Tue Aug 18 12:58:40.906924 2026] [security2:error] [pid 66623:tid 66643] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/qk.php"] [unique_id "aoSBMNO5rbWdOArH04KqfQABNwY"]
[Tue Aug 18 12:58:40.956884 2026] [security2:error] [pid 66623:tid 66781] [client 20.119.58.187:12002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/img/php8.php"] [unique_id "aoSBMNO5rbWdOArH04KqgAAAARk"]
[Tue Aug 18 12:58:40.987187 2026] [authz_core:error] [pid 66623:tid 66644] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:40.987460 2026] [authz_core:error] [pid 66623:tid 66644] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:40.994604 2026] [security2:error] [pid 66623:tid 66804] [client 74.248.18.37:8113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/t.php"] [unique_id "aoSBMNO5rbWdOArH04KqhgAAATA"]
[Tue Aug 18 12:58:40.994664 2026] [security2:error] [pid 66623:tid 66766] [client 74.248.18.37:40992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/wp-signup.php"] [unique_id "aoSBMNO5rbWdOArH04KqhQAAAQo"]
[Tue Aug 18 12:58:41.006335 2026] [security2:error] [pid 66623:tid 66770] [client 20.250.13.23:7400] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.comatmotos.com.br"] [uri "/1.php"] [unique_id "aoSBMdO5rbWdOArH04KqiAAAAQ4"]
[Tue Aug 18 12:58:41.006463 2026] [security2:error] [pid 66623:tid 66770] [client 20.250.13.23:7400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/1.php"] [unique_id "aoSBMdO5rbWdOArH04KqiAAAAQ4"]
[Tue Aug 18 12:58:41.033858 2026] [security2:error] [pid 66623:tid 66785] [client 20.104.85.180:22874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/lock360.php"] [unique_id "aoSBMdO5rbWdOArH04KqigAAAR0"]
[Tue Aug 18 12:58:41.057642 2026] [security2:error] [pid 66623:tid 66883] [client 20.25.139.174:4630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBMdO5rbWdOArH04KqjAAAAX8"]
[Tue Aug 18 12:58:41.079563 2026] [security2:error] [pid 66623:tid 66666] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSBMdO5rbWdOArH04KqjgABDx0"]
[Tue Aug 18 12:58:41.155116 2026] [security2:error] [pid 66623:tid 66884] [client 20.127.136.245:23883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/images/class-config.php"] [unique_id "aoSBMdO5rbWdOArH04KqkQAAAYA"]
[Tue Aug 18 12:58:41.208965 2026] [security2:error] [pid 66623:tid 66844] [client 68.155.155.199:4887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/buy.php"] [unique_id "aoSBMdO5rbWdOArH04KqkgAAAVg"]
[Tue Aug 18 12:58:41.214671 2026] [security2:error] [pid 66623:tid 66826] [client 213.35.127.232:53370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBMdO5rbWdOArH04KqkwAAAUY"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:41.249522 2026] [security2:error] [pid 66623:tid 66861] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/ano.php"] [unique_id "aoSBMdO5rbWdOArH04KqlgAAAWk"]
[Tue Aug 18 12:58:41.249554 2026] [security2:error] [pid 66623:tid 66796] [client 20.100.169.31:25140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSBMdO5rbWdOArH04KqlQAAASg"]
[Tue Aug 18 12:58:41.251362 2026] [security2:error] [pid 66623:tid 66869] [client 172.202.39.151:44569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBMdO5rbWdOArH04KqlwAAAXE"]
[Tue Aug 18 12:58:41.279801 2026] [security2:error] [pid 66623:tid 66807] [client 40.74.65.169:55844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/bajah.php"] [unique_id "aoSBMdO5rbWdOArH04KqmQAAATM"]
[Tue Aug 18 12:58:41.292051 2026] [security2:error] [pid 66623:tid 66663] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/fs.php"] [unique_id "aoSBMdO5rbWdOArH04KqmwABTRo"]
[Tue Aug 18 12:58:41.313065 2026] [security2:error] [pid 66623:tid 66836] [client 20.119.58.187:11984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/languages/php8.php"] [unique_id "aoSBMdO5rbWdOArH04KqnAAAAVA"]
[Tue Aug 18 12:58:41.371499 2026] [security2:error] [pid 66623:tid 66859] [client 114.119.140.102:20941] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rhemahost.com.br"] [uri "/robots.txt"] [unique_id "aoSBMdO5rbWdOArH04KqngAAAWc"], referer: http://rhemahost.com.br/robots.txt
[Tue Aug 18 12:58:41.391978 2026] [security2:error] [pid 66623:tid 66890] [client 52.173.121.69:35579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/jvcpa.php"] [unique_id "aoSBMdO5rbWdOArH04KqoAAAAYY"]
[Tue Aug 18 12:58:41.428474 2026] [security2:error] [pid 66623:tid 66866] [client 4.232.151.198:30025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/UomnmTO0r9.php"] [unique_id "aoSBMdO5rbWdOArH04KqowAAAW4"]
[Tue Aug 18 12:58:41.439143 2026] [security2:error] [pid 66623:tid 66863] [client 79.127.164.8:45764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/sessions.sql"] [unique_id "aoSBMdO5rbWdOArH04KqpAAAAWs"], referer: https://medihub.com.br/sessions.sql
[Tue Aug 18 12:58:41.471367 2026] [security2:error] [pid 66623:tid 66867] [client 20.250.13.23:1809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/info.php"] [unique_id "aoSBMdO5rbWdOArH04KqpgAAAW8"]
[Tue Aug 18 12:58:41.509000 2026] [security2:error] [pid 66623:tid 66698] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/rb.php"] [unique_id "aoSBMdO5rbWdOArH04KqqQABEz0"]
[Tue Aug 18 12:58:41.511362 2026] [security2:error] [pid 66623:tid 66787] [client 20.104.85.180:57677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wk/index.php"] [unique_id "aoSBMdO5rbWdOArH04KqqgAAAR8"]
[Tue Aug 18 12:58:41.511802 2026] [security2:error] [pid 66623:tid 66774] [client 20.48.236.86:25943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/signon.php"] [unique_id "aoSBMdO5rbWdOArH04KqqwAAARI"]
[Tue Aug 18 12:58:41.518011 2026] [security2:error] [pid 66623:tid 66871] [client 86.120.159.145:9729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBMdO5rbWdOArH04KqrAAAAXM"]
[Tue Aug 18 12:58:41.518298 2026] [security2:error] [pid 66623:tid 66871] [client 86.120.159.145:9729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBMdO5rbWdOArH04KqrAAAAXM"]
[Tue Aug 18 12:58:41.562390 2026] [security2:error] [pid 66623:tid 66874] [client 40.74.65.169:20394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/fpwch.php"] [unique_id "aoSBMdO5rbWdOArH04KqrQAAAXY"]
[Tue Aug 18 12:58:41.577066 2026] [autoindex:error] [pid 66623:tid 66808] [client 87.236.176.216:35909] AH01276: Cannot serve directory /home4/joadv/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:41.589718 2026] [authz_core:error] [pid 66623:tid 66639] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:41.590007 2026] [authz_core:error] [pid 66623:tid 66639] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:41.620523 2026] [security2:error] [pid 66623:tid 66888] [client 20.104.85.180:1591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/flower.php"] [unique_id "aoSBMdO5rbWdOArH04KqsQAAAYQ"]
[Tue Aug 18 12:58:41.625014 2026] [security2:error] [pid 66623:tid 66840] [client 158.23.17.4:62991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/dirs.php"] [unique_id "aoSBMdO5rbWdOArH04KqsgAAAVQ"]
[Tue Aug 18 12:58:41.637488 2026] [security2:error] [pid 66623:tid 66857] [client 20.25.139.174:4567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/404.php"] [unique_id "aoSBMdO5rbWdOArH04KqswAAAWU"]
[Tue Aug 18 12:58:41.666954 2026] [security2:error] [pid 66623:tid 66812] [client 4.232.94.69:49359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/storage/rip.php"] [unique_id "aoSBMdO5rbWdOArH04KquQAAATg"]
[Tue Aug 18 12:58:41.672224 2026] [security2:error] [pid 66623:tid 66805] [client 20.119.58.187:12253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/customize/php8.php"] [unique_id "aoSBMdO5rbWdOArH04KqugAAATE"]
[Tue Aug 18 12:58:41.681791 2026] [security2:error] [pid 66623:tid 66668] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/37.php"] [unique_id "aoSBMdO5rbWdOArH04KquwABER8"]
[Tue Aug 18 12:58:41.837529 2026] [security2:error] [pid 66623:tid 66721] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBMdO5rbWdOArH04KqvwABMFQ"]
[Tue Aug 18 12:58:41.837672 2026] [security2:error] [pid 66623:tid 66804] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBMdO5rbWdOArH04KqvwABMFQ"]
[Tue Aug 18 12:58:41.862632 2026] [security2:error] [pid 66623:tid 66865] [client 74.248.18.37:7722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBMdO5rbWdOArH04KqwAAAAW0"]
[Tue Aug 18 12:58:41.886116 2026] [security2:error] [pid 66623:tid 66770] [client 52.173.121.69:12193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSBMdO5rbWdOArH04KqxQAAAQ4"]
[Tue Aug 18 12:58:41.889439 2026] [authz_core:error] [pid 66623:tid 66716] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:41.889697 2026] [authz_core:error] [pid 66623:tid 66716] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:41.901947 2026] [security2:error] [pid 66623:tid 66740] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/md.php"] [unique_id "aoSBMdO5rbWdOArH04KqxwABHWc"]
[Tue Aug 18 12:58:41.903825 2026] [security2:error] [pid 66623:tid 66791] [client 20.215.241.237:59990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/dex.php"] [unique_id "aoSBMdO5rbWdOArH04KqyAAAASM"]
[Tue Aug 18 12:58:41.909550 2026] [security2:error] [pid 66623:tid 66824] [client 74.248.18.37:54967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/templates.php"] [unique_id "aoSBMdO5rbWdOArH04KqyQAAAUQ"]
[Tue Aug 18 12:58:42.015464 2026] [security2:error] [pid 66623:tid 66795] [client 172.182.200.96:7556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSBMtO5rbWdOArH04Kq0QAAASc"]
[Tue Aug 18 12:58:42.028114 2026] [security2:error] [pid 66623:tid 66835] [client 20.119.58.187:12006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes.bak/html-api/php8.php"] [unique_id "aoSBMtO5rbWdOArH04Kq0gAAAU8"]
[Tue Aug 18 12:58:42.046113 2026] [security2:error] [pid 66623:tid 66856] [client 20.104.85.180:15162] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/1.php"] [unique_id "aoSBMtO5rbWdOArH04Kq1QAAAWQ"]
[Tue Aug 18 12:58:42.046215 2026] [security2:error] [pid 66623:tid 66856] [client 20.104.85.180:15162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/1.php"] [unique_id "aoSBMtO5rbWdOArH04Kq1QAAAWQ"]
[Tue Aug 18 12:58:42.050662 2026] [security2:error] [pid 66623:tid 66868] [client 20.104.85.180:28647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/13.php"] [unique_id "aoSBMtO5rbWdOArH04Kq1wAAAXA"]
[Tue Aug 18 12:58:42.060007 2026] [security2:error] [pid 66623:tid 66802] [client 40.74.65.169:56446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/ajax.php"] [unique_id "aoSBMtO5rbWdOArH04Kq2QAAAS4"]
[Tue Aug 18 12:58:42.061541 2026] [security2:error] [pid 66623:tid 66853] [client 20.203.138.185:27990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/un.php"] [unique_id "aoSBMtO5rbWdOArH04Kq2gAAAWE"]
[Tue Aug 18 12:58:42.086273 2026] [security2:error] [pid 66623:tid 66870] [client 20.250.13.23:53668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/profile.php"] [unique_id "aoSBMtO5rbWdOArH04Kq2wAAAXI"]
[Tue Aug 18 12:58:42.105514 2026] [security2:error] [pid 66623:tid 66722] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/iy.php"] [unique_id "aoSBMtO5rbWdOArH04Kq3QABWFU"]
[Tue Aug 18 12:58:42.109957 2026] [security2:error] [pid 66623:tid 66846] [client 4.232.151.198:62673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/New.php"] [unique_id "aoSBMtO5rbWdOArH04Kq3gAAAVo"]
[Tue Aug 18 12:58:42.133993 2026] [security2:error] [pid 66623:tid 66786] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/ai.php"] [unique_id "aoSBMtO5rbWdOArH04Kq3wAAAR4"]
[Tue Aug 18 12:58:42.168838 2026] [security2:error] [pid 66623:tid 66821] [client 68.155.155.199:12024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/cong.php"] [unique_id "aoSBMtO5rbWdOArH04Kq4gAAAUE"]
[Tue Aug 18 12:58:42.208559 2026] [security2:error] [pid 66623:tid 66819] [client 20.25.139.174:4642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wk/index.php"] [unique_id "aoSBMtO5rbWdOArH04Kq5AAAAT8"]
[Tue Aug 18 12:58:42.220120 2026] [security2:error] [pid 66623:tid 66836] [client 20.206.73.37:59943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/bless6.php"] [unique_id "aoSBMtO5rbWdOArH04Kq5QAAAVA"]
[Tue Aug 18 12:58:42.234785 2026] [security2:error] [pid 66623:tid 66876] [client 213.35.127.232:53583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBMtO5rbWdOArH04Kq5wAAAXg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:42.259760 2026] [security2:error] [pid 66623:tid 66832] [client 40.74.65.169:47059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/FWAZ.php"] [unique_id "aoSBMtO5rbWdOArH04Kq6QAAAUw"]
[Tue Aug 18 12:58:42.297246 2026] [security2:error] [pid 66623:tid 66778] [client 52.173.121.69:14555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSBMtO5rbWdOArH04Kq6wAAARY"]
[Tue Aug 18 12:58:42.326067 2026] [security2:error] [pid 66623:tid 66649] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/og.php"] [unique_id "aoSBMtO5rbWdOArH04Kq7gABaww"]
[Tue Aug 18 12:58:42.353012 2026] [security2:error] [pid 66623:tid 66893] [client 20.127.136.245:3226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/alfa.php"] [unique_id "aoSBMtO5rbWdOArH04Kq7wAAAYk"]
[Tue Aug 18 12:58:42.396606 2026] [security2:error] [pid 66623:tid 66871] [client 20.118.172.148:2718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBMtO5rbWdOArH04Kq8AAAAXM"]
[Tue Aug 18 12:58:42.425618 2026] [security2:error] [pid 66623:tid 66817] [client 20.119.58.187:12275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/widgets/php8.php"] [unique_id "aoSBMtO5rbWdOArH04Kq9QAAAT0"]
[Tue Aug 18 12:58:42.430768 2026] [security2:error] [pid 66623:tid 66840] [client 91.92.47.210:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autoconfig.equipecamisavermelha.com.br"] [uri "/"] [unique_id "aoSBMtO5rbWdOArH04Kq9gAAAVQ"]
[Tue Aug 18 12:58:42.441065 2026] [security2:error] [pid 66623:tid 66818] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/w1px.php"] [unique_id "aoSBMtO5rbWdOArH04Kq9wAAAT4"]
[Tue Aug 18 12:58:42.463316 2026] [security2:error] [pid 66623:tid 66848] [client 172.202.39.151:44568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSBMtO5rbWdOArH04Kq-AAAAVw"]
[Tue Aug 18 12:58:42.492915 2026] [authz_core:error] [pid 66623:tid 66697] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:42.493173 2026] [authz_core:error] [pid 66623:tid 66697] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:42.503804 2026] [security2:error] [pid 66623:tid 66690] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/lp.php"] [unique_id "aoSBMtO5rbWdOArH04KrCwABETU"]
[Tue Aug 18 12:58:42.526468 2026] [security2:error] [pid 66623:tid 66827] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBMtO5rbWdOArH04KrCQABR0g"]
[Tue Aug 18 12:58:42.544717 2026] [security2:error] [pid 66623:tid 66811] [client 20.104.85.180:19715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/cc.php"] [unique_id "aoSBMtO5rbWdOArH04KrDwAAATc"]
[Tue Aug 18 12:58:42.570653 2026] [security2:error] [pid 66623:tid 66830] [client 20.48.236.86:36108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/file61.php"] [unique_id "aoSBMtO5rbWdOArH04KrEAAAAUo"]
[Tue Aug 18 12:58:42.592484 2026] [security2:error] [pid 66623:tid 66854] [client 74.248.18.37:40984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSBMtO5rbWdOArH04KrFQAAAWI"]
[Tue Aug 18 12:58:42.595605 2026] [security2:error] [pid 66623:tid 66875] [client 114.5.214.109:50410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBMtO5rbWdOArH04KrFgAAAXc"]
[Tue Aug 18 12:58:42.595676 2026] [security2:error] [pid 66623:tid 66875] [client 114.5.214.109:50410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBMtO5rbWdOArH04KrFgAAAXc"]
[Tue Aug 18 12:58:42.691878 2026] [security2:error] [pid 66623:tid 66785] [client 52.173.121.69:24779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-2019.php"] [unique_id "aoSBMtO5rbWdOArH04KrHQAAAR0"]
[Tue Aug 18 12:58:42.695140 2026] [security2:error] [pid 66623:tid 66711] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ey.php"] [unique_id "aoSBMtO5rbWdOArH04KrHgABI0o"]
[Tue Aug 18 12:58:42.739998 2026] [security2:error] [pid 66623:tid 66780] [client 74.248.18.37:8095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/term.php"] [unique_id "aoSBMtO5rbWdOArH04KrIQAAARg"]
[Tue Aug 18 12:58:42.743472 2026] [security2:error] [pid 66623:tid 66839] [client 20.250.13.23:53665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/sx.php"] [unique_id "aoSBMtO5rbWdOArH04KrIgAAAVM"]
[Tue Aug 18 12:58:42.763783 2026] [security2:error] [pid 66623:tid 66769] [client 4.232.151.198:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-includes/panel.php"] [unique_id "aoSBMtO5rbWdOArH04KrJAAAAQ0"]
[Tue Aug 18 12:58:42.777312 2026] [security2:error] [pid 66623:tid 66831] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/zi-936.php"] [unique_id "aoSBMtO5rbWdOArH04KrJgAAAUs"]
[Tue Aug 18 12:58:42.784569 2026] [security2:error] [pid 66623:tid 66789] [client 20.119.58.187:11844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/IXR/php8.php"] [unique_id "aoSBMtO5rbWdOArH04KrKAAAASE"]
[Tue Aug 18 12:58:42.804888 2026] [security2:error] [pid 66623:tid 66804] [client 20.25.139.174:4559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/about.php"] [unique_id "aoSBMtO5rbWdOArH04KrKQAAATA"]
[Tue Aug 18 12:58:42.808919 2026] [security2:error] [pid 66623:tid 66814] [client 52.173.121.69:48990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSBMtO5rbWdOArH04KrKgAAATo"]
[Tue Aug 18 12:58:42.825679 2026] [security2:error] [pid 66623:tid 66771] [client 20.100.169.31:29036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/themes.php"] [unique_id "aoSBMtO5rbWdOArH04KrKwAAAQ8"]
[Tue Aug 18 12:58:42.866688 2026] [security2:error] [pid 66623:tid 66647] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/lv.php"] [unique_id "aoSBMtO5rbWdOArH04KrLAABYQo"]
[Tue Aug 18 12:58:42.925402 2026] [security2:error] [pid 66623:tid 66766] [client 40.74.65.169:56441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBMtO5rbWdOArH04KrPgAAAQo"]
[Tue Aug 18 12:58:42.955562 2026] [security2:error] [pid 66623:tid 66796] [client 40.74.65.169:20128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/blurbs.php"] [unique_id "aoSBMtO5rbWdOArH04KrTgAAASg"]
[Tue Aug 18 12:58:42.981663 2026] [security2:error] [pid 66623:tid 66795] [client 132.196.30.78:14980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/inputs.php"] [unique_id "aoSBMtO5rbWdOArH04KrWAAAASc"]
[Tue Aug 18 12:58:43.026455 2026] [security2:error] [pid 66623:tid 66845] [client 4.232.94.69:40084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/.__info.php"] [unique_id "aoSBM9O5rbWdOArH04KrWQAAAVk"]
[Tue Aug 18 12:58:43.038013 2026] [security2:error] [pid 66623:tid 66876] [client 20.203.138.185:47205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/autogooey.php"] [unique_id "aoSBM9O5rbWdOArH04KrWgAAAXg"]
[Tue Aug 18 12:58:43.042880 2026] [security2:error] [pid 66623:tid 66652] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/51.php"] [unique_id "aoSBM9O5rbWdOArH04KrWwABZw8"]
[Tue Aug 18 12:58:43.070833 2026] [security2:error] [pid 66623:tid 66829] [client 172.202.39.151:4426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content/admin.php"] [unique_id "aoSBM9O5rbWdOArH04KrXQAAAUk"]
[Tue Aug 18 12:58:43.095876 2026] [authz_core:error] [pid 66623:tid 66763] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:43.096150 2026] [authz_core:error] [pid 66623:tid 66763] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:43.104838 2026] [security2:error] [pid 66623:tid 66863] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/dcsgumnm.php"] [unique_id "aoSBM9O5rbWdOArH04KrYAAAAWs"]
[Tue Aug 18 12:58:43.130609 2026] [security2:error] [pid 66623:tid 66809] [client 20.104.85.180:45971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSBM9O5rbWdOArH04KrZAAAATU"]
[Tue Aug 18 12:58:43.138400 2026] [security2:error] [pid 66623:tid 66836] [client 20.119.58.187:11978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/js/php8.php"] [unique_id "aoSBM9O5rbWdOArH04KrZQAAAVA"]
[Tue Aug 18 12:58:43.152138 2026] [security2:error] [pid 66623:tid 66881] [client 20.206.73.37:11943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/special.php"] [unique_id "aoSBM9O5rbWdOArH04KraAAAAX0"]
[Tue Aug 18 12:58:43.173311 2026] [security2:error] [pid 66623:tid 66767] [client 20.250.13.23:44959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/alfa.php"] [unique_id "aoSBM9O5rbWdOArH04KraQAAAQs"]
[Tue Aug 18 12:58:43.177623 2026] [security2:error] [pid 66623:tid 66888] [client 52.173.121.69:35536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSBM9O5rbWdOArH04KragAAAYQ"]
[Tue Aug 18 12:58:43.221425 2026] [security2:error] [pid 66623:tid 66705] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ew.php"] [unique_id "aoSBM9O5rbWdOArH04KrawABOEQ"]
[Tue Aug 18 12:58:43.246578 2026] [security2:error] [pid 66623:tid 66844] [client 213.35.127.232:53813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBM9O5rbWdOArH04KrbQAAAVg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:43.295253 2026] [security2:error] [pid 66623:tid 66854] [client 172.182.200.96:14093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSBM9O5rbWdOArH04KrbgAAAWI"]
[Tue Aug 18 12:58:43.305470 2026] [security2:error] [pid 66623:tid 66834] [client 172.202.39.151:40359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/about.php"] [unique_id "aoSBM9O5rbWdOArH04KrcAAAAU4"]
[Tue Aug 18 12:58:43.308730 2026] [security2:error] [pid 66623:tid 66808] [client 52.173.121.69:16469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSBM9O5rbWdOArH04KrcQAAATQ"]
[Tue Aug 18 12:58:43.361837 2026] [security2:error] [pid 66623:tid 66787] [client 20.250.13.23:45749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBM9O5rbWdOArH04KrdwAAAR8"]
[Tue Aug 18 12:58:43.362553 2026] [security2:error] [pid 66623:tid 66824] [client 20.104.85.180:22894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBM9O5rbWdOArH04KreAAAAUQ"]
[Tue Aug 18 12:58:43.383893 2026] [security2:error] [pid 66623:tid 66782] [client 20.25.139.174:4563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/term.php"] [unique_id "aoSBM9O5rbWdOArH04KrfgAAARo"]
[Tue Aug 18 12:58:43.415484 2026] [security2:error] [pid 66623:tid 66873] [client 4.232.151.198:30036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-includes/ID/module.audio.flac.php"] [unique_id "aoSBM9O5rbWdOArH04KrgwAAAXU"]
[Tue Aug 18 12:58:43.441755 2026] [security2:error] [pid 66623:tid 66857] [client 74.248.18.37:8100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-blog.php"] [unique_id "aoSBM9O5rbWdOArH04KrnAAAAWU"]
[Tue Aug 18 12:58:43.449575 2026] [autoindex:error] [pid 66623:tid 66814] [client 68.155.153.139:0] AH01276: Cannot serve directory /home1/cnascimentoasses/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:43.462278 2026] [security2:error] [pid 66623:tid 66815] [client 74.248.18.37:7710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/test.php"] [unique_id "aoSBM9O5rbWdOArH04KrnwAAATs"]
[Tue Aug 18 12:58:43.498473 2026] [security2:error] [pid 66623:tid 66798] [client 20.119.58.187:12232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/pki-validation/php8.php"] [unique_id "aoSBM9O5rbWdOArH04KroQAAASo"]
[Tue Aug 18 12:58:43.521382 2026] [security2:error] [pid 66623:tid 66785] [client 132.196.30.78:15668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/admin.php"] [unique_id "aoSBM9O5rbWdOArH04KrqQAAAR0"]
[Tue Aug 18 12:58:43.538146 2026] [security2:error] [pid 66623:tid 66741] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/pqr.php"] [unique_id "aoSBM9O5rbWdOArH04KrqgABK2g"]
[Tue Aug 18 12:58:43.539716 2026] [security2:error] [pid 66623:tid 66800] [client 37.40.227.74:57194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBM9O5rbWdOArH04KrqwAAASw"]
[Tue Aug 18 12:58:43.539887 2026] [security2:error] [pid 66623:tid 66800] [client 37.40.227.74:57194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBM9O5rbWdOArH04KrqwAAASw"]
[Tue Aug 18 12:58:43.567214 2026] [security2:error] [pid 66623:tid 66868] [client 103.184.169.37:42422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBM9O5rbWdOArH04KrrQAAAXA"]
[Tue Aug 18 12:58:43.567333 2026] [security2:error] [pid 66623:tid 66868] [client 103.184.169.37:42422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBM9O5rbWdOArH04KrrQAAAXA"]
[Tue Aug 18 12:58:43.629819 2026] [security2:error] [pid 66623:tid 66869] [client 20.127.136.245:23429] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.turial.com.br"] [uri "/1.php"] [unique_id "aoSBM9O5rbWdOArH04KrsgAAAXE"]
[Tue Aug 18 12:58:43.629949 2026] [security2:error] [pid 66623:tid 66869] [client 20.127.136.245:23429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/1.php"] [unique_id "aoSBM9O5rbWdOArH04KrsgAAAXE"]
[Tue Aug 18 12:58:43.631119 2026] [security2:error] [pid 66623:tid 66864] [client 40.74.65.169:42438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/100.php"] [unique_id "aoSBM9O5rbWdOArH04KrswAAAWw"]
[Tue Aug 18 12:58:43.639388 2026] [security2:error] [pid 66623:tid 66807] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/php.php"] [unique_id "aoSBM9O5rbWdOArH04KrtgAAATM"]
[Tue Aug 18 12:58:43.644609 2026] [security2:error] [pid 66623:tid 66877] [client 52.173.121.69:14911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSBM9O5rbWdOArH04KrtwAAAXk"]
[Tue Aug 18 12:58:43.645406 2026] [security2:error] [pid 66623:tid 66819] [client 103.120.71.157:59458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBM9O5rbWdOArH04KruAAAAT8"]
[Tue Aug 18 12:58:43.645512 2026] [security2:error] [pid 66623:tid 66819] [client 103.120.71.157:59458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBM9O5rbWdOArH04KruAAAAT8"]
[Tue Aug 18 12:58:43.696257 2026] [authz_core:error] [pid 66623:tid 66706] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:43.696546 2026] [authz_core:error] [pid 66623:tid 66706] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:43.727227 2026] [security2:error] [pid 66623:tid 66696] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/an.php"] [unique_id "aoSBM9O5rbWdOArH04Kr4QABiTs"]
[Tue Aug 18 12:58:43.781217 2026] [security2:error] [pid 66623:tid 66867] [client 20.203.138.185:63780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/sty.php"] [unique_id "aoSBM9O5rbWdOArH04Kr4wAAAW8"]
[Tue Aug 18 12:58:43.845589 2026] [security2:error] [pid 66623:tid 66803] [client 5.161.194.92:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "1td.com.br"] [uri "/index.php"] [unique_id "aoSBMtO5rbWdOArH04Kq4QABL2U"], referer: https://1td.com.br
[Tue Aug 18 12:58:43.860736 2026] [security2:error] [pid 66623:tid 66855] [client 20.119.58.187:11991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/pomo/php8.php"] [unique_id "aoSBM9O5rbWdOArH04Kr6wAAAWM"]
[Tue Aug 18 12:58:43.904272 2026] [security2:error] [pid 66623:tid 66827] [client 52.173.121.69:24987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/.cache/x.php"] [unique_id "aoSBM9O5rbWdOArH04Kr7gAAAUc"]
[Tue Aug 18 12:58:43.919651 2026] [security2:error] [pid 66623:tid 66844] [client 20.104.85.180:27930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBM9O5rbWdOArH04Kr7wAAAVg"]
[Tue Aug 18 12:58:43.924594 2026] [security2:error] [pid 66623:tid 66676] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/sy.php"] [unique_id "aoSBM9O5rbWdOArH04Kr8AABJSc"]
[Tue Aug 18 12:58:43.950796 2026] [security2:error] [pid 66623:tid 66809] [client 20.25.139.174:4566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBM9O5rbWdOArH04Kr8wAAATU"]
[Tue Aug 18 12:58:43.951378 2026] [security2:error] [pid 66623:tid 66876] [client 20.100.169.31:27714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/cv.php"] [unique_id "aoSBM9O5rbWdOArH04Kr9AAAAXg"]
[Tue Aug 18 12:58:43.971297 2026] [security2:error] [pid 66623:tid 66776] [client 20.250.13.23:45726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBM9O5rbWdOArH04Kr9wAAARQ"]
[Tue Aug 18 12:58:43.981404 2026] [security2:error] [pid 66623:tid 66843] [client 52.173.121.69:32598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSBM9O5rbWdOArH04Kr-AAAAVc"]
[Tue Aug 18 12:58:43.997296 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:43.997576 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:44.055369 2026] [authz_core:error] [pid 66623:tid 66650] [remote 57.141.22.31:33026] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:44.055765 2026] [authz_core:error] [pid 66623:tid 66650] [remote 57.141.22.31:33026] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:44.065435 2026] [security2:error] [pid 66623:tid 66848] [client 4.232.151.198:30073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/gallery.php"] [unique_id "aoSBNNO5rbWdOArH04KsBwAAAVw"]
[Tue Aug 18 12:58:44.094638 2026] [security2:error] [pid 66623:tid 66705] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/57.php"] [unique_id "aoSBNNO5rbWdOArH04KsCgABHUQ"]
[Tue Aug 18 12:58:44.128453 2026] [security2:error] [pid 66623:tid 66890] [client 20.104.85.180:22863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSBNNO5rbWdOArH04KsCwAAAYY"]
[Tue Aug 18 12:58:44.142041 2026] [security2:error] [pid 66623:tid 66851] [client 74.248.18.37:8076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/test1.php"] [unique_id "aoSBNNO5rbWdOArH04KsDQAAAV8"]
[Tue Aug 18 12:58:44.155772 2026] [security2:error] [pid 66623:tid 66643] [remote 129.121.123.168:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.123.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "altostima.com.br"] [uri "/wp-login.php"] [unique_id "aoSBNNO5rbWdOArH04KsDgABdQY"]
[Tue Aug 18 12:58:44.174259 2026] [security2:error] [pid 66623:tid 66768] [client 74.248.18.37:8099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-blogs.php"] [unique_id "aoSBNNO5rbWdOArH04KsEQAAAQw"]
[Tue Aug 18 12:58:44.186223 2026] [security2:error] [pid 66623:tid 66778] [client 46.232.235.137:8070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.235.232.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.blueorbit.com.br"] [uri "/wp-login.php"] [unique_id "aoSBNNO5rbWdOArH04KsEgAAARY"]
[Tue Aug 18 12:58:44.210404 2026] [security2:error] [pid 66623:tid 66878] [client 20.119.58.187:12051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/block-patterns/php8.php"] [unique_id "aoSBNNO5rbWdOArH04KsHgAAAXo"]
[Tue Aug 18 12:58:44.231312 2026] [security2:error] [pid 66623:tid 66868] [client 138.36.100.162:42982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNNO5rbWdOArH04KsLAAAAXA"]
[Tue Aug 18 12:58:44.231425 2026] [security2:error] [pid 66623:tid 66868] [client 138.36.100.162:42982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNNO5rbWdOArH04KsLAAAAXA"]
[Tue Aug 18 12:58:44.261874 2026] [security2:error] [pid 66623:tid 66830] [client 213.35.127.232:54047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBNNO5rbWdOArH04KsMAAAAUo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:44.291011 2026] [security2:error] [pid 66623:tid 66854] [client 132.196.30.78:14996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/goods.php"] [unique_id "aoSBNNO5rbWdOArH04KsMgAAAWI"]
[Tue Aug 18 12:58:44.306644 2026] [security2:error] [pid 66623:tid 66779] [client 40.74.65.169:20124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/ccc.php"] [unique_id "aoSBNNO5rbWdOArH04KsMwAAARc"]
[Tue Aug 18 12:58:44.315603 2026] [security2:error] [pid 66623:tid 66866] [client 20.48.236.86:32867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/copypaths.php"] [unique_id "aoSBNNO5rbWdOArH04KsNAAAAW4"]
[Tue Aug 18 12:58:44.368642 2026] [security2:error] [pid 66623:tid 66751] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ah.php"] [unique_id "aoSBNNO5rbWdOArH04KsOwABTHI"]
[Tue Aug 18 12:58:44.394349 2026] [security2:error] [pid 66623:tid 66774] [client 52.173.121.69:6099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSBNNO5rbWdOArH04KsPAAAARI"]
[Tue Aug 18 12:58:44.444315 2026] [security2:error] [pid 66623:tid 66838] [client 172.182.200.96:14084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSBNNO5rbWdOArH04KsPgAAAVI"]
[Tue Aug 18 12:58:44.459997 2026] [security2:error] [pid 66623:tid 66861] [client 158.23.17.4:14076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/sn.php"] [unique_id "aoSBNNO5rbWdOArH04KsQAAAAWk"]
[Tue Aug 18 12:58:44.481833 2026] [security2:error] [pid 66623:tid 66887] [client 20.25.139.174:4548] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.clickseo.com.br"] [uri "/1.php"] [unique_id "aoSBNNO5rbWdOArH04KsQQAAAYM"]
[Tue Aug 18 12:58:44.481912 2026] [security2:error] [pid 66623:tid 66887] [client 20.25.139.174:4548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/1.php"] [unique_id "aoSBNNO5rbWdOArH04KsQQAAAYM"]
[Tue Aug 18 12:58:44.497343 2026] [security2:error] [pid 66623:tid 66823] [client 142.111.55.8:38312] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSBNNO5rbWdOArH04KsRQAAAUM"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/
[Tue Aug 18 12:58:44.513084 2026] [security2:error] [pid 66623:tid 66827] [client 52.173.121.69:30375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSBNNO5rbWdOArH04KsTAAAAUc"]
[Tue Aug 18 12:58:44.530630 2026] [security2:error] [pid 66623:tid 66773] [client 68.155.155.199:19989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSBNNO5rbWdOArH04KsTgAAARE"]
[Tue Aug 18 12:58:44.559280 2026] [security2:error] [pid 66623:tid 66872] [client 172.202.39.151:40336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBNNO5rbWdOArH04KsTwAAAXQ"]
[Tue Aug 18 12:58:44.565397 2026] [security2:error] [pid 66623:tid 66767] [client 20.119.58.187:12057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/updraft/php8.php"] [unique_id "aoSBNNO5rbWdOArH04KsUAAAAQs"]
[Tue Aug 18 12:58:44.593071 2026] [security2:error] [pid 66623:tid 66723] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/vw.php"] [unique_id "aoSBNNO5rbWdOArH04KsUgABTlY"]
[Tue Aug 18 12:58:44.600636 2026] [authz_core:error] [pid 66623:tid 66755] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:44.600912 2026] [authz_core:error] [pid 66623:tid 66755] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:44.606444 2026] [security2:error] [pid 66623:tid 66809] [client 20.203.138.185:24267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wio.php"] [unique_id "aoSBNNO5rbWdOArH04KsVQAAATU"]
[Tue Aug 18 12:58:44.702149 2026] [security2:error] [pid 66623:tid 66829] [client 4.232.151.198:30057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/Cache.php"] [unique_id "aoSBNNO5rbWdOArH04KsXQAAAUk"]
[Tue Aug 18 12:58:44.714568 2026] [security2:error] [pid 66623:tid 66856] [client 20.104.85.180:15153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/as.php"] [unique_id "aoSBNNO5rbWdOArH04KsXgAAAWQ"]
[Tue Aug 18 12:58:44.740037 2026] [security2:error] [pid 66623:tid 66835] [client 192.141.172.134:51661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNNO5rbWdOArH04KsXwAAAU8"]
[Tue Aug 18 12:58:44.740172 2026] [security2:error] [pid 66623:tid 66835] [client 192.141.172.134:51661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNNO5rbWdOArH04KsXwAAAU8"]
[Tue Aug 18 12:58:44.767906 2026] [security2:error] [pid 66623:tid 66859] [client 149.34.210.141:62738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBNNO5rbWdOArH04KsYAAAAWc"]
[Tue Aug 18 12:58:44.794083 2026] [security2:error] [pid 66623:tid 66677] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/lj.php"] [unique_id "aoSBNNO5rbWdOArH04KsZQABKyg"]
[Tue Aug 18 12:58:44.801488 2026] [security2:error] [pid 66623:tid 66851] [client 20.250.13.23:45699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBNNO5rbWdOArH04KsZwAAAV8"]
[Tue Aug 18 12:58:44.840399 2026] [security2:error] [pid 66623:tid 66778] [client 91.92.47.210:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.equipecamisavermelha.com.br"] [uri "/"] [unique_id "aoSBNNO5rbWdOArH04KsaAAAARY"]
[Tue Aug 18 12:58:44.845302 2026] [security2:error] [pid 66623:tid 66878] [client 20.38.3.247:41489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBNNO5rbWdOArH04KsaQAAAXo"]
[Tue Aug 18 12:58:44.874866 2026] [security2:error] [pid 66623:tid 66789] [client 132.196.30.78:15646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/file.php"] [unique_id "aoSBNNO5rbWdOArH04KsbQAAASE"]
[Tue Aug 18 12:58:44.884658 2026] [security2:error] [pid 66623:tid 66780] [client 74.248.18.37:47236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-config.php"] [unique_id "aoSBNNO5rbWdOArH04KsbgAAARg"]
[Tue Aug 18 12:58:44.894196 2026] [security2:error] [pid 66623:tid 66786] [client 52.173.121.69:25011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBNNO5rbWdOArH04KscAAAAR4"]
[Tue Aug 18 12:58:44.905031 2026] [authz_core:error] [pid 66623:tid 66713] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:44.905451 2026] [authz_core:error] [pid 66623:tid 66713] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:44.922850 2026] [security2:error] [pid 66623:tid 66873] [client 20.119.58.187:11974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/upgrade-temp-backup/php8.php"] [unique_id "aoSBNNO5rbWdOArH04KsdAAAAXU"]
[Tue Aug 18 12:58:44.957838 2026] [security2:error] [pid 66623:tid 66820] [client 74.248.18.37:7580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/thoms.php"] [unique_id "aoSBNNO5rbWdOArH04KsdQAAAUA"]
[Tue Aug 18 12:58:44.958463 2026] [security2:error] [pid 66623:tid 66830] [client 52.173.121.69:48984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSBNNO5rbWdOArH04KsdgAAAUo"]
[Tue Aug 18 12:58:44.985483 2026] [security2:error] [pid 66623:tid 66846] [client 157.20.138.62:53215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNNO5rbWdOArH04KseAAAAVo"]
[Tue Aug 18 12:58:44.985777 2026] [security2:error] [pid 66623:tid 66846] [client 157.20.138.62:53215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNNO5rbWdOArH04KseAAAAVo"]
[Tue Aug 18 12:58:44.989701 2026] [security2:error] [pid 66623:tid 66688] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kh.php"] [unique_id "aoSBNNO5rbWdOArH04KseQABTTM"]
[Tue Aug 18 12:58:45.003678 2026] [security2:error] [pid 66623:tid 66819] [client 40.74.65.169:42439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/get.php"] [unique_id "aoSBNdO5rbWdOArH04KsegAAAT8"]
[Tue Aug 18 12:58:45.031207 2026] [security2:error] [pid 66623:tid 66859] [client 149.34.210.141:62738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBNNO5rbWdOArH04KsYAAAAWc"]
[Tue Aug 18 12:58:45.035066 2026] [security2:error] [pid 66623:tid 66790] [client 20.25.139.174:4631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/alfa.php"] [unique_id "aoSBNdO5rbWdOArH04KsewAAASI"]
[Tue Aug 18 12:58:45.099978 2026] [security2:error] [pid 66623:tid 66863] [client 20.206.73.37:60482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/fz.php"] [unique_id "aoSBNdO5rbWdOArH04KsfAAAAWs"]
[Tue Aug 18 12:58:45.112069 2026] [security2:error] [pid 66623:tid 66862] [client 5.31.227.224:7815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNdO5rbWdOArH04KsfQAAAWo"]
[Tue Aug 18 12:58:45.112227 2026] [security2:error] [pid 66623:tid 66862] [client 5.31.227.224:7815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNdO5rbWdOArH04KsfQAAAWo"]
[Tue Aug 18 12:58:45.115305 2026] [security2:error] [pid 66623:tid 66823] [client 142.111.55.8:38312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSBNNO5rbWdOArH04KsRQAAAUM"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/
[Tue Aug 18 12:58:45.156955 2026] [security2:error] [pid 66623:tid 66774] [client 20.104.85.180:1557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/01.php"] [unique_id "aoSBNdO5rbWdOArH04KsfwAAARI"]
[Tue Aug 18 12:58:45.161956 2026] [security2:error] [pid 66623:tid 66641] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/jb.php"] [unique_id "aoSBNdO5rbWdOArH04KsgAABewQ"]
[Tue Aug 18 12:58:45.183780 2026] [security2:error] [pid 66623:tid 66888] [client 20.104.85.180:47156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBNdO5rbWdOArH04KsggAAAYQ"]
[Tue Aug 18 12:58:45.208648 2026] [authz_core:error] [pid 66623:tid 66685] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:45.209063 2026] [authz_core:error] [pid 66623:tid 66685] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:45.219985 2026] [security2:error] [pid 66623:tid 66887] [client 52.173.121.69:16461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBNdO5rbWdOArH04KshgAAAYM"]
[Tue Aug 18 12:58:45.221576 2026] [security2:error] [pid 66623:tid 66772] [client 20.250.13.23:32643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/edit.php"] [unique_id "aoSBNdO5rbWdOArH04KshwAAARA"]
[Tue Aug 18 12:58:45.284700 2026] [security2:error] [pid 66623:tid 66889] [client 172.182.200.96:14086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSBNdO5rbWdOArH04KsigAAAYU"]
[Tue Aug 18 12:58:45.286346 2026] [security2:error] [pid 66623:tid 66831] [client 213.35.127.232:54245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBNdO5rbWdOArH04KsiwAAAUs"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:45.305847 2026] [security2:error] [pid 66623:tid 66817] [client 20.119.58.187:12235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/php8.php"] [unique_id "aoSBNdO5rbWdOArH04KskAAAAT0"]
[Tue Aug 18 12:58:45.337286 2026] [security2:error] [pid 66623:tid 66701] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/do.php"] [unique_id "aoSBNdO5rbWdOArH04KskQABd0A"]
[Tue Aug 18 12:58:45.341565 2026] [security2:error] [pid 66623:tid 66852] [client 4.232.151.198:58716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-add.php"] [unique_id "aoSBNdO5rbWdOArH04KskgAAAWA"]
[Tue Aug 18 12:58:45.409336 2026] [security2:error] [pid 66623:tid 66828] [client 52.173.121.69:48997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSBNdO5rbWdOArH04KslAAAAUg"]
[Tue Aug 18 12:58:45.457085 2026] [security2:error] [pid 66623:tid 66883] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/sf.php"] [unique_id "aoSBNdO5rbWdOArH04KslwAAAX8"]
[Tue Aug 18 12:58:45.462968 2026] [security2:error] [pid 66623:tid 66800] [client 4.232.94.69:52512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/access.php"] [unique_id "aoSBNdO5rbWdOArH04KsmAAAASw"]
[Tue Aug 18 12:58:45.499930 2026] [security2:error] [pid 66623:tid 66796] [client 132.196.30.78:14979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBNdO5rbWdOArH04KsmwAAASg"]
[Tue Aug 18 12:58:45.503969 2026] [authz_core:error] [pid 66623:tid 66689] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:45.504236 2026] [authz_core:error] [pid 66623:tid 66689] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:45.527114 2026] [security2:error] [pid 66623:tid 66848] [client 223.185.37.47:11697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBNdO5rbWdOArH04KsnQAAAVw"]
[Tue Aug 18 12:58:45.527213 2026] [security2:error] [pid 66623:tid 66848] [client 223.185.37.47:11697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBNdO5rbWdOArH04KsnQAAAVw"]
[Tue Aug 18 12:58:45.527540 2026] [security2:error] [pid 66623:tid 66651] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/yw.php"] [unique_id "aoSBNdO5rbWdOArH04KsnAABSQ4"]
[Tue Aug 18 12:58:45.608256 2026] [security2:error] [pid 66623:tid 66776] [client 20.25.139.174:4558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/edit.php"] [unique_id "aoSBNdO5rbWdOArH04KsogAAARQ"]
[Tue Aug 18 12:58:45.609831 2026] [security2:error] [pid 66623:tid 66834] [client 74.248.18.37:47237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSBNdO5rbWdOArH04KsowAAAU4"]
[Tue Aug 18 12:58:45.610413 2026] [security2:error] [pid 66623:tid 66876] [client 74.248.18.37:7559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/tool.php"] [unique_id "aoSBNdO5rbWdOArH04KspAAAAXg"]
[Tue Aug 18 12:58:45.627344 2026] [security2:error] [pid 66623:tid 66885] [client 20.203.138.185:37287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/1061.php"] [unique_id "aoSBNdO5rbWdOArH04KspwAAAYE"]
[Tue Aug 18 12:58:45.646618 2026] [security2:error] [pid 66623:tid 66778] [client 52.173.121.69:24769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSBNdO5rbWdOArH04KsqAAAARY"]
[Tue Aug 18 12:58:45.647804 2026] [security2:error] [pid 66623:tid 66880] [client 20.250.13.23:45702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSBNdO5rbWdOArH04KsqQAAAXw"]
[Tue Aug 18 12:58:45.648126 2026] [security2:error] [pid 66623:tid 66878] [client 68.155.155.199:13064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/db.php"] [unique_id "aoSBNdO5rbWdOArH04KsqgAAAXo"]
[Tue Aug 18 12:58:45.654487 2026] [security2:error] [pid 66623:tid 66877] [client 178.153.171.161:13359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNdO5rbWdOArH04KsqwAAAXk"]
[Tue Aug 18 12:58:45.654592 2026] [security2:error] [pid 66623:tid 66877] [client 178.153.171.161:13359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNdO5rbWdOArH04KsqwAAAXk"]
[Tue Aug 18 12:58:45.667754 2026] [security2:error] [pid 66623:tid 66856] [client 20.119.58.187:11882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/includes/php8.php"] [unique_id "aoSBNdO5rbWdOArH04KsrAAAAWQ"]
[Tue Aug 18 12:58:45.682220 2026] [security2:error] [pid 66623:tid 66853] [client 40.74.65.169:42465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/images.php"] [unique_id "aoSBNdO5rbWdOArH04KsrgAAAWE"]
[Tue Aug 18 12:58:45.703204 2026] [security2:error] [pid 66623:tid 66837] [client 172.182.200.96:14207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSBNdO5rbWdOArH04KsrwAAAVE"]
[Tue Aug 18 12:58:45.753772 2026] [security2:error] [pid 66623:tid 66637] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNdO5rbWdOArH04KsswABMgA"]
[Tue Aug 18 12:58:45.753922 2026] [security2:error] [pid 66623:tid 66806] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNdO5rbWdOArH04KsswABMgA"]
[Tue Aug 18 12:58:45.760467 2026] [security2:error] [pid 66623:tid 66787] [client 20.118.172.148:19683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/rip.php"] [unique_id "aoSBNdO5rbWdOArH04KstAAAAR8"]
[Tue Aug 18 12:58:45.760851 2026] [security2:error] [pid 66623:tid 66669] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/qh.php"] [unique_id "aoSBNdO5rbWdOArH04KstQABQCA"]
[Tue Aug 18 12:58:45.782469 2026] [security2:error] [pid 66623:tid 66768] [client 5.253.84.92:64410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.84.253.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sindsecurpr.com.br"] [uri "/wp-login.php"] [unique_id "aoSBNdO5rbWdOArH04KstgAAAQw"]
[Tue Aug 18 12:58:45.797693 2026] [security2:error] [pid 66623:tid 66771] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/xx.php"] [unique_id "aoSBNdO5rbWdOArH04KsuAAAAQ8"]
[Tue Aug 18 12:58:45.804275 2026] [authz_core:error] [pid 66623:tid 66746] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:45.804541 2026] [authz_core:error] [pid 66623:tid 66746] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:45.833727 2026] [security2:error] [pid 66623:tid 66792] [client 20.104.85.180:23943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSBNdO5rbWdOArH04KsugAAASQ"]
[Tue Aug 18 12:58:45.900176 2026] [security2:error] [pid 66623:tid 66823] [client 20.48.236.86:2789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/bless6.php"] [unique_id "aoSBNdO5rbWdOArH04KswAAAAUM"]
[Tue Aug 18 12:58:45.924093 2026] [security2:error] [pid 66623:tid 66879] [client 20.100.169.31:38650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBNdO5rbWdOArH04KswQAAAXs"]
[Tue Aug 18 12:58:45.955270 2026] [security2:error] [pid 66623:tid 66810] [client 52.173.121.69:27860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSBNdO5rbWdOArH04KswwAAATY"]
[Tue Aug 18 12:58:45.982473 2026] [security2:error] [pid 66623:tid 66830] [client 4.232.151.198:30018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/cgi-bin/cloud.php"] [unique_id "aoSBNdO5rbWdOArH04KsxQAAAUo"]
[Tue Aug 18 12:58:46.006239 2026] [security2:error] [pid 66623:tid 66664] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/r.php"] [unique_id "aoSBNtO5rbWdOArH04KsxwABEBs"]
[Tue Aug 18 12:58:46.022134 2026] [security2:error] [pid 66623:tid 66860] [client 132.196.30.78:15639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/404.php"] [unique_id "aoSBNtO5rbWdOArH04KsyAAAAWg"]
[Tue Aug 18 12:58:46.026990 2026] [security2:error] [pid 66623:tid 66836] [client 20.119.58.187:11997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/images/php8.php"] [unique_id "aoSBNtO5rbWdOArH04KsyQAAAVA"]
[Tue Aug 18 12:58:46.056039 2026] [security2:error] [pid 66623:tid 66767] [client 20.104.85.180:18815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/lv.php"] [unique_id "aoSBNtO5rbWdOArH04KsygAAAQs"]
[Tue Aug 18 12:58:46.100424 2026] [security2:error] [pid 66623:tid 66793] [client 52.173.121.69:24787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSBNtO5rbWdOArH04KszQAAASU"]
[Tue Aug 18 12:58:46.114495 2026] [security2:error] [pid 66623:tid 66867] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/uwu.php"] [unique_id "aoSBNtO5rbWdOArH04KszwAAAW8"]
[Tue Aug 18 12:58:46.179950 2026] [security2:error] [pid 66623:tid 66858] [client 20.25.139.174:4639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/elp.php"] [unique_id "aoSBNtO5rbWdOArH04Ks0gAAAWY"]
[Tue Aug 18 12:58:46.187040 2026] [security2:error] [pid 66623:tid 66712] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/17.php"] [unique_id "aoSBNtO5rbWdOArH04Ks0wABOUs"]
[Tue Aug 18 12:58:46.257465 2026] [security2:error] [pid 66623:tid 66889] [client 20.250.13.23:1813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSBNtO5rbWdOArH04Ks1QAAAYU"]
[Tue Aug 18 12:58:46.282755 2026] [security2:error] [pid 66623:tid 66788] [client 158.23.17.4:20385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/43.php"] [unique_id "aoSBNtO5rbWdOArH04Ks2AAAASA"]
[Tue Aug 18 12:58:46.299257 2026] [security2:error] [pid 66623:tid 66838] [client 213.35.127.232:54454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBNtO5rbWdOArH04Ks3QAAAVI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:46.329159 2026] [security2:error] [pid 66623:tid 66798] [client 20.104.85.180:15149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSBNtO5rbWdOArH04Ks3wAAASo"]
[Tue Aug 18 12:58:46.331392 2026] [security2:error] [pid 66623:tid 66834] [client 20.203.138.185:17843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/gec.php"] [unique_id "aoSBNtO5rbWdOArH04Ks4AAAAU4"]
[Tue Aug 18 12:58:46.359507 2026] [security2:error] [pid 66623:tid 66875] [client 74.248.18.37:8111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/tools.php"] [unique_id "aoSBNtO5rbWdOArH04Ks4gAAAXc"]
[Tue Aug 18 12:58:46.361381 2026] [security2:error] [pid 66623:tid 66770] [client 74.248.18.37:47279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-content.php"] [unique_id "aoSBNtO5rbWdOArH04Ks4wAAAQ4"]
[Tue Aug 18 12:58:46.368682 2026] [security2:error] [pid 66623:tid 66851] [client 20.127.136.245:17916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/222.php"] [unique_id "aoSBNtO5rbWdOArH04Ks5AAAAV8"]
[Tue Aug 18 12:58:46.368686 2026] [security2:error] [pid 66623:tid 66885] [client 40.74.65.169:20113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/alls.php"] [unique_id "aoSBNtO5rbWdOArH04Ks5QAAAYE"]
[Tue Aug 18 12:58:46.374883 2026] [security2:error] [pid 66623:tid 66797] [client 85.154.68.202:17889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBNtO5rbWdOArH04Ks5wAAASk"]
[Tue Aug 18 12:58:46.375001 2026] [security2:error] [pid 66623:tid 66797] [client 85.154.68.202:17889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBNtO5rbWdOArH04Ks5wAAASk"]
[Tue Aug 18 12:58:46.382947 2026] [security2:error] [pid 66623:tid 66829] [client 20.119.58.187:11985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/blogs.dir/php8.php"] [unique_id "aoSBNtO5rbWdOArH04Ks6AAAAUk"]
[Tue Aug 18 12:58:46.386445 2026] [security2:error] [pid 66623:tid 66686] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ev.php"] [unique_id "aoSBNtO5rbWdOArH04Ks6QABejE"]
[Tue Aug 18 12:58:46.407323 2026] [authz_core:error] [pid 66623:tid 66646] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:46.407598 2026] [authz_core:error] [pid 66623:tid 66646] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:46.442123 2026] [security2:error] [pid 66623:tid 66837] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/signon.php"] [unique_id "aoSBNtO5rbWdOArH04Ks7QAAAVE"]
[Tue Aug 18 12:58:46.492220 2026] [security2:error] [pid 66623:tid 66820] [client 52.173.121.69:42736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSBNtO5rbWdOArH04Ks8wAAAUA"]
[Tue Aug 18 12:58:46.511231 2026] [core:notice] [pid 66623:tid 66697] AH00113: /home3/uniaonutri/public_html/.htaccess:34 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Tue Aug 18 12:58:46.538832 2026] [security2:error] [pid 66623:tid 66833] [client 52.173.121.69:25009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBNtO5rbWdOArH04Ks-wAAAU0"]
[Tue Aug 18 12:58:46.546769 2026] [security2:error] [pid 66623:tid 66825] [client 68.155.155.199:6131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/dropdown.php"] [unique_id "aoSBNtO5rbWdOArH04Ks_AAAAUU"]
[Tue Aug 18 12:58:46.600806 2026] [security2:error] [pid 66623:tid 66821] [client 132.196.30.78:14651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wk/index.php"] [unique_id "aoSBNtO5rbWdOArH04Ks_QAAAUE"]
[Tue Aug 18 12:58:46.602171 2026] [security2:error] [pid 66623:tid 66674] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/xs.php"] [unique_id "aoSBNtO5rbWdOArH04Ks_gABTCU"]
[Tue Aug 18 12:58:46.605552 2026] [security2:error] [pid 66623:tid 66789] [client 4.232.151.198:6128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/moddofuns.php"] [unique_id "aoSBNtO5rbWdOArH04Ks_wAAASE"]
[Tue Aug 18 12:58:46.691429 2026] [security2:error] [pid 66623:tid 66810] [client 20.104.85.180:1577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/new.php"] [unique_id "aoSBNtO5rbWdOArH04KtBQAAATY"]
[Tue Aug 18 12:58:46.714569 2026] [authz_core:error] [pid 66623:tid 66643] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:46.715040 2026] [authz_core:error] [pid 66623:tid 66643] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:46.738216 2026] [security2:error] [pid 66623:tid 66795] [client 20.25.139.174:4666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBNtO5rbWdOArH04KtCAAAASc"]
[Tue Aug 18 12:58:46.746676 2026] [security2:error] [pid 66623:tid 66862] [client 20.119.58.187:12244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/images/php8.php"] [unique_id "aoSBNtO5rbWdOArH04KtCgAAAWo"]
[Tue Aug 18 12:58:46.757779 2026] [security2:error] [pid 66623:tid 66772] [client 172.182.200.96:14116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSBNtO5rbWdOArH04KtCwAAARA"]
[Tue Aug 18 12:58:46.806595 2026] [security2:error] [pid 66623:tid 66706] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/lmfi2.php"] [unique_id "aoSBNtO5rbWdOArH04KtDAABUEU"]
[Tue Aug 18 12:58:46.855600 2026] [security2:error] [pid 66623:tid 66767] [client 20.118.172.148:58803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/update/da222.php"] [unique_id "aoSBNtO5rbWdOArH04KtEAAAAQs"]
[Tue Aug 18 12:58:46.892416 2026] [security2:error] [pid 66623:tid 66874] [client 20.250.13.23:1800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBNtO5rbWdOArH04KtEgAAAXY"]
[Tue Aug 18 12:58:46.900426 2026] [security2:error] [pid 66623:tid 66808] [client 5.253.84.92:59751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.84.253.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sindsecurpr.com.br"] [uri "/wp-login.php"] [unique_id "aoSBNtO5rbWdOArH04KtFAAAATQ"]
[Tue Aug 18 12:58:46.949239 2026] [security2:error] [pid 66623:tid 66865] [client 20.48.236.86:32856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/special.php"] [unique_id "aoSBNtO5rbWdOArH04KtGQAAAW0"]
[Tue Aug 18 12:58:46.960203 2026] [security2:error] [pid 66623:tid 66841] [client 4.232.94.69:54105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/02.php"] [unique_id "aoSBNtO5rbWdOArH04KtGgAAAVU"]
[Tue Aug 18 12:58:46.988735 2026] [security2:error] [pid 66623:tid 66883] [client 52.173.121.69:50201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSBNtO5rbWdOArH04KtHAAAAX8"]
[Tue Aug 18 12:58:47.004395 2026] [security2:error] [pid 66623:tid 66794] [client 79.127.164.8:35150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/site.bak"] [unique_id "aoSBN9O5rbWdOArH04KtIAAAASY"], referer: https://medihub.com.br/site.bak
[Tue Aug 18 12:58:47.008338 2026] [authz_core:error] [pid 66623:tid 66764] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:47.008608 2026] [authz_core:error] [pid 66623:tid 66764] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:47.014476 2026] [security2:error] [pid 66623:tid 66889] [client 20.127.136.245:23452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/asasx.php"] [unique_id "aoSBN9O5rbWdOArH04KtIQAAAYU"]
[Tue Aug 18 12:58:47.024987 2026] [security2:error] [pid 66623:tid 66815] [client 68.155.155.199:13302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/file.php"] [unique_id "aoSBN9O5rbWdOArH04KtIgAAATs"]
[Tue Aug 18 12:58:47.043385 2026] [security2:error] [pid 66623:tid 66702] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/fd.php"] [unique_id "aoSBN9O5rbWdOArH04KtIwABHUE"]
[Tue Aug 18 12:58:47.049392 2026] [security2:error] [pid 66623:tid 66838] [client 40.74.65.169:20150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/coffexium.php"] [unique_id "aoSBN9O5rbWdOArH04KtJAAAAVI"]
[Tue Aug 18 12:58:47.070834 2026] [security2:error] [pid 66623:tid 66834] [client 20.118.133.132:15579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/1xmomo.php"] [unique_id "aoSBN9O5rbWdOArH04KtJwAAAU4"]
[Tue Aug 18 12:58:47.070885 2026] [security2:error] [pid 66623:tid 66798] [client 20.104.85.180:27965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBN9O5rbWdOArH04KtKAAAASo"]
[Tue Aug 18 12:58:47.096074 2026] [security2:error] [pid 66623:tid 66844] [client 74.248.18.37:7613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/txets.php"] [unique_id "aoSBN9O5rbWdOArH04KtKgAAAVg"]
[Tue Aug 18 12:58:47.099325 2026] [security2:error] [pid 66623:tid 66770] [client 20.206.73.37:20684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/clque.php"] [unique_id "aoSBN9O5rbWdOArH04KtKwAAAQ4"]
[Tue Aug 18 12:58:47.102789 2026] [security2:error] [pid 66623:tid 66805] [client 20.119.58.187:12277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/php8.php"] [unique_id "aoSBN9O5rbWdOArH04KtLAAAATE"]
[Tue Aug 18 12:58:47.158628 2026] [security2:error] [pid 66623:tid 66813] [client 132.196.30.78:14631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/about.php"] [unique_id "aoSBN9O5rbWdOArH04KtLgAAATk"]
[Tue Aug 18 12:58:47.213987 2026] [security2:error] [pid 66623:tid 66837] [client 52.173.121.69:25021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSBN9O5rbWdOArH04KtMQAAAVE"]
[Tue Aug 18 12:58:47.227647 2026] [security2:error] [pid 66623:tid 66788] [client 4.232.151.198:6121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/system_log.php"] [unique_id "aoSBN9O5rbWdOArH04KtMgAAASA"]
[Tue Aug 18 12:58:47.244548 2026] [security2:error] [pid 66623:tid 66749] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/info2.php"] [unique_id "aoSBN9O5rbWdOArH04KtNQABMnA"]
[Tue Aug 18 12:58:47.251346 2026] [security2:error] [pid 66623:tid 66775] [client 20.104.85.180:20268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/222.php"] [unique_id "aoSBN9O5rbWdOArH04KtNgAAARM"]
[Tue Aug 18 12:58:47.256694 2026] [security2:error] [pid 66623:tid 66880] [client 20.203.138.185:18337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/scx.php7"] [unique_id "aoSBN9O5rbWdOArH04KtNwAAAXw"]
[Tue Aug 18 12:58:47.286476 2026] [security2:error] [pid 66623:tid 66851] [client 20.25.139.174:4659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/666.php"] [unique_id "aoSBN9O5rbWdOArH04KtOQAAAV8"]
[Tue Aug 18 12:58:47.316607 2026] [security2:error] [pid 66623:tid 66782] [client 213.35.127.232:54656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBN9O5rbWdOArH04KtOgAAARo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:47.354527 2026] [security2:error] [pid 66623:tid 66854] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/file61.php"] [unique_id "aoSBN9O5rbWdOArH04KtPAAAAWI"]
[Tue Aug 18 12:58:47.388584 2026] [security2:error] [pid 66623:tid 66771] [client 74.248.18.37:7727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSBN9O5rbWdOArH04KtQAAAAQ8"]
[Tue Aug 18 12:58:47.398900 2026] [security2:error] [pid 66623:tid 66823] [client 158.23.17.4:56763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/fresh.php"] [unique_id "aoSBN9O5rbWdOArH04KtQQAAAUM"]
[Tue Aug 18 12:58:47.445112 2026] [security2:error] [pid 66623:tid 66810] [client 52.173.121.69:48319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSBN9O5rbWdOArH04KtRwAAATY"]
[Tue Aug 18 12:58:47.448993 2026] [security2:error] [pid 66623:tid 66866] [client 213.202.253.4:64071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/postnews.php"] [unique_id "aoSBN9O5rbWdOArH04KtSgAAAW4"], referer: www.google.com
[Tue Aug 18 12:58:47.475220 2026] [security2:error] [pid 66623:tid 66742] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/sx.php"] [unique_id "aoSBN9O5rbWdOArH04KtTQABamk"]
[Tue Aug 18 12:58:47.502194 2026] [security2:error] [pid 66623:tid 66777] [client 20.250.13.23:1802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSBN9O5rbWdOArH04KtUgAAARU"]
[Tue Aug 18 12:58:47.511475 2026] [security2:error] [pid 66623:tid 66856] [client 114.119.149.169:45915] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "classeamotel.com"] [uri "/robots.txt"] [unique_id "aoSBN9O5rbWdOArH04KtUwAAAWQ"], referer: https://classeamotel.com/robots.txt
[Tue Aug 18 12:58:47.537386 2026] [security2:error] [pid 66623:tid 66792] [client 20.119.58.187:12513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/php8.php"] [unique_id "aoSBN9O5rbWdOArH04KtWgAAASQ"]
[Tue Aug 18 12:58:47.595430 2026] [security2:error] [pid 66623:tid 66874] [client 20.127.136.245:1596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/filemanager.php"] [unique_id "aoSBN9O5rbWdOArH04KtYgAAAXY"]
[Tue Aug 18 12:58:47.608604 2026] [authz_core:error] [pid 66623:tid 66718] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:47.608871 2026] [authz_core:error] [pid 66623:tid 66718] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:47.637912 2026] [security2:error] [pid 66623:tid 66858] [client 52.173.121.69:17957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSBN9O5rbWdOArH04KtaQAAAWY"]
[Tue Aug 18 12:58:47.666578 2026] [security2:error] [pid 66623:tid 66776] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/copypaths.php"] [unique_id "aoSBN9O5rbWdOArH04KtbAAAARQ"]
[Tue Aug 18 12:58:47.680781 2026] [security2:error] [pid 66623:tid 66883] [client 192.141.172.134:51988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBN9O5rbWdOArH04KtbgAAAX8"]
[Tue Aug 18 12:58:47.680906 2026] [security2:error] [pid 66623:tid 66883] [client 192.141.172.134:51988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBN9O5rbWdOArH04KtbgAAAX8"]
[Tue Aug 18 12:58:47.681333 2026] [security2:error] [pid 66623:tid 66739] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/nu.php"] [unique_id "aoSBN9O5rbWdOArH04KtbwABTmY"]
[Tue Aug 18 12:58:47.717418 2026] [security2:error] [pid 66623:tid 66844] [client 20.104.85.180:52547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/chosen.php"] [unique_id "aoSBN9O5rbWdOArH04KtcQAAAVg"]
[Tue Aug 18 12:58:47.724537 2026] [security2:error] [pid 66623:tid 66770] [client 172.182.200.96:7679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBN9O5rbWdOArH04KtdAAAAQ4"]
[Tue Aug 18 12:58:47.735796 2026] [security2:error] [pid 66623:tid 66885] [client 40.74.65.169:20101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/red.php"] [unique_id "aoSBN9O5rbWdOArH04KtdQAAAYE"]
[Tue Aug 18 12:58:47.782628 2026] [security2:error] [pid 66623:tid 66778] [client 20.118.172.148:2701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/upload.php"] [unique_id "aoSBN9O5rbWdOArH04KtdwAAARY"]
[Tue Aug 18 12:58:47.795784 2026] [security2:error] [pid 66623:tid 66867] [client 132.196.30.78:15660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/term.php"] [unique_id "aoSBN9O5rbWdOArH04KteAAAAW8"]
[Tue Aug 18 12:58:47.812623 2026] [security2:error] [pid 66623:tid 66886] [client 74.248.18.37:7567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/u.php"] [unique_id "aoSBN9O5rbWdOArH04KtegAAAYI"]
[Tue Aug 18 12:58:47.858533 2026] [security2:error] [pid 66623:tid 66835] [client 4.232.151.198:58727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/motu.php"] [unique_id "aoSBN9O5rbWdOArH04KtfgAAAU8"]
[Tue Aug 18 12:58:47.878544 2026] [security2:error] [pid 66623:tid 66882] [client 20.48.236.86:2319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/fz.php"] [unique_id "aoSBN9O5rbWdOArH04KtfwAAAX4"]
[Tue Aug 18 12:58:47.890731 2026] [security2:error] [pid 66623:tid 66720] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ko.php"] [unique_id "aoSBN9O5rbWdOArH04KtgQABLlM"]
[Tue Aug 18 12:58:47.891988 2026] [security2:error] [pid 66623:tid 66876] [client 20.119.58.187:12246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/gallery/php8.php"] [unique_id "aoSBN9O5rbWdOArH04KtggAAAXg"]
[Tue Aug 18 12:58:47.894527 2026] [security2:error] [pid 66623:tid 66857] [client 172.202.39.151:44500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/f35.php"] [unique_id "aoSBN9O5rbWdOArH04KtgwAAAWU"]
[Tue Aug 18 12:58:47.901903 2026] [security2:error] [pid 66623:tid 66818] [client 52.173.121.69:35546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSBN9O5rbWdOArH04KthwAAAT4"]
[Tue Aug 18 12:58:47.904217 2026] [authz_core:error] [pid 66623:tid 66741] [remote 57.141.22.33:46288] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:47.904571 2026] [authz_core:error] [pid 66623:tid 66741] [remote 57.141.22.33:46288] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:47.910573 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:47.910845 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:47.912008 2026] [security2:error] [pid 66623:tid 66860] [client 20.100.169.31:12536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/ws83.php"] [unique_id "aoSBN9O5rbWdOArH04KtiQAAAWg"]
[Tue Aug 18 12:58:48.012329 2026] [security2:error] [pid 66623:tid 66864] [client 158.23.17.4:40441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/gj.php"] [unique_id "aoSBONO5rbWdOArH04KtkAAAAWw"]
[Tue Aug 18 12:58:48.036917 2026] [security2:error] [pid 66623:tid 66854] [client 68.155.155.199:1448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/goods.php"] [unique_id "aoSBONO5rbWdOArH04KtkgAAAWI"]
[Tue Aug 18 12:58:48.067124 2026] [security2:error] [pid 66623:tid 66817] [client 74.248.18.37:8102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-content/ad4599c5/admin.php"] [unique_id "aoSBONO5rbWdOArH04KtkwAAAT0"]
[Tue Aug 18 12:58:48.069028 2026] [security2:error] [pid 66623:tid 66869] [client 172.202.39.151:4701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/gelay.php"] [unique_id "aoSBONO5rbWdOArH04KtlAAAAXE"]
[Tue Aug 18 12:58:48.160095 2026] [security2:error] [pid 66623:tid 66719] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/pl.php"] [unique_id "aoSBONO5rbWdOArH04KtmQABhFI"]
[Tue Aug 18 12:58:48.173699 2026] [security2:error] [pid 66623:tid 66851] [client 20.250.13.23:53651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBONO5rbWdOArH04KtmgAAAV8"]
[Tue Aug 18 12:58:48.220085 2026] [authz_core:error] [pid 66623:tid 66763] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:48.220377 2026] [authz_core:error] [pid 66623:tid 66763] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:48.236140 2026] [security2:error] [pid 66623:tid 66772] [client 20.104.85.180:57722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSBONO5rbWdOArH04KtoQAAARA"]
[Tue Aug 18 12:58:48.261415 2026] [security2:error] [pid 66623:tid 66881] [client 20.119.58.187:11969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/blocks/php8.php"] [unique_id "aoSBONO5rbWdOArH04KtpAAAAX0"]
[Tue Aug 18 12:58:48.263182 2026] [security2:error] [pid 66623:tid 66836] [client 20.203.138.185:18495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-admin/sc.php"] [unique_id "aoSBONO5rbWdOArH04KtpQAAAVA"]
[Tue Aug 18 12:58:48.274263 2026] [security2:error] [pid 66623:tid 66821] [client 20.206.73.37:59957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/nano.php"] [unique_id "aoSBONO5rbWdOArH04KtqAAAAUE"]
[Tue Aug 18 12:58:48.278397 2026] [security2:error] [pid 66623:tid 66804] [client 172.182.200.96:7570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSBONO5rbWdOArH04KtqQAAATA"]
[Tue Aug 18 12:58:48.282315 2026] [security2:error] [pid 66623:tid 66822] [client 52.173.121.69:47326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSBONO5rbWdOArH04KtqgAAAUI"]
[Tue Aug 18 12:58:48.300823 2026] [security2:error] [pid 66623:tid 66874] [client 20.104.85.180:52569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/info.php"] [unique_id "aoSBONO5rbWdOArH04KtqwAAAXY"]
[Tue Aug 18 12:58:48.329732 2026] [security2:error] [pid 66623:tid 66872] [client 213.35.127.232:54861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBONO5rbWdOArH04KtrAAAAXQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:48.335770 2026] [security2:error] [pid 66623:tid 66709] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/env.php"] [unique_id "aoSBONO5rbWdOArH04KtrQABNEg"]
[Tue Aug 18 12:58:48.386907 2026] [security2:error] [pid 66623:tid 66890] [client 20.25.139.174:4546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/ws54.php"] [unique_id "aoSBONO5rbWdOArH04KtsQAAAYY"]
[Tue Aug 18 12:58:48.391867 2026] [security2:error] [pid 66623:tid 66856] [client 178.156.185.231:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bn2s.com.br"] [uri "/index.php"] [unique_id "aoSBONO5rbWdOArH04KtogAAAWQ"], referer: https://bn2s.com.br/
[Tue Aug 18 12:58:48.435468 2026] [security2:error] [pid 66623:tid 66776] [client 20.118.172.148:33488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wk/index.php"] [unique_id "aoSBONO5rbWdOArH04KttgAAARQ"]
[Tue Aug 18 12:58:48.456757 2026] [security2:error] [pid 66623:tid 66798] [client 52.173.121.69:24982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBONO5rbWdOArH04KtuAAAASo"]
[Tue Aug 18 12:58:48.478610 2026] [security2:error] [pid 66623:tid 66871] [client 74.248.18.37:8084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ultra.php"] [unique_id "aoSBONO5rbWdOArH04KtuQAAAXM"]
[Tue Aug 18 12:58:48.486626 2026] [security2:error] [pid 66623:tid 66792] [client 132.196.30.78:15635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBONO5rbWdOArH04KtugAAASQ"]
[Tue Aug 18 12:58:48.498754 2026] [security2:error] [pid 66623:tid 66870] [client 4.232.151.198:30023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/uploads/2024//chosen.php"] [unique_id "aoSBONO5rbWdOArH04KtuwAAAXI"]
[Tue Aug 18 12:58:48.521825 2026] [authz_core:error] [pid 66623:tid 66637] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:48.522094 2026] [authz_core:error] [pid 66623:tid 66637] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:48.576672 2026] [security2:error] [pid 66623:tid 66848] [client 20.127.136.245:14520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/themes.php"] [unique_id "aoSBONO5rbWdOArH04KtvgAAAVw"]
[Tue Aug 18 12:58:48.587343 2026] [security2:error] [pid 66623:tid 66673] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/mz.php"] [unique_id "aoSBONO5rbWdOArH04KtvwABfiQ"]
[Tue Aug 18 12:58:48.600109 2026] [security2:error] [pid 66623:tid 66815] [client 20.25.139.174:4656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/inputs.php"] [unique_id "aoSBONO5rbWdOArH04KtwAAAATs"]
[Tue Aug 18 12:58:48.672865 2026] [security2:error] [pid 66623:tid 66791] [client 20.250.13.23:7835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/elp.php"] [unique_id "aoSBONO5rbWdOArH04KtwwAAASM"]
[Tue Aug 18 12:58:48.728111 2026] [security2:error] [pid 66623:tid 66816] [client 74.248.18.37:8098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBONO5rbWdOArH04KtxgAAATw"]
[Tue Aug 18 12:58:48.773972 2026] [security2:error] [pid 66623:tid 66675] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ft.php"] [unique_id "aoSBONO5rbWdOArH04KtyAABYiY"]
[Tue Aug 18 12:58:48.775044 2026] [security2:error] [pid 66623:tid 66825] [client 20.104.85.180:59523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/an.php"] [unique_id "aoSBONO5rbWdOArH04KtyQAAAUU"]
[Tue Aug 18 12:58:48.801748 2026] [security2:error] [pid 66623:tid 66863] [client 168.62.48.100:1116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBONO5rbWdOArH04KtygAAAWs"]
[Tue Aug 18 12:58:48.812978 2026] [security2:error] [pid 66623:tid 66789] [client 52.173.121.69:14535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSBONO5rbWdOArH04KtzAAAASE"]
[Tue Aug 18 12:58:48.818949 2026] [security2:error] [pid 66623:tid 66817] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/bless6.php"] [unique_id "aoSBONO5rbWdOArH04KtzQAAAT0"]
[Tue Aug 18 12:58:48.819602 2026] [security2:error] [pid 66623:tid 66835] [client 20.250.13.23:53663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSBONO5rbWdOArH04KtzgAAAU8"]
[Tue Aug 18 12:58:48.867030 2026] [security2:error] [pid 66623:tid 66851] [client 68.155.155.199:6544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBONO5rbWdOArH04KtzwAAAV8"]
[Tue Aug 18 12:58:48.935334 2026] [security2:error] [pid 66623:tid 66836] [client 20.206.73.37:59941] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "villasgarage.com.br"] [uri "/.mopj.php"] [unique_id "aoSBONO5rbWdOArH04Kt0gAAAVA"]
[Tue Aug 18 12:58:48.963871 2026] [security2:error] [pid 66623:tid 66859] [client 20.25.139.174:4628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSBONO5rbWdOArH04Kt1AAAAWc"]
[Tue Aug 18 12:58:48.972412 2026] [security2:error] [pid 66623:tid 66685] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/h.php"] [unique_id "aoSBONO5rbWdOArH04Kt1QABQjA"]
[Tue Aug 18 12:58:48.988341 2026] [security2:error] [pid 66623:tid 66788] [client 20.118.172.148:33484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-act.php"] [unique_id "aoSBONO5rbWdOArH04Kt1gAAASA"]
[Tue Aug 18 12:58:48.998757 2026] [security2:error] [pid 66623:tid 66874] [client 52.173.121.69:16449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSBONO5rbWdOArH04Kt2AAAAXY"]
[Tue Aug 18 12:58:49.041099 2026] [security2:error] [pid 66623:tid 66775] [client 132.196.30.78:14992] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.cadema.com.br"] [uri "/1.php"] [unique_id "aoSBOdO5rbWdOArH04Kt2gAAARM"]
[Tue Aug 18 12:58:49.041200 2026] [security2:error] [pid 66623:tid 66775] [client 132.196.30.78:14992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/1.php"] [unique_id "aoSBOdO5rbWdOArH04Kt2gAAARM"]
[Tue Aug 18 12:58:49.069453 2026] [security2:error] [pid 66623:tid 66808] [client 168.62.48.100:1079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBOdO5rbWdOArH04Kt3AAAATQ"]
[Tue Aug 18 12:58:49.101674 2026] [security2:error] [pid 66623:tid 66769] [client 172.182.200.96:7657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSBOdO5rbWdOArH04Kt3wAAAQ0"]
[Tue Aug 18 12:58:49.113709 2026] [security2:error] [pid 66623:tid 66800] [client 20.25.139.174:4668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/admin.php"] [unique_id "aoSBOdO5rbWdOArH04Kt4QAAASw"]
[Tue Aug 18 12:58:49.117348 2026] [authz_core:error] [pid 66623:tid 66727] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:49.117607 2026] [authz_core:error] [pid 66623:tid 66727] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:49.125490 2026] [security2:error] [pid 66623:tid 66803] [client 74.248.18.37:8078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/un.php"] [unique_id "aoSBOdO5rbWdOArH04Kt4gAAAS8"]
[Tue Aug 18 12:58:49.129238 2026] [security2:error] [pid 66623:tid 66890] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/special.php"] [unique_id "aoSBOdO5rbWdOArH04Kt5AAAAYY"]
[Tue Aug 18 12:58:49.182020 2026] [security2:error] [pid 66623:tid 66842] [client 52.173.121.69:50236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSBOdO5rbWdOArH04Kt6QAAAVY"]
[Tue Aug 18 12:58:49.184553 2026] [security2:error] [pid 66623:tid 66768] [client 4.232.151.198:6135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/help.php"] [unique_id "aoSBOdO5rbWdOArH04Kt6gAAAQw"]
[Tue Aug 18 12:58:49.263642 2026] [security2:error] [pid 66623:tid 66792] [client 158.23.17.4:7190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/pd.php"] [unique_id "aoSBOdO5rbWdOArH04Kt7AAAASQ"]
[Tue Aug 18 12:58:49.266758 2026] [security2:error] [pid 66623:tid 66738] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/40.php"] [unique_id "aoSBOdO5rbWdOArH04Kt7gABgWU"]
[Tue Aug 18 12:58:49.321317 2026] [security2:error] [pid 66623:tid 66778] [client 168.62.48.100:1095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/weozh.php"] [unique_id "aoSBOdO5rbWdOArH04Kt7wAAARY"]
[Tue Aug 18 12:58:49.324699 2026] [security2:error] [pid 66623:tid 66867] [client 20.203.138.185:47140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp5.php"] [unique_id "aoSBOdO5rbWdOArH04Kt8AAAAW8"]
[Tue Aug 18 12:58:49.341654 2026] [security2:error] [pid 66623:tid 66873] [client 20.104.85.180:20272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBOdO5rbWdOArH04Kt8QAAAXU"]
[Tue Aug 18 12:58:49.353581 2026] [security2:error] [pid 66623:tid 66852] [client 213.35.127.232:55051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBOdO5rbWdOArH04Kt8gAAAWA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:49.410697 2026] [security2:error] [pid 66623:tid 66876] [client 52.173.121.69:24775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSBOdO5rbWdOArH04Kt9QAAAXg"]
[Tue Aug 18 12:58:49.418980 2026] [authz_core:error] [pid 66623:tid 66689] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:49.419243 2026] [authz_core:error] [pid 66623:tid 66689] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:49.445609 2026] [security2:error] [pid 66623:tid 66733] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ee.php"] [unique_id "aoSBOdO5rbWdOArH04Kt9wABPmA"]
[Tue Aug 18 12:58:49.485283 2026] [security2:error] [pid 66623:tid 66870] [client 20.250.13.23:53637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSBOdO5rbWdOArH04Kt-gAAAXI"]
[Tue Aug 18 12:58:49.512350 2026] [security2:error] [pid 66623:tid 66819] [client 20.48.236.86:36109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/clque.php"] [unique_id "aoSBOdO5rbWdOArH04Kt_AAAAT8"]
[Tue Aug 18 12:58:49.541374 2026] [security2:error] [pid 66623:tid 66833] [client 68.155.155.199:12895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/htaccess.php"] [unique_id "aoSBOdO5rbWdOArH04Kt_gAAAU0"]
[Tue Aug 18 12:58:49.589946 2026] [security2:error] [pid 66623:tid 66826] [client 168.62.48.100:1105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/rymmm.php"] [unique_id "aoSBOdO5rbWdOArH04Kt_wAAAUY"]
[Tue Aug 18 12:58:49.621551 2026] [security2:error] [pid 66623:tid 66868] [client 20.118.172.148:46763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSBOdO5rbWdOArH04KuAQAAAXA"]
[Tue Aug 18 12:58:49.629351 2026] [security2:error] [pid 66623:tid 66825] [client 20.104.85.180:15709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/404.php"] [unique_id "aoSBOdO5rbWdOArH04KuAgAAAUU"]
[Tue Aug 18 12:58:49.635346 2026] [security2:error] [pid 66623:tid 66882] [client 20.25.139.174:4545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/function/function.php"] [unique_id "aoSBOdO5rbWdOArH04KuBQAAAX4"]
[Tue Aug 18 12:58:49.636700 2026] [security2:error] [pid 66623:tid 66849] [client 52.173.121.69:27875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSBOdO5rbWdOArH04KuBgAAAV0"]
[Tue Aug 18 12:58:49.669414 2026] [security2:error] [pid 66623:tid 66744] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ak.php"] [unique_id "aoSBOdO5rbWdOArH04KuBwABIWs"]
[Tue Aug 18 12:58:49.670267 2026] [security2:error] [pid 66623:tid 66860] [client 132.196.30.78:22174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/alfa.php"] [unique_id "aoSBOdO5rbWdOArH04KuCAAAAWg"]
[Tue Aug 18 12:58:49.684322 2026] [security2:error] [pid 66623:tid 66820] [client 20.127.136.245:17047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBOdO5rbWdOArH04KuCQAAAUA"]
[Tue Aug 18 12:58:49.721777 2026] [authz_core:error] [pid 66623:tid 66696] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:49.722031 2026] [authz_core:error] [pid 66623:tid 66696] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:49.791585 2026] [security2:error] [pid 66623:tid 66827] [client 74.248.18.37:7565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/up.php"] [unique_id "aoSBOdO5rbWdOArH04KuDQAAAUc"]
[Tue Aug 18 12:58:49.829644 2026] [security2:error] [pid 66623:tid 66863] [client 20.25.139.174:4573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/goods.php"] [unique_id "aoSBOdO5rbWdOArH04KuEAAAAWs"]
[Tue Aug 18 12:58:49.830177 2026] [security2:error] [pid 66623:tid 66880] [client 4.232.151.198:58695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/js/about.php"] [unique_id "aoSBOdO5rbWdOArH04KuEQAAAXw"]
[Tue Aug 18 12:58:49.854999 2026] [security2:error] [pid 66623:tid 66821] [client 168.62.48.100:1080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/lddxs.php"] [unique_id "aoSBOdO5rbWdOArH04KuFAAAAUE"]
[Tue Aug 18 12:58:49.906520 2026] [security2:error] [pid 66623:tid 66728] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/test_info.php"] [unique_id "aoSBOdO5rbWdOArH04KuFwABJVs"]
[Tue Aug 18 12:58:49.936637 2026] [security2:error] [pid 66623:tid 66788] [client 52.173.121.69:24778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBOdO5rbWdOArH04KuGQAAASA"]
[Tue Aug 18 12:58:49.970261 2026] [security2:error] [pid 66623:tid 66865] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/fz.php"] [unique_id "aoSBOdO5rbWdOArH04KuHwAAAW0"]
[Tue Aug 18 12:58:50.021759 2026] [authz_core:error] [pid 66623:tid 66676] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:50.022019 2026] [authz_core:error] [pid 66623:tid 66676] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:50.030427 2026] [security2:error] [pid 66623:tid 66877] [client 196.12.128.158:59939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBOtO5rbWdOArH04KuIwAAAXk"]
[Tue Aug 18 12:58:50.030532 2026] [security2:error] [pid 66623:tid 66877] [client 196.12.128.158:59939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBOtO5rbWdOArH04KuIwAAAXk"]
[Tue Aug 18 12:58:50.044220 2026] [security2:error] [pid 66623:tid 66797] [client 52.173.121.69:48296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSBOtO5rbWdOArH04KuJAAAASk"]
[Tue Aug 18 12:58:50.051359 2026] [security2:error] [pid 66623:tid 66806] [client 20.250.13.23:46820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBOtO5rbWdOArH04KuJQAAATI"]
[Tue Aug 18 12:58:50.082183 2026] [security2:error] [pid 66623:tid 66776] [client 68.155.155.199:1441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/images/wso.php"] [unique_id "aoSBOtO5rbWdOArH04KuJwAAARQ"]
[Tue Aug 18 12:58:50.115581 2026] [security2:error] [pid 66623:tid 66831] [client 20.250.13.23:53659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBOtO5rbWdOArH04KuKQAAAUs"]
[Tue Aug 18 12:58:50.128267 2026] [security2:error] [pid 66623:tid 66855] [client 20.25.139.174:4629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/nw.php"] [unique_id "aoSBOtO5rbWdOArH04KuKgAAAWM"]
[Tue Aug 18 12:58:50.129262 2026] [security2:error] [pid 66623:tid 66862] [client 168.62.48.100:1059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/zjggu.php"] [unique_id "aoSBOtO5rbWdOArH04KuKwAAAWo"]
[Tue Aug 18 12:58:50.136451 2026] [security2:error] [pid 66623:tid 66657] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/14.php"] [unique_id "aoSBOtO5rbWdOArH04KuLAABDBQ"]
[Tue Aug 18 12:58:50.164174 2026] [security2:error] [pid 66623:tid 66871] [client 20.104.85.180:26705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-login.php"] [unique_id "aoSBOtO5rbWdOArH04KuLgAAAXM"]
[Tue Aug 18 12:58:50.224926 2026] [security2:error] [pid 66623:tid 66884] [client 4.232.94.69:54088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/menu.php"] [unique_id "aoSBOtO5rbWdOArH04KuMQAAAYA"]
[Tue Aug 18 12:58:50.243058 2026] [security2:error] [pid 66623:tid 66798] [client 132.196.30.78:14990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/edit.php"] [unique_id "aoSBOtO5rbWdOArH04KuMgAAASo"]
[Tue Aug 18 12:58:50.287535 2026] [security2:error] [pid 66623:tid 66848] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/clque.php"] [unique_id "aoSBOtO5rbWdOArH04KuNAAAAVw"]
[Tue Aug 18 12:58:50.333352 2026] [security2:error] [pid 66623:tid 66693] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/tk.php"] [unique_id "aoSBOtO5rbWdOArH04KuNQABeDg"]
[Tue Aug 18 12:58:50.342263 2026] [security2:error] [pid 66623:tid 66843] [client 20.25.139.174:4661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/file.php"] [unique_id "aoSBOtO5rbWdOArH04KuOAAAAVc"]
[Tue Aug 18 12:58:50.347891 2026] [security2:error] [pid 66623:tid 66791] [client 158.23.17.4:56755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/th.php"] [unique_id "aoSBOtO5rbWdOArH04KuOQAAASM"]
[Tue Aug 18 12:58:50.374632 2026] [security2:error] [pid 66623:tid 66856] [client 213.35.127.232:55255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBOtO5rbWdOArH04KuPAAAAWQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:50.434755 2026] [security2:error] [pid 66623:tid 66864] [client 168.62.48.100:1042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/dlvqo.php"] [unique_id "aoSBOtO5rbWdOArH04KuQQAAAWw"]
[Tue Aug 18 12:58:50.472117 2026] [security2:error] [pid 66623:tid 66825] [client 52.173.121.69:17978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBOtO5rbWdOArH04KuQwAAAUU"]
[Tue Aug 18 12:58:50.496834 2026] [security2:error] [pid 66623:tid 66849] [client 172.182.200.96:7651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSBOtO5rbWdOArH04KuRAAAAV0"]
[Tue Aug 18 12:58:50.510064 2026] [security2:error] [pid 66623:tid 66770] [client 4.232.151.198:30017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/hplfuns.php"] [unique_id "aoSBOtO5rbWdOArH04KuRgAAAQ4"]
[Tue Aug 18 12:58:50.519528 2026] [security2:error] [pid 66623:tid 66832] [client 172.202.39.151:4451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBOtO5rbWdOArH04KuRwAAAUw"]
[Tue Aug 18 12:58:50.522717 2026] [security2:error] [pid 66623:tid 66756] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/hp.php"] [unique_id "aoSBOtO5rbWdOArH04KuSgABT3c"]
[Tue Aug 18 12:58:50.523911 2026] [security2:error] [pid 66623:tid 66820] [client 52.173.121.69:50224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSBOtO5rbWdOArH04KuSwAAAUA"]
[Tue Aug 18 12:58:50.572516 2026] [security2:error] [pid 66623:tid 66846] [client 157.51.166.53:54127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBOtO5rbWdOArH04KuTgAAAVo"]
[Tue Aug 18 12:58:50.572668 2026] [security2:error] [pid 66623:tid 66846] [client 157.51.166.53:54127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBOtO5rbWdOArH04KuTgAAAVo"]
[Tue Aug 18 12:58:50.585013 2026] [security2:error] [pid 66623:tid 66847] [client 79.127.164.8:35198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/site.sql"] [unique_id "aoSBOtO5rbWdOArH04KuTwAAAVs"], referer: https://medihub.com.br/site.sql
[Tue Aug 18 12:58:50.615905 2026] [security2:error] [pid 66623:tid 66866] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/nano.php"] [unique_id "aoSBOtO5rbWdOArH04KuUAAAAW4"]
[Tue Aug 18 12:58:50.619260 2026] [security2:error] [pid 66623:tid 66790] [client 20.203.138.185:18328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/a2.php"] [unique_id "aoSBOtO5rbWdOArH04KuUgAAASI"]
[Tue Aug 18 12:58:50.624577 2026] [authz_core:error] [pid 66623:tid 66639] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:50.624842 2026] [authz_core:error] [pid 66623:tid 66639] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:50.639581 2026] [security2:error] [pid 66623:tid 66882] [client 20.25.139.174:4660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/xleet.php"] [unique_id "aoSBOtO5rbWdOArH04KuVQAAAX4"]
[Tue Aug 18 12:58:50.692357 2026] [security2:error] [pid 66623:tid 66793] [client 168.62.48.100:1065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/pkmoj.php"] [unique_id "aoSBOtO5rbWdOArH04KuWAAAASU"]
[Tue Aug 18 12:58:50.736371 2026] [security2:error] [pid 66623:tid 66775] [client 68.155.155.199:9675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/index/function.php"] [unique_id "aoSBOtO5rbWdOArH04KuWwAAARM"]
[Tue Aug 18 12:58:50.746175 2026] [security2:error] [pid 66623:tid 66808] [client 74.248.18.37:8067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/users.php"] [unique_id "aoSBOtO5rbWdOArH04KuXAAAATQ"]
[Tue Aug 18 12:58:50.757971 2026] [security2:error] [pid 66623:tid 66841] [client 20.127.136.245:7659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/buy.php"] [unique_id "aoSBOtO5rbWdOArH04KuXQAAAVU"]
[Tue Aug 18 12:58:50.773012 2026] [security2:error] [pid 66623:tid 66803] [client 20.104.85.180:18721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBOtO5rbWdOArH04KuXgAAAS8"]
[Tue Aug 18 12:58:50.778985 2026] [security2:error] [pid 66623:tid 66725] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/wx.php"] [unique_id "aoSBOtO5rbWdOArH04KuYAABeVg"]
[Tue Aug 18 12:58:50.807871 2026] [security2:error] [pid 66623:tid 66797] [client 20.48.236.86:25926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/nano.php"] [unique_id "aoSBOtO5rbWdOArH04KuYQAAASk"]
[Tue Aug 18 12:58:50.819164 2026] [security2:error] [pid 66623:tid 66800] [client 197.184.64.235:41946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBOtO5rbWdOArH04KuYwAAASw"]
[Tue Aug 18 12:58:50.828457 2026] [security2:error] [pid 66623:tid 66800] [client 197.184.64.235:41946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBOtO5rbWdOArH04KuYwAAASw"]
[Tue Aug 18 12:58:50.862488 2026] [security2:error] [pid 66623:tid 66768] [client 68.221.73.131:45128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBOtO5rbWdOArH04KuZwAAAQw"]
[Tue Aug 18 12:58:50.877942 2026] [security2:error] [pid 66623:tid 66788] [client 20.25.139.174:4617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBOtO5rbWdOArH04KuawAAASA"]
[Tue Aug 18 12:58:50.892330 2026] [security2:error] [pid 66623:tid 66821] [client 20.250.13.23:45712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSBOtO5rbWdOArH04KubAAAAUE"]
[Tue Aug 18 12:58:50.922228 2026] [authz_core:error] [pid 66623:tid 66732] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:50.922524 2026] [authz_core:error] [pid 66623:tid 66732] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:50.922898 2026] [security2:error] [pid 66623:tid 66812] [client 132.196.30.78:15012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/elp.php"] [unique_id "aoSBOtO5rbWdOArH04KucwAAATg"]
[Tue Aug 18 12:58:50.928323 2026] [security2:error] [pid 66623:tid 66884] [client 68.155.153.139:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "cnascimentoassessoria.com"] [uri "/.mopj.php"] [unique_id "aoSBOtO5rbWdOArH04KudAAAAYA"]
[Tue Aug 18 12:58:50.952997 2026] [security2:error] [pid 66623:tid 66695] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/dj.php"] [unique_id "aoSBOtO5rbWdOArH04KudQABbzo"]
[Tue Aug 18 12:58:50.974685 2026] [security2:error] [pid 66623:tid 66813] [client 20.104.85.180:42245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSBOtO5rbWdOArH04KudwAAATk"]
[Tue Aug 18 12:58:50.978062 2026] [security2:error] [pid 66623:tid 66848] [client 168.62.48.100:1068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/kopyw.php"] [unique_id "aoSBOtO5rbWdOArH04KueAAAAVw"]
[Tue Aug 18 12:58:51.003393 2026] [security2:error] [pid 66623:tid 66780] [client 20.206.73.37:59963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/bengi.php"] [unique_id "aoSBO9O5rbWdOArH04KuegAAARg"]
[Tue Aug 18 12:58:51.066086 2026] [security2:error] [pid 66623:tid 66857] [client 52.173.121.69:14582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSBO9O5rbWdOArH04KufQAAAWU"]
[Tue Aug 18 12:58:51.131638 2026] [security2:error] [pid 66623:tid 66764] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/fa.php"] [unique_id "aoSBO9O5rbWdOArH04KugwABcH8"]
[Tue Aug 18 12:58:51.144394 2026] [security2:error] [pid 66623:tid 66781] [client 4.232.151.198:58714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/02.php"] [unique_id "aoSBO9O5rbWdOArH04KuhQAAARk"]
[Tue Aug 18 12:58:51.152454 2026] [security2:error] [pid 66623:tid 66816] [client 127.0.0.1:37358] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aoSBO9O5rbWdOArH04KuggAAATw"]
[Tue Aug 18 12:58:51.152507 2026] [security2:error] [pid 66623:tid 66852] [client 74.7.175.172:50386] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.inovartararas.com.br"] [uri "/robots.txt"] [unique_id "aoSBO9O5rbWdOArH04KugAABYCE"]
[Tue Aug 18 12:58:51.180287 2026] [security2:error] [pid 66623:tid 66773] [client 20.25.139.174:4648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp.php"] [unique_id "aoSBO9O5rbWdOArH04KuiAAAARE"]
[Tue Aug 18 12:58:51.226821 2026] [authz_core:error] [pid 66623:tid 66655] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:51.227081 2026] [authz_core:error] [pid 66623:tid 66655] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:51.244942 2026] [security2:error] [pid 66623:tid 66802] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/bengi.php"] [unique_id "aoSBO9O5rbWdOArH04KujgAAAS4"]
[Tue Aug 18 12:58:51.249995 2026] [security2:error] [pid 66623:tid 66792] [client 20.250.13.23:52789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/666.php"] [unique_id "aoSBO9O5rbWdOArH04KujwAAASQ"]
[Tue Aug 18 12:58:51.292191 2026] [security2:error] [pid 66623:tid 66790] [client 168.62.48.100:1032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/zznmg.php"] [unique_id "aoSBO9O5rbWdOArH04KukgAAASI"]
[Tue Aug 18 12:58:51.312643 2026] [security2:error] [pid 66623:tid 66678] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/fb.php"] [unique_id "aoSBO9O5rbWdOArH04KukwABfik"]
[Tue Aug 18 12:58:51.321457 2026] [security2:error] [pid 66623:tid 66777] [client 20.127.136.245:1361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/dropdown.php"] [unique_id "aoSBO9O5rbWdOArH04KulAAAARU"]
[Tue Aug 18 12:58:51.359567 2026] [security2:error] [pid 66623:tid 66858] [client 4.232.94.69:16057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/spip.php"] [unique_id "aoSBO9O5rbWdOArH04KulgAAAWY"]
[Tue Aug 18 12:58:51.386414 2026] [security2:error] [pid 66623:tid 66843] [client 213.35.127.232:55443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBO9O5rbWdOArH04KumQAAAVc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:51.403377 2026] [security2:error] [pid 66623:tid 66771] [client 20.25.139.174:4549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/404.php"] [unique_id "aoSBO9O5rbWdOArH04KumwAAAQ8"]
[Tue Aug 18 12:58:51.415514 2026] [security2:error] [pid 66623:tid 66832] [client 74.248.18.37:41014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/v.php"] [unique_id "aoSBO9O5rbWdOArH04KunAAAAUw"]
[Tue Aug 18 12:58:51.505997 2026] [security2:error] [pid 66623:tid 66827] [client 20.250.13.23:45709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSBO9O5rbWdOArH04KuowAAAUc"]
[Tue Aug 18 12:58:51.527049 2026] [authz_core:error] [pid 66623:tid 66660] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:51.527320 2026] [authz_core:error] [pid 66623:tid 66660] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:51.528134 2026] [security2:error] [pid 66623:tid 66677] [remote 216.38.28.47:57578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.28.38.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "castroeferres.com.br"] [uri "/wp-login.php"] [unique_id "aoSBO9O5rbWdOArH04KupQABbig"]
[Tue Aug 18 12:58:51.549463 2026] [security2:error] [pid 66623:tid 66720] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gw.php"] [unique_id "aoSBO9O5rbWdOArH04KupgABL1M"]
[Tue Aug 18 12:58:51.556314 2026] [security2:error] [pid 66623:tid 66877] [client 40.74.65.169:43033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBO9O5rbWdOArH04KuqAAAAXk"]
[Tue Aug 18 12:58:51.559967 2026] [security2:error] [pid 66623:tid 66892] [client 168.62.48.100:1112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/bhfnd.php"] [unique_id "aoSBO9O5rbWdOArH04KuqQAAAYg"]
[Tue Aug 18 12:58:51.566918 2026] [security2:error] [pid 66623:tid 66797] [client 68.155.155.199:13300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/info.php"] [unique_id "aoSBO9O5rbWdOArH04KuqgAAASk"]
[Tue Aug 18 12:58:51.575412 2026] [security2:error] [pid 66623:tid 66834] [client 20.118.172.148:43513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBO9O5rbWdOArH04KuqwAAAU4"]
[Tue Aug 18 12:58:51.580688 2026] [security2:error] [pid 66623:tid 66831] [client 52.173.121.69:47318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSBO9O5rbWdOArH04KurAAAAUs"]
[Tue Aug 18 12:58:51.581982 2026] [security2:error] [pid 66623:tid 66800] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/file2.php"] [unique_id "aoSBO9O5rbWdOArH04KurQAAASw"]
[Tue Aug 18 12:58:51.671684 2026] [security2:error] [pid 66623:tid 66796] [client 132.196.30.78:20385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBO9O5rbWdOArH04KusgAAASg"]
[Tue Aug 18 12:58:51.696231 2026] [security2:error] [pid 66623:tid 66828] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBO9O5rbWdOArH04KuswAAAUg"]
[Tue Aug 18 12:58:51.746384 2026] [security2:error] [pid 66623:tid 66785] [client 158.23.17.4:40446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/admin404.php"] [unique_id "aoSBO9O5rbWdOArH04KuuAAAAR0"]
[Tue Aug 18 12:58:51.775934 2026] [security2:error] [pid 66623:tid 66815] [client 172.182.200.96:14194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSBO9O5rbWdOArH04KuuQAAATs"]
[Tue Aug 18 12:58:51.777167 2026] [security2:error] [pid 66623:tid 66782] [client 20.25.139.174:4612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/155.php"] [unique_id "aoSBO9O5rbWdOArH04KuugAAARo"]
[Tue Aug 18 12:58:51.787715 2026] [security2:error] [pid 66623:tid 66710] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/sw.php"] [unique_id "aoSBO9O5rbWdOArH04KuvAABPkk"]
[Tue Aug 18 12:58:51.796494 2026] [security2:error] [pid 66623:tid 66878] [client 20.203.138.185:18465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/app.php"] [unique_id "aoSBO9O5rbWdOArH04KuvQAAAXo"]
[Tue Aug 18 12:58:51.797300 2026] [security2:error] [pid 66623:tid 66838] [client 4.232.151.198:58741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/upgrade/alfanew.php7"] [unique_id "aoSBO9O5rbWdOArH04KuvgAAAVI"]
[Tue Aug 18 12:58:51.809887 2026] [security2:error] [pid 66623:tid 66845] [client 20.127.136.245:1345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/inputs.php"] [unique_id "aoSBO9O5rbWdOArH04KuvwAAAVk"]
[Tue Aug 18 12:58:51.827069 2026] [security2:error] [pid 66623:tid 66870] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBO9O5rbWdOArH04KuwgAAAXI"]
[Tue Aug 18 12:58:51.832498 2026] [authz_core:error] [pid 66623:tid 66711] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:51.832951 2026] [authz_core:error] [pid 66623:tid 66711] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:51.871427 2026] [security2:error] [pid 66623:tid 66807] [client 168.62.48.100:1094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/qfvqu.php"] [unique_id "aoSBO9O5rbWdOArH04KuwwAAATM"]
[Tue Aug 18 12:58:51.915390 2026] [security2:error] [pid 66623:tid 66861] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/gm.php"] [unique_id "aoSBO9O5rbWdOArH04KuxgAAAWk"]
[Tue Aug 18 12:58:51.917031 2026] [security2:error] [pid 66623:tid 66868] [client 52.173.121.69:24986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBO9O5rbWdOArH04KuxwAAAXA"]
[Tue Aug 18 12:58:51.951172 2026] [security2:error] [pid 66623:tid 66806] [client 20.104.85.180:15111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wso.php"] [unique_id "aoSBO9O5rbWdOArH04KuyQAAATI"]
[Tue Aug 18 12:58:51.960386 2026] [security2:error] [pid 66623:tid 66719] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gc.php"] [unique_id "aoSBO9O5rbWdOArH04KuygABQFI"]
[Tue Aug 18 12:58:51.970625 2026] [security2:error] [pid 66623:tid 66876] [client 20.25.139.174:4561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wk/index.php"] [unique_id "aoSBO9O5rbWdOArH04KuzAAAAXg"]
[Tue Aug 18 12:58:51.984159 2026] [security2:error] [pid 66623:tid 66879] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBO9O5rbWdOArH04KuzQAAAXs"]
[Tue Aug 18 12:58:52.011218 2026] [security2:error] [pid 66623:tid 66776] [client 86.120.159.145:9995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPNO5rbWdOArH04KuzwAAARQ"]
[Tue Aug 18 12:58:52.011368 2026] [security2:error] [pid 66623:tid 66776] [client 86.120.159.145:9995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPNO5rbWdOArH04KuzwAAARQ"]
[Tue Aug 18 12:58:52.083673 2026] [security2:error] [pid 66623:tid 66794] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBPNO5rbWdOArH04Ku0wAAASY"]
[Tue Aug 18 12:58:52.118507 2026] [security2:error] [pid 66623:tid 66843] [client 168.62.48.100:1033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/oivcl.php"] [unique_id "aoSBPNO5rbWdOArH04Ku1wAAAVc"]
[Tue Aug 18 12:58:52.131387 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:52.131701 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:52.152324 2026] [security2:error] [pid 66623:tid 66817] [client 20.250.13.23:1806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSBPNO5rbWdOArH04Ku2QAAAT0"]
[Tue Aug 18 12:58:52.160122 2026] [security2:error] [pid 66623:tid 66709] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/uq.php"] [unique_id "aoSBPNO5rbWdOArH04Ku2gABYkg"]
[Tue Aug 18 12:58:52.161702 2026] [security2:error] [pid 66623:tid 66774] [client 52.173.121.69:50208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSBPNO5rbWdOArH04Ku2wAAARI"]
[Tue Aug 18 12:58:52.235131 2026] [security2:error] [pid 66623:tid 66877] [client 20.48.236.86:25940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "cabeceiragrandemg.com.br"] [uri "/.mopj.php"] [unique_id "aoSBPNO5rbWdOArH04Ku3wAAAXk"]
[Tue Aug 18 12:58:52.247939 2026] [security2:error] [pid 66623:tid 66842] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/ws55.php"] [unique_id "aoSBPNO5rbWdOArH04Ku4QAAAVY"]
[Tue Aug 18 12:58:52.261147 2026] [security2:error] [pid 66623:tid 66768] [client 40.74.65.169:20406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/admin.php"] [unique_id "aoSBPNO5rbWdOArH04Ku4wAAAQw"]
[Tue Aug 18 12:58:52.272286 2026] [security2:error] [pid 66623:tid 66805] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBPNO5rbWdOArH04Ku5AAAATE"]
[Tue Aug 18 12:58:52.272463 2026] [security2:error] [pid 66623:tid 66866] [client 192.141.172.134:52235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPNO5rbWdOArH04Ku5gAAAW4"]
[Tue Aug 18 12:58:52.272484 2026] [security2:error] [pid 66623:tid 66844] [client 20.104.85.180:38024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/sf.php"] [unique_id "aoSBPNO5rbWdOArH04Ku5QAAAVg"]
[Tue Aug 18 12:58:52.272570 2026] [security2:error] [pid 66623:tid 66866] [client 192.141.172.134:52235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPNO5rbWdOArH04Ku5gAAAW4"]
[Tue Aug 18 12:58:52.286245 2026] [security2:error] [pid 66623:tid 66846] [client 74.248.18.37:40998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/v5.php"] [unique_id "aoSBPNO5rbWdOArH04Ku6AAAAVo"]
[Tue Aug 18 12:58:52.304884 2026] [security2:error] [pid 66623:tid 66771] [client 132.196.30.78:15839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/666.php"] [unique_id "aoSBPNO5rbWdOArH04Ku6QAAAQ8"]
[Tue Aug 18 12:58:52.313102 2026] [security2:error] [pid 66623:tid 66822] [client 20.25.139.174:4609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/96i.php"] [unique_id "aoSBPNO5rbWdOArH04Ku6gAAAUI"]
[Tue Aug 18 12:58:52.338594 2026] [security2:error] [pid 66623:tid 66796] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/img.php"] [unique_id "aoSBPNO5rbWdOArH04Ku6wAAASg"]
[Tue Aug 18 12:58:52.351976 2026] [security2:error] [pid 66623:tid 66694] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/32.php"] [unique_id "aoSBPNO5rbWdOArH04Ku7QABFjk"]
[Tue Aug 18 12:58:52.408054 2026] [security2:error] [pid 66623:tid 66777] [client 213.35.127.232:55677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBPNO5rbWdOArH04Ku7wAAARU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:52.449274 2026] [security2:error] [pid 66623:tid 66797] [client 4.232.151.198:5492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-includes/sodium_compat/src/index.php"] [unique_id "aoSBPNO5rbWdOArH04Ku8gAAASk"]
[Tue Aug 18 12:58:52.463179 2026] [security2:error] [pid 66623:tid 66785] [client 168.62.48.100:1083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/zugvi.php"] [unique_id "aoSBPNO5rbWdOArH04Ku9AAAAR0"]
[Tue Aug 18 12:58:52.481389 2026] [security2:error] [pid 66623:tid 66815] [client 20.206.73.37:20726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/file2.php"] [unique_id "aoSBPNO5rbWdOArH04Ku9QAAATs"]
[Tue Aug 18 12:58:52.488895 2026] [security2:error] [pid 66623:tid 66812] [client 20.25.139.174:4593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/about.php"] [unique_id "aoSBPNO5rbWdOArH04Ku9gAAATg"]
[Tue Aug 18 12:58:52.550027 2026] [security2:error] [pid 66623:tid 66826] [client 20.127.136.245:1546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/100.php"] [unique_id "aoSBPNO5rbWdOArH04Ku-gAAAUY"]
[Tue Aug 18 12:58:52.573449 2026] [security2:error] [pid 66623:tid 66786] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/m.php"] [unique_id "aoSBPNO5rbWdOArH04Ku_gAAAR4"]
[Tue Aug 18 12:58:52.596101 2026] [security2:error] [pid 66623:tid 66773] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/aa.php"] [unique_id "aoSBPNO5rbWdOArH04KvAAAAARE"]
[Tue Aug 18 12:58:52.611607 2026] [security2:error] [pid 66623:tid 66669] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/73.php"] [unique_id "aoSBPNO5rbWdOArH04KvAQABCyA"]
[Tue Aug 18 12:58:52.625930 2026] [security2:error] [pid 66623:tid 66874] [client 158.23.17.4:20404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/qo.php"] [unique_id "aoSBPNO5rbWdOArH04KvAgAAAXY"]
[Tue Aug 18 12:58:52.670836 2026] [security2:error] [pid 66623:tid 66821] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/cok.php"] [unique_id "aoSBPNO5rbWdOArH04KvBgAAAUE"]
[Tue Aug 18 12:58:52.729270 2026] [security2:error] [pid 66623:tid 66858] [client 52.173.121.69:30393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSBPNO5rbWdOArH04KvCgAAAWY"]
[Tue Aug 18 12:58:52.733119 2026] [authz_core:error] [pid 66623:tid 66757] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:52.733380 2026] [authz_core:error] [pid 66623:tid 66757] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:52.735186 2026] [security2:error] [pid 66623:tid 66787] [client 168.62.48.100:1034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wsrer.php"] [unique_id "aoSBPNO5rbWdOArH04KvDAAAAR8"]
[Tue Aug 18 12:58:52.755311 2026] [security2:error] [pid 66623:tid 66779] [client 20.104.85.180:38634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/index/function.php"] [unique_id "aoSBPNO5rbWdOArH04KvDQAAARc"]
[Tue Aug 18 12:58:52.779489 2026] [security2:error] [pid 66623:tid 66832] [client 172.182.200.96:7586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSBPNO5rbWdOArH04KvDgAAAUw"]
[Tue Aug 18 12:58:52.781967 2026] [security2:error] [pid 66623:tid 66807] [client 20.250.13.23:53634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBPNO5rbWdOArH04KvDwAAATM"]
[Tue Aug 18 12:58:52.804470 2026] [security2:error] [pid 66623:tid 66664] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ib.php"] [unique_id "aoSBPNO5rbWdOArH04KvEAABYhs"]
[Tue Aug 18 12:58:52.873716 2026] [security2:error] [pid 66623:tid 66803] [client 20.118.172.148:53093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSBPNO5rbWdOArH04KvEwAAAS8"]
[Tue Aug 18 12:58:52.907018 2026] [security2:error] [pid 66623:tid 66802] [client 20.25.139.174:4544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/as.php"] [unique_id "aoSBPNO5rbWdOArH04KvFgAAAS4"]
[Tue Aug 18 12:58:52.914888 2026] [security2:error] [pid 66623:tid 66831] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/33.php"] [unique_id "aoSBPNO5rbWdOArH04KvGQAAAUs"]
[Tue Aug 18 12:58:52.915153 2026] [security2:error] [pid 66623:tid 66800] [client 68.155.155.199:6331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/profile.php"] [unique_id "aoSBPNO5rbWdOArH04KvFwAAASw"]
[Tue Aug 18 12:58:52.957516 2026] [security2:error] [pid 66623:tid 66811] [client 40.74.65.169:20105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/file52.php"] [unique_id "aoSBPNO5rbWdOArH04KvGwAAATc"]
[Tue Aug 18 12:58:52.961542 2026] [security2:error] [pid 66623:tid 66822] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/accesson.php"] [unique_id "aoSBPNO5rbWdOArH04KvHAAAAUI"]
[Tue Aug 18 12:58:52.994636 2026] [security2:error] [pid 66623:tid 66884] [client 168.62.48.100:1156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/ucpfr.php"] [unique_id "aoSBPNO5rbWdOArH04KvHgAAAYA"]
[Tue Aug 18 12:58:52.996696 2026] [security2:error] [pid 66623:tid 66640] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/xm.php"] [unique_id "aoSBPNO5rbWdOArH04KvHwABKAM"]
[Tue Aug 18 12:58:53.002349 2026] [security2:error] [pid 66623:tid 66840] [client 172.202.39.151:40357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/inputs.php"] [unique_id "aoSBPdO5rbWdOArH04KvIQAAAVQ"]
[Tue Aug 18 12:58:53.031965 2026] [authz_core:error] [pid 66623:tid 66721] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:53.032239 2026] [authz_core:error] [pid 66623:tid 66721] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:53.040509 2026] [security2:error] [pid 66623:tid 66892] [client 20.25.139.174:4590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/term.php"] [unique_id "aoSBPdO5rbWdOArH04KvJAAAAYg"]
[Tue Aug 18 12:58:53.061507 2026] [security2:error] [pid 66623:tid 66890] [client 74.248.18.37:8091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/we.php"] [unique_id "aoSBPdO5rbWdOArH04KvJQAAAYY"]
[Tue Aug 18 12:58:53.093178 2026] [security2:error] [pid 66623:tid 66808] [client 4.232.151.198:58749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/js/widgets/about.php"] [unique_id "aoSBPdO5rbWdOArH04KvJgAAATQ"]
[Tue Aug 18 12:58:53.118716 2026] [security2:error] [pid 66623:tid 66815] [client 20.104.85.180:54533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/edit.php"] [unique_id "aoSBPdO5rbWdOArH04KvKQAAATs"]
[Tue Aug 18 12:58:53.145666 2026] [autoindex:error] [pid 66623:tid 66785] [client 169.58.72.248:53716] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:58:53.178133 2026] [security2:error] [pid 66623:tid 66883] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/av.php"] [unique_id "aoSBPdO5rbWdOArH04KvLQAAAX8"]
[Tue Aug 18 12:58:53.179987 2026] [security2:error] [pid 66623:tid 66699] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/zy.php"] [unique_id "aoSBPdO5rbWdOArH04KvLgABKz4"]
[Tue Aug 18 12:58:53.192139 2026] [security2:error] [pid 66623:tid 66826] [client 52.173.121.69:30364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSBPdO5rbWdOArH04KvMAAAAUY"]
[Tue Aug 18 12:58:53.209267 2026] [security2:error] [pid 66623:tid 66781] [client 20.203.138.185:63778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBPdO5rbWdOArH04KvMwAAARk"]
[Tue Aug 18 12:58:53.227737 2026] [security2:error] [pid 66623:tid 66816] [client 172.182.200.96:7591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSBPdO5rbWdOArH04KvNAAAATw"]
[Tue Aug 18 12:58:53.246911 2026] [security2:error] [pid 66623:tid 66835] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/packed.php"] [unique_id "aoSBPdO5rbWdOArH04KvNQAAAU8"]
[Tue Aug 18 12:58:53.253930 2026] [security2:error] [pid 66623:tid 66767] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/av.php"] [unique_id "aoSBPdO5rbWdOArH04KvNgAAAQs"]
[Tue Aug 18 12:58:53.309425 2026] [security2:error] [pid 66623:tid 66776] [client 20.215.241.237:65234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/puc.php"] [unique_id "aoSBPdO5rbWdOArH04KvOAAAARQ"]
[Tue Aug 18 12:58:53.310786 2026] [security2:error] [pid 66623:tid 66821] [client 52.173.121.69:25023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/well-known/index.php"] [unique_id "aoSBPdO5rbWdOArH04KvOQAAAUE"]
[Tue Aug 18 12:58:53.340487 2026] [security2:error] [pid 66623:tid 66858] [client 168.62.48.100:1069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/yxijx.php"] [unique_id "aoSBPdO5rbWdOArH04KvQAAAAWY"]
[Tue Aug 18 12:58:53.372389 2026] [security2:error] [pid 66623:tid 66689] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/q.php"] [unique_id "aoSBPdO5rbWdOArH04KvSQABVzQ"]
[Tue Aug 18 12:58:53.388744 2026] [security2:error] [pid 66623:tid 66832] [client 20.127.136.245:17065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/akc.php"] [unique_id "aoSBPdO5rbWdOArH04KvSwAAAUw"]
[Tue Aug 18 12:58:53.403999 2026] [security2:error] [pid 66623:tid 66836] [client 20.65.98.162:18329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBPdO5rbWdOArH04KvTAAAAVA"]
[Tue Aug 18 12:58:53.406523 2026] [security2:error] [pid 66623:tid 66803] [client 20.48.236.86:32841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/bengi.php"] [unique_id "aoSBPdO5rbWdOArH04KvTQAAAS8"]
[Tue Aug 18 12:58:53.420552 2026] [security2:error] [pid 66623:tid 66788] [client 20.25.139.174:4640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/min.php"] [unique_id "aoSBPdO5rbWdOArH04KvTgAAASA"]
[Tue Aug 18 12:58:53.425827 2026] [security2:error] [pid 66623:tid 66797] [client 213.35.127.232:55871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBPdO5rbWdOArH04KvUAAAASk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:53.428138 2026] [security2:error] [pid 66623:tid 66770] [client 20.100.169.31:12481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/atex1.php"] [unique_id "aoSBPdO5rbWdOArH04KvUQAAAQ4"]
[Tue Aug 18 12:58:53.433260 2026] [security2:error] [pid 66623:tid 66814] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/media.php"] [unique_id "aoSBPdO5rbWdOArH04KvUgAAATo"]
[Tue Aug 18 12:58:53.453482 2026] [security2:error] [pid 66623:tid 66889] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPdO5rbWdOArH04KvTwABhSU"]
[Tue Aug 18 12:58:53.539669 2026] [security2:error] [pid 66623:tid 66789] [client 20.250.13.23:45757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBPdO5rbWdOArH04KvVgAAASE"]
[Tue Aug 18 12:58:53.541359 2026] [security2:error] [pid 66623:tid 66783] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/kj.php"] [unique_id "aoSBPdO5rbWdOArH04KvVwAAARs"]
[Tue Aug 18 12:58:53.552396 2026] [security2:error] [pid 66623:tid 66693] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/xf.php"] [unique_id "aoSBPdO5rbWdOArH04KvWQABVDg"]
[Tue Aug 18 12:58:53.566213 2026] [security2:error] [pid 66623:tid 66804] [client 20.25.139.174:4704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBPdO5rbWdOArH04KvXAAAATA"]
[Tue Aug 18 12:58:53.577280 2026] [security2:error] [pid 66623:tid 66892] [client 52.173.121.69:47357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSBPdO5rbWdOArH04KvXQAAAYg"]
[Tue Aug 18 12:58:53.612515 2026] [security2:error] [pid 66623:tid 66819] [client 158.23.17.4:47630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/sd.php"] [unique_id "aoSBPdO5rbWdOArH04KvYAAAAT8"]
[Tue Aug 18 12:58:53.659423 2026] [security2:error] [pid 66623:tid 66791] [client 168.62.48.100:1073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/zwlsv.php"] [unique_id "aoSBPdO5rbWdOArH04KvYgAAASM"]
[Tue Aug 18 12:58:53.662407 2026] [security2:error] [pid 66623:tid 66815] [client 40.74.65.169:20156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/geck.php"] [unique_id "aoSBPdO5rbWdOArH04KvYwAAATs"]
[Tue Aug 18 12:58:53.662940 2026] [security2:error] [pid 66623:tid 66877] [client 213.202.253.4:50195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/postnews.php"] [unique_id "aoSBPdO5rbWdOArH04KvZAAAAXk"], referer: www.google.com
[Tue Aug 18 12:58:53.665906 2026] [security2:error] [pid 66623:tid 66782] [client 20.206.73.37:20704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/gm.php"] [unique_id "aoSBPdO5rbWdOArH04KvZQAAARo"]
[Tue Aug 18 12:58:53.703930 2026] [security2:error] [pid 66623:tid 66818] [client 20.104.85.180:46010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSBPdO5rbWdOArH04KvZgAAAT4"]
[Tue Aug 18 12:58:53.708671 2026] [security2:error] [pid 66623:tid 66838] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/images.php"] [unique_id "aoSBPdO5rbWdOArH04KvZwAAAVI"]
[Tue Aug 18 12:58:53.733621 2026] [security2:error] [pid 66623:tid 66750] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gb.php"] [unique_id "aoSBPdO5rbWdOArH04KvaQABWXE"]
[Tue Aug 18 12:58:53.737166 2026] [security2:error] [pid 66623:tid 66849] [client 172.182.200.96:14189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSBPdO5rbWdOArH04KvawAAAV0"]
[Tue Aug 18 12:58:53.757246 2026] [security2:error] [pid 66623:tid 66778] [client 4.232.151.198:5461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/json.php"] [unique_id "aoSBPdO5rbWdOArH04KvcAAAARY"]
[Tue Aug 18 12:58:53.764269 2026] [security2:error] [pid 66623:tid 66662] [remote 66.102.134.13:48530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.134.102.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/wp-login.php"] [unique_id "aoSBPdO5rbWdOArH04KvcQABHhk"]
[Tue Aug 18 12:58:53.773077 2026] [security2:error] [pid 66623:tid 66811] [client 74.248.18.37:47255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wkl.php"] [unique_id "aoSBPdO5rbWdOArH04KvcgAAATc"]
[Tue Aug 18 12:58:53.820388 2026] [security2:error] [pid 66623:tid 66820] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSBPdO5rbWdOArH04KvcwAAAUA"]
[Tue Aug 18 12:58:53.919369 2026] [security2:error] [pid 66623:tid 66810] [client 149.50.220.157:13873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.220.50.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "informatik.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPdO5rbWdOArH04KvbAAAATY"]
[Tue Aug 18 12:58:53.919494 2026] [security2:error] [pid 66623:tid 66810] [client 149.50.220.157:13873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "informatik.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPdO5rbWdOArH04KvbAAAATY"]
[Tue Aug 18 12:58:53.931367 2026] [security2:error] [pid 66623:tid 66885] [client 168.62.48.100:1064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/jrpga.php"] [unique_id "aoSBPdO5rbWdOArH04KveAAAAYE"]
[Tue Aug 18 12:58:53.935186 2026] [security2:error] [pid 66623:tid 66725] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/jp.php"] [unique_id "aoSBPdO5rbWdOArH04KvewABZlg"]
[Tue Aug 18 12:58:53.937505 2026] [authz_core:error] [pid 66623:tid 66761] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:53.937813 2026] [authz_core:error] [pid 66623:tid 66761] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:53.976811 2026] [security2:error] [pid 66623:tid 66854] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/admin.php"] [unique_id "aoSBPdO5rbWdOArH04KvfwAAAWI"]
[Tue Aug 18 12:58:53.977260 2026] [security2:error] [pid 66623:tid 66749] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPdO5rbWdOArH04KvfgABTHA"]
[Tue Aug 18 12:58:53.977442 2026] [security2:error] [pid 66623:tid 66832] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPdO5rbWdOArH04KvfgABTHA"]
[Tue Aug 18 12:58:54.020080 2026] [security2:error] [pid 66623:tid 66803] [client 20.118.172.148:50069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSBPtO5rbWdOArH04KvgwAAAS8"]
[Tue Aug 18 12:58:54.068952 2026] [security2:error] [pid 66623:tid 66770] [client 20.104.85.180:57678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-good.php"] [unique_id "aoSBPtO5rbWdOArH04KvhQAAAQ4"]
[Tue Aug 18 12:58:54.075733 2026] [security2:error] [pid 66623:tid 66814] [client 52.173.121.69:14855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBPtO5rbWdOArH04KvhgAAATo"]
[Tue Aug 18 12:58:54.087492 2026] [security2:error] [pid 66623:tid 66829] [client 20.25.139.174:4614] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cadema.com.br"] [uri "/1.php"] [unique_id "aoSBPtO5rbWdOArH04KvhwAAAUk"]
[Tue Aug 18 12:58:54.087594 2026] [security2:error] [pid 66623:tid 66829] [client 20.25.139.174:4614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/1.php"] [unique_id "aoSBPtO5rbWdOArH04KvhwAAAUk"]
[Tue Aug 18 12:58:54.107995 2026] [security2:error] [pid 66623:tid 66831] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/png.php"] [unique_id "aoSBPtO5rbWdOArH04KviQAAAUs"]
[Tue Aug 18 12:58:54.115956 2026] [authz_core:error] [pid 66623:tid 66638] [remote 57.141.22.105:37446] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:54.116215 2026] [authz_core:error] [pid 66623:tid 66638] [remote 57.141.22.105:37446] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:54.117299 2026] [security2:error] [pid 66623:tid 66800] [client 158.23.17.4:47621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/km.php"] [unique_id "aoSBPtO5rbWdOArH04KviwAAASw"]
[Tue Aug 18 12:58:54.147480 2026] [security2:error] [pid 66623:tid 66866] [client 172.182.200.96:7644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSBPtO5rbWdOArH04KvjAAAAW4"]
[Tue Aug 18 12:58:54.149571 2026] [security2:error] [pid 66623:tid 66827] [client 37.40.227.74:56856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPtO5rbWdOArH04KvjQAAAUc"]
[Tue Aug 18 12:58:54.149666 2026] [security2:error] [pid 66623:tid 66827] [client 37.40.227.74:56856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPtO5rbWdOArH04KvjQAAAUc"]
[Tue Aug 18 12:58:54.152710 2026] [security2:error] [pid 66623:tid 66844] [client 20.203.138.185:37271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/cxc.php"] [unique_id "aoSBPtO5rbWdOArH04KvjgAAAVg"]
[Tue Aug 18 12:58:54.185884 2026] [security2:error] [pid 66623:tid 66822] [client 168.62.48.100:1148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSBPtO5rbWdOArH04KvkAAAAUI"]
[Tue Aug 18 12:58:54.202761 2026] [security2:error] [pid 66623:tid 66884] [client 68.155.155.199:12927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/sx.php"] [unique_id "aoSBPtO5rbWdOArH04KvkwAAAYA"]
[Tue Aug 18 12:58:54.230826 2026] [security2:error] [pid 66623:tid 66828] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/222.php"] [unique_id "aoSBPtO5rbWdOArH04KvlgAAAUg"]
[Tue Aug 18 12:58:54.238131 2026] [security2:error] [pid 66623:tid 66672] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/eq.php"] [unique_id "aoSBPtO5rbWdOArH04KvlwABMCM"]
[Tue Aug 18 12:58:54.276612 2026] [security2:error] [pid 66623:tid 66862] [client 103.184.169.37:42460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPtO5rbWdOArH04KvmgAAAWo"]
[Tue Aug 18 12:58:54.276760 2026] [security2:error] [pid 66623:tid 66862] [client 103.184.169.37:42460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPtO5rbWdOArH04KvmgAAAWo"]
[Tue Aug 18 12:58:54.339318 2026] [authz_core:error] [pid 66623:tid 66670] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:54.339780 2026] [authz_core:error] [pid 66623:tid 66670] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:54.340990 2026] [security2:error] [pid 66623:tid 66877] [client 20.127.136.245:3259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSBPtO5rbWdOArH04KvngAAAXk"]
[Tue Aug 18 12:58:54.359328 2026] [security2:error] [pid 66623:tid 66853] [client 40.74.65.169:20140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/biufile.php"] [unique_id "aoSBPtO5rbWdOArH04KvoAAAAWE"]
[Tue Aug 18 12:58:54.382354 2026] [security2:error] [pid 66623:tid 66834] [client 52.173.121.69:17975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBPtO5rbWdOArH04KvowAAAU4"]
[Tue Aug 18 12:58:54.387147 2026] [security2:error] [pid 66623:tid 66778] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/ab.php"] [unique_id "aoSBPtO5rbWdOArH04KvpAAAARY"]
[Tue Aug 18 12:58:54.396545 2026] [security2:error] [pid 66623:tid 66883] [client 103.120.71.157:60068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPtO5rbWdOArH04KvpgAAAX8"]
[Tue Aug 18 12:58:54.396638 2026] [security2:error] [pid 66623:tid 66883] [client 103.120.71.157:60068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPtO5rbWdOArH04KvpgAAAX8"]
[Tue Aug 18 12:58:54.414510 2026] [security2:error] [pid 66623:tid 66846] [client 4.232.151.198:5482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/css/index.php"] [unique_id "aoSBPtO5rbWdOArH04KvpwAAAVo"]
[Tue Aug 18 12:58:54.415056 2026] [security2:error] [pid 66623:tid 66864] [client 20.118.172.148:2713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBPtO5rbWdOArH04KvqAAAAWw"]
[Tue Aug 18 12:58:54.416373 2026] [security2:error] [pid 66623:tid 66732] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ep.php"] [unique_id "aoSBPtO5rbWdOArH04KvqQABHl8"]
[Tue Aug 18 12:58:54.446688 2026] [security2:error] [pid 66623:tid 66889] [client 213.35.127.232:56084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBPtO5rbWdOArH04KvqgAAAYU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:54.474305 2026] [security2:error] [pid 66623:tid 66806] [client 168.62.48.100:1038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/nwwha.php"] [unique_id "aoSBPtO5rbWdOArH04KvrQAAATI"]
[Tue Aug 18 12:58:54.491219 2026] [security2:error] [pid 66623:tid 66767] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/mac.php"] [unique_id "aoSBPtO5rbWdOArH04KvsQAAAQs"]
[Tue Aug 18 12:58:54.511759 2026] [security2:error] [pid 66623:tid 66873] [client 20.25.139.174:4633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/php8.php"] [unique_id "aoSBPtO5rbWdOArH04KvsgAAAXU"]
[Tue Aug 18 12:58:54.513385 2026] [security2:error] [pid 66623:tid 66874] [client 172.182.200.96:14166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSBPtO5rbWdOArH04KvswAAAXY"]
[Tue Aug 18 12:58:54.532267 2026] [security2:error] [pid 66623:tid 66882] [client 20.100.169.31:12338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBPtO5rbWdOArH04KvtAAAAX4"]
[Tue Aug 18 12:58:54.578969 2026] [security2:error] [pid 66623:tid 66858] [client 20.206.73.37:20685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/ws55.php"] [unique_id "aoSBPtO5rbWdOArH04KvugAAAWY"]
[Tue Aug 18 12:58:54.581341 2026] [security2:error] [pid 66623:tid 66807] [client 20.250.13.23:1815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSBPtO5rbWdOArH04KvuwAAATM"]
[Tue Aug 18 12:58:54.609012 2026] [security2:error] [pid 66623:tid 66754] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/rf.php"] [unique_id "aoSBPtO5rbWdOArH04KvvgABH3U"]
[Tue Aug 18 12:58:54.631099 2026] [security2:error] [pid 66623:tid 66781] [client 20.25.139.174:4552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/alfa.php"] [unique_id "aoSBPtO5rbWdOArH04KvwAAAARk"]
[Tue Aug 18 12:58:54.724496 2026] [security2:error] [pid 66623:tid 66872] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/12.php"] [unique_id "aoSBPtO5rbWdOArH04KvyAAAAXQ"]
[Tue Aug 18 12:58:54.725247 2026] [security2:error] [pid 66623:tid 66861] [client 52.173.121.69:48290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSBPtO5rbWdOArH04KvyQAAAWk"]
[Tue Aug 18 12:58:54.732579 2026] [security2:error] [pid 66623:tid 66822] [client 20.48.236.86:32867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/file2.php"] [unique_id "aoSBPtO5rbWdOArH04KvygAAAUI"]
[Tue Aug 18 12:58:54.742348 2026] [security2:error] [pid 66623:tid 66783] [client 168.62.48.100:1103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/opsqt.php"] [unique_id "aoSBPtO5rbWdOArH04KvzQAAARs"]
[Tue Aug 18 12:58:54.756568 2026] [security2:error] [pid 66623:tid 66823] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/ops.php"] [unique_id "aoSBPtO5rbWdOArH04KvzgAAAUM"]
[Tue Aug 18 12:58:54.761058 2026] [security2:error] [pid 66623:tid 66792] [client 74.248.18.37:7556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/work.php"] [unique_id "aoSBPtO5rbWdOArH04KvzwAAASQ"]
[Tue Aug 18 12:58:54.763676 2026] [security2:error] [pid 66623:tid 66698] [remote 57.141.22.99:60356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSBPtO5rbWdOArH04Kv0QABST0"]
[Tue Aug 18 12:58:54.824454 2026] [security2:error] [pid 66623:tid 66862] [client 20.127.136.245:6130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/php.php"] [unique_id "aoSBPtO5rbWdOArH04Kv0gAAAWo"]
[Tue Aug 18 12:58:54.839580 2026] [authz_core:error] [pid 66623:tid 66739] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:54.839871 2026] [authz_core:error] [pid 66623:tid 66739] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:54.841042 2026] [security2:error] [pid 66623:tid 66658] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/xynz1.php"] [unique_id "aoSBPtO5rbWdOArH04Kv1QABNRU"]
[Tue Aug 18 12:58:54.841492 2026] [security2:error] [pid 66623:tid 66780] [client 20.104.85.180:38031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/tes.php"] [unique_id "aoSBPtO5rbWdOArH04Kv1gAAARg"]
[Tue Aug 18 12:58:54.871588 2026] [security2:error] [pid 66623:tid 66857] [client 20.203.138.185:27982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSBPtO5rbWdOArH04Kv2AAAAWU"]
[Tue Aug 18 12:58:54.914603 2026] [security2:error] [pid 66623:tid 66848] [client 172.182.200.96:14083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSBPtO5rbWdOArH04Kv2QAAAVw"]
[Tue Aug 18 12:58:55.017919 2026] [security2:error] [pid 66623:tid 66769] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/x1da.php"] [unique_id "aoSBP9O5rbWdOArH04Kv4wAAAQ0"]
[Tue Aug 18 12:58:55.021357 2026] [security2:error] [pid 66623:tid 66668] [remote 172.237.150.158:46238] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "capecodcleaningservice.com"] [uri "/"] [unique_id "aoSBP9O5rbWdOArH04Kv4gABUh8"]
[Tue Aug 18 12:58:55.023303 2026] [security2:error] [pid 66623:tid 66835] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/8.php"] [unique_id "aoSBP9O5rbWdOArH04Kv5gAAAU8"]
[Tue Aug 18 12:58:55.041208 2026] [security2:error] [pid 66623:tid 66818] [client 20.25.139.174:4655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBP9O5rbWdOArH04Kv6gAAAT4"]
[Tue Aug 18 12:58:55.043818 2026] [security2:error] [pid 66623:tid 66819] [client 4.232.151.198:5456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/assets/images/tinyimg.php"] [unique_id "aoSBP9O5rbWdOArH04Kv7QAAAT8"]
[Tue Aug 18 12:58:55.056782 2026] [security2:error] [pid 66623:tid 66847] [client 40.74.65.169:43042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/dejavu.php"] [unique_id "aoSBP9O5rbWdOArH04Kv7gAAAVs"]
[Tue Aug 18 12:58:55.087707 2026] [security2:error] [pid 66623:tid 66801] [client 168.62.48.100:1039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/jvcpa.php"] [unique_id "aoSBP9O5rbWdOArH04Kv7wAAAS0"]
[Tue Aug 18 12:58:55.146348 2026] [security2:error] [pid 66623:tid 66889] [client 20.25.139.174:4664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/edit.php"] [unique_id "aoSBP9O5rbWdOArH04Kv9AAAAYU"]
[Tue Aug 18 12:58:55.167614 2026] [security2:error] [pid 66623:tid 66832] [client 52.173.121.69:29013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSBP9O5rbWdOArH04Kv9QAAAUw"]
[Tue Aug 18 12:58:55.192156 2026] [security2:error] [pid 66623:tid 66855] [client 20.250.13.23:1855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSBP9O5rbWdOArH04Kv9gAAAWM"]
[Tue Aug 18 12:58:55.228812 2026] [security2:error] [pid 66623:tid 66784] [client 149.34.210.141:63442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBP9O5rbWdOArH04Kv-AAAARw"]
[Tue Aug 18 12:58:55.253601 2026] [security2:error] [pid 66623:tid 66854] [client 172.182.200.96:7628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSBP9O5rbWdOArH04Kv_gAAAWI"]
[Tue Aug 18 12:58:55.289435 2026] [security2:error] [pid 66623:tid 66701] [remote 110.249.202.144:19298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gustavofrison.com.br"] [uri "/wp-content/uploads/2016/10/facebook.png"] [unique_id "aoSBP9O5rbWdOArH04KwAQABNEA"]
[Tue Aug 18 12:58:55.290161 2026] [security2:error] [pid 66623:tid 66790] [client 20.104.85.180:46756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/files/index.php"] [unique_id "aoSBP9O5rbWdOArH04KwAgAAASI"]
[Tue Aug 18 12:58:55.295972 2026] [security2:error] [pid 66623:tid 66865] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/biufile.php"] [unique_id "aoSBP9O5rbWdOArH04KwAwAAAW0"]
[Tue Aug 18 12:58:55.296302 2026] [security2:error] [pid 66623:tid 66773] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/mcs.php"] [unique_id "aoSBP9O5rbWdOArH04KwBAAAARE"]
[Tue Aug 18 12:58:55.363559 2026] [security2:error] [pid 66623:tid 66783] [client 20.118.172.148:19688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/0x.php"] [unique_id "aoSBP9O5rbWdOArH04KwCQAAARs"]
[Tue Aug 18 12:58:55.377849 2026] [security2:error] [pid 66623:tid 66823] [client 20.127.136.245:21484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/t.php"] [unique_id "aoSBP9O5rbWdOArH04KwCgAAAUM"]
[Tue Aug 18 12:58:55.386811 2026] [security2:error] [pid 66623:tid 66792] [client 168.62.48.100:1096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSBP9O5rbWdOArH04KwCwAAASQ"]
[Tue Aug 18 12:58:55.398257 2026] [security2:error] [pid 66623:tid 66837] [client 74.248.18.37:7599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/worksec.php"] [unique_id "aoSBP9O5rbWdOArH04KwDQAAAVE"]
[Tue Aug 18 12:58:55.401747 2026] [security2:error] [pid 66623:tid 66804] [client 158.23.17.4:56544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/mf.php"] [unique_id "aoSBP9O5rbWdOArH04KwDgAAATA"]
[Tue Aug 18 12:58:55.459272 2026] [security2:error] [pid 66623:tid 66779] [client 213.35.127.232:56289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBP9O5rbWdOArH04KwEQAAARc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:55.483971 2026] [security2:error] [pid 66623:tid 66763] [remote 172.237.150.158:46252] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "capecodcleaningservice.com"] [uri "/"] [unique_id "aoSBP9O5rbWdOArH04KwEwABQn4"]
[Tue Aug 18 12:58:55.487089 2026] [security2:error] [pid 66623:tid 66800] [client 157.20.138.62:53852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBP9O5rbWdOArH04KwFgAAASw"]
[Tue Aug 18 12:58:55.487179 2026] [security2:error] [pid 66623:tid 66800] [client 157.20.138.62:53852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBP9O5rbWdOArH04KwFgAAASw"]
[Tue Aug 18 12:58:55.491260 2026] [security2:error] [pid 66623:tid 66824] [client 20.104.85.180:19753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/k.php"] [unique_id "aoSBP9O5rbWdOArH04KwFwAAAUQ"]
[Tue Aug 18 12:58:55.495220 2026] [security2:error] [pid 66623:tid 66784] [client 149.34.210.141:63442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBP9O5rbWdOArH04Kv-AAAARw"]
[Tue Aug 18 12:58:55.530075 2026] [security2:error] [pid 66623:tid 66796] [client 20.25.139.174:4635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/222.php"] [unique_id "aoSBP9O5rbWdOArH04KwGAAAASg"]
[Tue Aug 18 12:58:55.542903 2026] [security2:error] [pid 66623:tid 66782] [client 52.173.121.69:17971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBP9O5rbWdOArH04KwGQAAARo"]
[Tue Aug 18 12:58:55.546881 2026] [security2:error] [pid 66623:tid 66845] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/coffexium.php"] [unique_id "aoSBP9O5rbWdOArH04KwGgAAAVk"]
[Tue Aug 18 12:58:55.555784 2026] [security2:error] [pid 66623:tid 66853] [client 20.203.138.185:18355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/0.php"] [unique_id "aoSBP9O5rbWdOArH04KwGwAAAWE"]
[Tue Aug 18 12:58:55.610367 2026] [security2:error] [pid 66623:tid 66883] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/adminner.php"] [unique_id "aoSBP9O5rbWdOArH04KwHQAAAX8"]
[Tue Aug 18 12:58:55.638715 2026] [security2:error] [pid 66623:tid 66786] [client 168.62.48.100:1041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSBP9O5rbWdOArH04KwHwAAAR4"]
[Tue Aug 18 12:58:55.643208 2026] [security2:error] [pid 66623:tid 66881] [client 20.25.139.174:4720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/elp.php"] [unique_id "aoSBP9O5rbWdOArH04KwIAAAAX0"]
[Tue Aug 18 12:58:55.678836 2026] [security2:error] [pid 66623:tid 66769] [client 52.173.121.69:48298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSBP9O5rbWdOArH04KwJAAAAQ0"]
[Tue Aug 18 12:58:55.685703 2026] [security2:error] [pid 66623:tid 66777] [client 4.232.151.198:5470] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.gotap.cc"] [uri "/wp-content/themes/twentytwentyfour/1.php"] [unique_id "aoSBP9O5rbWdOArH04KwJQAAARU"]
[Tue Aug 18 12:58:55.685816 2026] [security2:error] [pid 66623:tid 66777] [client 4.232.151.198:5470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/themes/twentytwentyfour/1.php"] [unique_id "aoSBP9O5rbWdOArH04KwJQAAARU"]
[Tue Aug 18 12:58:55.737236 2026] [security2:error] [pid 66623:tid 66851] [client 172.182.200.96:14181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/rezor.php"] [unique_id "aoSBP9O5rbWdOArH04KwKAAAAV8"]
[Tue Aug 18 12:58:55.738748 2026] [security2:error] [pid 66623:tid 66882] [client 40.74.65.169:20138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/aaf.php"] [unique_id "aoSBP9O5rbWdOArH04KwKQAAAX4"]
[Tue Aug 18 12:58:55.739508 2026] [security2:error] [pid 66623:tid 66821] [client 5.31.227.224:59068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBP9O5rbWdOArH04KwKgAAAUE"]
[Tue Aug 18 12:58:55.739597 2026] [security2:error] [pid 66623:tid 66821] [client 5.31.227.224:59068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBP9O5rbWdOArH04KwKgAAAUE"]
[Tue Aug 18 12:58:55.760363 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:55.760627 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:55.847902 2026] [security2:error] [pid 66623:tid 66727] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/vo.php"] [unique_id "aoSBP9O5rbWdOArH04KwMQABQFo"]
[Tue Aug 18 12:58:55.879410 2026] [security2:error] [pid 66623:tid 66871] [client 20.104.85.180:35895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBP9O5rbWdOArH04KwNQAAAXM"]
[Tue Aug 18 12:58:55.888553 2026] [security2:error] [pid 66623:tid 66880] [client 168.62.48.100:1133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSBP9O5rbWdOArH04KwNwAAAXw"]
[Tue Aug 18 12:58:55.896572 2026] [security2:error] [pid 66623:tid 66836] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/dragonshell.php"] [unique_id "aoSBP9O5rbWdOArH04KwOAAAAVA"]
[Tue Aug 18 12:58:55.944282 2026] [security2:error] [pid 66623:tid 66743] [remote 172.237.150.158:46262] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "capecodcleaningservice.com"] [uri "/"] [unique_id "aoSBP9O5rbWdOArH04KwOwABRmo"]
[Tue Aug 18 12:58:55.985647 2026] [security2:error] [pid 66623:tid 66868] [client 20.250.13.23:36134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/ws54.php"] [unique_id "aoSBP9O5rbWdOArH04KwPQAAAXA"]
[Tue Aug 18 12:58:56.042455 2026] [authz_core:error] [pid 66623:tid 66728] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:56.042715 2026] [authz_core:error] [pid 66623:tid 66728] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:56.046403 2026] [security2:error] [pid 66623:tid 66855] [client 20.25.139.174:4585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBQNO5rbWdOArH04KwQgAAAWM"]
[Tue Aug 18 12:58:56.053303 2026] [security2:error] [pid 66623:tid 66861] [client 52.173.121.69:17924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBQNO5rbWdOArH04KwQwAAAWk"]
[Tue Aug 18 12:58:56.065792 2026] [security2:error] [pid 66623:tid 66850] [client 20.127.136.245:1585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/index/function.php"] [unique_id "aoSBQNO5rbWdOArH04KwRAAAAV4"]
[Tue Aug 18 12:58:56.066834 2026] [security2:error] [pid 66623:tid 66844] [client 20.48.236.86:2235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/gm.php"] [unique_id "aoSBQNO5rbWdOArH04KwRQAAAVg"]
[Tue Aug 18 12:58:56.071353 2026] [security2:error] [pid 66623:tid 66792] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/dex.php"] [unique_id "aoSBQNO5rbWdOArH04KwRgAAASQ"]
[Tue Aug 18 12:58:56.082047 2026] [security2:error] [pid 66623:tid 66834] [client 138.36.100.162:43092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwRwAAAU4"]
[Tue Aug 18 12:58:56.082153 2026] [security2:error] [pid 66623:tid 66834] [client 138.36.100.162:43092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwRwAAAU4"]
[Tue Aug 18 12:58:56.084885 2026] [security2:error] [pid 66623:tid 66887] [client 172.182.200.96:7581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSBQNO5rbWdOArH04KwSAAAAYM"]
[Tue Aug 18 12:58:56.111889 2026] [security2:error] [pid 66623:tid 66780] [client 178.153.171.161:63355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwSgAAARg"]
[Tue Aug 18 12:58:56.112061 2026] [security2:error] [pid 66623:tid 66780] [client 178.153.171.161:63355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwSgAAARg"]
[Tue Aug 18 12:58:56.158324 2026] [security2:error] [pid 66623:tid 66802] [client 68.221.73.131:27442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBQNO5rbWdOArH04KwUAAAAS4"]
[Tue Aug 18 12:58:56.161514 2026] [security2:error] [pid 66623:tid 66790] [client 20.25.139.174:4607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBQNO5rbWdOArH04KwUQAAASI"]
[Tue Aug 18 12:58:56.179167 2026] [security2:error] [pid 66623:tid 66808] [client 79.127.164.8:58254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/spider/uninstallmysql.bak"] [unique_id "aoSBQNO5rbWdOArH04KwUgAAATQ"], referer: https://medihub.com.br/spider/uninstallmysql.bak
[Tue Aug 18 12:58:56.213160 2026] [security2:error] [pid 66623:tid 66815] [client 20.104.85.180:31252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/images/images/about.php"] [unique_id "aoSBQNO5rbWdOArH04KwUwAAATs"]
[Tue Aug 18 12:58:56.220345 2026] [security2:error] [pid 66623:tid 66796] [client 20.250.13.23:1798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBQNO5rbWdOArH04KwVQAAASg"]
[Tue Aug 18 12:58:56.243030 2026] [security2:error] [pid 66623:tid 66776] [client 172.202.39.151:40364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/alfa.php"] [unique_id "aoSBQNO5rbWdOArH04KwVgAAARQ"]
[Tue Aug 18 12:58:56.256813 2026] [security2:error] [pid 66623:tid 66781] [client 74.248.18.37:19269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-activate.php"] [unique_id "aoSBQNO5rbWdOArH04KwWAAAARk"]
[Tue Aug 18 12:58:56.269664 2026] [security2:error] [pid 66623:tid 66810] [client 223.185.37.47:17159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwWgAAATY"]
[Tue Aug 18 12:58:56.269800 2026] [security2:error] [pid 66623:tid 66810] [client 223.185.37.47:17159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwWgAAATY"]
[Tue Aug 18 12:58:56.281433 2026] [security2:error] [pid 66623:tid 66888] [client 158.23.17.4:15766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ie.php"] [unique_id "aoSBQNO5rbWdOArH04KwXAAAAYQ"]
[Tue Aug 18 12:58:56.290754 2026] [security2:error] [pid 66623:tid 66883] [client 20.206.73.37:20731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/m.php"] [unique_id "aoSBQNO5rbWdOArH04KwXwAAAX8"]
[Tue Aug 18 12:58:56.310974 2026] [security2:error] [pid 66623:tid 66674] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/wu.php"] [unique_id "aoSBQNO5rbWdOArH04KwYgABPCU"]
[Tue Aug 18 12:58:56.332381 2026] [security2:error] [pid 66623:tid 66838] [client 20.65.98.162:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "tecpolorefrigeracao.com.br"] [uri "/1.php"] [unique_id "aoSBQNO5rbWdOArH04KwZQAAAVI"]
[Tue Aug 18 12:58:56.332472 2026] [security2:error] [pid 66623:tid 66838] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/1.php"] [unique_id "aoSBQNO5rbWdOArH04KwZQAAAVI"]
[Tue Aug 18 12:58:56.346767 2026] [authz_core:error] [pid 66623:tid 66676] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:56.347053 2026] [authz_core:error] [pid 66623:tid 66676] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:56.372543 2026] [security2:error] [pid 66623:tid 66819] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/setup-config.php"] [unique_id "aoSBQNO5rbWdOArH04KwaAAAAT8"]
[Tue Aug 18 12:58:56.374927 2026] [security2:error] [pid 66623:tid 66793] [client 4.232.94.69:54098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ab1ux1ft.php"] [unique_id "aoSBQNO5rbWdOArH04KwaQAAASU"]
[Tue Aug 18 12:58:56.378281 2026] [security2:error] [pid 66623:tid 66882] [client 168.62.48.100:1177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSBQNO5rbWdOArH04KwagAAAX4"]
[Tue Aug 18 12:58:56.393328 2026] [security2:error] [pid 66623:tid 66799] [client 20.118.172.148:63071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/222.php"] [unique_id "aoSBQNO5rbWdOArH04KwawAAASs"]
[Tue Aug 18 12:58:56.400740 2026] [security2:error] [pid 66623:tid 66867] [client 20.104.85.180:20258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/403.php"] [unique_id "aoSBQNO5rbWdOArH04KwbwAAAW8"]
[Tue Aug 18 12:58:56.401567 2026] [security2:error] [pid 66623:tid 66721] [remote 172.237.150.158:46272] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "capecodcleaningservice.com"] [uri "/"] [unique_id "aoSBQNO5rbWdOArH04KwbQABXVQ"]
[Tue Aug 18 12:58:56.402960 2026] [security2:error] [pid 66623:tid 66659] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwbgABeBY"]
[Tue Aug 18 12:58:56.403140 2026] [security2:error] [pid 66623:tid 66876] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwbgABeBY"]
[Tue Aug 18 12:58:56.436623 2026] [security2:error] [pid 66623:tid 66848] [client 40.74.65.169:20346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSBQNO5rbWdOArH04KwcAAAAVw"]
[Tue Aug 18 12:58:56.472940 2026] [security2:error] [pid 66623:tid 66779] [client 213.35.127.232:56485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBQNO5rbWdOArH04KwcQAAARc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:56.504574 2026] [security2:error] [pid 66623:tid 66852] [client 172.182.200.96:14115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSBQNO5rbWdOArH04KwcwAAAWA"]
[Tue Aug 18 12:58:56.531838 2026] [security2:error] [pid 66623:tid 66803] [client 20.203.138.185:10412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/dom.php"] [unique_id "aoSBQNO5rbWdOArH04KwdAAAAS8"]
[Tue Aug 18 12:58:56.537925 2026] [security2:error] [pid 66623:tid 66851] [client 20.25.139.174:4677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/info.php"] [unique_id "aoSBQNO5rbWdOArH04KwdQAAAV8"]
[Tue Aug 18 12:58:56.563439 2026] [security2:error] [pid 66623:tid 66842] [client 20.65.98.162:19668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBQNO5rbWdOArH04KweAAAAVY"]
[Tue Aug 18 12:58:56.573941 2026] [security2:error] [pid 66623:tid 66826] [client 4.232.151.198:58708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/filefuns.php"] [unique_id "aoSBQNO5rbWdOArH04KwegAAAUY"]
[Tue Aug 18 12:58:56.621411 2026] [security2:error] [pid 66623:tid 66860] [client 20.127.136.245:19406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wk/index.php"] [unique_id "aoSBQNO5rbWdOArH04KwfgAAAWg"]
[Tue Aug 18 12:58:56.630090 2026] [security2:error] [pid 66623:tid 66855] [client 20.104.85.180:54576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBQNO5rbWdOArH04KwfwAAAWM"]
[Tue Aug 18 12:58:56.650197 2026] [security2:error] [pid 66623:tid 66746] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/de.php"] [unique_id "aoSBQNO5rbWdOArH04KwgAABG20"]
[Tue Aug 18 12:58:56.683814 2026] [security2:error] [pid 66623:tid 66833] [client 20.25.139.174:4623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/666.php"] [unique_id "aoSBQNO5rbWdOArH04KwhAAAAU0"]
[Tue Aug 18 12:58:56.741076 2026] [security2:error] [pid 66623:tid 66802] [client 52.173.121.69:50187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSBQNO5rbWdOArH04KwhgAAAS4"]
[Tue Aug 18 12:58:56.744821 2026] [security2:error] [pid 66623:tid 66790] [client 168.62.48.100:1102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSBQNO5rbWdOArH04KwhwAAASI"]
[Tue Aug 18 12:58:56.819594 2026] [security2:error] [pid 66623:tid 66810] [client 20.48.236.86:31056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/ws55.php"] [unique_id "aoSBQNO5rbWdOArH04KwiwAAATY"]
[Tue Aug 18 12:58:56.835763 2026] [security2:error] [pid 66623:tid 66809] [client 85.154.68.202:18233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwjAAAATU"]
[Tue Aug 18 12:58:56.835913 2026] [security2:error] [pid 66623:tid 66809] [client 85.154.68.202:18233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwjAAAATU"]
[Tue Aug 18 12:58:56.856081 2026] [security2:error] [pid 66623:tid 66653] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/album.php"] [unique_id "aoSBQNO5rbWdOArH04KwjwABOhA"]
[Tue Aug 18 12:58:56.863184 2026] [security2:error] [pid 66623:tid 66827] [client 20.250.13.23:53674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSBQNO5rbWdOArH04KwkAAAAUc"]
[Tue Aug 18 12:58:56.888378 2026] [security2:error] [pid 66623:tid 66846] [client 172.182.200.96:14205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/index/function.php"] [unique_id "aoSBQNO5rbWdOArH04KwkwAAAVo"]
[Tue Aug 18 12:58:56.942061 2026] [security2:error] [pid 66623:tid 66881] [client 20.127.136.245:13475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBQNO5rbWdOArH04KwlgAAAX0"]
[Tue Aug 18 12:58:56.969343 2026] [security2:error] [pid 66623:tid 66892] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/f35.update.php"] [unique_id "aoSBQNO5rbWdOArH04KwmAAAAYg"]
[Tue Aug 18 12:58:57.021330 2026] [security2:error] [pid 66623:tid 66784] [client 74.248.18.37:7596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin.php"] [unique_id "aoSBQdO5rbWdOArH04KwmQAAARw"]
[Tue Aug 18 12:58:57.036351 2026] [security2:error] [pid 66623:tid 66794] [client 168.62.48.100:1091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSBQdO5rbWdOArH04KwmwAAASY"]
[Tue Aug 18 12:58:57.050995 2026] [security2:error] [pid 66623:tid 66798] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/coffee.php"] [unique_id "aoSBQdO5rbWdOArH04KwnAAAASo"]
[Tue Aug 18 12:58:57.055744 2026] [security2:error] [pid 66623:tid 66839] [client 102.213.179.104:58109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwkgAAAVM"]
[Tue Aug 18 12:58:57.055953 2026] [security2:error] [pid 66623:tid 66839] [client 102.213.179.104:58109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwkgAAAVM"]
[Tue Aug 18 12:58:57.058979 2026] [security2:error] [pid 66623:tid 66864] [client 20.25.139.174:4554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/a.php"] [unique_id "aoSBQdO5rbWdOArH04KwngAAAWw"]
[Tue Aug 18 12:58:57.060958 2026] [security2:error] [pid 66623:tid 66707] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kv.php"] [unique_id "aoSBQdO5rbWdOArH04KwnwABe0Y"]
[Tue Aug 18 12:58:57.071413 2026] [security2:error] [pid 66623:tid 66793] [client 20.118.172.148:53092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/aa.php"] [unique_id "aoSBQdO5rbWdOArH04KwogAAASU"]
[Tue Aug 18 12:58:57.098568 2026] [security2:error] [pid 66623:tid 66821] [client 52.173.121.69:25017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/mt/byp.php"] [unique_id "aoSBQdO5rbWdOArH04KwowAAAUE"]
[Tue Aug 18 12:58:57.112864 2026] [security2:error] [pid 66623:tid 66804] [client 40.74.65.169:20114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/155.php"] [unique_id "aoSBQdO5rbWdOArH04KwpQAAATA"]
[Tue Aug 18 12:58:57.118826 2026] [security2:error] [pid 66623:tid 66867] [client 20.206.73.37:60537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/33.php"] [unique_id "aoSBQdO5rbWdOArH04KwpgAAAW8"]
[Tue Aug 18 12:58:57.136374 2026] [security2:error] [pid 66623:tid 66876] [client 20.104.85.180:54584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/rip.php"] [unique_id "aoSBQdO5rbWdOArH04KwqAAAAXg"]
[Tue Aug 18 12:58:57.192232 2026] [security2:error] [pid 66623:tid 66801] [client 20.118.133.132:14426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/mosty.php"] [unique_id "aoSBQdO5rbWdOArH04KwqgAAAS0"]
[Tue Aug 18 12:58:57.204982 2026] [security2:error] [pid 66623:tid 66837] [client 20.250.13.23:32072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSBQdO5rbWdOArH04KwqwAAAVE"]
[Tue Aug 18 12:58:57.230858 2026] [security2:error] [pid 66623:tid 66886] [client 172.202.39.151:4680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/adminfuns.php"] [unique_id "aoSBQdO5rbWdOArH04KwrgAAAYI"]
[Tue Aug 18 12:58:57.253568 2026] [authz_core:error] [pid 66623:tid 66732] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:57.254031 2026] [authz_core:error] [pid 66623:tid 66732] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:57.256253 2026] [security2:error] [pid 66623:tid 66865] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/bdroot.php"] [unique_id "aoSBQdO5rbWdOArH04KwtAAAAW0"]
[Tue Aug 18 12:58:57.273015 2026] [security2:error] [pid 66623:tid 66874] [client 4.232.151.198:58726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/h.php"] [unique_id "aoSBQdO5rbWdOArH04KwtQAAAXY"]
[Tue Aug 18 12:58:57.294685 2026] [security2:error] [pid 66623:tid 66844] [client 52.173.121.69:48299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSBQdO5rbWdOArH04KwtwAAAVg"]
[Tue Aug 18 12:58:57.330367 2026] [security2:error] [pid 66623:tid 66823] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBQdO5rbWdOArH04KwvAAAAUM"]
[Tue Aug 18 12:58:57.345793 2026] [security2:error] [pid 66623:tid 66642] [remote 74.208.9.170:51180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.9.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themenstyle.com.br"] [uri "/wp-login.php"] [unique_id "aoSBQdO5rbWdOArH04KwvgABUgU"]
[Tue Aug 18 12:58:57.369252 2026] [security2:error] [pid 66623:tid 66678] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/z.php"] [unique_id "aoSBQdO5rbWdOArH04KwwQABSCk"]
[Tue Aug 18 12:58:57.399439 2026] [security2:error] [pid 66623:tid 66770] [client 172.182.200.96:14147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSBQdO5rbWdOArH04KwxQAAAQ4"]
[Tue Aug 18 12:58:57.406776 2026] [security2:error] [pid 66623:tid 66796] [client 20.203.138.185:18448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/bb.php"] [unique_id "aoSBQdO5rbWdOArH04KwxgAAASg"]
[Tue Aug 18 12:58:57.425682 2026] [security2:error] [pid 66623:tid 66781] [client 20.206.73.37:59882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/packed.php"] [unique_id "aoSBQdO5rbWdOArH04KwxwAAARk"]
[Tue Aug 18 12:58:57.442553 2026] [security2:error] [pid 66623:tid 66638] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.git/config"] [unique_id "aoSBQdO5rbWdOArH04KwywABNgE"]
[Tue Aug 18 12:58:57.443351 2026] [security2:error] [pid 66623:tid 66754] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.aws/config"] [unique_id "aoSBQdO5rbWdOArH04KwzAABNnU"]
[Tue Aug 18 12:58:57.446949 2026] [security2:error] [pid 66623:tid 66681] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.aws/credentials"] [unique_id "aoSBQdO5rbWdOArH04KwzgABhSw"]
[Tue Aug 18 12:58:57.450267 2026] [security2:error] [pid 66623:tid 66687] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.git/HEAD"] [unique_id "aoSBQdO5rbWdOArH04KwzwABhDI"]
[Tue Aug 18 12:58:57.451774 2026] [security2:error] [pid 66623:tid 66677] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/rclone.conf"] [unique_id "aoSBQdO5rbWdOArH04Kw0AABOig"]
[Tue Aug 18 12:58:57.489795 2026] [security2:error] [pid 66623:tid 66843] [client 213.35.127.232:56663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBQdO5rbWdOArH04Kw0wAAAVc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:57.534002 2026] [security2:error] [pid 66623:tid 66800] [client 168.62.48.100:1085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSBQdO5rbWdOArH04Kw1gAAASw"]
[Tue Aug 18 12:58:57.549207 2026] [security2:error] [pid 66623:tid 66698] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/xg.php"] [unique_id "aoSBQdO5rbWdOArH04Kw1wABIT0"]
[Tue Aug 18 12:58:57.554256 2026] [security2:error] [pid 66623:tid 66822] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-temp.php"] [unique_id "aoSBQdO5rbWdOArH04Kw2AAAAUI"]
[Tue Aug 18 12:58:57.559167 2026] [security2:error] [pid 66623:tid 66646] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/z9x8c7v6b5-debug-trigger-acpecasebaterias.com.br"] [unique_id "aoSBQdO5rbWdOArH04Kw2gABOwk"]
[Tue Aug 18 12:58:57.566689 2026] [authz_core:error] [pid 66623:tid 66658] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:57.566988 2026] [authz_core:error] [pid 66623:tid 66658] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:57.601824 2026] [security2:error] [pid 66623:tid 66794] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBQdO5rbWdOArH04Kw3gAAASY"]
[Tue Aug 18 12:58:57.605917 2026] [security2:error] [pid 66623:tid 66782] [client 20.25.139.174:4598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/chosen.php"] [unique_id "aoSBQdO5rbWdOArH04Kw3wAAARo"]
[Tue Aug 18 12:58:57.636566 2026] [security2:error] [pid 66623:tid 66811] [client 4.232.94.69:16021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/aksinet.php"] [unique_id "aoSBQdO5rbWdOArH04Kw4AAAATc"]
[Tue Aug 18 12:58:57.643742 2026] [security2:error] [pid 66623:tid 66864] [client 20.127.136.245:18649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/xfun.php"] [unique_id "aoSBQdO5rbWdOArH04Kw4QAAAWw"]
[Tue Aug 18 12:58:57.654805 2026] [security2:error] [pid 66623:tid 66893] [client 20.104.85.180:52580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/gecko.php"] [unique_id "aoSBQdO5rbWdOArH04Kw4gAAAYk"]
[Tue Aug 18 12:58:57.678108 2026] [security2:error] [pid 66623:tid 66710] [remote 74.208.9.170:51180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.9.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themenstyle.com.br"] [uri "/wp-login.php"] [unique_id "aoSBQdO5rbWdOArH04Kw4wABdUk"], referer: https://themenstyle.com.br/wp-login.php
[Tue Aug 18 12:58:57.684413 2026] [security2:error] [pid 66623:tid 66882] [client 20.250.13.23:45703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSBQdO5rbWdOArH04Kw5QAAAX4"]
[Tue Aug 18 12:58:57.708350 2026] [security2:error] [pid 66623:tid 66805] [client 68.221.73.131:10567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBQdO5rbWdOArH04Kw5gAAATE"]
[Tue Aug 18 12:58:57.722422 2026] [security2:error] [pid 66623:tid 66867] [client 52.173.121.69:29024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSBQdO5rbWdOArH04Kw6QAAAW8"]
[Tue Aug 18 12:58:57.749151 2026] [security2:error] [pid 66623:tid 66718] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/nd.php"] [unique_id "aoSBQdO5rbWdOArH04Kw8QABOFE"]
[Tue Aug 18 12:58:57.809441 2026] [security2:error] [pid 66623:tid 66779] [client 40.74.65.169:20135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/ops.php"] [unique_id "aoSBQdO5rbWdOArH04Kw-AAAARc"]
[Tue Aug 18 12:58:57.838524 2026] [security2:error] [pid 66623:tid 66772] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-css.php"] [unique_id "aoSBQdO5rbWdOArH04Kw_wAAARA"]
[Tue Aug 18 12:58:57.838554 2026] [security2:error] [pid 66623:tid 66852] [client 168.62.48.100:1138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSBQdO5rbWdOArH04Kw_gAAAWA"]
[Tue Aug 18 12:58:57.845511 2026] [security2:error] [pid 66623:tid 66869] [client 158.23.17.4:15778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/nw.php"] [unique_id "aoSBQdO5rbWdOArH04KxAQAAAXE"]
[Tue Aug 18 12:58:57.864620 2026] [security2:error] [pid 66623:tid 66851] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/mgrr.php"] [unique_id "aoSBQdO5rbWdOArH04KxAgAAAV8"]
[Tue Aug 18 12:58:57.907111 2026] [security2:error] [pid 66623:tid 66821] [client 4.232.151.198:58718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/plugins/link.php"] [unique_id "aoSBQdO5rbWdOArH04KxBgAAAUE"]
[Tue Aug 18 12:58:57.907314 2026] [security2:error] [pid 66623:tid 66826] [client 172.182.200.96:14191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/Cachex.php"] [unique_id "aoSBQdO5rbWdOArH04KxBwAAAUY"]
[Tue Aug 18 12:58:57.942132 2026] [security2:error] [pid 66623:tid 66866] [client 52.173.121.69:17981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSBQdO5rbWdOArH04KxCQAAAW4"]
[Tue Aug 18 12:58:57.948793 2026] [security2:error] [pid 66623:tid 66786] [client 20.250.13.23:7192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/function/function.php"] [unique_id "aoSBQdO5rbWdOArH04KxCwAAAR4"]
[Tue Aug 18 12:58:57.958738 2026] [security2:error] [pid 66623:tid 66855] [client 132.196.30.78:14997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/ws54.php"] [unique_id "aoSBQdO5rbWdOArH04KxEAAAAWM"]
[Tue Aug 18 12:58:57.968127 2026] [security2:error] [pid 66623:tid 66708] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ri.php"] [unique_id "aoSBQdO5rbWdOArH04KxEQABWEc"]
[Tue Aug 18 12:58:58.008074 2026] [security2:error] [pid 66623:tid 66792] [client 74.248.18.37:8075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/about.php"] [unique_id "aoSBQtO5rbWdOArH04KxEwAAASQ"]
[Tue Aug 18 12:58:58.113987 2026] [security2:error] [pid 66623:tid 66872] [client 20.25.139.174:4523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBQtO5rbWdOArH04KxHQAAAXQ"]
[Tue Aug 18 12:58:58.127601 2026] [security2:error] [pid 66623:tid 66781] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/flox.php"] [unique_id "aoSBQtO5rbWdOArH04KxHwAAARk"]
[Tue Aug 18 12:58:58.140379 2026] [security2:error] [pid 66623:tid 66683] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/tp.php"] [unique_id "aoSBQtO5rbWdOArH04KxIgABay4"]
[Tue Aug 18 12:58:58.151360 2026] [authz_core:error] [pid 66623:tid 66647] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:58.151654 2026] [authz_core:error] [pid 66623:tid 66647] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:58.154468 2026] [security2:error] [pid 66623:tid 66778] [client 168.62.48.100:1087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSBQtO5rbWdOArH04KxJAAAARY"]
[Tue Aug 18 12:58:58.170898 2026] [security2:error] [pid 66623:tid 66712] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.gitconfig"] [unique_id "aoSBQtO5rbWdOArH04KxJwABZUs"]
[Tue Aug 18 12:58:58.175997 2026] [security2:error] [pid 66623:tid 66675] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.git-credentials"] [unique_id "aoSBQtO5rbWdOArH04KxKAABZSY"]
[Tue Aug 18 12:58:58.256762 2026] [security2:error] [pid 66623:tid 66752] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.gitlab-ci.yml"] [unique_id "aoSBQtO5rbWdOArH04KxLAABLHM"]
[Tue Aug 18 12:58:58.268754 2026] [security2:error] [pid 66623:tid 66743] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.github/workflows/deploy.yml"] [unique_id "aoSBQtO5rbWdOArH04KxLwABLGo"]
[Tue Aug 18 12:58:58.275831 2026] [security2:error] [pid 66623:tid 66856] [client 20.203.138.185:10414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ok.php"] [unique_id "aoSBQtO5rbWdOArH04KxMAAAAWQ"]
[Tue Aug 18 12:58:58.276203 2026] [security2:error] [pid 66623:tid 66745] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env"] [unique_id "aoSBQtO5rbWdOArH04KxMQABLGw"]
[Tue Aug 18 12:58:58.276550 2026] [security2:error] [pid 66623:tid 66850] [client 172.182.200.96:7646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSBQtO5rbWdOArH04KxMgAAAV4"]
[Tue Aug 18 12:58:58.298766 2026] [security2:error] [pid 66623:tid 66892] [client 52.173.121.69:47332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSBQtO5rbWdOArH04KxMwAAAYg"]
[Tue Aug 18 12:58:58.301508 2026] [security2:error] [pid 66623:tid 66713] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.example"] [unique_id "aoSBQtO5rbWdOArH04KxNAABLEw"]
[Tue Aug 18 12:58:58.308760 2026] [security2:error] [pid 66623:tid 66769] [client 20.104.85.180:22896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/aa.php"] [unique_id "aoSBQtO5rbWdOArH04KxNgAAAQ0"]
[Tue Aug 18 12:58:58.338643 2026] [security2:error] [pid 66623:tid 66794] [client 20.127.136.245:18658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/p.php"] [unique_id "aoSBQtO5rbWdOArH04KxOgAAASY"]
[Tue Aug 18 12:58:58.359900 2026] [security2:error] [pid 66623:tid 66816] [client 192.141.172.134:52560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBQtO5rbWdOArH04KxOwAAATw"]
[Tue Aug 18 12:58:58.360012 2026] [security2:error] [pid 66623:tid 66816] [client 192.141.172.134:52560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBQtO5rbWdOArH04KxOwAAATw"]
[Tue Aug 18 12:58:58.370008 2026] [security2:error] [pid 66623:tid 66671] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/zj.php"] [unique_id "aoSBQtO5rbWdOArH04KxPAABcCI"]
[Tue Aug 18 12:58:58.387387 2026] [security2:error] [pid 66623:tid 66839] [client 20.118.172.148:63091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/abcd.php"] [unique_id "aoSBQtO5rbWdOArH04KxPQAAAVM"]
[Tue Aug 18 12:58:58.389822 2026] [security2:error] [pid 66623:tid 66699] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.production"] [unique_id "aoSBQtO5rbWdOArH04KxPgABez4"]
[Tue Aug 18 12:58:58.425358 2026] [security2:error] [pid 66623:tid 66873] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/op.php"] [unique_id "aoSBQtO5rbWdOArH04KxQwAAAXU"]
[Tue Aug 18 12:58:58.455714 2026] [authz_core:error] [pid 66623:tid 66700] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:58.455971 2026] [authz_core:error] [pid 66623:tid 66700] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:58.494843 2026] [security2:error] [pid 66623:tid 66848] [client 20.104.85.180:54546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBQtO5rbWdOArH04KxRwAAAVw"]
[Tue Aug 18 12:58:58.506487 2026] [security2:error] [pid 66623:tid 66888] [client 213.35.127.232:56873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBQtO5rbWdOArH04KxSgAAAYQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:58.511947 2026] [security2:error] [pid 66623:tid 66775] [client 40.74.65.169:20149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/mac.php"] [unique_id "aoSBQtO5rbWdOArH04KxSwAAARM"]
[Tue Aug 18 12:58:58.512183 2026] [security2:error] [pid 66623:tid 66825] [client 20.250.13.23:17064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSBQtO5rbWdOArH04KxTAAAAUU"]
[Tue Aug 18 12:58:58.540342 2026] [security2:error] [pid 66623:tid 66758] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.local"] [unique_id "aoSBQtO5rbWdOArH04KxTQABd3k"]
[Tue Aug 18 12:58:58.550039 2026] [security2:error] [pid 66623:tid 66801] [client 158.23.17.4:14036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/sb.php"] [unique_id "aoSBQtO5rbWdOArH04KxTgAAAS0"]
[Tue Aug 18 12:58:58.552773 2026] [security2:error] [pid 66623:tid 66784] [client 132.196.30.78:15636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSBQtO5rbWdOArH04KxTwAAARw"]
[Tue Aug 18 12:58:58.572480 2026] [security2:error] [pid 66623:tid 66721] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/x.php"] [unique_id "aoSBQtO5rbWdOArH04KxUgABfFQ"]
[Tue Aug 18 12:58:58.589595 2026] [security2:error] [pid 66623:tid 66659] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.bak"] [unique_id "aoSBQtO5rbWdOArH04KxUwABURY"]
[Tue Aug 18 12:58:58.605815 2026] [security2:error] [pid 66623:tid 66886] [client 172.182.200.96:14162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-2019.php"] [unique_id "aoSBQtO5rbWdOArH04KxVgAAAYI"]
[Tue Aug 18 12:58:58.607169 2026] [security2:error] [pid 66623:tid 66736] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.old"] [unique_id "aoSBQtO5rbWdOArH04KxVwABJWM"]
[Tue Aug 18 12:58:58.609445 2026] [security2:error] [pid 66623:tid 66648] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.backup"] [unique_id "aoSBQtO5rbWdOArH04KxWAABZws"]
[Tue Aug 18 12:58:58.610387 2026] [security2:error] [pid 66623:tid 66884] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/55.php"] [unique_id "aoSBQtO5rbWdOArH04KxWQAAAYA"]
[Tue Aug 18 12:58:58.626117 2026] [security2:error] [pid 66623:tid 66744] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/.env"] [unique_id "aoSBQtO5rbWdOArH04KxWwABhms"]
[Tue Aug 18 12:58:58.629645 2026] [security2:error] [pid 66623:tid 66807] [client 168.62.48.100:1098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSBQtO5rbWdOArH04KxXAAAATM"]
[Tue Aug 18 12:58:58.630340 2026] [security2:error] [pid 66623:tid 66788] [client 20.65.98.162:18324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/admin.php"] [unique_id "aoSBQtO5rbWdOArH04KxXQAAASA"]
[Tue Aug 18 12:58:58.631681 2026] [security2:error] [pid 66623:tid 66780] [client 20.25.139.174:4658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/vx.php"] [unique_id "aoSBQtO5rbWdOArH04KxXgAAARg"]
[Tue Aug 18 12:58:58.663882 2026] [security2:error] [pid 66623:tid 66666] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/admin/.env"] [unique_id "aoSBQtO5rbWdOArH04KxYAABhh0"]
[Tue Aug 18 12:58:58.683746 2026] [security2:error] [pid 66623:tid 66804] [client 20.48.236.86:2324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/m.php"] [unique_id "aoSBQtO5rbWdOArH04KxYQAAATA"]
[Tue Aug 18 12:58:58.755396 2026] [security2:error] [pid 66623:tid 66653] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/backend/.env"] [unique_id "aoSBQtO5rbWdOArH04KxZgABSRA"]
[Tue Aug 18 12:58:58.755873 2026] [security2:error] [pid 66623:tid 66823] [client 52.173.121.69:16504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBQtO5rbWdOArH04KxaAAAAUM"]
[Tue Aug 18 12:58:58.783231 2026] [security2:error] [pid 66623:tid 66852] [client 74.248.18.37:7558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSBQtO5rbWdOArH04KxagAAAWA"]
[Tue Aug 18 12:58:58.799188 2026] [security2:error] [pid 66623:tid 66696] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/yn.php"] [unique_id "aoSBQtO5rbWdOArH04KxawABWTs"]
[Tue Aug 18 12:58:58.808124 2026] [security2:error] [pid 66623:tid 66652] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/.env"] [unique_id "aoSBQtO5rbWdOArH04KxbAABgw8"]
[Tue Aug 18 12:58:58.821148 2026] [security2:error] [pid 66623:tid 66749] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/secrets.yml"] [unique_id "aoSBQtO5rbWdOArH04KxbgABaHA"]
[Tue Aug 18 12:58:58.848787 2026] [security2:error] [pid 66623:tid 66729] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/secrets.json"] [unique_id "aoSBQtO5rbWdOArH04KxcAABDlw"]
[Tue Aug 18 12:58:58.875144 2026] [security2:error] [pid 66623:tid 66813] [client 4.232.94.69:15609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/simple.php"] [unique_id "aoSBQtO5rbWdOArH04KxcgAAATk"]
[Tue Aug 18 12:58:58.876578 2026] [security2:error] [pid 66623:tid 66673] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/service-account.json"] [unique_id "aoSBQtO5rbWdOArH04KxcwABMiQ"]
[Tue Aug 18 12:58:58.884298 2026] [security2:error] [pid 66623:tid 66796] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/ajax.php"] [unique_id "aoSBQtO5rbWdOArH04KxdAAAASg"]
[Tue Aug 18 12:58:58.896082 2026] [security2:error] [pid 66623:tid 66707] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/credentials.json"] [unique_id "aoSBQtO5rbWdOArH04KxdQABa0Y"]
[Tue Aug 18 12:58:58.901733 2026] [security2:error] [pid 66623:tid 66889] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/1xmomo.php"] [unique_id "aoSBQtO5rbWdOArH04KxdwAAAYU"]
[Tue Aug 18 12:58:58.914774 2026] [security2:error] [pid 66623:tid 66814] [client 20.203.138.185:63779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp9.php"] [unique_id "aoSBQtO5rbWdOArH04KxeAAAATo"]
[Tue Aug 18 12:58:58.937970 2026] [security2:error] [pid 66623:tid 66878] [client 68.155.155.199:13536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBQtO5rbWdOArH04KxegAAAXo"]
[Tue Aug 18 12:58:58.942321 2026] [security2:error] [pid 66623:tid 66857] [client 20.215.241.237:22275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/inso.php"] [unique_id "aoSBQtO5rbWdOArH04KxewAAAWU"]
[Tue Aug 18 12:58:58.968578 2026] [security2:error] [pid 66623:tid 66877] [client 168.62.48.100:1107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSBQtO5rbWdOArH04KxfQAAAXk"]
[Tue Aug 18 12:58:58.969236 2026] [security2:error] [pid 66623:tid 66843] [client 4.232.151.198:5474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/class-t.api.php"] [unique_id "aoSBQtO5rbWdOArH04KxfgAAAVc"]
[Tue Aug 18 12:58:58.970660 2026] [security2:error] [pid 66623:tid 66803] [client 172.202.39.151:44547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/lock360.php"] [unique_id "aoSBQtO5rbWdOArH04KxfwAAAS8"]
[Tue Aug 18 12:58:58.987226 2026] [security2:error] [pid 66623:tid 66725] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/key.json"] [unique_id "aoSBQtO5rbWdOArH04KxgAABIVg"]
[Tue Aug 18 12:58:58.990379 2026] [security2:error] [pid 66623:tid 66657] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/11.php"] [unique_id "aoSBQtO5rbWdOArH04KxgQABQhQ"]
[Tue Aug 18 12:58:59.033911 2026] [security2:error] [pid 66623:tid 66676] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/serviceAccountKey.json"] [unique_id "aoSBQ9O5rbWdOArH04KxgwABIic"]
[Tue Aug 18 12:58:59.034199 2026] [security2:error] [pid 66623:tid 66892] [client 172.182.200.96:14157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSBQ9O5rbWdOArH04KxggAAAYg"]
[Tue Aug 18 12:58:59.054651 2026] [security2:error] [pid 66623:tid 66644] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/firebase-adminsdk.json"] [unique_id "aoSBQ9O5rbWdOArH04KxhgABSwc"]
[Tue Aug 18 12:58:59.055374 2026] [authz_core:error] [pid 66623:tid 66706] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:59.055642 2026] [authz_core:error] [pid 66623:tid 66706] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:59.078598 2026] [security2:error] [pid 66623:tid 66800] [client 20.104.85.180:59540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/moon.php"] [unique_id "aoSBQ9O5rbWdOArH04KxiAAAASw"]
[Tue Aug 18 12:58:59.101377 2026] [security2:error] [pid 66623:tid 66846] [client 20.250.13.23:36145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/nw.php"] [unique_id "aoSBQ9O5rbWdOArH04KxigAAAVo"]
[Tue Aug 18 12:58:59.126032 2026] [security2:error] [pid 66623:tid 66809] [client 20.250.13.23:1835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSBQ9O5rbWdOArH04KxiwAAATU"]
[Tue Aug 18 12:58:59.132885 2026] [security2:error] [pid 66623:tid 66799] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/yj09.php"] [unique_id "aoSBQ9O5rbWdOArH04KxjAAAASs"]
[Tue Aug 18 12:58:59.145445 2026] [security2:error] [pid 66623:tid 66827] [client 20.127.136.245:18624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBQ9O5rbWdOArH04KxjgAAAUc"]
[Tue Aug 18 12:58:59.155397 2026] [security2:error] [pid 66623:tid 66695] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/service_account.json"] [unique_id "aoSBQ9O5rbWdOArH04KxjwABMTo"]
[Tue Aug 18 12:58:59.165936 2026] [security2:error] [pid 66623:tid 66751] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/vm.php"] [unique_id "aoSBQ9O5rbWdOArH04KxkQABW3I"]
[Tue Aug 18 12:58:59.174977 2026] [security2:error] [pid 66623:tid 66858] [client 20.48.236.86:31062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/33.php"] [unique_id "aoSBQ9O5rbWdOArH04KxkgAAAWY"]
[Tue Aug 18 12:58:59.201564 2026] [security2:error] [pid 66623:tid 66801] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/txets.php"] [unique_id "aoSBQ9O5rbWdOArH04KxmAAAAS0"]
[Tue Aug 18 12:58:59.206224 2026] [security2:error] [pid 66623:tid 66784] [client 168.62.48.100:1099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSBQ9O5rbWdOArH04KxmQAAARw"]
[Tue Aug 18 12:58:59.218539 2026] [security2:error] [pid 66623:tid 66678] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/firebase-service-account.json"] [unique_id "aoSBQ9O5rbWdOArH04KxmgABTCk"]
[Tue Aug 18 12:58:59.235178 2026] [security2:error] [pid 66623:tid 66883] [client 132.196.30.78:2993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/function/function.php"] [unique_id "aoSBQ9O5rbWdOArH04KxnAAAAX8"]
[Tue Aug 18 12:58:59.247689 2026] [security2:error] [pid 66623:tid 66880] [client 52.173.121.69:50207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSBQ9O5rbWdOArH04KxnQAAAXw"]
[Tue Aug 18 12:58:59.259445 2026] [security2:error] [pid 66623:tid 66772] [client 52.173.121.69:17965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBQ9O5rbWdOArH04KxngAAARA"]
[Tue Aug 18 12:58:59.307180 2026] [security2:error] [pid 66623:tid 66638] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.github/.env"] [unique_id "aoSBQ9O5rbWdOArH04KxoAABgAE"]
[Tue Aug 18 12:58:59.307504 2026] [security2:error] [pid 66623:tid 66724] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/Dockerfile"] [unique_id "aoSBQ9O5rbWdOArH04KxoQABgFc"]
[Tue Aug 18 12:58:59.320360 2026] [security2:error] [pid 66623:tid 66681] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.docker/config.json"] [unique_id "aoSBQ9O5rbWdOArH04KxpAABMyw"]
[Tue Aug 18 12:58:59.324318 2026] [security2:error] [pid 66623:tid 66788] [client 20.118.172.148:2697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/admin.php"] [unique_id "aoSBQ9O5rbWdOArH04KxpQAAASA"]
[Tue Aug 18 12:58:59.339265 2026] [security2:error] [pid 66623:tid 66687] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.npmrc"] [unique_id "aoSBQ9O5rbWdOArH04KxpwABiTI"]
[Tue Aug 18 12:58:59.348382 2026] [security2:error] [pid 66623:tid 66773] [client 20.25.139.174:4565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/ws54.php"] [unique_id "aoSBQ9O5rbWdOArH04KxqAAAARE"]
[Tue Aug 18 12:58:59.356763 2026] [authz_core:error] [pid 66623:tid 66677] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:58:59.357033 2026] [authz_core:error] [pid 66623:tid 66677] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:58:59.361217 2026] [security2:error] [pid 66623:tid 66804] [client 172.182.200.96:7502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/.cache/x.php"] [unique_id "aoSBQ9O5rbWdOArH04KxqgAAATA"]
[Tue Aug 18 12:58:59.388711 2026] [security2:error] [pid 66623:tid 66767] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/scxy.php"] [unique_id "aoSBQ9O5rbWdOArH04KxrAAAAQs"]
[Tue Aug 18 12:58:59.395168 2026] [security2:error] [pid 66623:tid 66715] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.s3cfg"] [unique_id "aoSBQ9O5rbWdOArH04KxrQABJ04"]
[Tue Aug 18 12:58:59.417114 2026] [security2:error] [pid 66623:tid 66732] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/eg.php"] [unique_id "aoSBQ9O5rbWdOArH04KxrwABSV8"]
[Tue Aug 18 12:58:59.443824 2026] [security2:error] [pid 66623:tid 66853] [client 74.248.18.37:7595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/admin.php"] [unique_id "aoSBQ9O5rbWdOArH04KxsgAAAWE"]
[Tue Aug 18 12:58:59.463097 2026] [security2:error] [pid 66623:tid 66682] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.boto"] [unique_id "aoSBQ9O5rbWdOArH04KxtAABJC0"]
[Tue Aug 18 12:58:59.488108 2026] [security2:error] [pid 66623:tid 66811] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/img.php"] [unique_id "aoSBQ9O5rbWdOArH04KxtgAAATc"]
[Tue Aug 18 12:58:59.520035 2026] [security2:error] [pid 66623:tid 66812] [client 213.35.127.232:57085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBQ9O5rbWdOArH04KxuQAAATg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:58:59.521759 2026] [security2:error] [pid 66623:tid 66887] [client 68.221.73.131:58741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBQ9O5rbWdOArH04KxugAAAYM"]
[Tue Aug 18 12:58:59.543790 2026] [security2:error] [pid 66623:tid 66710] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.svn/entries"] [unique_id "aoSBQ9O5rbWdOArH04KxuwABNEk"]
[Tue Aug 18 12:58:59.547466 2026] [security2:error] [pid 66623:tid 66740] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.htpasswd"] [unique_id "aoSBQ9O5rbWdOArH04KxvAABcmc"]
[Tue Aug 18 12:58:59.564080 2026] [security2:error] [pid 66623:tid 66742] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/terraform.tfstate"] [unique_id "aoSBQ9O5rbWdOArH04KxvQABI2k"]
[Tue Aug 18 12:58:59.569952 2026] [security2:error] [pid 66623:tid 66874] [client 20.127.136.245:17062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/aaa.php"] [unique_id "aoSBQ9O5rbWdOArH04KxvgAAAXY"]
[Tue Aug 18 12:58:59.580315 2026] [security2:error] [pid 66623:tid 66872] [client 168.62.48.100:1030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSBQ9O5rbWdOArH04KxwAAAAXQ"]
[Tue Aug 18 12:58:59.582214 2026] [security2:error] [pid 66623:tid 66781] [client 68.155.155.199:12924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBQ9O5rbWdOArH04KxwQAAARk"]
[Tue Aug 18 12:58:59.614878 2026] [security2:error] [pid 66623:tid 66785] [client 4.232.151.198:58722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoSBQ9O5rbWdOArH04KxxQAAAR0"]
[Tue Aug 18 12:58:59.619366 2026] [security2:error] [pid 66623:tid 66718] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/uk.php"] [unique_id "aoSBQ9O5rbWdOArH04KxxgABhVE"]
[Tue Aug 18 12:58:59.630204 2026] [security2:error] [pid 66623:tid 66709] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/docker-compose.yaml"] [unique_id "aoSBQ9O5rbWdOArH04KxyAABekg"]
[Tue Aug 18 12:58:59.645247 2026] [security2:error] [pid 66623:tid 66877] [client 20.203.138.185:27995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ws59.php"] [unique_id "aoSBQ9O5rbWdOArH04KxyQAAAXk"]
[Tue Aug 18 12:58:59.651075 2026] [security2:error] [pid 66623:tid 66843] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/ws13.php"] [unique_id "aoSBQ9O5rbWdOArH04KxywAAAVc"]
[Tue Aug 18 12:58:59.669691 2026] [security2:error] [pid 66623:tid 66755] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.vscode/launch.json"] [unique_id "aoSBQ9O5rbWdOArH04KxzQABKXY"]
[Tue Aug 18 12:58:59.736541 2026] [security2:error] [pid 66623:tid 66790] [client 20.104.85.180:52596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/0x.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx0QAAASI"]
[Tue Aug 18 12:58:59.738264 2026] [security2:error] [pid 66623:tid 66892] [client 52.173.121.69:14553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx0gAAAYg"]
[Tue Aug 18 12:58:59.746278 2026] [security2:error] [pid 66623:tid 66813] [client 20.25.139.174:4550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wap.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx0wAAATk"]
[Tue Aug 18 12:58:59.764034 2026] [security2:error] [pid 66623:tid 66865] [client 172.182.200.96:7574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx1QAAAW0"]
[Tue Aug 18 12:58:59.768863 2026] [security2:error] [pid 66623:tid 66747] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSBQ9O5rbWdOArH04Kx1gABS24"]
[Tue Aug 18 12:58:59.788249 2026] [security2:error] [pid 66623:tid 66800] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx2AAAASw"]
[Tue Aug 18 12:58:59.801227 2026] [security2:error] [pid 66623:tid 66690] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "aoSBQ9O5rbWdOArH04Kx2QABUzU"]
[Tue Aug 18 12:58:59.805635 2026] [security2:error] [pid 66623:tid 66863] [client 79.127.164.8:58286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/spider/uninstallmysql.sql"] [unique_id "aoSBQ9O5rbWdOArH04Kx2gAAAWs"], referer: https://medihub.com.br/spider/uninstallmysql.sql
[Tue Aug 18 12:58:59.808236 2026] [security2:error] [pid 66623:tid 66719] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/creds.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx2wABbFI"]
[Tue Aug 18 12:58:59.820793 2026] [security2:error] [pid 66623:tid 66810] [client 132.196.30.78:15637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/nw.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx3QAAATY"]
[Tue Aug 18 12:58:59.826314 2026] [security2:error] [pid 66623:tid 66720] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "aoSBQ9O5rbWdOArH04Kx3gABe1M"]
[Tue Aug 18 12:58:59.850196 2026] [security2:error] [pid 66623:tid 66680] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSBQ9O5rbWdOArH04Kx3wABdSs"]
[Tue Aug 18 12:58:59.906191 2026] [security2:error] [pid 66623:tid 66655] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.ssh/authorized_keys"] [unique_id "aoSBQ9O5rbWdOArH04Kx4gABbxI"]
[Tue Aug 18 12:58:59.906904 2026] [security2:error] [pid 66623:tid 66856] [client 20.250.13.23:17075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx4wAAAWQ"]
[Tue Aug 18 12:58:59.913111 2026] [security2:error] [pid 66623:tid 66847] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/btx25.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx5AAAAVs"]
[Tue Aug 18 12:58:59.926706 2026] [security2:error] [pid 66623:tid 66828] [client 20.25.139.174:4686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx5QAAAUg"]
[Tue Aug 18 12:58:59.967245 2026] [security2:error] [pid 66623:tid 66684] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.ssh/config"] [unique_id "aoSBQ9O5rbWdOArH04Kx5wABLS8"]
[Tue Aug 18 12:59:00.027967 2026] [security2:error] [pid 66623:tid 66775] [client 168.62.48.100:1086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSBRNO5rbWdOArH04Kx6AAAARM"]
[Tue Aug 18 12:59:00.056972 2026] [security2:error] [pid 66623:tid 66772] [client 114.119.141.40:41249] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sindifisconacional-pel.org.br"] [uri "/curtir_noticia_todas.php"] [unique_id "aoSBRNO5rbWdOArH04Kx7QAAARA"], referer: http://www.sindifisconacional-pel.org.br/todasnoticias.php?pg=2
[Tue Aug 18 12:59:00.066337 2026] [security2:error] [pid 66623:tid 66886] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBRNO5rbWdOArH04Kx7gAAAYI"]
[Tue Aug 18 12:59:00.067960 2026] [security2:error] [pid 66623:tid 66753] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ho.php"] [unique_id "aoSBRNO5rbWdOArH04Kx7wABZ3Q"]
[Tue Aug 18 12:59:00.074019 2026] [security2:error] [pid 66623:tid 66807] [client 158.23.17.4:25362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/xj.php"] [unique_id "aoSBRNO5rbWdOArH04Kx8AAAATM"]
[Tue Aug 18 12:59:00.093170 2026] [security2:error] [pid 66623:tid 66805] [client 74.248.18.37:7588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBRNO5rbWdOArH04Kx8QAAATE"]
[Tue Aug 18 12:59:00.115842 2026] [security2:error] [pid 66623:tid 66893] [client 172.182.200.96:7576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBRNO5rbWdOArH04Kx8wAAAYk"]
[Tue Aug 18 12:59:00.168163 2026] [security2:error] [pid 66623:tid 66773] [client 20.127.136.245:6095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/term.php"] [unique_id "aoSBRNO5rbWdOArH04Kx9QAAARE"]
[Tue Aug 18 12:59:00.225545 2026] [security2:error] [pid 66623:tid 66784] [client 20.250.13.23:38260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/xleet.php"] [unique_id "aoSBRNO5rbWdOArH04Kx9wAAARw"]
[Tue Aug 18 12:59:00.232653 2026] [security2:error] [pid 66623:tid 66836] [client 20.118.172.148:50099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBRNO5rbWdOArH04Kx-AAAAVA"]
[Tue Aug 18 12:59:00.239783 2026] [security2:error] [pid 66623:tid 66658] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/id_rsa"] [unique_id "aoSBRNO5rbWdOArH04Kx-gABWBU"]
[Tue Aug 18 12:59:00.248993 2026] [security2:error] [pid 66623:tid 66840] [client 20.65.98.162:17815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/biufile.php"] [unique_id "aoSBRNO5rbWdOArH04Kx-wAAAVQ"]
[Tue Aug 18 12:59:00.257100 2026] [security2:error] [pid 66623:tid 66651] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/id_dsa"] [unique_id "aoSBRNO5rbWdOArH04Kx_gABYQ4"]
[Tue Aug 18 12:59:00.261266 2026] [security2:error] [pid 66623:tid 66711] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/id_ed25519"] [unique_id "aoSBRNO5rbWdOArH04Kx_wABJEo"]
[Tue Aug 18 12:59:00.267978 2026] [security2:error] [pid 66623:tid 66849] [client 4.232.151.198:58750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/vx.php"] [unique_id "aoSBRNO5rbWdOArH04KyAAAAAV0"]
[Tue Aug 18 12:59:00.271923 2026] [security2:error] [pid 66623:tid 66811] [client 20.104.85.180:38632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/cache.php"] [unique_id "aoSBRNO5rbWdOArH04KyAQAAATc"]
[Tue Aug 18 12:59:00.290387 2026] [security2:error] [pid 66623:tid 66788] [client 20.25.139.174:4570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSBRNO5rbWdOArH04KyAgAAASA"]
[Tue Aug 18 12:59:00.306332 2026] [security2:error] [pid 66623:tid 66683] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/97.php"] [unique_id "aoSBRNO5rbWdOArH04KyBAABOC4"]
[Tue Aug 18 12:59:00.312555 2026] [security2:error] [pid 66623:tid 66688] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/id_ecdsa"] [unique_id "aoSBRNO5rbWdOArH04KyBQABLjM"]
[Tue Aug 18 12:59:00.342818 2026] [security2:error] [pid 66623:tid 66712] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/server.key"] [unique_id "aoSBRNO5rbWdOArH04KyBwABQ0s"]
[Tue Aug 18 12:59:00.348957 2026] [security2:error] [pid 66623:tid 66890] [client 132.196.30.78:15656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/xleet.php"] [unique_id "aoSBRNO5rbWdOArH04KyCAAAAYY"]
[Tue Aug 18 12:59:00.351252 2026] [security2:error] [pid 66623:tid 66870] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSBRNO5rbWdOArH04KyCQAAAXI"]
[Tue Aug 18 12:59:00.351602 2026] [security2:error] [pid 66623:tid 66692] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.ssh/known_hosts"] [unique_id "aoSBRNO5rbWdOArH04KyCwABdDc"]
[Tue Aug 18 12:59:00.355835 2026] [security2:error] [pid 66623:tid 66781] [client 168.62.48.100:1070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSBRNO5rbWdOArH04KyDAAAARk"]
[Tue Aug 18 12:59:00.378613 2026] [security2:error] [pid 66623:tid 66780] [client 4.232.94.69:45425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/berax.php"] [unique_id "aoSBRNO5rbWdOArH04KyDQAAARg"]
[Tue Aug 18 12:59:00.402628 2026] [security2:error] [pid 66623:tid 66889] [client 20.203.138.185:10401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/Ov-Simple1.php"] [unique_id "aoSBRNO5rbWdOArH04KyDgAAAYU"]
[Tue Aug 18 12:59:00.444634 2026] [security2:error] [pid 66623:tid 66852] [client 20.25.139.174:4695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/function/function.php"] [unique_id "aoSBRNO5rbWdOArH04KyEwAAAWA"]
[Tue Aug 18 12:59:00.478177 2026] [security2:error] [pid 66623:tid 66892] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSBRNO5rbWdOArH04KyFQAAAYg"]
[Tue Aug 18 12:59:00.504253 2026] [security2:error] [pid 66623:tid 66745] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/rh.php"] [unique_id "aoSBRNO5rbWdOArH04KyFwABa2w"]
[Tue Aug 18 12:59:00.535900 2026] [security2:error] [pid 66623:tid 66727] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/key.pem"] [unique_id "aoSBRNO5rbWdOArH04KyGgABJlo"]
[Tue Aug 18 12:59:00.539998 2026] [security2:error] [pid 66623:tid 66685] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/private-key"] [unique_id "aoSBRNO5rbWdOArH04KyHAABWjA"]
[Tue Aug 18 12:59:00.540144 2026] [security2:error] [pid 66623:tid 66786] [client 213.35.127.232:57310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBRNO5rbWdOArH04KyHQAAAR4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:00.556791 2026] [security2:error] [pid 66623:tid 66862] [client 196.12.128.158:60750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBRNO5rbWdOArH04KyIAAAAWo"]
[Tue Aug 18 12:59:00.556946 2026] [security2:error] [pid 66623:tid 66862] [client 196.12.128.158:60750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBRNO5rbWdOArH04KyIAAAAWo"]
[Tue Aug 18 12:59:00.559253 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:00.559554 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:00.576505 2026] [security2:error] [pid 66623:tid 66735] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/privatekey.key"] [unique_id "aoSBRNO5rbWdOArH04KyJQABTmI"]
[Tue Aug 18 12:59:00.577122 2026] [security2:error] [pid 66623:tid 66664] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/localhost.key"] [unique_id "aoSBRNO5rbWdOArH04KyJgABfhs"]
[Tue Aug 18 12:59:00.598279 2026] [security2:error] [pid 66623:tid 66654] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/ssl/server.key"] [unique_id "aoSBRNO5rbWdOArH04KyKAABbxE"]
[Tue Aug 18 12:59:00.604183 2026] [security2:error] [pid 66623:tid 66856] [client 52.173.121.69:44015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSBRNO5rbWdOArH04KyKgAAAWQ"]
[Tue Aug 18 12:59:00.612458 2026] [security2:error] [pid 66623:tid 66738] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/host.key"] [unique_id "aoSBRNO5rbWdOArH04KyLAABW2U"]
[Tue Aug 18 12:59:00.621229 2026] [security2:error] [pid 66623:tid 66835] [client 172.182.200.96:7630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBRNO5rbWdOArH04KyLgAAAU8"]
[Tue Aug 18 12:59:00.627256 2026] [security2:error] [pid 66623:tid 66888] [client 20.127.136.245:4213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/7.php"] [unique_id "aoSBRNO5rbWdOArH04KyLwAAAYQ"]
[Tue Aug 18 12:59:00.644919 2026] [security2:error] [pid 66623:tid 66857] [client 213.202.253.4:50740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/userfuns.php"] [unique_id "aoSBRNO5rbWdOArH04KyMAAAAWU"], referer: www.google.com
[Tue Aug 18 12:59:00.651677 2026] [security2:error] [pid 66623:tid 66825] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSBRNO5rbWdOArH04KyMQAAAUU"]
[Tue Aug 18 12:59:00.662976 2026] [security2:error] [pid 66623:tid 66885] [client 168.62.48.100:1093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSBRNO5rbWdOArH04KyMgAAAYE"]
[Tue Aug 18 12:59:00.742356 2026] [security2:error] [pid 66623:tid 66850] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBRNO5rbWdOArH04KyNgAAAV4"]
[Tue Aug 18 12:59:00.747628 2026] [security2:error] [pid 66623:tid 66866] [client 20.104.85.180:18749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/zxz.php"] [unique_id "aoSBRNO5rbWdOArH04KyNwAAAW4"]
[Tue Aug 18 12:59:00.750934 2026] [security2:error] [pid 66623:tid 66659] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/yg.php"] [unique_id "aoSBRNO5rbWdOArH04KyOAABfBY"]
[Tue Aug 18 12:59:00.757867 2026] [security2:error] [pid 66623:tid 66768] [client 68.221.73.131:25278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/xx.php"] [unique_id "aoSBRNO5rbWdOArH04KyOQAAAQw"]
[Tue Aug 18 12:59:00.821169 2026] [security2:error] [pid 66623:tid 66827] [client 20.25.139.174:4589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/bgymj.php"] [unique_id "aoSBRNO5rbWdOArH04KyQAAAAUc"]
[Tue Aug 18 12:59:00.861960 2026] [security2:error] [pid 66623:tid 66773] [client 52.173.121.69:17983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBRNO5rbWdOArH04KyQwAAARE"]
[Tue Aug 18 12:59:00.862115 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:00.862376 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:00.912686 2026] [security2:error] [pid 66623:tid 66875] [client 4.232.151.198:5468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/mjq.php"] [unique_id "aoSBRNO5rbWdOArH04KyRwAAAXc"]
[Tue Aug 18 12:59:00.926703 2026] [security2:error] [pid 66623:tid 66792] [client 168.62.48.100:1060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSBRNO5rbWdOArH04KySAAAASQ"]
[Tue Aug 18 12:59:00.928875 2026] [security2:error] [pid 66623:tid 66849] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/term.php"] [unique_id "aoSBRNO5rbWdOArH04KySQAAAV0"]
[Tue Aug 18 12:59:00.933495 2026] [security2:error] [pid 66623:tid 66811] [client 20.250.13.23:53679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSBRNO5rbWdOArH04KySgAAATc"]
[Tue Aug 18 12:59:00.957206 2026] [security2:error] [pid 66623:tid 66693] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/et.php"] [unique_id "aoSBRNO5rbWdOArH04KyTQABgzg"]
[Tue Aug 18 12:59:00.982885 2026] [security2:error] [pid 66623:tid 66653] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/ssl/localhost.key"] [unique_id "aoSBRNO5rbWdOArH04KyTwABhhA"]
[Tue Aug 18 12:59:00.991163 2026] [security2:error] [pid 66623:tid 66870] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBRNO5rbWdOArH04KyUAAAAXI"]
[Tue Aug 18 12:59:00.994004 2026] [security2:error] [pid 66623:tid 66872] [client 74.248.18.37:19268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/about.php"] [unique_id "aoSBRNO5rbWdOArH04KyUQAAAXQ"]
[Tue Aug 18 12:59:01.003353 2026] [security2:error] [pid 66623:tid 66674] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.openclaw/openclaw.json"] [unique_id "aoSBRdO5rbWdOArH04KyUgABGSU"]
[Tue Aug 18 12:59:01.003678 2026] [security2:error] [pid 66623:tid 66804] [client 157.51.166.53:54772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBRdO5rbWdOArH04KyUwAAATA"]
[Tue Aug 18 12:59:01.003781 2026] [security2:error] [pid 66623:tid 66804] [client 157.51.166.53:54772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBRdO5rbWdOArH04KyUwAAATA"]
[Tue Aug 18 12:59:01.015323 2026] [security2:error] [pid 66623:tid 66893] [client 20.25.139.174:4636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/nw.php"] [unique_id "aoSBRdO5rbWdOArH04KyVAAAAYk"]
[Tue Aug 18 12:59:01.083784 2026] [security2:error] [pid 66623:tid 66775] [client 132.196.30.78:15630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp.php"] [unique_id "aoSBRdO5rbWdOArH04KyVgAAARM"]
[Tue Aug 18 12:59:01.103895 2026] [security2:error] [pid 66623:tid 66762] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.aider.conf.yml"] [unique_id "aoSBRdO5rbWdOArH04KyWQABeX0"]
[Tue Aug 18 12:59:01.119611 2026] [security2:error] [pid 66623:tid 66696] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.cursor/mcp.json"] [unique_id "aoSBRdO5rbWdOArH04KyWwABTTs"]
[Tue Aug 18 12:59:01.120175 2026] [security2:error] [pid 66623:tid 66652] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSBRdO5rbWdOArH04KyXAABKQ8"]
[Tue Aug 18 12:59:01.149915 2026] [security2:error] [pid 66623:tid 66822] [client 20.118.172.148:33489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/akc.php"] [unique_id "aoSBRdO5rbWdOArH04KyXgAAAUI"]
[Tue Aug 18 12:59:01.161938 2026] [authz_core:error] [pid 66623:tid 66749] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:01.162196 2026] [authz_core:error] [pid 66623:tid 66749] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:01.169900 2026] [security2:error] [pid 66623:tid 66729] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.continue/config.json"] [unique_id "aoSBRdO5rbWdOArH04KyYAABQVw"]
[Tue Aug 18 12:59:01.184813 2026] [security2:error] [pid 66623:tid 66673] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/of.php"] [unique_id "aoSBRdO5rbWdOArH04KyYQABiCQ"]
[Tue Aug 18 12:59:01.203103 2026] [security2:error] [pid 66623:tid 66816] [client 168.62.48.100:1045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSBRdO5rbWdOArH04KyYgAAATw"]
[Tue Aug 18 12:59:01.208593 2026] [security2:error] [pid 66623:tid 66839] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/black.php"] [unique_id "aoSBRdO5rbWdOArH04KyYwAAAVM"]
[Tue Aug 18 12:59:01.225487 2026] [security2:error] [pid 66623:tid 66794] [client 40.74.65.169:42487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBRdO5rbWdOArH04KyZQAAASY"]
[Tue Aug 18 12:59:01.234754 2026] [security2:error] [pid 66623:tid 66846] [client 20.203.138.185:18480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSBRdO5rbWdOArH04KyZwAAAVo"]
[Tue Aug 18 12:59:01.235926 2026] [security2:error] [pid 66623:tid 66786] [client 52.173.121.69:35544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSBRdO5rbWdOArH04KyaQAAAR4"]
[Tue Aug 18 12:59:01.238531 2026] [security2:error] [pid 66623:tid 66864] [client 197.184.64.235:41947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBRdO5rbWdOArH04KyawAAAWw"]
[Tue Aug 18 12:59:01.238953 2026] [security2:error] [pid 66623:tid 66862] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/sky.php"] [unique_id "aoSBRdO5rbWdOArH04KyagAAAWo"]
[Tue Aug 18 12:59:01.239096 2026] [security2:error] [pid 66623:tid 66868] [client 20.250.13.23:48479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp.php"] [unique_id "aoSBRdO5rbWdOArH04KybAAAAXA"]
[Tue Aug 18 12:59:01.243377 2026] [security2:error] [pid 66623:tid 66864] [client 197.184.64.235:41947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBRdO5rbWdOArH04KyawAAAWw"]
[Tue Aug 18 12:59:01.301002 2026] [security2:error] [pid 66623:tid 66771] [client 158.23.17.4:20405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ns.php"] [unique_id "aoSBRdO5rbWdOArH04KycwAAAQ8"]
[Tue Aug 18 12:59:01.328318 2026] [security2:error] [pid 66623:tid 66824] [client 20.104.85.180:18779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/www.php"] [unique_id "aoSBRdO5rbWdOArH04KydQAAAUQ"]
[Tue Aug 18 12:59:01.350481 2026] [security2:error] [pid 66623:tid 66790] [client 20.25.139.174:4584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/aa.php"] [unique_id "aoSBRdO5rbWdOArH04KydwAAASI"]
[Tue Aug 18 12:59:01.388868 2026] [security2:error] [pid 66623:tid 66801] [client 172.182.200.96:14085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSBRdO5rbWdOArH04KyeQAAAS0"]
[Tue Aug 18 12:59:01.431983 2026] [security2:error] [pid 66623:tid 66662] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/bu.php"] [unique_id "aoSBRdO5rbWdOArH04KyfwABPhk"]
[Tue Aug 18 12:59:01.457746 2026] [security2:error] [pid 66623:tid 66756] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.codex/config.toml"] [unique_id "aoSBRdO5rbWdOArH04KygQABUXc"]
[Tue Aug 18 12:59:01.460882 2026] [security2:error] [pid 66623:tid 66678] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.hermes/.env"] [unique_id "aoSBRdO5rbWdOArH04KyggABcyk"]
[Tue Aug 18 12:59:01.474274 2026] [security2:error] [pid 66623:tid 66865] [client 4.232.94.69:45406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/fi2.php"] [unique_id "aoSBRdO5rbWdOArH04KygwAAAW0"]
[Tue Aug 18 12:59:01.518844 2026] [security2:error] [pid 66623:tid 66805] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/file5.php"] [unique_id "aoSBRdO5rbWdOArH04KyhAAAATE"]
[Tue Aug 18 12:59:01.522475 2026] [security2:error] [pid 66623:tid 66854] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/as.php"] [unique_id "aoSBRdO5rbWdOArH04KyhQAAAWI"]
[Tue Aug 18 12:59:01.530838 2026] [security2:error] [pid 66623:tid 66885] [client 20.25.139.174:4555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/xleet.php"] [unique_id "aoSBRdO5rbWdOArH04KyhgAAAYE"]
[Tue Aug 18 12:59:01.531005 2026] [security2:error] [pid 66623:tid 66803] [client 168.62.48.100:1129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSBRdO5rbWdOArH04KyhwAAAS8"]
[Tue Aug 18 12:59:01.531033 2026] [security2:error] [pid 66623:tid 66704] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.hermes/config.yaml"] [unique_id "aoSBRdO5rbWdOArH04KyiAABJ0M"]
[Tue Aug 18 12:59:01.531905 2026] [security2:error] [pid 66623:tid 66827] [client 52.173.121.69:17921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBRdO5rbWdOArH04KyiQAAAUc"]
[Tue Aug 18 12:59:01.549805 2026] [security2:error] [pid 66623:tid 66773] [client 20.104.85.180:15160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBRdO5rbWdOArH04KyiwAAARE"]
[Tue Aug 18 12:59:01.552320 2026] [security2:error] [pid 66623:tid 66817] [client 213.35.127.232:57520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBRdO5rbWdOArH04KyjAAAAT0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:01.552632 2026] [security2:error] [pid 66623:tid 66642] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.config/anthropic/credentials/default.json"] [unique_id "aoSBRdO5rbWdOArH04KyjQABGwU"]
[Tue Aug 18 12:59:01.560590 2026] [security2:error] [pid 66623:tid 66667] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.hermes/auth.json"] [unique_id "aoSBRdO5rbWdOArH04KyjgABaR4"]
[Tue Aug 18 12:59:01.567930 2026] [security2:error] [pid 66623:tid 66888] [client 4.232.151.198:5256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-includes/PHPMailer/about.php"] [unique_id "aoSBRdO5rbWdOArH04KykAAAAYQ"]
[Tue Aug 18 12:59:01.583472 2026] [security2:error] [pid 66623:tid 66844] [client 52.173.121.69:12167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/rezor.php"] [unique_id "aoSBRdO5rbWdOArH04KykQAAAVg"]
[Tue Aug 18 12:59:01.601556 2026] [security2:error] [pid 66623:tid 66700] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.claude.json"] [unique_id "aoSBRdO5rbWdOArH04KykgABJD8"]
[Tue Aug 18 12:59:01.673337 2026] [security2:error] [pid 66623:tid 66872] [client 20.127.136.245:14789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/file5.php"] [unique_id "aoSBRdO5rbWdOArH04KyngAAAXQ"]
[Tue Aug 18 12:59:01.677335 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:01.677583 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:01.729401 2026] [security2:error] [pid 66623:tid 66889] [client 20.118.172.148:63088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/buy.php"] [unique_id "aoSBRdO5rbWdOArH04KyoAAAAYU"]
[Tue Aug 18 12:59:01.738037 2026] [security2:error] [pid 66623:tid 66764] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.mcp.json"] [unique_id "aoSBRdO5rbWdOArH04KyoQABV38"]
[Tue Aug 18 12:59:01.756848 2026] [security2:error] [pid 66623:tid 66858] [client 132.196.30.78:15648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/155.php"] [unique_id "aoSBRdO5rbWdOArH04KyogAAAWY"]
[Tue Aug 18 12:59:01.756971 2026] [security2:error] [pid 66623:tid 66833] [client 20.250.13.23:53633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBRdO5rbWdOArH04KyowAAAU0"]
[Tue Aug 18 12:59:01.757393 2026] [security2:error] [pid 66623:tid 66731] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.claude/settings.json"] [unique_id "aoSBRdO5rbWdOArH04KypAABKV4"]
[Tue Aug 18 12:59:01.775287 2026] [security2:error] [pid 66623:tid 66710] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/rn.php"] [unique_id "aoSBRdO5rbWdOArH04KypgABIUk"]
[Tue Aug 18 12:59:01.783124 2026] [security2:error] [pid 66623:tid 66822] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/xyn.php"] [unique_id "aoSBRdO5rbWdOArH04KypwAAAUI"]
[Tue Aug 18 12:59:01.794998 2026] [security2:error] [pid 66623:tid 66821] [client 168.62.48.100:1161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSBRdO5rbWdOArH04KyqAAAAUE"]
[Tue Aug 18 12:59:01.807273 2026] [security2:error] [pid 66623:tid 66777] [client 172.202.39.151:44599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/flower.php"] [unique_id "aoSBRdO5rbWdOArH04KyqwAAARU"]
[Tue Aug 18 12:59:01.807417 2026] [security2:error] [pid 66623:tid 66816] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/pucci.php"] [unique_id "aoSBRdO5rbWdOArH04KyrAAAATw"]
[Tue Aug 18 12:59:01.815166 2026] [security2:error] [pid 66623:tid 66798] [client 74.248.18.37:19295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSBRdO5rbWdOArH04KyrQAAASo"]
[Tue Aug 18 12:59:01.830669 2026] [security2:error] [pid 66623:tid 66748] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.bashrc"] [unique_id "aoSBRdO5rbWdOArH04KyrwABU28"]
[Tue Aug 18 12:59:01.834692 2026] [security2:error] [pid 66623:tid 66718] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.bash_profile"] [unique_id "aoSBRdO5rbWdOArH04KysAABJlE"]
[Tue Aug 18 12:59:01.837069 2026] [security2:error] [pid 66623:tid 66709] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.zshrc"] [unique_id "aoSBRdO5rbWdOArH04KysQABWkg"]
[Tue Aug 18 12:59:01.879062 2026] [security2:error] [pid 66623:tid 66820] [client 20.25.139.174:4652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBRdO5rbWdOArH04KyswAAAUA"]
[Tue Aug 18 12:59:01.906255 2026] [security2:error] [pid 66623:tid 66755] [remote 185.227.135.83:45740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.135.227.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rafaelbuzatto.com.br"] [uri "/wp-login.php"] [unique_id "aoSBRdO5rbWdOArH04KytQABW3Y"]
[Tue Aug 18 12:59:01.909047 2026] [authz_core:error] [pid 66623:tid 66769] [client 192.178.4.133:60828] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:01.909311 2026] [authz_core:error] [pid 66623:tid 66769] [client 192.178.4.133:60828] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:01.914516 2026] [security2:error] [pid 66623:tid 66698] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.profile"] [unique_id "aoSBRdO5rbWdOArH04KytwABbD0"]
[Tue Aug 18 12:59:01.932882 2026] [security2:error] [pid 66623:tid 66882] [client 40.74.65.169:19468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSBRdO5rbWdOArH04KyuAAAAX4"]
[Tue Aug 18 12:59:01.991221 2026] [security2:error] [pid 66623:tid 66809] [client 20.48.236.86:2814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/packed.php"] [unique_id "aoSBRdO5rbWdOArH04KyvQAAATU"]
[Tue Aug 18 12:59:02.000395 2026] [security2:error] [pid 66623:tid 66857] [client 52.173.121.69:49012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/uploads/bypass.php"] [unique_id "aoSBRdO5rbWdOArH04KywAAAAWU"]
[Tue Aug 18 12:59:02.003215 2026] [security2:error] [pid 66623:tid 66719] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ut.php"] [unique_id "aoSBRtO5rbWdOArH04KywQABRVI"]
[Tue Aug 18 12:59:02.052053 2026] [security2:error] [pid 66623:tid 66869] [client 20.65.98.162:21357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/coffexium.php"] [unique_id "aoSBRtO5rbWdOArH04KywwAAAXE"]
[Tue Aug 18 12:59:02.056009 2026] [security2:error] [pid 66623:tid 66850] [client 52.173.121.69:16464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBRtO5rbWdOArH04KyxAAAAV4"]
[Tue Aug 18 12:59:02.086507 2026] [security2:error] [pid 66623:tid 66768] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wicked.php"] [unique_id "aoSBRtO5rbWdOArH04KyxgAAAQw"]
[Tue Aug 18 12:59:02.113347 2026] [security2:error] [pid 66623:tid 66720] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "acpecasebaterias.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSBRtO5rbWdOArH04KyyQABUVM"]
[Tue Aug 18 12:59:02.116498 2026] [security2:error] [pid 66623:tid 66680] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "acpecasebaterias.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSBRtO5rbWdOArH04KyygABcys"]
[Tue Aug 18 12:59:02.119855 2026] [security2:error] [pid 66623:tid 66812] [client 20.25.139.174:4650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp.php"] [unique_id "aoSBRtO5rbWdOArH04KyywAAATg"]
[Tue Aug 18 12:59:02.132662 2026] [security2:error] [pid 66623:tid 66865] [client 168.62.48.100:1056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSBRtO5rbWdOArH04KyzQAAAW0"]
[Tue Aug 18 12:59:02.180840 2026] [security2:error] [pid 66623:tid 66702] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.php.bak"] [unique_id "aoSBRtO5rbWdOArH04Ky0AABMUE"]
[Tue Aug 18 12:59:02.191004 2026] [security2:error] [pid 66623:tid 66824] [client 4.232.151.198:5500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/themes/twentytwelve/inc/.php"] [unique_id "aoSBRtO5rbWdOArH04Ky0gAAAUQ"]
[Tue Aug 18 12:59:02.201264 2026] [security2:error] [pid 66623:tid 66826] [client 20.203.138.185:17809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/vx.php"] [unique_id "aoSBRtO5rbWdOArH04Ky0wAAAUY"]
[Tue Aug 18 12:59:02.216187 2026] [security2:error] [pid 66623:tid 66655] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/eh.php"] [unique_id "aoSBRtO5rbWdOArH04Ky1AABLxI"]
[Tue Aug 18 12:59:02.223758 2026] [security2:error] [pid 66623:tid 66795] [client 20.104.85.180:14555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wicked.php"] [unique_id "aoSBRtO5rbWdOArH04Ky1QAAASc"]
[Tue Aug 18 12:59:02.250343 2026] [security2:error] [pid 66623:tid 66817] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBRtO5rbWdOArH04Ky1gAAAT0"]
[Tue Aug 18 12:59:02.295276 2026] [security2:error] [pid 66623:tid 66722] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/.env.php"] [unique_id "aoSBRtO5rbWdOArH04Ky2QABd1U"]
[Tue Aug 18 12:59:02.341534 2026] [security2:error] [pid 66623:tid 66649] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "aoSBRtO5rbWdOArH04Ky2gABJAw"]
[Tue Aug 18 12:59:02.341535 2026] [security2:error] [pid 66623:tid 66656] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/laravel/.env"] [unique_id "aoSBRtO5rbWdOArH04Ky2wABJBM"]
[Tue Aug 18 12:59:02.412620 2026] [security2:error] [pid 66623:tid 66679] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ad.php"] [unique_id "aoSBRtO5rbWdOArH04Ky3wABIyo"]
[Tue Aug 18 12:59:02.431148 2026] [security2:error] [pid 66623:tid 66827] [client 20.250.13.23:17053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSBRtO5rbWdOArH04Ky4QAAAUc"]
[Tue Aug 18 12:59:02.438977 2026] [security2:error] [pid 66623:tid 66888] [client 20.25.139.174:4618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/bolt.php"] [unique_id "aoSBRtO5rbWdOArH04Ky4gAAAYQ"]
[Tue Aug 18 12:59:02.448655 2026] [security2:error] [pid 66623:tid 66872] [client 52.173.121.69:14850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSBRtO5rbWdOArH04Ky5AAAAXQ"]
[Tue Aug 18 12:59:02.466943 2026] [security2:error] [pid 66623:tid 66783] [client 74.248.18.37:47293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/colors.php"] [unique_id "aoSBRtO5rbWdOArH04Ky5gAAARs"]
[Tue Aug 18 12:59:02.476228 2026] [security2:error] [pid 66623:tid 66796] [client 20.118.172.148:50089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/cong.php"] [unique_id "aoSBRtO5rbWdOArH04Ky5wAAASg"]
[Tue Aug 18 12:59:02.494470 2026] [security2:error] [pid 66623:tid 66893] [client 168.62.48.100:1029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSBRtO5rbWdOArH04Ky6AAAAYk"]
[Tue Aug 18 12:59:02.508400 2026] [security2:error] [pid 66623:tid 66784] [client 132.196.30.78:25104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/96i.php"] [unique_id "aoSBRtO5rbWdOArH04Ky6QAAARw"]
[Tue Aug 18 12:59:02.531063 2026] [security2:error] [pid 66623:tid 66785] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/inso.php"] [unique_id "aoSBRtO5rbWdOArH04Ky6gAAAR0"]
[Tue Aug 18 12:59:02.576788 2026] [authz_core:error] [pid 66623:tid 66650] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:02.577054 2026] [authz_core:error] [pid 66623:tid 66650] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:02.584984 2026] [security2:error] [pid 66623:tid 66838] [client 213.35.127.232:57752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBRtO5rbWdOArH04Ky7gAAAVI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:02.597342 2026] [security2:error] [pid 66623:tid 66677] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/vd.php"] [unique_id "aoSBRtO5rbWdOArH04Ky7wABdig"]
[Tue Aug 18 12:59:02.599758 2026] [security2:error] [pid 66623:tid 66708] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/core/.env"] [unique_id "aoSBRtO5rbWdOArH04Ky8AABDkc"]
[Tue Aug 18 12:59:02.603431 2026] [security2:error] [pid 66623:tid 66891] [client 86.120.159.145:61785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBRtO5rbWdOArH04Ky8QAAAYc"]
[Tue Aug 18 12:59:02.603545 2026] [security2:error] [pid 66623:tid 66891] [client 86.120.159.145:61785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBRtO5rbWdOArH04Ky8QAAAYc"]
[Tue Aug 18 12:59:02.610061 2026] [security2:error] [pid 66623:tid 66658] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/auth.json"] [unique_id "aoSBRtO5rbWdOArH04Ky8gABhRU"]
[Tue Aug 18 12:59:02.610996 2026] [security2:error] [pid 66623:tid 66781] [client 20.25.139.174:4721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/155.php"] [unique_id "aoSBRtO5rbWdOArH04Ky8wAAARk"]
[Tue Aug 18 12:59:02.618073 2026] [security2:error] [pid 66623:tid 66858] [client 40.74.65.169:43069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/system_log.php"] [unique_id "aoSBRtO5rbWdOArH04Ky9AAAAWY"]
[Tue Aug 18 12:59:02.619573 2026] [fcgid:warn] [pid 66623:tid 66833] (70014)End of file found: [client 167.94.146.51:8968] mod_fcgid: can't get data from http client
[Tue Aug 18 12:59:02.636799 2026] [security2:error] [pid 66623:tid 66789] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/water.php"] [unique_id "aoSBRtO5rbWdOArH04Ky-QAAASE"]
[Tue Aug 18 12:59:02.640908 2026] [security2:error] [pid 66623:tid 66711] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config.php.bak"] [unique_id "aoSBRtO5rbWdOArH04Ky-gABQko"]
[Tue Aug 18 12:59:02.664567 2026] [security2:error] [pid 66623:tid 66816] [client 20.104.85.180:52572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSBRtO5rbWdOArH04Ky-wAAATw"]
[Tue Aug 18 12:59:02.689000 2026] [security2:error] [pid 66623:tid 66716] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSBRtO5rbWdOArH04Ky_AABU08"]
[Tue Aug 18 12:59:02.692513 2026] [security2:error] [pid 66623:tid 66683] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.dev"] [unique_id "aoSBRtO5rbWdOArH04Ky_QABJi4"]
[Tue Aug 18 12:59:02.700918 2026] [security2:error] [pid 66623:tid 66688] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.swp"] [unique_id "aoSBRtO5rbWdOArH04Ky_gABWjM"]
[Tue Aug 18 12:59:02.733751 2026] [security2:error] [pid 66623:tid 66879] [client 168.62.48.100:1142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSBRtO5rbWdOArH04KzAAAAAXs"]
[Tue Aug 18 12:59:02.768092 2026] [security2:error] [pid 66623:tid 66868] [client 68.221.73.131:39579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/av.php"] [unique_id "aoSBRtO5rbWdOArH04KzAQAAAXA"]
[Tue Aug 18 12:59:02.810641 2026] [security2:error] [pid 66623:tid 66864] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/puc.php"] [unique_id "aoSBRtO5rbWdOArH04KzAwAAAWw"]
[Tue Aug 18 12:59:02.839008 2026] [security2:error] [pid 66623:tid 66841] [client 4.232.151.198:5445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wsa.php"] [unique_id "aoSBRtO5rbWdOArH04KzBQAAAVU"]
[Tue Aug 18 12:59:02.841420 2026] [security2:error] [pid 66623:tid 66878] [client 192.141.172.134:52803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBRtO5rbWdOArH04KzBgAAAXo"]
[Tue Aug 18 12:59:02.841583 2026] [security2:error] [pid 66623:tid 66878] [client 192.141.172.134:52803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBRtO5rbWdOArH04KzBgAAAXo"]
[Tue Aug 18 12:59:02.844847 2026] [security2:error] [pid 66623:tid 66692] [remote 185.227.135.83:45740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.135.227.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rafaelbuzatto.com.br"] [uri "/wp-login.php"] [unique_id "aoSBRtO5rbWdOArH04KzCAABVjc"], referer: https://rafaelbuzatto.com.br/wp-login.php
[Tue Aug 18 12:59:02.844983 2026] [security2:error] [pid 66623:tid 66876] [client 52.173.121.69:14547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/index/function.php"] [unique_id "aoSBRtO5rbWdOArH04KzBwAAAXg"]
[Tue Aug 18 12:59:02.867417 2026] [security2:error] [pid 66623:tid 66675] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/56.php"] [unique_id "aoSBRtO5rbWdOArH04KzCQABLSY"]
[Tue Aug 18 12:59:02.876816 2026] [authz_core:error] [pid 66623:tid 66661] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:02.877076 2026] [authz_core:error] [pid 66623:tid 66661] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:02.885575 2026] [security2:error] [pid 66623:tid 66850] [client 158.23.17.4:56572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/gk.php"] [unique_id "aoSBRtO5rbWdOArH04KzCwAAAV4"]
[Tue Aug 18 12:59:02.927308 2026] [security2:error] [pid 66623:tid 66752] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/public/.env"] [unique_id "aoSBRtO5rbWdOArH04KzDQABb3M"]
[Tue Aug 18 12:59:02.946076 2026] [security2:error] [pid 66623:tid 66730] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/web/.env"] [unique_id "aoSBRtO5rbWdOArH04KzDwABc10"]
[Tue Aug 18 12:59:02.981764 2026] [security2:error] [pid 66623:tid 66774] [client 20.25.139.174:4667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/bthil.php"] [unique_id "aoSBRtO5rbWdOArH04KzEAAAARI"]
[Tue Aug 18 12:59:02.985012 2026] [security2:error] [pid 66623:tid 66772] [client 168.62.48.100:1113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSBRtO5rbWdOArH04KzEQAAARA"]
[Tue Aug 18 12:59:03.005060 2026] [security2:error] [pid 66623:tid 66727] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/application.yml"] [unique_id "aoSBR9O5rbWdOArH04KzEwABbVo"]
[Tue Aug 18 12:59:03.016668 2026] [security2:error] [pid 66623:tid 66797] [client 4.232.94.69:57515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/feeds.php"] [unique_id "aoSBR9O5rbWdOArH04KzFAAAASk"]
[Tue Aug 18 12:59:03.046140 2026] [security2:error] [pid 66623:tid 66685] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/rx.php"] [unique_id "aoSBR9O5rbWdOArH04KzFgABdTA"]
[Tue Aug 18 12:59:03.047948 2026] [security2:error] [pid 66623:tid 66790] [client 20.203.138.185:15725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ah25.php"] [unique_id "aoSBR9O5rbWdOArH04KzFwAAASI"]
[Tue Aug 18 12:59:03.048880 2026] [security2:error] [pid 66623:tid 66809] [client 20.250.13.23:17034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSBR9O5rbWdOArH04KzGAAAATU"]
[Tue Aug 18 12:59:03.050003 2026] [security2:error] [pid 66623:tid 66735] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/application.properties"] [unique_id "aoSBR9O5rbWdOArH04KzGQABM2I"]
[Tue Aug 18 12:59:03.050184 2026] [security2:error] [pid 66623:tid 66664] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/application.properties"] [unique_id "aoSBR9O5rbWdOArH04KzGgABMxs"]
[Tue Aug 18 12:59:03.051520 2026] [security2:error] [pid 66623:tid 66717] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/bootstrap.yml"] [unique_id "aoSBR9O5rbWdOArH04KzGwABMVA"]
[Tue Aug 18 12:59:03.078538 2026] [security2:error] [pid 66623:tid 66826] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/19.php"] [unique_id "aoSBR9O5rbWdOArH04KzHQAAAUY"]
[Tue Aug 18 12:59:03.095609 2026] [security2:error] [pid 66623:tid 66793] [client 132.196.30.78:14976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/as.php"] [unique_id "aoSBR9O5rbWdOArH04KzHwAAASU"]
[Tue Aug 18 12:59:03.171503 2026] [security2:error] [pid 66623:tid 66787] [client 20.25.139.174:4572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/96i.php"] [unique_id "aoSBR9O5rbWdOArH04KzJAAAAR8"]
[Tue Aug 18 12:59:03.178883 2026] [authz_core:error] [pid 66623:tid 66763] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:03.179143 2026] [authz_core:error] [pid 66623:tid 66763] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:03.217362 2026] [security2:error] [pid 66623:tid 66778] [client 20.250.13.23:38246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/155.php"] [unique_id "aoSBR9O5rbWdOArH04KzJgAAARY"]
[Tue Aug 18 12:59:03.219701 2026] [security2:error] [pid 66623:tid 66671] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/mandrill.php"] [unique_id "aoSBR9O5rbWdOArH04KzJwABUCI"]
[Tue Aug 18 12:59:03.226354 2026] [security2:error] [pid 66623:tid 66844] [client 52.173.121.69:35560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSBR9O5rbWdOArH04KzKQAAAVg"]
[Tue Aug 18 12:59:03.229190 2026] [security2:error] [pid 66623:tid 66840] [client 168.62.48.100:1179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSBR9O5rbWdOArH04KzKgAAAVQ"]
[Tue Aug 18 12:59:03.248552 2026] [security2:error] [pid 66623:tid 66792] [client 20.118.172.148:63103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSBR9O5rbWdOArH04KzLAAAASQ"]
[Tue Aug 18 12:59:03.257768 2026] [security2:error] [pid 66623:tid 66640] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/bootstrap.properties"] [unique_id "aoSBR9O5rbWdOArH04KzLwABWQM"]
[Tue Aug 18 12:59:03.260550 2026] [security2:error] [pid 66623:tid 66814] [client 20.104.85.180:15148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBR9O5rbWdOArH04KzMQAAATo"]
[Tue Aug 18 12:59:03.262085 2026] [security2:error] [pid 66623:tid 66808] [client 52.173.121.69:16500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBR9O5rbWdOArH04KzMgAAATQ"]
[Tue Aug 18 12:59:03.289415 2026] [security2:error] [pid 66623:tid 66637] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/secrets.yml"] [unique_id "aoSBR9O5rbWdOArH04KzMwABRwA"]
[Tue Aug 18 12:59:03.372312 2026] [security2:error] [pid 66623:tid 66860] [client 74.248.18.37:19322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBR9O5rbWdOArH04KzNgAAAWg"]
[Tue Aug 18 12:59:03.413070 2026] [security2:error] [pid 66623:tid 66743] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/actuator/env"] [unique_id "aoSBR9O5rbWdOArH04KzOAABHWo"]
[Tue Aug 18 12:59:03.424745 2026] [security2:error] [pid 66623:tid 66758] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/main.php"] [unique_id "aoSBR9O5rbWdOArH04KzOgABUnk"]
[Tue Aug 18 12:59:03.465949 2026] [security2:error] [pid 66623:tid 66782] [client 4.232.151.198:5483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/add.php"] [unique_id "aoSBR9O5rbWdOArH04KzPQAAARo"]
[Tue Aug 18 12:59:03.480384 2026] [authz_core:error] [pid 66623:tid 66736] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:03.480640 2026] [authz_core:error] [pid 66623:tid 66736] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:03.514483 2026] [security2:error] [pid 66623:tid 66713] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.gradle/gradle.properties"] [unique_id "aoSBR9O5rbWdOArH04KzQQABZkw"]
[Tue Aug 18 12:59:03.514484 2026] [security2:error] [pid 66623:tid 66741] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/gradle.properties"] [unique_id "aoSBR9O5rbWdOArH04KzQAABZmg"]
[Tue Aug 18 12:59:03.514979 2026] [security2:error] [pid 66623:tid 66744] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/appsettings.json"] [unique_id "aoSBR9O5rbWdOArH04KzQgABTWs"]
[Tue Aug 18 12:59:03.518478 2026] [security2:error] [pid 66623:tid 66779] [client 168.62.48.100:1076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSBR9O5rbWdOArH04KzQwAAARc"]
[Tue Aug 18 12:59:03.608468 2026] [security2:error] [pid 66623:tid 66791] [client 213.35.127.232:57982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBR9O5rbWdOArH04KzSQAAASM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:03.613705 2026] [security2:error] [pid 66623:tid 66777] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/133.php"] [unique_id "aoSBR9O5rbWdOArH04KzSwAAARU"]
[Tue Aug 18 12:59:03.646656 2026] [security2:error] [pid 66623:tid 66859] [client 132.196.30.78:15000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/min.php"] [unique_id "aoSBR9O5rbWdOArH04KzTQAAAWc"]
[Tue Aug 18 12:59:03.648346 2026] [security2:error] [pid 66623:tid 66750] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/appsettings.Development.json"] [unique_id "aoSBR9O5rbWdOArH04KzTgABJnE"]
[Tue Aug 18 12:59:03.652049 2026] [security2:error] [pid 66623:tid 66846] [client 52.173.121.69:32629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/Cachex.php"] [unique_id "aoSBR9O5rbWdOArH04KzTwAAAVo"]
[Tue Aug 18 12:59:03.667349 2026] [security2:error] [pid 66623:tid 66648] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ga.php"] [unique_id "aoSBR9O5rbWdOArH04KzUgABQAs"]
[Tue Aug 18 12:59:03.676054 2026] [security2:error] [pid 66623:tid 66674] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/appsettings.Production.json"] [unique_id "aoSBR9O5rbWdOArH04KzUwABaiU"]
[Tue Aug 18 12:59:03.697839 2026] [security2:error] [pid 66623:tid 66789] [client 20.25.139.174:4637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/as.php"] [unique_id "aoSBR9O5rbWdOArH04KzVQAAASE"]
[Tue Aug 18 12:59:03.740115 2026] [security2:error] [pid 66623:tid 66762] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/web.config"] [unique_id "aoSBR9O5rbWdOArH04KzWAABbH0"]
[Tue Aug 18 12:59:03.810214 2026] [security2:error] [pid 66623:tid 66842] [client 168.62.48.100:1027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBR9O5rbWdOArH04KzXQAAAVY"]
[Tue Aug 18 12:59:03.814568 2026] [security2:error] [pid 66623:tid 66673] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/master.key"] [unique_id "aoSBR9O5rbWdOArH04KzXgABNyQ"]
[Tue Aug 18 12:59:03.816195 2026] [security2:error] [pid 66623:tid 66689] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/database.yml"] [unique_id "aoSBR9O5rbWdOArH04KzXwABZTQ"]
[Tue Aug 18 12:59:03.822549 2026] [security2:error] [pid 66623:tid 66828] [client 172.182.200.96:14108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSBR9O5rbWdOArH04KzYAAAAUg"]
[Tue Aug 18 12:59:03.845743 2026] [security2:error] [pid 66623:tid 66686] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/wb.php"] [unique_id "aoSBR9O5rbWdOArH04KzYgABLTE"]
[Tue Aug 18 12:59:03.872226 2026] [security2:error] [pid 66623:tid 66676] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/local.settings.json"] [unique_id "aoSBR9O5rbWdOArH04KzYwABgic"]
[Tue Aug 18 12:59:03.873266 2026] [security2:error] [pid 66623:tid 66867] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/1xmomo.php"] [unique_id "aoSBR9O5rbWdOArH04KzZAAAAW8"]
[Tue Aug 18 12:59:03.878773 2026] [security2:error] [pid 66623:tid 66775] [client 20.100.169.31:32652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/w.php"] [unique_id "aoSBR9O5rbWdOArH04KzZQAAARM"]
[Tue Aug 18 12:59:03.913977 2026] [security2:error] [pid 66623:tid 66880] [client 20.250.13.23:45730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-themes.php"] [unique_id "aoSBR9O5rbWdOArH04KzZwAAAXw"]
[Tue Aug 18 12:59:03.929452 2026] [fcgid:warn] [pid 66623:tid 66774] (70014)End of file found: [client 66.132.172.140:56148] mod_fcgid: can't get data from http client
[Tue Aug 18 12:59:04.034039 2026] [security2:error] [pid 66623:tid 66756] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/storage.yml"] [unique_id "aoSBSNO5rbWdOArH04KzbgABf3c"]
[Tue Aug 18 12:59:04.064884 2026] [security2:error] [pid 66623:tid 66803] [client 20.118.172.148:46783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/db.php"] [unique_id "aoSBSNO5rbWdOArH04KzcAAAAS8"]
[Tue Aug 18 12:59:04.067010 2026] [security2:error] [pid 66623:tid 66678] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/xn.php"] [unique_id "aoSBSNO5rbWdOArH04KzcQABgSk"]
[Tue Aug 18 12:59:04.080434 2026] [security2:error] [pid 66623:tid 66869] [client 74.248.18.37:7608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "aoSBSNO5rbWdOArH04KzcwAAAXE"]
[Tue Aug 18 12:59:04.082940 2026] [security2:error] [pid 66623:tid 66835] [client 168.62.48.100:1062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSBSNO5rbWdOArH04KzdAAAAU8"]
[Tue Aug 18 12:59:04.085030 2026] [security2:error] [pid 66623:tid 66871] [client 20.25.139.174:4608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/x.php"] [unique_id "aoSBSNO5rbWdOArH04KzdgAAAXM"]
[Tue Aug 18 12:59:04.085192 2026] [security2:error] [pid 66623:tid 66823] [client 20.38.3.247:46716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/media.php"] [unique_id "aoSBSNO5rbWdOArH04KzdwAAAUM"]
[Tue Aug 18 12:59:04.110706 2026] [security2:error] [pid 66623:tid 66816] [client 4.232.94.69:45424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/curl.php"] [unique_id "aoSBSNO5rbWdOArH04KzeQAAATw"]
[Tue Aug 18 12:59:04.116024 2026] [security2:error] [pid 66623:tid 66667] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.pypirc"] [unique_id "aoSBSNO5rbWdOArH04KzegABFh4"]
[Tue Aug 18 12:59:04.116168 2026] [security2:error] [pid 66623:tid 66667] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/settings.py"] [unique_id "aoSBSNO5rbWdOArH04KzfAABFh4"]
[Tue Aug 18 12:59:04.117318 2026] [security2:error] [pid 66623:tid 66787] [client 52.173.121.69:14554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSBSNO5rbWdOArH04KzfQAAAR8"]
[Tue Aug 18 12:59:04.126681 2026] [security2:error] [pid 66623:tid 66840] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/fine.php"] [unique_id "aoSBSNO5rbWdOArH04KzfwAAAVQ"]
[Tue Aug 18 12:59:04.133587 2026] [security2:error] [pid 66623:tid 66875] [client 52.173.121.69:24998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/first.php"] [unique_id "aoSBSNO5rbWdOArH04KzgAAAAXc"]
[Tue Aug 18 12:59:04.165349 2026] [security2:error] [pid 66623:tid 66834] [client 4.232.151.198:5473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/cron.php"] [unique_id "aoSBSNO5rbWdOArH04KzggAAAU4"]
[Tue Aug 18 12:59:04.239879 2026] [autoindex:error] [pid 66623:tid 66793] [client 132.196.30.78:15651] AH01276: Cannot serve directory /home3/cadema/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:04.275020 2026] [security2:error] [pid 66623:tid 66806] [client 20.25.139.174:4615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/min.php"] [unique_id "aoSBSNO5rbWdOArH04KziQAAATI"]
[Tue Aug 18 12:59:04.302613 2026] [security2:error] [pid 66623:tid 66639] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.streamlit/secrets.toml"] [unique_id "aoSBSNO5rbWdOArH04KziwABiQI"]
[Tue Aug 18 12:59:04.308591 2026] [security2:error] [pid 66623:tid 66681] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/47.php"] [unique_id "aoSBSNO5rbWdOArH04KzjAABaCw"]
[Tue Aug 18 12:59:04.315892 2026] [security2:error] [pid 66623:tid 66785] [client 158.23.17.4:20470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/wn.php"] [unique_id "aoSBSNO5rbWdOArH04KzjgAAAR0"]
[Tue Aug 18 12:59:04.335128 2026] [security2:error] [pid 66623:tid 66877] [client 168.62.48.100:1258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSBSNO5rbWdOArH04KzkAAAAXk"]
[Tue Aug 18 12:59:04.345430 2026] [security2:error] [pid 66623:tid 66672] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/core/settings.py"] [unique_id "aoSBSNO5rbWdOArH04KzkgABZiM"]
[Tue Aug 18 12:59:04.376609 2026] [security2:error] [pid 66623:tid 66695] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/settings.py"] [unique_id "aoSBSNO5rbWdOArH04KzmAABSzo"]
[Tue Aug 18 12:59:04.386434 2026] [authz_core:error] [pid 66623:tid 66764] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:04.386898 2026] [authz_core:error] [pid 66623:tid 66764] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:04.398937 2026] [security2:error] [pid 66623:tid 66855] [client 20.104.85.180:23995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/o.php"] [unique_id "aoSBSNO5rbWdOArH04KznAAAAWM"]
[Tue Aug 18 12:59:04.411995 2026] [security2:error] [pid 66623:tid 66748] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/app/settings.py"] [unique_id "aoSBSNO5rbWdOArH04KzngABg28"]
[Tue Aug 18 12:59:04.415388 2026] [security2:error] [pid 66623:tid 66815] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/loader.php"] [unique_id "aoSBSNO5rbWdOArH04KznwAAATs"]
[Tue Aug 18 12:59:04.426289 2026] [security2:error] [pid 66623:tid 66770] [client 132.196.30.78:15651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/php8.php"] [unique_id "aoSBSNO5rbWdOArH04KzoAAAAQ4"]
[Tue Aug 18 12:59:04.489382 2026] [security2:error] [pid 66623:tid 66709] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/backend/settings.py"] [unique_id "aoSBSNO5rbWdOArH04KzogABU0g"]
[Tue Aug 18 12:59:04.497398 2026] [security2:error] [pid 66623:tid 66746] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/payout.php"] [unique_id "aoSBSNO5rbWdOArH04KzowABJm0"]
[Tue Aug 18 12:59:04.509251 2026] [security2:error] [pid 66623:tid 66638] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config.py"] [unique_id "aoSBSNO5rbWdOArH04KzpQABewE"]
[Tue Aug 18 12:59:04.533653 2026] [security2:error] [pid 66623:tid 66782] [client 20.250.13.23:53666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSNO5rbWdOArH04KzpwAAARo"]
[Tue Aug 18 12:59:04.537839 2026] [security2:error] [pid 66623:tid 66789] [client 20.104.85.180:14582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBSNO5rbWdOArH04KzqAAAASE"]
[Tue Aug 18 12:59:04.553960 2026] [security2:error] [pid 66623:tid 66889] [client 52.173.121.69:50249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-2019.php"] [unique_id "aoSBSNO5rbWdOArH04KzqgAAAYU"]
[Tue Aug 18 12:59:04.561742 2026] [security2:error] [pid 66623:tid 66862] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSNO5rbWdOArH04KzpgABanY"]
[Tue Aug 18 12:59:04.612325 2026] [security2:error] [pid 66623:tid 66740] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/instance/config.py"] [unique_id "aoSBSNO5rbWdOArH04KzrgABhmc"]
[Tue Aug 18 12:59:04.627783 2026] [security2:error] [pid 66623:tid 66680] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.development"] [unique_id "aoSBSNO5rbWdOArH04KzsAABRSs"]
[Tue Aug 18 12:59:04.631594 2026] [security2:error] [pid 66623:tid 66824] [client 213.35.127.232:58206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBSNO5rbWdOArH04KzsgAAAUQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:04.640960 2026] [security2:error] [pid 66623:tid 66857] [client 168.62.48.100:1119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSBSNO5rbWdOArH04KztAAAAWU"]
[Tue Aug 18 12:59:04.672096 2026] [security2:error] [pid 66623:tid 66690] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.staging"] [unique_id "aoSBSNO5rbWdOArH04KztQABLTU"]
[Tue Aug 18 12:59:04.674455 2026] [security2:error] [pid 66623:tid 66702] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/bh.php"] [unique_id "aoSBSNO5rbWdOArH04KztgABXkE"]
[Tue Aug 18 12:59:04.678135 2026] [security2:error] [pid 66623:tid 66798] [client 20.25.139.174:4603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/index/function.php"] [unique_id "aoSBSNO5rbWdOArH04KztwAAASo"]
[Tue Aug 18 12:59:04.687158 2026] [authz_core:error] [pid 66623:tid 66760] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:04.687442 2026] [authz_core:error] [pid 66623:tid 66760] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:04.693493 2026] [security2:error] [pid 66623:tid 66867] [client 40.74.65.169:20147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/pucci.php"] [unique_id "aoSBSNO5rbWdOArH04KzuQAAAW8"]
[Tue Aug 18 12:59:04.702152 2026] [security2:error] [pid 66623:tid 66775] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/zero.php"] [unique_id "aoSBSNO5rbWdOArH04KzugAAARM"]
[Tue Aug 18 12:59:04.723224 2026] [security2:error] [pid 66623:tid 66884] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/mosty.php"] [unique_id "aoSBSNO5rbWdOArH04KzuwAAAYA"]
[Tue Aug 18 12:59:04.733927 2026] [security2:error] [pid 66623:tid 66774] [client 20.118.172.148:53097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/dropdown.php"] [unique_id "aoSBSNO5rbWdOArH04KzvgAAARI"]
[Tue Aug 18 12:59:04.734415 2026] [security2:error] [pid 66623:tid 66761] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.test"] [unique_id "aoSBSNO5rbWdOArH04KzvwABdXw"]
[Tue Aug 18 12:59:04.791903 2026] [security2:error] [pid 66623:tid 66856] [client 20.65.98.162:2902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/dex.php"] [unique_id "aoSBSNO5rbWdOArH04KzwgAAAWQ"]
[Tue Aug 18 12:59:04.830086 2026] [security2:error] [pid 66623:tid 66771] [client 4.232.151.198:6124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/we.php"] [unique_id "aoSBSNO5rbWdOArH04KzxAAAAQ8"]
[Tue Aug 18 12:59:04.854100 2026] [security2:error] [pid 66623:tid 66656] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config.env"] [unique_id "aoSBSNO5rbWdOArH04KzxQABgRM"]
[Tue Aug 18 12:59:04.871402 2026] [security2:error] [pid 66623:tid 66714] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/sendgrid.env"] [unique_id "aoSBSNO5rbWdOArH04KzyAABaU0"]
[Tue Aug 18 12:59:04.877095 2026] [autoindex:error] [pid 66623:tid 66848] [client 20.25.139.174:4624] AH01276: Cannot serve directory /home3/cadema/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:04.892753 2026] [security2:error] [pid 66623:tid 66835] [client 168.62.48.100:1092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSBSNO5rbWdOArH04KzyQAAAU8"]
[Tue Aug 18 12:59:04.895347 2026] [security2:error] [pid 66623:tid 66679] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ct.php"] [unique_id "aoSBSNO5rbWdOArH04KzygABFCo"]
[Tue Aug 18 12:59:04.926758 2026] [security2:error] [pid 66623:tid 66886] [client 74.248.18.37:19289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "aoSBSNO5rbWdOArH04KzzAAAAYI"]
[Tue Aug 18 12:59:04.965375 2026] [security2:error] [pid 66623:tid 66826] [client 132.196.30.78:15026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBSNO5rbWdOArH04KzzgAAAUY"]
[Tue Aug 18 12:59:04.975912 2026] [security2:error] [pid 66623:tid 66863] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/blurbs.php"] [unique_id "aoSBSNO5rbWdOArH04KzzwAAAWs"]
[Tue Aug 18 12:59:04.979367 2026] [security2:error] [pid 66623:tid 66808] [client 103.184.169.37:42511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSNO5rbWdOArH04Kz0AAAATQ"]
[Tue Aug 18 12:59:04.979654 2026] [security2:error] [pid 66623:tid 66808] [client 103.184.169.37:42511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSNO5rbWdOArH04Kz0AAAATQ"]
[Tue Aug 18 12:59:04.981692 2026] [security2:error] [pid 66623:tid 66706] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/app/.env"] [unique_id "aoSBSNO5rbWdOArH04Kz0QABH0U"]
[Tue Aug 18 12:59:04.988991 2026] [authz_core:error] [pid 66623:tid 66645] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:04.989245 2026] [authz_core:error] [pid 66623:tid 66645] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:05.006510 2026] [security2:error] [pid 66623:tid 66684] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/src/.env"] [unique_id "aoSBSdO5rbWdOArH04Kz1QABPS8"]
[Tue Aug 18 12:59:05.006528 2026] [security2:error] [pid 66623:tid 66844] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/002.php"] [unique_id "aoSBSdO5rbWdOArH04Kz1AAAAVg"]
[Tue Aug 18 12:59:05.046648 2026] [security2:error] [pid 66623:tid 66853] [client 68.221.73.131:10634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/media.php"] [unique_id "aoSBSdO5rbWdOArH04Kz1gAAAWE"]
[Tue Aug 18 12:59:05.049412 2026] [security2:error] [pid 66623:tid 66845] [client 20.25.139.174:4624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/php8.php"] [unique_id "aoSBSdO5rbWdOArH04Kz1wAAAVk"]
[Tue Aug 18 12:59:05.072269 2026] [security2:error] [pid 66623:tid 66854] [client 52.173.121.69:29019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSBSdO5rbWdOArH04Kz2AAAAWI"]
[Tue Aug 18 12:59:05.091173 2026] [security2:error] [pid 66623:tid 66828] [client 4.232.94.69:54142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/Njima.php"] [unique_id "aoSBSdO5rbWdOArH04Kz2QAAAUg"]
[Tue Aug 18 12:59:05.123265 2026] [security2:error] [pid 66623:tid 66872] [client 52.173.121.69:16457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBSdO5rbWdOArH04Kz3AAAAXQ"]
[Tue Aug 18 12:59:05.129110 2026] [security2:error] [pid 66623:tid 66658] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gy.php"] [unique_id "aoSBSdO5rbWdOArH04Kz3QABMBU"]
[Tue Aug 18 12:59:05.172709 2026] [security2:error] [pid 66623:tid 66846] [client 103.120.71.157:18181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSdO5rbWdOArH04Kz3gAAAVo"]
[Tue Aug 18 12:59:05.172849 2026] [security2:error] [pid 66623:tid 66846] [client 103.120.71.157:18181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSdO5rbWdOArH04Kz3gAAAVo"]
[Tue Aug 18 12:59:05.183634 2026] [security2:error] [pid 66623:tid 66802] [client 20.118.172.148:43465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/file.php"] [unique_id "aoSBSdO5rbWdOArH04Kz4AAAAS4"]
[Tue Aug 18 12:59:05.184450 2026] [security2:error] [pid 66623:tid 66785] [client 168.62.48.100:1036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSBSdO5rbWdOArH04Kz4gAAAR0"]
[Tue Aug 18 12:59:05.222460 2026] [security2:error] [pid 66623:tid 66711] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/frontend/.env"] [unique_id "aoSBSdO5rbWdOArH04Kz5QABF0o"]
[Tue Aug 18 12:59:05.222829 2026] [security2:error] [pid 66623:tid 66795] [client 158.23.17.4:56704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/app.php"] [unique_id "aoSBSdO5rbWdOArH04Kz5AAAASc"]
[Tue Aug 18 12:59:05.235511 2026] [security2:error] [pid 66623:tid 66830] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/bajah.php"] [unique_id "aoSBSdO5rbWdOArH04Kz5wAAAUo"]
[Tue Aug 18 12:59:05.244826 2026] [security2:error] [pid 66623:tid 66797] [client 20.250.13.23:46901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/96i.php"] [unique_id "aoSBSdO5rbWdOArH04Kz6AAAASk"]
[Tue Aug 18 12:59:05.254839 2026] [security2:error] [pid 66623:tid 66814] [client 20.25.139.174:4490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/aaa.php"] [unique_id "aoSBSdO5rbWdOArH04Kz6QAAATo"]
[Tue Aug 18 12:59:05.276422 2026] [security2:error] [pid 66623:tid 66683] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/server/.env"] [unique_id "aoSBSdO5rbWdOArH04Kz6wABYy4"]
[Tue Aug 18 12:59:05.298037 2026] [security2:error] [pid 66623:tid 66783] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/zxz.php"] [unique_id "aoSBSdO5rbWdOArH04Kz7AAAARs"]
[Tue Aug 18 12:59:05.332154 2026] [security2:error] [pid 66623:tid 66688] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/tt.php"] [unique_id "aoSBSdO5rbWdOArH04Kz7QABZzM"]
[Tue Aug 18 12:59:05.387640 2026] [security2:error] [pid 66623:tid 66753] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/production/.env"] [unique_id "aoSBSdO5rbWdOArH04Kz7wABIXQ"]
[Tue Aug 18 12:59:05.412091 2026] [authz_core:error] [pid 66623:tid 66668] [remote 57.141.22.127:30348] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:05.412359 2026] [authz_core:error] [pid 66623:tid 66668] [remote 57.141.22.127:30348] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:05.437435 2026] [security2:error] [pid 66623:tid 66692] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/docker/.env"] [unique_id "aoSBSdO5rbWdOArH04Kz9AABQDc"]
[Tue Aug 18 12:59:05.446185 2026] [security2:error] [pid 66623:tid 66675] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/staging/.env"] [unique_id "aoSBSdO5rbWdOArH04Kz9QABhiY"]
[Tue Aug 18 12:59:05.453361 2026] [security2:error] [pid 66623:tid 66824] [client 20.203.138.185:10964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/tt.php"] [unique_id "aoSBSdO5rbWdOArH04Kz9wAAAUQ"]
[Tue Aug 18 12:59:05.463032 2026] [security2:error] [pid 66623:tid 66831] [client 79.127.164.8:58368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/sql.bak"] [unique_id "aoSBSdO5rbWdOArH04Kz-QAAAUs"], referer: https://medihub.com.br/sql.bak
[Tue Aug 18 12:59:05.468142 2026] [security2:error] [pid 66623:tid 66842] [client 52.173.121.69:42693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/.cache/x.php"] [unique_id "aoSBSdO5rbWdOArH04Kz-gAAAVY"]
[Tue Aug 18 12:59:05.487131 2026] [security2:error] [pid 66623:tid 66813] [client 138.36.100.162:42273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSdO5rbWdOArH04Kz_AAAATk"]
[Tue Aug 18 12:59:05.487238 2026] [security2:error] [pid 66623:tid 66813] [client 138.36.100.162:42273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSdO5rbWdOArH04Kz_AAAATk"]
[Tue Aug 18 12:59:05.487926 2026] [security2:error] [pid 66623:tid 66790] [client 4.232.151.198:30045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/themes/newsfeed-theme/bbh.php"] [unique_id "aoSBSdO5rbWdOArH04Kz_QAAASI"]
[Tue Aug 18 12:59:05.499440 2026] [security2:error] [pid 66623:tid 66768] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/h.php"] [unique_id "aoSBSdO5rbWdOArH04Kz_gAAAQw"]
[Tue Aug 18 12:59:05.509120 2026] [security2:error] [pid 66623:tid 66752] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/dev/.env"] [unique_id "aoSBSdO5rbWdOArH04Kz_wABXnM"]
[Tue Aug 18 12:59:05.520458 2026] [security2:error] [pid 66623:tid 66819] [client 168.62.48.100:1121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSBSdO5rbWdOArH04K0AAAAAT8"]
[Tue Aug 18 12:59:05.536790 2026] [security2:error] [pid 66623:tid 66772] [client 20.104.85.180:28628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/cah.php"] [unique_id "aoSBSdO5rbWdOArH04K0AgAAARA"]
[Tue Aug 18 12:59:05.541048 2026] [security2:error] [pid 66623:tid 66782] [client 20.25.139.174:4662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBSdO5rbWdOArH04K0AwAAARo"]
[Tue Aug 18 12:59:05.582478 2026] [security2:error] [pid 66623:tid 66727] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/mq.php"] [unique_id "aoSBSdO5rbWdOArH04K0BQABiFo"]
[Tue Aug 18 12:59:05.583590 2026] [security2:error] [pid 66623:tid 66810] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/memberfuns.php"] [unique_id "aoSBSdO5rbWdOArH04K0BgAAATY"]
[Tue Aug 18 12:59:05.592030 2026] [security2:error] [pid 66623:tid 66889] [client 132.196.30.78:20406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/222.php"] [unique_id "aoSBSdO5rbWdOArH04K0CAAAAYU"]
[Tue Aug 18 12:59:05.594910 2026] [authz_core:error] [pid 66623:tid 66685] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:05.595163 2026] [authz_core:error] [pid 66623:tid 66685] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:05.610436 2026] [security2:error] [pid 66623:tid 66735] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.docker"] [unique_id "aoSBSdO5rbWdOArH04K0CgABD2I"]
[Tue Aug 18 12:59:05.638787 2026] [security2:error] [pid 66623:tid 66664] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.production.bak"] [unique_id "aoSBSdO5rbWdOArH04K0CwABgRs"]
[Tue Aug 18 12:59:05.644220 2026] [security2:error] [pid 66623:tid 66777] [client 213.35.127.232:58453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBSdO5rbWdOArH04K0DQAAARU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:05.667829 2026] [security2:error] [pid 66623:tid 66835] [client 20.104.85.180:47121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/bb.php"] [unique_id "aoSBSdO5rbWdOArH04K0DwAAAU8"]
[Tue Aug 18 12:59:05.669836 2026] [security2:error] [pid 66623:tid 66836] [client 37.40.227.74:57061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSdO5rbWdOArH04K0EAAAAVA"]
[Tue Aug 18 12:59:05.679007 2026] [security2:error] [pid 66623:tid 66836] [client 37.40.227.74:57061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSdO5rbWdOArH04K0EAAAAVA"]
[Tue Aug 18 12:59:05.728979 2026] [security2:error] [pid 66623:tid 66705] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.prod.bak"] [unique_id "aoSBSdO5rbWdOArH04K0EgABH0Q"]
[Tue Aug 18 12:59:05.756839 2026] [security2:error] [pid 66623:tid 66874] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/ano.php"] [unique_id "aoSBSdO5rbWdOArH04K0FQAAAXY"]
[Tue Aug 18 12:59:05.763823 2026] [security2:error] [pid 66623:tid 66745] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/@fs/.env"] [unique_id "aoSBSdO5rbWdOArH04K0FgABbWw"]
[Tue Aug 18 12:59:05.774023 2026] [security2:error] [pid 66623:tid 66640] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/13.php"] [unique_id "aoSBSdO5rbWdOArH04K0FwABJAM"]
[Tue Aug 18 12:59:05.783013 2026] [security2:error] [pid 66623:tid 66637] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/@fs/root/.env"] [unique_id "aoSBSdO5rbWdOArH04K0GAABWQA"]
[Tue Aug 18 12:59:05.795733 2026] [security2:error] [pid 66623:tid 66881] [client 168.62.48.100:1088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSBSdO5rbWdOArH04K0GgAAAX0"]
[Tue Aug 18 12:59:05.797782 2026] [security2:error] [pid 66623:tid 66839] [client 149.34.210.141:64150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBSdO5rbWdOArH04K0GwAAAVM"]
[Tue Aug 18 12:59:05.813356 2026] [security2:error] [pid 66623:tid 66832] [client 74.248.18.37:32076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/colors/ectoplasm/about.php"] [unique_id "aoSBSdO5rbWdOArH04K0HQAAAUw"]
[Tue Aug 18 12:59:05.825641 2026] [security2:error] [pid 66623:tid 66803] [client 20.25.139.174:4616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/abcd.php"] [unique_id "aoSBSdO5rbWdOArH04K0HwAAAS8"]
[Tue Aug 18 12:59:05.846619 2026] [security2:error] [pid 66623:tid 66800] [client 52.173.121.69:14543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSBSdO5rbWdOArH04K0IgAAASw"]
[Tue Aug 18 12:59:05.850672 2026] [security2:error] [pid 66623:tid 66872] [client 172.202.39.151:44548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/13.php"] [unique_id "aoSBSdO5rbWdOArH04K0IwAAAXQ"]
[Tue Aug 18 12:59:05.852001 2026] [security2:error] [pid 66623:tid 66758] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBSdO5rbWdOArH04K0JAABMHk"]
[Tue Aug 18 12:59:05.856939 2026] [security2:error] [pid 66623:tid 66796] [client 20.118.172.148:63081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/goods.php"] [unique_id "aoSBSdO5rbWdOArH04K0JQAAASg"]
[Tue Aug 18 12:59:05.861440 2026] [security2:error] [pid 66623:tid 66893] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/aa.php"] [unique_id "aoSBSdO5rbWdOArH04K0JgAAAYk"]
[Tue Aug 18 12:59:05.875731 2026] [security2:error] [pid 66623:tid 66818] [client 68.221.73.131:27392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/images.php"] [unique_id "aoSBSdO5rbWdOArH04K0KQAAAT4"]
[Tue Aug 18 12:59:05.902954 2026] [authz_core:error] [pid 66623:tid 66654] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:05.903404 2026] [authz_core:error] [pid 66623:tid 66654] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:05.931574 2026] [security2:error] [pid 66623:tid 66856] [client 4.232.94.69:21159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/colors.php"] [unique_id "aoSBSdO5rbWdOArH04K0LAAAAWQ"]
[Tue Aug 18 12:59:05.941884 2026] [security2:error] [pid 66623:tid 66741] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/gcp-credentials.json"] [unique_id "aoSBSdO5rbWdOArH04K0LQABEWg"]
[Tue Aug 18 12:59:05.975055 2026] [security2:error] [pid 66623:tid 66783] [client 172.202.39.151:4435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSBSdO5rbWdOArH04K0LgAAARs"]
[Tue Aug 18 12:59:05.986044 2026] [security2:error] [pid 66623:tid 66744] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/so.php"] [unique_id "aoSBSdO5rbWdOArH04K0LwABJms"]
[Tue Aug 18 12:59:06.007314 2026] [security2:error] [pid 66623:tid 66891] [client 157.20.138.62:54497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0MgAAAYc"]
[Tue Aug 18 12:59:06.007417 2026] [security2:error] [pid 66623:tid 66891] [client 157.20.138.62:54497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0MgAAAYc"]
[Tue Aug 18 12:59:06.012351 2026] [security2:error] [pid 66623:tid 66786] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/ai.php"] [unique_id "aoSBStO5rbWdOArH04K0MwAAAR4"]
[Tue Aug 18 12:59:06.014486 2026] [security2:error] [pid 66623:tid 66733] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/google-credentials.json"] [unique_id "aoSBStO5rbWdOArH04K0NAABQGA"]
[Tue Aug 18 12:59:06.023350 2026] [security2:error] [pid 66623:tid 66739] [remote 129.121.123.168:42342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.123.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-login.php"] [unique_id "aoSBStO5rbWdOArH04K0NQABVWY"]
[Tue Aug 18 12:59:06.042607 2026] [security2:error] [pid 66623:tid 66767] [client 168.62.48.100:1163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSBStO5rbWdOArH04K0NwAAAQs"]
[Tue Aug 18 12:59:06.049642 2026] [security2:error] [pid 66623:tid 66838] [client 20.25.139.174:4654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/222.php"] [unique_id "aoSBStO5rbWdOArH04K0OAAAAVI"]
[Tue Aug 18 12:59:06.076514 2026] [security2:error] [pid 66623:tid 66839] [client 149.34.210.141:64150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBSdO5rbWdOArH04K0GwAAAVM"]
[Tue Aug 18 12:59:06.080694 2026] [security2:error] [pid 66623:tid 66768] [client 172.182.200.96:7650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBStO5rbWdOArH04K0OgAAAQw"]
[Tue Aug 18 12:59:06.115319 2026] [security2:error] [pid 66623:tid 66850] [client 52.173.121.69:16453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBStO5rbWdOArH04K0PgAAAV4"]
[Tue Aug 18 12:59:06.121172 2026] [security2:error] [pid 66623:tid 66648] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/keys/service-account.json"] [unique_id "aoSBStO5rbWdOArH04K0PwABPws"]
[Tue Aug 18 12:59:06.133508 2026] [security2:error] [pid 66623:tid 66674] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/sa.json"] [unique_id "aoSBStO5rbWdOArH04K0QgABECU"]
[Tue Aug 18 12:59:06.133798 2026] [security2:error] [pid 66623:tid 66834] [client 4.232.151.198:58711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/network/xleet.php"] [unique_id "aoSBStO5rbWdOArH04K0QQAAAU4"]
[Tue Aug 18 12:59:06.151019 2026] [security2:error] [pid 66623:tid 66659] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/firebase-credentials.json"] [unique_id "aoSBStO5rbWdOArH04K0QwABGRY"]
[Tue Aug 18 12:59:06.158553 2026] [security2:error] [pid 66623:tid 66879] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/echkm.php"] [unique_id "aoSBStO5rbWdOArH04K0RAAAAXs"]
[Tue Aug 18 12:59:06.162428 2026] [security2:error] [pid 66623:tid 66661] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/10.php"] [unique_id "aoSBStO5rbWdOArH04K0RQABDxg"]
[Tue Aug 18 12:59:06.196356 2026] [security2:error] [pid 66623:tid 66696] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/firebase-admin.json"] [unique_id "aoSBStO5rbWdOArH04K0SQABgTs"]
[Tue Aug 18 12:59:06.202043 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:06.202515 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:06.213917 2026] [security2:error] [pid 66623:tid 66775] [client 114.5.214.109:50412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0SgAAARM"]
[Tue Aug 18 12:59:06.215667 2026] [security2:error] [pid 66623:tid 66775] [client 114.5.214.109:50412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0SgAAARM"]
[Tue Aug 18 12:59:06.220193 2026] [security2:error] [pid 66623:tid 66882] [client 132.196.30.78:20370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBStO5rbWdOArH04K0TAAAAX4"]
[Tue Aug 18 12:59:06.224224 2026] [security2:error] [pid 66623:tid 66835] [client 20.104.85.180:35886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSBStO5rbWdOArH04K0TgAAAU8"]
[Tue Aug 18 12:59:06.224742 2026] [security2:error] [pid 66623:tid 66886] [client 52.173.121.69:30384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-content/index.php"] [unique_id "aoSBStO5rbWdOArH04K0TwAAAYI"]
[Tue Aug 18 12:59:06.226102 2026] [security2:error] [pid 66623:tid 66689] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/gcp-key.json"] [unique_id "aoSBStO5rbWdOArH04K0UAABUDQ"]
[Tue Aug 18 12:59:06.275273 2026] [security2:error] [pid 66623:tid 66686] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/public/admin.json"] [unique_id "aoSBStO5rbWdOArH04K0UgABWDE"]
[Tue Aug 18 12:59:06.307113 2026] [security2:error] [pid 66623:tid 66865] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/w1px.php"] [unique_id "aoSBStO5rbWdOArH04K0VAAAAW0"]
[Tue Aug 18 12:59:06.317743 2026] [security2:error] [pid 66623:tid 66810] [client 20.25.139.174:4712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-good.php"] [unique_id "aoSBStO5rbWdOArH04K0VQAAATY"]
[Tue Aug 18 12:59:06.358549 2026] [security2:error] [pid 66623:tid 66652] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/firebase-admin.json"] [unique_id "aoSBStO5rbWdOArH04K0WAABLw8"]
[Tue Aug 18 12:59:06.368661 2026] [security2:error] [pid 66623:tid 66707] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/te.php"] [unique_id "aoSBStO5rbWdOArH04K0WQABSEY"]
[Tue Aug 18 12:59:06.378113 2026] [security2:error] [pid 66623:tid 66763] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/gcp-credentials.json"] [unique_id "aoSBStO5rbWdOArH04K0WwABMn4"]
[Tue Aug 18 12:59:06.380288 2026] [security2:error] [pid 66623:tid 66756] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/firebase.json"] [unique_id "aoSBStO5rbWdOArH04K0XAABLHc"]
[Tue Aug 18 12:59:06.383909 2026] [security2:error] [pid 66623:tid 66872] [client 168.62.48.100:1072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSBStO5rbWdOArH04K0XQAAAXQ"]
[Tue Aug 18 12:59:06.387028 2026] [security2:error] [pid 66623:tid 66678] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0XgABOSk"]
[Tue Aug 18 12:59:06.387225 2026] [security2:error] [pid 66623:tid 66813] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0XgABOSk"]
[Tue Aug 18 12:59:06.416910 2026] [security2:error] [pid 66623:tid 66875] [client 5.31.227.224:7835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0YgAAAXc"]
[Tue Aug 18 12:59:06.417034 2026] [security2:error] [pid 66623:tid 66875] [client 5.31.227.224:7835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0YgAAAXc"]
[Tue Aug 18 12:59:06.442303 2026] [security2:error] [pid 66623:tid 66693] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/google-service-account.json"] [unique_id "aoSBStO5rbWdOArH04K0ZgABSjg"]
[Tue Aug 18 12:59:06.444604 2026] [security2:error] [pid 66623:tid 66797] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/domvf.php"] [unique_id "aoSBStO5rbWdOArH04K0ZwAAASk"]
[Tue Aug 18 12:59:06.447714 2026] [security2:error] [pid 66623:tid 66822] [client 20.203.138.185:37253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/xqq.php"] [unique_id "aoSBStO5rbWdOArH04K0aAAAAUI"]
[Tue Aug 18 12:59:06.449104 2026] [security2:error] [pid 66623:tid 66856] [client 20.104.85.180:18735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/system_log.php"] [unique_id "aoSBStO5rbWdOArH04K0aQAAAWQ"]
[Tue Aug 18 12:59:06.462828 2026] [security2:error] [pid 66623:tid 66725] [remote 162.214.205.212:56014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ihostiweb.com"] [uri "/wp-login.php"] [unique_id "aoSBStO5rbWdOArH04K0agABYVg"]
[Tue Aug 18 12:59:06.477404 2026] [security2:error] [pid 66623:tid 66700] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/push_config.json"] [unique_id "aoSBStO5rbWdOArH04K0bAABQz8"]
[Tue Aug 18 12:59:06.527910 2026] [security2:error] [pid 66623:tid 66724] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/gc-service.json"] [unique_id "aoSBStO5rbWdOArH04K0cAABI1c"]
[Tue Aug 18 12:59:06.535700 2026] [security2:error] [pid 66623:tid 66814] [client 178.153.171.161:8532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0cQAAATo"]
[Tue Aug 18 12:59:06.535817 2026] [security2:error] [pid 66623:tid 66814] [client 178.153.171.161:8532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0cQAAATo"]
[Tue Aug 18 12:59:06.554794 2026] [security2:error] [pid 66623:tid 66643] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kc.php"] [unique_id "aoSBStO5rbWdOArH04K0cwABJgY"]
[Tue Aug 18 12:59:06.570344 2026] [security2:error] [pid 66623:tid 66877] [client 20.25.139.174:4692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBStO5rbWdOArH04K0dAAAAXk"]
[Tue Aug 18 12:59:06.575768 2026] [security2:error] [pid 66623:tid 66736] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/gcp-service.json"] [unique_id "aoSBStO5rbWdOArH04K0dgABNWM"]
[Tue Aug 18 12:59:06.580578 2026] [security2:error] [pid 66623:tid 66881] [client 74.248.18.37:25338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/colors/ectoplasm/wp-login.php"] [unique_id "aoSBStO5rbWdOArH04K0dQAAAX0"]
[Tue Aug 18 12:59:06.591671 2026] [security2:error] [pid 66623:tid 66788] [client 20.118.172.148:64264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBStO5rbWdOArH04K0dwAAASA"]
[Tue Aug 18 12:59:06.592345 2026] [security2:error] [pid 66623:tid 66639] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/debug/pprof/"] [unique_id "aoSBStO5rbWdOArH04K0eAABHgI"]
[Tue Aug 18 12:59:06.592933 2026] [security2:error] [pid 66623:tid 66681] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/google-services.json"] [unique_id "aoSBStO5rbWdOArH04K0eQABHiw"]
[Tue Aug 18 12:59:06.596070 2026] [security2:error] [pid 66623:tid 66864] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/zi-936.php"] [unique_id "aoSBStO5rbWdOArH04K0egAAAWw"]
[Tue Aug 18 12:59:06.653901 2026] [security2:error] [pid 66623:tid 66793] [client 213.35.127.232:58685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBStO5rbWdOArH04K0hwAAASU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:06.666857 2026] [security2:error] [pid 66623:tid 66838] [client 168.62.48.100:1108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSBStO5rbWdOArH04K0iAAAAVI"]
[Tue Aug 18 12:59:06.687856 2026] [security2:error] [pid 66623:tid 66825] [client 52.173.121.69:14874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBStO5rbWdOArH04K0iQAAAUU"]
[Tue Aug 18 12:59:06.747281 2026] [security2:error] [pid 66623:tid 66728] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/debug/pprof/cmdline"] [unique_id "aoSBStO5rbWdOArH04K0jQABP1s"]
[Tue Aug 18 12:59:06.762411 2026] [security2:error] [pid 66623:tid 66859] [client 4.232.151.198:6106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "aoSBStO5rbWdOArH04K0jwAAAWc"]
[Tue Aug 18 12:59:06.764475 2026] [security2:error] [pid 66623:tid 66820] [client 132.196.30.78:14620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/info.php"] [unique_id "aoSBStO5rbWdOArH04K0kAAAAUA"]
[Tue Aug 18 12:59:06.773782 2026] [security2:error] [pid 66623:tid 66774] [client 40.74.65.169:20139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-temp.php"] [unique_id "aoSBStO5rbWdOArH04K0kQAAARI"]
[Tue Aug 18 12:59:06.774072 2026] [security2:error] [pid 66623:tid 66892] [client 20.250.13.23:48025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/as.php"] [unique_id "aoSBStO5rbWdOArH04K0kgAAAYg"]
[Tue Aug 18 12:59:06.775823 2026] [security2:error] [pid 66623:tid 66801] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/red.php"] [unique_id "aoSBStO5rbWdOArH04K0kwAAAS0"]
[Tue Aug 18 12:59:06.788371 2026] [security2:error] [pid 66623:tid 66638] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/jn.php"] [unique_id "aoSBStO5rbWdOArH04K0lAABewE"]
[Tue Aug 18 12:59:06.798511 2026] [authz_core:error] [pid 66623:tid 66687] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:06.798792 2026] [authz_core:error] [pid 66623:tid 66687] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:06.799084 2026] [security2:error] [pid 66623:tid 66755] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/debug/vars"] [unique_id "aoSBStO5rbWdOArH04K0lgABdXY"]
[Tue Aug 18 12:59:06.816922 2026] [security2:error] [pid 66623:tid 66824] [client 20.25.139.174:4571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/simple.php"] [unique_id "aoSBStO5rbWdOArH04K0mAAAAUQ"]
[Tue Aug 18 12:59:06.859448 2026] [security2:error] [pid 66623:tid 66780] [client 20.100.169.31:24428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/archive.php"] [unique_id "aoSBStO5rbWdOArH04K0ngAAARg"]
[Tue Aug 18 12:59:06.872727 2026] [security2:error] [pid 66623:tid 66720] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/metrics"] [unique_id "aoSBStO5rbWdOArH04K0oAABT1M"]
[Tue Aug 18 12:59:06.874331 2026] [security2:error] [pid 66623:tid 66886] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/dcsgumnm.php"] [unique_id "aoSBStO5rbWdOArH04K0oQAAAYI"]
[Tue Aug 18 12:59:06.930222 2026] [security2:error] [pid 66623:tid 66718] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config.yaml"] [unique_id "aoSBStO5rbWdOArH04K0pwABVlE"]
[Tue Aug 18 12:59:06.945776 2026] [security2:error] [pid 66623:tid 66817] [client 168.62.48.100:1164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSBStO5rbWdOArH04K0qAAAAT0"]
[Tue Aug 18 12:59:06.999710 2026] [security2:error] [pid 66623:tid 66781] [client 132.196.30.78:15036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/inputs.php"] [unique_id "aoSBStO5rbWdOArH04K0rgAAARk"]
[Tue Aug 18 12:59:07.031688 2026] [security2:error] [pid 66623:tid 66706] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/bf.php"] [unique_id "aoSBS9O5rbWdOArH04K0sQABOUU"]
[Tue Aug 18 12:59:07.052473 2026] [security2:error] [pid 66623:tid 66655] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config.toml"] [unique_id "aoSBS9O5rbWdOArH04K0swABFBI"]
[Tue Aug 18 12:59:07.065062 2026] [security2:error] [pid 66623:tid 66787] [client 20.25.139.174:4605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/info.php"] [unique_id "aoSBS9O5rbWdOArH04K0tQAAAR8"]
[Tue Aug 18 12:59:07.081240 2026] [security2:error] [pid 66623:tid 66874] [client 223.185.37.47:24499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBS9O5rbWdOArH04K0tgAAAXY"]
[Tue Aug 18 12:59:07.085727 2026] [security2:error] [pid 66623:tid 66874] [client 223.185.37.47:24499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBS9O5rbWdOArH04K0tgAAAXY"]
[Tue Aug 18 12:59:07.107005 2026] [authz_core:error] [pid 66623:tid 66723] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:07.107426 2026] [authz_core:error] [pid 66623:tid 66723] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:07.119052 2026] [security2:error] [pid 66623:tid 66773] [client 20.104.85.180:27287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSBS9O5rbWdOArH04K0vQAAARE"]
[Tue Aug 18 12:59:07.122469 2026] [security2:error] [pid 66623:tid 66812] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/JawirGenk.php"] [unique_id "aoSBS9O5rbWdOArH04K0vgAAATg"]
[Tue Aug 18 12:59:07.153448 2026] [security2:error] [pid 66623:tid 66747] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBS9O5rbWdOArH04K0wAABHW4"]
[Tue Aug 18 12:59:07.153682 2026] [security2:error] [pid 66623:tid 66785] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBS9O5rbWdOArH04K0wAABHW4"]
[Tue Aug 18 12:59:07.157794 2026] [security2:error] [pid 66623:tid 66791] [client 52.173.121.69:30353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSBS9O5rbWdOArH04K0wgAAASM"]
[Tue Aug 18 12:59:07.216228 2026] [security2:error] [pid 66623:tid 66891] [client 168.62.48.100:1100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/rezor.php"] [unique_id "aoSBS9O5rbWdOArH04K0yQAAAYc"]
[Tue Aug 18 12:59:07.246363 2026] [security2:error] [pid 66623:tid 66675] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/dashboard"] [unique_id "aoSBS9O5rbWdOArH04K0ygABbCY"]
[Tue Aug 18 12:59:07.246656 2026] [security2:error] [pid 66623:tid 66754] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/info"] [unique_id "aoSBS9O5rbWdOArH04K0ywABbHU"]
[Tue Aug 18 12:59:07.248132 2026] [security2:error] [pid 66623:tid 66645] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/_health"] [unique_id "aoSBS9O5rbWdOArH04K0zQABXwg"]
[Tue Aug 18 12:59:07.299776 2026] [security2:error] [pid 66623:tid 66818] [client 74.248.18.37:25312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBS9O5rbWdOArH04K01wAAAT4"]
[Tue Aug 18 12:59:07.303839 2026] [security2:error] [pid 66623:tid 66880] [client 85.154.68.202:18593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBS9O5rbWdOArH04K02AAAAXw"]
[Tue Aug 18 12:59:07.303971 2026] [security2:error] [pid 66623:tid 66880] [client 85.154.68.202:18593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBS9O5rbWdOArH04K02AAAAXw"]
[Tue Aug 18 12:59:07.320393 2026] [security2:error] [pid 66623:tid 66867] [client 20.65.98.162:29290] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "lecarveiculospira.com.br"] [uri "/1.php"] [unique_id "aoSBS9O5rbWdOArH04K02QAAAW8"]
[Tue Aug 18 12:59:07.320502 2026] [security2:error] [pid 66623:tid 66867] [client 20.65.98.162:29290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/1.php"] [unique_id "aoSBS9O5rbWdOArH04K02QAAAW8"]
[Tue Aug 18 12:59:07.356846 2026] [security2:error] [pid 66623:tid 66794] [client 132.196.30.78:22144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/a.php"] [unique_id "aoSBS9O5rbWdOArH04K02wAAASY"]
[Tue Aug 18 12:59:07.390401 2026] [security2:error] [pid 66623:tid 66860] [client 20.25.139.174:4710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/edit-tags.php"] [unique_id "aoSBS9O5rbWdOArH04K03gAAAWg"]
[Tue Aug 18 12:59:07.406656 2026] [security2:error] [pid 66623:tid 66789] [client 4.232.151.198:5499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/num.php"] [unique_id "aoSBS9O5rbWdOArH04K04AAAASE"]
[Tue Aug 18 12:59:07.409491 2026] [authz_core:error] [pid 66623:tid 66640] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:07.409770 2026] [authz_core:error] [pid 66623:tid 66640] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:07.414799 2026] [security2:error] [pid 66623:tid 66770] [client 4.232.94.69:52543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "aoSBS9O5rbWdOArH04K04QAAAQ4"]
[Tue Aug 18 12:59:07.430810 2026] [security2:error] [pid 66623:tid 66637] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/runtime.exs"] [unique_id "aoSBS9O5rbWdOArH04K04gABWgA"]
[Tue Aug 18 12:59:07.435690 2026] [security2:error] [pid 66623:tid 66883] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/options.php"] [unique_id "aoSBS9O5rbWdOArH04K04wAAAX8"]
[Tue Aug 18 12:59:07.466106 2026] [security2:error] [pid 66623:tid 66758] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/prod.exs"] [unique_id "aoSBS9O5rbWdOArH04K06AABGHk"]
[Tue Aug 18 12:59:07.467173 2026] [security2:error] [pid 66623:tid 66835] [client 40.74.65.169:20401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBS9O5rbWdOArH04K06QAAAU8"]
[Tue Aug 18 12:59:07.512135 2026] [security2:error] [pid 66623:tid 66841] [client 213.202.253.4:58792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/userfuns.php"] [unique_id "aoSBS9O5rbWdOArH04K06wAAAVU"], referer: www.google.com
[Tue Aug 18 12:59:07.514148 2026] [security2:error] [pid 66623:tid 66826] [client 20.118.172.148:43479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/htaccess.php"] [unique_id "aoSBS9O5rbWdOArH04K07AAAAUY"]
[Tue Aug 18 12:59:07.535164 2026] [security2:error] [pid 66623:tid 66816] [client 20.203.138.185:18467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/06.php"] [unique_id "aoSBS9O5rbWdOArH04K07QAAATw"]
[Tue Aug 18 12:59:07.542937 2026] [security2:error] [pid 66623:tid 66842] [client 168.62.48.100:1115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSBS9O5rbWdOArH04K07gAAAVY"]
[Tue Aug 18 12:59:07.579527 2026] [security2:error] [pid 66623:tid 66803] [client 20.104.85.180:46773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSBS9O5rbWdOArH04K08gAAAS8"]
[Tue Aug 18 12:59:07.590549 2026] [security2:error] [pid 66623:tid 66873] [client 20.25.139.174:4701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/a.php"] [unique_id "aoSBS9O5rbWdOArH04K08wAAAXU"]
[Tue Aug 18 12:59:07.599866 2026] [security2:error] [pid 66623:tid 66843] [client 52.173.121.69:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSBS9O5rbWdOArH04K09QAAAVc"]
[Tue Aug 18 12:59:07.601241 2026] [security2:error] [pid 66623:tid 66861] [client 52.173.121.69:24786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBS9O5rbWdOArH04K09wAAAWk"]
[Tue Aug 18 12:59:07.609940 2026] [security2:error] [pid 66623:tid 66772] [client 5.161.75.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jgbdominiosolucoes.com.br"] [uri "/index.php"] [unique_id "aoSBS9O5rbWdOArH04K05gABEEA"], referer: https://jgbdominiosolucoes.com.br/
[Tue Aug 18 12:59:07.647172 2026] [security2:error] [pid 66623:tid 66868] [client 132.196.30.78:13466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/admin.php"] [unique_id "aoSBS9O5rbWdOArH04K0-QAAAXA"]
[Tue Aug 18 12:59:07.655032 2026] [security2:error] [pid 66623:tid 66827] [client 20.104.85.180:18757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSBS9O5rbWdOArH04K0-wAAAUc"]
[Tue Aug 18 12:59:07.658009 2026] [security2:error] [pid 66623:tid 66776] [client 158.23.17.4:20406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/87.php"] [unique_id "aoSBS9O5rbWdOArH04K0_AAAARQ"]
[Tue Aug 18 12:59:07.665773 2026] [security2:error] [pid 66623:tid 66824] [client 20.100.169.31:24494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/bless.php"] [unique_id "aoSBS9O5rbWdOArH04K0_QAAAUQ"]
[Tue Aug 18 12:59:07.669591 2026] [security2:error] [pid 66623:tid 66738] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/aws-exports.js"] [unique_id "aoSBS9O5rbWdOArH04K0_gABH2U"]
[Tue Aug 18 12:59:07.670004 2026] [security2:error] [pid 66623:tid 66829] [client 213.35.127.232:58914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBS9O5rbWdOArH04K0_wAAAUk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:07.710313 2026] [authz_core:error] [pid 66623:tid 66733] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:07.710582 2026] [authz_core:error] [pid 66623:tid 66733] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:07.716123 2026] [security2:error] [pid 66623:tid 66866] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSBS9O5rbWdOArH04K1AQAAAW4"]
[Tue Aug 18 12:59:07.735471 2026] [security2:error] [pid 66623:tid 66739] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/aws-config.js"] [unique_id "aoSBS9O5rbWdOArH04K1AgABQmY"]
[Tue Aug 18 12:59:07.748098 2026] [security2:error] [pid 66623:tid 66648] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/awsConfig.js"] [unique_id "aoSBS9O5rbWdOArH04K1BAABQQs"]
[Tue Aug 18 12:59:07.761183 2026] [security2:error] [pid 66623:tid 66674] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/amplifyconfiguration.json"] [unique_id "aoSBS9O5rbWdOArH04K1BQABGyU"]
[Tue Aug 18 12:59:07.765467 2026] [security2:error] [pid 66623:tid 66769] [client 172.182.200.96:14112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSBS9O5rbWdOArH04K1BgAAAQ0"]
[Tue Aug 18 12:59:07.812634 2026] [security2:error] [pid 66623:tid 66795] [client 102.213.179.104:58589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBS9O5rbWdOArH04K1BwAAASc"]
[Tue Aug 18 12:59:07.812752 2026] [security2:error] [pid 66623:tid 66795] [client 102.213.179.104:58589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBS9O5rbWdOArH04K1BwAAASc"]
[Tue Aug 18 12:59:07.830063 2026] [security2:error] [pid 66623:tid 66823] [client 168.62.48.100:1159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSBS9O5rbWdOArH04K1CgAAAUM"]
[Tue Aug 18 12:59:07.834483 2026] [security2:error] [pid 66623:tid 66653] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/values.yaml"] [unique_id "aoSBS9O5rbWdOArH04K1CwABXxA"]
[Tue Aug 18 12:59:07.838261 2026] [security2:error] [pid 66623:tid 66661] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/wp-json"] [unique_id "aoSBS9O5rbWdOArH04K1DAABHBg"]
[Tue Aug 18 12:59:07.877640 2026] [security2:error] [pid 66623:tid 66779] [client 20.25.139.174:4580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/u.php"] [unique_id "aoSBS9O5rbWdOArH04K1DgAAARc"]
[Tue Aug 18 12:59:08.000543 2026] [security2:error] [pid 66623:tid 66689] [remote 203.99.146.53:37362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stremma.com.br"] [uri "/wp-login.php"] [unique_id "aoSBS9O5rbWdOArH04K1EwABZjQ"]
[Tue Aug 18 12:59:08.002944 2026] [security2:error] [pid 66623:tid 66846] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSBTNO5rbWdOArH04K1FQAAAVo"]
[Tue Aug 18 12:59:08.035954 2026] [security2:error] [pid 66623:tid 66768] [client 74.7.228.45:57906] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "marcellomeneghel.com.br"] [uri "/robots.txt"] [unique_id "aoSBTNO5rbWdOArH04K1GQABDA8"]
[Tue Aug 18 12:59:08.060963 2026] [security2:error] [pid 66623:tid 66836] [client 20.118.172.148:53107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/images/wso.php"] [unique_id "aoSBTNO5rbWdOArH04K1HQAAAVA"]
[Tue Aug 18 12:59:08.061421 2026] [security2:error] [pid 66623:tid 66786] [client 132.196.30.78:22168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/chosen.php"] [unique_id "aoSBTNO5rbWdOArH04K1HgAAAR4"]
[Tue Aug 18 12:59:08.069087 2026] [security2:error] [pid 66623:tid 66750] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/__/firebase/init.json"] [unique_id "aoSBTNO5rbWdOArH04K1IAABRnE"]
[Tue Aug 18 12:59:08.081025 2026] [security2:error] [pid 66623:tid 66850] [client 20.25.139.174:4690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/chosen.php"] [unique_id "aoSBTNO5rbWdOArH04K1IQAAAV4"]
[Tue Aug 18 12:59:08.083582 2026] [security2:error] [pid 66623:tid 66816] [client 168.62.48.100:1101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/index/function.php"] [unique_id "aoSBTNO5rbWdOArH04K1IgAAATw"]
[Tue Aug 18 12:59:08.085346 2026] [security2:error] [pid 66623:tid 66831] [client 74.248.18.37:19264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/colors/light/wp-login.php"] [unique_id "aoSBTNO5rbWdOArH04K1JAAAAUs"]
[Tue Aug 18 12:59:08.123908 2026] [security2:error] [pid 66623:tid 66865] [client 52.173.121.69:30383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBTNO5rbWdOArH04K1KQAAAW0"]
[Tue Aug 18 12:59:08.148127 2026] [security2:error] [pid 66623:tid 66729] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config.json"] [unique_id "aoSBTNO5rbWdOArH04K1KgABZVw"]
[Tue Aug 18 12:59:08.154012 2026] [security2:error] [pid 66623:tid 66803] [client 52.173.121.69:16478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/blog/byp.php"] [unique_id "aoSBTNO5rbWdOArH04K1KwAAAS8"]
[Tue Aug 18 12:59:08.155322 2026] [security2:error] [pid 66623:tid 66873] [client 158.23.17.4:20463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/zi.php"] [unique_id "aoSBTNO5rbWdOArH04K1LAAAAXU"]
[Tue Aug 18 12:59:08.155507 2026] [security2:error] [pid 66623:tid 66843] [client 40.74.65.169:20355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/puc.php"] [unique_id "aoSBTNO5rbWdOArH04K1LQAAAVc"]
[Tue Aug 18 12:59:08.184440 2026] [security2:error] [pid 66623:tid 66673] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/config"] [unique_id "aoSBTNO5rbWdOArH04K1LgABSCQ"]
[Tue Aug 18 12:59:08.184440 2026] [security2:error] [pid 66623:tid 66685] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config.js"] [unique_id "aoSBTNO5rbWdOArH04K1LwABSDA"]
[Tue Aug 18 12:59:08.187910 2026] [security2:error] [pid 66623:tid 66772] [client 20.104.85.180:18765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBTNO5rbWdOArH04K1MAAAARA"]
[Tue Aug 18 12:59:08.192021 2026] [security2:error] [pid 66623:tid 66882] [client 132.196.30.78:14999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/goods.php"] [unique_id "aoSBTNO5rbWdOArH04K1MQAAAX4"]
[Tue Aug 18 12:59:08.196382 2026] [security2:error] [pid 66623:tid 66800] [client 68.221.73.131:39566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/mac.php"] [unique_id "aoSBTNO5rbWdOArH04K1MwAAASw"]
[Tue Aug 18 12:59:08.262644 2026] [security2:error] [pid 66623:tid 66829] [client 4.232.151.198:30038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/xmlrpc.php0"] [unique_id "aoSBTNO5rbWdOArH04K1NQAAAUk"]
[Tue Aug 18 12:59:08.266884 2026] [security2:error] [pid 66623:tid 66725] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/settings.json"] [unique_id "aoSBTNO5rbWdOArH04K1NwABZFg"]
[Tue Aug 18 12:59:08.282578 2026] [security2:error] [pid 66623:tid 66822] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/output.php"] [unique_id "aoSBTNO5rbWdOArH04K1OQAAAUI"]
[Tue Aug 18 12:59:08.319953 2026] [security2:error] [pid 66623:tid 66812] [client 20.104.85.180:54589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/file.php"] [unique_id "aoSBTNO5rbWdOArH04K1OwAAATg"]
[Tue Aug 18 12:59:08.346518 2026] [security2:error] [pid 66623:tid 66848] [client 168.62.48.100:1104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSBTNO5rbWdOArH04K1PgAAAVw"]
[Tue Aug 18 12:59:08.350415 2026] [security2:error] [pid 66623:tid 66890] [client 20.203.138.185:37310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/166.php"] [unique_id "aoSBTNO5rbWdOArH04K1PwAAAYY"]
[Tue Aug 18 12:59:08.379377 2026] [security2:error] [pid 66623:tid 66796] [client 20.25.139.174:4627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBTNO5rbWdOArH04K1QwAAASg"]
[Tue Aug 18 12:59:08.441968 2026] [security2:error] [pid 66623:tid 66732] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/settings"] [unique_id "aoSBTNO5rbWdOArH04K1ZQABN18"]
[Tue Aug 18 12:59:08.459640 2026] [security2:error] [pid 66623:tid 66698] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/v1/settings"] [unique_id "aoSBTNO5rbWdOArH04K1ZwABbz0"]
[Tue Aug 18 12:59:08.561903 2026] [security2:error] [pid 66623:tid 66768] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/tiny2.php"] [unique_id "aoSBTNO5rbWdOArH04K1dQAAAQw"]
[Tue Aug 18 12:59:08.576441 2026] [security2:error] [pid 66623:tid 66767] [client 20.25.139.174:4643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBTNO5rbWdOArH04K1dwAAAQs"]
[Tue Aug 18 12:59:08.579392 2026] [security2:error] [pid 66623:tid 66840] [client 132.196.30.78:22147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBTNO5rbWdOArH04K1eAAAAVQ"]
[Tue Aug 18 12:59:08.584962 2026] [security2:error] [pid 66623:tid 66844] [client 52.173.121.69:14566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSBTNO5rbWdOArH04K1egAAAVg"]
[Tue Aug 18 12:59:08.615949 2026] [security2:error] [pid 66623:tid 66747] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/env.js"] [unique_id "aoSBTNO5rbWdOArH04K1ewABdm4"]
[Tue Aug 18 12:59:08.625528 2026] [authz_core:error] [pid 66623:tid 66764] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:08.625830 2026] [authz_core:error] [pid 66623:tid 66764] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:08.632747 2026] [security2:error] [pid 66623:tid 66649] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/firebase-config.json"] [unique_id "aoSBTNO5rbWdOArH04K1fgABXQw"]
[Tue Aug 18 12:59:08.635397 2026] [security2:error] [pid 66623:tid 66677] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/env.json"] [unique_id "aoSBTNO5rbWdOArH04K1fwABbSg"]
[Tue Aug 18 12:59:08.649399 2026] [security2:error] [pid 66623:tid 66832] [client 20.118.172.148:63075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/index/function.php"] [unique_id "aoSBTNO5rbWdOArH04K1gQAAAUw"]
[Tue Aug 18 12:59:08.658125 2026] [security2:error] [pid 66623:tid 66675] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.well-known/jwks.json"] [unique_id "aoSBTNO5rbWdOArH04K1gwABWyY"]
[Tue Aug 18 12:59:08.686895 2026] [security2:error] [pid 66623:tid 66785] [client 213.35.127.232:59139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBTNO5rbWdOArH04K1hQAAAR0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:08.707775 2026] [security2:error] [pid 66623:tid 66781] [client 168.62.48.100:1026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/Cachex.php"] [unique_id "aoSBTNO5rbWdOArH04K1iAAAARk"]
[Tue Aug 18 12:59:08.737393 2026] [security2:error] [pid 66623:tid 66893] [client 132.196.30.78:14603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/file.php"] [unique_id "aoSBTNO5rbWdOArH04K1igAAAYk"]
[Tue Aug 18 12:59:08.744440 2026] [security2:error] [pid 66623:tid 66716] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/v2/config"] [unique_id "aoSBTNO5rbWdOArH04K1jAABOU8"]
[Tue Aug 18 12:59:08.761893 2026] [security2:error] [pid 66623:tid 66752] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/v1/config"] [unique_id "aoSBTNO5rbWdOArH04K1jQABRHM"]
[Tue Aug 18 12:59:08.798571 2026] [security2:error] [pid 66623:tid 66839] [client 47.128.99.181:65228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitepaintball.com.br"] [uri "/robots.txt"] [unique_id "aoSBTNO5rbWdOArH04K1jgAAAVM"]
[Tue Aug 18 12:59:08.851327 2026] [security2:error] [pid 66623:tid 66810] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wpxml.php"] [unique_id "aoSBTNO5rbWdOArH04K1lQAAATY"]
[Tue Aug 18 12:59:08.859454 2026] [security2:error] [pid 66623:tid 66821] [client 52.173.121.69:17951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBTNO5rbWdOArH04K1lgAAAUE"]
[Tue Aug 18 12:59:08.899363 2026] [security2:error] [pid 66623:tid 66873] [client 4.232.151.198:58717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/maint/item.php"] [unique_id "aoSBTNO5rbWdOArH04K1mAAAAXU"]
[Tue Aug 18 12:59:08.901505 2026] [security2:error] [pid 66623:tid 66735] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/env"] [unique_id "aoSBTNO5rbWdOArH04K1mQABNGI"]
[Tue Aug 18 12:59:08.903214 2026] [security2:error] [pid 66623:tid 66726] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/runtime-config.js"] [unique_id "aoSBTNO5rbWdOArH04K1mgABG1k"]
[Tue Aug 18 12:59:08.909015 2026] [security2:error] [pid 66623:tid 66705] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/v2/settings"] [unique_id "aoSBTNO5rbWdOArH04K1mwABDUQ"]
[Tue Aug 18 12:59:08.917778 2026] [security2:error] [pid 66623:tid 66802] [client 20.25.139.174:4621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/h.php"] [unique_id "aoSBTNO5rbWdOArH04K1nAAAAS4"]
[Tue Aug 18 12:59:08.926839 2026] [authz_core:error] [pid 66623:tid 66687] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:08.927090 2026] [authz_core:error] [pid 66623:tid 66687] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:08.940579 2026] [security2:error] [pid 66623:tid 66745] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/manifest.webmanifest"] [unique_id "aoSBTNO5rbWdOArH04K1oAABY2w"]
[Tue Aug 18 12:59:08.970080 2026] [security2:error] [pid 66623:tid 66843] [client 4.232.94.69:20784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/radio.php"] [unique_id "aoSBTNO5rbWdOArH04K1owAAAVc"]
[Tue Aug 18 12:59:08.986027 2026] [security2:error] [pid 66623:tid 66829] [client 79.127.164.8:41498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/sql.sql"] [unique_id "aoSBTNO5rbWdOArH04K1rwAAAUk"], referer: https://medihub.com.br/sql.sql
[Tue Aug 18 12:59:08.995080 2026] [security2:error] [pid 66623:tid 66809] [client 172.202.39.151:4717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/about.php"] [unique_id "aoSBTNO5rbWdOArH04K1sAAAATU"]
[Tue Aug 18 12:59:09.017612 2026] [security2:error] [pid 66623:tid 66743] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/openapi.json"] [unique_id "aoSBTdO5rbWdOArH04K1swABg2o"]
[Tue Aug 18 12:59:09.018250 2026] [autoindex:error] [pid 66623:tid 66838] [client 3.210.118.109:55408] AH01276: Cannot serve directory /home1/agencialkx/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:09.026763 2026] [security2:error] [pid 66623:tid 66674] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/openapi.json"] [unique_id "aoSBTdO5rbWdOArH04K1tQABeSU"]
[Tue Aug 18 12:59:09.035870 2026] [security2:error] [pid 66623:tid 66868] [client 20.100.169.31:15204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/sagax1.php"] [unique_id "aoSBTdO5rbWdOArH04K1tgAAAXA"]
[Tue Aug 18 12:59:09.039876 2026] [security2:error] [pid 66623:tid 66798] [client 20.104.85.180:54545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/epinyins.php"] [unique_id "aoSBTdO5rbWdOArH04K1twAAASo"]
[Tue Aug 18 12:59:09.047387 2026] [security2:error] [pid 66623:tid 66867] [client 52.173.121.69:42719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSBTdO5rbWdOArH04K1uAAAAW8"]
[Tue Aug 18 12:59:09.059314 2026] [security2:error] [pid 66623:tid 66833] [client 168.62.48.100:1028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSBTdO5rbWdOArH04K1uQAAAU0"]
[Tue Aug 18 12:59:09.082484 2026] [security2:error] [pid 66623:tid 66892] [client 172.202.39.151:44562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/cc.php"] [unique_id "aoSBTdO5rbWdOArH04K1uwAAAYg"]
[Tue Aug 18 12:59:09.097088 2026] [security2:error] [pid 66623:tid 66805] [client 20.104.85.180:1361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/abc.php"] [unique_id "aoSBTdO5rbWdOArH04K1vAAAATE"]
[Tue Aug 18 12:59:09.139049 2026] [security2:error] [pid 66623:tid 66789] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSBTdO5rbWdOArH04K1wgAAASE"]
[Tue Aug 18 12:59:09.143149 2026] [security2:error] [pid 66623:tid 66788] [client 132.196.30.78:14991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/vx.php"] [unique_id "aoSBTdO5rbWdOArH04K1wwAAASA"]
[Tue Aug 18 12:59:09.176255 2026] [security2:error] [pid 66623:tid 66768] [client 20.203.138.185:15729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/snq.php"] [unique_id "aoSBTdO5rbWdOArH04K1xQAAAQw"]
[Tue Aug 18 12:59:09.187894 2026] [security2:error] [pid 66623:tid 66823] [client 20.25.139.174:4576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/vx.php"] [unique_id "aoSBTdO5rbWdOArH04K1yAAAAUM"]
[Tue Aug 18 12:59:09.230832 2026] [security2:error] [pid 66623:tid 66778] [client 20.215.241.237:65244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/aa.php"] [unique_id "aoSBTdO5rbWdOArH04K1zwAAARY"]
[Tue Aug 18 12:59:09.234233 2026] [security2:error] [pid 66623:tid 66652] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/app-config.json"] [unique_id "aoSBTdO5rbWdOArH04K10AABdg8"]
[Tue Aug 18 12:59:09.234536 2026] [authz_core:error] [pid 66623:tid 66699] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:09.234804 2026] [authz_core:error] [pid 66623:tid 66699] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:09.249030 2026] [security2:error] [pid 66623:tid 66707] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/account"] [unique_id "aoSBTdO5rbWdOArH04K10QABWUY"]
[Tue Aug 18 12:59:09.267329 2026] [security2:error] [pid 66623:tid 66750] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/health"] [unique_id "aoSBTdO5rbWdOArH04K10gABTHE"]
[Tue Aug 18 12:59:09.303026 2026] [security2:error] [pid 66623:tid 66794] [client 168.62.48.100:1114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-2019.php"] [unique_id "aoSBTdO5rbWdOArH04K11gAAASY"]
[Tue Aug 18 12:59:09.306805 2026] [security2:error] [pid 66623:tid 66880] [client 132.196.30.78:15016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBTdO5rbWdOArH04K11wAAAXw"]
[Tue Aug 18 12:59:09.310002 2026] [security2:error] [pid 66623:tid 66659] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/health"] [unique_id "aoSBTdO5rbWdOArH04K12AABLxY"]
[Tue Aug 18 12:59:09.365751 2026] [security2:error] [pid 66623:tid 66759] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/swagger.json"] [unique_id "aoSBTdO5rbWdOArH04K12gABMno"]
[Tue Aug 18 12:59:09.381411 2026] [security2:error] [pid 66623:tid 66685] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/__env.js"] [unique_id "aoSBTdO5rbWdOArH04K12wABLDA"]
[Tue Aug 18 12:59:09.407635 2026] [security2:error] [pid 66623:tid 66865] [client 20.25.139.174:4644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBTdO5rbWdOArH04K13gAAAW0"]
[Tue Aug 18 12:59:09.438009 2026] [security2:error] [pid 66623:tid 66886] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/ccou.php"] [unique_id "aoSBTdO5rbWdOArH04K14AAAAYI"]
[Tue Aug 18 12:59:09.472792 2026] [security2:error] [pid 66623:tid 66856] [client 20.65.98.162:32258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/coffee.php"] [unique_id "aoSBTdO5rbWdOArH04K14gAAAWQ"]
[Tue Aug 18 12:59:09.485183 2026] [security2:error] [pid 66623:tid 66842] [client 74.248.18.37:32101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBTdO5rbWdOArH04K15AAAAVY"]
[Tue Aug 18 12:59:09.513268 2026] [security2:error] [pid 66623:tid 66853] [client 40.74.65.169:20117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/8.php"] [unique_id "aoSBTdO5rbWdOArH04K15gAAAWE"]
[Tue Aug 18 12:59:09.521685 2026] [security2:error] [pid 66623:tid 66810] [client 52.173.121.69:39251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBTdO5rbWdOArH04K15wAAATY"]
[Tue Aug 18 12:59:09.583604 2026] [security2:error] [pid 66623:tid 66777] [client 168.62.48.100:1110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSBTdO5rbWdOArH04K16wAAARU"]
[Tue Aug 18 12:59:09.592214 2026] [security2:error] [pid 66623:tid 66890] [client 52.173.121.69:24772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBTdO5rbWdOArH04K17AAAAYY"]
[Tue Aug 18 12:59:09.671176 2026] [security2:error] [pid 66623:tid 66850] [client 158.23.17.4:25348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/92.php"] [unique_id "aoSBTdO5rbWdOArH04K18QAAAV4"]
[Tue Aug 18 12:59:09.674822 2026] [security2:error] [pid 66623:tid 66851] [client 172.182.200.96:14122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSBTdO5rbWdOArH04K18gAAAV8"]
[Tue Aug 18 12:59:09.695841 2026] [security2:error] [pid 66623:tid 66784] [client 20.118.172.148:2740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/info.php"] [unique_id "aoSBTdO5rbWdOArH04K18wAAARw"]
[Tue Aug 18 12:59:09.703950 2026] [security2:error] [pid 66623:tid 66828] [client 213.35.127.232:59358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBTdO5rbWdOArH04K19AAAAUg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:09.720831 2026] [security2:error] [pid 66623:tid 66811] [client 20.104.85.180:14534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/akcc.php"] [unique_id "aoSBTdO5rbWdOArH04K19QAAATc"]
[Tue Aug 18 12:59:09.725875 2026] [security2:error] [pid 66623:tid 66790] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/crgio.php"] [unique_id "aoSBTdO5rbWdOArH04K1-AAAASI"]
[Tue Aug 18 12:59:09.761191 2026] [security2:error] [pid 66623:tid 66814] [client 20.104.85.180:13600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBTdO5rbWdOArH04K1-wAAATo"]
[Tue Aug 18 12:59:09.836005 2026] [authz_core:error] [pid 66623:tid 66681] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:09.836263 2026] [authz_core:error] [pid 66623:tid 66681] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:09.874981 2026] [security2:error] [pid 66623:tid 66885] [client 20.250.13.23:36119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/min.php"] [unique_id "aoSBTdO5rbWdOArH04K2AQAAAYE"]
[Tue Aug 18 12:59:09.882188 2026] [autoindex:error] [pid 66623:tid 66639] [remote 20.65.98.162:0] AH01276: Cannot serve directory /home4/tecpolo/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:09.904599 2026] [security2:error] [pid 66623:tid 66788] [client 168.62.48.100:1182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/.cache/x.php"] [unique_id "aoSBTdO5rbWdOArH04K2AwAAASA"]
[Tue Aug 18 12:59:09.949831 2026] [security2:error] [pid 66623:tid 66867] [client 20.25.139.174:4711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/a7.php"] [unique_id "aoSBTdO5rbWdOArH04K2BQAAAW8"]
[Tue Aug 18 12:59:09.955754 2026] [security2:error] [pid 66623:tid 66798] [client 132.196.30.78:13672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/404.php"] [unique_id "aoSBTdO5rbWdOArH04K2BgAAASo"]
[Tue Aug 18 12:59:09.969322 2026] [security2:error] [pid 66623:tid 66780] [client 52.173.121.69:47308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/update/wpupex.php"] [unique_id "aoSBTdO5rbWdOArH04K2CAAAARg"]
[Tue Aug 18 12:59:10.012517 2026] [security2:error] [pid 66623:tid 66796] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSBTtO5rbWdOArH04K2CgAAASg"]
[Tue Aug 18 12:59:10.016937 2026] [security2:error] [pid 66623:tid 66826] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/php.php"] [unique_id "aoSBTtO5rbWdOArH04K2CwAAAUY"]
[Tue Aug 18 12:59:10.111917 2026] [security2:error] [pid 66623:tid 66849] [client 52.173.121.69:6062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/images/security.php"] [unique_id "aoSBTtO5rbWdOArH04K2DwAAAV0"]
[Tue Aug 18 12:59:10.136038 2026] [authz_core:error] [pid 66623:tid 66748] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:10.136290 2026] [authz_core:error] [pid 66623:tid 66748] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:10.140445 2026] [security2:error] [pid 66623:tid 66768] [client 74.248.18.37:25299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/data.php"] [unique_id "aoSBTtO5rbWdOArH04K2EgAAAQw"]
[Tue Aug 18 12:59:10.175546 2026] [security2:error] [pid 66623:tid 66857] [client 20.203.138.185:25479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-access.php"] [unique_id "aoSBTtO5rbWdOArH04K2EwAAAWU"]
[Tue Aug 18 12:59:10.204329 2026] [security2:error] [pid 66623:tid 66880] [client 40.74.65.169:38789] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "maisautoveiculo.com.br"] [uri "/1.php"] [unique_id "aoSBTtO5rbWdOArH04K2FAAAAXw"]
[Tue Aug 18 12:59:10.204457 2026] [security2:error] [pid 66623:tid 66880] [client 40.74.65.169:38789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/1.php"] [unique_id "aoSBTtO5rbWdOArH04K2FAAAAXw"]
[Tue Aug 18 12:59:10.220107 2026] [security2:error] [pid 66623:tid 66785] [client 168.62.48.100:1118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSBTtO5rbWdOArH04K2FgAAAR0"]
[Tue Aug 18 12:59:10.270751 2026] [security2:error] [pid 66623:tid 66806] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/sf.php"] [unique_id "aoSBTtO5rbWdOArH04K2GAAAATI"]
[Tue Aug 18 12:59:10.280201 2026] [security2:error] [pid 66623:tid 66889] [client 158.23.17.4:14045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/jm.php"] [unique_id "aoSBTtO5rbWdOArH04K2GQAAAYU"]
[Tue Aug 18 12:59:10.328468 2026] [security2:error] [pid 66623:tid 66772] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/css.php"] [unique_id "aoSBTtO5rbWdOArH04K2HAAAARA"]
[Tue Aug 18 12:59:10.329408 2026] [security2:error] [pid 66623:tid 66813] [client 20.118.172.148:46757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/profile.php"] [unique_id "aoSBTtO5rbWdOArH04K2HQAAATk"]
[Tue Aug 18 12:59:10.373540 2026] [security2:error] [pid 66623:tid 66875] [client 52.173.121.69:50178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-admin/install.php"] [unique_id "aoSBTtO5rbWdOArH04K2HwAAAXc"]
[Tue Aug 18 12:59:10.409379 2026] [security2:error] [pid 66623:tid 66797] [client 20.104.85.180:28656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wk/index.php"] [unique_id "aoSBTtO5rbWdOArH04K2IwAAASk"]
[Tue Aug 18 12:59:10.498262 2026] [security2:error] [pid 66623:tid 66821] [client 168.62.48.100:1109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBTtO5rbWdOArH04K2KwAAAUE"]
[Tue Aug 18 12:59:10.501750 2026] [security2:error] [pid 66623:tid 66766] [client 4.232.94.69:37504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSBTtO5rbWdOArH04K2LAAAAQo"]
[Tue Aug 18 12:59:10.522808 2026] [security2:error] [pid 66623:tid 66769] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/xx.php"] [unique_id "aoSBTtO5rbWdOArH04K2LQAAAQ0"]
[Tue Aug 18 12:59:10.531065 2026] [security2:error] [pid 66623:tid 66859] [client 172.202.39.151:4732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBTtO5rbWdOArH04K2LgAAAWc"]
[Tue Aug 18 12:59:10.544857 2026] [security2:error] [pid 66623:tid 66776] [client 20.25.139.174:4551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/manager.php"] [unique_id "aoSBTtO5rbWdOArH04K2MAAAARQ"]
[Tue Aug 18 12:59:10.615338 2026] [security2:error] [pid 66623:tid 66871] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBTtO5rbWdOArH04K2MgAAAXM"]
[Tue Aug 18 12:59:10.704473 2026] [security2:error] [pid 66623:tid 66884] [client 132.196.30.78:13688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wk/index.php"] [unique_id "aoSBTtO5rbWdOArH04K2NgAAAYA"]
[Tue Aug 18 12:59:10.718706 2026] [security2:error] [pid 66623:tid 66787] [client 213.35.127.232:59569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBTtO5rbWdOArH04K2OAAAAR8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:10.772533 2026] [security2:error] [pid 66623:tid 66861] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/uwu.php"] [unique_id "aoSBTtO5rbWdOArH04K2OgAAAWk"]
[Tue Aug 18 12:59:10.816898 2026] [security2:error] [pid 66623:tid 66801] [client 172.182.200.96:14118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBTtO5rbWdOArH04K2OwAAAS0"]
[Tue Aug 18 12:59:10.825653 2026] [security2:error] [pid 66623:tid 66881] [client 74.248.18.37:19298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/disagrsxr.php"] [unique_id "aoSBTtO5rbWdOArH04K2PAAAAX0"]
[Tue Aug 18 12:59:10.856655 2026] [security2:error] [pid 66623:tid 66789] [client 52.173.121.69:48315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBTtO5rbWdOArH04K2QAAAASE"]
[Tue Aug 18 12:59:10.873425 2026] [security2:error] [pid 66623:tid 66870] [client 132.196.30.78:20391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wap.php"] [unique_id "aoSBTtO5rbWdOArH04K2QwAAAXI"]
[Tue Aug 18 12:59:10.884307 2026] [security2:error] [pid 66623:tid 66786] [client 45.131.195.97:22149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.195.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alltimeadm.com.br"] [uri "/wp-login.php"] [unique_id "aoSBTtO5rbWdOArH04K2NwAAAR4"]
[Tue Aug 18 12:59:10.888259 2026] [security2:error] [pid 66623:tid 66788] [client 40.74.65.169:20411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/about.php"] [unique_id "aoSBTtO5rbWdOArH04K2RAAAASA"]
[Tue Aug 18 12:59:10.900441 2026] [security2:error] [pid 66623:tid 66869] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/epinyins.php"] [unique_id "aoSBTtO5rbWdOArH04K2RgAAAXE"]
[Tue Aug 18 12:59:10.906067 2026] [security2:error] [pid 66623:tid 66780] [client 20.25.139.174:4579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wap.php"] [unique_id "aoSBTtO5rbWdOArH04K2SAAAARg"]
[Tue Aug 18 12:59:10.925954 2026] [security2:error] [pid 66623:tid 66891] [client 168.62.48.100:1197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBTtO5rbWdOArH04K2SQAAAYc"]
[Tue Aug 18 12:59:10.972541 2026] [security2:error] [pid 66623:tid 66778] [client 20.203.138.185:15691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/nw.php"] [unique_id "aoSBTtO5rbWdOArH04K2SwAAARY"]
[Tue Aug 18 12:59:11.029152 2026] [security2:error] [pid 66623:tid 66812] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/signon.php"] [unique_id "aoSBT9O5rbWdOArH04K2TQAAATg"]
[Tue Aug 18 12:59:11.037012 2026] [authz_core:error] [pid 66623:tid 66732] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:11.037268 2026] [authz_core:error] [pid 66623:tid 66732] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:11.048125 2026] [security2:error] [pid 66623:tid 66830] [client 196.12.128.158:61617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBT9O5rbWdOArH04K2TwAAAUo"]
[Tue Aug 18 12:59:11.048279 2026] [security2:error] [pid 66623:tid 66830] [client 196.12.128.158:61617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBT9O5rbWdOArH04K2TwAAAUo"]
[Tue Aug 18 12:59:11.148742 2026] [security2:error] [pid 66623:tid 66826] [client 20.25.139.174:4557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/w1.php"] [unique_id "aoSBT9O5rbWdOArH04K2VgAAAUY"]
[Tue Aug 18 12:59:11.172090 2026] [security2:error] [pid 66623:tid 66824] [client 20.118.172.148:43489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/sx.php"] [unique_id "aoSBT9O5rbWdOArH04K2VwAAAUQ"]
[Tue Aug 18 12:59:11.205336 2026] [security2:error] [pid 66623:tid 66779] [client 172.182.200.96:14109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSBT9O5rbWdOArH04K2WQAAARc"]
[Tue Aug 18 12:59:11.258025 2026] [security2:error] [pid 66623:tid 66810] [client 168.62.48.100:1194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSBT9O5rbWdOArH04K2XQAAATY"]
[Tue Aug 18 12:59:11.296685 2026] [security2:error] [pid 66623:tid 66821] [client 20.104.85.180:28634] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/1.php"] [unique_id "aoSBT9O5rbWdOArH04K2XgAAAUE"]
[Tue Aug 18 12:59:11.296760 2026] [security2:error] [pid 66623:tid 66766] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/file61.php"] [unique_id "aoSBT9O5rbWdOArH04K2XwAAAQo"]
[Tue Aug 18 12:59:11.296788 2026] [security2:error] [pid 66623:tid 66821] [client 20.104.85.180:28634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/1.php"] [unique_id "aoSBT9O5rbWdOArH04K2XgAAAUE"]
[Tue Aug 18 12:59:11.312456 2026] [security2:error] [pid 66623:tid 66769] [client 158.23.17.4:7193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/wj.php"] [unique_id "aoSBT9O5rbWdOArH04K2YQAAAQ0"]
[Tue Aug 18 12:59:11.323191 2026] [security2:error] [pid 66623:tid 66859] [client 52.173.121.69:48270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBT9O5rbWdOArH04K2YwAAAWc"]
[Tue Aug 18 12:59:11.339894 2026] [security2:error] [pid 66623:tid 66777] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/load.php"] [unique_id "aoSBT9O5rbWdOArH04K2ZgAAARU"]
[Tue Aug 18 12:59:11.340272 2026] [authz_core:error] [pid 66623:tid 66709] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:11.340651 2026] [authz_core:error] [pid 66623:tid 66709] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:11.378501 2026] [security2:error] [pid 66623:tid 66813] [client 132.196.30.78:21967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/about.php"] [unique_id "aoSBT9O5rbWdOArH04K2aQAAATk"]
[Tue Aug 18 12:59:11.399180 2026] [security2:error] [pid 66623:tid 66819] [client 20.25.139.174:4665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSBT9O5rbWdOArH04K2bAAAAT8"]
[Tue Aug 18 12:59:11.436895 2026] [security2:error] [pid 66623:tid 66846] [client 197.184.64.235:41948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBT9O5rbWdOArH04K2bgAAAVo"]
[Tue Aug 18 12:59:11.437035 2026] [security2:error] [pid 66623:tid 66846] [client 197.184.64.235:41948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBT9O5rbWdOArH04K2bgAAAVo"]
[Tue Aug 18 12:59:11.491072 2026] [security2:error] [pid 66623:tid 66856] [client 132.196.30.78:13691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSBT9O5rbWdOArH04K2cQAAAWQ"]
[Tue Aug 18 12:59:11.491097 2026] [security2:error] [pid 66623:tid 66817] [client 74.248.18.37:25341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/dropdown.php"] [unique_id "aoSBT9O5rbWdOArH04K2cgAAAT0"]
[Tue Aug 18 12:59:11.546849 2026] [security2:error] [pid 66623:tid 66805] [client 20.104.85.180:46761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSBT9O5rbWdOArH04K2dAAAATE"]
[Tue Aug 18 12:59:11.561117 2026] [security2:error] [pid 66623:tid 66771] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/copypaths.php"] [unique_id "aoSBT9O5rbWdOArH04K2dQAAAQ8"]
[Tue Aug 18 12:59:11.597238 2026] [security2:error] [pid 66623:tid 66788] [client 40.74.65.169:19508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/admin.php"] [unique_id "aoSBT9O5rbWdOArH04K2eAAAASA"]
[Tue Aug 18 12:59:11.601496 2026] [security2:error] [pid 66623:tid 66867] [client 66.187.6.102:57610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/.env"] [unique_id "aoSBT9O5rbWdOArH04K2eQAAAW8"]
[Tue Aug 18 12:59:11.616043 2026] [security2:error] [pid 66623:tid 66798] [client 172.182.200.96:7642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSBT9O5rbWdOArH04K2egAAASo"]
[Tue Aug 18 12:59:11.631033 2026] [security2:error] [pid 66623:tid 66780] [client 168.62.48.100:1090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSBT9O5rbWdOArH04K2ewAAARg"]
[Tue Aug 18 12:59:11.641574 2026] [authz_core:error] [pid 66623:tid 66640] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:11.641915 2026] [authz_core:error] [pid 66623:tid 66640] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:11.642511 2026] [security2:error] [pid 66623:tid 66811] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSBT9O5rbWdOArH04K2fQAAATc"]
[Tue Aug 18 12:59:11.658955 2026] [security2:error] [pid 66623:tid 66770] [client 52.173.121.69:14571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBT9O5rbWdOArH04K2fwAAAQ4"]
[Tue Aug 18 12:59:11.673499 2026] [security2:error] [pid 66623:tid 66778] [client 20.203.138.185:18305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ws62.php"] [unique_id "aoSBT9O5rbWdOArH04K2gwAAARY"]
[Tue Aug 18 12:59:11.713602 2026] [security2:error] [pid 66623:tid 66849] [client 172.202.39.151:4428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/f35.php"] [unique_id "aoSBT9O5rbWdOArH04K2hAAAAV0"]
[Tue Aug 18 12:59:11.733858 2026] [security2:error] [pid 66623:tid 66809] [client 213.35.127.232:59800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBT9O5rbWdOArH04K2iAAAATU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:11.797326 2026] [security2:error] [pid 66623:tid 66773] [client 20.100.169.31:39058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wpc.php"] [unique_id "aoSBT9O5rbWdOArH04K2iwAAARE"]
[Tue Aug 18 12:59:11.841153 2026] [security2:error] [pid 66623:tid 66785] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/bless6.php"] [unique_id "aoSBT9O5rbWdOArH04K2jQAAAR0"]
[Tue Aug 18 12:59:11.852424 2026] [security2:error] [pid 66623:tid 66835] [client 157.51.166.53:55417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBT9O5rbWdOArH04K2jwAAAU8"]
[Tue Aug 18 12:59:11.852523 2026] [security2:error] [pid 66623:tid 66835] [client 157.51.166.53:55417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBT9O5rbWdOArH04K2jwAAAU8"]
[Tue Aug 18 12:59:11.877196 2026] [security2:error] [pid 66623:tid 66827] [client 20.65.98.162:23494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBT9O5rbWdOArH04K2kAAAAUc"]
[Tue Aug 18 12:59:11.898709 2026] [security2:error] [pid 66623:tid 66875] [client 158.23.17.4:20368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/74.php"] [unique_id "aoSBT9O5rbWdOArH04K2kgAAAXc"]
[Tue Aug 18 12:59:11.903868 2026] [security2:error] [pid 66623:tid 66854] [client 20.25.139.174:4638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/bgymj.php"] [unique_id "aoSBT9O5rbWdOArH04K2kwAAAWI"]
[Tue Aug 18 12:59:11.929240 2026] [security2:error] [pid 66623:tid 66839] [client 66.187.6.102:57610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/.env.bak"] [unique_id "aoSBT9O5rbWdOArH04K2lQAAAVM"]
[Tue Aug 18 12:59:11.944582 2026] [authz_core:error] [pid 66623:tid 66677] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:11.945053 2026] [authz_core:error] [pid 66623:tid 66677] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:11.954144 2026] [security2:error] [pid 66623:tid 66824] [client 192.141.172.134:53131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBT9O5rbWdOArH04K2mQAAAUQ"]
[Tue Aug 18 12:59:11.955855 2026] [security2:error] [pid 66623:tid 66824] [client 192.141.172.134:53131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBT9O5rbWdOArH04K2mQAAAUQ"]
[Tue Aug 18 12:59:11.977520 2026] [security2:error] [pid 66623:tid 66783] [client 168.62.48.100:1117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBT9O5rbWdOArH04K2mwAAARs"]
[Tue Aug 18 12:59:12.045795 2026] [security2:error] [pid 66623:tid 66840] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/ty.php"] [unique_id "aoSBUNO5rbWdOArH04K2oAAAAVQ"]
[Tue Aug 18 12:59:12.099752 2026] [security2:error] [pid 66623:tid 66813] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/special.php"] [unique_id "aoSBUNO5rbWdOArH04K2oQAAATk"]
[Tue Aug 18 12:59:12.104573 2026] [security2:error] [pid 66623:tid 66851] [client 52.173.121.69:49002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/well-known/index.php"] [unique_id "aoSBUNO5rbWdOArH04K2ogAAAV8"]
[Tue Aug 18 12:59:12.137164 2026] [security2:error] [pid 66623:tid 66828] [client 66.187.6.102:57610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/.env.backup"] [unique_id "aoSBUNO5rbWdOArH04K2pgAAAUg"]
[Tue Aug 18 12:59:12.141918 2026] [security2:error] [pid 66623:tid 66772] [client 132.196.30.78:13645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/bgymj.php"] [unique_id "aoSBUNO5rbWdOArH04K2pwAAARA"]
[Tue Aug 18 12:59:12.152197 2026] [security2:error] [pid 66623:tid 66846] [client 20.104.85.180:19733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSBUNO5rbWdOArH04K2qQAAAVo"]
[Tue Aug 18 12:59:12.210059 2026] [security2:error] [pid 66623:tid 66794] [client 132.196.30.78:15028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/term.php"] [unique_id "aoSBUNO5rbWdOArH04K2rAAAASY"]
[Tue Aug 18 12:59:12.242937 2026] [authz_core:error] [pid 66623:tid 66722] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:12.243192 2026] [authz_core:error] [pid 66623:tid 66722] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:12.253038 2026] [security2:error] [pid 66623:tid 66817] [client 168.62.48.100:1044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSBUNO5rbWdOArH04K2rgAAAT0"]
[Tue Aug 18 12:59:12.317014 2026] [security2:error] [pid 66623:tid 66819] [client 20.25.139.174:4663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-login.php"] [unique_id "aoSBUNO5rbWdOArH04K2rwAAAT8"]
[Tue Aug 18 12:59:12.973024 2026] [security2:error] [pid 66623:tid 66871] [client 4.232.94.69:36320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBUNO5rbWdOArH04K2swAAAXM"]
[Tue Aug 18 12:59:13.047266 2026] [http2:info] [pid 123784:tid 123784] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Aug 18 12:59:13.069381 2026] [security2:error] [pid 123784:tid 123918] [client 40.74.65.169:43061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/edit.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcBwAAAAA"]
[Tue Aug 18 12:59:13.070421 2026] [security2:error] [pid 123784:tid 123920] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcCAAAAAI"]
[Tue Aug 18 12:59:13.070833 2026] [security2:error] [pid 123784:tid 123922] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/fz.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcCQAAAAQ"]
[Tue Aug 18 12:59:13.071491 2026] [security2:error] [pid 123784:tid 123924] [client 158.23.17.4:15790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/av.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcCgAAAAY"]
[Tue Aug 18 12:59:13.071953 2026] [security2:error] [pid 123784:tid 123928] [client 168.62.48.100:1269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcCwAAAAo"]
[Tue Aug 18 12:59:13.072964 2026] [security2:error] [pid 123784:tid 123930] [client 172.202.39.151:44593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcDAAAAAw"]
[Tue Aug 18 12:59:13.073335 2026] [security2:error] [pid 123784:tid 123927] [client 52.173.121.69:50282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcDQAAAAk"]
[Tue Aug 18 12:59:13.073345 2026] [security2:error] [pid 123784:tid 123932] [client 20.104.85.180:35893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcDgAAAA4"]
[Tue Aug 18 12:59:13.073624 2026] [security2:error] [pid 123784:tid 123934] [client 20.203.138.185:15472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/public/vx.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcDwAAABA"]
[Tue Aug 18 12:59:13.172170 2026] [security2:error] [pid 123784:tid 123960] [client 20.104.85.180:52582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcFAAAACo"]
[Tue Aug 18 12:59:13.227911 2026] [security2:error] [pid 123784:tid 123946] [client 132.196.30.78:13670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcJAAAABw"]
[Tue Aug 18 12:59:13.232425 2026] [security2:error] [pid 123784:tid 123937] [client 132.196.30.78:13636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/aa.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcJgAAABM"]
[Tue Aug 18 12:59:13.271478 2026] [security2:error] [pid 123784:tid 123926] [client 20.25.139.174:4591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/aa.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcJwAAAAg"]
[Tue Aug 18 12:59:13.278155 2026] [security2:error] [pid 123784:tid 123945] [client 20.25.139.174:4683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/default.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcKQAAABs"]
[Tue Aug 18 12:59:13.323401 2026] [security2:error] [pid 123784:tid 123948] [client 74.248.18.37:25305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/images/about.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcKwAAAB4"]
[Tue Aug 18 12:59:13.374010 2026] [security2:error] [pid 123784:tid 123984] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/dot.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcMAAAAEI"]
[Tue Aug 18 12:59:13.375088 2026] [security2:error] [pid 123784:tid 123985] [client 172.182.200.96:7578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcMwAAAEM"]
[Tue Aug 18 12:59:13.376826 2026] [security2:error] [pid 123784:tid 123986] [client 168.62.48.100:1169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcNAAAAEQ"]
[Tue Aug 18 12:59:13.377981 2026] [security2:error] [pid 123784:tid 123988] [client 52.173.121.69:12218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcNQAAAEY"]
[Tue Aug 18 12:59:13.395576 2026] [security2:error] [pid 123784:tid 123994] [client 20.215.241.237:62908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/img.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcNwAAAEw"]
[Tue Aug 18 12:59:13.415305 2026] [security2:error] [pid 123784:tid 123933] [client 213.35.127.232:60048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcOwAAAA8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:13.424493 2026] [security2:error] [pid 123784:tid 123935] [client 20.100.169.31:25978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/fone1.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcPgAAABE"]
[Tue Aug 18 12:59:13.424944 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:13.425365 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:13.428855 2026] [authz_core:error] [pid 123784:tid 123815] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:13.429245 2026] [authz_core:error] [pid 123784:tid 123815] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:13.473017 2026] [security2:error] [pid 123784:tid 123935] [client 192.141.172.134:53376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcQgAAABE"]
[Tue Aug 18 12:59:13.473189 2026] [security2:error] [pid 123784:tid 123935] [client 192.141.172.134:53376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcQgAAABE"]
[Tue Aug 18 12:59:13.525102 2026] [authz_core:error] [pid 123784:tid 123794] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:13.525561 2026] [authz_core:error] [pid 123784:tid 123794] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:13.529995 2026] [security2:error] [pid 123784:tid 123943] [client 86.120.159.145:10515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcSwAAABk"]
[Tue Aug 18 12:59:13.530192 2026] [security2:error] [pid 123784:tid 123943] [client 86.120.159.145:10515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcSwAAABk"]
[Tue Aug 18 12:59:13.571733 2026] [security2:error] [pid 123784:tid 124036] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcTQAAAHY"]
[Tue Aug 18 12:59:13.662195 2026] [security2:error] [pid 123784:tid 123944] [client 168.62.48.100:1048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcUAAAABo"]
[Tue Aug 18 12:59:13.663583 2026] [security2:error] [pid 123784:tid 123957] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/005.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcUQAAACc"]
[Tue Aug 18 12:59:13.776614 2026] [security2:error] [pid 123784:tid 124031] [client 132.196.30.78:13686] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcUgAAAHE"]
[Tue Aug 18 12:59:13.776794 2026] [security2:error] [pid 123784:tid 124031] [client 132.196.30.78:13686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcUgAAAHE"]
[Tue Aug 18 12:59:13.780437 2026] [security2:error] [pid 123784:tid 123945] [client 40.74.65.169:20326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcVAAAABs"]
[Tue Aug 18 12:59:13.780843 2026] [security2:error] [pid 123784:tid 123924] [client 132.196.30.78:2984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcVQAAAAY"]
[Tue Aug 18 12:59:13.783389 2026] [security2:error] [pid 123784:tid 123959] [client 52.173.121.69:14559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcVgAAACk"]
[Tue Aug 18 12:59:13.786377 2026] [security2:error] [pid 123784:tid 123976] [client 20.118.172.148:34213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcVwAAADo"]
[Tue Aug 18 12:59:13.817415 2026] [security2:error] [pid 123784:tid 123930] [client 20.25.139.174:4671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcWQAAAAw"]
[Tue Aug 18 12:59:13.822176 2026] [security2:error] [pid 123784:tid 123928] [client 20.25.139.174:4724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/i.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcWgAAAAo"]
[Tue Aug 18 12:59:13.859543 2026] [security2:error] [pid 123784:tid 123987] [client 20.104.85.180:18804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/as.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcXAAAAEU"]
[Tue Aug 18 12:59:13.891106 2026] [security2:error] [pid 123784:tid 123981] [client 20.104.85.180:27266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcXQAAAD8"]
[Tue Aug 18 12:59:13.928629 2026] [security2:error] [pid 123784:tid 123994] [client 168.62.48.100:1078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcYgAAAEw"]
[Tue Aug 18 12:59:13.942954 2026] [security2:error] [pid 123784:tid 123974] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcZAAAADg"]
[Tue Aug 18 12:59:13.949496 2026] [security2:error] [pid 123784:tid 123933] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/v2.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcZQAAAA8"]
[Tue Aug 18 12:59:14.019736 2026] [security2:error] [pid 123784:tid 124007] [client 20.203.138.185:46144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/loxi-o.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcaAAAAFk"]
[Tue Aug 18 12:59:14.048114 2026] [security2:error] [pid 123784:tid 123979] [client 74.248.18.37:32085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcagAAAD0"]
[Tue Aug 18 12:59:14.072750 2026] [authz_core:error] [pid 123784:tid 123832] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:14.073061 2026] [authz_core:error] [pid 123784:tid 123832] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:14.150111 2026] [security2:error] [pid 123784:tid 124008] [client 66.187.6.102:57624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/.env.old"] [unique_id "aoSBUmwDnJBNj2tDbYbccgAAAFo"]
[Tue Aug 18 12:59:14.190095 2026] [security2:error] [pid 123784:tid 123989] [client 20.250.13.23:38227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/php8.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcdgAAAEc"]
[Tue Aug 18 12:59:14.204876 2026] [security2:error] [pid 123784:tid 124033] [client 168.62.48.100:1176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBUmwDnJBNj2tDbYbceAAAAHM"]
[Tue Aug 18 12:59:14.209416 2026] [security2:error] [pid 123784:tid 124035] [client 52.173.121.69:30338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/mt/byp.php"] [unique_id "aoSBUmwDnJBNj2tDbYbceQAAAHU"]
[Tue Aug 18 12:59:14.264021 2026] [security2:error] [pid 123784:tid 124040] [client 66.187.6.102:57624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/api/.env"] [unique_id "aoSBUmwDnJBNj2tDbYbcfwAAAHo"]
[Tue Aug 18 12:59:14.265143 2026] [security2:error] [pid 123784:tid 124010] [client 20.100.169.31:24417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/ncx.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcgAAAAFw"]
[Tue Aug 18 12:59:14.268138 2026] [security2:error] [pid 123784:tid 124019] [client 132.196.30.78:13694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/alfa.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcgQAAAGU"]
[Tue Aug 18 12:59:14.289751 2026] [security2:error] [pid 123784:tid 124043] [client 20.65.98.162:32294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcggAAAH0"]
[Tue Aug 18 12:59:14.296479 2026] [security2:error] [pid 123784:tid 124044] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/weozh.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcgwAAAH4"]
[Tue Aug 18 12:59:14.321907 2026] [security2:error] [pid 123784:tid 124045] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/clque.php"] [unique_id "aoSBUmwDnJBNj2tDbYbchQAAAH8"]
[Tue Aug 18 12:59:14.341169 2026] [security2:error] [pid 123784:tid 123932] [client 20.38.3.247:55616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBUmwDnJBNj2tDbYbciAAAAA4"]
[Tue Aug 18 12:59:14.361326 2026] [security2:error] [pid 123784:tid 124024] [client 132.196.30.78:14599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/bolt.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcigAAAGo"]
[Tue Aug 18 12:59:14.367420 2026] [security2:error] [pid 123784:tid 124028] [client 20.25.139.174:4489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/bolt.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcjAAAAG4"]
[Tue Aug 18 12:59:14.368405 2026] [security2:error] [pid 123784:tid 124037] [client 66.187.6.102:57660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/backend/.env"] [unique_id "aoSBUmwDnJBNj2tDbYbcjQAAAHc"]
[Tue Aug 18 12:59:14.378320 2026] [security2:error] [pid 123784:tid 123973] [client 66.187.6.102:57624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/config/.env"] [unique_id "aoSBUmwDnJBNj2tDbYbcjwAAADc"]
[Tue Aug 18 12:59:14.413170 2026] [security2:error] [pid 123784:tid 124022] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wkl.php"] [unique_id "aoSBUmwDnJBNj2tDbYbclAAAAGg"]
[Tue Aug 18 12:59:14.440832 2026] [security2:error] [pid 123784:tid 124016] [client 213.35.127.232:60402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBUmwDnJBNj2tDbYbclQAAAGI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:14.458440 2026] [security2:error] [pid 123784:tid 123949] [client 168.62.48.100:1074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcmAAAAB8"]
[Tue Aug 18 12:59:14.477322 2026] [security2:error] [pid 123784:tid 123971] [client 40.74.65.169:19519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/inputs.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcmQAAADU"]
[Tue Aug 18 12:59:14.535087 2026] [security2:error] [pid 123784:tid 123924] [client 20.104.85.180:15205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/function/function.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcnQAAAAY"]
[Tue Aug 18 12:59:14.578571 2026] [security2:error] [pid 123784:tid 123967] [client 158.23.17.4:20433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ag.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcoQAAADE"]
[Tue Aug 18 12:59:14.596101 2026] [security2:error] [pid 123784:tid 123984] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/nano.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcowAAAEI"]
[Tue Aug 18 12:59:14.622592 2026] [security2:error] [pid 123784:tid 123987] [client 20.251.48.93:60686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcpAAAAEU"]
[Tue Aug 18 12:59:14.630462 2026] [security2:error] [pid 123784:tid 123988] [client 52.173.121.69:49009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/MTOS/byp.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcpQAAAEY"]
[Tue Aug 18 12:59:14.650942 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:14.651209 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:14.659361 2026] [security2:error] [pid 123784:tid 123994] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/rymmm.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcqAAAAEw"]
[Tue Aug 18 12:59:14.659382 2026] [security2:error] [pid 123784:tid 123947] [client 213.202.253.4:64391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/gdftps.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcqQAAAB0"], referer: www.google.com
[Tue Aug 18 12:59:14.690817 2026] [security2:error] [pid 123784:tid 123974] [client 20.104.85.180:1372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcrAAAADg"]
[Tue Aug 18 12:59:14.712462 2026] [security2:error] [pid 123784:tid 123997] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-asudo.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcrQAAAE8"]
[Tue Aug 18 12:59:14.778385 2026] [security2:error] [pid 123784:tid 123935] [client 168.62.48.100:1168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcsQAAABE"]
[Tue Aug 18 12:59:14.815229 2026] [autoindex:error] [pid 123784:tid 123966] [client 43.155.157.239:48154] AH01276: Cannot serve directory /home4/movei611/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.teresinahost.site
[Tue Aug 18 12:59:14.840875 2026] [security2:error] [pid 123784:tid 124012] [client 74.248.18.37:26478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcuAAAAF4"]
[Tue Aug 18 12:59:14.852059 2026] [security2:error] [pid 123784:tid 124033] [client 172.202.39.151:40378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcugAAAHM"]
[Tue Aug 18 12:59:14.872594 2026] [security2:error] [pid 123784:tid 124038] [client 20.65.98.162:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "tecpolorefrigeracao.com.br"] [uri "/.mopj.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcvQAAAHg"]
[Tue Aug 18 12:59:14.905631 2026] [security2:error] [pid 123784:tid 124002] [client 20.25.139.174:4647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/bthil.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcvwAAAFQ"]
[Tue Aug 18 12:59:14.907339 2026] [security2:error] [pid 123784:tid 124004] [client 20.25.139.174:4575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcwQAAAFY"]
[Tue Aug 18 12:59:14.951285 2026] [authz_core:error] [pid 123784:tid 123860] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:14.951574 2026] [authz_core:error] [pid 123784:tid 123860] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:14.962257 2026] [security2:error] [pid 123784:tid 124003] [client 132.196.30.78:13684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/edit.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcxwAAAFU"]
[Tue Aug 18 12:59:15.014113 2026] [security2:error] [pid 123784:tid 124022] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/lddxs.php"] [unique_id "aoSBU2wDnJBNj2tDbYbcyQAAAGg"]
[Tue Aug 18 12:59:15.014083 2026] [security2:error] [pid 123784:tid 123942] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/az.php"] [unique_id "aoSBU2wDnJBNj2tDbYbcygAAABg"]
[Tue Aug 18 12:59:15.062030 2026] [security2:error] [pid 123784:tid 123931] [client 168.62.48.100:1171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/well-known/index.php"] [unique_id "aoSBU2wDnJBNj2tDbYbczQAAAA0"]
[Tue Aug 18 12:59:15.067678 2026] [security2:error] [pid 123784:tid 123954] [client 20.118.172.148:2702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBU2wDnJBNj2tDbYbczgAAACQ"]
[Tue Aug 18 12:59:15.110327 2026] [security2:error] [pid 123784:tid 124010] [client 132.196.30.78:13661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/bthil.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc0AAAAFw"]
[Tue Aug 18 12:59:15.116090 2026] [security2:error] [pid 123784:tid 123944] [client 20.91.215.254:10185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/lock360.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc0QAAABo"]
[Tue Aug 18 12:59:15.151052 2026] [security2:error] [pid 123784:tid 123924] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/bengi.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc0wAAAAY"]
[Tue Aug 18 12:59:15.175130 2026] [security2:error] [pid 123784:tid 124021] [client 40.74.65.169:43016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/av.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc1AAAAGc"]
[Tue Aug 18 12:59:15.205810 2026] [security2:error] [pid 123784:tid 123948] [client 52.173.121.69:12194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc1gAAAB4"]
[Tue Aug 18 12:59:15.211088 2026] [security2:error] [pid 123784:tid 124005] [client 20.100.169.31:38054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc1wAAAFc"]
[Tue Aug 18 12:59:15.293861 2026] [security2:error] [pid 123784:tid 123993] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/z43agz.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc2gAAAEs"]
[Tue Aug 18 12:59:15.313521 2026] [security2:error] [pid 123784:tid 123945] [client 20.203.138.185:25499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/sdsa.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc3QAAABs"]
[Tue Aug 18 12:59:15.321619 2026] [security2:error] [pid 123784:tid 123990] [client 168.62.48.100:1203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc3gAAAEg"]
[Tue Aug 18 12:59:15.363814 2026] [security2:error] [pid 123784:tid 123996] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/zjggu.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc4AAAAE4"]
[Tue Aug 18 12:59:15.384895 2026] [security2:error] [pid 123784:tid 124029] [client 110.249.201.76:41368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rakhomed.com.br"] [uri "/robots.txt"] [unique_id "aoSBU2wDnJBNj2tDbYbc5AAAAG8"]
[Tue Aug 18 12:59:15.385903 2026] [security2:error] [pid 123784:tid 123997] [client 20.104.85.180:35518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc5QAAAE8"]
[Tue Aug 18 12:59:15.406206 2026] [security2:error] [pid 123784:tid 123929] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/file2.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc6QAAAAs"]
[Tue Aug 18 12:59:15.420003 2026] [security2:error] [pid 123784:tid 123919] [client 172.182.200.96:14150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc6gAAAAE"]
[Tue Aug 18 12:59:15.430254 2026] [security2:error] [pid 123784:tid 123978] [client 79.127.164.8:41552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/structure.bak"] [unique_id "aoSBU2wDnJBNj2tDbYbc6wAAADw"], referer: https://medihub.com.br/structure.bak
[Tue Aug 18 12:59:15.455955 2026] [security2:error] [pid 123784:tid 124041] [client 20.25.139.174:4601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc7AAAAHs"]
[Tue Aug 18 12:59:15.457127 2026] [security2:error] [pid 123784:tid 123937] [client 213.35.127.232:60610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc7gAAABM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:15.458142 2026] [core:crit] [pid 123784:tid 123981] (13)Permission denied: [client 20.25.139.174:4675] AH00529: /home3/cadema/public_html/cgi-bin/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home3/cadema/public_html/cgi-bin/' is executable
[Tue Aug 18 12:59:15.511857 2026] [security2:error] [pid 123784:tid 124013] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc7wAAX1M"]
[Tue Aug 18 12:59:15.553021 2026] [authz_core:error] [pid 123784:tid 123876] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:15.553374 2026] [authz_core:error] [pid 123784:tid 123876] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:15.582201 2026] [security2:error] [pid 123784:tid 124014] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/3.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc9gAAAGA"]
[Tue Aug 18 12:59:15.600026 2026] [security2:error] [pid 123784:tid 124038] [client 52.173.121.69:41121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc-AAAAHg"]
[Tue Aug 18 12:59:15.604114 2026] [security2:error] [pid 123784:tid 124040] [client 66.187.6.102:57670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/.env.orig"] [unique_id "aoSBU2wDnJBNj2tDbYbc-gAAAHo"]
[Tue Aug 18 12:59:15.623864 2026] [security2:error] [pid 123784:tid 124042] [client 20.25.139.174:4675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/x.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc-wAAAHw"]
[Tue Aug 18 12:59:15.648634 2026] [security2:error] [pid 123784:tid 123966] [client 132.196.30.78:15808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/elp.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc_QAAADA"]
[Tue Aug 18 12:59:15.652003 2026] [security2:error] [pid 123784:tid 123920] [client 103.184.169.37:42549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc_gAAAAI"]
[Tue Aug 18 12:59:15.652113 2026] [security2:error] [pid 123784:tid 123920] [client 103.184.169.37:42549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc_gAAAAI"]
[Tue Aug 18 12:59:15.654760 2026] [security2:error] [pid 123784:tid 124025] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/gm.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc_wAAAGs"]
[Tue Aug 18 12:59:15.671687 2026] [security2:error] [pid 123784:tid 124044] [client 4.232.94.69:15153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/u.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdAQAAAH4"]
[Tue Aug 18 12:59:15.694009 2026] [security2:error] [pid 123784:tid 123991] [client 168.62.48.100:1067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdBAAAAEk"]
[Tue Aug 18 12:59:15.698762 2026] [security2:error] [pid 123784:tid 123961] [client 103.120.71.157:18801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdAwAAACs"]
[Tue Aug 18 12:59:15.698907 2026] [security2:error] [pid 123784:tid 123961] [client 103.120.71.157:18801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdAwAAACs"]
[Tue Aug 18 12:59:15.716768 2026] [security2:error] [pid 123784:tid 124039] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/dlvqo.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdBQAAAHk"]
[Tue Aug 18 12:59:15.745497 2026] [core:crit] [pid 123784:tid 124017] (13)Permission denied: [client 132.196.30.78:13649] AH00529: /home3/cadema/public_html/cgi-bin/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home3/cadema/public_html/cgi-bin/' is executable
[Tue Aug 18 12:59:15.751955 2026] [security2:error] [pid 123784:tid 124034] [client 20.91.215.254:10209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/log.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdBwAAAHQ"]
[Tue Aug 18 12:59:15.766531 2026] [security2:error] [pid 123784:tid 124028] [client 172.202.39.151:44511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/01.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdFwAAAG4"]
[Tue Aug 18 12:59:15.774341 2026] [security2:error] [pid 123784:tid 123973] [client 158.23.17.4:14041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ig.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdHgAAADc"]
[Tue Aug 18 12:59:15.798098 2026] [security2:error] [pid 123784:tid 124027] [client 66.187.6.102:57670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/.env.copy"] [unique_id "aoSBU2wDnJBNj2tDbYbdJAAAAG0"]
[Tue Aug 18 12:59:15.800215 2026] [security2:error] [pid 123784:tid 123938] [client 138.36.100.162:41761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdJQAAABQ"]
[Tue Aug 18 12:59:15.800290 2026] [security2:error] [pid 123784:tid 123938] [client 138.36.100.162:41761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdJQAAABQ"]
[Tue Aug 18 12:59:15.826844 2026] [security2:error] [pid 123784:tid 123951] [client 68.221.73.131:10743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/ops.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdJwAAACE"]
[Tue Aug 18 12:59:15.869271 2026] [security2:error] [pid 123784:tid 123972] [client 40.74.65.169:44112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdLAAAADY"]
[Tue Aug 18 12:59:15.884850 2026] [security2:error] [pid 123784:tid 123976] [client 132.196.30.78:13649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/x.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdLwAAADo"]
[Tue Aug 18 12:59:15.901896 2026] [security2:error] [pid 123784:tid 123927] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/log.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdMQAAAAk"]
[Tue Aug 18 12:59:15.924767 2026] [security2:error] [pid 123784:tid 123948] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/ws55.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdNQAAAB4"]
[Tue Aug 18 12:59:15.983807 2026] [security2:error] [pid 123784:tid 123988] [client 20.38.3.247:64734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdTQAAAEY"]
[Tue Aug 18 12:59:16.001223 2026] [security2:error] [pid 123784:tid 123968] [client 20.25.139.174:4574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdTwAAADI"]
[Tue Aug 18 12:59:16.035319 2026] [security2:error] [pid 123784:tid 123935] [client 20.215.241.237:60361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/222.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdUwAAABE"]
[Tue Aug 18 12:59:16.039659 2026] [security2:error] [pid 123784:tid 123919] [client 168.62.48.100:1082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdVQAAAAE"]
[Tue Aug 18 12:59:16.064692 2026] [security2:error] [pid 123784:tid 124041] [client 52.173.121.69:12193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdWAAAAHs"]
[Tue Aug 18 12:59:16.073639 2026] [security2:error] [pid 123784:tid 123981] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/pkmoj.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdWQAAAD8"]
[Tue Aug 18 12:59:16.159527 2026] [security2:error] [pid 123784:tid 124045] [client 49.13.24.81:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "blog.tinna.com.br"] [uri "/index.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcwwAAAH8"], referer: http://blog.tinna.com.br
[Tue Aug 18 12:59:16.189470 2026] [security2:error] [pid 123784:tid 124038] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/ohct.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdXQAAAHg"]
[Tue Aug 18 12:59:16.204675 2026] [security2:error] [pid 123784:tid 124006] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/m.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdXgAAAFg"]
[Tue Aug 18 12:59:16.228099 2026] [security2:error] [pid 123784:tid 123947] [client 20.104.85.180:1400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdYAAAAB0"]
[Tue Aug 18 12:59:16.230062 2026] [security2:error] [pid 123784:tid 123937] [client 20.25.139.174:4676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/index/function.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdYQAAABM"]
[Tue Aug 18 12:59:16.243868 2026] [security2:error] [pid 123784:tid 124018] [client 66.187.6.102:57670] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/.env.yaml"] [unique_id "aoSBVGwDnJBNj2tDbYbdYgAAAGQ"]
[Tue Aug 18 12:59:16.249738 2026] [security2:error] [pid 123784:tid 124024] [client 132.196.30.78:13666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdYwAAAGo"]
[Tue Aug 18 12:59:16.254466 2026] [security2:error] [pid 123784:tid 123953] [client 74.248.18.37:32099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/includes/about.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdZAAAACM"]
[Tue Aug 18 12:59:16.290300 2026] [security2:error] [pid 123784:tid 123961] [client 20.203.138.185:10993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-freya.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdZwAAACs"]
[Tue Aug 18 12:59:16.319331 2026] [security2:error] [pid 123784:tid 124010] [client 149.34.210.141:64851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdaQAAAFw"]
[Tue Aug 18 12:59:16.358563 2026] [security2:error] [pid 123784:tid 123960] [client 168.62.48.100:1219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/mt/byp.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdagAAACo"]
[Tue Aug 18 12:59:16.392341 2026] [security2:error] [pid 123784:tid 124014] [client 20.91.215.254:10176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/lv.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdbgAAAGA"]
[Tue Aug 18 12:59:16.415490 2026] [security2:error] [pid 123784:tid 123920] [client 132.196.30.78:14610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/index/function.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdcAAAAAI"]
[Tue Aug 18 12:59:16.450000 2026] [security2:error] [pid 123784:tid 124036] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/kopyw.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdcgAAAHY"]
[Tue Aug 18 12:59:16.459018 2026] [security2:error] [pid 123784:tid 123934] [client 66.187.6.102:57724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/.env.local.bak"] [unique_id "aoSBVGwDnJBNj2tDbYbdcwAAABA"]
[Tue Aug 18 12:59:16.474941 2026] [security2:error] [pid 123784:tid 123943] [client 213.35.127.232:60813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBVGwDnJBNj2tDbYbddAAAABk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:16.476366 2026] [security2:error] [pid 123784:tid 124016] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/ot.php"] [unique_id "aoSBVGwDnJBNj2tDbYbddQAAAGI"]
[Tue Aug 18 12:59:16.480647 2026] [security2:error] [pid 123784:tid 124032] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/33.php"] [unique_id "aoSBVGwDnJBNj2tDbYbddgAAAHI"]
[Tue Aug 18 12:59:16.520133 2026] [security2:error] [pid 123784:tid 123962] [client 157.20.138.62:55135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdeQAAACw"]
[Tue Aug 18 12:59:16.520275 2026] [security2:error] [pid 123784:tid 123962] [client 157.20.138.62:55135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdeQAAACw"]
[Tue Aug 18 12:59:16.532352 2026] [security2:error] [pid 123784:tid 124043] [client 52.173.121.69:27886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdewAAAH0"]
[Tue Aug 18 12:59:16.543670 2026] [security2:error] [pid 123784:tid 123972] [client 40.74.65.169:20341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdfAAAADY"]
[Tue Aug 18 12:59:16.575410 2026] [security2:error] [pid 123784:tid 123973] [client 20.25.139.174:4678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/NewFile.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdfQAAADc"]
[Tue Aug 18 12:59:16.595529 2026] [security2:error] [pid 123784:tid 124010] [client 149.34.210.141:64851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdaQAAAFw"]
[Tue Aug 18 12:59:16.629840 2026] [security2:error] [pid 123784:tid 123930] [client 172.202.39.151:40382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/lv.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdgAAAAAw"]
[Tue Aug 18 12:59:16.632481 2026] [security2:error] [pid 123784:tid 123970] [client 20.38.3.247:29799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/media.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdgQAAADQ"]
[Tue Aug 18 12:59:16.632700 2026] [security2:error] [pid 123784:tid 123971] [client 20.250.13.23:55514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdggAAADU"]
[Tue Aug 18 12:59:16.688539 2026] [security2:error] [pid 123784:tid 123990] [client 168.62.48.100:1055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdhAAAAEg"]
[Tue Aug 18 12:59:16.695904 2026] [security2:error] [pid 123784:tid 123968] [client 20.104.85.180:42297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdhgAAADI"]
[Tue Aug 18 12:59:16.739960 2026] [security2:error] [pid 123784:tid 123974] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/packed.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdhwAAADg"]
[Tue Aug 18 12:59:16.752128 2026] [security2:error] [pid 123784:tid 123933] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/v5.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdigAAAA8"]
[Tue Aug 18 12:59:16.756096 2026] [security2:error] [pid 123784:tid 124021] [client 20.25.139.174:4592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/aaa.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdiwAAAGc"]
[Tue Aug 18 12:59:16.758321 2026] [authz_core:error] [pid 123784:tid 123833] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:16.758601 2026] [authz_core:error] [pid 123784:tid 123833] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:16.776614 2026] [security2:error] [pid 123784:tid 123919] [client 158.23.17.4:47624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ta.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdjQAAAAE"]
[Tue Aug 18 12:59:16.805841 2026] [security2:error] [pid 123784:tid 123929] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/zznmg.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdkAAAAAs"]
[Tue Aug 18 12:59:16.819846 2026] [security2:error] [pid 123784:tid 123958] [client 173.239.254.5:48729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.254.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriacristal.com.br"] [uri "/wp-login.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdkQAAACg"]
[Tue Aug 18 12:59:16.916778 2026] [security2:error] [pid 123784:tid 123993] [client 132.196.30.78:13660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/666.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdlAAAAEs"]
[Tue Aug 18 12:59:17.002374 2026] [security2:error] [pid 123784:tid 123935] [client 74.248.18.37:7776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/index.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdlwAAABE"]
[Tue Aug 18 12:59:17.010992 2026] [security2:error] [pid 123784:tid 124006] [client 168.62.48.100:1126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdmAAAAFg"]
[Tue Aug 18 12:59:17.022223 2026] [security2:error] [pid 123784:tid 124041] [client 20.91.215.254:13378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/mah/function.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdmQAAAHs"]
[Tue Aug 18 12:59:17.027797 2026] [security2:error] [pid 123784:tid 123932] [client 5.31.227.224:30444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdmgAAAA4"]
[Tue Aug 18 12:59:17.037702 2026] [security2:error] [pid 123784:tid 123932] [client 5.31.227.224:30444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdmgAAAA4"]
[Tue Aug 18 12:59:17.040849 2026] [security2:error] [pid 123784:tid 123957] [client 178.153.171.161:34435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdnAAAACc"]
[Tue Aug 18 12:59:17.041005 2026] [security2:error] [pid 123784:tid 123957] [client 178.153.171.161:34435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdnAAAACc"]
[Tue Aug 18 12:59:17.054380 2026] [security2:error] [pid 123784:tid 124019] [client 68.155.154.236:25358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdnwAAAGU"]
[Tue Aug 18 12:59:17.092981 2026] [security2:error] [pid 123784:tid 123994] [client 132.196.30.78:13642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/aaa.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdoAAAAEw"]
[Tue Aug 18 12:59:17.096329 2026] [security2:error] [pid 123784:tid 123997] [client 20.203.138.185:25524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/fleen.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdoQAAAE8"]
[Tue Aug 18 12:59:17.110000 2026] [security2:error] [pid 123784:tid 124033] [client 20.25.139.174:4729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdogAAAHM"]
[Tue Aug 18 12:59:17.138979 2026] [security2:error] [pid 123784:tid 123966] [client 66.187.6.102:57724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/.env.prod.bak"] [unique_id "aoSBVWwDnJBNj2tDbYbdpQAAADA"]
[Tue Aug 18 12:59:17.158063 2026] [security2:error] [pid 123784:tid 123953] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/bhfnd.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdpgAAACM"]
[Tue Aug 18 12:59:17.165234 2026] [security2:error] [pid 123784:tid 124026] [client 52.173.121.69:27883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdpwAAAGw"]
[Tue Aug 18 12:59:17.193611 2026] [security2:error] [pid 123784:tid 124044] [client 20.104.85.180:57710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/ok.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdqQAAAH4"]
[Tue Aug 18 12:59:17.219368 2026] [security2:error] [pid 123784:tid 124017] [client 20.104.85.180:1370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdqwAAAGM"]
[Tue Aug 18 12:59:17.224220 2026] [security2:error] [pid 123784:tid 124034] [client 40.74.65.169:20396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-blog.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdrQAAAHQ"]
[Tue Aug 18 12:59:17.285871 2026] [security2:error] [pid 123784:tid 123920] [client 168.62.48.100:1057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdrwAAAAI"]
[Tue Aug 18 12:59:17.316996 2026] [security2:error] [pid 123784:tid 123938] [client 20.38.3.247:35148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/admin.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdsgAAABQ"]
[Tue Aug 18 12:59:17.486269 2026] [security2:error] [pid 123784:tid 123918] [client 20.25.139.174:4619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/abcd.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdugAAAAA"]
[Tue Aug 18 12:59:17.486269 2026] [security2:error] [pid 123784:tid 124018] [client 213.35.127.232:61017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBVWwDnJBNj2tDbYbduQAAAGQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:17.488029 2026] [security2:error] [pid 123784:tid 123939] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoSBVWwDnJBNj2tDbYbduwAAABU"]
[Tue Aug 18 12:59:17.512679 2026] [security2:error] [pid 123784:tid 123925] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/qfvqu.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdvgAAAAc"]
[Tue Aug 18 12:59:17.565872 2026] [security2:error] [pid 123784:tid 123970] [client 68.221.73.131:26045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/coffexium.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdwAAAADQ"]
[Tue Aug 18 12:59:17.570593 2026] [security2:error] [pid 123784:tid 123971] [client 168.62.48.100:1162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdwQAAADU"]
[Tue Aug 18 12:59:17.639502 2026] [security2:error] [pid 123784:tid 123980] [client 66.187.6.102:57724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/.env.development.old"] [unique_id "aoSBVWwDnJBNj2tDbYbdyAAAAD4"]
[Tue Aug 18 12:59:17.642595 2026] [security2:error] [pid 123784:tid 123949] [client 223.185.37.47:5876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdygAAAB8"]
[Tue Aug 18 12:59:17.642832 2026] [security2:error] [pid 123784:tid 123949] [client 223.185.37.47:5876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdygAAAB8"]
[Tue Aug 18 12:59:17.667812 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:17.668159 2026] [security2:error] [pid 123784:tid 123927] [client 132.196.30.78:15038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/abcd.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdzgAAAAk"]
[Tue Aug 18 12:59:17.668237 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:17.673385 2026] [security2:error] [pid 123784:tid 124043] [client 20.91.215.254:10238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdzwAAAH0"]
[Tue Aug 18 12:59:17.707592 2026] [security2:error] [pid 123784:tid 123919] [client 20.251.48.93:53319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd1AAAAAE"]
[Tue Aug 18 12:59:17.736086 2026] [security2:error] [pid 123784:tid 123950] [client 52.173.121.69:50183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd1gAAACA"]
[Tue Aug 18 12:59:17.737538 2026] [security2:error] [pid 123784:tid 123952] [client 20.25.139.174:4715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd1wAAACI"]
[Tue Aug 18 12:59:17.790912 2026] [security2:error] [pid 123784:tid 124031] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd3QAAAHE"]
[Tue Aug 18 12:59:17.837156 2026] [security2:error] [pid 123784:tid 123975] [client 168.62.48.100:1199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd3wAAADk"]
[Tue Aug 18 12:59:17.848491 2026] [security2:error] [pid 123784:tid 124025] [client 85.154.68.202:60396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd4AAAAGs"]
[Tue Aug 18 12:59:17.848656 2026] [security2:error] [pid 123784:tid 124025] [client 85.154.68.202:60396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd4AAAAGs"]
[Tue Aug 18 12:59:17.870043 2026] [security2:error] [pid 123784:tid 124008] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/oivcl.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd4wAAAFo"]
[Tue Aug 18 12:59:17.931270 2026] [security2:error] [pid 123784:tid 123994] [client 20.38.3.247:9378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/mac.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd6AAAAEw"]
[Tue Aug 18 12:59:17.945826 2026] [security2:error] [pid 123784:tid 124040] [client 74.248.18.37:32074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/js/about.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd6QAAAHo"]
[Tue Aug 18 12:59:17.970284 2026] [authz_core:error] [pid 123784:tid 123859] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:17.970729 2026] [authz_core:error] [pid 123784:tid 123859] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:17.982497 2026] [security2:error] [pid 123784:tid 123961] [client 4.232.94.69:37525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/k.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd7QAAACs"]
[Tue Aug 18 12:59:18.010188 2026] [security2:error] [pid 123784:tid 124028] [client 20.203.138.185:11118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/e.php"] [unique_id "aoSBVmwDnJBNj2tDbYbd7gAAAG4"]
[Tue Aug 18 12:59:18.087124 2026] [security2:error] [pid 123784:tid 124036] [client 168.62.48.100:1180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBVmwDnJBNj2tDbYbd8QAAAHY"]
[Tue Aug 18 12:59:18.090949 2026] [security2:error] [pid 123784:tid 123982] [client 20.25.139.174:4682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-good.php"] [unique_id "aoSBVmwDnJBNj2tDbYbd8gAAAEA"]
[Tue Aug 18 12:59:18.092338 2026] [security2:error] [pid 123784:tid 123934] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/dk.php"] [unique_id "aoSBVmwDnJBNj2tDbYbd8wAAABA"]
[Tue Aug 18 12:59:18.117754 2026] [security2:error] [pid 123784:tid 123951] [client 20.104.85.180:29534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/item.php"] [unique_id "aoSBVmwDnJBNj2tDbYbd9AAAACE"]
[Tue Aug 18 12:59:18.129267 2026] [security2:error] [pid 123784:tid 123984] [client 52.173.121.69:48981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/first.php"] [unique_id "aoSBVmwDnJBNj2tDbYbd9QAAAEI"]
[Tue Aug 18 12:59:18.177649 2026] [security2:error] [pid 123784:tid 123973] [client 66.187.6.102:57724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/.env.beta"] [unique_id "aoSBVmwDnJBNj2tDbYbd-QAAADc"]
[Tue Aug 18 12:59:18.177762 2026] [security2:error] [pid 123784:tid 123973] [client 66.187.6.102:57724] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/.env.beta"] [unique_id "aoSBVmwDnJBNj2tDbYbd-QAAADc"]
[Tue Aug 18 12:59:18.188612 2026] [security2:error] [pid 123784:tid 123937] [client 185.191.171.10:27756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1752011076/1753920000/"] [unique_id "aoSBVmwDnJBNj2tDbYbd-wAAABM"]
[Tue Aug 18 12:59:18.188774 2026] [security2:error] [pid 123784:tid 123937] [client 185.191.171.10:27756] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1752011076/1753920000/"] [unique_id "aoSBVmwDnJBNj2tDbYbd-wAAABM"]
[Tue Aug 18 12:59:18.189081 2026] [security2:error] [pid 123784:tid 123993] [client 20.250.13.23:48022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/222.php"] [unique_id "aoSBVmwDnJBNj2tDbYbd_AAAAEs"]
[Tue Aug 18 12:59:18.203981 2026] [security2:error] [pid 123784:tid 124023] [client 132.196.30.78:15019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/ws54.php"] [unique_id "aoSBVmwDnJBNj2tDbYbd_QAAAGk"]
[Tue Aug 18 12:59:18.220177 2026] [security2:error] [pid 123784:tid 123991] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/zugvi.php"] [unique_id "aoSBVmwDnJBNj2tDbYbd_wAAAEk"]
[Tue Aug 18 12:59:18.238692 2026] [security2:error] [pid 123784:tid 123942] [client 20.25.139.174:4689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/themes.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeAQAAABg"]
[Tue Aug 18 12:59:18.244215 2026] [security2:error] [pid 123784:tid 124015] [client 132.196.30.78:15015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-good.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeAgAAAGE"]
[Tue Aug 18 12:59:18.271168 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:18.271430 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:18.313096 2026] [security2:error] [pid 123784:tid 123943] [client 20.91.215.254:13377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/mass.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeCQAAABk"]
[Tue Aug 18 12:59:18.322685 2026] [security2:error] [pid 123784:tid 123929] [client 172.202.39.151:44584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/new.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeCwAAAAs"]
[Tue Aug 18 12:59:18.345400 2026] [security2:error] [pid 123784:tid 123893] [remote 203.99.146.53:46936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "orientadoraespiritualbhsp.com.br"] [uri "/wp-login.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeDQAAOGg"]
[Tue Aug 18 12:59:18.349351 2026] [security2:error] [pid 123784:tid 123990] [client 37.40.227.74:57070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeDgAAAEg"]
[Tue Aug 18 12:59:18.349465 2026] [security2:error] [pid 123784:tid 123990] [client 37.40.227.74:57070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeDgAAAEg"]
[Tue Aug 18 12:59:18.373564 2026] [security2:error] [pid 123784:tid 124031] [client 20.104.85.180:28641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeDwAAAHE"]
[Tue Aug 18 12:59:18.377182 2026] [security2:error] [pid 123784:tid 124013] [client 168.62.48.100:1037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeEAAAAF8"]
[Tue Aug 18 12:59:18.396852 2026] [security2:error] [pid 123784:tid 124025] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/bal.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeEgAAAGs"]
[Tue Aug 18 12:59:18.413356 2026] [security2:error] [pid 123784:tid 123882] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeFAAAA10"]
[Tue Aug 18 12:59:18.413594 2026] [security2:error] [pid 123784:tid 123921] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeFAAAA10"]
[Tue Aug 18 12:59:18.421062 2026] [security2:error] [pid 123784:tid 123888] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeFQAAGmM"]
[Tue Aug 18 12:59:18.421307 2026] [security2:error] [pid 123784:tid 123944] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeFQAAGmM"]
[Tue Aug 18 12:59:18.447704 2026] [security2:error] [pid 123784:tid 123979] [client 66.187.6.102:57720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/server/.env"] [unique_id "aoSBVmwDnJBNj2tDbYbeFgAAAD0"]
[Tue Aug 18 12:59:18.497640 2026] [security2:error] [pid 123784:tid 123940] [client 213.35.127.232:61244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeGAAAABY"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:18.538954 2026] [security2:error] [pid 123784:tid 123997] [client 20.38.3.247:64090] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/1.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeGQAAAE8"]
[Tue Aug 18 12:59:18.539094 2026] [security2:error] [pid 123784:tid 123997] [client 20.38.3.247:64090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/1.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeGQAAAE8"]
[Tue Aug 18 12:59:18.569400 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:18.569668 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:18.574831 2026] [security2:error] [pid 123784:tid 124040] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wsrer.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeGwAAAHo"]
[Tue Aug 18 12:59:18.615335 2026] [security2:error] [pid 123784:tid 124008] [client 20.25.139.174:4681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/simple.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeHgAAAFo"]
[Tue Aug 18 12:59:18.622439 2026] [security2:error] [pid 123784:tid 124028] [client 20.65.98.162:57854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/mgrr.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeHwAAAG4"]
[Tue Aug 18 12:59:18.670090 2026] [security2:error] [pid 123784:tid 124030] [client 66.187.6.102:57720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/app/.env"] [unique_id "aoSBVmwDnJBNj2tDbYbeIAAAAHA"]
[Tue Aug 18 12:59:18.683012 2026] [security2:error] [pid 123784:tid 124014] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/yawa.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeIgAAAGA"]
[Tue Aug 18 12:59:18.690012 2026] [security2:error] [pid 123784:tid 123920] [client 52.173.121.69:14872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeIwAAAAI"]
[Tue Aug 18 12:59:18.722302 2026] [security2:error] [pid 123784:tid 124035] [client 168.62.48.100:1211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/first.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeJAAAAHU"]
[Tue Aug 18 12:59:18.754957 2026] [security2:error] [pid 123784:tid 123952] [client 114.5.214.109:50413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeJgAAACI"]
[Tue Aug 18 12:59:18.755636 2026] [security2:error] [pid 123784:tid 123952] [client 114.5.214.109:50413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeJgAAACI"]
[Tue Aug 18 12:59:18.761531 2026] [security2:error] [pid 123784:tid 124044] [client 132.196.30.78:15002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/simple.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeJwAAAH4"]
[Tue Aug 18 12:59:18.772071 2026] [security2:error] [pid 123784:tid 123947] [client 20.25.139.174:4602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/cv.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeKQAAAB0"]
[Tue Aug 18 12:59:18.783861 2026] [security2:error] [pid 123784:tid 123924] [client 132.196.30.78:14592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeKgAAAAY"]
[Tue Aug 18 12:59:18.834529 2026] [security2:error] [pid 123784:tid 123976] [client 20.203.138.185:21039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/hello.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeKwAAADo"]
[Tue Aug 18 12:59:18.889931 2026] [security2:error] [pid 123784:tid 123953] [client 79.127.164.8:41868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/structure.sql"] [unique_id "aoSBVmwDnJBNj2tDbYbeMAAAACM"], referer: https://medihub.com.br/structure.sql
[Tue Aug 18 12:59:18.935712 2026] [security2:error] [pid 123784:tid 124005] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/ucpfr.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeNAAAAFc"]
[Tue Aug 18 12:59:18.937340 2026] [security2:error] [pid 123784:tid 124027] [client 74.248.18.37:26477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeNQAAAG0"]
[Tue Aug 18 12:59:18.950460 2026] [security2:error] [pid 123784:tid 124032] [client 20.91.215.254:10186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/memberfuns.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeNwAAAHI"]
[Tue Aug 18 12:59:18.952388 2026] [security2:error] [pid 123784:tid 123980] [client 66.187.6.102:57720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/src/.env"] [unique_id "aoSBVmwDnJBNj2tDbYbeOAAAAD4"]
[Tue Aug 18 12:59:18.957696 2026] [security2:error] [pid 123784:tid 123961] [client 4.232.94.69:37533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/elp.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeOwAAACs"]
[Tue Aug 18 12:59:18.968563 2026] [security2:error] [pid 123784:tid 123986] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSBVmwDnJBNj2tDbYbePAAAAEQ"]
[Tue Aug 18 12:59:18.981898 2026] [security2:error] [pid 123784:tid 123942] [client 168.62.48.100:1195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBVmwDnJBNj2tDbYbePQAAABg"]
[Tue Aug 18 12:59:18.996174 2026] [security2:error] [pid 123784:tid 124015] [client 20.104.85.180:14531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSBVmwDnJBNj2tDbYbePwAAAGE"]
[Tue Aug 18 12:59:18.996903 2026] [security2:error] [pid 123784:tid 123996] [client 172.182.200.96:7654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeQAAAAE4"]
[Tue Aug 18 12:59:19.127796 2026] [security2:error] [pid 123784:tid 123991] [client 20.25.139.174:4606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/edit-tags.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeRQAAAEk"]
[Tue Aug 18 12:59:19.136788 2026] [security2:error] [pid 123784:tid 123929] [client 20.65.98.162:18820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/55.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeTQAAAAs"]
[Tue Aug 18 12:59:19.188033 2026] [security2:error] [pid 123784:tid 123967] [client 20.100.169.31:39099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wso.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeTwAAADE"]
[Tue Aug 18 12:59:19.246336 2026] [security2:error] [pid 123784:tid 123987] [client 52.173.121.69:32611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeVgAAAEU"]
[Tue Aug 18 12:59:19.249364 2026] [security2:error] [pid 123784:tid 123923] [client 20.215.241.237:65267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/key.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeVwAAAAU"]
[Tue Aug 18 12:59:19.260870 2026] [security2:error] [pid 123784:tid 124045] [client 66.187.6.102:57720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/docker/.env"] [unique_id "aoSBV2wDnJBNj2tDbYbeWQAAAH8"]
[Tue Aug 18 12:59:19.266263 2026] [security2:error] [pid 123784:tid 124000] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/7.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeWgAAAFI"]
[Tue Aug 18 12:59:19.314147 2026] [security2:error] [pid 123784:tid 124038] [client 40.74.65.169:42485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeXAAAAHg"]
[Tue Aug 18 12:59:19.316022 2026] [security2:error] [pid 123784:tid 123963] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/yxijx.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeXgAAAC0"]
[Tue Aug 18 12:59:19.316514 2026] [security2:error] [pid 123784:tid 123935] [client 168.62.48.100:1216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeXwAAABE"]
[Tue Aug 18 12:59:19.391439 2026] [security2:error] [pid 123784:tid 124025] [client 132.196.30.78:13662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/function/function.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeYwAAAGs"]
[Tue Aug 18 12:59:19.471998 2026] [authz_core:error] [pid 123784:tid 123789] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:19.472274 2026] [authz_core:error] [pid 123784:tid 123789] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:19.482956 2026] [security2:error] [pid 123784:tid 124035] [client 20.38.3.247:61962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/coffee.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeaQAAAHU"]
[Tue Aug 18 12:59:19.519172 2026] [security2:error] [pid 123784:tid 124031] [client 213.35.127.232:61451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBV2wDnJBNj2tDbYbebgAAAHE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:19.521729 2026] [security2:error] [pid 123784:tid 123951] [client 68.155.154.236:27526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBV2wDnJBNj2tDbYbebwAAACE"]
[Tue Aug 18 12:59:19.607773 2026] [security2:error] [pid 123784:tid 123930] [client 168.62.48.100:1052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBV2wDnJBNj2tDbYbecQAAAAw"]
[Tue Aug 18 12:59:19.635582 2026] [security2:error] [pid 123784:tid 123925] [client 20.104.85.180:43579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBV2wDnJBNj2tDbYbecgAAAAc"]
[Tue Aug 18 12:59:19.664633 2026] [security2:error] [pid 123784:tid 124034] [client 20.91.215.254:10208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/meta.php"] [unique_id "aoSBV2wDnJBNj2tDbYbecwAAAHQ"]
[Tue Aug 18 12:59:19.669324 2026] [security2:error] [pid 123784:tid 124005] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/zwlsv.php"] [unique_id "aoSBV2wDnJBNj2tDbYbedAAAAFc"]
[Tue Aug 18 12:59:19.670289 2026] [security2:error] [pid 123784:tid 124030] [client 132.196.30.78:14996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/edit-tags.php"] [unique_id "aoSBV2wDnJBNj2tDbYbedQAAAHA"]
[Tue Aug 18 12:59:19.672281 2026] [security2:error] [pid 123784:tid 124027] [client 20.203.138.185:11131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/brc.php"] [unique_id "aoSBV2wDnJBNj2tDbYbedgAAAG0"]
[Tue Aug 18 12:59:19.687339 2026] [security2:error] [pid 123784:tid 123993] [client 192.141.172.134:53713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBV2wDnJBNj2tDbYbedwAAAEs"]
[Tue Aug 18 12:59:19.687444 2026] [security2:error] [pid 123784:tid 123993] [client 192.141.172.134:53713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBV2wDnJBNj2tDbYbedwAAAEs"]
[Tue Aug 18 12:59:19.699082 2026] [security2:error] [pid 123784:tid 124032] [client 20.251.48.93:53187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeeAAAAHI"]
[Tue Aug 18 12:59:19.718943 2026] [security2:error] [pid 123784:tid 123924] [client 20.25.139.174:4581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/u.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeegAAAAY"]
[Tue Aug 18 12:59:19.721046 2026] [security2:error] [pid 123784:tid 123791] [remote 162.55.89.48:58468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villanobreeventos.com.br"] [uri "/wp-login.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeeQAAYwI"]
[Tue Aug 18 12:59:19.785567 2026] [security2:error] [pid 123784:tid 123919] [client 52.173.121.69:42731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBV2wDnJBNj2tDbYbefwAAAAE"]
[Tue Aug 18 12:59:19.791255 2026] [authz_core:error] [pid 123784:tid 123803] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:19.791571 2026] [authz_core:error] [pid 123784:tid 123803] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:19.811099 2026] [security2:error] [pid 123784:tid 123952] [client 4.232.94.69:21157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSBV2wDnJBNj2tDbYbegQAAACI"]
[Tue Aug 18 12:59:19.851305 2026] [security2:error] [pid 123784:tid 123955] [client 168.62.48.100:1149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/blog/byp.php"] [unique_id "aoSBV2wDnJBNj2tDbYbegwAAACU"]
[Tue Aug 18 12:59:19.866660 2026] [security2:error] [pid 123784:tid 123974] [client 158.23.17.4:57245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/f.php"] [unique_id "aoSBV2wDnJBNj2tDbYbehAAAADg"]
[Tue Aug 18 12:59:19.890903 2026] [security2:error] [pid 123784:tid 123927] [client 20.25.139.174:4685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBV2wDnJBNj2tDbYbehgAAAAk"]
[Tue Aug 18 12:59:19.936789 2026] [security2:error] [pid 123784:tid 124037] [client 102.213.179.104:59271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeiQAAAHc"]
[Tue Aug 18 12:59:19.936937 2026] [security2:error] [pid 123784:tid 124037] [client 102.213.179.104:59271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeiQAAAHc"]
[Tue Aug 18 12:59:20.019620 2026] [security2:error] [pid 123784:tid 123956] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/jrpga.php"] [unique_id "aoSBWGwDnJBNj2tDbYbejAAAACY"]
[Tue Aug 18 12:59:20.027608 2026] [security2:error] [pid 123784:tid 124038] [client 40.74.65.169:19485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBWGwDnJBNj2tDbYbejQAAAHg"]
[Tue Aug 18 12:59:20.035948 2026] [security2:error] [pid 123784:tid 124026] [client 132.196.30.78:15655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/nw.php"] [unique_id "aoSBWGwDnJBNj2tDbYbejgAAAGw"]
[Tue Aug 18 12:59:20.102454 2026] [security2:error] [pid 123784:tid 124042] [client 74.248.18.37:19271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoSBWGwDnJBNj2tDbYbekAAAAHw"]
[Tue Aug 18 12:59:20.107026 2026] [security2:error] [pid 123784:tid 124040] [client 168.62.48.100:1212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBWGwDnJBNj2tDbYbekQAAAHo"]
[Tue Aug 18 12:59:20.111956 2026] [security2:error] [pid 123784:tid 123928] [client 68.221.73.131:51751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBWGwDnJBNj2tDbYbekgAAAAo"]
[Tue Aug 18 12:59:20.225868 2026] [security2:error] [pid 123784:tid 124012] [client 52.173.121.69:50211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/blog/byp.php"] [unique_id "aoSBWGwDnJBNj2tDbYbenAAAAF4"]
[Tue Aug 18 12:59:20.230521 2026] [security2:error] [pid 123784:tid 123968] [client 20.25.139.174:4588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBWGwDnJBNj2tDbYbenQAAADI"]
[Tue Aug 18 12:59:20.239132 2026] [security2:error] [pid 123784:tid 123982] [client 5.161.194.92:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "markettohome.com.br"] [uri "/index.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeLQAAQGU"], referer: https://markettohome.com.br/
[Tue Aug 18 12:59:20.245472 2026] [security2:error] [pid 123784:tid 124035] [client 20.38.3.247:61953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBWGwDnJBNj2tDbYbenwAAAHU"]
[Tue Aug 18 12:59:20.269421 2026] [security2:error] [pid 123784:tid 124013] [client 132.196.30.78:15014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/u.php"] [unique_id "aoSBWGwDnJBNj2tDbYbeoAAAAF8"]
[Tue Aug 18 12:59:20.303890 2026] [security2:error] [pid 123784:tid 123994] [client 20.91.215.254:13397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/mini.php"] [unique_id "aoSBWGwDnJBNj2tDbYbeoQAAAEw"]
[Tue Aug 18 12:59:20.359934 2026] [security2:error] [pid 123784:tid 124022] [client 168.62.48.100:1127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBWGwDnJBNj2tDbYbeqwAAAGg"]
[Tue Aug 18 12:59:20.373412 2026] [authz_core:error] [pid 123784:tid 123802] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:20.373690 2026] [authz_core:error] [pid 123784:tid 123802] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:20.390575 2026] [security2:error] [pid 123784:tid 123939] [client 20.104.85.180:18783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/an.php"] [unique_id "aoSBWGwDnJBNj2tDbYberQAAABU"]
[Tue Aug 18 12:59:20.395764 2026] [security2:error] [pid 123784:tid 124044] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSBWGwDnJBNj2tDbYbergAAAH4"]
[Tue Aug 18 12:59:20.414569 2026] [security2:error] [pid 123784:tid 124005] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/ws77.php"] [unique_id "aoSBWGwDnJBNj2tDbYbesAAAAFc"]
[Tue Aug 18 12:59:20.450353 2026] [security2:error] [pid 123784:tid 123954] [client 20.25.139.174:4507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/ws83.php"] [unique_id "aoSBWGwDnJBNj2tDbYbesQAAACQ"]
[Tue Aug 18 12:59:20.500045 2026] [security2:error] [pid 123784:tid 124003] [client 172.202.39.151:40381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/222.php"] [unique_id "aoSBWGwDnJBNj2tDbYbeswAAAFU"]
[Tue Aug 18 12:59:20.535884 2026] [security2:error] [pid 123784:tid 123966] [client 213.35.127.232:61643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBWGwDnJBNj2tDbYbetQAAADA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:20.544181 2026] [security2:error] [pid 123784:tid 124029] [client 20.203.138.185:11104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/file52.php"] [unique_id "aoSBWGwDnJBNj2tDbYbetgAAAG8"]
[Tue Aug 18 12:59:20.602578 2026] [security2:error] [pid 123784:tid 124004] [client 168.62.48.100:1106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/images/security.php"] [unique_id "aoSBWGwDnJBNj2tDbYbeuwAAAFY"]
[Tue Aug 18 12:59:20.613140 2026] [security2:error] [pid 123784:tid 123971] [client 213.202.253.4:57984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/gdftps.php"] [unique_id "aoSBWGwDnJBNj2tDbYbevQAAADU"], referer: www.google.com
[Tue Aug 18 12:59:20.614186 2026] [security2:error] [pid 123784:tid 123958] [client 158.23.17.4:14048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/34.php"] [unique_id "aoSBWGwDnJBNj2tDbYbevgAAACg"]
[Tue Aug 18 12:59:20.619832 2026] [security2:error] [pid 123784:tid 123937] [client 158.23.17.4:33466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/30.php"] [unique_id "aoSBWGwDnJBNj2tDbYbevwAAABM"]
[Tue Aug 18 12:59:20.642005 2026] [security2:error] [pid 123784:tid 123969] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBWGwDnJBNj2tDbYbewQAAADM"]
[Tue Aug 18 12:59:20.677897 2026] [authz_core:error] [pid 123784:tid 123815] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:20.678370 2026] [authz_core:error] [pid 123784:tid 123815] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:20.699614 2026] [autoindex:error] [pid 123784:tid 124034] [client 4.232.94.69:46050] AH01276: Cannot serve directory /home2/vfunnelcrmcom/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:20.715508 2026] [security2:error] [pid 123784:tid 123918] [client 40.74.65.169:42478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/222.php"] [unique_id "aoSBWGwDnJBNj2tDbYbeygAAAAA"]
[Tue Aug 18 12:59:20.715544 2026] [security2:error] [pid 123784:tid 124002] [client 132.196.30.78:14977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/xleet.php"] [unique_id "aoSBWGwDnJBNj2tDbYbeywAAAFQ"]
[Tue Aug 18 12:59:20.718420 2026] [security2:error] [pid 123784:tid 123923] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/read.php"] [unique_id "aoSBWGwDnJBNj2tDbYbezAAAAAU"]
[Tue Aug 18 12:59:20.738249 2026] [security2:error] [pid 123784:tid 123987] [client 52.173.121.69:50211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBWGwDnJBNj2tDbYbezgAAAEU"]
[Tue Aug 18 12:59:20.747122 2026] [security2:error] [pid 123784:tid 123944] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/nwwha.php"] [unique_id "aoSBWGwDnJBNj2tDbYbezwAAABo"]
[Tue Aug 18 12:59:20.759514 2026] [security2:error] [pid 123784:tid 123952] [client 20.25.139.174:4709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/h.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe0AAAACI"]
[Tue Aug 18 12:59:20.771030 2026] [security2:error] [pid 123784:tid 123949] [client 68.155.154.236:27541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/weozh.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe0wAAAB8"]
[Tue Aug 18 12:59:20.793430 2026] [security2:error] [pid 123784:tid 123970] [client 74.248.18.37:32112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/link-add.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe1AAAADQ"]
[Tue Aug 18 12:59:20.862257 2026] [security2:error] [pid 123784:tid 124006] [client 20.251.48.93:53208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/av.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe2AAAAFg"]
[Tue Aug 18 12:59:20.874630 2026] [security2:error] [pid 123784:tid 123974] [client 132.196.30.78:15013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe2gAAADg"]
[Tue Aug 18 12:59:20.909453 2026] [security2:error] [pid 123784:tid 124042] [client 4.232.94.69:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/o.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe3gAAAHw"]
[Tue Aug 18 12:59:20.926068 2026] [security2:error] [pid 123784:tid 123977] [client 20.38.3.247:8683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe3wAAADs"]
[Tue Aug 18 12:59:20.962363 2026] [security2:error] [pid 123784:tid 123956] [client 20.25.139.174:4613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/atex1.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe4gAAACY"]
[Tue Aug 18 12:59:20.966095 2026] [security2:error] [pid 123784:tid 124045] [client 20.91.215.254:13379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/mm.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe4wAAAH8"]
[Tue Aug 18 12:59:20.980765 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:20.981216 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:20.985147 2026] [security2:error] [pid 123784:tid 123997] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe5QAAAE8"]
[Tue Aug 18 12:59:20.997845 2026] [security2:error] [pid 123784:tid 124012] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/albin.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe5gAAAF4"]
[Tue Aug 18 12:59:21.071679 2026] [security2:error] [pid 123784:tid 124013] [client 66.187.6.102:57720] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/secrets.json"] [unique_id "aoSBWWwDnJBNj2tDbYbe6gAAAF8"]
[Tue Aug 18 12:59:21.095367 2026] [security2:error] [pid 123784:tid 123946] [client 52.173.121.69:27879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBWWwDnJBNj2tDbYbe6wAAABw"]
[Tue Aug 18 12:59:21.098116 2026] [security2:error] [pid 123784:tid 124009] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/opsqt.php"] [unique_id "aoSBWWwDnJBNj2tDbYbe7AAAAFs"]
[Tue Aug 18 12:59:21.218040 2026] [security2:error] [pid 123784:tid 123953] [client 20.203.138.185:25123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/sxdfrt.php"] [unique_id "aoSBWWwDnJBNj2tDbYbe9AAAACM"]
[Tue Aug 18 12:59:21.286860 2026] [security2:error] [pid 123784:tid 123954] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/fw/34.php"] [unique_id "aoSBWWwDnJBNj2tDbYbe9wAAACQ"]
[Tue Aug 18 12:59:21.310784 2026] [security2:error] [pid 123784:tid 124003] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBWWwDnJBNj2tDbYbe-AAAAFU"]
[Tue Aug 18 12:59:21.321068 2026] [security2:error] [pid 123784:tid 123984] [client 20.25.139.174:4594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBWWwDnJBNj2tDbYbe-wAAAEI"]
[Tue Aug 18 12:59:21.338085 2026] [security2:error] [pid 123784:tid 124020] [client 20.250.13.23:56547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBWWwDnJBNj2tDbYbe_AAAAGY"]
[Tue Aug 18 12:59:21.341167 2026] [security2:error] [pid 123784:tid 123986] [client 172.182.200.96:7545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/well-known/index.php"] [unique_id "aoSBWWwDnJBNj2tDbYbe_QAAAEQ"]
[Tue Aug 18 12:59:21.390448 2026] [security2:error] [pid 123784:tid 123991] [client 20.104.85.180:20248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/404.php"] [unique_id "aoSBWWwDnJBNj2tDbYbe_gAAAEk"]
[Tue Aug 18 12:59:21.397011 2026] [security2:error] [pid 123784:tid 123936] [client 158.23.17.4:62986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/he.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfAAAAABI"]
[Tue Aug 18 12:59:21.416636 2026] [security2:error] [pid 123784:tid 123971] [client 40.74.65.169:43039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfAgAAADU"]
[Tue Aug 18 12:59:21.426838 2026] [security2:error] [pid 123784:tid 123937] [client 158.23.17.4:20204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/pu.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfAwAAABM"]
[Tue Aug 18 12:59:21.460011 2026] [security2:error] [pid 123784:tid 124007] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/jvcpa.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfBQAAAFk"]
[Tue Aug 18 12:59:21.489812 2026] [security2:error] [pid 123784:tid 124043] [client 20.25.139.174:4684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfCAAAAH0"]
[Tue Aug 18 12:59:21.516193 2026] [security2:error] [pid 123784:tid 124034] [client 51.195.183.37:41748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "padariaeconfeitariabrasil.com.br"] [uri "/robots.txt"] [unique_id "aoSBWWwDnJBNj2tDbYbfCwAAAHQ"]
[Tue Aug 18 12:59:21.516351 2026] [security2:error] [pid 123784:tid 124034] [client 51.195.183.37:41748] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "padariaeconfeitariabrasil.com.br"] [uri "/robots.txt"] [unique_id "aoSBWWwDnJBNj2tDbYbfCwAAAHQ"]
[Tue Aug 18 12:59:21.559890 2026] [security2:error] [pid 123784:tid 123939] [client 213.35.127.232:61853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfDQAAABU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:21.573800 2026] [security2:error] [pid 123784:tid 123949] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp9.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfEAAAAB8"]
[Tue Aug 18 12:59:21.580078 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:21.580340 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:21.594312 2026] [security2:error] [pid 123784:tid 123963] [client 52.173.121.69:42705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/images/security.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfEgAAAC0"]
[Tue Aug 18 12:59:21.600014 2026] [security2:error] [pid 123784:tid 123943] [client 20.91.215.254:10206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/modules/mod_footer.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfEwAAABk"]
[Tue Aug 18 12:59:21.627350 2026] [security2:error] [pid 123784:tid 124014] [client 196.12.128.158:62391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfFAAAAGA"]
[Tue Aug 18 12:59:21.627452 2026] [security2:error] [pid 123784:tid 124014] [client 196.12.128.158:62391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfFAAAAGA"]
[Tue Aug 18 12:59:21.628299 2026] [security2:error] [pid 123784:tid 124041] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/av.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfFQAAAHs"]
[Tue Aug 18 12:59:21.701066 2026] [security2:error] [pid 123784:tid 124002] [client 132.196.30.78:13639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfGwAAAFQ"]
[Tue Aug 18 12:59:21.737073 2026] [autoindex:error] [pid 123784:tid 124018] [client 198.235.24.25:64108] AH01276: Cannot serve directory /home1/activevaluecom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:21.774388 2026] [security2:error] [pid 123784:tid 124016] [client 20.100.169.31:12380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/zup.php73"] [unique_id "aoSBWWwDnJBNj2tDbYbfIQAAAGI"]
[Tue Aug 18 12:59:21.778860 2026] [security2:error] [pid 123784:tid 124012] [client 68.155.154.236:27533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/rymmm.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfIgAAAF4"]
[Tue Aug 18 12:59:21.801873 2026] [security2:error] [pid 123784:tid 123982] [client 74.248.18.37:32118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfJAAAAEA"]
[Tue Aug 18 12:59:21.814860 2026] [security2:error] [pid 123784:tid 124009] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfJQAAAFs"]
[Tue Aug 18 12:59:21.856664 2026] [security2:error] [pid 123784:tid 124028] [client 20.25.139.174:4583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/a7.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfJwAAAG4"]
[Tue Aug 18 12:59:21.859886 2026] [security2:error] [pid 123784:tid 123957] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/save.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfKgAAACc"]
[Tue Aug 18 12:59:21.874086 2026] [security2:error] [pid 123784:tid 123848] [remote 14.194.153.54:40684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.153.194.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fbenevides.com.br"] [uri "/wp-login.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfLQAAbzs"]
[Tue Aug 18 12:59:21.877737 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:21.877999 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:21.939393 2026] [security2:error] [pid 123784:tid 123950] [client 197.184.64.235:41949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfLgAAACA"]
[Tue Aug 18 12:59:21.944102 2026] [security2:error] [pid 123784:tid 123950] [client 197.184.64.235:41949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfLgAAACA"]
[Tue Aug 18 12:59:22.027299 2026] [security2:error] [pid 123784:tid 124044] [client 172.202.39.151:44561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/chosen.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfMgAAAH4"]
[Tue Aug 18 12:59:22.055417 2026] [security2:error] [pid 123784:tid 123994] [client 20.25.139.174:4691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/w.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfNAAAAEw"]
[Tue Aug 18 12:59:22.093061 2026] [security2:error] [pid 123784:tid 124008] [client 132.196.30.78:13641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/h.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfNQAAAFo"]
[Tue Aug 18 12:59:22.114334 2026] [security2:error] [pid 123784:tid 123935] [client 40.74.65.169:43047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfNgAAABE"]
[Tue Aug 18 12:59:22.151007 2026] [security2:error] [pid 123784:tid 123998] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfOAAAAFA"]
[Tue Aug 18 12:59:22.171314 2026] [security2:error] [pid 123784:tid 123984] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfOgAAAEI"]
[Tue Aug 18 12:59:22.183498 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:22.183784 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:22.193101 2026] [security2:error] [pid 123784:tid 123942] [client 66.187.6.102:57708] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/serviceAccountKey.json"] [unique_id "aoSBWmwDnJBNj2tDbYbfPQAAABg"]
[Tue Aug 18 12:59:22.193655 2026] [security2:error] [pid 123784:tid 124019] [client 158.23.17.4:56563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/gz.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfPgAAAGU"]
[Tue Aug 18 12:59:22.225877 2026] [security2:error] [pid 123784:tid 123989] [client 20.203.138.185:10483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/path.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfQQAAAEc"]
[Tue Aug 18 12:59:22.236825 2026] [security2:error] [pid 123784:tid 123936] [client 20.38.3.247:64066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/yj09.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfQgAAABI"]
[Tue Aug 18 12:59:22.237683 2026] [security2:error] [pid 123784:tid 123978] [client 20.91.215.254:13394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/moon.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfQwAAADw"]
[Tue Aug 18 12:59:22.327090 2026] [security2:error] [pid 123784:tid 123918] [client 68.155.154.236:25369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/lddxs.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfRwAAAAA"]
[Tue Aug 18 12:59:22.394197 2026] [security2:error] [pid 123784:tid 124023] [client 20.25.139.174:4539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/manager.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfSgAAAGk"]
[Tue Aug 18 12:59:22.404139 2026] [security2:error] [pid 123784:tid 124022] [client 4.232.94.69:21133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/theme.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfSwAAAGg"]
[Tue Aug 18 12:59:22.432732 2026] [security2:error] [pid 123784:tid 123980] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfTgAAAD4"]
[Tue Aug 18 12:59:22.458970 2026] [security2:error] [pid 123784:tid 123992] [client 20.251.48.93:53315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/images.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfUAAAAEo"]
[Tue Aug 18 12:59:22.479419 2026] [security2:error] [pid 123784:tid 123963] [client 20.104.85.180:29096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-login.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfUgAAAC0"]
[Tue Aug 18 12:59:22.482376 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:22.482585 2026] [security2:error] [pid 123784:tid 123975] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/images.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfUwAAADk"]
[Tue Aug 18 12:59:22.482642 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:22.515115 2026] [security2:error] [pid 123784:tid 123977] [client 157.51.166.53:56079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfVQAAADs"]
[Tue Aug 18 12:59:22.516311 2026] [security2:error] [pid 123784:tid 123977] [client 157.51.166.53:56079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfVQAAADs"]
[Tue Aug 18 12:59:22.541545 2026] [security2:error] [pid 123784:tid 124014] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfVwAAAGA"]
[Tue Aug 18 12:59:22.541668 2026] [security2:error] [pid 123784:tid 124043] [client 74.248.18.37:7806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfVgAAAH0"]
[Tue Aug 18 12:59:22.575024 2026] [security2:error] [pid 123784:tid 124004] [client 213.35.127.232:62065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfWgAAAFY"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:22.606981 2026] [security2:error] [pid 123784:tid 123939] [client 20.25.139.174:4672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/archive.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfXQAAABU"]
[Tue Aug 18 12:59:22.634080 2026] [security2:error] [pid 123784:tid 123948] [client 68.221.73.131:40330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/sf.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfXgAAAB4"]
[Tue Aug 18 12:59:22.638322 2026] [security2:error] [pid 123784:tid 124002] [client 158.23.17.4:8941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ry.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfXwAAAFQ"]
[Tue Aug 18 12:59:22.660330 2026] [security2:error] [pid 123784:tid 123920] [client 132.196.30.78:13674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/155.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfYAAAAAI"]
[Tue Aug 18 12:59:22.677096 2026] [security2:error] [pid 123784:tid 123997] [client 66.187.6.102:57702] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/.docker/config.json"] [unique_id "aoSBWmwDnJBNj2tDbYbfYQAAAE8"]
[Tue Aug 18 12:59:22.713377 2026] [security2:error] [pid 123784:tid 123981] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/df.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfZQAAAD8"]
[Tue Aug 18 12:59:22.752736 2026] [security2:error] [pid 123784:tid 123969] [client 20.100.169.31:12624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/k.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfZwAAADM"]
[Tue Aug 18 12:59:22.795428 2026] [security2:error] [pid 123784:tid 124029] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/ops.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfbAAAAG8"]
[Tue Aug 18 12:59:22.801859 2026] [security2:error] [pid 123784:tid 124011] [client 132.196.30.78:14987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfbQAAAF0"]
[Tue Aug 18 12:59:22.912955 2026] [security2:error] [pid 123784:tid 123953] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfcAAAACM"]
[Tue Aug 18 12:59:22.927657 2026] [security2:error] [pid 123784:tid 123938] [client 20.91.215.254:10215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/n.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfcgAAABQ"]
[Tue Aug 18 12:59:22.948970 2026] [security2:error] [pid 123784:tid 124008] [client 54.39.136.223:55818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "padariaeconfeitariabrasil.com.br"] [uri "/"] [unique_id "aoSBWmwDnJBNj2tDbYbfcwAAAFo"]
[Tue Aug 18 12:59:22.949064 2026] [security2:error] [pid 123784:tid 124008] [client 54.39.136.223:55818] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "padariaeconfeitariabrasil.com.br"] [uri "/"] [unique_id "aoSBWmwDnJBNj2tDbYbfcwAAAFo"]
[Tue Aug 18 12:59:22.960945 2026] [security2:error] [pid 123784:tid 123990] [client 20.25.139.174:4611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/w1.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfdgAAAEg"]
[Tue Aug 18 12:59:23.035995 2026] [security2:error] [pid 123784:tid 123951] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfewAAACE"]
[Tue Aug 18 12:59:23.084787 2026] [security2:error] [pid 123784:tid 123991] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/coffexium.php"] [unique_id "aoSBW2wDnJBNj2tDbYbffgAAAEk"]
[Tue Aug 18 12:59:23.111046 2026] [security2:error] [pid 123784:tid 123978] [client 20.104.85.180:13070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfgQAAADw"]
[Tue Aug 18 12:59:23.125756 2026] [security2:error] [pid 123784:tid 123935] [client 20.25.139.174:4687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/bless.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfggAAABE"]
[Tue Aug 18 12:59:23.135632 2026] [security2:error] [pid 123784:tid 123955] [client 158.23.17.4:14077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/nf.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfhAAAACU"]
[Tue Aug 18 12:59:23.178698 2026] [autoindex:error] [pid 123784:tid 123871] [remote 23.80.142.158:59948] AH01276: Cannot serve directory /home3/bergon98/contabiltax.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:23.238224 2026] [security2:error] [pid 123784:tid 124003] [client 74.248.18.37:7790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/maint/wpxml.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfiQAAAFU"]
[Tue Aug 18 12:59:23.278127 2026] [security2:error] [pid 123784:tid 123998] [client 132.196.30.78:22157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/96i.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfigAAAFA"]
[Tue Aug 18 12:59:23.280330 2026] [security2:error] [pid 123784:tid 123952] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfiwAAACI"]
[Tue Aug 18 12:59:23.301836 2026] [security2:error] [pid 123784:tid 123885] [remote 162.214.205.212:44812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ezycolor.com.br"] [uri "/wp-login.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfjQAAbWA"]
[Tue Aug 18 12:59:23.314186 2026] [security2:error] [pid 123784:tid 124038] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/usr.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfjgAAAHg"]
[Tue Aug 18 12:59:23.404928 2026] [security2:error] [pid 123784:tid 123892] [remote 162.214.205.212:44818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michelepamela.com.br"] [uri "/wp-login.php"] [unique_id "aoSBW2wDnJBNj2tDbYbflAAARWc"]
[Tue Aug 18 12:59:23.412924 2026] [security2:error] [pid 123784:tid 123939] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBW2wDnJBNj2tDbYbflgAAABU"]
[Tue Aug 18 12:59:23.415107 2026] [security2:error] [pid 123784:tid 123941] [client 132.196.30.78:13640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/a7.php"] [unique_id "aoSBW2wDnJBNj2tDbYbflwAAABc"]
[Tue Aug 18 12:59:23.428712 2026] [security2:error] [pid 123784:tid 124042] [client 20.251.48.93:57515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/ops.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfmgAAAHw"]
[Tue Aug 18 12:59:23.449588 2026] [security2:error] [pid 123784:tid 123924] [client 20.203.138.185:24955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wpo.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfmwAAAAY"]
[Tue Aug 18 12:59:23.471063 2026] [security2:error] [pid 123784:tid 124045] [client 40.74.65.169:20344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfnAAAAH8"]
[Tue Aug 18 12:59:23.485729 2026] [security2:error] [pid 123784:tid 123988] [client 68.155.154.236:27524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/zjggu.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfnQAAAEY"]
[Tue Aug 18 12:59:23.545141 2026] [autoindex:error] [pid 123784:tid 124006] [client 20.25.139.174:4482] AH01276: Cannot serve directory /home3/cadema/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:23.560457 2026] [security2:error] [pid 123784:tid 123932] [client 20.91.215.254:13418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/nc4.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfoQAAAA4"]
[Tue Aug 18 12:59:23.563409 2026] [security2:error] [pid 123784:tid 123894] [remote 156.59.198.135:36672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mempel.com.br"] [uri "/wp-content/uploads/2023/01/work-pdf.pdf"] [unique_id "aoSBW2wDnJBNj2tDbYbfogAAKmk"]
[Tue Aug 18 12:59:23.570545 2026] [security2:error] [pid 123784:tid 123933] [client 158.23.17.4:7225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/xv.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfowAAAA8"]
[Tue Aug 18 12:59:23.597976 2026] [security2:error] [pid 123784:tid 123967] [client 213.35.127.232:62292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfpgAAADE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:23.617800 2026] [security2:error] [pid 123784:tid 123983] [client 66.187.6.102:57692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.6.187.66.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pinceisroma.com.br"] [uri "/wp-config.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfpwAAAEE"]
[Tue Aug 18 12:59:23.631815 2026] [security2:error] [pid 123784:tid 123973] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfqAAAADc"]
[Tue Aug 18 12:59:23.636790 2026] [access_compat:error] [pid 123784:tid 124010] [client 52.167.144.64:39768] AH01797: client denied by server configuration: /home2/maxxbox/public_html/robots.txt
[Tue Aug 18 12:59:23.642013 2026] [security2:error] [pid 123784:tid 123963] [client 20.100.169.31:28413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfqgAAAC0"]
[Tue Aug 18 12:59:23.647647 2026] [security2:error] [pid 123784:tid 124040] [client 86.120.159.145:62836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfqwAAAHo"]
[Tue Aug 18 12:59:23.648095 2026] [security2:error] [pid 123784:tid 124040] [client 86.120.159.145:62836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfqwAAAHo"]
[Tue Aug 18 12:59:23.685117 2026] [authz_core:error] [pid 123784:tid 123906] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:23.685387 2026] [authz_core:error] [pid 123784:tid 123906] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:23.706074 2026] [security2:error] [pid 123784:tid 123982] [client 20.25.139.174:4547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/sagax1.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfsgAAAEA"]
[Tue Aug 18 12:59:23.708133 2026] [security2:error] [pid 123784:tid 123953] [client 20.25.139.174:4482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-login.php"] [unique_id "aoSBW2wDnJBNj2tDbYbftQAAACM"]
[Tue Aug 18 12:59:23.741971 2026] [security2:error] [pid 123784:tid 124008] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/sf.php"] [unique_id "aoSBW2wDnJBNj2tDbYbftgAAAFo"]
[Tue Aug 18 12:59:23.765068 2026] [security2:error] [pid 123784:tid 123954] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSBW2wDnJBNj2tDbYbftwAAACQ"]
[Tue Aug 18 12:59:23.767955 2026] [security2:error] [pid 123784:tid 123931] [client 158.23.17.4:34003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/pm.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfuAAAAA0"]
[Tue Aug 18 12:59:23.845445 2026] [security2:error] [pid 123784:tid 123965] [client 66.187.6.102:57684] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "pinceisroma.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSBW2wDnJBNj2tDbYbfvQAAAC8"]
[Tue Aug 18 12:59:23.860125 2026] [security2:error] [pid 123784:tid 123976] [client 20.127.136.245:28503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/inputs.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfvgAAADo"]
[Tue Aug 18 12:59:23.872924 2026] [security2:error] [pid 123784:tid 123989] [client 68.155.154.236:27551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/dlvqo.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfwAAAAEc"]
[Tue Aug 18 12:59:23.946601 2026] [security2:error] [pid 123784:tid 123937] [client 20.38.3.247:61970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/scxy.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfwQAAABM"]
[Tue Aug 18 12:59:23.992122 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:23.992415 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:24.006513 2026] [security2:error] [pid 123784:tid 124023] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSBXGwDnJBNj2tDbYbfxAAAAGk"]
[Tue Aug 18 12:59:24.015860 2026] [security2:error] [pid 123784:tid 123994] [client 132.196.30.78:14981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/as.php"] [unique_id "aoSBXGwDnJBNj2tDbYbfxQAAAEw"]
[Tue Aug 18 12:59:24.062890 2026] [security2:error] [pid 123784:tid 123923] [client 192.141.172.134:53953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXGwDnJBNj2tDbYbfzAAAAAU"]
[Tue Aug 18 12:59:24.062999 2026] [security2:error] [pid 123784:tid 123923] [client 192.141.172.134:53953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXGwDnJBNj2tDbYbfzAAAAAU"]
[Tue Aug 18 12:59:24.064306 2026] [security2:error] [pid 123784:tid 123945] [client 4.232.94.69:46031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSBXGwDnJBNj2tDbYbfzQAAABs"]
[Tue Aug 18 12:59:24.077336 2026] [security2:error] [pid 123784:tid 123975] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/k.php"] [unique_id "aoSBXGwDnJBNj2tDbYbfzgAAADk"]
[Tue Aug 18 12:59:24.103995 2026] [security2:error] [pid 123784:tid 123978] [client 132.196.30.78:14598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/manager.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf0AAAADw"]
[Tue Aug 18 12:59:24.107821 2026] [security2:error] [pid 123784:tid 123935] [client 74.248.18.37:7783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/maintenance.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf0QAAABE"]
[Tue Aug 18 12:59:24.163331 2026] [security2:error] [pid 123784:tid 124004] [client 20.38.3.247:60320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/mac.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf0wAAAFY"]
[Tue Aug 18 12:59:24.168497 2026] [security2:error] [pid 123784:tid 123987] [client 40.74.65.169:38809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/i.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf1AAAAEU"]
[Tue Aug 18 12:59:24.186258 2026] [security2:error] [pid 123784:tid 124042] [client 20.203.138.185:10670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/a1vx.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf1QAAAHw"]
[Tue Aug 18 12:59:24.217344 2026] [security2:error] [pid 123784:tid 124025] [client 20.25.139.174:4694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/default.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf1wAAAGs"]
[Tue Aug 18 12:59:24.222740 2026] [security2:error] [pid 123784:tid 123944] [client 20.91.215.254:10188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/new.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf2AAAABo"]
[Tue Aug 18 12:59:24.226788 2026] [security2:error] [pid 123784:tid 124027] [client 20.25.139.174:4569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wpc.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf2QAAAG0"]
[Tue Aug 18 12:59:24.276911 2026] [security2:error] [pid 123784:tid 124012] [client 158.23.17.4:47654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/mx.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf3wAAAF4"]
[Tue Aug 18 12:59:24.287616 2026] [authz_core:error] [pid 123784:tid 123869] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:24.287902 2026] [authz_core:error] [pid 123784:tid 123869] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:24.303287 2026] [security2:error] [pid 123784:tid 123941] [client 20.127.136.245:28090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/admin.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf4gAAABc"]
[Tue Aug 18 12:59:24.372136 2026] [security2:error] [pid 123784:tid 123928] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf5AAAAAo"]
[Tue Aug 18 12:59:24.387623 2026] [security2:error] [pid 123784:tid 124006] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/css/database.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf5QAAAFg"]
[Tue Aug 18 12:59:24.389040 2026] [security2:error] [pid 123784:tid 123929] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/82.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf5gAAAAs"]
[Tue Aug 18 12:59:24.413119 2026] [security2:error] [pid 123784:tid 123957] [client 68.155.154.236:27525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/pkmoj.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf6gAAACc"]
[Tue Aug 18 12:59:24.471266 2026] [security2:error] [pid 123784:tid 123796] [remote 103.56.163.133:58862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amp.adv.br"] [uri "/wp-login.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf6wAAEAc"]
[Tue Aug 18 12:59:24.475561 2026] [security2:error] [pid 123784:tid 124024] [client 20.104.85.180:28648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wso.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf7AAAAGo"]
[Tue Aug 18 12:59:24.503466 2026] [security2:error] [pid 123784:tid 123922] [client 20.251.48.93:9932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/coffexium.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf7QAAAAQ"]
[Tue Aug 18 12:59:24.562980 2026] [security2:error] [pid 123784:tid 123993] [client 20.215.241.237:43698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/chosen.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf8AAAAEs"]
[Tue Aug 18 12:59:24.589552 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:24.589869 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:24.613864 2026] [security2:error] [pid 123784:tid 123999] [client 213.35.127.232:62487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf9QAAAFE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:24.669948 2026] [security2:error] [pid 123784:tid 123965] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/privdayz.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf9wAAAC8"]
[Tue Aug 18 12:59:24.679442 2026] [security2:error] [pid 123784:tid 123971] [client 132.196.30.78:13653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/w1.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf-AAAADU"]
[Tue Aug 18 12:59:24.685886 2026] [security2:error] [pid 123784:tid 123942] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/dex.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf-gAAABg"]
[Tue Aug 18 12:59:24.733899 2026] [security2:error] [pid 123784:tid 123936] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf_AAAABI"]
[Tue Aug 18 12:59:24.787004 2026] [security2:error] [pid 123784:tid 124026] [client 20.25.139.174:4703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/i.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgAgAAAGw"]
[Tue Aug 18 12:59:24.788596 2026] [security2:error] [pid 123784:tid 124017] [client 20.25.139.174:4670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/fone1.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgAwAAAGM"]
[Tue Aug 18 12:59:24.802127 2026] [security2:error] [pid 123784:tid 124029] [client 20.51.153.15:7285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgBAAAAG8"]
[Tue Aug 18 12:59:24.874961 2026] [security2:error] [pid 123784:tid 124015] [client 20.127.136.245:28049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/goods.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgBwAAAGE"]
[Tue Aug 18 12:59:24.878805 2026] [security2:error] [pid 123784:tid 123968] [client 132.196.30.78:14978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/min.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgCAAAADI"]
[Tue Aug 18 12:59:24.880082 2026] [security2:error] [pid 123784:tid 123949] [client 40.74.65.169:20400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/abcd.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgCgAAAB8"]
[Tue Aug 18 12:59:24.881595 2026] [security2:error] [pid 123784:tid 124044] [client 20.91.215.254:10200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/packed.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgCwAAAH4"]
[Tue Aug 18 12:59:24.966374 2026] [security2:error] [pid 123784:tid 123927] [client 74.248.18.37:7786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/network/about.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgDwAAAAk"]
[Tue Aug 18 12:59:24.971621 2026] [security2:error] [pid 123784:tid 124042] [client 20.38.3.247:34994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgEAAAAHw"]
[Tue Aug 18 12:59:24.984970 2026] [security2:error] [pid 123784:tid 124032] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/puc.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgEQAAAHI"]
[Tue Aug 18 12:59:25.004199 2026] [security2:error] [pid 123784:tid 124018] [client 20.203.138.185:25494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ty.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgFQAAAGQ"]
[Tue Aug 18 12:59:25.004259 2026] [security2:error] [pid 123784:tid 124025] [client 158.23.17.4:32532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/dr.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgFAAAAGs"]
[Tue Aug 18 12:59:25.036991 2026] [security2:error] [pid 123784:tid 124027] [client 20.51.153.15:7275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgFwAAAG0"]
[Tue Aug 18 12:59:25.074088 2026] [security2:error] [pid 123784:tid 124033] [client 20.250.13.23:7291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/info.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgGgAAAHM"]
[Tue Aug 18 12:59:25.099078 2026] [security2:error] [pid 123784:tid 123974] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgHAAAADg"]
[Tue Aug 18 12:59:25.113746 2026] [security2:error] [pid 123784:tid 123946] [client 158.23.17.4:47677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/45.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgHQAAABw"]
[Tue Aug 18 12:59:25.191079 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:25.191358 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:25.199760 2026] [security2:error] [pid 123784:tid 123929] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wg459o.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgIwAAAAs"]
[Tue Aug 18 12:59:25.200766 2026] [security2:error] [pid 123784:tid 124002] [client 79.127.164.8:41938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/tables.bak"] [unique_id "aoSBXWwDnJBNj2tDbYbgIgAAAFQ"], referer: https://medihub.com.br/tables.bak
[Tue Aug 18 12:59:25.202482 2026] [security2:error] [pid 123784:tid 124034] [client 68.221.73.131:51713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/k.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgJQAAAHQ"]
[Tue Aug 18 12:59:25.296705 2026] [security2:error] [pid 123784:tid 123972] [client 68.155.154.236:27550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/kopyw.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgKQAAADY"]
[Tue Aug 18 12:59:25.317619 2026] [security2:error] [pid 123784:tid 123925] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/inso.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgKgAAAAc"]
[Tue Aug 18 12:59:25.340252 2026] [security2:error] [pid 123784:tid 124006] [client 20.127.136.245:28077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/file.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgLQAAAFg"]
[Tue Aug 18 12:59:25.352657 2026] [security2:error] [pid 123784:tid 124005] [client 20.51.153.15:7243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/dirs.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgMAAAAFc"]
[Tue Aug 18 12:59:25.371569 2026] [security2:error] [pid 123784:tid 123954] [client 20.104.85.180:52586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/sf.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgMQAAACQ"]
[Tue Aug 18 12:59:25.379164 2026] [security2:error] [pid 123784:tid 123931] [client 172.202.39.151:44518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/info.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgMgAAAA0"]
[Tue Aug 18 12:59:25.424479 2026] [security2:error] [pid 123784:tid 123956] [client 20.25.139.174:4705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/ncx.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgNAAAACY"]
[Tue Aug 18 12:59:25.436977 2026] [autoindex:error] [pid 123784:tid 123981] [client 20.25.139.174:4505] AH01276: Cannot serve directory /home3/cadema/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:25.443550 2026] [autoindex:error] [pid 123784:tid 124009] [client 132.196.30.78:14983] AH01276: Cannot serve directory /home3/cadema/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:25.458689 2026] [security2:error] [pid 123784:tid 124035] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgOAAAAHU"]
[Tue Aug 18 12:59:25.494685 2026] [authz_core:error] [pid 123784:tid 123878] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:25.495133 2026] [authz_core:error] [pid 123784:tid 123878] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:25.566214 2026] [security2:error] [pid 123784:tid 124017] [client 40.74.65.169:19515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-manager.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgQQAAAGM"]
[Tue Aug 18 12:59:25.591912 2026] [security2:error] [pid 123784:tid 123979] [client 132.196.30.78:14983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-login.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgRAAAAD0"]
[Tue Aug 18 12:59:25.624173 2026] [security2:error] [pid 123784:tid 123998] [client 20.38.3.247:35136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgRwAAAFA"]
[Tue Aug 18 12:59:25.626000 2026] [security2:error] [pid 123784:tid 123921] [client 20.25.139.174:4505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgSAAAAAM"]
[Tue Aug 18 12:59:25.631797 2026] [security2:error] [pid 123784:tid 123992] [client 213.35.127.232:62744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgSQAAAEo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:25.638186 2026] [security2:error] [pid 123784:tid 124015] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/aa.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgSgAAAGE"]
[Tue Aug 18 12:59:25.682997 2026] [security2:error] [pid 123784:tid 123968] [client 20.51.153.15:7252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/fresh.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgSwAAADI"]
[Tue Aug 18 12:59:25.699332 2026] [security2:error] [pid 123784:tid 124003] [client 66.187.6.102:51564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/api/v1/settings"] [unique_id "aoSBXWwDnJBNj2tDbYbgTwAAAFU"]
[Tue Aug 18 12:59:25.699451 2026] [security2:error] [pid 123784:tid 124003] [client 66.187.6.102:51564] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/api/v1/settings"] [unique_id "aoSBXWwDnJBNj2tDbYbgTwAAAFU"]
[Tue Aug 18 12:59:25.713041 2026] [security2:error] [pid 123784:tid 123971] [client 74.248.18.37:7605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgUAAAADU"]
[Tue Aug 18 12:59:25.718441 2026] [security2:error] [pid 123784:tid 123975] [client 68.155.154.236:27552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/zznmg.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgUQAAADk"]
[Tue Aug 18 12:59:25.723912 2026] [security2:error] [pid 123784:tid 124038] [client 20.91.215.254:10187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/plugin.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgUgAAAHg"]
[Tue Aug 18 12:59:25.745229 2026] [security2:error] [pid 123784:tid 124001] [client 20.203.138.185:25498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/vgtyu.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgUwAAAFM"]
[Tue Aug 18 12:59:25.802791 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:25.803361 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:25.808166 2026] [authz_core:error] [pid 123784:tid 123828] [remote 57.141.22.120:48344] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:25.808436 2026] [authz_core:error] [pid 123784:tid 123828] [remote 57.141.22.120:48344] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:25.822166 2026] [security2:error] [pid 123784:tid 124036] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgWQAAAHY"]
[Tue Aug 18 12:59:25.844228 2026] [security2:error] [pid 123784:tid 124012] [client 158.23.17.4:57253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ts.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgWwAAAF4"]
[Tue Aug 18 12:59:25.894874 2026] [security2:error] [pid 123784:tid 123983] [client 37.40.227.74:57196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgXwAAAEE"]
[Tue Aug 18 12:59:25.899123 2026] [security2:error] [pid 123784:tid 123983] [client 37.40.227.74:57196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgXwAAAEE"]
[Tue Aug 18 12:59:25.922799 2026] [security2:error] [pid 123784:tid 123987] [client 20.127.136.245:28065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/adminfuns.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgYAAAAEU"]
[Tue Aug 18 12:59:25.929189 2026] [security2:error] [pid 123784:tid 123988] [client 66.187.6.102:51566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/openapi.json"] [unique_id "aoSBXWwDnJBNj2tDbYbgYQAAAEY"]
[Tue Aug 18 12:59:25.929274 2026] [security2:error] [pid 123784:tid 123988] [client 66.187.6.102:51566] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/openapi.json"] [unique_id "aoSBXWwDnJBNj2tDbYbgYQAAAEY"]
[Tue Aug 18 12:59:25.957676 2026] [security2:error] [pid 123784:tid 124011] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/img.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgYgAAAF0"]
[Tue Aug 18 12:59:25.962940 2026] [security2:error] [pid 123784:tid 123929] [client 158.23.17.4:40413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/wy.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgZAAAAAs"]
[Tue Aug 18 12:59:25.965211 2026] [security2:error] [pid 123784:tid 124034] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/mifta.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgZQAAAHQ"]
[Tue Aug 18 12:59:25.978064 2026] [security2:error] [pid 123784:tid 123960] [client 20.51.153.15:7271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/admin404.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgZgAAACo"]
[Tue Aug 18 12:59:26.025260 2026] [security2:error] [pid 123784:tid 123920] [client 20.250.13.23:7232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/a.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgZwAAAAI"]
[Tue Aug 18 12:59:26.051519 2026] [security2:error] [pid 123784:tid 123941] [client 20.25.139.174:4529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgaAAAABc"]
[Tue Aug 18 12:59:26.098925 2026] [security2:error] [pid 123784:tid 123923] [client 172.182.200.96:14130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgbAAAAAU"]
[Tue Aug 18 12:59:26.099075 2026] [authz_core:error] [pid 123784:tid 123802] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:26.099535 2026] [authz_core:error] [pid 123784:tid 123802] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:26.187357 2026] [security2:error] [pid 123784:tid 123973] [client 20.25.139.174:4538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgcAAAADc"]
[Tue Aug 18 12:59:26.222513 2026] [security2:error] [pid 123784:tid 124002] [client 132.196.30.78:13675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/default.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgcQAAAFQ"]
[Tue Aug 18 12:59:26.228143 2026] [security2:error] [pid 123784:tid 124009] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgcgAAAFs"]
[Tue Aug 18 12:59:26.235306 2026] [security2:error] [pid 123784:tid 123919] [client 68.155.154.236:27576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/bhfnd.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgdAAAAAE"]
[Tue Aug 18 12:59:26.238947 2026] [security2:error] [pid 123784:tid 123980] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgdQAAAD4"]
[Tue Aug 18 12:59:26.241604 2026] [security2:error] [pid 123784:tid 124028] [client 132.196.30.78:14985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/php8.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgdgAAAG4"]
[Tue Aug 18 12:59:26.244020 2026] [security2:error] [pid 123784:tid 123967] [client 40.74.65.169:20363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgdwAAADE"]
[Tue Aug 18 12:59:26.259136 2026] [security2:error] [pid 123784:tid 123958] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/222.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgeAAAACg"]
[Tue Aug 18 12:59:26.276150 2026] [security2:error] [pid 123784:tid 124023] [client 103.120.71.157:62240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgegAAAGk"]
[Tue Aug 18 12:59:26.276340 2026] [security2:error] [pid 123784:tid 124023] [client 103.120.71.157:62240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgegAAAGk"]
[Tue Aug 18 12:59:26.293351 2026] [security2:error] [pid 123784:tid 124030] [client 103.184.169.37:42590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgewAAAHA"]
[Tue Aug 18 12:59:26.293525 2026] [security2:error] [pid 123784:tid 124030] [client 103.184.169.37:42590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgewAAAHA"]
[Tue Aug 18 12:59:26.294907 2026] [security2:error] [pid 123784:tid 123937] [client 20.38.3.247:64714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/blurbs.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgfAAAABM"]
[Tue Aug 18 12:59:26.305957 2026] [security2:error] [pid 123784:tid 124029] [client 20.51.153.15:7235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/loading.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgfgAAAG8"]
[Tue Aug 18 12:59:26.311798 2026] [security2:error] [pid 123784:tid 123976] [client 20.251.48.93:53328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgfwAAADo"]
[Tue Aug 18 12:59:26.325755 2026] [security2:error] [pid 123784:tid 124008] [client 4.232.94.69:21122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/bi.php"] [unique_id "aoSBXmwDnJBNj2tDbYbggQAAAFo"]
[Tue Aug 18 12:59:26.391322 2026] [security2:error] [pid 123784:tid 123955] [client 66.187.6.102:51568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/id_rsa"] [unique_id "aoSBXmwDnJBNj2tDbYbghgAAACU"]
[Tue Aug 18 12:59:26.410740 2026] [security2:error] [pid 123784:tid 123943] [client 20.127.136.245:28499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/404.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgjAAAABk"]
[Tue Aug 18 12:59:26.415155 2026] [security2:error] [pid 123784:tid 123945] [client 185.198.240.227:43905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mempel.com.br"] [uri "/wp-login.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgjQAAABs"]
[Tue Aug 18 12:59:26.430414 2026] [security2:error] [pid 123784:tid 123948] [client 216.244.66.243:36666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/buser777.cc-1/"] [unique_id "aoSBXmwDnJBNj2tDbYbglQAAAB4"]
[Tue Aug 18 12:59:26.430516 2026] [security2:error] [pid 123784:tid 123948] [client 216.244.66.243:36666] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/buser777.cc-1/"] [unique_id "aoSBXmwDnJBNj2tDbYbglQAAAB4"]
[Tue Aug 18 12:59:26.507100 2026] [security2:error] [pid 123784:tid 124036] [client 20.203.138.185:10665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/mans.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgmwAAAHY"]
[Tue Aug 18 12:59:26.521637 2026] [security2:error] [pid 123784:tid 123938] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/index2.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgngAAABQ"]
[Tue Aug 18 12:59:26.528792 2026] [security2:error] [pid 123784:tid 123994] [client 20.100.169.31:12656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/ww5.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgnwAAAEw"]
[Tue Aug 18 12:59:26.530556 2026] [security2:error] [pid 123784:tid 124033] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgmQAAcyw"]
[Tue Aug 18 12:59:26.540676 2026] [security2:error] [pid 123784:tid 124022] [client 74.248.18.37:7761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/options-privacy.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgoAAAAGg"]
[Tue Aug 18 12:59:26.543329 2026] [security2:error] [pid 123784:tid 124007] [client 20.51.153.15:7274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/conn-test.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgoQAAAFk"]
[Tue Aug 18 12:59:26.551874 2026] [security2:error] [pid 123784:tid 123952] [client 20.25.139.174:4625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wso.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgowAAACI"]
[Tue Aug 18 12:59:26.577249 2026] [security2:error] [pid 123784:tid 124034] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/key.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgpAAAAHQ"]
[Tue Aug 18 12:59:26.578560 2026] [security2:error] [pid 123784:tid 124013] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgpQAAAF8"]
[Tue Aug 18 12:59:26.599688 2026] [security2:error] [pid 123784:tid 123920] [client 20.91.215.254:10192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/public/moon.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgpgAAAAI"]
[Tue Aug 18 12:59:26.613544 2026] [security2:error] [pid 123784:tid 123941] [client 158.23.17.4:14039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/f.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgqAAAABc"]
[Tue Aug 18 12:59:26.647743 2026] [security2:error] [pid 123784:tid 123979] [client 213.35.127.232:62969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgqwAAAD0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:26.694321 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:26.694592 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:26.709067 2026] [security2:error] [pid 123784:tid 123981] [client 138.36.100.162:41486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgrwAAAD8"]
[Tue Aug 18 12:59:26.709183 2026] [security2:error] [pid 123784:tid 123981] [client 138.36.100.162:41486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgrwAAAD8"]
[Tue Aug 18 12:59:26.722415 2026] [security2:error] [pid 123784:tid 123988] [client 20.25.139.174:4697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgsAAAAEY"]
[Tue Aug 18 12:59:26.746405 2026] [security2:error] [pid 123784:tid 124006] [client 20.38.3.247:18857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/bajah.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgsgAAAFg"]
[Tue Aug 18 12:59:26.766677 2026] [security2:error] [pid 123784:tid 124044] [client 66.187.6.102:51568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/app/.git/HEAD"] [unique_id "aoSBXmwDnJBNj2tDbYbgswAAAH4"]
[Tue Aug 18 12:59:26.766793 2026] [security2:error] [pid 123784:tid 124044] [client 66.187.6.102:51568] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/app/.git/HEAD"] [unique_id "aoSBXmwDnJBNj2tDbYbgswAAAH4"]
[Tue Aug 18 12:59:26.794173 2026] [security2:error] [pid 123784:tid 123951] [client 149.34.210.141:49176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgtgAAACE"]
[Tue Aug 18 12:59:26.795079 2026] [security2:error] [pid 123784:tid 123926] [client 132.196.30.78:13693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgtwAAAAg"]
[Tue Aug 18 12:59:26.801863 2026] [security2:error] [pid 123784:tid 124017] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/8.php"] [unique_id "aoSBXmwDnJBNj2tDbYbguAAAAGM"]
[Tue Aug 18 12:59:26.807457 2026] [security2:error] [pid 123784:tid 123950] [client 132.196.30.78:13638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/i.php"] [unique_id "aoSBXmwDnJBNj2tDbYbguQAAACA"]
[Tue Aug 18 12:59:26.825221 2026] [security2:error] [pid 123784:tid 123985] [client 20.51.153.15:7173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/evil.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgugAAAEM"]
[Tue Aug 18 12:59:26.876627 2026] [security2:error] [pid 123784:tid 124015] [client 68.221.73.131:33164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/82.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgwAAAAGE"]
[Tue Aug 18 12:59:26.900105 2026] [security2:error] [pid 123784:tid 123953] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/chosen.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgwwAAACM"]
[Tue Aug 18 12:59:26.923706 2026] [security2:error] [pid 123784:tid 124009] [client 20.127.136.245:28500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wk/index.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgxAAAAFs"]
[Tue Aug 18 12:59:26.935928 2026] [security2:error] [pid 123784:tid 123940] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgxQAAABY"]
[Tue Aug 18 12:59:26.938913 2026] [security2:error] [pid 123784:tid 123943] [client 40.74.65.169:20364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgxgAAABk"]
[Tue Aug 18 12:59:26.996338 2026] [authz_core:error] [pid 123784:tid 123868] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:26.996610 2026] [authz_core:error] [pid 123784:tid 123868] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:27.056969 2026] [security2:error] [pid 123784:tid 123997] [client 68.155.154.236:27556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/qfvqu.php"] [unique_id "aoSBX2wDnJBNj2tDbYbgzwAAAE8"]
[Tue Aug 18 12:59:27.059257 2026] [security2:error] [pid 123784:tid 123951] [client 149.34.210.141:49176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgtgAAACE"]
[Tue Aug 18 12:59:27.087241 2026] [security2:error] [pid 123784:tid 123974] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/images.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg0AAAADg"]
[Tue Aug 18 12:59:27.098513 2026] [security2:error] [pid 123784:tid 123986] [client 20.25.139.174:4526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/zup.php73"] [unique_id "aoSBX2wDnJBNj2tDbYbg0gAAAEQ"]
[Tue Aug 18 12:59:27.126849 2026] [security2:error] [pid 123784:tid 124016] [client 20.51.153.15:7287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/wp-key.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg0wAAAGI"]
[Tue Aug 18 12:59:27.141652 2026] [security2:error] [pid 123784:tid 123987] [client 20.38.3.247:34974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/domvf.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg1AAAAEU"]
[Tue Aug 18 12:59:27.155308 2026] [security2:error] [pid 123784:tid 123918] [client 157.20.138.62:55786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg1wAAAAA"]
[Tue Aug 18 12:59:27.155431 2026] [security2:error] [pid 123784:tid 123918] [client 157.20.138.62:55786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg1wAAAAA"]
[Tue Aug 18 12:59:27.239341 2026] [security2:error] [pid 123784:tid 124013] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/wpxml.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg2gAAAF8"]
[Tue Aug 18 12:59:27.245921 2026] [security2:error] [pid 123784:tid 123991] [client 20.215.241.237:18121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/wpxml.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg2wAAAEk"]
[Tue Aug 18 12:59:27.246912 2026] [security2:error] [pid 123784:tid 124018] [client 20.91.215.254:13430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/public/storage.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg3AAAAGQ"]
[Tue Aug 18 12:59:27.260230 2026] [security2:error] [pid 123784:tid 124012] [client 20.25.139.174:4457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/NewFile.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg3QAAAF4"]
[Tue Aug 18 12:59:27.268740 2026] [security2:error] [pid 123784:tid 123948] [client 74.248.18.37:7774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/options.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg3gAAAB4"]
[Tue Aug 18 12:59:27.271816 2026] [security2:error] [pid 123784:tid 124005] [client 213.202.253.4:56744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg3wAAAFc"], referer: www.google.com
[Tue Aug 18 12:59:27.290905 2026] [security2:error] [pid 123784:tid 123971] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg4QAAADU"]
[Tue Aug 18 12:59:27.297630 2026] [authz_core:error] [pid 123784:tid 123875] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:27.297909 2026] [authz_core:error] [pid 123784:tid 123875] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:27.308214 2026] [security2:error] [pid 123784:tid 123941] [client 20.203.138.185:24913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/co.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg4gAAABc"]
[Tue Aug 18 12:59:27.373514 2026] [security2:error] [pid 123784:tid 123982] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/a.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg5gAAAEA"]
[Tue Aug 18 12:59:27.393254 2026] [security2:error] [pid 123784:tid 124034] [client 20.127.136.245:28046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/about.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg5wAAAHQ"]
[Tue Aug 18 12:59:27.466247 2026] [security2:error] [pid 123784:tid 124028] [client 20.51.153.15:7259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/phpcheck.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg6wAAAG4"]
[Tue Aug 18 12:59:27.541475 2026] [security2:error] [pid 123784:tid 123956] [client 178.153.171.161:55221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg8QAAACY"]
[Tue Aug 18 12:59:27.541597 2026] [security2:error] [pid 123784:tid 123956] [client 178.153.171.161:55221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg8QAAACY"]
[Tue Aug 18 12:59:27.563006 2026] [security2:error] [pid 123784:tid 124024] [client 132.196.30.78:20388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/222.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg9AAAAGo"]
[Tue Aug 18 12:59:27.570120 2026] [autoindex:error] [pid 123784:tid 123934] [client 132.196.30.78:14989] AH01276: Cannot serve directory /home3/cadema/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:27.589852 2026] [security2:error] [pid 123784:tid 123950] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/file1221.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg9QAAACA"]
[Tue Aug 18 12:59:27.617619 2026] [security2:error] [pid 123784:tid 123999] [client 5.31.227.224:30460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg-gAAAFE"]
[Tue Aug 18 12:59:27.622335 2026] [security2:error] [pid 123784:tid 123999] [client 5.31.227.224:30460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg-gAAAFE"]
[Tue Aug 18 12:59:27.639221 2026] [security2:error] [pid 123784:tid 123936] [client 20.25.139.174:4564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/k.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg-wAAABI"]
[Tue Aug 18 12:59:27.654223 2026] [security2:error] [pid 123784:tid 123968] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg_QAAADI"]
[Tue Aug 18 12:59:27.659156 2026] [security2:error] [pid 123784:tid 123995] [client 213.35.127.232:63198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg_gAAAE0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:27.666182 2026] [security2:error] [pid 123784:tid 124026] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg_wAAAGw"]
[Tue Aug 18 12:59:27.670918 2026] [security2:error] [pid 123784:tid 123946] [client 20.38.3.247:34984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/fpwch.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhAAAAABw"]
[Tue Aug 18 12:59:27.682205 2026] [security2:error] [pid 123784:tid 123954] [client 68.155.154.236:25352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/oivcl.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhAQAAACQ"]
[Tue Aug 18 12:59:27.767598 2026] [security2:error] [pid 123784:tid 123962] [client 158.23.17.4:40415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/30.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhBwAAACw"]
[Tue Aug 18 12:59:27.770063 2026] [security2:error] [pid 123784:tid 124043] [client 132.196.30.78:14989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhCAAAAH0"]
[Tue Aug 18 12:59:27.772557 2026] [security2:error] [pid 123784:tid 123955] [client 158.23.17.4:34027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/53.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhCQAAACU"]
[Tue Aug 18 12:59:27.783195 2026] [security2:error] [pid 123784:tid 124042] [client 20.51.153.15:7268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/mimes.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhCwAAAHw"]
[Tue Aug 18 12:59:27.823073 2026] [security2:error] [pid 123784:tid 123930] [client 20.25.139.174:4531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhDgAAAAw"]
[Tue Aug 18 12:59:27.879182 2026] [security2:error] [pid 123784:tid 123943] [client 20.127.136.245:28071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/term.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhFAAAABk"]
[Tue Aug 18 12:59:27.905162 2026] [security2:error] [pid 123784:tid 124014] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/nox.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhFwAAAGA"]
[Tue Aug 18 12:59:27.905303 2026] [authz_core:error] [pid 123784:tid 123899] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:27.905561 2026] [authz_core:error] [pid 123784:tid 123899] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:27.918552 2026] [security2:error] [pid 123784:tid 123953] [client 20.91.215.254:13414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/radio.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhGAAAACM"]
[Tue Aug 18 12:59:27.946002 2026] [security2:error] [pid 123784:tid 124007] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/99.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhGwAAAFk"]
[Tue Aug 18 12:59:28.046422 2026] [security2:error] [pid 123784:tid 123906] [remote 162.214.96.231:33038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.capecodcleaningservice.com"] [uri "/wp-login.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhHwAAMHU"]
[Tue Aug 18 12:59:28.060850 2026] [security2:error] [pid 123784:tid 124005] [client 68.155.154.236:27530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/zugvi.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhIgAAAFc"]
[Tue Aug 18 12:59:28.061975 2026] [security2:error] [pid 123784:tid 123963] [client 20.51.153.15:7170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/fraie1p4.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhIwAAAC0"]
[Tue Aug 18 12:59:28.122191 2026] [security2:error] [pid 123784:tid 123923] [client 20.203.138.185:33236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/btx25.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhJgAAAAU"]
[Tue Aug 18 12:59:28.154491 2026] [security2:error] [pid 123784:tid 123980] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhKgAAAD4"]
[Tue Aug 18 12:59:28.170506 2026] [security2:error] [pid 123784:tid 123918] [client 74.248.18.37:32113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/plugin-install.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhKwAAAAA"]
[Tue Aug 18 12:59:28.192608 2026] [security2:error] [pid 123784:tid 123982] [client 158.23.17.4:14062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/pu.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhLAAAAEA"]
[Tue Aug 18 12:59:28.202887 2026] [security2:error] [pid 123784:tid 123924] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/akismet.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhLgAAAAY"]
[Tue Aug 18 12:59:28.202955 2026] [security2:error] [pid 123784:tid 123978] [client 20.25.139.174:4646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhLQAAADw"]
[Tue Aug 18 12:59:28.252748 2026] [security2:error] [pid 123784:tid 123981] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/yup.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhMQAAAD8"]
[Tue Aug 18 12:59:28.268041 2026] [security2:error] [pid 123784:tid 123932] [client 132.196.30.78:14995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhMgAAAA4"]
[Tue Aug 18 12:59:28.299283 2026] [security2:error] [pid 123784:tid 124025] [client 40.74.65.169:20289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/simple.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhNgAAAGs"]
[Tue Aug 18 12:59:28.341923 2026] [security2:error] [pid 123784:tid 123964] [client 223.185.37.47:14604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhOAAAAC4"]
[Tue Aug 18 12:59:28.345863 2026] [security2:error] [pid 123784:tid 123964] [client 223.185.37.47:14604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhOAAAAC4"]
[Tue Aug 18 12:59:28.346151 2026] [security2:error] [pid 123784:tid 123925] [client 132.196.30.78:14632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhOQAAAAc"]
[Tue Aug 18 12:59:28.365379 2026] [security2:error] [pid 123784:tid 124009] [client 85.154.68.202:19301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhOwAAAFs"]
[Tue Aug 18 12:59:28.365403 2026] [security2:error] [pid 123784:tid 123938] [client 20.25.139.174:4699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhOgAAABQ"]
[Tue Aug 18 12:59:28.365499 2026] [security2:error] [pid 123784:tid 124009] [client 85.154.68.202:19301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhOwAAAFs"]
[Tue Aug 18 12:59:28.385332 2026] [security2:error] [pid 123784:tid 124024] [client 20.51.153.15:7277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/pqr.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhPgAAAGo"]
[Tue Aug 18 12:59:28.435729 2026] [security2:error] [pid 123784:tid 123999] [client 68.155.154.236:27532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wsrer.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhQQAAAFE"]
[Tue Aug 18 12:59:28.448246 2026] [security2:error] [pid 123784:tid 124015] [client 20.38.3.247:35000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/adminner.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhQgAAAGE"]
[Tue Aug 18 12:59:28.505881 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:28.506329 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:28.531944 2026] [security2:error] [pid 123784:tid 123935] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhRwAAABE"]
[Tue Aug 18 12:59:28.532257 2026] [security2:error] [pid 123784:tid 123940] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/222.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhSAAAABY"]
[Tue Aug 18 12:59:28.538590 2026] [security2:error] [pid 123784:tid 124021] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/admin.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhSQAAAGc"]
[Tue Aug 18 12:59:28.551177 2026] [security2:error] [pid 123784:tid 124038] [client 20.251.48.93:10109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/sf.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhSgAAAHg"]
[Tue Aug 18 12:59:28.556407 2026] [security2:error] [pid 123784:tid 123945] [client 20.104.85.180:20237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/index/function.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhSwAAABs"]
[Tue Aug 18 12:59:28.566076 2026] [security2:error] [pid 123784:tid 124031] [client 20.91.215.254:13410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/root.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhTQAAAHE"]
[Tue Aug 18 12:59:28.671362 2026] [security2:error] [pid 123784:tid 124030] [client 213.35.127.232:63417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhUAAAAHA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:28.695980 2026] [security2:error] [pid 123784:tid 123986] [client 20.51.153.15:7286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/lmfi2.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhUwAAAEQ"]
[Tue Aug 18 12:59:28.748009 2026] [security2:error] [pid 123784:tid 124020] [client 20.100.169.31:21227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/2.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhWwAAAGY"]
[Tue Aug 18 12:59:28.789320 2026] [security2:error] [pid 123784:tid 123995] [client 20.250.13.23:56548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/chosen.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhXwAAAE0"]
[Tue Aug 18 12:59:28.805781 2026] [authz_core:error] [pid 123784:tid 123817] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:28.806069 2026] [authz_core:error] [pid 123784:tid 123817] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:28.819456 2026] [security2:error] [pid 123784:tid 123984] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-temp.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhYwAAAEI"]
[Tue Aug 18 12:59:28.861823 2026] [security2:error] [pid 123784:tid 123930] [client 74.248.18.37:26451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/wp-cron.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhaAAAAAw"]
[Tue Aug 18 12:59:28.866175 2026] [security2:error] [pid 123784:tid 123948] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/ajax.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhaQAAAB4"]
[Tue Aug 18 12:59:28.900215 2026] [security2:error] [pid 123784:tid 123923] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhbgAAAAU"]
[Tue Aug 18 12:59:28.938083 2026] [security2:error] [pid 123784:tid 123980] [client 68.155.154.236:27522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/ucpfr.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhbwAAAD4"]
[Tue Aug 18 12:59:28.938416 2026] [security2:error] [pid 123784:tid 123996] [client 132.196.30.78:2953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhcAAAAE4"]
[Tue Aug 18 12:59:28.971858 2026] [security2:error] [pid 123784:tid 124018] [client 20.25.139.174:4653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/themes.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhdgAAAGQ"]
[Tue Aug 18 12:59:28.989762 2026] [security2:error] [pid 123784:tid 123992] [client 132.196.30.78:13659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/info.php"] [unique_id "aoSBYGwDnJBNj2tDbYbheAAAAEo"]
[Tue Aug 18 12:59:29.050795 2026] [security2:error] [pid 123784:tid 123988] [client 20.51.153.15:7179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/info2.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhfQAAAEY"]
[Tue Aug 18 12:59:29.078262 2026] [security2:error] [pid 123784:tid 123964] [client 158.23.17.4:33431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/lq.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhfwAAAC4"]
[Tue Aug 18 12:59:29.094738 2026] [security2:error] [pid 123784:tid 123973] [client 20.127.136.245:28501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/ioxi-o.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhgAAAADc"]
[Tue Aug 18 12:59:29.256791 2026] [security2:error] [pid 123784:tid 123999] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhigAAAFE"]
[Tue Aug 18 12:59:29.265173 2026] [security2:error] [pid 123784:tid 123824] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhiwAAViM"]
[Tue Aug 18 12:59:29.265412 2026] [security2:error] [pid 123784:tid 124004] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhiwAAViM"]
[Tue Aug 18 12:59:29.288347 2026] [security2:error] [pid 123784:tid 123968] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/spadex.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhjAAAADI"]
[Tue Aug 18 12:59:29.291863 2026] [security2:error] [pid 123784:tid 124023] [client 20.91.215.254:10236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/server.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhjQAAAGk"]
[Tue Aug 18 12:59:29.297895 2026] [security2:error] [pid 123784:tid 123925] [client 79.127.164.8:58604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/tables.sql"] [unique_id "aoSBYWwDnJBNj2tDbYbhjgAAAAc"], referer: https://medihub.com.br/tables.sql
[Tue Aug 18 12:59:29.309861 2026] [security2:error] [pid 123784:tid 124001] [client 20.51.153.15:7272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/test_info.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhkAAAAFM"]
[Tue Aug 18 12:59:29.383016 2026] [security2:error] [pid 123784:tid 123979] [client 114.5.214.109:50414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhmAAAAD0"]
[Tue Aug 18 12:59:29.383129 2026] [security2:error] [pid 123784:tid 123979] [client 114.5.214.109:50414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhmAAAAD0"]
[Tue Aug 18 12:59:29.398877 2026] [security2:error] [pid 123784:tid 123951] [client 20.38.3.247:60312] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/1.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhmQAAACE"]
[Tue Aug 18 12:59:29.398984 2026] [security2:error] [pid 123784:tid 123951] [client 20.38.3.247:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/1.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhmQAAACE"]
[Tue Aug 18 12:59:29.405491 2026] [security2:error] [pid 123784:tid 124008] [client 20.203.138.185:24934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/avim.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhmgAAAFo"]
[Tue Aug 18 12:59:29.447671 2026] [security2:error] [pid 123784:tid 123974] [client 172.182.200.96:7569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhnAAAADg"]
[Tue Aug 18 12:59:29.476080 2026] [security2:error] [pid 123784:tid 124039] [client 20.25.139.174:4417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/cv.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhngAAAHk"]
[Tue Aug 18 12:59:29.476182 2026] [security2:error] [pid 123784:tid 123936] [client 20.100.169.31:25393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhnQAAABI"]
[Tue Aug 18 12:59:29.493306 2026] [security2:error] [pid 123784:tid 124019] [client 158.23.17.4:14064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ry.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhoAAAAGU"]
[Tue Aug 18 12:59:29.510156 2026] [security2:error] [pid 123784:tid 123945] [client 132.196.30.78:14998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/NewFile.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhogAAABs"]
[Tue Aug 18 12:59:29.565788 2026] [security2:error] [pid 123784:tid 124031] [client 74.248.18.37:32097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/wp-settings.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhpwAAAHE"]
[Tue Aug 18 12:59:29.567775 2026] [security2:error] [pid 123784:tid 123958] [client 20.38.3.247:8692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/abcd.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhqAAAACg"]
[Tue Aug 18 12:59:29.610561 2026] [security2:error] [pid 123784:tid 123952] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhqwAAACI"]
[Tue Aug 18 12:59:29.612908 2026] [security2:error] [pid 123784:tid 124014] [client 20.127.136.245:28495] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/1.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhrAAAAGA"]
[Tue Aug 18 12:59:29.613009 2026] [security2:error] [pid 123784:tid 124014] [client 20.127.136.245:28495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/1.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhrAAAAGA"]
[Tue Aug 18 12:59:29.634266 2026] [security2:error] [pid 123784:tid 123941] [client 68.155.154.236:25375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/yxijx.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhrQAAABc"]
[Tue Aug 18 12:59:29.665972 2026] [security2:error] [pid 123784:tid 123996] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhrwAAAE4"]
[Tue Aug 18 12:59:29.673625 2026] [security2:error] [pid 123784:tid 123918] [client 20.51.153.15:7182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/xynz1.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhsAAAAAA"]
[Tue Aug 18 12:59:29.685276 2026] [security2:error] [pid 123784:tid 124043] [client 213.35.127.232:63642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhsgAAAH0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:29.693985 2026] [security2:error] [pid 123784:tid 123992] [client 20.119.58.187:10500] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "tomiogroup.com.br"] [uri "/1.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhtQAAAEo"]
[Tue Aug 18 12:59:29.694069 2026] [security2:error] [pid 123784:tid 123992] [client 20.119.58.187:10500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/1.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhtQAAAEo"]
[Tue Aug 18 12:59:29.697244 2026] [security2:error] [pid 123784:tid 123981] [client 40.74.65.169:20347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/chosen.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhtwAAAD8"]
[Tue Aug 18 12:59:29.702223 2026] [security2:error] [pid 123784:tid 123827] [remote 216.73.216.206:33796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/"] [unique_id "aoSBYWwDnJBNj2tDbYbhuAAAbCY"]
[Tue Aug 18 12:59:29.729503 2026] [security2:error] [pid 123784:tid 123986] [client 132.196.30.78:22204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/a.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhugAAAEQ"]
[Tue Aug 18 12:59:29.816645 2026] [security2:error] [pid 123784:tid 123978] [client 20.119.58.187:10527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/2.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhvAAAADw"]
[Tue Aug 18 12:59:29.928126 2026] [security2:error] [pid 123784:tid 123920] [client 20.91.215.254:10212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhxgAAAAI"]
[Tue Aug 18 12:59:29.929097 2026] [security2:error] [pid 123784:tid 123968] [client 20.51.153.15:7292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/album.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhxwAAADI"]
[Tue Aug 18 12:59:29.967854 2026] [security2:error] [pid 123784:tid 123940] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhyQAAABY"]
[Tue Aug 18 12:59:30.010377 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:30.010633 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:30.030017 2026] [security2:error] [pid 123784:tid 123935] [client 172.202.39.151:4692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/inputs.php"] [unique_id "aoSBYmwDnJBNj2tDbYbhzQAAABE"]
[Tue Aug 18 12:59:30.044864 2026] [autoindex:error] [pid 123784:tid 124017] [client 20.25.139.174:4669] AH01276: Cannot serve directory /home3/cadema/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:30.051090 2026] [security2:error] [pid 123784:tid 124012] [client 68.155.154.236:25372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/zwlsv.php"] [unique_id "aoSBYmwDnJBNj2tDbYbhzwAAAF4"]
[Tue Aug 18 12:59:30.069005 2026] [security2:error] [pid 123784:tid 123969] [client 20.38.3.247:58833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/simple.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh0wAAADM"]
[Tue Aug 18 12:59:30.070177 2026] [security2:error] [pid 123784:tid 123990] [client 4.232.94.69:41410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/disagraeosc.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh1AAAAEg"]
[Tue Aug 18 12:59:30.081067 2026] [security2:error] [pid 123784:tid 124023] [client 20.127.136.245:28509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/alfa.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh1QAAAGk"]
[Tue Aug 18 12:59:30.129930 2026] [security2:error] [pid 123784:tid 124039] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/srontol.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh1wAAAHk"]
[Tue Aug 18 12:59:30.167593 2026] [security2:error] [pid 123784:tid 124007] [client 158.23.17.4:44849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/you.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh2gAAAFk"]
[Tue Aug 18 12:59:30.169599 2026] [security2:error] [pid 123784:tid 123951] [client 20.119.58.187:10508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/7.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh2wAAACE"]
[Tue Aug 18 12:59:30.194541 2026] [security2:error] [pid 123784:tid 123945] [client 20.51.153.15:7249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/creds.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh3gAAABs"]
[Tue Aug 18 12:59:30.210510 2026] [security2:error] [pid 123784:tid 123991] [client 20.25.139.174:4669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh4QAAAEk"]
[Tue Aug 18 12:59:30.215201 2026] [security2:error] [pid 123784:tid 123944] [client 132.196.30.78:13677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh4wAAABo"]
[Tue Aug 18 12:59:30.216449 2026] [security2:error] [pid 123784:tid 123998] [client 158.23.17.4:25387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/pm.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh5AAAAFA"]
[Tue Aug 18 12:59:30.249174 2026] [security2:error] [pid 123784:tid 124037] [client 74.248.18.37:32091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/wp-signup.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh5gAAAHc"]
[Tue Aug 18 12:59:30.314659 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:30.315004 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:30.325085 2026] [security2:error] [pid 123784:tid 124028] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh6gAAAG4"]
[Tue Aug 18 12:59:30.351842 2026] [security2:error] [pid 123784:tid 124034] [client 168.119.53.160:56740] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.connectformaturas.com.br"] [uri "/index.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhhQAAAHQ"], referer: https://www.connectformaturas.com.br
[Tue Aug 18 12:59:30.403036 2026] [security2:error] [pid 123784:tid 123856] [remote 103.56.163.133:57704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnomor.com.br"] [uri "/wp-login.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh7wAAH0M"]
[Tue Aug 18 12:59:30.419134 2026] [security2:error] [pid 123784:tid 123948] [client 20.25.139.174:4500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/ww5.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh8gAAAB4"]
[Tue Aug 18 12:59:30.498368 2026] [security2:error] [pid 123784:tid 123967] [client 20.51.153.15:7241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/mandrill.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh-AAAADE"]
[Tue Aug 18 12:59:30.522658 2026] [security2:error] [pid 123784:tid 124043] [client 20.119.58.187:10531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/10.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh_AAAAH0"]
[Tue Aug 18 12:59:30.539017 2026] [security2:error] [pid 123784:tid 124011] [client 132.196.30.78:13685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/chosen.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh_wAAAF0"]
[Tue Aug 18 12:59:30.542201 2026] [security2:error] [pid 123784:tid 123956] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/file5.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiAQAAACY"]
[Tue Aug 18 12:59:30.605760 2026] [security2:error] [pid 123784:tid 123966] [client 20.203.138.185:21042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/myfile.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiBwAAADA"]
[Tue Aug 18 12:59:30.611986 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:30.612292 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:30.614662 2026] [security2:error] [pid 123784:tid 123923] [client 192.141.172.134:54291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiCQAAAAU"]
[Tue Aug 18 12:59:30.614801 2026] [security2:error] [pid 123784:tid 123923] [client 192.141.172.134:54291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiCQAAAAU"]
[Tue Aug 18 12:59:30.620125 2026] [security2:error] [pid 123784:tid 123922] [client 20.127.136.245:28520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/edit.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiCgAAAAQ"]
[Tue Aug 18 12:59:30.630916 2026] [security2:error] [pid 123784:tid 123963] [client 20.91.215.254:9909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/shell.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiDAAAAC0"]
[Tue Aug 18 12:59:30.653101 2026] [security2:error] [pid 123784:tid 123919] [client 216.244.66.243:44400] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/firebotblaze-0/"] [unique_id "aoSBYmwDnJBNj2tDbYbiDgAAAAE"]
[Tue Aug 18 12:59:30.653219 2026] [security2:error] [pid 123784:tid 123919] [client 216.244.66.243:44400] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/firebotblaze-0/"] [unique_id "aoSBYmwDnJBNj2tDbYbiDgAAAAE"]
[Tue Aug 18 12:59:30.665943 2026] [security2:error] [pid 123784:tid 123968] [client 20.38.3.247:29793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/wp-manager.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiDwAAADI"]
[Tue Aug 18 12:59:30.672802 2026] [security2:error] [pid 123784:tid 123861] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiEAAAPkg"]
[Tue Aug 18 12:59:30.672992 2026] [security2:error] [pid 123784:tid 123980] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiEAAAPkg"]
[Tue Aug 18 12:59:30.700302 2026] [security2:error] [pid 123784:tid 123996] [client 213.35.127.232:63846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiEgAAAE4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:30.708276 2026] [security2:error] [pid 123784:tid 124021] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiFQAAAGc"]
[Tue Aug 18 12:59:30.713090 2026] [security2:error] [pid 123784:tid 123955] [client 20.215.241.237:18154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/file1221.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiFgAAACU"]
[Tue Aug 18 12:59:30.718896 2026] [security2:error] [pid 123784:tid 124035] [client 20.25.139.174:4634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/ws83.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiFwAAAHU"]
[Tue Aug 18 12:59:30.750655 2026] [security2:error] [pid 123784:tid 123979] [client 68.155.154.236:25405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/jrpga.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiGgAAAD0"]
[Tue Aug 18 12:59:30.777162 2026] [security2:error] [pid 123784:tid 123954] [client 20.51.153.15:7227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/main.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiGwAAACQ"]
[Tue Aug 18 12:59:30.823632 2026] [security2:error] [pid 123784:tid 124030] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/yup.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiHQAAAHA"]
[Tue Aug 18 12:59:30.874787 2026] [security2:error] [pid 123784:tid 124012] [client 20.119.58.187:10556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/13.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiIQAAAF4"]
[Tue Aug 18 12:59:30.890445 2026] [security2:error] [pid 123784:tid 124033] [client 132.196.30.78:20372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiJgAAAHM"]
[Tue Aug 18 12:59:30.933997 2026] [security2:error] [pid 123784:tid 124038] [client 74.248.18.37:32095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiKAAAAHg"]
[Tue Aug 18 12:59:30.948932 2026] [security2:error] [pid 123784:tid 123944] [client 158.23.17.4:38307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ez.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiKQAAABo"]
[Tue Aug 18 12:59:30.987423 2026] [security2:error] [pid 123784:tid 123965] [client 20.25.139.174:4424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/2.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiKwAAAC8"]
[Tue Aug 18 12:59:31.043571 2026] [security2:error] [pid 123784:tid 123962] [client 20.51.153.15:7212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/payout.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiLQAAACw"]
[Tue Aug 18 12:59:31.043888 2026] [security2:error] [pid 123784:tid 124024] [client 20.127.136.245:28053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/elp.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiLAAAAGo"]
[Tue Aug 18 12:59:31.052481 2026] [security2:error] [pid 123784:tid 124010] [client 20.38.3.247:64713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/xiugai.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiLwAAAFw"]
[Tue Aug 18 12:59:31.065975 2026] [security2:error] [pid 123784:tid 123952] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiMQAAACI"]
[Tue Aug 18 12:59:31.092081 2026] [security2:error] [pid 123784:tid 123941] [client 40.74.65.169:19473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/als.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiMgAAABc"]
[Tue Aug 18 12:59:31.117849 2026] [security2:error] [pid 123784:tid 123971] [client 158.23.17.4:56736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/dr.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiMwAAADU"]
[Tue Aug 18 12:59:31.119424 2026] [security2:error] [pid 123784:tid 123942] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiNAAAABg"]
[Tue Aug 18 12:59:31.160445 2026] [security2:error] [pid 123784:tid 123984] [client 132.196.30.78:25108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiOAAAAEI"]
[Tue Aug 18 12:59:31.212797 2026] [security2:error] [pid 123784:tid 123975] [client 102.213.179.104:59984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiPAAAADk"]
[Tue Aug 18 12:59:31.212997 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:31.213024 2026] [security2:error] [pid 123784:tid 123975] [client 102.213.179.104:59984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiPAAAADk"]
[Tue Aug 18 12:59:31.213243 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:31.226509 2026] [security2:error] [pid 123784:tid 124001] [client 20.119.58.187:10501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/100.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiPQAAAFM"]
[Tue Aug 18 12:59:31.251968 2026] [security2:error] [pid 123784:tid 124014] [client 20.25.139.174:4595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/atex1.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiPwAAAGA"]
[Tue Aug 18 12:59:31.261457 2026] [security2:error] [pid 123784:tid 124031] [client 20.91.215.254:10230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/sim.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiQQAAAHE"]
[Tue Aug 18 12:59:31.279155 2026] [security2:error] [pid 123784:tid 124011] [client 20.38.3.247:43345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/coffee.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiQgAAAF0"]
[Tue Aug 18 12:59:31.322064 2026] [security2:error] [pid 123784:tid 123877] [remote 178.156.200.16:49888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.200.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "m2mit.cloud"] [uri "/wp-login.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiRAAAblg"]
[Tue Aug 18 12:59:31.374713 2026] [security2:error] [pid 123784:tid 123966] [client 20.51.153.15:7281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/Mailgun.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiSAAAADA"]
[Tue Aug 18 12:59:31.405157 2026] [security2:error] [pid 123784:tid 123978] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-the.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiSgAAADw"]
[Tue Aug 18 12:59:31.421878 2026] [security2:error] [pid 123784:tid 123963] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiSwAAAC0"]
[Tue Aug 18 12:59:31.428598 2026] [security2:error] [pid 123784:tid 124042] [client 20.104.85.180:28609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/edit.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiTQAAAHw"]
[Tue Aug 18 12:59:31.446289 2026] [security2:error] [pid 123784:tid 123985] [client 20.38.3.247:61959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/wp-load.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiTwAAAEM"]
[Tue Aug 18 12:59:31.468030 2026] [security2:error] [pid 123784:tid 123940] [client 68.155.154.236:25361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiUAAAABY"]
[Tue Aug 18 12:59:31.487242 2026] [security2:error] [pid 123784:tid 124021] [client 20.203.138.185:24944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/xmy.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiUQAAAGc"]
[Tue Aug 18 12:59:31.487697 2026] [security2:error] [pid 123784:tid 124009] [client 20.25.139.174:4556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiUgAAAFs"]
[Tue Aug 18 12:59:31.550568 2026] [security2:error] [pid 123784:tid 123999] [client 20.127.136.245:28056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/classwithtostring.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiVQAAAFE"]
[Tue Aug 18 12:59:31.580157 2026] [security2:error] [pid 123784:tid 123922] [client 132.196.30.78:15617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/themes.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiVwAAAAQ"]
[Tue Aug 18 12:59:31.604652 2026] [security2:error] [pid 123784:tid 123977] [client 20.119.58.187:10449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/222.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiWAAAADs"]
[Tue Aug 18 12:59:31.649919 2026] [security2:error] [pid 123784:tid 124033] [client 20.51.153.15:7129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/oauth.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiWgAAAHM"]
[Tue Aug 18 12:59:31.654637 2026] [security2:error] [pid 123784:tid 123957] [client 74.248.18.37:26450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiWwAAACc"]
[Tue Aug 18 12:59:31.686769 2026] [security2:error] [pid 123784:tid 123928] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiXAAAAAo"]
[Tue Aug 18 12:59:31.688129 2026] [security2:error] [pid 123784:tid 124022] [client 158.23.17.4:7195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ts.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiXwAAAGg"]
[Tue Aug 18 12:59:31.717090 2026] [security2:error] [pid 123784:tid 123923] [client 213.35.127.232:64063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiZgAAAAU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:31.766775 2026] [security2:error] [pid 123784:tid 124024] [client 158.23.17.4:31878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/asus.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiaQAAAGo"]
[Tue Aug 18 12:59:31.770473 2026] [security2:error] [pid 123784:tid 124010] [client 40.74.65.169:20342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/nox.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiagAAAFw"]
[Tue Aug 18 12:59:31.778384 2026] [security2:error] [pid 123784:tid 124003] [client 132.196.30.78:15029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/vx.php"] [unique_id "aoSBY2wDnJBNj2tDbYbibAAAAFU"]
[Tue Aug 18 12:59:31.780022 2026] [security2:error] [pid 123784:tid 123932] [client 20.25.139.174:4438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBY2wDnJBNj2tDbYbibQAAAA4"]
[Tue Aug 18 12:59:31.794274 2026] [security2:error] [pid 123784:tid 123971] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSBY2wDnJBNj2tDbYbicgAAADU"]
[Tue Aug 18 12:59:31.819049 2026] [security2:error] [pid 123784:tid 123807] [remote 8.29.155.129:36225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.155.29.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "humanitics.com.br"] [uri "/wp-login.php"] [unique_id "aoSBY2wDnJBNj2tDbYbidAAAERI"]
[Tue Aug 18 12:59:31.832349 2026] [security2:error] [pid 123784:tid 123988] [client 4.232.94.69:14594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/24.php"] [unique_id "aoSBY2wDnJBNj2tDbYbidQAAAEY"]
[Tue Aug 18 12:59:31.907688 2026] [security2:error] [pid 123784:tid 124038] [client 20.91.215.254:10183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/simple.php"] [unique_id "aoSBY2wDnJBNj2tDbYbieQAAAHg"]
[Tue Aug 18 12:59:31.940122 2026] [security2:error] [pid 123784:tid 123881] [remote 162.214.96.231:33052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tigre.tur.br.slweb.net.br"] [uri "/wp-login.php"] [unique_id "aoSBY2wDnJBNj2tDbYbifAAATFw"]
[Tue Aug 18 12:59:31.957502 2026] [security2:error] [pid 123784:tid 123992] [client 20.119.58.187:10504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBY2wDnJBNj2tDbYbifQAAAEo"]
[Tue Aug 18 12:59:31.969939 2026] [security2:error] [pid 123784:tid 123986] [client 20.38.3.247:58821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/155.php"] [unique_id "aoSBY2wDnJBNj2tDbYbifgAAAEQ"]
[Tue Aug 18 12:59:31.993849 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:31.994106 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:32.002135 2026] [security2:error] [pid 123784:tid 123989] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/xwpg.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiggAAAEc"]
[Tue Aug 18 12:59:32.007148 2026] [security2:error] [pid 123784:tid 123933] [client 20.25.139.174:4688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/atomlib.php"] [unique_id "aoSBZGwDnJBNj2tDbYbigwAAAA8"]
[Tue Aug 18 12:59:32.024564 2026] [security2:error] [pid 123784:tid 123929] [client 20.127.136.245:28088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/666.php"] [unique_id "aoSBZGwDnJBNj2tDbYbihAAAAAs"]
[Tue Aug 18 12:59:32.051841 2026] [security2:error] [pid 123784:tid 123970] [client 68.155.154.236:25362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/nwwha.php"] [unique_id "aoSBZGwDnJBNj2tDbYbihQAAADQ"]
[Tue Aug 18 12:59:32.058777 2026] [security2:error] [pid 123784:tid 124042] [client 20.51.153.15:7263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/timeclock.php"] [unique_id "aoSBZGwDnJBNj2tDbYbihgAAAHw"]
[Tue Aug 18 12:59:32.108247 2026] [security2:error] [pid 123784:tid 123925] [client 196.12.128.158:63143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiiQAAAAc"]
[Tue Aug 18 12:59:32.108366 2026] [security2:error] [pid 123784:tid 123925] [client 196.12.128.158:63143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiiQAAAAc"]
[Tue Aug 18 12:59:32.145580 2026] [security2:error] [pid 123784:tid 124030] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiiwAAAHA"]
[Tue Aug 18 12:59:32.155754 2026] [security2:error] [pid 123784:tid 124039] [client 20.250.13.23:35124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBZGwDnJBNj2tDbYbijAAAAHk"]
[Tue Aug 18 12:59:32.189596 2026] [security2:error] [pid 123784:tid 123921] [client 132.196.30.78:15629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/cv.php"] [unique_id "aoSBZGwDnJBNj2tDbYbikAAAAAM"]
[Tue Aug 18 12:59:32.284998 2026] [security2:error] [pid 123784:tid 123957] [client 158.23.17.4:47620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/53.php"] [unique_id "aoSBZGwDnJBNj2tDbYbikgAAACc"]
[Tue Aug 18 12:59:32.287879 2026] [security2:error] [pid 123784:tid 123936] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/dex.php"] [unique_id "aoSBZGwDnJBNj2tDbYbikwAAABI"]
[Tue Aug 18 12:59:32.307831 2026] [security2:error] [pid 123784:tid 123983] [client 20.119.58.187:10437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/abcd.php"] [unique_id "aoSBZGwDnJBNj2tDbYbilQAAAEE"]
[Tue Aug 18 12:59:32.320641 2026] [security2:error] [pid 123784:tid 123990] [client 20.25.139.174:4730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/w.php"] [unique_id "aoSBZGwDnJBNj2tDbYbilgAAAEg"]
[Tue Aug 18 12:59:32.325394 2026] [security2:error] [pid 123784:tid 123951] [client 20.251.48.93:57172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/k.php"] [unique_id "aoSBZGwDnJBNj2tDbYbilwAAACE"]
[Tue Aug 18 12:59:32.370606 2026] [security2:error] [pid 123784:tid 124025] [client 20.203.138.185:24904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/xda.php"] [unique_id "aoSBZGwDnJBNj2tDbYbimQAAAGs"]
[Tue Aug 18 12:59:32.377008 2026] [security2:error] [pid 123784:tid 123965] [client 20.38.3.247:8640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/index.php"] [unique_id "aoSBZGwDnJBNj2tDbYbimwAAAC8"]
[Tue Aug 18 12:59:32.389839 2026] [authz_core:error] [pid 123784:tid 123945] [client 82.102.18.182:55188] AH01630: client denied by server configuration: /home4/ctrrefrigeracao/public_html/wp-content/plugins/akismet/
[Tue Aug 18 12:59:32.395345 2026] [security2:error] [pid 123784:tid 123812] [remote 208.122.213.225:38078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.213.122.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "konneqt.cloud"] [uri "/wp-login.php"] [unique_id "aoSBZGwDnJBNj2tDbYbinQAAQBc"]
[Tue Aug 18 12:59:32.425245 2026] [security2:error] [pid 123784:tid 124024] [client 172.182.200.96:7664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBZGwDnJBNj2tDbYbioQAAAGo"]
[Tue Aug 18 12:59:32.463889 2026] [security2:error] [pid 123784:tid 123924] [client 197.184.64.235:41950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiowAAAAY"]
[Tue Aug 18 12:59:32.464039 2026] [security2:error] [pid 123784:tid 123924] [client 197.184.64.235:41950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiowAAAAY"]
[Tue Aug 18 12:59:32.466856 2026] [security2:error] [pid 123784:tid 123997] [client 74.248.18.37:26453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-blog.php"] [unique_id "aoSBZGwDnJBNj2tDbYbipAAAAE8"]
[Tue Aug 18 12:59:32.480386 2026] [security2:error] [pid 123784:tid 123964] [client 40.74.65.169:43010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/file59.php"] [unique_id "aoSBZGwDnJBNj2tDbYbipwAAAC4"]
[Tue Aug 18 12:59:32.521807 2026] [security2:error] [pid 123784:tid 123998] [client 20.25.139.174:4693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/rip.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiqQAAAFA"]
[Tue Aug 18 12:59:32.533014 2026] [security2:error] [pid 123784:tid 124015] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiqgAAAGE"]
[Tue Aug 18 12:59:32.551988 2026] [security2:error] [pid 123784:tid 124005] [client 20.91.215.254:10233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/st.php"] [unique_id "aoSBZGwDnJBNj2tDbYbirAAAAFc"]
[Tue Aug 18 12:59:32.574124 2026] [security2:error] [pid 123784:tid 123935] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/xyn.php"] [unique_id "aoSBZGwDnJBNj2tDbYbirQAAABE"]
[Tue Aug 18 12:59:32.614013 2026] [security2:error] [pid 123784:tid 124019] [client 20.65.98.162:23513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/ajax.php"] [unique_id "aoSBZGwDnJBNj2tDbYbirwAAAGU"]
[Tue Aug 18 12:59:32.616733 2026] [security2:error] [pid 123784:tid 123960] [client 20.127.136.245:28485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/ws54.php"] [unique_id "aoSBZGwDnJBNj2tDbYbisAAAACo"]
[Tue Aug 18 12:59:32.660607 2026] [security2:error] [pid 123784:tid 123918] [client 20.119.58.187:10499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/al.php"] [unique_id "aoSBZGwDnJBNj2tDbYbisgAAAAA"]
[Tue Aug 18 12:59:32.683776 2026] [security2:error] [pid 123784:tid 124028] [client 158.23.17.4:20196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/22.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiswAAAG4"]
[Tue Aug 18 12:59:32.729315 2026] [security2:error] [pid 123784:tid 123973] [client 213.35.127.232:64303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiuQAAADc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:32.832831 2026] [security2:error] [pid 123784:tid 123953] [client 20.38.3.247:35142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/aaa.php"] [unique_id "aoSBZGwDnJBNj2tDbYbivQAAACM"]
[Tue Aug 18 12:59:32.833038 2026] [security2:error] [pid 123784:tid 123925] [client 68.155.154.236:27528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/opsqt.php"] [unique_id "aoSBZGwDnJBNj2tDbYbivgAAAAc"]
[Tue Aug 18 12:59:32.857835 2026] [security2:error] [pid 123784:tid 124037] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiwAAAAHc"]
[Tue Aug 18 12:59:32.892044 2026] [security2:error] [pid 123784:tid 124039] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSBZGwDnJBNj2tDbYbixAAAAHk"]
[Tue Aug 18 12:59:32.894363 2026] [security2:error] [pid 123784:tid 123933] [client 20.25.139.174:4698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/archive.php"] [unique_id "aoSBZGwDnJBNj2tDbYbixQAAAA8"]
[Tue Aug 18 12:59:32.899936 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:32.900195 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:32.902464 2026] [autoindex:error] [pid 123784:tid 124040] [client 132.196.30.78:22119] AH01276: Cannot serve directory /home3/cadema/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:32.943235 2026] [security2:error] [pid 123784:tid 124033] [client 172.202.39.151:44508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiywAAAHM"]
[Tue Aug 18 12:59:33.012400 2026] [security2:error] [pid 123784:tid 123999] [client 20.119.58.187:10541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/alfa.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi0QAAAFE"]
[Tue Aug 18 12:59:33.039440 2026] [security2:error] [pid 123784:tid 124009] [client 20.25.139.174:4708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/p.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi1AAAAFs"]
[Tue Aug 18 12:59:33.047534 2026] [security2:error] [pid 123784:tid 124025] [client 132.196.30.78:22119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi1gAAAGs"]
[Tue Aug 18 12:59:33.076798 2026] [autoindex:error] [pid 123784:tid 123946] [client 169.58.72.248:50450] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:33.113982 2026] [security2:error] [pid 123784:tid 123976] [client 74.248.18.37:26446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-blogs.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi2QAAADo"]
[Tue Aug 18 12:59:33.123611 2026] [security2:error] [pid 123784:tid 123834] [remote 97.74.87.194:53128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/wp-login.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi2gAAXC0"]
[Tue Aug 18 12:59:33.128870 2026] [security2:error] [pid 123784:tid 123954] [client 132.196.30.78:20398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wap.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi3gAAACQ"]
[Tue Aug 18 12:59:33.141086 2026] [security2:error] [pid 123784:tid 123943] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-good.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi3wAAABk"]
[Tue Aug 18 12:59:33.163125 2026] [security2:error] [pid 123784:tid 123964] [client 68.221.73.131:51760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/dex.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi5AAAAC4"]
[Tue Aug 18 12:59:33.164509 2026] [security2:error] [pid 123784:tid 123951] [client 20.127.136.245:28085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/deepseek_d.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi5QAAACE"]
[Tue Aug 18 12:59:33.168391 2026] [security2:error] [pid 123784:tid 123955] [client 40.74.65.169:20338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/admin.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi5gAAACU"]
[Tue Aug 18 12:59:33.185730 2026] [security2:error] [pid 123784:tid 124015] [client 172.202.39.151:4695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/alfa.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi5wAAAGE"]
[Tue Aug 18 12:59:33.198941 2026] [authz_core:error] [pid 123784:tid 123904] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:33.199207 2026] [authz_core:error] [pid 123784:tid 123904] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:33.210325 2026] [security2:error] [pid 123784:tid 123928] [client 20.91.215.254:9919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/subdom/ant/makeasmtp.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi6gAAAAo"]
[Tue Aug 18 12:59:33.217256 2026] [security2:error] [pid 123784:tid 124017] [client 157.51.166.53:56631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi6wAAAGM"]
[Tue Aug 18 12:59:33.217401 2026] [security2:error] [pid 123784:tid 124017] [client 157.51.166.53:56631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi6wAAAGM"]
[Tue Aug 18 12:59:33.246933 2026] [security2:error] [pid 123784:tid 123975] [client 158.23.17.4:12494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/zs.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi7gAAADk"]
[Tue Aug 18 12:59:33.251683 2026] [security2:error] [pid 123784:tid 124019] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi8AAAAGU"]
[Tue Aug 18 12:59:33.290521 2026] [security2:error] [pid 123784:tid 124031] [client 168.62.48.100:5518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi8gAAAHE"]
[Tue Aug 18 12:59:33.331079 2026] [security2:error] [pid 123784:tid 124028] [client 20.38.3.247:17535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/FWAZ.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi9AAAAG4"]
[Tue Aug 18 12:59:33.365175 2026] [security2:error] [pid 123784:tid 124001] [client 20.119.58.187:10503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/as.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi9wAAAFM"]
[Tue Aug 18 12:59:33.386456 2026] [security2:error] [pid 123784:tid 124016] [client 20.104.85.180:20232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi-AAAAGI"]
[Tue Aug 18 12:59:33.387315 2026] [security2:error] [pid 123784:tid 123927] [client 20.25.139.174:4586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/bless.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi-QAAAAk"]
[Tue Aug 18 12:59:33.443996 2026] [security2:error] [pid 123784:tid 123919] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wmore1.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi-wAAAAE"]
[Tue Aug 18 12:59:33.446699 2026] [security2:error] [pid 123784:tid 123939] [client 20.38.3.247:60325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi_AAAABU"]
[Tue Aug 18 12:59:33.448073 2026] [security2:error] [pid 123784:tid 123956] [client 68.155.154.236:27572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/jvcpa.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi_QAAACY"]
[Tue Aug 18 12:59:33.503312 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:33.503565 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:33.539677 2026] [security2:error] [pid 123784:tid 124027] [client 213.202.253.4:58068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjAwAAAG0"], referer: www.google.com
[Tue Aug 18 12:59:33.573964 2026] [security2:error] [pid 123784:tid 123989] [client 20.25.139.174:4543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/php.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjBQAAAEc"]
[Tue Aug 18 12:59:33.581224 2026] [security2:error] [pid 123784:tid 123929] [client 132.196.30.78:22083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/ws83.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjBgAAAAs"]
[Tue Aug 18 12:59:33.615555 2026] [security2:error] [pid 123784:tid 123945] [client 20.250.13.23:33157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/vx.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjCQAAABs"]
[Tue Aug 18 12:59:33.627439 2026] [security2:error] [pid 123784:tid 124040] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjCwAAAHo"]
[Tue Aug 18 12:59:33.695783 2026] [security2:error] [pid 123784:tid 123949] [client 20.127.136.245:28506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/function/function.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjDQAAAB8"]
[Tue Aug 18 12:59:33.717941 2026] [security2:error] [pid 123784:tid 124030] [client 20.119.58.187:10505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/aa.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjDwAAAHA"]
[Tue Aug 18 12:59:33.736930 2026] [security2:error] [pid 123784:tid 124011] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/special.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjEAAAAF0"]
[Tue Aug 18 12:59:33.748716 2026] [security2:error] [pid 123784:tid 123973] [client 213.35.127.232:64532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjEQAAADc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:33.791251 2026] [security2:error] [pid 123784:tid 124037] [client 74.248.18.37:26442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-config.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjFAAAAHc"]
[Tue Aug 18 12:59:33.808259 2026] [security2:error] [pid 123784:tid 123990] [client 20.51.153.15:7295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/email.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjFgAAAEg"]
[Tue Aug 18 12:59:33.843001 2026] [security2:error] [pid 123784:tid 123996] [client 216.244.66.243:44416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/xxx+bet-3/"] [unique_id "aoSBZWwDnJBNj2tDbYbjGgAAAE4"]
[Tue Aug 18 12:59:33.843134 2026] [security2:error] [pid 123784:tid 123996] [client 216.244.66.243:44416] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/xxx+bet-3/"] [unique_id "aoSBZWwDnJBNj2tDbYbjGgAAAE4"]
[Tue Aug 18 12:59:33.846093 2026] [authz_core:error] [pid 123784:tid 123957] [client 192.178.4.133:50505] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:33.846359 2026] [authz_core:error] [pid 123784:tid 123957] [client 192.178.4.133:50505] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:33.847769 2026] [security2:error] [pid 123784:tid 124004] [client 20.91.215.254:9476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/system.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjGwAAAFY"]
[Tue Aug 18 12:59:33.862195 2026] [security2:error] [pid 123784:tid 123982] [client 40.74.65.169:20410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/aa2.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjHQAAAEA"]
[Tue Aug 18 12:59:33.875663 2026] [security2:error] [pid 123784:tid 123946] [client 20.251.48.93:10091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/82.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjHgAAABw"]
[Tue Aug 18 12:59:33.889136 2026] [security2:error] [pid 123784:tid 123926] [client 20.25.139.174:4728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/sagax1.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjIAAAAAg"]
[Tue Aug 18 12:59:33.982234 2026] [security2:error] [pid 123784:tid 123997] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjJAAAAE8"]
[Tue Aug 18 12:59:34.023003 2026] [security2:error] [pid 123784:tid 124012] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjJQAAAF4"]
[Tue Aug 18 12:59:34.069070 2026] [security2:error] [pid 123784:tid 124017] [client 20.51.153.15:7223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/profile.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjKAAAAGM"]
[Tue Aug 18 12:59:34.070255 2026] [security2:error] [pid 123784:tid 123943] [client 20.119.58.187:10445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/abc.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjKQAAABk"]
[Tue Aug 18 12:59:34.103030 2026] [authz_core:error] [pid 123784:tid 123885] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:34.103313 2026] [authz_core:error] [pid 123784:tid 123885] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:34.173548 2026] [security2:error] [pid 123784:tid 123936] [client 86.120.159.145:11033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjLwAAABI"]
[Tue Aug 18 12:59:34.175662 2026] [security2:error] [pid 123784:tid 123936] [client 86.120.159.145:11033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjLwAAABI"]
[Tue Aug 18 12:59:34.179790 2026] [security2:error] [pid 123784:tid 123979] [client 132.196.30.78:13633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjMAAAAD0"]
[Tue Aug 18 12:59:34.189812 2026] [security2:error] [pid 123784:tid 124036] [client 132.196.30.78:22124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/atex1.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjMwAAAHY"]
[Tue Aug 18 12:59:34.223219 2026] [security2:error] [pid 123784:tid 124013] [client 20.127.136.245:28484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/nw.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjOAAAAF8"]
[Tue Aug 18 12:59:34.244945 2026] [security2:error] [pid 123784:tid 124016] [client 158.23.17.4:47638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/lq.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjOgAAAGI"]
[Tue Aug 18 12:59:34.265931 2026] [autoindex:error] [pid 123784:tid 123971] [client 4.232.94.69:17324] AH01276: Cannot serve directory /home2/vfunnelcrmcom/public_html/wp-includes/css/dist/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:34.306640 2026] [security2:error] [pid 123784:tid 123970] [client 158.23.17.4:34122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/iz.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjPAAAADQ"]
[Tue Aug 18 12:59:34.313920 2026] [security2:error] [pid 123784:tid 123939] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/thoms.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjPQAAABU"]
[Tue Aug 18 12:59:34.342795 2026] [security2:error] [pid 123784:tid 123938] [client 20.51.153.15:7178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/summary.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjQQAAABQ"]
[Tue Aug 18 12:59:34.345058 2026] [security2:error] [pid 123784:tid 123985] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjQgAAAEM"]
[Tue Aug 18 12:59:34.354796 2026] [security2:error] [pid 123784:tid 124006] [client 172.202.39.151:4681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/lock360.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjQwAAAFg"]
[Tue Aug 18 12:59:34.396007 2026] [security2:error] [pid 123784:tid 123941] [client 20.25.139.174:4596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wpc.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjRQAAABc"]
[Tue Aug 18 12:59:34.404385 2026] [authz_core:error] [pid 123784:tid 123888] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:34.404637 2026] [authz_core:error] [pid 123784:tid 123888] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:34.423399 2026] [security2:error] [pid 123784:tid 124041] [client 20.119.58.187:10559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/av.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjRwAAAHs"]
[Tue Aug 18 12:59:34.443704 2026] [security2:error] [pid 123784:tid 123948] [client 74.248.18.37:25285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjSQAAAB4"]
[Tue Aug 18 12:59:34.506031 2026] [security2:error] [pid 123784:tid 124045] [client 20.38.3.247:64765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/site.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjTwAAAH8"]
[Tue Aug 18 12:59:34.568862 2026] [security2:error] [pid 123784:tid 123920] [client 40.74.65.169:20294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/xamp.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjUgAAAAI"]
[Tue Aug 18 12:59:34.571863 2026] [security2:error] [pid 123784:tid 123980] [client 20.91.215.254:10220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/system_log.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjUwAAAD4"]
[Tue Aug 18 12:59:34.599904 2026] [security2:error] [pid 123784:tid 123946] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjVAAAABw"]
[Tue Aug 18 12:59:34.614350 2026] [security2:error] [pid 123784:tid 123930] [client 192.141.172.134:54527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjVgAAAAw"]
[Tue Aug 18 12:59:34.614470 2026] [security2:error] [pid 123784:tid 123930] [client 192.141.172.134:54527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjVgAAAAw"]
[Tue Aug 18 12:59:34.661446 2026] [security2:error] [pid 123784:tid 123981] [client 20.51.153.15:7230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/conf.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjVwAAAD8"]
[Tue Aug 18 12:59:34.706890 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:34.707146 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:34.709827 2026] [security2:error] [pid 123784:tid 124020] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjXgAAAGY"]
[Tue Aug 18 12:59:34.739085 2026] [security2:error] [pid 123784:tid 123996] [client 20.127.136.245:28079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/xleet.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjXwAAAE4"]
[Tue Aug 18 12:59:34.761423 2026] [security2:error] [pid 123784:tid 123967] [client 158.23.17.4:20472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/you.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjYAAAADE"]
[Tue Aug 18 12:59:34.762604 2026] [security2:error] [pid 123784:tid 123958] [client 213.35.127.232:64722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjYQAAACg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:34.767736 2026] [security2:error] [pid 123784:tid 123974] [client 132.196.30.78:13647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/bgymj.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjYgAAADg"]
[Tue Aug 18 12:59:34.789911 2026] [security2:error] [pid 123784:tid 124010] [client 20.119.58.187:10549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjZQAAAFw"]
[Tue Aug 18 12:59:34.809111 2026] [security2:error] [pid 123784:tid 123975] [client 68.155.154.236:25368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjZwAAADk"]
[Tue Aug 18 12:59:34.840052 2026] [security2:error] [pid 123784:tid 123990] [client 132.196.30.78:22111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjawAAAEg"]
[Tue Aug 18 12:59:34.840191 2026] [autoindex:error] [pid 123784:tid 124014] [client 4.232.94.69:17324] AH01276: Cannot serve directory /home2/vfunnelcrmcom/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:34.870478 2026] [security2:error] [pid 123784:tid 124044] [client 20.203.138.185:23411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/zz.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjbAAAAH4"]
[Tue Aug 18 12:59:34.890392 2026] [security2:error] [pid 123784:tid 123932] [client 20.25.139.174:4727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/fone1.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjcAAAAA4"]
[Tue Aug 18 12:59:34.905898 2026] [security2:error] [pid 123784:tid 123942] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/root.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjcgAAABg"]
[Tue Aug 18 12:59:34.948278 2026] [security2:error] [pid 123784:tid 123985] [client 20.104.85.180:43531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjeAAAAEM"]
[Tue Aug 18 12:59:34.952870 2026] [security2:error] [pid 123784:tid 124006] [client 20.51.153.15:7279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/bala.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjeQAAAFg"]
[Tue Aug 18 12:59:35.010475 2026] [authz_core:error] [pid 123784:tid 123915] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:35.010935 2026] [authz_core:error] [pid 123784:tid 123915] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:35.011229 2026] [security2:error] [pid 123784:tid 123929] [client 20.38.3.247:15261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/ccc.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjgAAAAAs"]
[Tue Aug 18 12:59:35.026649 2026] [security2:error] [pid 123784:tid 124041] [client 158.23.17.4:31901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/se.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjggAAAHs"]
[Tue Aug 18 12:59:35.045517 2026] [security2:error] [pid 123784:tid 123936] [client 79.127.164.8:58670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/temp.bak"] [unique_id "aoSBZ2wDnJBNj2tDbYbjgwAAABI"], referer: https://medihub.com.br/temp.bak
[Tue Aug 18 12:59:35.047515 2026] [security2:error] [pid 123784:tid 123933] [client 4.232.94.69:17324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-block.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjhQAAAA8"]
[Tue Aug 18 12:59:35.068872 2026] [security2:error] [pid 123784:tid 123949] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjiQAAAB8"]
[Tue Aug 18 12:59:35.128438 2026] [security2:error] [pid 123784:tid 123983] [client 20.104.85.180:22852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-good.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjjQAAAEE"]
[Tue Aug 18 12:59:35.149242 2026] [security2:error] [pid 123784:tid 123925] [client 20.119.58.187:10516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/asus.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjjwAAAAc"]
[Tue Aug 18 12:59:35.163587 2026] [security2:error] [pid 123784:tid 124022] [client 172.202.39.151:60118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjkwAAAGg"]
[Tue Aug 18 12:59:35.183200 2026] [security2:error] [pid 123784:tid 123790] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/web/.env"] [unique_id "aoSBZ2wDnJBNj2tDbYbjlQAABgE"]
[Tue Aug 18 12:59:35.193255 2026] [security2:error] [pid 123784:tid 124009] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/fpwch.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjmwAAAFs"]
[Tue Aug 18 12:59:35.199569 2026] [security2:error] [pid 123784:tid 123980] [client 20.51.153.15:7258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/222.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjnQAAAD4"]
[Tue Aug 18 12:59:35.237800 2026] [security2:error] [pid 123784:tid 124013] [client 74.248.18.37:26447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-content.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjoAAAAF8"]
[Tue Aug 18 12:59:35.248467 2026] [security2:error] [pid 123784:tid 123953] [client 20.91.215.254:10210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/templates/beez3/error.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjogAAACM"]
[Tue Aug 18 12:59:35.258386 2026] [security2:error] [pid 123784:tid 123926] [client 40.74.65.169:20353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/bless.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjowAAAAg"]
[Tue Aug 18 12:59:35.267653 2026] [security2:error] [pid 123784:tid 123876] [remote 95.111.251.70:53738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.251.111.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sci.atlas-ia.com"] [uri "/wp-login.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjpQAAdFc"]
[Tue Aug 18 12:59:35.306537 2026] [security2:error] [pid 123784:tid 123954] [client 20.104.85.180:43551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/o.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjqAAAACQ"]
[Tue Aug 18 12:59:35.309817 2026] [security2:error] [pid 123784:tid 123973] [client 20.127.136.245:28076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjqQAAADc"]
[Tue Aug 18 12:59:35.311200 2026] [security2:error] [pid 123784:tid 123923] [client 20.215.241.237:52705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/nox.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjqgAAAAU"]
[Tue Aug 18 12:59:35.313034 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:35.313473 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:35.390173 2026] [security2:error] [pid 123784:tid 124035] [client 132.196.30.78:22092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/aa.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjrgAAAHU"]
[Tue Aug 18 12:59:35.390186 2026] [security2:error] [pid 123784:tid 123982] [client 20.25.139.174:4511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/ncx.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjrwAAAEA"]
[Tue Aug 18 12:59:35.392466 2026] [security2:error] [pid 123784:tid 123958] [client 68.155.154.236:25353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjsAAAACg"]
[Tue Aug 18 12:59:35.396844 2026] [security2:error] [pid 123784:tid 124023] [client 168.62.48.100:5568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjsQAAAGk"]
[Tue Aug 18 12:59:35.420458 2026] [security2:error] [pid 123784:tid 123965] [client 132.196.30.78:13644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/w.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjswAAAC8"]
[Tue Aug 18 12:59:35.425318 2026] [security2:error] [pid 123784:tid 123961] [client 20.203.138.185:52700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/xa.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjtAAAACs"]
[Tue Aug 18 12:59:35.431778 2026] [security2:error] [pid 123784:tid 124018] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjtQAAAGQ"]
[Tue Aug 18 12:59:35.454196 2026] [security2:error] [pid 123784:tid 124017] [client 20.38.3.247:9358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/admin.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjtwAAAGM"]
[Tue Aug 18 12:59:35.468420 2026] [security2:error] [pid 123784:tid 123935] [client 20.51.153.15:7273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/routes.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjuAAAABE"]
[Tue Aug 18 12:59:35.469523 2026] [security2:error] [pid 123784:tid 123990] [client 158.23.17.4:20391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ez.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjuQAAAEg"]
[Tue Aug 18 12:59:35.500947 2026] [security2:error] [pid 123784:tid 124044] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/mg.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjugAAAH4"]
[Tue Aug 18 12:59:35.503874 2026] [security2:error] [pid 123784:tid 124012] [client 20.119.58.187:10540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/about.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjuwAAAF4"]
[Tue Aug 18 12:59:35.510577 2026] [security2:error] [pid 123784:tid 123986] [client 172.182.200.96:14082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/mt/byp.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjvAAAAEQ"]
[Tue Aug 18 12:59:35.547765 2026] [authz_core:error] [pid 123784:tid 123811] [remote 57.141.22.113:41714] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:35.548209 2026] [authz_core:error] [pid 123784:tid 123811] [remote 57.141.22.113:41714] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:35.590438 2026] [security2:error] [pid 123784:tid 123970] [client 20.104.85.180:43536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/bb.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjwgAAADQ"]
[Tue Aug 18 12:59:35.607847 2026] [authz_core:error] [pid 123784:tid 123803] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:35.608108 2026] [authz_core:error] [pid 123784:tid 123803] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:35.722483 2026] [security2:error] [pid 123784:tid 123936] [client 20.251.48.93:10096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/dex.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjzAAAABI"]
[Tue Aug 18 12:59:35.773594 2026] [security2:error] [pid 123784:tid 124024] [client 20.127.136.245:28482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/155.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj0gAAAGo"]
[Tue Aug 18 12:59:35.777557 2026] [security2:error] [pid 123784:tid 123928] [client 213.35.127.232:64948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj1AAAAAo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:35.792335 2026] [security2:error] [pid 123784:tid 124007] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/reop3.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj1QAAAFk"]
[Tue Aug 18 12:59:35.792359 2026] [security2:error] [pid 123784:tid 124030] [client 68.155.154.236:27548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj1gAAAHA"]
[Tue Aug 18 12:59:35.796587 2026] [security2:error] [pid 123784:tid 123983] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/rezor.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj2AAAAEE"]
[Tue Aug 18 12:59:35.811957 2026] [security2:error] [pid 123784:tid 124022] [client 20.51.153.15:7195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/php5.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj2gAAAGg"]
[Tue Aug 18 12:59:35.855914 2026] [security2:error] [pid 123784:tid 124001] [client 20.119.58.187:10518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/atomlib.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj2wAAAFM"]
[Tue Aug 18 12:59:35.876544 2026] [security2:error] [pid 123784:tid 123980] [client 20.104.85.180:6922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj3QAAAD4"]
[Tue Aug 18 12:59:35.888504 2026] [security2:error] [pid 123784:tid 123978] [client 20.91.215.254:18771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/test.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj3wAAADw"]
[Tue Aug 18 12:59:35.910394 2026] [security2:error] [pid 123784:tid 123966] [client 20.25.139.174:4494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj4gAAADA"]
[Tue Aug 18 12:59:35.932556 2026] [security2:error] [pid 123784:tid 123973] [client 20.38.3.247:9346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/reviall.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj5wAAADc"]
[Tue Aug 18 12:59:35.957176 2026] [security2:error] [pid 123784:tid 123951] [client 40.74.65.169:20293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/file25.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj7QAAACE"]
[Tue Aug 18 12:59:35.969910 2026] [security2:error] [pid 123784:tid 124040] [client 4.232.94.69:19685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wk/index.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj7wAAAHo"]
[Tue Aug 18 12:59:35.975286 2026] [security2:error] [pid 123784:tid 123961] [client 158.23.17.4:57233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/vp.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj8AAAACs"]
[Tue Aug 18 12:59:36.064351 2026] [security2:error] [pid 123784:tid 123984] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/php5.php"] [unique_id "aoSBaGwDnJBNj2tDbYbj9gAAAEI"]
[Tue Aug 18 12:59:36.111267 2026] [security2:error] [pid 123784:tid 123922] [client 132.196.30.78:22096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/archive.php"] [unique_id "aoSBaGwDnJBNj2tDbYbj-gAAAAQ"]
[Tue Aug 18 12:59:36.130799 2026] [security2:error] [pid 123784:tid 123999] [client 20.51.153.15:7266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/Black.php"] [unique_id "aoSBaGwDnJBNj2tDbYbj_QAAAFE"]
[Tue Aug 18 12:59:36.162242 2026] [security2:error] [pid 123784:tid 124010] [client 20.250.13.23:33156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wap.php"] [unique_id "aoSBaGwDnJBNj2tDbYbj_wAAAFw"]
[Tue Aug 18 12:59:36.162406 2026] [security2:error] [pid 123784:tid 124031] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkAAAAAHE"]
[Tue Aug 18 12:59:36.206778 2026] [security2:error] [pid 123784:tid 123918] [client 20.119.58.187:10537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSBaGwDnJBNj2tDbYbkBgAAAAA"]
[Tue Aug 18 12:59:36.211821 2026] [authz_core:error] [pid 123784:tid 123831] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:36.212082 2026] [authz_core:error] [pid 123784:tid 123831] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:36.237222 2026] [security2:error] [pid 123784:tid 123940] [client 68.221.73.131:49775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/puc.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkCAAAABY"]
[Tue Aug 18 12:59:36.288241 2026] [security2:error] [pid 123784:tid 123936] [client 68.155.154.236:25370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkCwAAABI"]
[Tue Aug 18 12:59:36.302186 2026] [security2:error] [pid 123784:tid 124042] [client 74.248.18.37:26452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkDAAAAHw"]
[Tue Aug 18 12:59:36.303923 2026] [security2:error] [pid 123784:tid 124042] [client 216.244.66.243:44418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.jclareteimoveis.com.br"] [uri "/fatal+model+em+eunapolis+bahia-2/"] [unique_id "aoSBaGwDnJBNj2tDbYbkDgAAAHw"]
[Tue Aug 18 12:59:36.304017 2026] [security2:error] [pid 123784:tid 124042] [client 216.244.66.243:44418] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.jclareteimoveis.com.br"] [uri "/fatal+model+em+eunapolis+bahia-2/"] [unique_id "aoSBaGwDnJBNj2tDbYbkDgAAAHw"]
[Tue Aug 18 12:59:36.310132 2026] [security2:error] [pid 123784:tid 123949] [client 158.23.17.4:56545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/asus.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkEAAAAB8"]
[Tue Aug 18 12:59:36.361516 2026] [security2:error] [pid 123784:tid 124022] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/acp.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkFQAAAGg"]
[Tue Aug 18 12:59:36.408120 2026] [security2:error] [pid 123784:tid 123969] [client 20.25.139.174:4597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wso.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkGgAAADM"]
[Tue Aug 18 12:59:36.415594 2026] [security2:error] [pid 123784:tid 123992] [client 20.104.85.180:18719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/tes.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkGwAAAEo"]
[Tue Aug 18 12:59:36.420541 2026] [security2:error] [pid 123784:tid 124043] [client 20.127.136.245:28061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/96i.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkHAAAAH0"]
[Tue Aug 18 12:59:36.439326 2026] [security2:error] [pid 123784:tid 124004] [client 20.51.153.15:7199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/filesystems.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkHQAAAFY"]
[Tue Aug 18 12:59:36.458936 2026] [security2:error] [pid 123784:tid 124045] [client 132.196.30.78:15018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkHwAAAH8"]
[Tue Aug 18 12:59:36.518612 2026] [security2:error] [pid 123784:tid 124014] [client 20.91.215.254:18779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/test1.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkJgAAAGA"]
[Tue Aug 18 12:59:36.530814 2026] [security2:error] [pid 123784:tid 123968] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkKQAAADI"]
[Tue Aug 18 12:59:36.561009 2026] [security2:error] [pid 123784:tid 123998] [client 20.119.58.187:10542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/b.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkKwAAAFA"]
[Tue Aug 18 12:59:36.657483 2026] [security2:error] [pid 123784:tid 124023] [client 40.74.65.169:20331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/file15.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkMQAAAGk"]
[Tue Aug 18 12:59:36.685361 2026] [security2:error] [pid 123784:tid 123959] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/yas.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkMgAAACk"]
[Tue Aug 18 12:59:36.711898 2026] [security2:error] [pid 123784:tid 123935] [client 68.155.154.236:27564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkNQAAABE"]
[Tue Aug 18 12:59:36.734322 2026] [security2:error] [pid 123784:tid 124013] [client 20.51.153.15:7190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/showphpinfo.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkOgAAAF8"]
[Tue Aug 18 12:59:36.790203 2026] [security2:error] [pid 123784:tid 123962] [client 213.35.127.232:65164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkPgAAACw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:36.814935 2026] [authz_core:error] [pid 123784:tid 123864] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:36.815192 2026] [authz_core:error] [pid 123784:tid 123864] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:36.816118 2026] [security2:error] [pid 123784:tid 123994] [client 20.104.85.180:25795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/files/index.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkQQAAAEw"]
[Tue Aug 18 12:59:36.843259 2026] [security2:error] [pid 123784:tid 123931] [client 4.232.94.69:31569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/w.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkQgAAAA0"]
[Tue Aug 18 12:59:36.855930 2026] [security2:error] [pid 123784:tid 123954] [client 132.196.30.78:22141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/bless.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkRQAAACQ"]
[Tue Aug 18 12:59:36.887909 2026] [security2:error] [pid 123784:tid 123944] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/index/function.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkSgAAABo"]
[Tue Aug 18 12:59:36.913107 2026] [security2:error] [pid 123784:tid 123923] [client 20.119.58.187:10535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/buy.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkTQAAAAU"]
[Tue Aug 18 12:59:36.918791 2026] [security2:error] [pid 123784:tid 123986] [client 20.127.136.245:28036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/as.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkTgAAAEQ"]
[Tue Aug 18 12:59:36.950507 2026] [security2:error] [pid 123784:tid 124036] [client 103.184.169.37:42643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkUQAAAHY"]
[Tue Aug 18 12:59:36.950619 2026] [security2:error] [pid 123784:tid 124036] [client 103.184.169.37:42643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkUQAAAHY"]
[Tue Aug 18 12:59:36.967652 2026] [security2:error] [pid 123784:tid 124016] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/ah25.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkUwAAAGI"]
[Tue Aug 18 12:59:37.046319 2026] [security2:error] [pid 123784:tid 124042] [client 158.23.17.4:57247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ph.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkWAAAAHw"]
[Tue Aug 18 12:59:37.065738 2026] [security2:error] [pid 123784:tid 123991] [client 20.25.139.174:4473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/zup.php73"] [unique_id "aoSBaWwDnJBNj2tDbYbkWQAAAEk"]
[Tue Aug 18 12:59:37.078513 2026] [security2:error] [pid 123784:tid 124030] [client 20.51.153.15:7258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/phpstatus.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkWgAAAHA"]
[Tue Aug 18 12:59:37.140312 2026] [security2:error] [pid 123784:tid 123978] [client 103.120.71.157:20045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkYwAAADw"]
[Tue Aug 18 12:59:37.140449 2026] [security2:error] [pid 123784:tid 123978] [client 103.120.71.157:20045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkYwAAADw"]
[Tue Aug 18 12:59:37.158973 2026] [security2:error] [pid 123784:tid 124028] [client 20.91.215.254:10189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/text.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkZAAAAG4"]
[Tue Aug 18 12:59:37.171408 2026] [security2:error] [pid 123784:tid 124027] [client 132.196.30.78:14600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/bolt.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkZwAAAG0"]
[Tue Aug 18 12:59:37.221090 2026] [security2:error] [pid 123784:tid 124006] [client 74.248.18.37:7804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-content/ad4599c5/admin.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkdQAAAFg"]
[Tue Aug 18 12:59:37.240671 2026] [security2:error] [pid 123784:tid 123980] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/ano.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkdwAAAD4"]
[Tue Aug 18 12:59:37.248684 2026] [security2:error] [pid 123784:tid 123974] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkeAAAADg"]
[Tue Aug 18 12:59:37.265254 2026] [security2:error] [pid 123784:tid 124022] [client 20.119.58.187:10523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/bless.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkeQAAAGg"]
[Tue Aug 18 12:59:37.273362 2026] [security2:error] [pid 123784:tid 123920] [client 149.34.210.141:49891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkewAAAAI"]
[Tue Aug 18 12:59:37.316100 2026] [security2:error] [pid 123784:tid 123926] [client 20.51.153.15:7290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/del.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkfwAAAAg"]
[Tue Aug 18 12:59:37.337606 2026] [security2:error] [pid 123784:tid 123966] [client 40.74.65.169:42457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/f35.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkggAAADA"]
[Tue Aug 18 12:59:37.339372 2026] [security2:error] [pid 123784:tid 123933] [client 20.104.85.180:18759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkgwAAAA8"]
[Tue Aug 18 12:59:37.386666 2026] [security2:error] [pid 123784:tid 123992] [client 20.127.136.245:28488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/min.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkhgAAAEo"]
[Tue Aug 18 12:59:37.424214 2026] [security2:error] [pid 123784:tid 124033] [client 20.100.169.31:21223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/atomlib.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkiAAAAHM"]
[Tue Aug 18 12:59:37.446547 2026] [security2:error] [pid 123784:tid 123918] [client 20.250.13.23:31087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkiQAAAAA"]
[Tue Aug 18 12:59:37.470048 2026] [security2:error] [pid 123784:tid 123958] [client 20.38.3.247:15237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/nope.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkiwAAACg"]
[Tue Aug 18 12:59:37.514293 2026] [security2:error] [pid 123784:tid 124005] [client 172.202.39.151:40942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkjAAAAFc"]
[Tue Aug 18 12:59:37.539873 2026] [security2:error] [pid 123784:tid 123920] [client 149.34.210.141:49891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkewAAAAI"]
[Tue Aug 18 12:59:37.545098 2026] [security2:error] [pid 123784:tid 123935] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/nwflm.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkkQAAABE"]
[Tue Aug 18 12:59:37.573414 2026] [security2:error] [pid 123784:tid 123996] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkjgAATgQ"]
[Tue Aug 18 12:59:37.583390 2026] [security2:error] [pid 123784:tid 123976] [client 68.155.154.236:27553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkkwAAADo"]
[Tue Aug 18 12:59:37.586354 2026] [security2:error] [pid 123784:tid 123998] [client 20.25.139.174:4696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/k.php"] [unique_id "aoSBaWwDnJBNj2tDbYbklAAAAFA"]
[Tue Aug 18 12:59:37.593595 2026] [security2:error] [pid 123784:tid 123924] [client 20.203.138.185:51314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/f6.php"] [unique_id "aoSBaWwDnJBNj2tDbYbklQAAAAY"]
[Tue Aug 18 12:59:37.612832 2026] [security2:error] [pid 123784:tid 123994] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/Cachex.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkmAAAAEw"]
[Tue Aug 18 12:59:37.615982 2026] [security2:error] [pid 123784:tid 123988] [client 20.51.153.15:7175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/moderator.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkmQAAAEY"]
[Tue Aug 18 12:59:37.619019 2026] [security2:error] [pid 123784:tid 123955] [client 20.119.58.187:10545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkmgAAACU"]
[Tue Aug 18 12:59:37.632570 2026] [security2:error] [pid 123784:tid 123922] [client 172.182.200.96:7626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSBaWwDnJBNj2tDbYbknAAAAAQ"]
[Tue Aug 18 12:59:37.689141 2026] [security2:error] [pid 123784:tid 123919] [client 157.20.138.62:56435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkngAAAAE"]
[Tue Aug 18 12:59:37.689307 2026] [security2:error] [pid 123784:tid 123919] [client 157.20.138.62:56435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkngAAAAE"]
[Tue Aug 18 12:59:37.691019 2026] [security2:error] [pid 123784:tid 123997] [client 158.23.17.4:20194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/s.php"] [unique_id "aoSBaWwDnJBNj2tDbYbknwAAAE8"]
[Tue Aug 18 12:59:37.722432 2026] [authz_core:error] [pid 123784:tid 123804] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:37.722906 2026] [authz_core:error] [pid 123784:tid 123804] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:37.738623 2026] [security2:error] [pid 123784:tid 124015] [client 132.196.30.78:14601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/bthil.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkpAAAAGE"]
[Tue Aug 18 12:59:37.749187 2026] [security2:error] [pid 123784:tid 124013] [client 132.196.30.78:14597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/sagax1.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkpQAAAF8"]
[Tue Aug 18 12:59:37.808997 2026] [security2:error] [pid 123784:tid 124023] [client 213.35.127.232:65388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkpgAAAGk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:37.818239 2026] [security2:error] [pid 123784:tid 123960] [client 20.91.215.254:18766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/themes/zmousse/otuz1.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkqAAAACo"]
[Tue Aug 18 12:59:37.820401 2026] [security2:error] [pid 123784:tid 123949] [client 168.62.48.100:5516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/weozh.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkqQAAAB8"]
[Tue Aug 18 12:59:37.852532 2026] [security2:error] [pid 123784:tid 124044] [client 20.51.153.15:7185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/infoinfo.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkqwAAAH4"]
[Tue Aug 18 12:59:37.857764 2026] [security2:error] [pid 123784:tid 124027] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-load.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkrQAAAG0"]
[Tue Aug 18 12:59:37.956249 2026] [security2:error] [pid 123784:tid 123977] [client 68.155.154.236:25365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSBaWwDnJBNj2tDbYbksQAAADs"]
[Tue Aug 18 12:59:37.960598 2026] [security2:error] [pid 123784:tid 123953] [client 158.23.17.4:7208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/22.php"] [unique_id "aoSBaWwDnJBNj2tDbYbksgAAACM"]
[Tue Aug 18 12:59:37.968519 2026] [security2:error] [pid 123784:tid 124045] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSBaWwDnJBNj2tDbYbktAAAAH8"]
[Tue Aug 18 12:59:37.969266 2026] [security2:error] [pid 123784:tid 123940] [client 74.248.18.37:26432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBaWwDnJBNj2tDbYbktQAAABY"]
[Tue Aug 18 12:59:37.970750 2026] [security2:error] [pid 123784:tid 123978] [client 20.119.58.187:10437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/cache.php"] [unique_id "aoSBaWwDnJBNj2tDbYbktgAAADw"]
[Tue Aug 18 12:59:37.975153 2026] [security2:error] [pid 123784:tid 124041] [client 20.38.3.247:63448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/nope.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkuAAAAHs"]
[Tue Aug 18 12:59:38.021534 2026] [security2:error] [pid 123784:tid 123945] [client 40.74.65.169:19491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-load.php"] [unique_id "aoSBamwDnJBNj2tDbYbkvAAAABs"]
[Tue Aug 18 12:59:38.079425 2026] [security2:error] [pid 123784:tid 123967] [client 20.104.85.180:19723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/images/images/about.php"] [unique_id "aoSBamwDnJBNj2tDbYbkyAAAADE"]
[Tue Aug 18 12:59:38.080222 2026] [security2:error] [pid 123784:tid 123980] [client 20.25.139.174:4556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBamwDnJBNj2tDbYbkygAAAD4"]
[Tue Aug 18 12:59:38.135983 2026] [security2:error] [pid 123784:tid 123938] [client 20.127.136.245:28321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/php8.php"] [unique_id "aoSBamwDnJBNj2tDbYbkywAAABQ"]
[Tue Aug 18 12:59:38.144997 2026] [security2:error] [pid 123784:tid 123959] [client 178.153.171.161:55978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBamwDnJBNj2tDbYbkzAAAACk"]
[Tue Aug 18 12:59:38.145177 2026] [security2:error] [pid 123784:tid 123959] [client 178.153.171.161:55978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBamwDnJBNj2tDbYbkzAAAACk"]
[Tue Aug 18 12:59:38.184666 2026] [security2:error] [pid 123784:tid 124035] [client 20.251.48.93:57523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/puc.php"] [unique_id "aoSBamwDnJBNj2tDbYbkzQAAAHU"]
[Tue Aug 18 12:59:38.196336 2026] [security2:error] [pid 123784:tid 123988] [client 20.51.153.15:7180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/c99shell.php"] [unique_id "aoSBamwDnJBNj2tDbYbkzgAAAEY"]
[Tue Aug 18 12:59:38.199261 2026] [security2:error] [pid 123784:tid 124042] [client 4.232.94.69:19648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-admin/css/wp-login.php"] [unique_id "aoSBamwDnJBNj2tDbYbkwgAAAHw"]
[Tue Aug 18 12:59:38.235117 2026] [security2:error] [pid 123784:tid 124012] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/jj.php"] [unique_id "aoSBamwDnJBNj2tDbYbk0AAAAF4"]
[Tue Aug 18 12:59:38.238458 2026] [security2:error] [pid 123784:tid 123975] [client 5.31.227.224:7818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBamwDnJBNj2tDbYbk0QAAADk"]
[Tue Aug 18 12:59:38.242787 2026] [security2:error] [pid 123784:tid 123975] [client 5.31.227.224:7818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBamwDnJBNj2tDbYbk0QAAADk"]
[Tue Aug 18 12:59:38.306266 2026] [security2:error] [pid 123784:tid 123985] [client 20.100.169.31:30799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/rip.php"] [unique_id "aoSBamwDnJBNj2tDbYbk2gAAAEM"]
[Tue Aug 18 12:59:38.324304 2026] [security2:error] [pid 123784:tid 124034] [client 20.119.58.187:10439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/content.php"] [unique_id "aoSBamwDnJBNj2tDbYbk3AAAAHQ"]
[Tue Aug 18 12:59:38.334952 2026] [security2:error] [pid 123784:tid 124002] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-2019.php"] [unique_id "aoSBamwDnJBNj2tDbYbk3QAAAFQ"]
[Tue Aug 18 12:59:38.424005 2026] [security2:error] [pid 123784:tid 124024] [client 158.23.17.4:38308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/uo.php"] [unique_id "aoSBamwDnJBNj2tDbYbk4AAAAGo"]
[Tue Aug 18 12:59:38.453290 2026] [security2:error] [pid 123784:tid 124027] [client 68.155.154.236:27569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSBamwDnJBNj2tDbYbk4wAAAG0"]
[Tue Aug 18 12:59:38.457104 2026] [security2:error] [pid 123784:tid 123950] [client 20.91.215.254:18792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/u.php"] [unique_id "aoSBamwDnJBNj2tDbYbk5QAAACA"]
[Tue Aug 18 12:59:38.460081 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:38.460346 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:38.462586 2026] [security2:error] [pid 123784:tid 124043] [client 20.51.153.15:7114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/profiler.php"] [unique_id "aoSBamwDnJBNj2tDbYbk5wAAAH0"]
[Tue Aug 18 12:59:38.480191 2026] [security2:error] [pid 123784:tid 123955] [client 132.196.30.78:22087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wpc.php"] [unique_id "aoSBamwDnJBNj2tDbYbk6QAAACU"]
[Tue Aug 18 12:59:38.515137 2026] [security2:error] [pid 123784:tid 123977] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/img.php"] [unique_id "aoSBamwDnJBNj2tDbYbk7AAAADs"]
[Tue Aug 18 12:59:38.613009 2026] [security2:error] [pid 123784:tid 123962] [client 20.38.3.247:34989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/new.php"] [unique_id "aoSBamwDnJBNj2tDbYbk9QAAACw"]
[Tue Aug 18 12:59:38.614018 2026] [security2:error] [pid 123784:tid 123848] [remote 216.73.216.206:33796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "bioarquitetar.com"] [uri "/page/2/"] [unique_id "aoSBamwDnJBNj2tDbYbk9gAAZTs"]
[Tue Aug 18 12:59:38.677649 2026] [security2:error] [pid 123784:tid 123978] [client 20.119.58.187:10525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBamwDnJBNj2tDbYbk-wAAADw"]
[Tue Aug 18 12:59:38.711232 2026] [security2:error] [pid 123784:tid 123968] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSBamwDnJBNj2tDbYbk_AAAADI"]
[Tue Aug 18 12:59:38.721332 2026] [security2:error] [pid 123784:tid 123992] [client 20.51.153.15:7218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/findes.php"] [unique_id "aoSBamwDnJBNj2tDbYbk_wAAAEo"]
[Tue Aug 18 12:59:38.748447 2026] [security2:error] [pid 123784:tid 123851] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/wp-login.php"] [unique_id "aoSBamwDnJBNj2tDbYbk8QAAcD4"], referer: https://tecpolorefrigeracaosp.com.br/login
[Tue Aug 18 12:59:38.770219 2026] [security2:error] [pid 123784:tid 123982] [client 20.127.136.245:28501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBamwDnJBNj2tDbYblAAAAAEA"]
[Tue Aug 18 12:59:38.779390 2026] [security2:error] [pid 123784:tid 124006] [client 172.202.39.151:4715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/flower.php"] [unique_id "aoSBamwDnJBNj2tDbYblAgAAAFg"]
[Tue Aug 18 12:59:38.793096 2026] [security2:error] [pid 123784:tid 123918] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/we.php"] [unique_id "aoSBamwDnJBNj2tDbYblBAAAAAA"]
[Tue Aug 18 12:59:38.800204 2026] [security2:error] [pid 123784:tid 123941] [client 79.127.164.8:43438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/temp.sql"] [unique_id "aoSBamwDnJBNj2tDbYblBQAAABc"], referer: https://medihub.com.br/temp.sql
[Tue Aug 18 12:59:38.823508 2026] [security2:error] [pid 123784:tid 123961] [client 68.155.154.236:25364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSBamwDnJBNj2tDbYblCAAAACs"]
[Tue Aug 18 12:59:38.827030 2026] [security2:error] [pid 123784:tid 124029] [client 213.35.127.232:49215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBamwDnJBNj2tDbYblCQAAAG8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:38.902218 2026] [security2:error] [pid 123784:tid 123995] [client 85.154.68.202:61557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBamwDnJBNj2tDbYblDQAAAE0"]
[Tue Aug 18 12:59:38.902337 2026] [security2:error] [pid 123784:tid 123995] [client 85.154.68.202:61557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBamwDnJBNj2tDbYblDQAAAE0"]
[Tue Aug 18 12:59:38.903268 2026] [security2:error] [pid 123784:tid 124037] [client 213.202.253.4:61323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/memberfuns.php"] [unique_id "aoSBamwDnJBNj2tDbYblDgAAAHc"], referer: www.google.com
[Tue Aug 18 12:59:38.923705 2026] [authz_core:error] [pid 123784:tid 123850] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:38.923964 2026] [authz_core:error] [pid 123784:tid 123850] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:38.930858 2026] [security2:error] [pid 123784:tid 123956] [client 68.221.73.131:10557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/inso.php"] [unique_id "aoSBamwDnJBNj2tDbYblEAAAACY"]
[Tue Aug 18 12:59:38.957028 2026] [security2:error] [pid 123784:tid 124035] [client 20.104.85.180:18751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBamwDnJBNj2tDbYblEQAAAHU"]
[Tue Aug 18 12:59:38.972144 2026] [security2:error] [pid 123784:tid 124000] [client 20.51.153.15:7282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/fedora.php"] [unique_id "aoSBamwDnJBNj2tDbYblEgAAAFI"]
[Tue Aug 18 12:59:39.041887 2026] [security2:error] [pid 123784:tid 123925] [client 20.119.58.187:10534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/css.php"] [unique_id "aoSBa2wDnJBNj2tDbYblFwAAAAc"]
[Tue Aug 18 12:59:39.056329 2026] [security2:error] [pid 123784:tid 123904] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/wp-login.php"] [unique_id "aoSBa2wDnJBNj2tDbYblGAAARnM"], referer: https://tecpolorefrigeracaosp.com.br/wp-admin/
[Tue Aug 18 12:59:39.060161 2026] [security2:error] [pid 123784:tid 123927] [client 223.185.37.47:6512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBa2wDnJBNj2tDbYblGQAAAAk"]
[Tue Aug 18 12:59:39.060267 2026] [security2:error] [pid 123784:tid 123927] [client 223.185.37.47:6512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBa2wDnJBNj2tDbYblGQAAAAk"]
[Tue Aug 18 12:59:39.064232 2026] [security2:error] [pid 123784:tid 123980] [client 132.196.30.78:22123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/x.php"] [unique_id "aoSBa2wDnJBNj2tDbYblGgAAAD4"]
[Tue Aug 18 12:59:39.070984 2026] [security2:error] [pid 123784:tid 123984] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/.cache/x.php"] [unique_id "aoSBa2wDnJBNj2tDbYblGwAAAEI"]
[Tue Aug 18 12:59:39.088076 2026] [security2:error] [pid 123784:tid 123935] [client 132.196.30.78:22085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/fone1.php"] [unique_id "aoSBa2wDnJBNj2tDbYblHAAAABE"]
[Tue Aug 18 12:59:39.089177 2026] [security2:error] [pid 123784:tid 124005] [client 20.91.215.254:18770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/updates.php"] [unique_id "aoSBa2wDnJBNj2tDbYblHgAAAFc"]
[Tue Aug 18 12:59:39.113406 2026] [security2:error] [pid 123784:tid 123872] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/wp-login.php"] [unique_id "aoSBa2wDnJBNj2tDbYblHwAAE1M"], referer: https://tecpolorefrigeracaosp.com.br/wp-admin/
[Tue Aug 18 12:59:39.209801 2026] [security2:error] [pid 123784:tid 123971] [client 68.155.154.236:27582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSBa2wDnJBNj2tDbYblJQAAADU"]
[Tue Aug 18 12:59:39.226633 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:39.227069 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:39.249124 2026] [security2:error] [pid 123784:tid 124032] [client 20.127.136.245:28306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/222.php"] [unique_id "aoSBa2wDnJBNj2tDbYblKQAAAHI"]
[Tue Aug 18 12:59:39.290746 2026] [security2:error] [pid 123784:tid 124038] [client 20.38.3.247:34975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/new.php"] [unique_id "aoSBa2wDnJBNj2tDbYblKwAAAHg"]
[Tue Aug 18 12:59:39.372480 2026] [security2:error] [pid 123784:tid 123919] [client 20.100.169.31:13018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/p.php"] [unique_id "aoSBa2wDnJBNj2tDbYblLwAAAAE"]
[Tue Aug 18 12:59:39.374606 2026] [security2:error] [pid 123784:tid 124010] [client 20.51.153.15:7201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/path.php"] [unique_id "aoSBa2wDnJBNj2tDbYblMAAAAFw"]
[Tue Aug 18 12:59:39.393695 2026] [security2:error] [pid 123784:tid 124043] [client 20.119.58.187:10524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/chosen.php"] [unique_id "aoSBa2wDnJBNj2tDbYblMgAAAH0"]
[Tue Aug 18 12:59:39.435654 2026] [security2:error] [pid 123784:tid 123978] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSBa2wDnJBNj2tDbYblMwAAADw"]
[Tue Aug 18 12:59:39.528588 2026] [authz_core:error] [pid 123784:tid 123843] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:39.529035 2026] [authz_core:error] [pid 123784:tid 123843] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:39.558403 2026] [security2:error] [pid 123784:tid 123920] [client 68.155.154.236:27549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSBa2wDnJBNj2tDbYblOQAAAAI"]
[Tue Aug 18 12:59:39.572376 2026] [security2:error] [pid 123784:tid 123998] [client 4.232.94.69:19677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-content/languages/index.php"] [unique_id "aoSBa2wDnJBNj2tDbYblOwAAAFA"]
[Tue Aug 18 12:59:39.575238 2026] [security2:error] [pid 123784:tid 124030] [client 20.203.138.185:23412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/mcs.php"] [unique_id "aoSBa2wDnJBNj2tDbYblPAAAAHA"]
[Tue Aug 18 12:59:39.683667 2026] [security2:error] [pid 123784:tid 123976] [client 20.51.153.15:7176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/456.php"] [unique_id "aoSBa2wDnJBNj2tDbYblPgAAADo"]
[Tue Aug 18 12:59:39.702696 2026] [security2:error] [pid 123784:tid 124029] [client 20.127.136.245:28529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBa2wDnJBNj2tDbYblPwAAAG8"]
[Tue Aug 18 12:59:39.709762 2026] [security2:error] [pid 123784:tid 123994] [client 37.40.227.74:56761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBa2wDnJBNj2tDbYblQAAAAEw"]
[Tue Aug 18 12:59:39.709928 2026] [security2:error] [pid 123784:tid 123994] [client 37.40.227.74:56761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBa2wDnJBNj2tDbYblQAAAAEw"]
[Tue Aug 18 12:59:39.724185 2026] [security2:error] [pid 123784:tid 123958] [client 20.91.215.254:18761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/upload/autoload_classmap.php"] [unique_id "aoSBa2wDnJBNj2tDbYblQwAAACg"]
[Tue Aug 18 12:59:39.727202 2026] [security2:error] [pid 123784:tid 124035] [client 168.62.48.100:5601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/rymmm.php"] [unique_id "aoSBa2wDnJBNj2tDbYblRAAAAHU"]
[Tue Aug 18 12:59:39.743800 2026] [security2:error] [pid 123784:tid 123995] [client 20.119.58.187:10521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/doc.php"] [unique_id "aoSBa2wDnJBNj2tDbYblSAAAAE0"]
[Tue Aug 18 12:59:39.747993 2026] [security2:error] [pid 123784:tid 124042] [client 20.38.3.247:18817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/apreset.php"] [unique_id "aoSBa2wDnJBNj2tDbYblSQAAAHw"]
[Tue Aug 18 12:59:39.769316 2026] [autoindex:error] [pid 123784:tid 123956] [client 20.25.139.174:4468] AH01276: Cannot serve directory /home3/cadema/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:39.777537 2026] [security2:error] [pid 123784:tid 123974] [client 132.196.30.78:22106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/index/function.php"] [unique_id "aoSBa2wDnJBNj2tDbYblSgAAADg"]
[Tue Aug 18 12:59:39.787776 2026] [security2:error] [pid 123784:tid 123954] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBa2wDnJBNj2tDbYblSwAAACQ"]
[Tue Aug 18 12:59:39.839386 2026] [security2:error] [pid 123784:tid 123918] [client 213.35.127.232:49405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBa2wDnJBNj2tDbYblUAAAAAA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:39.910675 2026] [security2:error] [pid 123784:tid 124008] [client 68.155.154.236:27535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSBa2wDnJBNj2tDbYblUQAAAFo"]
[Tue Aug 18 12:59:39.921555 2026] [security2:error] [pid 123784:tid 123997] [client 138.36.100.162:41816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBa2wDnJBNj2tDbYblUwAAAE8"]
[Tue Aug 18 12:59:39.921686 2026] [security2:error] [pid 123784:tid 123997] [client 138.36.100.162:41816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBa2wDnJBNj2tDbYblUwAAAE8"]
[Tue Aug 18 12:59:39.943170 2026] [security2:error] [pid 123784:tid 123987] [client 20.250.13.23:35101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/bgymj.php"] [unique_id "aoSBa2wDnJBNj2tDbYblVgAAAEU"]
[Tue Aug 18 12:59:39.987319 2026] [security2:error] [pid 123784:tid 123940] [client 20.51.153.15:7194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/SMTP.php"] [unique_id "aoSBa2wDnJBNj2tDbYblXAAAABY"]
[Tue Aug 18 12:59:40.017938 2026] [security2:error] [pid 123784:tid 123996] [client 158.23.17.4:32564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/kx.php"] [unique_id "aoSBbGwDnJBNj2tDbYblXQAAAE4"]
[Tue Aug 18 12:59:40.095682 2026] [security2:error] [pid 123784:tid 123922] [client 20.119.58.187:10498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/elp.php"] [unique_id "aoSBbGwDnJBNj2tDbYblXwAAAAQ"]
[Tue Aug 18 12:59:40.101707 2026] [security2:error] [pid 123784:tid 123950] [client 20.25.139.174:4468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/ww5.php"] [unique_id "aoSBbGwDnJBNj2tDbYblYAAAACA"]
[Tue Aug 18 12:59:40.131865 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:40.132307 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:40.146033 2026] [security2:error] [pid 123784:tid 124044] [client 74.7.228.30:36466] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "carnescapellari.top"] [uri "/index.php"] [unique_id "aoSBamwDnJBNj2tDbYbk7gAAfno"]
[Tue Aug 18 12:59:40.154590 2026] [security2:error] [pid 123784:tid 123939] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBbGwDnJBNj2tDbYblZwAAABU"]
[Tue Aug 18 12:59:40.155016 2026] [security2:error] [pid 123784:tid 124012] [client 132.196.30.78:22098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/ncx.php"] [unique_id "aoSBbGwDnJBNj2tDbYblaAAAAF4"]
[Tue Aug 18 12:59:40.175207 2026] [security2:error] [pid 123784:tid 124039] [client 20.127.136.245:28067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/info.php"] [unique_id "aoSBbGwDnJBNj2tDbYblawAAAHk"]
[Tue Aug 18 12:59:40.187850 2026] [security2:error] [pid 123784:tid 123807] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBbGwDnJBNj2tDbYblbAAABRI"]
[Tue Aug 18 12:59:40.188077 2026] [security2:error] [pid 123784:tid 123923] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBbGwDnJBNj2tDbYblbAAABRI"]
[Tue Aug 18 12:59:40.233917 2026] [security2:error] [pid 123784:tid 123952] [client 20.38.3.247:8663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/1mage.php"] [unique_id "aoSBbGwDnJBNj2tDbYblbgAAACI"]
[Tue Aug 18 12:59:40.280766 2026] [security2:error] [pid 123784:tid 124006] [client 68.155.154.236:25357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSBbGwDnJBNj2tDbYblcAAAAFg"]
[Tue Aug 18 12:59:40.304791 2026] [security2:error] [pid 123784:tid 123914] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/phpinfo.php"] [unique_id "aoSBbGwDnJBNj2tDbYblcQAASH0"]
[Tue Aug 18 12:59:40.307625 2026] [security2:error] [pid 123784:tid 123921] [client 172.202.39.151:4725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/13.php"] [unique_id "aoSBbGwDnJBNj2tDbYblcgAAAAM"]
[Tue Aug 18 12:59:40.311259 2026] [security2:error] [pid 123784:tid 123870] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/pi.php"] [unique_id "aoSBbGwDnJBNj2tDbYbldQAAMVE"]
[Tue Aug 18 12:59:40.311289 2026] [security2:error] [pid 123784:tid 123912] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/i.php"] [unique_id "aoSBbGwDnJBNj2tDbYbldgAAMXs"]
[Tue Aug 18 12:59:40.311314 2026] [security2:error] [pid 123784:tid 123891] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/info.php"] [unique_id "aoSBbGwDnJBNj2tDbYblcwAAMWY"]
[Tue Aug 18 12:59:40.311350 2026] [security2:error] [pid 123784:tid 123896] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/test.php"] [unique_id "aoSBbGwDnJBNj2tDbYbldAAAMWs"]
[Tue Aug 18 12:59:40.332575 2026] [security2:error] [pid 123784:tid 123981] [client 20.104.85.180:52583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/rip.php"] [unique_id "aoSBbGwDnJBNj2tDbYbldwAAAD8"]
[Tue Aug 18 12:59:40.354463 2026] [security2:error] [pid 123784:tid 124025] [client 20.91.215.254:18782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/uploads/admin.php"] [unique_id "aoSBbGwDnJBNj2tDbYbleQAAAGs"]
[Tue Aug 18 12:59:40.371390 2026] [security2:error] [pid 123784:tid 124030] [client 20.51.153.15:7186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/vbseo.php"] [unique_id "aoSBbGwDnJBNj2tDbYblegAAAHA"]
[Tue Aug 18 12:59:40.398684 2026] [security2:error] [pid 123784:tid 124020] [client 114.5.214.109:50415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBbGwDnJBNj2tDbYblggAAAGY"]
[Tue Aug 18 12:59:40.404700 2026] [security2:error] [pid 123784:tid 124020] [client 114.5.214.109:50415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBbGwDnJBNj2tDbYblggAAAGY"]
[Tue Aug 18 12:59:40.428119 2026] [authz_core:error] [pid 123784:tid 123884] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:40.428391 2026] [authz_core:error] [pid 123784:tid 123884] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:40.450172 2026] [security2:error] [pid 123784:tid 124007] [client 20.119.58.187:10126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/Exception-class.php"] [unique_id "aoSBbGwDnJBNj2tDbYblhQAAAFk"]
[Tue Aug 18 12:59:40.475771 2026] [security2:error] [pid 123784:tid 123991] [client 20.203.138.185:22635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/xleet.php"] [unique_id "aoSBbGwDnJBNj2tDbYblhgAAAEk"]
[Tue Aug 18 12:59:40.526832 2026] [security2:error] [pid 123784:tid 123945] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSBbGwDnJBNj2tDbYblhwAAABs"]
[Tue Aug 18 12:59:40.555958 2026] [security2:error] [pid 123784:tid 123791] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "aoSBbGwDnJBNj2tDbYbligAACQI"]
[Tue Aug 18 12:59:40.559946 2026] [security2:error] [pid 123784:tid 123790] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/app_dev.php"] [unique_id "aoSBbGwDnJBNj2tDbYbliwAACQE"]
[Tue Aug 18 12:59:40.600267 2026] [security2:error] [pid 123784:tid 123953] [client 20.25.139.174:4587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/2.php"] [unique_id "aoSBbGwDnJBNj2tDbYblkgAAACM"]
[Tue Aug 18 12:59:40.612078 2026] [security2:error] [pid 123784:tid 124015] [client 20.51.153.15:7184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/sysinfo.php"] [unique_id "aoSBbGwDnJBNj2tDbYbllAAAAGE"]
[Tue Aug 18 12:59:40.638091 2026] [security2:error] [pid 123784:tid 123954] [client 20.127.136.245:28060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/a.php"] [unique_id "aoSBbGwDnJBNj2tDbYbllgAAACQ"]
[Tue Aug 18 12:59:40.670506 2026] [security2:error] [pid 123784:tid 124013] [client 68.155.154.236:27581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSBbGwDnJBNj2tDbYblmAAAAF8"]
[Tue Aug 18 12:59:40.670899 2026] [security2:error] [pid 123784:tid 123965] [client 132.196.30.78:13632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBbGwDnJBNj2tDbYblmQAAAC8"]
[Tue Aug 18 12:59:40.737141 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:40.737591 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:40.759768 2026] [security2:error] [pid 123784:tid 123869] [remote 109.205.180.55:51256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centraldasvariedades.com.br"] [uri "/wp-login.php"] [unique_id "aoSBbGwDnJBNj2tDbYbloAAAVlA"]
[Tue Aug 18 12:59:40.761976 2026] [security2:error] [pid 123784:tid 123964] [client 132.196.30.78:22089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/aaa.php"] [unique_id "aoSBbGwDnJBNj2tDbYbloQAAAC4"]
[Tue Aug 18 12:59:40.766728 2026] [security2:error] [pid 123784:tid 123968] [client 40.74.65.169:43024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSBbGwDnJBNj2tDbYblogAAADI"]
[Tue Aug 18 12:59:40.768448 2026] [security2:error] [pid 123784:tid 123938] [client 78.46.190.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.doroincorporacoes.com.br"] [uri "/index.php"] [unique_id "aoSBa2wDnJBNj2tDbYblQQAAFE4"], referer: https://www.doroincorporacoes.com.br/
[Tue Aug 18 12:59:40.803581 2026] [security2:error] [pid 123784:tid 124033] [client 20.119.58.187:10555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/ee.php"] [unique_id "aoSBbGwDnJBNj2tDbYblqAAAAHM"]
[Tue Aug 18 12:59:40.844174 2026] [security2:error] [pid 123784:tid 123989] [client 20.38.3.247:15265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/imsc.php"] [unique_id "aoSBbGwDnJBNj2tDbYblrAAAAEc"]
[Tue Aug 18 12:59:40.852559 2026] [security2:error] [pid 123784:tid 123931] [client 213.35.127.232:49593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBbGwDnJBNj2tDbYblrgAAAA0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:40.853583 2026] [security2:error] [pid 123784:tid 123980] [client 20.250.13.23:41760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/aa.php"] [unique_id "aoSBbGwDnJBNj2tDbYblrwAAAD4"]
[Tue Aug 18 12:59:40.878964 2026] [authz_core:error] [pid 123784:tid 123817] [remote 57.141.22.113:41742] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:40.879248 2026] [authz_core:error] [pid 123784:tid 123817] [remote 57.141.22.113:41742] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:40.883619 2026] [security2:error] [pid 123784:tid 123939] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSBbGwDnJBNj2tDbYblswAAABU"]
[Tue Aug 18 12:59:40.905970 2026] [security2:error] [pid 123784:tid 124010] [client 20.51.153.15:7191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/ppinfo.php"] [unique_id "aoSBbGwDnJBNj2tDbYbltgAAAFw"]
[Tue Aug 18 12:59:40.953521 2026] [security2:error] [pid 123784:tid 123926] [client 158.23.17.4:8943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/va.php"] [unique_id "aoSBbGwDnJBNj2tDbYbluwAAAAg"]
[Tue Aug 18 12:59:40.970840 2026] [security2:error] [pid 123784:tid 123923] [client 192.141.172.134:54861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBbGwDnJBNj2tDbYblvgAAAAU"]
[Tue Aug 18 12:59:40.970982 2026] [security2:error] [pid 123784:tid 123923] [client 192.141.172.134:54861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBbGwDnJBNj2tDbYblvgAAAAU"]
[Tue Aug 18 12:59:40.984189 2026] [security2:error] [pid 123784:tid 123903] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/server-info"] [unique_id "aoSBbGwDnJBNj2tDbYblwAAAN3I"]
[Tue Aug 18 12:59:41.028868 2026] [security2:error] [pid 123784:tid 123978] [client 172.182.200.96:7592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBbWwDnJBNj2tDbYblzQAAADw"]
[Tue Aug 18 12:59:41.053710 2026] [access_compat:error] [pid 123784:tid 123895] [remote 136.66.23.178:0] AH01797: client denied by server configuration: /home4/tecpolosp/public_html/server-status
[Tue Aug 18 12:59:41.073620 2026] [security2:error] [pid 123784:tid 123811] [remote 203.99.146.53:48498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fabyfranco.com.br"] [uri "/wp-login.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl0AAAJhY"]
[Tue Aug 18 12:59:41.112920 2026] [security2:error] [pid 123784:tid 123982] [client 20.127.136.245:28039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/chosen.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl1QAAAEA"]
[Tue Aug 18 12:59:41.123856 2026] [security2:error] [pid 123784:tid 123990] [client 20.25.139.174:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl1gAAAEg"]
[Tue Aug 18 12:59:41.141390 2026] [security2:error] [pid 123784:tid 124011] [client 172.202.39.151:4461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/cc.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl2gAAAF0"]
[Tue Aug 18 12:59:41.155671 2026] [security2:error] [pid 123784:tid 124023] [client 20.119.58.187:10520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/edit.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl3AAAAGk"]
[Tue Aug 18 12:59:41.208628 2026] [security2:error] [pid 123784:tid 123985] [client 20.51.153.15:7254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/globals.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl3wAAAEM"]
[Tue Aug 18 12:59:41.226782 2026] [security2:error] [pid 123784:tid 123965] [client 68.155.154.236:4053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl4gAAAC8"]
[Tue Aug 18 12:59:41.230028 2026] [security2:error] [pid 123784:tid 123801] [remote 129.121.74.194:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.74.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tivinalili.com.br"] [uri "/wp-login.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl4AAAMAw"]
[Tue Aug 18 12:59:41.249402 2026] [security2:error] [pid 123784:tid 124014] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl4wAAAGA"]
[Tue Aug 18 12:59:41.277710 2026] [security2:error] [pid 123784:tid 123994] [client 132.196.30.78:14986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/abcd.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl6QAAAEw"]
[Tue Aug 18 12:59:41.297907 2026] [security2:error] [pid 123784:tid 123968] [client 20.38.3.247:64106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/imscjpg.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl6wAAADI"]
[Tue Aug 18 12:59:41.324113 2026] [security2:error] [pid 123784:tid 123958] [client 132.196.30.78:22131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wso.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl7QAAACg"]
[Tue Aug 18 12:59:41.332590 2026] [authz_core:error] [pid 123784:tid 123851] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:41.332876 2026] [authz_core:error] [pid 123784:tid 123851] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:41.426202 2026] [security2:error] [pid 123784:tid 123939] [client 20.203.138.185:53769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/fr/ms.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl9gAAABU"]
[Tue Aug 18 12:59:41.454367 2026] [security2:error] [pid 123784:tid 124039] [client 40.74.65.169:19505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/aaa.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl-AAAAHk"]
[Tue Aug 18 12:59:41.467359 2026] [security2:error] [pid 123784:tid 124004] [client 20.104.85.180:20252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl6gAAAFY"]
[Tue Aug 18 12:59:41.485340 2026] [security2:error] [pid 123784:tid 123996] [client 20.51.153.15:7109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/yindu.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl-wAAAE4"]
[Tue Aug 18 12:59:41.508768 2026] [security2:error] [pid 123784:tid 124027] [client 20.119.58.187:10512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/f35.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl_QAAAG0"]
[Tue Aug 18 12:59:41.572498 2026] [security2:error] [pid 123784:tid 123921] [client 68.155.154.236:25363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmBAAAAAM"]
[Tue Aug 18 12:59:41.614492 2026] [security2:error] [pid 123784:tid 123998] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmBgAAAFA"]
[Tue Aug 18 12:59:41.629560 2026] [security2:error] [pid 123784:tid 123962] [client 20.25.139.174:4674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/atomlib.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmCQAAACw"]
[Tue Aug 18 12:59:41.630783 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:41.631052 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:41.637734 2026] [security2:error] [pid 123784:tid 123978] [client 20.251.48.93:9362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/inso.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmCgAAADw"]
[Tue Aug 18 12:59:41.686872 2026] [security2:error] [pid 123784:tid 123882] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.env"] [unique_id "aoSBbWwDnJBNj2tDbYbmDgAAWF0"]
[Tue Aug 18 12:59:41.705349 2026] [security2:error] [pid 123784:tid 123967] [client 20.127.136.245:28092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-content/index.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmEAAAADE"]
[Tue Aug 18 12:59:41.826153 2026] [security2:error] [pid 123784:tid 123992] [client 132.196.30.78:14624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-good.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmFgAAAEo"]
[Tue Aug 18 12:59:41.860572 2026] [security2:error] [pid 123784:tid 124037] [client 20.119.58.187:10473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/fff.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmGQAAAHc"]
[Tue Aug 18 12:59:41.866114 2026] [security2:error] [pid 123784:tid 123926] [client 213.35.127.232:49799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmHAAAAAg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:41.867514 2026] [security2:error] [pid 123784:tid 123999] [client 20.51.153.15:7269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/sxx.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmHQAAAFE"]
[Tue Aug 18 12:59:41.915392 2026] [security2:error] [pid 123784:tid 123969] [client 68.155.154.236:27537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmJgAAADM"]
[Tue Aug 18 12:59:41.918440 2026] [security2:error] [pid 123784:tid 123814] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.env.backup"] [unique_id "aoSBbWwDnJBNj2tDbYbmJwAAcRk"]
[Tue Aug 18 12:59:41.923606 2026] [security2:error] [pid 123784:tid 123864] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.env.bak"] [unique_id "aoSBbWwDnJBNj2tDbYbmKAAAcUs"]
[Tue Aug 18 12:59:41.930758 2026] [authz_core:error] [pid 123784:tid 123845] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:41.931069 2026] [authz_core:error] [pid 123784:tid 123845] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:41.969814 2026] [security2:error] [pid 123784:tid 123985] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmKwAAAEM"]
[Tue Aug 18 12:59:41.970853 2026] [security2:error] [pid 123784:tid 123906] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.env.old"] [unique_id "aoSBbWwDnJBNj2tDbYbmKgAAcXU"]
[Tue Aug 18 12:59:41.989371 2026] [security2:error] [pid 123784:tid 124034] [client 20.38.3.247:34998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/qlex1.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmLwAAAHQ"]
[Tue Aug 18 12:59:42.005106 2026] [security2:error] [pid 123784:tid 123994] [client 20.215.241.237:43698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/akismet.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmMQAAAEw"]
[Tue Aug 18 12:59:42.014378 2026] [security2:error] [pid 123784:tid 123947] [client 132.196.30.78:22093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/zup.php73"] [unique_id "aoSBbmwDnJBNj2tDbYbmMwAAAB0"]
[Tue Aug 18 12:59:42.077511 2026] [security2:error] [pid 123784:tid 123896] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/api/.env"] [unique_id "aoSBbmwDnJBNj2tDbYbmOQAAAGs"]
[Tue Aug 18 12:59:42.116550 2026] [security2:error] [pid 123784:tid 124035] [client 158.23.17.4:31926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/fo.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmOwAAAHU"]
[Tue Aug 18 12:59:42.142715 2026] [security2:error] [pid 123784:tid 123965] [client 20.25.139.174:4713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/rip.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmPAAAAC8"]
[Tue Aug 18 12:59:42.155262 2026] [security2:error] [pid 123784:tid 123857] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/backend/.env"] [unique_id "aoSBbmwDnJBNj2tDbYbmPQAABEQ"]
[Tue Aug 18 12:59:42.160979 2026] [security2:error] [pid 123784:tid 124033] [client 40.74.65.169:20104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/gecko.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmPwAAAHM"]
[Tue Aug 18 12:59:42.164049 2026] [security2:error] [pid 123784:tid 123865] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/config/.env"] [unique_id "aoSBbmwDnJBNj2tDbYbmQAAABEw"]
[Tue Aug 18 12:59:42.214630 2026] [security2:error] [pid 123784:tid 123936] [client 20.119.58.187:10146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/ff1.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmQgAAABI"]
[Tue Aug 18 12:59:42.215361 2026] [security2:error] [pid 123784:tid 123946] [client 20.51.153.15:7106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/settings.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmQwAAABw"]
[Tue Aug 18 12:59:42.287700 2026] [security2:error] [pid 123784:tid 124015] [client 20.250.13.23:33203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmRwAAAGE"]
[Tue Aug 18 12:59:42.300765 2026] [security2:error] [pid 123784:tid 123938] [client 20.127.136.245:28045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/vx.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmSgAAABQ"]
[Tue Aug 18 12:59:42.338086 2026] [security2:error] [pid 123784:tid 123941] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmTgAAABc"]
[Tue Aug 18 12:59:42.362374 2026] [autoindex:error] [pid 123784:tid 123952] [client 169.58.72.248:60775] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:42.367371 2026] [security2:error] [pid 123784:tid 123921] [client 68.155.154.236:27577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmUgAAAAM"]
[Tue Aug 18 12:59:42.480565 2026] [security2:error] [pid 123784:tid 123976] [client 102.213.179.104:60650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmWAAAADo"]
[Tue Aug 18 12:59:42.481061 2026] [security2:error] [pid 123784:tid 123976] [client 102.213.179.104:60650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmWAAAADo"]
[Tue Aug 18 12:59:42.482781 2026] [security2:error] [pid 123784:tid 124022] [client 20.51.153.15:7224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/spip.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmWQAAAGg"]
[Tue Aug 18 12:59:42.534990 2026] [authz_core:error] [pid 123784:tid 123812] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:42.535442 2026] [authz_core:error] [pid 123784:tid 123812] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:42.549115 2026] [security2:error] [pid 123784:tid 123943] [client 158.23.17.4:25399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/zs.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmYAAAABk"]
[Tue Aug 18 12:59:42.567317 2026] [security2:error] [pid 123784:tid 124030] [client 20.119.58.187:10502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/flower.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmYQAAAHA"]
[Tue Aug 18 12:59:42.575732 2026] [security2:error] [pid 123784:tid 124029] [client 68.221.73.131:18857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/aa.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmYwAAAG8"]
[Tue Aug 18 12:59:42.638966 2026] [security2:error] [pid 123784:tid 123933] [client 20.251.48.93:9345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/aa.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmbAAAAA8"]
[Tue Aug 18 12:59:42.656333 2026] [security2:error] [pid 123784:tid 123990] [client 20.203.138.185:45493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/gool.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmbgAAAEg"]
[Tue Aug 18 12:59:42.680685 2026] [security2:error] [pid 123784:tid 123927] [client 196.12.128.158:63892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmbwAAAAk"]
[Tue Aug 18 12:59:42.680817 2026] [security2:error] [pid 123784:tid 123927] [client 196.12.128.158:63892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmbwAAAAk"]
[Tue Aug 18 12:59:42.683813 2026] [security2:error] [pid 123784:tid 123959] [client 132.196.30.78:22139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/k.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmcAAAACk"]
[Tue Aug 18 12:59:42.684489 2026] [security2:error] [pid 123784:tid 123978] [client 20.25.139.174:4600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/p.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmcQAAADw"]
[Tue Aug 18 12:59:42.715002 2026] [security2:error] [pid 123784:tid 123974] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmdQAAADg"]
[Tue Aug 18 12:59:42.717289 2026] [security2:error] [pid 123784:tid 124023] [client 20.38.3.247:64099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/mariju.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmdgAAAGk"]
[Tue Aug 18 12:59:42.723359 2026] [security2:error] [pid 123784:tid 123953] [client 68.155.154.236:4044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmdwAAACM"]
[Tue Aug 18 12:59:42.732810 2026] [security2:error] [pid 123784:tid 123982] [client 4.232.94.69:29414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/file5.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmeAAAAEA"]
[Tue Aug 18 12:59:42.762397 2026] [security2:error] [pid 123784:tid 123960] [client 132.196.30.78:13654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/simple.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmegAAACo"]
[Tue Aug 18 12:59:42.812945 2026] [security2:error] [pid 123784:tid 124001] [client 20.215.241.237:52740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/admin.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmfQAAAFM"]
[Tue Aug 18 12:59:42.834006 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:42.834266 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:42.835214 2026] [security2:error] [pid 123784:tid 123897] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.github/.env"] [unique_id "aoSBbmwDnJBNj2tDbYbmfwAAMGw"]
[Tue Aug 18 12:59:42.851640 2026] [security2:error] [pid 123784:tid 123994] [client 40.74.65.169:43015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/xiugai.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmggAAAEw"]
[Tue Aug 18 12:59:42.857020 2026] [security2:error] [pid 123784:tid 124031] [client 20.51.153.15:7265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/search.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmgwAAAHE"]
[Tue Aug 18 12:59:42.880638 2026] [security2:error] [pid 123784:tid 123937] [client 213.35.127.232:50040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmhQAAABM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:42.921637 2026] [security2:error] [pid 123784:tid 123988] [client 20.119.58.187:10515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/file.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmiAAAAEY"]
[Tue Aug 18 12:59:43.001571 2026] [security2:error] [pid 123784:tid 123970] [client 20.127.136.245:28091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wap.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmjQAAADQ"]
[Tue Aug 18 12:59:43.076264 2026] [authz_core:error] [pid 123784:tid 123799] [remote 136.66.23.178:0] AH01630: client denied by server configuration: /home4/tecpolosp/public_html/.htpasswd
[Tue Aug 18 12:59:43.088849 2026] [security2:error] [pid 123784:tid 124044] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmlAAAAH4"]
[Tue Aug 18 12:59:43.127976 2026] [security2:error] [pid 123784:tid 124039] [client 20.38.3.247:8681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmlgAAAHk"]
[Tue Aug 18 12:59:43.135905 2026] [authz_core:error] [pid 123784:tid 123895] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:43.136162 2026] [authz_core:error] [pid 123784:tid 123895] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:43.178054 2026] [security2:error] [pid 123784:tid 123984] [client 132.196.30.78:22110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmmQAAAEI"]
[Tue Aug 18 12:59:43.190029 2026] [security2:error] [pid 123784:tid 124043] [client 168.62.48.100:5604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/lddxs.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmmwAAAH0"]
[Tue Aug 18 12:59:43.216671 2026] [security2:error] [pid 123784:tid 124026] [client 68.155.154.236:27563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmngAAAGw"]
[Tue Aug 18 12:59:43.245190 2026] [security2:error] [pid 123784:tid 124024] [client 20.51.153.15:7244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/build.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmnwAAAGo"]
[Tue Aug 18 12:59:43.274285 2026] [security2:error] [pid 123784:tid 123949] [client 197.184.64.235:41951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmoQAAAB8"]
[Tue Aug 18 12:59:43.274439 2026] [security2:error] [pid 123784:tid 123949] [client 197.184.64.235:41951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmoQAAAB8"]
[Tue Aug 18 12:59:43.274867 2026] [security2:error] [pid 123784:tid 123919] [client 20.119.58.187:10495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/goods.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmogAAAAE"]
[Tue Aug 18 12:59:43.274986 2026] [security2:error] [pid 123784:tid 123980] [client 20.25.139.174:4495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/php.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmowAAAD4"]
[Tue Aug 18 12:59:43.356037 2026] [security2:error] [pid 123784:tid 124030] [client 20.104.85.180:52584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/moon.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmpwAAAHA"]
[Tue Aug 18 12:59:43.379410 2026] [security2:error] [pid 123784:tid 124015] [client 132.196.30.78:2960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/edit-tags.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmqgAAAGE"]
[Tue Aug 18 12:59:43.425107 2026] [security2:error] [pid 123784:tid 123977] [client 20.251.48.93:9616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/img.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmrAAAADs"]
[Tue Aug 18 12:59:43.460518 2026] [security2:error] [pid 123784:tid 123963] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmsQAAAC0"]
[Tue Aug 18 12:59:43.467880 2026] [security2:error] [pid 123784:tid 123830] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSBb2wDnJBNj2tDbYbmsgAAdCk"]
[Tue Aug 18 12:59:43.471984 2026] [security2:error] [pid 123784:tid 123967] [client 20.127.136.245:28041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmswAAADE"]
[Tue Aug 18 12:59:43.498995 2026] [security2:error] [pid 123784:tid 123794] [remote 108.167.161.148:29664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.161.167.108.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "paciolli.com.br"] [uri "/wp-login.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmtgAAXgU"]
[Tue Aug 18 12:59:43.533109 2026] [security2:error] [pid 123784:tid 124005] [client 20.51.153.15:7140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/defaul.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmugAAAFc"]
[Tue Aug 18 12:59:43.533793 2026] [security2:error] [pid 123784:tid 123834] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/id_rsa"] [unique_id "aoSBb2wDnJBNj2tDbYbmuQAAdC0"]
[Tue Aug 18 12:59:43.546320 2026] [security2:error] [pid 123784:tid 123960] [client 40.74.65.169:43054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/adminner.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmuwAAACo"]
[Tue Aug 18 12:59:43.626977 2026] [security2:error] [pid 123784:tid 123999] [client 20.119.58.187:10548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/g.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmwAAAAFE"]
[Tue Aug 18 12:59:43.632951 2026] [security2:error] [pid 123784:tid 123925] [client 158.23.17.4:33992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/loading.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmwQAAAAc"]
[Tue Aug 18 12:59:43.637509 2026] [security2:error] [pid 123784:tid 124036] [client 68.155.154.236:25356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmwgAAAHY"]
[Tue Aug 18 12:59:43.679009 2026] [security2:error] [pid 123784:tid 123964] [client 20.38.3.247:37121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/contacto.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmxgAAAC4"]
[Tue Aug 18 12:59:43.701499 2026] [security2:error] [pid 123784:tid 123825] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSBb2wDnJBNj2tDbYbmyAAAJSQ"]
[Tue Aug 18 12:59:43.742274 2026] [authz_core:error] [pid 123784:tid 123844] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:43.742714 2026] [authz_core:error] [pid 123784:tid 123844] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:43.803740 2026] [security2:error] [pid 123784:tid 123932] [client 20.51.153.15:7225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/twin.php"] [unique_id "aoSBb2wDnJBNj2tDbYbm0wAAAA4"]
[Tue Aug 18 12:59:43.839602 2026] [security2:error] [pid 123784:tid 123993] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBb2wDnJBNj2tDbYbm1gAAAEs"]
[Tue Aug 18 12:59:43.893795 2026] [security2:error] [pid 123784:tid 123935] [client 213.35.127.232:50259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBb2wDnJBNj2tDbYbm2AAAABE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:43.926590 2026] [security2:error] [pid 123784:tid 123995] [client 20.38.3.247:43339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBb2wDnJBNj2tDbYbm2QAAAE0"]
[Tue Aug 18 12:59:43.947221 2026] [security2:error] [pid 123784:tid 123847] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/id_dsa"] [unique_id "aoSBb2wDnJBNj2tDbYbm2gAAFTo"]
[Tue Aug 18 12:59:43.974702 2026] [security2:error] [pid 123784:tid 123924] [client 20.127.136.245:28511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/bgymj.php"] [unique_id "aoSBb2wDnJBNj2tDbYbm4AAAAAY"]
[Tue Aug 18 12:59:43.991467 2026] [security2:error] [pid 123784:tid 123972] [client 20.119.58.187:10517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBb2wDnJBNj2tDbYbm5AAAADY"]
[Tue Aug 18 12:59:43.992216 2026] [security2:error] [pid 123784:tid 123957] [client 132.196.30.78:2946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/u.php"] [unique_id "aoSBb2wDnJBNj2tDbYbm5QAAACc"]
[Tue Aug 18 12:59:44.014210 2026] [security2:error] [pid 123784:tid 124043] [client 68.155.154.236:4038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSBcGwDnJBNj2tDbYbm5gAAAH0"]
[Tue Aug 18 12:59:44.017323 2026] [security2:error] [pid 123784:tid 124040] [client 20.203.138.185:51280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/maxro.php"] [unique_id "aoSBcGwDnJBNj2tDbYbm5wAAAHo"]
[Tue Aug 18 12:59:44.039287 2026] [authz_core:error] [pid 123784:tid 123850] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:44.039564 2026] [authz_core:error] [pid 123784:tid 123850] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:44.091357 2026] [security2:error] [pid 123784:tid 124014] [client 20.250.13.23:31084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/bolt.php"] [unique_id "aoSBcGwDnJBNj2tDbYbm6gAAAGA"]
[Tue Aug 18 12:59:44.160633 2026] [security2:error] [pid 123784:tid 124003] [client 20.51.153.15:7221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/new2.php"] [unique_id "aoSBcGwDnJBNj2tDbYbm7AAAAFU"]
[Tue Aug 18 12:59:44.194122 2026] [security2:error] [pid 123784:tid 123831] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/privatekey.key"] [unique_id "aoSBcGwDnJBNj2tDbYbm8QAAMyo"]
[Tue Aug 18 12:59:44.201370 2026] [security2:error] [pid 123784:tid 124010] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBcGwDnJBNj2tDbYbm9AAAAFw"]
[Tue Aug 18 12:59:44.213664 2026] [security2:error] [pid 123784:tid 123911] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/key.pem"] [unique_id "aoSBcGwDnJBNj2tDbYbm-QAAM3o"]
[Tue Aug 18 12:59:44.243661 2026] [security2:error] [pid 123784:tid 123977] [client 20.38.3.247:15250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/image2.php"] [unique_id "aoSBcGwDnJBNj2tDbYbm-wAAADs"]
[Tue Aug 18 12:59:44.249174 2026] [security2:error] [pid 123784:tid 123933] [client 40.74.65.169:19461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/file1221.php"] [unique_id "aoSBcGwDnJBNj2tDbYbm_AAAAA8"]
[Tue Aug 18 12:59:44.291709 2026] [security2:error] [pid 123784:tid 124025] [client 172.182.200.96:14142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBcGwDnJBNj2tDbYbm_wAAAGs"]
[Tue Aug 18 12:59:44.340686 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:44.341049 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:44.350945 2026] [security2:error] [pid 123784:tid 123962] [client 20.119.58.187:10514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnBQAAACw"]
[Tue Aug 18 12:59:44.425999 2026] [security2:error] [pid 123784:tid 123959] [client 68.221.73.131:10333] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/1.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnCQAAACk"]
[Tue Aug 18 12:59:44.426118 2026] [security2:error] [pid 123784:tid 123959] [client 68.221.73.131:10333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/1.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnCQAAACk"]
[Tue Aug 18 12:59:44.441264 2026] [security2:error] [pid 123784:tid 124013] [client 20.51.153.15:7288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/rex.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnDgAAAF8"]
[Tue Aug 18 12:59:44.447385 2026] [security2:error] [pid 123784:tid 123967] [client 20.127.136.245:28498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/aa.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnDwAAADE"]
[Tue Aug 18 12:59:44.474714 2026] [security2:error] [pid 123784:tid 124019] [client 68.155.154.236:4033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnEgAAAGU"]
[Tue Aug 18 12:59:44.534608 2026] [security2:error] [pid 123784:tid 124011] [client 79.127.164.8:43514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/test.bak"] [unique_id "aoSBcGwDnJBNj2tDbYbnGQAAAF0"], referer: https://medihub.com.br/test.bak
[Tue Aug 18 12:59:44.567381 2026] [security2:error] [pid 123784:tid 123918] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/well-known/index.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnHAAAAAA"]
[Tue Aug 18 12:59:44.590859 2026] [security2:error] [pid 123784:tid 123951] [client 132.196.30.78:20476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnIAAAACE"]
[Tue Aug 18 12:59:44.591340 2026] [security2:error] [pid 123784:tid 123891] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSBcGwDnJBNj2tDbYbnHwAAM2Y"]
[Tue Aug 18 12:59:44.688744 2026] [security2:error] [pid 123784:tid 123992] [client 86.120.159.145:11293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnKAAAAEo"]
[Tue Aug 18 12:59:44.688871 2026] [security2:error] [pid 123784:tid 123992] [client 86.120.159.145:11293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnKAAAAEo"]
[Tue Aug 18 12:59:44.705192 2026] [security2:error] [pid 123784:tid 123981] [client 20.119.58.187:10536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/in.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnKQAAAD8"]
[Tue Aug 18 12:59:44.742497 2026] [security2:error] [pid 123784:tid 123936] [client 20.38.3.247:29763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/fb.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnLgAAABI"]
[Tue Aug 18 12:59:44.785183 2026] [security2:error] [pid 123784:tid 124016] [client 20.100.169.31:38131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/php.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnMQAAAGI"]
[Tue Aug 18 12:59:44.786145 2026] [autoindex:error] [pid 123784:tid 123924] [client 132.196.30.78:22138] AH01276: Cannot serve directory /home3/cadema/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:44.859409 2026] [security2:error] [pid 123784:tid 124040] [client 20.51.153.15:7283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/verification.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnNwAAAHo"]
[Tue Aug 18 12:59:44.867915 2026] [security2:error] [pid 123784:tid 123971] [client 20.104.85.180:14575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/cache.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnOAAAADU"]
[Tue Aug 18 12:59:44.874370 2026] [security2:error] [pid 123784:tid 123942] [client 68.155.154.236:4057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnOQAAABg"]
[Tue Aug 18 12:59:44.904063 2026] [security2:error] [pid 123784:tid 123876] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.hermes/.env"] [unique_id "aoSBcGwDnJBNj2tDbYbnOwAARVc"]
[Tue Aug 18 12:59:44.906830 2026] [security2:error] [pid 123784:tid 123932] [client 213.35.127.232:50459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnPAAAAA4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:44.907894 2026] [security2:error] [pid 123784:tid 123941] [client 20.203.138.185:22639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wdf.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnPQAAABc"]
[Tue Aug 18 12:59:44.931169 2026] [security2:error] [pid 123784:tid 123952] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnQAAAACI"]
[Tue Aug 18 12:59:44.941151 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:44.941421 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:44.943836 2026] [security2:error] [pid 123784:tid 123938] [client 40.74.65.169:20103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/inx.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnQwAAABQ"]
[Tue Aug 18 12:59:44.960902 2026] [security2:error] [pid 123784:tid 123972] [client 20.127.136.245:28508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-mail.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnRgAAADY"]
[Tue Aug 18 12:59:45.058748 2026] [security2:error] [pid 123784:tid 124024] [client 20.119.58.187:10444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/info.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnTQAAAGo"]
[Tue Aug 18 12:59:45.131764 2026] [security2:error] [pid 123784:tid 123973] [client 20.38.3.247:15251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/gi.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnUgAAADc"]
[Tue Aug 18 12:59:45.154948 2026] [security2:error] [pid 123784:tid 124042] [client 132.196.30.78:22138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/ww5.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnVQAAAHw"]
[Tue Aug 18 12:59:45.159389 2026] [security2:error] [pid 123784:tid 124038] [client 213.202.253.4:57502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/memberfuns.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnVgAAAHg"], referer: www.google.com
[Tue Aug 18 12:59:45.193226 2026] [security2:error] [pid 123784:tid 123955] [client 49.13.134.145:37158] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.webeb.com.br"] [uri "/index.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnJAAAACU"], referer: http://www.webeb.com.br
[Tue Aug 18 12:59:45.202914 2026] [security2:error] [pid 123784:tid 124005] [client 20.251.48.93:18425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/222.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnXgAAAFc"]
[Tue Aug 18 12:59:45.216991 2026] [security2:error] [pid 123784:tid 123996] [client 20.215.241.237:36129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/ajax.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnYAAAAE4"]
[Tue Aug 18 12:59:45.220584 2026] [security2:error] [pid 123784:tid 123940] [client 192.141.172.134:55095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnYgAAABY"]
[Tue Aug 18 12:59:45.220705 2026] [security2:error] [pid 123784:tid 123940] [client 192.141.172.134:55095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnYgAAABY"]
[Tue Aug 18 12:59:45.235214 2026] [security2:error] [pid 123784:tid 124023] [client 20.51.153.15:7233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/smtp.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnZAAAAGk"]
[Tue Aug 18 12:59:45.244980 2026] [authz_core:error] [pid 123784:tid 123822] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:45.245246 2026] [authz_core:error] [pid 123784:tid 123822] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:45.250198 2026] [security2:error] [pid 123784:tid 124013] [client 20.38.3.247:7277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/yj09.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnZgAAAF8"]
[Tue Aug 18 12:59:45.272389 2026] [authz_core:error] [pid 123784:tid 123812] [remote 57.141.14.91:30200] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:45.272680 2026] [authz_core:error] [pid 123784:tid 123812] [remote 57.141.14.91:30200] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:45.292866 2026] [security2:error] [pid 123784:tid 123994] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnbAAAAEw"]
[Tue Aug 18 12:59:45.328509 2026] [security2:error] [pid 123784:tid 123921] [client 132.196.30.78:20443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/h.php"] [unique_id "aoSBcWwDnJBNj2tDbYbncAAAAAM"]
[Tue Aug 18 12:59:45.347647 2026] [security2:error] [pid 123784:tid 123944] [client 68.155.154.236:27521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSBcWwDnJBNj2tDbYbncgAAABo"]
[Tue Aug 18 12:59:45.410930 2026] [security2:error] [pid 123784:tid 123966] [client 20.119.58.187:10511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/inputs.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnegAAADA"]
[Tue Aug 18 12:59:45.478096 2026] [security2:error] [pid 123784:tid 123992] [client 20.51.153.15:7250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/teste.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnfwAAAEo"]
[Tue Aug 18 12:59:45.516378 2026] [security2:error] [pid 123784:tid 124000] [client 20.127.136.245:28083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/bolt.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnggAAAFI"]
[Tue Aug 18 12:59:45.548206 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:45.548668 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:45.580343 2026] [security2:error] [pid 123784:tid 123827] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/laravel/.env"] [unique_id "aoSBcWwDnJBNj2tDbYbniQAAMyY"]
[Tue Aug 18 12:59:45.592889 2026] [security2:error] [pid 123784:tid 124033] [client 3.149.0.107:59994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.natupedras.com.br"] [uri "/robots.txt"] [unique_id "aoSBcWwDnJBNj2tDbYbnjAAAAHM"]
[Tue Aug 18 12:59:45.599960 2026] [security2:error] [pid 123784:tid 123979] [client 158.23.17.4:34042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ke.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnjQAAAD0"]
[Tue Aug 18 12:59:45.620591 2026] [security2:error] [pid 123784:tid 124040] [client 40.74.65.169:42489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/reviall.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnjwAAAHo"]
[Tue Aug 18 12:59:45.639380 2026] [security2:error] [pid 123784:tid 123895] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/config/.env.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnlgAAM2o"]
[Tue Aug 18 12:59:45.642165 2026] [security2:error] [pid 123784:tid 123942] [client 20.38.3.247:15232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/video.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnlwAAABg"]
[Tue Aug 18 12:59:45.658796 2026] [security2:error] [pid 123784:tid 124027] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnmAAAAG0"]
[Tue Aug 18 12:59:45.753606 2026] [security2:error] [pid 123784:tid 123938] [client 20.251.48.93:18423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/key.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnnAAAABQ"]
[Tue Aug 18 12:59:45.765595 2026] [security2:error] [pid 123784:tid 123947] [client 20.119.58.187:10455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/item.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnnQAAAB0"]
[Tue Aug 18 12:59:45.801711 2026] [security2:error] [pid 123784:tid 124016] [client 132.196.30.78:20453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/2.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnngAAAGI"]
[Tue Aug 18 12:59:45.804311 2026] [security2:error] [pid 123784:tid 123987] [client 68.155.154.236:4045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnoAAAAEU"]
[Tue Aug 18 12:59:45.813953 2026] [authz_core:error] [pid 123784:tid 123826] [remote 57.141.22.18:41402] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:45.814214 2026] [authz_core:error] [pid 123784:tid 123826] [remote 57.141.22.18:41402] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:45.815033 2026] [security2:error] [pid 123784:tid 124030] [client 20.51.153.15:7267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/local.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnogAAAHA"]
[Tue Aug 18 12:59:45.825885 2026] [security2:error] [pid 123784:tid 123797] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.env.php.bak"] [unique_id "aoSBcWwDnJBNj2tDbYbnpQAAWQg"]
[Tue Aug 18 12:59:45.916399 2026] [security2:error] [pid 123784:tid 123866] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/config.php.bak"] [unique_id "aoSBcWwDnJBNj2tDbYbnqwAAG00"]
[Tue Aug 18 12:59:45.916488 2026] [security2:error] [pid 123784:tid 123831] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSBcWwDnJBNj2tDbYbnrAAAGyo"]
[Tue Aug 18 12:59:45.928835 2026] [security2:error] [pid 123784:tid 123957] [client 213.35.127.232:50673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnrwAAACc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:45.942921 2026] [security2:error] [pid 123784:tid 123843] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/core/.env"] [unique_id "aoSBcWwDnJBNj2tDbYbnsQAAQDY"]
[Tue Aug 18 12:59:45.972475 2026] [security2:error] [pid 123784:tid 123970] [client 20.38.3.247:15245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/hel.php"] [unique_id "aoSBcWwDnJBNj2tDbYbntAAAADQ"]
[Tue Aug 18 12:59:46.026015 2026] [security2:error] [pid 123784:tid 123980] [client 20.127.136.245:28315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/bthil.php"] [unique_id "aoSBcmwDnJBNj2tDbYbnuQAAAD4"]
[Tue Aug 18 12:59:46.035445 2026] [security2:error] [pid 123784:tid 123997] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/mt/byp.php"] [unique_id "aoSBcmwDnJBNj2tDbYbnugAAAE8"]
[Tue Aug 18 12:59:46.057431 2026] [authz_core:error] [pid 123784:tid 123908] [remote 57.141.22.34:36012] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:46.057696 2026] [authz_core:error] [pid 123784:tid 123908] [remote 57.141.22.34:36012] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:46.060390 2026] [security2:error] [pid 123784:tid 123893] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.env.swp"] [unique_id "aoSBcmwDnJBNj2tDbYbnvQAAQGg"]
[Tue Aug 18 12:59:46.062662 2026] [security2:error] [pid 123784:tid 124029] [client 20.51.153.15:7216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/wp_sitting.php"] [unique_id "aoSBcmwDnJBNj2tDbYbnvgAAAG8"]
[Tue Aug 18 12:59:46.075795 2026] [security2:error] [pid 123784:tid 124006] [client 172.202.39.151:52913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/admin.php"] [unique_id "aoSBcmwDnJBNj2tDbYbnvwAAAFg"]
[Tue Aug 18 12:59:46.116769 2026] [security2:error] [pid 123784:tid 123944] [client 20.119.58.187:10558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/k.php"] [unique_id "aoSBcmwDnJBNj2tDbYbnxQAAABo"]
[Tue Aug 18 12:59:46.143183 2026] [security2:error] [pid 123784:tid 123874] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/public/.env"] [unique_id "aoSBcmwDnJBNj2tDbYbnyQAAKFU"]
[Tue Aug 18 12:59:46.158852 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:46.159306 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:46.176627 2026] [security2:error] [pid 123784:tid 123992] [client 68.155.154.236:25380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBcmwDnJBNj2tDbYbnzgAAAEo"]
[Tue Aug 18 12:59:46.190325 2026] [security2:error] [pid 123784:tid 124000] [client 20.203.138.185:24946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ff1.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn0gAAAFI"]
[Tue Aug 18 12:59:46.302954 2026] [security2:error] [pid 123784:tid 124027] [client 20.118.133.132:22737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/bajah.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn2QAAAG0"]
[Tue Aug 18 12:59:46.319197 2026] [security2:error] [pid 123784:tid 124020] [client 40.74.65.169:20372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/11.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn2gAAAGY"]
[Tue Aug 18 12:59:46.330569 2026] [security2:error] [pid 123784:tid 123959] [client 3.149.0.107:59992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "natupedras.com.br"] [uri "/"] [unique_id "aoSBcmwDnJBNj2tDbYbn2wAAACk"]
[Tue Aug 18 12:59:46.349558 2026] [security2:error] [pid 123784:tid 123969] [client 20.51.153.15:7219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/ninja.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn3QAAADM"]
[Tue Aug 18 12:59:46.372305 2026] [security2:error] [pid 123784:tid 123972] [client 132.196.30.78:20437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn4AAAADY"]
[Tue Aug 18 12:59:46.378493 2026] [security2:error] [pid 123784:tid 123947] [client 158.23.17.4:44855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/nh.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn4gAAAB0"]
[Tue Aug 18 12:59:46.402476 2026] [security2:error] [pid 123784:tid 123988] [client 172.202.39.151:53715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/public/css.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn5gAAAEY"]
[Tue Aug 18 12:59:46.402948 2026] [security2:error] [pid 123784:tid 123954] [client 4.232.94.69:14980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/new.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn5wAAACQ"]
[Tue Aug 18 12:59:46.414081 2026] [security2:error] [pid 123784:tid 123989] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn6AAAAEc"]
[Tue Aug 18 12:59:46.450775 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:46.451131 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:46.469454 2026] [security2:error] [pid 123784:tid 123923] [client 20.119.58.187:10532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/license.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn7QAAAAU"]
[Tue Aug 18 12:59:46.565586 2026] [security2:error] [pid 123784:tid 123963] [client 158.23.17.4:46826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/iz.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn9gAAAC0"]
[Tue Aug 18 12:59:46.598988 2026] [security2:error] [pid 123784:tid 123852] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn-AAACD8"]
[Tue Aug 18 12:59:46.599221 2026] [security2:error] [pid 123784:tid 123926] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn-AAACD8"]
[Tue Aug 18 12:59:46.614640 2026] [security2:error] [pid 123784:tid 123996] [client 20.38.3.247:8685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/grok.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn-QAAAE4"]
[Tue Aug 18 12:59:46.627715 2026] [security2:error] [pid 123784:tid 123929] [client 20.51.153.15:7294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/phpprobe.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn_QAAAAs"]
[Tue Aug 18 12:59:46.651211 2026] [security2:error] [pid 123784:tid 123994] [client 20.127.136.245:28062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/x.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn_wAAAEw"]
[Tue Aug 18 12:59:46.683452 2026] [security2:error] [pid 123784:tid 123974] [client 3.149.0.107:59978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.natupedras.com.br"] [uri "/robots.txt"] [unique_id "aoSBcmwDnJBNj2tDbYboAgAAADg"]
[Tue Aug 18 12:59:46.689276 2026] [security2:error] [pid 123784:tid 124042] [client 68.155.154.236:25381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSBcmwDnJBNj2tDbYboAwAAAHw"]
[Tue Aug 18 12:59:46.739680 2026] [security2:error] [pid 123784:tid 123973] [client 132.196.30.78:20438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBcmwDnJBNj2tDbYboBgAAADc"]
[Tue Aug 18 12:59:46.747233 2026] [authz_core:error] [pid 123784:tid 123876] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:46.747521 2026] [authz_core:error] [pid 123784:tid 123876] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:46.780052 2026] [security2:error] [pid 123784:tid 123951] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBcmwDnJBNj2tDbYboCAAAACE"]
[Tue Aug 18 12:59:46.823996 2026] [security2:error] [pid 123784:tid 124011] [client 20.119.58.187:10552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/load.php"] [unique_id "aoSBcmwDnJBNj2tDbYboCgAAAF0"]
[Tue Aug 18 12:59:46.934059 2026] [security2:error] [pid 123784:tid 123854] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/config/.env.php"] [unique_id "aoSBcmwDnJBNj2tDbYboEQAATUE"]
[Tue Aug 18 12:59:46.944345 2026] [security2:error] [pid 123784:tid 123945] [client 213.35.127.232:50894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBcmwDnJBNj2tDbYboEgAAABs"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:46.954914 2026] [security2:error] [pid 123784:tid 124045] [client 20.38.3.247:63454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/indes.php"] [unique_id "aoSBcmwDnJBNj2tDbYboFAAAAH8"]
[Tue Aug 18 12:59:46.956169 2026] [security2:error] [pid 123784:tid 123824] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/.env.php.bak"] [unique_id "aoSBcmwDnJBNj2tDbYboGwAAXCM"]
[Tue Aug 18 12:59:47.017053 2026] [security2:error] [pid 123784:tid 124032] [client 40.74.65.169:20295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/File.php"] [unique_id "aoSBc2wDnJBNj2tDbYboHwAAAHI"]
[Tue Aug 18 12:59:47.035631 2026] [security2:error] [pid 123784:tid 124043] [client 172.202.39.151:44497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBc2wDnJBNj2tDbYboIAAAAH0"]
[Tue Aug 18 12:59:47.046994 2026] [security2:error] [pid 123784:tid 123968] [client 20.104.85.180:20257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBc2wDnJBNj2tDbYboIgAAADI"]
[Tue Aug 18 12:59:47.050059 2026] [security2:error] [pid 123784:tid 124040] [client 20.51.153.15:7231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/wp-title.php"] [unique_id "aoSBc2wDnJBNj2tDbYboIwAAAHo"]
[Tue Aug 18 12:59:47.060445 2026] [security2:error] [pid 123784:tid 124029] [client 132.196.30.78:14602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/a7.php"] [unique_id "aoSBc2wDnJBNj2tDbYboJQAAAG8"]
[Tue Aug 18 12:59:47.116807 2026] [security2:error] [pid 123784:tid 123820] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/config.php.bak"] [unique_id "aoSBc2wDnJBNj2tDbYboJwAABB8"]
[Tue Aug 18 12:59:47.119777 2026] [security2:error] [pid 123784:tid 123890] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSBc2wDnJBNj2tDbYboKAAAD2U"]
[Tue Aug 18 12:59:47.162454 2026] [security2:error] [pid 123784:tid 123959] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBc2wDnJBNj2tDbYboKwAAACk"]
[Tue Aug 18 12:59:47.175999 2026] [security2:error] [pid 123784:tid 124039] [client 20.119.58.187:10454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/manager.php"] [unique_id "aoSBc2wDnJBNj2tDbYboLQAAAHk"]
[Tue Aug 18 12:59:47.179052 2026] [security2:error] [pid 123784:tid 123978] [client 68.155.154.236:25379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSBc2wDnJBNj2tDbYboLgAAADw"]
[Tue Aug 18 12:59:47.200130 2026] [security2:error] [pid 123784:tid 124044] [client 3.149.0.107:50058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.natupedras.com.br"] [uri "/ads.txt"] [unique_id "aoSBc2wDnJBNj2tDbYboMAAAAH4"]
[Tue Aug 18 12:59:47.254499 2026] [security2:error] [pid 123784:tid 123948] [client 20.127.136.245:28510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/index/function.php"] [unique_id "aoSBc2wDnJBNj2tDbYboMQAAAB4"]
[Tue Aug 18 12:59:47.271769 2026] [security2:error] [pid 123784:tid 124027] [client 132.196.30.78:20465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/atomlib.php"] [unique_id "aoSBc2wDnJBNj2tDbYboMwAAAG0"]
[Tue Aug 18 12:59:47.314232 2026] [security2:error] [pid 123784:tid 124030] [client 168.62.48.100:5609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/zjggu.php"] [unique_id "aoSBc2wDnJBNj2tDbYboNQAAAHA"]
[Tue Aug 18 12:59:47.391280 2026] [security2:error] [pid 123784:tid 124025] [client 158.23.17.4:8954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/oo.php"] [unique_id "aoSBc2wDnJBNj2tDbYboPgAAAGs"]
[Tue Aug 18 12:59:47.393069 2026] [security2:error] [pid 123784:tid 123998] [client 172.202.39.151:53699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/classwithtostring.php"] [unique_id "aoSBc2wDnJBNj2tDbYboPwAAAFA"]
[Tue Aug 18 12:59:47.410171 2026] [security2:error] [pid 123784:tid 123962] [client 20.51.153.15:7257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/styles.php"] [unique_id "aoSBc2wDnJBNj2tDbYboQAAAACw"]
[Tue Aug 18 12:59:47.422563 2026] [security2:error] [pid 123784:tid 124005] [client 20.250.13.23:41773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/bthil.php"] [unique_id "aoSBc2wDnJBNj2tDbYboQwAAAFc"]
[Tue Aug 18 12:59:47.462018 2026] [security2:error] [pid 123784:tid 123949] [client 20.38.3.247:37123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/tTPcH.php"] [unique_id "aoSBc2wDnJBNj2tDbYboRgAAAB8"]
[Tue Aug 18 12:59:47.475179 2026] [security2:error] [pid 123784:tid 123963] [client 138.36.100.162:42205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBc2wDnJBNj2tDbYboRwAAAC0"]
[Tue Aug 18 12:59:47.475291 2026] [security2:error] [pid 123784:tid 123963] [client 138.36.100.162:42205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBc2wDnJBNj2tDbYboRwAAAC0"]
[Tue Aug 18 12:59:47.528773 2026] [security2:error] [pid 123784:tid 123923] [client 3.149.0.107:50046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.natupedras.com.br"] [uri "/"] [unique_id "aoSBc2wDnJBNj2tDbYboSQAAAAU"]
[Tue Aug 18 12:59:47.534573 2026] [security2:error] [pid 123784:tid 123982] [client 103.184.169.37:42715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBc2wDnJBNj2tDbYboSwAAAEA"]
[Tue Aug 18 12:59:47.535051 2026] [security2:error] [pid 123784:tid 123982] [client 103.184.169.37:42715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBc2wDnJBNj2tDbYboSwAAAEA"]
[Tue Aug 18 12:59:47.536420 2026] [security2:error] [pid 123784:tid 124028] [client 20.119.58.187:10474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/media.php"] [unique_id "aoSBc2wDnJBNj2tDbYboTAAAAG4"]
[Tue Aug 18 12:59:47.542535 2026] [security2:error] [pid 123784:tid 123977] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBc2wDnJBNj2tDbYboTQAAADs"]
[Tue Aug 18 12:59:47.559446 2026] [security2:error] [pid 123784:tid 124042] [client 158.23.17.4:57031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBc2wDnJBNj2tDbYboTwAAAHw"]
[Tue Aug 18 12:59:47.648819 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:47.649082 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:47.671838 2026] [security2:error] [pid 123784:tid 124018] [client 20.51.153.15:7127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/server.php"] [unique_id "aoSBc2wDnJBNj2tDbYboWgAAAGQ"]
[Tue Aug 18 12:59:47.725757 2026] [security2:error] [pid 123784:tid 123983] [client 40.74.65.169:42455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/fi22.php"] [unique_id "aoSBc2wDnJBNj2tDbYboYAAAAEE"]
[Tue Aug 18 12:59:47.787716 2026] [security2:error] [pid 123784:tid 123990] [client 216.73.161.213:60125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.161.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBc2wDnJBNj2tDbYboZQAAAEg"], referer: https://ozzyfernandesoficial.com.br/wp-login.php
[Tue Aug 18 12:59:47.832504 2026] [security2:error] [pid 123784:tid 124029] [client 20.38.3.247:34993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/bs1.php"] [unique_id "aoSBc2wDnJBNj2tDbYboagAAAG8"]
[Tue Aug 18 12:59:47.832776 2026] [security2:error] [pid 123784:tid 123961] [client 172.182.200.96:7600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBc2wDnJBNj2tDbYboawAAACs"]
[Tue Aug 18 12:59:47.837353 2026] [security2:error] [pid 123784:tid 123922] [client 68.155.154.236:4073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSBc2wDnJBNj2tDbYbobAAAAAQ"]
[Tue Aug 18 12:59:47.873067 2026] [security2:error] [pid 123784:tid 124023] [client 149.34.210.141:50596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBc2wDnJBNj2tDbYbocQAAAGk"]
[Tue Aug 18 12:59:47.873660 2026] [security2:error] [pid 123784:tid 124041] [client 20.127.136.245:28291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/aaa.php"] [unique_id "aoSBc2wDnJBNj2tDbYbocgAAAHs"]
[Tue Aug 18 12:59:47.884840 2026] [security2:error] [pid 123784:tid 124045] [client 132.196.30.78:20456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/manager.php"] [unique_id "aoSBc2wDnJBNj2tDbYbocwAAAH8"]
[Tue Aug 18 12:59:47.889953 2026] [security2:error] [pid 123784:tid 123924] [client 20.119.58.187:10528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/mar.php"] [unique_id "aoSBc2wDnJBNj2tDbYbodAAAAAY"]
[Tue Aug 18 12:59:47.906177 2026] [security2:error] [pid 123784:tid 123993] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBc2wDnJBNj2tDbYbodgAAAEs"]
[Tue Aug 18 12:59:47.913614 2026] [security2:error] [pid 123784:tid 123927] [client 158.23.17.4:12486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ja.php"] [unique_id "aoSBc2wDnJBNj2tDbYboeAAAAAk"]
[Tue Aug 18 12:59:47.936933 2026] [security2:error] [pid 123784:tid 123948] [client 172.202.39.151:48902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content/admin.php"] [unique_id "aoSBc2wDnJBNj2tDbYboegAAAB4"]
[Tue Aug 18 12:59:47.941755 2026] [security2:error] [pid 123784:tid 124022] [client 20.203.138.185:32842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/guk.php"] [unique_id "aoSBc2wDnJBNj2tDbYboewAAAGg"]
[Tue Aug 18 12:59:47.942341 2026] [security2:error] [pid 123784:tid 124027] [client 20.104.85.180:1546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBc2wDnJBNj2tDbYbofAAAAG0"]
[Tue Aug 18 12:59:47.952808 2026] [security2:error] [pid 123784:tid 123936] [client 132.196.30.78:15652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/rip.php"] [unique_id "aoSBc2wDnJBNj2tDbYbofgAAABI"]
[Tue Aug 18 12:59:47.953122 2026] [authz_core:error] [pid 123784:tid 123838] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:47.953482 2026] [authz_core:error] [pid 123784:tid 123838] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:47.957209 2026] [security2:error] [pid 123784:tid 123988] [client 20.51.153.15:7174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/xinfo.php"] [unique_id "aoSBc2wDnJBNj2tDbYbofwAAAEY"]
[Tue Aug 18 12:59:47.958198 2026] [security2:error] [pid 123784:tid 123973] [client 213.35.127.232:51134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBc2wDnJBNj2tDbYbogAAAADc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:47.973759 2026] [security2:error] [pid 123784:tid 124014] [client 20.251.48.93:61465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/chosen.php"] [unique_id "aoSBc2wDnJBNj2tDbYbogQAAAGA"]
[Tue Aug 18 12:59:48.040122 2026] [security2:error] [pid 123784:tid 124035] [client 4.232.94.69:14969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/fm.php"] [unique_id "aoSBdGwDnJBNj2tDbYbohwAAAHU"]
[Tue Aug 18 12:59:48.089287 2026] [autoindex:error] [pid 123784:tid 123947] [client 39.46.181.96:34610] AH01276: Cannot serve directory /home3/worldportascom/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://worldportas.com.br/wp-includes/
[Tue Aug 18 12:59:48.089845 2026] [security2:error] [pid 123784:tid 124024] [client 79.127.164.8:36272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/test.sql"] [unique_id "aoSBdGwDnJBNj2tDbYbojAAAAGo"], referer: https://medihub.com.br/test.sql
[Tue Aug 18 12:59:48.128500 2026] [security2:error] [pid 123784:tid 123942] [client 158.23.17.4:17552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBdGwDnJBNj2tDbYbojgAAABg"]
[Tue Aug 18 12:59:48.140690 2026] [security2:error] [pid 123784:tid 124023] [client 149.34.210.141:50596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBc2wDnJBNj2tDbYbocQAAAGk"]
[Tue Aug 18 12:59:48.200559 2026] [security2:error] [pid 123784:tid 123921] [client 20.38.3.247:64091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/hp2.php"] [unique_id "aoSBdGwDnJBNj2tDbYbokwAAAAM"]
[Tue Aug 18 12:59:48.236140 2026] [security2:error] [pid 123784:tid 124042] [client 216.244.66.243:56006] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/car+parking+dinheiro+infinito+e+tudo+desbloqueado-3/"] [unique_id "aoSBdGwDnJBNj2tDbYbolgAAAHw"]
[Tue Aug 18 12:59:48.236240 2026] [security2:error] [pid 123784:tid 124042] [client 216.244.66.243:56006] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/car+parking+dinheiro+infinito+e+tudo+desbloqueado-3/"] [unique_id "aoSBdGwDnJBNj2tDbYbolgAAAHw"]
[Tue Aug 18 12:59:48.244284 2026] [security2:error] [pid 123784:tid 124015] [client 20.119.58.187:10544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/my1.php"] [unique_id "aoSBdGwDnJBNj2tDbYbomAAAAGE"]
[Tue Aug 18 12:59:48.250629 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:48.250894 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:48.269942 2026] [security2:error] [pid 123784:tid 124031] [client 68.155.154.236:4061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSBdGwDnJBNj2tDbYbonQAAAHE"]
[Tue Aug 18 12:59:48.278411 2026] [security2:error] [pid 123784:tid 123987] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBdGwDnJBNj2tDbYbonwAAAEU"]
[Tue Aug 18 12:59:48.284279 2026] [security2:error] [pid 123784:tid 123951] [client 20.51.153.15:7171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/sym.php"] [unique_id "aoSBdGwDnJBNj2tDbYbooAAAACE"]
[Tue Aug 18 12:59:48.305119 2026] [security2:error] [pid 123784:tid 123929] [client 157.20.138.62:57079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBdGwDnJBNj2tDbYbooQAAAAs"]
[Tue Aug 18 12:59:48.305257 2026] [security2:error] [pid 123784:tid 123929] [client 157.20.138.62:57079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBdGwDnJBNj2tDbYbooQAAAAs"]
[Tue Aug 18 12:59:48.333062 2026] [security2:error] [pid 123784:tid 124002] [client 20.104.85.180:18693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/o.php"] [unique_id "aoSBdGwDnJBNj2tDbYboowAAAFQ"]
[Tue Aug 18 12:59:48.365112 2026] [security2:error] [pid 123784:tid 123999] [client 20.127.136.245:28084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/abcd.php"] [unique_id "aoSBdGwDnJBNj2tDbYboqAAAAFE"]
[Tue Aug 18 12:59:48.410303 2026] [security2:error] [pid 123784:tid 123995] [client 40.74.65.169:19478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBdGwDnJBNj2tDbYboqwAAAE0"]
[Tue Aug 18 12:59:48.444891 2026] [security2:error] [pid 123784:tid 123965] [client 68.221.73.131:21303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/img.php"] [unique_id "aoSBdGwDnJBNj2tDbYbosQAAAC8"]
[Tue Aug 18 12:59:48.452453 2026] [security2:error] [pid 123784:tid 123983] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBdGwDnJBNj2tDbYborQAAQTM"]
[Tue Aug 18 12:59:48.467792 2026] [security2:error] [pid 123784:tid 123935] [client 172.202.39.151:60124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/gelay.php"] [unique_id "aoSBdGwDnJBNj2tDbYbosgAAABE"]
[Tue Aug 18 12:59:48.544641 2026] [security2:error] [pid 123784:tid 124040] [client 20.51.153.15:7203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/ye.php"] [unique_id "aoSBdGwDnJBNj2tDbYbotwAAAHo"]
[Tue Aug 18 12:59:48.593914 2026] [security2:error] [pid 123784:tid 124012] [client 132.196.30.78:20433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/w1.php"] [unique_id "aoSBdGwDnJBNj2tDbYbovAAAAF4"]
[Tue Aug 18 12:59:48.597324 2026] [security2:error] [pid 123784:tid 124043] [client 20.119.58.187:10543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/mm.php"] [unique_id "aoSBdGwDnJBNj2tDbYbovQAAAH0"]
[Tue Aug 18 12:59:48.619555 2026] [security2:error] [pid 123784:tid 123941] [client 37.40.227.74:56921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBdGwDnJBNj2tDbYbovwAAABc"]
[Tue Aug 18 12:59:48.619710 2026] [security2:error] [pid 123784:tid 123941] [client 37.40.227.74:56921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBdGwDnJBNj2tDbYbovwAAABc"]
[Tue Aug 18 12:59:48.625099 2026] [security2:error] [pid 123784:tid 124026] [client 158.23.17.4:15771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/se.php"] [unique_id "aoSBdGwDnJBNj2tDbYbowQAAAGw"]
[Tue Aug 18 12:59:48.631792 2026] [security2:error] [pid 123784:tid 123918] [client 132.196.30.78:22091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/p.php"] [unique_id "aoSBdGwDnJBNj2tDbYbowwAAAAA"]
[Tue Aug 18 12:59:48.654714 2026] [security2:error] [pid 123784:tid 123991] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBdGwDnJBNj2tDbYboxgAAAEk"]
[Tue Aug 18 12:59:48.715147 2026] [security2:error] [pid 123784:tid 123928] [client 178.153.171.161:63451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBdGwDnJBNj2tDbYboygAAAAo"]
[Tue Aug 18 12:59:48.715347 2026] [security2:error] [pid 123784:tid 123928] [client 178.153.171.161:63451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBdGwDnJBNj2tDbYboygAAAAo"]
[Tue Aug 18 12:59:48.726017 2026] [security2:error] [pid 123784:tid 123988] [client 20.38.3.247:64113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/yb.php"] [unique_id "aoSBdGwDnJBNj2tDbYbozAAAAEY"]
[Tue Aug 18 12:59:48.786400 2026] [security2:error] [pid 123784:tid 123960] [client 158.23.17.4:51146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/st.php"] [unique_id "aoSBdGwDnJBNj2tDbYbo0gAAACo"]
[Tue Aug 18 12:59:48.803099 2026] [security2:error] [pid 123784:tid 124028] [client 5.31.227.224:29897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBdGwDnJBNj2tDbYbo0wAAAG4"]
[Tue Aug 18 12:59:48.807603 2026] [security2:error] [pid 123784:tid 124028] [client 5.31.227.224:29897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBdGwDnJBNj2tDbYbo0wAAAG4"]
[Tue Aug 18 12:59:48.816383 2026] [security2:error] [pid 123784:tid 124025] [client 68.155.154.236:25351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSBdGwDnJBNj2tDbYbo1wAAAGs"]
[Tue Aug 18 12:59:48.838751 2026] [security2:error] [pid 123784:tid 124044] [client 20.127.136.245:28483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-good.php"] [unique_id "aoSBdGwDnJBNj2tDbYbo2QAAAH4"]
[Tue Aug 18 12:59:48.859032 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:48.859480 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:48.910794 2026] [authz_core:error] [pid 123784:tid 123888] [remote 57.141.22.28:56226] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:48.911054 2026] [authz_core:error] [pid 123784:tid 123888] [remote 57.141.22.28:56226] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:48.928677 2026] [security2:error] [pid 123784:tid 123880] [remote 192.250.229.214:41598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.229.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savvyoffshore.com.br"] [uri "/wp-login.php"] [unique_id "aoSBdGwDnJBNj2tDbYbo3gAAZls"]
[Tue Aug 18 12:59:48.950028 2026] [security2:error] [pid 123784:tid 123953] [client 20.119.58.187:10458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/network.php"] [unique_id "aoSBdGwDnJBNj2tDbYbo3wAAACM"]
[Tue Aug 18 12:59:48.974760 2026] [security2:error] [pid 123784:tid 124045] [client 213.35.127.232:51358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBdGwDnJBNj2tDbYbo4QAAAH8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:49.019829 2026] [security2:error] [pid 123784:tid 123970] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/first.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo6AAAADQ"]
[Tue Aug 18 12:59:49.058673 2026] [security2:error] [pid 123784:tid 124033] [client 158.23.17.4:33425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/xx.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo6QAAAHM"]
[Tue Aug 18 12:59:49.059968 2026] [security2:error] [pid 123784:tid 124042] [client 20.104.85.180:1544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/bb.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo6gAAAHw"]
[Tue Aug 18 12:59:49.099057 2026] [security2:error] [pid 123784:tid 123977] [client 40.74.65.169:20292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo7AAAADs"]
[Tue Aug 18 12:59:49.119680 2026] [security2:error] [pid 123784:tid 123939] [client 158.23.17.4:56716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/vp.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo7QAAABU"]
[Tue Aug 18 12:59:49.136757 2026] [security2:error] [pid 123784:tid 124016] [client 20.203.138.185:53777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-the.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo7wAAAGI"]
[Tue Aug 18 12:59:49.155979 2026] [authz_core:error] [pid 123784:tid 123824] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:49.156256 2026] [authz_core:error] [pid 123784:tid 123824] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:49.223589 2026] [security2:error] [pid 123784:tid 123950] [client 158.23.17.4:15144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/le.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo9QAAACA"]
[Tue Aug 18 12:59:49.239543 2026] [security2:error] [pid 123784:tid 123923] [client 132.196.30.78:14635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/php.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo9gAAAAU"]
[Tue Aug 18 12:59:49.296079 2026] [security2:error] [pid 123784:tid 123796] [remote 35.185.79.185:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.outlimit.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBdWwDnJBNj2tDbYbo-wAATQc"]
[Tue Aug 18 12:59:49.303269 2026] [security2:error] [pid 123784:tid 123929] [client 20.119.58.187:10462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/new.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo_AAAAAs"]
[Tue Aug 18 12:59:49.309751 2026] [security2:error] [pid 123784:tid 123945] [client 20.38.3.247:8644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/vc.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo_QAAABs"]
[Tue Aug 18 12:59:49.369477 2026] [security2:error] [pid 123784:tid 123966] [client 20.127.136.245:28535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/simple.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpCAAAADA"]
[Tue Aug 18 12:59:49.383018 2026] [security2:error] [pid 123784:tid 123983] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpCQAAAEE"]
[Tue Aug 18 12:59:49.415415 2026] [security2:error] [pid 123784:tid 123990] [client 172.202.39.151:61645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/k.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpCwAAAEg"]
[Tue Aug 18 12:59:49.418690 2026] [security2:error] [pid 123784:tid 123912] [remote 35.185.79.185:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.outlimit.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBdWwDnJBNj2tDbYbpDgAAens"]
[Tue Aug 18 12:59:49.435748 2026] [security2:error] [pid 123784:tid 123989] [client 85.154.68.202:62134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpFAAAAEc"]
[Tue Aug 18 12:59:49.435921 2026] [security2:error] [pid 123784:tid 123989] [client 85.154.68.202:62134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpFAAAAEc"]
[Tue Aug 18 12:59:49.456778 2026] [authz_core:error] [pid 123784:tid 123873] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:49.457185 2026] [authz_core:error] [pid 123784:tid 123873] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:49.541997 2026] [security2:error] [pid 123784:tid 123800] [remote 35.185.79.185:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.outlimit.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBdWwDnJBNj2tDbYbpHQAAGQs"]
[Tue Aug 18 12:59:49.549038 2026] [security2:error] [pid 123784:tid 124022] [client 68.155.154.236:4083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpIAAAAGg"]
[Tue Aug 18 12:59:49.572109 2026] [security2:error] [pid 123784:tid 123972] [client 168.62.48.100:5614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/dlvqo.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpIQAAADY"]
[Tue Aug 18 12:59:49.600552 2026] [security2:error] [pid 123784:tid 123932] [client 223.185.37.47:30862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpJQAAAA4"]
[Tue Aug 18 12:59:49.600649 2026] [security2:error] [pid 123784:tid 123932] [client 223.185.37.47:30862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpJQAAAA4"]
[Tue Aug 18 12:59:49.657227 2026] [security2:error] [pid 123784:tid 124028] [client 158.23.17.4:7223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ph.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpLgAAAG4"]
[Tue Aug 18 12:59:49.663510 2026] [security2:error] [pid 123784:tid 123914] [remote 35.185.79.185:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.outlimit.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBdWwDnJBNj2tDbYbpMAAAa30"]
[Tue Aug 18 12:59:49.668267 2026] [security2:error] [pid 123784:tid 123936] [client 20.119.58.187:10123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/0x.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpMgAAABI"]
[Tue Aug 18 12:59:49.685787 2026] [security2:error] [pid 123784:tid 123920] [client 172.182.200.96:7524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpNAAAAAI"]
[Tue Aug 18 12:59:49.699321 2026] [security2:error] [pid 123784:tid 124007] [client 114.119.132.101:60885] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "uniaoac.com.br"] [uri "/solucoes-contabeis/restaurantes"] [unique_id "aoSBdWwDnJBNj2tDbYbpNwAAAFk"], referer: https://uniaoac.com.br/blog/28/voce-ja-ouviu-falar-em-acordo-por-fora-na-rescisao
[Tue Aug 18 12:59:49.751304 2026] [security2:error] [pid 123784:tid 124029] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpOgAAAG8"]
[Tue Aug 18 12:59:49.784070 2026] [security2:error] [pid 123784:tid 123802] [remote 35.185.79.185:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.outlimit.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBdWwDnJBNj2tDbYbpPAAAfw0"]
[Tue Aug 18 12:59:49.792994 2026] [security2:error] [pid 123784:tid 123947] [client 40.74.65.169:20333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpQQAAAB0"]
[Tue Aug 18 12:59:49.844128 2026] [security2:error] [pid 123784:tid 123921] [client 158.23.17.4:8925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/conn-test.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpRQAAAAM"]
[Tue Aug 18 12:59:49.878143 2026] [security2:error] [pid 123784:tid 123937] [client 20.127.136.245:28066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/edit-tags.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpRgAAABM"]
[Tue Aug 18 12:59:49.894288 2026] [security2:error] [pid 123784:tid 124033] [client 20.104.85.180:19751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpRwAAAHM"]
[Tue Aug 18 12:59:49.904761 2026] [security2:error] [pid 123784:tid 123872] [remote 35.185.79.185:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.outlimit.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBdWwDnJBNj2tDbYbpSgAAYVM"]
[Tue Aug 18 12:59:49.918107 2026] [security2:error] [pid 123784:tid 124013] [client 20.38.3.247:35005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/pema.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpTgAAAF8"]
[Tue Aug 18 12:59:49.945034 2026] [security2:error] [pid 123784:tid 124031] [client 158.23.17.4:47873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/hr.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpTwAAAHE"]
[Tue Aug 18 12:59:49.982135 2026] [authz_core:error] [pid 123784:tid 123843] [remote 57.141.22.30:22340] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:49.982406 2026] [authz_core:error] [pid 123784:tid 123843] [remote 57.141.22.30:22340] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:49.989652 2026] [security2:error] [pid 123784:tid 124009] [client 213.35.127.232:51564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpUwAAAFs"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:50.010259 2026] [security2:error] [pid 123784:tid 123986] [client 20.250.13.23:26677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/x.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpVgAAAEQ"]
[Tue Aug 18 12:59:50.029820 2026] [security2:error] [pid 123784:tid 123963] [client 20.119.58.187:10432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/0.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpWAAAAC0"]
[Tue Aug 18 12:59:50.055855 2026] [autoindex:error] [pid 123784:tid 124037] [client 52.73.140.57:45514] AH01276: Cannot serve directory /home3/viadupla/aeromodelismounai.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:50.060322 2026] [authz_core:error] [pid 123784:tid 123866] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:50.060582 2026] [authz_core:error] [pid 123784:tid 123866] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:50.080712 2026] [security2:error] [pid 123784:tid 123995] [client 216.244.66.243:56016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/jogos+de+fogo+e+agua+poki-2/"] [unique_id "aoSBdmwDnJBNj2tDbYbpXAAAAE0"]
[Tue Aug 18 12:59:50.080857 2026] [security2:error] [pid 123784:tid 123995] [client 216.244.66.243:56016] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/jogos+de+fogo+e+agua+poki-2/"] [unique_id "aoSBdmwDnJBNj2tDbYbpXAAAAE0"]
[Tue Aug 18 12:59:50.081446 2026] [security2:error] [pid 123784:tid 123978] [client 132.196.30.78:20463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-login.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpXQAAADw"]
[Tue Aug 18 12:59:50.113934 2026] [security2:error] [pid 123784:tid 123980] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpXwAAAD4"]
[Tue Aug 18 12:59:50.280332 2026] [security2:error] [pid 123784:tid 123840] [remote 35.185.79.185:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.outlimit.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBdmwDnJBNj2tDbYbpawAAETM"]
[Tue Aug 18 12:59:50.323550 2026] [security2:error] [pid 123784:tid 123927] [client 20.203.138.185:52703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/sbhu.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpbAAAAAk"]
[Tue Aug 18 12:59:50.335358 2026] [authz_core:error] [pid 123784:tid 123823] [remote 57.141.22.111:45870] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:50.335741 2026] [authz_core:error] [pid 123784:tid 123823] [remote 57.141.22.111:45870] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:50.373190 2026] [security2:error] [pid 123784:tid 124022] [client 158.158.74.177:3860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/lock360.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpcgAAAGg"]
[Tue Aug 18 12:59:50.382641 2026] [security2:error] [pid 123784:tid 124001] [client 20.119.58.187:10551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/oxshell.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpcwAAAFM"]
[Tue Aug 18 12:59:50.387600 2026] [security2:error] [pid 123784:tid 123972] [client 68.155.154.236:27544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpdQAAADY"]
[Tue Aug 18 12:59:50.388980 2026] [security2:error] [pid 123784:tid 123988] [client 20.38.3.247:8654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/sh.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpdgAAAEY"]
[Tue Aug 18 12:59:50.477459 2026] [security2:error] [pid 123784:tid 124039] [client 20.127.136.245:28539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/u.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpeAAAAHk"]
[Tue Aug 18 12:59:50.490137 2026] [security2:error] [pid 123784:tid 123991] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/blog/byp.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpeQAAAEk"]
[Tue Aug 18 12:59:50.509262 2026] [security2:error] [pid 123784:tid 123998] [client 158.23.17.4:20400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/s.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpewAAAFA"]
[Tue Aug 18 12:59:50.510544 2026] [security2:error] [pid 123784:tid 123936] [client 40.74.65.169:20096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpfAAAABI"]
[Tue Aug 18 12:59:50.567628 2026] [security2:error] [pid 123784:tid 123974] [client 158.23.17.4:32557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/fg.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpgAAAADg"]
[Tue Aug 18 12:59:50.605153 2026] [security2:error] [pid 123784:tid 124004] [client 114.119.134.80:63129] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.higicenterpel.com.br"] [uri "/dados_produtos.php"] [unique_id "aoSBdmwDnJBNj2tDbYbphgAAAFY"], referer: http://www.higicenterpel.com.br/listaprodutossub.php?subcategoria=11
[Tue Aug 18 12:59:50.607930 2026] [security2:error] [pid 123784:tid 123954] [client 158.23.17.4:60781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/kt.php"] [unique_id "aoSBdmwDnJBNj2tDbYbphwAAACQ"]
[Tue Aug 18 12:59:50.661130 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:50.661441 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:50.682443 2026] [security2:error] [pid 123784:tid 123968] [client 132.196.30.78:20472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/default.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpjAAAADI"]
[Tue Aug 18 12:59:50.723584 2026] [security2:error] [pid 123784:tid 123946] [client 20.104.85.180:18758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpjwAAABw"]
[Tue Aug 18 12:59:50.734199 2026] [security2:error] [pid 123784:tid 123969] [client 20.119.58.187:10456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/php8.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpkAAAADM"]
[Tue Aug 18 12:59:50.761252 2026] [security2:error] [pid 123784:tid 124024] [client 4.232.94.69:34421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/bolt.php"] [unique_id "aoSBdmwDnJBNj2tDbYbplwAAAGo"]
[Tue Aug 18 12:59:50.827091 2026] [autoindex:error] [pid 123784:tid 123950] [client 147.185.132.51:63668] AH01276: Cannot serve directory /home2/siderurgiabrasil/anuariodoaco.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:50.852273 2026] [security2:error] [pid 123784:tid 123923] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpnwAAAAU"]
[Tue Aug 18 12:59:50.926512 2026] [security2:error] [pid 123784:tid 123965] [client 172.202.39.151:63737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpogAAAC8"]
[Tue Aug 18 12:59:50.959742 2026] [security2:error] [pid 123784:tid 123964] [client 158.23.17.4:51141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ww.php"] [unique_id "aoSBdmwDnJBNj2tDbYbppQAAAC4"]
[Tue Aug 18 12:59:50.962852 2026] [authz_core:error] [pid 123784:tid 123806] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:50.963105 2026] [authz_core:error] [pid 123784:tid 123806] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:50.979081 2026] [security2:error] [pid 123784:tid 123982] [client 158.23.17.4:15775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/uo.php"] [unique_id "aoSBdmwDnJBNj2tDbYbppgAAAEA"]
[Tue Aug 18 12:59:51.000468 2026] [security2:error] [pid 123784:tid 124015] [client 158.158.74.177:16159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/log.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpqgAAAGE"]
[Tue Aug 18 12:59:51.000498 2026] [security2:error] [pid 123784:tid 123921] [client 213.35.127.232:51774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpqwAAAAM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:51.010947 2026] [security2:error] [pid 123784:tid 123966] [client 20.38.3.247:62401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/button.php"] [unique_id "aoSBd2wDnJBNj2tDbYbprAAAADA"]
[Tue Aug 18 12:59:51.032999 2026] [security2:error] [pid 123784:tid 123869] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBd2wDnJBNj2tDbYbpsQAAc1A"]
[Tue Aug 18 12:59:51.033135 2026] [security2:error] [pid 123784:tid 124033] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBd2wDnJBNj2tDbYbpsQAAc1A"]
[Tue Aug 18 12:59:51.077383 2026] [security2:error] [pid 123784:tid 123995] [client 20.127.136.245:28497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBd2wDnJBNj2tDbYbpswAAAE0"]
[Tue Aug 18 12:59:51.086330 2026] [security2:error] [pid 123784:tid 123990] [client 20.119.58.187:10155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/p.php"] [unique_id "aoSBd2wDnJBNj2tDbYbptQAAAEg"]
[Tue Aug 18 12:59:51.139755 2026] [security2:error] [pid 123784:tid 124037] [client 54.162.181.231:23938] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "304"] [hostname "siderurgiabrasil.com.br"] [uri "/index.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpqAAAd24"]
[Tue Aug 18 12:59:51.216647 2026] [security2:error] [pid 123784:tid 124039] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBd2wDnJBNj2tDbYbpugAAAHk"]
[Tue Aug 18 12:59:51.221884 2026] [security2:error] [pid 123784:tid 123993] [client 40.74.65.169:47051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSBd2wDnJBNj2tDbYbpvAAAAEs"]
[Tue Aug 18 12:59:51.243213 2026] [security2:error] [pid 123784:tid 123960] [client 68.155.154.236:27542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSBd2wDnJBNj2tDbYbpvQAAACo"]
[Tue Aug 18 12:59:51.264287 2026] [security2:error] [pid 123784:tid 123938] [client 20.104.85.180:18859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSBd2wDnJBNj2tDbYbpvwAAABQ"]
[Tue Aug 18 12:59:51.315587 2026] [security2:error] [pid 123784:tid 123992] [client 158.23.17.4:17541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/mo.php"] [unique_id "aoSBd2wDnJBNj2tDbYbpxgAAAEo"]
[Tue Aug 18 12:59:51.369111 2026] [security2:error] [pid 123784:tid 124023] [client 168.62.48.100:5615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/pkmoj.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp0gAAAGk"]
[Tue Aug 18 12:59:51.371400 2026] [security2:error] [pid 123784:tid 123924] [client 132.196.30.78:21956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/i.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp1AAAAAY"]
[Tue Aug 18 12:59:51.381833 2026] [security2:error] [pid 123784:tid 123957] [client 158.23.17.4:25372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/kx.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp1QAAACc"]
[Tue Aug 18 12:59:51.437251 2026] [security2:error] [pid 123784:tid 123945] [client 20.119.58.187:10557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/php.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp1wAAABs"]
[Tue Aug 18 12:59:51.531271 2026] [security2:error] [pid 123784:tid 124009] [client 192.141.172.134:55495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp4QAAAFs"]
[Tue Aug 18 12:59:51.531416 2026] [security2:error] [pid 123784:tid 124009] [client 192.141.172.134:55495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp4QAAAFs"]
[Tue Aug 18 12:59:51.568932 2026] [authz_core:error] [pid 123784:tid 123898] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:51.569406 2026] [authz_core:error] [pid 123784:tid 123898] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:51.599832 2026] [security2:error] [pid 123784:tid 123965] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/images/security.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp5wAAAC8"]
[Tue Aug 18 12:59:51.612119 2026] [security2:error] [pid 123784:tid 123946] [client 20.127.136.245:28487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/h.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp6AAAABw"]
[Tue Aug 18 12:59:51.618591 2026] [security2:error] [pid 123784:tid 124031] [client 158.158.74.177:3891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/lv.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp7AAAAHE"]
[Tue Aug 18 12:59:51.628446 2026] [security2:error] [pid 123784:tid 124008] [client 20.104.85.180:43569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp7QAAAFo"]
[Tue Aug 18 12:59:51.654239 2026] [security2:error] [pid 123784:tid 124036] [client 168.62.48.100:5618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/kopyw.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp8AAAAHY"]
[Tue Aug 18 12:59:51.708203 2026] [security2:error] [pid 123784:tid 123920] [client 4.232.94.69:42664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp_wAAAAI"]
[Tue Aug 18 12:59:51.747651 2026] [security2:error] [pid 123784:tid 123927] [client 68.155.154.236:27573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqAQAAAAk"]
[Tue Aug 18 12:59:51.749598 2026] [security2:error] [pid 123784:tid 123919] [client 158.23.17.4:14057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/va.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqAgAAAAE"]
[Tue Aug 18 12:59:51.753053 2026] [security2:error] [pid 123784:tid 124045] [client 158.23.17.4:60790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/qr.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqAwAAAH8"]
[Tue Aug 18 12:59:51.769450 2026] [security2:error] [pid 123784:tid 123995] [client 20.203.138.185:24942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/zc-318.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqBAAAAE0"]
[Tue Aug 18 12:59:51.789152 2026] [security2:error] [pid 123784:tid 123982] [client 20.119.58.187:10442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/past.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqBgAAAEA"]
[Tue Aug 18 12:59:51.833641 2026] [security2:error] [pid 123784:tid 123943] [client 20.38.3.247:35007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/wlc.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqCwAAABk"]
[Tue Aug 18 12:59:51.856686 2026] [security2:error] [pid 123784:tid 123988] [client 20.104.85.180:18801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqDQAAAEY"]
[Tue Aug 18 12:59:51.868692 2026] [security2:error] [pid 123784:tid 123958] [client 172.182.200.96:7560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqDwAAACg"]
[Tue Aug 18 12:59:51.870507 2026] [authz_core:error] [pid 123784:tid 123797] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:51.871384 2026] [authz_core:error] [pid 123784:tid 123797] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:51.895600 2026] [security2:error] [pid 123784:tid 124019] [client 40.74.65.169:20381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqEAAAAGU"]
[Tue Aug 18 12:59:51.967332 2026] [security2:error] [pid 123784:tid 123847] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/inputs.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqFAAAKTo"]
[Tue Aug 18 12:59:51.999508 2026] [security2:error] [pid 123784:tid 123967] [client 112.171.203.65:47164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.203.171.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldportas.com.br"] [uri "/wp-login.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqCgAAADE"], referer: https://worldportas.com.br/wp-login.php
[Tue Aug 18 12:59:52.013554 2026] [security2:error] [pid 123784:tid 123921] [client 213.35.127.232:51970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqFgAAAAM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:52.045602 2026] [security2:error] [pid 123784:tid 123957] [client 20.104.85.180:6991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/file.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqGAAAACc"]
[Tue Aug 18 12:59:52.115259 2026] [security2:error] [pid 123784:tid 123942] [client 20.127.136.245:28055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/ms-edit.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqIAAAABg"]
[Tue Aug 18 12:59:52.144282 2026] [security2:error] [pid 123784:tid 123953] [client 20.119.58.187:10434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/root.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqIwAAACM"]
[Tue Aug 18 12:59:52.147892 2026] [security2:error] [pid 123784:tid 124032] [client 114.5.214.109:50416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqIgAAAHI"]
[Tue Aug 18 12:59:52.148028 2026] [security2:error] [pid 123784:tid 124032] [client 114.5.214.109:50416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqIgAAAHI"]
[Tue Aug 18 12:59:52.154691 2026] [security2:error] [pid 123784:tid 123951] [client 158.23.17.4:62980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/fo.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqJQAAACE"]
[Tue Aug 18 12:59:52.204303 2026] [security2:error] [pid 123784:tid 123989] [client 20.251.48.93:37576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/wpxml.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqKwAAAEc"]
[Tue Aug 18 12:59:52.234472 2026] [security2:error] [pid 123784:tid 123929] [client 158.23.17.4:57259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ve.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqLgAAAAs"]
[Tue Aug 18 12:59:52.236067 2026] [security2:error] [pid 123784:tid 123984] [client 178.128.23.175:56653] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.caminhosdaregiao.com.br"] [uri "/"] [unique_id "aoSBeGwDnJBNj2tDbYbqLwAAAEI"]
[Tue Aug 18 12:59:52.269036 2026] [security2:error] [pid 123784:tid 123954] [client 158.158.74.177:16130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/mah/function.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqMQAAACQ"]
[Tue Aug 18 12:59:52.290149 2026] [security2:error] [pid 123784:tid 123946] [client 68.155.154.236:25371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqMwAAABw"]
[Tue Aug 18 12:59:52.331255 2026] [security2:error] [pid 123784:tid 124028] [client 20.38.3.247:63461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/fi.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqOQAAAG4"]
[Tue Aug 18 12:59:52.340767 2026] [security2:error] [pid 123784:tid 124016] [client 158.23.17.4:51150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/dirs.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqOgAAAGI"]
[Tue Aug 18 12:59:52.409374 2026] [security2:error] [pid 123784:tid 123935] [client 103.120.71.157:63533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqQQAAABE"]
[Tue Aug 18 12:59:52.409514 2026] [security2:error] [pid 123784:tid 123935] [client 103.120.71.157:63533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqQQAAABE"]
[Tue Aug 18 12:59:52.441840 2026] [security2:error] [pid 123784:tid 123987] [client 4.232.94.69:54411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/php.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqQgAAAEU"]
[Tue Aug 18 12:59:52.441891 2026] [security2:error] [pid 123784:tid 123927] [client 20.104.85.180:18817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/epinyins.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqQwAAAAk"]
[Tue Aug 18 12:59:52.467539 2026] [authz_core:error] [pid 123784:tid 123874] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:52.467811 2026] [authz_core:error] [pid 123784:tid 123874] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:52.468269 2026] [security2:error] [pid 123784:tid 123990] [client 172.202.39.151:44570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/403.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqSQAAAEg"]
[Tue Aug 18 12:59:52.500254 2026] [security2:error] [pid 123784:tid 123920] [client 20.119.58.187:10546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/r.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqSgAAAAI"]
[Tue Aug 18 12:59:52.503611 2026] [security2:error] [pid 123784:tid 123857] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/admin.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqSwAAfUQ"]
[Tue Aug 18 12:59:52.572472 2026] [security2:error] [pid 123784:tid 124037] [client 158.23.17.4:20414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/loading.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqUgAAAHc"]
[Tue Aug 18 12:59:52.576163 2026] [security2:error] [pid 123784:tid 123988] [client 40.74.65.169:20157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/media.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqUwAAAEY"]
[Tue Aug 18 12:59:52.677351 2026] [security2:error] [pid 123784:tid 123921] [client 20.203.138.185:10665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ccou.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqXAAAAAM"]
[Tue Aug 18 12:59:52.686849 2026] [security2:error] [pid 123784:tid 123868] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/goods.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqYAAADE8"]
[Tue Aug 18 12:59:52.695137 2026] [security2:error] [pid 123784:tid 123982] [client 20.127.136.245:28316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/a7.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqYQAAAEA"]
[Tue Aug 18 12:59:52.768201 2026] [authz_core:error] [pid 123784:tid 123864] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:52.768472 2026] [authz_core:error] [pid 123784:tid 123864] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:52.774379 2026] [security2:error] [pid 123784:tid 124039] [client 132.196.30.78:22132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqaQAAAHk"]
[Tue Aug 18 12:59:52.774406 2026] [security2:error] [pid 123784:tid 123969] [client 168.62.48.100:5580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/zznmg.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqagAAADM"]
[Tue Aug 18 12:59:52.813621 2026] [security2:error] [pid 123784:tid 124035] [client 213.202.253.4:56269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/delpaths.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqbAAAAHU"], referer: www.google.com
[Tue Aug 18 12:59:52.831317 2026] [security2:error] [pid 123784:tid 124025] [client 20.104.85.180:7011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqbgAAAGs"]
[Tue Aug 18 12:59:52.849487 2026] [security2:error] [pid 123784:tid 123869] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/file.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqcQAADVA"]
[Tue Aug 18 12:59:52.854891 2026] [security2:error] [pid 123784:tid 123998] [client 20.119.58.187:10465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/sid3.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqcgAAAFA"]
[Tue Aug 18 12:59:52.886633 2026] [security2:error] [pid 123784:tid 124010] [client 20.104.85.180:19713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/file.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqcwAAAFw"]
[Tue Aug 18 12:59:52.895370 2026] [security2:error] [pid 123784:tid 123924] [client 158.158.74.177:3884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqdAAAAAY"]
[Tue Aug 18 12:59:53.024142 2026] [security2:error] [pid 123784:tid 124023] [client 213.35.127.232:52194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqegAAAGk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:53.060248 2026] [security2:error] [pid 123784:tid 123948] [client 158.23.17.4:54759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/sn.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqfAAAAB4"]
[Tue Aug 18 12:59:53.071399 2026] [authz_core:error] [pid 123784:tid 123880] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:53.071663 2026] [authz_core:error] [pid 123784:tid 123880] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:53.079312 2026] [security2:error] [pid 123784:tid 123852] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqfgAACD8"]
[Tue Aug 18 12:59:53.130919 2026] [security2:error] [pid 123784:tid 123945] [client 20.127.136.245:28034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/manager.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqgQAAABs"]
[Tue Aug 18 12:59:53.148264 2026] [security2:error] [pid 123784:tid 124037] [client 158.23.17.4:48997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ke.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqhgAAAHc"]
[Tue Aug 18 12:59:53.164981 2026] [security2:error] [pid 123784:tid 123961] [client 196.12.128.158:64639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqhwAAACs"]
[Tue Aug 18 12:59:53.165116 2026] [security2:error] [pid 123784:tid 123961] [client 196.12.128.158:64639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqhwAAACs"]
[Tue Aug 18 12:59:53.211150 2026] [security2:error] [pid 123784:tid 124003] [client 20.119.58.187:10480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/ss.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqigAAAFU"]
[Tue Aug 18 12:59:53.213089 2026] [security2:error] [pid 123784:tid 123934] [client 172.182.200.96:7580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqiwAAABA"]
[Tue Aug 18 12:59:53.220283 2026] [security2:error] [pid 123784:tid 123993] [client 68.155.154.236:27583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqjAAAAEs"]
[Tue Aug 18 12:59:53.238002 2026] [security2:error] [pid 123784:tid 123936] [client 20.203.138.185:23368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/txets.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqjQAAABI"]
[Tue Aug 18 12:59:53.242970 2026] [security2:error] [pid 123784:tid 123798] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/404.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqjgAABAk"]
[Tue Aug 18 12:59:53.258658 2026] [security2:error] [pid 123784:tid 124044] [client 40.74.65.169:20399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/inso.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqjwAAAH4"]
[Tue Aug 18 12:59:53.272574 2026] [security2:error] [pid 123784:tid 123964] [client 158.23.17.4:10985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqkQAAAC4"]
[Tue Aug 18 12:59:53.317091 2026] [security2:error] [pid 123784:tid 123995] [client 132.196.30.78:20449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqlQAAAE0"]
[Tue Aug 18 12:59:53.332610 2026] [autoindex:error] [pid 123784:tid 123979] [client 4.232.94.69:31723] AH01276: Cannot serve directory /home2/vfunnelcrmcom/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:53.335507 2026] [security2:error] [pid 123784:tid 123982] [client 172.202.39.151:53732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/adminfuns.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqlgAAAEA"]
[Tue Aug 18 12:59:53.369605 2026] [authz_core:error] [pid 123784:tid 123888] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:53.369870 2026] [authz_core:error] [pid 123784:tid 123888] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:53.404936 2026] [security2:error] [pid 123784:tid 123959] [client 20.38.3.247:63479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/chris.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqnAAAACk"]
[Tue Aug 18 12:59:53.411941 2026] [security2:error] [pid 123784:tid 123890] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqnQAAWWU"]
[Tue Aug 18 12:59:53.429134 2026] [security2:error] [pid 123784:tid 123859] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wk/index.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqnwAALEY"]
[Tue Aug 18 12:59:53.441914 2026] [security2:error] [pid 123784:tid 123975] [client 20.104.85.180:22857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/epinyins.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqoQAAADk"]
[Tue Aug 18 12:59:53.475553 2026] [security2:error] [pid 123784:tid 123989] [client 168.62.48.100:5597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/bhfnd.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqogAAAEc"]
[Tue Aug 18 12:59:53.511994 2026] [security2:error] [pid 123784:tid 123921] [client 158.158.74.177:3881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/mass.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqowAAAAM"]
[Tue Aug 18 12:59:53.562938 2026] [security2:error] [pid 123784:tid 124025] [client 20.119.58.187:10486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/sts.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqpAAAAGs"]
[Tue Aug 18 12:59:53.579165 2026] [security2:error] [pid 123784:tid 124002] [client 4.232.94.69:31723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-includes/wp-class.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqpgAAAFQ"]
[Tue Aug 18 12:59:53.650954 2026] [security2:error] [pid 123784:tid 123876] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/about.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqrAAAD1c"]
[Tue Aug 18 12:59:53.672167 2026] [authz_core:error] [pid 123784:tid 123806] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:53.672436 2026] [authz_core:error] [pid 123784:tid 123806] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:53.678142 2026] [security2:error] [pid 123784:tid 123927] [client 158.23.17.4:44820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ia.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqsAAAAAk"]
[Tue Aug 18 12:59:53.685156 2026] [security2:error] [pid 123784:tid 123953] [client 158.23.17.4:56743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/nh.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqsQAAACM"]
[Tue Aug 18 12:59:53.696877 2026] [security2:error] [pid 123784:tid 123945] [client 20.203.138.185:22603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/fun.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqswAAABs"]
[Tue Aug 18 12:59:53.735082 2026] [security2:error] [pid 123784:tid 123924] [client 20.127.136.245:28534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/w1.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqtgAAAAY"]
[Tue Aug 18 12:59:53.740948 2026] [security2:error] [pid 123784:tid 123961] [client 158.23.17.4:17541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/43.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqtwAAACs"]
[Tue Aug 18 12:59:53.748599 2026] [security2:error] [pid 123784:tid 123937] [client 197.184.64.235:41952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBeWwDnJBNj2tDbYbquQAAABM"]
[Tue Aug 18 12:59:53.748674 2026] [security2:error] [pid 123784:tid 123937] [client 197.184.64.235:41952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBeWwDnJBNj2tDbYbquQAAABM"]
[Tue Aug 18 12:59:53.786321 2026] [security2:error] [pid 123784:tid 124019] [client 172.182.200.96:7612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/first.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqvwAAAGU"]
[Tue Aug 18 12:59:53.838164 2026] [security2:error] [pid 123784:tid 124023] [client 79.127.164.8:36338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/transferdrupalbackup.bak"] [unique_id "aoSBeWwDnJBNj2tDbYbqwgAAAGk"], referer: https://medihub.com.br/transferdrupalbackup.bak
[Tue Aug 18 12:59:53.861363 2026] [security2:error] [pid 123784:tid 123862] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/term.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqwwAAGkk"]
[Tue Aug 18 12:59:53.916441 2026] [security2:error] [pid 123784:tid 124003] [client 20.119.58.187:10547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/shell.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqzQAAAFU"]
[Tue Aug 18 12:59:53.956619 2026] [security2:error] [pid 123784:tid 123918] [client 40.74.65.169:20413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/shiny.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqzwAAAAA"]
[Tue Aug 18 12:59:53.980732 2026] [security2:error] [pid 123784:tid 124014] [client 20.104.85.180:28636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBeWwDnJBNj2tDbYbq0gAAAGA"]
[Tue Aug 18 12:59:54.012770 2026] [security2:error] [pid 123784:tid 123960] [client 102.213.179.104:61310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBemwDnJBNj2tDbYbq1QAAACo"]
[Tue Aug 18 12:59:54.012894 2026] [security2:error] [pid 123784:tid 123960] [client 102.213.179.104:61310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBemwDnJBNj2tDbYbq1QAAACo"]
[Tue Aug 18 12:59:54.019057 2026] [security2:error] [pid 123784:tid 123792] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/phpinfo.php"] [unique_id "aoSBemwDnJBNj2tDbYbq1gAAeQM"]
[Tue Aug 18 12:59:54.024452 2026] [security2:error] [pid 123784:tid 123815] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBemwDnJBNj2tDbYbq1wAAIho"]
[Tue Aug 18 12:59:54.033179 2026] [security2:error] [pid 123784:tid 124020] [client 68.155.154.236:25367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/rezor.php"] [unique_id "aoSBemwDnJBNj2tDbYbq2AAAAGY"]
[Tue Aug 18 12:59:54.046932 2026] [security2:error] [pid 123784:tid 124043] [client 213.35.127.232:52403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBemwDnJBNj2tDbYbq2wAAAH0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:54.052558 2026] [security2:error] [pid 123784:tid 124005] [client 20.250.13.23:27943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/index/function.php"] [unique_id "aoSBemwDnJBNj2tDbYbq3QAAAFc"]
[Tue Aug 18 12:59:54.103473 2026] [security2:error] [pid 123784:tid 123900] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/info.php"] [unique_id "aoSBemwDnJBNj2tDbYbq3wAAR28"]
[Tue Aug 18 12:59:54.120553 2026] [security2:error] [pid 123784:tid 123930] [client 132.196.30.78:16136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBemwDnJBNj2tDbYbq4QAAAAw"]
[Tue Aug 18 12:59:54.131704 2026] [security2:error] [pid 123784:tid 123995] [client 158.158.74.177:16129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/memberfuns.php"] [unique_id "aoSBemwDnJBNj2tDbYbq4gAAAE0"]
[Tue Aug 18 12:59:54.136498 2026] [security2:error] [pid 123784:tid 123818] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/pi.php"] [unique_id "aoSBemwDnJBNj2tDbYbq4wAALR0"]
[Tue Aug 18 12:59:54.142518 2026] [security2:error] [pid 123784:tid 124010] [client 20.38.3.247:63483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/doc.php"] [unique_id "aoSBemwDnJBNj2tDbYbq5AAAAFw"]
[Tue Aug 18 12:59:54.171913 2026] [security2:error] [pid 123784:tid 123962] [client 74.7.228.42:33226] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "bfautomovel.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSBemwDnJBNj2tDbYbq5gAALA0"]
[Tue Aug 18 12:59:54.199048 2026] [security2:error] [pid 123784:tid 123965] [client 172.182.200.96:7518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBemwDnJBNj2tDbYbq6QAAAC8"]
[Tue Aug 18 12:59:54.225806 2026] [security2:error] [pid 123784:tid 123954] [client 158.23.17.4:56524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/oo.php"] [unique_id "aoSBemwDnJBNj2tDbYbq6wAAACQ"]
[Tue Aug 18 12:59:54.240412 2026] [security2:error] [pid 123784:tid 123909] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/test.php"] [unique_id "aoSBemwDnJBNj2tDbYbq7gAAcXg"]
[Tue Aug 18 12:59:54.258477 2026] [security2:error] [pid 123784:tid 123833] [remote 74.248.18.37:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.alsconsultoria.com.br"] [uri "/1.php"] [unique_id "aoSBemwDnJBNj2tDbYbq7wAAByw"]
[Tue Aug 18 12:59:54.258559 2026] [security2:error] [pid 123784:tid 123833] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/1.php"] [unique_id "aoSBemwDnJBNj2tDbYbq7wAAByw"]
[Tue Aug 18 12:59:54.274945 2026] [security2:error] [pid 123784:tid 123978] [client 20.119.58.187:10553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/setup-config.php"] [unique_id "aoSBemwDnJBNj2tDbYbq8QAAADw"]
[Tue Aug 18 12:59:54.275796 2026] [security2:error] [pid 123784:tid 123834] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/i.php"] [unique_id "aoSBemwDnJBNj2tDbYbq8gAAbi0"]
[Tue Aug 18 12:59:54.276050 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:54.276305 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:54.358126 2026] [security2:error] [pid 123784:tid 123805] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBemwDnJBNj2tDbYbq9gAAORA"]
[Tue Aug 18 12:59:54.362270 2026] [security2:error] [pid 123784:tid 123915] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "aoSBemwDnJBNj2tDbYbq9wAARX4"]
[Tue Aug 18 12:59:54.374066 2026] [security2:error] [pid 123784:tid 123898] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/app_dev.php"] [unique_id "aoSBemwDnJBNj2tDbYbq-AAAf20"]
[Tue Aug 18 12:59:54.422287 2026] [security2:error] [pid 123784:tid 123904] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/alfa.php"] [unique_id "aoSBemwDnJBNj2tDbYbq-gAAE3M"]
[Tue Aug 18 12:59:54.543672 2026] [security2:error] [pid 123784:tid 124009] [client 20.203.138.185:42442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/jq.php"] [unique_id "aoSBemwDnJBNj2tDbYbq_gAAAFs"]
[Tue Aug 18 12:59:54.552621 2026] [security2:error] [pid 123784:tid 123932] [client 172.182.200.96:7571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBemwDnJBNj2tDbYbrAwAAAA4"]
[Tue Aug 18 12:59:54.556557 2026] [security2:error] [pid 123784:tid 123990] [client 20.127.136.245:28038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-login.php"] [unique_id "aoSBemwDnJBNj2tDbYbq-QAAAEg"]
[Tue Aug 18 12:59:54.567067 2026] [security2:error] [pid 123784:tid 124023] [client 68.155.154.236:27571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSBemwDnJBNj2tDbYbrBAAAAGk"]
[Tue Aug 18 12:59:54.606078 2026] [security2:error] [pid 123784:tid 123944] [client 158.23.17.4:56540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ja.php"] [unique_id "aoSBemwDnJBNj2tDbYbrCwAAABo"]
[Tue Aug 18 12:59:54.619187 2026] [security2:error] [pid 123784:tid 123810] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/edit.php"] [unique_id "aoSBemwDnJBNj2tDbYbrDQAABBU"]
[Tue Aug 18 12:59:54.632604 2026] [security2:error] [pid 123784:tid 123981] [client 20.119.58.187:10459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/t.php"] [unique_id "aoSBemwDnJBNj2tDbYbrDwAAAD8"]
[Tue Aug 18 12:59:54.636140 2026] [security2:error] [pid 123784:tid 123943] [client 40.74.65.169:20131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/403dd.php"] [unique_id "aoSBemwDnJBNj2tDbYbrEAAAABk"]
[Tue Aug 18 12:59:54.697064 2026] [security2:error] [pid 123784:tid 124026] [client 4.232.94.69:35813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-admin/includes/index.php"] [unique_id "aoSBemwDnJBNj2tDbYbrEgAAAGw"]
[Tue Aug 18 12:59:54.717275 2026] [security2:error] [pid 123784:tid 124042] [client 132.196.30.78:16168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/NewFile.php"] [unique_id "aoSBemwDnJBNj2tDbYbrEwAAAHw"]
[Tue Aug 18 12:59:54.737462 2026] [security2:error] [pid 123784:tid 123838] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/domvf.php"] [unique_id "aoSBemwDnJBNj2tDbYbrFQAAQzE"]
[Tue Aug 18 12:59:54.770423 2026] [security2:error] [pid 123784:tid 123994] [client 20.38.3.247:18832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/1337.php"] [unique_id "aoSBemwDnJBNj2tDbYbrFgAAAEw"]
[Tue Aug 18 12:59:54.843927 2026] [security2:error] [pid 123784:tid 123871] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/elp.php"] [unique_id "aoSBemwDnJBNj2tDbYbrHAAAClI"]
[Tue Aug 18 12:59:54.882941 2026] [authz_core:error] [pid 123784:tid 123822] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:54.883427 2026] [authz_core:error] [pid 123784:tid 123822] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:54.889911 2026] [security2:error] [pid 123784:tid 123929] [client 158.23.17.4:57066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/fresh.php"] [unique_id "aoSBemwDnJBNj2tDbYbrIQAAAAs"]
[Tue Aug 18 12:59:54.913911 2026] [security2:error] [pid 123784:tid 123984] [client 172.182.200.96:7596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBemwDnJBNj2tDbYbrIwAAAEI"]
[Tue Aug 18 12:59:54.964395 2026] [security2:error] [pid 123784:tid 123919] [client 20.104.85.180:18795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSBemwDnJBNj2tDbYbrJgAAAAE"]
[Tue Aug 18 12:59:54.964460 2026] [security2:error] [pid 123784:tid 124035] [client 20.127.136.245:28086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/default.php"] [unique_id "aoSBemwDnJBNj2tDbYbrJQAAAHU"]
[Tue Aug 18 12:59:54.979479 2026] [security2:error] [pid 123784:tid 124014] [client 158.158.74.177:16149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/meta.php"] [unique_id "aoSBemwDnJBNj2tDbYbrJwAAAGA"]
[Tue Aug 18 12:59:54.986272 2026] [security2:error] [pid 123784:tid 124005] [client 20.119.58.187:10115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/up.php"] [unique_id "aoSBemwDnJBNj2tDbYbrKAAAAFc"]
[Tue Aug 18 12:59:55.011551 2026] [security2:error] [pid 123784:tid 123865] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrLAAAO0w"]
[Tue Aug 18 12:59:55.021012 2026] [security2:error] [pid 123784:tid 123947] [client 158.23.17.4:57255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/kn.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrLQAAAB0"]
[Tue Aug 18 12:59:55.059140 2026] [security2:error] [pid 123784:tid 123893] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrLwAAHGg"]
[Tue Aug 18 12:59:55.068416 2026] [security2:error] [pid 123784:tid 123957] [client 213.35.127.232:52607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrMAAAACc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:55.133415 2026] [security2:error] [pid 123784:tid 124017] [client 158.23.17.4:56561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/xx.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrMgAAAGM"]
[Tue Aug 18 12:59:55.153905 2026] [security2:error] [pid 123784:tid 123986] [client 168.62.48.100:5621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/qfvqu.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrMwAAAEQ"]
[Tue Aug 18 12:59:55.178703 2026] [security2:error] [pid 123784:tid 123797] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/666.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrOAAAOQg"]
[Tue Aug 18 12:59:55.213034 2026] [security2:error] [pid 123784:tid 123935] [client 20.251.48.93:51709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/file1221.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrOQAAABE"]
[Tue Aug 18 12:59:55.221879 2026] [security2:error] [pid 123784:tid 124001] [client 86.120.159.145:64402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrOgAAAFM"]
[Tue Aug 18 12:59:55.222372 2026] [security2:error] [pid 123784:tid 124001] [client 86.120.159.145:64402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrOgAAAFM"]
[Tue Aug 18 12:59:55.298580 2026] [security2:error] [pid 123784:tid 123949] [client 68.155.154.236:27574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrPgAAAB8"]
[Tue Aug 18 12:59:55.306738 2026] [security2:error] [pid 123784:tid 123997] [client 132.196.30.78:16155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrPwAAAE8"]
[Tue Aug 18 12:59:55.335537 2026] [security2:error] [pid 123784:tid 123945] [client 40.74.65.169:43010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/baba.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrQAAAABs"]
[Tue Aug 18 12:59:55.339600 2026] [security2:error] [pid 123784:tid 123987] [client 20.119.58.187:10144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/ultra.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrQQAAAEU"]
[Tue Aug 18 12:59:55.351203 2026] [core:error] [pid 123784:tid 123855] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 12:59:55.351226 2026] [core:error] [pid 123784:tid 123855] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 12:59:55.355587 2026] [security2:error] [pid 123784:tid 123970] [client 20.38.3.247:38141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/Njima.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrRAAAADQ"]
[Tue Aug 18 12:59:55.437465 2026] [security2:error] [pid 123784:tid 123908] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/gec.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrRgAADnc"]
[Tue Aug 18 12:59:55.478577 2026] [authz_core:error] [pid 123784:tid 123877] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:55.478849 2026] [authz_core:error] [pid 123784:tid 123877] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:55.519510 2026] [security2:error] [pid 123784:tid 123896] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/ws54.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrSwAARms"]
[Tue Aug 18 12:59:55.598021 2026] [security2:error] [pid 123784:tid 124016] [client 158.158.74.177:16155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/mini.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrUwAAAGI"]
[Tue Aug 18 12:59:55.598051 2026] [security2:error] [pid 123784:tid 123985] [client 158.23.17.4:15760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/conn-test.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrUgAAAEM"]
[Tue Aug 18 12:59:55.614808 2026] [security2:error] [pid 123784:tid 124037] [client 20.127.136.245:28078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/i.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrVwAAAHc"]
[Tue Aug 18 12:59:55.631639 2026] [security2:error] [pid 123784:tid 123979] [client 20.203.138.185:22617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/sys.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrWgAAAD0"]
[Tue Aug 18 12:59:55.636558 2026] [security2:error] [pid 123784:tid 123941] [client 158.23.17.4:33458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/wm.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrWwAAABc"]
[Tue Aug 18 12:59:55.686873 2026] [security2:error] [pid 123784:tid 123852] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrXgAAfT8"]
[Tue Aug 18 12:59:55.693509 2026] [security2:error] [pid 123784:tid 123991] [client 20.119.58.187:10451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/vv.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrXwAAAEk"]
[Tue Aug 18 12:59:55.734529 2026] [security2:error] [pid 123784:tid 124034] [client 192.141.172.134:55810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrYQAAAHQ"]
[Tue Aug 18 12:59:55.734679 2026] [security2:error] [pid 123784:tid 124034] [client 192.141.172.134:55810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrYQAAAHQ"]
[Tue Aug 18 12:59:55.747247 2026] [security2:error] [pid 123784:tid 123948] [client 20.250.13.23:36074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/aaa.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrYgAAAB4"]
[Tue Aug 18 12:59:55.768019 2026] [security2:error] [pid 123784:tid 124041] [client 154.72.114.68:7287] ModSecurity: Warning. Matched phrase "Firefox/7.0" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "nolancollection.com.br"] [uri "/index.php"] [unique_id "aoSBemwDnJBNj2tDbYbq4AAAAHs"]
[Tue Aug 18 12:59:55.781610 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:55.781923 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:55.854003 2026] [security2:error] [pid 123784:tid 123798] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/function/function.php"] [unique_id "aoSBe2wDnJBNj2tDbYbraQAAXgk"]
[Tue Aug 18 12:59:55.857422 2026] [security2:error] [pid 123784:tid 123813] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/sky.php"] [unique_id "aoSBe2wDnJBNj2tDbYbragAAaxg"]
[Tue Aug 18 12:59:55.878454 2026] [security2:error] [pid 123784:tid 123957] [client 172.182.200.96:14113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/blog/byp.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrbAAAACc"]
[Tue Aug 18 12:59:55.888589 2026] [security2:error] [pid 123784:tid 124028] [client 172.202.39.151:4436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/gecko-new.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrbgAAAG4"]
[Tue Aug 18 12:59:55.904455 2026] [authz_core:error] [pid 123784:tid 123864] [remote 57.141.22.0:55326] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:55.904916 2026] [authz_core:error] [pid 123784:tid 123864] [remote 57.141.22.0:55326] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:55.914390 2026] [security2:error] [pid 123784:tid 124027] [client 158.23.17.4:51180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/gj.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrcwAAAG0"]
[Tue Aug 18 12:59:55.923622 2026] [security2:error] [pid 123784:tid 123966] [client 68.155.154.236:25387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/index/function.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrdQAAADA"]
[Tue Aug 18 12:59:55.944490 2026] [security2:error] [pid 123784:tid 123926] [client 20.38.3.247:8665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/BIBIL.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrdwAAAAg"]
[Tue Aug 18 12:59:55.990530 2026] [security2:error] [pid 123784:tid 124001] [client 20.104.85.180:22873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBe2wDnJBNj2tDbYbreQAAAFM"]
[Tue Aug 18 12:59:56.014410 2026] [security2:error] [pid 123784:tid 123927] [client 40.74.65.169:47046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/site.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrewAAAAk"]
[Tue Aug 18 12:59:56.024599 2026] [security2:error] [pid 123784:tid 123953] [client 135.225.78.186:58903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrfAAAACM"]
[Tue Aug 18 12:59:56.046442 2026] [security2:error] [pid 123784:tid 123986] [client 20.119.58.187:10491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/V5.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrfQAAAEQ"]
[Tue Aug 18 12:59:56.059694 2026] [security2:error] [pid 123784:tid 123890] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/nw.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrfgAARWU"]
[Tue Aug 18 12:59:56.080291 2026] [security2:error] [pid 123784:tid 124022] [client 213.35.127.232:52837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrgAAAAGg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:56.086810 2026] [authz_core:error] [pid 123784:tid 123859] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:56.087136 2026] [authz_core:error] [pid 123784:tid 123859] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:56.149938 2026] [security2:error] [pid 123784:tid 123933] [client 132.196.30.78:16183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrhQAAAA8"]
[Tue Aug 18 12:59:56.176427 2026] [security2:error] [pid 123784:tid 124023] [client 172.202.39.151:41132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSBfGwDnJBNj2tDbYbriAAAAGk"]
[Tue Aug 18 12:59:56.206796 2026] [security2:error] [pid 123784:tid 123799] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/sixxis.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrigAAZQo"]
[Tue Aug 18 12:59:56.216671 2026] [security2:error] [pid 123784:tid 123934] [client 158.23.17.4:7170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/fg.php"] [unique_id "aoSBfGwDnJBNj2tDbYbriwAAABA"]
[Tue Aug 18 12:59:56.227756 2026] [security2:error] [pid 123784:tid 123819] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/xleet.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrjAAAVB4"]
[Tue Aug 18 12:59:56.238308 2026] [security2:error] [pid 123784:tid 123925] [client 158.158.74.177:3879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/mm.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrjQAAAAc"]
[Tue Aug 18 12:59:56.278158 2026] [security2:error] [pid 123784:tid 123922] [client 20.127.136.245:28033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrkAAAAAQ"]
[Tue Aug 18 12:59:56.287141 2026] [security2:error] [pid 123784:tid 124040] [client 68.155.154.236:25355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrkQAAAHo"]
[Tue Aug 18 12:59:56.389118 2026] [authz_core:error] [pid 123784:tid 123876] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:56.389562 2026] [authz_core:error] [pid 123784:tid 123876] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:56.394849 2026] [security2:error] [pid 123784:tid 123901] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrlQAAM3A"]
[Tue Aug 18 12:59:56.400609 2026] [security2:error] [pid 123784:tid 123974] [client 20.119.58.187:10149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/wp-user.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrlgAAADg"]
[Tue Aug 18 12:59:56.401480 2026] [security2:error] [pid 123784:tid 124016] [client 158.23.17.4:34040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ac.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrlwAAAGI"]
[Tue Aug 18 12:59:56.489612 2026] [security2:error] [pid 123784:tid 124020] [client 20.104.85.180:52598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp.php"] [unique_id "aoSBfGwDnJBNj2tDbYbroAAAAGY"]
[Tue Aug 18 12:59:56.500089 2026] [security2:error] [pid 123784:tid 124043] [client 20.203.138.185:32863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/pp.php"] [unique_id "aoSBfGwDnJBNj2tDbYbroQAAAH0"]
[Tue Aug 18 12:59:56.504835 2026] [security2:error] [pid 123784:tid 123991] [client 20.38.3.247:15283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/too.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrogAAAEk"]
[Tue Aug 18 12:59:56.522503 2026] [security2:error] [pid 123784:tid 123862] [remote 62.60.130.128:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sttudio.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrpAAAakk"]
[Tue Aug 18 12:59:56.561336 2026] [security2:error] [pid 123784:tid 123888] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/155.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrqAAAdWM"]
[Tue Aug 18 12:59:56.655472 2026] [security2:error] [pid 123784:tid 123946] [client 158.23.17.4:20442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ve.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrrwAAABw"]
[Tue Aug 18 12:59:56.712284 2026] [security2:error] [pid 123784:tid 123926] [client 40.74.65.169:19476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrsgAAAAg"]
[Tue Aug 18 12:59:56.748868 2026] [security2:error] [pid 123784:tid 123965] [client 20.127.136.245:28489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrtQAAAC8"]
[Tue Aug 18 12:59:56.750471 2026] [authz_core:error] [pid 123784:tid 123792] [remote 57.141.22.42:40470] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:56.750928 2026] [authz_core:error] [pid 123784:tid 123792] [remote 57.141.22.42:40470] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:56.755354 2026] [security2:error] [pid 123784:tid 124012] [client 20.119.58.187:10513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/wp-blog.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrtgAAAF4"]
[Tue Aug 18 12:59:56.771840 2026] [security2:error] [pid 123784:tid 123953] [client 68.155.154.236:27560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/Cachex.php"] [unique_id "aoSBfGwDnJBNj2tDbYbruQAAACM"]
[Tue Aug 18 12:59:56.798642 2026] [security2:error] [pid 123784:tid 123804] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/96i.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrvAAAGw8"]
[Tue Aug 18 12:59:56.845382 2026] [security2:error] [pid 123784:tid 123920] [client 172.202.39.151:4734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content.php.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrxAAAAAI"]
[Tue Aug 18 12:59:56.869705 2026] [security2:error] [pid 123784:tid 123947] [client 158.158.74.177:16175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/modules/mod_footer.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrxQAAAB0"]
[Tue Aug 18 12:59:56.919240 2026] [security2:error] [pid 123784:tid 123879] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/yj09.php"] [unique_id "aoSBfGwDnJBNj2tDbYbryAAAD1o"]
[Tue Aug 18 12:59:56.947656 2026] [security2:error] [pid 123784:tid 124000] [client 172.202.39.151:60139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/about.php"] [unique_id "aoSBfGwDnJBNj2tDbYbryQAAAFI"]
[Tue Aug 18 12:59:56.966511 2026] [security2:error] [pid 123784:tid 123909] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/as.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrywAAVHg"]
[Tue Aug 18 12:59:56.986150 2026] [authz_core:error] [pid 123784:tid 123895] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:56.986471 2026] [authz_core:error] [pid 123784:tid 123895] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:57.009789 2026] [security2:error] [pid 123784:tid 123943] [client 20.38.3.247:8684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/g3.php"] [unique_id "aoSBfWwDnJBNj2tDbYbrzgAAABk"]
[Tue Aug 18 12:59:57.040661 2026] [security2:error] [pid 123784:tid 123971] [client 168.62.48.100:5608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/oivcl.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr0AAAADU"]
[Tue Aug 18 12:59:57.059450 2026] [security2:error] [pid 123784:tid 123854] [remote 62.60.130.128:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sttudio.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr0QAAWkE"]
[Tue Aug 18 12:59:57.070842 2026] [security2:error] [pid 123784:tid 124011] [client 68.221.73.131:16063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/222.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr0gAAAF0"]
[Tue Aug 18 12:59:57.095198 2026] [security2:error] [pid 123784:tid 124006] [client 132.196.30.78:2752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/themes.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr1gAAAFg"]
[Tue Aug 18 12:59:57.097122 2026] [security2:error] [pid 123784:tid 123935] [client 213.35.127.232:53047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr1wAAABE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:57.109394 2026] [security2:error] [pid 123784:tid 123944] [client 20.119.58.187:10497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/wp.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr2QAAABo"]
[Tue Aug 18 12:59:57.134085 2026] [security2:error] [pid 123784:tid 123805] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/min.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr2gAAcxA"]
[Tue Aug 18 12:59:57.164240 2026] [security2:error] [pid 123784:tid 124016] [client 158.23.17.4:60299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/pd.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr3AAAAGI"]
[Tue Aug 18 12:59:57.206070 2026] [security2:error] [pid 123784:tid 123928] [client 20.127.136.245:28481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/gecko-new.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr3gAAAAo"]
[Tue Aug 18 12:59:57.231877 2026] [security2:error] [pid 123784:tid 123941] [client 158.23.17.4:20217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/yz.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr4AAAABc"]
[Tue Aug 18 12:59:57.256062 2026] [security2:error] [pid 123784:tid 123980] [client 68.155.154.236:27555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr4QAAAD4"]
[Tue Aug 18 12:59:57.283003 2026] [security2:error] [pid 123784:tid 123816] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/k.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr5AAAdBs"]
[Tue Aug 18 12:59:57.286787 2026] [authz_core:error] [pid 123784:tid 123827] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:57.287221 2026] [authz_core:error] [pid 123784:tid 123827] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:57.305201 2026] [core:error] [pid 123784:tid 123841] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 12:59:57.305221 2026] [core:error] [pid 123784:tid 123841] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 12:59:57.310858 2026] [security2:error] [pid 123784:tid 123998] [client 20.104.85.180:20285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/function/function.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr5wAAAFA"]
[Tue Aug 18 12:59:57.323763 2026] [security2:error] [pid 123784:tid 124010] [client 20.38.3.247:7272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/scxy.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr6AAAAFw"]
[Tue Aug 18 12:59:57.419363 2026] [security2:error] [pid 123784:tid 123931] [client 40.74.65.169:20301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/cabs.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr6gAAAA0"]
[Tue Aug 18 12:59:57.439063 2026] [security2:error] [pid 123784:tid 123952] [client 79.127.164.8:60034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/transferdrupalbackup.sql"] [unique_id "aoSBfWwDnJBNj2tDbYbr6wAAACI"], referer: https://medihub.com.br/transferdrupalbackup.sql
[Tue Aug 18 12:59:57.443972 2026] [security2:error] [pid 123784:tid 124025] [client 158.23.17.4:7231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ia.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr7AAAAGs"]
[Tue Aug 18 12:59:57.459788 2026] [security2:error] [pid 123784:tid 124032] [client 20.251.48.93:57981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/nox.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr7wAAAHI"]
[Tue Aug 18 12:59:57.461465 2026] [security2:error] [pid 123784:tid 123962] [client 20.119.58.187:10478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/worksec.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr8AAAACw"]
[Tue Aug 18 12:59:57.490844 2026] [security2:error] [pid 123784:tid 123991] [client 158.158.74.177:16138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/moon.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr8gAAAEk"]
[Tue Aug 18 12:59:57.521659 2026] [security2:error] [pid 123784:tid 123810] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/php8.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr9gAAIRU"]
[Tue Aug 18 12:59:57.558768 2026] [security2:error] [pid 123784:tid 123926] [client 135.225.78.186:37579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr9wAAAAg"]
[Tue Aug 18 12:59:57.586609 2026] [authz_core:error] [pid 123784:tid 123831] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:57.586894 2026] [authz_core:error] [pid 123784:tid 123831] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:57.627352 2026] [security2:error] [pid 123784:tid 123875] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/w.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr-wAAI1Y"]
[Tue Aug 18 12:59:57.635987 2026] [security2:error] [pid 123784:tid 123997] [client 20.203.138.185:32856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wqqs.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr_AAAAE8"]
[Tue Aug 18 12:59:57.646999 2026] [security2:error] [pid 123784:tid 123963] [client 20.104.85.180:14577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr_QAAAC0"]
[Tue Aug 18 12:59:57.690727 2026] [security2:error] [pid 123784:tid 123830] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBfWwDnJBNj2tDbYbsAQAADCk"]
[Tue Aug 18 12:59:57.733391 2026] [security2:error] [pid 123784:tid 123996] [client 132.196.30.78:9937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/cv.php"] [unique_id "aoSBfWwDnJBNj2tDbYbsAwAAAE4"]
[Tue Aug 18 12:59:57.792634 2026] [security2:error] [pid 123784:tid 124029] [client 20.127.136.245:28035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/NewFile.php"] [unique_id "aoSBfWwDnJBNj2tDbYbsBgAAAG8"]
[Tue Aug 18 12:59:57.815797 2026] [security2:error] [pid 123784:tid 123939] [client 20.119.58.187:10522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/wp-themes.php"] [unique_id "aoSBfWwDnJBNj2tDbYbsCAAAABU"]
[Tue Aug 18 12:59:57.860405 2026] [security2:error] [pid 123784:tid 123871] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/222.php"] [unique_id "aoSBfWwDnJBNj2tDbYbsCwAAMVI"]
[Tue Aug 18 12:59:57.887279 2026] [authz_core:error] [pid 123784:tid 123857] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:57.887607 2026] [authz_core:error] [pid 123784:tid 123857] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:57.911155 2026] [security2:error] [pid 123784:tid 124006] [client 158.23.17.4:55192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/th.php"] [unique_id "aoSBfWwDnJBNj2tDbYbsDQAAAFg"]
[Tue Aug 18 12:59:57.926737 2026] [security2:error] [pid 123784:tid 124033] [client 158.23.17.4:63617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBfWwDnJBNj2tDbYbsEAAAAHM"]
[Tue Aug 18 12:59:57.935051 2026] [security2:error] [pid 123784:tid 123982] [client 158.23.17.4:20209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/kj.php"] [unique_id "aoSBfWwDnJBNj2tDbYbsEQAAAEA"]
[Tue Aug 18 12:59:57.944808 2026] [security2:error] [pid 123784:tid 123865] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/fpwch.php"] [unique_id "aoSBfWwDnJBNj2tDbYbsEgAAcUw"]
[Tue Aug 18 12:59:58.014759 2026] [security2:error] [pid 123784:tid 124014] [client 68.155.154.236:25396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-2019.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsFwAAAGA"]
[Tue Aug 18 12:59:58.028153 2026] [security2:error] [pid 123784:tid 123847] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsGAAAPjo"]
[Tue Aug 18 12:59:58.069624 2026] [security2:error] [pid 123784:tid 123994] [client 158.23.17.4:15777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/kn.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsGwAAAEw"]
[Tue Aug 18 12:59:58.114595 2026] [security2:error] [pid 123784:tid 123919] [client 40.74.65.169:19486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/insc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsHgAAAAE"]
[Tue Aug 18 12:59:58.115542 2026] [security2:error] [pid 123784:tid 124000] [client 213.35.127.232:53309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsHwAAAFI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:58.147886 2026] [security2:error] [pid 123784:tid 123935] [client 158.158.74.177:16181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/n.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsIAAAABE"]
[Tue Aug 18 12:59:58.151534 2026] [security2:error] [pid 123784:tid 123814] [remote 47.128.124.115:15438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "caetesturismo.com.br"] [uri "/galeria/trekking-lencois-maranhenses/"] [unique_id "aoSBfmwDnJBNj2tDbYbsIQAAaxk"]
[Tue Aug 18 12:59:58.183250 2026] [security2:error] [pid 123784:tid 123999] [client 103.184.169.37:42751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsIgAAAFE"]
[Tue Aug 18 12:59:58.183379 2026] [security2:error] [pid 123784:tid 123999] [client 103.184.169.37:42751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsIgAAAFE"]
[Tue Aug 18 12:59:58.194422 2026] [security2:error] [pid 123784:tid 123929] [client 20.119.58.187:10435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/wp-signin.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsIwAAAAs"]
[Tue Aug 18 12:59:58.202541 2026] [security2:error] [pid 123784:tid 123855] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/info.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsJQAAbkI"]
[Tue Aug 18 12:59:58.211728 2026] [security2:error] [pid 123784:tid 124032] [client 20.203.138.185:51298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/clasa99.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsJgAAAHI"]
[Tue Aug 18 12:59:58.217354 2026] [security2:error] [pid 123784:tid 123962] [client 172.202.39.151:60146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsJwAAACw"]
[Tue Aug 18 12:59:58.235287 2026] [security2:error] [pid 123784:tid 123921] [client 20.127.136.245:28095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-Blogs.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsKAAAAAM"]
[Tue Aug 18 12:59:58.271291 2026] [security2:error] [pid 123784:tid 123822] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/FWAZ.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsKQAAcCE"]
[Tue Aug 18 12:59:58.311758 2026] [authz_core:error] [pid 123784:tid 123828] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:58.312181 2026] [authz_core:error] [pid 123784:tid 123828] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:58.361432 2026] [security2:error] [pid 123784:tid 123997] [client 138.36.100.162:42755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsLwAAAE8"]
[Tue Aug 18 12:59:58.361555 2026] [security2:error] [pid 123784:tid 123997] [client 138.36.100.162:42755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsLwAAAE8"]
[Tue Aug 18 12:59:58.369316 2026] [security2:error] [pid 123784:tid 123907] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/a.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsMQAAf3Y"]
[Tue Aug 18 12:59:58.389962 2026] [security2:error] [pid 123784:tid 123945] [client 37.40.227.74:56528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsMwAAABs"]
[Tue Aug 18 12:59:58.393887 2026] [security2:error] [pid 123784:tid 123945] [client 37.40.227.74:56528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsMwAAABs"]
[Tue Aug 18 12:59:58.403250 2026] [security2:error] [pid 123784:tid 124035] [client 158.23.17.4:55188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/admin404.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsNQAAAHU"]
[Tue Aug 18 12:59:58.415359 2026] [security2:error] [pid 123784:tid 124024] [client 20.104.85.180:52559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsNgAAAGo"]
[Tue Aug 18 12:59:58.421773 2026] [security2:error] [pid 123784:tid 123986] [client 149.34.210.141:51299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsNwAAAEQ"]
[Tue Aug 18 12:59:58.466437 2026] [security2:error] [pid 123784:tid 124023] [client 158.23.17.4:20215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/vg.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsOQAAAGk"]
[Tue Aug 18 12:59:58.516832 2026] [security2:error] [pid 123784:tid 123969] [client 20.226.56.190:8305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsPgAAADM"]
[Tue Aug 18 12:59:58.536514 2026] [security2:error] [pid 123784:tid 123826] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/chosen.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsQAAAYiU"]
[Tue Aug 18 12:59:58.561494 2026] [security2:error] [pid 123784:tid 124040] [client 20.119.58.187:10513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsQQAAAHo"]
[Tue Aug 18 12:59:58.604641 2026] [security2:error] [pid 123784:tid 123883] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/blurbs.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsQwAAJF4"]
[Tue Aug 18 12:59:58.621626 2026] [security2:error] [pid 123784:tid 123948] [client 158.23.17.4:63033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/wm.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsRQAAAB4"]
[Tue Aug 18 12:59:58.685096 2026] [security2:error] [pid 123784:tid 123986] [client 149.34.210.141:51299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsNwAAAEQ"]
[Tue Aug 18 12:59:58.686349 2026] [security2:error] [pid 123784:tid 124025] [client 20.226.56.190:21159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsSgAAAGs"]
[Tue Aug 18 12:59:58.701407 2026] [security2:error] [pid 123784:tid 123989] [client 68.155.154.236:25359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsTAAAAEc"]
[Tue Aug 18 12:59:58.703258 2026] [security2:error] [pid 123784:tid 123957] [client 158.23.17.4:29463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/st.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsTQAAACc"]
[Tue Aug 18 12:59:58.703705 2026] [security2:error] [pid 123784:tid 123793] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsTgAAUQQ"]
[Tue Aug 18 12:59:58.718309 2026] [security2:error] [pid 123784:tid 124004] [client 4.232.94.69:59736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/go.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsTwAAAFY"]
[Tue Aug 18 12:59:58.746771 2026] [security2:error] [pid 123784:tid 123991] [client 20.38.3.247:62208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsUgAAAEk"]
[Tue Aug 18 12:59:58.762887 2026] [security2:error] [pid 123784:tid 123988] [client 135.225.78.186:45189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsUwAAAEY"]
[Tue Aug 18 12:59:58.767364 2026] [security2:error] [pid 123784:tid 124002] [client 158.158.74.177:16185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/nc4.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsVAAAAFQ"]
[Tue Aug 18 12:59:58.791793 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:58.792092 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:58.818698 2026] [autoindex:error] [pid 123784:tid 123980] [client 20.100.169.31:23955] AH01276: Cannot serve directory /home1/xsolutions/ciacard-adm.3xsolutions.com/admin/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 12:59:58.820412 2026] [security2:error] [pid 123784:tid 123947] [client 40.74.65.169:20332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/file.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsWQAAAB0"]
[Tue Aug 18 12:59:58.853983 2026] [security2:error] [pid 123784:tid 123994] [client 20.127.136.245:28296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsXAAAAEw"]
[Tue Aug 18 12:59:58.871343 2026] [security2:error] [pid 123784:tid 123866] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/vx.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsXQAAY00"]
[Tue Aug 18 12:59:58.888454 2026] [security2:error] [pid 123784:tid 123961] [client 157.20.138.62:57721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsXwAAACs"]
[Tue Aug 18 12:59:58.888598 2026] [security2:error] [pid 123784:tid 123961] [client 157.20.138.62:57721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsXwAAACs"]
[Tue Aug 18 12:59:58.914113 2026] [security2:error] [pid 123784:tid 123928] [client 172.182.200.96:14144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsYgAAAAo"]
[Tue Aug 18 12:59:58.943664 2026] [security2:error] [pid 123784:tid 124035] [client 20.116.17.175:60478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsZgAAAHU"]
[Tue Aug 18 12:59:58.966053 2026] [security2:error] [pid 123784:tid 123813] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/100.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsZwAABBg"]
[Tue Aug 18 12:59:58.999515 2026] [security2:error] [pid 123784:tid 123964] [client 20.226.56.190:15202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/st.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsawAAAC4"]
[Tue Aug 18 12:59:59.075931 2026] [security2:error] [pid 123784:tid 123939] [client 20.203.138.185:42444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/666.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsbgAAABU"]
[Tue Aug 18 12:59:59.091510 2026] [core:error] [pid 123784:tid 123890] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 12:59:59.091533 2026] [core:error] [pid 123784:tid 123890] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 12:59:59.096882 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:59.097093 2026] [security2:error] [pid 123784:tid 123944] [client 158.23.17.4:17595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/qo.php"] [unique_id "aoSBf2wDnJBNj2tDbYbscQAAABo"]
[Tue Aug 18 12:59:59.097354 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:59.099666 2026] [security2:error] [pid 123784:tid 123974] [client 20.79.204.6:14082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSBf2wDnJBNj2tDbYbscgAAADg"]
[Tue Aug 18 12:59:59.122774 2026] [security2:error] [pid 123784:tid 123953] [client 132.196.30.78:25174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsdAAAACM"]
[Tue Aug 18 12:59:59.130770 2026] [security2:error] [pid 123784:tid 123959] [client 213.35.127.232:53528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsdQAAACk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 12:59:59.163276 2026] [security2:error] [pid 123784:tid 123982] [client 68.155.154.236:27529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/.cache/x.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsdgAAAEA"]
[Tue Aug 18 12:59:59.218217 2026] [security2:error] [pid 123784:tid 124040] [client 20.116.17.175:60462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBf2wDnJBNj2tDbYbseAAAAHo"]
[Tue Aug 18 12:59:59.245929 2026] [security2:error] [pid 123784:tid 124003] [client 158.23.17.4:57249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/sm.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsfAAAAFU"]
[Tue Aug 18 12:59:59.251333 2026] [security2:error] [pid 123784:tid 124010] [client 178.153.171.161:57712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsfgAAAFw"]
[Tue Aug 18 12:59:59.251461 2026] [security2:error] [pid 123784:tid 124010] [client 178.153.171.161:57712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsfgAAAFw"]
[Tue Aug 18 12:59:59.258995 2026] [security2:error] [pid 123784:tid 123819] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wap.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsfwAAFx4"]
[Tue Aug 18 12:59:59.282004 2026] [security2:error] [pid 123784:tid 123948] [client 68.221.73.131:29158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/key.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsgQAAAB4"]
[Tue Aug 18 12:59:59.293515 2026] [security2:error] [pid 123784:tid 123853] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/ccc.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsggAAUEA"]
[Tue Aug 18 12:59:59.305965 2026] [security2:error] [pid 123784:tid 123926] [client 20.119.58.187:10487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/ws.php"] [unique_id "aoSBf2wDnJBNj2tDbYbshAAAAAg"]
[Tue Aug 18 12:59:59.332404 2026] [security2:error] [pid 123784:tid 123952] [client 20.104.85.180:20266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/ok.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsjgAAACI"]
[Tue Aug 18 12:59:59.345526 2026] [security2:error] [pid 123784:tid 123999] [client 172.202.39.151:41128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/f35.php"] [unique_id "aoSBf2wDnJBNj2tDbYbskAAAAFE"]
[Tue Aug 18 12:59:59.373999 2026] [security2:error] [pid 123784:tid 123957] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsjwAAJwY"]
[Tue Aug 18 12:59:59.391837 2026] [security2:error] [pid 123784:tid 124031] [client 158.158.74.177:3883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/new.php"] [unique_id "aoSBf2wDnJBNj2tDbYbskwAAAHE"]
[Tue Aug 18 12:59:59.398179 2026] [authz_core:error] [pid 123784:tid 123820] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:59.398627 2026] [authz_core:error] [pid 123784:tid 123820] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:59.416467 2026] [security2:error] [pid 123784:tid 124044] [client 20.127.136.245:28094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/themes.php"] [unique_id "aoSBf2wDnJBNj2tDbYbslgAAAH4"]
[Tue Aug 18 12:59:59.426402 2026] [security2:error] [pid 123784:tid 123862] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsmAAAcEk"]
[Tue Aug 18 12:59:59.428876 2026] [security2:error] [pid 123784:tid 123975] [client 5.31.227.224:59009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBf2wDnJBNj2tDbYbslwAAADk"]
[Tue Aug 18 12:59:59.429886 2026] [security2:error] [pid 123784:tid 123975] [client 5.31.227.224:59009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBf2wDnJBNj2tDbYbslwAAADk"]
[Tue Aug 18 12:59:59.453054 2026] [security2:error] [pid 123784:tid 124002] [client 172.202.39.151:4458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/01.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsmQAAAFQ"]
[Tue Aug 18 12:59:59.460449 2026] [security2:error] [pid 123784:tid 124001] [client 158.23.17.4:20445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ac.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsmgAAAFM"]
[Tue Aug 18 12:59:59.492884 2026] [security2:error] [pid 123784:tid 123947] [client 20.116.17.175:60475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsnQAAAB0"]
[Tue Aug 18 12:59:59.514826 2026] [security2:error] [pid 123784:tid 123994] [client 20.38.3.247:46742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsoAAAAEw"]
[Tue Aug 18 12:59:59.514891 2026] [security2:error] [pid 123784:tid 124045] [client 40.74.65.169:20302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/dex.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsnwAAAH8"]
[Tue Aug 18 12:59:59.531007 2026] [security2:error] [pid 123784:tid 123971] [client 20.226.56.190:42471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/le.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsoQAAADU"]
[Tue Aug 18 12:59:59.555807 2026] [security2:error] [pid 123784:tid 124006] [client 168.62.48.100:5507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/zugvi.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsogAAAFg"]
[Tue Aug 18 12:59:59.594147 2026] [security2:error] [pid 123784:tid 123806] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/bgymj.php"] [unique_id "aoSBf2wDnJBNj2tDbYbspgAANBE"]
[Tue Aug 18 12:59:59.598807 2026] [security2:error] [pid 123784:tid 123918] [client 213.202.253.4:59697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/delpaths.php"] [unique_id "aoSBf2wDnJBNj2tDbYbspwAAAAA"], referer: www.google.com
[Tue Aug 18 12:59:59.625153 2026] [security2:error] [pid 123784:tid 123870] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/get.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsqAAAalE"]
[Tue Aug 18 12:59:59.660255 2026] [security2:error] [pid 123784:tid 123961] [client 20.119.58.187:10554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/wsa.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsqgAAACs"]
[Tue Aug 18 12:59:59.694924 2026] [authz_core:error] [pid 123784:tid 123800] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 12:59:59.695181 2026] [authz_core:error] [pid 123784:tid 123800] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 12:59:59.708067 2026] [security2:error] [pid 123784:tid 123979] [client 20.79.204.6:14084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsrAAAAD0"]
[Tue Aug 18 12:59:59.754078 2026] [security2:error] [pid 123784:tid 124017] [client 132.196.30.78:16995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/ws83.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsrwAAAGM"]
[Tue Aug 18 12:59:59.763076 2026] [security2:error] [pid 123784:tid 123815] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/aa.php"] [unique_id "aoSBf2wDnJBNj2tDbYbssAAAfBo"]
[Tue Aug 18 12:59:59.774182 2026] [security2:error] [pid 123784:tid 123939] [client 20.116.17.175:59976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/cok.php"] [unique_id "aoSBf2wDnJBNj2tDbYbssQAAABU"]
[Tue Aug 18 12:59:59.819556 2026] [security2:error] [pid 123784:tid 123804] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBf2wDnJBNj2tDbYbssgAAOA8"]
[Tue Aug 18 12:59:59.819787 2026] [security2:error] [pid 123784:tid 123974] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBf2wDnJBNj2tDbYbssgAAOA8"]
[Tue Aug 18 12:59:59.872775 2026] [security2:error] [pid 123784:tid 124026] [client 158.23.17.4:38316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/28.php"] [unique_id "aoSBf2wDnJBNj2tDbYbstgAAAGw"]
[Tue Aug 18 12:59:59.928677 2026] [security2:error] [pid 123784:tid 123941] [client 20.226.56.190:10580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/hr.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsugAAABc"]
[Tue Aug 18 12:59:59.930734 2026] [security2:error] [pid 123784:tid 123803] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsuwAAYA4"]
[Tue Aug 18 12:59:59.947574 2026] [security2:error] [pid 123784:tid 123958] [client 20.127.136.245:28318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/cv.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsvQAAACg"]
[Tue Aug 18 12:59:59.982516 2026] [security2:error] [pid 123784:tid 123965] [client 157.90.156.63:17428] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.institutoferiani.com.br"] [uri "/index.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsaAAAAC8"], referer: https://www.institutoferiani.com.br
[Tue Aug 18 13:00:00.012690 2026] [security2:error] [pid 123784:tid 124037] [client 20.119.58.187:10159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/w.php"] [unique_id "aoSBgGwDnJBNj2tDbYbsvgAAAHc"]
[Tue Aug 18 13:00:00.015337 2026] [security2:error] [pid 123784:tid 123944] [client 158.158.74.177:3387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/packed.php"] [unique_id "aoSBgGwDnJBNj2tDbYbsvwAAABo"]
[Tue Aug 18 13:00:00.023923 2026] [security2:error] [pid 123784:tid 123821] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/images.php"] [unique_id "aoSBgGwDnJBNj2tDbYbswAAATSA"]
[Tue Aug 18 13:00:00.038075 2026] [security2:error] [pid 123784:tid 123972] [client 20.251.48.93:64057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/akismet.php"] [unique_id "aoSBgGwDnJBNj2tDbYbswwAAADY"]
[Tue Aug 18 13:00:00.042132 2026] [security2:error] [pid 123784:tid 123926] [client 158.23.17.4:63023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/yz.php"] [unique_id "aoSBgGwDnJBNj2tDbYbsxAAAAAg"]
[Tue Aug 18 13:00:00.056388 2026] [security2:error] [pid 123784:tid 124005] [client 68.155.154.236:27566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSBgGwDnJBNj2tDbYbsxQAAAFc"]
[Tue Aug 18 13:00:00.065365 2026] [security2:error] [pid 123784:tid 124022] [client 20.116.17.175:60426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/accesson.php"] [unique_id "aoSBgGwDnJBNj2tDbYbsxgAAAGg"]
[Tue Aug 18 13:00:00.077853 2026] [security2:error] [pid 123784:tid 123935] [client 85.154.68.202:62639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBgGwDnJBNj2tDbYbsxwAAABE"]
[Tue Aug 18 13:00:00.078032 2026] [security2:error] [pid 123784:tid 123935] [client 85.154.68.202:62639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBgGwDnJBNj2tDbYbsxwAAABE"]
[Tue Aug 18 13:00:00.098363 2026] [security2:error] [pid 123784:tid 123879] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/bolt.php"] [unique_id "aoSBgGwDnJBNj2tDbYbsyAAAVlo"]
[Tue Aug 18 13:00:00.156025 2026] [security2:error] [pid 123784:tid 124016] [client 213.35.127.232:53725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBgGwDnJBNj2tDbYbsywAAAGI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:00.184786 2026] [security2:error] [pid 123784:tid 123988] [client 223.185.37.47:17634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBgGwDnJBNj2tDbYbszAAAAEY"]
[Tue Aug 18 13:00:00.184903 2026] [security2:error] [pid 123784:tid 123988] [client 223.185.37.47:17634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBgGwDnJBNj2tDbYbszAAAAEY"]
[Tue Aug 18 13:00:00.211750 2026] [security2:error] [pid 123784:tid 124044] [client 40.74.65.169:20297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/key.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs0QAAAH4"]
[Tue Aug 18 13:00:00.233020 2026] [security2:error] [pid 123784:tid 123975] [client 20.226.56.190:17934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kt.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs0gAAADk"]
[Tue Aug 18 13:00:00.241035 2026] [security2:error] [pid 123784:tid 124002] [client 135.225.78.186:38863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/av.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs1AAAAFQ"]
[Tue Aug 18 13:00:00.262180 2026] [security2:error] [pid 123784:tid 123930] [client 20.203.138.185:22609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/thui.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs1QAAAAw"]
[Tue Aug 18 13:00:00.265027 2026] [security2:error] [pid 123784:tid 123938] [client 20.104.85.180:18714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/item.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs1gAAABQ"]
[Tue Aug 18 13:00:00.265246 2026] [security2:error] [pid 123784:tid 123846] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/bthil.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs1wAAGDk"]
[Tue Aug 18 13:00:00.297798 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:00.298066 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:00.330471 2026] [security2:error] [pid 123784:tid 123915] [remote 185.118.190.176:55052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.190.118.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "site.supercarconsulting.com.br"] [uri "/wp-login.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs2gAAUn4"]
[Tue Aug 18 13:00:00.332485 2026] [security2:error] [pid 123784:tid 123962] [client 20.79.204.6:14105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs2wAAACw"]
[Tue Aug 18 13:00:00.356136 2026] [security2:error] [pid 123784:tid 123923] [client 20.116.17.175:59988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/av.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs3AAAAAU"]
[Tue Aug 18 13:00:00.365311 2026] [security2:error] [pid 123784:tid 124031] [client 132.196.30.78:25196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/atex1.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs3QAAAHE"]
[Tue Aug 18 13:00:00.377393 2026] [security2:error] [pid 123784:tid 124001] [client 20.119.58.187:10538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/x.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs3gAAAFM"]
[Tue Aug 18 13:00:00.399356 2026] [security2:error] [pid 123784:tid 123876] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/alls.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs4QAAHVc"]
[Tue Aug 18 13:00:00.442046 2026] [security2:error] [pid 123784:tid 123994] [client 20.226.56.190:10607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ww.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs4gAAAEw"]
[Tue Aug 18 13:00:00.492474 2026] [security2:error] [pid 123784:tid 124019] [client 158.23.17.4:20430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/kj.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs5AAAAGU"]
[Tue Aug 18 13:00:00.508403 2026] [security2:error] [pid 123784:tid 123945] [client 158.23.17.4:51196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/sd.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs5QAAABs"]
[Tue Aug 18 13:00:00.510642 2026] [security2:error] [pid 123784:tid 123970] [client 20.226.56.190:10569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/mo.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs5gAAADQ"]
[Tue Aug 18 13:00:00.515043 2026] [core:error] [pid 123784:tid 123816] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 13:00:00.515059 2026] [core:error] [pid 123784:tid 123816] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 13:00:00.524416 2026] [security2:error] [pid 123784:tid 123983] [client 158.23.17.4:8899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/m.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs6AAAAEE"]
[Tue Aug 18 13:00:00.591955 2026] [security2:error] [pid 123784:tid 124017] [client 158.23.17.4:33529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/le.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs8QAAAGM"]
[Tue Aug 18 13:00:00.601223 2026] [authz_core:error] [pid 123784:tid 123841] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:00.601692 2026] [authz_core:error] [pid 123784:tid 123841] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:00.631070 2026] [security2:error] [pid 123784:tid 123925] [client 20.116.17.175:60445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/kj.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs8gAAAAc"]
[Tue Aug 18 13:00:00.636409 2026] [security2:error] [pid 123784:tid 123997] [client 20.226.56.190:11615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/qr.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs8wAAAE8"]
[Tue Aug 18 13:00:00.649268 2026] [security2:error] [pid 123784:tid 123953] [client 20.250.27.191:63180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs-AAAACM"]
[Tue Aug 18 13:00:00.682294 2026] [security2:error] [pid 123784:tid 123898] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/x.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs-wAAXG0"]
[Tue Aug 18 13:00:00.717962 2026] [security2:error] [pid 123784:tid 123941] [client 172.202.39.151:44132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/inputs.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs_QAAABc"]
[Tue Aug 18 13:00:00.730929 2026] [security2:error] [pid 123784:tid 123966] [client 68.155.154.236:25344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs_gAAADA"]
[Tue Aug 18 13:00:00.731213 2026] [security2:error] [pid 123784:tid 123969] [client 20.119.58.187:10443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/xx.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs_wAAADM"]
[Tue Aug 18 13:00:00.732039 2026] [security2:error] [pid 123784:tid 123904] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/coffexium.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtAAAAIHM"]
[Tue Aug 18 13:00:00.745657 2026] [security2:error] [pid 123784:tid 123922] [client 20.127.136.245:28042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtAQAAAAQ"]
[Tue Aug 18 13:00:00.849187 2026] [security2:error] [pid 123784:tid 124032] [client 158.158.74.177:16136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/plugin.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtCgAAAHI"]
[Tue Aug 18 13:00:00.858970 2026] [security2:error] [pid 123784:tid 123985] [client 20.226.56.190:20912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/dirs.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtCwAAAEM"]
[Tue Aug 18 13:00:00.868277 2026] [security2:error] [pid 123784:tid 123789] [remote 97.74.87.194:47920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "immobili.adm.br"] [uri "/wp-login.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtDAAAAwA"]
[Tue Aug 18 13:00:00.881378 2026] [security2:error] [pid 123784:tid 123856] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/index/function.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtDgAAfkM"]
[Tue Aug 18 13:00:00.886698 2026] [security2:error] [pid 123784:tid 124030] [client 40.74.65.169:47057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/kir.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtDwAAAHA"]
[Tue Aug 18 13:00:00.901070 2026] [authz_core:error] [pid 123784:tid 123895] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:00.901493 2026] [authz_core:error] [pid 123784:tid 123895] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:00.913065 2026] [security2:error] [pid 123784:tid 124013] [client 20.116.17.175:59987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtEgAAAF8"]
[Tue Aug 18 13:00:00.939772 2026] [security2:error] [pid 123784:tid 123958] [client 20.79.204.6:14030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/st.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtFgAAACg"]
[Tue Aug 18 13:00:01.046200 2026] [security2:error] [pid 123784:tid 124001] [client 158.23.17.4:20371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/vg.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtHQAAAFM"]
[Tue Aug 18 13:00:01.055156 2026] [security2:error] [pid 123784:tid 123996] [client 20.250.27.191:28029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtHgAAAE4"]
[Tue Aug 18 13:00:01.075692 2026] [security2:error] [pid 123784:tid 123902] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/aaa.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtIAAATHE"]
[Tue Aug 18 13:00:01.101257 2026] [security2:error] [pid 123784:tid 123933] [client 20.226.56.190:40136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/sn.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtIgAAAA8"]
[Tue Aug 18 13:00:01.110106 2026] [security2:error] [pid 123784:tid 123892] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/red.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtIwAAWGc"]
[Tue Aug 18 13:00:01.134820 2026] [security2:error] [pid 123784:tid 124009] [client 20.203.138.185:24920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/agg.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtJQAAAFs"]
[Tue Aug 18 13:00:01.171091 2026] [security2:error] [pid 123784:tid 123989] [client 213.35.127.232:53949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtJgAAAEc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:01.177358 2026] [security2:error] [pid 123784:tid 124000] [client 132.196.30.78:25191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtJwAAAFI"]
[Tue Aug 18 13:00:01.196235 2026] [security2:error] [pid 123784:tid 123977] [client 20.116.17.175:60439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/png.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtKAAAADs"]
[Tue Aug 18 13:00:01.204179 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:01.205567 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:01.213504 2026] [security2:error] [pid 123784:tid 123932] [client 147.53.121.226:9883] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtDQAAAA4"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/
[Tue Aug 18 13:00:01.243892 2026] [security2:error] [pid 123784:tid 123814] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/abcd.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtLQAAKxk"]
[Tue Aug 18 13:00:01.250345 2026] [security2:error] [pid 123784:tid 123942] [client 20.119.58.187:10461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtIQAAABg"]
[Tue Aug 18 13:00:01.270647 2026] [security2:error] [pid 123784:tid 123928] [client 20.127.136.245:28521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/ws83.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtLwAAAAo"]
[Tue Aug 18 13:00:01.337446 2026] [security2:error] [pid 123784:tid 124042] [client 172.182.200.96:7554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtMgAAAHw"]
[Tue Aug 18 13:00:01.375971 2026] [security2:error] [pid 123784:tid 123924] [client 68.155.154.236:27559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtNQAAAAY"]
[Tue Aug 18 13:00:01.421872 2026] [security2:error] [pid 123784:tid 123797] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-good.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtOAAAIwg"]
[Tue Aug 18 13:00:01.437953 2026] [security2:error] [pid 123784:tid 123959] [client 158.23.17.4:44839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/nl.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtOQAAACk"]
[Tue Aug 18 13:00:01.440320 2026] [security2:error] [pid 123784:tid 124026] [client 158.23.17.4:7221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/sm.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtOgAAAGw"]
[Tue Aug 18 13:00:01.462609 2026] [security2:error] [pid 123784:tid 123987] [client 20.250.27.191:40183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/domvf.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtPAAAAEU"]
[Tue Aug 18 13:00:01.474876 2026] [security2:error] [pid 123784:tid 123941] [client 20.116.17.175:60441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/ab.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtPQAAABc"]
[Tue Aug 18 13:00:01.536163 2026] [security2:error] [pid 123784:tid 123948] [client 20.226.56.190:10623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/43.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtQQAAAB4"]
[Tue Aug 18 13:00:01.578338 2026] [security2:error] [pid 123784:tid 123925] [client 20.79.204.6:14085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtQgAAAAc"]
[Tue Aug 18 13:00:01.583572 2026] [security2:error] [pid 123784:tid 123995] [client 20.226.56.190:20915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fresh.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtQwAAAE0"]
[Tue Aug 18 13:00:01.590006 2026] [security2:error] [pid 123784:tid 124020] [client 40.74.65.169:47043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/nofile.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtRQAAAGY"]
[Tue Aug 18 13:00:01.590847 2026] [security2:error] [pid 123784:tid 123891] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/simple.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtRgAANmY"]
[Tue Aug 18 13:00:01.606587 2026] [security2:error] [pid 123784:tid 123966] [client 20.119.58.187:10530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/y.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtRwAAADA"]
[Tue Aug 18 13:00:01.623891 2026] [security2:error] [pid 123784:tid 124028] [client 158.23.17.4:15122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/km.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtSQAAAG4"]
[Tue Aug 18 13:00:01.650788 2026] [security2:error] [pid 123784:tid 123844] [remote 47.89.174.181:26996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.api.atlas-ia.com"] [uri "/.env"] [unique_id "aoSBgWwDnJBNj2tDbYbtSgAAdDc"]
[Tue Aug 18 13:00:01.695048 2026] [security2:error] [pid 123784:tid 124027] [client 135.225.78.186:37592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/images.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtUAAAAG0"]
[Tue Aug 18 13:00:01.703099 2026] [security2:error] [pid 123784:tid 124021] [client 158.158.74.177:3855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/public/moon.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtUQAAAGc"]
[Tue Aug 18 13:00:01.728464 2026] [security2:error] [pid 123784:tid 124044] [client 68.155.154.236:25398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtUwAAAH4"]
[Tue Aug 18 13:00:01.729409 2026] [authz_core:error] [pid 123784:tid 123883] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:01.729883 2026] [authz_core:error] [pid 123784:tid 123883] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:01.764560 2026] [security2:error] [pid 123784:tid 123912] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/edit-tags.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtVwAAcHs"]
[Tue Aug 18 13:00:01.769355 2026] [security2:error] [pid 123784:tid 124024] [client 20.116.17.175:60447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/12.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtWAAAAGo"]
[Tue Aug 18 13:00:01.801172 2026] [security2:error] [pid 123784:tid 123952] [client 132.196.30.78:25155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/w.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtWQAAACI"]
[Tue Aug 18 13:00:01.874810 2026] [security2:error] [pid 123784:tid 123954] [client 20.226.56.190:17962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gj.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtXgAAACQ"]
[Tue Aug 18 13:00:01.882192 2026] [security2:error] [pid 123784:tid 124031] [client 20.251.48.93:64063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/admin.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtXwAAAHE"]
[Tue Aug 18 13:00:01.893603 2026] [security2:error] [pid 123784:tid 123947] [client 20.250.27.191:43479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtYAAAAB0"]
[Tue Aug 18 13:00:01.903593 2026] [security2:error] [pid 123784:tid 124045] [client 158.23.17.4:47671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/28.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtYQAAAH8"]
[Tue Aug 18 13:00:01.923547 2026] [security2:error] [pid 123784:tid 123932] [client 147.53.121.226:9883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtDQAAAA4"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/
[Tue Aug 18 13:00:01.939048 2026] [security2:error] [pid 123784:tid 123793] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/u.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtYgAAGwQ"]
[Tue Aug 18 13:00:01.963806 2026] [security2:error] [pid 123784:tid 123970] [client 172.202.39.151:4230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/lv.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtZAAAADQ"]
[Tue Aug 18 13:00:01.965809 2026] [security2:error] [pid 123784:tid 123977] [client 20.203.138.185:51312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/erty.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtZQAAADs"]
[Tue Aug 18 13:00:01.999433 2026] [autoindex:error] [pid 123784:tid 123984] [client 4.232.94.69:37658] AH01276: Cannot serve directory /home2/vfunnelcrmcom/public_html/wp-includes/rest-api/fields/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:02.018687 2026] [security2:error] [pid 123784:tid 123990] [client 20.226.56.190:10560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/pd.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtbAAAAEg"]
[Tue Aug 18 13:00:02.019683 2026] [security2:error] [pid 123784:tid 123928] [client 172.182.200.96:14099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/images/security.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtbQAAAAo"]
[Tue Aug 18 13:00:02.061129 2026] [security2:error] [pid 123784:tid 124017] [client 20.116.17.175:60429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/x1da.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtcAAAAGM"]
[Tue Aug 18 13:00:02.075732 2026] [security2:error] [pid 123784:tid 124042] [client 192.141.172.134:56231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtcQAAAHw"]
[Tue Aug 18 13:00:02.075955 2026] [security2:error] [pid 123784:tid 124042] [client 192.141.172.134:56231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtcQAAAHw"]
[Tue Aug 18 13:00:02.090220 2026] [security2:error] [pid 123784:tid 123996] [client 20.127.136.245:28542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/atex1.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtcgAAAE4"]
[Tue Aug 18 13:00:02.113532 2026] [security2:error] [pid 123784:tid 123858] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtdAAAI0U"]
[Tue Aug 18 13:00:02.164491 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:12504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/68.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtdwAAAH0"]
[Tue Aug 18 13:00:02.171429 2026] [security2:error] [pid 123784:tid 124007] [client 20.226.56.190:15184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/th.php"] [unique_id "aoSBgmwDnJBNj2tDbYbteAAAAFk"]
[Tue Aug 18 13:00:02.188677 2026] [security2:error] [pid 123784:tid 123943] [client 20.79.204.6:14088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-configs.php"] [unique_id "aoSBgmwDnJBNj2tDbYbteQAAABk"]
[Tue Aug 18 13:00:02.193007 2026] [security2:error] [pid 123784:tid 123960] [client 213.35.127.232:54155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtegAAACo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:02.209910 2026] [security2:error] [pid 123784:tid 123926] [client 68.155.154.236:4054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtewAAAAg"]
[Tue Aug 18 13:00:02.236619 2026] [security2:error] [pid 123784:tid 123966] [client 4.232.94.69:37658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/atomlib.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtfQAAADA"]
[Tue Aug 18 13:00:02.258039 2026] [security2:error] [pid 123784:tid 124022] [client 20.226.56.190:17955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/admin404.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtfwAAAGg"]
[Tue Aug 18 13:00:02.265600 2026] [security2:error] [pid 123784:tid 123890] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtgAAAUmU"]
[Tue Aug 18 13:00:02.267518 2026] [security2:error] [pid 123784:tid 124000] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtgAAAUmU"]
[Tue Aug 18 13:00:02.281870 2026] [security2:error] [pid 123784:tid 123881] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/h.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtggAAc1w"]
[Tue Aug 18 13:00:02.292904 2026] [security2:error] [pid 123784:tid 124028] [client 40.74.65.169:19496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/fling.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtgwAAAG4"]
[Tue Aug 18 13:00:02.313974 2026] [security2:error] [pid 123784:tid 123937] [client 20.250.27.191:63191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/gec.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtiAAAABM"]
[Tue Aug 18 13:00:02.317345 2026] [security2:error] [pid 123784:tid 123988] [client 20.226.56.190:21150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/qo.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtiQAAAEY"]
[Tue Aug 18 13:00:02.325218 2026] [authz_core:error] [pid 123784:tid 123799] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:02.325700 2026] [authz_core:error] [pid 123784:tid 123799] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:02.338067 2026] [security2:error] [pid 123784:tid 124041] [client 158.158.74.177:3861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/public/storage.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtigAAAHs"]
[Tue Aug 18 13:00:02.412699 2026] [security2:error] [pid 123784:tid 124002] [client 20.116.17.175:59982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/mcs.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtkAAAAFQ"]
[Tue Aug 18 13:00:02.424110 2026] [security2:error] [pid 123784:tid 123930] [client 20.226.56.190:7324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/sd.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtkQAAAAw"]
[Tue Aug 18 13:00:02.449538 2026] [security2:error] [pid 123784:tid 123853] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtkgAALEA"]
[Tue Aug 18 13:00:02.452905 2026] [security2:error] [pid 123784:tid 123940] [client 158.23.17.4:15797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/m.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtkwAAABY"]
[Tue Aug 18 13:00:02.458249 2026] [security2:error] [pid 123784:tid 123927] [client 20.226.56.190:17952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/km.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtlAAAAAk"]
[Tue Aug 18 13:00:02.517738 2026] [security2:error] [pid 123784:tid 124038] [client 20.226.56.190:6380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/mf.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtmgAAAHg"]
[Tue Aug 18 13:00:02.524959 2026] [security2:error] [pid 123784:tid 123994] [client 20.38.3.247:61589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/blurbs.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtmwAAAEw"]
[Tue Aug 18 13:00:02.531457 2026] [security2:error] [pid 123784:tid 124018] [client 158.23.17.4:51185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/mf.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtnAAAAGQ"]
[Tue Aug 18 13:00:02.538095 2026] [security2:error] [pid 123784:tid 124005] [client 132.196.30.78:17004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/archive.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtnQAAAFc"]
[Tue Aug 18 13:00:02.609781 2026] [security2:error] [pid 123784:tid 123946] [client 20.226.56.190:17946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ie.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtoAAAABw"]
[Tue Aug 18 13:00:02.619326 2026] [security2:error] [pid 123784:tid 123850] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/a7.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtogAAQj0"]
[Tue Aug 18 13:00:02.630436 2026] [authz_core:error] [pid 123784:tid 123842] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:02.631168 2026] [authz_core:error] [pid 123784:tid 123842] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:02.642593 2026] [security2:error] [pid 123784:tid 124031] [client 20.127.136.245:28092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/class-t.api.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtpAAAAHE"]
[Tue Aug 18 13:00:02.655502 2026] [security2:error] [pid 123784:tid 123928] [client 20.226.56.190:8283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/nw.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtpQAAAAo"]
[Tue Aug 18 13:00:02.677309 2026] [security2:error] [pid 123784:tid 123920] [client 20.203.138.185:53761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/mini.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtqAAAAAI"]
[Tue Aug 18 13:00:02.689638 2026] [security2:error] [pid 123784:tid 124042] [client 20.116.17.175:60463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/adminner.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtqQAAAHw"]
[Tue Aug 18 13:00:02.720614 2026] [security2:error] [pid 123784:tid 124009] [client 68.155.154.236:27543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtqgAAAFs"]
[Tue Aug 18 13:00:02.726706 2026] [security2:error] [pid 123784:tid 123949] [client 20.250.27.191:28007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/sky.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtqwAAAB8"]
[Tue Aug 18 13:00:02.738171 2026] [security2:error] [pid 123784:tid 123905] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-content/index.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtrAAANXQ"]
[Tue Aug 18 13:00:02.764783 2026] [security2:error] [pid 123784:tid 123976] [client 158.23.17.4:12504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/jl.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtrwAAADo"]
[Tue Aug 18 13:00:02.788879 2026] [security2:error] [pid 123784:tid 123807] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/manager.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtsAAAbRI"]
[Tue Aug 18 13:00:02.819853 2026] [security2:error] [pid 123784:tid 123980] [client 20.79.204.6:14086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-post.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtsQAAAD4"]
[Tue Aug 18 13:00:02.859601 2026] [security2:error] [pid 123784:tid 123982] [client 20.226.56.190:10610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/sb.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtswAAAEA"]
[Tue Aug 18 13:00:02.929531 2026] [security2:error] [pid 123784:tid 124029] [client 158.23.17.4:15758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/nl.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtugAAAG8"]
[Tue Aug 18 13:00:02.935046 2026] [authz_core:error] [pid 123784:tid 123851] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:02.939668 2026] [authz_core:error] [pid 123784:tid 123851] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:02.957793 2026] [security2:error] [pid 123784:tid 123929] [client 136.66.149.90:38974] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/graphql"] [unique_id "aoSBgmwDnJBNj2tDbYbtvQAAAAs"], referer: https://cpcontacts.lojasmemo.com.br
[Tue Aug 18 13:00:02.959516 2026] [security2:error] [pid 123784:tid 123939] [client 158.158.74.177:16145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/radio.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtvgAAABU"]
[Tue Aug 18 13:00:02.959583 2026] [security2:error] [pid 123784:tid 123992] [client 136.66.149.90:39036] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/proc/self/environ"] [unique_id "aoSBgmwDnJBNj2tDbYbtvwAAAEo"]
[Tue Aug 18 13:00:02.963473 2026] [security2:error] [pid 123784:tid 124011] [client 136.66.149.90:39026] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBgmwDnJBNj2tDbYbtwAAAAF0"]
[Tue Aug 18 13:00:02.975251 2026] [security2:error] [pid 123784:tid 124018] [client 40.74.65.169:42484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/zoo1.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtxQAAAGQ"]
[Tue Aug 18 13:00:02.976113 2026] [security2:error] [pid 123784:tid 124044] [client 20.116.17.175:60446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/dragonshell.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtygAAAH4"]
[Tue Aug 18 13:00:02.994220 2026] [security2:error] [pid 123784:tid 124016] [client 136.66.149.90:39166] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@vite/env"] [unique_id "aoSBgmwDnJBNj2tDbYbt1QAAAGI"]
[Tue Aug 18 13:00:03.005497 2026] [core:error] [pid 123784:tid 123988] [client 136.66.149.90:39268] AH10244: invalid URI path (/assets../../../etc/passwd)
[Tue Aug 18 13:00:03.008495 2026] [security2:error] [pid 123784:tid 123897] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/w1.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt3AAAD2w"]
[Tue Aug 18 13:00:03.011899 2026] [security2:error] [pid 123784:tid 124020] [client 136.66.149.90:38986] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBg2wDnJBNj2tDbYbt3gAAAGY"]
[Tue Aug 18 13:00:03.015101 2026] [security2:error] [pid 123784:tid 124033] [client 136.66.149.90:39184] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/etc/passwd"] [unique_id "aoSBg2wDnJBNj2tDbYbt4AAAAHM"]
[Tue Aug 18 13:00:03.017013 2026] [security2:error] [pid 123784:tid 124043] [client 136.66.149.90:38970] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/fetch"] [unique_id "aoSBg2wDnJBNj2tDbYbt4gAAAH0"]
[Tue Aug 18 13:00:03.018239 2026] [security2:error] [pid 123784:tid 124025] [client 136.66.149.90:39124] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/home/ec2-user/.aws/credentials"] [unique_id "aoSBg2wDnJBNj2tDbYbt4wAAAGs"]
[Tue Aug 18 13:00:03.019427 2026] [security2:error] [pid 123784:tid 124043] [client 168.62.48.100:18048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt5AAAAH0"]
[Tue Aug 18 13:00:03.021553 2026] [security2:error] [pid 123784:tid 123966] [client 136.66.149.90:39182] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/read"] [unique_id "aoSBg2wDnJBNj2tDbYbt6AAAADA"]
[Tue Aug 18 13:00:03.023251 2026] [security2:error] [pid 123784:tid 123944] [client 136.66.149.90:39240] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.env"] [unique_id "aoSBg2wDnJBNj2tDbYbt6gAAABo"]
[Tue Aug 18 13:00:03.025586 2026] [security2:error] [pid 123784:tid 123926] [client 136.66.149.90:39096] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/actuator/env"] [unique_id "aoSBg2wDnJBNj2tDbYbt6wAAAAg"]
[Tue Aug 18 13:00:03.064398 2026] [security2:error] [pid 123784:tid 123911] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/admin.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt8AAAHHo"]
[Tue Aug 18 13:00:03.064912 2026] [security2:error] [pid 123784:tid 123967] [client 68.155.154.236:25360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt8QAAADE"]
[Tue Aug 18 13:00:03.075753 2026] [security2:error] [pid 123784:tid 123983] [client 190.92.174.183:47178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBgmwDnJBNj2tDbYbttgAAAEE"]
[Tue Aug 18 13:00:03.075984 2026] [security2:error] [pid 123784:tid 123983] [client 190.92.174.183:47178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBgmwDnJBNj2tDbYbttgAAAEE"]
[Tue Aug 18 13:00:03.142285 2026] [security2:error] [pid 123784:tid 123973] [client 20.250.27.191:27985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/sixxis.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt9QAAADc"]
[Tue Aug 18 13:00:03.156098 2026] [security2:error] [pid 123784:tid 123994] [client 132.196.30.78:16993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/bless.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt9wAAAEw"]
[Tue Aug 18 13:00:03.169101 2026] [security2:error] [pid 123784:tid 124019] [client 20.127.136.245:28505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/w.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt-AAAAGU"]
[Tue Aug 18 13:00:03.181444 2026] [core:error] [pid 123784:tid 123815] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 13:00:03.181469 2026] [core:error] [pid 123784:tid 123815] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 13:00:03.187676 2026] [security2:error] [pid 123784:tid 124009] [client 20.251.48.93:64056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/ajax.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt-wAAAFs"]
[Tue Aug 18 13:00:03.206799 2026] [security2:error] [pid 123784:tid 123974] [client 168.62.48.100:5625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wsrer.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt_QAAADg"]
[Tue Aug 18 13:00:03.212536 2026] [security2:error] [pid 123784:tid 124032] [client 213.35.127.232:54399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt_wAAAHI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:03.247171 2026] [security2:error] [pid 123784:tid 123985] [client 103.120.71.157:21211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuAwAAAEM"]
[Tue Aug 18 13:00:03.247370 2026] [security2:error] [pid 123784:tid 123985] [client 103.120.71.157:21211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuAwAAAEM"]
[Tue Aug 18 13:00:03.263735 2026] [security2:error] [pid 123784:tid 123930] [client 20.226.56.190:40164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xj.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuBQAAAAw"]
[Tue Aug 18 13:00:03.275120 2026] [security2:error] [pid 123784:tid 124023] [client 168.62.48.100:18144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuBgAAAGk"]
[Tue Aug 18 13:00:03.298754 2026] [security2:error] [pid 123784:tid 123958] [client 158.23.17.4:15805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/68.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuCAAAACg"]
[Tue Aug 18 13:00:03.332236 2026] [security2:error] [pid 123784:tid 123927] [client 20.65.98.162:45619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuCgAAAAk"]
[Tue Aug 18 13:00:03.351918 2026] [security2:error] [pid 123784:tid 123863] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-login.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuCwAAeEo"]
[Tue Aug 18 13:00:03.367031 2026] [security2:error] [pid 123784:tid 124044] [client 20.116.17.175:59972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/setup-config.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuDAAAAH4"]
[Tue Aug 18 13:00:03.441858 2026] [security2:error] [pid 123784:tid 123935] [client 20.79.204.6:14022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuFAAAABE"]
[Tue Aug 18 13:00:03.452330 2026] [security2:error] [pid 123784:tid 124006] [client 20.226.56.190:17961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ns.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuFQAAAFg"]
[Tue Aug 18 13:00:03.480352 2026] [security2:error] [pid 123784:tid 123959] [client 20.203.138.185:32212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/sid3.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuGQAAACk"]
[Tue Aug 18 13:00:03.532037 2026] [security2:error] [pid 123784:tid 123968] [client 168.62.48.100:18117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/weozh.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuJAAAADI"]
[Tue Aug 18 13:00:03.543302 2026] [security2:error] [pid 123784:tid 123915] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/default.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuJQAAK34"]
[Tue Aug 18 13:00:03.546928 2026] [authz_core:error] [pid 123784:tid 123820] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:03.547475 2026] [authz_core:error] [pid 123784:tid 123820] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:03.560543 2026] [security2:error] [pid 123784:tid 123802] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/file52.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuJwAAcA0"]
[Tue Aug 18 13:00:03.563339 2026] [security2:error] [pid 123784:tid 124030] [client 68.155.154.236:25393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuKAAAAHA"]
[Tue Aug 18 13:00:03.571205 2026] [security2:error] [pid 123784:tid 123948] [client 20.250.27.191:40159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/yj09.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuKQAAAB4"]
[Tue Aug 18 13:00:03.582094 2026] [security2:error] [pid 123784:tid 123931] [client 158.158.74.177:16182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/root.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuKgAAAA0"]
[Tue Aug 18 13:00:03.590394 2026] [security2:error] [pid 123784:tid 124007] [client 79.127.164.8:60088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/upload.bak"] [unique_id "aoSBg2wDnJBNj2tDbYbuLAAAAFk"], referer: https://medihub.com.br/upload.bak
[Tue Aug 18 13:00:03.610333 2026] [security2:error] [pid 123784:tid 124017] [client 20.226.56.190:20904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gk.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuLQAAAGM"]
[Tue Aug 18 13:00:03.645044 2026] [security2:error] [pid 123784:tid 123946] [client 20.127.136.245:28502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/archive.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuLgAAABw"]
[Tue Aug 18 13:00:03.654593 2026] [security2:error] [pid 123784:tid 123957] [client 20.116.17.175:60435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/f35.update.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuMAAAACc"]
[Tue Aug 18 13:00:03.657560 2026] [security2:error] [pid 123784:tid 123995] [client 20.226.56.190:15175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wn.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuMQAAAE0"]
[Tue Aug 18 13:00:03.663437 2026] [security2:error] [pid 123784:tid 124041] [client 172.202.39.151:60155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/alfa.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuMwAAAHs"]
[Tue Aug 18 13:00:03.675178 2026] [security2:error] [pid 123784:tid 123974] [client 40.74.65.169:20388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/zoo2.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuOAAAADg"]
[Tue Aug 18 13:00:03.677799 2026] [security2:error] [pid 123784:tid 123997] [client 158.23.17.4:38900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/hr.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuOQAAAE8"]
[Tue Aug 18 13:00:03.693597 2026] [security2:error] [pid 123784:tid 123991] [client 158.23.17.4:60289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ie.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuOwAAAEk"]
[Tue Aug 18 13:00:03.714372 2026] [security2:error] [pid 123784:tid 123805] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/i.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuPQAAIxA"]
[Tue Aug 18 13:00:03.721419 2026] [security2:error] [pid 123784:tid 124023] [client 158.23.17.4:20448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/jl.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuPgAAAGk"]
[Tue Aug 18 13:00:03.780863 2026] [security2:error] [pid 123784:tid 123986] [client 168.62.48.100:18116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/rymmm.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuQQAAAEQ"]
[Tue Aug 18 13:00:03.782165 2026] [security2:error] [pid 123784:tid 123987] [client 20.226.56.190:20877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/app.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuQgAAAEU"]
[Tue Aug 18 13:00:03.819481 2026] [security2:error] [pid 123784:tid 124002] [client 20.226.56.190:10586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/87.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuRQAAAFQ"]
[Tue Aug 18 13:00:03.829271 2026] [authz_core:error] [pid 123784:tid 123848] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:03.829707 2026] [authz_core:error] [pid 123784:tid 123848] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:03.857475 2026] [security2:error] [pid 123784:tid 123925] [client 136.66.149.90:39136] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.env.save"] [unique_id "aoSBg2wDnJBNj2tDbYbuSAAAAAc"]
[Tue Aug 18 13:00:03.859201 2026] [security2:error] [pid 123784:tid 123969] [client 136.66.149.90:39034] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/core/.env"] [unique_id "aoSBg2wDnJBNj2tDbYbuVAAAADM"]
[Tue Aug 18 13:00:03.860253 2026] [security2:error] [pid 123784:tid 123967] [client 136.66.149.90:38930] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.env.backup"] [unique_id "aoSBg2wDnJBNj2tDbYbuVgAAADE"]
[Tue Aug 18 13:00:03.861064 2026] [security2:error] [pid 123784:tid 123972] [client 136.66.149.90:39134] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/back/.env"] [unique_id "aoSBg2wDnJBNj2tDbYbuVwAAADY"]
[Tue Aug 18 13:00:03.886240 2026] [core:error] [pid 123784:tid 123792] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 13:00:03.886260 2026] [core:error] [pid 123784:tid 123792] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 13:00:03.890960 2026] [security2:error] [pid 123784:tid 123836] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/geck.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuYQAAGC8"]
[Tue Aug 18 13:00:03.935285 2026] [security2:error] [pid 123784:tid 124019] [client 135.225.78.186:24071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/ops.php"] [unique_id "aoSBg2wDnJBNj2tDbYbubAAAAGU"]
[Tue Aug 18 13:00:03.943349 2026] [security2:error] [pid 123784:tid 123946] [client 20.116.17.175:59978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/bdroot.php"] [unique_id "aoSBg2wDnJBNj2tDbYbubQAAABw"]
[Tue Aug 18 13:00:03.948240 2026] [security2:error] [pid 123784:tid 123957] [client 136.66.149.90:38982] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/root/.aws/credentials"] [unique_id "aoSBg2wDnJBNj2tDbYbubgAAACc"]
[Tue Aug 18 13:00:03.955627 2026] [security2:error] [pid 123784:tid 123976] [client 132.196.30.78:25156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/sagax1.php"] [unique_id "aoSBg2wDnJBNj2tDbYbucQAAADo"]
[Tue Aug 18 13:00:03.987797 2026] [security2:error] [pid 123784:tid 123934] [client 136.66.149.90:38946] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/home/node/.aws/credentials"] [unique_id "aoSBg2wDnJBNj2tDbYbudAAAABA"]
[Tue Aug 18 13:00:04.011795 2026] [security2:error] [pid 123784:tid 123977] [client 20.250.27.191:63203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/k.php"] [unique_id "aoSBhGwDnJBNj2tDbYbudQAAADs"]
[Tue Aug 18 13:00:04.037987 2026] [security2:error] [pid 123784:tid 123958] [client 168.62.48.100:18057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/lddxs.php"] [unique_id "aoSBhGwDnJBNj2tDbYbudgAAACg"]
[Tue Aug 18 13:00:04.053266 2026] [security2:error] [pid 123784:tid 123871] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSBhGwDnJBNj2tDbYbueQAACVI"]
[Tue Aug 18 13:00:04.057715 2026] [security2:error] [pid 123784:tid 123943] [client 190.92.174.183:47194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhGwDnJBNj2tDbYbuewAAABk"]
[Tue Aug 18 13:00:04.057880 2026] [security2:error] [pid 123784:tid 123943] [client 190.92.174.183:47194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhGwDnJBNj2tDbYbuewAAABk"]
[Tue Aug 18 13:00:04.076738 2026] [security2:error] [pid 123784:tid 124008] [client 20.79.204.6:14029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSBhGwDnJBNj2tDbYbufgAAAFo"]
[Tue Aug 18 13:00:04.118581 2026] [security2:error] [pid 123784:tid 123989] [client 136.66.149.90:39256] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/app/.aws/credentials"] [unique_id "aoSBhGwDnJBNj2tDbYbulAAAAEc"]
[Tue Aug 18 13:00:04.120499 2026] [security2:error] [pid 123784:tid 124043] [client 20.226.56.190:7319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/zi.php"] [unique_id "aoSBhGwDnJBNj2tDbYbulQAAAH0"]
[Tue Aug 18 13:00:04.124282 2026] [security2:error] [pid 123784:tid 123981] [client 20.203.138.185:52694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/moon.php"] [unique_id "aoSBhGwDnJBNj2tDbYbulgAAAD8"]
[Tue Aug 18 13:00:04.130823 2026] [security2:error] [pid 123784:tid 123998] [client 136.66.149.90:39208] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhGwDnJBNj2tDbYbumAAAAFA"]
[Tue Aug 18 13:00:04.147467 2026] [security2:error] [pid 123784:tid 123959] [client 136.66.149.90:39192] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/1/environ"] [unique_id "aoSBhGwDnJBNj2tDbYbumwAAACk"]
[Tue Aug 18 13:00:04.162127 2026] [security2:error] [pid 123784:tid 123979] [client 158.23.17.4:7203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/tq.php"] [unique_id "aoSBhGwDnJBNj2tDbYbunQAAAD0"]
[Tue Aug 18 13:00:04.187239 2026] [security2:error] [pid 123784:tid 124031] [client 158.23.17.4:47924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/nw.php"] [unique_id "aoSBhGwDnJBNj2tDbYbuoQAAAHE"]
[Tue Aug 18 13:00:04.202247 2026] [security2:error] [pid 123784:tid 123974] [client 20.127.136.245:28073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/bless.php"] [unique_id "aoSBhGwDnJBNj2tDbYbuowAAADg"]
[Tue Aug 18 13:00:04.204151 2026] [security2:error] [pid 123784:tid 123952] [client 197.184.64.235:41953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhGwDnJBNj2tDbYbupAAAACI"]
[Tue Aug 18 13:00:04.204325 2026] [security2:error] [pid 123784:tid 123952] [client 197.184.64.235:41953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhGwDnJBNj2tDbYbupAAAACI"]
[Tue Aug 18 13:00:04.208260 2026] [security2:error] [pid 123784:tid 123971] [client 158.158.74.177:3858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/server.php"] [unique_id "aoSBhGwDnJBNj2tDbYbupgAAADU"]
[Tue Aug 18 13:00:04.210425 2026] [core:error] [pid 123784:tid 124012] [client 136.66.149.90:39436] AH10244: invalid URI path (/assets../../../.env)
[Tue Aug 18 13:00:04.225324 2026] [security2:error] [pid 123784:tid 123840] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBhGwDnJBNj2tDbYburAAAWDM"]
[Tue Aug 18 13:00:04.225396 2026] [security2:error] [pid 123784:tid 124034] [client 20.226.56.190:21126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/92.php"] [unique_id "aoSBhGwDnJBNj2tDbYburQAAAHQ"]
[Tue Aug 18 13:00:04.226628 2026] [security2:error] [pid 123784:tid 123946] [client 20.65.98.162:56456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBhGwDnJBNj2tDbYburgAAABw"]
[Tue Aug 18 13:00:04.230514 2026] [security2:error] [pid 123784:tid 123942] [client 213.35.127.232:54629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBhGwDnJBNj2tDbYbusAAAABg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:04.241287 2026] [security2:error] [pid 123784:tid 124013] [client 136.66.149.90:39442] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.github/workflows/ci.yml"] [unique_id "aoSBhGwDnJBNj2tDbYbusgAAAF8"]
[Tue Aug 18 13:00:04.242372 2026] [security2:error] [pid 123784:tid 123929] [client 136.66.149.90:39460] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.github/.env"] [unique_id "aoSBhGwDnJBNj2tDbYbuswAAAAs"]
[Tue Aug 18 13:00:04.255424 2026] [security2:error] [pid 123784:tid 123960] [client 136.66.149.90:39298] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/fetch"] [unique_id "aoSBhGwDnJBNj2tDbYbuuAAAACo"]
[Tue Aug 18 13:00:04.258825 2026] [security2:error] [pid 123784:tid 123935] [client 20.116.17.175:59977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-temp.php"] [unique_id "aoSBhGwDnJBNj2tDbYbuvAAAABE"]
[Tue Aug 18 13:00:04.280676 2026] [security2:error] [pid 123784:tid 123866] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/biufile.php"] [unique_id "aoSBhGwDnJBNj2tDbYbuxgAAb00"]
[Tue Aug 18 13:00:04.286591 2026] [security2:error] [pid 123784:tid 123937] [client 168.62.48.100:18157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/zjggu.php"] [unique_id "aoSBhGwDnJBNj2tDbYbuxwAAABM"]
[Tue Aug 18 13:00:04.305879 2026] [security2:error] [pid 123784:tid 123993] [client 136.66.149.90:39490] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/debug/pprof/cmdline"] [unique_id "aoSBhGwDnJBNj2tDbYbuywAAAEs"]
[Tue Aug 18 13:00:04.348135 2026] [security2:error] [pid 123784:tid 124027] [client 20.226.56.190:20894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/jm.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu0gAAAG0"]
[Tue Aug 18 13:00:04.367449 2026] [security2:error] [pid 123784:tid 123989] [client 51.89.129.243:61280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "marcellomeneghel.com"] [uri "/robots.txt"] [unique_id "aoSBhGwDnJBNj2tDbYbu1QAAAEc"]
[Tue Aug 18 13:00:04.367603 2026] [security2:error] [pid 123784:tid 123989] [client 51.89.129.243:61280] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "marcellomeneghel.com"] [uri "/robots.txt"] [unique_id "aoSBhGwDnJBNj2tDbYbu1QAAAEc"]
[Tue Aug 18 13:00:04.376798 2026] [security2:error] [pid 123784:tid 124043] [client 40.74.65.169:42458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/org.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu1gAAAH0"]
[Tue Aug 18 13:00:04.393686 2026] [security2:error] [pid 123784:tid 123858] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu2AAAMUU"]
[Tue Aug 18 13:00:04.397694 2026] [security2:error] [pid 123784:tid 124030] [client 136.66.149.90:39262] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhGwDnJBNj2tDbYbu2QAAAHA"]
[Tue Aug 18 13:00:04.418954 2026] [security2:error] [pid 123784:tid 123952] [client 136.66.149.90:39014] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/read"] [unique_id "aoSBhGwDnJBNj2tDbYbu3AAAACI"]
[Tue Aug 18 13:00:04.424476 2026] [security2:error] [pid 123784:tid 124000] [client 20.250.27.191:43492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/w.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu3gAAAFI"]
[Tue Aug 18 13:00:04.433216 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:04.433713 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:04.463419 2026] [security2:error] [pid 123784:tid 124006] [client 68.155.156.252:21939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu4AAAAFg"]
[Tue Aug 18 13:00:04.536608 2026] [security2:error] [pid 123784:tid 123984] [client 136.66.149.90:39220] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/fetch"] [unique_id "aoSBhGwDnJBNj2tDbYbu5AAAAEI"]
[Tue Aug 18 13:00:04.542954 2026] [security2:error] [pid 123784:tid 123924] [client 168.62.48.100:18133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/dlvqo.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu5QAAAAY"]
[Tue Aug 18 13:00:04.554137 2026] [security2:error] [pid 123784:tid 123962] [client 20.116.17.175:59983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-css.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu5gAAACw"]
[Tue Aug 18 13:00:04.584273 2026] [security2:error] [pid 123784:tid 124002] [client 158.23.17.4:14054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/cv.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu6AAAAFQ"]
[Tue Aug 18 13:00:04.585267 2026] [security2:error] [pid 123784:tid 123988] [client 68.221.73.131:35851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/chosen.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu6QAAAEY"]
[Tue Aug 18 13:00:04.591994 2026] [security2:error] [pid 123784:tid 123945] [client 68.155.154.236:4036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu6gAAABs"]
[Tue Aug 18 13:00:04.603888 2026] [security2:error] [pid 123784:tid 124044] [client 158.23.17.4:57260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/tq.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu7AAAAH4"]
[Tue Aug 18 13:00:04.611487 2026] [security2:error] [pid 123784:tid 123881] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/NewFile.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu7QAAeVw"]
[Tue Aug 18 13:00:04.617154 2026] [security2:error] [pid 123784:tid 124043] [client 136.66.149.90:39114] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhGwDnJBNj2tDbYbu7gAAAH0"]
[Tue Aug 18 13:00:04.619628 2026] [security2:error] [pid 123784:tid 124016] [client 20.226.56.190:42493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wj.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu7wAAAGI"]
[Tue Aug 18 13:00:04.711222 2026] [security2:error] [pid 123784:tid 124013] [client 20.79.204.6:14099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-2019.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu8gAAAF8"]
[Tue Aug 18 13:00:04.726156 2026] [authz_core:error] [pid 123784:tid 123899] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:04.726448 2026] [authz_core:error] [pid 123784:tid 123899] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:04.734962 2026] [security2:error] [pid 123784:tid 124017] [client 132.196.30.78:25175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wpc.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu9QAAAGM"]
[Tue Aug 18 13:00:04.779540 2026] [security2:error] [pid 123784:tid 123798] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu9wAAFQk"]
[Tue Aug 18 13:00:04.781195 2026] [security2:error] [pid 123784:tid 124004] [client 168.62.48.100:18155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/pkmoj.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu-AAAAFY"]
[Tue Aug 18 13:00:04.789906 2026] [autoindex:error] [pid 123784:tid 124001] [client 4.232.94.69:42501] AH01276: Cannot serve directory /home2/vfunnelcrmcom/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:04.793215 2026] [security2:error] [pid 123784:tid 123869] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/dejavu.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu_AAARVA"]
[Tue Aug 18 13:00:04.796373 2026] [security2:error] [pid 123784:tid 124038] [client 20.127.136.245:28300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/sagax1.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu_gAAAHg"]
[Tue Aug 18 13:00:04.829236 2026] [security2:error] [pid 123784:tid 123984] [client 136.66.149.90:39232] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhGwDnJBNj2tDbYbvAAAAAEI"]
[Tue Aug 18 13:00:04.831592 2026] [security2:error] [pid 123784:tid 124003] [client 158.158.74.177:3366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSBhGwDnJBNj2tDbYbvAQAAAFU"]
[Tue Aug 18 13:00:04.833734 2026] [security2:error] [pid 123784:tid 123924] [client 20.250.27.191:63193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/fpwch.php"] [unique_id "aoSBhGwDnJBNj2tDbYbvAgAAAAY"]
[Tue Aug 18 13:00:04.835102 2026] [security2:error] [pid 123784:tid 124045] [client 20.116.17.175:60422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/flox.php"] [unique_id "aoSBhGwDnJBNj2tDbYbvAwAAAH8"]
[Tue Aug 18 13:00:04.948051 2026] [security2:error] [pid 123784:tid 123883] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSBhGwDnJBNj2tDbYbvCAAAfl4"]
[Tue Aug 18 13:00:04.959155 2026] [security2:error] [pid 123784:tid 123812] [remote 3.109.96.140:33626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.96.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mempel.com.br"] [uri "/wp-login.php"] [unique_id "aoSBhGwDnJBNj2tDbYbvCQAACBc"]
[Tue Aug 18 13:00:04.996667 2026] [security2:error] [pid 123784:tid 124024] [client 4.232.94.69:42501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBhGwDnJBNj2tDbYbvCwAAAGo"]
[Tue Aug 18 13:00:05.019189 2026] [security2:error] [pid 123784:tid 124021] [client 136.66.149.90:39506] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhWwDnJBNj2tDbYbvDQAAAGc"]
[Tue Aug 18 13:00:05.025061 2026] [security2:error] [pid 123784:tid 123959] [client 168.62.48.100:18153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/kopyw.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvEAAAACk"]
[Tue Aug 18 13:00:05.030058 2026] [authz_core:error] [pid 123784:tid 123813] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:05.030396 2026] [authz_core:error] [pid 123784:tid 123813] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:05.033094 2026] [security2:error] [pid 123784:tid 123967] [client 20.226.56.190:42435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/74.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvEQAAADE"]
[Tue Aug 18 13:00:05.056958 2026] [security2:error] [pid 123784:tid 123964] [client 20.203.138.185:45468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ms.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvFQAAAC4"]
[Tue Aug 18 13:00:05.060672 2026] [security2:error] [pid 123784:tid 124026] [client 40.74.65.169:43027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/imageskir.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvFgAAAGw"]
[Tue Aug 18 13:00:05.116445 2026] [security2:error] [pid 123784:tid 123999] [client 20.116.17.175:60020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/op.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvFwAAAFE"]
[Tue Aug 18 13:00:05.131437 2026] [security2:error] [pid 123784:tid 124035] [client 20.226.56.190:15189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/av.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvGQAAAHU"]
[Tue Aug 18 13:00:05.159856 2026] [security2:error] [pid 123784:tid 123905] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/themes.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvHQAAY3Q"]
[Tue Aug 18 13:00:05.160403 2026] [security2:error] [pid 123784:tid 123938] [client 20.250.13.23:47428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/abcd.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvHgAAABQ"]
[Tue Aug 18 13:00:05.176347 2026] [security2:error] [pid 123784:tid 124023] [client 172.202.39.151:4691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/new.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvIAAAAGk"]
[Tue Aug 18 13:00:05.190256 2026] [security2:error] [pid 123784:tid 123958] [client 136.66.149.90:39508] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhWwDnJBNj2tDbYbvIgAAACg"]
[Tue Aug 18 13:00:05.247566 2026] [security2:error] [pid 123784:tid 123980] [client 213.35.127.232:54845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvJgAAAD4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:05.248626 2026] [security2:error] [pid 123784:tid 123940] [client 20.250.27.191:40153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/FWAZ.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvJwAAABY"]
[Tue Aug 18 13:00:05.252117 2026] [security2:error] [pid 123784:tid 124038] [client 158.23.17.4:10966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/kt.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvKAAAAHg"]
[Tue Aug 18 13:00:05.285077 2026] [security2:error] [pid 123784:tid 124003] [client 158.23.17.4:20467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/un.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvKQAAAFU"]
[Tue Aug 18 13:00:05.287206 2026] [security2:error] [pid 123784:tid 123924] [client 20.226.56.190:20875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ag.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvKgAAAAY"]
[Tue Aug 18 13:00:05.294136 2026] [security2:error] [pid 123784:tid 123932] [client 20.127.136.245:28289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wpc.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvKwAAAA4"]
[Tue Aug 18 13:00:05.297159 2026] [security2:error] [pid 123784:tid 123948] [client 168.62.48.100:18121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/zznmg.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvLAAAAB4"]
[Tue Aug 18 13:00:05.308246 2026] [security2:error] [pid 123784:tid 123807] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/aaf.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvLgAAcBI"]
[Tue Aug 18 13:00:05.322713 2026] [security2:error] [pid 123784:tid 123925] [client 20.79.204.6:14122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/cjfuns.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvMAAAAAc"]
[Tue Aug 18 13:00:05.361802 2026] [security2:error] [pid 123784:tid 123945] [client 136.66.149.90:39100] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhWwDnJBNj2tDbYbvNgAAABs"]
[Tue Aug 18 13:00:05.379198 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:1050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/cv.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvOAAAAH0"]
[Tue Aug 18 13:00:05.379623 2026] [security2:error] [pid 123784:tid 123897] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/cv.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvOQAAfmw"]
[Tue Aug 18 13:00:05.451767 2026] [security2:error] [pid 123784:tid 124004] [client 132.196.30.78:25208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/fone1.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvPgAAAFY"]
[Tue Aug 18 13:00:05.465103 2026] [security2:error] [pid 123784:tid 123959] [client 20.116.17.175:60416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/1xmomo.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvPwAAACk"]
[Tue Aug 18 13:00:05.466238 2026] [security2:error] [pid 123784:tid 123937] [client 158.158.74.177:3862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/shell.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvQAAAABM"]
[Tue Aug 18 13:00:05.533087 2026] [security2:error] [pid 123784:tid 123952] [client 136.66.149.90:39052] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhWwDnJBNj2tDbYbvSgAAACI"]
[Tue Aug 18 13:00:05.541063 2026] [security2:error] [pid 123784:tid 123999] [client 168.62.48.100:18171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/bhfnd.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvTAAAAFE"]
[Tue Aug 18 13:00:05.579193 2026] [security2:error] [pid 123784:tid 124034] [client 20.226.56.190:20870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ig.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvUAAAAHQ"]
[Tue Aug 18 13:00:05.581209 2026] [core:error] [pid 123784:tid 123870] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 13:00:05.581232 2026] [core:error] [pid 123784:tid 123870] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 13:00:05.583356 2026] [security2:error] [pid 123784:tid 123923] [client 20.65.98.162:56478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/img.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvUQAAAAU"]
[Tue Aug 18 13:00:05.656405 2026] [security2:error] [pid 123784:tid 123958] [client 20.250.27.191:45781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/blurbs.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvVAAAACg"]
[Tue Aug 18 13:00:05.658576 2026] [security2:error] [pid 123784:tid 123842] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/h02ugyh.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvVQAAPjU"]
[Tue Aug 18 13:00:05.672230 2026] [security2:error] [pid 123784:tid 123992] [client 158.23.17.4:51138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/sb.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvVgAAAEo"]
[Tue Aug 18 13:00:05.701924 2026] [security2:error] [pid 123784:tid 123924] [client 20.226.56.190:40166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ta.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvWwAAAAY"]
[Tue Aug 18 13:00:05.704204 2026] [security2:error] [pid 123784:tid 123933] [client 136.66.149.90:39480] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhWwDnJBNj2tDbYbvXAAAAA8"]
[Tue Aug 18 13:00:05.729837 2026] [security2:error] [pid 123784:tid 124033] [client 20.226.56.190:6397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/34.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvXwAAAHM"]
[Tue Aug 18 13:00:05.741248 2026] [security2:error] [pid 123784:tid 123942] [client 20.116.17.175:60455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/txets.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvYgAAABg"]
[Tue Aug 18 13:00:05.744778 2026] [security2:error] [pid 123784:tid 123954] [client 136.66.149.90:39386] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/api/preview"] [unique_id "aoSBhWwDnJBNj2tDbYbvYwAAACQ"]
[Tue Aug 18 13:00:05.744824 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:05.745015 2026] [authz_core:error] [pid 123784:tid 123901] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:05.745121 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:05.745316 2026] [authz_core:error] [pid 123784:tid 123901] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:05.749143 2026] [security2:error] [pid 123784:tid 124010] [client 172.202.39.151:60132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/lock360.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvZAAAAFw"]
[Tue Aug 18 13:00:05.758333 2026] [security2:error] [pid 123784:tid 123974] [client 20.203.138.185:49918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wsws.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvZQAAADg"]
[Tue Aug 18 13:00:05.761453 2026] [security2:error] [pid 123784:tid 123990] [client 20.127.136.245:28301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/fone1.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvZgAAAEg"]
[Tue Aug 18 13:00:05.761996 2026] [security2:error] [pid 123784:tid 123918] [client 40.74.65.169:43052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/indexo.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvZwAAAAA"]
[Tue Aug 18 13:00:05.772138 2026] [security2:error] [pid 123784:tid 123998] [client 102.213.179.104:61968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvaQAAAFA"]
[Tue Aug 18 13:00:05.772295 2026] [security2:error] [pid 123784:tid 123998] [client 102.213.179.104:61968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvaQAAAFA"]
[Tue Aug 18 13:00:05.779259 2026] [security2:error] [pid 123784:tid 123982] [client 168.62.48.100:18163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/qfvqu.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvawAAAEA"]
[Tue Aug 18 13:00:05.792412 2026] [security2:error] [pid 123784:tid 123829] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvbgAAfig"]
[Tue Aug 18 13:00:05.793374 2026] [security2:error] [pid 123784:tid 124043] [client 68.155.154.236:25397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvbwAAAH0"]
[Tue Aug 18 13:00:05.822309 2026] [security2:error] [pid 123784:tid 123922] [client 86.120.159.145:64930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvcQAAAAQ"]
[Tue Aug 18 13:00:05.822667 2026] [security2:error] [pid 123784:tid 123922] [client 86.120.159.145:64930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvcQAAAAQ"]
[Tue Aug 18 13:00:05.875465 2026] [security2:error] [pid 123784:tid 124042] [client 136.66.149.90:39284] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhWwDnJBNj2tDbYbvdQAAAHw"]
[Tue Aug 18 13:00:05.897626 2026] [security2:error] [pid 123784:tid 123984] [client 190.92.174.183:50468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "aoSBhWwDnJBNj2tDbYbveQAAAEI"]
[Tue Aug 18 13:00:05.897717 2026] [security2:error] [pid 123784:tid 123984] [client 190.92.174.183:50468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "aoSBhWwDnJBNj2tDbYbveQAAAEI"]
[Tue Aug 18 13:00:05.910334 2026] [security2:error] [pid 123784:tid 123953] [client 136.66.149.90:39768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/fetch"] [unique_id "aoSBhWwDnJBNj2tDbYbvegAAACM"]
[Tue Aug 18 13:00:05.916273 2026] [security2:error] [pid 123784:tid 123964] [client 136.66.149.90:38912] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/proxy"] [unique_id "aoSBhWwDnJBNj2tDbYbvewAAAC4"]
[Tue Aug 18 13:00:05.927146 2026] [security2:error] [pid 123784:tid 123985] [client 158.23.17.4:40447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/evil.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvfgAAAEM"]
[Tue Aug 18 13:00:05.931811 2026] [authz_core:error] [pid 123784:tid 123864] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:05.932247 2026] [authz_core:error] [pid 123784:tid 123864] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:05.948859 2026] [security2:error] [pid 123784:tid 124026] [client 136.66.149.90:39420] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/fetch"] [unique_id "aoSBhWwDnJBNj2tDbYbvgAAAAGw"]
[Tue Aug 18 13:00:05.958336 2026] [security2:error] [pid 123784:tid 124030] [client 20.79.204.6:14132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvggAAAHA"]
[Tue Aug 18 13:00:05.976139 2026] [security2:error] [pid 123784:tid 124034] [client 54.39.136.154:26394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "marcellomeneghel.com"] [uri "/"] [unique_id "aoSBhWwDnJBNj2tDbYbvhQAAAHQ"]
[Tue Aug 18 13:00:05.976258 2026] [security2:error] [pid 123784:tid 124034] [client 54.39.136.154:26394] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "marcellomeneghel.com"] [uri "/"] [unique_id "aoSBhWwDnJBNj2tDbYbvhQAAAHQ"]
[Tue Aug 18 13:00:05.981448 2026] [security2:error] [pid 123784:tid 123945] [client 132.196.30.78:25206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/ncx.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvhgAAABs"]
[Tue Aug 18 13:00:05.992612 2026] [security2:error] [pid 123784:tid 123790] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/ws83.php"] [unique_id "aoSBhWwDnJBNj2tDbYbviAAAdQE"]
[Tue Aug 18 13:00:06.000160 2026] [security2:error] [pid 123784:tid 123920] [client 158.23.17.4:32555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/un.php"] [unique_id "aoSBhWwDnJBNj2tDbYbviQAAAAI"]
[Tue Aug 18 13:00:06.022577 2026] [security2:error] [pid 123784:tid 123995] [client 168.62.48.100:18126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/oivcl.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvigAAAE0"]
[Tue Aug 18 13:00:06.023159 2026] [security2:error] [pid 123784:tid 124023] [client 20.116.17.175:60417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/img.php"] [unique_id "aoSBhmwDnJBNj2tDbYbviwAAAGk"]
[Tue Aug 18 13:00:06.039706 2026] [security2:error] [pid 123784:tid 123915] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/155.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvjAAAZn4"]
[Tue Aug 18 13:00:06.047082 2026] [security2:error] [pid 123784:tid 123977] [client 136.66.149.90:39076] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhmwDnJBNj2tDbYbvjQAAADs"]
[Tue Aug 18 13:00:06.070583 2026] [security2:error] [pid 123784:tid 123992] [client 20.226.56.190:15179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/he.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvjwAAAEo"]
[Tue Aug 18 13:00:06.071976 2026] [security2:error] [pid 123784:tid 123924] [client 136.66.149.90:39520] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/fetch"] [unique_id "aoSBhmwDnJBNj2tDbYbvkAAAAAY"]
[Tue Aug 18 13:00:06.074067 2026] [security2:error] [pid 123784:tid 124045] [client 68.155.156.252:54276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvkQAAAH8"]
[Tue Aug 18 13:00:06.083950 2026] [security2:error] [pid 123784:tid 124000] [client 136.66.149.90:39376] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/fetch"] [unique_id "aoSBhmwDnJBNj2tDbYbvlAAAAFI"]
[Tue Aug 18 13:00:06.087576 2026] [security2:error] [pid 123784:tid 123933] [client 136.66.149.90:39382] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/proxy"] [unique_id "aoSBhmwDnJBNj2tDbYbvlQAAAA8"]
[Tue Aug 18 13:00:06.087936 2026] [security2:error] [pid 123784:tid 124033] [client 20.250.27.191:34821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/100.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvlgAAAHM"]
[Tue Aug 18 13:00:06.089780 2026] [security2:error] [pid 123784:tid 124004] [client 158.158.74.177:3886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/sim.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvlwAAAFY"]
[Tue Aug 18 13:00:06.154170 2026] [security2:error] [pid 123784:tid 123846] [remote 129.121.123.168:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.123.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fabispinazolapilates.com.br"] [uri "/wp-login.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvmgAAfjk"]
[Tue Aug 18 13:00:06.159604 2026] [security2:error] [pid 123784:tid 123802] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/atex1.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvmwAATw0"]
[Tue Aug 18 13:00:06.214536 2026] [security2:error] [pid 123784:tid 123937] [client 20.65.98.162:45578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/aa.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvngAAABM"]
[Tue Aug 18 13:00:06.218313 2026] [security2:error] [pid 123784:tid 124002] [client 136.66.149.90:39346] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhmwDnJBNj2tDbYbvnwAAAFQ"]
[Tue Aug 18 13:00:06.259037 2026] [security2:error] [pid 123784:tid 124026] [client 136.66.149.90:39468] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/proxy"] [unique_id "aoSBhmwDnJBNj2tDbYbvogAAAGw"]
[Tue Aug 18 13:00:06.261375 2026] [security2:error] [pid 123784:tid 123999] [client 213.35.127.232:55064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvowAAAFE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:06.277137 2026] [security2:error] [pid 123784:tid 124034] [client 172.202.39.151:4448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/222.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvpAAAAHQ"]
[Tue Aug 18 13:00:06.299433 2026] [security2:error] [pid 123784:tid 123960] [client 20.116.17.175:59991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvpQAAACo"]
[Tue Aug 18 13:00:06.328287 2026] [security2:error] [pid 123784:tid 123859] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvpwAAGUY"]
[Tue Aug 18 13:00:06.332166 2026] [security2:error] [pid 123784:tid 123919] [client 20.127.136.245:28538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/ncx.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvqAAAAAE"]
[Tue Aug 18 13:00:06.339656 2026] [security2:error] [pid 123784:tid 124040] [client 168.62.48.100:18049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/zugvi.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvqgAAAHo"]
[Tue Aug 18 13:00:06.340559 2026] [security2:error] [pid 123784:tid 124009] [client 158.23.17.4:56568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/pw.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvqwAAAFs"]
[Tue Aug 18 13:00:06.344863 2026] [security2:error] [pid 123784:tid 123927] [client 192.141.172.134:56509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvrAAAAAk"]
[Tue Aug 18 13:00:06.345022 2026] [security2:error] [pid 123784:tid 123927] [client 192.141.172.134:56509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvrAAAAAk"]
[Tue Aug 18 13:00:06.408529 2026] [security2:error] [pid 123784:tid 124041] [client 136.66.149.90:39410] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhmwDnJBNj2tDbYbvrwAAAHs"]
[Tue Aug 18 13:00:06.430070 2026] [security2:error] [pid 123784:tid 123923] [client 135.225.78.186:58886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/coffexium.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvsgAAAAU"]
[Tue Aug 18 13:00:06.444519 2026] [security2:error] [pid 123784:tid 124006] [client 136.66.149.90:39218] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/proxy"] [unique_id "aoSBhmwDnJBNj2tDbYbvswAAAFg"]
[Tue Aug 18 13:00:06.464386 2026] [security2:error] [pid 123784:tid 123954] [client 40.74.65.169:20389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvtQAAACQ"]
[Tue Aug 18 13:00:06.498469 2026] [security2:error] [pid 123784:tid 123806] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/w.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvugAAABE"]
[Tue Aug 18 13:00:06.503314 2026] [security2:error] [pid 123784:tid 124025] [client 20.250.27.191:63194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/ccc.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvuwAAAGs"]
[Tue Aug 18 13:00:06.523424 2026] [security2:error] [pid 123784:tid 124038] [client 20.250.13.23:38288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-good.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvvQAAAHg"]
[Tue Aug 18 13:00:06.526355 2026] [security2:error] [pid 123784:tid 124036] [client 168.62.48.100:5623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/ucpfr.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvvgAAAHY"]
[Tue Aug 18 13:00:06.557705 2026] [security2:error] [pid 123784:tid 123836] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/ops.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvvwAAfi8"]
[Tue Aug 18 13:00:06.560337 2026] [security2:error] [pid 123784:tid 123958] [client 20.79.204.6:14130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvwAAAACg"]
[Tue Aug 18 13:00:06.570391 2026] [security2:error] [pid 123784:tid 123930] [client 20.226.56.190:8280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gz.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvwgAAAAw"]
[Tue Aug 18 13:00:06.589663 2026] [security2:error] [pid 123784:tid 124024] [client 168.62.48.100:18114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wsrer.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvxAAAAGo"]
[Tue Aug 18 13:00:06.602400 2026] [security2:error] [pid 123784:tid 124039] [client 20.116.17.175:60002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvxQAAAHk"]
[Tue Aug 18 13:00:06.666049 2026] [security2:error] [pid 123784:tid 123825] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/archive.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvyAAAbiQ"]
[Tue Aug 18 13:00:06.681254 2026] [security2:error] [pid 123784:tid 123928] [client 158.23.17.4:14025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/fn.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvygAAAAo"]
[Tue Aug 18 13:00:06.683593 2026] [security2:error] [pid 123784:tid 123968] [client 20.203.138.185:42494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/motu.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvywAAADI"]
[Tue Aug 18 13:00:06.687362 2026] [security2:error] [pid 123784:tid 124014] [client 132.196.30.78:22168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvzAAAAGA"]
[Tue Aug 18 13:00:06.712899 2026] [security2:error] [pid 123784:tid 124029] [client 158.23.17.4:44806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/evil.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvzgAAAG8"]
[Tue Aug 18 13:00:06.728006 2026] [security2:error] [pid 123784:tid 123959] [client 172.202.39.151:4729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/chosen.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvzwAAACk"]
[Tue Aug 18 13:00:06.728992 2026] [security2:error] [pid 123784:tid 124022] [client 68.221.73.131:32034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/thoms.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv0AAAAGg"]
[Tue Aug 18 13:00:06.735612 2026] [security2:error] [pid 123784:tid 123941] [client 158.158.74.177:16133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/simple.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv0QAAABc"]
[Tue Aug 18 13:00:06.791196 2026] [security2:error] [pid 123784:tid 123946] [client 20.226.56.190:10588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/nf.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv1wAAABw"]
[Tue Aug 18 13:00:06.829693 2026] [authz_core:error] [pid 123784:tid 123789] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:06.829994 2026] [authz_core:error] [pid 123784:tid 123789] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:06.831909 2026] [security2:error] [pid 123784:tid 124032] [client 168.62.48.100:18053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/ucpfr.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv2wAAAHI"]
[Tue Aug 18 13:00:06.854205 2026] [security2:error] [pid 123784:tid 123925] [client 190.92.174.183:50484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv3AAAAAc"]
[Tue Aug 18 13:00:06.854316 2026] [security2:error] [pid 123784:tid 123925] [client 190.92.174.183:50484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv3AAAAAc"]
[Tue Aug 18 13:00:06.861640 2026] [security2:error] [pid 123784:tid 123876] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/bless.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv3QAATVc"]
[Tue Aug 18 13:00:06.882702 2026] [security2:error] [pid 123784:tid 124023] [client 20.116.17.175:60424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv3gAAAGk"]
[Tue Aug 18 13:00:06.914087 2026] [security2:error] [pid 123784:tid 124020] [client 20.250.27.191:63177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/get.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv4AAAAGY"]
[Tue Aug 18 13:00:06.985107 2026] [security2:error] [pid 123784:tid 123966] [client 136.66.149.90:39826] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhmwDnJBNj2tDbYbv4wAAADA"]
[Tue Aug 18 13:00:06.985371 2026] [security2:error] [pid 123784:tid 124007] [client 20.127.136.245:28305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv5AAAAFk"]
[Tue Aug 18 13:00:07.012014 2026] [security2:error] [pid 123784:tid 123929] [client 68.155.154.236:25376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSBh2wDnJBNj2tDbYbv5QAAAAs"]
[Tue Aug 18 13:00:07.030753 2026] [security2:error] [pid 123784:tid 123871] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/sagax1.php"] [unique_id "aoSBh2wDnJBNj2tDbYbv5wAAElI"]
[Tue Aug 18 13:00:07.036141 2026] [security2:error] [pid 123784:tid 124027] [client 136.66.149.90:39842] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/proxy"] [unique_id "aoSBh2wDnJBNj2tDbYbv6AAAAG0"]
[Tue Aug 18 13:00:07.071268 2026] [security2:error] [pid 123784:tid 124000] [client 20.38.3.247:46776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/bajah.php"] [unique_id "aoSBh2wDnJBNj2tDbYbv6wAAAFI"]
[Tue Aug 18 13:00:07.084494 2026] [security2:error] [pid 123784:tid 124004] [client 168.62.48.100:18051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/yxijx.php"] [unique_id "aoSBh2wDnJBNj2tDbYbv7AAAAFY"]
[Tue Aug 18 13:00:07.108035 2026] [security2:error] [pid 123784:tid 123947] [client 20.226.56.190:42484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xv.php"] [unique_id "aoSBh2wDnJBNj2tDbYbv7gAAAB0"]
[Tue Aug 18 13:00:07.115886 2026] [security2:error] [pid 123784:tid 124008] [client 158.23.17.4:14057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/kf.php"] [unique_id "aoSBh2wDnJBNj2tDbYbv7wAAAFo"]
[Tue Aug 18 13:00:07.132936 2026] [security2:error] [pid 123784:tid 124036] [client 20.65.98.162:56465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/av.php"] [unique_id "aoSBh2wDnJBNj2tDbYbv8QAAAHY"]
[Tue Aug 18 13:00:07.135289 2026] [authz_core:error] [pid 123784:tid 123851] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:07.135755 2026] [authz_core:error] [pid 123784:tid 123851] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:07.162174 2026] [security2:error] [pid 123784:tid 123981] [client 40.74.65.169:20316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSBh2wDnJBNj2tDbYbv9gAAAD8"]
[Tue Aug 18 13:00:07.176519 2026] [security2:error] [pid 123784:tid 123953] [client 20.79.204.6:13708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/import.php"] [unique_id "aoSBh2wDnJBNj2tDbYbv_gAAACM"]
[Tue Aug 18 13:00:07.190212 2026] [security2:error] [pid 123784:tid 123968] [client 158.23.17.4:58705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/xj.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwAgAAADI"]
[Tue Aug 18 13:00:07.199388 2026] [security2:error] [pid 123784:tid 123908] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wpc.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwAwAAfHc"]
[Tue Aug 18 13:00:07.200695 2026] [security2:error] [pid 123784:tid 124014] [client 158.23.17.4:29502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ww.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwBAAAAGA"]
[Tue Aug 18 13:00:07.237736 2026] [security2:error] [pid 123784:tid 123992] [client 132.196.30.78:2783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wso.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwBwAAAEo"]
[Tue Aug 18 13:00:07.247275 2026] [security2:error] [pid 123784:tid 123998] [client 172.202.39.151:4683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/info.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwFAAAAFA"]
[Tue Aug 18 13:00:07.275404 2026] [security2:error] [pid 123784:tid 123959] [client 20.226.56.190:40153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/mx.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwHgAAACk"]
[Tue Aug 18 13:00:07.280967 2026] [security2:error] [pid 123784:tid 124040] [client 213.35.127.232:55291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwHwAAAHo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:07.287757 2026] [security2:error] [pid 123784:tid 123934] [client 20.116.17.175:60438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwIAAAABA"]
[Tue Aug 18 13:00:07.320182 2026] [security2:error] [pid 123784:tid 123973] [client 79.127.164.8:56702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/upload.sql"] [unique_id "aoSBh2wDnJBNj2tDbYbwIgAAADc"], referer: https://medihub.com.br/upload.sql
[Tue Aug 18 13:00:07.344888 2026] [security2:error] [pid 123784:tid 123964] [client 168.62.48.100:18149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/zwlsv.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwJAAAAC4"]
[Tue Aug 18 13:00:07.357647 2026] [security2:error] [pid 123784:tid 124043] [client 158.158.74.177:16177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/st.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwJQAAAH0"]
[Tue Aug 18 13:00:07.358524 2026] [security2:error] [pid 123784:tid 123926] [client 20.250.27.191:45767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/images.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwJgAAAAg"]
[Tue Aug 18 13:00:07.367207 2026] [security2:error] [pid 123784:tid 123794] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/fone1.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwJwAAOAU"]
[Tue Aug 18 13:00:07.395442 2026] [security2:error] [pid 123784:tid 123835] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/mac.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwLAAAWi4"]
[Tue Aug 18 13:00:07.421087 2026] [security2:error] [pid 123784:tid 124021] [client 20.127.136.245:28313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wso.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwLgAAAGc"]
[Tue Aug 18 13:00:07.517527 2026] [security2:error] [pid 123784:tid 123988] [client 20.226.56.190:6388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/45.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwOwAAAEY"]
[Tue Aug 18 13:00:07.517532 2026] [security2:error] [pid 123784:tid 123951] [client 136.66.149.90:11438] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/jenkins/config.xml.bak"] [unique_id "aoSBh2wDnJBNj2tDbYbwOgAAACE"]
[Tue Aug 18 13:00:07.519954 2026] [security2:error] [pid 123784:tid 123993] [client 136.66.149.90:11410] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/jenkins/credentials.xml"] [unique_id "aoSBh2wDnJBNj2tDbYbwQAAAAEs"]
[Tue Aug 18 13:00:07.526179 2026] [security2:error] [pid 123784:tid 123919] [client 136.66.149.90:11548] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/cloudbuild.yaml"] [unique_id "aoSBh2wDnJBNj2tDbYbwTAAAAAE"]
[Tue Aug 18 13:00:07.529888 2026] [security2:error] [pid 123784:tid 123976] [client 136.66.149.90:11650] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/jenkins/secrets/master.key"] [unique_id "aoSBh2wDnJBNj2tDbYbwVQAAADo"]
[Tue Aug 18 13:00:07.531745 2026] [security2:error] [pid 123784:tid 123936] [client 136.66.149.90:11738] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.env.local.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwWgAAABI"]
[Tue Aug 18 13:00:07.533080 2026] [security2:error] [pid 123784:tid 123960] [client 136.66.149.90:11516] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.travis.yml"] [unique_id "aoSBh2wDnJBNj2tDbYbwXwAAACo"]
[Tue Aug 18 13:00:07.533106 2026] [security2:error] [pid 123784:tid 124045] [client 136.66.149.90:11680] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.env.development.local"] [unique_id "aoSBh2wDnJBNj2tDbYbwYAAAAH8"]
[Tue Aug 18 13:00:07.538824 2026] [security2:error] [pid 123784:tid 123940] [client 136.66.149.90:11728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.149.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.env.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwWwAAABY"]
[Tue Aug 18 13:00:07.559334 2026] [security2:error] [pid 123784:tid 123928] [client 20.116.17.175:60449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/term.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwZAAAAAo"]
[Tue Aug 18 13:00:07.574540 2026] [security2:error] [pid 123784:tid 123883] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/ncx.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwZQAAYF4"]
[Tue Aug 18 13:00:07.584174 2026] [security2:error] [pid 123784:tid 123931] [client 20.203.138.185:45501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/fff.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwZwAAAA0"]
[Tue Aug 18 13:00:07.602055 2026] [security2:error] [pid 123784:tid 123998] [client 168.62.48.100:18135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/jrpga.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwcQAAAFA"]
[Tue Aug 18 13:00:07.656682 2026] [security2:error] [pid 123784:tid 124012] [client 158.23.17.4:60332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ns.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwdgAAAF4"]
[Tue Aug 18 13:00:07.692505 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:40397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/su.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwhgAAAH0"]
[Tue Aug 18 13:00:07.719806 2026] [security2:error] [pid 123784:tid 123942] [client 136.66.149.90:11530] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/%2eenv"] [unique_id "aoSBh2wDnJBNj2tDbYbwiQAAABg"]
[Tue Aug 18 13:00:07.736438 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:07.736896 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:07.747745 2026] [security2:error] [pid 123784:tid 123970] [client 136.66.149.90:11362] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/public/plugins/alertlist/../../../../../../../../.env"] [unique_id "aoSBh2wDnJBNj2tDbYbwjQAAADQ"]
[Tue Aug 18 13:00:07.773146 2026] [security2:error] [pid 123784:tid 123919] [client 136.66.149.90:11346] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "aoSBh2wDnJBNj2tDbYbwjwAAAAE"]
[Tue Aug 18 13:00:07.787514 2026] [security2:error] [pid 123784:tid 123976] [client 136.66.149.90:11394] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.netlify/.env"] [unique_id "aoSBh2wDnJBNj2tDbYbwkAAAADo"]
[Tue Aug 18 13:00:07.787869 2026] [security2:error] [pid 123784:tid 123921] [client 20.79.204.6:14033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/cropper.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwkQAAAAM"]
[Tue Aug 18 13:00:07.794848 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.56.190:17965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wy.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwkgAAAH8"]
[Tue Aug 18 13:00:07.799510 2026] [core:error] [pid 123784:tid 123960] [client 136.66.149.90:11426] AH10244: invalid URI path (/public/plugins/grafana-clock-panel/../../../../../../../../.env)
[Tue Aug 18 13:00:07.800638 2026] [security2:error] [pid 123784:tid 123790] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwlQAAHAE"]
[Tue Aug 18 13:00:07.807621 2026] [security2:error] [pid 123784:tid 124028] [client 190.92.174.183:50498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwlgAAAG4"]
[Tue Aug 18 13:00:07.807756 2026] [security2:error] [pid 123784:tid 124028] [client 190.92.174.183:50498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwlgAAAG4"]
[Tue Aug 18 13:00:07.813814 2026] [security2:error] [pid 123784:tid 123940] [client 136.66.149.90:11344] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.env.yml"] [unique_id "aoSBh2wDnJBNj2tDbYbwlwAAABY"]
[Tue Aug 18 13:00:07.828120 2026] [security2:error] [pid 123784:tid 123922] [client 136.66.149.90:11452] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.env"] [unique_id "aoSBh2wDnJBNj2tDbYbwmAAAAAQ"]
[Tue Aug 18 13:00:07.838663 2026] [security2:error] [pid 123784:tid 123928] [client 40.74.65.169:20159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/.admin.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwmQAAAAo"]
[Tue Aug 18 13:00:07.839890 2026] [security2:error] [pid 123784:tid 124044] [client 168.62.48.100:18160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwmgAAAH4"]
[Tue Aug 18 13:00:07.840062 2026] [security2:error] [pid 123784:tid 123971] [client 20.250.27.191:35662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/alls.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwmwAAADU"]
[Tue Aug 18 13:00:07.842055 2026] [security2:error] [pid 123784:tid 124034] [client 136.66.149.90:11356] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ"] [unique_id "aoSBh2wDnJBNj2tDbYbwnAAAAHQ"]
[Tue Aug 18 13:00:07.848818 2026] [security2:error] [pid 123784:tid 124014] [client 20.116.17.175:59998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/black.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwnQAAAGA"]
[Tue Aug 18 13:00:07.862787 2026] [security2:error] [pid 123784:tid 124030] [client 158.23.17.4:38887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/mo.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwoAAAAHA"]
[Tue Aug 18 13:00:07.875850 2026] [core:error] [pid 123784:tid 123937] [client 136.66.149.90:11444] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.env)
[Tue Aug 18 13:00:07.877091 2026] [security2:error] [pid 123784:tid 123944] [client 132.196.30.78:13395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/zup.php73"] [unique_id "aoSBh2wDnJBNj2tDbYbwogAAABo"]
[Tue Aug 18 13:00:07.879932 2026] [security2:error] [pid 123784:tid 123967] [client 20.226.56.190:20922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/f.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwowAAADE"]
[Tue Aug 18 13:00:07.880228 2026] [security2:error] [pid 123784:tid 123924] [client 20.127.136.245:27664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/zup.php73"] [unique_id "aoSBh2wDnJBNj2tDbYbwpAAAAAY"]
[Tue Aug 18 13:00:07.884992 2026] [security2:error] [pid 123784:tid 123992] [client 136.66.149.90:11462] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/..%252F..%252F..%252F..%252F..%252F.env"] [unique_id "aoSBh2wDnJBNj2tDbYbwpQAAAEo"]
[Tue Aug 18 13:00:07.941135 2026] [security2:error] [pid 123784:tid 123985] [client 136.66.149.90:11606] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/debug.log"] [unique_id "aoSBh2wDnJBNj2tDbYbwrwAAAEM"]
[Tue Aug 18 13:00:07.967339 2026] [security2:error] [pid 123784:tid 123888] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wso.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwswAALmM"]
[Tue Aug 18 13:00:07.993684 2026] [security2:error] [pid 123784:tid 124006] [client 136.66.149.90:11668] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/..%252F..%252F..%252F..%252F..%252Fproc/self/environ"] [unique_id "aoSBh2wDnJBNj2tDbYbwuQAAAFg"]
[Tue Aug 18 13:00:08.009519 2026] [authz_core:error] [pid 123784:tid 123903] [remote 57.141.22.114:28570] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:08.009804 2026] [authz_core:error] [pid 123784:tid 123903] [remote 57.141.22.114:28570] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:08.019610 2026] [security2:error] [pid 123784:tid 124021] [client 20.226.56.190:20908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/30.php"] [unique_id "aoSBiGwDnJBNj2tDbYbwvQAAAGc"]
[Tue Aug 18 13:00:08.034136 2026] [authz_core:error] [pid 123784:tid 123901] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:08.034416 2026] [authz_core:error] [pid 123784:tid 123901] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:08.034748 2026] [security2:error] [pid 123784:tid 123845] [remote 20.54.134.42:3671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.134.54.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maxhost.com.br"] [uri "/wp-login.php"] [unique_id "aoSBiGwDnJBNj2tDbYbwwAAAIzg"]
[Tue Aug 18 13:00:08.045949 2026] [security2:error] [pid 123784:tid 124013] [client 20.226.56.190:10603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/pu.php"] [unique_id "aoSBiGwDnJBNj2tDbYbwwwAAAF8"]
[Tue Aug 18 13:00:08.046856 2026] [security2:error] [pid 123784:tid 123968] [client 158.158.74.177:16174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/subdom/ant/makeasmtp.php"] [unique_id "aoSBiGwDnJBNj2tDbYbwxAAAADI"]
[Tue Aug 18 13:00:08.059893 2026] [security2:error] [pid 123784:tid 123948] [client 20.226.56.190:20879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ry.php"] [unique_id "aoSBiGwDnJBNj2tDbYbwxgAAAB4"]
[Tue Aug 18 13:00:08.073662 2026] [security2:error] [pid 123784:tid 124023] [client 168.62.48.100:18162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/nwwha.php"] [unique_id "aoSBiGwDnJBNj2tDbYbwywAAAGk"]
[Tue Aug 18 13:00:08.090960 2026] [security2:error] [pid 123784:tid 123943] [client 20.226.56.190:15210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/pm.php"] [unique_id "aoSBiGwDnJBNj2tDbYbwzgAAABk"]
[Tue Aug 18 13:00:08.137572 2026] [security2:error] [pid 123784:tid 124001] [client 20.116.17.175:58117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/as.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw0wAAAFM"]
[Tue Aug 18 13:00:08.179092 2026] [security2:error] [pid 123784:tid 124007] [client 20.226.56.190:7323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/dr.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw2AAAAFk"]
[Tue Aug 18 13:00:08.182788 2026] [security2:error] [pid 123784:tid 123800] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/zup.php73"] [unique_id "aoSBiGwDnJBNj2tDbYbw2QAAQgs"]
[Tue Aug 18 13:00:08.202001 2026] [security2:error] [pid 123784:tid 124030] [client 20.104.85.180:18858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw2wAAAHA"]
[Tue Aug 18 13:00:08.218556 2026] [security2:error] [pid 123784:tid 123939] [client 136.66.149.90:11374] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ"] [unique_id "aoSBiGwDnJBNj2tDbYbw3QAAABU"]
[Tue Aug 18 13:00:08.249449 2026] [security2:error] [pid 123784:tid 123959] [client 20.250.27.191:34828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/coffexium.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw5wAAACk"]
[Tue Aug 18 13:00:08.259113 2026] [security2:error] [pid 123784:tid 123980] [client 158.23.17.4:60774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/gk.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw6gAAAD4"]
[Tue Aug 18 13:00:08.274855 2026] [security2:error] [pid 123784:tid 123923] [client 136.66.149.90:11380] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/docker/.env"] [unique_id "aoSBiGwDnJBNj2tDbYbw6wAAAAU"]
[Tue Aug 18 13:00:08.294218 2026] [security2:error] [pid 123784:tid 124035] [client 213.35.127.232:55503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw7QAAAHU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:08.327387 2026] [security2:error] [pid 123784:tid 124000] [client 168.62.48.100:18139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/opsqt.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw8gAAAFI"]
[Tue Aug 18 13:00:08.329241 2026] [security2:error] [pid 123784:tid 123983] [client 20.226.56.190:7317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ts.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw9AAAAEE"]
[Tue Aug 18 13:00:08.337634 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:08.337989 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:08.342683 2026] [security2:error] [pid 123784:tid 123987] [client 20.226.56.190:6399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/53.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw9gAAAEU"]
[Tue Aug 18 13:00:08.347906 2026] [security2:error] [pid 123784:tid 124032] [client 20.65.98.162:55218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/media.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw-AAAAHI"]
[Tue Aug 18 13:00:08.350212 2026] [security2:error] [pid 123784:tid 123834] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/k.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw-QAANi0"]
[Tue Aug 18 13:00:08.352850 2026] [security2:error] [pid 123784:tid 124021] [client 136.66.149.90:11546] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/internal/.env.production"] [unique_id "aoSBiGwDnJBNj2tDbYbw-gAAAGc"]
[Tue Aug 18 13:00:08.365217 2026] [security2:error] [pid 123784:tid 124038] [client 136.66.149.90:11640] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/private/.env.production"] [unique_id "aoSBiGwDnJBNj2tDbYbw-wAAAHg"]
[Tue Aug 18 13:00:08.370220 2026] [security2:error] [pid 123784:tid 123933] [client 20.226.56.190:21128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/lq.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw_AAAAA8"]
[Tue Aug 18 13:00:08.413958 2026] [security2:error] [pid 123784:tid 123954] [client 20.226.56.190:17926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/you.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw_gAAACQ"]
[Tue Aug 18 13:00:08.415838 2026] [security2:error] [pid 123784:tid 124013] [client 20.116.17.175:60456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/pucci.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw_wAAAF8"]
[Tue Aug 18 13:00:08.420456 2026] [security2:error] [pid 123784:tid 124033] [client 158.23.17.4:20361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/wp-key.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxAAAAAHM"]
[Tue Aug 18 13:00:08.420717 2026] [security2:error] [pid 123784:tid 123948] [client 136.66.149.90:11696] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/app/.env.production"] [unique_id "aoSBiGwDnJBNj2tDbYbxAQAAAB4"]
[Tue Aug 18 13:00:08.426556 2026] [security2:error] [pid 123784:tid 123988] [client 20.226.56.190:7315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ez.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxAgAAAEY"]
[Tue Aug 18 13:00:08.439371 2026] [security2:error] [pid 123784:tid 124014] [client 20.79.204.6:14019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxBgAAAGA"]
[Tue Aug 18 13:00:08.441075 2026] [security2:error] [pid 123784:tid 124018] [client 20.127.136.245:28063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/k.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxBwAAAGQ"]
[Tue Aug 18 13:00:08.449617 2026] [security2:error] [pid 123784:tid 124019] [client 20.226.56.190:8276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/asus.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxCAAAAGU"]
[Tue Aug 18 13:00:08.457137 2026] [security2:error] [pid 123784:tid 123994] [client 74.7.241.181:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.bini.imb.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSBiGwDnJBNj2tDbYbxCQAATFY"]
[Tue Aug 18 13:00:08.488863 2026] [security2:error] [pid 123784:tid 124028] [client 68.155.156.252:12626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxEAAAAG4"]
[Tue Aug 18 13:00:08.491844 2026] [security2:error] [pid 123784:tid 124022] [client 136.66.149.90:11694] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/..%252F..%252F..%252F..%252F..%252Fproc/self/environ"] [unique_id "aoSBiGwDnJBNj2tDbYbxEQAAAGg"]
[Tue Aug 18 13:00:08.521577 2026] [security2:error] [pid 123784:tid 123941] [client 40.74.65.169:20132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wsomini.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxFAAAABc"]
[Tue Aug 18 13:00:08.531963 2026] [security2:error] [pid 123784:tid 123920] [client 20.104.85.180:18841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxFgAAAAI"]
[Tue Aug 18 13:00:08.563207 2026] [security2:error] [pid 123784:tid 123944] [client 20.226.56.190:40161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/22.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxGAAAABo"]
[Tue Aug 18 13:00:08.569431 2026] [security2:error] [pid 123784:tid 123932] [client 20.203.138.185:49900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/66.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxGwAAAA4"]
[Tue Aug 18 13:00:08.569966 2026] [security2:error] [pid 123784:tid 123902] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxHAAAUHE"]
[Tue Aug 18 13:00:08.577355 2026] [security2:error] [pid 123784:tid 124003] [client 136.66.149.90:11724] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/backup/.env"] [unique_id "aoSBiGwDnJBNj2tDbYbxHQAAAFU"]
[Tue Aug 18 13:00:08.611548 2026] [security2:error] [pid 123784:tid 124016] [client 168.62.48.100:18172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/jvcpa.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxIQAAAGI"]
[Tue Aug 18 13:00:08.620924 2026] [security2:error] [pid 123784:tid 123963] [client 132.196.30.78:2803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/k.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxIgAAAC0"]
[Tue Aug 18 13:00:08.651841 2026] [security2:error] [pid 123784:tid 123919] [client 136.66.149.90:11384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.149.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/sendgrid/.env.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxJQAAAAE"]
[Tue Aug 18 13:00:08.658571 2026] [security2:error] [pid 123784:tid 123961] [client 20.250.27.191:40186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/red.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxJgAAACs"]
[Tue Aug 18 13:00:08.665102 2026] [security2:error] [pid 123784:tid 123943] [client 158.158.74.177:16163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/system.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxJwAAABk"]
[Tue Aug 18 13:00:08.667425 2026] [security2:error] [pid 123784:tid 124043] [client 136.66.149.90:11482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.149.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/twilio/.env.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxKAAAAH0"]
[Tue Aug 18 13:00:08.669466 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.56.190:42476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/zs.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxKwAAAFI"]
[Tue Aug 18 13:00:08.685138 2026] [security2:error] [pid 123784:tid 124021] [client 136.66.149.90:11502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.149.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/app_dev.php/_profiler/.env"] [unique_id "aoSBiGwDnJBNj2tDbYbxMAAAAGc"]
[Tue Aug 18 13:00:08.691109 2026] [security2:error] [pid 123784:tid 123940] [client 136.66.149.90:11708] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ"] [unique_id "aoSBiGwDnJBNj2tDbYbxMQAAABY"]
[Tue Aug 18 13:00:08.707305 2026] [security2:error] [pid 123784:tid 124038] [client 136.66.149.90:11592] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.hermes/.env"] [unique_id "aoSBiGwDnJBNj2tDbYbxMgAAAHg"]
[Tue Aug 18 13:00:08.724309 2026] [security2:error] [pid 123784:tid 123953] [client 20.116.17.175:60427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wicked.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxNQAAACM"]
[Tue Aug 18 13:00:08.743353 2026] [core:error] [pid 123784:tid 123849] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 13:00:08.743378 2026] [core:error] [pid 123784:tid 123849] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 13:00:08.744260 2026] [security2:error] [pid 123784:tid 123971] [client 136.66.149.90:11562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.149.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/_profiler/phpinfo.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxOAAAADU"]
[Tue Aug 18 13:00:08.751678 2026] [security2:error] [pid 123784:tid 124013] [client 68.221.73.131:49696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/wpxml.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxOQAAAF8"]
[Tue Aug 18 13:00:08.756057 2026] [security2:error] [pid 123784:tid 123957] [client 136.66.149.90:11564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.149.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/config/.env.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxOwAAACc"]
[Tue Aug 18 13:00:08.775078 2026] [security2:error] [pid 123784:tid 124033] [client 136.66.149.90:11658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.149.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.env.php.bak"] [unique_id "aoSBiGwDnJBNj2tDbYbxPAAAAHM"]
[Tue Aug 18 13:00:08.795393 2026] [security2:error] [pid 123784:tid 124020] [client 136.66.149.90:11494] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.env.test"] [unique_id "aoSBiGwDnJBNj2tDbYbxPQAAAGY"]
[Tue Aug 18 13:00:08.796565 2026] [security2:error] [pid 123784:tid 123891] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/makeasmtp.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxPgAANGY"]
[Tue Aug 18 13:00:08.812670 2026] [security2:error] [pid 123784:tid 123936] [client 20.104.85.180:43568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxQAAAABI"]
[Tue Aug 18 13:00:08.812757 2026] [security2:error] [pid 123784:tid 123925] [client 136.66.149.90:11784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.149.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/phpinfo.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxQQAAAAc"]
[Tue Aug 18 13:00:08.828552 2026] [security2:error] [pid 123784:tid 124009] [client 103.184.169.37:42792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxRAAAAFs"]
[Tue Aug 18 13:00:08.828762 2026] [security2:error] [pid 123784:tid 124009] [client 103.184.169.37:42792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxRAAAAFs"]
[Tue Aug 18 13:00:08.903952 2026] [security2:error] [pid 123784:tid 124004] [client 168.62.48.100:18078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxSgAAAFY"]
[Tue Aug 18 13:00:08.910270 2026] [security2:error] [pid 123784:tid 123928] [client 158.23.17.4:63957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/qr.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxTAAAAAo"]
[Tue Aug 18 13:00:08.918235 2026] [core:error] [pid 123784:tid 123916] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 13:00:08.918272 2026] [core:error] [pid 123784:tid 123916] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 13:00:08.918697 2026] [security2:error] [pid 123784:tid 124034] [client 149.34.210.141:52006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxTgAAAHQ"]
[Tue Aug 18 13:00:08.922674 2026] [security2:error] [pid 123784:tid 123978] [client 190.92.174.183:50504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/news/xmlrpc.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxTwAAADw"]
[Tue Aug 18 13:00:08.922835 2026] [security2:error] [pid 123784:tid 123978] [client 190.92.174.183:50504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/news/xmlrpc.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxTwAAADw"]
[Tue Aug 18 13:00:08.967378 2026] [security2:error] [pid 123784:tid 123966] [client 68.155.154.236:27536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxUwAAADA"]
[Tue Aug 18 13:00:08.982713 2026] [security2:error] [pid 123784:tid 124010] [client 158.23.17.4:34171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/pw.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxVAAAAFw"]
[Tue Aug 18 13:00:08.990226 2026] [security2:error] [pid 123784:tid 123918] [client 20.127.136.245:28080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-blink.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxVgAAAAA"]
[Tue Aug 18 13:00:09.003545 2026] [security2:error] [pid 123784:tid 124016] [client 135.225.78.186:23161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/BDKR28WP.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxVwAAAGI"]
[Tue Aug 18 13:00:09.013496 2026] [security2:error] [pid 123784:tid 123963] [client 20.116.17.175:60423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/water.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxWQAAAC0"]
[Tue Aug 18 13:00:09.039617 2026] [security2:error] [pid 123784:tid 124023] [client 20.79.204.6:14048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxXAAAAGk"]
[Tue Aug 18 13:00:09.047193 2026] [security2:error] [pid 123784:tid 124039] [client 136.66.149.90:11580] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/aws/metadata/iam/security-credentials"] [unique_id "aoSBiWwDnJBNj2tDbYbxXgAAAHk"]
[Tue Aug 18 13:00:09.103001 2026] [security2:error] [pid 123784:tid 123967] [client 20.104.85.180:18867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/function/function.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxZwAAADE"]
[Tue Aug 18 13:00:09.128952 2026] [security2:error] [pid 123784:tid 124027] [client 136.66.149.90:11624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.149.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "aoSBiWwDnJBNj2tDbYbxagAAAG0"]
[Tue Aug 18 13:00:09.143265 2026] [security2:error] [pid 123784:tid 123982] [client 168.62.48.100:18170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxawAAAEA"]
[Tue Aug 18 13:00:09.147800 2026] [security2:error] [pid 123784:tid 123980] [client 158.23.17.4:15782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/gg.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxbAAAAD4"]
[Tue Aug 18 13:00:09.165973 2026] [core:error] [pid 123784:tid 123857] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 13:00:09.165995 2026] [core:error] [pid 123784:tid 123857] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 13:00:09.185029 2026] [security2:error] [pid 123784:tid 124034] [client 149.34.210.141:52006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxTgAAAHQ"]
[Tue Aug 18 13:00:09.210810 2026] [security2:error] [pid 123784:tid 124036] [client 138.36.100.162:41566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxcwAAAHY"]
[Tue Aug 18 13:00:09.210949 2026] [security2:error] [pid 123784:tid 124036] [client 138.36.100.162:41566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxcwAAAHY"]
[Tue Aug 18 13:00:09.218706 2026] [security2:error] [pid 123784:tid 123991] [client 136.66.149.90:11772] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/aws-credentials.json"] [unique_id "aoSBiWwDnJBNj2tDbYbxdAAAAEk"]
[Tue Aug 18 13:00:09.238832 2026] [security2:error] [pid 123784:tid 123948] [client 40.74.65.169:20376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/vr.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxdgAAAB4"]
[Tue Aug 18 13:00:09.243163 2026] [security2:error] [pid 123784:tid 123844] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxdwAARjc"]
[Tue Aug 18 13:00:09.244311 2026] [security2:error] [pid 123784:tid 123943] [client 132.196.30.78:2769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxeAAAABk"]
[Tue Aug 18 13:00:09.244559 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:09.245016 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:09.247521 2026] [security2:error] [pid 123784:tid 124020] [client 158.23.17.4:15123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/wn.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxeQAAAGY"]
[Tue Aug 18 13:00:09.247783 2026] [security2:error] [pid 123784:tid 123970] [client 136.66.149.90:11712] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/data/aws/credentials"] [unique_id "aoSBiWwDnJBNj2tDbYbxegAAADQ"]
[Tue Aug 18 13:00:09.270329 2026] [security2:error] [pid 123784:tid 124026] [client 136.66.149.90:11424] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/ecs/task-credentials"] [unique_id "aoSBiWwDnJBNj2tDbYbxfAAAAGw"]
[Tue Aug 18 13:00:09.291693 2026] [security2:error] [pid 123784:tid 123924] [client 20.65.98.162:55222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/images.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxgAAAAAY"]
[Tue Aug 18 13:00:09.310134 2026] [security2:error] [pid 123784:tid 123977] [client 213.35.127.232:55720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxhAAAADs"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:09.326727 2026] [security2:error] [pid 123784:tid 123962] [client 20.116.17.175:60433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/fine.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxhgAAACw"]
[Tue Aug 18 13:00:09.334040 2026] [security2:error] [pid 123784:tid 123797] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/ww5.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxhwAAVgg"]
[Tue Aug 18 13:00:09.358644 2026] [security2:error] [pid 123784:tid 124005] [client 20.226.56.190:8317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/iz.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxiQAAAFc"]
[Tue Aug 18 13:00:09.380428 2026] [security2:error] [pid 123784:tid 124032] [client 136.66.149.90:11750] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/html/.env"] [unique_id "aoSBiWwDnJBNj2tDbYbxiwAAAHI"]
[Tue Aug 18 13:00:09.388420 2026] [security2:error] [pid 123784:tid 123981] [client 158.158.74.177:3865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/system_log.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxjAAAAD8"]
[Tue Aug 18 13:00:09.420611 2026] [security2:error] [pid 123784:tid 123998] [client 20.104.85.180:43581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxjwAAAFA"]
[Tue Aug 18 13:00:09.422235 2026] [security2:error] [pid 123784:tid 124041] [client 157.20.138.62:58325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxkAAAAHs"]
[Tue Aug 18 13:00:09.422378 2026] [security2:error] [pid 123784:tid 124041] [client 157.20.138.62:58325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxkAAAAHs"]
[Tue Aug 18 13:00:09.442774 2026] [security2:error] [pid 123784:tid 124029] [client 168.62.48.100:18062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxkQAAAG8"]
[Tue Aug 18 13:00:09.473559 2026] [security2:error] [pid 123784:tid 124022] [client 136.66.149.90:11470] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/vendor/aws/credentials"] [unique_id "aoSBiWwDnJBNj2tDbYbxlQAAAGg"]
[Tue Aug 18 13:00:09.502253 2026] [security2:error] [pid 123784:tid 123895] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/2.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxmQAAamo"]
[Tue Aug 18 13:00:09.505710 2026] [security2:error] [pid 123784:tid 123985] [client 20.203.138.185:32195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/g.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxmgAAAEM"]
[Tue Aug 18 13:00:09.541227 2026] [authz_core:error] [pid 123784:tid 123835] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:09.541507 2026] [authz_core:error] [pid 123784:tid 123835] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:09.563742 2026] [security2:error] [pid 123784:tid 123929] [client 20.226.56.190:6385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/se.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxnwAAAAs"]
[Tue Aug 18 13:00:09.622938 2026] [security2:error] [pid 123784:tid 123953] [client 20.116.17.175:60469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/loader.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxoQAAACM"]
[Tue Aug 18 13:00:09.630528 2026] [security2:error] [pid 123784:tid 123984] [client 102.214.136.52:54883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.136.214.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "impactoveiculos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxogAAAEI"]
[Tue Aug 18 13:00:09.630690 2026] [security2:error] [pid 123784:tid 123984] [client 102.214.136.52:54883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "impactoveiculos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxogAAAEI"]
[Tue Aug 18 13:00:09.639804 2026] [security2:error] [pid 123784:tid 123841] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/system_log.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxpQAABDQ"]
[Tue Aug 18 13:00:09.645930 2026] [security2:error] [pid 123784:tid 123966] [client 20.79.204.6:14089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/goat.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxpgAAADA"]
[Tue Aug 18 13:00:09.658551 2026] [security2:error] [pid 123784:tid 124034] [client 40.74.65.169:60229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxpwAAAHQ"]
[Tue Aug 18 13:00:09.691737 2026] [security2:error] [pid 123784:tid 123974] [client 158.23.17.4:20357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/gi.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxqQAAADg"]
[Tue Aug 18 13:00:09.707694 2026] [security2:error] [pid 123784:tid 123942] [client 20.104.85.180:43580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxqgAAABg"]
[Tue Aug 18 13:00:09.714406 2026] [security2:error] [pid 123784:tid 124033] [client 168.62.48.100:18124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxrAAAAHM"]
[Tue Aug 18 13:00:09.727900 2026] [security2:error] [pid 123784:tid 123890] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxrwAAfGU"]
[Tue Aug 18 13:00:09.743653 2026] [security2:error] [pid 123784:tid 123936] [client 20.226.56.190:20926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/vp.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxsAAAABI"]
[Tue Aug 18 13:00:09.749014 2026] [security2:error] [pid 123784:tid 124009] [client 20.250.27.191:40178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxsQAAAFs"]
[Tue Aug 18 13:00:09.779792 2026] [security2:error] [pid 123784:tid 124028] [client 20.226.56.190:42460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ph.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxswAAAG4"]
[Tue Aug 18 13:00:09.804029 2026] [security2:error] [pid 123784:tid 123946] [client 178.153.171.161:28483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxtAAAABw"]
[Tue Aug 18 13:00:09.804236 2026] [security2:error] [pid 123784:tid 123946] [client 178.153.171.161:28483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxtAAAABw"]
[Tue Aug 18 13:00:09.814196 2026] [security2:error] [pid 123784:tid 123931] [client 158.23.17.4:10975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/dirs.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxtgAAAA0"]
[Tue Aug 18 13:00:09.859879 2026] [security2:error] [pid 123784:tid 123981] [client 136.66.149.90:11620] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.aws/metadata/iam/security-credentials/"] [unique_id "aoSBiWwDnJBNj2tDbYbxuwAAAD8"]
[Tue Aug 18 13:00:09.885040 2026] [security2:error] [pid 123784:tid 124000] [client 190.92.174.183:50518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/main/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxvAAAAFI"]
[Tue Aug 18 13:00:09.885143 2026] [security2:error] [pid 123784:tid 124000] [client 190.92.174.183:50518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/main/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxvAAAAFI"]
[Tue Aug 18 13:00:09.895393 2026] [security2:error] [pid 123784:tid 123831] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/atomlib.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxvgAAayo"]
[Tue Aug 18 13:00:09.909014 2026] [security2:error] [pid 123784:tid 123944] [client 20.116.17.175:59991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/zero.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxwgAAABo"]
[Tue Aug 18 13:00:09.918811 2026] [security2:error] [pid 123784:tid 123951] [client 20.226.56.190:8313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/s.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxwwAAACE"]
[Tue Aug 18 13:00:09.969132 2026] [security2:error] [pid 123784:tid 124017] [client 20.65.98.162:45602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/admin.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxxAAAAGM"]
[Tue Aug 18 13:00:09.984538 2026] [security2:error] [pid 123784:tid 123937] [client 37.40.227.74:57106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxxwAAABM"]
[Tue Aug 18 13:00:09.984651 2026] [security2:error] [pid 123784:tid 123937] [client 37.40.227.74:57106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxxwAAABM"]
[Tue Aug 18 13:00:09.999984 2026] [security2:error] [pid 123784:tid 123918] [client 20.104.85.180:18868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/ok.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxygAAAAA"]
[Tue Aug 18 13:00:10.027563 2026] [security2:error] [pid 123784:tid 124016] [client 168.62.48.100:18068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSBimwDnJBNj2tDbYbxzAAAAGI"]
[Tue Aug 18 13:00:10.028737 2026] [security2:error] [pid 123784:tid 123963] [client 20.127.136.245:28082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/ww5.php"] [unique_id "aoSBimwDnJBNj2tDbYbxzQAAAC0"]
[Tue Aug 18 13:00:10.039658 2026] [security2:error] [pid 123784:tid 123985] [client 68.155.156.252:40761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/av.php"] [unique_id "aoSBimwDnJBNj2tDbYbxzgAAAEM"]
[Tue Aug 18 13:00:10.061462 2026] [security2:error] [pid 123784:tid 124032] [client 158.158.74.177:3351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/templates/beez3/error.php"] [unique_id "aoSBimwDnJBNj2tDbYbxzwAAAHI"]
[Tue Aug 18 13:00:10.063344 2026] [security2:error] [pid 123784:tid 123899] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/rip.php"] [unique_id "aoSBimwDnJBNj2tDbYbx0QAAcW4"]
[Tue Aug 18 13:00:10.077739 2026] [security2:error] [pid 123784:tid 123978] [client 5.31.227.224:30422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBimwDnJBNj2tDbYbx0wAAADw"]
[Tue Aug 18 13:00:10.082455 2026] [security2:error] [pid 123784:tid 123978] [client 5.31.227.224:30422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBimwDnJBNj2tDbYbx0wAAADw"]
[Tue Aug 18 13:00:10.136212 2026] [security2:error] [pid 123784:tid 123987] [client 158.23.17.4:12501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/fn.php"] [unique_id "aoSBimwDnJBNj2tDbYbx1gAAAEU"]
[Tue Aug 18 13:00:10.145328 2026] [authz_core:error] [pid 123784:tid 123807] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:10.145777 2026] [authz_core:error] [pid 123784:tid 123807] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:10.162692 2026] [security2:error] [pid 123784:tid 123982] [client 20.250.27.191:63206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/admin.php"] [unique_id "aoSBimwDnJBNj2tDbYbx1wAAAEA"]
[Tue Aug 18 13:00:10.202804 2026] [security2:error] [pid 123784:tid 123973] [client 20.116.17.175:59997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/002.php"] [unique_id "aoSBimwDnJBNj2tDbYbx4AAAADc"]
[Tue Aug 18 13:00:10.204400 2026] [security2:error] [pid 123784:tid 123991] [client 158.23.17.4:60318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/app.php"] [unique_id "aoSBimwDnJBNj2tDbYbx4QAAAEk"]
[Tue Aug 18 13:00:10.230454 2026] [security2:error] [pid 123784:tid 123852] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/p.php"] [unique_id "aoSBimwDnJBNj2tDbYbx5wAAGT8"]
[Tue Aug 18 13:00:10.246361 2026] [security2:error] [pid 123784:tid 124012] [client 20.79.204.6:14123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/Session.php"] [unique_id "aoSBimwDnJBNj2tDbYbx6QAAAF4"]
[Tue Aug 18 13:00:10.252401 2026] [security2:error] [pid 123784:tid 124026] [client 172.202.39.151:4698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBimwDnJBNj2tDbYbx6gAAAGw"]
[Tue Aug 18 13:00:10.261503 2026] [security2:error] [pid 123784:tid 123988] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBimwDnJBNj2tDbYbx5gAARnY"]
[Tue Aug 18 13:00:10.273417 2026] [security2:error] [pid 123784:tid 124020] [client 168.62.48.100:18146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSBimwDnJBNj2tDbYbx7AAAAGY"]
[Tue Aug 18 13:00:10.281354 2026] [security2:error] [pid 123784:tid 123939] [client 20.104.85.180:18828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/item.php"] [unique_id "aoSBimwDnJBNj2tDbYbx7QAAABU"]
[Tue Aug 18 13:00:10.326280 2026] [security2:error] [pid 123784:tid 123983] [client 213.35.127.232:55946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBimwDnJBNj2tDbYbx8AAAAEE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:10.349366 2026] [security2:error] [pid 123784:tid 124023] [client 68.221.73.131:32055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/file1221.php"] [unique_id "aoSBimwDnJBNj2tDbYbx8QAAAGk"]
[Tue Aug 18 13:00:10.355455 2026] [security2:error] [pid 123784:tid 123965] [client 40.74.65.169:60166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBimwDnJBNj2tDbYbx8gAAAC8"]
[Tue Aug 18 13:00:10.398684 2026] [security2:error] [pid 123784:tid 123870] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/php.php"] [unique_id "aoSBimwDnJBNj2tDbYbx9AAADVE"]
[Tue Aug 18 13:00:10.417882 2026] [security2:error] [pid 123784:tid 123990] [client 4.232.94.69:27553] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "vfunnelcrm.com.br"] [uri "/1.php"] [unique_id "aoSBimwDnJBNj2tDbYbx9QAAAEg"]
[Tue Aug 18 13:00:10.417997 2026] [security2:error] [pid 123784:tid 123990] [client 4.232.94.69:27553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/1.php"] [unique_id "aoSBimwDnJBNj2tDbYbx9QAAAEg"]
[Tue Aug 18 13:00:10.420009 2026] [security2:error] [pid 123784:tid 124011] [client 20.203.138.185:32253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/x7.php"] [unique_id "aoSBimwDnJBNj2tDbYbx9gAAAF0"]
[Tue Aug 18 13:00:10.423881 2026] [security2:error] [pid 123784:tid 123941] [client 20.226.56.190:42457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/uo.php"] [unique_id "aoSBimwDnJBNj2tDbYbx-AAAABc"]
[Tue Aug 18 13:00:10.443382 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:10.443645 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:10.452407 2026] [security2:error] [pid 123784:tid 124045] [client 20.127.136.245:28047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/2.php"] [unique_id "aoSBimwDnJBNj2tDbYbx_gAAAH8"]
[Tue Aug 18 13:00:10.488478 2026] [authz_core:error] [pid 123784:tid 123813] [remote 57.141.22.49:20090] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:10.488766 2026] [authz_core:error] [pid 123784:tid 123813] [remote 57.141.22.49:20090] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:10.510126 2026] [security2:error] [pid 123784:tid 123913] [remote 212.29.237.5:38564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.237.29.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nadianobre.com.br"] [uri "/wp-login.php"] [unique_id "aoSBimwDnJBNj2tDbYbyAAAAU3w"]
[Tue Aug 18 13:00:10.513149 2026] [security2:error] [pid 123784:tid 123993] [client 20.116.17.175:60451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/zxz.php"] [unique_id "aoSBimwDnJBNj2tDbYbyAwAAAEs"]
[Tue Aug 18 13:00:10.517406 2026] [security2:error] [pid 123784:tid 123998] [client 20.226.56.190:21182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kx.php"] [unique_id "aoSBimwDnJBNj2tDbYbyBAAAAFA"]
[Tue Aug 18 13:00:10.532659 2026] [security2:error] [pid 123784:tid 123923] [client 20.226.56.190:42466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/va.php"] [unique_id "aoSBimwDnJBNj2tDbYbyBQAAAAU"]
[Tue Aug 18 13:00:10.534544 2026] [security2:error] [pid 123784:tid 124003] [client 168.62.48.100:5570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/yxijx.php"] [unique_id "aoSBimwDnJBNj2tDbYbyBgAAAFU"]
[Tue Aug 18 13:00:10.547717 2026] [security2:error] [pid 123784:tid 124017] [client 168.62.48.100:18127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSBimwDnJBNj2tDbYbyCQAAAGM"]
[Tue Aug 18 13:00:10.573554 2026] [security2:error] [pid 123784:tid 123996] [client 20.226.56.190:15182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fo.php"] [unique_id "aoSBimwDnJBNj2tDbYbyCgAAAE4"]
[Tue Aug 18 13:00:10.575046 2026] [security2:error] [pid 123784:tid 124010] [client 20.250.27.191:63169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/file52.php"] [unique_id "aoSBimwDnJBNj2tDbYbyCwAAAFw"]
[Tue Aug 18 13:00:10.584518 2026] [security2:error] [pid 123784:tid 123963] [client 20.226.56.190:17938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/loading.php"] [unique_id "aoSBimwDnJBNj2tDbYbyDwAAAC0"]
[Tue Aug 18 13:00:10.647870 2026] [security2:error] [pid 123784:tid 124043] [client 68.155.154.236:4069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBimwDnJBNj2tDbYbyIQAAAH0"]
[Tue Aug 18 13:00:10.672500 2026] [security2:error] [pid 123784:tid 123947] [client 172.202.39.151:4416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBimwDnJBNj2tDbYbyKQAAAB0"]
[Tue Aug 18 13:00:10.683487 2026] [security2:error] [pid 123784:tid 124025] [client 158.158.74.177:16187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/test.php"] [unique_id "aoSBimwDnJBNj2tDbYbyKgAAAGs"]
[Tue Aug 18 13:00:10.729396 2026] [security2:error] [pid 123784:tid 123950] [client 68.155.156.252:10110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/images.php"] [unique_id "aoSBimwDnJBNj2tDbYbyLAAAACA"]
[Tue Aug 18 13:00:10.731047 2026] [security2:error] [pid 123784:tid 124036] [client 158.23.17.4:40436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/pz.php"] [unique_id "aoSBimwDnJBNj2tDbYbyLQAAAHY"]
[Tue Aug 18 13:00:10.744899 2026] [authz_core:error] [pid 123784:tid 123836] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:10.745163 2026] [authz_core:error] [pid 123784:tid 123836] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:10.818666 2026] [security2:error] [pid 123784:tid 123825] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/pucci.php"] [unique_id "aoSBimwDnJBNj2tDbYbyMwAAXiQ"]
[Tue Aug 18 13:00:10.835401 2026] [security2:error] [pid 123784:tid 123988] [client 168.62.48.100:18085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSBimwDnJBNj2tDbYbyNAAAAEY"]
[Tue Aug 18 13:00:10.845449 2026] [security2:error] [pid 123784:tid 123940] [client 20.116.17.175:60418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/memberfuns.php"] [unique_id "aoSBimwDnJBNj2tDbYbyNQAAABY"]
[Tue Aug 18 13:00:10.846814 2026] [security2:error] [pid 123784:tid 124006] [client 20.79.204.6:14143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSBimwDnJBNj2tDbYbyNgAAAFg"]
[Tue Aug 18 13:00:10.871784 2026] [security2:error] [pid 123784:tid 124009] [client 20.226.56.190:21167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ke.php"] [unique_id "aoSBimwDnJBNj2tDbYbyNwAAAFs"]
[Tue Aug 18 13:00:10.900208 2026] [security2:error] [pid 123784:tid 123957] [client 223.185.37.47:30107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBimwDnJBNj2tDbYbyOAAAACc"]
[Tue Aug 18 13:00:10.900372 2026] [security2:error] [pid 123784:tid 123957] [client 223.185.37.47:30107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBimwDnJBNj2tDbYbyOAAAACc"]
[Tue Aug 18 13:00:10.901971 2026] [security2:error] [pid 123784:tid 123989] [client 158.23.17.4:38869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/sn.php"] [unique_id "aoSBimwDnJBNj2tDbYbyOQAAAEc"]
[Tue Aug 18 13:00:10.950789 2026] [security2:error] [pid 123784:tid 123991] [client 20.127.136.245:28068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBimwDnJBNj2tDbYbyPwAAAEk"]
[Tue Aug 18 13:00:11.012454 2026] [security2:error] [pid 123784:tid 123919] [client 190.92.174.183:50524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/wp-site/xmlrpc.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyQgAAAAE"]
[Tue Aug 18 13:00:11.012545 2026] [security2:error] [pid 123784:tid 123919] [client 190.92.174.183:50524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/wp-site/xmlrpc.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyQgAAAAE"]
[Tue Aug 18 13:00:11.013063 2026] [security2:error] [pid 123784:tid 123936] [client 20.79.204.6:10718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/inputs.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyQwAAABI"]
[Tue Aug 18 13:00:11.031984 2026] [security2:error] [pid 123784:tid 124045] [client 20.250.27.191:27977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/geck.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyRAAAAH8"]
[Tue Aug 18 13:00:11.044325 2026] [security2:error] [pid 123784:tid 124007] [client 40.74.65.169:60243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/aa.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyRwAAAFk"]
[Tue Aug 18 13:00:11.048078 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:11.048506 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:11.049549 2026] [security2:error] [pid 123784:tid 124005] [client 158.23.17.4:60351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/87.php"] [unique_id "aoSBi2wDnJBNj2tDbYbySAAAAFc"]
[Tue Aug 18 13:00:11.089139 2026] [security2:error] [pid 123784:tid 124030] [client 168.62.48.100:18156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSBi2wDnJBNj2tDbYbySQAAAHA"]
[Tue Aug 18 13:00:11.108295 2026] [security2:error] [pid 123784:tid 124017] [client 20.226.56.190:20901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/nh.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyTwAAAGM"]
[Tue Aug 18 13:00:11.124511 2026] [security2:error] [pid 123784:tid 123962] [client 20.116.17.175:58116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/aa.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyUQAAACw"]
[Tue Aug 18 13:00:11.137185 2026] [security2:error] [pid 123784:tid 123958] [client 172.202.39.151:4706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/k.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyUgAAACg"]
[Tue Aug 18 13:00:11.146824 2026] [security2:error] [pid 123784:tid 124010] [client 172.202.39.151:41125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/flower.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyVAAAAFw"]
[Tue Aug 18 13:00:11.212875 2026] [security2:error] [pid 123784:tid 124039] [client 68.221.73.131:10946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/nox.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyaAAAAHk"]
[Tue Aug 18 13:00:11.330118 2026] [security2:error] [pid 123784:tid 124025] [client 20.226.56.190:40172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/oo.php"] [unique_id "aoSBi2wDnJBNj2tDbYbycAAAAGs"]
[Tue Aug 18 13:00:11.332258 2026] [security2:error] [pid 123784:tid 123998] [client 158.158.74.177:3877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/test1.php"] [unique_id "aoSBi2wDnJBNj2tDbYbycQAAAFA"]
[Tue Aug 18 13:00:11.341951 2026] [security2:error] [pid 123784:tid 123990] [client 213.35.127.232:56142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBi2wDnJBNj2tDbYbycwAAAEg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:11.350807 2026] [authz_core:error] [pid 123784:tid 123878] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:11.351239 2026] [authz_core:error] [pid 123784:tid 123878] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:11.351332 2026] [security2:error] [pid 123784:tid 123982] [client 168.62.48.100:18101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSBi2wDnJBNj2tDbYbydAAAAEA"]
[Tue Aug 18 13:00:11.360642 2026] [security2:error] [pid 123784:tid 123949] [client 68.155.154.236:4058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBi2wDnJBNj2tDbYbydQAAAB8"]
[Tue Aug 18 13:00:11.406472 2026] [security2:error] [pid 123784:tid 124033] [client 20.116.17.175:60007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/echkm.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyeAAAAHM"]
[Tue Aug 18 13:00:11.425213 2026] [security2:error] [pid 123784:tid 123945] [client 20.127.136.245:28335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/atomlib.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyegAAABs"]
[Tue Aug 18 13:00:11.447941 2026] [security2:error] [pid 123784:tid 123940] [client 20.250.27.191:45821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/biufile.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyewAAABY"]
[Tue Aug 18 13:00:11.453223 2026] [security2:error] [pid 123784:tid 124006] [client 20.65.98.162:45584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/222.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyfAAAAFg"]
[Tue Aug 18 13:00:11.453943 2026] [security2:error] [pid 123784:tid 123995] [client 20.79.204.6:14074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/abcd.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyfQAAAE0"]
[Tue Aug 18 13:00:11.461251 2026] [security2:error] [pid 123784:tid 123981] [client 4.232.94.69:27165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-includes/blocks/about.php"] [unique_id "aoSBi2wDnJBNj2tDbYbygAAAAD8"]
[Tue Aug 18 13:00:11.521020 2026] [security2:error] [pid 123784:tid 124023] [client 138.199.60.10:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "jgbdominiosolucoes.com.br"] [uri "/"] [unique_id "aoSBi2wDnJBNj2tDbYbyggAAAGk"]
[Tue Aug 18 13:00:11.545369 2026] [security2:error] [pid 123784:tid 124004] [client 20.203.138.185:42436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/god.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyhgAAAFY"]
[Tue Aug 18 13:00:11.575515 2026] [security2:error] [pid 123784:tid 124011] [client 20.226.56.190:15220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ja.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyigAAAF0"]
[Tue Aug 18 13:00:11.602546 2026] [security2:error] [pid 123784:tid 123932] [client 168.62.48.100:18095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyiwAAAA4"]
[Tue Aug 18 13:00:11.671616 2026] [security2:error] [pid 123784:tid 123993] [client 20.226.56.190:6362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xx.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyjQAAAEs"]
[Tue Aug 18 13:00:11.696113 2026] [security2:error] [pid 123784:tid 123923] [client 20.116.17.175:60467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/domvf.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyjwAAAAU"]
[Tue Aug 18 13:00:11.696672 2026] [security2:error] [pid 123784:tid 123962] [client 20.226.56.190:6362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/conn-test.php"] [unique_id "aoSBi2wDnJBNj2tDbYbykAAAACw"]
[Tue Aug 18 13:00:11.708562 2026] [security2:error] [pid 123784:tid 123918] [client 20.226.56.190:7302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fg.php"] [unique_id "aoSBi2wDnJBNj2tDbYbykQAAAAA"]
[Tue Aug 18 13:00:11.727643 2026] [security2:error] [pid 123784:tid 124032] [client 20.226.56.190:21153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ve.php"] [unique_id "aoSBi2wDnJBNj2tDbYbykwAAAHI"]
[Tue Aug 18 13:00:11.733498 2026] [security2:error] [pid 123784:tid 124024] [client 40.74.65.169:60286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/av.php"] [unique_id "aoSBi2wDnJBNj2tDbYbylQAAAGo"]
[Tue Aug 18 13:00:11.746029 2026] [security2:error] [pid 123784:tid 123952] [client 68.155.156.252:15667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/ops.php"] [unique_id "aoSBi2wDnJBNj2tDbYbylwAAACI"]
[Tue Aug 18 13:00:11.746695 2026] [security2:error] [pid 123784:tid 123921] [client 158.23.17.4:63024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/kk.php"] [unique_id "aoSBi2wDnJBNj2tDbYbymAAAAAM"]
[Tue Aug 18 13:00:11.779496 2026] [security2:error] [pid 123784:tid 123975] [client 158.23.17.4:38323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/kf.php"] [unique_id "aoSBi2wDnJBNj2tDbYbymgAAADk"]
[Tue Aug 18 13:00:11.812678 2026] [security2:error] [pid 123784:tid 123951] [client 20.226.56.190:10615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ia.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyngAAACE"]
[Tue Aug 18 13:00:11.841307 2026] [security2:error] [pid 123784:tid 123998] [client 68.155.154.236:25350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/well-known/index.php"] [unique_id "aoSBi2wDnJBNj2tDbYbynwAAAFA"]
[Tue Aug 18 13:00:11.849104 2026] [security2:error] [pid 123784:tid 123990] [client 158.23.17.4:47927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/zi.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyoAAAAEg"]
[Tue Aug 18 13:00:11.862834 2026] [security2:error] [pid 123784:tid 123949] [client 168.62.48.100:18054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyoQAAAB8"]
[Tue Aug 18 13:00:11.887103 2026] [security2:error] [pid 123784:tid 123973] [client 20.250.27.191:34829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/dejavu.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyogAAADc"]
[Tue Aug 18 13:00:11.898102 2026] [security2:error] [pid 123784:tid 124039] [client 20.127.136.245:28074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/rip.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyowAAAHk"]
[Tue Aug 18 13:00:11.950618 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:11.951048 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:11.952067 2026] [security2:error] [pid 123784:tid 123959] [client 158.158.74.177:3860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/text.php"] [unique_id "aoSBi2wDnJBNj2tDbYbypgAAACk"]
[Tue Aug 18 13:00:11.958430 2026] [security2:error] [pid 123784:tid 123965] [client 20.250.13.23:53542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/simple.php"] [unique_id "aoSBi2wDnJBNj2tDbYbypwAAAC8"]
[Tue Aug 18 13:00:11.972447 2026] [security2:error] [pid 123784:tid 123968] [client 74.7.244.10:60068] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.old.useemede.com.br"] [uri "/index.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxxgAAMkI"]
[Tue Aug 18 13:00:11.977395 2026] [security2:error] [pid 123784:tid 123810] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-temp.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyqgAATRU"]
[Tue Aug 18 13:00:11.990209 2026] [security2:error] [pid 123784:tid 123986] [client 20.116.17.175:60466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/red.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyqwAAAEQ"]
[Tue Aug 18 13:00:12.021782 2026] [security2:error] [pid 123784:tid 123972] [client 132.196.30.78:14600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/ww5.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyrQAAADY"]
[Tue Aug 18 13:00:12.056592 2026] [security2:error] [pid 123784:tid 123982] [client 20.79.204.6:14111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/kj.php"] [unique_id "aoSBjGwDnJBNj2tDbYbysAAAAEA"]
[Tue Aug 18 13:00:12.098459 2026] [security2:error] [pid 123784:tid 124002] [client 20.226.56.190:15191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kn.php"] [unique_id "aoSBjGwDnJBNj2tDbYbytQAAAFQ"]
[Tue Aug 18 13:00:12.129631 2026] [security2:error] [pid 123784:tid 123978] [client 190.92.174.183:50540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/old/xmlrpc.php"] [unique_id "aoSBjGwDnJBNj2tDbYbytwAAADw"]
[Tue Aug 18 13:00:12.129793 2026] [security2:error] [pid 123784:tid 123978] [client 190.92.174.183:50540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/old/xmlrpc.php"] [unique_id "aoSBjGwDnJBNj2tDbYbytwAAADw"]
[Tue Aug 18 13:00:12.142815 2026] [security2:error] [pid 123784:tid 124008] [client 168.62.48.100:18129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyuAAAAFo"]
[Tue Aug 18 13:00:12.170191 2026] [security2:error] [pid 123784:tid 123853] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyuQAAZUA"]
[Tue Aug 18 13:00:12.170438 2026] [security2:error] [pid 123784:tid 124019] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyuQAAZUA"]
[Tue Aug 18 13:00:12.228236 2026] [security2:error] [pid 123784:tid 123937] [client 68.155.154.236:4049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBjGwDnJBNj2tDbYbywAAAABM"]
[Tue Aug 18 13:00:12.250002 2026] [authz_core:error] [pid 123784:tid 123883] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:12.250262 2026] [authz_core:error] [pid 123784:tid 123883] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:12.263546 2026] [security2:error] [pid 123784:tid 123987] [client 20.116.17.175:60444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/JawirGenk.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyxAAAAEU"]
[Tue Aug 18 13:00:12.267144 2026] [security2:error] [pid 123784:tid 123939] [client 20.79.204.6:10738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/admin.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyxQAAABU"]
[Tue Aug 18 13:00:12.297091 2026] [security2:error] [pid 123784:tid 123980] [client 20.250.27.191:27974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/aaf.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyxgAAAD4"]
[Tue Aug 18 13:00:12.327625 2026] [security2:error] [pid 123784:tid 123928] [client 158.23.17.4:63938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/43.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyxwAAAAo"]
[Tue Aug 18 13:00:12.350774 2026] [security2:error] [pid 123784:tid 123918] [client 20.127.136.245:28290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/p.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyyAAAAAA"]
[Tue Aug 18 13:00:12.357069 2026] [security2:error] [pid 123784:tid 123920] [client 213.35.127.232:56366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyyQAAAAI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:12.387564 2026] [security2:error] [pid 123784:tid 123897] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyywAAdGw"]
[Tue Aug 18 13:00:12.396217 2026] [security2:error] [pid 123784:tid 123949] [client 20.226.56.190:21142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wm.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyzAAAAB8"]
[Tue Aug 18 13:00:12.416822 2026] [security2:error] [pid 123784:tid 124013] [client 40.74.65.169:60230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/media.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyzQAAAF8"]
[Tue Aug 18 13:00:12.447507 2026] [security2:error] [pid 123784:tid 123959] [client 68.155.156.252:53435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/coffexium.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyzwAAACk"]
[Tue Aug 18 13:00:12.468492 2026] [security2:error] [pid 123784:tid 123933] [client 158.23.17.4:56538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/phpcheck.php"] [unique_id "aoSBjGwDnJBNj2tDbYby0AAAAA8"]
[Tue Aug 18 13:00:12.470896 2026] [security2:error] [pid 123784:tid 123940] [client 168.62.48.100:18115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSBjGwDnJBNj2tDbYby0QAAABY"]
[Tue Aug 18 13:00:12.510156 2026] [security2:error] [pid 123784:tid 123983] [client 20.226.56.190:6347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ac.php"] [unique_id "aoSBjGwDnJBNj2tDbYby1AAAAEE"]
[Tue Aug 18 13:00:12.553020 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:12.553280 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:12.562925 2026] [security2:error] [pid 123784:tid 123972] [client 158.23.17.4:51144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/92.php"] [unique_id "aoSBjGwDnJBNj2tDbYby1wAAADY"]
[Tue Aug 18 13:00:12.575837 2026] [security2:error] [pid 123784:tid 123950] [client 68.155.154.236:3980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBjGwDnJBNj2tDbYby2AAAACA"]
[Tue Aug 18 13:00:12.580542 2026] [security2:error] [pid 123784:tid 123997] [client 20.116.17.175:59999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/options.php"] [unique_id "aoSBjGwDnJBNj2tDbYby2QAAAE8"]
[Tue Aug 18 13:00:12.609854 2026] [security2:error] [pid 123784:tid 123982] [client 20.226.56.190:40133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/yz.php"] [unique_id "aoSBjGwDnJBNj2tDbYby3gAAAEA"]
[Tue Aug 18 13:00:12.640635 2026] [security2:error] [pid 123784:tid 123931] [client 20.226.56.190:21181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kj.php"] [unique_id "aoSBjGwDnJBNj2tDbYby4AAAAA0"]
[Tue Aug 18 13:00:12.653273 2026] [security2:error] [pid 123784:tid 124025] [client 158.158.74.177:16191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/themes/zmousse/otuz1.php"] [unique_id "aoSBjGwDnJBNj2tDbYby4QAAAGs"]
[Tue Aug 18 13:00:12.663033 2026] [security2:error] [pid 123784:tid 123935] [client 20.79.204.6:14133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/languages.php"] [unique_id "aoSBjGwDnJBNj2tDbYby4gAAABE"]
[Tue Aug 18 13:00:12.668269 2026] [security2:error] [pid 123784:tid 123905] [remote 47.89.174.181:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.api.devota.com.br"] [uri "/.env"] [unique_id "aoSBjGwDnJBNj2tDbYby5QAAYXQ"]
[Tue Aug 18 13:00:12.676421 2026] [security2:error] [pid 123784:tid 124026] [client 132.196.30.78:16184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/2.php"] [unique_id "aoSBjGwDnJBNj2tDbYby5gAAAGw"]
[Tue Aug 18 13:00:12.690595 2026] [security2:error] [pid 123784:tid 123984] [client 20.203.138.185:49858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ebahvhhh.php"] [unique_id "aoSBjGwDnJBNj2tDbYby6AAAAEI"]
[Tue Aug 18 13:00:12.704263 2026] [security2:error] [pid 123784:tid 123958] [client 20.250.27.191:63168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSBjGwDnJBNj2tDbYby6gAAACg"]
[Tue Aug 18 13:00:12.706164 2026] [security2:error] [pid 123784:tid 124002] [client 20.226.56.190:21156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/vg.php"] [unique_id "aoSBjGwDnJBNj2tDbYby6wAAAFQ"]
[Tue Aug 18 13:00:12.719906 2026] [security2:error] [pid 123784:tid 124010] [client 20.226.56.190:21176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/sm.php"] [unique_id "aoSBjGwDnJBNj2tDbYby7AAAAFw"]
[Tue Aug 18 13:00:12.735306 2026] [security2:error] [pid 123784:tid 123978] [client 172.202.39.151:4420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/403.php"] [unique_id "aoSBjGwDnJBNj2tDbYby7QAAADw"]
[Tue Aug 18 13:00:12.747165 2026] [security2:error] [pid 123784:tid 124030] [client 20.226.56.190:7322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/28.php"] [unique_id "aoSBjGwDnJBNj2tDbYby7gAAAHA"]
[Tue Aug 18 13:00:12.761705 2026] [security2:error] [pid 123784:tid 124040] [client 20.226.56.190:11589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/m.php"] [unique_id "aoSBjGwDnJBNj2tDbYby7wAAAHo"]
[Tue Aug 18 13:00:12.769694 2026] [security2:error] [pid 123784:tid 123981] [client 74.7.244.10:60078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "old.useemede.com.br"] [uri "/index.php"] [unique_id "aoSBjGwDnJBNj2tDbYby3wAAPwI"], referer: https://www.old.useemede.com.br/robots.txt
[Tue Aug 18 13:00:12.780394 2026] [security2:error] [pid 123784:tid 124022] [client 20.226.56.190:6114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/nl.php"] [unique_id "aoSBjGwDnJBNj2tDbYby8AAAAGg"]
[Tue Aug 18 13:00:12.817023 2026] [security2:error] [pid 123784:tid 123953] [client 168.62.48.100:18074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSBjGwDnJBNj2tDbYby8QAAACM"]
[Tue Aug 18 13:00:12.826600 2026] [security2:error] [pid 123784:tid 123985] [client 20.226.56.190:20904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/68.php"] [unique_id "aoSBjGwDnJBNj2tDbYby8gAAAEM"]
[Tue Aug 18 13:00:12.852570 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:12.852832 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:12.866457 2026] [security2:error] [pid 123784:tid 123922] [client 20.116.17.175:60437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSBjGwDnJBNj2tDbYby9QAAAAQ"]
[Tue Aug 18 13:00:12.873963 2026] [security2:error] [pid 123784:tid 124016] [client 168.62.48.100:5504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/zwlsv.php"] [unique_id "aoSBjGwDnJBNj2tDbYby9wAAAGI"]
[Tue Aug 18 13:00:12.877941 2026] [security2:error] [pid 123784:tid 124033] [client 20.127.136.245:28543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/php.php"] [unique_id "aoSBjGwDnJBNj2tDbYby-QAAAHM"]
[Tue Aug 18 13:00:12.878333 2026] [security2:error] [pid 123784:tid 123951] [client 4.232.94.69:32031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "aoSBjGwDnJBNj2tDbYby-gAAACE"]
[Tue Aug 18 13:00:12.881110 2026] [security2:error] [pid 123784:tid 123989] [client 158.23.17.4:31923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/su.php"] [unique_id "aoSBjGwDnJBNj2tDbYby-wAAAEc"]
[Tue Aug 18 13:00:12.913293 2026] [security2:error] [pid 123784:tid 123990] [client 20.226.56.190:9941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/jl.php"] [unique_id "aoSBjGwDnJBNj2tDbYby_QAAAEg"]
[Tue Aug 18 13:00:12.919981 2026] [security2:error] [pid 123784:tid 123975] [client 158.23.17.4:10994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/fresh.php"] [unique_id "aoSBjGwDnJBNj2tDbYby_wAAADk"]
[Tue Aug 18 13:00:12.925745 2026] [security2:error] [pid 123784:tid 123974] [client 68.155.154.236:27534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBjGwDnJBNj2tDbYbzAAAAADg"]
[Tue Aug 18 13:00:12.968250 2026] [security2:error] [pid 123784:tid 124013] [client 20.226.56.190:10610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/tq.php"] [unique_id "aoSBjGwDnJBNj2tDbYbzAgAAAF8"]
[Tue Aug 18 13:00:12.972556 2026] [security2:error] [pid 123784:tid 123913] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/puc.php"] [unique_id "aoSBjGwDnJBNj2tDbYbzAwAAMHw"]
[Tue Aug 18 13:00:12.988069 2026] [security2:error] [pid 123784:tid 123940] [client 172.202.39.151:44134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/13.php"] [unique_id "aoSBjGwDnJBNj2tDbYbzBAAAABY"]
[Tue Aug 18 13:00:13.041737 2026] [security2:error] [pid 123784:tid 123992] [client 20.226.56.190:40179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/cv.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzBQAAAEo"]
[Tue Aug 18 13:00:13.067947 2026] [security2:error] [pid 123784:tid 124014] [client 168.62.48.100:18023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzBgAAAGA"]
[Tue Aug 18 13:00:13.078777 2026] [security2:error] [pid 123784:tid 123957] [client 20.226.56.190:10576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/un.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzBwAAACc"]
[Tue Aug 18 13:00:13.104746 2026] [security2:error] [pid 123784:tid 123948] [client 20.226.56.190:11609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/evil.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzDAAAAB4"]
[Tue Aug 18 13:00:13.109173 2026] [security2:error] [pid 123784:tid 124042] [client 20.250.27.191:43505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/155.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzDQAAAHw"]
[Tue Aug 18 13:00:13.133105 2026] [security2:error] [pid 123784:tid 123935] [client 40.74.65.169:60256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/images.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzDwAAABE"]
[Tue Aug 18 13:00:13.148453 2026] [security2:error] [pid 123784:tid 124011] [client 20.116.17.175:60006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzEQAAAF0"]
[Tue Aug 18 13:00:13.150488 2026] [security2:error] [pid 123784:tid 123984] [client 20.226.56.190:11617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/pw.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzEwAAAEI"]
[Tue Aug 18 13:00:13.155313 2026] [authz_core:error] [pid 123784:tid 123882] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:13.155602 2026] [authz_core:error] [pid 123784:tid 123882] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:13.162393 2026] [security2:error] [pid 123784:tid 123988] [client 20.226.56.190:10575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fn.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzFAAAAEY"]
[Tue Aug 18 13:00:13.181366 2026] [security2:error] [pid 123784:tid 124002] [client 20.226.56.190:8282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kf.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzFQAAAFQ"]
[Tue Aug 18 13:00:13.192585 2026] [security2:error] [pid 123784:tid 123995] [client 20.118.133.132:13814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/ano.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzFgAAAE0"]
[Tue Aug 18 13:00:13.193474 2026] [security2:error] [pid 123784:tid 124033] [client 190.92.174.183:50542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/new/xmlrpc.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzFwAAAHM"]
[Tue Aug 18 13:00:13.193559 2026] [security2:error] [pid 123784:tid 124033] [client 190.92.174.183:50542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/new/xmlrpc.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzFwAAAHM"]
[Tue Aug 18 13:00:13.201421 2026] [security2:error] [pid 123784:tid 124010] [client 20.226.56.190:15206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/su.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzGAAAAFw"]
[Tue Aug 18 13:00:13.217533 2026] [security2:error] [pid 123784:tid 124018] [client 20.226.56.190:10601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wp-key.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzGgAAAGQ"]
[Tue Aug 18 13:00:13.245337 2026] [security2:error] [pid 123784:tid 124001] [client 158.23.17.4:58740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/jm.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzHAAAAFM"]
[Tue Aug 18 13:00:13.268321 2026] [security2:error] [pid 123784:tid 124008] [client 172.202.39.151:44521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/gecko.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzHQAAAFo"]
[Tue Aug 18 13:00:13.275088 2026] [security2:error] [pid 123784:tid 124020] [client 158.158.74.177:3864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/u.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzHgAAAGY"]
[Tue Aug 18 13:00:13.277074 2026] [security2:error] [pid 123784:tid 123790] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzHwAAGwE"]
[Tue Aug 18 13:00:13.277222 2026] [security2:error] [pid 123784:tid 123945] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzHwAAGwE"]
[Tue Aug 18 13:00:13.285511 2026] [security2:error] [pid 123784:tid 124030] [client 158.23.17.4:62995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/dg.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzIgAAAHA"]
[Tue Aug 18 13:00:13.287542 2026] [security2:error] [pid 123784:tid 124025] [client 132.196.30.78:9924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzJAAAAGs"]
[Tue Aug 18 13:00:13.298296 2026] [security2:error] [pid 123784:tid 124019] [client 20.226.56.190:15203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gg.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzJgAAAGU"]
[Tue Aug 18 13:00:13.357357 2026] [security2:error] [pid 123784:tid 123999] [client 168.62.48.100:18145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzKQAAAFE"]
[Tue Aug 18 13:00:13.379209 2026] [security2:error] [pid 123784:tid 123983] [client 213.35.127.232:56586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzKwAAAEE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:13.380605 2026] [security2:error] [pid 123784:tid 124024] [client 68.155.154.236:27565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/mt/byp.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzLAAAAGo"]
[Tue Aug 18 13:00:13.414428 2026] [security2:error] [pid 123784:tid 123976] [client 20.226.56.190:42472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gi.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzLQAAADo"]
[Tue Aug 18 13:00:13.457228 2026] [security2:error] [pid 123784:tid 124043] [client 20.116.17.175:60458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/output.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzLwAAAH0"]
[Tue Aug 18 13:00:13.474228 2026] [security2:error] [pid 123784:tid 124021] [client 20.203.138.185:32526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/8.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzMAAAAGc"]
[Tue Aug 18 13:00:13.481693 2026] [security2:error] [pid 123784:tid 123989] [client 20.79.204.6:14017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/nw.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzMQAAAEc"]
[Tue Aug 18 13:00:13.533547 2026] [security2:error] [pid 123784:tid 123990] [client 68.155.156.252:40740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzMgAAAEg"]
[Tue Aug 18 13:00:13.564459 2026] [security2:error] [pid 123784:tid 123975] [client 20.226.56.190:8259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/pz.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzNAAAADk"]
[Tue Aug 18 13:00:13.595417 2026] [security2:error] [pid 123784:tid 124039] [client 20.250.27.191:45799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/ops.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzNgAAAHk"]
[Tue Aug 18 13:00:13.625594 2026] [security2:error] [pid 123784:tid 123940] [client 168.62.48.100:18118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzOAAAABY"]
[Tue Aug 18 13:00:13.637707 2026] [security2:error] [pid 123784:tid 124027] [client 20.226.56.190:41960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kk.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzOQAAAG0"]
[Tue Aug 18 13:00:13.650956 2026] [security2:error] [pid 123784:tid 123992] [client 158.23.17.4:8939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/wp-key.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzOwAAAEo"]
[Tue Aug 18 13:00:13.652953 2026] [security2:error] [pid 123784:tid 123986] [client 20.226.56.190:6379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/phpcheck.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzPAAAAEQ"]
[Tue Aug 18 13:00:13.680338 2026] [security2:error] [pid 123784:tid 123939] [client 79.127.164.8:56770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/users.bak"] [unique_id "aoSBjWwDnJBNj2tDbYbzPQAAABU"], referer: https://medihub.com.br/users.bak
[Tue Aug 18 13:00:13.684467 2026] [security2:error] [pid 123784:tid 123854] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/8.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzPgAAe0E"]
[Tue Aug 18 13:00:13.714371 2026] [security2:error] [pid 123784:tid 123931] [client 20.226.56.190:6382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/dg.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzQAAAAA0"]
[Tue Aug 18 13:00:13.715167 2026] [security2:error] [pid 123784:tid 123960] [client 135.225.78.186:48113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/sf.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzQQAAACo"]
[Tue Aug 18 13:00:13.727169 2026] [security2:error] [pid 123784:tid 124004] [client 20.226.56.190:21131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/bm.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzQgAAAFY"]
[Tue Aug 18 13:00:13.737458 2026] [security2:error] [pid 123784:tid 124011] [client 20.226.56.190:40182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/vu.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzQwAAAF0"]
[Tue Aug 18 13:00:13.737518 2026] [security2:error] [pid 123784:tid 123984] [client 20.116.17.175:59994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/tiny2.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzRAAAAEI"]
[Tue Aug 18 13:00:13.740217 2026] [security2:error] [pid 123784:tid 123918] [client 4.232.94.69:58106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/aaa.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzRQAAAAA"]
[Tue Aug 18 13:00:13.742635 2026] [security2:error] [pid 123784:tid 123936] [client 172.202.39.151:4432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/gecko.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzRgAAABI"]
[Tue Aug 18 13:00:13.757537 2026] [authz_core:error] [pid 123784:tid 123845] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:13.757807 2026] [authz_core:error] [pid 123784:tid 123845] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:13.779479 2026] [security2:error] [pid 123784:tid 123988] [client 158.23.17.4:63640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/gj.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzSQAAAEY"]
[Tue Aug 18 13:00:13.793921 2026] [security2:error] [pid 123784:tid 124038] [client 68.155.154.236:25374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzSgAAAHg"]
[Tue Aug 18 13:00:13.800668 2026] [security2:error] [pid 123784:tid 124015] [client 192.141.172.134:56867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzSwAAAGE"]
[Tue Aug 18 13:00:13.800848 2026] [security2:error] [pid 123784:tid 124015] [client 192.141.172.134:56867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzSwAAAGE"]
[Tue Aug 18 13:00:13.829143 2026] [security2:error] [pid 123784:tid 124033] [client 40.74.65.169:60285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/admin.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzTAAAAHM"]
[Tue Aug 18 13:00:13.834788 2026] [security2:error] [pid 123784:tid 124010] [client 20.226.56.190:21161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ic.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzTwAAAFw"]
[Tue Aug 18 13:00:13.853852 2026] [security2:error] [pid 123784:tid 124018] [client 20.226.56.190:42489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ue.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzUAAAAGQ"]
[Tue Aug 18 13:00:13.861525 2026] [security2:error] [pid 123784:tid 123944] [client 168.62.48.100:18112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzUQAAABo"]
[Tue Aug 18 13:00:13.871586 2026] [security2:error] [pid 123784:tid 123978] [client 20.226.56.190:21139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/lr.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzUgAAADw"]
[Tue Aug 18 13:00:13.893183 2026] [security2:error] [pid 123784:tid 124005] [client 20.226.56.190:15219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ka.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzUwAAAFc"]
[Tue Aug 18 13:00:13.901541 2026] [security2:error] [pid 123784:tid 123977] [client 158.158.74.177:3853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/updates.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzVQAAADs"]
[Tue Aug 18 13:00:13.925099 2026] [security2:error] [pid 123784:tid 123964] [client 20.226.56.190:8303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ot.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzVgAAAC4"]
[Tue Aug 18 13:00:13.962498 2026] [security2:error] [pid 123784:tid 124019] [client 20.226.56.190:40137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ih.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzVwAAAGU"]
[Tue Aug 18 13:00:14.006682 2026] [security2:error] [pid 123784:tid 123896] [remote 20.196.200.88:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.paypix.co"] [uri "/1.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzWAAAaGs"]
[Tue Aug 18 13:00:14.006823 2026] [security2:error] [pid 123784:tid 123896] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/1.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzWAAAaGs"]
[Tue Aug 18 13:00:14.041541 2026] [security2:error] [pid 123784:tid 123953] [client 20.116.17.175:57934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wpxml.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzWgAAACM"]
[Tue Aug 18 13:00:14.057869 2026] [security2:error] [pid 123784:tid 124002] [client 132.196.30.78:14606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/atomlib.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzXAAAAFQ"]
[Tue Aug 18 13:00:14.061411 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:14.061817 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:14.072238 2026] [security2:error] [pid 123784:tid 123985] [client 20.226.56.190:21173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/k.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzXQAAAEM"]
[Tue Aug 18 13:00:14.086140 2026] [security2:error] [pid 123784:tid 123976] [client 158.23.17.4:15162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/wj.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzXgAAADo"]
[Tue Aug 18 13:00:14.088238 2026] [security2:error] [pid 123784:tid 124020] [client 20.79.204.6:14117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzXwAAAGY"]
[Tue Aug 18 13:00:14.099355 2026] [security2:error] [pid 123784:tid 123926] [client 168.62.48.100:18064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzYAAAAAg"]
[Tue Aug 18 13:00:14.111509 2026] [security2:error] [pid 123784:tid 124000] [client 20.250.27.191:40133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/mac.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzYQAAAFI"]
[Tue Aug 18 13:00:14.139179 2026] [security2:error] [pid 123784:tid 123922] [client 158.23.17.4:34131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/gg.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzYgAAAAQ"]
[Tue Aug 18 13:00:14.187395 2026] [security2:error] [pid 123784:tid 123951] [client 172.202.39.151:40323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/aa.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzZQAAACE"]
[Tue Aug 18 13:00:14.187427 2026] [security2:error] [pid 123784:tid 123980] [client 158.23.17.4:62988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/bm.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzZgAAAD4"]
[Tue Aug 18 13:00:14.197191 2026] [security2:error] [pid 123784:tid 124007] [client 20.250.13.23:33144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/edit-tags.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzZwAAAFk"]
[Tue Aug 18 13:00:14.222443 2026] [security2:error] [pid 123784:tid 123974] [client 196.12.128.158:49770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzaAAAADg"]
[Tue Aug 18 13:00:14.222587 2026] [security2:error] [pid 123784:tid 123974] [client 196.12.128.158:49770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzaAAAADg"]
[Tue Aug 18 13:00:14.223133 2026] [security2:error] [pid 123784:tid 123800] [remote 162.214.205.212:38440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ancavisi.com.br"] [uri "/wp-login.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzaQAALws"]
[Tue Aug 18 13:00:14.299664 2026] [security2:error] [pid 123784:tid 123929] [client 68.155.154.236:25385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzbgAAAAs"]
[Tue Aug 18 13:00:14.351938 2026] [security2:error] [pid 123784:tid 123940] [client 20.116.17.175:60428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzcAAAABY"]
[Tue Aug 18 13:00:14.361362 2026] [security2:error] [pid 123784:tid 123924] [client 20.226.56.190:8284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/iu.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzcgAAAAY"]
[Tue Aug 18 13:00:14.364717 2026] [authz_core:error] [pid 123784:tid 123818] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:14.365174 2026] [authz_core:error] [pid 123784:tid 123818] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:14.387020 2026] [security2:error] [pid 123784:tid 123915] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/about.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzcwAASn4"]
[Tue Aug 18 13:00:14.388660 2026] [security2:error] [pid 123784:tid 123986] [client 68.155.156.252:7220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzdAAAAEQ"]
[Tue Aug 18 13:00:14.396119 2026] [security2:error] [pid 123784:tid 123993] [client 213.35.127.232:56804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzdQAAAEs"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:14.406575 2026] [security2:error] [pid 123784:tid 123957] [client 168.62.48.100:18128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzdgAAACc"]
[Tue Aug 18 13:00:14.412429 2026] [security2:error] [pid 123784:tid 124041] [client 158.23.17.4:8708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/pd.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzeAAAAHs"]
[Tue Aug 18 13:00:14.508548 2026] [security2:error] [pid 123784:tid 123918] [client 40.74.65.169:60183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/222.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzfAAAAAA"]
[Tue Aug 18 13:00:14.526379 2026] [security2:error] [pid 123784:tid 123927] [client 158.158.74.177:16132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/upload/autoload_classmap.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzfgAAAAk"]
[Tue Aug 18 13:00:14.629915 2026] [security2:error] [pid 123784:tid 124018] [client 20.116.17.175:60008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/ccou.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzgAAAAGQ"]
[Tue Aug 18 13:00:14.636880 2026] [security2:error] [pid 123784:tid 123944] [client 20.203.138.185:32216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/koiy.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzgQAAABo"]
[Tue Aug 18 13:00:14.650774 2026] [security2:error] [pid 123784:tid 123960] [client 132.196.30.78:2776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/rip.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzggAAACo"]
[Tue Aug 18 13:00:14.661528 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:14.661802 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:14.695340 2026] [security2:error] [pid 123784:tid 124008] [client 68.155.154.236:27558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzhQAAAFo"]
[Tue Aug 18 13:00:14.710734 2026] [security2:error] [pid 123784:tid 123801] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/admin.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzhgAAYAw"]
[Tue Aug 18 13:00:14.723147 2026] [security2:error] [pid 123784:tid 123945] [client 168.62.48.100:18097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzhwAAABs"]
[Tue Aug 18 13:00:14.723181 2026] [security2:error] [pid 123784:tid 124005] [client 20.226.56.190:10574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/pk.php"] [unique_id "aoSBjmwDnJBNj2tDbYbziAAAAFc"]
[Tue Aug 18 13:00:14.742278 2026] [autoindex:error] [pid 123784:tid 123988] [client 20.79.204.6:14138] AH01276: Cannot serve directory /home4/soraya/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:14.768460 2026] [security2:error] [pid 123784:tid 124024] [client 197.184.64.235:41954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzjQAAAGo"]
[Tue Aug 18 13:00:14.768562 2026] [security2:error] [pid 123784:tid 124024] [client 197.184.64.235:41954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzjQAAAGo"]
[Tue Aug 18 13:00:14.788019 2026] [security2:error] [pid 123784:tid 124022] [client 158.23.17.4:11438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/vu.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzjwAAAGg"]
[Tue Aug 18 13:00:14.818710 2026] [security2:error] [pid 123784:tid 123934] [client 68.155.156.252:61814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzkQAAABA"]
[Tue Aug 18 13:00:14.869687 2026] [security2:error] [pid 123784:tid 123942] [client 20.65.98.162:45576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/mac.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzlQAAABg"]
[Tue Aug 18 13:00:14.910918 2026] [security2:error] [pid 123784:tid 123980] [client 20.116.17.175:60024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/crgio.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzmAAAAD4"]
[Tue Aug 18 13:00:14.928830 2026] [security2:error] [pid 123784:tid 123958] [client 20.226.56.190:11586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ge.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzmQAAACg"]
[Tue Aug 18 13:00:14.947236 2026] [security2:error] [pid 123784:tid 123989] [client 20.79.204.6:14138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzmgAAAEc"]
[Tue Aug 18 13:00:14.953131 2026] [security2:error] [pid 123784:tid 124012] [client 172.202.39.151:44592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/0x.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzmwAAAF4"]
[Tue Aug 18 13:00:14.955525 2026] [security2:error] [pid 123784:tid 123974] [client 20.250.27.191:43495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBjmwDnJBNj2tDbYbznQAAADg"]
[Tue Aug 18 13:00:14.962068 2026] [authz_core:error] [pid 123784:tid 123868] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:14.962364 2026] [authz_core:error] [pid 123784:tid 123868] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:15.035282 2026] [security2:error] [pid 123784:tid 124039] [client 20.226.56.190:6384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kl.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzoQAAAHk"]
[Tue Aug 18 13:00:15.041071 2026] [security2:error] [pid 123784:tid 123809] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/edit.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzogAAbxQ"]
[Tue Aug 18 13:00:15.053895 2026] [security2:error] [pid 123784:tid 123986] [client 20.226.56.190:20902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gs.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzpQAAAEQ"]
[Tue Aug 18 13:00:15.059266 2026] [security2:error] [pid 123784:tid 123993] [client 168.62.48.100:18075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzpgAAAEs"]
[Tue Aug 18 13:00:15.100252 2026] [security2:error] [pid 123784:tid 123939] [client 158.23.17.4:54728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/74.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzqgAAABU"]
[Tue Aug 18 13:00:15.101662 2026] [security2:error] [pid 123784:tid 124031] [client 20.226.56.190:42433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/lw.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzqwAAAHE"]
[Tue Aug 18 13:00:15.114187 2026] [security2:error] [pid 123784:tid 123983] [client 172.202.39.151:4682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/aa.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzrAAAAEE"]
[Tue Aug 18 13:00:15.116878 2026] [security2:error] [pid 123784:tid 123921] [client 20.226.56.190:17941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/vj.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzrQAAAAM"]
[Tue Aug 18 13:00:15.162156 2026] [security2:error] [pid 123784:tid 124004] [client 20.226.56.190:10567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/mimes.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzrgAAAFY"]
[Tue Aug 18 13:00:15.165091 2026] [security2:error] [pid 123784:tid 123935] [client 158.23.17.4:29489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/th.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzrwAAABE"]
[Tue Aug 18 13:00:15.175076 2026] [security2:error] [pid 123784:tid 123965] [client 158.158.74.177:16188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/uploads/admin.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzsAAAAC8"]
[Tue Aug 18 13:00:15.186792 2026] [security2:error] [pid 123784:tid 123954] [client 40.74.65.169:60231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/mac.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzsgAAACQ"]
[Tue Aug 18 13:00:15.188000 2026] [security2:error] [pid 123784:tid 124026] [client 20.116.17.175:60452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzswAAAGw"]
[Tue Aug 18 13:00:15.193913 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.56.190:11629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ni.php"] [unique_id "aoSBj2wDnJBNj2tDbYbztAAAAH8"]
[Tue Aug 18 13:00:15.217518 2026] [security2:error] [pid 123784:tid 123936] [client 20.226.56.190:17923] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSBj2wDnJBNj2tDbYbztQAAABI"]
[Tue Aug 18 13:00:15.217615 2026] [security2:error] [pid 123784:tid 123936] [client 20.226.56.190:17923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSBj2wDnJBNj2tDbYbztQAAABI"]
[Tue Aug 18 13:00:15.219031 2026] [security2:error] [pid 123784:tid 123996] [client 68.155.156.252:59758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/media.php"] [unique_id "aoSBj2wDnJBNj2tDbYbztgAAAE4"]
[Tue Aug 18 13:00:15.256594 2026] [security2:error] [pid 123784:tid 124033] [client 68.155.156.252:40953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/sf.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzuAAAAHM"]
[Tue Aug 18 13:00:15.262363 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:15.262512 2026] [security2:error] [pid 123784:tid 124021] [client 190.92.174.183:50762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/wp-login.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzuQAAAGc"]
[Tue Aug 18 13:00:15.262613 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:15.277906 2026] [security2:error] [pid 123784:tid 123946] [client 132.196.30.78:16130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/p.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzuwAAABw"]
[Tue Aug 18 13:00:15.283076 2026] [security2:error] [pid 123784:tid 123978] [client 20.226.56.190:8302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/88.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzvAAAADw"]
[Tue Aug 18 13:00:15.323541 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:33422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/gi.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzvgAAAH0"]
[Tue Aug 18 13:00:15.324541 2026] [security2:error] [pid 123784:tid 123945] [client 20.226.56.190:45247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/hj.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzvwAAABs"]
[Tue Aug 18 13:00:15.354233 2026] [security2:error] [pid 123784:tid 124025] [client 68.155.154.236:27579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzwgAAAGs"]
[Tue Aug 18 13:00:15.356602 2026] [security2:error] [pid 123784:tid 123964] [client 168.62.48.100:17991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzwwAAAC4"]
[Tue Aug 18 13:00:15.360098 2026] [security2:error] [pid 123784:tid 124030] [client 20.250.27.191:34831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzxAAAAHA"]
[Tue Aug 18 13:00:15.389295 2026] [security2:error] [pid 123784:tid 124037] [client 20.226.56.190:40188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ij.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzxgAAAHc"]
[Tue Aug 18 13:00:15.396763 2026] [security2:error] [pid 123784:tid 123937] [client 20.250.13.23:42700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/u.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzxwAAABM"]
[Tue Aug 18 13:00:15.416362 2026] [security2:error] [pid 123784:tid 123968] [client 213.35.127.232:57023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzyQAAADI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:15.430677 2026] [security2:error] [pid 123784:tid 123967] [client 20.226.56.190:8291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ud.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzygAAADE"]
[Tue Aug 18 13:00:15.466069 2026] [security2:error] [pid 123784:tid 123863] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-content/admin.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzywAAZko"]
[Tue Aug 18 13:00:15.490872 2026] [security2:error] [pid 123784:tid 123922] [client 20.226.56.190:8292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ip.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzzAAAAAQ"]
[Tue Aug 18 13:00:15.492526 2026] [security2:error] [pid 123784:tid 123980] [client 20.116.17.175:60014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/css.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzzQAAAD4"]
[Tue Aug 18 13:00:15.505114 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.56.190:17945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/99.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzzgAAAEc"]
[Tue Aug 18 13:00:15.556993 2026] [security2:error] [pid 123784:tid 123988] [client 20.79.204.6:14030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzzwAAAEY"]
[Tue Aug 18 13:00:15.573348 2026] [security2:error] [pid 123784:tid 123995] [client 20.226.56.190:6364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/er.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz0AAAAE0"]
[Tue Aug 18 13:00:15.627682 2026] [security2:error] [pid 123784:tid 124041] [client 68.155.156.252:32278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/admin.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz0wAAAHs"]
[Tue Aug 18 13:00:15.639119 2026] [security2:error] [pid 123784:tid 123933] [client 20.226.56.190:8263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/qk.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz1AAAAA8"]
[Tue Aug 18 13:00:15.641920 2026] [security2:error] [pid 123784:tid 123931] [client 168.62.48.100:18164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz1QAAAA0"]
[Tue Aug 18 13:00:15.666123 2026] [security2:error] [pid 123784:tid 123966] [client 20.226.56.190:40187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz1gAAADA"]
[Tue Aug 18 13:00:15.690615 2026] [authz_core:error] [pid 123784:tid 123901] [remote 57.141.22.13:29544] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:15.690882 2026] [authz_core:error] [pid 123784:tid 123901] [remote 57.141.22.13:29544] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:15.697807 2026] [security2:error] [pid 123784:tid 123935] [client 20.226.56.190:40130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fs.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz2AAAABE"]
[Tue Aug 18 13:00:15.736207 2026] [security2:error] [pid 123784:tid 123969] [client 172.202.39.151:44595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/zxz.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz2QAAADM"]
[Tue Aug 18 13:00:15.779064 2026] [security2:error] [pid 123784:tid 123927] [client 20.226.56.190:18598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/rb.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz2gAAAAk"]
[Tue Aug 18 13:00:15.783431 2026] [security2:error] [pid 123784:tid 123996] [client 20.116.17.175:58170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz2wAAAE4"]
[Tue Aug 18 13:00:15.803251 2026] [security2:error] [pid 123784:tid 123963] [client 68.155.154.236:27572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz3AAAAC0"]
[Tue Aug 18 13:00:15.810163 2026] [security2:error] [pid 123784:tid 124033] [client 158.23.17.4:9296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/admin404.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz3QAAAHM"]
[Tue Aug 18 13:00:15.847487 2026] [security2:error] [pid 123784:tid 124021] [client 158.23.17.4:57222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/pz.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz4AAAAGc"]
[Tue Aug 18 13:00:15.859337 2026] [security2:error] [pid 123784:tid 123982] [client 20.226.56.190:6363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/37.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz4QAAAEA"]
[Tue Aug 18 13:00:15.861643 2026] [security2:error] [pid 123784:tid 124018] [client 40.74.65.169:60268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ops.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz4gAAAGQ"]
[Tue Aug 18 13:00:15.869396 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:15.869648 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:15.888463 2026] [security2:error] [pid 123784:tid 123984] [client 132.196.30.78:9956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/php.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz5gAAAEI"]
[Tue Aug 18 13:00:15.913160 2026] [security2:error] [pid 123784:tid 123817] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/inputs.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz6AAAPBw"]
[Tue Aug 18 13:00:15.931447 2026] [security2:error] [pid 123784:tid 124032] [client 158.23.17.4:40424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ic.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz6QAAAHI"]
[Tue Aug 18 13:00:15.947739 2026] [security2:error] [pid 123784:tid 124014] [client 20.250.27.191:63221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/system_log.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz6gAAAGA"]
[Tue Aug 18 13:00:15.949016 2026] [security2:error] [pid 123784:tid 124043] [client 20.226.56.190:42447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/md.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz6wAAAH0"]
[Tue Aug 18 13:00:15.961782 2026] [security2:error] [pid 123784:tid 123977] [client 20.226.56.190:42451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/iy.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz7AAAADs"]
[Tue Aug 18 13:00:15.980792 2026] [security2:error] [pid 123784:tid 123961] [client 168.62.48.100:18071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz7QAAACs"]
[Tue Aug 18 13:00:15.987376 2026] [security2:error] [pid 123784:tid 123964] [client 20.100.169.31:17251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz7gAAAC4"]
[Tue Aug 18 13:00:15.991716 2026] [security2:error] [pid 123784:tid 123952] [client 172.202.39.151:4425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/0x.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz7wAAACI"]
[Tue Aug 18 13:00:15.994260 2026] [security2:error] [pid 123784:tid 123971] [client 20.203.138.185:46431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/iko.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz8AAAADU"]
[Tue Aug 18 13:00:16.022538 2026] [security2:error] [pid 123784:tid 124040] [client 172.202.39.151:44102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/cc.php"] [unique_id "aoSBkGwDnJBNj2tDbYbz8QAAAHo"]
[Tue Aug 18 13:00:16.042122 2026] [security2:error] [pid 123784:tid 124037] [client 20.226.56.190:40189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/og.php"] [unique_id "aoSBkGwDnJBNj2tDbYbz8gAAAHc"]
[Tue Aug 18 13:00:16.077580 2026] [security2:error] [pid 123784:tid 123967] [client 68.155.156.252:59741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/mac.php"] [unique_id "aoSBkGwDnJBNj2tDbYbz9gAAADE"]
[Tue Aug 18 13:00:16.122173 2026] [security2:error] [pid 123784:tid 123930] [client 20.116.17.175:60004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/epinyins.php"] [unique_id "aoSBkGwDnJBNj2tDbYbz-AAAAAw"]
[Tue Aug 18 13:00:16.149046 2026] [security2:error] [pid 123784:tid 123973] [client 20.226.56.190:41950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/lp.php"] [unique_id "aoSBkGwDnJBNj2tDbYbz-QAAADc"]
[Tue Aug 18 13:00:16.161963 2026] [security2:error] [pid 123784:tid 123945] [client 20.79.204.6:14140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/f7.php"] [unique_id "aoSBkGwDnJBNj2tDbYbz_AAAABs"]
[Tue Aug 18 13:00:16.164483 2026] [security2:error] [pid 123784:tid 123922] [client 20.226.56.190:6367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ey.php"] [unique_id "aoSBkGwDnJBNj2tDbYbz_QAAAAQ"]
[Tue Aug 18 13:00:16.166275 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:16.166561 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:16.187685 2026] [security2:error] [pid 123784:tid 123989] [client 158.23.17.4:60330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/av.php"] [unique_id "aoSBkGwDnJBNj2tDbYbz_gAAAEc"]
[Tue Aug 18 13:00:16.203135 2026] [security2:error] [pid 123784:tid 123990] [client 20.226.56.190:11622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/lv.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0AQAAAEg"]
[Tue Aug 18 13:00:16.225205 2026] [security2:error] [pid 123784:tid 123943] [client 20.226.56.190:13057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/51.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0AgAAABk"]
[Tue Aug 18 13:00:16.258501 2026] [security2:error] [pid 123784:tid 123920] [client 68.155.156.252:40905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/k.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0AwAAAAI"]
[Tue Aug 18 13:00:16.295475 2026] [security2:error] [pid 123784:tid 124005] [client 20.226.56.190:40177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ew.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0BAAAAFc"]
[Tue Aug 18 13:00:16.311101 2026] [security2:error] [pid 123784:tid 124031] [client 172.202.39.151:44482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/www.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0BQAAAHE"]
[Tue Aug 18 13:00:16.323520 2026] [security2:error] [pid 123784:tid 123983] [client 168.62.48.100:18174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0BwAAAEE"]
[Tue Aug 18 13:00:16.354752 2026] [security2:error] [pid 123784:tid 123849] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/av.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0CgAAHjw"]
[Tue Aug 18 13:00:16.391240 2026] [security2:error] [pid 123784:tid 124011] [client 20.226.56.190:8269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/pqr.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0DgAAAF0"]
[Tue Aug 18 13:00:16.401201 2026] [security2:error] [pid 123784:tid 123932] [client 20.116.17.175:60476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/load.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0DwAAAA4"]
[Tue Aug 18 13:00:16.404247 2026] [security2:error] [pid 123784:tid 123981] [client 20.100.169.31:3994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/0x.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0EAAAAD8"]
[Tue Aug 18 13:00:16.413820 2026] [security2:error] [pid 123784:tid 123918] [client 158.23.17.4:44521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/qo.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0EQAAAAA"]
[Tue Aug 18 13:00:16.424126 2026] [security2:error] [pid 123784:tid 124025] [client 86.120.159.145:12085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0EgAAAGs"]
[Tue Aug 18 13:00:16.424241 2026] [security2:error] [pid 123784:tid 124025] [client 86.120.159.145:12085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0EgAAAGs"]
[Tue Aug 18 13:00:16.430495 2026] [security2:error] [pid 123784:tid 123953] [client 213.35.127.232:57236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0EwAAACM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:16.461664 2026] [security2:error] [pid 123784:tid 124026] [client 20.226.56.190:7316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/an.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0FQAAAGw"]
[Tue Aug 18 13:00:16.462254 2026] [security2:error] [pid 123784:tid 124023] [client 158.23.17.4:14016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ue.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0FgAAAGk"]
[Tue Aug 18 13:00:16.466140 2026] [security2:error] [pid 123784:tid 123936] [client 68.155.156.252:50913] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0FwAAABI"]
[Tue Aug 18 13:00:16.466213 2026] [security2:error] [pid 123784:tid 123936] [client 68.155.156.252:50913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0FwAAABI"]
[Tue Aug 18 13:00:16.466682 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:16.466948 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:16.487439 2026] [security2:error] [pid 123784:tid 124015] [client 20.226.56.190:6363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/sy.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0GAAAAGE"]
[Tue Aug 18 13:00:16.538383 2026] [security2:error] [pid 123784:tid 124010] [client 40.74.65.169:60177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/8.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0GgAAAFw"]
[Tue Aug 18 13:00:16.540219 2026] [security2:error] [pid 123784:tid 123982] [client 68.155.154.236:3979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0GwAAAEA"]
[Tue Aug 18 13:00:16.556565 2026] [security2:error] [pid 123784:tid 123960] [client 20.226.56.190:11627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/57.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0HAAAACo"]
[Tue Aug 18 13:00:16.579926 2026] [security2:error] [pid 123784:tid 124036] [client 158.23.17.4:34027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/kk.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0HwAAAHY"]
[Tue Aug 18 13:00:16.605540 2026] [security2:error] [pid 123784:tid 124032] [client 20.226.56.190:6366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ah.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0IAAAAHI"]
[Tue Aug 18 13:00:16.631087 2026] [security2:error] [pid 123784:tid 124043] [client 20.226.56.190:13096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/vw.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0IQAAAH0"]
[Tue Aug 18 13:00:16.663344 2026] [security2:error] [pid 123784:tid 123949] [client 20.250.13.23:39055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0JAAAAB8"]
[Tue Aug 18 13:00:16.692282 2026] [security2:error] [pid 123784:tid 123952] [client 20.116.17.175:12233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0JgAAACI"]
[Tue Aug 18 13:00:16.726461 2026] [security2:error] [pid 123784:tid 123944] [client 168.62.48.100:18058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0JwAAABo"]
[Tue Aug 18 13:00:16.767367 2026] [authz_core:error] [pid 123784:tid 123792] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:16.767664 2026] [authz_core:error] [pid 123784:tid 123792] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:16.776165 2026] [security2:error] [pid 123784:tid 123984] [client 20.79.204.6:13699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/photo.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0KgAAAEI"]
[Tue Aug 18 13:00:16.789104 2026] [security2:error] [pid 123784:tid 123999] [client 20.250.27.191:34838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/pucci.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0KwAAAFE"]
[Tue Aug 18 13:00:16.833449 2026] [security2:error] [pid 123784:tid 124020] [client 20.226.56.190:42491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/lj.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0LQAAAGY"]
[Tue Aug 18 13:00:16.855744 2026] [security2:error] [pid 123784:tid 123893] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/classwithtostring.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0LgAAGGg"]
[Tue Aug 18 13:00:16.882132 2026] [security2:error] [pid 123784:tid 123945] [client 20.118.133.132:13943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/ai.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0LwAAABs"]
[Tue Aug 18 13:00:16.909639 2026] [security2:error] [pid 123784:tid 124029] [client 68.155.154.236:25389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0MgAAAG8"]
[Tue Aug 18 13:00:16.919748 2026] [security2:error] [pid 123784:tid 124035] [client 20.79.204.6:10734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/goods.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0MwAAAHU"]
[Tue Aug 18 13:00:16.929116 2026] [security2:error] [pid 123784:tid 123974] [client 20.226.56.190:15223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kh.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0NAAAADg"]
[Tue Aug 18 13:00:16.984342 2026] [security2:error] [pid 123784:tid 123988] [client 20.116.17.175:60009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/ty.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0NgAAAEY"]
[Tue Aug 18 13:00:16.992379 2026] [security2:error] [pid 123784:tid 123943] [client 68.155.156.252:50913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/coffee.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0NwAAABk"]
[Tue Aug 18 13:00:16.997363 2026] [security2:error] [pid 123784:tid 123959] [client 168.62.48.100:18120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0OAAAACk"]
[Tue Aug 18 13:00:17.001574 2026] [security2:error] [pid 123784:tid 123998] [client 172.202.39.151:44565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wicked.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0OQAAAFA"]
[Tue Aug 18 13:00:17.008245 2026] [security2:error] [pid 123784:tid 123958] [client 20.203.138.185:16783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/raw.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0OgAAACg"]
[Tue Aug 18 13:00:17.027378 2026] [security2:error] [pid 123784:tid 124002] [client 20.100.169.31:3796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/222.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0PAAAAFQ"]
[Tue Aug 18 13:00:17.072031 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:17.072286 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:17.072953 2026] [security2:error] [pid 123784:tid 123983] [client 20.226.56.190:8312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/jb.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0PgAAAEE"]
[Tue Aug 18 13:00:17.127840 2026] [security2:error] [pid 123784:tid 124028] [client 172.202.39.151:4675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/zxz.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0PwAAAG4"]
[Tue Aug 18 13:00:17.164366 2026] [security2:error] [pid 123784:tid 123932] [client 20.226.56.190:8312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/do.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0QQAAAA4"]
[Tue Aug 18 13:00:17.176294 2026] [security2:error] [pid 123784:tid 124016] [client 20.226.56.190:40142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/yw.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0QgAAAGI"]
[Tue Aug 18 13:00:17.202806 2026] [security2:error] [pid 123784:tid 124026] [client 20.226.56.190:20921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/qh.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0QwAAAGw"]
[Tue Aug 18 13:00:17.220403 2026] [security2:error] [pid 123784:tid 124044] [client 20.226.56.190:21163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/r.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0RQAAAH4"]
[Tue Aug 18 13:00:17.235568 2026] [security2:error] [pid 123784:tid 123982] [client 20.226.56.190:42438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/17.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0RgAAAEA"]
[Tue Aug 18 13:00:17.235592 2026] [security2:error] [pid 123784:tid 123960] [client 40.74.65.169:60189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/biufile.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0RwAAACo"]
[Tue Aug 18 13:00:17.265290 2026] [security2:error] [pid 123784:tid 124031] [client 79.127.164.8:42736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/users.sql"] [unique_id "aoSBkWwDnJBNj2tDbYb0SQAAAHE"], referer: https://medihub.com.br/users.sql
[Tue Aug 18 13:00:17.273327 2026] [security2:error] [pid 123784:tid 124043] [client 20.116.17.175:58136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0SgAAAH0"]
[Tue Aug 18 13:00:17.273799 2026] [security2:error] [pid 123784:tid 124034] [client 68.155.154.236:4050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/first.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0SwAAAHQ"]
[Tue Aug 18 13:00:17.284277 2026] [security2:error] [pid 123784:tid 123977] [client 172.202.39.151:53719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/gecko-new.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0TAAAADs"]
[Tue Aug 18 13:00:17.297631 2026] [security2:error] [pid 123784:tid 123803] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0TgAAcA4"]
[Tue Aug 18 13:00:17.306680 2026] [security2:error] [pid 123784:tid 123952] [client 168.62.48.100:18108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0TwAAACI"]
[Tue Aug 18 13:00:17.312096 2026] [security2:error] [pid 123784:tid 124040] [client 20.226.56.190:21129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ev.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0UAAAAHo"]
[Tue Aug 18 13:00:17.328656 2026] [security2:error] [pid 123784:tid 124017] [client 20.226.56.190:42450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xs.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0UgAAAGM"]
[Tue Aug 18 13:00:17.369115 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:17.369504 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:17.383476 2026] [security2:error] [pid 123784:tid 124025] [client 20.79.204.6:14040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-aa.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0WwAAAGs"]
[Tue Aug 18 13:00:17.398791 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.56.190:11641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/lmfi2.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0XQAAAH8"]
[Tue Aug 18 13:00:17.403364 2026] [security2:error] [pid 123784:tid 123951] [client 158.23.17.4:38870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/sd.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0XgAAACE"]
[Tue Aug 18 13:00:17.417247 2026] [security2:error] [pid 123784:tid 123980] [client 68.155.156.252:59753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0XwAAAD4"]
[Tue Aug 18 13:00:17.425215 2026] [security2:error] [pid 123784:tid 124029] [client 20.226.56.190:42461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fd.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0YgAAAG8"]
[Tue Aug 18 13:00:17.445604 2026] [security2:error] [pid 123784:tid 123948] [client 213.35.127.232:57466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0ZAAAAB4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:17.446129 2026] [security2:error] [pid 123784:tid 124019] [client 20.226.56.190:10606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/info2.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0ZQAAAGU"]
[Tue Aug 18 13:00:17.452764 2026] [security2:error] [pid 123784:tid 123988] [client 172.202.39.151:40339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0ZgAAAEY"]
[Tue Aug 18 13:00:17.461547 2026] [security2:error] [pid 123784:tid 123959] [client 68.221.73.131:56491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/akismet.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0ZwAAACk"]
[Tue Aug 18 13:00:17.489845 2026] [security2:error] [pid 123784:tid 123978] [client 20.250.13.23:7752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/h.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0egAAADw"]
[Tue Aug 18 13:00:17.506062 2026] [security2:error] [pid 123784:tid 124002] [client 158.23.17.4:51189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ag.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0fQAAAFQ"]
[Tue Aug 18 13:00:17.596105 2026] [security2:error] [pid 123784:tid 124000] [client 20.116.17.175:58147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/dot.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0jgAAAFI"]
[Tue Aug 18 13:00:17.600057 2026] [security2:error] [pid 123784:tid 124042] [client 20.226.56.190:45242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/sx.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0jwAAAHw"]
[Tue Aug 18 13:00:17.605841 2026] [security2:error] [pid 123784:tid 124038] [client 49.13.130.29:7646] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.saojudas.com.br"] [uri "/index.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0JQAAAHg"], referer: https://www.saojudas.com.br/
[Tue Aug 18 13:00:17.605913 2026] [security2:error] [pid 123784:tid 123965] [client 128.140.106.114:34940] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.saojudas.com.br"] [uri "/index.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0WgAAAC8"], referer: https://www.saojudas.com.br
[Tue Aug 18 13:00:17.644358 2026] [security2:error] [pid 123784:tid 123928] [client 168.62.48.100:18161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0kgAAAAo"]
[Tue Aug 18 13:00:17.644375 2026] [security2:error] [pid 123784:tid 123926] [client 20.250.27.191:63198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-temp.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0kwAAAAg"]
[Tue Aug 18 13:00:17.651181 2026] [security2:error] [pid 123784:tid 123968] [client 158.23.17.4:44826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/phpcheck.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0lAAAADI"]
[Tue Aug 18 13:00:17.663624 2026] [security2:error] [pid 123784:tid 124013] [client 20.100.169.31:4026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/aa.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0lQAAAF8"]
[Tue Aug 18 13:00:17.672905 2026] [security2:error] [pid 123784:tid 123920] [client 102.213.179.104:62609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0lgAAAAI"]
[Tue Aug 18 13:00:17.673001 2026] [security2:error] [pid 123784:tid 123920] [client 102.213.179.104:62609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0lgAAAAI"]
[Tue Aug 18 13:00:17.688268 2026] [security2:error] [pid 123784:tid 123935] [client 20.226.56.190:7304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/nu.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0lwAAABE"]
[Tue Aug 18 13:00:17.738760 2026] [security2:error] [pid 123784:tid 124016] [client 20.65.98.162:55171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/ops.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0mAAAAGI"]
[Tue Aug 18 13:00:17.760730 2026] [security2:error] [pid 123784:tid 123954] [client 20.226.56.190:42475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ko.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0mQAAACQ"]
[Tue Aug 18 13:00:17.768696 2026] [security2:error] [pid 123784:tid 123905] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-blog.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0mwAAbHQ"]
[Tue Aug 18 13:00:17.769861 2026] [security2:error] [pid 123784:tid 123942] [client 97.74.89.162:35632] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "massagemrelax.com"] [uri "/wp-json/batch/v1"] [unique_id "aoSBkWwDnJBNj2tDbYb0mgAAABg"]
[Tue Aug 18 13:00:17.796042 2026] [security2:error] [pid 123784:tid 124027] [client 4.232.94.69:17521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/alfa.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0nAAAAG0"]
[Tue Aug 18 13:00:17.815077 2026] [security2:error] [pid 123784:tid 124001] [client 68.155.156.252:51278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0nQAAAFM"]
[Tue Aug 18 13:00:17.820044 2026] [security2:error] [pid 123784:tid 124008] [client 135.225.78.186:60383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/k.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0ngAAAFo"]
[Tue Aug 18 13:00:17.844605 2026] [security2:error] [pid 123784:tid 124043] [client 20.226.56.190:41944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/pl.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0oAAAAH0"]
[Tue Aug 18 13:00:17.854994 2026] [security2:error] [pid 123784:tid 123961] [client 20.226.56.190:20909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/env.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0oQAAACs"]
[Tue Aug 18 13:00:17.866573 2026] [security2:error] [pid 123784:tid 123969] [client 20.226.56.190:21147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/mz.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0ogAAADM"]
[Tue Aug 18 13:00:17.880364 2026] [security2:error] [pid 123784:tid 124030] [client 20.226.56.190:17971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ft.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0owAAAHA"]
[Tue Aug 18 13:00:17.889448 2026] [security2:error] [pid 123784:tid 124040] [client 20.116.17.175:60019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/005.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0pAAAAHo"]
[Tue Aug 18 13:00:17.894989 2026] [security2:error] [pid 123784:tid 124007] [client 20.226.56.190:42494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/h.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0pQAAAFk"]
[Tue Aug 18 13:00:17.909979 2026] [security2:error] [pid 123784:tid 123971] [client 40.74.65.169:60245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/coffexium.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0pwAAADU"]
[Tue Aug 18 13:00:17.919819 2026] [security2:error] [pid 123784:tid 123937] [client 168.62.48.100:18122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0qAAAABM"]
[Tue Aug 18 13:00:17.940505 2026] [fcgid:warn] [pid 123784:tid 123934] (70014)End of file found: [client 199.45.155.87:40250] mod_fcgid: can't get data from http client
[Tue Aug 18 13:00:17.971640 2026] [authz_core:error] [pid 123784:tid 123828] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:17.971923 2026] [authz_core:error] [pid 123784:tid 123828] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:17.998609 2026] [security2:error] [pid 123784:tid 124021] [client 20.79.204.6:14125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/d.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0qwAAAGc"]
[Tue Aug 18 13:00:18.037019 2026] [security2:error] [pid 123784:tid 124025] [client 172.202.39.151:44495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0rQAAAGs"]
[Tue Aug 18 13:00:18.058288 2026] [security2:error] [pid 123784:tid 123951] [client 68.155.154.236:27557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0rgAAACE"]
[Tue Aug 18 13:00:18.122770 2026] [security2:error] [pid 123784:tid 123948] [client 20.203.138.185:11020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/05.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0sQAAAB4"]
[Tue Aug 18 13:00:18.130206 2026] [security2:error] [pid 123784:tid 123988] [client 20.250.27.191:40129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0swAAAEY"]
[Tue Aug 18 13:00:18.153359 2026] [security2:error] [pid 123784:tid 123883] [remote 91.86.16.6:46188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.16.86.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/wp-login.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0tAAAKV4"]
[Tue Aug 18 13:00:18.154763 2026] [security2:error] [pid 123784:tid 123958] [client 158.23.17.4:63996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/km.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0tQAAACg"]
[Tue Aug 18 13:00:18.172936 2026] [security2:error] [pid 123784:tid 123995] [client 20.116.17.175:59984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/v2.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0twAAAE0"]
[Tue Aug 18 13:00:18.202567 2026] [security2:error] [pid 123784:tid 124002] [client 168.62.48.100:18130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0uAAAAFQ"]
[Tue Aug 18 13:00:18.207307 2026] [security2:error] [pid 123784:tid 123986] [client 158.23.17.4:47616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/lr.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0uQAAAEQ"]
[Tue Aug 18 13:00:18.272078 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:18.272328 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:18.286233 2026] [security2:error] [pid 123784:tid 123965] [client 68.155.156.252:39836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/yj09.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0uwAAAC8"]
[Tue Aug 18 13:00:18.289569 2026] [security2:error] [pid 123784:tid 124037] [client 20.100.169.31:3989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/abcd.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0vwAAAHc"]
[Tue Aug 18 13:00:18.347582 2026] [security2:error] [pid 123784:tid 123918] [client 158.23.17.4:60296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ig.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0wQAAAAA"]
[Tue Aug 18 13:00:18.450875 2026] [security2:error] [pid 123784:tid 123936] [client 20.116.17.175:60450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wkl.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0xgAAABI"]
[Tue Aug 18 13:00:18.460422 2026] [security2:error] [pid 123784:tid 124019] [client 213.35.127.232:57652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0yAAAAGU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:18.483125 2026] [security2:error] [pid 123784:tid 124036] [client 168.62.48.100:17989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0ygAAAHY"]
[Tue Aug 18 13:00:18.536833 2026] [security2:error] [pid 123784:tid 124014] [client 68.155.154.236:25403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0zAAAAGA"]
[Tue Aug 18 13:00:18.552514 2026] [security2:error] [pid 123784:tid 123843] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/adminfuns.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0zQAAdDY"]
[Tue Aug 18 13:00:18.578707 2026] [authz_core:error] [pid 123784:tid 123796] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:18.579179 2026] [authz_core:error] [pid 123784:tid 123796] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:18.587438 2026] [security2:error] [pid 123784:tid 123969] [client 20.250.27.191:45816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/puc.php"] [unique_id "aoSBkmwDnJBNj2tDbYb00gAAADM"]
[Tue Aug 18 13:00:18.594102 2026] [security2:error] [pid 123784:tid 124030] [client 40.74.65.169:60182] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSBkmwDnJBNj2tDbYb00wAAAHA"]
[Tue Aug 18 13:00:18.594178 2026] [security2:error] [pid 123784:tid 124030] [client 40.74.65.169:60182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSBkmwDnJBNj2tDbYb00wAAAHA"]
[Tue Aug 18 13:00:18.601158 2026] [security2:error] [pid 123784:tid 124023] [client 20.79.204.6:14142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSBkmwDnJBNj2tDbYb01AAAAGk"]
[Tue Aug 18 13:00:18.611286 2026] [security2:error] [pid 123784:tid 124040] [client 172.202.39.151:44493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/cah.php"] [unique_id "aoSBkmwDnJBNj2tDbYb01QAAAHo"]
[Tue Aug 18 13:00:18.615924 2026] [security2:error] [pid 123784:tid 123944] [client 68.221.73.131:29026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/admin.php"] [unique_id "aoSBkmwDnJBNj2tDbYb01gAAABo"]
[Tue Aug 18 13:00:18.620404 2026] [security2:error] [pid 123784:tid 124024] [client 158.23.17.4:38278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/dg.php"] [unique_id "aoSBkmwDnJBNj2tDbYb01wAAAGo"]
[Tue Aug 18 13:00:18.626049 2026] [security2:error] [pid 123784:tid 123925] [client 20.104.100.201:61398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBkmwDnJBNj2tDbYb02AAAAAc"]
[Tue Aug 18 13:00:18.682872 2026] [security2:error] [pid 123784:tid 123971] [client 68.155.156.252:7187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/scxy.php"] [unique_id "aoSBkmwDnJBNj2tDbYb02gAAADU"]
[Tue Aug 18 13:00:18.729755 2026] [security2:error] [pid 123784:tid 123941] [client 172.202.39.151:53728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content.php.php"] [unique_id "aoSBkmwDnJBNj2tDbYb02wAAABc"]
[Tue Aug 18 13:00:18.791598 2026] [security2:error] [pid 123784:tid 123930] [client 168.62.48.100:18016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSBkmwDnJBNj2tDbYb03AAAAAw"]
[Tue Aug 18 13:00:18.810023 2026] [security2:error] [pid 123784:tid 123922] [client 20.116.17.175:59975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-asudo.php"] [unique_id "aoSBkmwDnJBNj2tDbYb03gAAAAQ"]
[Tue Aug 18 13:00:18.842949 2026] [security2:error] [pid 123784:tid 124035] [client 20.203.138.185:16769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/public/hi.php"] [unique_id "aoSBkmwDnJBNj2tDbYb04QAAAHU"]
[Tue Aug 18 13:00:18.872588 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:18.872870 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:18.916795 2026] [security2:error] [pid 123784:tid 124018] [client 20.104.100.201:62015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBkmwDnJBNj2tDbYb05gAAAGQ"]
[Tue Aug 18 13:00:18.941491 2026] [security2:error] [pid 123784:tid 123802] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/ms-edit.php"] [unique_id "aoSBkmwDnJBNj2tDbYb05wAAUQ0"]
[Tue Aug 18 13:00:18.945858 2026] [security2:error] [pid 123784:tid 124010] [client 20.100.169.31:4010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/admin.php"] [unique_id "aoSBkmwDnJBNj2tDbYb06AAAAFw"]
[Tue Aug 18 13:00:18.964591 2026] [security2:error] [pid 123784:tid 124016] [client 4.232.94.69:14542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "aoSBkmwDnJBNj2tDbYb06wAAAGI"]
[Tue Aug 18 13:00:19.040003 2026] [security2:error] [pid 123784:tid 123918] [client 158.23.17.4:9335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/mf.php"] [unique_id "aoSBk2wDnJBNj2tDbYb08QAAAAA"]
[Tue Aug 18 13:00:19.066480 2026] [security2:error] [pid 123784:tid 123940] [client 168.62.48.100:5528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/jrpga.php"] [unique_id "aoSBk2wDnJBNj2tDbYb08gAAABY"]
[Tue Aug 18 13:00:19.091919 2026] [security2:error] [pid 123784:tid 123924] [client 20.226.56.190:17982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/40.php"] [unique_id "aoSBk2wDnJBNj2tDbYb08wAAAAY"]
[Tue Aug 18 13:00:19.098645 2026] [security2:error] [pid 123784:tid 124028] [client 20.116.17.175:58145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/az.php"] [unique_id "aoSBk2wDnJBNj2tDbYb09QAAAG4"]
[Tue Aug 18 13:00:19.116816 2026] [security2:error] [pid 123784:tid 123927] [client 68.155.156.252:39843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSBk2wDnJBNj2tDbYb09gAAAAk"]
[Tue Aug 18 13:00:19.146831 2026] [security2:error] [pid 123784:tid 123960] [client 20.226.56.190:15201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ee.php"] [unique_id "aoSBk2wDnJBNj2tDbYb0-AAAACo"]
[Tue Aug 18 13:00:19.167970 2026] [security2:error] [pid 123784:tid 123998] [client 20.226.56.190:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ak.php"] [unique_id "aoSBk2wDnJBNj2tDbYb0-QAAAFA"]
[Tue Aug 18 13:00:19.207075 2026] [security2:error] [pid 123784:tid 124013] [client 20.79.204.6:14113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSBk2wDnJBNj2tDbYb0-wAAAF8"]
[Tue Aug 18 13:00:19.215618 2026] [security2:error] [pid 123784:tid 124033] [client 158.23.17.4:58729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ta.php"] [unique_id "aoSBk2wDnJBNj2tDbYb0_AAAAHM"]
[Tue Aug 18 13:00:19.223311 2026] [security2:error] [pid 123784:tid 123983] [client 85.208.96.204:57770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754458104/1756598400/"] [unique_id "aoSBk2wDnJBNj2tDbYb0_gAAAEE"]
[Tue Aug 18 13:00:19.223461 2026] [security2:error] [pid 123784:tid 123983] [client 85.208.96.204:57770] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754458104/1756598400/"] [unique_id "aoSBk2wDnJBNj2tDbYb0_gAAAEE"]
[Tue Aug 18 13:00:19.236106 2026] [security2:error] [pid 123784:tid 124040] [client 20.250.27.191:43487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/8.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1AAAAAHo"]
[Tue Aug 18 13:00:19.268048 2026] [security2:error] [pid 123784:tid 123925] [client 20.226.56.190:6390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/test_info.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1AQAAAAc"]
[Tue Aug 18 13:00:19.286735 2026] [security2:error] [pid 123784:tid 124007] [client 40.74.65.169:60273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/coffee.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1AgAAAFk"]
[Tue Aug 18 13:00:19.287951 2026] [security2:error] [pid 123784:tid 123971] [client 20.104.100.201:61378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1AwAAADU"]
[Tue Aug 18 13:00:19.290740 2026] [security2:error] [pid 123784:tid 123915] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/222.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1BQAAE34"]
[Tue Aug 18 13:00:19.310280 2026] [security2:error] [pid 123784:tid 123929] [client 172.202.39.151:4689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/www.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1BgAAAAs"]
[Tue Aug 18 13:00:19.346411 2026] [security2:error] [pid 123784:tid 123984] [client 158.23.17.4:14024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ka.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1BwAAAEI"]
[Tue Aug 18 13:00:19.362403 2026] [security2:error] [pid 123784:tid 124021] [client 172.202.39.151:44513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/system_log.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1CAAAAGc"]
[Tue Aug 18 13:00:19.384694 2026] [security2:error] [pid 123784:tid 123932] [client 20.116.17.175:58150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/z43agz.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1CQAAAA4"]
[Tue Aug 18 13:00:19.387933 2026] [security2:error] [pid 123784:tid 124020] [client 20.226.56.190:20913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/14.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1CgAAAGY"]
[Tue Aug 18 13:00:19.433363 2026] [security2:error] [pid 123784:tid 123951] [client 20.226.56.190:11634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/tk.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1DQAAACE"]
[Tue Aug 18 13:00:19.438087 2026] [security2:error] [pid 123784:tid 124015] [client 20.79.204.6:10717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/file.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1DgAAAGE"]
[Tue Aug 18 13:00:19.446923 2026] [security2:error] [pid 123784:tid 123922] [client 68.155.154.236:3973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1DwAAAAQ"]
[Tue Aug 18 13:00:19.449377 2026] [security2:error] [pid 123784:tid 124012] [client 68.155.156.252:35146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1EAAAAF4"]
[Tue Aug 18 13:00:19.471697 2026] [security2:error] [pid 123784:tid 123963] [client 213.35.127.232:57841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1EgAAAC0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:19.489775 2026] [security2:error] [pid 123784:tid 124032] [client 172.202.39.151:60158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/01.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1EwAAAHI"]
[Tue Aug 18 13:00:19.530933 2026] [security2:error] [pid 123784:tid 123953] [client 149.34.210.141:52857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1FgAAACM"]
[Tue Aug 18 13:00:19.532735 2026] [security2:error] [pid 123784:tid 124006] [client 20.226.56.190:40151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/hp.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1FwAAAFg"]
[Tue Aug 18 13:00:19.568703 2026] [security2:error] [pid 123784:tid 123943] [client 103.184.169.37:42836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1GQAAABk"]
[Tue Aug 18 13:00:19.569062 2026] [security2:error] [pid 123784:tid 123943] [client 103.184.169.37:42836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1GQAAABk"]
[Tue Aug 18 13:00:19.602420 2026] [security2:error] [pid 123784:tid 124010] [client 158.23.17.4:32567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/bm.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1GwAAAFw"]
[Tue Aug 18 13:00:19.621913 2026] [security2:error] [pid 123784:tid 123801] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/cgi-bin/index.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1HAAAYgw"]
[Tue Aug 18 13:00:19.680846 2026] [security2:error] [pid 123784:tid 124035] [client 20.250.13.23:7712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1HgAAAHU"]
[Tue Aug 18 13:00:19.680862 2026] [security2:error] [pid 123784:tid 123933] [client 20.104.100.201:61389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/cok.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1HwAAAA8"]
[Tue Aug 18 13:00:19.682318 2026] [security2:error] [pid 123784:tid 123920] [client 20.250.27.191:27981] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/1.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1IAAAAAI"]
[Tue Aug 18 13:00:19.682380 2026] [security2:error] [pid 123784:tid 123920] [client 20.250.27.191:27981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/1.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1IAAAAAI"]
[Tue Aug 18 13:00:19.692797 2026] [security2:error] [pid 123784:tid 123918] [client 20.116.17.175:60459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/3.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1IQAAAAA"]
[Tue Aug 18 13:00:19.698662 2026] [security2:error] [pid 123784:tid 123982] [client 20.118.133.132:16602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/w1px.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1IgAAAEA"]
[Tue Aug 18 13:00:19.749389 2026] [security2:error] [pid 123784:tid 123936] [client 20.65.98.162:55216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/8.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1JAAAABI"]
[Tue Aug 18 13:00:19.761769 2026] [security2:error] [pid 123784:tid 123987] [client 20.203.138.185:46419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/get.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1JQAAAEU"]
[Tue Aug 18 13:00:19.776609 2026] [authz_core:error] [pid 123784:tid 123799] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:19.776899 2026] [authz_core:error] [pid 123784:tid 123799] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:19.793838 2026] [security2:error] [pid 123784:tid 124027] [client 20.100.169.31:17231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1KAAAAG0"]
[Tue Aug 18 13:00:19.797137 2026] [security2:error] [pid 123784:tid 123953] [client 149.34.210.141:52857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1FgAAACM"]
[Tue Aug 18 13:00:19.814075 2026] [security2:error] [pid 123784:tid 123965] [client 20.79.204.6:14118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1KgAAAC8"]
[Tue Aug 18 13:00:19.845885 2026] [security2:error] [pid 123784:tid 123977] [client 20.226.56.190:20892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wx.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1LAAAADs"]
[Tue Aug 18 13:00:19.853461 2026] [security2:error] [pid 123784:tid 123972] [client 68.155.156.252:61795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/blurbs.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1LgAAADY"]
[Tue Aug 18 13:00:19.917583 2026] [security2:error] [pid 123784:tid 124004] [client 68.155.154.236:4056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/blog/byp.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1MQAAAFY"]
[Tue Aug 18 13:00:19.978296 2026] [security2:error] [pid 123784:tid 123925] [client 20.116.17.175:60454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/log.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1MgAAAAc"]
[Tue Aug 18 13:00:19.985217 2026] [security2:error] [pid 123784:tid 124007] [client 40.74.65.169:60248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1MwAAAFk"]
[Tue Aug 18 13:00:19.994037 2026] [security2:error] [pid 123784:tid 123971] [client 20.104.100.201:61968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/accesson.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1NAAAADU"]
[Tue Aug 18 13:00:20.013507 2026] [security2:error] [pid 123784:tid 123825] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/BDKR28WP.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1NQAAHSQ"]
[Tue Aug 18 13:00:20.045703 2026] [security2:error] [pid 123784:tid 123923] [client 172.202.39.151:40332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1NwAAAAU"]
[Tue Aug 18 13:00:20.076331 2026] [security2:error] [pid 123784:tid 124024] [client 157.20.138.62:58937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1OQAAAGo"]
[Tue Aug 18 13:00:20.076502 2026] [security2:error] [pid 123784:tid 124024] [client 157.20.138.62:58937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1OQAAAGo"]
[Tue Aug 18 13:00:20.082235 2026] [authz_core:error] [pid 123784:tid 123859] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:20.082520 2026] [authz_core:error] [pid 123784:tid 123859] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:20.110388 2026] [security2:error] [pid 123784:tid 124029] [client 20.250.27.191:35651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/about.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1OgAAAG8"]
[Tue Aug 18 13:00:20.158455 2026] [security2:error] [pid 123784:tid 123932] [client 68.221.73.131:35383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/bajah.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1PAAAAA4"]
[Tue Aug 18 13:00:20.206350 2026] [security2:error] [pid 123784:tid 123957] [client 178.153.171.161:30960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1PgAAACc"]
[Tue Aug 18 13:00:20.206479 2026] [security2:error] [pid 123784:tid 123957] [client 178.153.171.161:30960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1PgAAACc"]
[Tue Aug 18 13:00:20.224540 2026] [security2:error] [pid 123784:tid 124012] [client 68.155.156.252:50898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/bajah.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1PwAAAF4"]
[Tue Aug 18 13:00:20.251127 2026] [security2:error] [pid 123784:tid 123974] [client 158.23.17.4:60327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/34.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1QAAAADg"]
[Tue Aug 18 13:00:20.256787 2026] [security2:error] [pid 123784:tid 123967] [client 20.116.17.175:59970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/ohct.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1QQAAADE"]
[Tue Aug 18 13:00:20.264407 2026] [security2:error] [pid 123784:tid 124025] [client 158.23.17.4:33993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/vu.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1QgAAAGs"]
[Tue Aug 18 13:00:20.310118 2026] [security2:error] [pid 123784:tid 123949] [client 158.23.17.4:49079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ot.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1RQAAAB8"]
[Tue Aug 18 13:00:20.380820 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:20.381076 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:20.414786 2026] [security2:error] [pid 123784:tid 123980] [client 20.79.204.6:14041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1SgAAAD4"]
[Tue Aug 18 13:00:20.428569 2026] [security2:error] [pid 123784:tid 123922] [client 20.100.169.31:17218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/akc.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1SwAAAAQ"]
[Tue Aug 18 13:00:20.461624 2026] [security2:error] [pid 123784:tid 124000] [client 158.23.17.4:38868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ie.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1TAAAAFI"]
[Tue Aug 18 13:00:20.484332 2026] [security2:error] [pid 123784:tid 124017] [client 213.35.127.232:58047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1TgAAAGM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:20.515928 2026] [security2:error] [pid 123784:tid 123939] [client 20.203.138.185:32192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/rpk.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1UQAAABU"]
[Tue Aug 18 13:00:20.529629 2026] [security2:error] [pid 123784:tid 123935] [client 20.250.27.191:34853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/admin.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1UgAAABE"]
[Tue Aug 18 13:00:20.535634 2026] [security2:error] [pid 123784:tid 123933] [client 20.116.17.175:60443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/ot.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1UwAAAA8"]
[Tue Aug 18 13:00:20.546010 2026] [security2:error] [pid 123784:tid 124035] [client 20.104.100.201:61977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/av.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1VAAAAHU"]
[Tue Aug 18 13:00:20.559243 2026] [security2:error] [pid 123784:tid 123920] [client 68.155.156.252:39827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/domvf.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1VgAAAAI"]
[Tue Aug 18 13:00:20.631450 2026] [security2:error] [pid 123784:tid 123924] [client 172.202.39.151:40328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1VwAAAAY"]
[Tue Aug 18 13:00:20.661278 2026] [security2:error] [pid 123784:tid 123987] [client 40.74.65.169:60280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1WQAAAEU"]
[Tue Aug 18 13:00:20.673062 2026] [security2:error] [pid 123784:tid 123937] [client 5.31.227.224:30435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1WgAAABM"]
[Tue Aug 18 13:00:20.673176 2026] [security2:error] [pid 123784:tid 123937] [client 5.31.227.224:30435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1WgAAABM"]
[Tue Aug 18 13:00:20.680312 2026] [authz_core:error] [pid 123784:tid 123807] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:20.680562 2026] [authz_core:error] [pid 123784:tid 123807] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:20.688585 2026] [security2:error] [pid 123784:tid 123806] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1XQAAIxE"]
[Tue Aug 18 13:00:20.735025 2026] [security2:error] [pid 123784:tid 123926] [client 68.155.154.236:27554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1XgAAAAg"]
[Tue Aug 18 13:00:20.764858 2026] [security2:error] [pid 123784:tid 123941] [client 37.40.227.74:57008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1XwAAABc"]
[Tue Aug 18 13:00:20.764991 2026] [security2:error] [pid 123784:tid 123941] [client 37.40.227.74:57008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1XwAAABc"]
[Tue Aug 18 13:00:20.816712 2026] [security2:error] [pid 123784:tid 123981] [client 158.23.17.4:38332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ic.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1YQAAAD8"]
[Tue Aug 18 13:00:20.821574 2026] [security2:error] [pid 123784:tid 123983] [client 20.104.100.201:61953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/kj.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1YgAAAEE"]
[Tue Aug 18 13:00:20.827295 2026] [security2:error] [pid 123784:tid 123968] [client 20.116.17.175:60464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/v5.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1YwAAADI"]
[Tue Aug 18 13:00:20.871008 2026] [security2:error] [pid 123784:tid 123975] [client 20.226.56.190:6337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/dj.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1ZQAAADk"]
[Tue Aug 18 13:00:20.875760 2026] [security2:error] [pid 123784:tid 123944] [client 172.202.39.151:53751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/lv.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1ZgAAABo"]
[Tue Aug 18 13:00:20.884852 2026] [security2:error] [pid 123784:tid 124030] [client 158.23.17.4:60308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/he.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1ZwAAAHA"]
[Tue Aug 18 13:00:20.917809 2026] [security2:error] [pid 123784:tid 123925] [client 20.226.56.190:11642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fa.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1agAAAAc"]
[Tue Aug 18 13:00:20.967429 2026] [security2:error] [pid 123784:tid 123934] [client 20.250.27.191:35678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/edit.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1awAAABA"]
[Tue Aug 18 13:00:20.980440 2026] [security2:error] [pid 123784:tid 123964] [client 20.65.98.162:2202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/scxy.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1bQAAAC4"]
[Tue Aug 18 13:00:20.982678 2026] [authz_core:error] [pid 123784:tid 123902] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:20.982925 2026] [authz_core:error] [pid 123784:tid 123902] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:21.008360 2026] [security2:error] [pid 123784:tid 124038] [client 168.62.48.100:5602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/museu/yhweq.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1bgAAAHg"]
[Tue Aug 18 13:00:21.015999 2026] [security2:error] [pid 123784:tid 124013] [client 20.79.204.6:14025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1bwAAAF8"]
[Tue Aug 18 13:00:21.018333 2026] [security2:error] [pid 123784:tid 123863] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/i.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1cQAAG0o"]
[Tue Aug 18 13:00:21.022851 2026] [security2:error] [pid 123784:tid 123957] [client 20.226.56.190:7321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fb.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1cgAAACc"]
[Tue Aug 18 13:00:21.037557 2026] [security2:error] [pid 123784:tid 124012] [client 20.226.56.190:6351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gw.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1cwAAAF4"]
[Tue Aug 18 13:00:21.063090 2026] [security2:error] [pid 123784:tid 124040] [client 20.100.169.31:17232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/buy.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1dQAAAHo"]
[Tue Aug 18 13:00:21.063813 2026] [security2:error] [pid 123784:tid 124025] [client 20.226.56.190:6348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/sw.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1dgAAAGs"]
[Tue Aug 18 13:00:21.066238 2026] [security2:error] [pid 123784:tid 124041] [client 68.155.156.252:57297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/fpwch.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1dwAAAHs"]
[Tue Aug 18 13:00:21.070745 2026] [security2:error] [pid 123784:tid 124032] [client 158.23.17.4:20395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ih.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1eAAAAHI"]
[Tue Aug 18 13:00:21.074004 2026] [security2:error] [pid 123784:tid 124034] [client 20.118.133.132:16478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/zi-936.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1eQAAAHQ"]
[Tue Aug 18 13:00:21.082501 2026] [security2:error] [pid 123784:tid 123959] [client 172.202.39.151:4422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wicked.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1egAAACk"]
[Tue Aug 18 13:00:21.108762 2026] [security2:error] [pid 123784:tid 123995] [client 20.116.17.175:58144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1ewAAAE0"]
[Tue Aug 18 13:00:21.138367 2026] [security2:error] [pid 123784:tid 123930] [client 188.166.118.89:52844] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "tivinalili.com.br"] [uri "/wp-login.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1fAAAAAw"]
[Tue Aug 18 13:00:21.138481 2026] [security2:error] [pid 123784:tid 123930] [client 188.166.118.89:52844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "tivinalili.com.br"] [uri "/wp-login.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1fAAAAAw"]
[Tue Aug 18 13:00:21.154653 2026] [security2:error] [pid 123784:tid 124002] [client 20.104.100.201:61397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1fgAAAFQ"]
[Tue Aug 18 13:00:21.185060 2026] [security2:error] [pid 123784:tid 123922] [client 68.155.156.252:10971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/82.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1fwAAAAQ"]
[Tue Aug 18 13:00:21.235376 2026] [security2:error] [pid 123784:tid 124000] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1gAAAUiI"]
[Tue Aug 18 13:00:21.321287 2026] [security2:error] [pid 123784:tid 123938] [client 20.203.138.185:10511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-blog.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1hAAAABQ"]
[Tue Aug 18 13:00:21.341332 2026] [security2:error] [pid 123784:tid 124037] [client 40.74.65.169:60172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/yj09.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1hQAAAHc"]
[Tue Aug 18 13:00:21.355044 2026] [security2:error] [pid 123784:tid 123927] [client 68.221.73.131:28062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/ajax.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1hgAAAAk"]
[Tue Aug 18 13:00:21.359755 2026] [security2:error] [pid 123784:tid 123986] [client 45.117.63.159:49263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.63.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1fQAAAEQ"], referer: https://plenitude.com.br/como-a-reprogramacao-mental-equilibra/
[Tue Aug 18 13:00:21.359855 2026] [security2:error] [pid 123784:tid 123986] [client 45.117.63.159:49263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plenitude.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1fQAAAEQ"], referer: https://plenitude.com.br/como-a-reprogramacao-mental-equilibra/
[Tue Aug 18 13:00:21.383925 2026] [security2:error] [pid 123784:tid 123954] [client 172.202.39.151:40322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/abc.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1iAAAACQ"]
[Tue Aug 18 13:00:21.388577 2026] [security2:error] [pid 123784:tid 124019] [client 20.116.17.175:57975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1iQAAAGU"]
[Tue Aug 18 13:00:21.405460 2026] [security2:error] [pid 123784:tid 123817] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/abcd.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1igAAUBw"]
[Tue Aug 18 13:00:21.405703 2026] [security2:error] [pid 123784:tid 123960] [client 20.250.27.191:34841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1iwAAACo"]
[Tue Aug 18 13:00:21.427600 2026] [security2:error] [pid 123784:tid 123921] [client 158.23.17.4:32566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ue.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1jQAAAAM"]
[Tue Aug 18 13:00:21.449817 2026] [security2:error] [pid 123784:tid 124008] [client 20.104.100.201:62003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/png.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1jgAAAFo"]
[Tue Aug 18 13:00:21.498238 2026] [security2:error] [pid 123784:tid 123950] [client 213.35.127.232:58255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1jwAAACA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:21.526056 2026] [security2:error] [pid 123784:tid 123952] [client 138.36.100.162:42146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1kAAAACI"]
[Tue Aug 18 13:00:21.526201 2026] [security2:error] [pid 123784:tid 123952] [client 138.36.100.162:42146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1kAAAACI"]
[Tue Aug 18 13:00:21.542025 2026] [security2:error] [pid 123784:tid 124033] [client 68.155.156.252:32270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/adminner.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1kgAAAHM"]
[Tue Aug 18 13:00:21.594405 2026] [authz_core:error] [pid 123784:tid 123833] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:21.594664 2026] [authz_core:error] [pid 123784:tid 123833] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:21.616585 2026] [security2:error] [pid 123784:tid 123925] [client 158.23.17.4:60331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/gz.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1mAAAAAc"]
[Tue Aug 18 13:00:21.616677 2026] [security2:error] [pid 123784:tid 123953] [client 20.79.204.6:14110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/abc.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1mQAAACM"]
[Tue Aug 18 13:00:21.627641 2026] [security2:error] [pid 123784:tid 123996] [client 223.185.37.47:10693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1mgAAAE4"]
[Tue Aug 18 13:00:21.627717 2026] [security2:error] [pid 123784:tid 123996] [client 223.185.37.47:10693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1mgAAAE4"]
[Tue Aug 18 13:00:21.693807 2026] [security2:error] [pid 123784:tid 123947] [client 20.116.17.175:59980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/dk.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1nAAAAB0"]
[Tue Aug 18 13:00:21.706578 2026] [security2:error] [pid 123784:tid 124014] [client 20.100.169.31:4024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/cong.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1nQAAAGA"]
[Tue Aug 18 13:00:21.723950 2026] [security2:error] [pid 123784:tid 123795] [remote 162.214.205.212:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/wp-login.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1ngAAMwY"]
[Tue Aug 18 13:00:21.725883 2026] [security2:error] [pid 123784:tid 123838] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-manager.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1nwAAQjE"]
[Tue Aug 18 13:00:21.729409 2026] [security2:error] [pid 123784:tid 123914] [remote 103.13.51.160:37800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.51.13.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/wp-login.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1kwAABX0"]
[Tue Aug 18 13:00:21.816314 2026] [security2:error] [pid 123784:tid 124011] [client 20.250.27.191:40165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/inputs.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1oAAAAF0"]
[Tue Aug 18 13:00:21.818705 2026] [security2:error] [pid 123784:tid 124020] [client 20.104.100.201:61979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/ab.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1oQAAAGY"]
[Tue Aug 18 13:00:21.834275 2026] [security2:error] [pid 123784:tid 124013] [client 68.155.154.236:25348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1ogAAAF8"]
[Tue Aug 18 13:00:21.887842 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:21.888105 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:21.967002 2026] [security2:error] [pid 123784:tid 124034] [client 20.116.17.175:58146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/bal.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1pQAAAHQ"]
[Tue Aug 18 13:00:22.030671 2026] [security2:error] [pid 123784:tid 123958] [client 40.74.65.169:60236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/scxy.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1pwAAACg"]
[Tue Aug 18 13:00:22.067090 2026] [security2:error] [pid 123784:tid 124002] [client 172.202.39.151:44553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/akcc.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1qAAAAFQ"]
[Tue Aug 18 13:00:22.080040 2026] [security2:error] [pid 123784:tid 123942] [client 158.23.17.4:25370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/k.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1qQAAABg"]
[Tue Aug 18 13:00:22.103635 2026] [security2:error] [pid 123784:tid 123999] [client 20.226.56.190:18595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gc.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1qwAAAFE"]
[Tue Aug 18 13:00:22.115307 2026] [security2:error] [pid 123784:tid 124039] [client 172.202.39.151:44157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/new.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1rAAAAHk"]
[Tue Aug 18 13:00:22.131739 2026] [security2:error] [pid 123784:tid 124016] [client 168.62.48.100:5569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/nwwha.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1rQAAAGI"]
[Tue Aug 18 13:00:22.145405 2026] [security2:error] [pid 123784:tid 123951] [client 20.65.98.162:56487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/biufile.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1rgAAACE"]
[Tue Aug 18 13:00:22.153597 2026] [security2:error] [pid 123784:tid 123939] [client 20.104.100.201:61952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/12.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1sAAAABU"]
[Tue Aug 18 13:00:22.168872 2026] [security2:error] [pid 123784:tid 123876] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1sQAAWFc"]
[Tue Aug 18 13:00:22.189127 2026] [authz_core:error] [pid 123784:tid 123893] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:22.189402 2026] [authz_core:error] [pid 123784:tid 123893] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:22.227787 2026] [security2:error] [pid 123784:tid 123982] [client 158.23.17.4:33483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/nw.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1twAAAEA"]
[Tue Aug 18 13:00:22.239401 2026] [autoindex:error] [pid 123784:tid 123839] [remote 158.158.74.177:0] AH01276: Cannot serve directory /home1/w32lie55icas3ua4/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:22.247131 2026] [security2:error] [pid 123784:tid 123938] [client 20.116.17.175:60003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/yawa.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1uQAAABQ"]
[Tue Aug 18 13:00:22.248844 2026] [security2:error] [pid 123784:tid 123924] [client 20.250.27.191:35707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/av.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1ugAAAAY"]
[Tue Aug 18 13:00:22.251609 2026] [security2:error] [pid 123784:tid 124005] [client 20.79.204.6:14104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/sf.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1uwAAAFc"]
[Tue Aug 18 13:00:22.308958 2026] [security2:error] [pid 123784:tid 123960] [client 158.23.17.4:31902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/lr.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1wgAAACo"]
[Tue Aug 18 13:00:22.342880 2026] [security2:error] [pid 123784:tid 123946] [client 20.65.98.162:44487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/ws13.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1wwAAABw"]
[Tue Aug 18 13:00:22.366684 2026] [security2:error] [pid 123784:tid 124026] [client 20.100.169.31:17221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1xAAAAGw"]
[Tue Aug 18 13:00:22.429747 2026] [security2:error] [pid 123784:tid 124033] [client 68.221.73.131:59668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1xgAAAHM"]
[Tue Aug 18 13:00:22.443576 2026] [security2:error] [pid 123784:tid 123983] [client 172.202.39.151:4703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/HLA-dd.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1xwAAAEE"]
[Tue Aug 18 13:00:22.477338 2026] [security2:error] [pid 123784:tid 123948] [client 20.104.100.201:61376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/x1da.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1yQAAAB4"]
[Tue Aug 18 13:00:22.511661 2026] [security2:error] [pid 123784:tid 123933] [client 213.35.127.232:58466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1ywAAAA8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:22.539393 2026] [security2:error] [pid 123784:tid 123996] [client 20.116.17.175:60420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1zQAAAE4"]
[Tue Aug 18 13:00:22.592646 2026] [security2:error] [pid 123784:tid 123929] [client 20.203.138.185:16242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/mga.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1zwAAAAs"]
[Tue Aug 18 13:00:22.661204 2026] [security2:error] [pid 123784:tid 123992] [client 20.79.204.6:10744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBlmwDnJBNj2tDbYb10QAAAEo"]
[Tue Aug 18 13:00:22.712033 2026] [security2:error] [pid 123784:tid 123984] [client 20.250.27.191:34820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBlmwDnJBNj2tDbYb10gAAAEI"]
[Tue Aug 18 13:00:22.715285 2026] [security2:error] [pid 123784:tid 123920] [client 4.232.94.69:20017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/sf.php"] [unique_id "aoSBlmwDnJBNj2tDbYb10wAAAAI"]
[Tue Aug 18 13:00:22.717342 2026] [security2:error] [pid 123784:tid 123923] [client 40.74.65.169:60190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBlmwDnJBNj2tDbYb11AAAAAU"]
[Tue Aug 18 13:00:22.731686 2026] [security2:error] [pid 123784:tid 123964] [client 158.23.17.4:8933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ka.php"] [unique_id "aoSBlmwDnJBNj2tDbYb11QAAAC4"]
[Tue Aug 18 13:00:22.752033 2026] [security2:error] [pid 123784:tid 124009] [client 135.225.78.186:43322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/82.php"] [unique_id "aoSBlmwDnJBNj2tDbYb11wAAAFs"]
[Tue Aug 18 13:00:22.752078 2026] [security2:error] [pid 123784:tid 123895] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/cgi-bin/admin.php"] [unique_id "aoSBlmwDnJBNj2tDbYb11gAAb2o"]
[Tue Aug 18 13:00:22.789968 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:22.790240 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:22.796111 2026] [security2:error] [pid 123784:tid 123945] [client 158.23.17.4:57074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/nf.php"] [unique_id "aoSBlmwDnJBNj2tDbYb12QAAABs"]
[Tue Aug 18 13:00:22.822717 2026] [security2:error] [pid 123784:tid 123965] [client 20.116.17.175:60457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/7.php"] [unique_id "aoSBlmwDnJBNj2tDbYb12wAAAC8"]
[Tue Aug 18 13:00:22.826835 2026] [security2:error] [pid 123784:tid 124042] [client 20.104.100.201:61988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/mcs.php"] [unique_id "aoSBlmwDnJBNj2tDbYb13AAAAHw"]
[Tue Aug 18 13:00:22.846489 2026] [security2:error] [pid 123784:tid 124012] [client 172.202.39.151:12744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wk/index.php"] [unique_id "aoSBlmwDnJBNj2tDbYb13QAAAF4"]
[Tue Aug 18 13:00:22.870487 2026] [security2:error] [pid 123784:tid 124040] [client 68.155.154.236:3990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/images/security.php"] [unique_id "aoSBlmwDnJBNj2tDbYb13gAAAHo"]
[Tue Aug 18 13:00:22.902658 2026] [security2:error] [pid 123784:tid 124025] [client 158.23.17.4:9396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/sb.php"] [unique_id "aoSBlmwDnJBNj2tDbYb14AAAAGs"]
[Tue Aug 18 13:00:22.910288 2026] [security2:error] [pid 123784:tid 123969] [client 20.79.204.6:14115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/chosen.php"] [unique_id "aoSBlmwDnJBNj2tDbYb14QAAADM"]
[Tue Aug 18 13:00:22.945124 2026] [security2:error] [pid 123784:tid 124027] [client 168.62.48.100:5593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/opsqt.php"] [unique_id "aoSBlmwDnJBNj2tDbYb14gAAAG0"]
[Tue Aug 18 13:00:23.048626 2026] [security2:error] [pid 123784:tid 123940] [client 20.100.169.31:17261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/db.php"] [unique_id "aoSBl2wDnJBNj2tDbYb15wAAABY"]
[Tue Aug 18 13:00:23.098225 2026] [authz_core:error] [pid 123784:tid 123878] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:23.098685 2026] [authz_core:error] [pid 123784:tid 123878] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:23.119847 2026] [security2:error] [pid 123784:tid 123935] [client 20.250.27.191:35663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBl2wDnJBNj2tDbYb16gAAABE"]
[Tue Aug 18 13:00:23.139517 2026] [security2:error] [pid 123784:tid 123990] [client 20.116.17.175:59990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/ws77.php"] [unique_id "aoSBl2wDnJBNj2tDbYb16wAAAEg"]
[Tue Aug 18 13:00:23.155626 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.56.190:17957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/uq.php"] [unique_id "aoSBl2wDnJBNj2tDbYb17gAAAH8"]
[Tue Aug 18 13:00:23.185070 2026] [security2:error] [pid 123784:tid 123931] [client 20.104.100.201:61405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/adminner.php"] [unique_id "aoSBl2wDnJBNj2tDbYb17wAAAA0"]
[Tue Aug 18 13:00:23.189270 2026] [security2:error] [pid 123784:tid 123938] [client 68.155.156.252:23111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/abcd.php"] [unique_id "aoSBl2wDnJBNj2tDbYb18gAAABQ"]
[Tue Aug 18 13:00:23.223461 2026] [security2:error] [pid 123784:tid 123927] [client 20.226.56.190:6559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/32.php"] [unique_id "aoSBl2wDnJBNj2tDbYb18wAAAAk"]
[Tue Aug 18 13:00:23.261050 2026] [security2:error] [pid 123784:tid 123999] [client 79.127.164.8:42804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/wbboardacplibinserts.bak"] [unique_id "aoSBl2wDnJBNj2tDbYb19AAAAFE"], referer: https://medihub.com.br/wbboardacplibinserts.bak
[Tue Aug 18 13:00:23.301010 2026] [security2:error] [pid 123784:tid 123960] [client 20.226.56.190:17947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/73.php"] [unique_id "aoSBl2wDnJBNj2tDbYb19QAAACo"]
[Tue Aug 18 13:00:23.327989 2026] [security2:error] [pid 123784:tid 123950] [client 158.23.17.4:60339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/xv.php"] [unique_id "aoSBl2wDnJBNj2tDbYb19wAAACA"]
[Tue Aug 18 13:00:23.360585 2026] [security2:error] [pid 123784:tid 123981] [client 158.158.74.177:23695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/lock360.php"] [unique_id "aoSBl2wDnJBNj2tDbYb1-wAAAD8"]
[Tue Aug 18 13:00:23.361468 2026] [security2:error] [pid 123784:tid 124033] [client 158.23.17.4:12523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ot.php"] [unique_id "aoSBl2wDnJBNj2tDbYb1_AAAAHM"]
[Tue Aug 18 13:00:23.389960 2026] [authz_core:error] [pid 123784:tid 123872] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:23.390123 2026] [security2:error] [pid 123784:tid 123919] [client 40.74.65.169:60207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2AAAAAAE"]
[Tue Aug 18 13:00:23.390223 2026] [authz_core:error] [pid 123784:tid 123872] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:23.410185 2026] [autoindex:error] [pid 123784:tid 123975] [client 169.58.72.248:50954] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:23.412325 2026] [security2:error] [pid 123784:tid 124043] [client 156.59.198.135:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "buscacep.linkasites.com.br"] [uri "/livrocep/ms/campo-grande/jardim-mansur/img/rua-jane-rodrigues-pache-jardim-mansur-campo-grande-ms.webp"] [unique_id "aoSBl2wDnJBNj2tDbYb2AgAAAH0"], referer: https://www.icep.com.br/livrocep/ms/campo-grande/jardim-mansur/rua-jane-rodrigues-pache-cep-79051630/
[Tue Aug 18 13:00:23.416488 2026] [security2:error] [pid 123784:tid 123948] [client 20.116.17.175:59993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/read.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2AwAAAB4"]
[Tue Aug 18 13:00:23.421539 2026] [security2:error] [pid 123784:tid 123925] [client 20.226.56.190:17947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ib.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2BAAAAAc"]
[Tue Aug 18 13:00:23.425397 2026] [security2:error] [pid 123784:tid 123968] [client 192.141.172.134:57451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2BQAAADI"]
[Tue Aug 18 13:00:23.425503 2026] [security2:error] [pid 123784:tid 123968] [client 192.141.172.134:57451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2BQAAADI"]
[Tue Aug 18 13:00:23.449347 2026] [security2:error] [pid 123784:tid 123963] [client 68.155.156.252:37107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/dex.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2BgAAAC0"]
[Tue Aug 18 13:00:23.472955 2026] [security2:error] [pid 123784:tid 123929] [client 20.226.56.190:11636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xm.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2CAAAAAs"]
[Tue Aug 18 13:00:23.484239 2026] [security2:error] [pid 123784:tid 123944] [client 20.226.56.190:15230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/zy.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2CQAAABo"]
[Tue Aug 18 13:00:23.485517 2026] [security2:error] [pid 123784:tid 123984] [client 20.104.100.201:61956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/dragonshell.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2CgAAAEI"]
[Tue Aug 18 13:00:23.494750 2026] [security2:error] [pid 123784:tid 123920] [client 158.23.17.4:33530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/xj.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2CwAAAAI"]
[Tue Aug 18 13:00:23.517276 2026] [security2:error] [pid 123784:tid 124003] [client 20.226.56.190:41950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/q.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2DAAAAFU"]
[Tue Aug 18 13:00:23.521445 2026] [security2:error] [pid 123784:tid 124008] [client 20.79.204.6:14136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/u.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2DQAAAFo"]
[Tue Aug 18 13:00:23.531595 2026] [security2:error] [pid 123784:tid 124037] [client 213.35.127.232:58714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2DgAAAHc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:23.540240 2026] [security2:error] [pid 123784:tid 123873] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/simple.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2DwAAb1Q"]
[Tue Aug 18 13:00:23.545470 2026] [security2:error] [pid 123784:tid 124021] [client 20.250.27.191:45820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-blog.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2EAAAAGc"]
[Tue Aug 18 13:00:23.592235 2026] [security2:error] [pid 123784:tid 123997] [client 20.226.56.190:21124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xf.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2EgAAAE8"]
[Tue Aug 18 13:00:23.606818 2026] [security2:error] [pid 123784:tid 124012] [client 20.226.56.190:21124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gb.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2FAAAAF4"]
[Tue Aug 18 13:00:23.611963 2026] [security2:error] [pid 123784:tid 124004] [client 68.155.156.252:42176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/simple.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2FQAAAFY"]
[Tue Aug 18 13:00:23.614617 2026] [security2:error] [pid 123784:tid 123848] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2FgAAHTs"]
[Tue Aug 18 13:00:23.669978 2026] [security2:error] [pid 123784:tid 123993] [client 20.100.169.31:3980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/dropdown.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2FwAAAEs"]
[Tue Aug 18 13:00:23.696579 2026] [security2:error] [pid 123784:tid 124032] [client 20.116.17.175:60440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/albin.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2GAAAAHI"]
[Tue Aug 18 13:00:23.715055 2026] [security2:error] [pid 123784:tid 123957] [client 20.203.138.185:18841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/fs.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2GQAAACc"]
[Tue Aug 18 13:00:23.734910 2026] [security2:error] [pid 123784:tid 124015] [client 20.65.98.162:45596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/coffexium.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2HAAAAGE"]
[Tue Aug 18 13:00:23.735439 2026] [security2:error] [pid 123784:tid 123922] [client 216.244.66.243:55626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/garotas+de+programa+serrinha+ba-0/"] [unique_id "aoSBl2wDnJBNj2tDbYb2HQAAAAQ"]
[Tue Aug 18 13:00:23.735560 2026] [security2:error] [pid 123784:tid 123922] [client 216.244.66.243:55626] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/garotas+de+programa+serrinha+ba-0/"] [unique_id "aoSBl2wDnJBNj2tDbYb2HQAAAAQ"]
[Tue Aug 18 13:00:23.775071 2026] [security2:error] [pid 123784:tid 123966] [client 20.250.13.23:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/a7.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2HwAAADA"]
[Tue Aug 18 13:00:23.838432 2026] [security2:error] [pid 123784:tid 123951] [client 172.202.39.151:44605] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/1.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2IAAAACE"]
[Tue Aug 18 13:00:23.838558 2026] [security2:error] [pid 123784:tid 123951] [client 172.202.39.151:44605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/1.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2IAAAACE"]
[Tue Aug 18 13:00:23.840358 2026] [security2:error] [pid 123784:tid 123939] [client 172.202.39.151:4688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2IQAAABU"]
[Tue Aug 18 13:00:23.845492 2026] [security2:error] [pid 123784:tid 124006] [client 135.225.78.186:27967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/dex.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2IgAAAFg"]
[Tue Aug 18 13:00:23.845945 2026] [security2:error] [pid 123784:tid 123935] [client 20.65.98.162:20824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/btx25.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2IwAAABE"]
[Tue Aug 18 13:00:23.852882 2026] [security2:error] [pid 123784:tid 123990] [client 158.23.17.4:44816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ih.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2JAAAAEg"]
[Tue Aug 18 13:00:23.894651 2026] [security2:error] [pid 123784:tid 123931] [client 20.104.100.201:62009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/setup-config.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2JQAAAA0"]
[Tue Aug 18 13:00:23.940666 2026] [security2:error] [pid 123784:tid 123936] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2KAAAABI"]
[Tue Aug 18 13:00:23.941793 2026] [security2:error] [pid 123784:tid 123998] [client 20.226.56.190:11636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/jp.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2KgAAAFA"]
[Tue Aug 18 13:00:23.976463 2026] [security2:error] [pid 123784:tid 123837] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2KwAAMzA"]
[Tue Aug 18 13:00:23.976858 2026] [security2:error] [pid 123784:tid 123969] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2KwAAMzA"]
[Tue Aug 18 13:00:23.980255 2026] [security2:error] [pid 123784:tid 123961] [client 158.158.74.177:17297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/log.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2LAAAACs"]
[Tue Aug 18 13:00:23.984256 2026] [security2:error] [pid 123784:tid 123977] [client 20.226.56.190:17929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/eq.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2LgAAADs"]
[Tue Aug 18 13:00:23.992725 2026] [authz_core:error] [pid 123784:tid 123844] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:23.992998 2026] [authz_core:error] [pid 123784:tid 123844] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:23.996460 2026] [security2:error] [pid 123784:tid 123952] [client 20.226.56.190:13104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ep.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2MAAAACI"]
[Tue Aug 18 13:00:24.029854 2026] [security2:error] [pid 123784:tid 123925] [client 20.116.17.175:58133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/fw/34.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2MgAAAAc"]
[Tue Aug 18 13:00:24.049084 2026] [security2:error] [pid 123784:tid 123996] [client 172.202.39.151:41109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/222.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2NQAAAE4"]
[Tue Aug 18 13:00:24.067711 2026] [security2:error] [pid 123784:tid 123963] [client 40.74.65.169:60247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2NgAAAC0"]
[Tue Aug 18 13:00:24.081612 2026] [security2:error] [pid 123784:tid 123793] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2NwAARwQ"]
[Tue Aug 18 13:00:24.103479 2026] [security2:error] [pid 123784:tid 123855] [remote 52.167.144.183:58978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memo.ind.br"] [uri "/index.php/atendimento/fale-conosco"] [unique_id "aoSBl2wDnJBNj2tDbYb2KQAASUI"]
[Tue Aug 18 13:00:24.159040 2026] [security2:error] [pid 123784:tid 123920] [client 68.155.156.252:7215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/wp-manager.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2OwAAAAI"]
[Tue Aug 18 13:00:24.169655 2026] [security2:error] [pid 123784:tid 123923] [client 20.226.56.190:10573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/rf.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2PAAAAAU"]
[Tue Aug 18 13:00:24.197322 2026] [security2:error] [pid 123784:tid 124024] [client 20.250.27.191:63176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2PQAAAGo"]
[Tue Aug 18 13:00:24.213491 2026] [security2:error] [pid 123784:tid 124009] [client 20.226.56.190:8267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xynz1.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2PwAAAFs"]
[Tue Aug 18 13:00:24.262190 2026] [security2:error] [pid 123784:tid 124020] [client 20.104.100.201:61385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/f35.update.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2QQAAAGY"]
[Tue Aug 18 13:00:24.279231 2026] [security2:error] [pid 123784:tid 123840] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/chosen.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2QwAALzM"]
[Tue Aug 18 13:00:24.281491 2026] [security2:error] [pid 123784:tid 123841] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/admin.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2RAAAfDQ"]
[Tue Aug 18 13:00:24.284208 2026] [security2:error] [pid 123784:tid 123978] [client 20.79.204.6:10703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/404.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2RQAAADw"]
[Tue Aug 18 13:00:24.290256 2026] [security2:error] [pid 123784:tid 124012] [client 168.62.48.100:5617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/jvcpa.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2SAAAAF4"]
[Tue Aug 18 13:00:24.290786 2026] [security2:error] [pid 123784:tid 123890] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2RwAAVmU"]
[Tue Aug 18 13:00:24.290959 2026] [security2:error] [pid 123784:tid 124004] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2RwAAVmU"]
[Tue Aug 18 13:00:24.292786 2026] [security2:error] [pid 123784:tid 123947] [client 158.23.17.4:63667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ns.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2SQAAAB0"]
[Tue Aug 18 13:00:24.294195 2026] [authz_core:error] [pid 123784:tid 123804] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:24.294458 2026] [authz_core:error] [pid 123784:tid 123804] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:24.295795 2026] [security2:error] [pid 123784:tid 123987] [client 20.226.56.190:41977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/vo.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2SwAAAEU"]
[Tue Aug 18 13:00:24.311911 2026] [security2:error] [pid 123784:tid 123954] [client 158.23.17.4:7187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/iu.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2TQAAACQ"]
[Tue Aug 18 13:00:24.313228 2026] [security2:error] [pid 123784:tid 124025] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2TgAAAGs"]
[Tue Aug 18 13:00:24.323009 2026] [security2:error] [pid 123784:tid 123949] [client 158.23.17.4:57037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/mx.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2UAAAAB8"]
[Tue Aug 18 13:00:24.328169 2026] [security2:error] [pid 123784:tid 124034] [client 20.116.17.175:58128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp9.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2UQAAAHQ"]
[Tue Aug 18 13:00:24.329553 2026] [security2:error] [pid 123784:tid 123992] [client 20.100.169.31:3780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/file.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2UgAAAEo"]
[Tue Aug 18 13:00:24.333875 2026] [security2:error] [pid 123784:tid 124032] [client 20.79.204.6:14098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/customize.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2UwAAAHI"]
[Tue Aug 18 13:00:24.335964 2026] [security2:error] [pid 123784:tid 124032] [client 20.226.56.190:20898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wu.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2VAAAAHI"]
[Tue Aug 18 13:00:24.427467 2026] [security2:error] [pid 123784:tid 124019] [client 45.117.63.159:49368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "plenitude.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2QgAAAGU"], referer: https://plenitude.com.br/como-a-reprogramacao-mental-equilibra/
[Tue Aug 18 13:00:24.457907 2026] [security2:error] [pid 123784:tid 123822] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/public/css.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2WAAAWCE"]
[Tue Aug 18 13:00:24.557596 2026] [security2:error] [pid 123784:tid 124007] [client 3.12.251.153:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thatianysantana.com.br"] [uri "/index.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2PgAAWW4"], referer: https://thatianysantana.com.br/
[Tue Aug 18 13:00:24.559432 2026] [security2:error] [pid 123784:tid 124037] [client 213.35.127.232:58927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2WwAAAHc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:24.567242 2026] [security2:error] [pid 123784:tid 123938] [client 68.155.156.252:32257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/xiugai.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2XAAAABQ"]
[Tue Aug 18 13:00:24.596099 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:24.596367 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:24.625566 2026] [security2:error] [pid 123784:tid 124005] [client 172.202.39.151:40326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2XwAAAFc"]
[Tue Aug 18 13:00:24.632807 2026] [security2:error] [pid 123784:tid 123921] [client 20.250.27.191:63215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2YAAAAAM"]
[Tue Aug 18 13:00:24.633685 2026] [security2:error] [pid 123784:tid 123946] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/admin.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2YgAAABw"]
[Tue Aug 18 13:00:24.637815 2026] [security2:error] [pid 123784:tid 123969] [client 20.116.17.175:60015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/save.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2ZAAAADM"]
[Tue Aug 18 13:00:24.647422 2026] [authz_core:error] [pid 123784:tid 123821] [remote 57.141.22.18:47344] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:24.647854 2026] [authz_core:error] [pid 123784:tid 123821] [remote 57.141.22.18:47344] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:24.651081 2026] [security2:error] [pid 123784:tid 123928] [client 68.155.156.252:37253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/puc.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2ZQAAAAo"]
[Tue Aug 18 13:00:24.653984 2026] [security2:error] [pid 123784:tid 123792] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/classwithtostring.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2ZgAAKwM"]
[Tue Aug 18 13:00:24.664991 2026] [security2:error] [pid 123784:tid 123922] [client 158.158.74.177:17308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/lv.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2ZwAAAAQ"]
[Tue Aug 18 13:00:24.709880 2026] [security2:error] [pid 123784:tid 124026] [client 20.118.133.132:28280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/dcsgumnm.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2aQAAAGw"]
[Tue Aug 18 13:00:24.714511 2026] [security2:error] [pid 123784:tid 123971] [client 20.104.100.201:61390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/bdroot.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2agAAADU"]
[Tue Aug 18 13:00:24.749198 2026] [security2:error] [pid 123784:tid 124043] [client 40.74.65.169:60253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/1xmomo.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2awAAAH0"]
[Tue Aug 18 13:00:24.812626 2026] [security2:error] [pid 123784:tid 123944] [client 196.12.128.158:50537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2bQAAABo"]
[Tue Aug 18 13:00:24.812765 2026] [security2:error] [pid 123784:tid 123944] [client 196.12.128.158:50537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2bQAAABo"]
[Tue Aug 18 13:00:24.815236 2026] [security2:error] [pid 123784:tid 124017] [client 168.62.48.100:5534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2bgAAAGM"]
[Tue Aug 18 13:00:24.846473 2026] [security2:error] [pid 123784:tid 123976] [client 172.202.39.151:4445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/cah.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2bwAAADo"]
[Tue Aug 18 13:00:24.859262 2026] [security2:error] [pid 123784:tid 123897] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/block-supports/"] [unique_id "aoSBmGwDnJBNj2tDbYb2cAAARGw"]
[Tue Aug 18 13:00:24.869661 2026] [security2:error] [pid 123784:tid 123991] [client 172.202.39.151:52925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/chosen.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2cQAAAEk"]
[Tue Aug 18 13:00:24.938295 2026] [security2:error] [pid 123784:tid 123958] [client 68.155.156.252:55963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/wp-load.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2cgAAACg"]
[Tue Aug 18 13:00:24.952053 2026] [security2:error] [pid 123784:tid 123975] [client 20.100.169.31:3810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/goods.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2dAAAADk"]
[Tue Aug 18 13:00:24.959710 2026] [security2:error] [pid 123784:tid 123810] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/als.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2dgAALhU"]
[Tue Aug 18 13:00:24.961711 2026] [security2:error] [pid 123784:tid 124018] [client 197.184.64.235:41955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2dQAAAGQ"]
[Tue Aug 18 13:00:24.961845 2026] [security2:error] [pid 123784:tid 124018] [client 197.184.64.235:41955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2dQAAAGQ"]
[Tue Aug 18 13:00:24.971523 2026] [security2:error] [pid 123784:tid 124008] [client 20.116.17.175:60460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2dwAAAFo"]
[Tue Aug 18 13:00:25.020669 2026] [security2:error] [pid 123784:tid 123973] [client 20.104.100.201:61401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-temp.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2eAAAADc"]
[Tue Aug 18 13:00:25.040659 2026] [security2:error] [pid 123784:tid 124036] [client 158.23.17.4:55215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/45.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2eQAAAHY"]
[Tue Aug 18 13:00:25.054921 2026] [security2:error] [pid 123784:tid 124029] [client 20.250.27.191:28124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/222.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2egAAAG8"]
[Tue Aug 18 13:00:25.080997 2026] [security2:error] [pid 123784:tid 124011] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/edit.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2fAAAAF0"]
[Tue Aug 18 13:00:25.138751 2026] [security2:error] [pid 123784:tid 123950] [client 20.203.138.185:42754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-tem.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2fQAAACA"]
[Tue Aug 18 13:00:25.147160 2026] [security2:error] [pid 123784:tid 123967] [client 20.79.204.6:14127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/mah/function.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2fgAAADE"]
[Tue Aug 18 13:00:25.198971 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:25.199241 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:25.201020 2026] [security2:error] [pid 123784:tid 123885] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/admin.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2gAAAemA"]
[Tue Aug 18 13:00:25.226703 2026] [security2:error] [pid 123784:tid 123949] [client 135.225.78.186:61045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/puc.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2gQAAAB8"]
[Tue Aug 18 13:00:25.227507 2026] [security2:error] [pid 123784:tid 124034] [client 158.23.17.4:34014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/k.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2ggAAAHQ"]
[Tue Aug 18 13:00:25.264516 2026] [security2:error] [pid 123784:tid 124002] [client 20.116.17.175:58164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2gwAAAFQ"]
[Tue Aug 18 13:00:25.268929 2026] [security2:error] [pid 123784:tid 123933] [client 20.79.204.6:10706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wk/index.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2hAAAAA8"]
[Tue Aug 18 13:00:25.281171 2026] [security2:error] [pid 123784:tid 123835] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/nox.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2hQAAPi4"]
[Tue Aug 18 13:00:25.293787 2026] [security2:error] [pid 123784:tid 123995] [client 20.65.98.162:28941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2hgAAAE0"]
[Tue Aug 18 13:00:25.302409 2026] [security2:error] [pid 123784:tid 123965] [client 158.158.74.177:23736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/mah/function.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2hwAAAC8"]
[Tue Aug 18 13:00:25.378263 2026] [security2:error] [pid 123784:tid 124019] [client 168.62.48.100:5446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2iQAAAGU"]
[Tue Aug 18 13:00:25.400319 2026] [security2:error] [pid 123784:tid 123908] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/gelay.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2iwAAYnc"]
[Tue Aug 18 13:00:25.435435 2026] [security2:error] [pid 123784:tid 123970] [client 158.23.17.4:63975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/gk.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2jAAAADQ"]
[Tue Aug 18 13:00:25.441949 2026] [security2:error] [pid 123784:tid 123990] [client 40.74.65.169:60178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/blurbs.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2jQAAAEg"]
[Tue Aug 18 13:00:25.444083 2026] [security2:error] [pid 123784:tid 123918] [client 20.104.100.201:62008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-css.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2jgAAAAA"]
[Tue Aug 18 13:00:25.445332 2026] [security2:error] [pid 123784:tid 124014] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/w.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2jwAAAGA"]
[Tue Aug 18 13:00:25.464127 2026] [security2:error] [pid 123784:tid 124045] [client 68.155.156.252:7206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/155.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2kAAAAH8"]
[Tue Aug 18 13:00:25.469836 2026] [security2:error] [pid 123784:tid 123932] [client 20.250.27.191:63192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2kQAAAA4"]
[Tue Aug 18 13:00:25.505657 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.56.190:20910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/de.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2kwAAAFI"]
[Tue Aug 18 13:00:25.522336 2026] [security2:error] [pid 123784:tid 123960] [client 20.226.56.190:20910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/album.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2lAAAACo"]
[Tue Aug 18 13:00:25.527533 2026] [security2:error] [pid 123784:tid 123956] [client 20.250.13.23:48472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/manager.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2lQAAACY"]
[Tue Aug 18 13:00:25.532881 2026] [security2:error] [pid 123784:tid 123921] [client 20.226.56.190:7306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kv.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2lgAAAAM"]
[Tue Aug 18 13:00:25.546330 2026] [security2:error] [pid 123784:tid 123961] [client 20.226.56.190:21179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/z.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2mAAAACs"]
[Tue Aug 18 13:00:25.561019 2026] [security2:error] [pid 123784:tid 123972] [client 20.116.17.175:60472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/df.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2mgAAADY"]
[Tue Aug 18 13:00:25.574313 2026] [security2:error] [pid 123784:tid 124032] [client 213.35.127.232:59164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2mwAAAHI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:25.579677 2026] [security2:error] [pid 123784:tid 123819] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2nAAAbB4"]
[Tue Aug 18 13:00:25.594371 2026] [security2:error] [pid 123784:tid 124041] [client 20.226.56.190:10577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xg.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2nQAAAHs"]
[Tue Aug 18 13:00:25.606645 2026] [security2:error] [pid 123784:tid 124043] [client 20.226.56.190:10619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/nd.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2ngAAAH0"]
[Tue Aug 18 13:00:25.622364 2026] [security2:error] [pid 123784:tid 123955] [client 74.7.228.25:59238] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "site.domcoworking.com.br"] [uri "/index.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2SgAAJWI"]
[Tue Aug 18 13:00:25.626479 2026] [security2:error] [pid 123784:tid 124035] [client 20.226.56.190:6588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ri.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2pAAAAHU"]
[Tue Aug 18 13:00:25.629986 2026] [security2:error] [pid 123784:tid 123939] [client 20.100.169.31:4020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2pQAAABU"]
[Tue Aug 18 13:00:25.659917 2026] [security2:error] [pid 123784:tid 124022] [client 158.23.17.4:56573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/pk.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2pgAAAGg"]
[Tue Aug 18 13:00:25.752269 2026] [security2:error] [pid 123784:tid 123922] [client 20.79.204.6:14109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/filter.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2rQAAAAQ"]
[Tue Aug 18 13:00:25.768532 2026] [security2:error] [pid 123784:tid 123843] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/adminfuns.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2rwAAWzY"]
[Tue Aug 18 13:00:25.799251 2026] [security2:error] [pid 123784:tid 124038] [client 20.104.100.201:62013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/flox.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2sgAAAHg"]
[Tue Aug 18 13:00:25.800610 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:25.800879 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:25.828510 2026] [security2:error] [pid 123784:tid 123877] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/file59.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2tAAAZlg"]
[Tue Aug 18 13:00:25.840624 2026] [security2:error] [pid 123784:tid 123997] [client 20.226.36.136:62203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2twAAAE8"]
[Tue Aug 18 13:00:25.844188 2026] [security2:error] [pid 123784:tid 123919] [client 20.116.17.175:59986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2uAAAAAE"]
[Tue Aug 18 13:00:25.844997 2026] [security2:error] [pid 123784:tid 124042] [client 68.155.156.252:37105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/inso.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2uQAAAHw"]
[Tue Aug 18 13:00:25.877447 2026] [security2:error] [pid 123784:tid 124012] [client 68.155.156.252:7199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/index.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2ugAAAF4"]
[Tue Aug 18 13:00:25.890535 2026] [security2:error] [pid 123784:tid 123947] [client 158.23.17.4:60755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/wy.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2vAAAAB0"]
[Tue Aug 18 13:00:25.911789 2026] [security2:error] [pid 123784:tid 123982] [client 20.250.27.191:28129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2vQAAAEA"]
[Tue Aug 18 13:00:25.953256 2026] [security2:error] [pid 123784:tid 123993] [client 158.23.17.4:34119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/iu.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2wAAAAEs"]
[Tue Aug 18 13:00:25.959068 2026] [security2:error] [pid 123784:tid 123957] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/file.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2wwAAACc"]
[Tue Aug 18 13:00:25.965166 2026] [security2:error] [pid 123784:tid 124024] [client 158.158.74.177:17316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2xAAAAGo"]
[Tue Aug 18 13:00:25.976493 2026] [security2:error] [pid 123784:tid 123796] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/css/"] [unique_id "aoSBmWwDnJBNj2tDbYb2xQAAVAc"]
[Tue Aug 18 13:00:26.092820 2026] [authz_core:error] [pid 123784:tid 123874] [remote 57.141.22.2:53486] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:26.093264 2026] [authz_core:error] [pid 123784:tid 123874] [remote 57.141.22.2:53486] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:26.103238 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:26.103516 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:26.108222 2026] [security2:error] [pid 123784:tid 124006] [client 20.104.100.201:61981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/op.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2yAAAAFg"]
[Tue Aug 18 13:00:26.134829 2026] [security2:error] [pid 123784:tid 124014] [client 40.74.65.169:60161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/bajah.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2ygAAAGA"]
[Tue Aug 18 13:00:26.144585 2026] [security2:error] [pid 123784:tid 123983] [client 20.116.17.175:58160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/usr.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2ywAAAEE"]
[Tue Aug 18 13:00:26.145863 2026] [security2:error] [pid 123784:tid 123854] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/admin.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2zAAAE0E"]
[Tue Aug 18 13:00:26.151451 2026] [security2:error] [pid 123784:tid 124045] [client 172.202.39.151:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/info.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2zQAAAH8"]
[Tue Aug 18 13:00:26.157515 2026] [security2:error] [pid 123784:tid 123800] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2zgAADgs"]
[Tue Aug 18 13:00:26.163045 2026] [security2:error] [pid 123784:tid 123987] [client 158.23.17.4:9315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/wn.php"] [unique_id "aoSBmmwDnJBNj2tDbYb20QAAAEU"]
[Tue Aug 18 13:00:26.163434 2026] [security2:error] [pid 123784:tid 123850] [remote 74.220.219.216:37410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.219.220.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "caminhosdaregiao.com.br"] [uri "/wp-login.php"] [unique_id "aoSBmmwDnJBNj2tDbYb20AAAOz0"]
[Tue Aug 18 13:00:26.166159 2026] [security2:error] [pid 123784:tid 124037] [client 172.202.39.151:44507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBmmwDnJBNj2tDbYb20gAAAHc"]
[Tue Aug 18 13:00:26.274603 2026] [security2:error] [pid 123784:tid 123956] [client 20.124.247.79:16715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBmmwDnJBNj2tDbYb20wAAACY"]
[Tue Aug 18 13:00:26.277432 2026] [security2:error] [pid 123784:tid 123921] [client 20.203.138.185:40983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/sadd.php"] [unique_id "aoSBmmwDnJBNj2tDbYb21AAAAAM"]
[Tue Aug 18 13:00:26.298930 2026] [security2:error] [pid 123784:tid 123961] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBmmwDnJBNj2tDbYb22AAAACs"]
[Tue Aug 18 13:00:26.306053 2026] [security2:error] [pid 123784:tid 123972] [client 20.226.36.136:61443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBmmwDnJBNj2tDbYb22gAAADY"]
[Tue Aug 18 13:00:26.312328 2026] [security2:error] [pid 123784:tid 123971] [client 68.155.156.252:50939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/aaa.php"] [unique_id "aoSBmmwDnJBNj2tDbYb22wAAADU"]
[Tue Aug 18 13:00:26.316485 2026] [security2:error] [pid 123784:tid 123940] [client 20.100.169.31:3975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/htaccess.php"] [unique_id "aoSBmmwDnJBNj2tDbYb23AAAABY"]
[Tue Aug 18 13:00:26.332163 2026] [security2:error] [pid 123784:tid 124004] [client 20.79.204.6:10689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/about.php"] [unique_id "aoSBmmwDnJBNj2tDbYb23gAAAFY"]
[Tue Aug 18 13:00:26.371207 2026] [security2:error] [pid 123784:tid 123815] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/about.php"] [unique_id "aoSBmmwDnJBNj2tDbYb23wAAIxo"]
[Tue Aug 18 13:00:26.413146 2026] [security2:error] [pid 123784:tid 123989] [client 135.225.78.186:65190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/inso.php"] [unique_id "aoSBmmwDnJBNj2tDbYb24AAAAEc"]
[Tue Aug 18 13:00:26.435560 2026] [security2:error] [pid 123784:tid 123927] [client 20.104.100.201:34247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/1xmomo.php"] [unique_id "aoSBmmwDnJBNj2tDbYb24gAAAAk"]
[Tue Aug 18 13:00:26.438617 2026] [security2:error] [pid 123784:tid 123991] [client 20.116.17.175:59992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSBmmwDnJBNj2tDbYb24wAAAEk"]
[Tue Aug 18 13:00:26.450283 2026] [security2:error] [pid 123784:tid 123936] [client 20.79.204.6:14037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/input.php"] [unique_id "aoSBmmwDnJBNj2tDbYb25AAAABI"]
[Tue Aug 18 13:00:26.508421 2026] [security2:error] [pid 123784:tid 123964] [client 20.226.36.136:61449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/weozh.php"] [unique_id "aoSBmmwDnJBNj2tDbYb25wAAAC4"]
[Tue Aug 18 13:00:26.534690 2026] [security2:error] [pid 123784:tid 124009] [client 20.250.27.191:40142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp.php"] [unique_id "aoSBmmwDnJBNj2tDbYb26AAAAFs"]
[Tue Aug 18 13:00:26.536053 2026] [security2:error] [pid 123784:tid 123922] [client 20.124.247.79:16731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBmmwDnJBNj2tDbYb26QAAAAQ"]
[Tue Aug 18 13:00:26.552600 2026] [security2:error] [pid 123784:tid 123881] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBmmwDnJBNj2tDbYb26gAARlw"]
[Tue Aug 18 13:00:26.562674 2026] [security2:error] [pid 123784:tid 123801] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/aa2.php"] [unique_id "aoSBmmwDnJBNj2tDbYb26wAAeAw"]
[Tue Aug 18 13:00:26.588947 2026] [security2:error] [pid 123784:tid 124031] [client 213.35.127.232:59389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBmmwDnJBNj2tDbYb27AAAAHE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:26.594750 2026] [security2:error] [pid 123784:tid 123996] [client 158.158.74.177:23737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/mass.php"] [unique_id "aoSBmmwDnJBNj2tDbYb27QAAAE4"]
[Tue Aug 18 13:00:26.655316 2026] [security2:error] [pid 123784:tid 123947] [client 68.155.156.252:35160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/FWAZ.php"] [unique_id "aoSBmmwDnJBNj2tDbYb27gAAAB0"]
[Tue Aug 18 13:00:26.658797 2026] [security2:error] [pid 123784:tid 124013] [client 158.23.17.4:12487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/pk.php"] [unique_id "aoSBmmwDnJBNj2tDbYb27wAAAF8"]
[Tue Aug 18 13:00:26.690406 2026] [security2:error] [pid 123784:tid 124040] [client 168.62.48.100:5512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSBmmwDnJBNj2tDbYb28AAAAHo"]
[Tue Aug 18 13:00:26.702997 2026] [authz_core:error] [pid 123784:tid 123860] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:26.703255 2026] [authz_core:error] [pid 123784:tid 123860] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:26.722622 2026] [security2:error] [pid 123784:tid 123992] [client 20.116.17.175:57922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/css/database.php"] [unique_id "aoSBmmwDnJBNj2tDbYb28gAAAEo"]
[Tue Aug 18 13:00:26.727580 2026] [security2:error] [pid 123784:tid 124034] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/aa.php"] [unique_id "aoSBmmwDnJBNj2tDbYb28wAAAHQ"]
[Tue Aug 18 13:00:26.765123 2026] [security2:error] [pid 123784:tid 123825] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/f35.php"] [unique_id "aoSBmmwDnJBNj2tDbYb29gAAaiQ"]
[Tue Aug 18 13:00:26.785152 2026] [security2:error] [pid 123784:tid 123926] [client 20.104.100.201:34249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/txets.php"] [unique_id "aoSBmmwDnJBNj2tDbYb29wAAAAg"]
[Tue Aug 18 13:00:26.811502 2026] [security2:error] [pid 123784:tid 124021] [client 78.46.190.63:18424] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.saojudas.com.br"] [uri "/index.php"] [unique_id "aoSBmmwDnJBNj2tDbYb29QAAAGc"], referer: https://www.saojudas.com.br
[Tue Aug 18 13:00:26.828709 2026] [security2:error] [pid 123784:tid 123942] [client 20.124.247.79:16744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2-gAAABg"]
[Tue Aug 18 13:00:26.832146 2026] [security2:error] [pid 123784:tid 123966] [client 40.74.65.169:60261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/domvf.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2-wAAADA"]
[Tue Aug 18 13:00:26.873496 2026] [security2:error] [pid 123784:tid 124018] [client 79.127.164.8:34676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/wbboardacplibinserts.sql"] [unique_id "aoSBmmwDnJBNj2tDbYb2_AAAAGQ"], referer: https://medihub.com.br/wbboardacplibinserts.sql
[Tue Aug 18 13:00:26.898021 2026] [security2:error] [pid 123784:tid 123880] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/xamp.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2_gAANFs"]
[Tue Aug 18 13:00:26.941563 2026] [security2:error] [pid 123784:tid 123923] [client 86.120.159.145:49608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBmmwDnJBNj2tDbYb3AAAAAAU"]
[Tue Aug 18 13:00:26.941635 2026] [security2:error] [pid 123784:tid 123993] [client 20.100.169.31:17268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/images/wso.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2_wAAAEs"]
[Tue Aug 18 13:00:26.941673 2026] [security2:error] [pid 123784:tid 123923] [client 86.120.159.145:49608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBmmwDnJBNj2tDbYb3AAAAAAU"]
[Tue Aug 18 13:00:26.942161 2026] [security2:error] [pid 123784:tid 123859] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/js/"] [unique_id "aoSBmmwDnJBNj2tDbYb3AQAADkY"]
[Tue Aug 18 13:00:26.944386 2026] [security2:error] [pid 123784:tid 123987] [client 20.250.27.191:35709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/i.php"] [unique_id "aoSBmmwDnJBNj2tDbYb3AwAAAEU"]
[Tue Aug 18 13:00:26.952843 2026] [security2:error] [pid 123784:tid 123938] [client 158.23.17.4:38863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/app.php"] [unique_id "aoSBmmwDnJBNj2tDbYb3BAAAABQ"]
[Tue Aug 18 13:00:26.982836 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.36.136:65319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/rymmm.php"] [unique_id "aoSBmmwDnJBNj2tDbYb3BQAAAFI"]
[Tue Aug 18 13:00:27.003157 2026] [security2:error] [pid 123784:tid 124005] [client 20.116.17.175:59995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/privdayz.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3CAAAAFc"]
[Tue Aug 18 13:00:27.003459 2026] [security2:error] [pid 123784:tid 123998] [client 20.65.98.162:56454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/dex.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3CQAAAFA"]
[Tue Aug 18 13:00:27.029026 2026] [security2:error] [pid 123784:tid 124026] [client 158.23.17.4:20449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ge.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3CwAAAGw"]
[Tue Aug 18 13:00:27.034756 2026] [security2:error] [pid 123784:tid 123952] [client 20.226.36.136:65298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/lddxs.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3DAAAACI"]
[Tue Aug 18 13:00:27.062320 2026] [security2:error] [pid 123784:tid 124019] [client 20.79.204.6:14131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/jquery.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3DgAAAGU"]
[Tue Aug 18 13:00:27.071383 2026] [security2:error] [pid 123784:tid 124004] [client 158.23.17.4:47917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/f.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3DwAAAFY"]
[Tue Aug 18 13:00:27.088673 2026] [security2:error] [pid 123784:tid 123953] [client 20.226.36.136:65339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/zjggu.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3EAAAACM"]
[Tue Aug 18 13:00:27.103943 2026] [security2:error] [pid 123784:tid 123918] [client 20.250.13.23:46855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/w1.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3EQAAAAA"]
[Tue Aug 18 13:00:27.119886 2026] [security2:error] [pid 123784:tid 123963] [client 172.202.39.151:44579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/as.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3EgAAAC0"]
[Tue Aug 18 13:00:27.128661 2026] [security2:error] [pid 123784:tid 123991] [client 20.124.247.79:16727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/av.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3FgAAAEk"]
[Tue Aug 18 13:00:27.130358 2026] [security2:error] [pid 123784:tid 124017] [client 20.104.100.201:61996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/img.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3FwAAAGM"]
[Tue Aug 18 13:00:27.131094 2026] [security2:error] [pid 123784:tid 123909] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/inputs.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3GAAAEng"]
[Tue Aug 18 13:00:27.138450 2026] [security2:error] [pid 123784:tid 123969] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3GgAAADM"]
[Tue Aug 18 13:00:27.170788 2026] [security2:error] [pid 123784:tid 123975] [client 158.23.17.4:8917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ge.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3IgAAADk"]
[Tue Aug 18 13:00:27.177931 2026] [security2:error] [pid 123784:tid 123986] [client 20.226.36.136:62199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/dlvqo.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3IwAAAEQ"]
[Tue Aug 18 13:00:27.213043 2026] [security2:error] [pid 123784:tid 123921] [client 158.158.74.177:23724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/memberfuns.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3JQAAAAM"]
[Tue Aug 18 13:00:27.238591 2026] [security2:error] [pid 123784:tid 124038] [client 68.155.156.252:7218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/site.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3JgAAAHg"]
[Tue Aug 18 13:00:27.249995 2026] [security2:error] [pid 123784:tid 123948] [client 20.226.36.136:52653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/pkmoj.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3JwAAAB4"]
[Tue Aug 18 13:00:27.276296 2026] [security2:error] [pid 123784:tid 123901] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/bless.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3KQAAIHA"]
[Tue Aug 18 13:00:27.286699 2026] [security2:error] [pid 123784:tid 124012] [client 20.116.17.175:60030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wg459o.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3KgAAAF4"]
[Tue Aug 18 13:00:27.308578 2026] [authz_core:error] [pid 123784:tid 123868] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:27.309045 2026] [authz_core:error] [pid 123784:tid 123868] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:27.326761 2026] [security2:error] [pid 123784:tid 124013] [client 68.155.156.252:37102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/aa.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3LQAAAF8"]
[Tue Aug 18 13:00:27.340220 2026] [security2:error] [pid 123784:tid 123957] [client 20.203.138.185:10356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ex.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3LwAAACc"]
[Tue Aug 18 13:00:27.350022 2026] [security2:error] [pid 123784:tid 124024] [client 20.250.27.191:43471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/abcd.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3MAAAAGo"]
[Tue Aug 18 13:00:27.379142 2026] [security2:error] [pid 123784:tid 123795] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/css/colors/"] [unique_id "aoSBm2wDnJBNj2tDbYb3MgAAPAY"]
[Tue Aug 18 13:00:27.421358 2026] [security2:error] [pid 123784:tid 123966] [client 20.124.247.79:16643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/images.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3MwAAADA"]
[Tue Aug 18 13:00:27.450858 2026] [security2:error] [pid 123784:tid 124018] [client 20.65.98.162:28975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3OQAAAGQ"]
[Tue Aug 18 13:00:27.473479 2026] [security2:error] [pid 123784:tid 124042] [client 20.226.36.136:62181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/kopyw.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3OwAAAHw"]
[Tue Aug 18 13:00:27.517473 2026] [security2:error] [pid 123784:tid 123923] [client 40.74.65.169:60279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fpwch.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3PQAAAAU"]
[Tue Aug 18 13:00:27.523052 2026] [security2:error] [pid 123784:tid 123933] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/about.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3PwAAAA8"]
[Tue Aug 18 13:00:27.536016 2026] [security2:error] [pid 123784:tid 123987] [client 20.104.100.201:61971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3QAAAAEU"]
[Tue Aug 18 13:00:27.555100 2026] [security2:error] [pid 123784:tid 123849] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/alfa.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3QQAAUTw"]
[Tue Aug 18 13:00:27.564549 2026] [security2:error] [pid 123784:tid 123926] [client 20.100.169.31:22599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/index/function.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3QgAAAAg"]
[Tue Aug 18 13:00:27.597684 2026] [security2:error] [pid 123784:tid 123956] [client 68.155.156.252:50942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/ccc.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3RAAAACY"]
[Tue Aug 18 13:00:27.604952 2026] [security2:error] [pid 123784:tid 123919] [client 213.35.127.232:59601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3RQAAAAE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:27.609066 2026] [security2:error] [pid 123784:tid 123891] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/file25.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3RgAANmY"]
[Tue Aug 18 13:00:27.615659 2026] [security2:error] [pid 123784:tid 123952] [client 20.116.17.175:60442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/mifta.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3RwAAACI"]
[Tue Aug 18 13:00:27.639413 2026] [security2:error] [pid 123784:tid 123962] [client 20.226.56.190:13108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/tp.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3SgAAACw"]
[Tue Aug 18 13:00:27.681142 2026] [security2:error] [pid 123784:tid 123977] [client 20.226.36.136:62177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/zznmg.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3SwAAADs"]
[Tue Aug 18 13:00:27.698217 2026] [security2:error] [pid 123784:tid 124014] [client 20.79.204.6:14031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/media-new.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3TAAAAGA"]
[Tue Aug 18 13:00:27.713328 2026] [security2:error] [pid 123784:tid 124017] [client 20.124.247.79:16670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/ops.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3TQAAAGM"]
[Tue Aug 18 13:00:27.732406 2026] [security2:error] [pid 123784:tid 123857] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/lock360.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3TgAAdUQ"]
[Tue Aug 18 13:00:27.733879 2026] [security2:error] [pid 123784:tid 123981] [client 158.23.17.4:34174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/kl.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3TwAAAD8"]
[Tue Aug 18 13:00:27.757420 2026] [security2:error] [pid 123784:tid 123974] [client 135.225.78.186:27960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/aa.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3UAAAADg"]
[Tue Aug 18 13:00:27.770825 2026] [security2:error] [pid 123784:tid 123924] [client 20.250.27.191:43459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-manager.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3UgAAAAY"]
[Tue Aug 18 13:00:27.796162 2026] [security2:error] [pid 123784:tid 123976] [client 20.226.36.136:65307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/bhfnd.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3VAAAADo"]
[Tue Aug 18 13:00:27.846742 2026] [security2:error] [pid 123784:tid 124030] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/goods.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3VQAAAHA"]
[Tue Aug 18 13:00:27.860882 2026] [security2:error] [pid 123784:tid 123971] [client 158.158.74.177:23727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/meta.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3VgAAADU"]
[Tue Aug 18 13:00:27.870796 2026] [security2:error] [pid 123784:tid 123964] [client 20.104.100.201:61984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3VwAAAC4"]
[Tue Aug 18 13:00:27.901042 2026] [security2:error] [pid 123784:tid 123922] [client 20.116.17.175:60477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3XAAAAAQ"]
[Tue Aug 18 13:00:27.906995 2026] [authz_core:error] [pid 123784:tid 123803] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:27.907283 2026] [authz_core:error] [pid 123784:tid 123803] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:27.938083 2026] [security2:error] [pid 123784:tid 123864] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/flower.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3XQAAeEs"]
[Tue Aug 18 13:00:27.940411 2026] [security2:error] [pid 123784:tid 123948] [client 20.226.36.136:61474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/qfvqu.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3XgAAAB4"]
[Tue Aug 18 13:00:27.943777 2026] [security2:error] [pid 123784:tid 123834] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/file15.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3XwAAMi0"]
[Tue Aug 18 13:00:27.964180 2026] [security2:error] [pid 123784:tid 123833] [remote 162.214.184.71:37796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "serviplascomercio.com.br"] [uri "/wp-login.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3YQAAHCw"]
[Tue Aug 18 13:00:27.987832 2026] [security2:error] [pid 123784:tid 123947] [client 20.124.247.79:16653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/coffexium.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3ZAAAAB0"]
[Tue Aug 18 13:00:28.018031 2026] [security2:error] [pid 123784:tid 124036] [client 158.23.17.4:29446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/87.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3ZQAAAHY"]
[Tue Aug 18 13:00:28.033713 2026] [security2:error] [pid 123784:tid 124043] [client 68.155.156.252:23165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/admin.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3ZgAAAH0"]
[Tue Aug 18 13:00:28.101789 2026] [security2:error] [pid 123784:tid 124021] [client 20.226.36.136:65336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/oivcl.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3aQAAAGc"]
[Tue Aug 18 13:00:28.120514 2026] [security2:error] [pid 123784:tid 123934] [client 172.202.39.151:44580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3awAAABA"]
[Tue Aug 18 13:00:28.132495 2026] [security2:error] [pid 123784:tid 123916] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/13.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3bAAAGH8"]
[Tue Aug 18 13:00:28.161587 2026] [security2:error] [pid 123784:tid 124003] [client 20.203.138.185:10555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/tax.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3bQAAAFU"]
[Tue Aug 18 13:00:28.186574 2026] [security2:error] [pid 123784:tid 123970] [client 20.250.27.191:40130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3cAAAADQ"]
[Tue Aug 18 13:00:28.188158 2026] [security2:error] [pid 123784:tid 124002] [client 20.116.17.175:60023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/index2.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3cQAAAFQ"]
[Tue Aug 18 13:00:28.195888 2026] [security2:error] [pid 123784:tid 123941] [client 20.100.169.31:3990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/info.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3cgAAABc"]
[Tue Aug 18 13:00:28.209033 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:28.209307 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:28.219230 2026] [security2:error] [pid 123784:tid 123980] [client 40.74.65.169:60188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/sf.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3dQAAAD4"]
[Tue Aug 18 13:00:28.281939 2026] [security2:error] [pid 123784:tid 124015] [client 20.124.247.79:16746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3eQAAAGE"]
[Tue Aug 18 13:00:28.301614 2026] [security2:error] [pid 123784:tid 123926] [client 20.104.100.201:61974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3ewAAAAg"]
[Tue Aug 18 13:00:28.306317 2026] [security2:error] [pid 123784:tid 124005] [client 158.23.17.4:20203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/gs.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3fAAAAFc"]
[Tue Aug 18 13:00:28.322631 2026] [security2:error] [pid 123784:tid 123856] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/f35.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3fgAAEUM"]
[Tue Aug 18 13:00:28.332639 2026] [security2:error] [pid 123784:tid 123873] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/cc.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3gAAAKFQ"]
[Tue Aug 18 13:00:28.342861 2026] [security2:error] [pid 123784:tid 123990] [client 103.120.71.157:65238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3gQAAAEg"]
[Tue Aug 18 13:00:28.343040 2026] [security2:error] [pid 123784:tid 123990] [client 103.120.71.157:65238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3gQAAAEg"]
[Tue Aug 18 13:00:28.371714 2026] [security2:error] [pid 123784:tid 123995] [client 20.79.204.6:14032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3gwAAAE0"]
[Tue Aug 18 13:00:28.376166 2026] [security2:error] [pid 123784:tid 123961] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/php8.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3hAAAACs"]
[Tue Aug 18 13:00:28.468830 2026] [security2:error] [pid 123784:tid 123944] [client 20.116.17.175:57938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/8.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3iAAAABo"]
[Tue Aug 18 13:00:28.481552 2026] [security2:error] [pid 123784:tid 123925] [client 158.158.74.177:23683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/mini.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3iQAAAAc"]
[Tue Aug 18 13:00:28.494865 2026] [security2:error] [pid 123784:tid 123932] [client 68.155.156.252:59733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/reviall.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3iwAAAA4"]
[Tue Aug 18 13:00:28.505288 2026] [security2:error] [pid 123784:tid 123963] [client 20.226.36.136:61460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/zugvi.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3jQAAAC0"]
[Tue Aug 18 13:00:28.513528 2026] [authz_core:error] [pid 123784:tid 123816] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:28.513806 2026] [authz_core:error] [pid 123784:tid 123816] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:28.518117 2026] [security2:error] [pid 123784:tid 124035] [client 20.65.98.162:55193] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "lavobotafogo.com"] [uri "/1.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3jwAAAHU"]
[Tue Aug 18 13:00:28.518233 2026] [security2:error] [pid 123784:tid 124035] [client 20.65.98.162:55193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/1.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3jwAAAHU"]
[Tue Aug 18 13:00:28.555438 2026] [security2:error] [pid 123784:tid 123872] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/gecko-new.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3kgAAP1M"]
[Tue Aug 18 13:00:28.571772 2026] [security2:error] [pid 123784:tid 123969] [client 68.155.156.252:62139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/img.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3kwAAADM"]
[Tue Aug 18 13:00:28.575862 2026] [security2:error] [pid 123784:tid 123939] [client 20.124.247.79:16667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/sf.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3lAAAABU"]
[Tue Aug 18 13:00:28.608065 2026] [security2:error] [pid 123784:tid 123920] [client 158.23.17.4:29494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/zi.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3lwAAAAI"]
[Tue Aug 18 13:00:28.615025 2026] [security2:error] [pid 123784:tid 124022] [client 20.250.27.191:63182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3mAAAAGg"]
[Tue Aug 18 13:00:28.622605 2026] [security2:error] [pid 123784:tid 123999] [client 213.35.127.232:59818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3mQAAAFE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:28.659211 2026] [security2:error] [pid 123784:tid 123866] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-load.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3nAAANU0"]
[Tue Aug 18 13:00:28.699516 2026] [security2:error] [pid 123784:tid 124011] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/info.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3ngAAAF0"]
[Tue Aug 18 13:00:28.745938 2026] [security2:error] [pid 123784:tid 124020] [client 20.116.17.175:58114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/images.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3oQAAAGY"]
[Tue Aug 18 13:00:28.753908 2026] [security2:error] [pid 123784:tid 123968] [client 158.23.17.4:58744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/30.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3ogAAADI"]
[Tue Aug 18 13:00:28.764792 2026] [security2:error] [pid 123784:tid 123855] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content.php.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3pAAAHEI"]
[Tue Aug 18 13:00:28.776771 2026] [security2:error] [pid 123784:tid 123996] [client 20.104.100.201:61416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3pQAAAE4"]
[Tue Aug 18 13:00:28.811154 2026] [authz_core:error] [pid 123784:tid 123831] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:28.811564 2026] [authz_core:error] [pid 123784:tid 123831] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:28.821796 2026] [security2:error] [pid 123784:tid 124012] [client 20.226.36.136:65314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wsrer.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3qQAAAF4"]
[Tue Aug 18 13:00:28.829052 2026] [security2:error] [pid 123784:tid 124043] [client 20.124.247.79:16707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/k.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3rgAAAH0"]
[Tue Aug 18 13:00:28.830608 2026] [security2:error] [pid 123784:tid 124030] [client 20.100.169.31:4027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/profile.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3rwAAAHA"]
[Tue Aug 18 13:00:28.869845 2026] [security2:error] [pid 123784:tid 124021] [client 68.155.156.252:48090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/nope.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3sAAAAGc"]
[Tue Aug 18 13:00:28.902921 2026] [security2:error] [pid 123784:tid 123966] [client 40.74.65.169:60227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xx.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3sQAAADA"]
[Tue Aug 18 13:00:28.913534 2026] [security2:error] [pid 123784:tid 124003] [client 172.202.39.151:44098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3swAAAFU"]
[Tue Aug 18 13:00:28.939699 2026] [security2:error] [pid 123784:tid 123890] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/01.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3tAAAVGU"]
[Tue Aug 18 13:00:28.978048 2026] [security2:error] [pid 123784:tid 124031] [client 20.79.204.6:14049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3tgAAAHE"]
[Tue Aug 18 13:00:29.034439 2026] [security2:error] [pid 123784:tid 123954] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/chosen.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3vAAAACQ"]
[Tue Aug 18 13:00:29.038786 2026] [security2:error] [pid 123784:tid 123992] [client 20.116.17.175:58148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/a.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3vQAAAEo"]
[Tue Aug 18 13:00:29.078757 2026] [security2:error] [pid 123784:tid 123990] [client 20.124.247.79:16663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/82.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3vwAAAEg"]
[Tue Aug 18 13:00:29.113747 2026] [security2:error] [pid 123784:tid 124024] [client 20.203.138.185:18852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/X7x.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3wwAAAGo"]
[Tue Aug 18 13:00:29.115916 2026] [security2:error] [pid 123784:tid 123792] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/lv.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3xAAAJgM"]
[Tue Aug 18 13:00:29.116658 2026] [security2:error] [pid 123784:tid 124016] [client 158.158.74.177:17325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/mm.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3xQAAAGI"]
[Tue Aug 18 13:00:29.122247 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:29.122712 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:29.128333 2026] [security2:error] [pid 123784:tid 123995] [client 20.104.100.201:61982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/term.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3xgAAAE0"]
[Tue Aug 18 13:00:29.224457 2026] [security2:error] [pid 123784:tid 123925] [client 158.23.17.4:33508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/92.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3ygAAAAc"]
[Tue Aug 18 13:00:29.238021 2026] [security2:error] [pid 123784:tid 123945] [client 20.226.36.136:65325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/ucpfr.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3ywAAABs"]
[Tue Aug 18 13:00:29.243864 2026] [security2:error] [pid 123784:tid 124014] [client 172.202.39.151:40373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3zAAAAGA"]
[Tue Aug 18 13:00:29.269761 2026] [security2:error] [pid 123784:tid 123981] [client 20.250.27.191:28004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/simple.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3zgAAAD8"]
[Tue Aug 18 13:00:29.270534 2026] [security2:error] [pid 123784:tid 124008] [client 158.23.17.4:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/lw.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3zwAAAFo"]
[Tue Aug 18 13:00:29.297159 2026] [security2:error] [pid 123784:tid 123897] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/new.php"] [unique_id "aoSBnWwDnJBNj2tDbYb30gAADWw"]
[Tue Aug 18 13:00:29.306809 2026] [security2:error] [pid 123784:tid 124029] [client 20.226.36.136:62183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/yxijx.php"] [unique_id "aoSBnWwDnJBNj2tDbYb30wAAAG8"]
[Tue Aug 18 13:00:29.306826 2026] [security2:error] [pid 123784:tid 123920] [client 68.155.156.252:23160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/nope.php"] [unique_id "aoSBnWwDnJBNj2tDbYb31AAAAAI"]
[Tue Aug 18 13:00:29.329413 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.36.136:65294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/zwlsv.php"] [unique_id "aoSBnWwDnJBNj2tDbYb31gAAAEc"]
[Tue Aug 18 13:00:29.342902 2026] [security2:error] [pid 123784:tid 123922] [client 20.124.247.79:16760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/dex.php"] [unique_id "aoSBnWwDnJBNj2tDbYb31wAAAAQ"]
[Tue Aug 18 13:00:29.364535 2026] [security2:error] [pid 123784:tid 124038] [client 20.116.17.175:59996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSBnWwDnJBNj2tDbYb32gAAAHg"]
[Tue Aug 18 13:00:29.377908 2026] [security2:error] [pid 123784:tid 123968] [client 20.226.36.136:65305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/jrpga.php"] [unique_id "aoSBnWwDnJBNj2tDbYb33AAAADI"]
[Tue Aug 18 13:00:29.409229 2026] [security2:error] [pid 123784:tid 123976] [client 20.226.36.136:65320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/museu/yhweq.php"] [unique_id "aoSBnWwDnJBNj2tDbYb33wAAADo"]
[Tue Aug 18 13:00:29.415758 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:29.416019 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:29.437687 2026] [security2:error] [pid 123784:tid 124043] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/simple.php"] [unique_id "aoSBnWwDnJBNj2tDbYb34AAAAH0"]
[Tue Aug 18 13:00:29.452579 2026] [security2:error] [pid 123784:tid 124017] [client 20.100.169.31:3781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/sx.php"] [unique_id "aoSBnWwDnJBNj2tDbYb34QAAAGM"]
[Tue Aug 18 13:00:29.473569 2026] [security2:error] [pid 123784:tid 123835] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/222.php"] [unique_id "aoSBnWwDnJBNj2tDbYb34wAAAC4"]
[Tue Aug 18 13:00:29.499231 2026] [security2:error] [pid 123784:tid 123973] [client 20.226.36.136:65324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/nwwha.php"] [unique_id "aoSBnWwDnJBNj2tDbYb35QAAADc"]
[Tue Aug 18 13:00:29.515192 2026] [security2:error] [pid 123784:tid 124010] [client 20.104.100.201:61394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/black.php"] [unique_id "aoSBnWwDnJBNj2tDbYb35gAAAFw"]
[Tue Aug 18 13:00:29.518935 2026] [security2:error] [pid 123784:tid 124018] [client 158.23.17.4:55169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/pu.php"] [unique_id "aoSBnWwDnJBNj2tDbYb35wAAAGQ"]
[Tue Aug 18 13:00:29.567453 2026] [security2:error] [pid 123784:tid 124001] [client 20.226.36.136:61482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/opsqt.php"] [unique_id "aoSBnWwDnJBNj2tDbYb36gAAAFM"]
[Tue Aug 18 13:00:29.587499 2026] [security2:error] [pid 123784:tid 123946] [client 20.79.204.6:14043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-admin/import.php"] [unique_id "aoSBnWwDnJBNj2tDbYb36wAAABw"]
[Tue Aug 18 13:00:29.601424 2026] [security2:error] [pid 123784:tid 123951] [client 40.74.65.169:60249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/adminner.php"] [unique_id "aoSBnWwDnJBNj2tDbYb37AAAACE"]
[Tue Aug 18 13:00:29.610326 2026] [security2:error] [pid 123784:tid 123998] [client 20.226.36.136:53556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/jvcpa.php"] [unique_id "aoSBnWwDnJBNj2tDbYb37QAAAFA"]
[Tue Aug 18 13:00:29.616567 2026] [security2:error] [pid 123784:tid 123956] [client 135.225.78.186:65174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/img.php"] [unique_id "aoSBnWwDnJBNj2tDbYb37gAAACY"]
[Tue Aug 18 13:00:29.635564 2026] [security2:error] [pid 123784:tid 124032] [client 213.35.127.232:60037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBnWwDnJBNj2tDbYb37wAAAHI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:29.636621 2026] [security2:error] [pid 123784:tid 124016] [client 20.124.247.79:16725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/puc.php"] [unique_id "aoSBnWwDnJBNj2tDbYb38AAAAGI"]
[Tue Aug 18 13:00:29.672246 2026] [security2:error] [pid 123784:tid 123847] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/chosen.php"] [unique_id "aoSBnWwDnJBNj2tDbYb39QAAPDo"]
[Tue Aug 18 13:00:29.674436 2026] [security2:error] [pid 123784:tid 123952] [client 20.116.17.175:60419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/99.php"] [unique_id "aoSBnWwDnJBNj2tDbYb39gAAACI"]
[Tue Aug 18 13:00:29.675626 2026] [security2:error] [pid 123784:tid 124019] [client 20.226.36.136:61465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSBnWwDnJBNj2tDbYb39wAAAGU"]
[Tue Aug 18 13:00:29.697185 2026] [security2:error] [pid 123784:tid 123925] [client 68.155.156.252:50903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/new.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3-QAAAAc"]
[Tue Aug 18 13:00:29.704846 2026] [security2:error] [pid 123784:tid 123877] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3-gAAdVg"]
[Tue Aug 18 13:00:29.715463 2026] [authz_core:error] [pid 123784:tid 123910] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:29.715730 2026] [authz_core:error] [pid 123784:tid 123910] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:29.716465 2026] [security2:error] [pid 123784:tid 123936] [client 20.226.36.136:62207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3_AAAABI"]
[Tue Aug 18 13:00:29.725878 2026] [security2:error] [pid 123784:tid 123842] [remote 156.59.198.135:40946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "designacao2022.cabeceiragrandemg.com.br"] [uri "/semed2022-1/convocacao_26-04-2022.pdf"] [unique_id "aoSBnWwDnJBNj2tDbYb3_gAAWjU"]
[Tue Aug 18 13:00:29.746425 2026] [security2:error] [pid 123784:tid 123941] [client 158.158.74.177:23705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/modules/mod_footer.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4AAAAABc"]
[Tue Aug 18 13:00:29.758249 2026] [security2:error] [pid 123784:tid 124029] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4BAAAAG8"]
[Tue Aug 18 13:00:29.785376 2026] [security2:error] [pid 123784:tid 123999] [client 20.203.138.185:16788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ocxla.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4CQAAAFE"]
[Tue Aug 18 13:00:29.820469 2026] [security2:error] [pid 123784:tid 123922] [client 20.226.36.136:62157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4DAAAAAQ"]
[Tue Aug 18 13:00:29.863637 2026] [security2:error] [pid 123784:tid 123796] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/info.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4DwAAXwc"]
[Tue Aug 18 13:00:29.899759 2026] [security2:error] [pid 123784:tid 123927] [client 20.124.247.79:16753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/inso.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4EQAAAAk"]
[Tue Aug 18 13:00:29.908282 2026] [security2:error] [pid 123784:tid 123976] [client 158.23.17.4:31928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/vj.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4EwAAADo"]
[Tue Aug 18 13:00:29.921514 2026] [security2:error] [pid 123784:tid 123947] [client 20.104.100.201:61960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/as.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4FQAAAB0"]
[Tue Aug 18 13:00:29.973031 2026] [security2:error] [pid 123784:tid 124005] [client 20.250.27.191:35685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/chosen.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4FgAAAFc"]
[Tue Aug 18 13:00:29.992059 2026] [security2:error] [pid 123784:tid 123965] [client 20.116.17.175:59981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/yup.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4GAAAAC8"]
[Tue Aug 18 13:00:30.017834 2026] [security2:error] [pid 123784:tid 124010] [client 20.226.36.136:61441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4GwAAAFw"]
[Tue Aug 18 13:00:30.026075 2026] [security2:error] [pid 123784:tid 123940] [client 20.250.13.23:46093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-login.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4DgAAABY"]
[Tue Aug 18 13:00:30.035124 2026] [security2:error] [pid 123784:tid 123789] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/aaa.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4HAAANAA"]
[Tue Aug 18 13:00:30.059971 2026] [security2:error] [pid 123784:tid 123958] [client 149.34.210.141:53679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4HQAAACg"]
[Tue Aug 18 13:00:30.062067 2026] [security2:error] [pid 123784:tid 123993] [client 20.226.36.136:65283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4HgAAAEs"]
[Tue Aug 18 13:00:30.062356 2026] [security2:error] [pid 123784:tid 123870] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/html-api/"] [unique_id "aoSBnmwDnJBNj2tDbYb4HwAAFFE"]
[Tue Aug 18 13:00:30.063246 2026] [security2:error] [pid 123784:tid 124028] [client 66.132.172.99:22300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.172.132.66.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atlantica.goptur.app.br"] [uri "/index.php/login"] [unique_id "aoSBnWwDnJBNj2tDbYb4EAAAAG4"]
[Tue Aug 18 13:00:30.063803 2026] [security2:error] [pid 123784:tid 124031] [client 68.155.156.252:62131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/222.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4IAAAAHE"]
[Tue Aug 18 13:00:30.091247 2026] [security2:error] [pid 123784:tid 123968] [client 20.100.169.31:3993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4IQAAADI"]
[Tue Aug 18 13:00:30.091931 2026] [security2:error] [pid 123784:tid 123926] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/av.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4IwAAAAg"]
[Tue Aug 18 13:00:30.121552 2026] [security2:error] [pid 123784:tid 123951] [client 158.23.17.4:33520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/jm.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4JAAAACE"]
[Tue Aug 18 13:00:30.168189 2026] [security2:error] [pid 123784:tid 123956] [client 20.124.247.79:16745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/aa.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4JgAAACY"]
[Tue Aug 18 13:00:30.171469 2026] [security2:error] [pid 123784:tid 124032] [client 20.226.36.136:61478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4JwAAAHI"]
[Tue Aug 18 13:00:30.195665 2026] [security2:error] [pid 123784:tid 124027] [client 20.79.204.6:14024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4KQAAAG0"]
[Tue Aug 18 13:00:30.242365 2026] [security2:error] [pid 123784:tid 123997] [client 103.184.169.37:42884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4KwAAAE8"]
[Tue Aug 18 13:00:30.242474 2026] [security2:error] [pid 123784:tid 123997] [client 103.184.169.37:42884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4KwAAAE8"]
[Tue Aug 18 13:00:30.247473 2026] [security2:error] [pid 123784:tid 123845] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4LAAAaTg"]
[Tue Aug 18 13:00:30.313188 2026] [security2:error] [pid 123784:tid 123929] [client 114.119.153.50:21583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "petceu.com.br"] [uri "/2017/12/page/2/"] [unique_id "aoSBnmwDnJBNj2tDbYb4MgAAAAs"], referer: https://petceu.com.br/2017/12?post_type=anjinhos
[Tue Aug 18 13:00:30.317606 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:30.317992 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:30.325214 2026] [security2:error] [pid 123784:tid 123958] [client 149.34.210.141:53679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4HQAAACg"]
[Tue Aug 18 13:00:30.334847 2026] [security2:error] [pid 123784:tid 123941] [client 20.116.17.175:58159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/222.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4NAAAABc"]
[Tue Aug 18 13:00:30.362527 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.36.136:61445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4NQAAAFI"]
[Tue Aug 18 13:00:30.363109 2026] [security2:error] [pid 123784:tid 123801] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/gecko.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4NgAAbww"]
[Tue Aug 18 13:00:30.378774 2026] [security2:error] [pid 123784:tid 123920] [client 68.155.156.252:55969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/new.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4OAAAAAI"]
[Tue Aug 18 13:00:30.420732 2026] [security2:error] [pid 123784:tid 123952] [client 158.158.74.177:17282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/moon.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4OwAAACI"]
[Tue Aug 18 13:00:30.423687 2026] [security2:error] [pid 123784:tid 123989] [client 20.203.138.185:10359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/post.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4PAAAAEc"]
[Tue Aug 18 13:00:30.431843 2026] [security2:error] [pid 123784:tid 124026] [client 20.104.100.201:61969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/pucci.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4PgAAAGw"]
[Tue Aug 18 13:00:30.438338 2026] [security2:error] [pid 123784:tid 124012] [client 20.79.204.6:10710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/term.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4PwAAAF4"]
[Tue Aug 18 13:00:30.442717 2026] [security2:error] [pid 123784:tid 123986] [client 20.124.247.79:16674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/img.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4QQAAAEQ"]
[Tue Aug 18 13:00:30.462027 2026] [security2:error] [pid 123784:tid 123974] [client 102.213.179.104:63258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4QwAAADg"]
[Tue Aug 18 13:00:30.462246 2026] [security2:error] [pid 123784:tid 123974] [client 102.213.179.104:63258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4QwAAADg"]
[Tue Aug 18 13:00:30.483196 2026] [security2:error] [pid 123784:tid 123798] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4RAAAHgk"]
[Tue Aug 18 13:00:30.487847 2026] [security2:error] [pid 123784:tid 124020] [client 20.226.36.136:62165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4RQAAAGY"]
[Tue Aug 18 13:00:30.498100 2026] [security2:error] [pid 123784:tid 123972] [client 172.202.39.151:44575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4RgAAADY"]
[Tue Aug 18 13:00:30.515032 2026] [security2:error] [pid 123784:tid 124015] [client 135.225.78.186:65167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/222.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4RwAAAGE"]
[Tue Aug 18 13:00:30.536618 2026] [security2:error] [pid 123784:tid 123933] [client 158.23.17.4:49031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/kl.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4SwAAAA8"]
[Tue Aug 18 13:00:30.549343 2026] [security2:error] [pid 123784:tid 123922] [client 138.36.100.162:42684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4TQAAAAQ"]
[Tue Aug 18 13:00:30.549436 2026] [security2:error] [pid 123784:tid 123922] [client 138.36.100.162:42684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4TQAAAAQ"]
[Tue Aug 18 13:00:30.553633 2026] [security2:error] [pid 123784:tid 124042] [client 158.23.17.4:32524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/mimes.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4TgAAAHw"]
[Tue Aug 18 13:00:30.577545 2026] [security2:error] [pid 123784:tid 124043] [client 20.38.3.247:4205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4TwAAAH0"]
[Tue Aug 18 13:00:30.598678 2026] [security2:error] [pid 123784:tid 123988] [client 20.226.36.136:61470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4UQAAAEY"]
[Tue Aug 18 13:00:30.616594 2026] [authz_core:error] [pid 123784:tid 123880] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:30.616932 2026] [authz_core:error] [pid 123784:tid 123880] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:30.627179 2026] [security2:error] [pid 123784:tid 124018] [client 20.116.17.175:58158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-temp.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4VAAAAGQ"]
[Tue Aug 18 13:00:30.637339 2026] [security2:error] [pid 123784:tid 123966] [client 158.23.17.4:47877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ry.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4VQAAADA"]
[Tue Aug 18 13:00:30.637402 2026] [security2:error] [pid 123784:tid 124009] [client 40.74.65.169:60265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/abcd.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4VgAAAFs"]
[Tue Aug 18 13:00:30.642714 2026] [security2:error] [pid 123784:tid 124011] [client 157.20.138.62:59554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4WAAAAF0"]
[Tue Aug 18 13:00:30.642845 2026] [security2:error] [pid 123784:tid 124011] [client 157.20.138.62:59554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4WAAAAF0"]
[Tue Aug 18 13:00:30.649568 2026] [security2:error] [pid 123784:tid 124002] [client 20.250.27.191:63211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/als.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4WQAAAFQ"]
[Tue Aug 18 13:00:30.653594 2026] [security2:error] [pid 123784:tid 123981] [client 213.35.127.232:60242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4WgAAAD8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:30.673168 2026] [security2:error] [pid 123784:tid 123799] [remote 129.121.48.235:48546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.48.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "boscoagriturismo.com"] [uri "/wp-login.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4WwAAcwo"]
[Tue Aug 18 13:00:30.683264 2026] [security2:error] [pid 123784:tid 123859] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/k.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4XAAAd0Y"]
[Tue Aug 18 13:00:30.689030 2026] [security2:error] [pid 123784:tid 123985] [client 20.100.169.31:38684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4XQAAAEM"]
[Tue Aug 18 13:00:30.693905 2026] [security2:error] [pid 123784:tid 124007] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4XgAAAFk"]
[Tue Aug 18 13:00:30.695603 2026] [security2:error] [pid 123784:tid 123888] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/xiugai.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4YAAAcWM"]
[Tue Aug 18 13:00:30.702868 2026] [security2:error] [pid 123784:tid 123957] [client 20.124.247.79:16647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/222.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4YQAAACc"]
[Tue Aug 18 13:00:30.732889 2026] [security2:error] [pid 123784:tid 123998] [client 20.226.36.136:62164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4ZAAAAFA"]
[Tue Aug 18 13:00:30.733663 2026] [security2:error] [pid 123784:tid 123951] [client 20.65.98.162:56474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/coffee.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4ZQAAACE"]
[Tue Aug 18 13:00:30.749227 2026] [security2:error] [pid 123784:tid 124040] [client 20.104.100.201:61400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wicked.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4ZwAAAHo"]
[Tue Aug 18 13:00:30.798524 2026] [security2:error] [pid 123784:tid 124027] [client 158.23.17.4:63669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/wj.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4agAAAG0"]
[Tue Aug 18 13:00:30.810103 2026] [security2:error] [pid 123784:tid 124005] [client 20.79.204.6:13723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/ebs.php7"] [unique_id "aoSBnmwDnJBNj2tDbYb4awAAAFc"]
[Tue Aug 18 13:00:30.811645 2026] [security2:error] [pid 123784:tid 124019] [client 172.202.39.151:41114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4bAAAAGU"]
[Tue Aug 18 13:00:30.817986 2026] [security2:error] [pid 123784:tid 123919] [client 178.153.171.161:63445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4bQAAAAE"]
[Tue Aug 18 13:00:30.818142 2026] [security2:error] [pid 123784:tid 123919] [client 178.153.171.161:63445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4bQAAAAE"]
[Tue Aug 18 13:00:30.851836 2026] [security2:error] [pid 123784:tid 123977] [client 52.173.121.69:48394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4bwAAADs"]
[Tue Aug 18 13:00:30.874192 2026] [security2:error] [pid 123784:tid 123829] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/js/"] [unique_id "aoSBnmwDnJBNj2tDbYb4cQAACyg"]
[Tue Aug 18 13:00:30.922420 2026] [security2:error] [pid 123784:tid 123944] [client 20.116.17.175:57977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/spadex.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4eQAAABo"]
[Tue Aug 18 13:00:30.925040 2026] [authz_core:error] [pid 123784:tid 123838] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:30.925378 2026] [authz_core:error] [pid 123784:tid 123838] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:30.948466 2026] [security2:error] [pid 123784:tid 123949] [client 20.124.247.79:15331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/key.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4ewAAAB8"]
[Tue Aug 18 13:00:30.963965 2026] [security2:error] [pid 123784:tid 123986] [client 20.226.36.136:61456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4fgAAAEQ"]
[Tue Aug 18 13:00:30.971611 2026] [security2:error] [pid 123784:tid 123930] [client 20.65.98.162:26923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4fwAAAAw"]
[Tue Aug 18 13:00:31.014616 2026] [security2:error] [pid 123784:tid 123851] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/adminner.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4gQAACT4"]
[Tue Aug 18 13:00:31.041080 2026] [security2:error] [pid 123784:tid 124023] [client 158.158.74.177:17293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/n.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4ggAAAGk"]
[Tue Aug 18 13:00:31.050214 2026] [security2:error] [pid 123784:tid 123894] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/403.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4gwAAD2k"]
[Tue Aug 18 13:00:31.059489 2026] [security2:error] [pid 123784:tid 123922] [client 158.23.17.4:38330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ni.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4hQAAAAQ"]
[Tue Aug 18 13:00:31.074849 2026] [security2:error] [pid 123784:tid 124034] [client 68.155.156.252:61804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/apreset.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4hgAAAHQ"]
[Tue Aug 18 13:00:31.095485 2026] [security2:error] [pid 123784:tid 124017] [client 20.104.100.201:61997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/water.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4hwAAAGM"]
[Tue Aug 18 13:00:31.107990 2026] [security2:error] [pid 123784:tid 124010] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/file2.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4iwAAAFw"]
[Tue Aug 18 13:00:31.191872 2026] [security2:error] [pid 123784:tid 124036] [client 20.124.247.79:16672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/chosen.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4jgAAAHY"]
[Tue Aug 18 13:00:31.193822 2026] [security2:error] [pid 123784:tid 123970] [client 158.23.17.4:9370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/74.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4jwAAADQ"]
[Tue Aug 18 13:00:31.206291 2026] [security2:error] [pid 123784:tid 124011] [client 158.23.17.4:56761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/gs.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4kAAAAF0"]
[Tue Aug 18 13:00:31.224032 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:31.224458 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:31.235807 2026] [security2:error] [pid 123784:tid 123993] [client 20.226.36.136:65281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4kgAAAEs"]
[Tue Aug 18 13:00:31.244621 2026] [security2:error] [pid 123784:tid 123879] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/images/"] [unique_id "aoSBn2wDnJBNj2tDbYb4lAAABlo"]
[Tue Aug 18 13:00:31.249662 2026] [security2:error] [pid 123784:tid 123985] [client 20.116.17.175:60017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4lQAAAEM"]
[Tue Aug 18 13:00:31.262654 2026] [security2:error] [pid 123784:tid 124030] [client 5.31.227.224:7826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4lgAAAHA"]
[Tue Aug 18 13:00:31.263698 2026] [security2:error] [pid 123784:tid 124001] [client 20.203.138.185:18839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/nhr.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4lwAAAFM"]
[Tue Aug 18 13:00:31.267319 2026] [security2:error] [pid 123784:tid 124030] [client 5.31.227.224:7826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4lgAAAHA"]
[Tue Aug 18 13:00:31.302266 2026] [security2:error] [pid 123784:tid 123923] [client 20.79.204.6:10384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4mgAAAAU"]
[Tue Aug 18 13:00:31.308146 2026] [security2:error] [pid 123784:tid 123957] [client 20.250.27.191:40169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/nox.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4mwAAACc"]
[Tue Aug 18 13:00:31.330467 2026] [security2:error] [pid 123784:tid 123926] [client 40.74.65.169:60241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wpxml.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4nQAAAAg"]
[Tue Aug 18 13:00:31.334530 2026] [security2:error] [pid 123784:tid 123902] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/file1221.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4ngAAUHE"]
[Tue Aug 18 13:00:31.335267 2026] [security2:error] [pid 123784:tid 123935] [client 158.23.17.4:60738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/pm.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4nwAAABE"]
[Tue Aug 18 13:00:31.354629 2026] [security2:error] [pid 123784:tid 123973] [client 68.155.156.252:62124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/key.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4oQAAADc"]
[Tue Aug 18 13:00:31.417865 2026] [security2:error] [pid 123784:tid 123873] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/cache/"] [unique_id "aoSBn2wDnJBNj2tDbYb4swAALFQ"]
[Tue Aug 18 13:00:31.419585 2026] [security2:error] [pid 123784:tid 124002] [client 20.79.204.6:14079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4tAAAAFQ"]
[Tue Aug 18 13:00:31.451182 2026] [security2:error] [pid 123784:tid 124006] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/images/class-config.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4tgAAAFg"]
[Tue Aug 18 13:00:31.458239 2026] [security2:error] [pid 123784:tid 123892] [remote 115.146.125.52:42002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melocorretordeimoveis.com.br"] [uri "/wp-login.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4twAAa2c"]
[Tue Aug 18 13:00:31.492666 2026] [security2:error] [pid 123784:tid 123918] [client 20.250.13.23:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/default.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4vAAAAAA"]
[Tue Aug 18 13:00:31.499006 2026] [security2:error] [pid 123784:tid 123929] [client 68.155.156.252:32306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/1mage.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4vQAAAAs"]
[Tue Aug 18 13:00:31.507531 2026] [security2:error] [pid 123784:tid 123931] [client 20.104.100.201:34279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/fine.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4vgAAAA0"]
[Tue Aug 18 13:00:31.511062 2026] [security2:error] [pid 123784:tid 123939] [client 68.155.154.236:55481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4vwAAABU"]
[Tue Aug 18 13:00:31.526330 2026] [security2:error] [pid 123784:tid 124022] [client 20.100.169.31:4025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4wgAAAGg"]
[Tue Aug 18 13:00:31.536122 2026] [security2:error] [pid 123784:tid 123954] [client 20.124.247.79:16694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/wpxml.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4wwAAACQ"]
[Tue Aug 18 13:00:31.554952 2026] [security2:error] [pid 123784:tid 123944] [client 20.116.17.175:60473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/srontol.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4xQAAABo"]
[Tue Aug 18 13:00:31.559872 2026] [security2:error] [pid 123784:tid 123989] [client 135.225.78.186:21789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/key.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4xgAAAEc"]
[Tue Aug 18 13:00:31.566110 2026] [security2:error] [pid 123784:tid 124026] [client 158.23.17.4:32556] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "vistadasmangueiras.com.br"] [uri "/1.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4yAAAAGw"]
[Tue Aug 18 13:00:31.566234 2026] [security2:error] [pid 123784:tid 124026] [client 158.23.17.4:32556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/1.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4yAAAAGw"]
[Tue Aug 18 13:00:31.603133 2026] [security2:error] [pid 123784:tid 123848] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/gecko.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4ygAADDs"]
[Tue Aug 18 13:00:31.661916 2026] [security2:error] [pid 123784:tid 123982] [client 158.158.74.177:23687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/nc4.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4zAAAAEA"]
[Tue Aug 18 13:00:31.676003 2026] [security2:error] [pid 123784:tid 123946] [client 213.35.127.232:60451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4zQAAABw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:31.703536 2026] [security2:error] [pid 123784:tid 123971] [client 158.23.17.4:10958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/av.php"] [unique_id "aoSBn2wDnJBNj2tDbYb42QAAADU"]
[Tue Aug 18 13:00:31.723240 2026] [security2:error] [pid 123784:tid 123789] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/inx.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4_AAAJQA"]
[Tue Aug 18 13:00:31.758088 2026] [security2:error] [pid 123784:tid 124010] [client 20.250.27.191:40158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/file59.php"] [unique_id "aoSBn2wDnJBNj2tDbYb5AQAAAFw"]
[Tue Aug 18 13:00:31.776248 2026] [security2:error] [pid 123784:tid 123800] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/"] [unique_id "aoSBn2wDnJBNj2tDbYb5AwAAFgs"]
[Tue Aug 18 13:00:31.816986 2026] [security2:error] [pid 123784:tid 123981] [client 52.173.121.69:57715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBn2wDnJBNj2tDbYb5CgAAAD8"]
[Tue Aug 18 13:00:31.820457 2026] [security2:error] [pid 123784:tid 123993] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/alfa.php"] [unique_id "aoSBn2wDnJBNj2tDbYb5CwAAAEs"]
[Tue Aug 18 13:00:31.820538 2026] [authz_core:error] [pid 123784:tid 123798] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:31.820807 2026] [authz_core:error] [pid 123784:tid 123798] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:31.825974 2026] [security2:error] [pid 123784:tid 123964] [client 20.104.100.201:61989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/loader.php"] [unique_id "aoSBn2wDnJBNj2tDbYb5DQAAAC4"]
[Tue Aug 18 13:00:31.844596 2026] [security2:error] [pid 123784:tid 124031] [client 20.116.17.175:60453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/file5.php"] [unique_id "aoSBn2wDnJBNj2tDbYb5EgAAAHE"]
[Tue Aug 18 13:00:31.879864 2026] [security2:error] [pid 123784:tid 123945] [client 68.155.156.252:7177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/imsc.php"] [unique_id "aoSBn2wDnJBNj2tDbYb5EwAAABs"]
[Tue Aug 18 13:00:31.879864 2026] [security2:error] [pid 123784:tid 123961] [client 20.124.247.79:16705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/file1221.php"] [unique_id "aoSBn2wDnJBNj2tDbYb5FAAAACs"]
[Tue Aug 18 13:00:31.926892 2026] [security2:error] [pid 123784:tid 123990] [client 78.46.215.1:25058] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.parquefazendadasflores.com.br"] [uri "/index.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4MwAAAEg"], referer: https://www.parquefazendadasflores.com.br
[Tue Aug 18 13:00:31.968763 2026] [security2:error] [pid 123784:tid 123915] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/aa.php"] [unique_id "aoSBn2wDnJBNj2tDbYb5GAAAfn4"]
[Tue Aug 18 13:00:31.969247 2026] [security2:error] [pid 123784:tid 124016] [client 20.203.138.185:19767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBn2wDnJBNj2tDbYb5GQAAAGI"]
[Tue Aug 18 13:00:32.018833 2026] [authz_core:error] [pid 123784:tid 123888] [remote 57.141.22.120:28824] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:32.019120 2026] [authz_core:error] [pid 123784:tid 123888] [remote 57.141.22.120:28824] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:32.028176 2026] [security2:error] [pid 123784:tid 124025] [client 168.62.48.100:5588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5HgAAAGs"]
[Tue Aug 18 13:00:32.050354 2026] [security2:error] [pid 123784:tid 124037] [client 20.79.204.6:14108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5IAAAAHc"]
[Tue Aug 18 13:00:32.126763 2026] [security2:error] [pid 123784:tid 124022] [client 158.23.17.4:44852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/88.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5KAAAAGg"]
[Tue Aug 18 13:00:32.143098 2026] [security2:error] [pid 123784:tid 123921] [client 20.226.36.136:65301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5KQAAAAM"]
[Tue Aug 18 13:00:32.144966 2026] [security2:error] [pid 123784:tid 123944] [client 68.155.146.130:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/1.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5KgAAABo"]
[Tue Aug 18 13:00:32.145072 2026] [security2:error] [pid 123784:tid 123944] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/1.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5KgAAABo"]
[Tue Aug 18 13:00:32.145110 2026] [security2:error] [pid 123784:tid 123900] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/0x.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5KwAAFG8"]
[Tue Aug 18 13:00:32.150535 2026] [security2:error] [pid 123784:tid 123851] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/reviall.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5LQAAXj4"]
[Tue Aug 18 13:00:32.154526 2026] [security2:error] [pid 123784:tid 123986] [client 20.116.17.175:12235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/yup.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5LgAAAEQ"]
[Tue Aug 18 13:00:32.163172 2026] [security2:error] [pid 123784:tid 123977] [client 52.22.236.30:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/index.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5HwAAOwg"], referer: https://tecpolorefrigeracaosp.com.br/
[Tue Aug 18 13:00:32.181000 2026] [security2:error] [pid 123784:tid 123997] [client 223.185.37.47:24175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5NAAAAE8"]
[Tue Aug 18 13:00:32.181158 2026] [security2:error] [pid 123784:tid 123997] [client 223.185.37.47:24175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5NAAAAE8"]
[Tue Aug 18 13:00:32.202696 2026] [security2:error] [pid 123784:tid 123937] [client 20.250.27.191:40173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/admin.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5NgAAABM"]
[Tue Aug 18 13:00:32.208074 2026] [security2:error] [pid 123784:tid 123930] [client 20.104.100.201:61399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/zero.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5NwAAAAw"]
[Tue Aug 18 13:00:32.221711 2026] [security2:error] [pid 123784:tid 123948] [client 51.116.232.28:19067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5OAAAAB4"]
[Tue Aug 18 13:00:32.226297 2026] [security2:error] [pid 123784:tid 124020] [client 68.155.156.252:8106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/imscjpg.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5OQAAAGY"]
[Tue Aug 18 13:00:32.254428 2026] [security2:error] [pid 123784:tid 123879] [remote 115.146.125.52:42018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qriarfood.com"] [uri "/wp-login.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5OwAAPlo"]
[Tue Aug 18 13:00:32.274109 2026] [security2:error] [pid 123784:tid 123936] [client 20.79.204.6:10737] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/1.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5PAAAABI"]
[Tue Aug 18 13:00:32.274233 2026] [security2:error] [pid 123784:tid 123936] [client 20.79.204.6:10737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/1.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5PAAAABI"]
[Tue Aug 18 13:00:32.284241 2026] [security2:error] [pid 123784:tid 123929] [client 158.158.74.177:17330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/new.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5PgAAAAs"]
[Tue Aug 18 13:00:32.293306 2026] [security2:error] [pid 123784:tid 123946] [client 20.124.247.79:16640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/nox.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5PwAAABw"]
[Tue Aug 18 13:00:32.294067 2026] [security2:error] [pid 123784:tid 123925] [client 158.23.17.4:25406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/lw.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5QAAAAAc"]
[Tue Aug 18 13:00:32.321806 2026] [security2:error] [pid 123784:tid 123901] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/zxz.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5RQAAHXA"]
[Tue Aug 18 13:00:32.333098 2026] [security2:error] [pid 123784:tid 123933] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5QgAAD3o"]
[Tue Aug 18 13:00:32.410932 2026] [security2:error] [pid 123784:tid 124009] [client 20.100.169.31:38668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5SAAAAFs"]
[Tue Aug 18 13:00:32.472061 2026] [security2:error] [pid 123784:tid 123964] [client 20.116.17.175:58127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5SwAAAC4"]
[Tue Aug 18 13:00:32.510097 2026] [security2:error] [pid 123784:tid 124028] [client 20.104.100.201:34284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/002.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5TgAAAG4"]
[Tue Aug 18 13:00:32.516905 2026] [security2:error] [pid 123784:tid 124034] [client 4.232.94.69:24991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/file56.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5TwAAAHQ"]
[Tue Aug 18 13:00:32.527442 2026] [security2:error] [pid 123784:tid 124001] [client 147.53.121.226:56689] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5UAAAAFM"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/
[Tue Aug 18 13:00:32.529735 2026] [security2:error] [pid 123784:tid 123814] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/www.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5UQAAcBk"]
[Tue Aug 18 13:00:32.540042 2026] [security2:error] [pid 123784:tid 123945] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/222.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5UgAAABs"]
[Tue Aug 18 13:00:32.563048 2026] [security2:error] [pid 123784:tid 123916] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/11.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5VgAAZ38"]
[Tue Aug 18 13:00:32.580147 2026] [security2:error] [pid 123784:tid 124044] [client 68.155.156.252:37256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/chosen.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5VwAAAH4"]
[Tue Aug 18 13:00:32.602518 2026] [security2:error] [pid 123784:tid 124016] [client 158.23.17.4:60293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/dr.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5WAAAAGI"]
[Tue Aug 18 13:00:32.608422 2026] [security2:error] [pid 123784:tid 123987] [client 68.155.156.252:32262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/qlex1.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5WQAAAEU"]
[Tue Aug 18 13:00:32.642774 2026] [security2:error] [pid 123784:tid 124006] [client 51.116.232.28:19013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5WwAAAFg"]
[Tue Aug 18 13:00:32.650176 2026] [security2:error] [pid 123784:tid 124025] [client 20.124.247.79:16673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/akismet.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5XQAAAGs"]
[Tue Aug 18 13:00:32.655161 2026] [security2:error] [pid 123784:tid 123993] [client 20.79.204.6:14062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/lite.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5XgAAAEs"]
[Tue Aug 18 13:00:32.658367 2026] [security2:error] [pid 123784:tid 123963] [client 52.173.121.69:57720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/weozh.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5YAAAAC0"]
[Tue Aug 18 13:00:32.676424 2026] [security2:error] [pid 123784:tid 124037] [client 20.250.27.191:40163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/aa2.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5YQAAAHc"]
[Tue Aug 18 13:00:32.693863 2026] [security2:error] [pid 123784:tid 124045] [client 213.35.127.232:60665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5ZAAAAH8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:32.710378 2026] [security2:error] [pid 123784:tid 123886] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wicked.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5ZQAAVmE"]
[Tue Aug 18 13:00:32.710792 2026] [security2:error] [pid 123784:tid 123931] [client 20.226.56.190:6368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/zj.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5ZgAAAA0"]
[Tue Aug 18 13:00:32.728903 2026] [authz_core:error] [pid 123784:tid 123903] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:32.729337 2026] [authz_core:error] [pid 123784:tid 123903] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:32.748793 2026] [security2:error] [pid 123784:tid 123989] [client 20.203.138.185:10326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ws79.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5aQAAAEc"]
[Tue Aug 18 13:00:32.778100 2026] [security2:error] [pid 123784:tid 124040] [client 79.127.164.8:34732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/wpbackup.bak"] [unique_id "aoSBoGwDnJBNj2tDbYb5agAAAHo"], referer: https://medihub.com.br/wpbackup.bak
[Tue Aug 18 13:00:32.779436 2026] [security2:error] [pid 123784:tid 123962] [client 20.127.136.245:27842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/inputs.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5awAAACw"]
[Tue Aug 18 13:00:32.789288 2026] [security2:error] [pid 123784:tid 124012] [client 158.23.17.4:44813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/hj.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5bAAAAF4"]
[Tue Aug 18 13:00:32.793854 2026] [security2:error] [pid 123784:tid 123974] [client 20.104.100.201:61393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/zxz.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5bQAAADg"]
[Tue Aug 18 13:00:32.839160 2026] [security2:error] [pid 123784:tid 123937] [client 20.116.17.175:58162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-the.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5bgAAABM"]
[Tue Aug 18 13:00:32.867930 2026] [security2:error] [pid 123784:tid 123972] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/asasx.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5bwAAADY"]
[Tue Aug 18 13:00:32.888857 2026] [security2:error] [pid 123784:tid 124013] [client 172.202.39.151:40368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5cQAAAF8"]
[Tue Aug 18 13:00:32.903330 2026] [security2:error] [pid 123784:tid 123956] [client 167.235.143.113:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.antoniopericiacontabil.com.br"] [uri "/index.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5JwAAACY"], referer: https://www.antoniopericiacontabil.com.br/
[Tue Aug 18 13:00:32.904513 2026] [security2:error] [pid 123784:tid 124008] [client 158.158.74.177:23725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/packed.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5dAAAAFo"]
[Tue Aug 18 13:00:32.913311 2026] [security2:error] [pid 123784:tid 123806] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/HLA-dd.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5dQAAYRE"]
[Tue Aug 18 13:00:32.949417 2026] [security2:error] [pid 123784:tid 123929] [client 20.124.247.79:16656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/admin.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5eAAAAAs"]
[Tue Aug 18 13:00:32.984100 2026] [security2:error] [pid 123784:tid 123955] [client 20.65.98.162:56502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/classwithtostring.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5egAAACU"]
[Tue Aug 18 13:00:32.992346 2026] [security2:error] [pid 123784:tid 124043] [client 68.155.156.252:7222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/mariju.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5ewAAAH0"]
[Tue Aug 18 13:00:32.993079 2026] [security2:error] [pid 123784:tid 123942] [client 135.225.78.186:33973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/chosen.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5fAAAABg"]
[Tue Aug 18 13:00:33.018014 2026] [security2:error] [pid 123784:tid 123794] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/File.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5gAAAagU"]
[Tue Aug 18 13:00:33.030383 2026] [security2:error] [pid 123784:tid 123977] [client 20.100.169.31:4011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5gQAAADs"]
[Tue Aug 18 13:00:33.084329 2026] [security2:error] [pid 123784:tid 124009] [client 51.116.232.28:19041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5hgAAAFs"]
[Tue Aug 18 13:00:33.093331 2026] [security2:error] [pid 123784:tid 124010] [client 20.104.100.201:62007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/memberfuns.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5hwAAAFw"]
[Tue Aug 18 13:00:33.097241 2026] [security2:error] [pid 123784:tid 123938] [client 20.79.204.6:10702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/alfa.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5iQAAABQ"]
[Tue Aug 18 13:00:33.105868 2026] [security2:error] [pid 123784:tid 123978] [client 20.250.13.23:53468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/i.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5iwAAADw"]
[Tue Aug 18 13:00:33.107874 2026] [security2:error] [pid 123784:tid 123893] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5jAAAP2g"]
[Tue Aug 18 13:00:33.117181 2026] [security2:error] [pid 123784:tid 123964] [client 20.116.17.175:60016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5jQAAAC4"]
[Tue Aug 18 13:00:33.134982 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:33.135361 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:33.137761 2026] [security2:error] [pid 123784:tid 124028] [client 20.250.27.191:43498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/xamp.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5kAAAAG4"]
[Tue Aug 18 13:00:33.158623 2026] [security2:error] [pid 123784:tid 124001] [client 147.53.121.226:56689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5UAAAAFM"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/
[Tue Aug 18 13:00:33.161667 2026] [security2:error] [pid 123784:tid 124035] [client 158.23.17.4:62993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/vj.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5kQAAAHU"]
[Tue Aug 18 13:00:33.187551 2026] [security2:error] [pid 123784:tid 123935] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/filemanager.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5kgAAABE"]
[Tue Aug 18 13:00:33.190953 2026] [security2:error] [pid 123784:tid 124021] [client 158.23.17.4:33518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ag.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5lAAAAGc"]
[Tue Aug 18 13:00:33.211122 2026] [security2:error] [pid 123784:tid 123968] [client 158.23.17.4:31882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ij.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5lQAAADI"]
[Tue Aug 18 13:00:33.239701 2026] [security2:error] [pid 123784:tid 123919] [client 20.124.247.79:16761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/ajax.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5lgAAAAE"]
[Tue Aug 18 13:00:33.272334 2026] [security2:error] [pid 123784:tid 123940] [client 20.79.204.6:14023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSBoWwDnJBNj2tDbYb5lwAAABY"]
[Tue Aug 18 13:00:33.281309 2026] [security2:error] [pid 123784:tid 124037] [client 52.173.121.69:15054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/rymmm.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5mgAAAHc"]
[Tue Aug 18 13:00:33.298010 2026] [security2:error] [pid 123784:tid 123855] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/cah.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5mwAAf0I"]
[Tue Aug 18 13:00:33.325123 2026] [security2:error] [pid 123784:tid 124022] [client 158.23.17.4:47882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ts.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5nQAAAGg"]
[Tue Aug 18 13:00:33.326081 2026] [security2:error] [pid 123784:tid 123999] [client 20.226.36.136:61487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5ngAAAFE"]
[Tue Aug 18 13:00:33.328779 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:33.329184 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:33.351015 2026] [security2:error] [pid 123784:tid 123974] [client 20.203.138.185:42758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/rtx.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5oQAAADg"]
[Tue Aug 18 13:00:33.357667 2026] [security2:error] [pid 123784:tid 123878] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/fi22.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5ogAAVVk"]
[Tue Aug 18 13:00:33.374069 2026] [security2:error] [pid 123784:tid 123989] [client 167.235.143.113:15928] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.antoniopericiacontabil.com"] [uri "/index.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5nwAAAEc"], referer: https://www.antoniopericiacontabil.com.br/
[Tue Aug 18 13:00:33.396199 2026] [security2:error] [pid 123784:tid 123937] [client 68.155.156.252:8124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5pQAAABM"]
[Tue Aug 18 13:00:33.404578 2026] [security2:error] [pid 123784:tid 124038] [client 20.116.17.175:57950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/xwpg.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5pwAAAHg"]
[Tue Aug 18 13:00:33.424789 2026] [security2:error] [pid 123784:tid 123918] [client 20.127.136.245:27888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/admin.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5qQAAAAA"]
[Tue Aug 18 13:00:33.439706 2026] [security2:error] [pid 123784:tid 123956] [client 20.104.100.201:61434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/aa.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5qgAAACY"]
[Tue Aug 18 13:00:33.465262 2026] [autoindex:error] [pid 123784:tid 123973] [client 20.91.215.254:26311] AH01276: Cannot serve directory /home3/cp38imobibrasil/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:33.474783 2026] [security2:error] [pid 123784:tid 123897] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/css/"] [unique_id "aoSBoWwDnJBNj2tDbYb5rgAAZmw"]
[Tue Aug 18 13:00:33.513517 2026] [security2:error] [pid 123784:tid 123926] [client 51.116.232.28:18959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/av.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5sQAAAAg"]
[Tue Aug 18 13:00:33.557842 2026] [security2:error] [pid 123784:tid 124032] [client 20.250.27.191:45814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/bless.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5tQAAAHI"]
[Tue Aug 18 13:00:33.574772 2026] [security2:error] [pid 123784:tid 123992] [client 37.40.227.74:56961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5uAAAAEo"]
[Tue Aug 18 13:00:33.579095 2026] [security2:error] [pid 123784:tid 123992] [client 37.40.227.74:56961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5uAAAAEo"]
[Tue Aug 18 13:00:33.609122 2026] [security2:error] [pid 123784:tid 124043] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/themes.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5ugAAAH0"]
[Tue Aug 18 13:00:33.629914 2026] [authz_core:error] [pid 123784:tid 123840] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:33.630198 2026] [authz_core:error] [pid 123784:tid 123840] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:33.648796 2026] [security2:error] [pid 123784:tid 123885] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/system_log.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5vgAAamA"]
[Tue Aug 18 13:00:33.674387 2026] [security2:error] [pid 123784:tid 123936] [client 20.100.169.31:4009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5vwAAABI"]
[Tue Aug 18 13:00:33.685819 2026] [security2:error] [pid 123784:tid 123977] [client 158.23.17.4:33419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ud.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5wAAAADs"]
[Tue Aug 18 13:00:33.688468 2026] [security2:error] [pid 123784:tid 123975] [client 20.116.17.175:58121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/dex.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5wQAAADk"]
[Tue Aug 18 13:00:33.710003 2026] [security2:error] [pid 123784:tid 123998] [client 213.35.127.232:60863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5wgAAAFA"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:33.726185 2026] [security2:error] [pid 123784:tid 124009] [client 20.226.56.190:41945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/x.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5wwAAAFs"]
[Tue Aug 18 13:00:33.767649 2026] [security2:error] [pid 123784:tid 124033] [client 158.158.74.177:17284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/plugin.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5xQAAAHM"]
[Tue Aug 18 13:00:33.768500 2026] [security2:error] [pid 123784:tid 123969] [client 68.155.156.252:42234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/contacto.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5xgAAADM"]
[Tue Aug 18 13:00:33.782306 2026] [security2:error] [pid 123784:tid 124007] [client 158.23.17.4:51197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/53.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5yAAAAFk"]
[Tue Aug 18 13:00:33.805474 2026] [security2:error] [pid 123784:tid 123945] [client 158.23.17.4:63784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ig.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5ygAAABs"]
[Tue Aug 18 13:00:33.827707 2026] [security2:error] [pid 123784:tid 123904] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/pomo/"] [unique_id "aoSBoWwDnJBNj2tDbYb5zAAAK3M"]
[Tue Aug 18 13:00:33.831099 2026] [security2:error] [pid 123784:tid 123990] [client 20.104.100.201:61377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/echkm.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5zQAAAEg"]
[Tue Aug 18 13:00:33.837816 2026] [security2:error] [pid 123784:tid 123821] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5zgAAESA"]
[Tue Aug 18 13:00:33.883656 2026] [security2:error] [pid 123784:tid 123934] [client 20.79.204.6:14072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5zwAAABA"]
[Tue Aug 18 13:00:33.906451 2026] [security2:error] [pid 123784:tid 123908] [remote 172.238.58.237:39336] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carlafiorinofraga.adv.br"] [uri "/"] [unique_id "aoSBoWwDnJBNj2tDbYb50AAAAnc"]
[Tue Aug 18 13:00:33.926074 2026] [security2:error] [pid 123784:tid 124018] [client 51.116.232.28:19036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/images.php"] [unique_id "aoSBoWwDnJBNj2tDbYb51AAAAGQ"]
[Tue Aug 18 13:00:33.930537 2026] [security2:error] [pid 123784:tid 123810] [remote 47.128.57.70:46752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "igsautomoveis.com.br"] [uri "/veiculo/1019039/vw-volkswagen-polo-track-1-0-flex-12v-5p-2024"] [unique_id "aoSBoWwDnJBNj2tDbYb51QAAFxU"]
[Tue Aug 18 13:00:33.931665 2026] [authz_core:error] [pid 123784:tid 123842] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:33.932110 2026] [authz_core:error] [pid 123784:tid 123842] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:33.972478 2026] [security2:error] [pid 123784:tid 124037] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBoWwDnJBNj2tDbYb51wAAAHc"]
[Tue Aug 18 13:00:33.978572 2026] [security2:error] [pid 123784:tid 123927] [client 20.250.27.191:27969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/file25.php"] [unique_id "aoSBoWwDnJBNj2tDbYb52AAAAAk"]
[Tue Aug 18 13:00:33.986658 2026] [security2:error] [pid 123784:tid 124004] [client 158.23.17.4:25380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/mimes.php"] [unique_id "aoSBoWwDnJBNj2tDbYb52gAAAFY"]
[Tue Aug 18 13:00:33.986924 2026] [security2:error] [pid 123784:tid 123950] [client 20.79.204.6:10743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/edit.php"] [unique_id "aoSBoWwDnJBNj2tDbYb52wAAACA"]
[Tue Aug 18 13:00:34.003031 2026] [security2:error] [pid 123784:tid 123853] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/user/index.php"] [unique_id "aoSBomwDnJBNj2tDbYb53AAANEA"]
[Tue Aug 18 13:00:34.023539 2026] [security2:error] [pid 123784:tid 123999] [client 20.226.36.136:62185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSBomwDnJBNj2tDbYb53gAAAFE"]
[Tue Aug 18 13:00:34.029695 2026] [security2:error] [pid 123784:tid 123931] [client 192.141.172.134:58033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBomwDnJBNj2tDbYb54AAAAA0"]
[Tue Aug 18 13:00:34.029870 2026] [security2:error] [pid 123784:tid 123931] [client 192.141.172.134:58033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBomwDnJBNj2tDbYb54AAAAA0"]
[Tue Aug 18 13:00:34.053617 2026] [security2:error] [pid 123784:tid 123923] [client 172.202.39.151:53753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/k.php"] [unique_id "aoSBomwDnJBNj2tDbYb54QAAAAU"]
[Tue Aug 18 13:00:34.070364 2026] [security2:error] [pid 123784:tid 124003] [client 20.116.17.175:58156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/xyn.php"] [unique_id "aoSBomwDnJBNj2tDbYb54gAAAFU"]
[Tue Aug 18 13:00:34.081365 2026] [security2:error] [pid 123784:tid 123997] [client 20.65.98.162:55224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/wp-ws68.php"] [unique_id "aoSBomwDnJBNj2tDbYb54wAAAE8"]
[Tue Aug 18 13:00:34.095266 2026] [security2:error] [pid 123784:tid 123980] [client 20.226.56.190:42471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/yn.php"] [unique_id "aoSBomwDnJBNj2tDbYb55AAAAD4"]
[Tue Aug 18 13:00:34.132179 2026] [security2:error] [pid 123784:tid 124041] [client 49.13.164.148:61698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "orientadoraespiritualbhsp.com.br"] [uri "/index.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5RAAAAHs"], referer: http://orientadoraespiritualbhsp.com.br/
[Tue Aug 18 13:00:34.133930 2026] [security2:error] [pid 123784:tid 124032] [client 20.104.100.201:61972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/domvf.php"] [unique_id "aoSBomwDnJBNj2tDbYb56wAAAHI"]
[Tue Aug 18 13:00:34.147130 2026] [security2:error] [pid 123784:tid 123946] [client 172.202.39.151:4694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/system_log.php"] [unique_id "aoSBomwDnJBNj2tDbYb57AAAABw"]
[Tue Aug 18 13:00:34.176239 2026] [security2:error] [pid 123784:tid 124025] [client 20.226.56.190:42467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/11.php"] [unique_id "aoSBomwDnJBNj2tDbYb57QAAAGs"]
[Tue Aug 18 13:00:34.196515 2026] [security2:error] [pid 123784:tid 123869] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/ioxi-o.php"] [unique_id "aoSBomwDnJBNj2tDbYb58AAAKlA"]
[Tue Aug 18 13:00:34.205158 2026] [security2:error] [pid 123784:tid 123936] [client 20.203.138.185:18849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/end.php"] [unique_id "aoSBomwDnJBNj2tDbYb58gAAABI"]
[Tue Aug 18 13:00:34.213382 2026] [security2:error] [pid 123784:tid 123899] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSBomwDnJBNj2tDbYb59AAAKG4"]
[Tue Aug 18 13:00:34.235465 2026] [authz_core:error] [pid 123784:tid 123905] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:34.235899 2026] [authz_core:error] [pid 123784:tid 123905] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:34.241517 2026] [security2:error] [pid 123784:tid 123921] [client 68.155.156.252:42202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/image2.php"] [unique_id "aoSBomwDnJBNj2tDbYb59gAAAAM"]
[Tue Aug 18 13:00:34.245556 2026] [security2:error] [pid 123784:tid 123938] [client 20.226.56.190:20923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/vm.php"] [unique_id "aoSBomwDnJBNj2tDbYb59wAAABQ"]
[Tue Aug 18 13:00:34.261807 2026] [security2:error] [pid 123784:tid 123981] [client 135.225.78.186:37147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/wpxml.php"] [unique_id "aoSBomwDnJBNj2tDbYb5-AAAAD8"]
[Tue Aug 18 13:00:34.278434 2026] [security2:error] [pid 123784:tid 123964] [client 167.235.143.113:59918] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.antoniopericiacontabil.com"] [uri "/index.php"] [unique_id "aoSBoWwDnJBNj2tDbYb51gAAAC4"], referer: https://www.antoniopericiacontabil.com.br/
[Tue Aug 18 13:00:34.302255 2026] [security2:error] [pid 123784:tid 124030] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/buy.php"] [unique_id "aoSBomwDnJBNj2tDbYb5-gAAAHA"]
[Tue Aug 18 13:00:34.302287 2026] [security2:error] [pid 123784:tid 124038] [client 20.100.169.31:4017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSBomwDnJBNj2tDbYb5-wAAAHg"]
[Tue Aug 18 13:00:34.322535 2026] [security2:error] [pid 123784:tid 123962] [client 158.23.17.4:9324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ta.php"] [unique_id "aoSBomwDnJBNj2tDbYb5_AAAACw"]
[Tue Aug 18 13:00:34.336464 2026] [security2:error] [pid 123784:tid 123933] [client 4.232.94.69:14577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/2.php"] [unique_id "aoSBomwDnJBNj2tDbYb5_QAAAA8"]
[Tue Aug 18 13:00:34.350307 2026] [security2:error] [pid 123784:tid 124035] [client 20.226.56.190:21151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/eg.php"] [unique_id "aoSBomwDnJBNj2tDbYb5_gAAAHU"]
[Tue Aug 18 13:00:34.350876 2026] [security2:error] [pid 123784:tid 123961] [client 20.116.17.175:58122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBomwDnJBNj2tDbYb5_wAAACs"]
[Tue Aug 18 13:00:34.364419 2026] [security2:error] [pid 123784:tid 123990] [client 158.23.17.4:15105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/lq.php"] [unique_id "aoSBomwDnJBNj2tDbYb6AQAAAEg"]
[Tue Aug 18 13:00:34.370684 2026] [security2:error] [pid 123784:tid 123948] [client 51.116.232.28:18972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/ops.php"] [unique_id "aoSBomwDnJBNj2tDbYb6AgAAAB4"]
[Tue Aug 18 13:00:34.383426 2026] [security2:error] [pid 123784:tid 123790] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/abc.php"] [unique_id "aoSBomwDnJBNj2tDbYb6BAAAQwE"]
[Tue Aug 18 13:00:34.407408 2026] [security2:error] [pid 123784:tid 123968] [client 158.23.17.4:40429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ni.php"] [unique_id "aoSBomwDnJBNj2tDbYb6BwAAADI"]
[Tue Aug 18 13:00:34.419343 2026] [security2:error] [pid 123784:tid 123987] [client 20.226.56.190:17979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/uk.php"] [unique_id "aoSBomwDnJBNj2tDbYb6CAAAAEU"]
[Tue Aug 18 13:00:34.423359 2026] [security2:error] [pid 123784:tid 123988] [client 20.250.27.191:27979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/file15.php"] [unique_id "aoSBomwDnJBNj2tDbYb6CQAAAEY"]
[Tue Aug 18 13:00:34.432138 2026] [security2:error] [pid 123784:tid 123957] [client 20.226.56.190:21179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/creds.php"] [unique_id "aoSBomwDnJBNj2tDbYb6CgAAACc"]
[Tue Aug 18 13:00:34.437443 2026] [security2:error] [pid 123784:tid 124009] [client 20.127.136.245:28059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/goods.php"] [unique_id "aoSBomwDnJBNj2tDbYb6CwAAAFs"]
[Tue Aug 18 13:00:34.448784 2026] [security2:error] [pid 123784:tid 124018] [client 158.23.17.4:31892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ip.php"] [unique_id "aoSBomwDnJBNj2tDbYb6DAAAAGQ"]
[Tue Aug 18 13:00:34.484633 2026] [security2:error] [pid 123784:tid 123913] [remote 172.238.58.237:39340] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carlafiorinofraga.adv.br"] [uri "/"] [unique_id "aoSBomwDnJBNj2tDbYb6DwAAbnw"]
[Tue Aug 18 13:00:34.486578 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.56.190:8311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ho.php"] [unique_id "aoSBomwDnJBNj2tDbYb6EAAAAH8"]
[Tue Aug 18 13:00:34.507949 2026] [security2:error] [pid 123784:tid 124014] [client 20.79.204.6:14094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSBomwDnJBNj2tDbYb6EQAAAGA"]
[Tue Aug 18 13:00:34.511267 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.36.136:52652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSBomwDnJBNj2tDbYb6EgAAAFI"]
[Tue Aug 18 13:00:34.549692 2026] [security2:error] [pid 123784:tid 123949] [client 20.104.100.201:62014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/red.php"] [unique_id "aoSBomwDnJBNj2tDbYb6FQAAAB8"]
[Tue Aug 18 13:00:34.553471 2026] [security2:error] [pid 123784:tid 123796] [remote 172.238.58.237:39356] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carlaflorianofraga.adv.br"] [uri "/"] [unique_id "aoSBomwDnJBNj2tDbYb6FAAAEQc"]
[Tue Aug 18 13:00:34.567807 2026] [security2:error] [pid 123784:tid 124003] [client 68.155.156.252:21376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/wpxml.php"] [unique_id "aoSBomwDnJBNj2tDbYb6FwAAAFU"]
[Tue Aug 18 13:00:34.576122 2026] [security2:error] [pid 123784:tid 123802] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBomwDnJBNj2tDbYb6GAAAIg0"]
[Tue Aug 18 13:00:34.576262 2026] [security2:error] [pid 123784:tid 123952] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBomwDnJBNj2tDbYb6GAAAIg0"]
[Tue Aug 18 13:00:34.604654 2026] [security2:error] [pid 123784:tid 123993] [client 158.158.74.177:23740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/public/moon.php"] [unique_id "aoSBomwDnJBNj2tDbYb6HAAAAEs"]
[Tue Aug 18 13:00:34.609035 2026] [security2:error] [pid 123784:tid 123852] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBomwDnJBNj2tDbYb6HgAAXz8"]
[Tue Aug 18 13:00:34.620758 2026] [security2:error] [pid 123784:tid 123887] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/akcc.php"] [unique_id "aoSBomwDnJBNj2tDbYb6HwAAAGI"]
[Tue Aug 18 13:00:34.654735 2026] [security2:error] [pid 123784:tid 123982] [client 20.226.56.190:10570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/97.php"] [unique_id "aoSBomwDnJBNj2tDbYb6IgAAAEA"]
[Tue Aug 18 13:00:34.654803 2026] [security2:error] [pid 123784:tid 123953] [client 68.155.156.252:23141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/fb.php"] [unique_id "aoSBomwDnJBNj2tDbYb6IQAAACM"]
[Tue Aug 18 13:00:34.667990 2026] [security2:error] [pid 123784:tid 123976] [client 20.116.17.175:58169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-good.php"] [unique_id "aoSBomwDnJBNj2tDbYb6IwAAADo"]
[Tue Aug 18 13:00:34.670464 2026] [security2:error] [pid 123784:tid 123924] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/dropdown.php"] [unique_id "aoSBomwDnJBNj2tDbYb6JAAAAAY"]
[Tue Aug 18 13:00:34.673284 2026] [security2:error] [pid 123784:tid 123928] [client 20.65.98.162:41709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/mgrr.php"] [unique_id "aoSBomwDnJBNj2tDbYb6JQAAAAo"]
[Tue Aug 18 13:00:34.690744 2026] [authz_core:error] [pid 123784:tid 123800] [remote 57.141.22.85:47140] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:34.691194 2026] [authz_core:error] [pid 123784:tid 123800] [remote 57.141.22.85:47140] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:34.724769 2026] [security2:error] [pid 123784:tid 123995] [client 213.35.127.232:61049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBomwDnJBNj2tDbYb6KAAAAE0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:34.728314 2026] [security2:error] [pid 123784:tid 124023] [client 49.13.164.148:31140] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "orientadoraespiritualbhsp.com.br"] [uri "/index.php"] [unique_id "aoSBomwDnJBNj2tDbYb6JwAAAGk"], referer: http://orientadoraespiritualbhsp.com.br/
[Tue Aug 18 13:00:34.749311 2026] [security2:error] [pid 123784:tid 123936] [client 52.173.121.69:42918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/lddxs.php"] [unique_id "aoSBomwDnJBNj2tDbYb6KwAAABI"]
[Tue Aug 18 13:00:34.755375 2026] [security2:error] [pid 123784:tid 124037] [client 20.79.204.6:10699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/elp.php"] [unique_id "aoSBomwDnJBNj2tDbYb6LAAAAHc"]
[Tue Aug 18 13:00:34.783992 2026] [security2:error] [pid 123784:tid 123958] [client 51.116.232.28:19043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/coffexium.php"] [unique_id "aoSBomwDnJBNj2tDbYb6LQAAACg"]
[Tue Aug 18 13:00:34.798412 2026] [security2:error] [pid 123784:tid 123910] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wk/index.php"] [unique_id "aoSBomwDnJBNj2tDbYb6LwAAA3k"]
[Tue Aug 18 13:00:34.832080 2026] [authz_core:error] [pid 123784:tid 123836] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:34.832353 2026] [authz_core:error] [pid 123784:tid 123836] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:34.853092 2026] [security2:error] [pid 123784:tid 123964] [client 20.104.100.201:61963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/JawirGenk.php"] [unique_id "aoSBomwDnJBNj2tDbYb6MwAAAC4"]
[Tue Aug 18 13:00:34.918408 2026] [security2:error] [pid 123784:tid 123791] [remote 66.102.134.13:33162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.134.102.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samarapraseres.com.br"] [uri "/wp-login.php"] [unique_id "aoSBomwDnJBNj2tDbYb6NwAAJgI"]
[Tue Aug 18 13:00:34.922178 2026] [security2:error] [pid 123784:tid 123962] [client 20.38.3.247:19580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBomwDnJBNj2tDbYb6OQAAACw"]
[Tue Aug 18 13:00:34.929842 2026] [security2:error] [pid 123784:tid 123854] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSBomwDnJBNj2tDbYb6OgAAD0E"]
[Tue Aug 18 13:00:34.948603 2026] [security2:error] [pid 123784:tid 123990] [client 20.116.17.175:59971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wmore1.php"] [unique_id "aoSBomwDnJBNj2tDbYb6PQAAAEg"]
[Tue Aug 18 13:00:34.954794 2026] [security2:error] [pid 123784:tid 123960] [client 20.100.169.31:38687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBomwDnJBNj2tDbYb6PgAAACo"]
[Tue Aug 18 13:00:34.972896 2026] [security2:error] [pid 123784:tid 123805] [remote 172.202.39.151:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.mrvprojetos.com"] [uri "/1.php"] [unique_id "aoSBomwDnJBNj2tDbYb6QAAAMRA"]
[Tue Aug 18 13:00:34.972996 2026] [security2:error] [pid 123784:tid 123805] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/1.php"] [unique_id "aoSBomwDnJBNj2tDbYb6QAAAMRA"]
[Tue Aug 18 13:00:34.989999 2026] [security2:error] [pid 123784:tid 123988] [client 172.202.39.151:44607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSBomwDnJBNj2tDbYb6QQAAAEY"]
[Tue Aug 18 13:00:34.993847 2026] [security2:error] [pid 123784:tid 123920] [client 158.23.17.4:34120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/99.php"] [unique_id "aoSBomwDnJBNj2tDbYb6QgAAAAI"]
[Tue Aug 18 13:00:35.001881 2026] [security2:error] [pid 123784:tid 123957] [client 20.226.56.190:42449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/rh.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6QwAAACc"]
[Tue Aug 18 13:00:35.005360 2026] [security2:error] [pid 123784:tid 124009] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/inputs.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6RQAAAFs"]
[Tue Aug 18 13:00:35.023250 2026] [security2:error] [pid 123784:tid 124006] [client 20.203.138.185:29933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ae.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6RwAAAFg"]
[Tue Aug 18 13:00:35.036793 2026] [security2:error] [pid 123784:tid 123941] [client 68.155.156.252:23155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/gi.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6SAAAABc"]
[Tue Aug 18 13:00:35.038818 2026] [security2:error] [pid 123784:tid 123940] [client 158.23.17.4:15120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/you.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6SQAAABY"]
[Tue Aug 18 13:00:35.043075 2026] [security2:error] [pid 123784:tid 124042] [client 168.62.48.100:5572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6SwAAAHw"]
[Tue Aug 18 13:00:35.047702 2026] [security2:error] [pid 123784:tid 123871] [remote 172.238.58.237:39362] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carlafiorinofraga.adv.br"] [uri "/"] [unique_id "aoSBo2wDnJBNj2tDbYb6SgAAcVI"]
[Tue Aug 18 13:00:35.050580 2026] [security2:error] [pid 123784:tid 124028] [client 20.250.27.191:35672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/f35.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6TAAAAG4"]
[Tue Aug 18 13:00:35.051229 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.56.190:10595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/yg.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6TQAAAH8"]
[Tue Aug 18 13:00:35.073657 2026] [security2:error] [pid 123784:tid 124010] [client 45.131.193.56:44775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.193.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nasbeauty.com.br"] [uri "/wp-login.php"] [unique_id "aoSBomwDnJBNj2tDbYb6NgAAAFw"]
[Tue Aug 18 13:00:35.092318 2026] [security2:error] [pid 123784:tid 123966] [client 20.226.56.190:8279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/et.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6TgAAADA"]
[Tue Aug 18 13:00:35.105004 2026] [security2:error] [pid 123784:tid 123875] [remote 172.238.58.237:39368] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carlaflorianofraga.adv.br"] [uri "/"] [unique_id "aoSBo2wDnJBNj2tDbYb6TwAAeFY"]
[Tue Aug 18 13:00:35.132097 2026] [security2:error] [pid 123784:tid 124030] [client 20.79.204.6:13710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6UwAAAHA"]
[Tue Aug 18 13:00:35.135798 2026] [security2:error] [pid 123784:tid 123971] [client 18.192.166.72:51060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "ancavisi.com.br"] [uri "/index.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5twAAADU"], referer: http://ancavisi.com.br/
[Tue Aug 18 13:00:35.153397 2026] [security2:error] [pid 123784:tid 123989] [client 20.104.100.201:61993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/options.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6VAAAAEc"]
[Tue Aug 18 13:00:35.166029 2026] [security2:error] [pid 123784:tid 123811] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/x/index.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6VwAAExY"]
[Tue Aug 18 13:00:35.172444 2026] [security2:error] [pid 123784:tid 123993] [client 158.23.17.4:29445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/34.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6WAAAAEs"]
[Tue Aug 18 13:00:35.206761 2026] [security2:error] [pid 123784:tid 124015] [client 51.116.232.28:18957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/BDKR28WP.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6WwAAAGE"]
[Tue Aug 18 13:00:35.223318 2026] [security2:error] [pid 123784:tid 123953] [client 20.116.17.175:60027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/special.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6XgAAACM"]
[Tue Aug 18 13:00:35.233584 2026] [security2:error] [pid 123784:tid 124018] [client 4.232.94.69:25524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6YAAAAGQ"]
[Tue Aug 18 13:00:35.233615 2026] [security2:error] [pid 123784:tid 123929] [client 158.158.74.177:17333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/public/storage.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6XwAAAAs"]
[Tue Aug 18 13:00:35.240341 2026] [security2:error] [pid 123784:tid 123946] [client 20.226.36.136:53530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6YQAAABw"]
[Tue Aug 18 13:00:35.254384 2026] [security2:error] [pid 123784:tid 124025] [client 172.202.39.151:4443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-admin/user/index.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6YgAAAGs"]
[Tue Aug 18 13:00:35.259336 2026] [security2:error] [pid 123784:tid 123995] [client 158.23.17.4:20353] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/1.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6YwAAAE0"]
[Tue Aug 18 13:00:35.259443 2026] [security2:error] [pid 123784:tid 123995] [client 158.23.17.4:20353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/1.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6YwAAAE0"]
[Tue Aug 18 13:00:35.283929 2026] [security2:error] [pid 123784:tid 123950] [client 20.127.136.245:27897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/file.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6ZAAAACA"]
[Tue Aug 18 13:00:35.292084 2026] [security2:error] [pid 123784:tid 124026] [client 196.12.128.158:51293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6ZgAAAGw"]
[Tue Aug 18 13:00:35.292234 2026] [security2:error] [pid 123784:tid 124026] [client 196.12.128.158:51293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6ZgAAAGw"]
[Tue Aug 18 13:00:35.297492 2026] [security2:error] [pid 123784:tid 124037] [client 20.226.56.190:6535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/of.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6ZwAAAHc"]
[Tue Aug 18 13:00:35.297877 2026] [security2:error] [pid 123784:tid 123900] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6aAAAdm8"]
[Tue Aug 18 13:00:35.335914 2026] [security2:error] [pid 123784:tid 123981] [client 52.173.121.69:60127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/zjggu.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6agAAAD8"]
[Tue Aug 18 13:00:35.350627 2026] [security2:error] [pid 123784:tid 123797] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/index.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6bQAADAg"]
[Tue Aug 18 13:00:35.354798 2026] [security2:error] [pid 123784:tid 123964] [client 68.155.156.252:37270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/file1221.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6bgAAAC4"]
[Tue Aug 18 13:00:35.384638 2026] [security2:error] [pid 123784:tid 123945] [client 68.155.156.252:7170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/video.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6cQAAABs"]
[Tue Aug 18 13:00:35.414750 2026] [security2:error] [pid 123784:tid 123998] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/100.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6cgAAAFA"]
[Tue Aug 18 13:00:35.414988 2026] [security2:error] [pid 123784:tid 123960] [client 20.65.98.162:56508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/55.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6cwAAACo"]
[Tue Aug 18 13:00:35.427016 2026] [security2:error] [pid 123784:tid 123967] [client 158.23.17.4:34030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/er.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6dAAAADE"]
[Tue Aug 18 13:00:35.463447 2026] [security2:error] [pid 123784:tid 123988] [client 20.226.56.190:7301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/bu.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6dQAAAEY"]
[Tue Aug 18 13:00:35.509272 2026] [security2:error] [pid 123784:tid 124001] [client 20.116.17.175:58112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6dwAAAFM"]
[Tue Aug 18 13:00:35.520339 2026] [security2:error] [pid 123784:tid 123941] [client 20.226.56.190:10587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/rn.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6eAAAABc"]
[Tue Aug 18 13:00:35.531599 2026] [security2:error] [pid 123784:tid 123823] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/as.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6eQAAcSI"]
[Tue Aug 18 13:00:35.554146 2026] [security2:error] [pid 123784:tid 124004] [client 20.104.100.201:34268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6ewAAAFY"]
[Tue Aug 18 13:00:35.561014 2026] [authz_core:error] [pid 123784:tid 124044] [client 192.178.4.133:41600] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:35.561448 2026] [authz_core:error] [pid 123784:tid 124044] [client 192.178.4.133:41600] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:35.567226 2026] [security2:error] [pid 123784:tid 123970] [client 20.226.56.190:17920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ut.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6fQAAADQ"]
[Tue Aug 18 13:00:35.576056 2026] [security2:error] [pid 123784:tid 124016] [client 20.100.169.31:3991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSBo2wDnJBNj2tDbYb6fgAAAGI"]
[Tue Aug 18 13:00:35.588060 2026] [security2:error] [pid 123784:tid 124038] [client 20.226.36.136:62151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6fwAAAHg"]
[Tue Aug 18 13:00:35.603592 2026] [security2:error] [pid 123784:tid 123818] [remote 172.238.58.237:39374] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carlafiorinofraga.adv.br"] [uri "/"] [unique_id "aoSBo2wDnJBNj2tDbYb6gAAAHh0"]
[Tue Aug 18 13:00:35.618317 2026] [security2:error] [pid 123784:tid 123881] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6gQAAJVw"]
[Tue Aug 18 13:00:35.633370 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.56.190:10582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/eh.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6hAAAAEc"]
[Tue Aug 18 13:00:35.656083 2026] [security2:error] [pid 123784:tid 123911] [remote 172.238.58.237:39390] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carlaflorianofraga.adv.br"] [uri "/"] [unique_id "aoSBo2wDnJBNj2tDbYb6hwAAEHo"]
[Tue Aug 18 13:00:35.700392 2026] [authz_core:error] [pid 123784:tid 124014] [client 192.178.4.134:57534] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:35.700664 2026] [authz_core:error] [pid 123784:tid 124014] [client 192.178.4.134:57534] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:35.709100 2026] [security2:error] [pid 123784:tid 123987] [client 197.184.64.235:41958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6iQAAAEU"]
[Tue Aug 18 13:00:35.712692 2026] [security2:error] [pid 123784:tid 123937] [client 20.250.27.191:40175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-load.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6iwAAABM"]
[Tue Aug 18 13:00:35.712762 2026] [security2:error] [pid 123784:tid 123795] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6igAAOwY"]
[Tue Aug 18 13:00:35.713697 2026] [security2:error] [pid 123784:tid 123987] [client 197.184.64.235:41958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6iQAAAEU"]
[Tue Aug 18 13:00:35.715552 2026] [security2:error] [pid 123784:tid 123993] [client 51.116.232.28:18946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/sf.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6jQAAAEs"]
[Tue Aug 18 13:00:35.737766 2026] [security2:error] [pid 123784:tid 124011] [client 68.155.156.252:8090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/hel.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6kgAAAF0"]
[Tue Aug 18 13:00:35.739812 2026] [security2:error] [pid 123784:tid 123973] [client 20.226.36.136:53526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6kwAAADc"]
[Tue Aug 18 13:00:35.742017 2026] [security2:error] [pid 123784:tid 123986] [client 20.226.56.190:8265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ad.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6lQAAAEQ"]
[Tue Aug 18 13:00:35.749113 2026] [security2:error] [pid 123784:tid 124015] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/akc.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6lgAAAGE"]
[Tue Aug 18 13:00:35.750516 2026] [security2:error] [pid 123784:tid 123990] [client 213.35.127.232:61255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6lwAAAEg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:35.750973 2026] [security2:error] [pid 123784:tid 123931] [client 20.127.136.245:28304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/adminfuns.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6mAAAAA0"]
[Tue Aug 18 13:00:35.784592 2026] [security2:error] [pid 123784:tid 123943] [client 20.79.204.6:14103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6mQAAABk"]
[Tue Aug 18 13:00:35.792350 2026] [security2:error] [pid 123784:tid 124018] [client 20.116.17.175:60448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/thoms.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6mgAAAGQ"]
[Tue Aug 18 13:00:35.797190 2026] [security2:error] [pid 123784:tid 123928] [client 158.23.17.4:9391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/he.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6mwAAAAo"]
[Tue Aug 18 13:00:35.817705 2026] [security2:error] [pid 123784:tid 124012] [client 20.226.56.190:11638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/vd.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6nAAAAF4"]
[Tue Aug 18 13:00:35.851114 2026] [security2:error] [pid 123784:tid 123997] [client 158.158.74.177:17342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/radio.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6oQAAAE8"]
[Tue Aug 18 13:00:35.854403 2026] [security2:error] [pid 123784:tid 123932] [client 20.79.204.6:10370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6ogAAAA4"]
[Tue Aug 18 13:00:35.869732 2026] [security2:error] [pid 123784:tid 123940] [client 18.192.166.72:1694] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ancavisi.com.br"] [uri "/index.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6jAAAABY"], referer: http://ancavisi.com.br/
[Tue Aug 18 13:00:35.892956 2026] [security2:error] [pid 123784:tid 124036] [client 158.23.17.4:34159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/qk.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6pQAAAHY"]
[Tue Aug 18 13:00:35.893866 2026] [security2:error] [pid 123784:tid 123958] [client 20.151.109.219:63989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6pgAAACg"]
[Tue Aug 18 13:00:35.897953 2026] [security2:error] [pid 123784:tid 123886] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-config-sample.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6pwAAFGE"]
[Tue Aug 18 13:00:35.932504 2026] [security2:error] [pid 123784:tid 124039] [client 68.155.156.252:12604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/nox.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6qgAAAHk"]
[Tue Aug 18 13:00:35.937599 2026] [security2:error] [pid 123784:tid 123833] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/media.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6qwAACSw"]
[Tue Aug 18 13:00:35.943808 2026] [security2:error] [pid 123784:tid 123991] [client 20.104.100.201:62010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6rAAAAEk"]
[Tue Aug 18 13:00:35.950922 2026] [authz_core:error] [pid 123784:tid 123806] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:35.951165 2026] [authz_core:error] [pid 123784:tid 123806] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:35.962333 2026] [security2:error] [pid 123784:tid 123933] [client 20.65.98.162:55202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/ajax.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6rgAAAA8"]
[Tue Aug 18 13:00:35.965259 2026] [security2:error] [pid 123784:tid 124035] [client 20.226.56.190:10609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/56.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6rwAAAHU"]
[Tue Aug 18 13:00:35.990837 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:54774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ez.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6sAAAAH0"]
[Tue Aug 18 13:00:35.995249 2026] [security2:error] [pid 123784:tid 123968] [client 20.226.56.190:20914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/rx.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6sgAAADI"]
[Tue Aug 18 13:00:36.018874 2026] [security2:error] [pid 123784:tid 123959] [client 20.226.56.190:20914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/mandrill.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6tQAAACk"]
[Tue Aug 18 13:00:36.104997 2026] [security2:error] [pid 123784:tid 124016] [client 20.38.3.247:53932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/fpwch.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6uAAAAGI"]
[Tue Aug 18 13:00:36.106853 2026] [security2:error] [pid 123784:tid 124038] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6uQAAAHg"]
[Tue Aug 18 13:00:36.112233 2026] [security2:error] [pid 123784:tid 123824] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6ugAAZSM"]
[Tue Aug 18 13:00:36.115087 2026] [security2:error] [pid 123784:tid 123948] [client 20.116.17.175:58130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6uwAAAB4"]
[Tue Aug 18 13:00:36.128520 2026] [security2:error] [pid 123784:tid 123971] [client 20.226.56.190:42469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/main.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6vQAAADU"]
[Tue Aug 18 13:00:36.151219 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.56.190:8310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ga.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6wwAAAEc"]
[Tue Aug 18 13:00:36.151959 2026] [security2:error] [pid 123784:tid 124003] [client 20.65.98.162:18304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/sky.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6xAAAAFU"]
[Tue Aug 18 13:00:36.157687 2026] [security2:error] [pid 123784:tid 124021] [client 51.116.232.28:19023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/k.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6xQAAAGc"]
[Tue Aug 18 13:00:36.207812 2026] [security2:error] [pid 123784:tid 123829] [remote 172.238.58.237:39404] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carlaflorianofraga.adv.br"] [uri "/"] [unique_id "aoSBpGwDnJBNj2tDbYb6yAAAASg"]
[Tue Aug 18 13:00:36.210001 2026] [security2:error] [pid 123784:tid 123965] [client 20.100.169.31:19776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6yQAAAC8"]
[Tue Aug 18 13:00:36.218523 2026] [security2:error] [pid 123784:tid 123918] [client 20.226.36.136:61479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6ygAAAAA"]
[Tue Aug 18 13:00:36.224974 2026] [security2:error] [pid 123784:tid 124011] [client 20.226.56.190:10604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wb.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6ywAAAF0"]
[Tue Aug 18 13:00:36.225424 2026] [security2:error] [pid 123784:tid 124013] [client 20.151.109.219:60894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6zAAAAF8"]
[Tue Aug 18 13:00:36.230414 2026] [security2:error] [pid 123784:tid 123973] [client 68.155.156.252:48126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/grok.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6zQAAADc"]
[Tue Aug 18 13:00:36.252119 2026] [authz_core:error] [pid 123784:tid 123860] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:36.252386 2026] [authz_core:error] [pid 123784:tid 123860] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:36.272044 2026] [security2:error] [pid 123784:tid 123953] [client 20.104.100.201:61955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/output.php"] [unique_id "aoSBpGwDnJBNj2tDbYb60QAAACM"]
[Tue Aug 18 13:00:36.276481 2026] [security2:error] [pid 123784:tid 123996] [client 158.23.17.4:57664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSBpGwDnJBNj2tDbYb60gAAAE4"]
[Tue Aug 18 13:00:36.283956 2026] [security2:error] [pid 123784:tid 123884] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/inso.php"] [unique_id "aoSBpGwDnJBNj2tDbYb60wAAGV8"]
[Tue Aug 18 13:00:36.310941 2026] [security2:error] [pid 123784:tid 123895] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBpGwDnJBNj2tDbYb61gAAZGo"]
[Tue Aug 18 13:00:36.314838 2026] [security2:error] [pid 123784:tid 123928] [client 20.79.204.6:2233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBpGwDnJBNj2tDbYb61wAAAAo"]
[Tue Aug 18 13:00:36.320780 2026] [security2:error] [pid 123784:tid 123946] [client 20.226.36.136:61463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSBpGwDnJBNj2tDbYb62AAAABw"]
[Tue Aug 18 13:00:36.325708 2026] [security2:error] [pid 123784:tid 124005] [client 52.173.121.69:48430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/dlvqo.php"] [unique_id "aoSBpGwDnJBNj2tDbYb62QAAAFc"]
[Tue Aug 18 13:00:36.336310 2026] [security2:error] [pid 123784:tid 123995] [client 68.221.73.131:46213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBpGwDnJBNj2tDbYb62gAAAE0"]
[Tue Aug 18 13:00:36.344497 2026] [security2:error] [pid 123784:tid 123992] [client 20.226.56.190:20925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xn.php"] [unique_id "aoSBpGwDnJBNj2tDbYb62wAAAEo"]
[Tue Aug 18 13:00:36.387597 2026] [security2:error] [pid 123784:tid 123922] [client 20.116.17.175:58155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/root.php"] [unique_id "aoSBpGwDnJBNj2tDbYb63QAAAAQ"]
[Tue Aug 18 13:00:36.399852 2026] [security2:error] [pid 123784:tid 124037] [client 168.62.48.100:5626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSBpGwDnJBNj2tDbYb64AAAAHc"]
[Tue Aug 18 13:00:36.410357 2026] [security2:error] [pid 123784:tid 123937] [client 20.127.136.245:27863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/404.php"] [unique_id "aoSBpGwDnJBNj2tDbYb64QAAABM"]
[Tue Aug 18 13:00:36.417217 2026] [security2:error] [pid 123784:tid 123930] [client 20.226.56.190:21149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/47.php"] [unique_id "aoSBpGwDnJBNj2tDbYb64gAAAAw"]
[Tue Aug 18 13:00:36.417612 2026] [security2:error] [pid 123784:tid 123969] [client 158.23.17.4:38874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/gz.php"] [unique_id "aoSBpGwDnJBNj2tDbYb64wAAADM"]
[Tue Aug 18 13:00:36.449309 2026] [security2:error] [pid 123784:tid 124020] [client 79.127.164.8:32906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/wpbackup.sql"] [unique_id "aoSBpGwDnJBNj2tDbYb65QAAAGY"], referer: https://medihub.com.br/wpbackup.sql
[Tue Aug 18 13:00:36.451329 2026] [security2:error] [pid 123784:tid 124017] [client 4.232.94.69:31424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBpGwDnJBNj2tDbYb65gAAAGM"]
[Tue Aug 18 13:00:36.458268 2026] [security2:error] [pid 123784:tid 123961] [client 20.250.13.23:44072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSBpGwDnJBNj2tDbYb65wAAACs"]
[Tue Aug 18 13:00:36.469190 2026] [security2:error] [pid 123784:tid 123931] [client 158.158.74.177:23690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/root.php"] [unique_id "aoSBpGwDnJBNj2tDbYb66QAAAA0"]
[Tue Aug 18 13:00:36.490631 2026] [security2:error] [pid 123784:tid 123863] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/images/smilies/"] [unique_id "aoSBpGwDnJBNj2tDbYb67AAAQ0o"]
[Tue Aug 18 13:00:36.514649 2026] [security2:error] [pid 123784:tid 124030] [client 20.79.204.6:2193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/0x.php"] [unique_id "aoSBpGwDnJBNj2tDbYb67wAAAHA"]
[Tue Aug 18 13:00:36.521572 2026] [security2:error] [pid 123784:tid 123988] [client 68.155.156.252:47953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/akismet.php"] [unique_id "aoSBpGwDnJBNj2tDbYb68QAAAEY"]
[Tue Aug 18 13:00:36.552759 2026] [security2:error] [pid 123784:tid 124027] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/php.php"] [unique_id "aoSBpGwDnJBNj2tDbYb68wAAAG0"]
[Tue Aug 18 13:00:36.553228 2026] [security2:error] [pid 123784:tid 124006] [client 20.226.36.136:61494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSBpGwDnJBNj2tDbYb69AAAAFg"]
[Tue Aug 18 13:00:36.563619 2026] [security2:error] [pid 123784:tid 123941] [client 20.65.98.162:45616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/yj09.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6-QAAABc"]
[Tue Aug 18 13:00:36.565146 2026] [security2:error] [pid 123784:tid 124044] [client 158.23.17.4:60793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/asus.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6-gAAAH4"]
[Tue Aug 18 13:00:36.565808 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:36.566217 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:36.574822 2026] [security2:error] [pid 123784:tid 124031] [client 20.151.109.219:14317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/st.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6-wAAAHE"]
[Tue Aug 18 13:00:36.596387 2026] [security2:error] [pid 123784:tid 123954] [client 20.79.204.6:14112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/ku.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6_AAAACQ"]
[Tue Aug 18 13:00:36.606312 2026] [security2:error] [pid 123784:tid 124010] [client 51.116.232.28:19031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/82.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6_QAAAFw"]
[Tue Aug 18 13:00:36.608389 2026] [security2:error] [pid 123784:tid 123963] [client 20.250.27.191:34834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6_gAAAC0"]
[Tue Aug 18 13:00:36.617703 2026] [security2:error] [pid 123784:tid 124041] [client 68.155.156.252:48076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/indes.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6_wAAAHs"]
[Tue Aug 18 13:00:36.624166 2026] [security2:error] [pid 123784:tid 124000] [client 20.104.100.201:61980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/tiny2.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7AAAAAFI"]
[Tue Aug 18 13:00:36.668335 2026] [security2:error] [pid 123784:tid 123936] [client 20.116.17.175:59985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/fpwch.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7AwAAABI"]
[Tue Aug 18 13:00:36.672459 2026] [security2:error] [pid 123784:tid 123873] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/cgi-bin/index.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7BAAANVQ"]
[Tue Aug 18 13:00:36.709116 2026] [security2:error] [pid 123784:tid 124021] [client 158.23.17.4:20169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/fs.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7BQAAAGc"]
[Tue Aug 18 13:00:36.730309 2026] [security2:error] [pid 123784:tid 123919] [client 158.23.17.4:47619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/88.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7BgAAAAE"]
[Tue Aug 18 13:00:36.767104 2026] [security2:error] [pid 123784:tid 123927] [client 213.35.127.232:61457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7CgAAAAk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:36.767558 2026] [security2:error] [pid 123784:tid 123825] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/shiny.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7CwAARCQ"]
[Tue Aug 18 13:00:36.792690 2026] [security2:error] [pid 123784:tid 123982] [client 20.226.36.136:61481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7DQAAAEA"]
[Tue Aug 18 13:00:36.815668 2026] [security2:error] [pid 123784:tid 123928] [client 20.226.56.190:17975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/payout.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7DgAAAAo"]
[Tue Aug 18 13:00:36.816541 2026] [security2:error] [pid 123784:tid 124012] [client 20.206.73.37:34791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7DwAAAF4"]
[Tue Aug 18 13:00:36.830141 2026] [security2:error] [pid 123784:tid 124022] [client 20.100.169.31:19791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7EAAAAGg"]
[Tue Aug 18 13:00:36.854184 2026] [security2:error] [pid 123784:tid 123841] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/an.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7EwAAbjQ"]
[Tue Aug 18 13:00:36.854645 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:36.855082 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:36.856297 2026] [security2:error] [pid 123784:tid 123962] [client 172.202.39.151:40356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/an.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7FAAAACw"]
[Tue Aug 18 13:00:36.874878 2026] [security2:error] [pid 123784:tid 123950] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/t.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7FQAAACA"]
[Tue Aug 18 13:00:36.894714 2026] [security2:error] [pid 123784:tid 124011] [client 20.127.136.245:27873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wk/index.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7FgAAAF0"]
[Tue Aug 18 13:00:36.925656 2026] [security2:error] [pid 123784:tid 124026] [client 52.173.121.69:15026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/pkmoj.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7GQAAAGw"]
[Tue Aug 18 13:00:36.935948 2026] [security2:error] [pid 123784:tid 124037] [client 20.151.109.219:60897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/le.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7GwAAAHc"]
[Tue Aug 18 13:00:36.954684 2026] [security2:error] [pid 123784:tid 123940] [client 20.116.17.175:58113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/mg.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7HAAAABY"]
[Tue Aug 18 13:00:36.987590 2026] [security2:error] [pid 123784:tid 123930] [client 158.23.17.4:63941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/nf.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7HgAAAAw"]
[Tue Aug 18 13:00:36.990847 2026] [security2:error] [pid 123784:tid 124039] [client 20.104.100.201:61407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wpxml.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7HwAAAHk"]
[Tue Aug 18 13:00:37.029315 2026] [security2:error] [pid 123784:tid 123945] [client 68.155.156.252:48091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/tTPcH.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7JAAAABs"]
[Tue Aug 18 13:00:37.034308 2026] [security2:error] [pid 123784:tid 123853] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/images/"] [unique_id "aoSBpWwDnJBNj2tDbYb7JQAAZkA"]
[Tue Aug 18 13:00:37.041698 2026] [security2:error] [pid 123784:tid 124035] [client 51.116.232.28:19064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/dex.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7JgAAAHU"]
[Tue Aug 18 13:00:37.090727 2026] [security2:error] [pid 123784:tid 124024] [client 158.158.74.177:17298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/server.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7KAAAAGo"]
[Tue Aug 18 13:00:37.104400 2026] [security2:error] [pid 123784:tid 123937] [client 159.69.158.189:7528] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "ceussmedicina.com.br"] [uri "/index.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7HQAAABM"], referer: http://ceussmedicina.com.br/
[Tue Aug 18 13:00:37.105104 2026] [security2:error] [pid 123784:tid 123967] [client 158.23.17.4:33455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/rb.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7KQAAADE"]
[Tue Aug 18 13:00:37.114787 2026] [security2:error] [pid 123784:tid 123920] [client 158.23.17.4:55177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/22.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7KwAAAAI"]
[Tue Aug 18 13:00:37.144770 2026] [security2:error] [pid 123784:tid 123812] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7LAAATRc"]
[Tue Aug 18 13:00:37.144972 2026] [security2:error] [pid 123784:tid 123995] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7LAAATRc"]
[Tue Aug 18 13:00:37.165960 2026] [security2:error] [pid 123784:tid 124006] [client 68.221.73.131:29628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7LgAAAFg"]
[Tue Aug 18 13:00:37.174780 2026] [security2:error] [pid 123784:tid 124002] [client 20.65.98.162:45612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/scxy.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7LwAAAFQ"]
[Tue Aug 18 13:00:37.189373 2026] [security2:error] [pid 123784:tid 123964] [client 20.79.204.6:2397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/222.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7MAAAAC4"]
[Tue Aug 18 13:00:37.192186 2026] [security2:error] [pid 123784:tid 123987] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/index/function.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7MQAAAEU"]
[Tue Aug 18 13:00:37.195123 2026] [security2:error] [pid 123784:tid 123975] [client 20.250.13.23:23681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7MgAAADk"]
[Tue Aug 18 13:00:37.205801 2026] [security2:error] [pid 123784:tid 123926] [client 20.250.27.191:28008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/aaa.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7NAAAAAg"]
[Tue Aug 18 13:00:37.208241 2026] [security2:error] [pid 123784:tid 123869] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/404.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7NQAAJFA"]
[Tue Aug 18 13:00:37.232307 2026] [security2:error] [pid 123784:tid 124041] [client 20.116.17.175:57933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/reop3.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7NwAAAHs"]
[Tue Aug 18 13:00:37.290529 2026] [security2:error] [pid 123784:tid 123948] [client 20.104.100.201:34296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7PAAAAB4"]
[Tue Aug 18 13:00:37.298422 2026] [security2:error] [pid 123784:tid 124021] [client 20.151.109.219:14320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/hr.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7PQAAAGc"]
[Tue Aug 18 13:00:37.365952 2026] [security2:error] [pid 123784:tid 123919] [client 20.226.56.190:8306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/bh.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7PwAAAAE"]
[Tue Aug 18 13:00:37.387796 2026] [security2:error] [pid 123784:tid 123835] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-login.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7QQAAUy4"]
[Tue Aug 18 13:00:37.395452 2026] [security2:error] [pid 123784:tid 124012] [client 20.226.36.136:61480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7QgAAAF4"]
[Tue Aug 18 13:00:37.406891 2026] [security2:error] [pid 123784:tid 123980] [client 20.127.136.245:27845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/about.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7QwAAAD4"]
[Tue Aug 18 13:00:37.420591 2026] [security2:error] [pid 123784:tid 123958] [client 86.120.159.145:50142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7RAAAACg"]
[Tue Aug 18 13:00:37.421005 2026] [security2:error] [pid 123784:tid 123958] [client 86.120.159.145:50142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7RAAAACg"]
[Tue Aug 18 13:00:37.435499 2026] [security2:error] [pid 123784:tid 123997] [client 68.155.156.252:47714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/admin.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7RgAAAE8"]
[Tue Aug 18 13:00:37.456531 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:37.456793 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:37.474237 2026] [security2:error] [pid 123784:tid 124037] [client 20.79.204.6:14097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/chosen.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7SwAAAHc"]
[Tue Aug 18 13:00:37.485203 2026] [security2:error] [pid 123784:tid 124036] [client 20.226.36.136:61476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7TAAAAHY"]
[Tue Aug 18 13:00:37.512909 2026] [security2:error] [pid 123784:tid 123940] [client 20.116.17.175:57932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/php5.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7TQAAABY"]
[Tue Aug 18 13:00:37.524153 2026] [security2:error] [pid 123784:tid 123969] [client 20.250.13.23:44265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7TgAAADM"]
[Tue Aug 18 13:00:37.539330 2026] [security2:error] [pid 123784:tid 124039] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wk/index.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7TwAAAHk"]
[Tue Aug 18 13:00:37.541447 2026] [security2:error] [pid 123784:tid 123956] [client 68.155.156.252:32284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/bs1.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7UAAAACY"]
[Tue Aug 18 13:00:37.577809 2026] [security2:error] [pid 123784:tid 123913] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7UgAAZnw"]
[Tue Aug 18 13:00:37.600094 2026] [security2:error] [pid 123784:tid 123978] [client 51.116.232.28:19035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/puc.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7VAAAADw"]
[Tue Aug 18 13:00:37.602270 2026] [security2:error] [pid 123784:tid 123931] [client 20.104.100.201:61958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/ccou.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7VQAAAA0"]
[Tue Aug 18 13:00:37.620234 2026] [security2:error] [pid 123784:tid 123970] [client 20.100.169.31:3978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7SAAAADQ"]
[Tue Aug 18 13:00:37.654979 2026] [security2:error] [pid 123784:tid 123988] [client 20.226.36.136:62189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7WQAAAEY"]
[Tue Aug 18 13:00:37.683630 2026] [security2:error] [pid 123784:tid 124008] [client 20.100.169.31:24192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7WgAAAFo"]
[Tue Aug 18 13:00:37.693607 2026] [security2:error] [pid 123784:tid 124027] [client 20.226.36.136:65330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7WwAAAG0"]
[Tue Aug 18 13:00:37.703266 2026] [security2:error] [pid 123784:tid 123941] [client 158.23.17.4:38302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/37.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7XAAAABc"]
[Tue Aug 18 13:00:37.713013 2026] [security2:error] [pid 123784:tid 123959] [client 158.158.74.177:17286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7XQAAACk"]
[Tue Aug 18 13:00:37.751080 2026] [security2:error] [pid 123784:tid 123852] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/ID3/"] [unique_id "aoSBpWwDnJBNj2tDbYb7aAAALj8"]
[Tue Aug 18 13:00:37.755970 2026] [authz_core:error] [pid 123784:tid 123840] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:37.756227 2026] [authz_core:error] [pid 123784:tid 123840] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:37.774709 2026] [security2:error] [pid 123784:tid 124044] [client 20.250.27.191:34822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/gecko.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7bQAAAH4"]
[Tue Aug 18 13:00:37.794765 2026] [security2:error] [pid 123784:tid 123961] [client 20.79.204.6:2380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/aa.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7bgAAACs"]
[Tue Aug 18 13:00:37.799861 2026] [security2:error] [pid 123784:tid 123926] [client 20.116.17.175:58119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/acp.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7cAAAAAg"]
[Tue Aug 18 13:00:37.800799 2026] [security2:error] [pid 123784:tid 124011] [client 213.35.127.232:61666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7bwAAAF0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:37.821365 2026] [security2:error] [pid 123784:tid 123921] [client 20.250.13.23:44048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7cwAAAAM"]
[Tue Aug 18 13:00:37.828812 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.36.136:62182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7dAAAAFI"]
[Tue Aug 18 13:00:37.833686 2026] [security2:error] [pid 123784:tid 123949] [client 159.69.158.189:34332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ceussmedicina.com.br"] [uri "/index.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7XgAAAB8"], referer: http://ceussmedicina.com.br/
[Tue Aug 18 13:00:37.840368 2026] [security2:error] [pid 123784:tid 123925] [client 20.226.56.190:20899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ct.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7dgAAAAc"]
[Tue Aug 18 13:00:37.843937 2026] [security2:error] [pid 123784:tid 123991] [client 158.23.17.4:9378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/xv.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7dwAAAEk"]
[Tue Aug 18 13:00:37.866364 2026] [security2:error] [pid 123784:tid 123856] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/403dd.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7eQAABUM"]
[Tue Aug 18 13:00:37.877236 2026] [security2:error] [pid 123784:tid 123936] [client 158.23.17.4:57061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/zs.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7egAAABI"]
[Tue Aug 18 13:00:37.880297 2026] [security2:error] [pid 123784:tid 123974] [client 68.155.156.252:61791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/hp2.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7ewAAADg"]
[Tue Aug 18 13:00:37.903211 2026] [security2:error] [pid 123784:tid 123935] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7fAAAABE"]
[Tue Aug 18 13:00:37.911983 2026] [security2:error] [pid 123784:tid 123965] [client 168.62.48.100:5590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7fQAAAC8"]
[Tue Aug 18 13:00:37.960560 2026] [security2:error] [pid 123784:tid 123910] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/.well-known/"] [unique_id "aoSBpWwDnJBNj2tDbYb7gQAAPnk"]
[Tue Aug 18 13:00:37.973128 2026] [autoindex:error] [pid 123784:tid 123918] [client 172.202.39.151:40355] AH01276: Cannot serve directory /home2/ctamcursos/grupoctam.com.br/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:37.979392 2026] [authz_core:error] [pid 123784:tid 123842] [remote 57.141.22.2:38240] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:37.979648 2026] [authz_core:error] [pid 123784:tid 123842] [remote 57.141.22.2:38240] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:38.008261 2026] [security2:error] [pid 123784:tid 123958] [client 20.151.109.219:63955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/kt.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7hQAAACg"]
[Tue Aug 18 13:00:38.012773 2026] [security2:error] [pid 123784:tid 123962] [client 20.65.98.162:55178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/ws13.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7hgAAACw"]
[Tue Aug 18 13:00:38.019203 2026] [security2:error] [pid 123784:tid 124026] [client 20.104.100.201:61396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/crgio.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7iAAAAGw"]
[Tue Aug 18 13:00:38.034268 2026] [security2:error] [pid 123784:tid 123969] [client 68.221.73.131:52925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/media.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7igAAADM"]
[Tue Aug 18 13:00:38.036093 2026] [security2:error] [pid 123784:tid 123956] [client 51.116.232.28:19062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/inso.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7iwAAACY"]
[Tue Aug 18 13:00:38.044445 2026] [security2:error] [pid 123784:tid 124033] [client 158.23.17.4:15798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/hj.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7jAAAAHM"]
[Tue Aug 18 13:00:38.055515 2026] [security2:error] [pid 123784:tid 124035] [client 172.202.39.151:4705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/ioxi-o.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7jwAAAHU"]
[Tue Aug 18 13:00:38.063052 2026] [authz_core:error] [pid 123784:tid 123844] [remote 57.141.22.104:60584] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:38.063332 2026] [authz_core:error] [pid 123784:tid 123844] [remote 57.141.22.104:60584] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:38.070275 2026] [autoindex:error] [pid 123784:tid 123989] [client 20.118.133.132:14958] AH01276: Cannot serve directory /home4/agrimotor/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:38.095518 2026] [security2:error] [pid 123784:tid 123967] [client 20.116.17.175:58137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/yas.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7lAAAADE"]
[Tue Aug 18 13:00:38.095890 2026] [security2:error] [pid 123784:tid 123952] [client 20.100.169.31:4416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/0x.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7lQAAACI"]
[Tue Aug 18 13:00:38.097255 2026] [security2:error] [pid 123784:tid 124028] [client 20.127.136.245:28500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/term.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7lgAAAG4"]
[Tue Aug 18 13:00:38.105868 2026] [security2:error] [pid 123784:tid 124027] [client 68.155.156.252:62138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/ajax.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7lwAAAG0"]
[Tue Aug 18 13:00:38.108097 2026] [security2:error] [pid 123784:tid 123948] [client 20.79.204.6:14078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/asd.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7mQAAAB4"]
[Tue Aug 18 13:00:38.142614 2026] [security2:error] [pid 123784:tid 123892] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wso.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7mwAATmc"]
[Tue Aug 18 13:00:38.151696 2026] [security2:error] [pid 123784:tid 123871] [remote 20.87.239.85:15772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.239.87.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "becacao.us"] [uri "/wp-login.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7nAAAClI"]
[Tue Aug 18 13:00:38.159999 2026] [security2:error] [pid 123784:tid 123963] [client 4.232.94.69:15650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/dav.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7ngAAAC0"]
[Tue Aug 18 13:00:38.168297 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.36.136:65295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7nwAAAH8"]
[Tue Aug 18 13:00:38.203910 2026] [security2:error] [pid 123784:tid 123845] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/baba.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7oQAAUDg"]
[Tue Aug 18 13:00:38.242068 2026] [security2:error] [pid 123784:tid 124039] [client 20.100.169.31:3718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7ogAAAHk"]
[Tue Aug 18 13:00:38.259058 2026] [security2:error] [pid 123784:tid 123923] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/xfun.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7pAAAAAU"]
[Tue Aug 18 13:00:38.296273 2026] [security2:error] [pid 123784:tid 124014] [client 168.62.48.100:5602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7pgAAAGA"]
[Tue Aug 18 13:00:38.309609 2026] [security2:error] [pid 123784:tid 123939] [client 20.250.27.191:40171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/xiugai.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7pwAAABU"]
[Tue Aug 18 13:00:38.324701 2026] [security2:error] [pid 123784:tid 123930] [client 68.155.156.252:59745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/yb.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7qAAAAAw"]
[Tue Aug 18 13:00:38.343875 2026] [security2:error] [pid 123784:tid 123919] [client 20.104.100.201:61424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7qQAAAAE"]
[Tue Aug 18 13:00:38.345543 2026] [security2:error] [pid 123784:tid 124013] [client 20.151.109.219:60405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ww.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7qgAAAF8"]
[Tue Aug 18 13:00:38.348612 2026] [security2:error] [pid 123784:tid 123811] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/sf.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7qwAAZBY"]
[Tue Aug 18 13:00:38.361388 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:38.361654 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:38.383012 2026] [security2:error] [pid 123784:tid 124012] [client 20.116.17.175:58138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/ah25.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7rgAAAF4"]
[Tue Aug 18 13:00:38.391235 2026] [security2:error] [pid 123784:tid 124011] [client 158.158.74.177:5092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/shell.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7rwAAAF0"]
[Tue Aug 18 13:00:38.417012 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:29456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/mx.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7sQAAAH0"]
[Tue Aug 18 13:00:38.465136 2026] [security2:error] [pid 123784:tid 123962] [client 51.116.232.28:19010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/aa.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7tAAAACw"]
[Tue Aug 18 13:00:38.474490 2026] [security2:error] [pid 123784:tid 124026] [client 20.226.36.136:65313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7tgAAAGw"]
[Tue Aug 18 13:00:38.474845 2026] [security2:error] [pid 123784:tid 124037] [client 158.23.17.4:34117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/md.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7twAAAHc"]
[Tue Aug 18 13:00:38.484848 2026] [security2:error] [pid 123784:tid 124003] [client 20.250.13.23:23725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/st.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7uAAAAFU"]
[Tue Aug 18 13:00:38.492855 2026] [security2:error] [pid 123784:tid 124021] [client 20.79.204.6:2640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/abcd.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7uQAAAGc"]
[Tue Aug 18 13:00:38.504970 2026] [security2:error] [pid 123784:tid 124033] [client 172.202.39.151:40355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/404.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7uwAAAHM"]
[Tue Aug 18 13:00:38.529607 2026] [security2:error] [pid 123784:tid 123989] [client 158.23.17.4:55174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/iz.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7vAAAAEc"]
[Tue Aug 18 13:00:38.550729 2026] [security2:error] [pid 123784:tid 123826] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/index/function.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7vgAAPCU"]
[Tue Aug 18 13:00:38.583472 2026] [security2:error] [pid 123784:tid 123906] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/site.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7wQAAAnU"]
[Tue Aug 18 13:00:38.587986 2026] [security2:error] [pid 123784:tid 124016] [client 20.65.98.162:45594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/btx25.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7wgAAAGI"]
[Tue Aug 18 13:00:38.617064 2026] [security2:error] [pid 123784:tid 124027] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/p.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7xgAAAG0"]
[Tue Aug 18 13:00:38.627092 2026] [security2:error] [pid 123784:tid 123948] [client 20.104.100.201:61395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/css.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7yAAAAB4"]
[Tue Aug 18 13:00:38.628056 2026] [security2:error] [pid 123784:tid 123992] [client 168.62.48.100:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7yQAAAEo"]
[Tue Aug 18 13:00:38.630546 2026] [authz_core:error] [pid 123784:tid 123836] [remote 57.141.22.35:24686] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:38.630999 2026] [authz_core:error] [pid 123784:tid 123836] [remote 57.141.22.35:24686] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:38.661761 2026] [authz_core:error] [pid 123784:tid 123915] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:38.662154 2026] [authz_core:error] [pid 123784:tid 123915] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:38.672331 2026] [security2:error] [pid 123784:tid 123927] [client 20.65.98.162:57905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/file5.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7zAAAAAk"]
[Tue Aug 18 13:00:38.673134 2026] [security2:error] [pid 123784:tid 123986] [client 20.116.17.175:58134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/ano.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7zQAAAEQ"]
[Tue Aug 18 13:00:38.674511 2026] [security2:error] [pid 123784:tid 123990] [client 135.225.78.186:33948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/file1221.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7zgAAAEg"]
[Tue Aug 18 13:00:38.712913 2026] [security2:error] [pid 123784:tid 123938] [client 20.79.204.6:14056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/akc.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7zwAAABQ"]
[Tue Aug 18 13:00:38.715709 2026] [security2:error] [pid 123784:tid 123952] [client 20.127.136.245:27860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/ioxi-o.php"] [unique_id "aoSBpmwDnJBNj2tDbYb70AAAACI"]
[Tue Aug 18 13:00:38.726709 2026] [security2:error] [pid 123784:tid 123843] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/edit.php"] [unique_id "aoSBpmwDnJBNj2tDbYb70QAATjY"]
[Tue Aug 18 13:00:38.729606 2026] [security2:error] [pid 123784:tid 124035] [client 20.100.169.31:4946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/222.php"] [unique_id "aoSBpmwDnJBNj2tDbYb70gAAAHU"]
[Tue Aug 18 13:00:38.771190 2026] [security2:error] [pid 123784:tid 123943] [client 172.202.39.151:48904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/403.php"] [unique_id "aoSBpmwDnJBNj2tDbYb71QAAABk"]
[Tue Aug 18 13:00:38.796018 2026] [security2:error] [pid 123784:tid 123975] [client 20.151.109.219:63983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/mo.php"] [unique_id "aoSBpmwDnJBNj2tDbYb71wAAADk"]
[Tue Aug 18 13:00:38.796953 2026] [autoindex:error] [pid 123784:tid 123955] [client 54.204.43.183:60073] AH01276: Cannot serve directory /home1/peretsites/admin.peretsites.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:38.798942 2026] [security2:error] [pid 123784:tid 124010] [client 20.250.27.191:40179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/adminner.php"] [unique_id "aoSBpmwDnJBNj2tDbYb72AAAAFw"]
[Tue Aug 18 13:00:38.812880 2026] [security2:error] [pid 123784:tid 123940] [client 213.35.127.232:61861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBpmwDnJBNj2tDbYb72QAAABY"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:38.874284 2026] [security2:error] [pid 123784:tid 123930] [client 68.155.156.252:51281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/vc.php"] [unique_id "aoSBpmwDnJBNj2tDbYb73gAAAAw"]
[Tue Aug 18 13:00:38.894479 2026] [security2:error] [pid 123784:tid 123919] [client 51.116.232.28:19030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/img.php"] [unique_id "aoSBpmwDnJBNj2tDbYb73wAAAAE"]
[Tue Aug 18 13:00:38.913709 2026] [security2:error] [pid 123784:tid 124011] [client 158.23.17.4:37398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/iy.php"] [unique_id "aoSBpmwDnJBNj2tDbYb74AAAAF0"]
[Tue Aug 18 13:00:38.919616 2026] [security2:error] [pid 123784:tid 123881] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSBpmwDnJBNj2tDbYb74QAAe1w"]
[Tue Aug 18 13:00:38.927140 2026] [security2:error] [pid 123784:tid 123918] [client 20.104.100.201:61404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBpmwDnJBNj2tDbYb74gAAAAA"]
[Tue Aug 18 13:00:38.928615 2026] [security2:error] [pid 123784:tid 123924] [client 68.221.73.131:21991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/admin.php"] [unique_id "aoSBpmwDnJBNj2tDbYb74wAAAAY"]
[Tue Aug 18 13:00:38.935811 2026] [security2:error] [pid 123784:tid 123962] [client 20.226.36.136:53550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSBpmwDnJBNj2tDbYb75QAAACw"]
[Tue Aug 18 13:00:38.944744 2026] [security2:error] [pid 123784:tid 123879] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/rest-api/"] [unique_id "aoSBpmwDnJBNj2tDbYb75wAAKlo"]
[Tue Aug 18 13:00:38.947003 2026] [security2:error] [pid 123784:tid 124004] [client 20.226.56.190:17932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gy.php"] [unique_id "aoSBpmwDnJBNj2tDbYb76AAAAFY"]
[Tue Aug 18 13:00:38.949870 2026] [security2:error] [pid 123784:tid 123956] [client 20.116.17.175:57923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/nwflm.php"] [unique_id "aoSBpmwDnJBNj2tDbYb76QAAACY"]
[Tue Aug 18 13:00:38.962135 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:38.962405 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:38.976407 2026] [security2:error] [pid 123784:tid 124042] [client 20.100.169.31:3728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSBpmwDnJBNj2tDbYb77AAAAHw"]
[Tue Aug 18 13:00:38.978608 2026] [security2:error] [pid 123784:tid 124029] [client 20.79.204.6:10371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/666.php"] [unique_id "aoSBpmwDnJBNj2tDbYb77QAAAG8"]
[Tue Aug 18 13:00:38.980826 2026] [security2:error] [pid 123784:tid 123982] [client 20.250.13.23:50913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBpmwDnJBNj2tDbYb77wAAAEA"]
[Tue Aug 18 13:00:39.020465 2026] [security2:error] [pid 123784:tid 123949] [client 158.158.74.177:5061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/sim.php"] [unique_id "aoSBp2wDnJBNj2tDbYb78gAAAB8"]
[Tue Aug 18 13:00:39.022795 2026] [security2:error] [pid 123784:tid 124022] [client 103.120.71.157:49466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBp2wDnJBNj2tDbYb79AAAAGg"]
[Tue Aug 18 13:00:39.022897 2026] [security2:error] [pid 123784:tid 124022] [client 103.120.71.157:49466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBp2wDnJBNj2tDbYb79AAAAGg"]
[Tue Aug 18 13:00:39.052005 2026] [security2:error] [pid 123784:tid 123989] [client 158.23.17.4:56727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ij.php"] [unique_id "aoSBp2wDnJBNj2tDbYb79gAAAEc"]
[Tue Aug 18 13:00:39.065401 2026] [security2:error] [pid 123784:tid 124005] [client 20.226.56.190:13091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/tt.php"] [unique_id "aoSBp2wDnJBNj2tDbYb79wAAAFc"]
[Tue Aug 18 13:00:39.101342 2026] [security2:error] [pid 123784:tid 124012] [client 20.79.204.6:2646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/admin.php"] [unique_id "aoSBp2wDnJBNj2tDbYb7-gAAAF4"]
[Tue Aug 18 13:00:39.119519 2026] [security2:error] [pid 123784:tid 123809] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSBp2wDnJBNj2tDbYb7_AAAbhQ"]
[Tue Aug 18 13:00:39.121236 2026] [security2:error] [pid 123784:tid 124027] [client 158.23.17.4:33486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/45.php"] [unique_id "aoSBp2wDnJBNj2tDbYb7_gAAAG0"]
[Tue Aug 18 13:00:39.121438 2026] [security2:error] [pid 123784:tid 124008] [client 20.226.56.190:20876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/mq.php"] [unique_id "aoSBp2wDnJBNj2tDbYb7_wAAAFo"]
[Tue Aug 18 13:00:39.148366 2026] [security2:error] [pid 123784:tid 123968] [client 20.250.13.23:23720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8AAAAADI"]
[Tue Aug 18 13:00:39.178662 2026] [security2:error] [pid 123784:tid 123938] [client 20.151.109.219:60400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/qr.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8AwAAABQ"]
[Tue Aug 18 13:00:39.191692 2026] [security2:error] [pid 123784:tid 124035] [client 52.173.121.69:61940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/kopyw.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8CAAAAHU"]
[Tue Aug 18 13:00:39.206527 2026] [security2:error] [pid 123784:tid 124044] [client 168.62.48.100:5539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8DgAAAH4"]
[Tue Aug 18 13:00:39.213140 2026] [security2:error] [pid 123784:tid 123954] [client 20.226.56.190:18560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/13.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8EQAAACQ"]
[Tue Aug 18 13:00:39.215238 2026] [security2:error] [pid 123784:tid 123926] [client 158.23.17.4:60784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/se.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8EgAAAAg"]
[Tue Aug 18 13:00:39.221617 2026] [security2:error] [pid 123784:tid 123955] [client 20.65.98.162:55191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/SDsadqwrf.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8FQAAACU"]
[Tue Aug 18 13:00:39.228210 2026] [security2:error] [pid 123784:tid 123921] [client 20.226.56.190:18560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/so.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8GQAAAAM"]
[Tue Aug 18 13:00:39.233173 2026] [security2:error] [pid 123784:tid 123973] [client 20.116.17.175:57952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-load.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8GwAAADc"]
[Tue Aug 18 13:00:39.247339 2026] [security2:error] [pid 123784:tid 123901] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/cabs.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8HgAAFnA"]
[Tue Aug 18 13:00:39.265519 2026] [authz_core:error] [pid 123784:tid 123866] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:39.265978 2026] [authz_core:error] [pid 123784:tid 123866] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:39.268688 2026] [security2:error] [pid 123784:tid 123946] [client 20.127.136.245:27901] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "whm.eezy.site"] [uri "/1.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8IgAAABw"]
[Tue Aug 18 13:00:39.268795 2026] [security2:error] [pid 123784:tid 123946] [client 20.127.136.245:27901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/1.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8IgAAABw"]
[Tue Aug 18 13:00:39.289880 2026] [security2:error] [pid 123784:tid 124011] [client 20.250.27.191:63216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/file1221.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8MQAAAF0"]
[Tue Aug 18 13:00:39.294997 2026] [security2:error] [pid 123784:tid 123933] [client 20.226.56.190:6132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/10.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8RQAAAA8"]
[Tue Aug 18 13:00:39.300963 2026] [security2:error] [pid 123784:tid 124041] [client 51.116.232.28:19061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/222.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8WAAAAHs"]
[Tue Aug 18 13:00:39.320687 2026] [security2:error] [pid 123784:tid 123877] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-good.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8XAAAQ1g"]
[Tue Aug 18 13:00:39.322375 2026] [security2:error] [pid 123784:tid 124036] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8XQAAAHY"]
[Tue Aug 18 13:00:39.330278 2026] [security2:error] [pid 123784:tid 123992] [client 20.79.204.6:14016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/maintenance.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8XgAAAEo"]
[Tue Aug 18 13:00:39.341529 2026] [security2:error] [pid 123784:tid 123993] [client 20.100.169.31:4629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/aa.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8YAAAAEs"]
[Tue Aug 18 13:00:39.345496 2026] [security2:error] [pid 123784:tid 124003] [client 68.155.156.252:23137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/pema.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8YQAAAFU"]
[Tue Aug 18 13:00:39.408392 2026] [security2:error] [pid 123784:tid 123981] [client 20.104.100.201:61987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/epinyins.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8aAAAAD8"]
[Tue Aug 18 13:00:39.428562 2026] [security2:error] [pid 123784:tid 124023] [client 20.226.56.190:40140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/te.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8agAAAGk"]
[Tue Aug 18 13:00:39.463400 2026] [security2:error] [pid 123784:tid 123988] [client 172.202.39.151:44571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-login.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8bAAAAEY"]
[Tue Aug 18 13:00:39.513884 2026] [security2:error] [pid 123784:tid 123789] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/js/widgets/"] [unique_id "aoSBp2wDnJBNj2tDbYb8fAAAWgA"]
[Tue Aug 18 13:00:39.514688 2026] [security2:error] [pid 123784:tid 123948] [client 20.226.56.190:45189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kc.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8fQAAAB4"]
[Tue Aug 18 13:00:39.523474 2026] [authz_core:error] [pid 123784:tid 123791] [remote 57.141.22.40:27228] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:39.523896 2026] [authz_core:error] [pid 123784:tid 123791] [remote 57.141.22.40:27228] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:39.530469 2026] [security2:error] [pid 123784:tid 123927] [client 20.116.17.175:58152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/jj.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8gAAAAAk"]
[Tue Aug 18 13:00:39.557038 2026] [security2:error] [pid 123784:tid 123976] [client 158.23.17.4:12526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/og.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8gQAAADo"]
[Tue Aug 18 13:00:39.582544 2026] [security2:error] [pid 123784:tid 123980] [client 20.151.109.219:39354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/dirs.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8hAAAAD4"]
[Tue Aug 18 13:00:39.623955 2026] [security2:error] [pid 123784:tid 123974] [client 20.226.56.190:6088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/jn.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8hwAAADg"]
[Tue Aug 18 13:00:39.635231 2026] [security2:error] [pid 123784:tid 123931] [client 20.100.169.31:38660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8mgAAAA0"]
[Tue Aug 18 13:00:39.669434 2026] [security2:error] [pid 123784:tid 124006] [client 168.62.48.100:5462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8owAAAFg"]
[Tue Aug 18 13:00:39.686167 2026] [security2:error] [pid 123784:tid 123958] [client 4.232.94.69:26583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp_wol.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8pQAAACg"]
[Tue Aug 18 13:00:39.691024 2026] [security2:error] [pid 123784:tid 124014] [client 158.23.17.4:29479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/wy.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8pgAAAGA"]
[Tue Aug 18 13:00:39.702708 2026] [security2:error] [pid 123784:tid 123935] [client 20.104.100.201:61995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/load.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8pwAAABE"]
[Tue Aug 18 13:00:39.726014 2026] [security2:error] [pid 123784:tid 123851] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/insc.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8rAAAeD4"]
[Tue Aug 18 13:00:39.733899 2026] [security2:error] [pid 123784:tid 123932] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/aaa.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8rQAAAA4"]
[Tue Aug 18 13:00:39.738908 2026] [security2:error] [pid 123784:tid 124013] [client 68.155.156.252:42231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/sh.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8rgAAAF8"]
[Tue Aug 18 13:00:39.757198 2026] [security2:error] [pid 123784:tid 123929] [client 51.116.232.28:19020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/key.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8rwAAAAs"]
[Tue Aug 18 13:00:39.763242 2026] [security2:error] [pid 123784:tid 123964] [client 20.250.13.23:18508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-configs.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8tAAAAC4"]
[Tue Aug 18 13:00:39.786337 2026] [security2:error] [pid 123784:tid 123918] [client 20.250.27.191:43484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/inx.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8tgAAAAA"]
[Tue Aug 18 13:00:39.792070 2026] [security2:error] [pid 123784:tid 123952] [client 158.158.74.177:17291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/simple.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8twAAACI"]
[Tue Aug 18 13:00:39.794170 2026] [security2:error] [pid 123784:tid 123924] [client 20.226.36.136:62186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8uAAAAAY"]
[Tue Aug 18 13:00:39.822408 2026] [security2:error] [pid 123784:tid 124037] [client 20.116.17.175:58171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/img.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8ugAAAHc"]
[Tue Aug 18 13:00:39.827409 2026] [security2:error] [pid 123784:tid 124036] [client 20.226.56.190:17981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/bf.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8uwAAAHY"]
[Tue Aug 18 13:00:39.827967 2026] [security2:error] [pid 123784:tid 123920] [client 213.35.127.232:62047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8vAAAAAI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:39.838616 2026] [security2:error] [pid 123784:tid 123992] [client 20.65.98.162:56501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8vQAAAEo"]
[Tue Aug 18 13:00:39.865147 2026] [authz_core:error] [pid 123784:tid 123857] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:39.865425 2026] [authz_core:error] [pid 123784:tid 123857] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:39.880514 2026] [security2:error] [pid 123784:tid 123950] [client 20.127.136.245:27875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/alfa.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8xAAAACA"]
[Tue Aug 18 13:00:39.889287 2026] [security2:error] [pid 123784:tid 123824] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/css/colors/midnight/"] [unique_id "aoSBp2wDnJBNj2tDbYb8xQAAbyM"]
[Tue Aug 18 13:00:39.936046 2026] [security2:error] [pid 123784:tid 123946] [client 20.79.204.6:14034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/options-writing.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8yAAAABw"]
[Tue Aug 18 13:00:39.978033 2026] [security2:error] [pid 123784:tid 124002] [client 20.151.109.219:60915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/sn.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8zwAAAFQ"]
[Tue Aug 18 13:00:39.988903 2026] [security2:error] [pid 123784:tid 124018] [client 20.100.169.31:4955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/abcd.php"] [unique_id "aoSBp2wDnJBNj2tDbYb80QAAAGQ"]
[Tue Aug 18 13:00:40.043842 2026] [security2:error] [pid 123784:tid 123816] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/file.php"] [unique_id "aoSBqGwDnJBNj2tDbYb80wAAIxs"]
[Tue Aug 18 13:00:40.063283 2026] [security2:error] [pid 123784:tid 123885] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/tes.php"] [unique_id "aoSBqGwDnJBNj2tDbYb81AAAOmA"]
[Tue Aug 18 13:00:40.073078 2026] [security2:error] [pid 123784:tid 123938] [client 20.104.100.201:61381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSBqGwDnJBNj2tDbYb81QAAABQ"]
[Tue Aug 18 13:00:40.097764 2026] [security2:error] [pid 123784:tid 123936] [client 158.23.17.4:63665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/f.php"] [unique_id "aoSBqGwDnJBNj2tDbYb82gAAABI"]
[Tue Aug 18 13:00:40.105799 2026] [security2:error] [pid 123784:tid 124044] [client 20.116.17.175:57962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/we.php"] [unique_id "aoSBqGwDnJBNj2tDbYb82wAAAH4"]
[Tue Aug 18 13:00:40.138729 2026] [security2:error] [pid 123784:tid 123954] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/term.php"] [unique_id "aoSBqGwDnJBNj2tDbYb83wAAACQ"]
[Tue Aug 18 13:00:40.167109 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:40.167377 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:40.208583 2026] [security2:error] [pid 123784:tid 123947] [client 51.116.232.28:19056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/chosen.php"] [unique_id "aoSBqGwDnJBNj2tDbYb84QAAAB0"]
[Tue Aug 18 13:00:40.244229 2026] [security2:error] [pid 123784:tid 123864] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/files/index.php"] [unique_id "aoSBqGwDnJBNj2tDbYb85AAAEUs"]
[Tue Aug 18 13:00:40.256921 2026] [security2:error] [pid 123784:tid 123939] [client 20.250.27.191:62761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/reviall.php"] [unique_id "aoSBqGwDnJBNj2tDbYb85QAAABU"]
[Tue Aug 18 13:00:40.257140 2026] [security2:error] [pid 123784:tid 123940] [client 20.65.98.162:45622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/BDKR28WP.php"] [unique_id "aoSBqGwDnJBNj2tDbYb85gAAABY"]
[Tue Aug 18 13:00:40.273402 2026] [security2:error] [pid 123784:tid 123964] [client 68.155.156.252:35144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/button.php"] [unique_id "aoSBqGwDnJBNj2tDbYb85wAAAC4"]
[Tue Aug 18 13:00:40.290547 2026] [security2:error] [pid 123784:tid 123980] [client 20.100.169.31:19780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBqGwDnJBNj2tDbYb86gAAAD4"]
[Tue Aug 18 13:00:40.302003 2026] [security2:error] [pid 123784:tid 123918] [client 172.202.39.151:44588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSBqGwDnJBNj2tDbYb87QAAAAA"]
[Tue Aug 18 13:00:40.304461 2026] [security2:error] [pid 123784:tid 123933] [client 135.225.78.186:33523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/nox.php"] [unique_id "aoSBqGwDnJBNj2tDbYb87wAAAA8"]
[Tue Aug 18 13:00:40.335322 2026] [security2:error] [pid 123784:tid 123997] [client 158.23.17.4:31903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/lp.php"] [unique_id "aoSBqGwDnJBNj2tDbYb88wAAAE8"]
[Tue Aug 18 13:00:40.372260 2026] [security2:error] [pid 123784:tid 123985] [client 20.151.109.219:60870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/43.php"] [unique_id "aoSBqGwDnJBNj2tDbYb8_QAAAEM"]
[Tue Aug 18 13:00:40.422907 2026] [security2:error] [pid 123784:tid 124014] [client 158.158.74.177:17339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/st.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9AQAAAGA"]
[Tue Aug 18 13:00:40.424427 2026] [security2:error] [pid 123784:tid 123812] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/dex.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9AwAAZhc"]
[Tue Aug 18 13:00:40.424435 2026] [security2:error] [pid 123784:tid 123923] [client 20.250.13.23:6181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-post.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9AgAAAAU"]
[Tue Aug 18 13:00:40.426519 2026] [security2:error] [pid 123784:tid 124029] [client 20.104.100.201:34256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/ty.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9BAAAAG8"]
[Tue Aug 18 13:00:40.427018 2026] [security2:error] [pid 123784:tid 123973] [client 20.127.136.245:27883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/edit.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9BQAAADc"]
[Tue Aug 18 13:00:40.430273 2026] [security2:error] [pid 123784:tid 123982] [client 158.23.17.4:51145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/vp.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9BgAAAEA"]
[Tue Aug 18 13:00:40.440935 2026] [security2:error] [pid 123784:tid 123853] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9CgAAc0A"]
[Tue Aug 18 13:00:40.466698 2026] [security2:error] [pid 123784:tid 123971] [client 68.221.73.131:55161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/mac.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9EAAAADU"]
[Tue Aug 18 13:00:40.467572 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:40.467862 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:40.472636 2026] [security2:error] [pid 123784:tid 123956] [client 138.36.100.162:42405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9EQAAACY"]
[Tue Aug 18 13:00:40.472740 2026] [security2:error] [pid 123784:tid 123956] [client 138.36.100.162:42405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9EQAAACY"]
[Tue Aug 18 13:00:40.551537 2026] [security2:error] [pid 123784:tid 124036] [client 20.79.204.6:14036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9FgAAAHY"]
[Tue Aug 18 13:00:40.563635 2026] [security2:error] [pid 123784:tid 123959] [client 158.23.17.4:62979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ud.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9FwAAACk"]
[Tue Aug 18 13:00:40.571026 2026] [security2:error] [pid 123784:tid 124017] [client 20.79.204.6:2415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9GAAAAGM"]
[Tue Aug 18 13:00:40.591306 2026] [security2:error] [pid 123784:tid 123943] [client 149.34.210.141:54388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9GgAAABk"]
[Tue Aug 18 13:00:40.611965 2026] [security2:error] [pid 123784:tid 123993] [client 20.100.169.31:32472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/admin.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9HAAAAEs"]
[Tue Aug 18 13:00:40.624805 2026] [security2:error] [pid 123784:tid 123953] [client 20.65.98.162:45583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/sky.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9HQAAACM"]
[Tue Aug 18 13:00:40.633900 2026] [security2:error] [pid 123784:tid 123850] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/images/images/about.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9HgAAXT0"]
[Tue Aug 18 13:00:40.648464 2026] [security2:error] [pid 123784:tid 123938] [client 168.62.48.100:5523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9HwAAABQ"]
[Tue Aug 18 13:00:40.650446 2026] [security2:error] [pid 123784:tid 123996] [client 51.116.232.28:19065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/wpxml.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9IAAAAE4"]
[Tue Aug 18 13:00:40.719667 2026] [security2:error] [pid 123784:tid 123972] [client 20.226.36.136:61495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9IgAAADY"]
[Tue Aug 18 13:00:40.739145 2026] [security2:error] [pid 123784:tid 123921] [client 20.79.204.6:10758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/ws54.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9IwAAAAM"]
[Tue Aug 18 13:00:40.758133 2026] [security2:error] [pid 123784:tid 123935] [client 20.151.109.219:24405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/fresh.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9JAAAABE"]
[Tue Aug 18 13:00:40.784948 2026] [security2:error] [pid 123784:tid 124013] [client 68.155.156.252:35147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/wlc.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9JwAAAF8"]
[Tue Aug 18 13:00:40.789558 2026] [security2:error] [pid 123784:tid 123964] [client 20.250.27.191:43513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/11.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9KAAAAC4"]
[Tue Aug 18 13:00:40.801868 2026] [security2:error] [pid 123784:tid 123795] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/key.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9KgAAPgY"]
[Tue Aug 18 13:00:40.822432 2026] [security2:error] [pid 123784:tid 123970] [client 20.104.100.201:61379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9KwAAADQ"]
[Tue Aug 18 13:00:40.826002 2026] [security2:error] [pid 123784:tid 123877] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/ms-edit.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9LAAAAFg"]
[Tue Aug 18 13:00:40.852676 2026] [security2:error] [pid 123784:tid 123978] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/7.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9LQAAADw"]
[Tue Aug 18 13:00:40.853390 2026] [security2:error] [pid 123784:tid 124001] [client 4.232.94.69:15616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/fm2.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9LgAAAFM"]
[Tue Aug 18 13:00:40.858162 2026] [security2:error] [pid 123784:tid 123943] [client 149.34.210.141:54388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9GgAAABk"]
[Tue Aug 18 13:00:40.862114 2026] [security2:error] [pid 123784:tid 124008] [client 213.35.127.232:62231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9MQAAAFo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:40.895745 2026] [security2:error] [pid 123784:tid 124035] [client 103.184.169.37:42946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9MwAAAHU"]
[Tue Aug 18 13:00:40.895890 2026] [security2:error] [pid 123784:tid 124035] [client 103.184.169.37:42946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9MwAAAHU"]
[Tue Aug 18 13:00:40.906137 2026] [security2:error] [pid 123784:tid 123998] [client 74.7.230.62:34044] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "babiferreiraarquitetura.com.br"] [uri "/index.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8uQAAUDw"]
[Tue Aug 18 13:00:40.925190 2026] [security2:error] [pid 123784:tid 123977] [client 20.127.136.245:28523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/elp.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9NgAAADs"]
[Tue Aug 18 13:00:40.982912 2026] [security2:error] [pid 123784:tid 124034] [client 20.65.98.162:56451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/file5.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9PgAAAHQ"]
[Tue Aug 18 13:00:40.985415 2026] [security2:error] [pid 123784:tid 123971] [client 158.23.17.4:57029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ph.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9PwAAADU"]
[Tue Aug 18 13:00:40.988505 2026] [security2:error] [pid 123784:tid 123956] [client 158.23.17.4:9326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/30.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9QQAAACY"]
[Tue Aug 18 13:00:41.003954 2026] [security2:error] [pid 123784:tid 123789] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/rip.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9RQAAVAA"]
[Tue Aug 18 13:00:41.039671 2026] [security2:error] [pid 123784:tid 123933] [client 20.250.13.23:44064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9RwAAAA8"]
[Tue Aug 18 13:00:41.051945 2026] [security2:error] [pid 123784:tid 123924] [client 20.151.109.219:60366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/gj.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9SwAAAAY"]
[Tue Aug 18 13:00:41.077827 2026] [security2:error] [pid 123784:tid 123968] [client 51.116.232.28:19059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/file1221.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9TQAAADI"]
[Tue Aug 18 13:00:41.100842 2026] [security2:error] [pid 123784:tid 124025] [client 158.158.74.177:5118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/subdom/ant/makeasmtp.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9UgAAAGs"]
[Tue Aug 18 13:00:41.127442 2026] [security2:error] [pid 123784:tid 124019] [client 158.23.17.4:56714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ip.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9VAAAAGU"]
[Tue Aug 18 13:00:41.134312 2026] [security2:error] [pid 123784:tid 123936] [client 158.23.17.4:34146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ey.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9VgAAABI"]
[Tue Aug 18 13:00:41.155715 2026] [security2:error] [pid 123784:tid 124024] [client 168.62.48.100:5589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9WQAAAGo"]
[Tue Aug 18 13:00:41.156635 2026] [security2:error] [pid 123784:tid 123932] [client 20.79.204.6:14092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/maint.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9WgAAAA4"]
[Tue Aug 18 13:00:41.175256 2026] [security2:error] [pid 123784:tid 123931] [client 20.104.100.201:61402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/dot.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9XAAAAA0"]
[Tue Aug 18 13:00:41.177954 2026] [security2:error] [pid 123784:tid 123929] [client 20.79.204.6:2235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/akc.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9XQAAAAs"]
[Tue Aug 18 13:00:41.182506 2026] [security2:error] [pid 123784:tid 123961] [client 54.167.223.174:6580] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.autocred360.com.br"] [uri "/index.php"] [unique_id "aoSBqGwDnJBNj2tDbYb86QAAACs"], referer: https://www.autocred360.com.br
[Tue Aug 18 13:00:41.185221 2026] [security2:error] [pid 123784:tid 123805] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/uploads/"] [unique_id "aoSBqWwDnJBNj2tDbYb9XgAAJRA"]
[Tue Aug 18 13:00:41.249843 2026] [security2:error] [pid 123784:tid 123843] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/kir.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9YAAAHTY"]
[Tue Aug 18 13:00:41.256689 2026] [security2:error] [pid 123784:tid 124040] [client 178.153.171.161:7100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9YQAAAHo"]
[Tue Aug 18 13:00:41.256838 2026] [security2:error] [pid 123784:tid 124040] [client 178.153.171.161:7100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9YQAAAHo"]
[Tue Aug 18 13:00:41.261974 2026] [security2:error] [pid 123784:tid 123989] [client 68.155.156.252:32302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/fi.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9YgAAAEc"]
[Tue Aug 18 13:00:41.292579 2026] [security2:error] [pid 123784:tid 123988] [client 157.20.138.62:60219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9YwAAAEY"]
[Tue Aug 18 13:00:41.292739 2026] [security2:error] [pid 123784:tid 123988] [client 157.20.138.62:60219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9YwAAAEY"]
[Tue Aug 18 13:00:41.329517 2026] [security2:error] [pid 123784:tid 123958] [client 20.65.98.162:45569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/xyn.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9aAAAACg"]
[Tue Aug 18 13:00:41.345177 2026] [security2:error] [pid 123784:tid 124030] [client 20.226.36.136:65340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9agAAAHA"]
[Tue Aug 18 13:00:41.348001 2026] [security2:error] [pid 123784:tid 123970] [client 52.173.121.69:53912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/zznmg.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9awAAADQ"]
[Tue Aug 18 13:00:41.353293 2026] [security2:error] [pid 123784:tid 123918] [client 20.100.169.31:3753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9bAAAAAA"]
[Tue Aug 18 13:00:41.371379 2026] [security2:error] [pid 123784:tid 123991] [client 20.127.136.245:28069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/classwithtostring.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9bQAAAEk"]
[Tue Aug 18 13:00:41.371818 2026] [security2:error] [pid 123784:tid 123943] [client 20.250.27.191:45791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/File.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9bgAAABk"]
[Tue Aug 18 13:00:41.382531 2026] [security2:error] [pid 123784:tid 123799] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/xmlrpc.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9cAAAaAo"]
[Tue Aug 18 13:00:41.479781 2026] [security2:error] [pid 123784:tid 123994] [client 216.73.161.219:27369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-login.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9ZgAAAEw"], referer: https://ozzyfernandesoficial.com.br/wp-login.php
[Tue Aug 18 13:00:41.486034 2026] [security2:error] [pid 123784:tid 124041] [client 20.100.169.31:4683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9ewAAAHs"]
[Tue Aug 18 13:00:41.513374 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:41.513772 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:41.550046 2026] [security2:error] [pid 123784:tid 123925] [client 51.116.232.28:18978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/nox.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9gAAAAAc"]
[Tue Aug 18 13:00:41.572954 2026] [security2:error] [pid 123784:tid 124028] [client 20.79.204.6:10383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9gQAAAG4"]
[Tue Aug 18 13:00:41.573908 2026] [security2:error] [pid 123784:tid 123852] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/moon.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9ggAAHj8"]
[Tue Aug 18 13:00:41.583863 2026] [security2:error] [pid 123784:tid 124039] [client 20.151.109.219:14125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/pd.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9gwAAAHk"]
[Tue Aug 18 13:00:41.634291 2026] [security2:error] [pid 123784:tid 124006] [client 20.65.98.162:45618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9hgAAAFg"]
[Tue Aug 18 13:00:41.635178 2026] [security2:error] [pid 123784:tid 123968] [client 68.155.156.252:8078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/chris.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9hwAAADI"]
[Tue Aug 18 13:00:41.636850 2026] [security2:error] [pid 123784:tid 123804] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/nofile.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9iAAAEA8"]
[Tue Aug 18 13:00:41.659551 2026] [security2:error] [pid 123784:tid 124035] [client 20.250.13.23:6374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9iQAAAHU"]
[Tue Aug 18 13:00:41.718590 2026] [security2:error] [pid 123784:tid 124023] [client 158.158.74.177:5119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/system.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9jAAAAGk"]
[Tue Aug 18 13:00:41.726540 2026] [security2:error] [pid 123784:tid 123953] [client 20.104.100.201:61978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/005.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9jQAAACM"]
[Tue Aug 18 13:00:41.762385 2026] [security2:error] [pid 123784:tid 123973] [client 20.250.13.23:51281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9jwAAADc"]
[Tue Aug 18 13:00:41.768264 2026] [security2:error] [pid 123784:tid 123874] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/cache.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9kAAAAVU"]
[Tue Aug 18 13:00:41.769573 2026] [security2:error] [pid 123784:tid 123949] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/file5.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9kQAAAB8"]
[Tue Aug 18 13:00:41.789969 2026] [security2:error] [pid 123784:tid 124018] [client 20.79.204.6:2229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/buy.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9kwAAAGQ"]
[Tue Aug 18 13:00:41.794466 2026] [security2:error] [pid 123784:tid 123942] [client 20.250.27.191:35690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/fi22.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9lAAAABg"]
[Tue Aug 18 13:00:41.813798 2026] [security2:error] [pid 123784:tid 124011] [client 158.23.17.4:33430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/lv.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9lQAAAF0"]
[Tue Aug 18 13:00:41.814199 2026] [security2:error] [pid 123784:tid 123936] [client 20.65.98.162:17323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/xyn.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9lgAAABI"]
[Tue Aug 18 13:00:41.828495 2026] [security2:error] [pid 123784:tid 123996] [client 20.38.3.247:24269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9lwAAAE4"]
[Tue Aug 18 13:00:41.828858 2026] [security2:error] [pid 123784:tid 123990] [client 20.127.136.245:28512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/666.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9mAAAAEg"]
[Tue Aug 18 13:00:41.832863 2026] [security2:error] [pid 123784:tid 123851] [remote 20.54.134.42:3697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.134.54.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/wp-login.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9mQAASj4"]
[Tue Aug 18 13:00:41.840382 2026] [security2:error] [pid 123784:tid 124002] [client 20.79.204.6:14121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/phpMailer.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9mgAAAFQ"]
[Tue Aug 18 13:00:41.860389 2026] [security2:error] [pid 123784:tid 123972] [client 5.31.227.224:1439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9nAAAADY"]
[Tue Aug 18 13:00:41.860559 2026] [security2:error] [pid 123784:tid 123972] [client 5.31.227.224:1439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9nAAAADY"]
[Tue Aug 18 13:00:41.861762 2026] [security2:error] [pid 123784:tid 123790] [remote 47.128.19.249:52060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cabeceiragrandemg.com.br"] [uri "/robots.txt"] [unique_id "aoSBqWwDnJBNj2tDbYb9ngAAagE"]
[Tue Aug 18 13:00:41.880661 2026] [security2:error] [pid 123784:tid 123963] [client 168.62.48.100:5610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9oAAAAC0"]
[Tue Aug 18 13:00:41.885407 2026] [security2:error] [pid 123784:tid 123971] [client 213.35.127.232:62445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9oQAAADU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:41.896992 2026] [security2:error] [pid 123784:tid 123931] [client 158.23.17.4:29490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/pu.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9ogAAAA0"]
[Tue Aug 18 13:00:41.952384 2026] [security2:error] [pid 123784:tid 123921] [client 51.116.232.28:18958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/akismet.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9pgAAAAM"]
[Tue Aug 18 13:00:41.955449 2026] [security2:error] [pid 123784:tid 123901] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/block-bindings/"] [unique_id "aoSBqWwDnJBNj2tDbYb9qAAAHXA"]
[Tue Aug 18 13:00:41.968393 2026] [security2:error] [pid 123784:tid 123965] [client 172.202.39.151:4728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/abc.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9qgAAAC8"]
[Tue Aug 18 13:00:41.973790 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:41.974073 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:41.981142 2026] [security2:error] [pid 123784:tid 124019] [client 20.100.169.31:19808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9qwAAAGU"]
[Tue Aug 18 13:00:41.990280 2026] [security2:error] [pid 123784:tid 123854] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/fling.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9rAAAR0E"]
[Tue Aug 18 13:00:41.994381 2026] [security2:error] [pid 123784:tid 123940] [client 135.225.78.186:37932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/akismet.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9rQAAABY"]
[Tue Aug 18 13:00:42.014074 2026] [security2:error] [pid 123784:tid 124013] [client 20.151.109.219:63976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/th.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9rwAAAF8"]
[Tue Aug 18 13:00:42.049554 2026] [security2:error] [pid 123784:tid 123918] [client 68.155.156.252:48105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/doc.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9swAAAAA"]
[Tue Aug 18 13:00:42.089368 2026] [security2:error] [pid 123784:tid 123952] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9tAAAACI"]
[Tue Aug 18 13:00:42.118190 2026] [security2:error] [pid 123784:tid 124037] [client 20.104.100.201:61414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/v2.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9tQAAAHc"]
[Tue Aug 18 13:00:42.125911 2026] [security2:error] [pid 123784:tid 123961] [client 20.100.169.31:4421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/akc.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9tgAAACs"]
[Tue Aug 18 13:00:42.137735 2026] [security2:error] [pid 123784:tid 123828] [remote 47.128.19.249:51956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "designacao2022.cabeceiragrandemg.com.br"] [uri "/robots.txt"] [unique_id "aoSBqmwDnJBNj2tDbYb9uAAAaCc"]
[Tue Aug 18 13:00:42.139209 2026] [security2:error] [pid 123784:tid 123824] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/vendor/"] [unique_id "aoSBqmwDnJBNj2tDbYb9uQAALCM"]
[Tue Aug 18 13:00:42.201987 2026] [security2:error] [pid 123784:tid 124012] [client 68.221.73.131:55163] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.acecdlunai.com.br"] [uri "/1.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9uwAAAF4"]
[Tue Aug 18 13:00:42.202090 2026] [security2:error] [pid 123784:tid 124012] [client 68.221.73.131:55163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/1.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9uwAAAF4"]
[Tue Aug 18 13:00:42.208426 2026] [security2:error] [pid 123784:tid 123941] [client 158.23.17.4:25404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/99.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9vQAAABc"]
[Tue Aug 18 13:00:42.239483 2026] [security2:error] [pid 123784:tid 124017] [client 20.65.98.162:56497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/inso.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9wAAAAGM"]
[Tue Aug 18 13:00:42.274133 2026] [authz_core:error] [pid 123784:tid 123888] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:42.274416 2026] [authz_core:error] [pid 123784:tid 123888] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:42.279947 2026] [security2:error] [pid 123784:tid 123998] [client 102.213.179.104:63937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9wwAAAFA"]
[Tue Aug 18 13:00:42.280335 2026] [security2:error] [pid 123784:tid 123998] [client 102.213.179.104:63937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9wwAAAFA"]
[Tue Aug 18 13:00:42.281352 2026] [security2:error] [pid 123784:tid 123953] [client 20.250.27.191:43514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9xAAAACM"]
[Tue Aug 18 13:00:42.297836 2026] [autoindex:error] [pid 123784:tid 124032] [client 201.69.204.147:52297] AH01276: Cannot serve directory /home3/luzpatchworkcom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:42.309743 2026] [security2:error] [pid 123784:tid 123791] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/zoo1.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9yAAAHwI"]
[Tue Aug 18 13:00:42.323751 2026] [security2:error] [pid 123784:tid 123997] [client 20.250.13.23:23716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-2019.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9ygAAAE8"]
[Tue Aug 18 13:00:42.325176 2026] [security2:error] [pid 123784:tid 124018] [client 158.23.17.4:51148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/s.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9ywAAAGQ"]
[Tue Aug 18 13:00:42.334840 2026] [security2:error] [pid 123784:tid 123886] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/themes/"] [unique_id "aoSBqmwDnJBNj2tDbYb9zQAAFGE"]
[Tue Aug 18 13:00:42.367701 2026] [security2:error] [pid 123784:tid 123936] [client 51.116.232.28:12868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/admin.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9zgAAABI"]
[Tue Aug 18 13:00:42.372197 2026] [security2:error] [pid 123784:tid 124044] [client 20.151.109.219:14085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/admin404.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9zwAAAH4"]
[Tue Aug 18 13:00:42.377619 2026] [security2:error] [pid 123784:tid 124026] [client 20.206.73.37:29991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBqmwDnJBNj2tDbYb90AAAAGw"]
[Tue Aug 18 13:00:42.391055 2026] [security2:error] [pid 123784:tid 123926] [client 20.79.204.6:2209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/cong.php"] [unique_id "aoSBqmwDnJBNj2tDbYb90QAAAAg"]
[Tue Aug 18 13:00:42.398130 2026] [security2:error] [pid 123784:tid 124002] [client 20.91.215.254:27394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/backup.php"] [unique_id "aoSBqmwDnJBNj2tDbYb90gAAAFQ"]
[Tue Aug 18 13:00:42.407496 2026] [security2:error] [pid 123784:tid 124020] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBqmwDnJBNj2tDbYb91AAAAGY"]
[Tue Aug 18 13:00:42.440143 2026] [security2:error] [pid 123784:tid 124006] [client 20.79.204.6:14018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSBqmwDnJBNj2tDbYb91gAAAFg"]
[Tue Aug 18 13:00:42.450524 2026] [security2:error] [pid 123784:tid 124033] [client 158.23.17.4:44829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/51.php"] [unique_id "aoSBqmwDnJBNj2tDbYb91wAAAHM"]
[Tue Aug 18 13:00:42.455216 2026] [security2:error] [pid 123784:tid 123963] [client 20.104.100.201:61433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wkl.php"] [unique_id "aoSBqmwDnJBNj2tDbYb92AAAAC0"]
[Tue Aug 18 13:00:42.458384 2026] [security2:error] [pid 123784:tid 123971] [client 20.127.136.245:28048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/ws54.php"] [unique_id "aoSBqmwDnJBNj2tDbYb92QAAADU"]
[Tue Aug 18 13:00:42.466108 2026] [security2:error] [pid 123784:tid 123993] [client 158.158.74.177:17287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/system_log.php"] [unique_id "aoSBqmwDnJBNj2tDbYb92gAAAEs"]
[Tue Aug 18 13:00:42.467218 2026] [security2:error] [pid 123784:tid 124045] [client 168.62.48.100:5576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSBqmwDnJBNj2tDbYb92wAAAH8"]
[Tue Aug 18 13:00:42.492339 2026] [security2:error] [pid 123784:tid 123956] [client 20.226.36.136:62205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSBqmwDnJBNj2tDbYb93QAAACY"]
[Tue Aug 18 13:00:42.509432 2026] [security2:error] [pid 123784:tid 123973] [client 79.127.164.8:32978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/www.bak"] [unique_id "aoSBqmwDnJBNj2tDbYb93wAAADc"], referer: https://medihub.com.br/www.bak
[Tue Aug 18 13:00:42.538810 2026] [security2:error] [pid 123784:tid 123914] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBqmwDnJBNj2tDbYb94wAAZX0"]
[Tue Aug 18 13:00:42.551193 2026] [security2:error] [pid 123784:tid 123940] [client 158.23.17.4:9369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ry.php"] [unique_id "aoSBqmwDnJBNj2tDbYb95AAAABY"]
[Tue Aug 18 13:00:42.575477 2026] [authz_core:error] [pid 123784:tid 123829] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:42.575741 2026] [authz_core:error] [pid 123784:tid 123829] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:42.599147 2026] [security2:error] [pid 123784:tid 123964] [client 68.155.156.252:50901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/1337.php"] [unique_id "aoSBqmwDnJBNj2tDbYb95wAAAC4"]
[Tue Aug 18 13:00:42.634045 2026] [autoindex:error] [pid 123784:tid 123980] [client 172.202.39.151:40344] AH01276: Cannot serve directory /home2/ctamcursos/grupoctam.com.br/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:42.638046 2026] [security2:error] [pid 123784:tid 123859] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/zoo2.php"] [unique_id "aoSBqmwDnJBNj2tDbYb96wAANEY"]
[Tue Aug 18 13:00:42.675963 2026] [autoindex:error] [pid 123784:tid 123978] [client 201.69.204.147:52301] AH01276: Cannot serve directory /home3/luzpatchworkcom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:42.693964 2026] [security2:error] [pid 123784:tid 123961] [client 20.151.109.219:60390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/qo.php"] [unique_id "aoSBqmwDnJBNj2tDbYb97gAAACs"]
[Tue Aug 18 13:00:42.697384 2026] [autoindex:error] [pid 123784:tid 124037] [client 169.58.72.248:54025] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:42.721243 2026] [security2:error] [pid 123784:tid 123994] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSBqmwDnJBNj2tDbYb98AAAAEw"]
[Tue Aug 18 13:00:42.746150 2026] [security2:error] [pid 123784:tid 124030] [client 20.65.98.162:55186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/puc.php"] [unique_id "aoSBqmwDnJBNj2tDbYb98QAAAHA"]
[Tue Aug 18 13:00:42.762977 2026] [security2:error] [pid 123784:tid 123950] [client 168.62.48.100:5573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSBqmwDnJBNj2tDbYb98wAAACA"]
[Tue Aug 18 13:00:42.770453 2026] [security2:error] [pid 123784:tid 123863] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/js/crop/"] [unique_id "aoSBqmwDnJBNj2tDbYb99AAAYko"]
[Tue Aug 18 13:00:42.771328 2026] [security2:error] [pid 123784:tid 124012] [client 20.104.100.201:61403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-asudo.php"] [unique_id "aoSBqmwDnJBNj2tDbYb99QAAAF4"]
[Tue Aug 18 13:00:42.779711 2026] [security2:error] [pid 123784:tid 123941] [client 51.116.232.28:12920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/ajax.php"] [unique_id "aoSBqmwDnJBNj2tDbYb99wAAABc"]
[Tue Aug 18 13:00:42.796875 2026] [security2:error] [pid 123784:tid 124039] [client 20.250.27.191:3597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9-AAAAHk"]
[Tue Aug 18 13:00:42.832366 2026] [autoindex:error] [pid 123784:tid 123927] [client 201.69.204.147:52305] AH01276: Cannot serve directory /home3/luzpatchworkcom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:42.875126 2026] [authz_core:error] [pid 123784:tid 123837] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:42.875381 2026] [authz_core:error] [pid 123784:tid 123837] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:42.902621 2026] [security2:error] [pid 123784:tid 123988] [client 213.35.127.232:62699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9_wAAAEY"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:42.909510 2026] [security2:error] [pid 123784:tid 124022] [client 20.100.169.31:24230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/buy.php"] [unique_id "aoSBqmwDnJBNj2tDbYb-AAAAAGg"]
[Tue Aug 18 13:00:42.909839 2026] [autoindex:error] [pid 123784:tid 123998] [client 201.69.204.147:52308] AH01276: Cannot serve directory /home3/luzpatchworkcom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:42.910872 2026] [security2:error] [pid 123784:tid 124031] [client 223.185.37.47:2599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBqmwDnJBNj2tDbYb-AQAAAHE"]
[Tue Aug 18 13:00:42.919500 2026] [security2:error] [pid 123784:tid 124031] [client 223.185.37.47:2599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBqmwDnJBNj2tDbYb-AQAAAHE"]
[Tue Aug 18 13:00:42.958182 2026] [security2:error] [pid 123784:tid 123862] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-mail.php"] [unique_id "aoSBqmwDnJBNj2tDbYb-BAAAFEk"]
[Tue Aug 18 13:00:42.969200 2026] [security2:error] [pid 123784:tid 123924] [client 20.127.136.245:27879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/deepseek_d.php"] [unique_id "aoSBqmwDnJBNj2tDbYb-BQAAAAY"]
[Tue Aug 18 13:00:42.969329 2026] [security2:error] [pid 123784:tid 124027] [client 20.250.13.23:44063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/cjfuns.php"] [unique_id "aoSBqmwDnJBNj2tDbYb-BgAAAG0"]
[Tue Aug 18 13:00:42.973318 2026] [security2:error] [pid 123784:tid 124007] [client 158.23.17.4:54741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/uo.php"] [unique_id "aoSBqmwDnJBNj2tDbYb-BwAAAFk"]
[Tue Aug 18 13:00:42.976619 2026] [security2:error] [pid 123784:tid 124011] [client 172.202.39.151:40344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wso.php"] [unique_id "aoSBqmwDnJBNj2tDbYb-CAAAAF0"]
[Tue Aug 18 13:00:42.992167 2026] [security2:error] [pid 123784:tid 123936] [client 20.226.36.136:52621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSBqmwDnJBNj2tDbYb-CQAAABI"]
[Tue Aug 18 13:00:43.014174 2026] [security2:error] [pid 123784:tid 123948] [client 20.79.204.6:2409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-CgAAAB4"]
[Tue Aug 18 13:00:43.027517 2026] [security2:error] [pid 123784:tid 123926] [client 20.151.109.219:39325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/sd.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-CwAAAAg"]
[Tue Aug 18 13:00:43.028637 2026] [security2:error] [pid 123784:tid 124009] [client 20.100.169.31:38657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-DAAAAFs"]
[Tue Aug 18 13:00:43.034380 2026] [security2:error] [pid 123784:tid 124002] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/atomlib.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-DQAAAFQ"]
[Tue Aug 18 13:00:43.042557 2026] [security2:error] [pid 123784:tid 123968] [client 20.79.204.6:14044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/al.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-DgAAADI"]
[Tue Aug 18 13:00:43.059966 2026] [security2:error] [pid 123784:tid 123792] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/org.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-EAAAZgM"]
[Tue Aug 18 13:00:43.076324 2026] [security2:error] [pid 123784:tid 124006] [client 68.155.156.252:42194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/Njima.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-EQAAAFg"]
[Tue Aug 18 13:00:43.081508 2026] [security2:error] [pid 123784:tid 123919] [client 158.23.17.4:31918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ew.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-EgAAAAE"]
[Tue Aug 18 13:00:43.089787 2026] [security2:error] [pid 123784:tid 124004] [client 158.158.74.177:5104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/templates/beez3/error.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-EwAAAFY"]
[Tue Aug 18 13:00:43.104068 2026] [security2:error] [pid 123784:tid 124033] [client 168.62.48.100:5629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-GAAAAHM"]
[Tue Aug 18 13:00:43.136328 2026] [security2:error] [pid 123784:tid 123953] [client 20.91.215.254:27402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-GgAAACM"]
[Tue Aug 18 13:00:43.139671 2026] [security2:error] [pid 123784:tid 124045] [client 20.104.100.201:61986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/az.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-GwAAAH8"]
[Tue Aug 18 13:00:43.145034 2026] [security2:error] [pid 123784:tid 123976] [client 185.191.171.8:42568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/robots.txt"] [unique_id "aoSBq2wDnJBNj2tDbYb-HQAAADo"]
[Tue Aug 18 13:00:43.145178 2026] [security2:error] [pid 123784:tid 123976] [client 185.191.171.8:42568] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/robots.txt"] [unique_id "aoSBq2wDnJBNj2tDbYb-HQAAADo"]
[Tue Aug 18 13:00:43.146408 2026] [security2:error] [pid 123784:tid 123931] [client 68.221.73.131:55128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/coffee.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-HgAAAA0"]
[Tue Aug 18 13:00:43.151751 2026] [security2:error] [pid 123784:tid 124005] [client 20.250.13.23:36928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/NewFile.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-HwAAAFc"]
[Tue Aug 18 13:00:43.154956 2026] [security2:error] [pid 123784:tid 123810] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/o.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-IAAACxU"]
[Tue Aug 18 13:00:43.176002 2026] [security2:error] [pid 123784:tid 123973] [client 135.225.78.186:59283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/admin.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-IwAAADc"]
[Tue Aug 18 13:00:43.254893 2026] [security2:error] [pid 123784:tid 123921] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-JQAAAzs"]
[Tue Aug 18 13:00:43.292126 2026] [security2:error] [pid 123784:tid 123954] [client 20.250.27.191:43467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-JwAAACQ"]
[Tue Aug 18 13:00:43.348897 2026] [security2:error] [pid 123784:tid 123912] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/bb.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-KgAAQHs"]
[Tue Aug 18 13:00:43.397755 2026] [security2:error] [pid 123784:tid 124037] [client 20.65.98.162:55177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/19.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-LQAAAHc"]
[Tue Aug 18 13:00:43.428276 2026] [security2:error] [pid 123784:tid 123841] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/imageskir.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-LwAAOTQ"]
[Tue Aug 18 13:00:43.473003 2026] [security2:error] [pid 123784:tid 124016] [client 168.62.48.100:5581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-MgAAAGI"]
[Tue Aug 18 13:00:43.477853 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:43.478124 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:43.498046 2026] [security2:error] [pid 123784:tid 123941] [client 20.104.100.201:61421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/z43agz.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-NAAAABc"]
[Tue Aug 18 13:00:43.529443 2026] [security2:error] [pid 123784:tid 124003] [client 4.232.94.69:15676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/xmlrpc.php0"] [unique_id "aoSBq2wDnJBNj2tDbYb-NgAAAFU"]
[Tue Aug 18 13:00:43.529543 2026] [security2:error] [pid 123784:tid 123967] [client 158.23.17.4:20398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/er.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-NwAAADE"]
[Tue Aug 18 13:00:43.533282 2026] [security2:error] [pid 123784:tid 123819] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-OAAAYx4"]
[Tue Aug 18 13:00:43.558931 2026] [security2:error] [pid 123784:tid 123934] [client 158.23.17.4:63663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/pm.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-OgAAABA"]
[Tue Aug 18 13:00:43.561429 2026] [security2:error] [pid 123784:tid 123958] [client 20.100.169.31:4348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/cong.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-OwAAACg"]
[Tue Aug 18 13:00:43.567686 2026] [security2:error] [pid 123784:tid 123962] [client 20.127.136.245:27851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/function/function.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-PAAAACw"]
[Tue Aug 18 13:00:43.579211 2026] [security2:error] [pid 123784:tid 124001] [client 20.79.204.6:10688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/function/function.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-PQAAAFM"]
[Tue Aug 18 13:00:43.587244 2026] [security2:error] [pid 123784:tid 124041] [client 20.226.56.190:28849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-PgAAAHs"]
[Tue Aug 18 13:00:43.606698 2026] [security2:error] [pid 123784:tid 124022] [client 68.155.156.252:59737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/BIBIL.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-QQAAAGg"]
[Tue Aug 18 13:00:43.627786 2026] [security2:error] [pid 123784:tid 124030] [client 20.79.204.6:2221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/db.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-QgAAAHA"]
[Tue Aug 18 13:00:43.650635 2026] [security2:error] [pid 123784:tid 123924] [client 20.226.36.136:62197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-RAAAAAY"]
[Tue Aug 18 13:00:43.651909 2026] [security2:error] [pid 123784:tid 123974] [client 20.79.204.6:14090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-RQAAADg"]
[Tue Aug 18 13:00:43.670713 2026] [security2:error] [pid 123784:tid 123925] [client 20.100.169.31:3760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-RgAAAAc"]
[Tue Aug 18 13:00:43.709041 2026] [security2:error] [pid 123784:tid 124039] [client 20.250.13.23:44056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-SwAAAHk"]
[Tue Aug 18 13:00:43.734234 2026] [security2:error] [pid 123784:tid 123825] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/network/"] [unique_id "aoSBq2wDnJBNj2tDbYb-TAAAHiQ"]
[Tue Aug 18 13:00:43.746956 2026] [security2:error] [pid 123784:tid 124002] [client 20.151.109.219:14289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/km.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-TQAAAFQ"]
[Tue Aug 18 13:00:43.748346 2026] [security2:error] [pid 123784:tid 123845] [remote 57.141.22.7:29010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSBq2wDnJBNj2tDbYb-TgAACTg"]
[Tue Aug 18 13:00:43.751130 2026] [security2:error] [pid 123784:tid 123861] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/indexo.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-TwAAaUg"]
[Tue Aug 18 13:00:43.757855 2026] [security2:error] [pid 123784:tid 123957] [client 168.62.48.100:5524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-UAAAACc"]
[Tue Aug 18 13:00:43.760983 2026] [security2:error] [pid 123784:tid 124020] [client 172.202.39.151:12736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/sf.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-UQAAAGY"]
[Tue Aug 18 13:00:43.776198 2026] [security2:error] [pid 123784:tid 124006] [client 158.23.17.4:32541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/pqr.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-UwAAAFg"]
[Tue Aug 18 13:00:43.778642 2026] [security2:error] [pid 123784:tid 124035] [client 158.158.74.177:5080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/test.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-VAAAAHU"]
[Tue Aug 18 13:00:43.779324 2026] [authz_core:error] [pid 123784:tid 123899] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:43.779585 2026] [authz_core:error] [pid 123784:tid 123899] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:43.805261 2026] [security2:error] [pid 123784:tid 124004] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/min.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-VQAAAFY"]
[Tue Aug 18 13:00:43.811803 2026] [security2:error] [pid 123784:tid 124000] [client 20.91.215.254:12009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/sx.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-VgAAAFI"]
[Tue Aug 18 13:00:43.855434 2026] [security2:error] [pid 123784:tid 123963] [client 52.141.58.175:9669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/tmp/index.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-WAAAAC0"]
[Tue Aug 18 13:00:43.857860 2026] [security2:error] [pid 123784:tid 124045] [client 20.104.100.201:61973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/3.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-WQAAAH8"]
[Tue Aug 18 13:00:43.909906 2026] [security2:error] [pid 123784:tid 123882] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-XAAAdl0"]
[Tue Aug 18 13:00:43.917977 2026] [security2:error] [pid 123784:tid 124025] [client 213.35.127.232:62916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-XQAAAGs"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:43.954550 2026] [security2:error] [pid 123784:tid 123977] [client 68.155.156.252:59721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/too.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-XwAAADs"]
[Tue Aug 18 13:00:44.016334 2026] [security2:error] [pid 123784:tid 124040] [client 172.202.39.151:4284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/akcc.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-YQAAAHo"]
[Tue Aug 18 13:00:44.032414 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.36.136:61459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-YgAAAEc"]
[Tue Aug 18 13:00:44.068409 2026] [security2:error] [pid 123784:tid 123956] [client 20.127.136.245:28091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/nw.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-ZQAAACY"]
[Tue Aug 18 13:00:44.082743 2026] [security2:error] [pid 123784:tid 123814] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/xmrlpc.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-aAAAXxk"]
[Tue Aug 18 13:00:44.083663 2026] [authz_core:error] [pid 123784:tid 123794] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:44.084121 2026] [authz_core:error] [pid 123784:tid 123794] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:44.100444 2026] [security2:error] [pid 123784:tid 124029] [client 20.65.98.162:45614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/133.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-aQAAAG8"]
[Tue Aug 18 13:00:44.107487 2026] [security2:error] [pid 123784:tid 123992] [client 68.221.73.131:39864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-agAAAEo"]
[Tue Aug 18 13:00:44.122596 2026] [security2:error] [pid 123784:tid 123980] [client 158.23.17.4:8905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/an.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-cwAAAD4"]
[Tue Aug 18 13:00:44.134168 2026] [security2:error] [pid 123784:tid 123943] [client 158.23.17.4:47928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/kx.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-dQAAABk"]
[Tue Aug 18 13:00:44.145086 2026] [security2:error] [pid 123784:tid 123985] [client 37.40.227.74:57058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-dgAAAEM"]
[Tue Aug 18 13:00:44.145243 2026] [security2:error] [pid 123784:tid 123985] [client 37.40.227.74:57058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-dgAAAEM"]
[Tue Aug 18 13:00:44.157770 2026] [security2:error] [pid 123784:tid 123933] [client 20.151.109.219:39302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/mf.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-eAAAAA8"]
[Tue Aug 18 13:00:44.178202 2026] [security2:error] [pid 123784:tid 124008] [client 20.104.100.201:61410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/log.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-eQAAAFo"]
[Tue Aug 18 13:00:44.194246 2026] [security2:error] [pid 123784:tid 123879] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-ewAAflo"]
[Tue Aug 18 13:00:44.195514 2026] [autoindex:error] [pid 123784:tid 124037] [client 137.184.230.120:55150] AH01276: Cannot serve directory /home3/andrades/mail.andradesales.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:44.197969 2026] [security2:error] [pid 123784:tid 124019] [client 20.100.169.31:4948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-fAAAAGU"]
[Tue Aug 18 13:00:44.221259 2026] [security2:error] [pid 123784:tid 124021] [client 158.23.17.4:20444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/qk.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-fgAAAGc"]
[Tue Aug 18 13:00:44.258933 2026] [security2:error] [pid 123784:tid 124014] [client 20.79.204.6:14139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-activat.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-gQAAAGA"]
[Tue Aug 18 13:00:44.270810 2026] [security2:error] [pid 123784:tid 123913] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/file.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-ggAAbnw"]
[Tue Aug 18 13:00:44.275432 2026] [security2:error] [pid 123784:tid 123940] [client 20.79.204.6:2196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/dropdown.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-gwAAABY"]
[Tue Aug 18 13:00:44.278511 2026] [security2:error] [pid 123784:tid 123932] [client 52.173.121.69:15020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/bhfnd.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-hAAAAA4"]
[Tue Aug 18 13:00:44.336358 2026] [security2:error] [pid 123784:tid 123973] [client 20.250.13.23:51902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-iAAAADc"]
[Tue Aug 18 13:00:44.347894 2026] [autoindex:error] [pid 123784:tid 124032] [client 205.210.31.18:63808] AH01276: Cannot serve directory /home1/gfrison965/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:44.354571 2026] [security2:error] [pid 123784:tid 123970] [client 20.250.13.23:44040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-iwAAADQ"]
[Tue Aug 18 13:00:44.358779 2026] [security2:error] [pid 123784:tid 123998] [client 168.62.48.100:5521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-jAAAAFA"]
[Tue Aug 18 13:00:44.392342 2026] [security2:error] [pid 123784:tid 123938] [client 172.202.39.151:60121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/gecko.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-jwAAABQ"]
[Tue Aug 18 13:00:44.406762 2026] [security2:error] [pid 123784:tid 124027] [client 68.155.156.252:57295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/g3.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-kAAAAG0"]
[Tue Aug 18 13:00:44.409472 2026] [security2:error] [pid 123784:tid 123930] [client 20.79.204.6:10388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/nw.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-kQAAAAw"]
[Tue Aug 18 13:00:44.419308 2026] [security2:error] [pid 123784:tid 123996] [client 43.157.22.57:56188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.22.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioarquitetar.com"] [uri "/wp-admin/upgrade.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-kgAAAE4"]
[Tue Aug 18 13:00:44.422436 2026] [security2:error] [pid 123784:tid 123995] [client 158.158.74.177:17341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/test1.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-lAAAAE0"]
[Tue Aug 18 13:00:44.423347 2026] [security2:error] [pid 123784:tid 123945] [client 52.141.58.175:11682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/tmpls.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-lQAAABs"]
[Tue Aug 18 13:00:44.449552 2026] [security2:error] [pid 123784:tid 123948] [client 172.202.39.151:40333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/index/function.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-lgAAAB4"]
[Tue Aug 18 13:00:44.450892 2026] [security2:error] [pid 123784:tid 123926] [client 20.75.92.165:4346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-lwAAAAg"]
[Tue Aug 18 13:00:44.489619 2026] [security2:error] [pid 123784:tid 123942] [client 20.250.27.191:35676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-ngAAABg"]
[Tue Aug 18 13:00:44.500273 2026] [security2:error] [pid 123784:tid 124006] [client 20.151.109.219:14103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ie.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-oAAAAFg"]
[Tue Aug 18 13:00:44.502590 2026] [security2:error] [pid 123784:tid 124035] [client 20.100.169.31:19826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-oQAAAHU"]
[Tue Aug 18 13:00:44.524575 2026] [security2:error] [pid 123784:tid 124000] [client 20.104.100.201:34270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/ohct.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-owAAAFI"]
[Tue Aug 18 13:00:44.526233 2026] [security2:error] [pid 123784:tid 124033] [client 20.118.133.132:13808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/php.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-pAAAAHM"]
[Tue Aug 18 13:00:44.535160 2026] [security2:error] [pid 123784:tid 123807] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/8pyceeo.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-pQAASxI"]
[Tue Aug 18 13:00:44.552575 2026] [security2:error] [pid 123784:tid 123963] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/mac.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-pgAAAC0"]
[Tue Aug 18 13:00:44.566848 2026] [security2:error] [pid 123784:tid 124005] [client 20.226.56.190:45054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-qQAAAFc"]
[Tue Aug 18 13:00:44.574103 2026] [security2:error] [pid 123784:tid 123949] [client 20.127.136.245:27858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/xleet.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-qgAAAB8"]
[Tue Aug 18 13:00:44.574419 2026] [security2:error] [pid 123784:tid 124030] [client 20.91.215.254:18138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/st.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-qwAAAHA"]
[Tue Aug 18 13:00:44.627209 2026] [security2:error] [pid 123784:tid 123803] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/epinyins.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-rgAAaw4"]
[Tue Aug 18 13:00:44.782103 2026] [security2:error] [pid 123784:tid 123982] [client 20.65.98.162:56479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/1xmomo.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-sgAAAEA"]
[Tue Aug 18 13:00:44.792385 2026] [security2:error] [pid 123784:tid 123918] [client 20.151.109.219:60867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/nw.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-tQAAAAA"]
[Tue Aug 18 13:00:44.804097 2026] [security2:error] [pid 123784:tid 124008] [client 158.23.17.4:54726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/va.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-tgAAAFo"]
[Tue Aug 18 13:00:44.813387 2026] [security2:error] [pid 123784:tid 123840] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-twAAfjM"]
[Tue Aug 18 13:00:44.827805 2026] [security2:error] [pid 123784:tid 124037] [client 68.221.73.131:55151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-uAAAAHc"]
[Tue Aug 18 13:00:44.865709 2026] [security2:error] [pid 123784:tid 123994] [client 20.75.92.165:4345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-uQAAAEw"]
[Tue Aug 18 13:00:44.869417 2026] [security2:error] [pid 123784:tid 123988] [client 20.79.204.6:13701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-ugAAAEY"]
[Tue Aug 18 13:00:44.872212 2026] [security2:error] [pid 123784:tid 123923] [client 20.100.169.31:4419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/db.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-uwAAAAU"]
[Tue Aug 18 13:00:44.881574 2026] [security2:error] [pid 123784:tid 124040] [client 20.79.204.6:2232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/file.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-vQAAAHo"]
[Tue Aug 18 13:00:44.884066 2026] [security2:error] [pid 123784:tid 123852] [remote 89.185.225.24:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.225.185.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-login.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-vgAAOT8"]
[Tue Aug 18 13:00:44.896973 2026] [security2:error] [pid 123784:tid 124016] [client 20.226.36.136:62172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/rezor.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-vwAAAGI"]
[Tue Aug 18 13:00:44.931272 2026] [security2:error] [pid 123784:tid 123946] [client 213.35.127.232:63127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-wAAAABw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:44.965446 2026] [security2:error] [pid 123784:tid 124003] [client 4.232.94.69:19564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/gebase.php69"] [unique_id "aoSBrGwDnJBNj2tDbYb-wgAAAFU"]
[Tue Aug 18 13:00:44.975834 2026] [security2:error] [pid 123784:tid 123804] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/.admin.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-wwAAEA8"]
[Tue Aug 18 13:00:44.983775 2026] [security2:error] [pid 123784:tid 123964] [client 20.250.13.23:23741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/import.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-xAAAAC4"]
[Tue Aug 18 13:00:44.997143 2026] [security2:error] [pid 123784:tid 123881] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/php-compat/"] [unique_id "aoSBrGwDnJBNj2tDbYb-xQAAClw"]
[Tue Aug 18 13:00:45.019677 2026] [security2:error] [pid 123784:tid 123973] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/nc4.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-yQAAADc"]
[Tue Aug 18 13:00:45.032567 2026] [security2:error] [pid 123784:tid 124032] [client 20.104.100.201:34251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/ot.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-ygAAAHI"]
[Tue Aug 18 13:00:45.035284 2026] [security2:error] [pid 123784:tid 123998] [client 158.23.17.4:34133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/sy.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-ywAAAFA"]
[Tue Aug 18 13:00:45.056118 2026] [security2:error] [pid 123784:tid 124019] [client 158.158.74.177:5109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/text.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-zAAAAGU"]
[Tue Aug 18 13:00:45.068230 2026] [security2:error] [pid 123784:tid 123967] [client 20.127.136.245:28493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-zgAAADE"]
[Tue Aug 18 13:00:45.112934 2026] [security2:error] [pid 123784:tid 123995] [client 20.250.27.191:45783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-0AAAAE0"]
[Tue Aug 18 13:00:45.113036 2026] [security2:error] [pid 123784:tid 123945] [client 158.23.17.4:63676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/dr.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-0QAAABs"]
[Tue Aug 18 13:00:45.114292 2026] [security2:error] [pid 123784:tid 123922] [client 20.151.109.219:14326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/sb.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-0gAAAAQ"]
[Tue Aug 18 13:00:45.136714 2026] [security2:error] [pid 123784:tid 123851] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-0wAAKj4"]
[Tue Aug 18 13:00:45.136933 2026] [security2:error] [pid 123784:tid 123960] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-0wAAKj4"]
[Tue Aug 18 13:00:45.164291 2026] [security2:error] [pid 123784:tid 123939] [client 20.226.36.136:65322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/uploads/bypass.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-1QAAABU"]
[Tue Aug 18 13:00:45.173514 2026] [security2:error] [pid 123784:tid 123865] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-1gAAGEw"]
[Tue Aug 18 13:00:45.184562 2026] [security2:error] [pid 123784:tid 124035] [client 20.65.98.162:45613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/mosty.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-2AAAAHU"]
[Tue Aug 18 13:00:45.208293 2026] [security2:error] [pid 123784:tid 124033] [client 20.75.92.165:4335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/admin.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-2gAAAHM"]
[Tue Aug 18 13:00:45.212516 2026] [security2:error] [pid 123784:tid 124001] [client 20.91.215.254:27403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-2wAAAFM"]
[Tue Aug 18 13:00:45.289486 2026] [authz_core:error] [pid 123784:tid 123790] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:45.289938 2026] [authz_core:error] [pid 123784:tid 123790] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:45.312244 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.36.136:62147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-3QAAAEc"]
[Tue Aug 18 13:00:45.331098 2026] [autoindex:error] [pid 123784:tid 123940] [client 137.184.230.120:35224] AH01276: Cannot serve directory /home3/andrades/mail.andradesales.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:45.332107 2026] [security2:error] [pid 123784:tid 123920] [client 158.23.17.4:60772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/fo.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-3wAAAAI"]
[Tue Aug 18 13:00:45.358955 2026] [security2:error] [pid 123784:tid 124013] [client 172.202.39.151:4723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wk/index.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-4AAAAF8"]
[Tue Aug 18 13:00:45.379435 2026] [security2:error] [pid 123784:tid 123826] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wsomini.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-4QAAPiU"]
[Tue Aug 18 13:00:45.380168 2026] [security2:error] [pid 123784:tid 123836] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-4wAASi8"]
[Tue Aug 18 13:00:45.380515 2026] [security2:error] [pid 123784:tid 123981] [client 20.100.169.31:19794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-4gAAAD8"]
[Tue Aug 18 13:00:45.391441 2026] [security2:error] [pid 123784:tid 123943] [client 20.226.36.136:65343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/index/function.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-5AAAABk"]
[Tue Aug 18 13:00:45.410769 2026] [security2:error] [pid 123784:tid 124037] [client 20.226.36.136:62159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-5QAAAHc"]
[Tue Aug 18 13:00:45.427990 2026] [security2:error] [pid 123784:tid 123923] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/as.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-5gAAAAU"]
[Tue Aug 18 13:00:45.451069 2026] [security2:error] [pid 123784:tid 123987] [client 20.226.36.136:61475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/Cachex.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-6AAAAEU"]
[Tue Aug 18 13:00:45.453943 2026] [security2:error] [pid 123784:tid 123941] [client 20.151.109.219:63958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/xj.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-6QAAABc"]
[Tue Aug 18 13:00:45.458218 2026] [security2:error] [pid 123784:tid 124042] [client 158.23.17.4:1287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/57.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-6gAAAHw"]
[Tue Aug 18 13:00:45.460742 2026] [security2:error] [pid 123784:tid 124028] [client 20.104.100.201:34763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/v5.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-6wAAAG4"]
[Tue Aug 18 13:00:45.471550 2026] [security2:error] [pid 123784:tid 124031] [client 52.141.58.175:4221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/tool.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-7AAAAHE"]
[Tue Aug 18 13:00:45.473983 2026] [security2:error] [pid 123784:tid 123991] [client 68.221.73.131:55133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/yj09.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-7QAAAEk"]
[Tue Aug 18 13:00:45.475092 2026] [security2:error] [pid 123784:tid 124025] [client 20.79.204.6:14134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/past1.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-7gAAAGs"]
[Tue Aug 18 13:00:45.498986 2026] [security2:error] [pid 123784:tid 123973] [client 20.226.36.136:65318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-8QAAADc"]
[Tue Aug 18 13:00:45.501790 2026] [security2:error] [pid 123784:tid 124022] [client 172.202.39.151:40371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/edit.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-8gAAAGg"]
[Tue Aug 18 13:00:45.504640 2026] [security2:error] [pid 123784:tid 123977] [client 20.100.169.31:4951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/dropdown.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-8wAAADs"]
[Tue Aug 18 13:00:45.525194 2026] [security2:error] [pid 123784:tid 124010] [client 20.79.204.6:2395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/goods.php"] [unique_id "aoSBrWwDnJBNj2tDbYb--QAAAFw"]
[Tue Aug 18 13:00:45.566289 2026] [security2:error] [pid 123784:tid 123985] [client 20.127.136.245:27849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/155.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_AQAAAEM"]
[Tue Aug 18 13:00:45.577037 2026] [security2:error] [pid 123784:tid 123827] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_BgAAEiY"]
[Tue Aug 18 13:00:45.585296 2026] [authz_core:error] [pid 123784:tid 123884] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:45.585747 2026] [authz_core:error] [pid 123784:tid 123884] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:45.592412 2026] [security2:error] [pid 123784:tid 123995] [client 20.226.36.136:65280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-2019.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_CAAAAE0"]
[Tue Aug 18 13:00:45.625876 2026] [security2:error] [pid 123784:tid 124006] [client 20.226.36.136:65323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_CwAAAFg"]
[Tue Aug 18 13:00:45.643513 2026] [security2:error] [pid 123784:tid 124035] [client 20.75.92.165:4313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/edit.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_DQAAAHU"]
[Tue Aug 18 13:00:45.644507 2026] [security2:error] [pid 123784:tid 123972] [client 20.226.56.190:23747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/dirs.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_DgAAADY"]
[Tue Aug 18 13:00:45.646088 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.36.136:53524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/.cache/x.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_DwAAAFI"]
[Tue Aug 18 13:00:45.675474 2026] [security2:error] [pid 123784:tid 124018] [client 158.158.74.177:5091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/themes/zmousse/otuz1.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_EgAAAGQ"]
[Tue Aug 18 13:00:45.679708 2026] [security2:error] [pid 123784:tid 123976] [client 20.226.36.136:52668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_EwAAADo"]
[Tue Aug 18 13:00:45.719505 2026] [security2:error] [pid 123784:tid 123978] [client 20.250.13.23:43787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/cropper.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_FQAAADw"]
[Tue Aug 18 13:00:45.753771 2026] [security2:error] [pid 123784:tid 123980] [client 20.226.36.136:53549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-content/index.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_GAAAAD4"]
[Tue Aug 18 13:00:45.761000 2026] [security2:error] [pid 123784:tid 123876] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/function/function.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_GQAASlc"]
[Tue Aug 18 13:00:45.803635 2026] [security2:error] [pid 123784:tid 123943] [client 20.104.100.201:61427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_GwAAABk"]
[Tue Aug 18 13:00:45.808126 2026] [security2:error] [pid 123784:tid 124038] [client 20.226.36.136:61448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_HAAAAHg"]
[Tue Aug 18 13:00:45.814424 2026] [security2:error] [pid 123784:tid 123957] [client 196.12.128.158:52045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_HgAAACc"]
[Tue Aug 18 13:00:45.814555 2026] [security2:error] [pid 123784:tid 123957] [client 196.12.128.158:52045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_HgAAACc"]
[Tue Aug 18 13:00:45.821676 2026] [security2:error] [pid 123784:tid 124037] [client 158.23.17.4:7216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_HwAAAHc"]
[Tue Aug 18 13:00:45.829024 2026] [security2:error] [pid 123784:tid 123994] [client 20.250.27.191:40154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_IAAAAEw"]
[Tue Aug 18 13:00:45.844688 2026] [security2:error] [pid 123784:tid 123859] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/vr.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_IQAAC0Y"]
[Tue Aug 18 13:00:45.846555 2026] [security2:error] [pid 123784:tid 123923] [client 52.173.121.69:48403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/qfvqu.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_IgAAAAU"]
[Tue Aug 18 13:00:45.859940 2026] [security2:error] [pid 123784:tid 123968] [client 20.226.36.136:53509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_JAAAADI"]
[Tue Aug 18 13:00:45.861578 2026] [security2:error] [pid 123784:tid 123987] [client 172.202.39.151:4434] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.eezy.site"] [uri "/1.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_JQAAAEU"]
[Tue Aug 18 13:00:45.861677 2026] [security2:error] [pid 123784:tid 123987] [client 172.202.39.151:4434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/1.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_JQAAAEU"]
[Tue Aug 18 13:00:45.884175 2026] [security2:error] [pid 123784:tid 123934] [client 158.23.17.4:33991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ah.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_MwAAABA"]
[Tue Aug 18 13:00:45.886702 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:45.886969 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:45.893750 2026] [security2:error] [pid 123784:tid 124025] [client 20.226.36.136:61469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_OgAAAGs"]
[Tue Aug 18 13:00:45.903552 2026] [security2:error] [pid 123784:tid 124030] [client 20.91.215.254:18119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-configs.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_PAAAAHA"]
[Tue Aug 18 13:00:45.913929 2026] [security2:error] [pid 123784:tid 123924] [client 197.184.64.235:41959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_QAAAAAY"]
[Tue Aug 18 13:00:45.914047 2026] [security2:error] [pid 123784:tid 123924] [client 197.184.64.235:41959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_QAAAAAY"]
[Tue Aug 18 13:00:45.935996 2026] [security2:error] [pid 123784:tid 123937] [client 20.226.36.136:65316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_RAAAABM"]
[Tue Aug 18 13:00:45.937395 2026] [security2:error] [pid 123784:tid 123959] [client 158.23.17.4:58373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/loading.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_RQAAACk"]
[Tue Aug 18 13:00:45.938195 2026] [security2:error] [pid 123784:tid 123898] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_RgAALm0"]
[Tue Aug 18 13:00:45.942783 2026] [security2:error] [pid 123784:tid 123960] [client 213.35.127.232:63357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_RwAAACo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:45.986446 2026] [security2:error] [pid 123784:tid 123997] [client 168.62.48.100:5620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_SQAAAE8"]
[Tue Aug 18 13:00:46.001900 2026] [security2:error] [pid 123784:tid 124027] [client 20.226.36.136:52641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_SgAAAG0"]
[Tue Aug 18 13:00:46.007136 2026] [security2:error] [pid 123784:tid 123985] [client 20.75.92.165:4336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/w.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_TAAAAEM"]
[Tue Aug 18 13:00:46.013489 2026] [security2:error] [pid 123784:tid 123982] [client 20.100.169.31:19803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_TQAAAEA"]
[Tue Aug 18 13:00:46.034473 2026] [security2:error] [pid 123784:tid 124039] [client 20.102.65.165:8313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_TgAAAHk"]
[Tue Aug 18 13:00:46.044438 2026] [security2:error] [pid 123784:tid 123979] [client 20.65.98.162:56477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/blurbs.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_UQAAAD0"]
[Tue Aug 18 13:00:46.063457 2026] [security2:error] [pid 123784:tid 124000] [client 20.151.109.219:24411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ns.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_UwAAAFI"]
[Tue Aug 18 13:00:46.084051 2026] [security2:error] [pid 123784:tid 124042] [client 20.79.204.6:14119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/file61.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_VQAAAHw"]
[Tue Aug 18 13:00:46.106522 2026] [security2:error] [pid 123784:tid 124045] [client 135.225.78.186:21801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/ajax.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_WAAAAH8"]
[Tue Aug 18 13:00:46.107537 2026] [security2:error] [pid 123784:tid 124018] [client 20.226.36.136:61486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_WQAAAGQ"]
[Tue Aug 18 13:00:46.109421 2026] [security2:error] [pid 123784:tid 123990] [client 20.127.136.245:28087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/96i.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_WgAAAEg"]
[Tue Aug 18 13:00:46.127519 2026] [security2:error] [pid 123784:tid 123905] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_WwAADnQ"]
[Tue Aug 18 13:00:46.128685 2026] [security2:error] [pid 123784:tid 124011] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/k.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_XAAAAF0"]
[Tue Aug 18 13:00:46.137603 2026] [security2:error] [pid 123784:tid 124003] [client 20.79.204.6:2211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_XQAAAFU"]
[Tue Aug 18 13:00:46.144843 2026] [security2:error] [pid 123784:tid 123970] [client 20.100.169.31:24218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/file.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_XgAAADQ"]
[Tue Aug 18 13:00:46.159125 2026] [security2:error] [pid 123784:tid 123991] [client 20.79.204.6:10748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/xleet.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_YAAAAEk"]
[Tue Aug 18 13:00:46.195008 2026] [authz_core:error] [pid 123784:tid 123789] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:46.195589 2026] [authz_core:error] [pid 123784:tid 123789] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:46.204336 2026] [security2:error] [pid 123784:tid 124002] [client 158.23.17.4:29474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ts.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_cgAAAFQ"]
[Tue Aug 18 13:00:46.223064 2026] [security2:error] [pid 123784:tid 124008] [client 68.221.73.131:29580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/scxy.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_cwAAAFo"]
[Tue Aug 18 13:00:46.230307 2026] [security2:error] [pid 123784:tid 123975] [client 20.104.100.201:61992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_dAAAADk"]
[Tue Aug 18 13:00:46.255056 2026] [security2:error] [pid 123784:tid 123969] [client 4.232.94.69:14480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/akcc.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_dwAAADM"]
[Tue Aug 18 13:00:46.292687 2026] [security2:error] [pid 123784:tid 123993] [client 158.158.74.177:17295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/u.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_lQAAAEs"]
[Tue Aug 18 13:00:46.329924 2026] [security2:error] [pid 123784:tid 123872] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/ok.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_nQAAKVM"]
[Tue Aug 18 13:00:46.343049 2026] [security2:error] [pid 123784:tid 124014] [client 20.226.36.136:53511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_ngAAAGA"]
[Tue Aug 18 13:00:46.345970 2026] [security2:error] [pid 123784:tid 123978] [client 20.250.13.23:23721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_nwAAADw"]
[Tue Aug 18 13:00:46.375097 2026] [security2:error] [pid 123784:tid 123946] [client 20.75.92.165:4343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/file.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_owAAABw"]
[Tue Aug 18 13:00:46.379932 2026] [security2:error] [pid 123784:tid 123925] [client 20.65.98.162:45615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/bajah.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_pAAAAAc"]
[Tue Aug 18 13:00:46.391993 2026] [security2:error] [pid 123784:tid 123985] [client 20.250.27.191:63183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/media.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_pQAAAEM"]
[Tue Aug 18 13:00:46.403159 2026] [security2:error] [pid 123784:tid 123996] [client 20.102.65.165:8266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_pgAAAE4"]
[Tue Aug 18 13:00:46.472915 2026] [security2:error] [pid 123784:tid 123962] [client 158.23.17.4:34164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/vw.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_vQAAACw"]
[Tue Aug 18 13:00:46.489141 2026] [security2:error] [pid 123784:tid 124015] [client 158.23.17.4:17548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ke.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_0QAAAGE"]
[Tue Aug 18 13:00:46.503127 2026] [security2:error] [pid 123784:tid 124045] [client 172.202.39.151:4419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content/x/index.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_1gAAAH8"]
[Tue Aug 18 13:00:46.504358 2026] [security2:error] [pid 123784:tid 123848] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/item.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_1wAASDs"]
[Tue Aug 18 13:00:46.533132 2026] [security2:error] [pid 123784:tid 123992] [client 52.141.58.175:9689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/txets.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_2gAAAEo"]
[Tue Aug 18 13:00:46.534402 2026] [security2:error] [pid 123784:tid 124036] [client 20.151.109.219:39309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/gk.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_2wAAAHY"]
[Tue Aug 18 13:00:46.541996 2026] [security2:error] [pid 123784:tid 124011] [client 20.104.100.201:61954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/dk.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_3AAAAF0"]
[Tue Aug 18 13:00:46.546706 2026] [security2:error] [pid 123784:tid 123964] [client 20.91.215.254:27411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-post.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_3QAAAC4"]
[Tue Aug 18 13:00:46.554740 2026] [security2:error] [pid 123784:tid 124043] [client 20.226.56.190:47146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/fresh.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_3wAAAH0"]
[Tue Aug 18 13:00:46.565797 2026] [security2:error] [pid 123784:tid 123970] [client 20.226.36.136:61455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/update/wpupex.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_4AAAADQ"]
[Tue Aug 18 13:00:46.592071 2026] [security2:error] [pid 123784:tid 123980] [client 20.102.65.165:8204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_4gAAAD4"]
[Tue Aug 18 13:00:46.592106 2026] [security2:error] [pid 123784:tid 123991] [client 158.23.17.4:14049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/fs.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_4QAAAEk"]
[Tue Aug 18 13:00:46.595584 2026] [security2:error] [pid 123784:tid 123942] [client 20.127.136.245:27871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/as.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_4wAAABg"]
[Tue Aug 18 13:00:46.628418 2026] [security2:error] [pid 123784:tid 123995] [client 79.127.164.8:33074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/www.sql"] [unique_id "aoSBrmwDnJBNj2tDbYb_5AAAAE0"], referer: https://medihub.com.br/www.sql
[Tue Aug 18 13:00:46.633896 2026] [security2:error] [pid 123784:tid 124021] [client 20.226.36.136:62161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-admin/install.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_5QAAAGc"]
[Tue Aug 18 13:00:46.639539 2026] [security2:error] [pid 123784:tid 123982] [client 20.100.169.31:19788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_5gAAAEA"]
[Tue Aug 18 13:00:46.643356 2026] [security2:error] [pid 123784:tid 124002] [client 20.75.92.165:4255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_6AAAAFQ"]
[Tue Aug 18 13:00:46.706694 2026] [security2:error] [pid 123784:tid 123923] [client 52.173.121.69:15022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/oivcl.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_6wAAAAU"]
[Tue Aug 18 13:00:46.717359 2026] [security2:error] [pid 123784:tid 123969] [client 68.221.73.131:13815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_7AAAADM"]
[Tue Aug 18 13:00:46.732297 2026] [security2:error] [pid 123784:tid 123987] [client 20.48.236.86:14504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_7QAAAEU"]
[Tue Aug 18 13:00:46.749799 2026] [security2:error] [pid 123784:tid 124025] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_8QAAAGs"]
[Tue Aug 18 13:00:46.757927 2026] [security2:error] [pid 123784:tid 124007] [client 20.79.204.6:2383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/htaccess.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_8gAAAFk"]
[Tue Aug 18 13:00:46.762581 2026] [security2:error] [pid 123784:tid 123993] [client 20.65.98.162:56511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/h.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_9AAAAEs"]
[Tue Aug 18 13:00:46.766059 2026] [security2:error] [pid 123784:tid 123920] [client 20.100.169.31:4653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/goods.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_9QAAAAI"]
[Tue Aug 18 13:00:46.809463 2026] [security2:error] [pid 123784:tid 123937] [client 172.202.39.151:44139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/aa.php"] [unique_id "aoSBrmwDnJBNj2tDbYYABAAAABM"]
[Tue Aug 18 13:00:46.842292 2026] [security2:error] [pid 123784:tid 124014] [client 20.226.36.136:65332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBrmwDnJBNj2tDbYYACQAAAGA"]
[Tue Aug 18 13:00:46.890860 2026] [security2:error] [pid 123784:tid 123869] [remote 136.110.27.48:47426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "_dc-mx.5306886f3ecd.brazriosimoveis.com.br"] [uri "/.env"] [unique_id "aoSBrmwDnJBNj2tDbYYADgAAdFA"]
[Tue Aug 18 13:00:46.912234 2026] [security2:error] [pid 123784:tid 123949] [client 20.104.100.201:61976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/bal.php"] [unique_id "aoSBrmwDnJBNj2tDbYYAFwAAAB8"]
[Tue Aug 18 13:00:46.912310 2026] [security2:error] [pid 123784:tid 123919] [client 20.75.92.165:4342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/aa.php"] [unique_id "aoSBrmwDnJBNj2tDbYYAGAAAAAE"]
[Tue Aug 18 13:00:46.924962 2026] [security2:error] [pid 123784:tid 124010] [client 20.102.65.165:8264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBrmwDnJBNj2tDbYYAGQAAAFw"]
[Tue Aug 18 13:00:46.957616 2026] [security2:error] [pid 123784:tid 123981] [client 213.35.127.232:63573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBrmwDnJBNj2tDbYYAHwAAAD8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:46.962059 2026] [security2:error] [pid 123784:tid 124006] [client 20.79.204.6:14054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/license.php"] [unique_id "aoSBrmwDnJBNj2tDbYYAIAAAAFg"]
[Tue Aug 18 13:00:46.975214 2026] [security2:error] [pid 123784:tid 124024] [client 158.158.74.177:17337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/updates.php"] [unique_id "aoSBrmwDnJBNj2tDbYYAIQAAAGo"]
[Tue Aug 18 13:00:46.982961 2026] [security2:error] [pid 123784:tid 123971] [client 158.23.17.4:2037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/lj.php"] [unique_id "aoSBrmwDnJBNj2tDbYYAJgAAADU"]
[Tue Aug 18 13:00:46.990849 2026] [security2:error] [pid 123784:tid 124012] [client 20.250.13.23:23726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSBrmwDnJBNj2tDbYYAKgAAAF4"]
[Tue Aug 18 13:00:47.010220 2026] [security2:error] [pid 123784:tid 123952] [client 20.250.27.191:45763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/inso.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAKwAAACI"]
[Tue Aug 18 13:00:47.070033 2026] [security2:error] [pid 123784:tid 124011] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/system_log.php"] [unique_id "aoSBr2wDnJBNj2tDbYYALgAAAF0"]
[Tue Aug 18 13:00:47.082160 2026] [security2:error] [pid 123784:tid 123964] [client 20.151.109.219:14142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/wn.php"] [unique_id "aoSBr2wDnJBNj2tDbYYALwAAAC4"]
[Tue Aug 18 13:00:47.124054 2026] [security2:error] [pid 123784:tid 124015] [client 20.127.136.245:27844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/min.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAMQAAAGE"]
[Tue Aug 18 13:00:47.139447 2026] [security2:error] [pid 123784:tid 123997] [client 4.232.94.69:29667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/BIBIL_0DAY.php/global.php"] [unique_id "aoSBr2wDnJBNj2tDbYYANAAAAE8"]
[Tue Aug 18 13:00:47.153597 2026] [security2:error] [pid 123784:tid 123980] [client 20.48.236.86:14489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBr2wDnJBNj2tDbYYANQAAAD4"]
[Tue Aug 18 13:00:47.193077 2026] [security2:error] [pid 123784:tid 123929] [client 20.79.204.6:10751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAOAAAAAs"]
[Tue Aug 18 13:00:47.196453 2026] [security2:error] [pid 123784:tid 123943] [client 20.75.92.165:4255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAOQAAABk"]
[Tue Aug 18 13:00:47.235550 2026] [security2:error] [pid 123784:tid 124001] [client 20.91.215.254:27395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp/images/my.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAOwAAAFM"]
[Tue Aug 18 13:00:47.254949 2026] [security2:error] [pid 123784:tid 123994] [client 20.102.65.165:8286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/media.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAPwAAAEw"]
[Tue Aug 18 13:00:47.274628 2026] [security2:error] [pid 123784:tid 123961] [client 20.127.136.245:5583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAQgAAACs"]
[Tue Aug 18 13:00:47.303928 2026] [security2:error] [pid 123784:tid 123941] [client 20.104.100.201:34254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/yawa.php"] [unique_id "aoSBr2wDnJBNj2tDbYYARAAAABc"]
[Tue Aug 18 13:00:47.309677 2026] [security2:error] [pid 123784:tid 123987] [client 20.65.98.162:55206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/ano.php"] [unique_id "aoSBr2wDnJBNj2tDbYYARQAAAEU"]
[Tue Aug 18 13:00:47.318534 2026] [security2:error] [pid 123784:tid 123950] [client 158.23.17.4:44482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/53.php"] [unique_id "aoSBr2wDnJBNj2tDbYYARgAAACA"]
[Tue Aug 18 13:00:47.327949 2026] [security2:error] [pid 123784:tid 123965] [client 20.226.36.136:62196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBr2wDnJBNj2tDbYYARwAAAC8"]
[Tue Aug 18 13:00:47.340456 2026] [security2:error] [pid 123784:tid 124030] [client 68.221.73.131:18801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBr2wDnJBNj2tDbYYASQAAAHA"]
[Tue Aug 18 13:00:47.360978 2026] [security2:error] [pid 123784:tid 123955] [client 20.79.204.6:2375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/images/wso.php"] [unique_id "aoSBr2wDnJBNj2tDbYYATAAAACU"]
[Tue Aug 18 13:00:47.393146 2026] [security2:error] [pid 123784:tid 123993] [client 158.23.17.4:34041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/kh.php"] [unique_id "aoSBr2wDnJBNj2tDbYYATgAAAEs"]
[Tue Aug 18 13:00:47.393911 2026] [authz_core:error] [pid 123784:tid 123907] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:47.394152 2026] [authz_core:error] [pid 123784:tid 123907] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:47.394407 2026] [security2:error] [pid 123784:tid 123995] [client 20.100.169.31:4959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAUAAAAE0"]
[Tue Aug 18 13:00:47.395018 2026] [security2:error] [pid 123784:tid 123920] [client 172.202.39.151:44509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAUQAAAAI"]
[Tue Aug 18 13:00:47.467079 2026] [security2:error] [pid 123784:tid 123967] [client 158.23.17.4:54732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/nh.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAVAAAADE"]
[Tue Aug 18 13:00:47.476642 2026] [security2:error] [pid 123784:tid 123946] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/x.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAVgAAABw"]
[Tue Aug 18 13:00:47.479455 2026] [security2:error] [pid 123784:tid 124027] [client 20.48.236.86:14501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/img.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAVwAAAG0"]
[Tue Aug 18 13:00:47.481399 2026] [security2:error] [pid 123784:tid 123925] [client 20.226.36.136:61450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAWAAAAAc"]
[Tue Aug 18 13:00:47.486548 2026] [security2:error] [pid 123784:tid 123996] [client 20.75.92.165:4322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/about.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAWwAAAE4"]
[Tue Aug 18 13:00:47.564869 2026] [security2:error] [pid 123784:tid 123981] [client 20.226.56.190:20387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/admin404.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAXgAAAD8"]
[Tue Aug 18 13:00:47.603272 2026] [security2:error] [pid 123784:tid 123957] [client 52.141.58.175:4161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/ty.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAYQAAACc"]
[Tue Aug 18 13:00:47.603644 2026] [security2:error] [pid 123784:tid 123924] [client 158.158.74.177:23692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/upload/autoload_classmap.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAYgAAAAY"]
[Tue Aug 18 13:00:47.619507 2026] [security2:error] [pid 123784:tid 124012] [client 20.250.27.191:27992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/shiny.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAYwAAAF4"]
[Tue Aug 18 13:00:47.621052 2026] [security2:error] [pid 123784:tid 124042] [client 20.104.100.201:34265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAZAAAAHw"]
[Tue Aug 18 13:00:47.624572 2026] [security2:error] [pid 123784:tid 123945] [client 20.226.36.136:52663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/well-known/index.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAZgAAABs"]
[Tue Aug 18 13:00:47.664238 2026] [security2:error] [pid 123784:tid 123918] [client 20.250.13.23:23685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/goat.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAaAAAAAA"]
[Tue Aug 18 13:00:47.685176 2026] [security2:error] [pid 123784:tid 123983] [client 20.100.169.31:3713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAawAAAEE"]
[Tue Aug 18 13:00:47.693642 2026] [security2:error] [pid 123784:tid 123921] [client 20.102.65.165:8303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/admin.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAbAAAAAM"]
[Tue Aug 18 13:00:47.705785 2026] [authz_core:error] [pid 123784:tid 123822] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:47.706024 2026] [authz_core:error] [pid 123784:tid 123822] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:47.714840 2026] [security2:error] [pid 123784:tid 123939] [client 20.226.36.136:53540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAdgAAABU"]
[Tue Aug 18 13:00:47.717003 2026] [security2:error] [pid 123784:tid 124039] [client 20.151.109.219:60376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/app.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAdwAAAHk"]
[Tue Aug 18 13:00:47.739134 2026] [security2:error] [pid 123784:tid 124026] [client 20.75.92.165:4339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/goods.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAeAAAAGw"]
[Tue Aug 18 13:00:47.773474 2026] [security2:error] [pid 123784:tid 123929] [client 52.173.121.69:61922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/zugvi.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAegAAAAs"]
[Tue Aug 18 13:00:47.781671 2026] [security2:error] [pid 123784:tid 124038] [client 20.127.136.245:28043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/php8.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAewAAAHg"]
[Tue Aug 18 13:00:47.825622 2026] [security2:error] [pid 123784:tid 123935] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAfQAAABE"]
[Tue Aug 18 13:00:47.844680 2026] [security2:error] [pid 123784:tid 123883] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAgQAAR14"]
[Tue Aug 18 13:00:47.844825 2026] [security2:error] [pid 123784:tid 123989] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAgQAAR14"]
[Tue Aug 18 13:00:47.859034 2026] [security2:error] [pid 123784:tid 123975] [client 158.23.17.4:44801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/jb.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAgwAAADk"]
[Tue Aug 18 13:00:47.885119 2026] [security2:error] [pid 123784:tid 124009] [client 20.226.36.136:65321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAhAAAAFs"]
[Tue Aug 18 13:00:47.952607 2026] [security2:error] [pid 123784:tid 123997] [client 20.91.215.254:27428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/function.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAhgAAAE8"]
[Tue Aug 18 13:00:47.962374 2026] [security2:error] [pid 123784:tid 123949] [client 86.120.159.145:50666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAhwAAAB8"]
[Tue Aug 18 13:00:47.962511 2026] [security2:error] [pid 123784:tid 123949] [client 86.120.159.145:50666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAhwAAAB8"]
[Tue Aug 18 13:00:47.971628 2026] [security2:error] [pid 123784:tid 124016] [client 213.35.127.232:63774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAiAAAAGI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:47.986603 2026] [security2:error] [pid 123784:tid 124029] [client 20.79.204.6:2636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/index/function.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAiQAAAG8"]
[Tue Aug 18 13:00:47.987483 2026] [security2:error] [pid 123784:tid 124028] [client 20.38.3.247:60706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/adminner.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAigAAAG4"]
[Tue Aug 18 13:00:47.988712 2026] [security2:error] [pid 123784:tid 123958] [client 20.75.92.165:4228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/php8.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAiwAAACg"]
[Tue Aug 18 13:00:48.002126 2026] [security2:error] [pid 123784:tid 123993] [client 20.104.100.201:61420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/7.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAjAAAAEs"]
[Tue Aug 18 13:00:48.005437 2026] [security2:error] [pid 123784:tid 123995] [client 158.23.17.4:8419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/oo.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAjQAAAE0"]
[Tue Aug 18 13:00:48.017577 2026] [security2:error] [pid 123784:tid 124032] [client 68.221.73.131:45975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/blurbs.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAjgAAAHI"]
[Tue Aug 18 13:00:48.028761 2026] [security2:error] [pid 123784:tid 124023] [client 168.62.48.100:5616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAjwAAAGk"]
[Tue Aug 18 13:00:48.041090 2026] [security2:error] [pid 123784:tid 123959] [client 20.226.36.136:61468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAkgAAACk"]
[Tue Aug 18 13:00:48.041232 2026] [security2:error] [pid 123784:tid 124001] [client 20.100.169.31:4930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/htaccess.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAkwAAAFM"]
[Tue Aug 18 13:00:48.055582 2026] [security2:error] [pid 123784:tid 123946] [client 20.102.65.165:8270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/mac.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAlQAAABw"]
[Tue Aug 18 13:00:48.071688 2026] [security2:error] [pid 123784:tid 124027] [client 20.226.36.136:65287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/mt/byp.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAlwAAAG0"]
[Tue Aug 18 13:00:48.097907 2026] [security2:error] [pid 123784:tid 123996] [client 20.48.236.86:14499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/aa.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAmQAAAE4"]
[Tue Aug 18 13:00:48.105096 2026] [security2:error] [pid 123784:tid 123985] [client 20.226.36.136:65304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/MTOS/byp.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAmgAAAEM"]
[Tue Aug 18 13:00:48.109698 2026] [security2:error] [pid 123784:tid 123936] [client 20.65.98.162:56464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/ai.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAnAAAABI"]
[Tue Aug 18 13:00:48.110182 2026] [security2:error] [pid 123784:tid 123969] [client 172.202.39.151:4697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content/index.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAnQAAADM"]
[Tue Aug 18 13:00:48.176381 2026] [security2:error] [pid 123784:tid 123962] [client 20.226.36.136:52647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAnwAAACw"]
[Tue Aug 18 13:00:48.216984 2026] [security2:error] [pid 123784:tid 123940] [client 20.79.204.6:10394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/155.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAogAAABY"]
[Tue Aug 18 13:00:48.255242 2026] [security2:error] [pid 123784:tid 124042] [client 20.151.109.219:14123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/87.php"] [unique_id "aoSBsGwDnJBNj2tDbYYApAAAAHw"]
[Tue Aug 18 13:00:48.266936 2026] [security2:error] [pid 123784:tid 123918] [client 20.75.92.165:2003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/info.php"] [unique_id "aoSBsGwDnJBNj2tDbYYApQAAAAA"]
[Tue Aug 18 13:00:48.270437 2026] [security2:error] [pid 123784:tid 123972] [client 158.158.74.177:5097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/uploads/admin.php"] [unique_id "aoSBsGwDnJBNj2tDbYYApgAAADY"]
[Tue Aug 18 13:00:48.294188 2026] [security2:error] [pid 123784:tid 123932] [client 158.23.17.4:57265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/do.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAqAAAAA4"]
[Tue Aug 18 13:00:48.298787 2026] [authz_core:error] [pid 123784:tid 123815] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:48.299235 2026] [authz_core:error] [pid 123784:tid 123815] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:48.313830 2026] [security2:error] [pid 123784:tid 124034] [client 20.250.13.23:23719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/Session.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAqgAAAHQ"]
[Tue Aug 18 13:00:48.319212 2026] [security2:error] [pid 123784:tid 124011] [client 20.250.27.191:63200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/403dd.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAqwAAAF0"]
[Tue Aug 18 13:00:48.337367 2026] [security2:error] [pid 123784:tid 124014] [client 20.127.136.245:28052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/admin.php"] [unique_id "aoSBsGwDnJBNj2tDbYYArQAAAGA"]
[Tue Aug 18 13:00:48.341430 2026] [security2:error] [pid 123784:tid 124015] [client 20.104.100.201:61962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/ws77.php"] [unique_id "aoSBsGwDnJBNj2tDbYYArgAAAGE"]
[Tue Aug 18 13:00:48.365730 2026] [security2:error] [pid 123784:tid 123939] [client 20.226.36.136:52626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBsGwDnJBNj2tDbYYArwAAABU"]
[Tue Aug 18 13:00:48.380923 2026] [security2:error] [pid 123784:tid 124039] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/hosty.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAsAAAAHk"]
[Tue Aug 18 13:00:48.387435 2026] [security2:error] [pid 123784:tid 124026] [client 20.206.73.37:35303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/admin.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAsQAAAGw"]
[Tue Aug 18 13:00:48.416490 2026] [security2:error] [pid 123784:tid 123929] [client 158.23.17.4:9394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/lq.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAtAAAAAs"]
[Tue Aug 18 13:00:48.425617 2026] [security2:error] [pid 123784:tid 123934] [client 20.102.65.165:8240] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/1.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAtQAAABA"]
[Tue Aug 18 13:00:48.425710 2026] [security2:error] [pid 123784:tid 123934] [client 20.102.65.165:8240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/1.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAtQAAABA"]
[Tue Aug 18 13:00:48.444781 2026] [security2:error] [pid 123784:tid 123953] [client 172.202.39.151:53747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/0x.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAtgAAACM"]
[Tue Aug 18 13:00:48.447555 2026] [security2:error] [pid 123784:tid 124035] [client 4.232.94.69:39257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/updates.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAuAAAAHU"]
[Tue Aug 18 13:00:48.471735 2026] [security2:error] [pid 123784:tid 124044] [client 20.65.98.162:2181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/inso.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAuQAAAH4"]
[Tue Aug 18 13:00:48.533998 2026] [security2:error] [pid 123784:tid 123923] [client 20.100.169.31:19814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAuwAAAAU"]
[Tue Aug 18 13:00:48.549603 2026] [security2:error] [pid 123784:tid 123987] [client 158.23.17.4:51184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ja.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAvAAAAEU"]
[Tue Aug 18 13:00:48.591220 2026] [security2:error] [pid 123784:tid 124041] [client 20.79.204.6:2215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/info.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAwAAAAHs"]
[Tue Aug 18 13:00:48.594623 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:48.594891 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:48.600054 2026] [security2:error] [pid 123784:tid 123980] [client 20.91.215.254:12008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-2019.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAwgAAAD4"]
[Tue Aug 18 13:00:48.617111 2026] [security2:error] [pid 123784:tid 123949] [client 20.151.109.219:14313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/zi.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAwwAAAB8"]
[Tue Aug 18 13:00:48.623608 2026] [security2:error] [pid 123784:tid 124016] [client 20.48.236.86:14789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/av.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAxAAAAGI"]
[Tue Aug 18 13:00:48.634349 2026] [security2:error] [pid 123784:tid 123958] [client 20.104.100.201:61975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/read.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAxgAAACg"]
[Tue Aug 18 13:00:48.634357 2026] [security2:error] [pid 123784:tid 124028] [client 20.75.92.165:4305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/chosen.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAxQAAAG4"]
[Tue Aug 18 13:00:48.663417 2026] [security2:error] [pid 123784:tid 123983] [client 52.141.58.175:4183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/u.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAyAAAAEE"]
[Tue Aug 18 13:00:48.687240 2026] [security2:error] [pid 123784:tid 123959] [client 20.102.65.165:8259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/coffee.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAzAAAACk"]
[Tue Aug 18 13:00:48.704188 2026] [security2:error] [pid 123784:tid 123978] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/test1.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAzwAAADw"]
[Tue Aug 18 13:00:48.705762 2026] [security2:error] [pid 123784:tid 123988] [client 158.23.17.4:20172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/yw.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA0AAAAEY"]
[Tue Aug 18 13:00:48.706443 2026] [security2:error] [pid 123784:tid 124008] [client 20.100.169.31:4743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/images/wso.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA0QAAAFo"]
[Tue Aug 18 13:00:48.719477 2026] [security2:error] [pid 123784:tid 123967] [client 172.202.39.151:61651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-good.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA0wAAADE"]
[Tue Aug 18 13:00:48.738313 2026] [security2:error] [pid 123784:tid 123938] [client 20.118.133.132:14467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/sf.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA1AAAABQ"]
[Tue Aug 18 13:00:48.776382 2026] [security2:error] [pid 123784:tid 124009] [client 5.161.61.238:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "yycc.com.br"] [uri "/index.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAxwAAW1Q"], referer: https://yycc.com.br/
[Tue Aug 18 13:00:48.821926 2026] [security2:error] [pid 123784:tid 123956] [client 114.119.131.123:63541] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ceussmedicina.com.br"] [uri "/zwdt/xzdt/202205/t20220531_1655934.html"] [unique_id "aoSBsGwDnJBNj2tDbYYA2AAAACY"], referer: https://ceussmedicina.com.br/zwdt/xzdt/202205/t20220531_1655934.html
[Tue Aug 18 13:00:48.822941 2026] [security2:error] [pid 123784:tid 124000] [client 20.250.27.191:28010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/baba.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA2QAAAFI"]
[Tue Aug 18 13:00:48.878087 2026] [security2:error] [pid 123784:tid 123926] [client 192.141.172.134:58832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA3AAAAAg"]
[Tue Aug 18 13:00:48.878204 2026] [security2:error] [pid 123784:tid 123926] [client 192.141.172.134:58832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA3AAAAAg"]
[Tue Aug 18 13:00:48.880104 2026] [security2:error] [pid 123784:tid 123946] [client 20.127.136.245:27867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/222.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA3QAAABw"]
[Tue Aug 18 13:00:48.884567 2026] [security2:error] [pid 123784:tid 124012] [client 20.75.92.165:4246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/simple.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA3gAAAF4"]
[Tue Aug 18 13:00:48.901283 2026] [authz_core:error] [pid 123784:tid 123792] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:48.901704 2026] [authz_core:error] [pid 123784:tid 123792] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:48.918796 2026] [security2:error] [pid 123784:tid 123992] [client 20.65.98.162:45598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/w1px.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA4wAAAEo"]
[Tue Aug 18 13:00:48.920034 2026] [security2:error] [pid 123784:tid 123972] [client 20.226.56.190:17857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/loading.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA5AAAADY"]
[Tue Aug 18 13:00:48.932677 2026] [security2:error] [pid 123784:tid 124027] [client 20.250.13.23:23730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA5gAAAG0"]
[Tue Aug 18 13:00:48.948503 2026] [security2:error] [pid 123784:tid 124011] [client 20.226.36.136:61467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA6QAAAF0"]
[Tue Aug 18 13:00:48.950165 2026] [security2:error] [pid 123784:tid 124010] [client 20.102.65.165:8192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA6gAAAFw"]
[Tue Aug 18 13:00:48.969775 2026] [security2:error] [pid 123784:tid 124014] [client 158.23.17.4:9374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/you.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA6wAAAGA"]
[Tue Aug 18 13:00:48.972415 2026] [security2:error] [pid 123784:tid 124015] [client 20.104.100.201:34259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/albin.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA7AAAAGE"]
[Tue Aug 18 13:00:48.985661 2026] [security2:error] [pid 123784:tid 123993] [client 213.35.127.232:63948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA7QAAAEs"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:49.058789 2026] [security2:error] [pid 123784:tid 123982] [client 20.151.109.219:24404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/92.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA7wAAAEA"]
[Tue Aug 18 13:00:49.074334 2026] [security2:error] [pid 123784:tid 123935] [client 20.48.236.86:14495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/media.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA8QAAABE"]
[Tue Aug 18 13:00:49.077329 2026] [security2:error] [pid 123784:tid 124044] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/zwso.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA8gAAAH4"]
[Tue Aug 18 13:00:49.124073 2026] [security2:error] [pid 123784:tid 124017] [client 20.226.36.136:62146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA8wAAAGM"]
[Tue Aug 18 13:00:49.150518 2026] [security2:error] [pid 123784:tid 123975] [client 20.226.36.136:61462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA9QAAADk"]
[Tue Aug 18 13:00:49.167950 2026] [security2:error] [pid 123784:tid 123923] [client 20.75.92.165:4295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA9gAAAAU"]
[Tue Aug 18 13:00:49.172514 2026] [security2:error] [pid 123784:tid 124005] [client 20.226.36.136:61485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA9wAAAFc"]
[Tue Aug 18 13:00:49.178217 2026] [security2:error] [pid 123784:tid 123964] [client 20.100.169.31:38661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA-AAAAC4"]
[Tue Aug 18 13:00:49.184013 2026] [security2:error] [pid 123784:tid 123976] [client 158.23.17.4:40400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/rb.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA-QAAADo"]
[Tue Aug 18 13:00:49.201535 2026] [authz_core:error] [pid 123784:tid 123810] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:49.201956 2026] [authz_core:error] [pid 123784:tid 123810] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:49.210175 2026] [security2:error] [pid 123784:tid 124041] [client 20.226.36.136:53522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/first.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA_AAAAHs"]
[Tue Aug 18 13:00:49.229522 2026] [security2:error] [pid 123784:tid 124026] [client 20.79.204.6:2192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/profile.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA_gAAAGw"]
[Tue Aug 18 13:00:49.257627 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.36.136:62174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA_wAAAH8"]
[Tue Aug 18 13:00:49.274511 2026] [security2:error] [pid 123784:tid 124029] [client 20.104.100.201:34295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/fw/34.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBAAAAAG8"]
[Tue Aug 18 13:00:49.279078 2026] [security2:error] [pid 123784:tid 123958] [client 172.202.39.151:4245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/as.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBAgAAACg"]
[Tue Aug 18 13:00:49.319583 2026] [security2:error] [pid 123784:tid 124035] [client 20.91.215.254:11912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/cjfuns.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBBQAAAHU"]
[Tue Aug 18 13:00:49.327022 2026] [security2:error] [pid 123784:tid 124008] [client 20.250.27.191:64293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/site.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBBgAAAFo"]
[Tue Aug 18 13:00:49.344274 2026] [security2:error] [pid 123784:tid 123961] [client 20.100.169.31:4437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/index/function.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBBwAAACs"]
[Tue Aug 18 13:00:49.361157 2026] [security2:error] [pid 123784:tid 123950] [client 20.226.36.136:52609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBCAAAACA"]
[Tue Aug 18 13:00:49.371222 2026] [security2:error] [pid 123784:tid 124022] [client 158.23.17.4:12534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/qh.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBCQAAAGg"]
[Tue Aug 18 13:00:49.413869 2026] [security2:error] [pid 123784:tid 123985] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/Geforce.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBCwAAAEM"]
[Tue Aug 18 13:00:49.417373 2026] [security2:error] [pid 123784:tid 123969] [client 20.102.65.165:8295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBDAAAADM"]
[Tue Aug 18 13:00:49.451937 2026] [security2:error] [pid 123784:tid 123987] [client 20.127.136.245:28528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBDQAAAEU"]
[Tue Aug 18 13:00:49.461098 2026] [security2:error] [pid 123784:tid 123948] [client 20.226.56.190:52047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/conn-test.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBDgAAAB4"]
[Tue Aug 18 13:00:49.463004 2026] [security2:error] [pid 123784:tid 123981] [client 158.23.17.4:47910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/xx.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBDwAAAD8"]
[Tue Aug 18 13:00:49.540101 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.36.136:62204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBEQAAAFI"]
[Tue Aug 18 13:00:49.571987 2026] [security2:error] [pid 123784:tid 123946] [client 20.75.92.165:4308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/av.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBFAAAABw"]
[Tue Aug 18 13:00:49.595877 2026] [security2:error] [pid 123784:tid 124019] [client 20.250.13.23:44050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/abcd.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBFgAAAGU"]
[Tue Aug 18 13:00:49.596662 2026] [security2:error] [pid 123784:tid 123979] [client 20.104.100.201:61383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp9.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBFwAAAD0"]
[Tue Aug 18 13:00:49.599349 2026] [security2:error] [pid 123784:tid 123918] [client 20.151.109.219:39322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/jm.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBGAAAAAA"]
[Tue Aug 18 13:00:49.637686 2026] [security2:error] [pid 123784:tid 123972] [client 20.65.98.162:37540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/zi-936.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBGQAAADY"]
[Tue Aug 18 13:00:49.650443 2026] [security2:error] [pid 123784:tid 123990] [client 20.79.204.6:10728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/96i.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBGgAAAEg"]
[Tue Aug 18 13:00:49.670986 2026] [security2:error] [pid 123784:tid 124010] [client 20.226.36.136:62148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/blog/byp.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBGwAAAFw"]
[Tue Aug 18 13:00:49.713626 2026] [security2:error] [pid 123784:tid 123977] [client 52.141.58.175:11668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/ultra.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBIQAAADs"]
[Tue Aug 18 13:00:49.725752 2026] [security2:error] [pid 123784:tid 123939] [client 68.221.73.131:13767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/bajah.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBIwAAABU"]
[Tue Aug 18 13:00:49.751687 2026] [security2:error] [pid 123784:tid 124004] [client 20.102.65.165:8292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/media.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBJwAAAFY"]
[Tue Aug 18 13:00:49.753951 2026] [security2:error] [pid 123784:tid 124037] [client 158.23.17.4:10995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ez.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBKQAAAHc"]
[Tue Aug 18 13:00:49.798219 2026] [security2:error] [pid 123784:tid 124032] [client 20.100.169.31:3764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBKwAAAHI"]
[Tue Aug 18 13:00:49.833358 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:49.833614 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:49.835854 2026] [security2:error] [pid 123784:tid 123992] [client 20.79.204.6:2231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/sx.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBLgAAAEo"]
[Tue Aug 18 13:00:49.842022 2026] [security2:error] [pid 123784:tid 123947] [client 20.226.36.136:65333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBLwAAAB0"]
[Tue Aug 18 13:00:49.844567 2026] [security2:error] [pid 123784:tid 124017] [client 20.102.65.165:8299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/yj09.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBMAAAAGM"]
[Tue Aug 18 13:00:49.893810 2026] [security2:error] [pid 123784:tid 123932] [client 20.104.100.201:61985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/save.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBMwAAAA4"]
[Tue Aug 18 13:00:49.924362 2026] [security2:error] [pid 123784:tid 123975] [client 158.23.17.4:20205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/r.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBNQAAADk"]
[Tue Aug 18 13:00:49.937758 2026] [security2:error] [pid 123784:tid 124027] [client 4.232.94.69:25510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/cnzcsfwm.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBNgAAAG0"]
[Tue Aug 18 13:00:49.949848 2026] [security2:error] [pid 123784:tid 123941] [client 20.48.236.86:14521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/images.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBOQAAABc"]
[Tue Aug 18 13:00:49.975029 2026] [security2:error] [pid 123784:tid 123942] [client 20.91.215.254:11986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBPAAAABg"]
[Tue Aug 18 13:00:49.975092 2026] [security2:error] [pid 123784:tid 124041] [client 158.23.17.4:54733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/conn-test.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBPQAAAHs"]
[Tue Aug 18 13:00:49.977087 2026] [security2:error] [pid 123784:tid 124038] [client 20.100.169.31:32509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/info.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBPgAAAHg"]
[Tue Aug 18 13:00:49.980068 2026] [security2:error] [pid 123784:tid 123980] [client 20.250.27.191:63224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBPwAAAD4"]
[Tue Aug 18 13:00:49.999450 2026] [security2:error] [pid 123784:tid 124011] [client 213.35.127.232:64153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBQAAAAF0"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:50.023997 2026] [security2:error] [pid 123784:tid 123955] [client 20.75.92.165:4319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBQQAAACU"]
[Tue Aug 18 13:00:50.156221 2026] [security2:error] [pid 123784:tid 123967] [client 20.102.65.165:8195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/admin.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBSgAAADE"]
[Tue Aug 18 13:00:50.172231 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:50.172666 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:50.208991 2026] [security2:error] [pid 123784:tid 123861] [remote 178.156.200.16:54988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.200.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agatrend.com.br"] [uri "/wp-login.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBTAAADUg"]
[Tue Aug 18 13:00:50.236478 2026] [security2:error] [pid 123784:tid 123996] [client 20.102.65.165:8205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/scxy.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBTgAAAE4"]
[Tue Aug 18 13:00:50.237405 2026] [security2:error] [pid 123784:tid 124026] [client 20.250.13.23:23714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/kj.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBTwAAAGw"]
[Tue Aug 18 13:00:50.305730 2026] [security2:error] [pid 123784:tid 123969] [client 20.75.92.165:4325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/file2.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBUwAAADM"]
[Tue Aug 18 13:00:50.312690 2026] [security2:error] [pid 123784:tid 123998] [client 20.151.109.219:14099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/wj.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBVAAAAFA"]
[Tue Aug 18 13:00:50.353107 2026] [security2:error] [pid 123784:tid 123960] [client 20.104.100.201:34248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBVgAAACo"]
[Tue Aug 18 13:00:50.365142 2026] [security2:error] [pid 123784:tid 123948] [client 20.65.98.162:41683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/dcsgumnm.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBVwAAAB4"]
[Tue Aug 18 13:00:50.408035 2026] [security2:error] [pid 123784:tid 123928] [client 20.250.13.23:7680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBWQAAAAo"]
[Tue Aug 18 13:00:50.433126 2026] [security2:error] [pid 123784:tid 124000] [client 158.23.17.4:34016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/17.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBWwAAAFI"]
[Tue Aug 18 13:00:50.437585 2026] [authz_core:error] [pid 123784:tid 123808] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:50.437869 2026] [authz_core:error] [pid 123784:tid 123808] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:50.445818 2026] [security2:error] [pid 123784:tid 123934] [client 20.127.136.245:27898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/info.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBXQAAABA"]
[Tue Aug 18 13:00:50.446050 2026] [security2:error] [pid 123784:tid 123973] [client 20.79.204.6:2188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBXAAAADc"]
[Tue Aug 18 13:00:50.471108 2026] [security2:error] [pid 123784:tid 124024] [client 172.202.39.151:61668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/tes.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBXwAAAGo"]
[Tue Aug 18 13:00:50.573959 2026] [security2:error] [pid 123784:tid 123946] [client 172.202.39.151:40938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/zxz.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBYQAAABw"]
[Tue Aug 18 13:00:50.633804 2026] [security2:error] [pid 123784:tid 123937] [client 20.102.65.165:8204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/mac.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBYgAAABM"]
[Tue Aug 18 13:00:50.766115 2026] [security2:error] [pid 123784:tid 123977] [client 20.75.92.165:4314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/images/class-config.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBZAAAADs"]
[Tue Aug 18 13:00:50.851616 2026] [security2:error] [pid 123784:tid 123939] [client 20.163.43.14:8943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBZgAAABU"]
[Tue Aug 18 13:00:50.865563 2026] [security2:error] [pid 123784:tid 124039] [client 20.151.109.219:60403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/74.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBbgAAAHk"]
[Tue Aug 18 13:00:50.907120 2026] [security2:error] [pid 123784:tid 124004] [client 20.102.65.165:8293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBbwAAAFY"]
[Tue Aug 18 13:00:50.923814 2026] [security2:error] [pid 123784:tid 123956] [client 103.120.71.157:50124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBcAAAACY"]
[Tue Aug 18 13:00:50.923918 2026] [security2:error] [pid 123784:tid 123956] [client 103.120.71.157:50124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBcAAAACY"]
[Tue Aug 18 13:00:50.930746 2026] [security2:error] [pid 123784:tid 123918] [client 20.250.13.23:35536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/languages.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBcQAAAAA"]
[Tue Aug 18 13:00:51.006971 2026] [security2:error] [pid 123784:tid 123947] [client 158.23.17.4:63953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/asus.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBcwAAAB0"]
[Tue Aug 18 13:00:51.016712 2026] [autoindex:error] [pid 123784:tid 123992] [client 20.65.98.162:56500] AH01276: Cannot serve directory /home4/labotafogo/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:51.066992 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.36.136:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBdAAAAEc"]
[Tue Aug 18 13:00:51.094568 2026] [security2:error] [pid 123784:tid 124027] [client 20.75.92.165:4296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/alfa.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBdQAAAG0"]
[Tue Aug 18 13:00:51.099712 2026] [security2:error] [pid 123784:tid 123923] [client 158.23.17.4:60783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/fg.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBdgAAAAU"]
[Tue Aug 18 13:00:51.115562 2026] [security2:error] [pid 123784:tid 123941] [client 20.251.112.238:39896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBdwAAABc"]
[Tue Aug 18 13:00:51.239405 2026] [security2:error] [pid 123784:tid 124038] [client 172.202.39.151:53703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/www.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBeQAAAHg"]
[Tue Aug 18 13:00:51.269959 2026] [security2:error] [pid 123784:tid 123949] [client 20.226.36.136:53539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/images/security.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBegAAAB8"]
[Tue Aug 18 13:00:51.328686 2026] [security2:error] [pid 123784:tid 124016] [client 20.65.98.162:56500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/php.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBfAAAAGI"]
[Tue Aug 18 13:00:51.361760 2026] [security2:error] [pid 123784:tid 123958] [client 20.226.56.190:28260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/evil.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBfQAAACg"]
[Tue Aug 18 13:00:51.520405 2026] [security2:error] [pid 123784:tid 124018] [client 20.91.215.254:12028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBfgAAAGQ"]
[Tue Aug 18 13:00:51.600648 2026] [security2:error] [pid 123784:tid 123996] [client 20.250.27.191:63197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/cabs.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBggAAAE4"]
[Tue Aug 18 13:00:51.621462 2026] [security2:error] [pid 123784:tid 124020] [client 158.23.17.4:33997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ev.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBgwAAAGY"]
[Tue Aug 18 13:00:51.625364 2026] [security2:error] [pid 123784:tid 123980] [client 138.36.100.162:43114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBhAAAAD4"]
[Tue Aug 18 13:00:51.625431 2026] [security2:error] [pid 123784:tid 123980] [client 138.36.100.162:43114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBhAAAAD4"]
[Tue Aug 18 13:00:51.757697 2026] [security2:error] [pid 123784:tid 124028] [client 20.38.3.247:39108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/av.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBiAAAAG4"]
[Tue Aug 18 13:00:51.791837 2026] [security2:error] [pid 123784:tid 123973] [client 20.206.73.37:29985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/biufile.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBigAAADc"]
[Tue Aug 18 13:00:51.817872 2026] [security2:error] [pid 123784:tid 123924] [client 20.104.100.201:34292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBiwAAAAY"]
[Tue Aug 18 13:00:51.849750 2026] [security2:error] [pid 123784:tid 123984] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/fpwch.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBjgAAAEI"]
[Tue Aug 18 13:00:51.922795 2026] [authz_core:error] [pid 123784:tid 123799] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:51.923065 2026] [authz_core:error] [pid 123784:tid 123799] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:51.959106 2026] [security2:error] [pid 123784:tid 123962] [client 52.141.58.175:11661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/up.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBkQAAACw"]
[Tue Aug 18 13:00:51.979697 2026] [security2:error] [pid 123784:tid 123925] [client 20.100.169.31:19802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-themes.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBkgAAAAc"]
[Tue Aug 18 13:00:51.997404 2026] [security2:error] [pid 123784:tid 123936] [client 20.100.169.31:4945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/profile.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBkwAAABI"]
[Tue Aug 18 13:00:52.022497 2026] [security2:error] [pid 123784:tid 123934] [client 20.127.136.245:27854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/a.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBlAAAABA"]
[Tue Aug 18 13:00:52.063808 2026] [security2:error] [pid 123784:tid 123918] [client 158.23.17.4:8755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/22.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBlwAAAAA"]
[Tue Aug 18 13:00:52.091367 2026] [security2:error] [pid 123784:tid 123932] [client 20.250.13.23:46088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/themes.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBmAAAAA4"]
[Tue Aug 18 13:00:52.145163 2026] [security2:error] [pid 123784:tid 124010] [client 20.79.204.6:2210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBmQAAAFw"]
[Tue Aug 18 13:00:52.179758 2026] [security2:error] [pid 123784:tid 123994] [client 158.23.17.4:62981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/37.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBngAAAEw"]
[Tue Aug 18 13:00:52.222628 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:52.222900 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:52.227637 2026] [security2:error] [pid 123784:tid 123940] [client 172.202.39.151:4259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBoQAAABY"]
[Tue Aug 18 13:00:52.362639 2026] [security2:error] [pid 123784:tid 124030] [client 20.250.27.191:28024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/insc.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBrQAAAHA"]
[Tue Aug 18 13:00:52.363132 2026] [security2:error] [pid 123784:tid 124038] [client 20.102.65.165:8288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBrgAAAHg"]
[Tue Aug 18 13:00:52.427825 2026] [security2:error] [pid 123784:tid 124045] [client 20.250.13.23:44071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/nw.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBrwAAAH8"]
[Tue Aug 18 13:00:52.508331 2026] [security2:error] [pid 123784:tid 124035] [client 20.127.136.245:20679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/atomlib.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBsgAAAHU"]
[Tue Aug 18 13:00:52.620221 2026] [security2:error] [pid 123784:tid 124020] [client 52.173.121.69:59036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wsrer.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBtAAAAGY"]
[Tue Aug 18 13:00:52.651155 2026] [security2:error] [pid 123784:tid 123991] [client 103.184.169.37:42991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBuAAAAEk"]
[Tue Aug 18 13:00:52.651263 2026] [security2:error] [pid 123784:tid 123991] [client 103.184.169.37:42991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBuAAAAEk"]
[Tue Aug 18 13:00:52.674141 2026] [security2:error] [pid 123784:tid 123985] [client 168.62.48.100:5549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBvAAAAEM"]
[Tue Aug 18 13:00:52.679051 2026] [security2:error] [pid 123784:tid 123958] [client 20.127.136.245:27857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/chosen.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBvQAAACg"]
[Tue Aug 18 13:00:52.740130 2026] [security2:error] [pid 123784:tid 123970] [client 172.202.39.151:44555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/files/index.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBvgAAADQ"]
[Tue Aug 18 13:00:52.776996 2026] [security2:error] [pid 123784:tid 124002] [client 157.20.138.62:60872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBwAAAAFQ"]
[Tue Aug 18 13:00:52.777145 2026] [security2:error] [pid 123784:tid 124002] [client 157.20.138.62:60872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBwAAAAFQ"]
[Tue Aug 18 13:00:52.826570 2026] [security2:error] [pid 123784:tid 123930] [client 20.91.215.254:27424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/import.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBwQAAAAw"]
[Tue Aug 18 13:00:52.848990 2026] [security2:error] [pid 123784:tid 123927] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBwgAAAAk"]
[Tue Aug 18 13:00:52.947872 2026] [security2:error] [pid 123784:tid 123928] [client 20.250.27.191:45762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/file.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBxgAAAAo"]
[Tue Aug 18 13:00:52.952327 2026] [security2:error] [pid 123784:tid 123960] [client 20.65.98.162:55227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/sf.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBxwAAACo"]
[Tue Aug 18 13:00:53.133430 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:53.133683 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:53.149036 2026] [security2:error] [pid 123784:tid 123919] [client 20.250.13.23:7739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/cv.php"] [unique_id "aoSBtWwDnJBNj2tDbYYBywAAAAE"]
[Tue Aug 18 13:00:53.222184 2026] [security2:error] [pid 123784:tid 124032] [client 158.23.17.4:60786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ve.php"] [unique_id "aoSBtWwDnJBNj2tDbYYBzQAAAHI"]
[Tue Aug 18 13:00:53.323489 2026] [security2:error] [pid 123784:tid 124025] [client 178.153.171.161:45415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB0AAAAGs"]
[Tue Aug 18 13:00:53.323647 2026] [security2:error] [pid 123784:tid 124025] [client 178.153.171.161:45415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB0AAAAGs"]
[Tue Aug 18 13:00:53.339254 2026] [security2:error] [pid 123784:tid 123797] [remote 162.214.96.231:36688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "polimentodemarmore.com.br"] [uri "/wp-login.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBrAAAJwg"]
[Tue Aug 18 13:00:53.384943 2026] [security2:error] [pid 123784:tid 124017] [client 20.226.56.190:23776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-key.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB0QAAAGM"]
[Tue Aug 18 13:00:53.438928 2026] [autoindex:error] [pid 123784:tid 124037] [client 20.79.204.6:2386] AH01276: Cannot serve directory /home3/brto26/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:53.597584 2026] [security2:error] [pid 123784:tid 124041] [client 172.202.39.151:4421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-config-sample.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB2gAAAHs"]
[Tue Aug 18 13:00:53.671523 2026] [security2:error] [pid 123784:tid 124029] [client 20.79.204.6:2386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB3QAAAG8"]
[Tue Aug 18 13:00:53.717856 2026] [security2:error] [pid 123784:tid 123923] [client 20.91.215.254:11976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/cropper.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB3wAAAAU"]
[Tue Aug 18 13:00:53.804647 2026] [security2:error] [pid 123784:tid 123926] [client 20.100.169.31:4967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/sx.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB4gAAAAg"]
[Tue Aug 18 13:00:53.840767 2026] [security2:error] [pid 123784:tid 123971] [client 158.23.17.4:47891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ia.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB4wAAADU"]
[Tue Aug 18 13:00:53.865581 2026] [security2:error] [pid 123784:tid 123938] [client 20.250.13.23:18517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB5AAAABQ"]
[Tue Aug 18 13:00:53.958762 2026] [security2:error] [pid 123784:tid 123977] [client 213.202.253.4:51961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/schallfuns.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB5wAAADs"], referer: www.google.com
[Tue Aug 18 13:00:53.971082 2026] [security2:error] [pid 123784:tid 123969] [client 172.202.39.151:40379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB6AAAADM"]
[Tue Aug 18 13:00:53.977284 2026] [security2:error] [pid 123784:tid 123967] [client 5.31.227.224:30426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB6QAAADE"]
[Tue Aug 18 13:00:53.982047 2026] [security2:error] [pid 123784:tid 123967] [client 5.31.227.224:30426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB6QAAADE"]
[Tue Aug 18 13:00:54.068740 2026] [security2:error] [pid 123784:tid 123974] [client 52.141.58.175:11711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/upload.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB6wAAADg"]
[Tue Aug 18 13:00:54.081711 2026] [security2:error] [pid 123784:tid 124006] [client 158.23.17.4:63673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/zs.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB7AAAAFg"]
[Tue Aug 18 13:00:54.097714 2026] [security2:error] [pid 123784:tid 123930] [client 20.118.133.132:30864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/xx.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB7QAAAAw"]
[Tue Aug 18 13:00:54.215082 2026] [security2:error] [pid 123784:tid 124013] [client 172.202.39.151:40929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wicked.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB8QAAAF8"]
[Tue Aug 18 13:00:54.235256 2026] [security2:error] [pid 123784:tid 124024] [client 20.127.136.245:1700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/min.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB8gAAAGo"]
[Tue Aug 18 13:00:54.243891 2026] [security2:error] [pid 123784:tid 124036] [client 20.65.98.162:55194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/xx.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB8wAAAHY"]
[Tue Aug 18 13:00:54.317346 2026] [authz_core:error] [pid 123784:tid 123817] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:54.317612 2026] [authz_core:error] [pid 123784:tid 123817] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:54.369292 2026] [security2:error] [pid 123784:tid 123939] [client 20.38.3.247:4190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/images.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB9wAAABU"]
[Tue Aug 18 13:00:54.478262 2026] [security2:error] [pid 123784:tid 124011] [client 223.185.37.47:7659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB-QAAAF0"]
[Tue Aug 18 13:00:54.478400 2026] [security2:error] [pid 123784:tid 124011] [client 223.185.37.47:7659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB-QAAAF0"]
[Tue Aug 18 13:00:54.478803 2026] [security2:error] [pid 123784:tid 124000] [client 68.221.73.131:21977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/domvf.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB-gAAAFI"]
[Tue Aug 18 13:00:54.490197 2026] [security2:error] [pid 123784:tid 124032] [client 114.119.138.140:25025] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "copemsa.com.br"] [uri "/"] [unique_id "aoSBtmwDnJBNj2tDbYYB-wAAAHI"], referer: https://www.brazilwebdirectory.com/redirect.php?s=whois/zhizi-medical.com
[Tue Aug 18 13:00:54.514280 2026] [security2:error] [pid 123784:tid 124025] [client 20.151.109.219:14331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/av.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB_AAAAGs"]
[Tue Aug 18 13:00:54.565605 2026] [security2:error] [pid 123784:tid 123992] [client 158.23.17.4:47673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/md.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB_QAAAEo"]
[Tue Aug 18 13:00:54.575110 2026] [security2:error] [pid 123784:tid 123995] [client 158.23.17.4:58696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/kn.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB_gAAAE0"]
[Tue Aug 18 13:00:54.583752 2026] [security2:error] [pid 123784:tid 124027] [client 20.102.65.165:8319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/blurbs.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB_wAAAG0"]
[Tue Aug 18 13:00:54.688820 2026] [security2:error] [pid 123784:tid 123941] [client 20.48.236.86:14471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/admin.php"] [unique_id "aoSBtmwDnJBNj2tDbYYCAAAAABc"]
[Tue Aug 18 13:00:54.747318 2026] [security2:error] [pid 123784:tid 123989] [client 52.173.121.69:9953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/ucpfr.php"] [unique_id "aoSBtmwDnJBNj2tDbYYCAQAAAEc"]
[Tue Aug 18 13:00:54.909056 2026] [security2:error] [pid 123784:tid 123923] [client 20.250.27.191:34819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/dex.php"] [unique_id "aoSBtmwDnJBNj2tDbYYCBQAAAAU"]
[Tue Aug 18 13:00:54.918429 2026] [authz_core:error] [pid 123784:tid 123837] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:54.918697 2026] [authz_core:error] [pid 123784:tid 123837] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:54.977057 2026] [security2:error] [pid 123784:tid 124035] [client 20.102.65.165:8212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/bajah.php"] [unique_id "aoSBtmwDnJBNj2tDbYYCBwAAAHU"]
[Tue Aug 18 13:00:55.042407 2026] [security2:error] [pid 123784:tid 123943] [client 20.79.204.6:10705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/as.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCCAAAABk"]
[Tue Aug 18 13:00:55.082669 2026] [security2:error] [pid 123784:tid 123960] [client 20.100.169.31:24217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCCgAAACo"]
[Tue Aug 18 13:00:55.101472 2026] [security2:error] [pid 123784:tid 123926] [client 20.75.92.165:1929] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/1.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCCwAAAAg"]
[Tue Aug 18 13:00:55.101583 2026] [security2:error] [pid 123784:tid 123926] [client 20.75.92.165:1929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/1.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCCwAAAAg"]
[Tue Aug 18 13:00:55.109651 2026] [security2:error] [pid 123784:tid 124007] [client 20.151.109.219:60878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ag.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCDAAAAFk"]
[Tue Aug 18 13:00:55.128603 2026] [security2:error] [pid 123784:tid 123996] [client 20.250.13.23:30134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCDQAAAE4"]
[Tue Aug 18 13:00:55.162921 2026] [security2:error] [pid 123784:tid 123991] [client 158.23.17.4:15136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/wm.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCDwAAAEk"]
[Tue Aug 18 13:00:55.188126 2026] [security2:error] [pid 123784:tid 123967] [client 20.104.100.201:34282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/df.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCEgAAADE"]
[Tue Aug 18 13:00:55.215642 2026] [security2:error] [pid 123784:tid 123975] [client 4.232.94.69:29694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/MYK4TJEfFvO.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCEwAAADk"]
[Tue Aug 18 13:00:55.298616 2026] [security2:error] [pid 123784:tid 124028] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/about/function.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCFAAAAG4"]
[Tue Aug 18 13:00:55.320627 2026] [security2:error] [pid 123784:tid 123930] [client 20.163.43.14:8957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCFQAAAAw"]
[Tue Aug 18 13:00:55.325207 2026] [security2:error] [pid 123784:tid 123968] [client 168.62.48.100:18027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/rezor.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCFgAAADI"]
[Tue Aug 18 13:00:55.328998 2026] [security2:error] [pid 123784:tid 123937] [client 149.34.210.141:55104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCFwAAABM"]
[Tue Aug 18 13:00:55.394602 2026] [security2:error] [pid 123784:tid 124019] [client 158.23.17.4:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/xs.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCGgAAAGU"]
[Tue Aug 18 13:00:55.419210 2026] [autoindex:error] [pid 123784:tid 123956] [client 20.79.204.6:2389] AH01276: Cannot serve directory /home3/brto26/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:55.424122 2026] [security2:error] [pid 123784:tid 123997] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCGQAAT2o"]
[Tue Aug 18 13:00:55.433954 2026] [security2:error] [pid 123784:tid 124013] [client 20.102.65.165:8250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/domvf.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCHAAAAF8"]
[Tue Aug 18 13:00:55.509157 2026] [security2:error] [pid 123784:tid 123983] [client 213.35.127.232:64343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCJAAAAEE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:00:55.572423 2026] [security2:error] [pid 123784:tid 123939] [client 20.104.100.201:34262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCKAAAABU"]
[Tue Aug 18 13:00:55.606934 2026] [security2:error] [pid 123784:tid 124043] [client 20.91.215.254:11925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/images/xmrlpc.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCKQAAAH0"]
[Tue Aug 18 13:00:55.624434 2026] [security2:error] [pid 123784:tid 123937] [client 149.34.210.141:55104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCFwAAABM"]
[Tue Aug 18 13:00:55.647655 2026] [security2:error] [pid 123784:tid 123924] [client 20.79.204.6:2389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCLQAAAAY"]
[Tue Aug 18 13:00:55.675357 2026] [autoindex:error] [pid 123784:tid 124045] [client 20.250.13.23:23736] AH01276: Cannot serve directory /home3/ezycolorcom/formeskin.com.br/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:55.691792 2026] [security2:error] [pid 123784:tid 124025] [client 20.151.109.219:60401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ig.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCLwAAAGs"]
[Tue Aug 18 13:00:55.699811 2026] [security2:error] [pid 123784:tid 123957] [client 20.163.43.14:8924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/admin.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCMAAAACc"]
[Tue Aug 18 13:00:55.732547 2026] [security2:error] [pid 123784:tid 123992] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/function/function.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCMQAAAEo"]
[Tue Aug 18 13:00:55.803434 2026] [security2:error] [pid 123784:tid 123941] [client 20.75.92.165:4227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/222.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCMgAAABc"]
[Tue Aug 18 13:00:55.863222 2026] [security2:error] [pid 123784:tid 123976] [client 20.38.3.247:35631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/ops.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCNgAAADo"]
[Tue Aug 18 13:00:55.907882 2026] [security2:error] [pid 123784:tid 123923] [client 20.250.13.23:23736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCOwAAAAU"]
[Tue Aug 18 13:00:55.976074 2026] [security2:error] [pid 123784:tid 124029] [client 68.221.73.131:46220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/fpwch.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCPwAAAG8"]
[Tue Aug 18 13:00:56.022078 2026] [security2:error] [pid 123784:tid 123973] [client 20.226.56.190:3053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/phpcheck.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCQgAAADc"]
[Tue Aug 18 13:00:56.149811 2026] [security2:error] [pid 123784:tid 123991] [client 20.206.73.37:34801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/coffexium.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCRwAAAEk"]
[Tue Aug 18 13:00:56.182568 2026] [security2:error] [pid 123784:tid 123967] [client 158.23.17.4:9365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/iz.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCSgAAADE"]
[Tue Aug 18 13:00:56.285331 2026] [security2:error] [pid 123784:tid 124033] [client 158.23.17.4:40418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/iy.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCSwAAAHM"]
[Tue Aug 18 13:00:56.326643 2026] [security2:error] [pid 123784:tid 123925] [client 20.100.169.31:19833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCUAAAAAc"]
[Tue Aug 18 13:00:56.326661 2026] [security2:error] [pid 123784:tid 123959] [client 20.100.169.31:4436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCTwAAACk"]
[Tue Aug 18 13:00:56.344944 2026] [security2:error] [pid 123784:tid 123958] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-signin.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCUQAAACg"]
[Tue Aug 18 13:00:56.423238 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:56.423513 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:56.524699 2026] [security2:error] [pid 123784:tid 123997] [client 158.23.17.4:17563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ac.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCVQAAAE8"]
[Tue Aug 18 13:00:56.534119 2026] [security2:error] [pid 123784:tid 123934] [client 20.127.136.245:27856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/index.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCVgAAABA"]
[Tue Aug 18 13:00:56.562063 2026] [security2:error] [pid 123784:tid 123942] [client 20.75.92.165:4234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/asasx.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCVwAAABg"]
[Tue Aug 18 13:00:56.577890 2026] [security2:error] [pid 123784:tid 123943] [client 197.184.64.235:41960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCWQAAABk"]
[Tue Aug 18 13:00:56.578025 2026] [security2:error] [pid 123784:tid 123943] [client 197.184.64.235:41960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCWQAAABk"]
[Tue Aug 18 13:00:56.585790 2026] [security2:error] [pid 123784:tid 124036] [client 20.163.43.14:8944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/public/css.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCWgAAAHY"]
[Tue Aug 18 13:00:56.597827 2026] [security2:error] [pid 123784:tid 124011] [client 114.119.148.208:62919] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "advogadocriminalgoiania.com.br"] [uri "/2022/01/"] [unique_id "aoSBuGwDnJBNj2tDbYYCWwAAAF0"], referer: https://advogadocriminalgoiania.com.br
[Tue Aug 18 13:00:56.614050 2026] [security2:error] [pid 123784:tid 123984] [client 20.250.27.191:27976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/key.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCXQAAAEI"]
[Tue Aug 18 13:00:56.634219 2026] [security2:error] [pid 123784:tid 123971] [client 102.213.179.104:64597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCXgAAADU"]
[Tue Aug 18 13:00:56.634346 2026] [security2:error] [pid 123784:tid 123971] [client 102.213.179.104:64597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCXgAAADU"]
[Tue Aug 18 13:00:56.639977 2026] [security2:error] [pid 123784:tid 123914] [remote 129.121.74.194:40546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.74.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rtvsolucoes.com.br"] [uri "/wp-login.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCXAAAPX0"]
[Tue Aug 18 13:00:56.689572 2026] [security2:error] [pid 123784:tid 123981] [client 172.202.39.151:52921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/HLA-dd.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCZwAAAD8"]
[Tue Aug 18 13:00:56.724585 2026] [authz_core:error] [pid 123784:tid 123790] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:56.724910 2026] [authz_core:error] [pid 123784:tid 123790] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:56.813729 2026] [security2:error] [pid 123784:tid 124024] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/f35.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCawAAAGo"]
[Tue Aug 18 13:00:56.893856 2026] [security2:error] [pid 123784:tid 123995] [client 20.75.92.165:4316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/filemanager.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCbAAAAE0"]
[Tue Aug 18 13:00:56.968369 2026] [security2:error] [pid 123784:tid 124001] [client 20.163.43.14:8919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCbgAAAFM"]
[Tue Aug 18 13:00:57.063157 2026] [security2:error] [pid 123784:tid 123969] [client 20.226.56.190:3051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/mimes.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCcQAAADM"]
[Tue Aug 18 13:00:57.066040 2026] [security2:error] [pid 123784:tid 123936] [client 78.46.215.1:1176] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.meucrescer.com.br"] [uri "/index.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCbwAAABI"], referer: https://www.meucrescer.com.br
[Tue Aug 18 13:00:57.096596 2026] [security2:error] [pid 123784:tid 123863] [remote 129.121.123.168:51106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.123.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ondaseventos.com"] [uri "/wp-login.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCRgAAXko"]
[Tue Aug 18 13:00:57.145515 2026] [security2:error] [pid 123784:tid 123931] [client 52.141.58.175:4166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/v5.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCcwAAAA0"]
[Tue Aug 18 13:00:57.156955 2026] [security2:error] [pid 123784:tid 124026] [client 158.23.17.4:47887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/yz.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCdAAAAGw"]
[Tue Aug 18 13:00:57.169638 2026] [security2:error] [pid 123784:tid 123930] [client 20.250.13.23:18549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCdQAAAAw"]
[Tue Aug 18 13:00:57.179319 2026] [security2:error] [pid 123784:tid 123982] [client 20.250.27.191:35703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/kir.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCdgAAAEA"]
[Tue Aug 18 13:00:57.204881 2026] [security2:error] [pid 123784:tid 124029] [client 20.75.92.165:4267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/themes.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCeAAAAG8"]
[Tue Aug 18 13:00:57.232387 2026] [security2:error] [pid 123784:tid 123932] [client 52.173.121.69:9939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/yxijx.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCeQAAAA4"]
[Tue Aug 18 13:00:57.241557 2026] [security2:error] [pid 123784:tid 124018] [client 172.202.39.151:44535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/images/images/about.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCegAAAGQ"]
[Tue Aug 18 13:00:57.242700 2026] [security2:error] [pid 123784:tid 124019] [client 196.12.128.158:52793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCewAAAGU"]
[Tue Aug 18 13:00:57.242851 2026] [security2:error] [pid 123784:tid 124019] [client 196.12.128.158:52793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCewAAAGU"]
[Tue Aug 18 13:00:57.268634 2026] [security2:error] [pid 123784:tid 123973] [client 88.90.243.36:49372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.jclareteimoveis.com.br"] [uri "/robots.txt"] [unique_id "aoSBuWwDnJBNj2tDbYYCfQAAADc"]
[Tue Aug 18 13:00:57.268751 2026] [security2:error] [pid 123784:tid 123973] [client 88.90.243.36:49372] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.jclareteimoveis.com.br"] [uri "/robots.txt"] [unique_id "aoSBuWwDnJBNj2tDbYYCfQAAADc"]
[Tue Aug 18 13:00:57.471904 2026] [security2:error] [pid 123784:tid 123992] [client 4.232.94.69:15245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/Casper.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCgQAAAEo"]
[Tue Aug 18 13:00:57.479021 2026] [security2:error] [pid 123784:tid 123940] [client 185.168.30.19:51317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "leguizaimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBtmwDnJBNj2tDbYYCAwAAABY"]
[Tue Aug 18 13:00:57.499152 2026] [security2:error] [pid 123784:tid 123987] [client 168.62.48.100:5532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCgwAAAEU"]
[Tue Aug 18 13:00:57.499864 2026] [security2:error] [pid 123784:tid 124002] [client 168.62.48.100:18055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSBuWwDnJBNj2tDbYYChAAAAFQ"]
[Tue Aug 18 13:00:57.555691 2026] [security2:error] [pid 123784:tid 123958] [client 158.23.17.4:15781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/og.php"] [unique_id "aoSBuWwDnJBNj2tDbYYChwAAACg"]
[Tue Aug 18 13:00:57.606913 2026] [security2:error] [pid 123784:tid 123977] [client 20.79.204.6:2387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCiAAAADs"]
[Tue Aug 18 13:00:57.715184 2026] [security2:error] [pid 123784:tid 123927] [client 20.250.27.191:27991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/nofile.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCigAAAAk"]
[Tue Aug 18 13:00:57.750853 2026] [security2:error] [pid 123784:tid 123956] [client 172.202.39.151:4714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCiwAAACY"]
[Tue Aug 18 13:00:57.817450 2026] [security2:error] [pid 123784:tid 123942] [client 20.100.169.31:4939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCjAAAABg"]
[Tue Aug 18 13:00:57.878479 2026] [security2:error] [pid 123784:tid 124044] [client 20.91.215.254:11961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCjgAAAH4"]
[Tue Aug 18 13:00:57.938788 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:57.939042 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:57.966218 2026] [security2:error] [pid 123784:tid 124003] [client 20.102.65.165:8282] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.lpcor.com.br"] [uri "/1.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCkwAAAFU"]
[Tue Aug 18 13:00:57.966337 2026] [security2:error] [pid 123784:tid 124003] [client 20.102.65.165:8282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/1.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCkwAAAFU"]
[Tue Aug 18 13:00:58.087409 2026] [security2:error] [pid 123784:tid 124025] [client 20.163.43.14:8851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBumwDnJBNj2tDbYYCmAAAAGs"]
[Tue Aug 18 13:00:58.170159 2026] [security2:error] [pid 123784:tid 123964] [client 20.151.109.219:60392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ta.php"] [unique_id "aoSBumwDnJBNj2tDbYYCmQAAAC4"]
[Tue Aug 18 13:00:58.198378 2026] [security2:error] [pid 123784:tid 124028] [client 20.250.13.23:18530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/f7.php"] [unique_id "aoSBumwDnJBNj2tDbYYCmgAAAG4"]
[Tue Aug 18 13:00:58.234490 2026] [security2:error] [pid 123784:tid 124000] [client 158.23.17.4:60341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/kj.php"] [unique_id "aoSBumwDnJBNj2tDbYYCmwAAAFI"]
[Tue Aug 18 13:00:58.252216 2026] [security2:error] [pid 123784:tid 123989] [client 68.221.73.131:13788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/adminner.php"] [unique_id "aoSBumwDnJBNj2tDbYYCngAAAEc"]
[Tue Aug 18 13:00:58.267112 2026] [security2:error] [pid 123784:tid 123990] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/gg.php"] [unique_id "aoSBumwDnJBNj2tDbYYCnwAAAEg"]
[Tue Aug 18 13:00:58.398616 2026] [security2:error] [pid 123784:tid 123946] [client 20.127.136.245:28491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/vx.php"] [unique_id "aoSBumwDnJBNj2tDbYYCoQAAABw"]
[Tue Aug 18 13:00:58.446595 2026] [security2:error] [pid 123784:tid 124029] [client 20.102.65.165:8208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/coffee.php"] [unique_id "aoSBumwDnJBNj2tDbYYCpQAAAG8"]
[Tue Aug 18 13:00:58.488067 2026] [security2:error] [pid 123784:tid 124019] [client 20.163.43.14:8839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/gelay.php"] [unique_id "aoSBumwDnJBNj2tDbYYCpwAAAGU"]
[Tue Aug 18 13:00:58.533481 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:58.533763 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:58.658132 2026] [security2:error] [pid 123784:tid 123843] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBumwDnJBNj2tDbYYCqwAAMTY"]
[Tue Aug 18 13:00:58.658370 2026] [security2:error] [pid 123784:tid 123967] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBumwDnJBNj2tDbYYCqwAAMTY"]
[Tue Aug 18 13:00:58.819794 2026] [security2:error] [pid 123784:tid 123950] [client 20.251.112.238:7773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBumwDnJBNj2tDbYYCsAAAACA"]
[Tue Aug 18 13:00:58.935249 2026] [security2:error] [pid 123784:tid 123977] [client 20.65.98.162:56507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/uwu.php"] [unique_id "aoSBumwDnJBNj2tDbYYCsQAAADs"]
[Tue Aug 18 13:00:58.959875 2026] [security2:error] [pid 123784:tid 124012] [client 144.76.22.181:58082] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "siderurgiabrasil.com.br"] [uri "/index.php"] [unique_id "aoSBumwDnJBNj2tDbYYCoAAAAF4"]
[Tue Aug 18 13:00:58.965091 2026] [security2:error] [pid 123784:tid 123952] [client 20.226.56.190:30987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSBumwDnJBNj2tDbYYCsgAAACI"]
[Tue Aug 18 13:00:58.984734 2026] [security2:error] [pid 123784:tid 123970] [client 158.23.17.4:10948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/se.php"] [unique_id "aoSBumwDnJBNj2tDbYYCswAAADQ"]
[Tue Aug 18 13:00:59.020791 2026] [security2:error] [pid 123784:tid 123927] [client 20.104.100.201:34771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/usr.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCtAAAAAk"]
[Tue Aug 18 13:00:59.067926 2026] [autoindex:error] [pid 123784:tid 123998] [client 169.58.72.248:53799] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:00:59.109295 2026] [security2:error] [pid 123784:tid 123943] [client 20.102.65.165:8194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/fpwch.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCtwAAABk"]
[Tue Aug 18 13:00:59.139943 2026] [security2:error] [pid 123784:tid 124011] [client 20.75.92.165:4240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCuAAAAF0"]
[Tue Aug 18 13:00:59.156393 2026] [security2:error] [pid 123784:tid 124044] [client 158.23.17.4:60310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/vg.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCugAAAH4"]
[Tue Aug 18 13:00:59.289580 2026] [security2:error] [pid 123784:tid 123983] [client 20.250.27.191:63205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/fling.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCwAAAAEE"]
[Tue Aug 18 13:00:59.372960 2026] [security2:error] [pid 123784:tid 123924] [client 20.251.112.238:45115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ws61.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCxQAAAAY"]
[Tue Aug 18 13:00:59.398161 2026] [security2:error] [pid 123784:tid 124025] [client 20.48.236.86:14785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/222.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCxgAAAGs"]
[Tue Aug 18 13:00:59.410839 2026] [security2:error] [pid 123784:tid 123957] [client 20.102.65.165:8262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/adminner.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCxwAAACc"]
[Tue Aug 18 13:00:59.436610 2026] [security2:error] [pid 123784:tid 124028] [client 20.118.133.132:19664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/uwu.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCyAAAAG4"]
[Tue Aug 18 13:00:59.440061 2026] [security2:error] [pid 123784:tid 124031] [client 172.202.39.151:44122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCyQAAAHE"]
[Tue Aug 18 13:00:59.509889 2026] [security2:error] [pid 123784:tid 123971] [client 20.79.204.6:10381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/min.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCzAAAADU"]
[Tue Aug 18 13:00:59.707696 2026] [security2:error] [pid 123784:tid 123958] [client 185.168.30.19:29507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "leguizaimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCzQAAACg"]
[Tue Aug 18 13:00:59.738140 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:00:59.738421 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:00:59.869531 2026] [security2:error] [pid 123784:tid 123973] [client 20.100.169.31:4929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSBu2wDnJBNj2tDbYYC4QAAADc"]
[Tue Aug 18 13:00:59.881979 2026] [security2:error] [pid 123784:tid 124007] [client 20.163.43.14:8946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBu2wDnJBNj2tDbYYC4gAAAFk"]
[Tue Aug 18 13:00:59.905513 2026] [security2:error] [pid 123784:tid 123996] [client 20.250.27.191:35686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/zoo1.php"] [unique_id "aoSBu2wDnJBNj2tDbYYC5QAAAE4"]
[Tue Aug 18 13:01:00.092546 2026] [security2:error] [pid 123784:tid 123932] [client 20.91.215.254:12138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/goat.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC6gAAAA4"]
[Tue Aug 18 13:01:00.256117 2026] [security2:error] [pid 123784:tid 123960] [client 20.79.204.6:2200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC8AAAACo"]
[Tue Aug 18 13:01:00.258547 2026] [security2:error] [pid 123784:tid 123969] [client 168.119.96.239:41686] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.meucrescer.com.br"] [uri "/index.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC7AAAADM"], referer: https://www.meucrescer.com.br
[Tue Aug 18 13:01:00.282170 2026] [security2:error] [pid 123784:tid 124013] [client 213.202.253.4:50003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/schallfuns.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC8QAAAF8"], referer: www.google.com
[Tue Aug 18 13:01:00.318589 2026] [security2:error] [pid 123784:tid 123948] [client 20.127.136.245:28057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wap.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC8gAAAB4"]
[Tue Aug 18 13:01:00.352296 2026] [security2:error] [pid 123784:tid 124009] [client 20.151.109.219:60885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/34.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC9AAAAFs"]
[Tue Aug 18 13:01:00.401067 2026] [security2:error] [pid 123784:tid 123993] [client 168.62.48.100:5622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC9QAAAEs"]
[Tue Aug 18 13:01:00.446325 2026] [security2:error] [pid 123784:tid 123956] [client 20.38.3.247:48508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/abcd.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC9wAAACY"]
[Tue Aug 18 13:01:00.510539 2026] [security2:error] [pid 123784:tid 124042] [client 52.141.58.175:4195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/w.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC-AAAAHw"]
[Tue Aug 18 13:01:00.579565 2026] [security2:error] [pid 123784:tid 124035] [client 20.250.27.191:35657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/zoo2.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC-gAAAHU"]
[Tue Aug 18 13:01:00.624936 2026] [security2:error] [pid 123784:tid 123939] [client 20.251.112.238:51094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/rum.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC-wAAABU"]
[Tue Aug 18 13:01:00.640047 2026] [authz_core:error] [pid 123784:tid 123796] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:00.640328 2026] [authz_core:error] [pid 123784:tid 123796] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:00.645242 2026] [security2:error] [pid 123784:tid 124020] [client 20.226.56.190:47120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/pqr.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC_QAAAGY"]
[Tue Aug 18 13:01:00.769785 2026] [security2:error] [pid 123784:tid 123983] [client 20.102.65.165:5078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/abcd.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC_gAAAEE"]
[Tue Aug 18 13:01:00.820078 2026] [security2:error] [pid 123784:tid 123957] [client 158.23.17.4:51192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/sm.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC_wAAACc"]
[Tue Aug 18 13:01:00.877364 2026] [security2:error] [pid 123784:tid 123926] [client 114.119.133.87:34453] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.brindesoxente.com"] [uri "/index.php/product/caneta-ecologica/"] [unique_id "aoSBvGwDnJBNj2tDbYYDBAAAAAg"], referer: https://www.brindesoxente.com/index.php/product/caneta-ecologica
[Tue Aug 18 13:01:00.917245 2026] [security2:error] [pid 123784:tid 124037] [client 20.127.136.245:12440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/mac.php"] [unique_id "aoSBvGwDnJBNj2tDbYYDBQAAAHc"]
[Tue Aug 18 13:01:01.027567 2026] [security2:error] [pid 123784:tid 124043] [client 20.38.3.247:19557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/coffexium.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDBgAAAH0"]
[Tue Aug 18 13:01:01.249412 2026] [security2:error] [pid 123784:tid 123997] [client 4.232.94.69:39260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/beence.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDDgAAAE8"]
[Tue Aug 18 13:01:01.274007 2026] [security2:error] [pid 123784:tid 123964] [client 86.120.159.145:51193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC7wAAAC4"]
[Tue Aug 18 13:01:01.275756 2026] [security2:error] [pid 123784:tid 123920] [client 20.163.43.14:8898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDDwAAAAI"]
[Tue Aug 18 13:01:01.298410 2026] [security2:error] [pid 123784:tid 124002] [client 20.250.13.23:18498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/photo.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDEAAAAFQ"]
[Tue Aug 18 13:01:01.421564 2026] [security2:error] [pid 123784:tid 123977] [client 20.100.169.31:4779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDFAAAADs"]
[Tue Aug 18 13:01:01.482120 2026] [security2:error] [pid 123784:tid 123919] [client 20.127.136.245:28054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-admin/wp.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDGAAAAAE"]
[Tue Aug 18 13:01:01.544631 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:01.544909 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:01.656121 2026] [security2:error] [pid 123784:tid 123925] [client 172.202.39.151:63688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/cah.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDIwAAAAc"]
[Tue Aug 18 13:01:01.673493 2026] [security2:error] [pid 123784:tid 123936] [client 20.65.98.162:55212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/signon.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDJQAAABI"]
[Tue Aug 18 13:01:01.727440 2026] [security2:error] [pid 123784:tid 124016] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/class.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDJgAAAGI"]
[Tue Aug 18 13:01:01.741822 2026] [security2:error] [pid 123784:tid 124012] [client 52.173.121.69:62948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/zwlsv.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDJwAAAF4"]
[Tue Aug 18 13:01:01.795691 2026] [security2:error] [pid 123784:tid 123927] [client 68.221.73.131:55126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/abcd.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDLwAAAAk"]
[Tue Aug 18 13:01:01.848153 2026] [security2:error] [pid 123784:tid 123958] [client 149.34.210.141:55809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDNAAAACg"]
[Tue Aug 18 13:01:01.963503 2026] [security2:error] [pid 123784:tid 123972] [client 20.102.65.165:8264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDOwAAADY"]
[Tue Aug 18 13:01:01.963907 2026] [security2:error] [pid 123784:tid 123952] [client 20.79.204.6:2214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDPAAAACI"]
[Tue Aug 18 13:01:01.970193 2026] [security2:error] [pid 123784:tid 124038] [client 20.48.236.86:14486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/mac.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDPQAAAHg"]
[Tue Aug 18 13:01:01.970476 2026] [security2:error] [pid 123784:tid 123967] [client 185.168.30.19:34431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "leguizaimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDLAAAADE"]
[Tue Aug 18 13:01:02.003284 2026] [security2:error] [pid 123784:tid 123968] [client 172.202.39.151:4707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDPgAAADI"]
[Tue Aug 18 13:01:02.049489 2026] [security2:error] [pid 123784:tid 123964] [client 86.120.159.145:51193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC7wAAAC4"]
[Tue Aug 18 13:01:02.070090 2026] [security2:error] [pid 123784:tid 123983] [client 20.65.98.162:28944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/puc.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDRwAAAEE"]
[Tue Aug 18 13:01:02.153350 2026] [security2:error] [pid 123784:tid 123958] [client 149.34.210.141:55809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDNAAAACg"]
[Tue Aug 18 13:01:02.161217 2026] [security2:error] [pid 123784:tid 123962] [client 20.91.215.254:22263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/Session.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDTwAAACw"]
[Tue Aug 18 13:01:02.199226 2026] [security2:error] [pid 123784:tid 124037] [client 20.251.112.238:7774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ze.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDUgAAAHc"]
[Tue Aug 18 13:01:02.206917 2026] [security2:error] [pid 123784:tid 123988] [client 20.79.204.6:10713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/php8.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDUwAAAEY"]
[Tue Aug 18 13:01:02.306849 2026] [security2:error] [pid 123784:tid 123998] [client 138.36.100.162:42290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDVQAAAFA"]
[Tue Aug 18 13:01:02.306985 2026] [security2:error] [pid 123784:tid 123998] [client 138.36.100.162:42290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDVQAAAFA"]
[Tue Aug 18 13:01:02.372701 2026] [security2:error] [pid 123784:tid 123986] [client 20.102.65.165:8311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDVgAAAEQ"]
[Tue Aug 18 13:01:02.438365 2026] [security2:error] [pid 123784:tid 123946] [client 168.62.48.100:18147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDVwAAABw"]
[Tue Aug 18 13:01:02.525944 2026] [security2:error] [pid 123784:tid 124019] [client 20.104.100.201:62002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDWgAAAGU"]
[Tue Aug 18 13:01:02.537963 2026] [security2:error] [pid 123784:tid 123945] [client 20.206.73.37:29982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/dex.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDWwAAABs"]
[Tue Aug 18 13:01:02.651710 2026] [security2:error] [pid 123784:tid 123947] [client 52.141.58.175:11653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/we.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDZAAAAB0"]
[Tue Aug 18 13:01:02.660126 2026] [security2:error] [pid 123784:tid 124002] [client 20.79.204.6:2204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDZwAAAFQ"]
[Tue Aug 18 13:01:02.736953 2026] [security2:error] [pid 123784:tid 124020] [client 20.127.136.245:27865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/bgymj.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDaQAAAGY"]
[Tue Aug 18 13:01:02.805389 2026] [security2:error] [pid 123784:tid 124009] [client 168.62.48.100:18076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/index/function.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDcAAAAFs"]
[Tue Aug 18 13:01:02.857924 2026] [security2:error] [pid 123784:tid 124011] [client 20.251.112.238:51100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/gjm.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDdAAAAF0"]
[Tue Aug 18 13:01:03.111535 2026] [security2:error] [pid 123784:tid 124005] [client 158.23.17.4:12503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/lmfi2.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDfAAAAFc"]
[Tue Aug 18 13:01:03.144631 2026] [security2:error] [pid 123784:tid 123980] [client 103.184.169.37:43028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDfQAAAD4"]
[Tue Aug 18 13:01:03.144772 2026] [security2:error] [pid 123784:tid 123980] [client 103.184.169.37:43028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDfQAAAD4"]
[Tue Aug 18 13:01:03.150371 2026] [security2:error] [pid 123784:tid 123983] [client 168.62.48.100:18167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDgAAAAEE"]
[Tue Aug 18 13:01:03.250171 2026] [security2:error] [pid 123784:tid 123962] [client 68.221.73.131:46268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/simple.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDggAAACw"]
[Tue Aug 18 13:01:03.408866 2026] [security2:error] [pid 123784:tid 124037] [client 20.75.92.165:4235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/buy.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDhwAAAHc"]
[Tue Aug 18 13:01:03.493297 2026] [security2:error] [pid 123784:tid 123998] [client 168.62.48.100:18137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/Cachex.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDiQAAAFA"]
[Tue Aug 18 13:01:03.578135 2026] [security2:error] [pid 123784:tid 124025] [client 20.127.136.245:27892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/aa.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDjAAAAGs"]
[Tue Aug 18 13:01:03.597532 2026] [security2:error] [pid 123784:tid 123946] [client 20.118.133.132:13721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/signon.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDkAAAABw"]
[Tue Aug 18 13:01:03.660986 2026] [security2:error] [pid 123784:tid 123945] [client 20.127.136.245:13761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/nc4.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDkgAAABs"]
[Tue Aug 18 13:01:03.799144 2026] [security2:error] [pid 123784:tid 123985] [client 158.23.17.4:9382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/vp.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDlQAAAEM"]
[Tue Aug 18 13:01:03.800129 2026] [security2:error] [pid 123784:tid 123947] [client 168.62.48.100:18165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDlgAAAB0"]
[Tue Aug 18 13:01:03.873456 2026] [security2:error] [pid 123784:tid 123960] [client 20.102.65.165:8219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/yj09.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDnAAAACo"]
[Tue Aug 18 13:01:03.905545 2026] [security2:error] [pid 123784:tid 124019] [client 20.91.215.254:12240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/acme-challenge.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDnwAAAGU"]
[Tue Aug 18 13:01:04.012818 2026] [security2:error] [pid 123784:tid 123926] [client 213.35.127.232:65432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDogAAAAg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:04.085597 2026] [security2:error] [pid 123784:tid 123938] [client 20.151.109.219:39352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/he.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDowAAABQ"]
[Tue Aug 18 13:01:04.130037 2026] [security2:error] [pid 123784:tid 123953] [client 20.38.3.247:39000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDpAAAACM"]
[Tue Aug 18 13:01:04.199046 2026] [security2:error] [pid 123784:tid 124006] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/flower.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDqAAAAFg"]
[Tue Aug 18 13:01:04.209692 2026] [security2:error] [pid 123784:tid 123972] [client 20.102.65.165:8276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/scxy.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDqQAAADY"]
[Tue Aug 18 13:01:04.212958 2026] [security2:error] [pid 123784:tid 123993] [client 74.7.228.22:47208] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gvc.eng.br"] [uri "/index.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDpQAASyI"]
[Tue Aug 18 13:01:04.378865 2026] [security2:error] [pid 123784:tid 124035] [client 20.226.56.190:31035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/lmfi2.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDqgAAAHU"]
[Tue Aug 18 13:01:04.489613 2026] [security2:error] [pid 123784:tid 124026] [client 20.151.109.219:60910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/gz.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDrAAAAGw"]
[Tue Aug 18 13:01:04.703034 2026] [security2:error] [pid 123784:tid 123957] [client 20.100.169.31:4956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDtwAAACc"]
[Tue Aug 18 13:01:04.769338 2026] [fcgid:warn] [pid 123784:tid 124018] (70014)End of file found: [client 66.132.195.121:50640] mod_fcgid: can't get data from http client
[Tue Aug 18 13:01:04.901691 2026] [security2:error] [pid 123784:tid 123996] [client 20.226.56.190:47118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/info2.php"] [unique_id "aoSBwGwDnJBNj2tDbYYD4wAAAE4"]
[Tue Aug 18 13:01:05.088996 2026] [security2:error] [pid 123784:tid 123960] [client 52.28.162.93:14674] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.pinceisroma.com.br"] [uri "/server.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD6AAAACo"], referer: http://www.pinceisroma.com.br
[Tue Aug 18 13:01:05.142248 2026] [security2:error] [pid 123784:tid 123959] [client 52.141.58.175:11650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wk/index.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD6gAAACk"]
[Tue Aug 18 13:01:05.210597 2026] [security2:error] [pid 123784:tid 123988] [client 37.40.227.74:56733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDpwAAAEY"]
[Tue Aug 18 13:01:05.210744 2026] [security2:error] [pid 123784:tid 123988] [client 37.40.227.74:56733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDpwAAAEY"]
[Tue Aug 18 13:01:05.211817 2026] [security2:error] [pid 123784:tid 124023] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD6QAAaXo"]
[Tue Aug 18 13:01:05.265506 2026] [security2:error] [pid 123784:tid 123938] [client 158.23.17.4:29462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ph.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD7QAAABQ"]
[Tue Aug 18 13:01:05.342430 2026] [security2:error] [pid 123784:tid 124013] [client 20.91.215.254:12101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/abcd.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD8QAAAF8"]
[Tue Aug 18 13:01:05.366676 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:05.366941 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:05.367083 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:05.367427 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:05.367910 2026] [authz_core:error] [pid 123784:tid 123820] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:05.368178 2026] [authz_core:error] [pid 123784:tid 123820] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:05.419318 2026] [security2:error] [pid 123784:tid 123954] [client 20.206.73.37:29981] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "novoverona.com.br"] [uri "/1.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD9QAAACQ"]
[Tue Aug 18 13:01:05.419408 2026] [security2:error] [pid 123784:tid 123954] [client 20.206.73.37:29981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/1.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD9QAAACQ"]
[Tue Aug 18 13:01:05.453459 2026] [security2:error] [pid 123784:tid 123819] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD9gAAFR4"]
[Tue Aug 18 13:01:05.476436 2026] [security2:error] [pid 123784:tid 123925] [client 20.118.133.132:13808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/file61.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD9wAAAAc"]
[Tue Aug 18 13:01:05.494361 2026] [security2:error] [pid 123784:tid 123992] [client 20.251.112.238:54431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/new4.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD-AAAAEo"]
[Tue Aug 18 13:01:05.515122 2026] [security2:error] [pid 123784:tid 123944] [client 213.35.127.232:50740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD-QAAABo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:05.574339 2026] [security2:error] [pid 123784:tid 123980] [client 20.102.65.165:8295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD-gAAAD4"]
[Tue Aug 18 13:01:05.615665 2026] [security2:error] [pid 123784:tid 123943] [client 20.48.236.86:14813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/ops.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD_QAAABk"]
[Tue Aug 18 13:01:05.657219 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.56.190:3012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/test_info.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD_gAAAFI"]
[Tue Aug 18 13:01:05.669373 2026] [security2:error] [pid 123784:tid 123881] [remote 216.194.122.158:38534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.122.194.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brandaoesa.com"] [uri "/wp-login.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDsgAAXlw"]
[Tue Aug 18 13:01:05.762053 2026] [security2:error] [pid 123784:tid 123949] [client 20.1.169.243:5777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/as.php"] [unique_id "aoSBwWwDnJBNj2tDbYYEDgAAAB8"]
[Tue Aug 18 13:01:05.899474 2026] [security2:error] [pid 123784:tid 123930] [client 20.127.136.245:8261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/as.php"] [unique_id "aoSBwWwDnJBNj2tDbYYEDwAAAAw"]
[Tue Aug 18 13:01:05.908116 2026] [security2:error] [pid 123784:tid 123945] [client 20.102.65.165:8265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBwWwDnJBNj2tDbYYEEAAAABs"]
[Tue Aug 18 13:01:05.936809 2026] [security2:error] [pid 123784:tid 123984] [client 20.151.109.219:39297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/nf.php"] [unique_id "aoSBwWwDnJBNj2tDbYYEEgAAAEI"]
[Tue Aug 18 13:01:06.031153 2026] [security2:error] [pid 123784:tid 123953] [client 20.127.136.245:28032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-mail.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEFgAAACM"]
[Tue Aug 18 13:01:06.039817 2026] [security2:error] [pid 123784:tid 123990] [client 168.62.48.100:18131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-2019.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEFwAAAEg"]
[Tue Aug 18 13:01:06.053816 2026] [security2:error] [pid 123784:tid 123955] [client 158.23.17.4:47884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/28.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEGAAAACU"]
[Tue Aug 18 13:01:06.231431 2026] [security2:error] [pid 123784:tid 123964] [client 158.23.17.4:56747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/lp.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEGgAAAC4"]
[Tue Aug 18 13:01:06.235181 2026] [security2:error] [pid 123784:tid 123919] [client 52.28.162.93:14684] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.pinceisroma.com.br"] [uri "/server.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEGQAAAAE"], referer: http://www.pinceisroma.com.br
[Tue Aug 18 13:01:06.273252 2026] [security2:error] [pid 123784:tid 123959] [client 52.173.121.69:49376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/jrpga.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEGwAAACk"]
[Tue Aug 18 13:01:06.303662 2026] [security2:error] [pid 123784:tid 123976] [client 20.226.56.190:31650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/xynz1.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEHQAAADo"]
[Tue Aug 18 13:01:06.484051 2026] [security2:error] [pid 123784:tid 123954] [client 20.151.109.219:60895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/xv.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEIQAAACQ"]
[Tue Aug 18 13:01:06.487892 2026] [security2:error] [pid 123784:tid 123993] [client 68.221.73.131:55166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/wp-manager.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEIgAAAEs"]
[Tue Aug 18 13:01:06.493125 2026] [security2:error] [pid 123784:tid 123952] [client 172.202.39.151:12739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEIwAAACI"]
[Tue Aug 18 13:01:06.493189 2026] [security2:error] [pid 123784:tid 123940] [client 20.91.215.254:12228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/kj.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEJAAAABY"]
[Tue Aug 18 13:01:06.585450 2026] [security2:error] [pid 123784:tid 124045] [client 158.23.17.4:17583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/m.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEKgAAAH8"]
[Tue Aug 18 13:01:06.591136 2026] [security2:error] [pid 123784:tid 124002] [client 102.213.179.104:65256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEKwAAAFQ"]
[Tue Aug 18 13:01:06.591251 2026] [security2:error] [pid 123784:tid 124002] [client 102.213.179.104:65256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEKwAAAFQ"]
[Tue Aug 18 13:01:06.647554 2026] [security2:error] [pid 123784:tid 124042] [client 20.1.169.243:5765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/atex1.php"] [unique_id "aoSBwmwDnJBNj2tDbYYELAAAAHw"]
[Tue Aug 18 13:01:06.683992 2026] [authz_core:error] [pid 123784:tid 123857] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:06.684255 2026] [authz_core:error] [pid 123784:tid 123857] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:06.693419 2026] [security2:error] [pid 123784:tid 124000] [client 20.48.236.86:14520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/8.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEMwAAAFI"]
[Tue Aug 18 13:01:06.703839 2026] [security2:error] [pid 123784:tid 123805] [remote 162.241.152.27:60470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jic.org.br"] [uri "/wp-login.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDtgAAMhA"]
[Tue Aug 18 13:01:06.763560 2026] [security2:error] [pid 123784:tid 124025] [client 20.100.169.31:4990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSBwmwDnJBNj2tDbYYENAAAAGs"]
[Tue Aug 18 13:01:06.824312 2026] [security2:error] [pid 123784:tid 123949] [client 20.151.109.219:24403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/mx.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEOAAAAB8"]
[Tue Aug 18 13:01:06.852672 2026] [security2:error] [pid 123784:tid 124009] [client 4.232.94.69:26577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/configs.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEOgAAAFs"]
[Tue Aug 18 13:01:06.872077 2026] [security2:error] [pid 123784:tid 123930] [client 20.226.56.190:31003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/album.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEOwAAAAw"]
[Tue Aug 18 13:01:06.946593 2026] [security2:error] [pid 123784:tid 123996] [client 158.23.17.4:29454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/s.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEPQAAAE4"]
[Tue Aug 18 13:01:06.958107 2026] [security2:error] [pid 123784:tid 123950] [client 20.104.100.201:61384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/css/database.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEPgAAACA"]
[Tue Aug 18 13:01:06.960389 2026] [security2:error] [pid 123784:tid 123955] [client 20.118.133.132:15620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/copypaths.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEPwAAACU"]
[Tue Aug 18 13:01:06.981081 2026] [security2:error] [pid 123784:tid 123938] [client 20.127.136.245:28050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/bolt.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEQAAAABQ"]
[Tue Aug 18 13:01:06.983390 2026] [security2:error] [pid 123784:tid 123985] [client 20.206.73.37:34765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/coffee.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEQQAAAEM"]
[Tue Aug 18 13:01:07.018598 2026] [security2:error] [pid 123784:tid 123964] [client 52.173.121.69:55180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSBw2wDnJBNj2tDbYYEQwAAAC4"]
[Tue Aug 18 13:01:07.198939 2026] [security2:error] [pid 123784:tid 123972] [client 49.13.24.81:39662] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "rakhomed.com.br"] [uri "/"] [unique_id "aoSBw2wDnJBNj2tDbYYERwAAADY"], referer: http://rakhomed.com.br
[Tue Aug 18 13:01:07.237101 2026] [security2:error] [pid 123784:tid 123952] [client 20.102.65.165:8291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/blurbs.php"] [unique_id "aoSBw2wDnJBNj2tDbYYESgAAACI"]
[Tue Aug 18 13:01:07.286204 2026] [security2:error] [pid 123784:tid 124045] [client 158.23.17.4:46579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/nl.php"] [unique_id "aoSBw2wDnJBNj2tDbYYETAAAAH8"]
[Tue Aug 18 13:01:07.548784 2026] [security2:error] [pid 123784:tid 123943] [client 20.79.222.117:17940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBw2wDnJBNj2tDbYYEUwAAABk"]
[Tue Aug 18 13:01:07.633433 2026] [security2:error] [pid 123784:tid 123990] [client 20.1.169.243:5813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/atomlib.php"] [unique_id "aoSBw2wDnJBNj2tDbYYEVQAAAEg"]
[Tue Aug 18 13:01:07.652708 2026] [security2:error] [pid 123784:tid 124001] [client 52.173.121.69:47601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/nwwha.php"] [unique_id "aoSBw2wDnJBNj2tDbYYEVgAAAFM"]
[Tue Aug 18 13:01:07.722695 2026] [security2:error] [pid 123784:tid 123962] [client 20.226.56.190:20378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/creds.php"] [unique_id "aoSBw2wDnJBNj2tDbYYEWQAAACw"]
[Tue Aug 18 13:01:07.822697 2026] [security2:error] [pid 123784:tid 123890] [remote 178.156.200.16:45080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.200.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocionais.com.br"] [uri "/wp-login.php"] [unique_id "aoSBw2wDnJBNj2tDbYYEWwAAN2U"]
[Tue Aug 18 13:01:07.932249 2026] [security2:error] [pid 123784:tid 123950] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/motu.php"] [unique_id "aoSBw2wDnJBNj2tDbYYEXgAAACA"]
[Tue Aug 18 13:01:08.017643 2026] [security2:error] [pid 123784:tid 123985] [client 20.79.222.117:18020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEYAAAAEM"]
[Tue Aug 18 13:01:08.117387 2026] [security2:error] [pid 123784:tid 124029] [client 20.127.136.245:27894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/bthil.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEYgAAAG8"]
[Tue Aug 18 13:01:08.125557 2026] [security2:error] [pid 123784:tid 124008] [client 158.23.17.4:58691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/68.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEYwAAAFo"]
[Tue Aug 18 13:01:08.235543 2026] [authz_core:error] [pid 123784:tid 123873] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:08.235981 2026] [authz_core:error] [pid 123784:tid 123873] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:08.238127 2026] [security2:error] [pid 123784:tid 123948] [client 20.251.112.238:7790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wp-act.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEbgAAAB4"]
[Tue Aug 18 13:01:08.240863 2026] [security2:error] [pid 123784:tid 123936] [client 52.141.58.175:4222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/worksec.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEbwAAABI"]
[Tue Aug 18 13:01:08.259154 2026] [security2:error] [pid 123784:tid 123991] [client 172.202.39.151:44581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/rip.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEcAAAAEk"]
[Tue Aug 18 13:01:08.286779 2026] [security2:error] [pid 123784:tid 123988] [client 216.244.66.243:43436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/cascaaapg.com-0/"] [unique_id "aoSBxGwDnJBNj2tDbYYEcQAAAEY"]
[Tue Aug 18 13:01:08.286883 2026] [security2:error] [pid 123784:tid 123988] [client 216.244.66.243:43436] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/cascaaapg.com-0/"] [unique_id "aoSBxGwDnJBNj2tDbYYEcQAAAEY"]
[Tue Aug 18 13:01:08.317667 2026] [security2:error] [pid 123784:tid 124018] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/404.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEegAAAGQ"]
[Tue Aug 18 13:01:08.333127 2026] [security2:error] [pid 123784:tid 123931] [client 20.151.109.219:14286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/45.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEewAAAA0"]
[Tue Aug 18 13:01:08.362957 2026] [security2:error] [pid 123784:tid 124045] [client 20.38.3.247:39397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/sf.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEfAAAAH8"]
[Tue Aug 18 13:01:08.401973 2026] [security2:error] [pid 123784:tid 124002] [client 49.13.130.29:48508] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "rakhomed.com.br"] [uri "/"] [unique_id "aoSBxGwDnJBNj2tDbYYEfgAAAFQ"], referer: http://rakhomed.com.br
[Tue Aug 18 13:01:08.454163 2026] [security2:error] [pid 123784:tid 123987] [client 20.206.73.37:29969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEgQAAAEU"]
[Tue Aug 18 13:01:08.539521 2026] [security2:error] [pid 123784:tid 123980] [client 20.79.222.117:18000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEhQAAAD4"]
[Tue Aug 18 13:01:08.553396 2026] [security2:error] [pid 123784:tid 124001] [client 20.226.56.190:23783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/mandrill.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEhwAAAFM"]
[Tue Aug 18 13:01:08.604586 2026] [security2:error] [pid 123784:tid 123955] [client 20.1.169.243:5762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/black.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEiAAAACU"]
[Tue Aug 18 13:01:08.638696 2026] [security2:error] [pid 123784:tid 123971] [client 157.90.155.240:26670] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.portaltomazzi.com.br"] [uri "/index.php"] [unique_id "aoSBw2wDnJBNj2tDbYYETwAAADU"], referer: https://www.portaltomazzi.com.br/
[Tue Aug 18 13:01:08.714756 2026] [security2:error] [pid 123784:tid 123998] [client 158.23.17.4:60776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/jl.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEjgAAAFA"]
[Tue Aug 18 13:01:08.717804 2026] [security2:error] [pid 123784:tid 124009] [client 52.173.121.69:51164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/opsqt.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEjwAAAFs"]
[Tue Aug 18 13:01:08.767448 2026] [security2:error] [pid 123784:tid 124013] [client 20.100.169.31:4974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEkgAAAF8"]
[Tue Aug 18 13:01:08.954249 2026] [security2:error] [pid 123784:tid 123991] [client 20.118.133.132:17766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/bless6.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEmAAAAEk"]
[Tue Aug 18 13:01:08.959049 2026] [security2:error] [pid 123784:tid 123988] [client 158.23.17.4:56732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ey.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEmQAAAEY"]
[Tue Aug 18 13:01:08.979191 2026] [security2:error] [pid 123784:tid 123952] [client 20.251.112.238:7756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/grsiuk.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEmgAAACI"]
[Tue Aug 18 13:01:09.062261 2026] [security2:error] [pid 123784:tid 123976] [client 20.1.169.243:5798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/bs1.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEnQAAADo"]
[Tue Aug 18 13:01:09.093590 2026] [security2:error] [pid 123784:tid 123954] [client 20.127.136.245:4721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/k.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEnwAAACQ"]
[Tue Aug 18 13:01:09.179690 2026] [http2:info] [pid 139043:tid 139043] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Aug 18 13:01:09.181917 2026] [security2:error] [pid 123784:tid 124014] [client 158.23.17.4:31891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/fd.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEoAAAAGA"]
[Tue Aug 18 13:01:09.222575 2026] [security2:error] [pid 123784:tid 123893] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEogAAUmg"]
[Tue Aug 18 13:01:09.222735 2026] [security2:error] [pid 123784:tid 124000] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEogAAUmg"]
[Tue Aug 18 13:01:09.239766 2026] [security2:error] [pid 123784:tid 123919] [client 49.13.134.145:31698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "siderurgiabrasil.com.br"] [uri "/index.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEngAAAAE"], referer: https://siderurgiabrasil.com.br
[Tue Aug 18 13:01:09.387324 2026] [security2:error] [pid 123784:tid 123984] [client 52.173.121.69:56391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/jvcpa.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEpgAAAEI"]
[Tue Aug 18 13:01:09.436689 2026] [authz_core:error] [pid 123784:tid 123916] [remote 57.141.22.42:32292] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:09.436960 2026] [authz_core:error] [pid 123784:tid 123916] [remote 57.141.22.42:32292] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:09.467284 2026] [security2:error] [pid 123784:tid 123983] [client 20.163.43.14:8903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEqQAAAEE"]
[Tue Aug 18 13:01:09.562812 2026] [security2:error] [pid 123784:tid 123953] [client 20.79.222.117:18039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/av.php"] [unique_id "aoSBxWwDnJBNj2tDbYYErgAAACM"]
[Tue Aug 18 13:01:09.594641 2026] [security2:error] [pid 123784:tid 123942] [client 4.232.94.69:60808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/delpaths.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEsAAAABg"]
[Tue Aug 18 13:01:09.914014 2026] [security2:error] [pid 139043:tid 139177] [client 158.23.17.4:8921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/info2.php"] [unique_id "aoSBxf2v-lWn9OzQT7UO0AAAAIk"]
[Tue Aug 18 13:01:09.957783 2026] [security2:error] [pid 123784:tid 124020] [client 168.62.48.100:18002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEtgAAAGY"]
[Tue Aug 18 13:01:10.047641 2026] [security2:error] [pid 123784:tid 124014] [client 68.221.73.131:35111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/xiugai.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEuQAAAGA"]
[Tue Aug 18 13:01:10.053456 2026] [security2:error] [pid 123784:tid 123863] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEugAAP0o"]
[Tue Aug 18 13:01:10.147194 2026] [security2:error] [pid 123784:tid 123940] [client 20.1.169.243:5772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/colors/blue/about.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEvAAAABY"]
[Tue Aug 18 13:01:10.164681 2026] [security2:error] [pid 123784:tid 123956] [client 158.23.17.4:14033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/lv.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEvQAAACY"]
[Tue Aug 18 13:01:10.226296 2026] [security2:error] [pid 123784:tid 123949] [client 20.127.136.245:28492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/x.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEvwAAAB8"]
[Tue Aug 18 13:01:10.280087 2026] [authz_core:error] [pid 123784:tid 123842] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:10.280339 2026] [authz_core:error] [pid 123784:tid 123842] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:10.317601 2026] [security2:error] [pid 123784:tid 123955] [client 172.202.39.151:44563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEwgAAACU"]
[Tue Aug 18 13:01:10.325095 2026] [security2:error] [pid 123784:tid 123938] [client 52.173.121.69:60068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEwwAAABQ"]
[Tue Aug 18 13:01:10.347924 2026] [security2:error] [pid 123784:tid 123983] [client 20.206.73.37:35317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBxmwDnJBNj2tDbYYExAAAAEE"]
[Tue Aug 18 13:01:10.350863 2026] [security2:error] [pid 123784:tid 124013] [client 20.163.43.14:8914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/about.php"] [unique_id "aoSBxmwDnJBNj2tDbYYExQAAAF8"]
[Tue Aug 18 13:01:10.372092 2026] [security2:error] [pid 123784:tid 123989] [client 20.65.98.162:55197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/file61.php"] [unique_id "aoSBxmwDnJBNj2tDbYYExwAAAEc"]
[Tue Aug 18 13:01:10.379042 2026] [security2:error] [pid 139043:tid 139183] [client 20.79.204.6:2369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSBxv2v-lWn9OzQT7UO0gAAAI8"]
[Tue Aug 18 13:01:10.607924 2026] [security2:error] [pid 123784:tid 123971] [client 20.1.169.243:5779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/con7.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEygAAADU"]
[Tue Aug 18 13:01:10.638627 2026] [security2:error] [pid 123784:tid 123899] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/admin.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEywAATm4"]
[Tue Aug 18 13:01:10.648769 2026] [security2:error] [pid 139043:tid 139185] [client 158.23.17.4:63628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/uo.php"] [unique_id "aoSBxv2v-lWn9OzQT7UO1AAAAJE"]
[Tue Aug 18 13:01:10.749694 2026] [security2:error] [pid 123784:tid 123936] [client 20.163.43.14:8905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEzQAAABI"]
[Tue Aug 18 13:01:10.816251 2026] [security2:error] [pid 123784:tid 124014] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/lite.php"] [unique_id "aoSBxmwDnJBNj2tDbYYE0QAAAGA"]
[Tue Aug 18 13:01:10.824147 2026] [security2:error] [pid 123784:tid 124044] [client 20.127.136.245:27885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/index/function.php"] [unique_id "aoSBxmwDnJBNj2tDbYYE0gAAAH4"]
[Tue Aug 18 13:01:10.930122 2026] [security2:error] [pid 123784:tid 123969] [client 20.250.13.23:44057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-aa.php"] [unique_id "aoSBxmwDnJBNj2tDbYYE1AAAADM"]
[Tue Aug 18 13:01:11.007983 2026] [security2:error] [pid 123784:tid 124045] [client 49.13.130.29:45190] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rakhomed.com.br"] [uri "/index.php"] [unique_id "aoSBxmwDnJBNj2tDbYYE1QAAAH8"], referer: http://rakhomed.com.br
[Tue Aug 18 13:01:11.139975 2026] [security2:error] [pid 123784:tid 124001] [client 20.163.43.14:8942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/f35.php"] [unique_id "aoSBx2wDnJBNj2tDbYYE1gAAAFM"]
[Tue Aug 18 13:01:11.198328 2026] [security2:error] [pid 123784:tid 123984] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/lock360.php"] [unique_id "aoSBx2wDnJBNj2tDbYYE1wAAAEI"]
[Tue Aug 18 13:01:11.223059 2026] [security2:error] [pid 123784:tid 124029] [client 20.226.56.190:31651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/main.php"] [unique_id "aoSBx2wDnJBNj2tDbYYE2QAAAG8"]
[Tue Aug 18 13:01:11.447173 2026] [security2:error] [pid 123784:tid 123920] [client 20.104.100.201:61412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/privdayz.php"] [unique_id "aoSBx2wDnJBNj2tDbYYE8gAAAAI"]
[Tue Aug 18 13:01:11.483381 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:11.483644 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:11.505477 2026] [security2:error] [pid 139043:tid 139193] [client 158.23.17.4:28358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/sx.php"] [unique_id "aoSBx_2v-lWn9OzQT7UO2AAAAJk"]
[Tue Aug 18 13:01:11.541711 2026] [security2:error] [pid 123784:tid 124026] [client 158.23.17.4:29450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/kx.php"] [unique_id "aoSBx2wDnJBNj2tDbYYE9QAAAGw"]
[Tue Aug 18 13:01:11.606834 2026] [security2:error] [pid 123784:tid 123996] [client 20.79.222.117:18036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/images.php"] [unique_id "aoSBx2wDnJBNj2tDbYYE-QAAAE4"]
[Tue Aug 18 13:01:11.742748 2026] [access_compat:error] [pid 123784:tid 123919] [client 74.7.175.173:0] AH01797: client denied by server configuration: /home1/rakhomed/public_html/robots.txt
[Tue Aug 18 13:01:11.744116 2026] [security2:error] [pid 123784:tid 123919] [client 74.7.175.173:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "rakhomed.com.br"] [uri "/cgi-sys/403.html"] [unique_id "aoSBx2wDnJBNj2tDbYYE-wAAAAE"]
[Tue Aug 18 13:01:11.749430 2026] [security2:error] [pid 139043:tid 139197] [client 158.23.17.4:15769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/51.php"] [unique_id "aoSBx_2v-lWn9OzQT7UO2QAAAJ0"]
[Tue Aug 18 13:01:11.777401 2026] [security2:error] [pid 123784:tid 123993] [client 74.7.175.173:46614] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "rakhomed.com.br"] [uri "/robots.txt"] [unique_id "aoSBxmwDnJBNj2tDbYYEzgAAS2M"]
[Tue Aug 18 13:01:11.786510 2026] [security2:error] [pid 139043:tid 139195] [client 20.100.169.31:4795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSBx_2v-lWn9OzQT7UO2gAAAJs"]
[Tue Aug 18 13:01:11.812831 2026] [security2:error] [pid 123784:tid 123954] [client 52.141.58.175:11688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-access.php"] [unique_id "aoSBx2wDnJBNj2tDbYYE_AAAACQ"]
[Tue Aug 18 13:01:11.893544 2026] [security2:error] [pid 123784:tid 123925] [client 68.221.73.131:33036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/wp-load.php"] [unique_id "aoSBx2wDnJBNj2tDbYYE_gAAAAc"]
[Tue Aug 18 13:01:11.919314 2026] [security2:error] [pid 123784:tid 123932] [client 20.79.204.6:10716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBx2wDnJBNj2tDbYYE_wAAAA4"]
[Tue Aug 18 13:01:11.924962 2026] [security2:error] [pid 123784:tid 124000] [client 172.202.39.151:4476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/cgi-bin/index.php"] [unique_id "aoSBx2wDnJBNj2tDbYYFAAAAAFI"]
[Tue Aug 18 13:01:12.044274 2026] [security2:error] [pid 123784:tid 123995] [client 4.232.94.69:25520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/NewFile.php"] [unique_id "aoSByGwDnJBNj2tDbYYFAgAAAE0"]
[Tue Aug 18 13:01:12.096070 2026] [security2:error] [pid 123784:tid 124006] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSByGwDnJBNj2tDbYYFBAAAAFg"]
[Tue Aug 18 13:01:12.244961 2026] [security2:error] [pid 123784:tid 123813] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/public/css.php"] [unique_id "aoSByGwDnJBNj2tDbYYFBwAAPxg"]
[Tue Aug 18 13:01:12.288615 2026] [security2:error] [pid 123784:tid 124010] [client 20.104.100.201:34302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wg459o.php"] [unique_id "aoSByGwDnJBNj2tDbYYFCAAAAFw"]
[Tue Aug 18 13:01:12.374141 2026] [security2:error] [pid 123784:tid 124029] [client 158.23.17.4:9320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/va.php"] [unique_id "aoSByGwDnJBNj2tDbYYFCgAAAG8"]
[Tue Aug 18 13:01:12.400105 2026] [authz_core:error] [pid 123784:tid 123913] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:12.400929 2026] [authz_core:error] [pid 123784:tid 123913] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:12.450328 2026] [security2:error] [pid 123784:tid 123809] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSByGwDnJBNj2tDbYYFDAAAQRQ"]
[Tue Aug 18 13:01:12.451814 2026] [security2:error] [pid 123784:tid 124013] [client 20.118.133.132:30853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/special.php"] [unique_id "aoSByGwDnJBNj2tDbYYFDQAAAF8"]
[Tue Aug 18 13:01:12.495241 2026] [security2:error] [pid 139043:tid 139206] [client 172.202.39.151:44601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/moon.php"] [unique_id "aoSByP2v-lWn9OzQT7UO4gAAAKY"]
[Tue Aug 18 13:01:12.532456 2026] [security2:error] [pid 123784:tid 124023] [client 20.65.98.162:2842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/19.php"] [unique_id "aoSByGwDnJBNj2tDbYYFEAAAAGk"]
[Tue Aug 18 13:01:12.564663 2026] [security2:error] [pid 139043:tid 139208] [client 172.202.39.151:4460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/an.php"] [unique_id "aoSByP2v-lWn9OzQT7UO4wAAAKg"]
[Tue Aug 18 13:01:12.688648 2026] [autoindex:error] [pid 123784:tid 124008] [client 83.140.110.35:18989] AH01276: Cannot serve directory /home4/varandasgp/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:12.720571 2026] [security2:error] [pid 139043:tid 139210] [client 20.163.43.14:8950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/inputs.php"] [unique_id "aoSByP2v-lWn9OzQT7UO5AAAAKo"]
[Tue Aug 18 13:01:12.745131 2026] [security2:error] [pid 123784:tid 123956] [client 20.250.13.23:18503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/d.php"] [unique_id "aoSByGwDnJBNj2tDbYYFFQAAACY"]
[Tue Aug 18 13:01:12.882413 2026] [security2:error] [pid 123784:tid 123988] [client 20.127.136.245:15058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSByGwDnJBNj2tDbYYFGQAAAEY"]
[Tue Aug 18 13:01:12.912939 2026] [authz_core:error] [pid 123784:tid 123903] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:12.913197 2026] [authz_core:error] [pid 123784:tid 123903] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:13.040286 2026] [security2:error] [pid 123784:tid 123976] [client 20.206.73.37:35285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/mgrr.php"] [unique_id "aoSByWwDnJBNj2tDbYYFHwAAADo"]
[Tue Aug 18 13:01:13.058877 2026] [security2:error] [pid 139043:tid 139219] [client 158.23.17.4:9361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/fo.php"] [unique_id "aoSByf2v-lWn9OzQT7UO5QAAALM"]
[Tue Aug 18 13:01:13.154155 2026] [security2:error] [pid 123784:tid 124020] [client 138.36.100.162:42439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSByWwDnJBNj2tDbYYFIQAAAGY"]
[Tue Aug 18 13:01:13.155793 2026] [security2:error] [pid 123784:tid 124020] [client 138.36.100.162:42439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSByWwDnJBNj2tDbYYFIQAAAGY"]
[Tue Aug 18 13:01:13.260005 2026] [security2:error] [pid 123784:tid 123890] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSByWwDnJBNj2tDbYYFIgAADWU"]
[Tue Aug 18 13:01:13.334508 2026] [security2:error] [pid 123784:tid 124014] [client 103.120.71.157:51356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSByWwDnJBNj2tDbYYFJAAAAGA"]
[Tue Aug 18 13:01:13.334712 2026] [security2:error] [pid 123784:tid 124014] [client 103.120.71.157:51356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSByWwDnJBNj2tDbYYFJAAAAGA"]
[Tue Aug 18 13:01:13.363601 2026] [security2:error] [pid 139043:tid 139222] [client 168.62.48.100:18113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/.cache/x.php"] [unique_id "aoSByf2v-lWn9OzQT7UO6QAAALY"]
[Tue Aug 18 13:01:13.393003 2026] [security2:error] [pid 123784:tid 124044] [client 149.34.210.141:56520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSByGwDnJBNj2tDbYYFCQAAAH4"]
[Tue Aug 18 13:01:13.393146 2026] [security2:error] [pid 123784:tid 124044] [client 149.34.210.141:56520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSByGwDnJBNj2tDbYYFCQAAAH4"]
[Tue Aug 18 13:01:13.464229 2026] [security2:error] [pid 123784:tid 123964] [client 49.13.24.81:52624] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rakhomed.com.br"] [uri "/index.php"] [unique_id "aoSByWwDnJBNj2tDbYYFJQAAAC4"], referer: http://rakhomed.com.br
[Tue Aug 18 13:01:13.475359 2026] [security2:error] [pid 123784:tid 123995] [client 20.251.112.238:26124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/h.php"] [unique_id "aoSByWwDnJBNj2tDbYYFJgAAAE0"]
[Tue Aug 18 13:01:13.568437 2026] [security2:error] [pid 123784:tid 124003] [client 20.118.133.132:15617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/fz.php"] [unique_id "aoSByWwDnJBNj2tDbYYFKAAAAFU"]
[Tue Aug 18 13:01:13.581683 2026] [security2:error] [pid 139043:tid 139229] [client 20.79.222.117:18040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/ops.php"] [unique_id "aoSByf2v-lWn9OzQT7UO6wAAAL0"]
[Tue Aug 18 13:01:13.610113 2026] [authz_core:error] [pid 123784:tid 123831] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:13.610386 2026] [authz_core:error] [pid 123784:tid 123831] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:13.789988 2026] [security2:error] [pid 139043:tid 139233] [client 168.62.48.100:18018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSByf2v-lWn9OzQT7UO7QAAAME"]
[Tue Aug 18 13:01:13.866554 2026] [security2:error] [pid 123784:tid 123856] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/gelay.php"] [unique_id "aoSByWwDnJBNj2tDbYYFKgAAX0M"]
[Tue Aug 18 13:01:13.874113 2026] [security2:error] [pid 123784:tid 124022] [client 68.221.73.131:42687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/155.php"] [unique_id "aoSByWwDnJBNj2tDbYYFKwAAAGg"]
[Tue Aug 18 13:01:13.882145 2026] [core:error] [pid 139043:tid 139227] [client 20.79.204.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 13:01:13.882171 2026] [core:error] [pid 139043:tid 139227] [client 20.79.204.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Aug 18 13:01:13.910796 2026] [security2:error] [pid 139043:tid 139236] [client 20.65.98.162:55217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/copypaths.php"] [unique_id "aoSByf2v-lWn9OzQT7UO8AAAAMQ"]
[Tue Aug 18 13:01:14.084045 2026] [security2:error] [pid 123784:tid 123953] [client 20.79.222.117:18015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/coffexium.php"] [unique_id "aoSBymwDnJBNj2tDbYYFLAAAACM"]
[Tue Aug 18 13:01:14.122558 2026] [security2:error] [pid 123784:tid 123946] [client 20.127.136.245:27847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/aaa.php"] [unique_id "aoSBymwDnJBNj2tDbYYFLQAAABw"]
[Tue Aug 18 13:01:14.128729 2026] [security2:error] [pid 139043:tid 139244] [client 168.62.48.100:17986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSByv2v-lWn9OzQT7UO8gAAAMw"]
[Tue Aug 18 13:01:14.206294 2026] [security2:error] [pid 123784:tid 123992] [client 20.251.112.238:7819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/koiy.php"] [unique_id "aoSBymwDnJBNj2tDbYYFLwAAAEo"]
[Tue Aug 18 13:01:14.261030 2026] [security2:error] [pid 123784:tid 123925] [client 20.250.13.23:18523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSBymwDnJBNj2tDbYYFMQAAAAc"]
[Tue Aug 18 13:01:14.410982 2026] [security2:error] [pid 139043:tid 139220] [client 20.100.169.31:4965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSByv2v-lWn9OzQT7UO9gAAALQ"]
[Tue Aug 18 13:01:14.580816 2026] [security2:error] [pid 139043:tid 139248] [client 172.202.39.151:12741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/cache.php"] [unique_id "aoSByv2v-lWn9OzQT7UO9wAAANA"]
[Tue Aug 18 13:01:14.590423 2026] [security2:error] [pid 123784:tid 123984] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSBymwDnJBNj2tDbYYFNwAAAEI"]
[Tue Aug 18 13:01:14.730374 2026] [security2:error] [pid 139043:tid 139254] [client 20.226.56.190:31663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/payout.php"] [unique_id "aoSByv2v-lWn9OzQT7UO-AAAANY"]
[Tue Aug 18 13:01:14.752103 2026] [security2:error] [pid 139043:tid 139255] [client 20.104.100.201:34261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/mifta.php"] [unique_id "aoSByv2v-lWn9OzQT7UO-QAAANc"]
[Tue Aug 18 13:01:14.954799 2026] [security2:error] [pid 123784:tid 124000] [client 157.20.138.62:62192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBymwDnJBNj2tDbYYFPQAAAFI"]
[Tue Aug 18 13:01:14.954910 2026] [security2:error] [pid 123784:tid 124000] [client 157.20.138.62:62192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBymwDnJBNj2tDbYYFPQAAAFI"]
[Tue Aug 18 13:01:14.973107 2026] [security2:error] [pid 123784:tid 123985] [client 52.141.58.175:11658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-admin.php"] [unique_id "aoSBymwDnJBNj2tDbYYFPgAAAEM"]
[Tue Aug 18 13:01:15.051113 2026] [security2:error] [pid 139043:tid 139249] [client 20.127.136.245:28333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/abcd.php"] [unique_id "aoSBy_2v-lWn9OzQT7UO_QAAANE"]
[Tue Aug 18 13:01:15.087007 2026] [security2:error] [pid 139043:tid 139256] [client 4.232.94.69:19547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/system.php"] [unique_id "aoSBy_2v-lWn9OzQT7UO_gAAANg"]
[Tue Aug 18 13:01:15.117442 2026] [authz_core:error] [pid 123784:tid 123882] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:15.117861 2026] [authz_core:error] [pid 123784:tid 123882] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:15.131338 2026] [security2:error] [pid 123784:tid 124045] [client 20.104.100.201:61990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSBy2wDnJBNj2tDbYYFQQAAAH8"]
[Tue Aug 18 13:01:15.136108 2026] [security2:error] [pid 139043:tid 139265] [client 20.79.222.117:18046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBy_2v-lWn9OzQT7UO_wAAAOE"]
[Tue Aug 18 13:01:15.220423 2026] [security2:error] [pid 123784:tid 123837] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBy2wDnJBNj2tDbYYFQgAANzA"]
[Tue Aug 18 13:01:15.225871 2026] [security2:error] [pid 123784:tid 123954] [client 5.161.194.92:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "atekrefrigeracao.com.br"] [uri "/index.php"] [unique_id "aoSBymwDnJBNj2tDbYYFNgAAJGo"], referer: https://atekrefrigeracao.com.br/
[Tue Aug 18 13:01:15.312227 2026] [security2:error] [pid 139043:tid 139216] [client 5.31.227.224:7846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBy_2v-lWn9OzQT7UPAAAAALA"]
[Tue Aug 18 13:01:15.312495 2026] [security2:error] [pid 139043:tid 139216] [client 5.31.227.224:7846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBy_2v-lWn9OzQT7UPAAAAALA"]
[Tue Aug 18 13:01:15.505100 2026] [security2:error] [pid 139043:tid 139280] [client 68.221.73.131:57574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/index.php"] [unique_id "aoSBy_2v-lWn9OzQT7UPAwAAAPA"]
[Tue Aug 18 13:01:15.558888 2026] [security2:error] [pid 139043:tid 139281] [client 20.48.236.86:14496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/biufile.php"] [unique_id "aoSBy_2v-lWn9OzQT7UPBQAAAPE"]
[Tue Aug 18 13:01:15.683679 2026] [autoindex:error] [pid 123784:tid 123796] [remote 34.122.173.216:10336] AH01276: Cannot serve directory /home2/siderurgiabrasil/anuariodoaco.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:15.702761 2026] [security2:error] [pid 123784:tid 124003] [client 20.79.204.6:2222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSBy2wDnJBNj2tDbYYFSwAAAFU"]
[Tue Aug 18 13:01:15.754063 2026] [security2:error] [pid 139043:tid 139286] [client 20.65.98.162:45571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/bless6.php"] [unique_id "aoSBy_2v-lWn9OzQT7UPBgAAAPY"]
[Tue Aug 18 13:01:15.757932 2026] [security2:error] [pid 139043:tid 139287] [client 20.251.112.238:62493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/fff.php"] [unique_id "aoSBy_2v-lWn9OzQT7UPBwAAAPc"]
[Tue Aug 18 13:01:15.798204 2026] [security2:error] [pid 123784:tid 123920] [client 213.35.127.232:51090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBy2wDnJBNj2tDbYYFUwAAAAI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:16.011574 2026] [security2:error] [pid 139043:tid 139295] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBy_2v-lWn9OzQT7UPDAAA_x0"]
[Tue Aug 18 13:01:16.018822 2026] [authz_core:error] [pid 123784:tid 123828] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:16.019189 2026] [authz_core:error] [pid 123784:tid 123828] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:16.072410 2026] [authz_core:error] [pid 123784:tid 123811] [remote 57.141.22.11:27910] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:16.072770 2026] [authz_core:error] [pid 123784:tid 123811] [remote 57.141.22.11:27910] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:16.190343 2026] [security2:error] [pid 139043:tid 139180] [client 20.48.236.86:14475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/coffexium.php"] [unique_id "aoSBzP2v-lWn9OzQT7UPEAAAAIw"]
[Tue Aug 18 13:01:16.200462 2026] [security2:error] [pid 123784:tid 124013] [client 20.91.215.254:12287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/languages.php"] [unique_id "aoSBzGwDnJBNj2tDbYYFYwAAAF8"]
[Tue Aug 18 13:01:16.212489 2026] [security2:error] [pid 139043:tid 139182] [client 158.23.17.4:63006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ew.php"] [unique_id "aoSBzP2v-lWn9OzQT7UPFAAAAI4"]
[Tue Aug 18 13:01:16.343112 2026] [security2:error] [pid 139043:tid 139264] [client 223.185.37.47:21731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBzP2v-lWn9OzQT7UPFQAAAOA"]
[Tue Aug 18 13:01:16.363931 2026] [security2:error] [pid 123784:tid 123962] [client 20.79.204.6:10715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/222.php"] [unique_id "aoSBzGwDnJBNj2tDbYYFZAAAACw"]
[Tue Aug 18 13:01:16.419000 2026] [security2:error] [pid 139043:tid 139187] [client 20.226.56.190:2507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/Mailgun.php"] [unique_id "aoSBzP2v-lWn9OzQT7UPHAAAAJM"]
[Tue Aug 18 13:01:16.575910 2026] [security2:error] [pid 123784:tid 124007] [client 20.127.136.245:27841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-good.php"] [unique_id "aoSBzGwDnJBNj2tDbYYFZwAAAFk"]
[Tue Aug 18 13:01:16.619877 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:16.620144 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:16.625290 2026] [security2:error] [pid 123784:tid 123793] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBzGwDnJBNj2tDbYYFagAAQgQ"]
[Tue Aug 18 13:01:16.758271 2026] [security2:error] [pid 139043:tid 139294] [client 20.100.169.31:4305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBzP2v-lWn9OzQT7UPKAAAAP4"]
[Tue Aug 18 13:01:16.845453 2026] [security2:error] [pid 123784:tid 124019] [client 20.250.13.23:6787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSBzGwDnJBNj2tDbYYFbQAAAGU"]
[Tue Aug 18 13:01:16.924656 2026] [security2:error] [pid 139043:tid 139177] [client 20.79.204.6:2376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBzP2v-lWn9OzQT7UPKQAAAIk"]
[Tue Aug 18 13:01:16.944316 2026] [security2:error] [pid 139043:tid 139211] [client 20.163.43.14:8921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/alfa.php"] [unique_id "aoSBzP2v-lWn9OzQT7UPKgAAAKs"]
[Tue Aug 18 13:01:17.000951 2026] [security2:error] [pid 139043:tid 139217] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/.alf.php"] [unique_id "aoSBzf2v-lWn9OzQT7UPLgAAALE"]
[Tue Aug 18 13:01:17.015429 2026] [security2:error] [pid 123784:tid 123823] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSBzWwDnJBNj2tDbYYFcQAAWCI"]
[Tue Aug 18 13:01:17.062271 2026] [security2:error] [pid 123784:tid 124045] [client 20.48.236.86:14482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/dex.php"] [unique_id "aoSBzWwDnJBNj2tDbYYFdAAAAH8"]
[Tue Aug 18 13:01:17.203015 2026] [security2:error] [pid 139043:tid 139191] [client 178.153.171.161:27409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBzf2v-lWn9OzQT7UPMwAAAJc"]
[Tue Aug 18 13:01:17.203156 2026] [security2:error] [pid 139043:tid 139191] [client 178.153.171.161:27409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBzf2v-lWn9OzQT7UPMwAAAJc"]
[Tue Aug 18 13:01:17.204454 2026] [security2:error] [pid 123784:tid 123870] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/about.php"] [unique_id "aoSBzWwDnJBNj2tDbYYFdgAAeVE"]
[Tue Aug 18 13:01:17.221506 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:17.221766 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:17.228235 2026] [security2:error] [pid 139043:tid 139234] [client 168.62.48.100:5513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSBzf2v-lWn9OzQT7UPNAAAAMI"]
[Tue Aug 18 13:01:17.431922 2026] [security2:error] [pid 123784:tid 123932] [client 20.127.136.245:21787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/system_log.php"] [unique_id "aoSBzWwDnJBNj2tDbYYFeQAAAA4"]
[Tue Aug 18 13:01:17.491483 2026] [security2:error] [pid 139043:tid 139242] [client 20.251.112.238:7137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/pouhg.php"] [unique_id "aoSBzf2v-lWn9OzQT7UPNwAAAMo"]
[Tue Aug 18 13:01:17.590113 2026] [security2:error] [pid 123784:tid 123839] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBzWwDnJBNj2tDbYYFggAAcTI"]
[Tue Aug 18 13:01:17.590218 2026] [security2:error] [pid 123784:tid 124031] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBzWwDnJBNj2tDbYYFggAAcTI"]
[Tue Aug 18 13:01:17.706100 2026] [security2:error] [pid 139043:tid 139222] [client 20.127.136.245:27874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/simple.php"] [unique_id "aoSBzf2v-lWn9OzQT7UPOwAAALY"]
[Tue Aug 18 13:01:17.762287 2026] [security2:error] [pid 123784:tid 123805] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBzWwDnJBNj2tDbYYFiQAAOxA"]
[Tue Aug 18 13:01:17.832848 2026] [security2:error] [pid 123784:tid 123860] [remote 111.225.149.175:28970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gustavofrison.com.br"] [uri "/wp-content/uploads/2019/05/11-10-400x284.jpg"] [unique_id "aoSBzWwDnJBNj2tDbYYFiwAAK0c"]
[Tue Aug 18 13:01:17.852119 2026] [security2:error] [pid 139043:tid 139173] [client 4.232.94.69:25016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/IDhrIlrLb.php"] [unique_id "aoSBzf2v-lWn9OzQT7UPPAAAAIU"]
[Tue Aug 18 13:01:18.070386 2026] [security2:error] [pid 123784:tid 123986] [client 20.48.236.86:14487] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "treinolab.com.br"] [uri "/1.php"] [unique_id "aoSBzmwDnJBNj2tDbYYFkAAAAEQ"]
[Tue Aug 18 13:01:18.070495 2026] [security2:error] [pid 123784:tid 123986] [client 20.48.236.86:14487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/1.php"] [unique_id "aoSBzmwDnJBNj2tDbYYFkAAAAEQ"]
[Tue Aug 18 13:01:18.119416 2026] [security2:error] [pid 139043:tid 139249] [client 168.62.48.100:17997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPQAAAANE"]
[Tue Aug 18 13:01:18.124886 2026] [security2:error] [pid 139043:tid 139229] [client 20.79.204.6:10411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPQQAAAL0"]
[Tue Aug 18 13:01:18.174438 2026] [security2:error] [pid 123784:tid 123996] [client 172.202.39.151:44557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBzmwDnJBNj2tDbYYFkQAAAE4"]
[Tue Aug 18 13:01:18.193255 2026] [security2:error] [pid 123784:tid 123962] [client 20.226.56.190:31632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/oauth.php"] [unique_id "aoSBzmwDnJBNj2tDbYYFkwAAACw"]
[Tue Aug 18 13:01:18.238752 2026] [security2:error] [pid 123784:tid 123927] [client 158.23.17.4:48433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/pqr.php"] [unique_id "aoSBzmwDnJBNj2tDbYYFlAAAAAk"]
[Tue Aug 18 13:01:18.316813 2026] [security2:error] [pid 123784:tid 123901] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/f35.php"] [unique_id "aoSBzmwDnJBNj2tDbYYFlgAAdXA"]
[Tue Aug 18 13:01:18.363337 2026] [security2:error] [pid 139043:tid 139216] [client 20.163.43.14:8936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/lock360.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPRgAAALA"]
[Tue Aug 18 13:01:18.447088 2026] [security2:error] [pid 139043:tid 139274] [client 20.118.133.132:15139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/clque.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPSAAAAOo"]
[Tue Aug 18 13:01:18.483976 2026] [security2:error] [pid 139043:tid 139277] [client 168.62.48.100:18099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPSgAAAO0"]
[Tue Aug 18 13:01:18.523786 2026] [security2:error] [pid 139043:tid 139280] [client 20.104.100.201:34759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/index2.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPSwAAAPA"]
[Tue Aug 18 13:01:18.651267 2026] [security2:error] [pid 139043:tid 139257] [client 20.1.169.243:5789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/contact-form-7/includes/js/jquery-ui/themes/smoothness/RxRywmgzyK.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPTAAAANk"]
[Tue Aug 18 13:01:18.716345 2026] [security2:error] [pid 139043:tid 139287] [client 20.250.27.191:35704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/imageskir.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPTQAAAPc"]
[Tue Aug 18 13:01:18.743180 2026] [authz_core:error] [pid 123784:tid 123909] [remote 57.141.22.44:21502] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:18.743453 2026] [authz_core:error] [pid 123784:tid 123909] [remote 57.141.22.44:21502] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:18.810077 2026] [security2:error] [pid 139043:tid 139295] [client 168.62.48.100:18081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPTwAAAP8"]
[Tue Aug 18 13:01:18.829101 2026] [security2:error] [pid 123784:tid 123992] [client 20.127.136.245:28308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/edit-tags.php"] [unique_id "aoSBzmwDnJBNj2tDbYYFnQAAAEo"]
[Tue Aug 18 13:01:18.951249 2026] [security2:error] [pid 139043:tid 139299] [client 158.23.17.4:32535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/nu.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPUQAAAQM"]
[Tue Aug 18 13:01:19.000937 2026] [security2:error] [pid 139043:tid 139174] [client 20.116.17.175:53562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPUgAAAIY"]
[Tue Aug 18 13:01:19.016663 2026] [security2:error] [pid 139043:tid 139264] [client 223.185.37.47:21731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBzP2v-lWn9OzQT7UPFQAAAOA"]
[Tue Aug 18 13:01:19.032937 2026] [security2:error] [pid 123784:tid 124014] [client 20.79.222.117:13250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/sf.php"] [unique_id "aoSBz2wDnJBNj2tDbYYFoAAAAGA"]
[Tue Aug 18 13:01:19.039654 2026] [security2:error] [pid 139043:tid 139214] [client 68.221.73.131:13810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/aaa.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPUwAAAK4"]
[Tue Aug 18 13:01:19.044044 2026] [security2:error] [pid 139043:tid 139228] [client 20.48.236.86:14508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/coffee.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPVAAAALw"]
[Tue Aug 18 13:01:19.060699 2026] [security2:error] [pid 123784:tid 123905] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/inputs.php"] [unique_id "aoSBz2wDnJBNj2tDbYYFogAAInQ"]
[Tue Aug 18 13:01:19.072692 2026] [security2:error] [pid 139043:tid 139179] [client 52.173.121.69:60336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPVgAAAIs"]
[Tue Aug 18 13:01:19.123384 2026] [security2:error] [pid 139043:tid 139188] [client 158.23.17.4:7194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/an.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPVwAAAJQ"]
[Tue Aug 18 13:01:19.209348 2026] [security2:error] [pid 139043:tid 139260] [client 197.184.64.235:41962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPWAAAANw"]
[Tue Aug 18 13:01:19.209492 2026] [security2:error] [pid 139043:tid 139260] [client 197.184.64.235:41962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPWAAAANw"]
[Tue Aug 18 13:01:19.281145 2026] [security2:error] [pid 139043:tid 139200] [client 168.62.48.100:17992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPWgAAAKA"]
[Tue Aug 18 13:01:19.282844 2026] [security2:error] [pid 123784:tid 123976] [client 196.12.128.158:54294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBz2wDnJBNj2tDbYYFpAAAADo"]
[Tue Aug 18 13:01:19.282975 2026] [security2:error] [pid 123784:tid 123976] [client 196.12.128.158:54294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBz2wDnJBNj2tDbYYFpAAAADo"]
[Tue Aug 18 13:01:19.321653 2026] [security2:error] [pid 139043:tid 139204] [client 20.251.112.238:26122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/moon3.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPWwAAAKQ"]
[Tue Aug 18 13:01:19.331346 2026] [security2:error] [pid 123784:tid 123957] [client 20.79.204.6:10378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/info.php"] [unique_id "aoSBz2wDnJBNj2tDbYYFpQAAACc"]
[Tue Aug 18 13:01:19.435214 2026] [security2:error] [pid 139043:tid 139212] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/.trash7206/index.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPXAAAAKw"]
[Tue Aug 18 13:01:19.474470 2026] [security2:error] [pid 139043:tid 139215] [client 20.127.136.245:12169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/x.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPXQAAAK8"]
[Tue Aug 18 13:01:19.498516 2026] [lsapi:error] [pid 123784:tid 123929] [client 201.32.74.208:56764] [host pensamentosimperfeitos.com.br] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown
[Tue Aug 18 13:01:19.498534 2026] [lsapi:error] [pid 123784:tid 123929] [client 201.32.74.208:56764] [host pensamentosimperfeitos.com.br] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache
[Tue Aug 18 13:01:19.498542 2026] [lsapi:error] [pid 123784:tid 123929] [client 201.32.74.208:56764] [host pensamentosimperfeitos.com.br] Client error on sending request(POST /wp-json/wp/v2/media HTTP/1.1); uri(/index.php) content-length(23018): user_get_body(tmpstackbuf, 16384): read from client failed
[Tue Aug 18 13:01:19.541623 2026] [security2:error] [pid 123784:tid 123954] [client 20.79.222.117:17921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/k.php"] [unique_id "aoSBz2wDnJBNj2tDbYYFpwAAACQ"]
[Tue Aug 18 13:01:19.547349 2026] [security2:error] [pid 139043:tid 139217] [client 20.104.100.201:49090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPXwAAALE"]
[Tue Aug 18 13:01:19.665255 2026] [security2:error] [pid 139043:tid 139184] [client 20.48.236.86:14806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPYQAAAJA"]
[Tue Aug 18 13:01:19.666399 2026] [security2:error] [pid 139043:tid 139221] [client 20.91.215.254:25846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/nw.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPYgAAALU"]
[Tue Aug 18 13:01:19.724821 2026] [security2:error] [pid 123784:tid 124045] [client 20.1.169.243:5797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/dist/alfa-rex.php"] [unique_id "aoSBz2wDnJBNj2tDbYYFrQAAAH8"]
[Tue Aug 18 13:01:19.794739 2026] [security2:error] [pid 123784:tid 123838] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/alfa.php"] [unique_id "aoSBz2wDnJBNj2tDbYYFrwAABTE"]
[Tue Aug 18 13:01:19.846738 2026] [security2:error] [pid 139043:tid 139209] [client 20.79.204.6:2186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSBzf2v-lWn9OzQT7UPOQAAAKk"]
[Tue Aug 18 13:01:19.886400 2026] [security2:error] [pid 139043:tid 139250] [client 20.104.100.201:49430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPZgAAANI"]
[Tue Aug 18 13:01:20.128161 2026] [security2:error] [pid 123784:tid 123955] [client 168.62.48.100:18079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSB0GwDnJBNj2tDbYYFsgAAACU"]
[Tue Aug 18 13:01:20.188591 2026] [security2:error] [pid 139043:tid 139255] [client 20.104.100.201:34756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/8.php"] [unique_id "aoSB0P2v-lWn9OzQT7UPbQAAANc"]
[Tue Aug 18 13:01:20.348552 2026] [security2:error] [pid 123784:tid 123809] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/lock360.php"] [unique_id "aoSB0GwDnJBNj2tDbYYFtQAANhQ"]
[Tue Aug 18 13:01:20.454953 2026] [security2:error] [pid 123784:tid 123949] [client 20.102.65.165:8476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB0GwDnJBNj2tDbYYFvAAAAB8"]
[Tue Aug 18 13:01:20.471515 2026] [security2:error] [pid 123784:tid 124004] [client 158.23.17.4:44822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ko.php"] [unique_id "aoSB0GwDnJBNj2tDbYYFvQAAAFY"]
[Tue Aug 18 13:01:20.558471 2026] [security2:error] [pid 123784:tid 123857] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/flower.php"] [unique_id "aoSB0GwDnJBNj2tDbYYFvwAALEQ"]
[Tue Aug 18 13:01:20.618179 2026] [security2:error] [pid 139043:tid 139237] [client 20.65.98.162:56483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/special.php"] [unique_id "aoSB0P2v-lWn9OzQT7UPcwAAAMU"]
[Tue Aug 18 13:01:20.715967 2026] [security2:error] [pid 139043:tid 139225] [client 185.191.171.11:55138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754314111/1756598400/"] [unique_id "aoSB0P2v-lWn9OzQT7UPdQAAALk"]
[Tue Aug 18 13:01:20.716083 2026] [security2:error] [pid 139043:tid 139225] [client 185.191.171.11:55138] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754314111/1756598400/"] [unique_id "aoSB0P2v-lWn9OzQT7UPdQAAALk"]
[Tue Aug 18 13:01:20.759518 2026] [security2:error] [pid 123784:tid 123913] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/13.php"] [unique_id "aoSB0GwDnJBNj2tDbYYFwQAAT3w"]
[Tue Aug 18 13:01:20.769638 2026] [security2:error] [pid 123784:tid 124016] [client 20.226.56.190:31618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/timeclock.php"] [unique_id "aoSB0GwDnJBNj2tDbYYFxQAAAGI"]
[Tue Aug 18 13:01:20.808661 2026] [security2:error] [pid 139043:tid 139224] [client 20.100.169.31:4691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSB0P2v-lWn9OzQT7UPdgAAALg"]
[Tue Aug 18 13:01:20.837126 2026] [authz_core:error] [pid 123784:tid 123829] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:20.837394 2026] [authz_core:error] [pid 123784:tid 123829] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:20.920733 2026] [security2:error] [pid 139043:tid 139129] [remote 72.167.40.62:55644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.40.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "proj.vitimarketing.com.br"] [uri "/wp-login.php"] [unique_id "aoSB0P2v-lWn9OzQT7UPdwAAzFU"]
[Tue Aug 18 13:01:20.936362 2026] [security2:error] [pid 123784:tid 123832] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/cc.php"] [unique_id "aoSB0GwDnJBNj2tDbYYFxwAAeis"]
[Tue Aug 18 13:01:21.113642 2026] [security2:error] [pid 139043:tid 139281] [client 20.65.98.162:24530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/133.php"] [unique_id "aoSB0f2v-lWn9OzQT7UPeAAAAPE"]
[Tue Aug 18 13:01:21.123290 2026] [security2:error] [pid 123784:tid 123880] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/gecko-new.php"] [unique_id "aoSB0WwDnJBNj2tDbYYFyAAAVFs"]
[Tue Aug 18 13:01:21.172162 2026] [security2:error] [pid 123784:tid 123968] [client 20.79.204.6:10430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/a.php"] [unique_id "aoSB0WwDnJBNj2tDbYYFyQAAADI"]
[Tue Aug 18 13:01:21.198865 2026] [autoindex:error] [pid 123784:tid 123986] [client 149.104.78.207:41376] AH01276: Cannot serve directory /home4/lomatel/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://lomatel.com.br/
[Tue Aug 18 13:01:21.274782 2026] [security2:error] [pid 139043:tid 139283] [client 20.104.100.201:49437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/makeasmtp.php"] [unique_id "aoSB0f2v-lWn9OzQT7UPeQAAAPM"]
[Tue Aug 18 13:01:21.285201 2026] [security2:error] [pid 123784:tid 124044] [client 158.23.17.4:7192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/sy.php"] [unique_id "aoSB0WwDnJBNj2tDbYYFywAAAH4"]
[Tue Aug 18 13:01:21.300089 2026] [security2:error] [pid 123784:tid 123885] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSB0WwDnJBNj2tDbYYFzAAAcmA"]
[Tue Aug 18 13:01:21.363938 2026] [security2:error] [pid 123784:tid 124000] [client 20.102.65.165:3047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB0WwDnJBNj2tDbYYFzQAAAFI"]
[Tue Aug 18 13:01:21.606108 2026] [security2:error] [pid 139043:tid 139298] [client 20.226.56.190:3017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/email.php"] [unique_id "aoSB0f2v-lWn9OzQT7UPfQAAAQI"]
[Tue Aug 18 13:01:21.619192 2026] [security2:error] [pid 123784:tid 123929] [client 20.104.100.201:49438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/cok.php"] [unique_id "aoSB0WwDnJBNj2tDbYYFzgAAAAs"]
[Tue Aug 18 13:01:21.726348 2026] [security2:error] [pid 139043:tid 139180] [client 68.221.73.131:39836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/FWAZ.php"] [unique_id "aoSB0f2v-lWn9OzQT7UPgAAAAIw"]
[Tue Aug 18 13:01:21.850074 2026] [security2:error] [pid 123784:tid 123817] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/01.php"] [unique_id "aoSB0WwDnJBNj2tDbYYF0QAAfxw"]
[Tue Aug 18 13:01:21.860699 2026] [security2:error] [pid 139043:tid 139228] [client 20.104.100.201:34242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/images.php"] [unique_id "aoSB0f2v-lWn9OzQT7UPgwAAALw"]
[Tue Aug 18 13:01:21.956140 2026] [security2:error] [pid 123784:tid 123789] [remote 34.176.82.226:42578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.82.176.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/wp-login.php"] [unique_id "aoSBzmwDnJBNj2tDbYYFnwAAWgA"]
[Tue Aug 18 13:01:21.958371 2026] [security2:error] [pid 123784:tid 123923] [client 20.104.100.201:49099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/accesson.php"] [unique_id "aoSB0WwDnJBNj2tDbYYF0gAAAAU"]
[Tue Aug 18 13:01:22.040143 2026] [authz_core:error] [pid 123784:tid 123790] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:22.040411 2026] [authz_core:error] [pid 123784:tid 123790] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:22.048866 2026] [security2:error] [pid 139043:tid 139188] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSB0v2v-lWn9OzQT7UPhAAAAJQ"]
[Tue Aug 18 13:01:22.054621 2026] [security2:error] [pid 123784:tid 123837] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/lv.php"] [unique_id "aoSB0mwDnJBNj2tDbYYF2QAAGDA"]
[Tue Aug 18 13:01:22.091016 2026] [security2:error] [pid 123784:tid 124024] [client 172.202.39.151:41099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/system_log.php"] [unique_id "aoSB0mwDnJBNj2tDbYYF2gAAAGo"]
[Tue Aug 18 13:01:22.240972 2026] [security2:error] [pid 123784:tid 123895] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/new.php"] [unique_id "aoSB0mwDnJBNj2tDbYYF2wAAP2o"]
[Tue Aug 18 13:01:22.244917 2026] [security2:error] [pid 123784:tid 123960] [client 20.102.65.165:3064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB0mwDnJBNj2tDbYYF3AAAACo"]
[Tue Aug 18 13:01:22.310940 2026] [security2:error] [pid 139043:tid 139220] [client 20.79.204.6:2384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSB0v2v-lWn9OzQT7UPhgAAALQ"]
[Tue Aug 18 13:01:22.311857 2026] [security2:error] [pid 139043:tid 139204] [client 20.104.100.201:34283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/a.php"] [unique_id "aoSB0v2v-lWn9OzQT7UPhwAAAKQ"]
[Tue Aug 18 13:01:22.417549 2026] [security2:error] [pid 139043:tid 139212] [client 20.102.65.165:8460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB0v2v-lWn9OzQT7UPiQAAAKw"]
[Tue Aug 18 13:01:22.583813 2026] [security2:error] [pid 139043:tid 139275] [client 20.79.204.6:10732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/chosen.php"] [unique_id "aoSB0v2v-lWn9OzQT7UPjQAAAOs"]
[Tue Aug 18 13:01:22.605356 2026] [security2:error] [pid 123784:tid 123952] [client 4.232.94.69:15284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/cJLGqzB.php"] [unique_id "aoSB0mwDnJBNj2tDbYYF3wAAACI"]
[Tue Aug 18 13:01:22.610783 2026] [security2:error] [pid 139043:tid 139240] [client 114.119.140.64:27089] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "viaduplaseguros.com.br"] [uri "/site/conteudo/61-Seguro_de_Cargas"] [unique_id "aoSB0v2v-lWn9OzQT7UPjwAAAMg"], referer: https://viaduplaseguros.com.br/site/
[Tue Aug 18 13:01:22.632711 2026] [security2:error] [pid 139043:tid 139226] [client 20.65.98.162:45617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/fz.php"] [unique_id "aoSB0v2v-lWn9OzQT7UPkAAAALo"]
[Tue Aug 18 13:01:22.698455 2026] [security2:error] [pid 123784:tid 124022] [client 20.104.100.201:62012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSB0mwDnJBNj2tDbYYF4AAAAGg"]
[Tue Aug 18 13:01:22.738937 2026] [security2:error] [pid 139043:tid 139297] [client 138.36.100.162:42333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB0v2v-lWn9OzQT7UPlAAAAQE"]
[Tue Aug 18 13:01:22.807085 2026] [security2:error] [pid 123784:tid 123877] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/222.php"] [unique_id "aoSB0mwDnJBNj2tDbYYF4QAANlg"]
[Tue Aug 18 13:01:22.850247 2026] [security2:error] [pid 139043:tid 139209] [client 172.202.39.151:44574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-mail.php"] [unique_id "aoSB0v2v-lWn9OzQT7UPlwAAAKk"]
[Tue Aug 18 13:01:22.956671 2026] [security2:error] [pid 123784:tid 124004] [client 109.122.18.177:54502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dulaomultimarcas.com.br"] [uri "/.env"] [unique_id "aoSB0mwDnJBNj2tDbYYF4wAAAFY"]
[Tue Aug 18 13:01:22.979936 2026] [security2:error] [pid 123784:tid 123874] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/chosen.php"] [unique_id "aoSB0mwDnJBNj2tDbYYF5AAAb1U"]
[Tue Aug 18 13:01:23.100229 2026] [security2:error] [pid 139043:tid 139258] [client 20.226.56.190:47138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/profile.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPmgAAANo"]
[Tue Aug 18 13:01:23.168763 2026] [security2:error] [pid 123784:tid 123814] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/info.php"] [unique_id "aoSB02wDnJBNj2tDbYYF5QAAGhk"]
[Tue Aug 18 13:01:23.171845 2026] [security2:error] [pid 139043:tid 139273] [client 20.250.13.23:18496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPmwAAAOk"]
[Tue Aug 18 13:01:23.328407 2026] [security2:error] [pid 123784:tid 124010] [client 213.35.127.232:53131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSB02wDnJBNj2tDbYYF5wAAAFw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:23.332052 2026] [autoindex:error] [pid 139043:tid 139143] [remote 34.158.8.33:53386] AH01276: Cannot serve directory /home4/adf/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:23.333841 2026] [security2:error] [pid 139043:tid 139208] [client 20.102.65.165:8465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPngAAAKg"]
[Tue Aug 18 13:01:23.348067 2026] [security2:error] [pid 123784:tid 123827] [remote 198.244.183.167:38626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.sergiopontesadvocacia.com.br"] [uri "/robots.txt"] [unique_id "aoSB02wDnJBNj2tDbYYF6QAAASY"]
[Tue Aug 18 13:01:23.348246 2026] [security2:error] [pid 123784:tid 123919] [client 198.244.183.167:38626] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sergiopontesadvocacia.com.br"] [uri "/robots.txt"] [unique_id "aoSB02wDnJBNj2tDbYYF6QAAASY"]
[Tue Aug 18 13:01:23.458009 2026] [security2:error] [pid 139043:tid 139262] [client 20.48.236.86:14483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPnwAAAN4"]
[Tue Aug 18 13:01:23.475378 2026] [security2:error] [pid 139043:tid 139297] [client 138.36.100.162:42333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB0v2v-lWn9OzQT7UPlAAAAQE"]
[Tue Aug 18 13:01:23.509627 2026] [security2:error] [pid 123784:tid 123984] [client 20.104.100.201:62006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/99.php"] [unique_id "aoSB02wDnJBNj2tDbYYF7AAAAEI"]
[Tue Aug 18 13:01:23.512352 2026] [authz_core:error] [pid 139043:tid 139144] [remote 57.141.22.9:37070] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:23.512643 2026] [authz_core:error] [pid 139043:tid 139144] [remote 57.141.22.9:37070] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:23.514546 2026] [security2:error] [pid 139043:tid 139229] [client 20.116.17.175:22978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPowAAAL0"]
[Tue Aug 18 13:01:23.535714 2026] [security2:error] [pid 123784:tid 123815] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSB02wDnJBNj2tDbYYF7gAADxo"]
[Tue Aug 18 13:01:23.581524 2026] [security2:error] [pid 123784:tid 123945] [client 20.118.133.132:25770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/nano.php"] [unique_id "aoSB02wDnJBNj2tDbYYF8QAAABs"]
[Tue Aug 18 13:01:23.644857 2026] [security2:error] [pid 123784:tid 123968] [client 52.173.121.69:32512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSB02wDnJBNj2tDbYYF8gAAADI"]
[Tue Aug 18 13:01:23.714431 2026] [security2:error] [pid 123784:tid 123876] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSB02wDnJBNj2tDbYYF8wAAflc"]
[Tue Aug 18 13:01:23.808274 2026] [authz_core:error] [pid 139043:tid 139147] [remote 57.141.22.86:40646] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:23.808547 2026] [authz_core:error] [pid 139043:tid 139147] [remote 57.141.22.86:40646] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:23.888818 2026] [security2:error] [pid 139043:tid 139241] [client 20.250.13.23:6816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPqAAAAMk"]
[Tue Aug 18 13:01:23.906830 2026] [security2:error] [pid 123784:tid 123831] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/k.php"] [unique_id "aoSB02wDnJBNj2tDbYYF9wAAQyo"]
[Tue Aug 18 13:01:23.946990 2026] [security2:error] [pid 123784:tid 123994] [client 20.102.65.165:8449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/av.php"] [unique_id "aoSB02wDnJBNj2tDbYYF-AAAAEw"]
[Tue Aug 18 13:01:23.975677 2026] [security2:error] [pid 139043:tid 139178] [client 86.120.159.145:13729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPqQAAAIo"]
[Tue Aug 18 13:01:23.975847 2026] [security2:error] [pid 139043:tid 139178] [client 86.120.159.145:13729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPqQAAAIo"]
[Tue Aug 18 13:01:23.994203 2026] [security2:error] [pid 139043:tid 139203] [client 158.23.17.4:20396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/57.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPqgAAAKM"]
[Tue Aug 18 13:01:24.057660 2026] [security2:error] [pid 123784:tid 124017] [client 20.206.73.37:34779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/55.php"] [unique_id "aoSB1GwDnJBNj2tDbYYF-QAAAGM"]
[Tue Aug 18 13:01:24.070819 2026] [security2:error] [pid 123784:tid 124045] [client 20.104.100.201:49464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/av.php"] [unique_id "aoSB1GwDnJBNj2tDbYYF-gAAAH8"]
[Tue Aug 18 13:01:24.075267 2026] [security2:error] [pid 123784:tid 124008] [client 20.75.92.165:4281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/inputs.php"] [unique_id "aoSB1GwDnJBNj2tDbYYF-wAAAFo"]
[Tue Aug 18 13:01:24.236267 2026] [authz_core:error] [pid 123784:tid 123801] [remote 57.141.22.10:60554] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:24.236533 2026] [authz_core:error] [pid 123784:tid 123801] [remote 57.141.22.10:60554] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:24.278001 2026] [security2:error] [pid 139043:tid 139264] [client 158.23.17.4:17561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/cv.php"] [unique_id "aoSB1P2v-lWn9OzQT7UPsAAAAOA"]
[Tue Aug 18 13:01:24.362983 2026] [security2:error] [pid 139043:tid 139185] [client 20.102.65.165:3030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSB1P2v-lWn9OzQT7UPsQAAAJE"]
[Tue Aug 18 13:01:24.399799 2026] [security2:error] [pid 139043:tid 139274] [client 20.1.169.243:5327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/elementor/wp-login.php"] [unique_id "aoSB0f2v-lWn9OzQT7UPegAAAOo"]
[Tue Aug 18 13:01:24.502804 2026] [authz_core:error] [pid 139043:tid 139152] [remote 57.141.22.116:48838] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:24.503078 2026] [authz_core:error] [pid 139043:tid 139152] [remote 57.141.22.116:48838] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:24.507594 2026] [security2:error] [pid 139043:tid 139218] [client 178.153.171.161:33092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPoAAAALI"]
[Tue Aug 18 13:01:24.525312 2026] [security2:error] [pid 139043:tid 139218] [client 178.153.171.161:33092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPoAAAALI"]
[Tue Aug 18 13:01:24.528340 2026] [security2:error] [pid 139043:tid 139187] [client 20.65.98.162:27927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/1xmomo.php"] [unique_id "aoSB1P2v-lWn9OzQT7UPtAAAAJM"]
[Tue Aug 18 13:01:24.565760 2026] [security2:error] [pid 123784:tid 124014] [client 157.20.138.62:62842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB1GwDnJBNj2tDbYYGAQAAAGA"]
[Tue Aug 18 13:01:24.565871 2026] [security2:error] [pid 123784:tid 124014] [client 157.20.138.62:62842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB1GwDnJBNj2tDbYYGAQAAAGA"]
[Tue Aug 18 13:01:24.638656 2026] [security2:error] [pid 123784:tid 123812] [remote 57.141.22.40:37740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSB1GwDnJBNj2tDbYYGAgAAHhc"]
[Tue Aug 18 13:01:24.741616 2026] [security2:error] [pid 139043:tid 139260] [client 168.119.53.160:31336] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.chicodareia.com.br"] [uri "/index.php"] [unique_id "aoSB1P2v-lWn9OzQT7UPqwAAANw"], referer: https://www.chicodareia.com.br/
[Tue Aug 18 13:01:24.741869 2026] [security2:error] [pid 139043:tid 139222] [client 20.79.204.6:10369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSB1P2v-lWn9OzQT7UPtwAAALY"]
[Tue Aug 18 13:01:24.782859 2026] [security2:error] [pid 123784:tid 123983] [client 20.127.136.245:10843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSB1GwDnJBNj2tDbYYGAwAAAEE"]
[Tue Aug 18 13:01:24.962227 2026] [security2:error] [pid 123784:tid 124031] [client 20.91.215.254:11624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/lofmebwd.php"] [unique_id "aoSB1GwDnJBNj2tDbYYGBwAAAHE"]
[Tue Aug 18 13:01:25.018282 2026] [security2:error] [pid 123784:tid 123996] [client 158.23.17.4:63025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ah.php"] [unique_id "aoSB1WwDnJBNj2tDbYYGCQAAAE4"]
[Tue Aug 18 13:01:25.043771 2026] [security2:error] [pid 123784:tid 124009] [client 20.65.98.162:45580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/clque.php"] [unique_id "aoSB1WwDnJBNj2tDbYYGCgAAAFs"]
[Tue Aug 18 13:01:25.103143 2026] [security2:error] [pid 123784:tid 123988] [client 4.232.94.69:39251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/akc.php"] [unique_id "aoSB1WwDnJBNj2tDbYYGCwAAAEY"]
[Tue Aug 18 13:01:25.155386 2026] [security2:error] [pid 123784:tid 123940] [client 20.100.169.31:4954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSB1WwDnJBNj2tDbYYGDAAAABY"]
[Tue Aug 18 13:01:25.313840 2026] [security2:error] [pid 123784:tid 124018] [client 20.48.236.86:14505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/mgrr.php"] [unique_id "aoSB1WwDnJBNj2tDbYYGDQAAAGQ"]
[Tue Aug 18 13:01:25.537206 2026] [security2:error] [pid 139043:tid 139278] [client 20.116.17.175:55241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB1f2v-lWn9OzQT7UPvQAAAO4"]
[Tue Aug 18 13:01:25.682948 2026] [security2:error] [pid 123784:tid 123968] [client 158.23.17.4:7200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/vw.php"] [unique_id "aoSB1WwDnJBNj2tDbYYGEQAAADI"]
[Tue Aug 18 13:01:25.714881 2026] [security2:error] [pid 123784:tid 123841] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/403.php"] [unique_id "aoSB1WwDnJBNj2tDbYYGEgAAIDQ"]
[Tue Aug 18 13:01:25.761633 2026] [security2:error] [pid 139043:tid 139262] [client 20.163.43.14:8927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/flower.php"] [unique_id "aoSB1f2v-lWn9OzQT7UPxAAAAN4"]
[Tue Aug 18 13:01:25.776022 2026] [security2:error] [pid 139043:tid 139239] [client 20.116.17.175:3437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB1f2v-lWn9OzQT7UPxQAAAMc"]
[Tue Aug 18 13:01:25.840573 2026] [security2:error] [pid 139043:tid 139249] [client 158.23.17.4:17557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/un.php"] [unique_id "aoSB1f2v-lWn9OzQT7UPxwAAANE"]
[Tue Aug 18 13:01:26.040684 2026] [security2:error] [pid 139043:tid 139267] [client 20.102.65.165:8529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/images.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP1QAAAOM"]
[Tue Aug 18 13:01:26.109144 2026] [security2:error] [pid 139043:tid 139225] [client 20.104.100.201:49104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/kj.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP1wAAALk"]
[Tue Aug 18 13:01:26.120407 2026] [security2:error] [pid 123784:tid 123954] [client 52.173.121.69:32521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSB1mwDnJBNj2tDbYYGGwAAACQ"]
[Tue Aug 18 13:01:26.163993 2026] [security2:error] [pid 139043:tid 139277] [client 20.163.43.14:8940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/13.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP2QAAAO0"]
[Tue Aug 18 13:01:26.189201 2026] [security2:error] [pid 123784:tid 123944] [client 213.35.127.232:54632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSB1mwDnJBNj2tDbYYGHQAAABo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:26.268139 2026] [security2:error] [pid 123784:tid 124017] [client 168.62.48.100:5557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSB1mwDnJBNj2tDbYYGHwAAAGM"]
[Tue Aug 18 13:01:26.313013 2026] [security2:error] [pid 139043:tid 139203] [client 20.186.30.159:10019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP3AAAAKM"]
[Tue Aug 18 13:01:26.412366 2026] [security2:error] [pid 123784:tid 123931] [client 20.102.65.165:3027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/av.php"] [unique_id "aoSB1mwDnJBNj2tDbYYGIAAAAA0"]
[Tue Aug 18 13:01:26.445584 2026] [security2:error] [pid 123784:tid 123969] [client 20.104.100.201:49102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSB1mwDnJBNj2tDbYYGIQAAADM"]
[Tue Aug 18 13:01:26.495373 2026] [security2:error] [pid 139043:tid 139300] [client 172.202.39.151:4252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/404.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP4wAAAQQ"]
[Tue Aug 18 13:01:26.557334 2026] [security2:error] [pid 139043:tid 139250] [client 20.163.43.14:8834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/cc.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP5QAAANI"]
[Tue Aug 18 13:01:26.562438 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:26.562716 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:26.587274 2026] [security2:error] [pid 139043:tid 139218] [client 20.127.136.245:23366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/hosty.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP6AAAALI"]
[Tue Aug 18 13:01:26.613328 2026] [security2:error] [pid 139043:tid 139289] [client 103.184.169.37:43115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP5wAAAPk"]
[Tue Aug 18 13:01:26.613479 2026] [security2:error] [pid 139043:tid 139289] [client 103.184.169.37:43115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP5wAAAPk"]
[Tue Aug 18 13:01:26.736800 2026] [security2:error] [pid 139043:tid 139234] [client 20.250.13.23:6821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP7AAAAMI"]
[Tue Aug 18 13:01:26.788089 2026] [security2:error] [pid 139043:tid 139233] [client 216.244.66.232:49954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP7QAAAME"]
[Tue Aug 18 13:01:26.788223 2026] [security2:error] [pid 139043:tid 139233] [client 216.244.66.232:49954] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP7QAAAME"]
[Tue Aug 18 13:01:26.841705 2026] [security2:error] [pid 123784:tid 123978] [client 20.65.98.162:45573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/nano.php"] [unique_id "aoSB1mwDnJBNj2tDbYYGKAAAADw"]
[Tue Aug 18 13:01:26.968963 2026] [security2:error] [pid 123784:tid 123918] [client 172.202.39.151:40340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/o.php"] [unique_id "aoSB1mwDnJBNj2tDbYYGKQAAAAA"]
[Tue Aug 18 13:01:26.992396 2026] [security2:error] [pid 123784:tid 123804] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/gecko.php"] [unique_id "aoSB1mwDnJBNj2tDbYYGKwAAIg8"]
[Tue Aug 18 13:01:26.997266 2026] [security2:error] [pid 123784:tid 123943] [client 20.65.98.162:22570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/mosty.php"] [unique_id "aoSB1mwDnJBNj2tDbYYGLAAAABk"]
[Tue Aug 18 13:01:26.997384 2026] [security2:error] [pid 139043:tid 139069] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/.env"] [unique_id "aoSB1v2v-lWn9OzQT7UP8QAApBk"]
[Tue Aug 18 13:01:26.997740 2026] [security2:error] [pid 139043:tid 139073] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/.env.backup"] [unique_id "aoSB1v2v-lWn9OzQT7UP9QAApB0"]
[Tue Aug 18 13:01:27.033590 2026] [security2:error] [pid 139043:tid 139290] [client 20.91.215.254:12241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSB1_2v-lWn9OzQT7UP_QAAAPo"]
[Tue Aug 18 13:01:27.036443 2026] [security2:error] [pid 123784:tid 124015] [client 20.102.65.165:3055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/images.php"] [unique_id "aoSB12wDnJBNj2tDbYYGLQAAAGE"]
[Tue Aug 18 13:01:27.125591 2026] [security2:error] [pid 139043:tid 139272] [client 20.226.56.190:31664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/summary.php"] [unique_id "aoSB1_2v-lWn9OzQT7UP_wAAAOg"]
[Tue Aug 18 13:01:27.184500 2026] [security2:error] [pid 123784:tid 123946] [client 20.48.236.86:14839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/55.php"] [unique_id "aoSB12wDnJBNj2tDbYYGNgAAABw"]
[Tue Aug 18 13:01:27.194627 2026] [security2:error] [pid 139043:tid 139230] [client 20.102.65.165:8526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/ops.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQAgAAAL4"]
[Tue Aug 18 13:01:27.234369 2026] [autoindex:error] [pid 123784:tid 124004] [client 169.58.72.248:62363] AH01276: Cannot serve directory /home3/adobankcom/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:27.236395 2026] [security2:error] [pid 139043:tid 139202] [client 20.75.92.165:4252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/100.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQAwAAAKI"]
[Tue Aug 18 13:01:27.260771 2026] [security2:error] [pid 139043:tid 139200] [client 158.23.17.4:55223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/evil.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQBAAAAKA"]
[Tue Aug 18 13:01:27.305436 2026] [security2:error] [pid 139043:tid 139231] [client 20.116.17.175:22967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQBgAAAL8"]
[Tue Aug 18 13:01:27.336601 2026] [security2:error] [pid 123784:tid 123925] [client 158.23.17.4:15756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/lj.php"] [unique_id "aoSB12wDnJBNj2tDbYYGOgAAAAc"]
[Tue Aug 18 13:01:27.372104 2026] [security2:error] [pid 123784:tid 123865] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/aa.php"] [unique_id "aoSB12wDnJBNj2tDbYYGOwAAW0w"]
[Tue Aug 18 13:01:27.390152 2026] [security2:error] [pid 123784:tid 123988] [client 20.79.222.117:17948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/82.php"] [unique_id "aoSB12wDnJBNj2tDbYYGPAAAAEY"]
[Tue Aug 18 13:01:27.394953 2026] [security2:error] [pid 139043:tid 139258] [client 20.1.169.243:5770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/goat1.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQBwAAANo"]
[Tue Aug 18 13:01:27.451528 2026] [security2:error] [pid 123784:tid 124003] [client 5.31.227.224:59066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB12wDnJBNj2tDbYYGPQAAAFU"]
[Tue Aug 18 13:01:27.451665 2026] [security2:error] [pid 123784:tid 124003] [client 5.31.227.224:59066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB12wDnJBNj2tDbYYGPQAAAFU"]
[Tue Aug 18 13:01:27.540487 2026] [security2:error] [pid 123784:tid 123997] [client 20.250.27.191:28016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/indexo.php"] [unique_id "aoSB12wDnJBNj2tDbYYGPgAAAE8"]
[Tue Aug 18 13:01:27.555179 2026] [security2:error] [pid 123784:tid 123850] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/0x.php"] [unique_id "aoSB12wDnJBNj2tDbYYGPwAAZD0"]
[Tue Aug 18 13:01:27.568242 2026] [security2:error] [pid 123784:tid 124020] [client 20.102.65.165:3070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/ops.php"] [unique_id "aoSB12wDnJBNj2tDbYYGQAAAAGY"]
[Tue Aug 18 13:01:27.585097 2026] [security2:error] [pid 139043:tid 139226] [client 20.102.65.165:8223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/domvf.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQCgAAALo"]
[Tue Aug 18 13:01:27.614893 2026] [security2:error] [pid 139043:tid 139082] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQCwAAzCY"]
[Tue Aug 18 13:01:27.614954 2026] [security2:error] [pid 139043:tid 139082] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQCwAAzCY"]
[Tue Aug 18 13:01:27.718542 2026] [security2:error] [pid 139043:tid 139295] [client 168.62.48.100:18110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQDAAAAP8"]
[Tue Aug 18 13:01:27.784503 2026] [security2:error] [pid 123784:tid 124013] [client 158.23.17.4:60761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/pw.php"] [unique_id "aoSB12wDnJBNj2tDbYYGRgAAAF8"]
[Tue Aug 18 13:01:27.820911 2026] [autoindex:error] [pid 139043:tid 139245] [client 82.102.18.182:37508] AH01276: Cannot serve directory /home4/ctrrefrigeracao/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:27.841074 2026] [security2:error] [pid 139043:tid 139065] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/.env.bak"] [unique_id "aoSB1_2v-lWn9OzQT7UQGwAA3hU"]
[Tue Aug 18 13:01:27.841152 2026] [security2:error] [pid 139043:tid 139088] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/.env.old"] [unique_id "aoSB1_2v-lWn9OzQT7UQFgAA3iw"]
[Tue Aug 18 13:01:27.937055 2026] [security2:error] [pid 123784:tid 123939] [client 158.23.17.4:47623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/kh.php"] [unique_id "aoSB12wDnJBNj2tDbYYGSQAAABU"]
[Tue Aug 18 13:01:27.939990 2026] [security2:error] [pid 123784:tid 123911] [remote 54.39.210.30:16006] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.sergiopontesadvocacia.com.br"] [uri "/"] [unique_id "aoSB12wDnJBNj2tDbYYGSgAAe3o"]
[Tue Aug 18 13:01:27.940177 2026] [security2:error] [pid 123784:tid 124041] [client 54.39.210.30:16006] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sergiopontesadvocacia.com.br"] [uri "/"] [unique_id "aoSB12wDnJBNj2tDbYYGSgAAe3o"]
[Tue Aug 18 13:01:27.953346 2026] [security2:error] [pid 123784:tid 123923] [client 20.79.204.6:10747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/vx.php"] [unique_id "aoSB12wDnJBNj2tDbYYGSwAAAAU"]
[Tue Aug 18 13:01:27.968587 2026] [security2:error] [pid 123784:tid 123936] [client 172.202.39.151:44517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/bb.php"] [unique_id "aoSB12wDnJBNj2tDbYYGTAAAABI"]
[Tue Aug 18 13:01:27.974120 2026] [security2:error] [pid 139043:tid 139229] [client 20.79.222.117:18032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/dex.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQHgAAAL0"]
[Tue Aug 18 13:01:28.022230 2026] [security2:error] [pid 139043:tid 139297] [client 20.250.27.191:45761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSB2P2v-lWn9OzQT7UQIQAAAQE"]
[Tue Aug 18 13:01:28.082791 2026] [security2:error] [pid 139043:tid 139223] [client 168.62.48.100:18119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSB2P2v-lWn9OzQT7UQIwAAALc"]
[Tue Aug 18 13:01:28.088027 2026] [security2:error] [pid 123784:tid 123799] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/zxz.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGUAAAWQo"]
[Tue Aug 18 13:01:28.245099 2026] [security2:error] [pid 123784:tid 123955] [client 114.119.133.236:46681] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/index.php/netvasco%2Bmobile-1/"] [unique_id "aoSB2GwDnJBNj2tDbYYGUgAAACU"], referer: http://cdlpinheiros.com.br/janaina%2Bsantos%2Bgata%2Bpop-3/
[Tue Aug 18 13:01:28.260340 2026] [security2:error] [pid 139043:tid 139293] [client 20.250.13.23:43931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/abc.php"] [unique_id "aoSB2P2v-lWn9OzQT7UQJQAAAP0"]
[Tue Aug 18 13:01:28.300280 2026] [security2:error] [pid 139043:tid 139107] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/api/.env"] [unique_id "aoSB2P2v-lWn9OzQT7UQKgAAvD8"]
[Tue Aug 18 13:01:28.300283 2026] [security2:error] [pid 139043:tid 139105] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/backend/.env"] [unique_id "aoSB2P2v-lWn9OzQT7UQKAAAvD0"]
[Tue Aug 18 13:01:28.363259 2026] [security2:error] [pid 139043:tid 139261] [client 20.91.215.254:11631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSB2P2v-lWn9OzQT7UQLAAAAN0"]
[Tue Aug 18 13:01:28.427580 2026] [security2:error] [pid 123784:tid 124011] [client 20.48.236.86:14494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/ajax.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGUwAAAF0"]
[Tue Aug 18 13:01:28.451587 2026] [security2:error] [pid 123784:tid 124010] [client 4.232.94.69:38958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/flower.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGVAAAAFw"]
[Tue Aug 18 13:01:28.640921 2026] [security2:error] [pid 123784:tid 123999] [client 20.118.133.132:13708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "agrimotor.com.br"] [uri "/.mopj.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGVgAAAFE"]
[Tue Aug 18 13:01:28.646646 2026] [security2:error] [pid 123784:tid 123901] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/www.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGVwAAPXA"]
[Tue Aug 18 13:01:28.680323 2026] [security2:error] [pid 139043:tid 139099] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/config/.env"] [unique_id "aoSB2P2v-lWn9OzQT7UQMgAAozc"]
[Tue Aug 18 13:01:28.787643 2026] [security2:error] [pid 123784:tid 124024] [client 158.23.17.4:9384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ke.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGWAAAAGo"]
[Tue Aug 18 13:01:28.789682 2026] [security2:error] [pid 123784:tid 123921] [client 20.75.92.165:4253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/akc.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGWQAAAAM"]
[Tue Aug 18 13:01:28.802486 2026] [security2:error] [pid 139043:tid 139183] [client 5.161.215.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tecpolorefrigeracao.com.br"] [uri "/index.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP4gAAjws"], referer: https://tecpolorefrigeracao.com.br/
[Tue Aug 18 13:01:28.829994 2026] [security2:error] [pid 123784:tid 123892] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wicked.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGWgAAVGc"]
[Tue Aug 18 13:01:28.842800 2026] [security2:error] [pid 139043:tid 139201] [client 20.151.109.219:63962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/f.php"] [unique_id "aoSB2P2v-lWn9OzQT7UQNQAAAKE"]
[Tue Aug 18 13:01:28.910618 2026] [security2:error] [pid 139043:tid 139212] [client 102.213.179.104:50209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQHQAAAKw"]
[Tue Aug 18 13:01:28.910754 2026] [security2:error] [pid 139043:tid 139212] [client 102.213.179.104:50209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQHQAAAKw"]
[Tue Aug 18 13:01:28.957637 2026] [authz_core:error] [pid 123784:tid 123808] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:28.957856 2026] [authz_core:error] [pid 123784:tid 123800] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:28.957894 2026] [authz_core:error] [pid 123784:tid 123808] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:28.958101 2026] [authz_core:error] [pid 123784:tid 123800] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:28.975118 2026] [security2:error] [pid 123784:tid 123987] [client 20.102.65.165:8479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/coffexium.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGXwAAAEU"]
[Tue Aug 18 13:01:29.018050 2026] [security2:error] [pid 123784:tid 123816] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSB2WwDnJBNj2tDbYYGYAAAKhs"]
[Tue Aug 18 13:01:29.052990 2026] [security2:error] [pid 123784:tid 123956] [client 20.1.169.243:5344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/google-seo-rank/module.php"] [unique_id "aoSB2WwDnJBNj2tDbYYGYQAAACY"]
[Tue Aug 18 13:01:29.087473 2026] [security2:error] [pid 123784:tid 123978] [client 158.23.17.4:47931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/fn.php"] [unique_id "aoSB2WwDnJBNj2tDbYYGYgAAADw"]
[Tue Aug 18 13:01:29.106841 2026] [security2:error] [pid 139043:tid 139259] [client 20.91.215.254:25818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/f7.php"] [unique_id "aoSB2f2v-lWn9OzQT7UQPAAAANs"]
[Tue Aug 18 13:01:29.123128 2026] [security2:error] [pid 123784:tid 124035] [client 196.12.128.158:55045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGTwAAAHU"]
[Tue Aug 18 13:01:29.127454 2026] [security2:error] [pid 139043:tid 139186] [client 4.232.151.198:40798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/inputs.php"] [unique_id "aoSB2f2v-lWn9OzQT7UQPQAAAJI"]
[Tue Aug 18 13:01:29.183031 2026] [security2:error] [pid 123784:tid 124035] [client 196.12.128.158:55045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGTwAAAHU"]
[Tue Aug 18 13:01:29.186874 2026] [security2:error] [pid 139043:tid 139179] [client 172.202.39.151:44538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSB2f2v-lWn9OzQT7UQPwAAAIs"]
[Tue Aug 18 13:01:29.271639 2026] [security2:error] [pid 123784:tid 123943] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB2WwDnJBNj2tDbYYGZAAAGXc"]
[Tue Aug 18 13:01:29.405363 2026] [security2:error] [pid 123784:tid 123935] [client 20.38.3.247:32593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/82.php"] [unique_id "aoSB2WwDnJBNj2tDbYYGZQAAABE"]
[Tue Aug 18 13:01:29.449027 2026] [autoindex:error] [pid 139043:tid 139139] [remote 34.31.203.120:2496] AH01276: Cannot serve directory /home2/siderurgiabrasil/anuariodasiderurgia.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:29.462760 2026] [security2:error] [pid 123784:tid 124016] [client 20.79.222.117:17997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/puc.php"] [unique_id "aoSB2WwDnJBNj2tDbYYGZgAAAGI"]
[Tue Aug 18 13:01:29.614420 2026] [security2:error] [pid 123784:tid 124022] [client 223.185.37.47:31056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSB2WwDnJBNj2tDbYYGaAAAAGg"]
[Tue Aug 18 13:01:29.614541 2026] [security2:error] [pid 123784:tid 124022] [client 223.185.37.47:31056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSB2WwDnJBNj2tDbYYGaAAAAGg"]
[Tue Aug 18 13:01:29.638401 2026] [security2:error] [pid 139043:tid 139230] [client 68.221.73.131:38499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/site.php"] [unique_id "aoSB2f2v-lWn9OzQT7UQWgAAAL4"]
[Tue Aug 18 13:01:29.662323 2026] [security2:error] [pid 139043:tid 139197] [client 20.151.109.219:14327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/30.php"] [unique_id "aoSB2f2v-lWn9OzQT7UQXAAAAJ0"]
[Tue Aug 18 13:01:29.850056 2026] [security2:error] [pid 139043:tid 139217] [client 168.62.48.100:5630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSB2f2v-lWn9OzQT7UQXwAAALE"]
[Tue Aug 18 13:01:29.891469 2026] [security2:error] [pid 139043:tid 139244] [client 20.206.73.37:29961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/ajax.php"] [unique_id "aoSB2f2v-lWn9OzQT7UQYQAAAMw"]
[Tue Aug 18 13:01:29.924189 2026] [security2:error] [pid 139043:tid 139227] [client 20.79.222.117:18038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/inso.php"] [unique_id "aoSB2f2v-lWn9OzQT7UQYgAAALs"]
[Tue Aug 18 13:01:29.927204 2026] [security2:error] [pid 139043:tid 139295] [client 20.79.204.6:10720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wap.php"] [unique_id "aoSB2f2v-lWn9OzQT7UQYwAAAP8"]
[Tue Aug 18 13:01:29.958962 2026] [security2:error] [pid 139043:tid 139131] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/.github/.env"] [unique_id "aoSB2f2v-lWn9OzQT7UQZwAA8Fc"]
[Tue Aug 18 13:01:30.006934 2026] [security2:error] [pid 139043:tid 139260] [client 20.1.169.243:5337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/h.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQawAAANw"]
[Tue Aug 18 13:01:30.024955 2026] [security2:error] [pid 123784:tid 124020] [client 20.151.109.219:14122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/pu.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGbQAAAGY"]
[Tue Aug 18 13:01:30.077213 2026] [security2:error] [pid 139043:tid 139237] [client 20.104.100.201:49095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/png.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQbQAAAMU"]
[Tue Aug 18 13:01:30.147410 2026] [security2:error] [pid 123784:tid 123855] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGcAAAdEI"]
[Tue Aug 18 13:01:30.148039 2026] [security2:error] [pid 139043:tid 139268] [client 172.202.39.151:4690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-login.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQcgAAAOQ"]
[Tue Aug 18 13:01:30.159433 2026] [security2:error] [pid 139043:tid 139198] [client 20.250.27.191:3612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQcwAAAJ4"]
[Tue Aug 18 13:01:30.161793 2026] [security2:error] [pid 123784:tid 123968] [client 20.65.98.162:31089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/blurbs.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGcgAAADI"]
[Tue Aug 18 13:01:30.262363 2026] [security2:error] [pid 139043:tid 139243] [client 20.65.98.162:56473] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "lavobotafogo.com"] [uri "/.mopj.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQdgAAAMs"]
[Tue Aug 18 13:01:30.292412 2026] [security2:error] [pid 139043:tid 139224] [client 20.80.111.3:17824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/as.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQeQAAALg"]
[Tue Aug 18 13:01:30.300329 2026] [security2:error] [pid 123784:tid 124045] [client 20.250.13.23:6818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/sf.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGdAAAAH8"]
[Tue Aug 18 13:01:30.323255 2026] [security2:error] [pid 123784:tid 123888] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/cah.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGdQAAFWM"]
[Tue Aug 18 13:01:30.369710 2026] [security2:error] [pid 139043:tid 139240] [client 109.122.18.177:54662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dulaomultimarcas.com.br"] [uri "/"] [unique_id "aoSB2v2v-lWn9OzQT7UQjAAAAMg"]
[Tue Aug 18 13:01:30.383173 2026] [security2:error] [pid 123784:tid 123998] [client 20.151.109.219:39296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ry.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGdwAAAFA"]
[Tue Aug 18 13:01:30.403538 2026] [security2:error] [pid 139043:tid 139251] [client 20.1.169.243:5799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/import/csv1.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQjwAAANM"]
[Tue Aug 18 13:01:30.435432 2026] [security2:error] [pid 139043:tid 139185] [client 20.104.100.201:49462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/ab.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQkgAAAJE"]
[Tue Aug 18 13:01:30.441025 2026] [security2:error] [pid 139043:tid 139186] [client 158.23.17.4:29468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/nh.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQkwAAAJI"]
[Tue Aug 18 13:01:30.533019 2026] [security2:error] [pid 123784:tid 123961] [client 213.35.127.232:55256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGewAAACs"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:30.563187 2026] [security2:error] [pid 139043:tid 139238] [client 20.127.136.245:1526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/test1.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQuQAAAMY"]
[Tue Aug 18 13:01:30.570714 2026] [security2:error] [pid 123784:tid 123994] [client 20.250.27.191:43478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/.admin.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGfAAAAEw"]
[Tue Aug 18 13:01:30.574878 2026] [security2:error] [pid 123784:tid 124011] [client 20.75.92.165:4231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGfQAAAF0"]
[Tue Aug 18 13:01:30.583699 2026] [security2:error] [pid 139043:tid 139211] [client 20.102.65.165:8548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/BDKR28WP.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQugAAAKs"]
[Tue Aug 18 13:01:30.593800 2026] [security2:error] [pid 139043:tid 139191] [client 20.80.111.3:31037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/atex1.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQuwAAAJc"]
[Tue Aug 18 13:01:30.636186 2026] [authz_core:error] [pid 123784:tid 123884] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:30.636459 2026] [authz_core:error] [pid 123784:tid 123884] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:30.649732 2026] [security2:error] [pid 123784:tid 123887] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/system_log.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGgQAAfGI"]
[Tue Aug 18 13:01:30.660026 2026] [security2:error] [pid 139043:tid 139247] [client 45.92.229.105:50133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.229.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/profile.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQlAAAAM8"], referer: https://ozzyfernandesoficial.com.br/wp-login.php
[Tue Aug 18 13:01:30.669296 2026] [security2:error] [pid 139043:tid 139197] [client 135.225.78.186:11747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQwQAAAJ0"]
[Tue Aug 18 13:01:30.688852 2026] [security2:error] [pid 139043:tid 139200] [client 20.151.109.219:14273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/pm.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQzgAAAKA"]
[Tue Aug 18 13:01:30.711537 2026] [security2:error] [pid 139043:tid 139258] [client 20.104.100.201:49450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/12.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQzwAAANo"]
[Tue Aug 18 13:01:30.713453 2026] [authz_core:error] [pid 139043:tid 139127] [remote 34.158.8.33:53386] AH01630: client denied by server configuration: /home4/adf/public_html/.htpasswd
[Tue Aug 18 13:01:30.745011 2026] [security2:error] [pid 123784:tid 123955] [client 20.91.215.254:11619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/photo.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGjAAAACU"]
[Tue Aug 18 13:01:30.769088 2026] [security2:error] [pid 139043:tid 139286] [client 20.1.169.243:5803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/index.bak.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQ1QAAAPY"]
[Tue Aug 18 13:01:30.860438 2026] [security2:error] [pid 123784:tid 124001] [client 158.23.17.4:9297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/oo.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGkwAAAFM"]
[Tue Aug 18 13:01:30.883599 2026] [security2:error] [pid 139043:tid 139297] [client 20.186.30.159:9993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQ2QAAAQE"]
[Tue Aug 18 13:01:30.903106 2026] [security2:error] [pid 123784:tid 123981] [client 20.75.92.165:4233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/php.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGmQAAAD8"]
[Tue Aug 18 13:01:30.905158 2026] [security2:error] [pid 139043:tid 139136] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQ3QAA_Vw"]
[Tue Aug 18 13:01:30.907176 2026] [security2:error] [pid 139043:tid 139198] [client 109.122.18.177:54691] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dulaomultimarcas.com.br"] [uri "/"] [unique_id "aoSB2v2v-lWn9OzQT7UQ3gAAAJ4"]
[Tue Aug 18 13:01:30.911055 2026] [security2:error] [pid 139043:tid 139228] [client 20.104.100.201:61436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/yup.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQ3wAAALw"]
[Tue Aug 18 13:01:30.914328 2026] [security2:error] [pid 123784:tid 124043] [client 185.198.240.186:20235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "riobrancoconsultorios.com.br"] [uri "/wp-login.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGmwAAAH0"]
[Tue Aug 18 13:01:30.925676 2026] [security2:error] [pid 139043:tid 139176] [client 20.226.56.190:17871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/conf.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQ4AAAAIg"]
[Tue Aug 18 13:01:30.925895 2026] [security2:error] [pid 123784:tid 124024] [client 20.250.13.23:55970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/chosen.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGnwAAAGo"]
[Tue Aug 18 13:01:30.975107 2026] [security2:error] [pid 123784:tid 123789] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGogAAbgA"]
[Tue Aug 18 13:01:30.986252 2026] [security2:error] [pid 123784:tid 123983] [client 20.104.100.201:49423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/x1da.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGowAAAEE"]
[Tue Aug 18 13:01:31.009137 2026] [security2:error] [pid 139043:tid 139281] [client 20.102.65.165:3020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/coffexium.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ5AAAAPE"]
[Tue Aug 18 13:01:31.020096 2026] [security2:error] [pid 123784:tid 123946] [client 20.250.27.191:45794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wsomini.php"] [unique_id "aoSB22wDnJBNj2tDbYYGpQAAABw"]
[Tue Aug 18 13:01:31.022583 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:31.023017 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:31.023333 2026] [security2:error] [pid 123784:tid 123980] [client 158.23.17.4:55207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/kf.php"] [unique_id "aoSB22wDnJBNj2tDbYYGpgAAAD4"]
[Tue Aug 18 13:01:31.038007 2026] [security2:error] [pid 139043:tid 139178] [client 20.80.111.3:3639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/atomlib.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ5wAAAIo"]
[Tue Aug 18 13:01:31.051983 2026] [security2:error] [pid 123784:tid 124029] [client 20.116.17.175:22935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/cok.php"] [unique_id "aoSB22wDnJBNj2tDbYYGpwAAAG8"]
[Tue Aug 18 13:01:31.054759 2026] [security2:error] [pid 123784:tid 124023] [client 20.151.109.219:60881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/dr.php"] [unique_id "aoSB22wDnJBNj2tDbYYGqAAAAGk"]
[Tue Aug 18 13:01:31.079835 2026] [security2:error] [pid 139043:tid 139255] [client 172.202.39.151:4679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ6AAAANc"]
[Tue Aug 18 13:01:31.082939 2026] [security2:error] [pid 139043:tid 139106] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/0x.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ6QABAD4"]
[Tue Aug 18 13:01:31.109681 2026] [security2:error] [pid 123784:tid 123947] [client 68.221.73.131:35119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/ccc.php"] [unique_id "aoSB22wDnJBNj2tDbYYGqQAAAB0"]
[Tue Aug 18 13:01:31.122022 2026] [security2:error] [pid 139043:tid 139215] [client 20.79.204.6:10690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ6wAAAK8"]
[Tue Aug 18 13:01:31.132748 2026] [security2:error] [pid 123784:tid 123971] [client 20.1.169.243:5814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/lite.php"] [unique_id "aoSB22wDnJBNj2tDbYYGqgAAADU"]
[Tue Aug 18 13:01:31.143310 2026] [security2:error] [pid 139043:tid 139259] [client 213.202.253.4:62598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/txets.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ7AAAANs"], referer: www.google.com
[Tue Aug 18 13:01:31.148647 2026] [security2:error] [pid 123784:tid 123867] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB22wDnJBNj2tDbYYGrAAADU4"]
[Tue Aug 18 13:01:31.197157 2026] [autoindex:error] [pid 123784:tid 124009] [client 169.58.72.248:62363] AH01276: Cannot serve directory /home3/adobankcom/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:31.204329 2026] [security2:error] [pid 139043:tid 139189] [client 20.104.100.201:34250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/222.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ8AAAAJU"]
[Tue Aug 18 13:01:31.213647 2026] [security2:error] [pid 123784:tid 123984] [client 20.186.30.159:9998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSB22wDnJBNj2tDbYYGrwAAAEI"]
[Tue Aug 18 13:01:31.245281 2026] [security2:error] [pid 139043:tid 139246] [client 20.127.136.245:3869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/zwso.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ8QAAAM4"]
[Tue Aug 18 13:01:31.256883 2026] [security2:error] [pid 139043:tid 139133] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/222.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ8gAAx1k"]
[Tue Aug 18 13:01:31.264575 2026] [security2:error] [pid 123784:tid 124033] [client 86.120.159.145:52786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB22wDnJBNj2tDbYYGsAAAAHM"]
[Tue Aug 18 13:01:31.264772 2026] [security2:error] [pid 123784:tid 124033] [client 86.120.159.145:52786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB22wDnJBNj2tDbYYGsAAAAHM"]
[Tue Aug 18 13:01:31.272024 2026] [security2:error] [pid 139043:tid 139177] [client 20.104.100.201:49092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/mcs.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ8wAAAIk"]
[Tue Aug 18 13:01:31.305280 2026] [security2:error] [pid 123784:tid 123803] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/abc.php"] [unique_id "aoSB22wDnJBNj2tDbYYGtQAAXg4"]
[Tue Aug 18 13:01:31.329607 2026] [security2:error] [pid 139043:tid 139243] [client 20.79.204.6:2206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ9QAAAMs"]
[Tue Aug 18 13:01:31.351843 2026] [security2:error] [pid 123784:tid 124041] [client 20.151.109.219:14136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ts.php"] [unique_id "aoSB22wDnJBNj2tDbYYGtgAAAHs"]
[Tue Aug 18 13:01:31.382235 2026] [security2:error] [pid 139043:tid 139258] [client 20.79.222.117:18027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/aa.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ-QAAANo"]
[Tue Aug 18 13:01:31.402374 2026] [security2:error] [pid 139043:tid 139222] [client 168.62.48.100:18015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ_AAAALY"]
[Tue Aug 18 13:01:31.426384 2026] [security2:error] [pid 123784:tid 124007] [client 158.23.17.4:54747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/su.php"] [unique_id "aoSB22wDnJBNj2tDbYYGuQAAAFk"]
[Tue Aug 18 13:01:31.435569 2026] [security2:error] [pid 139043:tid 139188] [client 20.250.27.191:34842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/vr.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ_QAAAJQ"]
[Tue Aug 18 13:01:31.436061 2026] [security2:error] [pid 139043:tid 139138] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/aa.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ_gAAzF4"]
[Tue Aug 18 13:01:31.436683 2026] [security2:error] [pid 123784:tid 123945] [client 20.91.215.254:11647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-aa.php"] [unique_id "aoSB22wDnJBNj2tDbYYGugAAABs"]
[Tue Aug 18 13:01:31.451594 2026] [security2:error] [pid 123784:tid 123970] [client 20.226.112.14:28746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB22wDnJBNj2tDbYYGvAAAADQ"]
[Tue Aug 18 13:01:31.460074 2026] [security2:error] [pid 123784:tid 123929] [client 20.75.92.165:4340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/t.php"] [unique_id "aoSB22wDnJBNj2tDbYYGvQAAAAs"]
[Tue Aug 18 13:01:31.472935 2026] [security2:error] [pid 123784:tid 123814] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/akcc.php"] [unique_id "aoSB22wDnJBNj2tDbYYGvwAAKxk"]
[Tue Aug 18 13:01:31.472988 2026] [security2:error] [pid 123784:tid 123954] [client 20.102.65.165:8569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/sf.php"] [unique_id "aoSB22wDnJBNj2tDbYYGvgAAACQ"]
[Tue Aug 18 13:01:31.473540 2026] [security2:error] [pid 123784:tid 123994] [client 158.23.17.4:8720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ja.php"] [unique_id "aoSB22wDnJBNj2tDbYYGwAAAAEw"]
[Tue Aug 18 13:01:31.477063 2026] [security2:error] [pid 123784:tid 124045] [client 20.80.111.3:33409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/black.php"] [unique_id "aoSB22wDnJBNj2tDbYYGwQAAAH8"]
[Tue Aug 18 13:01:31.497746 2026] [security2:error] [pid 139043:tid 139283] [client 20.1.169.243:5783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/live.php"] [unique_id "aoSB2_2v-lWn9OzQT7URAAAAAPM"]
[Tue Aug 18 13:01:31.508080 2026] [security2:error] [pid 139043:tid 139295] [client 20.104.100.201:34757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-temp.php"] [unique_id "aoSB2_2v-lWn9OzQT7URAQAAAP8"]
[Tue Aug 18 13:01:31.515906 2026] [security2:error] [pid 139043:tid 139173] [client 20.116.17.175:22953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/accesson.php"] [unique_id "aoSB2_2v-lWn9OzQT7URAgAAAIU"]
[Tue Aug 18 13:01:31.533258 2026] [security2:error] [pid 123784:tid 123974] [client 20.102.65.165:3016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSB22wDnJBNj2tDbYYGxAAAADg"]
[Tue Aug 18 13:01:31.540183 2026] [security2:error] [pid 139043:tid 139206] [client 158.23.17.4:63037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/jb.php"] [unique_id "aoSB2_2v-lWn9OzQT7URBQAAAKY"]
[Tue Aug 18 13:01:31.547358 2026] [security2:error] [pid 139043:tid 139276] [client 20.104.100.201:49107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/adminner.php"] [unique_id "aoSB2_2v-lWn9OzQT7URBwAAAOw"]
[Tue Aug 18 13:01:31.548157 2026] [security2:error] [pid 123784:tid 123972] [client 213.35.127.232:56142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSB22wDnJBNj2tDbYYGxQAAADY"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:31.561895 2026] [security2:error] [pid 139043:tid 139294] [client 20.250.13.23:55942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/u.php"] [unique_id "aoSB2_2v-lWn9OzQT7URCQAAAP4"]
[Tue Aug 18 13:01:31.565845 2026] [authz_core:error] [pid 123784:tid 123827] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:31.566277 2026] [authz_core:error] [pid 123784:tid 123827] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:31.568785 2026] [security2:error] [pid 139043:tid 139245] [client 20.226.112.14:22877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB2_2v-lWn9OzQT7URCgAAAM0"]
[Tue Aug 18 13:01:31.576806 2026] [security2:error] [pid 139043:tid 139140] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB2_2v-lWn9OzQT7URCwAAl2A"]
[Tue Aug 18 13:01:31.576993 2026] [security2:error] [pid 139043:tid 139191] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB2_2v-lWn9OzQT7URCwAAl2A"]
[Tue Aug 18 13:01:31.614079 2026] [security2:error] [pid 139043:tid 139131] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/abcd.php"] [unique_id "aoSB2_2v-lWn9OzQT7URDQAAw1c"]
[Tue Aug 18 13:01:31.637540 2026] [security2:error] [pid 123784:tid 123796] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wk/index.php"] [unique_id "aoSB22wDnJBNj2tDbYYGxwAAPQc"]
[Tue Aug 18 13:01:31.648508 2026] [security2:error] [pid 123784:tid 124002] [client 168.62.48.100:18025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSB22wDnJBNj2tDbYYGyAAAAFQ"]
[Tue Aug 18 13:01:31.700570 2026] [security2:error] [pid 139043:tid 139219] [client 20.151.109.219:14302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/53.php"] [unique_id "aoSB2_2v-lWn9OzQT7UREQAAALM"]
[Tue Aug 18 13:01:31.706290 2026] [security2:error] [pid 139043:tid 139154] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSB2_2v-lWn9OzQT7UREgAA5W4"]
[Tue Aug 18 13:01:31.757043 2026] [security2:error] [pid 139043:tid 139224] [client 20.186.30.159:10079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSB2_2v-lWn9OzQT7URFAAAALg"]
[Tue Aug 18 13:01:31.791104 2026] [security2:error] [pid 139043:tid 139155] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/admin.php"] [unique_id "aoSB2_2v-lWn9OzQT7URFQAA8W8"]
[Tue Aug 18 13:01:31.797989 2026] [security2:error] [pid 123784:tid 123849] [remote 20.7.73.61:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/1.php"] [unique_id "aoSB22wDnJBNj2tDbYYGywAAGTw"]
[Tue Aug 18 13:01:31.798069 2026] [security2:error] [pid 123784:tid 123849] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/1.php"] [unique_id "aoSB22wDnJBNj2tDbYYGywAAGTw"]
[Tue Aug 18 13:01:31.805194 2026] [security2:error] [pid 139043:tid 139214] [client 74.7.228.13:41454] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.innacorp.com.br"] [uri "/site/index.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQagAArnE"]
[Tue Aug 18 13:01:31.810434 2026] [security2:error] [pid 123784:tid 123876] [remote 47.128.31.181:18016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "maxxbox.ind.br"] [uri "/"] [unique_id "aoSB22wDnJBNj2tDbYYGzAAAP1c"]
[Tue Aug 18 13:01:31.814641 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:55218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/wp-key.php"] [unique_id "aoSB22wDnJBNj2tDbYYGzQAAAH0"]
[Tue Aug 18 13:01:31.823743 2026] [security2:error] [pid 123784:tid 124015] [client 20.104.100.201:49109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/dragonshell.php"] [unique_id "aoSB22wDnJBNj2tDbYYGzgAAAGE"]
[Tue Aug 18 13:01:31.824967 2026] [security2:error] [pid 123784:tid 123948] [client 20.79.222.117:17941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/img.php"] [unique_id "aoSB22wDnJBNj2tDbYYGzwAAAB4"]
[Tue Aug 18 13:01:31.836837 2026] [security2:error] [pid 139043:tid 139201] [client 20.104.100.201:61425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/spadex.php"] [unique_id "aoSB2_2v-lWn9OzQT7URGAAAAKE"]
[Tue Aug 18 13:01:31.847912 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:31.848188 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:31.858289 2026] [security2:error] [pid 123784:tid 123977] [client 20.65.98.162:27962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/bajah.php"] [unique_id "aoSB22wDnJBNj2tDbYYG0QAAADs"]
[Tue Aug 18 13:01:31.861968 2026] [security2:error] [pid 123784:tid 123989] [client 4.232.151.198:43932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/admin.php"] [unique_id "aoSB22wDnJBNj2tDbYYG0gAAAEc"]
[Tue Aug 18 13:01:31.862098 2026] [security2:error] [pid 139043:tid 139227] [client 20.1.169.243:5318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/bypass.php"] [unique_id "aoSB2_2v-lWn9OzQT7URGgAAALs"]
[Tue Aug 18 13:01:31.871156 2026] [security2:error] [pid 139043:tid 139251] [client 20.226.112.14:32516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ws61.php"] [unique_id "aoSB2_2v-lWn9OzQT7URGwAAANM"]
[Tue Aug 18 13:01:31.876603 2026] [security2:error] [pid 123784:tid 123958] [client 20.127.136.245:18371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/Geforce.php"] [unique_id "aoSB22wDnJBNj2tDbYYG0wAAACg"]
[Tue Aug 18 13:01:31.883520 2026] [security2:error] [pid 139043:tid 139229] [client 20.79.204.6:10382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/bgymj.php"] [unique_id "aoSB2_2v-lWn9OzQT7URHQAAAL0"]
[Tue Aug 18 13:01:31.912574 2026] [security2:error] [pid 123784:tid 124006] [client 20.80.111.3:3613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/bs1.php"] [unique_id "aoSB22wDnJBNj2tDbYYG1AAAAFg"]
[Tue Aug 18 13:01:31.913983 2026] [security2:error] [pid 139043:tid 139240] [client 168.62.48.100:18105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSB2_2v-lWn9OzQT7URHgAAAMg"]
[Tue Aug 18 13:01:31.916374 2026] [security2:error] [pid 139043:tid 139232] [client 20.119.58.187:10533] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "tinoequipamentos.com.br"] [uri "/1.php"] [unique_id "aoSB2_2v-lWn9OzQT7URHwAAAMA"]
[Tue Aug 18 13:01:31.916489 2026] [security2:error] [pid 139043:tid 139232] [client 20.119.58.187:10533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/1.php"] [unique_id "aoSB2_2v-lWn9OzQT7URHwAAAMA"]
[Tue Aug 18 13:01:31.952782 2026] [security2:error] [pid 123784:tid 124035] [client 20.79.204.6:2627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB22wDnJBNj2tDbYYG1gAAAHU"]
[Tue Aug 18 13:01:31.969785 2026] [security2:error] [pid 123784:tid 123893] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSB22wDnJBNj2tDbYYG1wAAH2g"]
[Tue Aug 18 13:01:31.971130 2026] [security2:error] [pid 123784:tid 124039] [client 158.23.17.4:47618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/do.php"] [unique_id "aoSB22wDnJBNj2tDbYYG2AAAAHk"]
[Tue Aug 18 13:01:32.015549 2026] [security2:error] [pid 139043:tid 139189] [client 20.75.92.165:4248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/index/function.php"] [unique_id "aoSB3P2v-lWn9OzQT7URJAAAAJU"]
[Tue Aug 18 13:01:32.032110 2026] [security2:error] [pid 123784:tid 124029] [client 20.102.65.165:3032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/sf.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG2gAAAG8"]
[Tue Aug 18 13:01:32.033346 2026] [security2:error] [pid 123784:tid 124030] [client 20.119.58.187:10440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/2.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG2wAAAHA"]
[Tue Aug 18 13:01:32.034207 2026] [security2:error] [pid 123784:tid 124023] [client 158.23.17.4:8736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/xx.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG3AAAAGk"]
[Tue Aug 18 13:01:32.051928 2026] [security2:error] [pid 139043:tid 139239] [client 20.226.112.14:22975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/rum.php"] [unique_id "aoSB3P2v-lWn9OzQT7URJQAAAMc"]
[Tue Aug 18 13:01:32.054715 2026] [security2:error] [pid 139043:tid 139204] [client 20.102.65.165:8555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/k.php"] [unique_id "aoSB3P2v-lWn9OzQT7URJgAAAKQ"]
[Tue Aug 18 13:01:32.078994 2026] [security2:error] [pid 123784:tid 123971] [client 20.151.109.219:60925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/lq.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG3gAAADU"]
[Tue Aug 18 13:01:32.086476 2026] [security2:error] [pid 123784:tid 123920] [client 20.91.215.254:11629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/d.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG3wAAAAI"]
[Tue Aug 18 13:01:32.097696 2026] [security2:error] [pid 123784:tid 123999] [client 20.104.100.201:49408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/setup-config.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG4AAAAFE"]
[Tue Aug 18 13:01:32.117904 2026] [security2:error] [pid 139043:tid 139220] [client 68.221.73.131:33030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/admin.php"] [unique_id "aoSB3P2v-lWn9OzQT7URKAAAALQ"]
[Tue Aug 18 13:01:32.134483 2026] [security2:error] [pid 123784:tid 123869] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG4gAAVVA"]
[Tue Aug 18 13:01:32.139749 2026] [security2:error] [pid 139043:tid 139164] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSB3P2v-lWn9OzQT7URKQAA6Hg"]
[Tue Aug 18 13:01:32.140271 2026] [security2:error] [pid 139043:tid 139256] [client 20.104.100.201:34794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSB3P2v-lWn9OzQT7URKgAAANg"]
[Tue Aug 18 13:01:32.152892 2026] [security2:error] [pid 123784:tid 123987] [client 20.48.236.86:14474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/yj09.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG5QAAAEU"]
[Tue Aug 18 13:01:32.154140 2026] [authz_core:error] [pid 123784:tid 123812] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:32.154397 2026] [authz_core:error] [pid 123784:tid 123812] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:32.215466 2026] [security2:error] [pid 139043:tid 139193] [client 20.226.112.14:32541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ze.php"] [unique_id "aoSB3P2v-lWn9OzQT7URLQAAAJk"]
[Tue Aug 18 13:01:32.271000 2026] [security2:error] [pid 123784:tid 123986] [client 20.65.98.162:45599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/bengi.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG6AAAAEQ"]
[Tue Aug 18 13:01:32.274688 2026] [security2:error] [pid 123784:tid 123939] [client 20.79.204.6:11529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG6QAAABU"]
[Tue Aug 18 13:01:32.283314 2026] [security2:error] [pid 123784:tid 123835] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/as.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG6gAAey4"]
[Tue Aug 18 13:01:32.294045 2026] [security2:error] [pid 139043:tid 139244] [client 20.116.17.175:22992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/av.php"] [unique_id "aoSB3P2v-lWn9OzQT7URLwAAAMw"]
[Tue Aug 18 13:01:32.303851 2026] [security2:error] [pid 123784:tid 123950] [client 20.79.222.117:17945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/222.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG6wAAACA"]
[Tue Aug 18 13:01:32.335504 2026] [security2:error] [pid 123784:tid 123997] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG7AAAAE8"]
[Tue Aug 18 13:01:32.351439 2026] [security2:error] [pid 123784:tid 123924] [client 20.1.169.243:5320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/lock360.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG7QAAAAY"]
[Tue Aug 18 13:01:32.355650 2026] [security2:error] [pid 123784:tid 124007] [client 20.151.109.219:39319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/you.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG7gAAAFk"]
[Tue Aug 18 13:01:32.357972 2026] [security2:error] [pid 139043:tid 139238] [client 4.232.94.69:14471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/class-IXR-encryption.php"] [unique_id "aoSB3P2v-lWn9OzQT7URNAAAAMY"]
[Tue Aug 18 13:01:32.359583 2026] [security2:error] [pid 139043:tid 139181] [client 20.80.111.3:3628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/colors/blue/about.php"] [unique_id "aoSB3P2v-lWn9OzQT7URNQAAAI0"]
[Tue Aug 18 13:01:32.374856 2026] [security2:error] [pid 139043:tid 139295] [client 20.104.100.201:49471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/f35.update.php"] [unique_id "aoSB3P2v-lWn9OzQT7UROAAAAP8"]
[Tue Aug 18 13:01:32.386631 2026] [security2:error] [pid 123784:tid 124012] [client 20.119.58.187:10492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/7.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG7wAAAF4"]
[Tue Aug 18 13:01:32.392345 2026] [security2:error] [pid 139043:tid 139175] [client 168.62.48.100:5605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSB3P2v-lWn9OzQT7UROQAAAIc"]
[Tue Aug 18 13:01:32.416818 2026] [security2:error] [pid 139043:tid 139280] [client 168.62.48.100:18123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSB3P2v-lWn9OzQT7UROwAAAPA"]
[Tue Aug 18 13:01:32.429231 2026] [security2:error] [pid 139043:tid 139226] [client 20.104.100.201:61967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/srontol.php"] [unique_id "aoSB3P2v-lWn9OzQT7URPAAAALo"]
[Tue Aug 18 13:01:32.437629 2026] [security2:error] [pid 123784:tid 123875] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG8wAAC1Y"]
[Tue Aug 18 13:01:32.449593 2026] [security2:error] [pid 139043:tid 139210] [client 20.102.65.165:2952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/k.php"] [unique_id "aoSB3P2v-lWn9OzQT7URPQAAAKo"]
[Tue Aug 18 13:01:32.469577 2026] [security2:error] [pid 139043:tid 139285] [client 74.7.228.13:41470] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "innacorp.com.br"] [uri "/site/index.php"] [unique_id "aoSB3P2v-lWn9OzQT7URMAAA9Qo"], referer: https://www.innacorp.com.br/robots.txt
[Tue Aug 18 13:01:32.482227 2026] [security2:error] [pid 139043:tid 139276] [client 158.23.17.4:11401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/yw.php"] [unique_id "aoSB3P2v-lWn9OzQT7URPwAAAOw"]
[Tue Aug 18 13:01:32.491428 2026] [security2:error] [pid 139043:tid 139052] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB3P2v-lWn9OzQT7URQAAAygg"]
[Tue Aug 18 13:01:32.493485 2026] [security2:error] [pid 123784:tid 124044] [client 20.186.30.159:10095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/xx.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG9gAAAH4"]
[Tue Aug 18 13:01:32.493595 2026] [security2:error] [pid 139043:tid 139294] [client 20.226.112.14:28771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/gjm.php"] [unique_id "aoSB3P2v-lWn9OzQT7URQQAAAP4"]
[Tue Aug 18 13:01:32.512445 2026] [security2:error] [pid 139043:tid 139297] [client 20.226.56.190:28279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/bala.php"] [unique_id "aoSB3P2v-lWn9OzQT7URQgAAAQE"]
[Tue Aug 18 13:01:32.521769 2026] [security2:error] [pid 139043:tid 139051] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/id_rsa"] [unique_id "aoSB3P2v-lWn9OzQT7URQwAAkAc"]
[Tue Aug 18 13:01:32.535249 2026] [security2:error] [pid 123784:tid 124008] [client 216.244.66.232:37430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG-QAAAFo"]
[Tue Aug 18 13:01:32.535361 2026] [security2:error] [pid 123784:tid 124008] [client 216.244.66.232:37430] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG-QAAAFo"]
[Tue Aug 18 13:01:32.545638 2026] [security2:error] [pid 123784:tid 124025] [client 158.23.17.4:17566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/gg.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG-gAAAGs"]
[Tue Aug 18 13:01:32.556473 2026] [security2:error] [pid 123784:tid 123945] [client 20.79.204.6:2202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG_QAAABs"]
[Tue Aug 18 13:01:32.563214 2026] [security2:error] [pid 139043:tid 139275] [client 213.35.127.232:56367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSB3P2v-lWn9OzQT7URRAAAAOs"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:32.575501 2026] [security2:error] [pid 139043:tid 139228] [client 20.250.13.23:55941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/customize.php"] [unique_id "aoSB3P2v-lWn9OzQT7URRQAAALw"]
[Tue Aug 18 13:01:32.588143 2026] [security2:error] [pid 123784:tid 123793] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHAAAAMwQ"]
[Tue Aug 18 13:01:32.614319 2026] [security2:error] [pid 139043:tid 139198] [client 20.75.92.165:4311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wk/index.php"] [unique_id "aoSB3P2v-lWn9OzQT7URRgAAAJ4"]
[Tue Aug 18 13:01:32.639261 2026] [security2:error] [pid 139043:tid 139187] [client 197.184.64.235:41963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3P2v-lWn9OzQT7URRwAAAJM"]
[Tue Aug 18 13:01:32.649884 2026] [security2:error] [pid 139043:tid 139203] [client 20.104.100.201:49455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/bdroot.php"] [unique_id "aoSB3P2v-lWn9OzQT7URSAAAAKM"]
[Tue Aug 18 13:01:32.656881 2026] [security2:error] [pid 139043:tid 139156] [remote 110.249.201.61:50556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "germania.com.br"] [uri "/Estofados_Germania_Igualdade_02.pdf"] [unique_id "aoSB3P2v-lWn9OzQT7URSQAA-3A"]
[Tue Aug 18 13:01:32.658081 2026] [security2:error] [pid 139043:tid 139225] [client 20.151.109.219:14265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ez.php"] [unique_id "aoSB3P2v-lWn9OzQT7URSgAAALk"]
[Tue Aug 18 13:01:32.667394 2026] [security2:error] [pid 139043:tid 139214] [client 135.225.78.186:64528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB3P2v-lWn9OzQT7URTAAAAK4"]
[Tue Aug 18 13:01:32.667590 2026] [security2:error] [pid 139043:tid 139059] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/akc.php"] [unique_id "aoSB3P2v-lWn9OzQT7URSwAAoQ8"]
[Tue Aug 18 13:01:32.683141 2026] [security2:error] [pid 139043:tid 139255] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSB3P2v-lWn9OzQT7URTQAAANc"]
[Tue Aug 18 13:01:32.703653 2026] [security2:error] [pid 123784:tid 124010] [client 168.62.48.100:18052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHBwAAAFw"]
[Tue Aug 18 13:01:32.716949 2026] [security2:error] [pid 123784:tid 123978] [client 20.79.222.117:18033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/key.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHCAAAADw"]
[Tue Aug 18 13:01:32.718170 2026] [security2:error] [pid 139043:tid 139299] [client 20.226.112.14:28760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/new4.php"] [unique_id "aoSB3P2v-lWn9OzQT7URTwAAAQM"]
[Tue Aug 18 13:01:32.738769 2026] [security2:error] [pid 139043:tid 139248] [client 20.119.58.187:10162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/10.php"] [unique_id "aoSB3P2v-lWn9OzQT7URUgAAANA"]
[Tue Aug 18 13:01:32.739625 2026] [security2:error] [pid 139043:tid 139284] [client 20.127.136.245:22172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/fpwch.php"] [unique_id "aoSB3P2v-lWn9OzQT7URUwAAAPQ"]
[Tue Aug 18 13:01:32.743620 2026] [security2:error] [pid 123784:tid 123851] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHCQAAUz4"]
[Tue Aug 18 13:01:32.747150 2026] [security2:error] [pid 139043:tid 139229] [client 20.104.100.201:62004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/file5.php"] [unique_id "aoSB3P2v-lWn9OzQT7URVAAAAL0"]
[Tue Aug 18 13:01:32.757647 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:32.758105 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:32.758592 2026] [security2:error] [pid 139043:tid 139215] [client 20.79.204.6:11696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/ioxi-o.php"] [unique_id "aoSB3P2v-lWn9OzQT7URVQAAAK8"]
[Tue Aug 18 13:01:32.777082 2026] [security2:error] [pid 139043:tid 139168] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/id_dsa"] [unique_id "aoSB3P2v-lWn9OzQT7URVwAAwHw"]
[Tue Aug 18 13:01:32.796975 2026] [security2:error] [pid 123784:tid 123979] [client 20.100.169.31:4981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHCwAAAD0"]
[Tue Aug 18 13:01:32.797553 2026] [security2:error] [pid 139043:tid 139205] [client 20.226.112.14:32555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-act.php"] [unique_id "aoSB3P2v-lWn9OzQT7URWQAAAKU"]
[Tue Aug 18 13:01:32.798903 2026] [security2:error] [pid 139043:tid 139281] [client 20.80.111.3:2027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/con7.php"] [unique_id "aoSB3P2v-lWn9OzQT7URWgAAAPE"]
[Tue Aug 18 13:01:32.805368 2026] [security2:error] [pid 123784:tid 123943] [client 20.102.65.165:3069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/82.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHDAAAABk"]
[Tue Aug 18 13:01:32.806395 2026] [security2:error] [pid 123784:tid 124043] [client 68.221.73.131:18779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/reviall.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHDQAAAH0"]
[Tue Aug 18 13:01:32.811326 2026] [security2:error] [pid 139043:tid 139269] [client 20.91.215.254:27133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-includes/widgets.php"] [unique_id "aoSB3P2v-lWn9OzQT7URWwAAAOU"]
[Tue Aug 18 13:01:32.824959 2026] [security2:error] [pid 139043:tid 139246] [client 20.102.65.165:8458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/82.php"] [unique_id "aoSB3P2v-lWn9OzQT7URXQAAAM4"]
[Tue Aug 18 13:01:32.829331 2026] [security2:error] [pid 139043:tid 139253] [client 20.226.112.14:22964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/grsiuk.php"] [unique_id "aoSB3P2v-lWn9OzQT7URXgAAANU"]
[Tue Aug 18 13:01:32.841699 2026] [security2:error] [pid 139043:tid 139081] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/buy.php"] [unique_id "aoSB3P2v-lWn9OzQT7URXwAAvyU"]
[Tue Aug 18 13:01:32.850568 2026] [security2:error] [pid 139043:tid 139204] [client 20.1.169.243:5313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/majalahpro-core/lib/index.php"] [unique_id "aoSB3P2v-lWn9OzQT7URYgAAAKQ"]
[Tue Aug 18 13:01:32.876093 2026] [security2:error] [pid 139043:tid 139212] [client 20.79.204.6:11555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/0x.php"] [unique_id "aoSB3P2v-lWn9OzQT7URZAAAAKw"]
[Tue Aug 18 13:01:32.904919 2026] [security2:error] [pid 123784:tid 123842] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHEwAAKDU"]
[Tue Aug 18 13:01:32.906117 2026] [security2:error] [pid 123784:tid 124028] [client 20.65.98.162:57022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/h.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHFAAAAG4"]
[Tue Aug 18 13:01:32.920842 2026] [security2:error] [pid 123784:tid 124031] [client 47.128.42.236:60528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "designacao2022.cabeceiragrandemg.com.br"] [uri "/robots.txt"] [unique_id "aoSB3GwDnJBNj2tDbYYHFQAAAHE"]
[Tue Aug 18 13:01:32.923214 2026] [security2:error] [pid 123784:tid 124006] [client 20.226.112.14:28591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/h.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHFgAAAFg"]
[Tue Aug 18 13:01:32.929671 2026] [security2:error] [pid 123784:tid 123983] [client 20.104.100.201:49434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-temp.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHFwAAAEE"]
[Tue Aug 18 13:01:32.938323 2026] [security2:error] [pid 123784:tid 124039] [client 20.151.109.219:60871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/asus.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHGAAAAHk"]
[Tue Aug 18 13:01:32.963870 2026] [security2:error] [pid 123784:tid 124016] [client 20.186.30.159:10048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/av.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHGQAAAGI"]
[Tue Aug 18 13:01:32.966290 2026] [security2:error] [pid 123784:tid 123946] [client 20.48.236.86:14509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/scxy.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHGgAAABw"]
[Tue Aug 18 13:01:32.971751 2026] [security2:error] [pid 139043:tid 139188] [client 20.75.92.165:4307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-blink.php"] [unique_id "aoSB3P2v-lWn9OzQT7URZgAAAJQ"]
[Tue Aug 18 13:01:32.979973 2026] [security2:error] [pid 139043:tid 139241] [client 168.62.48.100:18065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/well-known/index.php"] [unique_id "aoSB3P2v-lWn9OzQT7URZwAAAMk"]
[Tue Aug 18 13:01:33.001193 2026] [security2:error] [pid 123784:tid 124004] [client 20.226.112.14:28602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/koiy.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHGwAAAFY"]
[Tue Aug 18 13:01:33.003134 2026] [security2:error] [pid 139043:tid 139187] [client 197.184.64.235:41963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3P2v-lWn9OzQT7URRwAAAJM"]
[Tue Aug 18 13:01:33.019315 2026] [security2:error] [pid 139043:tid 139097] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/cong.php"] [unique_id "aoSB3f2v-lWn9OzQT7URaAAAjTU"]
[Tue Aug 18 13:01:33.052728 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:33.053014 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:33.067685 2026] [security2:error] [pid 139043:tid 139280] [client 20.116.17.175:55249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/kj.php"] [unique_id "aoSB3f2v-lWn9OzQT7URagAAAPA"]
[Tue Aug 18 13:01:33.069827 2026] [security2:error] [pid 139043:tid 139226] [client 158.23.17.4:51171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/gi.php"] [unique_id "aoSB3f2v-lWn9OzQT7URawAAALo"]
[Tue Aug 18 13:01:33.089878 2026] [security2:error] [pid 139043:tid 139244] [client 20.119.58.187:10114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/13.php"] [unique_id "aoSB3f2v-lWn9OzQT7URbAAAAMw"]
[Tue Aug 18 13:01:33.090264 2026] [security2:error] [pid 139043:tid 139285] [client 20.102.65.165:3014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/dex.php"] [unique_id "aoSB3f2v-lWn9OzQT7URbQAAAPU"]
[Tue Aug 18 13:01:33.117428 2026] [security2:error] [pid 123784:tid 123944] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/xmr.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHIAAAABo"]
[Tue Aug 18 13:01:33.128748 2026] [security2:error] [pid 139043:tid 139286] [client 5.161.75.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jlypiscinas.com.br"] [uri "/index.php"] [unique_id "aoSB2_2v-lWn9OzQT7URAwAA9mU"], referer: https://jlypiscinas.com.br/
[Tue Aug 18 13:01:33.131619 2026] [security2:error] [pid 139043:tid 139206] [client 103.120.71.157:26173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3f2v-lWn9OzQT7URcAAAAKY"]
[Tue Aug 18 13:01:33.131759 2026] [security2:error] [pid 139043:tid 139206] [client 103.120.71.157:26173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3f2v-lWn9OzQT7URcAAAAKY"]
[Tue Aug 18 13:01:33.162411 2026] [security2:error] [pid 123784:tid 124020] [client 20.104.100.201:61411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/yup.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHIgAAAGY"]
[Tue Aug 18 13:01:33.164825 2026] [authz_core:error] [pid 123784:tid 123850] [remote 57.141.22.30:61218] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:33.165101 2026] [authz_core:error] [pid 123784:tid 123850] [remote 57.141.22.30:61218] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:33.168366 2026] [security2:error] [pid 139043:tid 139294] [client 20.79.222.117:18014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/chosen.php"] [unique_id "aoSB3f2v-lWn9OzQT7URdAAAAP4"]
[Tue Aug 18 13:01:33.169090 2026] [security2:error] [pid 139043:tid 139263] [client 20.79.204.6:11543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/0x.php"] [unique_id "aoSB3f2v-lWn9OzQT7URdQAAAN8"]
[Tue Aug 18 13:01:33.177954 2026] [autoindex:error] [pid 139043:tid 139193] [client 20.79.204.6:2220] AH01276: Cannot serve directory /home3/brto26/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:33.193355 2026] [security2:error] [pid 139043:tid 139058] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSB3f2v-lWn9OzQT7URdwAA3A4"]
[Tue Aug 18 13:01:33.205247 2026] [security2:error] [pid 139043:tid 139278] [client 20.104.100.201:49094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-css.php"] [unique_id "aoSB3f2v-lWn9OzQT7UReQAAAO4"]
[Tue Aug 18 13:01:33.209282 2026] [security2:error] [pid 139043:tid 139107] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/key.pem"] [unique_id "aoSB3f2v-lWn9OzQT7URegAAkD8"]
[Tue Aug 18 13:01:33.213623 2026] [security2:error] [pid 139043:tid 139276] [client 20.1.169.243:5316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/pwnd/as.php"] [unique_id "aoSB3f2v-lWn9OzQT7URewAAAOw"]
[Tue Aug 18 13:01:33.222545 2026] [security2:error] [pid 123784:tid 123805] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHJAAAMhA"]
[Tue Aug 18 13:01:33.231253 2026] [security2:error] [pid 123784:tid 124033] [client 20.226.112.14:13666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/fff.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHJQAAAHM"]
[Tue Aug 18 13:01:33.233584 2026] [security2:error] [pid 139043:tid 139210] [client 20.80.111.3:18452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/contact-form-7/includes/js/jquery-ui/themes/smoothness/RxRywmgzyK.php"] [unique_id "aoSB3f2v-lWn9OzQT7URfAAAAKo"]
[Tue Aug 18 13:01:33.308026 2026] [security2:error] [pid 139043:tid 139075] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/privatekey.key"] [unique_id "aoSB3f2v-lWn9OzQT7URfgAA6R8"]
[Tue Aug 18 13:01:33.308810 2026] [security2:error] [pid 123784:tid 123948] [client 149.34.210.141:57935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHJwAAAB4"]
[Tue Aug 18 13:01:33.324021 2026] [security2:error] [pid 139043:tid 139261] [client 20.75.92.165:4271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/xfun.php"] [unique_id "aoSB3f2v-lWn9OzQT7URfwAAAN0"]
[Tue Aug 18 13:01:33.333681 2026] [security2:error] [pid 139043:tid 139176] [client 168.62.48.100:18098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSB3f2v-lWn9OzQT7URgAAAAIg"]
[Tue Aug 18 13:01:33.354209 2026] [security2:error] [pid 123784:tid 123934] [client 20.186.30.159:9995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/media.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHLAAAABA"]
[Tue Aug 18 13:01:33.360821 2026] [security2:error] [pid 139043:tid 139257] [client 20.151.109.219:60398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/22.php"] [unique_id "aoSB3f2v-lWn9OzQT7URggAAANk"]
[Tue Aug 18 13:01:33.368273 2026] [security2:error] [pid 139043:tid 139083] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/db.php"] [unique_id "aoSB3f2v-lWn9OzQT7URgwAA1yc"]
[Tue Aug 18 13:01:33.392393 2026] [security2:error] [pid 123784:tid 124007] [client 68.221.73.131:21952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/nope.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHLQAAAFk"]
[Tue Aug 18 13:01:33.409051 2026] [security2:error] [pid 139043:tid 139248] [client 20.250.13.23:55938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/mah/function.php"] [unique_id "aoSB3f2v-lWn9OzQT7URhQAAANA"]
[Tue Aug 18 13:01:33.412971 2026] [security2:error] [pid 123784:tid 123898] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/an.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHLgAAXm0"]
[Tue Aug 18 13:01:33.423148 2026] [security2:error] [pid 123784:tid 123957] [client 20.226.112.14:22904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/pouhg.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHLwAAACc"]
[Tue Aug 18 13:01:33.424044 2026] [security2:error] [pid 139043:tid 139298] [client 20.100.169.31:4318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB3f2v-lWn9OzQT7URhgAAAQI"]
[Tue Aug 18 13:01:33.435777 2026] [security2:error] [pid 123784:tid 123959] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/about.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHMAAAACk"]
[Tue Aug 18 13:01:33.442159 2026] [security2:error] [pid 123784:tid 123975] [client 20.119.58.187:10125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/100.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHMQAAADk"]
[Tue Aug 18 13:01:33.449011 2026] [security2:error] [pid 123784:tid 123954] [client 20.102.65.165:8532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/dex.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHNQAAACQ"]
[Tue Aug 18 13:01:33.465219 2026] [security2:error] [pid 123784:tid 123953] [client 20.91.215.254:25804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHOAAAACM"]
[Tue Aug 18 13:01:33.475758 2026] [security2:error] [pid 123784:tid 124044] [client 20.104.100.201:61428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHQgAAAH4"]
[Tue Aug 18 13:01:33.478016 2026] [security2:error] [pid 139043:tid 139179] [client 20.104.100.201:49105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/flox.php"] [unique_id "aoSB3f2v-lWn9OzQT7URiAAAAIs"]
[Tue Aug 18 13:01:33.482289 2026] [security2:error] [pid 139043:tid 139279] [client 20.79.204.6:11559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/222.php"] [unique_id "aoSB3f2v-lWn9OzQT7URiQAAAO8"]
[Tue Aug 18 13:01:33.492539 2026] [security2:error] [pid 123784:tid 123972] [client 20.206.73.37:34790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/yj09.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHSAAAADY"]
[Tue Aug 18 13:01:33.506307 2026] [security2:error] [pid 123784:tid 123967] [client 20.102.65.165:3037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/puc.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHSQAAADE"]
[Tue Aug 18 13:01:33.526989 2026] [security2:error] [pid 123784:tid 123945] [client 20.226.112.14:32523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/moon3.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHSgAAABs"]
[Tue Aug 18 13:01:33.542512 2026] [security2:error] [pid 139043:tid 139061] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/dropdown.php"] [unique_id "aoSB3f2v-lWn9OzQT7URjQAAjBE"]
[Tue Aug 18 13:01:33.571245 2026] [security2:error] [pid 123784:tid 123933] [client 20.79.204.6:10368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/aa.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHTgAAAA8"]
[Tue Aug 18 13:01:33.578418 2026] [security2:error] [pid 139043:tid 139232] [client 20.1.169.243:5787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/rk2.php"] [unique_id "aoSB3f2v-lWn9OzQT7URjwAAAMA"]
[Tue Aug 18 13:01:33.587348 2026] [security2:error] [pid 123784:tid 123948] [client 149.34.210.141:57935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHJwAAAB4"]
[Tue Aug 18 13:01:33.595950 2026] [security2:error] [pid 139043:tid 139236] [client 213.35.127.232:56590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSB3f2v-lWn9OzQT7URkQAAAMQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:33.597388 2026] [security2:error] [pid 139043:tid 139253] [client 168.62.48.100:18008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSB3f2v-lWn9OzQT7URkgAAANU"]
[Tue Aug 18 13:01:33.613937 2026] [security2:error] [pid 123784:tid 124011] [client 20.79.222.117:17942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/wpxml.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHUQAAAF0"]
[Tue Aug 18 13:01:33.618410 2026] [security2:error] [pid 123784:tid 123981] [client 158.23.17.4:47880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/pz.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHUgAAAD8"]
[Tue Aug 18 13:01:33.628486 2026] [security2:error] [pid 123784:tid 124032] [client 20.186.30.159:10027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/images.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHUwAAAHI"]
[Tue Aug 18 13:01:33.672717 2026] [security2:error] [pid 123784:tid 123991] [client 158.23.17.4:14061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/qh.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHVQAAAEk"]
[Tue Aug 18 13:01:33.673646 2026] [security2:error] [pid 123784:tid 124025] [client 20.80.111.3:39565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/dist/alfa-rex.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHVgAAAGs"]
[Tue Aug 18 13:01:33.689873 2026] [security2:error] [pid 123784:tid 123964] [client 138.36.100.162:43152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHVwAAAC4"]
[Tue Aug 18 13:01:33.690012 2026] [security2:error] [pid 123784:tid 123964] [client 138.36.100.162:43152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHVwAAAC4"]
[Tue Aug 18 13:01:33.724320 2026] [security2:error] [pid 139043:tid 139213] [client 20.151.109.219:60369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/zs.php"] [unique_id "aoSB3f2v-lWn9OzQT7URmAAAAK0"]
[Tue Aug 18 13:01:33.724805 2026] [security2:error] [pid 123784:tid 123910] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/404.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHWAAAEnk"]
[Tue Aug 18 13:01:33.751440 2026] [security2:error] [pid 139043:tid 139087] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/file.php"] [unique_id "aoSB3f2v-lWn9OzQT7URmQAA2is"]
[Tue Aug 18 13:01:33.752935 2026] [security2:error] [pid 139043:tid 139266] [client 20.104.100.201:49445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/op.php"] [unique_id "aoSB3f2v-lWn9OzQT7URmgAAAOI"]
[Tue Aug 18 13:01:33.755993 2026] [security2:error] [pid 139043:tid 139192] [client 20.116.17.175:54856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/makeasmtp.php"] [unique_id "aoSB3f2v-lWn9OzQT7URnAAAAJg"]
[Tue Aug 18 13:01:33.756092 2026] [security2:error] [pid 123784:tid 124031] [client 172.202.39.151:52876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-admin/user/index.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHWQAAAHE"]
[Tue Aug 18 13:01:33.773813 2026] [security2:error] [pid 123784:tid 123963] [client 20.79.204.6:12240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/222.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHWgAAAC0"]
[Tue Aug 18 13:01:33.787828 2026] [security2:error] [pid 123784:tid 124039] [client 20.226.112.14:32574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/opts.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHWwAAAHk"]
[Tue Aug 18 13:01:33.792124 2026] [security2:error] [pid 139043:tid 139252] [client 20.75.92.165:4229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/p.php"] [unique_id "aoSB3f2v-lWn9OzQT7URnQAAANQ"]
[Tue Aug 18 13:01:33.794955 2026] [security2:error] [pid 139043:tid 139243] [client 20.119.58.187:10153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/222.php"] [unique_id "aoSB3f2v-lWn9OzQT7URngAAAMs"]
[Tue Aug 18 13:01:33.797381 2026] [security2:error] [pid 139043:tid 139209] [client 20.104.100.201:34288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-the.php"] [unique_id "aoSB3f2v-lWn9OzQT7URnwAAAKk"]
[Tue Aug 18 13:01:33.803552 2026] [security2:error] [pid 123784:tid 123946] [client 20.118.133.132:15656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/bengi.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHXQAAABw"]
[Tue Aug 18 13:01:33.816940 2026] [security2:error] [pid 123784:tid 124004] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/admin.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHXgAAAFY"]
[Tue Aug 18 13:01:33.823557 2026] [security2:error] [pid 139043:tid 139270] [client 178.153.171.161:55736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3f2v-lWn9OzQT7URogAAAOY"]
[Tue Aug 18 13:01:33.823675 2026] [security2:error] [pid 139043:tid 139270] [client 178.153.171.161:55736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3f2v-lWn9OzQT7URogAAAOY"]
[Tue Aug 18 13:01:33.855110 2026] [security2:error] [pid 123784:tid 123927] [client 20.102.65.165:3041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/inso.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHYAAAAAk"]
[Tue Aug 18 13:01:33.884709 2026] [security2:error] [pid 123784:tid 123806] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-login.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHYQAANRE"]
[Tue Aug 18 13:01:33.914352 2026] [security2:error] [pid 123784:tid 123962] [client 20.163.43.14:8836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/gecko-new.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHYgAAACw"]
[Tue Aug 18 13:01:33.926586 2026] [security2:error] [pid 139043:tid 139078] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/goods.php"] [unique_id "aoSB3f2v-lWn9OzQT7URpwAA9iI"]
[Tue Aug 18 13:01:33.926769 2026] [security2:error] [pid 123784:tid 124018] [client 168.62.48.100:5631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHZAAAAGQ"]
[Tue Aug 18 13:01:33.935663 2026] [security2:error] [pid 139043:tid 139263] [client 168.62.48.100:17987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSB3f2v-lWn9OzQT7URqAAAAN8"]
[Tue Aug 18 13:01:33.943009 2026] [security2:error] [pid 139043:tid 139288] [client 20.1.169.243:5778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/storage/rip.php"] [unique_id "aoSB3f2v-lWn9OzQT7URqQAAAPg"]
[Tue Aug 18 13:01:33.955454 2026] [authz_core:error] [pid 123784:tid 123838] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:33.955734 2026] [authz_core:error] [pid 123784:tid 123838] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:33.969549 2026] [security2:error] [pid 139043:tid 139260] [client 172.202.39.151:4713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wso.php"] [unique_id "aoSB3f2v-lWn9OzQT7URqwAAANw"]
[Tue Aug 18 13:01:33.976424 2026] [security2:error] [pid 139043:tid 139228] [client 62.113.113.162:63441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.113.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSB3f2v-lWn9OzQT7URoAAAALw"], referer: https://orientaldistribuidora.com.br/
[Tue Aug 18 13:01:34.004866 2026] [security2:error] [pid 139043:tid 139278] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB3v2v-lWn9OzQT7URrQAAAO4"]
[Tue Aug 18 13:01:34.031803 2026] [security2:error] [pid 123784:tid 124033] [client 20.151.109.219:60926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/iz.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHZwAAAHM"]
[Tue Aug 18 13:01:34.033652 2026] [security2:error] [pid 139043:tid 139235] [client 20.104.100.201:49089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/1xmomo.php"] [unique_id "aoSB3v2v-lWn9OzQT7URrgAAAMM"]
[Tue Aug 18 13:01:34.038056 2026] [security2:error] [pid 139043:tid 139221] [client 20.79.222.117:17920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/file1221.php"] [unique_id "aoSB3v2v-lWn9OzQT7URrwAAALU"]
[Tue Aug 18 13:01:34.038347 2026] [security2:error] [pid 123784:tid 123915] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHagAAFn4"]
[Tue Aug 18 13:01:34.059844 2026] [security2:error] [pid 139043:tid 139238] [client 20.250.13.23:6819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/filter.php"] [unique_id "aoSB3v2v-lWn9OzQT7URsAAAAMY"]
[Tue Aug 18 13:01:34.062352 2026] [security2:error] [pid 139043:tid 139273] [client 20.226.112.14:13646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/zwq13.php"] [unique_id "aoSB3v2v-lWn9OzQT7URsQAAAOk"]
[Tue Aug 18 13:01:34.079604 2026] [security2:error] [pid 123784:tid 123990] [client 158.158.74.177:9271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHawAAAEg"]
[Tue Aug 18 13:01:34.088953 2026] [security2:error] [pid 123784:tid 123950] [client 20.186.30.159:10020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/mac.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHbAAAACA"]
[Tue Aug 18 13:01:34.091491 2026] [security2:error] [pid 139043:tid 139268] [client 20.104.100.201:34797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSB3v2v-lWn9OzQT7URswAAAOQ"]
[Tue Aug 18 13:01:34.092765 2026] [security2:error] [pid 139043:tid 139203] [client 158.23.17.4:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/kk.php"] [unique_id "aoSB3v2v-lWn9OzQT7URtAAAAKM"]
[Tue Aug 18 13:01:34.093574 2026] [security2:error] [pid 139043:tid 139291] [client 20.102.65.165:8525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/puc.php"] [unique_id "aoSB3v2v-lWn9OzQT7URtQAAAPs"]
[Tue Aug 18 13:01:34.100841 2026] [security2:error] [pid 139043:tid 139085] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/hplfuns.php"] [unique_id "aoSB3v2v-lWn9OzQT7URtgAAmyk"]
[Tue Aug 18 13:01:34.103394 2026] [security2:error] [pid 139043:tid 139217] [client 20.79.204.6:11535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/aa.php"] [unique_id "aoSB3v2v-lWn9OzQT7URtwAAALE"]
[Tue Aug 18 13:01:34.106363 2026] [security2:error] [pid 139043:tid 139227] [client 20.79.204.6:2220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSB3v2v-lWn9OzQT7URuQAAALs"]
[Tue Aug 18 13:01:34.112806 2026] [security2:error] [pid 139043:tid 139244] [client 20.100.169.31:4320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSB3v2v-lWn9OzQT7URugAAAMw"]
[Tue Aug 18 13:01:34.113115 2026] [security2:error] [pid 123784:tid 124020] [client 20.80.111.3:41250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/elementor/wp-login.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHbQAAAGY"]
[Tue Aug 18 13:01:34.154572 2026] [security2:error] [pid 139043:tid 139245] [client 20.91.215.254:11482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/abc.php"] [unique_id "aoSB3v2v-lWn9OzQT7URvQAAAM0"]
[Tue Aug 18 13:01:34.154827 2026] [security2:error] [pid 123784:tid 123931] [client 20.48.236.86:14477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/ws13.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHbgAAAA0"]
[Tue Aug 18 13:01:34.156389 2026] [security2:error] [pid 139043:tid 139184] [client 20.119.58.187:10488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB3v2v-lWn9OzQT7URvgAAAJA"]
[Tue Aug 18 13:01:34.190578 2026] [security2:error] [pid 139043:tid 139279] [client 20.102.65.165:3054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/aa.php"] [unique_id "aoSB3v2v-lWn9OzQT7URwQAAAO8"]
[Tue Aug 18 13:01:34.197459 2026] [security2:error] [pid 123784:tid 123924] [client 20.75.92.165:4244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHcAAAAAY"]
[Tue Aug 18 13:01:34.221982 2026] [security2:error] [pid 123784:tid 123973] [client 20.116.17.175:22937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHcQAAADc"]
[Tue Aug 18 13:01:34.242509 2026] [security2:error] [pid 139043:tid 139095] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adfschopan.com.br"] [uri "/phpinfo.php"] [unique_id "aoSB3v2v-lWn9OzQT7URwwAA5TM"]
[Tue Aug 18 13:01:34.274992 2026] [security2:error] [pid 139043:tid 139070] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/htaccess.php"] [unique_id "aoSB3v2v-lWn9OzQT7URxAAA1Ro"]
[Tue Aug 18 13:01:34.278788 2026] [security2:error] [pid 139043:tid 139262] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/as.php"] [unique_id "aoSB3v2v-lWn9OzQT7URxQAAAN4"]
[Tue Aug 18 13:01:34.283295 2026] [security2:error] [pid 123784:tid 124019] [client 168.62.48.100:17943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/mt/byp.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHcwAAAGU"]
[Tue Aug 18 13:01:34.304627 2026] [security2:error] [pid 139043:tid 139205] [client 157.20.138.62:63500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3v2v-lWn9OzQT7URxgAAAKU"]
[Tue Aug 18 13:01:34.304827 2026] [security2:error] [pid 139043:tid 139205] [client 157.20.138.62:63500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3v2v-lWn9OzQT7URxgAAAKU"]
[Tue Aug 18 13:01:34.307102 2026] [security2:error] [pid 139043:tid 139179] [client 20.1.169.243:5794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/tool.php"] [unique_id "aoSB3v2v-lWn9OzQT7URxwAAAIs"]
[Tue Aug 18 13:01:34.311519 2026] [security2:error] [pid 139043:tid 139292] [client 20.163.43.14:8941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSB3v2v-lWn9OzQT7URyAAAAPw"]
[Tue Aug 18 13:01:34.312144 2026] [security2:error] [pid 123784:tid 123995] [client 103.184.169.37:43157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHdAAAAE0"]
[Tue Aug 18 13:01:34.312263 2026] [security2:error] [pid 123784:tid 123995] [client 103.184.169.37:43157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHdAAAAE0"]
[Tue Aug 18 13:01:34.314449 2026] [security2:error] [pid 139043:tid 139290] [client 20.104.100.201:49410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/txets.php"] [unique_id "aoSB3v2v-lWn9OzQT7URyQAAAPo"]
[Tue Aug 18 13:01:34.338991 2026] [security2:error] [pid 123784:tid 123919] [client 20.151.109.219:60879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/se.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHdwAAAAE"]
[Tue Aug 18 13:01:34.348580 2026] [security2:error] [pid 139043:tid 139190] [client 135.225.78.186:59523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSB3v2v-lWn9OzQT7URywAAAJY"]
[Tue Aug 18 13:01:34.365900 2026] [security2:error] [pid 139043:tid 139258] [client 68.221.73.131:29575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/nope.php"] [unique_id "aoSB3v2v-lWn9OzQT7URzQAAANo"]
[Tue Aug 18 13:01:34.376346 2026] [autoindex:error] [pid 139043:tid 139282] [client 20.79.204.6:8371] AH01276: Cannot serve directory /home4/dp305k87/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:34.379010 2026] [security2:error] [pid 139043:tid 139240] [client 20.79.204.6:11664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/aa.php"] [unique_id "aoSB3v2v-lWn9OzQT7URzwAAAMg"]
[Tue Aug 18 13:01:34.379442 2026] [security2:error] [pid 139043:tid 139167] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSB3v2v-lWn9OzQT7URzgAA4ns"]
[Tue Aug 18 13:01:34.400316 2026] [security2:error] [pid 139043:tid 139259] [client 66.249.66.35:36431] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "testing.giordaniturismo.com.br"] [uri "/robots.txt"] [unique_id "aoSB3v2v-lWn9OzQT7UR0AAAANs"]
[Tue Aug 18 13:01:34.402855 2026] [security2:error] [pid 139043:tid 139069] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adfschopan.com.br"] [uri "/info.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR0QAAlBk"]
[Tue Aug 18 13:01:34.445298 2026] [security2:error] [pid 139043:tid 139079] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adfschopan.com.br"] [uri "/pi.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR0gAA5iM"]
[Tue Aug 18 13:01:34.446122 2026] [security2:error] [pid 123784:tid 123945] [client 20.79.222.117:17934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/nox.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHeQAAABs"]
[Tue Aug 18 13:01:34.455110 2026] [security2:error] [pid 139043:tid 139066] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/images/wso.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR0wAA4RY"]
[Tue Aug 18 13:01:34.456268 2026] [security2:error] [pid 123784:tid 124042] [client 158.23.17.4:47659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/r.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHegAAAHw"]
[Tue Aug 18 13:01:34.498053 2026] [security2:error] [pid 139043:tid 139173] [client 20.104.100.201:34258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/xwpg.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR1QAAAIU"]
[Tue Aug 18 13:01:34.499238 2026] [security2:error] [pid 139043:tid 139094] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adfschopan.com.br"] [uri "/test.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR1gAA6DI"]
[Tue Aug 18 13:01:34.510149 2026] [security2:error] [pid 139043:tid 139192] [client 20.119.58.187:10139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/abcd.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR1wAAAJg"]
[Tue Aug 18 13:01:34.526434 2026] [security2:error] [pid 139043:tid 139285] [client 20.226.112.14:34181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/Okxob.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR2QAAAPU"]
[Tue Aug 18 13:01:34.545475 2026] [security2:error] [pid 123784:tid 123886] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wso.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHfQAAAGE"]
[Tue Aug 18 13:01:34.546028 2026] [security2:error] [pid 123784:tid 123933] [client 168.62.48.100:18034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHfgAAAA8"]
[Tue Aug 18 13:01:34.558417 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:34.558697 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:34.583190 2026] [security2:error] [pid 139043:tid 139122] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adfschopan.com.br"] [uri "/i.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR3gAAmU4"]
[Tue Aug 18 13:01:34.594527 2026] [security2:error] [pid 123784:tid 123932] [client 20.104.100.201:49428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/img.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHgAAAAA4"]
[Tue Aug 18 13:01:34.611822 2026] [security2:error] [pid 139043:tid 139236] [client 213.35.127.232:56810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR3wAAAMQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:34.621935 2026] [security2:error] [pid 123784:tid 123952] [client 20.75.92.165:1986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/aaa.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHgQAAACI"]
[Tue Aug 18 13:01:34.629110 2026] [security2:error] [pid 139043:tid 139055] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/index/function.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR4AAA7gs"]
[Tue Aug 18 13:01:34.634152 2026] [security2:error] [pid 139043:tid 139178] [client 20.79.204.6:10727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-mail.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR4QAAAIo"]
[Tue Aug 18 13:01:34.643831 2026] [security2:error] [pid 123784:tid 123979] [client 20.186.30.159:9986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/ops.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHggAAAD0"]
[Tue Aug 18 13:01:34.647301 2026] [security2:error] [pid 123784:tid 123943] [client 20.102.65.165:8462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/inso.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHhAAAABk"]
[Tue Aug 18 13:01:34.647853 2026] [security2:error] [pid 123784:tid 124032] [client 20.151.109.219:60402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/vp.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHhQAAAHI"]
[Tue Aug 18 13:01:34.649146 2026] [security2:error] [pid 139043:tid 139276] [client 20.163.43.14:8845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/01.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR4gAAAOw"]
[Tue Aug 18 13:01:34.670312 2026] [security2:error] [pid 123784:tid 124010] [client 20.1.169.243:5332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/twentytwenty/functions.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHhgAAAFw"]
[Tue Aug 18 13:01:34.695225 2026] [security2:error] [pid 139043:tid 139234] [client 20.250.13.23:6822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/input.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR5QAAAMI"]
[Tue Aug 18 13:01:34.702153 2026] [security2:error] [pid 139043:tid 139280] [client 20.79.204.6:12248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/abcd.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR5gAAAPA"]
[Tue Aug 18 13:01:34.705301 2026] [security2:error] [pid 123784:tid 123863] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/sf.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHiAAALko"]
[Tue Aug 18 13:01:34.725995 2026] [security2:error] [pid 139043:tid 139238] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/bolt.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR5wAAAMY"]
[Tue Aug 18 13:01:34.741010 2026] [security2:error] [pid 139043:tid 139261] [client 20.65.98.162:22549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/ano.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR6gAAAN0"]
[Tue Aug 18 13:01:34.744018 2026] [security2:error] [pid 139043:tid 139206] [client 158.158.74.177:22870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR6wAAAKY"]
[Tue Aug 18 13:01:34.764022 2026] [security2:error] [pid 139043:tid 139230] [client 20.102.65.165:3046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/img.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR7QAAAL4"]
[Tue Aug 18 13:01:34.770896 2026] [security2:error] [pid 139043:tid 139300] [client 20.79.204.6:2404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR7gAAAQQ"]
[Tue Aug 18 13:01:34.802934 2026] [security2:error] [pid 139043:tid 139119] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/info.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR8AAAoUs"]
[Tue Aug 18 13:01:34.811432 2026] [security2:error] [pid 123784:tid 124035] [client 20.104.100.201:34261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/dex.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHigAAAHU"]
[Tue Aug 18 13:01:34.815909 2026] [security2:error] [pid 139043:tid 139227] [client 20.127.136.245:9009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR8QAAALs"]
[Tue Aug 18 13:01:34.858900 2026] [security2:error] [pid 139043:tid 139257] [client 20.79.222.117:17933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/akismet.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR8wAAANk"]
[Tue Aug 18 13:01:34.862294 2026] [security2:error] [pid 139043:tid 139268] [client 20.119.58.187:10475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/al.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR9AAAAOQ"]
[Tue Aug 18 13:01:34.869535 2026] [security2:error] [pid 139043:tid 139298] [client 20.116.17.175:53762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/cok.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR9QAAAQI"]
[Tue Aug 18 13:01:34.872763 2026] [security2:error] [pid 139043:tid 139184] [client 20.104.100.201:49412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/admin.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR9gAAAJA"]
[Tue Aug 18 13:01:34.887478 2026] [security2:error] [pid 123784:tid 123913] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/index/function.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHjAAAH3w"]
[Tue Aug 18 13:01:34.918469 2026] [security2:error] [pid 123784:tid 124001] [client 20.91.215.254:11462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/classwithtostring.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHjQAAAFM"]
[Tue Aug 18 13:01:34.946815 2026] [security2:error] [pid 139043:tid 139189] [client 168.62.48.100:18143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR-gAAAJU"]
[Tue Aug 18 13:01:34.956889 2026] [security2:error] [pid 123784:tid 123840] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHjgAAOjM"]
[Tue Aug 18 13:01:34.971995 2026] [security2:error] [pid 139043:tid 139231] [client 5.31.227.224:29946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR_AAAAL8"]
[Tue Aug 18 13:01:34.976580 2026] [security2:error] [pid 139043:tid 139231] [client 5.31.227.224:29946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR_AAAAL8"]
[Tue Aug 18 13:01:34.977097 2026] [security2:error] [pid 139043:tid 139253] [client 20.163.43.14:8920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/lv.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR_gAAANU"]
[Tue Aug 18 13:01:34.979704 2026] [security2:error] [pid 139043:tid 139204] [client 20.75.92.165:4243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/term.php"] [unique_id "aoSB3v2v-lWn9OzQT7USAAAAAKQ"]
[Tue Aug 18 13:01:34.982909 2026] [security2:error] [pid 139043:tid 139182] [client 20.226.112.14:32549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/file59.php"] [unique_id "aoSB3v2v-lWn9OzQT7USAQAAAI4"]
[Tue Aug 18 13:01:34.986907 2026] [security2:error] [pid 123784:tid 124000] [client 20.79.204.6:11575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/abcd.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHjwAAAFI"]
[Tue Aug 18 13:01:34.987439 2026] [security2:error] [pid 139043:tid 139205] [client 20.48.236.86:14472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/btx25.php"] [unique_id "aoSB3v2v-lWn9OzQT7USAgAAAKU"]
[Tue Aug 18 13:01:34.987716 2026] [security2:error] [pid 139043:tid 139233] [client 20.80.111.3:31260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/goat1.php"] [unique_id "aoSB3v2v-lWn9OzQT7USAwAAAME"]
[Tue Aug 18 13:01:34.988310 2026] [security2:error] [pid 123784:tid 124016] [client 68.221.73.131:52889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/new.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHkAAAAGI"]
[Tue Aug 18 13:01:34.989505 2026] [security2:error] [pid 139043:tid 139124] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/profile.php"] [unique_id "aoSB3v2v-lWn9OzQT7USBAAArFA"]
[Tue Aug 18 13:01:34.990781 2026] [security2:error] [pid 139043:tid 139248] [client 20.116.17.175:22973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/png.php"] [unique_id "aoSB3v2v-lWn9OzQT7USBQAAANA"]
[Tue Aug 18 13:01:35.002683 2026] [security2:error] [pid 139043:tid 139179] [client 158.23.17.4:17571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/phpcheck.php"] [unique_id "aoSB3_2v-lWn9OzQT7USBgAAAIs"]
[Tue Aug 18 13:01:35.022361 2026] [security2:error] [pid 139043:tid 139099] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adfschopan.com.br"] [uri "/app_dev.php"] [unique_id "aoSB3_2v-lWn9OzQT7USBwAA0jc"]
[Tue Aug 18 13:01:35.034646 2026] [security2:error] [pid 139043:tid 139218] [client 20.1.169.243:5801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/wp-admin.php"] [unique_id "aoSB3_2v-lWn9OzQT7USCAAAALI"]
[Tue Aug 18 13:01:35.048480 2026] [security2:error] [pid 123784:tid 123904] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/edit.php"] [unique_id "aoSB32wDnJBNj2tDbYYHkgAAVnM"]
[Tue Aug 18 13:01:35.054368 2026] [security2:error] [pid 139043:tid 139219] [client 20.186.30.159:10066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/coffexium.php"] [unique_id "aoSB3_2v-lWn9OzQT7USCQAAALM"]
[Tue Aug 18 13:01:35.060105 2026] [security2:error] [pid 139043:tid 139199] [client 66.187.6.102:56114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/produtos/pinceis-artisticos"] [unique_id "aoSB3_2v-lWn9OzQT7USCgAAAJ8"]
[Tue Aug 18 13:01:35.060213 2026] [security2:error] [pid 139043:tid 139199] [client 66.187.6.102:56114] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/produtos/pinceis-artisticos"] [unique_id "aoSB3_2v-lWn9OzQT7USCgAAAJ8"]
[Tue Aug 18 13:01:35.060929 2026] [security2:error] [pid 139043:tid 139213] [client 158.23.17.4:63007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/17.php"] [unique_id "aoSB3_2v-lWn9OzQT7USCwAAAK0"]
[Tue Aug 18 13:01:35.086411 2026] [security2:error] [pid 139043:tid 139240] [client 20.102.65.165:2960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/222.php"] [unique_id "aoSB3_2v-lWn9OzQT7USDgAAAMg"]
[Tue Aug 18 13:01:35.111485 2026] [security2:error] [pid 139043:tid 139243] [client 20.151.109.219:14315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ph.php"] [unique_id "aoSB3_2v-lWn9OzQT7USDwAAAMs"]
[Tue Aug 18 13:01:35.140855 2026] [security2:error] [pid 123784:tid 123960] [client 20.251.112.238:26144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/zwq13.php"] [unique_id "aoSB32wDnJBNj2tDbYYHlAAAACo"]
[Tue Aug 18 13:01:35.144518 2026] [security2:error] [pid 123784:tid 123947] [client 20.104.100.201:49671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/index.php"] [unique_id "aoSB32wDnJBNj2tDbYYHlQAAAB0"]
[Tue Aug 18 13:01:35.144716 2026] [security2:error] [pid 123784:tid 123880] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB32wDnJBNj2tDbYYHlgAACVs"]
[Tue Aug 18 13:01:35.152004 2026] [security2:error] [pid 139043:tid 139197] [client 20.104.100.201:61970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/xyn.php"] [unique_id "aoSB3_2v-lWn9OzQT7USEAAAAJ0"]
[Tue Aug 18 13:01:35.158250 2026] [authz_core:error] [pid 123784:tid 123909] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:35.158509 2026] [authz_core:error] [pid 123784:tid 123909] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:35.165218 2026] [security2:error] [pid 139043:tid 139271] [client 20.100.169.31:4306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSB3_2v-lWn9OzQT7USEQAAAOc"]
[Tue Aug 18 13:01:35.165912 2026] [security2:error] [pid 139043:tid 139104] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/sx.php"] [unique_id "aoSB3_2v-lWn9OzQT7USEgAA_zw"]
[Tue Aug 18 13:01:35.167883 2026] [security2:error] [pid 139043:tid 139125] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/.hermes/.env"] [unique_id "aoSB3_2v-lWn9OzQT7USEwAAz1E"]
[Tue Aug 18 13:01:35.195551 2026] [security2:error] [pid 139043:tid 139224] [client 172.202.39.151:40911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/ioxi-o.php"] [unique_id "aoSB3_2v-lWn9OzQT7USFAAAALg"]
[Tue Aug 18 13:01:35.206188 2026] [security2:error] [pid 123784:tid 124038] [client 4.232.94.69:14523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/OK.php"] [unique_id "aoSB32wDnJBNj2tDbYYHmgAAAHg"]
[Tue Aug 18 13:01:35.214922 2026] [security2:error] [pid 139043:tid 139259] [client 20.119.58.187:10198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/alfa.php"] [unique_id "aoSB3_2v-lWn9OzQT7USFgAAANs"]
[Tue Aug 18 13:01:35.236854 2026] [security2:error] [pid 139043:tid 139130] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adfschopan.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "aoSB3_2v-lWn9OzQT7USGAAA_lY"]
[Tue Aug 18 13:01:35.270370 2026] [security2:error] [pid 139043:tid 139260] [client 20.79.222.117:18031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/admin.php"] [unique_id "aoSB3_2v-lWn9OzQT7USGwAAANw"]
[Tue Aug 18 13:01:35.302366 2026] [security2:error] [pid 139043:tid 139297] [client 20.163.43.14:8902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/new.php"] [unique_id "aoSB3_2v-lWn9OzQT7USHAAAAQE"]
[Tue Aug 18 13:01:35.309514 2026] [security2:error] [pid 139043:tid 139073] [remote 89.185.225.24:42534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.225.185.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ofertas.vidracariafroesbox.com.br"] [uri "/wp-login.php"] [unique_id "aoSB3_2v-lWn9OzQT7USHQAAyh0"]
[Tue Aug 18 13:01:35.313539 2026] [security2:error] [pid 123784:tid 124023] [client 20.250.13.23:55959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/jquery.php"] [unique_id "aoSB32wDnJBNj2tDbYYHnwAAAGk"]
[Tue Aug 18 13:01:35.314895 2026] [security2:error] [pid 139043:tid 139221] [client 20.102.65.165:8278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/fpwch.php"] [unique_id "aoSB3_2v-lWn9OzQT7USHgAAALU"]
[Tue Aug 18 13:01:35.342602 2026] [security2:error] [pid 139043:tid 139053] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSB3_2v-lWn9OzQT7USIQAAqgk"]
[Tue Aug 18 13:01:35.358911 2026] [security2:error] [pid 123784:tid 123821] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSB32wDnJBNj2tDbYYHoAAARCA"]
[Tue Aug 18 13:01:35.363203 2026] [security2:error] [pid 123784:tid 123939] [client 20.65.98.162:55208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/file2.php"] [unique_id "aoSB32wDnJBNj2tDbYYHoQAAABU"]
[Tue Aug 18 13:01:35.375753 2026] [security2:error] [pid 139043:tid 139202] [client 158.23.17.4:15138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/dg.php"] [unique_id "aoSB3_2v-lWn9OzQT7USIwAAAKI"]
[Tue Aug 18 13:01:35.379909 2026] [security2:error] [pid 139043:tid 139251] [client 168.62.48.100:18042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSB3_2v-lWn9OzQT7USJAAAANM"]
[Tue Aug 18 13:01:35.381179 2026] [security2:error] [pid 139043:tid 139176] [client 20.79.204.6:11541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/admin.php"] [unique_id "aoSB3_2v-lWn9OzQT7USJQAAAIg"]
[Tue Aug 18 13:01:35.388805 2026] [security2:error] [pid 123784:tid 123923] [client 20.38.3.247:4513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/dex.php"] [unique_id "aoSB32wDnJBNj2tDbYYHogAAAAU"]
[Tue Aug 18 13:01:35.391805 2026] [security2:error] [pid 139043:tid 139238] [client 20.75.92.165:4239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/7.php"] [unique_id "aoSB3_2v-lWn9OzQT7USJgAAAMY"]
[Tue Aug 18 13:01:35.397608 2026] [security2:error] [pid 139043:tid 139228] [client 20.1.169.243:5346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSB3_2v-lWn9OzQT7USKAAAALw"]
[Tue Aug 18 13:01:35.410377 2026] [autoindex:error] [pid 139043:tid 139192] [client 20.79.204.6:2372] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:35.422688 2026] [authz_core:error] [pid 139043:tid 139106] [remote 57.141.22.94:52650] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:35.423004 2026] [authz_core:error] [pid 139043:tid 139106] [remote 57.141.22.94:52650] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:35.423803 2026] [security2:error] [pid 139043:tid 139261] [client 20.116.17.175:23014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/ab.php"] [unique_id "aoSB3_2v-lWn9OzQT7USKwAAAN0"]
[Tue Aug 18 13:01:35.424479 2026] [security2:error] [pid 139043:tid 139277] [client 20.104.100.201:49435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSB3_2v-lWn9OzQT7USLAAAAO0"]
[Tue Aug 18 13:01:35.429246 2026] [security2:error] [pid 123784:tid 123968] [client 20.80.111.3:33467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/google-seo-rank/module.php"] [unique_id "aoSB32wDnJBNj2tDbYYHowAAADI"]
[Tue Aug 18 13:01:35.437582 2026] [security2:error] [pid 139043:tid 139203] [client 172.202.39.151:4444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/sf.php"] [unique_id "aoSB3_2v-lWn9OzQT7USLQAAAKM"]
[Tue Aug 18 13:01:35.455268 2026] [security2:error] [pid 139043:tid 139214] [client 20.104.100.201:61429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSB3_2v-lWn9OzQT7USLgAAAK4"]
[Tue Aug 18 13:01:35.460080 2026] [security2:error] [pid 139043:tid 139299] [client 20.102.65.165:2959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/key.php"] [unique_id "aoSB3_2v-lWn9OzQT7USLwAAAQM"]
[Tue Aug 18 13:01:35.460188 2026] [authz_core:error] [pid 123784:tid 123878] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:35.460451 2026] [authz_core:error] [pid 123784:tid 123878] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:35.505428 2026] [security2:error] [pid 139043:tid 139253] [client 20.151.109.219:14296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/s.php"] [unique_id "aoSB3_2v-lWn9OzQT7USMAAAANU"]
[Tue Aug 18 13:01:35.508992 2026] [security2:error] [pid 123784:tid 123830] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-good.php"] [unique_id "aoSB32wDnJBNj2tDbYYHpgAANyk"]
[Tue Aug 18 13:01:35.518705 2026] [security2:error] [pid 139043:tid 139109] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSB3_2v-lWn9OzQT7USMQAApUE"]
[Tue Aug 18 13:01:35.530296 2026] [security2:error] [pid 139043:tid 139174] [client 158.158.74.177:9236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSB3_2v-lWn9OzQT7USMgAAAIY"]
[Tue Aug 18 13:01:35.567690 2026] [security2:error] [pid 139043:tid 139230] [client 20.119.58.187:10132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/as.php"] [unique_id "aoSB3_2v-lWn9OzQT7USNwAAAL4"]
[Tue Aug 18 13:01:35.574331 2026] [security2:error] [pid 123784:tid 123980] [client 66.187.6.102:56222] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/site/img/download.png"] [unique_id "aoSB32wDnJBNj2tDbYYHqgAAAD4"]
[Tue Aug 18 13:01:35.590542 2026] [security2:error] [pid 123784:tid 123990] [client 20.79.204.6:11537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/admin.php"] [unique_id "aoSB32wDnJBNj2tDbYYHrwAAAEg"]
[Tue Aug 18 13:01:35.607193 2026] [security2:error] [pid 139043:tid 139293] [client 159.69.158.189:64106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "dadicamotors.com.br"] [uri "/index.php"] [unique_id "aoSB3_2v-lWn9OzQT7USRwAAAP0"], referer: https://dadicamotors.com.br/
[Tue Aug 18 13:01:35.613855 2026] [security2:error] [pid 139043:tid 139213] [client 20.226.112.14:13670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/eauu.php"] [unique_id "aoSB3_2v-lWn9OzQT7USSQAAAK0"]
[Tue Aug 18 13:01:35.618470 2026] [security2:error] [pid 139043:tid 139232] [client 66.187.6.102:56358] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/produtos/acessorios"] [unique_id "aoSB3_2v-lWn9OzQT7USSgAAAMA"]
[Tue Aug 18 13:01:35.622353 2026] [security2:error] [pid 139043:tid 139177] [client 20.127.136.245:22657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/about/function.php"] [unique_id "aoSB3_2v-lWn9OzQT7USSwAAAIk"]
[Tue Aug 18 13:01:35.628300 2026] [autoindex:error] [pid 139043:tid 139199] [client 20.79.204.6:2372] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:35.628908 2026] [security2:error] [pid 139043:tid 139236] [client 213.35.127.232:57030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSB3_2v-lWn9OzQT7USTAAAAMQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:35.631553 2026] [security2:error] [pid 123784:tid 123970] [client 20.163.43.14:8931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/222.php"] [unique_id "aoSB32wDnJBNj2tDbYYHsQAAADQ"]
[Tue Aug 18 13:01:35.646476 2026] [security2:error] [pid 123784:tid 123950] [client 20.91.215.254:11519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/adminfuns.php"] [unique_id "aoSB32wDnJBNj2tDbYYHsgAAACA"]
[Tue Aug 18 13:01:35.683830 2026] [security2:error] [pid 139043:tid 139187] [client 20.251.112.238:8013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/Okxob.php"] [unique_id "aoSB3_2v-lWn9OzQT7USTgAAAJM"]
[Tue Aug 18 13:01:35.691195 2026] [security2:error] [pid 139043:tid 139197] [client 20.79.222.117:13268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/ajax.php"] [unique_id "aoSB3_2v-lWn9OzQT7USTwAAAJ0"]
[Tue Aug 18 13:01:35.699343 2026] [security2:error] [pid 123784:tid 123967] [client 20.104.100.201:49456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/cong.php"] [unique_id "aoSB32wDnJBNj2tDbYYHtAAAADE"]
[Tue Aug 18 13:01:35.708943 2026] [security2:error] [pid 123784:tid 123984] [client 168.62.48.100:18134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSB32wDnJBNj2tDbYYHtQAAAEI"]
[Tue Aug 18 13:01:35.715280 2026] [security2:error] [pid 123784:tid 123903] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/st.php"] [unique_id "aoSB32wDnJBNj2tDbYYHtgAAG3I"]
[Tue Aug 18 13:01:35.736008 2026] [authz_core:error] [pid 139043:tid 139112] [remote 57.141.22.122:58000] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:35.736460 2026] [authz_core:error] [pid 139043:tid 139112] [remote 57.141.22.122:58000] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:35.745495 2026] [autoindex:error] [pid 139043:tid 139128] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/dtbbrasilcom/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:35.761022 2026] [security2:error] [pid 139043:tid 139272] [client 20.75.92.165:4276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/file5.php"] [unique_id "aoSB3_2v-lWn9OzQT7USUgAAAOg"]
[Tue Aug 18 13:01:35.763541 2026] [security2:error] [pid 123784:tid 123918] [client 168.62.48.100:5594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSB32wDnJBNj2tDbYYHuwAAAAA"]
[Tue Aug 18 13:01:35.765193 2026] [authz_core:error] [pid 123784:tid 123802] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:35.765616 2026] [authz_core:error] [pid 123784:tid 123802] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:35.790685 2026] [security2:error] [pid 123784:tid 123932] [client 20.116.17.175:3438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/accesson.php"] [unique_id "aoSB32wDnJBNj2tDbYYHvAAAAA4"]
[Tue Aug 18 13:01:35.791697 2026] [security2:error] [pid 139043:tid 139285] [client 52.173.121.69:51814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSB3_2v-lWn9OzQT7USVgAAAPU"]
[Tue Aug 18 13:01:35.792588 2026] [security2:error] [pid 139043:tid 139250] [client 20.100.169.31:4434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSB3_2v-lWn9OzQT7USVwAAANI"]
[Tue Aug 18 13:01:35.826951 2026] [security2:error] [pid 139043:tid 139193] [client 20.116.17.175:22936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/12.php"] [unique_id "aoSB3_2v-lWn9OzQT7USWgAAAJk"]
[Tue Aug 18 13:01:35.829117 2026] [security2:error] [pid 139043:tid 139260] [client 20.79.204.6:2372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSB3_2v-lWn9OzQT7USWwAAANw"]
[Tue Aug 18 13:01:35.861581 2026] [security2:error] [pid 139043:tid 139297] [client 20.102.65.165:3060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/chosen.php"] [unique_id "aoSB3_2v-lWn9OzQT7USXAAAAQE"]
[Tue Aug 18 13:01:35.868616 2026] [security2:error] [pid 123784:tid 123925] [client 20.80.111.3:31005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/h.php"] [unique_id "aoSB32wDnJBNj2tDbYYHvgAAAAc"]
[Tue Aug 18 13:01:35.878199 2026] [security2:error] [pid 139043:tid 139178] [client 20.104.100.201:61994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-good.php"] [unique_id "aoSB3_2v-lWn9OzQT7USXQAAAIo"]
[Tue Aug 18 13:01:35.878276 2026] [security2:error] [pid 139043:tid 139242] [client 20.102.65.165:8542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/aa.php"] [unique_id "aoSB3_2v-lWn9OzQT7USXgAAAMo"]
[Tue Aug 18 13:01:35.919966 2026] [security2:error] [pid 123784:tid 123943] [client 20.119.58.187:10438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/aa.php"] [unique_id "aoSB32wDnJBNj2tDbYYHzgAAABk"]
[Tue Aug 18 13:01:35.924122 2026] [security2:error] [pid 139043:tid 139133] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSB3_2v-lWn9OzQT7USYgAAqlk"]
[Tue Aug 18 13:01:35.935222 2026] [security2:error] [pid 139043:tid 139247] [client 20.250.13.23:6847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/media-new.php"] [unique_id "aoSB3_2v-lWn9OzQT7USYwAAAM8"]
[Tue Aug 18 13:01:35.936704 2026] [security2:error] [pid 123784:tid 124035] [client 20.151.109.219:60888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/uo.php"] [unique_id "aoSB32wDnJBNj2tDbYYH0QAAAHU"]
[Tue Aug 18 13:01:35.948796 2026] [security2:error] [pid 123784:tid 123876] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/le.php"] [unique_id "aoSB32wDnJBNj2tDbYYH0gAAQVc"]
[Tue Aug 18 13:01:35.962932 2026] [security2:error] [pid 123784:tid 123965] [client 20.163.43.14:8835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/chosen.php"] [unique_id "aoSB32wDnJBNj2tDbYYH0wAAAC8"]
[Tue Aug 18 13:01:35.974106 2026] [security2:error] [pid 139043:tid 139251] [client 20.104.100.201:49114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/term.php"] [unique_id "aoSB3_2v-lWn9OzQT7USZAAAANM"]
[Tue Aug 18 13:01:35.975032 2026] [security2:error] [pid 123784:tid 124011] [client 172.202.39.151:4452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/index/function.php"] [unique_id "aoSB32wDnJBNj2tDbYYH1AAAAF0"]
[Tue Aug 18 13:01:35.995869 2026] [security2:error] [pid 123784:tid 123893] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/tes.php"] [unique_id "aoSB32wDnJBNj2tDbYYH1gAAR2g"]
[Tue Aug 18 13:01:36.002869 2026] [security2:error] [pid 139043:tid 139261] [client 158.23.17.4:10953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/conn-test.php"] [unique_id "aoSB4P2v-lWn9OzQT7USZQAAAN0"]
[Tue Aug 18 13:01:36.006356 2026] [security2:error] [pid 139043:tid 139203] [client 20.186.30.159:10076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSB4P2v-lWn9OzQT7USZgAAAKM"]
[Tue Aug 18 13:01:36.006422 2026] [security2:error] [pid 139043:tid 139264] [client 158.23.17.4:47899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/bm.php"] [unique_id "aoSB4P2v-lWn9OzQT7USZwAAAOA"]
[Tue Aug 18 13:01:36.008483 2026] [security2:error] [pid 139043:tid 139255] [client 20.1.169.243:5804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSB4P2v-lWn9OzQT7USaAAAANc"]
[Tue Aug 18 13:01:36.023818 2026] [security2:error] [pid 139043:tid 139184] [client 168.62.48.100:18089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSB4P2v-lWn9OzQT7USagAAAJA"]
[Tue Aug 18 13:01:36.093164 2026] [security2:error] [pid 123784:tid 124016] [client 20.226.112.14:22901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/dsd.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH2QAAAGI"]
[Tue Aug 18 13:01:36.145643 2026] [security2:error] [pid 123784:tid 123815] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/files/index.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH2gAAYxo"]
[Tue Aug 18 13:01:36.151778 2026] [autoindex:error] [pid 139043:tid 139134] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/dtbbrasilcom/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:36.162694 2026] [security2:error] [pid 123784:tid 123920] [client 20.75.92.165:4299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH2wAAAAI"]
[Tue Aug 18 13:01:36.162709 2026] [security2:error] [pid 123784:tid 123869] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/hr.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH3AAAGFA"]
[Tue Aug 18 13:01:36.185101 2026] [security2:error] [pid 123784:tid 124018] [client 20.79.204.6:12244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH4AAAAGQ"]
[Tue Aug 18 13:01:36.193910 2026] [security2:error] [pid 123784:tid 124009] [client 20.79.204.6:10783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/bolt.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH4QAAAFs"]
[Tue Aug 18 13:01:36.194747 2026] [security2:error] [pid 123784:tid 123958] [client 68.221.73.131:38511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/new.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH4gAAACg"]
[Tue Aug 18 13:01:36.204270 2026] [security2:error] [pid 139043:tid 139238] [client 158.158.74.177:18952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/st.php"] [unique_id "aoSB4P2v-lWn9OzQT7USbwAAAMY"]
[Tue Aug 18 13:01:36.214657 2026] [security2:error] [pid 139043:tid 139227] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/class-t.api.php"] [unique_id "aoSB4P2v-lWn9OzQT7UScQAAALs"]
[Tue Aug 18 13:01:36.228690 2026] [security2:error] [pid 123784:tid 124023] [client 20.104.100.201:34272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wmore1.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH4wAAAGk"]
[Tue Aug 18 13:01:36.256009 2026] [security2:error] [pid 139043:tid 139268] [client 20.104.100.201:49098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/black.php"] [unique_id "aoSB4P2v-lWn9OzQT7UScwAAAOQ"]
[Tue Aug 18 13:01:36.270206 2026] [security2:error] [pid 139043:tid 139290] [client 20.116.17.175:22986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/x1da.php"] [unique_id "aoSB4P2v-lWn9OzQT7USdAAAAPo"]
[Tue Aug 18 13:01:36.272005 2026] [security2:error] [pid 123784:tid 123971] [client 20.119.58.187:10119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/abc.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH5QAAADU"]
[Tue Aug 18 13:01:36.284808 2026] [security2:error] [pid 139043:tid 139237] [client 20.102.65.165:2951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wpxml.php"] [unique_id "aoSB4P2v-lWn9OzQT7USdQAAAMU"]
[Tue Aug 18 13:01:36.285809 2026] [security2:error] [pid 139043:tid 139208] [client 20.48.236.86:14801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSB4P2v-lWn9OzQT7USdgAAAKg"]
[Tue Aug 18 13:01:36.293859 2026] [security2:error] [pid 123784:tid 123847] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH6AAAZzo"]
[Tue Aug 18 13:01:36.294052 2026] [security2:error] [pid 123784:tid 123923] [client 20.151.109.219:63999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/kx.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH5wAAAAU"]
[Tue Aug 18 13:01:36.294079 2026] [security2:error] [pid 123784:tid 124030] [client 168.62.48.100:18169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH6QAAAHA"]
[Tue Aug 18 13:01:36.305910 2026] [security2:error] [pid 139043:tid 139239] [client 20.127.136.245:8973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/function/function.php"] [unique_id "aoSB4P2v-lWn9OzQT7USdwAAAMc"]
[Tue Aug 18 13:01:36.308060 2026] [security2:error] [pid 123784:tid 123999] [client 20.80.111.3:39591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/import/csv1.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH6gAAAFE"]
[Tue Aug 18 13:01:36.318360 2026] [security2:error] [pid 139043:tid 139218] [client 20.163.43.14:8934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/info.php"] [unique_id "aoSB4P2v-lWn9OzQT7USeQAAALI"]
[Tue Aug 18 13:01:36.332155 2026] [security2:error] [pid 139043:tid 139148] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSB4P2v-lWn9OzQT7USegAAmmg"]
[Tue Aug 18 13:01:36.344234 2026] [security2:error] [pid 139043:tid 139204] [client 20.91.215.254:11607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/abc.php"] [unique_id "aoSB4P2v-lWn9OzQT7USewAAAKQ"]
[Tue Aug 18 13:01:36.369559 2026] [authz_core:error] [pid 123784:tid 123827] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:36.369872 2026] [authz_core:error] [pid 123784:tid 123827] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:36.380884 2026] [security2:error] [pid 123784:tid 124007] [client 172.202.39.151:40946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/abc.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH7gAAAFk"]
[Tue Aug 18 13:01:36.388365 2026] [security2:error] [pid 139043:tid 139293] [client 85.204.70.114:57557] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aoSB4P2v-lWn9OzQT7USfgAAAP0"]
[Tue Aug 18 13:01:36.404608 2026] [security2:error] [pid 139043:tid 139267] [client 20.79.204.6:12237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/adminfuns.php"] [unique_id "aoSB4P2v-lWn9OzQT7USfwAAAOM"]
[Tue Aug 18 13:01:36.438194 2026] [security2:error] [pid 123784:tid 124013] [client 20.79.204.6:2203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH8AAAAF8"]
[Tue Aug 18 13:01:36.439471 2026] [security2:error] [pid 139043:tid 139236] [client 20.251.112.238:7133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/file59.php"] [unique_id "aoSB4P2v-lWn9OzQT7USgAAAAMQ"]
[Tue Aug 18 13:01:36.450776 2026] [security2:error] [pid 123784:tid 123826] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/images/images/about.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH8QAACyU"]
[Tue Aug 18 13:01:36.472613 2026] [security2:error] [pid 123784:tid 123994] [client 158.23.17.4:1077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/env.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH9AAAAEw"]
[Tue Aug 18 13:01:36.502547 2026] [security2:error] [pid 139043:tid 139266] [client 20.75.92.165:4327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSB4P2v-lWn9OzQT7USggAAAOI"]
[Tue Aug 18 13:01:36.505844 2026] [security2:error] [pid 139043:tid 139139] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSB4P2v-lWn9OzQT7USgwAAlF8"]
[Tue Aug 18 13:01:36.505844 2026] [security2:error] [pid 123784:tid 123953] [client 20.118.133.132:25301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/file2.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH9gAAACM"]
[Tue Aug 18 13:01:36.510921 2026] [security2:error] [pid 139043:tid 139283] [client 223.185.37.47:14429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSB4P2v-lWn9OzQT7UShAAAAPM"]
[Tue Aug 18 13:01:36.511027 2026] [security2:error] [pid 139043:tid 139283] [client 223.185.37.47:14429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSB4P2v-lWn9OzQT7UShAAAAPM"]
[Tue Aug 18 13:01:36.518634 2026] [security2:error] [pid 139043:tid 139270] [client 158.23.17.4:55173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/vu.php"] [unique_id "aoSB4P2v-lWn9OzQT7UShQAAAOY"]
[Tue Aug 18 13:01:36.528822 2026] [security2:error] [pid 123784:tid 123995] [client 20.116.17.175:56086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/av.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH9wAAAE0"]
[Tue Aug 18 13:01:36.537245 2026] [security2:error] [pid 139043:tid 139187] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/edit.php"] [unique_id "aoSB4P2v-lWn9OzQT7UShgAAAJM"]
[Tue Aug 18 13:01:36.537283 2026] [security2:error] [pid 123784:tid 123997] [client 20.104.100.201:34257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/special.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH-AAAAE8"]
[Tue Aug 18 13:01:36.539473 2026] [security2:error] [pid 123784:tid 124037] [client 20.104.100.201:49088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/as.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH-QAAAHc"]
[Tue Aug 18 13:01:36.562596 2026] [security2:error] [pid 139043:tid 139190] [client 20.250.13.23:6802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSB4P2v-lWn9OzQT7UShwAAAJY"]
[Tue Aug 18 13:01:36.602056 2026] [security2:error] [pid 123784:tid 123841] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/ms-edit.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH-wAANDQ"]
[Tue Aug 18 13:01:36.626681 2026] [security2:error] [pid 139043:tid 139183] [client 20.119.58.187:10496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/av.php"] [unique_id "aoSB4P2v-lWn9OzQT7USigAAAI8"]
[Tue Aug 18 13:01:36.627861 2026] [security2:error] [pid 139043:tid 139259] [client 168.62.48.100:5606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSB4P2v-lWn9OzQT7USiwAAANs"]
[Tue Aug 18 13:01:36.640421 2026] [security2:error] [pid 139043:tid 139211] [client 20.102.65.165:8272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/adminner.php"] [unique_id "aoSB4P2v-lWn9OzQT7USjAAAAKs"]
[Tue Aug 18 13:01:36.647958 2026] [security2:error] [pid 139043:tid 139195] [client 213.35.127.232:57230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSB4P2v-lWn9OzQT7USjQAAAJs"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:36.664559 2026] [security2:error] [pid 139043:tid 139260] [client 20.186.30.159:10081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/sf.php"] [unique_id "aoSB4P2v-lWn9OzQT7USkAAAANw"]
[Tue Aug 18 13:01:36.679750 2026] [security2:error] [pid 139043:tid 139120] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSB4P2v-lWn9OzQT7USkQABAUw"]
[Tue Aug 18 13:01:36.686494 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:36.686757 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:36.706699 2026] [security2:error] [pid 123784:tid 123798] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/kt.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH_gAAJQk"]
[Tue Aug 18 13:01:36.706699 2026] [security2:error] [pid 139043:tid 139242] [client 168.62.48.100:17995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSB4P2v-lWn9OzQT7USkgAAAMo"]
[Tue Aug 18 13:01:36.745101 2026] [security2:error] [pid 139043:tid 139234] [client 20.1.169.243:5792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/wp-includes/Text/Diff/Engine.php"] [unique_id "aoSB4P2v-lWn9OzQT7USkwAAAMI"]
[Tue Aug 18 13:01:36.754618 2026] [security2:error] [pid 139043:tid 139282] [client 20.80.111.3:18456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/index.bak.php"] [unique_id "aoSB4P2v-lWn9OzQT7USlQAAAPI"]
[Tue Aug 18 13:01:36.763551 2026] [security2:error] [pid 123784:tid 123906] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/rip.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIAAAAAHU"]
[Tue Aug 18 13:01:36.771023 2026] [security2:error] [pid 139043:tid 139198] [client 20.151.109.219:14322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/va.php"] [unique_id "aoSB4P2v-lWn9OzQT7USlgAAAJ4"]
[Tue Aug 18 13:01:36.777280 2026] [security2:error] [pid 123784:tid 123981] [client 20.102.65.165:2958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/file1221.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIAQAAAD8"]
[Tue Aug 18 13:01:36.788828 2026] [security2:error] [pid 123784:tid 123932] [client 85.204.70.114:33746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elietecamargosadv.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIAgAAAA4"]
[Tue Aug 18 13:01:36.792299 2026] [security2:error] [pid 139043:tid 139175] [client 20.79.204.6:11540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/akc.php"] [unique_id "aoSB4P2v-lWn9OzQT7USlwAAAIc"]
[Tue Aug 18 13:01:36.794959 2026] [security2:error] [pid 123784:tid 123977] [client 20.226.112.14:13038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/c4.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIAwAAADs"]
[Tue Aug 18 13:01:36.815339 2026] [security2:error] [pid 123784:tid 123991] [client 20.104.100.201:49463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/pucci.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIBQAAAEk"]
[Tue Aug 18 13:01:36.816887 2026] [security2:error] [pid 123784:tid 123925] [client 20.226.56.190:47107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/222.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIBgAAAAc"]
[Tue Aug 18 13:01:36.827523 2026] [security2:error] [pid 123784:tid 123992] [client 158.23.17.4:20452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ev.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIBwAAAEo"]
[Tue Aug 18 13:01:36.839063 2026] [security2:error] [pid 123784:tid 123964] [client 20.100.169.31:24196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSB4GwDnJBNj2tDbYYICAAAAC4"]
[Tue Aug 18 13:01:36.845179 2026] [security2:error] [pid 139043:tid 139249] [client 20.163.43.14:8922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSB4P2v-lWn9OzQT7USmQAAANE"]
[Tue Aug 18 13:01:36.847682 2026] [security2:error] [pid 123784:tid 124015] [client 213.202.253.4:61685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/txets.php"] [unique_id "aoSB4GwDnJBNj2tDbYYICQAAAGE"], referer: www.google.com
[Tue Aug 18 13:01:36.850559 2026] [security2:error] [pid 123784:tid 124014] [client 20.116.17.175:22985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/mcs.php"] [unique_id "aoSB4GwDnJBNj2tDbYYICgAAAGA"]
[Tue Aug 18 13:01:36.852624 2026] [security2:error] [pid 139043:tid 139147] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSB4P2v-lWn9OzQT7USmgAAw2c"]
[Tue Aug 18 13:01:36.860736 2026] [security2:error] [pid 123784:tid 124002] [client 135.225.78.186:64843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/av.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIDAAAAFQ"]
[Tue Aug 18 13:01:36.892578 2026] [security2:error] [pid 139043:tid 139181] [client 158.158.74.177:22869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSB4P2v-lWn9OzQT7USmwAAAI0"]
[Tue Aug 18 13:01:36.905015 2026] [security2:error] [pid 123784:tid 123983] [client 172.202.39.151:4457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/edit.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIDwAAAEE"]
[Tue Aug 18 13:01:36.913896 2026] [security2:error] [pid 123784:tid 123965] [client 20.48.236.86:14466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIEAAAAC8"]
[Tue Aug 18 13:01:36.925399 2026] [security2:error] [pid 123784:tid 123948] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/ff1.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIEgAAAB4"]
[Tue Aug 18 13:01:36.928057 2026] [security2:error] [pid 123784:tid 123989] [client 20.127.136.245:1276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-signin.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIEwAAAEc"]
[Tue Aug 18 13:01:36.934395 2026] [security2:error] [pid 139043:tid 139178] [client 20.79.204.6:10735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/bthil.php"] [unique_id "aoSB4P2v-lWn9OzQT7USnQAAAIo"]
[Tue Aug 18 13:01:36.967100 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:36.967366 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:36.977852 2026] [security2:error] [pid 123784:tid 123933] [client 20.119.58.187:10452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIFQAAAA8"]
[Tue Aug 18 13:01:36.986022 2026] [security2:error] [pid 123784:tid 123952] [client 20.91.215.254:27074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/sf.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIFwAAACI"]
[Tue Aug 18 13:01:37.008808 2026] [security2:error] [pid 123784:tid 123993] [client 20.79.204.6:11520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/akc.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIGAAAAEs"]
[Tue Aug 18 13:01:37.012177 2026] [security2:error] [pid 123784:tid 123976] [client 20.104.100.201:34303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIGQAAADo"]
[Tue Aug 18 13:01:37.021173 2026] [security2:error] [pid 123784:tid 124022] [client 20.75.92.165:2019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIGgAAAGg"]
[Tue Aug 18 13:01:37.028772 2026] [security2:error] [pid 139043:tid 139098] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSB4f2v-lWn9OzQT7USngAApTY"]
[Tue Aug 18 13:01:37.040773 2026] [security2:error] [pid 123784:tid 124017] [client 158.23.17.4:51198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ic.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIHQAAAGM"]
[Tue Aug 18 13:01:37.064487 2026] [autoindex:error] [pid 123784:tid 123936] [client 20.79.204.6:2226] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/Requests/src/Cookie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:37.075138 2026] [security2:error] [pid 123784:tid 123793] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIHwAAaQQ"]
[Tue Aug 18 13:01:37.093117 2026] [security2:error] [pid 139043:tid 139191] [client 20.104.100.201:49143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wicked.php"] [unique_id "aoSB4f2v-lWn9OzQT7USnwAAAJc"]
[Tue Aug 18 13:01:37.096312 2026] [security2:error] [pid 123784:tid 124041] [client 20.251.112.238:7142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/eauu.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIIQAAAHs"]
[Tue Aug 18 13:01:37.108846 2026] [security2:error] [pid 139043:tid 139174] [client 20.151.109.219:60907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/fo.php"] [unique_id "aoSB4f2v-lWn9OzQT7USoQAAAIY"]
[Tue Aug 18 13:01:37.134402 2026] [security2:error] [pid 123784:tid 123949] [client 52.173.121.69:60292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIIgAAAB8"]
[Tue Aug 18 13:01:37.166694 2026] [security2:error] [pid 139043:tid 139248] [client 20.102.65.165:3040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/nox.php"] [unique_id "aoSB4f2v-lWn9OzQT7USogAAANA"]
[Tue Aug 18 13:01:37.174204 2026] [security2:error] [pid 123784:tid 124003] [client 20.163.43.14:8923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIIwAAAFU"]
[Tue Aug 18 13:01:37.183035 2026] [security2:error] [pid 139043:tid 139179] [client 168.62.48.100:18007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/first.php"] [unique_id "aoSB4f2v-lWn9OzQT7USowAAAIs"]
[Tue Aug 18 13:01:37.186058 2026] [security2:error] [pid 123784:tid 123920] [client 20.80.111.3:27082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/lite.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIJAAAAAI"]
[Tue Aug 18 13:01:37.190964 2026] [security2:error] [pid 123784:tid 124039] [client 20.250.13.23:55940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIJgAAAHk"]
[Tue Aug 18 13:01:37.226592 2026] [security2:error] [pid 123784:tid 123828] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/moon.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIJwAAJyc"]
[Tue Aug 18 13:01:37.228675 2026] [security2:error] [pid 139043:tid 139230] [client 20.226.112.14:22866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/an7.php"] [unique_id "aoSB4f2v-lWn9OzQT7USpQAAAL4"]
[Tue Aug 18 13:01:37.245211 2026] [security2:error] [pid 123784:tid 123870] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ww.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIKAAAOVE"]
[Tue Aug 18 13:01:37.264610 2026] [security2:error] [pid 139043:tid 139140] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSB4f2v-lWn9OzQT7USpwABBGA"]
[Tue Aug 18 13:01:37.265867 2026] [security2:error] [pid 123784:tid 123931] [client 20.79.204.6:2226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIKgAAAA0"]
[Tue Aug 18 13:01:37.270112 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:37.270386 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:37.308379 2026] [security2:error] [pid 123784:tid 123929] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/fff.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIKwAAAAs"]
[Tue Aug 18 13:01:37.323480 2026] [security2:error] [pid 139043:tid 139186] [client 20.186.30.159:10003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/k.php"] [unique_id "aoSB4f2v-lWn9OzQT7USqAAAAJI"]
[Tue Aug 18 13:01:37.331371 2026] [security2:error] [pid 123784:tid 124007] [client 20.119.58.187:10485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/asus.php"] [unique_id "aoSB4WwDnJBNj2tDbYYILQAAAFk"]
[Tue Aug 18 13:01:37.357160 2026] [security2:error] [pid 139043:tid 139208] [client 20.116.17.175:23015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/adminner.php"] [unique_id "aoSB4f2v-lWn9OzQT7USqgAAAKg"]
[Tue Aug 18 13:01:37.368712 2026] [security2:error] [pid 139043:tid 139228] [client 20.104.100.201:49091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/water.php"] [unique_id "aoSB4f2v-lWn9OzQT7USqwAAALw"]
[Tue Aug 18 13:01:37.370890 2026] [security2:error] [pid 139043:tid 139218] [client 20.48.236.86:14485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSB4f2v-lWn9OzQT7USrAAAALI"]
[Tue Aug 18 13:01:37.375323 2026] [security2:error] [pid 123784:tid 123794] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/cache.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIMAAATwU"]
[Tue Aug 18 13:01:37.387708 2026] [security2:error] [pid 123784:tid 123953] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB4WwDnJBNj2tDbYYILwAAIw8"]
[Tue Aug 18 13:01:37.421321 2026] [security2:error] [pid 123784:tid 123972] [client 216.244.66.232:37446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIMQAAADY"]
[Tue Aug 18 13:01:37.421428 2026] [security2:error] [pid 123784:tid 123972] [client 216.244.66.232:37446] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIMQAAADY"]
[Tue Aug 18 13:01:37.423564 2026] [security2:error] [pid 139043:tid 139194] [client 20.127.136.245:8062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/f35.php"] [unique_id "aoSB4f2v-lWn9OzQT7USrQAAAJo"]
[Tue Aug 18 13:01:37.424699 2026] [security2:error] [pid 123784:tid 123851] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/mo.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIMgAAUD4"]
[Tue Aug 18 13:01:37.431838 2026] [security2:error] [pid 139043:tid 139204] [client 68.221.73.131:13401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/apreset.php"] [unique_id "aoSB4f2v-lWn9OzQT7USrgAAAKQ"]
[Tue Aug 18 13:01:37.443808 2026] [security2:error] [pid 139043:tid 139126] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSB4f2v-lWn9OzQT7USrwAA7VI"]
[Tue Aug 18 13:01:37.444374 2026] [security2:error] [pid 139043:tid 139292] [client 20.75.92.165:4317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/atomlib.php"] [unique_id "aoSB4f2v-lWn9OzQT7USsAAAAPw"]
[Tue Aug 18 13:01:37.460081 2026] [security2:error] [pid 123784:tid 123984] [client 20.116.17.175:53787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/kj.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIMwAAAEI"]
[Tue Aug 18 13:01:37.471536 2026] [security2:error] [pid 123784:tid 124042] [client 20.104.100.201:61965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/thoms.php"] [unique_id "aoSB4WwDnJBNj2tDbYYINAAAAHw"]
[Tue Aug 18 13:01:37.479490 2026] [security2:error] [pid 139043:tid 139268] [client 20.79.204.6:11681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/buy.php"] [unique_id "aoSB4f2v-lWn9OzQT7USsQAAAOQ"]
[Tue Aug 18 13:01:37.479828 2026] [security2:error] [pid 139043:tid 139245] [client 20.1.169.243:5800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/wp-mail.php"] [unique_id "aoSB4f2v-lWn9OzQT7USsgAAAM0"]
[Tue Aug 18 13:01:37.480695 2026] [security2:error] [pid 139043:tid 139200] [client 20.100.169.31:24250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSB4f2v-lWn9OzQT7USswAAAKA"]
[Tue Aug 18 13:01:37.510676 2026] [security2:error] [pid 139043:tid 139215] [client 158.23.17.4:56723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/xs.php"] [unique_id "aoSB4f2v-lWn9OzQT7UStAAAAK8"]
[Tue Aug 18 13:01:37.555347 2026] [security2:error] [pid 139043:tid 139236] [client 20.163.43.14:8938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/k.php"] [unique_id "aoSB4f2v-lWn9OzQT7UStQAAAMQ"]
[Tue Aug 18 13:01:37.556940 2026] [security2:error] [pid 123784:tid 124032] [client 37.40.227.74:57190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIOQAAAHI"]
[Tue Aug 18 13:01:37.557044 2026] [security2:error] [pid 123784:tid 124032] [client 37.40.227.74:57190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIOQAAAHI"]
[Tue Aug 18 13:01:37.572094 2026] [security2:error] [pid 139043:tid 139266] [client 85.204.70.114:60988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aoSB4f2v-lWn9OzQT7UStgAAAOI"]
[Tue Aug 18 13:01:37.576965 2026] [security2:error] [pid 139043:tid 139206] [client 20.186.30.159:10021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/82.php"] [unique_id "aoSB4f2v-lWn9OzQT7UStwAAAKY"]
[Tue Aug 18 13:01:37.586601 2026] [security2:error] [pid 139043:tid 139283] [client 158.23.17.4:31895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/mz.php"] [unique_id "aoSB4f2v-lWn9OzQT7USuAAAAPM"]
[Tue Aug 18 13:01:37.619458 2026] [security2:error] [pid 139043:tid 139131] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSB4f2v-lWn9OzQT7USugAAk1c"]
[Tue Aug 18 13:01:37.621244 2026] [security2:error] [pid 139043:tid 139213] [client 20.80.111.3:41256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/live.php"] [unique_id "aoSB4f2v-lWn9OzQT7USuwAAAK0"]
[Tue Aug 18 13:01:37.625971 2026] [security2:error] [pid 123784:tid 123991] [client 158.23.17.4:54744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ue.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIPAAAAEk"]
[Tue Aug 18 13:01:37.642009 2026] [security2:error] [pid 123784:tid 123919] [client 20.91.215.254:11598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/chosen.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIPQAAAAE"]
[Tue Aug 18 13:01:37.643205 2026] [security2:error] [pid 139043:tid 139197] [client 20.104.100.201:49420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/fine.php"] [unique_id "aoSB4f2v-lWn9OzQT7USvAAAAJ0"]
[Tue Aug 18 13:01:37.663884 2026] [security2:error] [pid 123784:tid 123935] [client 213.35.127.232:57418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIPwAAABE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:37.685049 2026] [security2:error] [pid 139043:tid 139267] [client 20.79.204.6:11577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/buy.php"] [unique_id "aoSB4f2v-lWn9OzQT7USvQAAAOM"]
[Tue Aug 18 13:01:37.685187 2026] [security2:error] [pid 139043:tid 139199] [client 20.119.58.187:10447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/about.php"] [unique_id "aoSB4f2v-lWn9OzQT7USvgAAAJ8"]
[Tue Aug 18 13:01:37.688765 2026] [security2:error] [pid 123784:tid 123992] [client 168.62.48.100:18080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIQQAAAEo"]
[Tue Aug 18 13:01:37.710599 2026] [security2:error] [pid 123784:tid 123970] [client 158.158.74.177:22873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-configs.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIQwAAADQ"]
[Tue Aug 18 13:01:37.724839 2026] [security2:error] [pid 139043:tid 139279] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/inputs.php"] [unique_id "aoSB4f2v-lWn9OzQT7USwAAAAO8"]
[Tue Aug 18 13:01:37.761449 2026] [security2:error] [pid 139043:tid 139259] [client 20.102.65.165:3061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/akismet.php"] [unique_id "aoSB4f2v-lWn9OzQT7USwQAAANs"]
[Tue Aug 18 13:01:37.785794 2026] [security2:error] [pid 139043:tid 139260] [client 20.75.92.165:4338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/min.php"] [unique_id "aoSB4f2v-lWn9OzQT7USwgAAANw"]
[Tue Aug 18 13:01:37.792683 2026] [security2:error] [pid 123784:tid 123943] [client 135.225.78.186:19402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/images.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIRwAAABk"]
[Tue Aug 18 13:01:37.794755 2026] [security2:error] [pid 139043:tid 139154] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSB4f2v-lWn9OzQT7USwwABAW4"]
[Tue Aug 18 13:01:37.821193 2026] [security2:error] [pid 123784:tid 123965] [client 172.202.39.151:63683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/akcc.php"] [unique_id "aoSB4WwDnJBNj2tDbYYISAAAAC8"]
[Tue Aug 18 13:01:37.843201 2026] [security2:error] [pid 123784:tid 123948] [client 20.226.112.14:34213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/bsg-management/php.php"] [unique_id "aoSB4WwDnJBNj2tDbYYISgAAAB4"]
[Tue Aug 18 13:01:37.844234 2026] [security2:error] [pid 123784:tid 124015] [client 20.1.169.243:5812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/wp-the.php"] [unique_id "aoSB4WwDnJBNj2tDbYYISwAAAGE"]
[Tue Aug 18 13:01:37.855935 2026] [security2:error] [pid 123784:tid 123977] [client 20.250.13.23:55971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-admin/import.php"] [unique_id "aoSB4WwDnJBNj2tDbYYITQAAADs"]
[Tue Aug 18 13:01:37.869236 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:37.869506 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:37.890932 2026] [autoindex:error] [pid 123784:tid 124025] [client 20.79.204.6:2625] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:37.917089 2026] [security2:error] [pid 139043:tid 139225] [client 20.104.100.201:61382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSB4f2v-lWn9OzQT7USyAAAALk"]
[Tue Aug 18 13:01:37.918031 2026] [security2:error] [pid 139043:tid 139175] [client 20.104.100.201:49683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/loader.php"] [unique_id "aoSB4f2v-lWn9OzQT7USyQAAAIc"]
[Tue Aug 18 13:01:37.940281 2026] [security2:error] [pid 139043:tid 139202] [client 20.251.112.238:20210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/dsd.php"] [unique_id "aoSB4f2v-lWn9OzQT7USygAAAKI"]
[Tue Aug 18 13:01:37.968281 2026] [security2:error] [pid 139043:tid 139251] [client 85.204.70.114:32768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aoSB4f2v-lWn9OzQT7USywAAANM"]
[Tue Aug 18 13:01:37.969672 2026] [security2:error] [pid 139043:tid 139157] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSB4f2v-lWn9OzQT7USzAAAqXE"]
[Tue Aug 18 13:01:37.975419 2026] [security2:error] [pid 139043:tid 139153] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB4f2v-lWn9OzQT7USzQAA0W0"]
[Tue Aug 18 13:01:37.997029 2026] [security2:error] [pid 123784:tid 123889] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/qr.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIUwAAHWQ"]
[Tue Aug 18 13:01:38.015611 2026] [security2:error] [pid 123784:tid 123848] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIVAAAEjs"]
[Tue Aug 18 13:01:38.017771 2026] [security2:error] [pid 123784:tid 123911] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIVQAAW3o"]
[Tue Aug 18 13:01:38.036349 2026] [security2:error] [pid 139043:tid 139159] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/media.php"] [unique_id "aoSB4v2v-lWn9OzQT7USzwAA4HM"]
[Tue Aug 18 13:01:38.037220 2026] [security2:error] [pid 139043:tid 139275] [client 20.119.58.187:10436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/atomlib.php"] [unique_id "aoSB4v2v-lWn9OzQT7US0AAAAOs"]
[Tue Aug 18 13:01:38.054268 2026] [security2:error] [pid 123784:tid 123898] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/admin.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIVgAAFm0"]
[Tue Aug 18 13:01:38.059985 2026] [security2:error] [pid 123784:tid 123993] [client 20.80.111.3:18449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/bypass.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIVwAAAEs"]
[Tue Aug 18 13:01:38.060882 2026] [security2:error] [pid 139043:tid 139203] [client 20.186.30.159:10004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/dex.php"] [unique_id "aoSB4v2v-lWn9OzQT7US0QAAAKM"]
[Tue Aug 18 13:01:38.068983 2026] [security2:error] [pid 123784:tid 124038] [client 20.163.43.14:8840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/403.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIWAAAAHg"]
[Tue Aug 18 13:01:38.075443 2026] [security2:error] [pid 123784:tid 123988] [client 20.151.109.219:14111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/loading.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIWwAAAEY"]
[Tue Aug 18 13:01:38.086471 2026] [security2:error] [pid 123784:tid 123952] [client 20.79.204.6:11691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/cong.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIXAAAACI"]
[Tue Aug 18 13:01:38.089367 2026] [security2:error] [pid 123784:tid 123892] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/mac.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIXQAAPWc"]
[Tue Aug 18 13:01:38.090754 2026] [security2:error] [pid 123784:tid 123956] [client 20.79.204.6:2625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIXgAAACY"]
[Tue Aug 18 13:01:38.103096 2026] [security2:error] [pid 139043:tid 139294] [client 20.75.92.165:4341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/mac.php"] [unique_id "aoSB4v2v-lWn9OzQT7US0wAAAP4"]
[Tue Aug 18 13:01:38.116764 2026] [security2:error] [pid 139043:tid 139047] [remote 191.237.254.161:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/1.php"] [unique_id "aoSB4v2v-lWn9OzQT7US1AABAwM"]
[Tue Aug 18 13:01:38.116854 2026] [security2:error] [pid 139043:tid 139047] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/1.php"] [unique_id "aoSB4v2v-lWn9OzQT7US1AABAwM"]
[Tue Aug 18 13:01:38.119119 2026] [security2:error] [pid 139043:tid 139184] [client 20.102.65.165:2991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/admin.php"] [unique_id "aoSB4v2v-lWn9OzQT7US1QAAAJA"]
[Tue Aug 18 13:01:38.133071 2026] [security2:error] [pid 139043:tid 139253] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB4v2v-lWn9OzQT7US1gAAANU"]
[Tue Aug 18 13:01:38.140022 2026] [security2:error] [pid 123784:tid 123829] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/coffee.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIYAAAeyg"]
[Tue Aug 18 13:01:38.147684 2026] [security2:error] [pid 139043:tid 139151] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSB4v2v-lWn9OzQT7US1wAAyWs"]
[Tue Aug 18 13:01:38.165612 2026] [security2:error] [pid 123784:tid 123858] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIYgAAH0U"]
[Tue Aug 18 13:01:38.172535 2026] [authz_core:error] [pid 123784:tid 123816] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:38.172798 2026] [authz_core:error] [pid 123784:tid 123816] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:38.177969 2026] [security2:error] [pid 139043:tid 139191] [client 20.116.17.175:53818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSB4v2v-lWn9OzQT7US2AAAAJc"]
[Tue Aug 18 13:01:38.195801 2026] [security2:error] [pid 139043:tid 139149] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSB4v2v-lWn9OzQT7US2QAA1mk"]
[Tue Aug 18 13:01:38.198085 2026] [security2:error] [pid 139043:tid 139269] [client 20.104.100.201:49436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/zero.php"] [unique_id "aoSB4v2v-lWn9OzQT7US2gAAAOU"]
[Tue Aug 18 13:01:38.198907 2026] [security2:error] [pid 139043:tid 139233] [client 158.23.17.4:58695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/lr.php"] [unique_id "aoSB4v2v-lWn9OzQT7US2wAAAME"]
[Tue Aug 18 13:01:38.207916 2026] [security2:error] [pid 139043:tid 139176] [client 20.1.169.243:5791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/wp.php"] [unique_id "aoSB4v2v-lWn9OzQT7US3AAAAIg"]
[Tue Aug 18 13:01:38.227156 2026] [security2:error] [pid 139043:tid 139248] [client 20.79.204.6:10711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/x.php"] [unique_id "aoSB4v2v-lWn9OzQT7US3QAAANA"]
[Tue Aug 18 13:01:38.233261 2026] [security2:error] [pid 139043:tid 139179] [client 172.202.39.151:44158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wk/index.php"] [unique_id "aoSB4v2v-lWn9OzQT7US3gAAAIs"]
[Tue Aug 18 13:01:38.233381 2026] [security2:error] [pid 139043:tid 139182] [client 168.62.48.100:18092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSB4v2v-lWn9OzQT7US3wAAAI4"]
[Tue Aug 18 13:01:38.257684 2026] [security2:error] [pid 123784:tid 123957] [client 20.226.112.14:34182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/byp8.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIZgAAACc"]
[Tue Aug 18 13:01:38.269640 2026] [security2:error] [pid 123784:tid 123931] [client 20.104.100.201:34260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/root.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIZwAAAA0"]
[Tue Aug 18 13:01:38.270519 2026] [security2:error] [pid 123784:tid 123790] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/yj09.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIaAAAcwE"]
[Tue Aug 18 13:01:38.286119 2026] [security2:error] [pid 139043:tid 139255] [client 20.79.204.6:11569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/cong.php"] [unique_id "aoSB4v2v-lWn9OzQT7US4AAAANc"]
[Tue Aug 18 13:01:38.307213 2026] [security2:error] [pid 123784:tid 123864] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/scxy.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIagAAWUs"]
[Tue Aug 18 13:01:38.318734 2026] [security2:error] [pid 139043:tid 139296] [client 20.91.215.254:27116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/u.php"] [unique_id "aoSB4v2v-lWn9OzQT7US4QAAAQA"]
[Tue Aug 18 13:01:38.324015 2026] [security2:error] [pid 139043:tid 139162] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB4v2v-lWn9OzQT7US4wABAnY"]
[Tue Aug 18 13:01:38.325875 2026] [security2:error] [pid 139043:tid 139169] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSB4v2v-lWn9OzQT7US5AAA6n0"]
[Tue Aug 18 13:01:38.327797 2026] [security2:error] [pid 123784:tid 124045] [client 20.100.169.31:4321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIbAAAAH8"]
[Tue Aug 18 13:01:38.330359 2026] [security2:error] [pid 123784:tid 123891] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-mail.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIbQAAJGY"]
[Tue Aug 18 13:01:38.342122 2026] [security2:error] [pid 123784:tid 123995] [client 20.186.30.159:9999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/puc.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIbgAAAE0"]
[Tue Aug 18 13:01:38.352734 2026] [security2:error] [pid 123784:tid 123791] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIbwAAIwI"]
[Tue Aug 18 13:01:38.353904 2026] [security2:error] [pid 139043:tid 139208] [client 85.204.70.114:32770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aoSB4v2v-lWn9OzQT7US5QAAAKg"]
[Tue Aug 18 13:01:38.363086 2026] [security2:error] [pid 123784:tid 123972] [client 20.116.17.175:22924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/dragonshell.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIcAAAADY"]
[Tue Aug 18 13:01:38.391876 2026] [security2:error] [pid 139043:tid 139239] [client 20.65.98.162:45624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/gm.php"] [unique_id "aoSB4v2v-lWn9OzQT7US5wAAAMc"]
[Tue Aug 18 13:01:38.391911 2026] [security2:error] [pid 139043:tid 139227] [client 20.119.58.187:10177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSB4v2v-lWn9OzQT7US5gAAALs"]
[Tue Aug 18 13:01:38.398334 2026] [security2:error] [pid 123784:tid 123860] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/blurbs.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIcwAAMUc"]
[Tue Aug 18 13:01:38.401669 2026] [security2:error] [pid 139043:tid 139243] [client 158.158.74.177:9244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-post.php"] [unique_id "aoSB4v2v-lWn9OzQT7US6AAAAMs"]
[Tue Aug 18 13:01:38.413066 2026] [security2:error] [pid 139043:tid 139218] [client 20.75.92.165:4236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/nc4.php"] [unique_id "aoSB4v2v-lWn9OzQT7US6QAAALI"]
[Tue Aug 18 13:01:38.426100 2026] [security2:error] [pid 139043:tid 139164] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/bajah.php"] [unique_id "aoSB4v2v-lWn9OzQT7US6gAApHg"]
[Tue Aug 18 13:01:38.445262 2026] [security2:error] [pid 139043:tid 139277] [client 20.151.109.219:60887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ke.php"] [unique_id "aoSB4v2v-lWn9OzQT7US6wAAAO0"]
[Tue Aug 18 13:01:38.456095 2026] [security2:error] [pid 139043:tid 139268] [client 20.48.236.86:14825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/sky.php"] [unique_id "aoSB4v2v-lWn9OzQT7US7gAAAOQ"]
[Tue Aug 18 13:01:38.463657 2026] [security2:error] [pid 123784:tid 123888] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/domvf.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIdAAAfGM"]
[Tue Aug 18 13:01:38.470903 2026] [authz_core:error] [pid 123784:tid 123855] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:38.471149 2026] [authz_core:error] [pid 123784:tid 123855] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:38.475971 2026] [security2:error] [pid 139043:tid 139215] [client 20.104.100.201:49141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/002.php"] [unique_id "aoSB4v2v-lWn9OzQT7US8AAAAK8"]
[Tue Aug 18 13:01:38.480046 2026] [security2:error] [pid 123784:tid 123882] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/o.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIdgAAQ10"]
[Tue Aug 18 13:01:38.489057 2026] [security2:error] [pid 139043:tid 139177] [client 20.102.65.165:3024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/ajax.php"] [unique_id "aoSB4v2v-lWn9OzQT7US8QAAAIk"]
[Tue Aug 18 13:01:38.492083 2026] [security2:error] [pid 139043:tid 139252] [client 20.250.13.23:6784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSB4v2v-lWn9OzQT7US8gAAANQ"]
[Tue Aug 18 13:01:38.494400 2026] [security2:error] [pid 123784:tid 123871] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/fpwch.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIeAAAA1I"]
[Tue Aug 18 13:01:38.500482 2026] [security2:error] [pid 139043:tid 139161] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSB4v2v-lWn9OzQT7US8wAA4nU"]
[Tue Aug 18 13:01:38.512313 2026] [security2:error] [pid 139043:tid 139137] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/adminner.php"] [unique_id "aoSB4v2v-lWn9OzQT7US9AAAk10"]
[Tue Aug 18 13:01:38.520390 2026] [security2:error] [pid 139043:tid 139210] [client 196.12.128.158:55797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSB4v2v-lWn9OzQT7US9QAAAKo"]
[Tue Aug 18 13:01:38.520541 2026] [security2:error] [pid 139043:tid 139210] [client 196.12.128.158:55797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSB4v2v-lWn9OzQT7US9QAAAKo"]
[Tue Aug 18 13:01:38.529847 2026] [security2:error] [pid 123784:tid 123846] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/abcd.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIegAAcjk"]
[Tue Aug 18 13:01:38.546577 2026] [security2:error] [pid 123784:tid 123894] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/simple.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIewAAP2k"]
[Tue Aug 18 13:01:38.562872 2026] [security2:error] [pid 123784:tid 123839] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/dirs.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIfQAATDI"]
[Tue Aug 18 13:01:38.568867 2026] [security2:error] [pid 123784:tid 123974] [client 20.104.100.201:34255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/fpwch.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIfgAAADg"]
[Tue Aug 18 13:01:38.573148 2026] [security2:error] [pid 139043:tid 139171] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/wp-manager.php"] [unique_id "aoSB4v2v-lWn9OzQT7US-AAAnH8"]
[Tue Aug 18 13:01:38.576616 2026] [security2:error] [pid 139043:tid 139291] [client 20.1.169.243:5350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/wso.php"] [unique_id "aoSB4v2v-lWn9OzQT7US-QAAAPs"]
[Tue Aug 18 13:01:38.586102 2026] [security2:error] [pid 139043:tid 139199] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/lite.php"] [unique_id "aoSB4v2v-lWn9OzQT7US-gAAAJ8"]
[Tue Aug 18 13:01:38.599389 2026] [security2:error] [pid 123784:tid 123905] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/xiugai.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIfwAASXQ"]
[Tue Aug 18 13:01:38.616204 2026] [security2:error] [pid 139043:tid 139286] [client 20.251.112.238:33941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/c4.php"] [unique_id "aoSB4v2v-lWn9OzQT7US-wAAAPY"]
[Tue Aug 18 13:01:38.616684 2026] [security2:error] [pid 123784:tid 123881] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/wp-load.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIgAAAB1w"]
[Tue Aug 18 13:01:38.629967 2026] [security2:error] [pid 123784:tid 123910] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/bb.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIgQAAAXk"]
[Tue Aug 18 13:01:38.638093 2026] [security2:error] [pid 123784:tid 124010] [client 20.186.30.159:9984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/inso.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIggAAAFw"]
[Tue Aug 18 13:01:38.641903 2026] [security2:error] [pid 139043:tid 139142] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/155.php"] [unique_id "aoSB4v2v-lWn9OzQT7US_QAAq2I"]
[Tue Aug 18 13:01:38.647127 2026] [security2:error] [pid 139043:tid 139263] [client 20.102.65.165:8485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/img.php"] [unique_id "aoSB4v2v-lWn9OzQT7US_gAAAN8"]
[Tue Aug 18 13:01:38.676974 2026] [security2:error] [pid 139043:tid 139195] [client 68.221.73.131:13387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/1mage.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTAAAAAJs"]
[Tue Aug 18 13:01:38.683393 2026] [security2:error] [pid 123784:tid 123997] [client 213.35.127.232:57638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIhAAAAE8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:38.688510 2026] [security2:error] [pid 139043:tid 139236] [client 20.79.204.6:11532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTAwAAAMQ"]
[Tue Aug 18 13:01:38.690532 2026] [authz_core:error] [pid 139043:tid 139048] [remote 20.79.204.6:0] AH01630: client denied by server configuration: /home2/dtbbrasilcom/public_html/wp-content/uploads/index.php
[Tue Aug 18 13:01:38.697871 2026] [security2:error] [pid 139043:tid 139189] [client 20.79.204.6:2378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTBAAAAJU"]
[Tue Aug 18 13:01:38.701757 2026] [security2:error] [pid 139043:tid 139235] [client 197.184.64.235:41964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTBQAAAMM"]
[Tue Aug 18 13:01:38.701860 2026] [security2:error] [pid 139043:tid 139235] [client 197.184.64.235:41964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTBQAAAMM"]
[Tue Aug 18 13:01:38.703228 2026] [security2:error] [pid 123784:tid 123850] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/index.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIhgAASj0"]
[Tue Aug 18 13:01:38.735656 2026] [security2:error] [pid 123784:tid 123792] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/aaa.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIiAAAZgM"]
[Tue Aug 18 13:01:38.742067 2026] [security2:error] [pid 139043:tid 139257] [client 20.127.136.245:23221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/gg.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTBwAAANk"]
[Tue Aug 18 13:01:38.745692 2026] [security2:error] [pid 139043:tid 139282] [client 85.204.70.114:32780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "aoSB4v2v-lWn9OzQT7UTCAAAAPI"]
[Tue Aug 18 13:01:38.746803 2026] [security2:error] [pid 139043:tid 139265] [client 20.119.58.187:10124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/b.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTCQAAAOE"]
[Tue Aug 18 13:01:38.758041 2026] [security2:error] [pid 139043:tid 139173] [client 20.104.100.201:49145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/zxz.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTCgAAAIU"]
[Tue Aug 18 13:01:38.767043 2026] [security2:error] [pid 139043:tid 139225] [client 20.151.109.219:39298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/nh.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTCwAAALk"]
[Tue Aug 18 13:01:38.773090 2026] [authz_core:error] [pid 123784:tid 123799] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:38.773371 2026] [authz_core:error] [pid 123784:tid 123799] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:38.784950 2026] [security2:error] [pid 123784:tid 123806] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIigAAThE"]
[Tue Aug 18 13:01:38.786326 2026] [security2:error] [pid 139043:tid 139054] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/FWAZ.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTDAAAyAo"]
[Tue Aug 18 13:01:38.789552 2026] [security2:error] [pid 139043:tid 139261] [client 20.102.65.165:5056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/abcd.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTDQAAAN0"]
[Tue Aug 18 13:01:38.804200 2026] [security2:error] [pid 123784:tid 123915] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/site.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIiwAAdX4"]
[Tue Aug 18 13:01:38.808215 2026] [security2:error] [pid 139043:tid 139209] [client 52.173.121.69:59266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTDgAAAKk"]
[Tue Aug 18 13:01:38.827029 2026] [security2:error] [pid 123784:tid 123859] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/ccc.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIjAAAQUY"]
[Tue Aug 18 13:01:38.828220 2026] [security2:error] [pid 139043:tid 139185] [client 20.163.43.14:8847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/gecko.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTEAAAAJE"]
[Tue Aug 18 13:01:38.841075 2026] [security2:error] [pid 139043:tid 139181] [client 20.48.236.86:14465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/file5.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTEQAAAI0"]
[Tue Aug 18 13:01:38.855183 2026] [security2:error] [pid 139043:tid 139052] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/admin.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTEgAA_gg"]
[Tue Aug 18 13:01:38.862208 2026] [security2:error] [pid 123784:tid 123948] [client 158.23.17.4:15148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ka.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIjwAAAB4"]
[Tue Aug 18 13:01:38.870382 2026] [security2:error] [pid 123784:tid 123989] [client 20.104.100.201:61426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/mg.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIkAAAAEc"]
[Tue Aug 18 13:01:38.875504 2026] [security2:error] [pid 123784:tid 123887] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/reviall.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIkQAAU2I"]
[Tue Aug 18 13:01:38.888870 2026] [authz_core:error] [pid 139043:tid 139051] [remote 20.79.204.6:0] AH01630: client denied by server configuration: /home2/dtbbrasilcom/public_html/wp-content/uploads/2025/index.php
[Tue Aug 18 13:01:38.890063 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:56535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/lmfi2.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIkgAAAH0"]
[Tue Aug 18 13:01:38.892069 2026] [security2:error] [pid 123784:tid 123977] [client 216.244.66.243:51274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/exus+mais+perigosos-3/"] [unique_id "aoSB4mwDnJBNj2tDbYYIkwAAADs"]
[Tue Aug 18 13:01:38.892182 2026] [security2:error] [pid 123784:tid 123977] [client 216.244.66.243:51274] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/exus+mais+perigosos-3/"] [unique_id "aoSB4mwDnJBNj2tDbYYIkwAAADs"]
[Tue Aug 18 13:01:38.893154 2026] [security2:error] [pid 139043:tid 139288] [client 20.79.204.6:11655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/css/classwithtostring.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTFAAAAPg"]
[Tue Aug 18 13:01:38.895457 2026] [security2:error] [pid 123784:tid 123813] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/nope.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIlAAAcRg"]
[Tue Aug 18 13:01:38.915278 2026] [security2:error] [pid 123784:tid 124025] [client 20.80.111.3:27101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/lock360.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIlQAAAGs"]
[Tue Aug 18 13:01:38.915282 2026] [security2:error] [pid 139043:tid 139156] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/nope.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTFQAA-XA"]
[Tue Aug 18 13:01:38.916296 2026] [security2:error] [pid 139043:tid 139205] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/ms-edit.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTFgAAAKU"]
[Tue Aug 18 13:01:38.939631 2026] [security2:error] [pid 139043:tid 139269] [client 158.23.17.4:12517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ft.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTFwAAAOU"]
[Tue Aug 18 13:01:38.941161 2026] [security2:error] [pid 139043:tid 139273] [client 20.1.169.243:5816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/www.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTGAAAAOk"]
[Tue Aug 18 13:01:38.950716 2026] [security2:error] [pid 123784:tid 123797] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/new.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIlwAAOgg"]
[Tue Aug 18 13:01:38.974221 2026] [security2:error] [pid 123784:tid 123886] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/new.php"] [unique_id "aoSB4mwDnJBNj2tDbYYImAAAHGE"]
[Tue Aug 18 13:01:38.979015 2026] [security2:error] [pid 139043:tid 139176] [client 20.226.112.14:34221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/plugins.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTHAAAAIg"]
[Tue Aug 18 13:01:38.993946 2026] [security2:error] [pid 139043:tid 139059] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/apreset.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTHQAA0A8"]
[Tue Aug 18 13:01:38.999321 2026] [security2:error] [pid 139043:tid 139201] [client 20.226.56.190:47153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/routes.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTHgAAAKE"]
[Tue Aug 18 13:01:39.000149 2026] [security2:error] [pid 123784:tid 124002] [client 20.79.204.6:10372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/index/function.php"] [unique_id "aoSB4mwDnJBNj2tDbYYImgAAAFQ"]
[Tue Aug 18 13:01:39.021599 2026] [security2:error] [pid 123784:tid 123941] [client 20.75.92.165:2030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/as.php"] [unique_id "aoSB42wDnJBNj2tDbYYImwAAABc"]
[Tue Aug 18 13:01:39.023622 2026] [security2:error] [pid 123784:tid 123990] [client 102.213.179.104:50872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB42wDnJBNj2tDbYYInAAAAEg"]
[Tue Aug 18 13:01:39.023745 2026] [security2:error] [pid 123784:tid 123990] [client 102.213.179.104:50872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB42wDnJBNj2tDbYYInAAAAEg"]
[Tue Aug 18 13:01:39.036856 2026] [security2:error] [pid 123784:tid 123927] [client 20.104.100.201:49414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/memberfuns.php"] [unique_id "aoSB42wDnJBNj2tDbYYInQAAAAk"]
[Tue Aug 18 13:01:39.042488 2026] [security2:error] [pid 123784:tid 123863] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/1mage.php"] [unique_id "aoSB42wDnJBNj2tDbYYIngAAY0o"]
[Tue Aug 18 13:01:39.062641 2026] [security2:error] [pid 123784:tid 123947] [client 20.151.109.219:63951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/oo.php"] [unique_id "aoSB42wDnJBNj2tDbYYInwAAAB0"]
[Tue Aug 18 13:01:39.064882 2026] [security2:error] [pid 139043:tid 139270] [client 158.158.74.177:9279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTIAAAAOY"]
[Tue Aug 18 13:01:39.065009 2026] [security2:error] [pid 123784:tid 123861] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/imsc.php"] [unique_id "aoSB42wDnJBNj2tDbYYIoAAALEg"]
[Tue Aug 18 13:01:39.074143 2026] [security2:error] [pid 139043:tid 139296] [client 20.116.17.175:56073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/png.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTIQAAAQA"]
[Tue Aug 18 13:01:39.076219 2026] [security2:error] [pid 139043:tid 139062] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTIgABAhI"]
[Tue Aug 18 13:01:39.080433 2026] [authz_core:error] [pid 123784:tid 123838] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:39.080757 2026] [authz_core:error] [pid 123784:tid 123838] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:39.084026 2026] [security2:error] [pid 139043:tid 139168] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/imscjpg.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTIwAA6nw"]
[Tue Aug 18 13:01:39.097943 2026] [security2:error] [pid 123784:tid 123907] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSB42wDnJBNj2tDbYYIogAAEnY"]
[Tue Aug 18 13:01:39.098694 2026] [security2:error] [pid 123784:tid 124016] [client 20.119.58.187:10117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/buy.php"] [unique_id "aoSB42wDnJBNj2tDbYYIowAAAGI"]
[Tue Aug 18 13:01:39.120728 2026] [security2:error] [pid 123784:tid 123913] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/qlex1.php"] [unique_id "aoSB42wDnJBNj2tDbYYIpAAAW3w"]
[Tue Aug 18 13:01:39.133735 2026] [security2:error] [pid 139043:tid 139239] [client 85.204.70.114:32786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aoSB4_2v-lWn9OzQT7UTJQAAAMc"]
[Tue Aug 18 13:01:39.134794 2026] [security2:error] [pid 139043:tid 139227] [client 168.62.48.100:18032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTJgAAALs"]
[Tue Aug 18 13:01:39.139085 2026] [security2:error] [pid 123784:tid 123933] [client 20.250.13.23:6800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/ebs.php7"] [unique_id "aoSB42wDnJBNj2tDbYYIpgAAAA8"]
[Tue Aug 18 13:01:39.146275 2026] [security2:error] [pid 123784:tid 123883] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/mariju.php"] [unique_id "aoSB42wDnJBNj2tDbYYIpwAAel4"]
[Tue Aug 18 13:01:39.160131 2026] [security2:error] [pid 139043:tid 139219] [client 20.251.112.238:18217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/an7.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTKAAAALM"]
[Tue Aug 18 13:01:39.161577 2026] [security2:error] [pid 139043:tid 139277] [client 20.100.169.31:4316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTKQAAAO0"]
[Tue Aug 18 13:01:39.179506 2026] [security2:error] [pid 139043:tid 139166] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTKgAAzXo"]
[Tue Aug 18 13:01:39.182343 2026] [security2:error] [pid 139043:tid 139287] [client 20.91.215.254:27092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/customize.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTKwAAAPc"]
[Tue Aug 18 13:01:39.184568 2026] [security2:error] [pid 139043:tid 139200] [client 20.186.30.159:9996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/aa.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTLAAAAKA"]
[Tue Aug 18 13:01:39.198217 2026] [security2:error] [pid 123784:tid 123857] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/contacto.php"] [unique_id "aoSB42wDnJBNj2tDbYYIqQAAeEQ"]
[Tue Aug 18 13:01:39.222932 2026] [security2:error] [pid 123784:tid 123904] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/image2.php"] [unique_id "aoSB42wDnJBNj2tDbYYIqgAAUnM"]
[Tue Aug 18 13:01:39.244065 2026] [security2:error] [pid 139043:tid 139252] [client 20.104.100.201:34778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/reop3.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTLQAAANQ"]
[Tue Aug 18 13:01:39.244852 2026] [security2:error] [pid 123784:tid 123809] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSB42wDnJBNj2tDbYYIqwAAexQ"]
[Tue Aug 18 13:01:39.250125 2026] [security2:error] [pid 139043:tid 139160] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTLgAApnQ"]
[Tue Aug 18 13:01:39.251048 2026] [security2:error] [pid 139043:tid 139081] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/fb.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTLwAAjCU"]
[Tue Aug 18 13:01:39.261856 2026] [security2:error] [pid 139043:tid 139197] [client 20.48.236.86:14519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/xyn.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTMAAAAJ0"]
[Tue Aug 18 13:01:39.268166 2026] [security2:error] [pid 139043:tid 139210] [client 20.116.17.175:55248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/setup-config.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTMQAAAKo"]
[Tue Aug 18 13:01:39.269773 2026] [security2:error] [pid 123784:tid 123880] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/gi.php"] [unique_id "aoSB42wDnJBNj2tDbYYIrAAAKls"]
[Tue Aug 18 13:01:39.287661 2026] [security2:error] [pid 123784:tid 123872] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/video.php"] [unique_id "aoSB42wDnJBNj2tDbYYIrQAAZ1M"]
[Tue Aug 18 13:01:39.295744 2026] [security2:error] [pid 123784:tid 123923] [client 135.225.78.186:65454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/ops.php"] [unique_id "aoSB42wDnJBNj2tDbYYIrwAAAAU"]
[Tue Aug 18 13:01:39.300088 2026] [security2:error] [pid 139043:tid 139188] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/rip.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTMgAAAJQ"]
[Tue Aug 18 13:01:39.302647 2026] [security2:error] [pid 139043:tid 139237] [client 20.79.204.6:11710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/db.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTMwAAAMU"]
[Tue Aug 18 13:01:39.306614 2026] [security2:error] [pid 139043:tid 139258] [client 20.1.169.243:5822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/x.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTNAAAANo"]
[Tue Aug 18 13:01:39.315631 2026] [security2:error] [pid 139043:tid 139267] [client 20.104.100.201:49416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/aa.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTNQAAAOM"]
[Tue Aug 18 13:01:39.320590 2026] [security2:error] [pid 139043:tid 139102] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/hel.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTNgAAnzo"]
[Tue Aug 18 13:01:39.321488 2026] [security2:error] [pid 139043:tid 139208] [client 20.79.204.6:2901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTNwAAAKg"]
[Tue Aug 18 13:01:39.331147 2026] [security2:error] [pid 139043:tid 139279] [client 20.163.43.14:8860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/aa.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTOAAAAO8"]
[Tue Aug 18 13:01:39.338333 2026] [security2:error] [pid 123784:tid 123817] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/grok.php"] [unique_id "aoSB42wDnJBNj2tDbYYIsAAAURw"]
[Tue Aug 18 13:01:39.359128 2026] [security2:error] [pid 123784:tid 123821] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/indes.php"] [unique_id "aoSB42wDnJBNj2tDbYYIswAAaCA"]
[Tue Aug 18 13:01:39.376162 2026] [security2:error] [pid 139043:tid 139097] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/tTPcH.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTOgAA7jU"]
[Tue Aug 18 13:01:39.396159 2026] [security2:error] [pid 123784:tid 123795] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/file.php"] [unique_id "aoSB42wDnJBNj2tDbYYItAAAagY"]
[Tue Aug 18 13:01:39.397856 2026] [security2:error] [pid 123784:tid 123856] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/bs1.php"] [unique_id "aoSB42wDnJBNj2tDbYYItQAAJ0M"]
[Tue Aug 18 13:01:39.409263 2026] [security2:error] [pid 123784:tid 123975] [client 20.151.109.219:39358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ja.php"] [unique_id "aoSB42wDnJBNj2tDbYYItgAAADk"]
[Tue Aug 18 13:01:39.426912 2026] [security2:error] [pid 123784:tid 123789] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/hp2.php"] [unique_id "aoSB42wDnJBNj2tDbYYIuAAADQA"]
[Tue Aug 18 13:01:39.436963 2026] [security2:error] [pid 139043:tid 139265] [client 158.23.17.4:15133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ot.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTPAAAAOE"]
[Tue Aug 18 13:01:39.445768 2026] [autoindex:error] [pid 139043:tid 139103] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/dtbbrasilcom/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:39.452246 2026] [security2:error] [pid 139043:tid 139145] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/yb.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTPQAAuWU"]
[Tue Aug 18 13:01:39.460806 2026] [security2:error] [pid 139043:tid 139286] [client 20.119.58.187:10463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/bless.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTPgAAAPY"]
[Tue Aug 18 13:01:39.464253 2026] [security2:error] [pid 123784:tid 124013] [client 68.221.73.131:46210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/imsc.php"] [unique_id "aoSB42wDnJBNj2tDbYYIuwAAAF8"]
[Tue Aug 18 13:01:39.492230 2026] [security2:error] [pid 123784:tid 123903] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/sn.php"] [unique_id "aoSB42wDnJBNj2tDbYYIvQAAWXI"]
[Tue Aug 18 13:01:39.492626 2026] [security2:error] [pid 123784:tid 123832] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/vc.php"] [unique_id "aoSB42wDnJBNj2tDbYYIvgAAfys"]
[Tue Aug 18 13:01:39.508575 2026] [security2:error] [pid 139043:tid 139261] [client 20.186.30.159:10107] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "marquesti.fabioweb.com.br"] [uri "/1.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTPwAAAN0"]
[Tue Aug 18 13:01:39.508693 2026] [security2:error] [pid 139043:tid 139261] [client 20.186.30.159:10107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/1.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTPwAAAN0"]
[Tue Aug 18 13:01:39.529518 2026] [security2:error] [pid 139043:tid 139276] [client 85.204.70.114:32802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aoSB4_2v-lWn9OzQT7UTQAAAAOw"]
[Tue Aug 18 13:01:39.531411 2026] [security2:error] [pid 123784:tid 123845] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/pema.php"] [unique_id "aoSB42wDnJBNj2tDbYYIvwAATTg"]
[Tue Aug 18 13:01:39.534316 2026] [security2:error] [pid 139043:tid 139264] [client 20.127.136.245:8025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/class.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTQQAAAOA"]
[Tue Aug 18 13:01:39.555550 2026] [security2:error] [pid 123784:tid 123885] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/epinyins.php"] [unique_id "aoSB42wDnJBNj2tDbYYIwAAANmA"]
[Tue Aug 18 13:01:39.557686 2026] [security2:error] [pid 139043:tid 139190] [client 20.79.204.6:11677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/db.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTQgAAAJY"]
[Tue Aug 18 13:01:39.559367 2026] [security2:error] [pid 139043:tid 139110] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/sh.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTQwAAo0I"]
[Tue Aug 18 13:01:39.583252 2026] [security2:error] [pid 139043:tid 139299] [client 20.104.100.201:34764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/php5.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTRAAAAQM"]
[Tue Aug 18 13:01:39.590903 2026] [security2:error] [pid 139043:tid 139178] [client 20.104.100.201:49454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/echkm.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTRQAAAIo"]
[Tue Aug 18 13:01:39.599273 2026] [security2:error] [pid 139043:tid 139231] [client 20.75.92.165:4300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/k.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTRgAAAL8"]
[Tue Aug 18 13:01:39.622361 2026] [security2:error] [pid 139043:tid 139289] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/update/da222.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTSAAAAPk"]
[Tue Aug 18 13:01:39.634149 2026] [security2:error] [pid 139043:tid 139273] [client 158.23.17.4:57256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/h.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTSgAAAOk"]
[Tue Aug 18 13:01:39.636509 2026] [autoindex:error] [pid 139043:tid 139058] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/dtbbrasilcom/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:39.636908 2026] [security2:error] [pid 139043:tid 139234] [client 20.102.65.165:8454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/222.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTSwAAAMI"]
[Tue Aug 18 13:01:39.640461 2026] [security2:error] [pid 139043:tid 139247] [client 20.251.112.238:26141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/bsg-management/php.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTTAAAAM8"]
[Tue Aug 18 13:01:39.661879 2026] [security2:error] [pid 139043:tid 139176] [client 172.202.39.151:61736] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.sfcacessorios.com"] [uri "/1.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTTQAAAIg"]
[Tue Aug 18 13:01:39.661993 2026] [security2:error] [pid 139043:tid 139176] [client 172.202.39.151:61736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/1.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTTQAAAIg"]
[Tue Aug 18 13:01:39.672940 2026] [security2:error] [pid 139043:tid 139214] [client 20.1.169.243:5335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTTwAAAK4"]
[Tue Aug 18 13:01:39.674906 2026] [authz_core:error] [pid 123784:tid 123895] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:39.675160 2026] [authz_core:error] [pid 123784:tid 123895] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:39.691406 2026] [security2:error] [pid 123784:tid 123877] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/button.php"] [unique_id "aoSB42wDnJBNj2tDbYYIxAAAWlg"]
[Tue Aug 18 13:01:39.693574 2026] [security2:error] [pid 123784:tid 123822] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/43.php"] [unique_id "aoSB42wDnJBNj2tDbYYIxQAAMSE"]
[Tue Aug 18 13:01:39.695603 2026] [security2:error] [pid 139043:tid 139263] [client 213.35.127.232:57841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTUQAAAN8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:39.697209 2026] [security2:error] [pid 139043:tid 139201] [client 20.163.43.14:8915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/0x.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTUgAAAKE"]
[Tue Aug 18 13:01:39.717455 2026] [security2:error] [pid 123784:tid 123890] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/wlc.php"] [unique_id "aoSB42wDnJBNj2tDbYYIxgAAQmU"]
[Tue Aug 18 13:01:39.726364 2026] [security2:error] [pid 139043:tid 139244] [client 158.158.74.177:9226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTUwAAAMw"]
[Tue Aug 18 13:01:39.730128 2026] [security2:error] [pid 123784:tid 123803] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSB42wDnJBNj2tDbYYIxwAAGw4"]
[Tue Aug 18 13:01:39.734561 2026] [security2:error] [pid 139043:tid 139063] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/fi.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTVQAA5hM"]
[Tue Aug 18 13:01:39.752770 2026] [security2:error] [pid 123784:tid 123874] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/chris.php"] [unique_id "aoSB42wDnJBNj2tDbYYIyQAAQ1U"]
[Tue Aug 18 13:01:39.762504 2026] [security2:error] [pid 139043:tid 139185] [client 20.79.204.6:10712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/aaa.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTVgAAAJE"]
[Tue Aug 18 13:01:39.770459 2026] [security2:error] [pid 123784:tid 123934] [client 20.80.111.3:41225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/majalahpro-core/lib/index.php"] [unique_id "aoSB42wDnJBNj2tDbYYIygAAABA"]
[Tue Aug 18 13:01:39.772270 2026] [security2:error] [pid 123784:tid 123900] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/doc.php"] [unique_id "aoSB42wDnJBNj2tDbYYIywAAZW8"]
[Tue Aug 18 13:01:39.782440 2026] [security2:error] [pid 139043:tid 139293] [client 20.100.169.31:4940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTVwAAAP0"]
[Tue Aug 18 13:01:39.804430 2026] [security2:error] [pid 139043:tid 139204] [client 20.186.30.159:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/img.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTWQAAAKQ"]
[Tue Aug 18 13:01:39.808237 2026] [security2:error] [pid 139043:tid 139091] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/1337.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTWgAAsy8"]
[Tue Aug 18 13:01:39.815130 2026] [security2:error] [pid 139043:tid 139238] [client 20.119.58.187:10446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/class-t.api.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTWwAAAMY"]
[Tue Aug 18 13:01:39.816741 2026] [security2:error] [pid 139043:tid 139068] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTXAAAmhg"]
[Tue Aug 18 13:01:39.821533 2026] [security2:error] [pid 139043:tid 139215] [client 20.151.109.219:60381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/xx.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTXQAAAK8"]
[Tue Aug 18 13:01:39.842210 2026] [security2:error] [pid 139043:tid 139200] [client 20.116.17.175:53143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/ab.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTXgAAAKA"]
[Tue Aug 18 13:01:39.850466 2026] [security2:error] [pid 123784:tid 123814] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/Njima.php"] [unique_id "aoSB42wDnJBNj2tDbYYIzAAAABk"]
[Tue Aug 18 13:01:39.855153 2026] [security2:error] [pid 139043:tid 139226] [client 20.250.13.23:6805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTXwAAALo"]
[Tue Aug 18 13:01:39.874931 2026] [security2:error] [pid 139043:tid 139266] [client 20.104.100.201:49452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/domvf.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTYQAAAOI"]
[Tue Aug 18 13:01:39.884107 2026] [security2:error] [pid 123784:tid 123837] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/BIBIL.php"] [unique_id "aoSB42wDnJBNj2tDbYYIzgAATDA"]
[Tue Aug 18 13:01:39.905392 2026] [security2:error] [pid 139043:tid 139083] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/too.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTYgAA8yc"]
[Tue Aug 18 13:01:39.907139 2026] [security2:error] [pid 139043:tid 139206] [client 20.226.56.190:47110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/php5.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTYwAAAKY"]
[Tue Aug 18 13:01:39.915108 2026] [security2:error] [pid 139043:tid 139210] [client 20.65.98.162:45572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/ws55.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTZQAAAKo"]
[Tue Aug 18 13:01:39.922249 2026] [security2:error] [pid 123784:tid 123876] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/g3.php"] [unique_id "aoSB42wDnJBNj2tDbYYI0AAASVc"]
[Tue Aug 18 13:01:39.929088 2026] [security2:error] [pid 123784:tid 123925] [client 85.204.70.114:32808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aoSB42wDnJBNj2tDbYYI0QAAAAc"]
[Tue Aug 18 13:01:39.936623 2026] [security2:error] [pid 123784:tid 123893] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/fresh.php"] [unique_id "aoSB42wDnJBNj2tDbYYI0gAAAWg"]
[Tue Aug 18 13:01:39.942382 2026] [security2:error] [pid 139043:tid 139258] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/upload.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTaAAAANo"]
[Tue Aug 18 13:01:39.951869 2026] [autoindex:error] [pid 139043:tid 139255] [client 20.79.204.6:2194] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:39.957456 2026] [security2:error] [pid 139043:tid 139267] [client 20.48.236.86:14512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTagAAAOM"]
[Tue Aug 18 13:01:39.972941 2026] [security2:error] [pid 139043:tid 139279] [client 158.23.17.4:17558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ih.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTawAAAO8"]
[Tue Aug 18 13:01:39.976673 2026] [authz_core:error] [pid 123784:tid 123884] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:39.976938 2026] [authz_core:error] [pid 123784:tid 123884] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:39.992501 2026] [security2:error] [pid 139043:tid 139061] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTbAAA2xE"]
[Tue Aug 18 13:01:40.024347 2026] [security2:error] [pid 139043:tid 139245] [client 20.79.204.6:11680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/dropdown.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTbQAAAM0"]
[Tue Aug 18 13:01:40.034575 2026] [security2:error] [pid 139043:tid 139281] [client 20.1.169.243:5338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/aaa.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTbgAAAPE"]
[Tue Aug 18 13:01:40.042107 2026] [security2:error] [pid 139043:tid 139278] [client 20.163.43.14:8916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/zxz.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTbwAAAO4"]
[Tue Aug 18 13:01:40.043600 2026] [security2:error] [pid 139043:tid 139260] [client 168.62.48.100:18175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/blog/byp.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTcAAAANw"]
[Tue Aug 18 13:01:40.052898 2026] [security2:error] [pid 123784:tid 123849] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI1QAAXDw"]
[Tue Aug 18 13:01:40.058790 2026] [security2:error] [pid 123784:tid 123980] [client 172.213.243.2:18365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI1gAAAD4"]
[Tue Aug 18 13:01:40.064301 2026] [security2:error] [pid 139043:tid 139216] [client 20.104.100.201:34267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/acp.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTcQAAALA"]
[Tue Aug 18 13:01:40.079585 2026] [security2:error] [pid 139043:tid 139265] [client 20.116.17.175:23036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/f35.update.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTcgAAAOE"]
[Tue Aug 18 13:01:40.083788 2026] [security2:error] [pid 139043:tid 139246] [client 20.251.112.238:26127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/byp8.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTcwAAAM4"]
[Tue Aug 18 13:01:40.095711 2026] [security2:error] [pid 139043:tid 139225] [client 20.91.215.254:11471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/mah/function.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTdgAAALk"]
[Tue Aug 18 13:01:40.110503 2026] [security2:error] [pid 123784:tid 123997] [client 20.118.133.132:1493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/gm.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI1wAAAE8"]
[Tue Aug 18 13:01:40.121333 2026] [security2:error] [pid 139043:tid 139250] [client 172.202.39.151:4417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTeAAAANI"]
[Tue Aug 18 13:01:40.137422 2026] [security2:error] [pid 139043:tid 139240] [client 20.75.92.165:4309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTeQAAAMg"]
[Tue Aug 18 13:01:40.149462 2026] [security2:error] [pid 123784:tid 123992] [client 20.186.30.159:10098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/222.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI2QAAAEo"]
[Tue Aug 18 13:01:40.150399 2026] [security2:error] [pid 123784:tid 123964] [client 20.104.100.201:49101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/red.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI2gAAAC4"]
[Tue Aug 18 13:01:40.167796 2026] [security2:error] [pid 139043:tid 139242] [client 20.119.58.187:10120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/cache.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTfAAAAMo"]
[Tue Aug 18 13:01:40.173092 2026] [security2:error] [pid 139043:tid 139224] [client 20.79.204.6:11522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/dropdown.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTfQAAALg"]
[Tue Aug 18 13:01:40.176833 2026] [security2:error] [pid 123784:tid 123820] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/gj.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI2wAAfh8"]
[Tue Aug 18 13:01:40.179456 2026] [security2:error] [pid 139043:tid 139209] [client 158.23.17.4:56740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/fd.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTfgAAAKk"]
[Tue Aug 18 13:01:40.187032 2026] [security2:error] [pid 139043:tid 139276] [client 20.206.73.37:35269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/scxy.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTgAAAAOw"]
[Tue Aug 18 13:01:40.189196 2026] [autoindex:error] [pid 139043:tid 139165] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/dtbbrasilcom/public_html/wp-includes/Requests/src/Cookie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:40.214035 2026] [security2:error] [pid 139043:tid 139221] [client 20.80.111.3:2037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/pwnd/as.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTgQAAALU"]
[Tue Aug 18 13:01:40.224848 2026] [security2:error] [pid 139043:tid 139184] [client 20.127.136.245:23404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/flower.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTggAAAJA"]
[Tue Aug 18 13:01:40.225378 2026] [security2:error] [pid 123784:tid 123815] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI3AAAZho"]
[Tue Aug 18 13:01:40.241233 2026] [security2:error] [pid 123784:tid 123968] [client 52.173.121.69:38563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI3QAAADI"]
[Tue Aug 18 13:01:40.278101 2026] [authz_core:error] [pid 123784:tid 123869] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:40.278374 2026] [authz_core:error] [pid 123784:tid 123869] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:40.284204 2026] [security2:error] [pid 139043:tid 139253] [client 20.151.109.219:24443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/conn-test.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTgwAAANU"]
[Tue Aug 18 13:01:40.307892 2026] [security2:error] [pid 139043:tid 139234] [client 85.204.70.114:32822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aoSB5P2v-lWn9OzQT7UThwAAAMI"]
[Tue Aug 18 13:01:40.360629 2026] [security2:error] [pid 139043:tid 139187] [client 20.104.100.201:61387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/yas.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTiAAAAJM"]
[Tue Aug 18 13:01:40.363210 2026] [security2:error] [pid 139043:tid 139201] [client 20.79.204.6:2194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTiQAAAKE"]
[Tue Aug 18 13:01:40.369859 2026] [security2:error] [pid 139043:tid 139230] [client 20.163.43.14:8930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/www.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTigAAAL4"]
[Tue Aug 18 13:01:40.371276 2026] [security2:error] [pid 139043:tid 139220] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wk/index.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTiwAAALQ"]
[Tue Aug 18 13:01:40.373511 2026] [security2:error] [pid 123784:tid 123835] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI4AAADi4"]
[Tue Aug 18 13:01:40.374636 2026] [security2:error] [pid 139043:tid 139217] [client 20.65.98.162:2470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/ai.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTjAAAALE"]
[Tue Aug 18 13:01:40.375665 2026] [security2:error] [pid 139043:tid 139074] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTjQAA5h4"]
[Tue Aug 18 13:01:40.397138 2026] [security2:error] [pid 123784:tid 123943] [client 20.1.169.243:5357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/fpwch.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI4gAAABk"]
[Tue Aug 18 13:01:40.406665 2026] [security2:error] [pid 139043:tid 139264] [client 20.100.169.31:4794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTjwAAAOA"]
[Tue Aug 18 13:01:40.406920 2026] [authz_core:error] [pid 139043:tid 139087] [remote 57.141.22.107:22500] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:40.407275 2026] [authz_core:error] [pid 139043:tid 139087] [remote 57.141.22.107:22500] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:40.419078 2026] [security2:error] [pid 123784:tid 123977] [client 168.62.48.100:18148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI4wAAADs"]
[Tue Aug 18 13:01:40.432786 2026] [security2:error] [pid 139043:tid 139185] [client 20.104.100.201:49415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/JawirGenk.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTkQAAAJE"]
[Tue Aug 18 13:01:40.449656 2026] [security2:error] [pid 139043:tid 139290] [client 20.75.92.165:4273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/system_log.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTkgAAAPo"]
[Tue Aug 18 13:01:40.458486 2026] [security2:error] [pid 123784:tid 123935] [client 158.158.74.177:22887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-2019.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI5QAAABE"]
[Tue Aug 18 13:01:40.475918 2026] [security2:error] [pid 139043:tid 139186] [client 172.213.243.2:16869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTkwAAAJI"]
[Tue Aug 18 13:01:40.480495 2026] [security2:error] [pid 139043:tid 139288] [client 20.250.13.23:51247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTlAAAAPg"]
[Tue Aug 18 13:01:40.520441 2026] [security2:error] [pid 123784:tid 124001] [client 20.119.58.187:10469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/content.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI6AAAAFM"]
[Tue Aug 18 13:01:40.530229 2026] [security2:error] [pid 123784:tid 124026] [client 68.221.73.131:18644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/imscjpg.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI6QAAAGw"]
[Tue Aug 18 13:01:40.536000 2026] [security2:error] [pid 123784:tid 123866] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/function/function.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI6gAAY00"]
[Tue Aug 18 13:01:40.566983 2026] [autoindex:error] [pid 139043:tid 139152] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/dtbbrasilcom/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:40.595479 2026] [security2:error] [pid 123784:tid 124009] [client 20.116.17.175:54266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/12.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI7AAAAFs"]
[Tue Aug 18 13:01:40.623559 2026] [security2:error] [pid 139043:tid 139188] [client 20.186.30.159:10052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/key.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTlgAAAJQ"]
[Tue Aug 18 13:01:40.629828 2026] [security2:error] [pid 123784:tid 123978] [client 20.79.204.6:11689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/file.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI7QAAADw"]
[Tue Aug 18 13:01:40.635678 2026] [security2:error] [pid 123784:tid 123993] [client 20.151.109.219:14130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/fg.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI7gAAAEs"]
[Tue Aug 18 13:01:40.649324 2026] [security2:error] [pid 123784:tid 124029] [client 20.80.111.3:3603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/rk2.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI7wAAAG8"]
[Tue Aug 18 13:01:40.659573 2026] [security2:error] [pid 123784:tid 123988] [client 20.226.112.14:22880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/100.kb.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI8AAAAEY"]
[Tue Aug 18 13:01:40.677744 2026] [security2:error] [pid 123784:tid 123956] [client 20.251.112.238:33951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/plugins.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI8QAAACY"]
[Tue Aug 18 13:01:40.688933 2026] [security2:error] [pid 123784:tid 123825] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI8gAAUiQ"]
[Tue Aug 18 13:01:40.696144 2026] [security2:error] [pid 123784:tid 124041] [client 20.163.43.14:8947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wicked.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI8wAAAHs"]
[Tue Aug 18 13:01:40.705708 2026] [security2:error] [pid 123784:tid 123841] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/pd.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI9AAAHzQ"]
[Tue Aug 18 13:01:40.707821 2026] [security2:error] [pid 123784:tid 124021] [client 20.104.100.201:49106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/options.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI9QAAAGc"]
[Tue Aug 18 13:01:40.708196 2026] [security2:error] [pid 123784:tid 124030] [client 158.23.17.4:60749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/k.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI9gAAAHA"]
[Tue Aug 18 13:01:40.715192 2026] [security2:error] [pid 139043:tid 139300] [client 213.35.127.232:58038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTlwAAAQQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:40.721927 2026] [security2:error] [pid 123784:tid 124006] [client 85.204.70.114:32838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aoSB5GwDnJBNj2tDbYYI9wAAAFg"]
[Tue Aug 18 13:01:40.723598 2026] [security2:error] [pid 123784:tid 124003] [client 158.23.17.4:34047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/40.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI-AAAAFU"]
[Tue Aug 18 13:01:40.735392 2026] [security2:error] [pid 123784:tid 124022] [client 20.65.98.162:41689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/m.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI-QAAAGg"]
[Tue Aug 18 13:01:40.741079 2026] [security2:error] [pid 123784:tid 124024] [client 168.62.48.100:17998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI-gAAAGo"]
[Tue Aug 18 13:01:40.781129 2026] [security2:error] [pid 123784:tid 123947] [client 20.79.204.6:11570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/file.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI-wAAAB0"]
[Tue Aug 18 13:01:40.784463 2026] [security2:error] [pid 123784:tid 123952] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-act.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI_AAAACI"]
[Tue Aug 18 13:01:40.793152 2026] [security2:error] [pid 123784:tid 124018] [client 20.91.215.254:11507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/filter.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI_QAAAGQ"]
[Tue Aug 18 13:01:40.797123 2026] [security2:error] [pid 123784:tid 123972] [client 20.104.100.201:61392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/ah25.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI_gAAADY"]
[Tue Aug 18 13:01:40.799841 2026] [security2:error] [pid 139043:tid 139214] [client 86.120.159.145:14325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTmAAAAK4"]
[Tue Aug 18 13:01:40.800024 2026] [security2:error] [pid 139043:tid 139214] [client 86.120.159.145:14325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTmAAAAK4"]
[Tue Aug 18 13:01:40.839822 2026] [security2:error] [pid 123784:tid 123798] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSB5GwDnJBNj2tDbYYJAAAAGwk"]
[Tue Aug 18 13:01:40.872731 2026] [security2:error] [pid 123784:tid 123975] [client 20.119.58.187:10433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSB5GwDnJBNj2tDbYYJAgAAADk"]
[Tue Aug 18 13:01:40.879806 2026] [authz_core:error] [pid 123784:tid 123875] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:40.880078 2026] [authz_core:error] [pid 123784:tid 123875] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:40.882571 2026] [security2:error] [pid 139043:tid 139105] [remote 72.167.40.62:57392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.40.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/wp-login.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTmwAA0z0"]
[Tue Aug 18 13:01:40.888614 2026] [security2:error] [pid 123784:tid 123973] [client 172.213.243.2:5227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ws61.php"] [unique_id "aoSB5GwDnJBNj2tDbYYJBAAAADc"]
[Tue Aug 18 13:01:40.900900 2026] [security2:error] [pid 123784:tid 123918] [client 158.23.17.4:62997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/info2.php"] [unique_id "aoSB5GwDnJBNj2tDbYYJBQAAAAA"]
[Tue Aug 18 13:01:40.909545 2026] [security2:error] [pid 123784:tid 123994] [client 20.75.92.165:4241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/x.php"] [unique_id "aoSB5GwDnJBNj2tDbYYJBgAAAEw"]
[Tue Aug 18 13:01:40.917138 2026] [security2:error] [pid 123784:tid 123974] [client 135.225.78.186:50169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/coffexium.php"] [unique_id "aoSB5GwDnJBNj2tDbYYJBwAAADg"]
[Tue Aug 18 13:01:40.922930 2026] [security2:error] [pid 123784:tid 123920] [client 20.48.236.86:14476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/inso.php"] [unique_id "aoSB5GwDnJBNj2tDbYYJCAAAAAI"]
[Tue Aug 18 13:01:40.972904 2026] [security2:error] [pid 139043:tid 139294] [client 20.151.109.219:24428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ve.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTogAAAP4"]
[Tue Aug 18 13:01:40.986445 2026] [security2:error] [pid 123784:tid 123906] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/ok.php"] [unique_id "aoSB5GwDnJBNj2tDbYYJCwAASnU"]
[Tue Aug 18 13:01:40.990074 2026] [autoindex:error] [pid 123784:tid 123929] [client 20.79.204.6:2225] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/images/media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:40.990104 2026] [security2:error] [pid 123784:tid 123970] [client 20.104.100.201:49459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSB5GwDnJBNj2tDbYYJDAAAADQ"]
[Tue Aug 18 13:01:41.008151 2026] [security2:error] [pid 139043:tid 139233] [client 168.62.48.100:17935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/images/security.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTpQAAAME"]
[Tue Aug 18 13:01:41.034764 2026] [security2:error] [pid 139043:tid 139201] [client 20.163.43.14:8932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTqQAAAKE"]
[Tue Aug 18 13:01:41.089368 2026] [security2:error] [pid 139043:tid 139217] [client 20.102.65.165:8561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/key.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTrgAAALE"]
[Tue Aug 18 13:01:41.089376 2026] [security2:error] [pid 123784:tid 123793] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJEAAAHgQ"]
[Tue Aug 18 13:01:41.089408 2026] [security2:error] [pid 123784:tid 123919] [client 20.80.111.3:41231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/storage/rip.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJEQAAAAE"]
[Tue Aug 18 13:01:41.098374 2026] [security2:error] [pid 123784:tid 123943] [client 85.204.70.114:32850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aoSB5WwDnJBNj2tDbYYJEgAAABk"]
[Tue Aug 18 13:01:41.098486 2026] [security2:error] [pid 139043:tid 139276] [client 158.158.74.177:22861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/cjfuns.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTsAAAAOw"]
[Tue Aug 18 13:01:41.102828 2026] [security2:error] [pid 123784:tid 124043] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJEwAAAH0"]
[Tue Aug 18 13:01:41.136067 2026] [security2:error] [pid 123784:tid 123844] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/item.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJFAAAHDc"]
[Tue Aug 18 13:01:41.144314 2026] [security2:error] [pid 123784:tid 123959] [client 20.104.100.201:34276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/ano.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJFQAAACk"]
[Tue Aug 18 13:01:41.147396 2026] [security2:error] [pid 123784:tid 123981] [client 20.250.13.23:51203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/lite.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJFgAAAD8"]
[Tue Aug 18 13:01:41.158437 2026] [security2:error] [pid 139043:tid 139185] [client 158.23.17.4:11832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/iu.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTsQAAAJE"]
[Tue Aug 18 13:01:41.191637 2026] [security2:error] [pid 123784:tid 123941] [client 172.202.39.151:61735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content/x/index.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJGgAAABc"]
[Tue Aug 18 13:01:41.192176 2026] [security2:error] [pid 123784:tid 123990] [client 20.79.204.6:2225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJGwAAAEg"]
[Tue Aug 18 13:01:41.231464 2026] [security2:error] [pid 123784:tid 123977] [client 20.119.58.187:10476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/css.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJHAAAADs"]
[Tue Aug 18 13:01:41.233484 2026] [security2:error] [pid 139043:tid 139187] [client 20.79.204.6:11578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/goods.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTsgAAAJM"]
[Tue Aug 18 13:01:41.266333 2026] [security2:error] [pid 139043:tid 139239] [client 20.104.100.201:49136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTswAAAMc"]
[Tue Aug 18 13:01:41.271443 2026] [security2:error] [pid 123784:tid 123870] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJHgAAYlE"]
[Tue Aug 18 13:01:41.278920 2026] [security2:error] [pid 123784:tid 123933] [client 20.75.92.165:2009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJHwAAAA8"]
[Tue Aug 18 13:01:41.279435 2026] [security2:error] [pid 123784:tid 123958] [client 20.151.109.219:24447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ia.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJIAAAACg"]
[Tue Aug 18 13:01:41.300138 2026] [security2:error] [pid 123784:tid 123993] [client 172.213.243.2:12080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/rum.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJIQAAAEs"]
[Tue Aug 18 13:01:41.304415 2026] [security2:error] [pid 139043:tid 139243] [client 20.186.30.159:10067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/chosen.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTtQAAAMs"]
[Tue Aug 18 13:01:41.347546 2026] [security2:error] [pid 123784:tid 124000] [client 20.127.136.245:18419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/motu.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJIwAAAFI"]
[Tue Aug 18 13:01:41.356248 2026] [security2:error] [pid 123784:tid 123949] [client 20.226.112.14:22932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/mamzi.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJJAAAAB8"]
[Tue Aug 18 13:01:41.358269 2026] [security2:error] [pid 139043:tid 139268] [client 20.163.43.14:8912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTtwAAAOQ"]
[Tue Aug 18 13:01:41.380475 2026] [security2:error] [pid 139043:tid 139238] [client 20.29.77.16:62872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTuAAAAMY"]
[Tue Aug 18 13:01:41.391842 2026] [security2:error] [pid 139043:tid 139293] [client 20.79.204.6:11656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/goods.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTuQAAAP0"]
[Tue Aug 18 13:01:41.406933 2026] [security2:error] [pid 139043:tid 139200] [client 68.221.73.131:50876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/qlex1.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTugAAAKA"]
[Tue Aug 18 13:01:41.439186 2026] [security2:error] [pid 123784:tid 123976] [client 20.91.215.254:11514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/input.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJJgAAADo"]
[Tue Aug 18 13:01:41.448492 2026] [security2:error] [pid 123784:tid 123851] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJJwAAVT4"]
[Tue Aug 18 13:01:41.453597 2026] [security2:error] [pid 123784:tid 124022] [client 20.48.236.86:14794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/puc.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJKAAAAGg"]
[Tue Aug 18 13:01:41.464413 2026] [security2:error] [pid 123784:tid 123957] [client 20.116.17.175:54850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/x1da.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJKQAAACc"]
[Tue Aug 18 13:01:41.483225 2026] [authz_core:error] [pid 123784:tid 123834] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:41.483486 2026] [authz_core:error] [pid 123784:tid 123834] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:41.491951 2026] [security2:error] [pid 139043:tid 139206] [client 85.204.70.114:32854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "aoSB5f2v-lWn9OzQT7UTvQAAAKY"]
[Tue Aug 18 13:01:41.505975 2026] [security2:error] [pid 139043:tid 139197] [client 20.100.169.31:4934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTvgAAAJ0"]
[Tue Aug 18 13:01:41.530099 2026] [security2:error] [pid 139043:tid 139196] [client 20.65.98.162:56499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/33.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTwAAAAJw"]
[Tue Aug 18 13:01:41.535624 2026] [security2:error] [pid 123784:tid 124021] [client 20.80.111.3:33416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/tool.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJKwAAAGc"]
[Tue Aug 18 13:01:41.541389 2026] [security2:error] [pid 123784:tid 124007] [client 20.104.100.201:49447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/output.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJLQAAAFk"]
[Tue Aug 18 13:01:41.541495 2026] [autoindex:error] [pid 139043:tid 139204] [client 20.100.169.31:13487] AH01276: Cannot serve directory /home1/xsolutions/vooo-api.3xsolutions.com/public/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:41.583770 2026] [security2:error] [pid 123784:tid 123931] [client 20.119.58.187:10133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/chosen.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJMAAAAA0"]
[Tue Aug 18 13:01:41.591511 2026] [security2:error] [pid 123784:tid 123953] [client 216.244.66.232:37454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJMQAAACM"]
[Tue Aug 18 13:01:41.591599 2026] [security2:error] [pid 123784:tid 123953] [client 216.244.66.232:37454] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJMQAAACM"]
[Tue Aug 18 13:01:41.596592 2026] [security2:error] [pid 139043:tid 139267] [client 20.104.100.201:61413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/nwflm.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTwgAAAOM"]
[Tue Aug 18 13:01:41.617166 2026] [security2:error] [pid 123784:tid 123853] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJMwAAUEA"]
[Tue Aug 18 13:01:41.617465 2026] [security2:error] [pid 123784:tid 123998] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJMwAAUEA"]
[Tue Aug 18 13:01:41.619457 2026] [security2:error] [pid 123784:tid 124008] [client 20.151.109.219:60387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/kn.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJNAAAAFo"]
[Tue Aug 18 13:01:41.625080 2026] [security2:error] [pid 123784:tid 123967] [client 20.251.112.238:8015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/100.kb.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJNQAAADE"]
[Tue Aug 18 13:01:41.649125 2026] [autoindex:error] [pid 123784:tid 123879] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/dtbbrasilcom/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:41.710607 2026] [security2:error] [pid 123784:tid 123975] [client 172.213.243.2:18459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ze.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJOAAAADk"]
[Tue Aug 18 13:01:41.729380 2026] [security2:error] [pid 139043:tid 139194] [client 213.35.127.232:58238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTxAAAAJo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:41.741040 2026] [security2:error] [pid 139043:tid 139211] [client 20.163.43.14:8866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/cah.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTxQAAAKs"]
[Tue Aug 18 13:01:41.744953 2026] [security2:error] [pid 123784:tid 124039] [client 20.186.30.159:10108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/thoms.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJOgAAAHk"]
[Tue Aug 18 13:01:41.750892 2026] [security2:error] [pid 139043:tid 139245] [client 20.226.112.14:22935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ms.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTxwAAAM0"]
[Tue Aug 18 13:01:41.768371 2026] [security2:error] [pid 123784:tid 123954] [client 158.158.74.177:22890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJOwAAACQ"]
[Tue Aug 18 13:01:41.771286 2026] [security2:error] [pid 123784:tid 123973] [client 20.75.92.165:4320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/hosty.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJPAAAADc"]
[Tue Aug 18 13:01:41.781738 2026] [security2:error] [pid 123784:tid 123995] [client 20.250.13.23:6925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSB5WwDnJBNj2tDbYYJPgAAAE0"]
[Tue Aug 18 13:01:41.797289 2026] [security2:error] [pid 123784:tid 124018] [client 20.79.204.6:2212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJPwAAAGQ"]
[Tue Aug 18 13:01:41.809684 2026] [security2:error] [pid 123784:tid 123991] [client 158.23.17.4:55170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/pk.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJQAAAAEk"]
[Tue Aug 18 13:01:41.824804 2026] [security2:error] [pid 123784:tid 124037] [client 20.104.100.201:49470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/tiny2.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJQgAAAHc"]
[Tue Aug 18 13:01:41.848768 2026] [security2:error] [pid 139043:tid 139272] [client 20.79.204.6:12224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/hplfuns.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTyQAAAOg"]
[Tue Aug 18 13:01:41.862109 2026] [security2:error] [pid 123784:tid 123987] [client 20.118.133.132:1510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/ws55.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJRAAAAEU"]
[Tue Aug 18 13:01:41.862204 2026] [security2:error] [pid 123784:tid 123924] [client 172.202.39.151:4437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-good.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJRQAAAAY"]
[Tue Aug 18 13:01:41.869883 2026] [security2:error] [pid 123784:tid 124035] [client 213.202.253.4:60801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/wp-content/txets.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJRwAAAHU"], referer: www.google.com
[Tue Aug 18 13:01:41.880214 2026] [security2:error] [pid 123784:tid 123992] [client 85.204.70.114:32868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aoSB5WwDnJBNj2tDbYYJSAAAAEo"]
[Tue Aug 18 13:01:41.934193 2026] [security2:error] [pid 139043:tid 139257] [client 20.116.17.175:23024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/bdroot.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTygAAANk"]
[Tue Aug 18 13:01:41.938341 2026] [security2:error] [pid 123784:tid 123920] [client 20.119.58.187:10483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/doc.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJSgAAAAI"]
[Tue Aug 18 13:01:41.963944 2026] [security2:error] [pid 123784:tid 124044] [client 20.151.109.219:39324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/wm.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJSwAAAH4"]
[Tue Aug 18 13:01:41.973452 2026] [security2:error] [pid 139043:tid 139297] [client 20.80.111.3:33438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/twentytwenty/functions.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTywAAAQE"]
[Tue Aug 18 13:01:41.993715 2026] [security2:error] [pid 123784:tid 123996] [client 158.23.17.4:63002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/sx.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJTAAAAE4"]
[Tue Aug 18 13:01:41.997546 2026] [security2:error] [pid 139043:tid 139278] [client 20.79.204.6:12235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/hplfuns.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTzAAAAO4"]
[Tue Aug 18 13:01:42.001423 2026] [security2:error] [pid 139043:tid 139190] [client 4.232.151.198:12165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/goods.php"] [unique_id "aoSB5v2v-lWn9OzQT7UTzQAAAJY"]
[Tue Aug 18 13:01:42.023637 2026] [security2:error] [pid 139043:tid 139284] [client 20.226.112.14:28764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/gfile.php"] [unique_id "aoSB5v2v-lWn9OzQT7UTzgAAAPQ"]
[Tue Aug 18 13:01:42.024623 2026] [security2:error] [pid 139043:tid 139286] [client 20.186.30.159:10012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/wpxml.php"] [unique_id "aoSB5v2v-lWn9OzQT7UTzwAAAPY"]
[Tue Aug 18 13:01:42.032667 2026] [security2:error] [pid 123784:tid 123898] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJTQAAHm0"]
[Tue Aug 18 13:01:42.052755 2026] [security2:error] [pid 139043:tid 139174] [client 20.102.65.165:8471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/chosen.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT0AAAAIY"]
[Tue Aug 18 13:01:42.069358 2026] [security2:error] [pid 123784:tid 123892] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/th.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJTgAAfWc"]
[Tue Aug 18 13:01:42.084207 2026] [security2:error] [pid 139043:tid 139299] [client 20.79.204.6:10722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/abcd.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT0wAAAQM"]
[Tue Aug 18 13:01:42.089991 2026] [security2:error] [pid 139043:tid 139254] [client 20.104.100.201:34787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-load.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT1AAAANY"]
[Tue Aug 18 13:01:42.090454 2026] [security2:error] [pid 123784:tid 124031] [client 20.127.136.245:22203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/404.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJTwAAAHE"]
[Tue Aug 18 13:01:42.105642 2026] [security2:error] [pid 139043:tid 139275] [client 20.104.100.201:49138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wpxml.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT1QAAAOs"]
[Tue Aug 18 13:01:42.122470 2026] [security2:error] [pid 139043:tid 139253] [client 20.29.77.16:40519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT1wAAANU"]
[Tue Aug 18 13:01:42.125137 2026] [security2:error] [pid 139043:tid 139205] [client 172.213.243.2:16874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/gjm.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT2AAAAKU"]
[Tue Aug 18 13:01:42.129928 2026] [security2:error] [pid 139043:tid 139223] [client 20.65.98.162:55211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/packed.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT2QAAALc"]
[Tue Aug 18 13:01:42.146976 2026] [security2:error] [pid 139043:tid 139246] [client 20.91.215.254:27081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/jquery.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT2wAAAM4"]
[Tue Aug 18 13:01:42.198098 2026] [security2:error] [pid 139043:tid 139244] [client 135.225.78.186:56239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT3AAAAMw"]
[Tue Aug 18 13:01:42.205786 2026] [security2:error] [pid 139043:tid 139217] [client 20.251.112.238:7150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/mamzi.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT3QAAALE"]
[Tue Aug 18 13:01:42.215020 2026] [security2:error] [pid 139043:tid 139276] [client 20.226.56.190:17862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/Black.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT3wAAAOw"]
[Tue Aug 18 13:01:42.220770 2026] [security2:error] [pid 123784:tid 123977] [client 172.202.39.151:44572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJUgAAADs"]
[Tue Aug 18 13:01:42.225728 2026] [autoindex:error] [pid 123784:tid 123829] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/dtbbrasilcom/public_html/wp-includes/images/media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:42.245770 2026] [security2:error] [pid 139043:tid 139256] [client 20.163.43.14:8928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/system_log.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT4QAAANg"]
[Tue Aug 18 13:01:42.249820 2026] [security2:error] [pid 123784:tid 123858] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/admin404.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJVAAAGEU"]
[Tue Aug 18 13:01:42.279845 2026] [security2:error] [pid 139043:tid 139222] [client 85.204.70.114:32880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aoSB5v2v-lWn9OzQT7UT5AAAALY"]
[Tue Aug 18 13:01:42.293044 2026] [security2:error] [pid 139043:tid 139248] [client 20.119.58.187:10112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/Exception-class.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT5QAAANA"]
[Tue Aug 18 13:01:42.314579 2026] [security2:error] [pid 139043:tid 139288] [client 20.100.169.31:4303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT5wAAAPg"]
[Tue Aug 18 13:01:42.335109 2026] [security2:error] [pid 139043:tid 139239] [client 158.23.17.4:54753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ge.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT6QAAAMc"]
[Tue Aug 18 13:01:42.353125 2026] [security2:error] [pid 139043:tid 139218] [client 20.186.30.159:10022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/file1221.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT6gAAALI"]
[Tue Aug 18 13:01:42.381237 2026] [security2:error] [pid 139043:tid 139293] [client 20.104.100.201:49426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/min.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT6wAAAP0"]
[Tue Aug 18 13:01:42.386946 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:42.387222 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:42.402260 2026] [security2:error] [pid 139043:tid 139261] [client 20.79.204.6:2396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT7gAAAN0"]
[Tue Aug 18 13:01:42.405761 2026] [security2:error] [pid 123784:tid 123936] [client 20.80.111.3:27095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-admin.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJWQAAABI"]
[Tue Aug 18 13:01:42.405828 2026] [security2:error] [pid 123784:tid 123935] [client 20.250.13.23:51228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJWgAAABE"]
[Tue Aug 18 13:01:42.405958 2026] [security2:error] [pid 139043:tid 139277] [client 20.104.100.201:34286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/jj.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT7wAAAO0"]
[Tue Aug 18 13:01:42.408470 2026] [security2:error] [pid 123784:tid 123914] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJWwAAb30"]
[Tue Aug 18 13:01:42.409892 2026] [security2:error] [pid 139043:tid 139241] [client 168.62.48.100:5611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT8QAAAMk"]
[Tue Aug 18 13:01:42.412897 2026] [security2:error] [pid 139043:tid 139219] [client 20.75.92.165:1984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/test1.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT8gAAALM"]
[Tue Aug 18 13:01:42.414923 2026] [security2:error] [pid 139043:tid 139252] [client 20.151.109.219:60374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ac.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT8wAAANQ"]
[Tue Aug 18 13:01:42.422431 2026] [security2:error] [pid 123784:tid 123864] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/qo.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJXAAACEs"]
[Tue Aug 18 13:01:42.426551 2026] [security2:error] [pid 123784:tid 123979] [client 20.116.17.175:56840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/mcs.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJXQAAAD0"]
[Tue Aug 18 13:01:42.452177 2026] [security2:error] [pid 123784:tid 123962] [client 20.79.204.6:11567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/htaccess.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJXgAAACw"]
[Tue Aug 18 13:01:42.461315 2026] [security2:error] [pid 139043:tid 139203] [client 158.158.74.177:18961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT9AAAAKM"]
[Tue Aug 18 13:01:42.530906 2026] [security2:error] [pid 139043:tid 139199] [client 20.226.112.14:28604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/public/wp-blog.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT9QAAAJ8"]
[Tue Aug 18 13:01:42.551539 2026] [security2:error] [pid 123784:tid 123960] [client 172.213.243.2:16867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/new4.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJYAAAACo"]
[Tue Aug 18 13:01:42.584357 2026] [security2:error] [pid 123784:tid 123791] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJYgAAUQI"]
[Tue Aug 18 13:01:42.598812 2026] [security2:error] [pid 123784:tid 124026] [client 20.79.204.6:11551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/htaccess.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJYwAAAGw"]
[Tue Aug 18 13:01:42.646809 2026] [security2:error] [pid 139043:tid 139179] [client 20.119.58.187:10161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/ee.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT-AAAAIs"]
[Tue Aug 18 13:01:42.653980 2026] [security2:error] [pid 139043:tid 139259] [client 20.104.100.201:49129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/ccou.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT-QAAANs"]
[Tue Aug 18 13:01:42.685975 2026] [security2:error] [pid 139043:tid 139189] [client 85.204.70.114:32890] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aoSB5v2v-lWn9OzQT7UT-gAAAJU"]
[Tue Aug 18 13:01:42.689431 2026] [authz_core:error] [pid 123784:tid 123860] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:42.689731 2026] [authz_core:error] [pid 123784:tid 123860] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:42.697563 2026] [security2:error] [pid 139043:tid 139235] [client 158.23.17.4:15788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/nu.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT-wAAAMM"]
[Tue Aug 18 13:01:42.697890 2026] [security2:error] [pid 139043:tid 139265] [client 20.102.65.165:8452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/wpxml.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT_AAAAOE"]
[Tue Aug 18 13:01:42.719916 2026] [security2:error] [pid 139043:tid 139257] [client 20.151.109.219:60367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/yz.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT_gAAANk"]
[Tue Aug 18 13:01:42.745818 2026] [security2:error] [pid 123784:tid 124022] [client 20.163.43.14:8837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJZgAAAGg"]
[Tue Aug 18 13:01:42.750418 2026] [security2:error] [pid 123784:tid 124024] [client 20.29.77.16:40521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/dirs.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJZwAAAGo"]
[Tue Aug 18 13:01:42.751087 2026] [security2:error] [pid 139043:tid 139226] [client 213.35.127.232:58455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT_wAAALo"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:42.761254 2026] [security2:error] [pid 123784:tid 123888] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJaAAAc2M"]
[Tue Aug 18 13:01:42.762561 2026] [security2:error] [pid 123784:tid 123940] [client 158.23.17.4:34169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ee.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJaQAAABY"]
[Tue Aug 18 13:01:42.766174 2026] [security2:error] [pid 123784:tid 124013] [client 20.226.56.190:3023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/filesystems.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJagAAAF8"]
[Tue Aug 18 13:01:42.790221 2026] [security2:error] [pid 123784:tid 123923] [client 20.91.215.254:11498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/media-new.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJawAAAAU"]
[Tue Aug 18 13:01:42.793818 2026] [security2:error] [pid 123784:tid 123983] [client 158.23.17.4:15151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/kl.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJbAAAAEE"]
[Tue Aug 18 13:01:42.798096 2026] [security2:error] [pid 123784:tid 123947] [client 172.202.39.151:53748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content/index.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJbQAAAB0"]
[Tue Aug 18 13:01:42.799271 2026] [security2:error] [pid 139043:tid 139250] [client 20.127.136.245:8044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/lite.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUAQAAANI"]
[Tue Aug 18 13:01:42.825627 2026] [security2:error] [pid 123784:tid 123931] [client 20.116.17.175:22997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-temp.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJbgAAAA0"]
[Tue Aug 18 13:01:42.840569 2026] [security2:error] [pid 139043:tid 139198] [client 20.80.111.3:39612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUBAAAAJ4"]
[Tue Aug 18 13:01:42.868224 2026] [security2:error] [pid 139043:tid 139251] [client 20.104.100.201:61419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/img.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUBQAAANM"]
[Tue Aug 18 13:01:42.890414 2026] [security2:error] [pid 139043:tid 139221] [client 20.251.112.238:33961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ms.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUBwAAALU"]
[Tue Aug 18 13:01:42.897382 2026] [security2:error] [pid 139043:tid 139183] [client 20.186.30.159:9994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/nox.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUCAAAAI8"]
[Tue Aug 18 13:01:42.942742 2026] [security2:error] [pid 139043:tid 139297] [client 20.100.169.31:4938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUCgAAAQE"]
[Tue Aug 18 13:01:42.943236 2026] [security2:error] [pid 139043:tid 139253] [client 20.104.100.201:49093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/crgio.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUCwAAANU"]
[Tue Aug 18 13:01:42.946606 2026] [security2:error] [pid 123784:tid 123846] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/sd.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJcQAAWjk"]
[Tue Aug 18 13:01:42.952236 2026] [autoindex:error] [pid 123784:tid 123871] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/dtbbrasilcom/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:42.966196 2026] [security2:error] [pid 139043:tid 139233] [client 172.213.243.2:18324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp-act.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUDgAAAME"]
[Tue Aug 18 13:01:42.967073 2026] [security2:error] [pid 123784:tid 123930] [client 20.226.112.14:34209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/cu.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJcgAAAAw"]
[Tue Aug 18 13:01:42.971686 2026] [security2:error] [pid 123784:tid 124040] [client 20.116.17.175:53782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/adminner.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJcwAAAHo"]
[Tue Aug 18 13:01:42.980200 2026] [security2:error] [pid 139043:tid 139243] [client 195.2.84.198:54858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.84.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paciolli.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUAgAAAMs"], referer: http://paciolli.com.br/contato/
[Tue Aug 18 13:01:42.990357 2026] [authz_core:error] [pid 123784:tid 123908] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:42.990619 2026] [authz_core:error] [pid 123784:tid 123908] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:43.000824 2026] [security2:error] [pid 139043:tid 139294] [client 20.119.58.187:10134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/edit.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUEAAAAP4"]
[Tue Aug 18 13:01:43.004604 2026] [security2:error] [pid 139043:tid 139192] [client 135.225.78.186:50123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/sf.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUEQAAAJg"]
[Tue Aug 18 13:01:43.007521 2026] [security2:error] [pid 139043:tid 139217] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUEgAAALE"]
[Tue Aug 18 13:01:43.024130 2026] [security2:error] [pid 139043:tid 139181] [client 20.151.109.219:39309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/kj.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUFAAAAI0"]
[Tue Aug 18 13:01:43.026694 2026] [autoindex:error] [pid 139043:tid 139193] [client 20.79.204.6:2236] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:43.061700 2026] [security2:error] [pid 139043:tid 139254] [client 20.79.204.6:11706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/images/wso.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUFQAAANY"]
[Tue Aug 18 13:01:43.066398 2026] [security2:error] [pid 139043:tid 139274] [client 20.163.43.14:8904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUFgAAAOo"]
[Tue Aug 18 13:01:43.094158 2026] [security2:error] [pid 139043:tid 139212] [client 20.250.13.23:6814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUFwAAAKw"]
[Tue Aug 18 13:01:43.099652 2026] [security2:error] [pid 139043:tid 139290] [client 52.173.121.69:54011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUGAAAAPo"]
[Tue Aug 18 13:01:43.106903 2026] [security2:error] [pid 123784:tid 124003] [client 20.79.204.6:10398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-good.php"] [unique_id "aoSB52wDnJBNj2tDbYYJeAAAAFU"]
[Tue Aug 18 13:01:43.112102 2026] [security2:error] [pid 123784:tid 124039] [client 20.75.92.165:1995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/zwso.php"] [unique_id "aoSB52wDnJBNj2tDbYYJeQAAAHk"]
[Tue Aug 18 13:01:43.114914 2026] [security2:error] [pid 123784:tid 123905] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/km.php"] [unique_id "aoSB52wDnJBNj2tDbYYJegAAcnQ"]
[Tue Aug 18 13:01:43.115042 2026] [security2:error] [pid 139043:tid 139222] [client 20.102.65.165:8453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/file1221.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUGQAAALY"]
[Tue Aug 18 13:01:43.132106 2026] [security2:error] [pid 123784:tid 123800] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-themes.php"] [unique_id "aoSB52wDnJBNj2tDbYYJewAAJAs"]
[Tue Aug 18 13:01:43.133537 2026] [security2:error] [pid 139043:tid 139216] [client 158.158.74.177:22882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/import.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUGgAAALA"]
[Tue Aug 18 13:01:43.149776 2026] [security2:error] [pid 139043:tid 139227] [client 158.23.17.4:46588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/gs.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUGwAAALs"]
[Tue Aug 18 13:01:43.166233 2026] [security2:error] [pid 139043:tid 139287] [client 20.226.112.14:13662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/X57.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUHAAAAPc"]
[Tue Aug 18 13:01:43.182237 2026] [security2:error] [pid 139043:tid 139280] [client 68.221.73.131:63559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/mariju.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUHgAAAPA"]
[Tue Aug 18 13:01:43.199854 2026] [security2:error] [pid 139043:tid 139277] [client 85.204.70.114:32898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aoSB5_2v-lWn9OzQT7UUHwAAAO0"]
[Tue Aug 18 13:01:43.201992 2026] [security2:error] [pid 139043:tid 139230] [client 20.79.204.6:11669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/images/wso.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUIAAAAL4"]
[Tue Aug 18 13:01:43.220159 2026] [security2:error] [pid 139043:tid 139266] [client 20.104.100.201:49118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUIgAAAOI"]
[Tue Aug 18 13:01:43.227987 2026] [security2:error] [pid 139043:tid 139283] [client 20.79.204.6:2236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-themes.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUIwAAAPM"]
[Tue Aug 18 13:01:43.264165 2026] [security2:error] [pid 139043:tid 139295] [client 4.232.94.69:52946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/config.php7"] [unique_id "aoSB5_2v-lWn9OzQT7UUJAAAAP8"]
[Tue Aug 18 13:01:43.273816 2026] [security2:error] [pid 139043:tid 139258] [client 158.23.17.4:34046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ak.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUJQAAANo"]
[Tue Aug 18 13:01:43.286572 2026] [security2:error] [pid 123784:tid 123797] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/mf.php"] [unique_id "aoSB52wDnJBNj2tDbYYJiAAAZAg"]
[Tue Aug 18 13:01:43.289325 2026] [authz_core:error] [pid 123784:tid 123813] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:43.289600 2026] [authz_core:error] [pid 123784:tid 123813] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:43.311954 2026] [security2:error] [pid 123784:tid 123886] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB52wDnJBNj2tDbYYJigAAOGE"]
[Tue Aug 18 13:01:43.313091 2026] [security2:error] [pid 123784:tid 124037] [client 20.151.109.219:39344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/vg.php"] [unique_id "aoSB52wDnJBNj2tDbYYJiwAAAHc"]
[Tue Aug 18 13:01:43.339797 2026] [security2:error] [pid 123784:tid 124042] [client 20.226.112.14:22897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/forbidals.php"] [unique_id "aoSB52wDnJBNj2tDbYYJjAAAAHw"]
[Tue Aug 18 13:01:43.340628 2026] [security2:error] [pid 139043:tid 139201] [client 20.104.100.201:34253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/we.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUKAAAAKE"]
[Tue Aug 18 13:01:43.354151 2026] [security2:error] [pid 139043:tid 139203] [client 20.119.58.187:10168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/f35.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUKQAAAKM"]
[Tue Aug 18 13:01:43.375268 2026] [security2:error] [pid 139043:tid 139300] [client 20.118.133.132:13993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/m.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUKwAAAQQ"]
[Tue Aug 18 13:01:43.378029 2026] [security2:error] [pid 139043:tid 139211] [client 20.186.30.159:10068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/akismet.php"] [unique_id "aoSB5_2v-lWn9OzQT7UULAAAAKs"]
[Tue Aug 18 13:01:43.382559 2026] [security2:error] [pid 139043:tid 139195] [client 172.213.243.2:19716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/grsiuk.php"] [unique_id "aoSB5_2v-lWn9OzQT7UULQAAAJs"]
[Tue Aug 18 13:01:43.384036 2026] [security2:error] [pid 139043:tid 139182] [client 157.90.156.63:44644] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.alcorseguros.com.br"] [uri "/index.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT6AAAAI4"], referer: https://www.alcorseguros.com.br
[Tue Aug 18 13:01:43.388557 2026] [security2:error] [pid 123784:tid 123987] [client 20.48.236.86:14481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/19.php"] [unique_id "aoSB52wDnJBNj2tDbYYJjQAAAEU"]
[Tue Aug 18 13:01:43.391841 2026] [security2:error] [pid 139043:tid 139245] [client 20.163.43.14:8849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/abc.php"] [unique_id "aoSB5_2v-lWn9OzQT7UULgAAAM0"]
[Tue Aug 18 13:01:43.412816 2026] [security2:error] [pid 139043:tid 139260] [client 172.202.39.151:44559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSB5_2v-lWn9OzQT7UULwAAANw"]
[Tue Aug 18 13:01:43.413710 2026] [security2:error] [pid 139043:tid 139189] [client 20.127.136.245:14208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/lock360.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUMAAAAJU"]
[Tue Aug 18 13:01:43.420610 2026] [security2:error] [pid 139043:tid 139187] [client 20.251.112.238:7174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/gfile.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUMQAAAJM"]
[Tue Aug 18 13:01:43.430645 2026] [security2:error] [pid 123784:tid 124010] [client 20.102.65.165:8469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/nox.php"] [unique_id "aoSB52wDnJBNj2tDbYYJkAAAAFw"]
[Tue Aug 18 13:01:43.434743 2026] [security2:error] [pid 139043:tid 139219] [client 20.91.215.254:11592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUMgAAALM"]
[Tue Aug 18 13:01:43.453463 2026] [security2:error] [pid 123784:tid 123907] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ie.php"] [unique_id "aoSB52wDnJBNj2tDbYYJkQAAdXY"]
[Tue Aug 18 13:01:43.492034 2026] [security2:error] [pid 139043:tid 139214] [client 20.104.100.201:49111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/css.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUNAAAAK4"]
[Tue Aug 18 13:01:43.506157 2026] [security2:error] [pid 123784:tid 123986] [client 20.226.112.14:34228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/edit.php"] [unique_id "aoSB52wDnJBNj2tDbYYJkgAAAEQ"]
[Tue Aug 18 13:01:43.540433 2026] [security2:error] [pid 123784:tid 124020] [client 20.75.92.165:4315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/Geforce.php"] [unique_id "aoSB52wDnJBNj2tDbYYJlAAAAGY"]
[Tue Aug 18 13:01:43.576791 2026] [security2:error] [pid 139043:tid 139207] [client 20.100.169.31:4313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUOAAAAKc"]
[Tue Aug 18 13:01:43.597300 2026] [security2:error] [pid 139043:tid 139196] [client 158.23.17.4:51142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/lw.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUOQAAAJw"]
[Tue Aug 18 13:01:43.598893 2026] [security2:error] [pid 139043:tid 139183] [client 85.204.70.114:32908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aoSB5_2v-lWn9OzQT7UUOgAAAI8"]
[Tue Aug 18 13:01:43.610622 2026] [security2:error] [pid 139043:tid 139174] [client 172.202.39.151:49865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/as.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUOwAAAIY"]
[Tue Aug 18 13:01:43.665805 2026] [security2:error] [pid 123784:tid 123992] [client 20.79.204.6:12251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/index/function.php"] [unique_id "aoSB52wDnJBNj2tDbYYJmQAAAEo"]
[Tue Aug 18 13:01:43.672698 2026] [security2:error] [pid 123784:tid 123965] [client 20.29.77.16:33588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/fresh.php"] [unique_id "aoSB52wDnJBNj2tDbYYJmgAAAC8"]
[Tue Aug 18 13:01:43.700678 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.112.14:22893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/kj.php"] [unique_id "aoSB52wDnJBNj2tDbYYJmwAAAEc"]
[Tue Aug 18 13:01:43.706072 2026] [security2:error] [pid 123784:tid 124043] [client 20.186.30.159:10078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/admin.php"] [unique_id "aoSB52wDnJBNj2tDbYYJnAAAAH0"]
[Tue Aug 18 13:01:43.710507 2026] [security2:error] [pid 139043:tid 139221] [client 20.119.58.187:10137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/fff.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUPQAAALU"]
[Tue Aug 18 13:01:43.714192 2026] [security2:error] [pid 123784:tid 123970] [client 20.250.13.23:51256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSB52wDnJBNj2tDbYYJnQAAADQ"]
[Tue Aug 18 13:01:43.715042 2026] [security2:error] [pid 139043:tid 139223] [client 20.80.111.3:18438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUPgAAALc"]
[Tue Aug 18 13:01:43.721088 2026] [security2:error] [pid 139043:tid 139176] [client 20.163.43.14:8910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/akcc.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUPwAAAIg"]
[Tue Aug 18 13:01:43.746016 2026] [security2:error] [pid 123784:tid 123971] [client 20.151.109.219:24401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/sm.php"] [unique_id "aoSB52wDnJBNj2tDbYYJnwAAADU"]
[Tue Aug 18 13:01:43.763317 2026] [security2:error] [pid 123784:tid 123946] [client 20.65.98.162:27493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/sf.php"] [unique_id "aoSB52wDnJBNj2tDbYYJoAAAABw"]
[Tue Aug 18 13:01:43.764655 2026] [security2:error] [pid 139043:tid 139235] [client 213.35.127.232:58670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUQAAAAMM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:43.764752 2026] [security2:error] [pid 123784:tid 123959] [client 20.104.100.201:49108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSB52wDnJBNj2tDbYYJoQAAACk"]
[Tue Aug 18 13:01:43.774694 2026] [security2:error] [pid 139043:tid 139192] [client 20.116.17.175:54864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/dragonshell.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUQQAAAJg"]
[Tue Aug 18 13:01:43.792912 2026] [security2:error] [pid 123784:tid 123980] [client 4.232.151.198:12204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/file.php"] [unique_id "aoSB52wDnJBNj2tDbYYJowAAAD4"]
[Tue Aug 18 13:01:43.807584 2026] [security2:error] [pid 139043:tid 139236] [client 172.213.243.2:18450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/h.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUQgAAAMQ"]
[Tue Aug 18 13:01:43.807793 2026] [security2:error] [pid 139043:tid 139253] [client 20.79.204.6:11527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/index/function.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUQwAAANU"]
[Tue Aug 18 13:01:43.810237 2026] [security2:error] [pid 123784:tid 123939] [client 158.158.74.177:9250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/cropper.php"] [unique_id "aoSB52wDnJBNj2tDbYYJpAAAABU"]
[Tue Aug 18 13:01:43.828207 2026] [security2:error] [pid 123784:tid 123938] [client 149.34.210.141:58642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSB52wDnJBNj2tDbYYJpQAAABQ"]
[Tue Aug 18 13:01:43.852470 2026] [security2:error] [pid 139043:tid 139291] [client 20.79.204.6:2178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB5_2v-lWn9OzQT7UURAAAAPs"]
[Tue Aug 18 13:01:43.858406 2026] [security2:error] [pid 139043:tid 139254] [client 20.226.112.14:22936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/bes.php"] [unique_id "aoSB5_2v-lWn9OzQT7UURgAAANY"]
[Tue Aug 18 13:01:43.892347 2026] [authz_core:error] [pid 123784:tid 123872] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:43.892675 2026] [authz_core:error] [pid 123784:tid 123872] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:43.899083 2026] [security2:error] [pid 139043:tid 139177] [client 103.120.71.157:26799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB5_2v-lWn9OzQT7UURwAAAIk"]
[Tue Aug 18 13:01:43.899254 2026] [security2:error] [pid 139043:tid 139177] [client 103.120.71.157:26799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB5_2v-lWn9OzQT7UURwAAAIk"]
[Tue Aug 18 13:01:43.915537 2026] [security2:error] [pid 123784:tid 123978] [client 20.116.17.175:55236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-css.php"] [unique_id "aoSB52wDnJBNj2tDbYYJqQAAADw"]
[Tue Aug 18 13:01:43.932173 2026] [security2:error] [pid 123784:tid 123958] [client 158.23.17.4:34035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/test_info.php"] [unique_id "aoSB52wDnJBNj2tDbYYJqgAAACg"]
[Tue Aug 18 13:01:43.946231 2026] [security2:error] [pid 123784:tid 124023] [client 20.75.92.165:2033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/fpwch.php"] [unique_id "aoSB52wDnJBNj2tDbYYJqwAAAGk"]
[Tue Aug 18 13:01:43.989751 2026] [security2:error] [pid 139043:tid 139244] [client 159.69.158.189:9900] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lifetreemarketing.com"] [uri "/wp-content/cache/all/index.html"] [unique_id "aoSB5_2v-lWn9OzQT7UUSQAAAMw"], referer: https://lifetreemarketing.com/
[Tue Aug 18 13:01:44.009896 2026] [security2:error] [pid 123784:tid 123988] [client 20.226.112.14:22848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ws60.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJrAAAAEY"]
[Tue Aug 18 13:01:44.019333 2026] [security2:error] [pid 123784:tid 123962] [client 20.251.112.238:62485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/public/wp-blog.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJrQAAACw"]
[Tue Aug 18 13:01:44.039183 2026] [security2:error] [pid 123784:tid 124000] [client 20.104.100.201:49443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/epinyins.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJsAAAAFI"]
[Tue Aug 18 13:01:44.060055 2026] [security2:error] [pid 123784:tid 123999] [client 20.163.43.14:8949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wk/index.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJsQAAAFE"]
[Tue Aug 18 13:01:44.063808 2026] [security2:error] [pid 123784:tid 123993] [client 20.119.58.187:10135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/ff1.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJsgAAAEs"]
[Tue Aug 18 13:01:44.075698 2026] [security2:error] [pid 139043:tid 139256] [client 20.91.215.254:19432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUSgAAANg"]
[Tue Aug 18 13:01:44.080291 2026] [autoindex:error] [pid 123784:tid 124041] [client 169.58.72.248:58322] AH01276: Cannot serve directory /home3/adobankcom/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:44.093177 2026] [security2:error] [pid 123784:tid 124017] [client 20.48.236.86:14479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/133.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJswAAAGM"]
[Tue Aug 18 13:01:44.094805 2026] [security2:error] [pid 123784:tid 123938] [client 149.34.210.141:58642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSB52wDnJBNj2tDbYYJpQAAABQ"]
[Tue Aug 18 13:01:44.113045 2026] [security2:error] [pid 139043:tid 139218] [client 68.221.73.131:57837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUSwAAALI"]
[Tue Aug 18 13:01:44.121416 2026] [security2:error] [pid 123784:tid 123942] [client 20.79.204.6:10694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/simple.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJtAAAABg"]
[Tue Aug 18 13:01:44.125138 2026] [security2:error] [pid 123784:tid 124022] [client 20.226.56.190:23767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/showphpinfo.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJuwAAAGg"]
[Tue Aug 18 13:01:44.166462 2026] [security2:error] [pid 139043:tid 139293] [client 20.29.77.16:64935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/admin404.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUTAAAAP0"]
[Tue Aug 18 13:01:44.167566 2026] [security2:error] [pid 123784:tid 123957] [client 20.127.136.245:8975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJwAAAACc"]
[Tue Aug 18 13:01:44.192407 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:44.192673 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:44.216416 2026] [security2:error] [pid 139043:tid 139230] [client 158.23.17.4:46410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/vj.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUTQAAAL4"]
[Tue Aug 18 13:01:44.225366 2026] [security2:error] [pid 139043:tid 139229] [client 172.213.243.2:12036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/koiy.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUTgAAAL0"]
[Tue Aug 18 13:01:44.247114 2026] [security2:error] [pid 123784:tid 123953] [client 172.202.39.151:49350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJyQAAACM"]
[Tue Aug 18 13:01:44.262951 2026] [security2:error] [pid 123784:tid 123944] [client 20.226.112.14:22896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/olfclass.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJywAAABo"]
[Tue Aug 18 13:01:44.276316 2026] [security2:error] [pid 139043:tid 139216] [client 20.79.204.6:12257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/info.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUTwAAALA"]
[Tue Aug 18 13:01:44.300370 2026] [security2:error] [pid 139043:tid 139273] [client 20.151.109.219:24384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/28.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUUAAAAOk"]
[Tue Aug 18 13:01:44.310025 2026] [security2:error] [pid 123784:tid 124038] [client 20.116.17.175:53546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/setup-config.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJ2wAAAHg"]
[Tue Aug 18 13:01:44.314405 2026] [security2:error] [pid 139043:tid 139295] [client 20.104.100.201:49451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/load.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUUQAAAP8"]
[Tue Aug 18 13:01:44.341329 2026] [security2:error] [pid 139043:tid 139258] [client 158.23.17.4:25364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ko.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUUgAAANo"]
[Tue Aug 18 13:01:44.342020 2026] [security2:error] [pid 123784:tid 123943] [client 178.153.171.161:23465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJ4gAAABk"]
[Tue Aug 18 13:01:44.342110 2026] [security2:error] [pid 123784:tid 123943] [client 178.153.171.161:23465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJ4gAAABk"]
[Tue Aug 18 13:01:44.388359 2026] [security2:error] [pid 139043:tid 139267] [client 135.225.78.186:16794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/k.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUUwAAAOM"]
[Tue Aug 18 13:01:44.402806 2026] [security2:error] [pid 139043:tid 139199] [client 20.186.30.159:10102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/bajah.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUVAAAAJ8"]
[Tue Aug 18 13:01:44.407914 2026] [security2:error] [pid 139043:tid 139208] [client 20.163.43.14:8873] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/1.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUVQAAAKg"]
[Tue Aug 18 13:01:44.408030 2026] [security2:error] [pid 139043:tid 139208] [client 20.163.43.14:8873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/1.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUVQAAAKg"]
[Tue Aug 18 13:01:44.409503 2026] [security2:error] [pid 123784:tid 124034] [client 20.100.169.31:4301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-themes.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJ5QAAAHQ"]
[Tue Aug 18 13:01:44.411996 2026] [security2:error] [pid 123784:tid 124002] [client 20.79.204.6:11707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/info.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJ5gAAAFQ"]
[Tue Aug 18 13:01:44.416670 2026] [security2:error] [pid 139043:tid 139285] [client 20.119.58.187:10494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/flower.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUVgAAAPU"]
[Tue Aug 18 13:01:44.433893 2026] [security2:error] [pid 139043:tid 139241] [client 158.158.74.177:9278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUVwAAAMk"]
[Tue Aug 18 13:01:44.457407 2026] [security2:error] [pid 139043:tid 139266] [client 20.250.13.23:51226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUWQAAAOI"]
[Tue Aug 18 13:01:44.471606 2026] [security2:error] [pid 123784:tid 124018] [client 20.226.112.14:28767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wpver.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJ-gAAAGQ"]
[Tue Aug 18 13:01:44.494840 2026] [authz_core:error] [pid 123784:tid 123851] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:44.495102 2026] [authz_core:error] [pid 123784:tid 123851] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:44.499566 2026] [security2:error] [pid 123784:tid 123994] [client 52.139.47.57:16592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/hplfuns.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJ_QAAAEw"]
[Tue Aug 18 13:01:44.508907 2026] [security2:error] [pid 139043:tid 139179] [client 20.48.236.86:14531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/1xmomo.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUWgAAAIs"]
[Tue Aug 18 13:01:44.564443 2026] [security2:error] [pid 139043:tid 139265] [client 20.102.65.165:8475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/akismet.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUWwAAAOE"]
[Tue Aug 18 13:01:44.594190 2026] [security2:error] [pid 139043:tid 139190] [client 20.104.100.201:49676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUXAAAAJY"]
[Tue Aug 18 13:01:44.619005 2026] [security2:error] [pid 123784:tid 123924] [client 20.80.111.3:3604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/Text/Diff/Engine.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKAAAAAAY"]
[Tue Aug 18 13:01:44.642099 2026] [security2:error] [pid 139043:tid 139240] [client 172.213.243.2:12064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/fff.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUXgAAAMg"]
[Tue Aug 18 13:01:44.680871 2026] [security2:error] [pid 139043:tid 139194] [client 52.173.121.69:9741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUXwAAAJo"]
[Tue Aug 18 13:01:44.718733 2026] [security2:error] [pid 139043:tid 139289] [client 20.226.112.14:22958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/thui.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUYAAAAPk"]
[Tue Aug 18 13:01:44.725058 2026] [security2:error] [pid 123784:tid 123995] [client 4.232.151.198:11590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKAwAAAE0"]
[Tue Aug 18 13:01:44.732865 2026] [security2:error] [pid 123784:tid 124020] [client 20.151.109.219:14119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/m.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKBAAAAGY"]
[Tue Aug 18 13:01:44.735044 2026] [security2:error] [pid 123784:tid 123968] [client 20.163.43.14:8854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKBQAAADI"]
[Tue Aug 18 13:01:44.736848 2026] [security2:error] [pid 123784:tid 124014] [client 20.116.17.175:23016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/flox.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKBgAAAGA"]
[Tue Aug 18 13:01:44.737162 2026] [security2:error] [pid 123784:tid 123996] [client 20.75.92.165:4261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKBwAAAE4"]
[Tue Aug 18 13:01:44.739247 2026] [security2:error] [pid 123784:tid 123921] [client 20.116.17.175:54892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/f35.update.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKCAAAAAM"]
[Tue Aug 18 13:01:44.739631 2026] [security2:error] [pid 139043:tid 139260] [client 20.91.215.254:19409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/import.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUYQAAANw"]
[Tue Aug 18 13:01:44.770470 2026] [security2:error] [pid 139043:tid 139220] [client 20.119.58.187:10472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/file.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUYgAAALQ"]
[Tue Aug 18 13:01:44.774873 2026] [security2:error] [pid 139043:tid 139299] [client 20.29.77.16:64952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/loading.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUYwAAAQM"]
[Tue Aug 18 13:01:44.779556 2026] [security2:error] [pid 139043:tid 139182] [client 213.35.127.232:58893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUZAAAAI4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:44.786885 2026] [security2:error] [pid 123784:tid 123952] [client 68.221.73.131:50875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/contacto.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKCwAAACI"]
[Tue Aug 18 13:01:44.799170 2026] [security2:error] [pid 123784:tid 123989] [client 20.127.136.245:22206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKDQAAAEc"]
[Tue Aug 18 13:01:44.828358 2026] [security2:error] [pid 139043:tid 139275] [client 20.186.30.159:10073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/ajax.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUZQAAAOs"]
[Tue Aug 18 13:01:44.872992 2026] [security2:error] [pid 139043:tid 139239] [client 157.20.138.62:64149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUZgAAAMc"]
[Tue Aug 18 13:01:44.873140 2026] [security2:error] [pid 139043:tid 139239] [client 157.20.138.62:64149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUZgAAAMc"]
[Tue Aug 18 13:01:44.873398 2026] [security2:error] [pid 139043:tid 139278] [client 20.48.236.86:14513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/mosty.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUZwAAAO4"]
[Tue Aug 18 13:01:44.875093 2026] [security2:error] [pid 139043:tid 139174] [client 20.104.100.201:49144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/ty.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUaAAAAIY"]
[Tue Aug 18 13:01:44.883485 2026] [security2:error] [pid 139043:tid 139202] [client 20.79.204.6:12241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/profile.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUaQAAAKI"]
[Tue Aug 18 13:01:44.902376 2026] [security2:error] [pid 123784:tid 123959] [client 20.251.112.238:18198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/cu.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKEAAAACk"]
[Tue Aug 18 13:01:45.006578 2026] [security2:error] [pid 139043:tid 139197] [client 103.184.169.37:43205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUagAAAJ0"]
[Tue Aug 18 13:01:45.006690 2026] [security2:error] [pid 139043:tid 139197] [client 103.184.169.37:43205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUagAAAJ0"]
[Tue Aug 18 13:01:45.023243 2026] [security2:error] [pid 139043:tid 139236] [client 158.23.17.4:57085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/mimes.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUawAAAMQ"]
[Tue Aug 18 13:01:45.023494 2026] [security2:error] [pid 139043:tid 139251] [client 20.79.204.6:11566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/profile.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUbAAAANM"]
[Tue Aug 18 13:01:45.048498 2026] [security2:error] [pid 139043:tid 139253] [client 20.75.92.165:4326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/about/function.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUbQAAANU"]
[Tue Aug 18 13:01:45.066038 2026] [security2:error] [pid 123784:tid 124031] [client 20.100.169.31:4336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKFAAAAHE"]
[Tue Aug 18 13:01:45.067129 2026] [security2:error] [pid 139043:tid 139249] [client 172.213.243.2:14349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/pouhg.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUcAAAANE"]
[Tue Aug 18 13:01:45.090826 2026] [security2:error] [pid 123784:tid 123956] [client 52.173.121.69:53634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKFwAAACY"]
[Tue Aug 18 13:01:45.094866 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:45.095129 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:45.124426 2026] [security2:error] [pid 139043:tid 139192] [client 20.119.58.187:10186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/goods.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUcwAAAJg"]
[Tue Aug 18 13:01:45.131790 2026] [security2:error] [pid 123784:tid 123981] [client 158.158.74.177:9239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKGQAAAD8"]
[Tue Aug 18 13:01:45.139586 2026] [security2:error] [pid 123784:tid 123819] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/nw.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKGgAALB4"]
[Tue Aug 18 13:01:45.142247 2026] [security2:error] [pid 139043:tid 139254] [client 20.163.43.14:8918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUdAAAANY"]
[Tue Aug 18 13:01:45.152443 2026] [security2:error] [pid 139043:tid 139184] [client 20.104.100.201:49695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUdQAAAJA"]
[Tue Aug 18 13:01:45.164117 2026] [security2:error] [pid 123784:tid 124000] [client 216.244.66.232:51596] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKGwAAAFI"]
[Tue Aug 18 13:01:45.164197 2026] [security2:error] [pid 123784:tid 124000] [client 216.244.66.232:51596] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKGwAAAFI"]
[Tue Aug 18 13:01:45.167880 2026] [security2:error] [pid 123784:tid 123948] [client 20.151.109.219:39313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/nl.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKHAAAAB4"]
[Tue Aug 18 13:01:45.171332 2026] [security2:error] [pid 139043:tid 139203] [client 4.232.94.69:25487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/hyIPpxWDQ.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUdgAAAKM"]
[Tue Aug 18 13:01:45.191815 2026] [security2:error] [pid 139043:tid 139177] [client 158.23.17.4:20408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/pl.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUdwAAAIk"]
[Tue Aug 18 13:01:45.258935 2026] [security2:error] [pid 139043:tid 139288] [client 20.29.77.16:40542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/conn-test.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUeQAAAPg"]
[Tue Aug 18 13:01:45.301581 2026] [security2:error] [pid 139043:tid 139218] [client 20.250.13.23:6808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/ku.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUewAAALI"]
[Tue Aug 18 13:01:45.319031 2026] [security2:error] [pid 139043:tid 139268] [client 20.75.92.165:4310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/function/function.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUfAAAAOQ"]
[Tue Aug 18 13:01:45.328908 2026] [security2:error] [pid 139043:tid 139270] [client 20.48.236.86:14523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/blurbs.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUfQAAAOY"]
[Tue Aug 18 13:01:45.341396 2026] [security2:error] [pid 139043:tid 139277] [client 20.116.17.175:53554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/bdroot.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUfwAAAO0"]
[Tue Aug 18 13:01:45.347465 2026] [security2:error] [pid 139043:tid 139232] [client 114.119.138.172:27291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cainelli.com.br"] [uri "/uploads/site/nifedipine-35-weeks-pregnant-neurontin-d2b316"] [unique_id "aoSB6f2v-lWn9OzQT7UUgAAAAMA"], referer: http://cainelli.com.br/uploads/site/ferrellgas-rumors-paroxetine-d2b316
[Tue Aug 18 13:01:45.354117 2026] [security2:error] [pid 123784:tid 123898] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/sb.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKHwAAbG0"]
[Tue Aug 18 13:01:45.400311 2026] [authz_core:error] [pid 123784:tid 123892] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:45.400716 2026] [authz_core:error] [pid 123784:tid 123892] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:45.427382 2026] [security2:error] [pid 139043:tid 139295] [client 20.186.30.159:9988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUggAAAP8"]
[Tue Aug 18 13:01:45.431212 2026] [security2:error] [pid 139043:tid 139180] [client 20.104.100.201:49424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/dot.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUgwAAAIw"]
[Tue Aug 18 13:01:45.470395 2026] [security2:error] [pid 139043:tid 139285] [client 20.163.43.14:8926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/as.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUhAAAAPU"]
[Tue Aug 18 13:01:45.474915 2026] [security2:error] [pid 139043:tid 139279] [client 172.213.243.2:16832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/moon3.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUhQAAAO8"]
[Tue Aug 18 13:01:45.477074 2026] [security2:error] [pid 139043:tid 139195] [client 20.151.109.219:24409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/68.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUhgAAAJs"]
[Tue Aug 18 13:01:45.481598 2026] [security2:error] [pid 139043:tid 139283] [client 20.119.58.187:10131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/g.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUhwAAAPM"]
[Tue Aug 18 13:01:45.486198 2026] [security2:error] [pid 139043:tid 139224] [client 20.79.204.6:11547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/sx.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUiQAAALg"]
[Tue Aug 18 13:01:45.503099 2026] [security2:error] [pid 139043:tid 139248] [client 20.91.215.254:11591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUigAAANA"]
[Tue Aug 18 13:01:45.504165 2026] [security2:error] [pid 139043:tid 139241] [client 20.80.111.3:27074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-mail.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUiwAAAMk"]
[Tue Aug 18 13:01:45.519445 2026] [security2:error] [pid 123784:tid 123938] [client 20.127.136.245:18431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/.alf.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKIwAAABQ"]
[Tue Aug 18 13:01:45.532795 2026] [security2:error] [pid 123784:tid 123911] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/xj.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKJAAAOno"]
[Tue Aug 18 13:01:45.546035 2026] [security2:error] [pid 139043:tid 139280] [client 52.139.47.57:3817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/hosty.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUjQAAAPA"]
[Tue Aug 18 13:01:45.565494 2026] [security2:error] [pid 123784:tid 123829] [remote 104.248.149.255:33938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.149.248.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gustavofrison.com.br"] [uri "/wp-login.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKJgAAKCg"]
[Tue Aug 18 13:01:45.584055 2026] [security2:error] [pid 123784:tid 124022] [client 172.202.39.151:53739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-config-sample.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKKAAAAGg"]
[Tue Aug 18 13:01:45.592045 2026] [security2:error] [pid 123784:tid 123920] [client 158.23.17.4:47915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ni.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKKQAAAAI"]
[Tue Aug 18 13:01:45.602088 2026] [security2:error] [pid 139043:tid 139247] [client 20.116.17.175:22956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/op.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUjgAAAM8"]
[Tue Aug 18 13:01:45.623366 2026] [security2:error] [pid 139043:tid 139271] [client 20.79.204.6:11565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/sx.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUjwAAAOc"]
[Tue Aug 18 13:01:45.644218 2026] [security2:error] [pid 139043:tid 139257] [client 20.226.112.14:22948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/tmpls.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUkAAAANk"]
[Tue Aug 18 13:01:45.655385 2026] [security2:error] [pid 139043:tid 139246] [client 4.232.151.198:45061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/404.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUkQAAAM4"]
[Tue Aug 18 13:01:45.664728 2026] [security2:error] [pid 139043:tid 139284] [client 20.75.92.165:4306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-signin.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUkgAAAPQ"]
[Tue Aug 18 13:01:45.705878 2026] [security2:error] [pid 139043:tid 139194] [client 20.104.100.201:49427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/005.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUkwAAAJo"]
[Tue Aug 18 13:01:45.726604 2026] [security2:error] [pid 123784:tid 124023] [client 5.31.227.224:59035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKLQAAAGk"]
[Tue Aug 18 13:01:45.726700 2026] [security2:error] [pid 123784:tid 124023] [client 5.31.227.224:59035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKLQAAAGk"]
[Tue Aug 18 13:01:45.739696 2026] [security2:error] [pid 139043:tid 139188] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUlAAAAJQ"]
[Tue Aug 18 13:01:45.740843 2026] [security2:error] [pid 139043:tid 139220] [client 20.29.77.16:61082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/evil.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUlQAAALQ"]
[Tue Aug 18 13:01:45.779854 2026] [security2:error] [pid 139043:tid 139242] [client 20.151.109.219:63727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/jl.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUlgAAAMo"]
[Tue Aug 18 13:01:45.790967 2026] [security2:error] [pid 123784:tid 123901] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ns.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKLwAAc3A"]
[Tue Aug 18 13:01:45.795239 2026] [security2:error] [pid 139043:tid 139199] [client 213.35.127.232:59111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUmAAAAJ8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:45.799504 2026] [security2:error] [pid 139043:tid 139196] [client 20.251.112.238:62515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/X57.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUmQAAAJw"]
[Tue Aug 18 13:01:45.802476 2026] [security2:error] [pid 139043:tid 139189] [client 158.158.74.177:9237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/goat.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUmgAAAJU"]
[Tue Aug 18 13:01:45.808570 2026] [security2:error] [pid 139043:tid 139183] [client 20.163.43.14:8852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUmwAAAI8"]
[Tue Aug 18 13:01:45.825325 2026] [security2:error] [pid 139043:tid 139239] [client 20.48.236.86:14804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/bajah.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUnAAAAMc"]
[Tue Aug 18 13:01:45.825975 2026] [security2:error] [pid 139043:tid 139278] [client 158.23.17.4:56533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/env.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUnQAAAO4"]
[Tue Aug 18 13:01:45.837316 2026] [security2:error] [pid 139043:tid 139289] [client 20.119.58.187:10160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/hplfuns.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUngAAAPk"]
[Tue Aug 18 13:01:45.883362 2026] [security2:error] [pid 139043:tid 139243] [client 172.213.243.2:36147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/opts.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUnwAAAMs"]
[Tue Aug 18 13:01:45.936860 2026] [security2:error] [pid 139043:tid 139175] [client 20.118.133.132:25778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/33.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUoAAAAIc"]
[Tue Aug 18 13:01:45.939006 2026] [security2:error] [pid 139043:tid 139173] [client 20.80.111.3:27077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-the.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUoQAAAIU"]
[Tue Aug 18 13:01:45.950779 2026] [security2:error] [pid 139043:tid 139235] [client 52.173.121.69:60619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUogAAAMM"]
[Tue Aug 18 13:01:45.963680 2026] [security2:error] [pid 123784:tid 123935] [client 74.7.241.191:47706] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "riovacinas.com.br"] [uri "/index.html"] [unique_id "aoSB6WwDnJBNj2tDbYYKNwAAEVI"]
[Tue Aug 18 13:01:45.980781 2026] [security2:error] [pid 139043:tid 139251] [client 20.104.100.201:49124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/v2.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUqQAAANM"]
[Tue Aug 18 13:01:46.016406 2026] [security2:error] [pid 139043:tid 139185] [client 138.185.145.78:39228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "aoSB6v2v-lWn9OzQT7UUsQAAAJE"]
[Tue Aug 18 13:01:46.016506 2026] [security2:error] [pid 139043:tid 139185] [client 138.185.145.78:39228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "aoSB6v2v-lWn9OzQT7UUsQAAAJE"]
[Tue Aug 18 13:01:46.020348 2026] [security2:error] [pid 139043:tid 139269] [client 20.226.56.190:30983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/phpstatus.php"] [unique_id "aoSB6v2v-lWn9OzQT7UUvQAAAOU"]
[Tue Aug 18 13:01:46.045324 2026] [security2:error] [pid 123784:tid 123998] [client 20.75.92.165:4298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/f35.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKOwAAAFA"]
[Tue Aug 18 13:01:46.077239 2026] [security2:error] [pid 123784:tid 124008] [client 20.116.17.175:53157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-temp.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKPAAAAFo"]
[Tue Aug 18 13:01:46.079241 2026] [security2:error] [pid 139043:tid 139178] [client 158.23.17.4:60737] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "floripaveiculos.com.br"] [uri "/1.php"] [unique_id "aoSB6v2v-lWn9OzQT7UUygAAAIo"]
[Tue Aug 18 13:01:46.079336 2026] [security2:error] [pid 139043:tid 139178] [client 158.23.17.4:60737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/1.php"] [unique_id "aoSB6v2v-lWn9OzQT7UUygAAAIo"]
[Tue Aug 18 13:01:46.085466 2026] [security2:error] [pid 139043:tid 139212] [client 148.113.128.234:50254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "cstcoop.co.mz"] [uri "/robots.txt"] [unique_id "aoSB6v2v-lWn9OzQT7UUywAAAKw"]
[Tue Aug 18 13:01:46.085552 2026] [security2:error] [pid 139043:tid 139212] [client 148.113.128.234:50254] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cstcoop.co.mz"] [uri "/robots.txt"] [unique_id "aoSB6v2v-lWn9OzQT7UUywAAAKw"]
[Tue Aug 18 13:01:46.101038 2026] [security2:error] [pid 139043:tid 139176] [client 20.79.204.6:11702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSB6v2v-lWn9OzQT7UUzAAAAIg"]
[Tue Aug 18 13:01:46.115799 2026] [security2:error] [pid 139043:tid 139222] [client 20.127.136.245:22713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/.trash7206/index.php"] [unique_id "aoSB6v2v-lWn9OzQT7UUzgAAALY"]
[Tue Aug 18 13:01:46.125046 2026] [security2:error] [pid 139043:tid 139255] [client 37.40.227.74:57039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6v2v-lWn9OzQT7UUzwAAANc"]
[Tue Aug 18 13:01:46.125192 2026] [security2:error] [pid 139043:tid 139255] [client 37.40.227.74:57039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6v2v-lWn9OzQT7UUzwAAANc"]
[Tue Aug 18 13:01:46.125407 2026] [security2:error] [pid 139043:tid 139186] [client 20.151.109.219:24424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/tq.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU0AAAAJI"]
[Tue Aug 18 13:01:46.130648 2026] [security2:error] [pid 139043:tid 139288] [client 20.29.77.16:62850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/wp-key.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU0QAAAPg"]
[Tue Aug 18 13:01:46.143012 2026] [security2:error] [pid 139043:tid 139234] [client 20.163.43.14:8948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU0gAAAMI"]
[Tue Aug 18 13:01:46.185451 2026] [security2:error] [pid 139043:tid 139276] [client 20.91.215.254:11501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/ebs.php7"] [unique_id "aoSB6v2v-lWn9OzQT7UU1AAAAOw"]
[Tue Aug 18 13:01:46.188493 2026] [security2:error] [pid 139043:tid 139184] [client 20.119.58.187:10190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU1QAAAJA"]
[Tue Aug 18 13:01:46.191053 2026] [security2:error] [pid 123784:tid 123943] [client 20.250.13.23:51208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/chosen.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKQAAAABk"]
[Tue Aug 18 13:01:46.232178 2026] [security2:error] [pid 139043:tid 139274] [client 20.79.204.6:11672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU1gAAAOo"]
[Tue Aug 18 13:01:46.233977 2026] [security2:error] [pid 123784:tid 123919] [client 52.139.47.57:18083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/t.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKQgAAAAE"]
[Tue Aug 18 13:01:46.237452 2026] [security2:error] [pid 123784:tid 124019] [client 20.48.236.86:14803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/h.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKQwAAAGU"]
[Tue Aug 18 13:01:46.245700 2026] [security2:error] [pid 139043:tid 139232] [client 20.226.112.14:22861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/nzv.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU1wAAAMA"]
[Tue Aug 18 13:01:46.255948 2026] [security2:error] [pid 139043:tid 139264] [client 20.104.100.201:49429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wkl.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU2AAAAOA"]
[Tue Aug 18 13:01:46.258200 2026] [security2:error] [pid 139043:tid 139216] [client 172.202.39.151:52897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU2QAAALA"]
[Tue Aug 18 13:01:46.294676 2026] [security2:error] [pid 139043:tid 139258] [client 172.213.243.2:48376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/zwq13.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU2gAAANo"]
[Tue Aug 18 13:01:46.301434 2026] [authz_core:error] [pid 123784:tid 123882] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:46.301812 2026] [authz_core:error] [pid 123784:tid 123882] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:46.332822 2026] [security2:error] [pid 123784:tid 123873] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/gk.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKRgAAclQ"]
[Tue Aug 18 13:01:46.368342 2026] [security2:error] [pid 123784:tid 123954] [client 20.75.92.165:4254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/gg.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKRwAAACQ"]
[Tue Aug 18 13:01:46.378622 2026] [security2:error] [pid 139043:tid 139268] [client 20.80.111.3:3320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU2wAAAOQ"]
[Tue Aug 18 13:01:46.395221 2026] [security2:error] [pid 139043:tid 139195] [client 20.116.17.175:22975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/1xmomo.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU3AAAAJs"]
[Tue Aug 18 13:01:46.404746 2026] [security2:error] [pid 139043:tid 139224] [client 20.102.65.165:8524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/admin.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU3QAAALg"]
[Tue Aug 18 13:01:46.435106 2026] [security2:error] [pid 123784:tid 124041] [client 114.119.131.28:26211] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "plenitude.com.br"] [uri "/sobre"] [unique_id "aoSB6mwDnJBNj2tDbYYKSQAAAHs"], referer: https://plenitude.com.br/e-book-o-segredo-da-felicidade/
[Tue Aug 18 13:01:46.444779 2026] [security2:error] [pid 139043:tid 139241] [client 20.151.109.219:14131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/cv.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU3gAAAMk"]
[Tue Aug 18 13:01:46.449182 2026] [security2:error] [pid 139043:tid 139230] [client 158.158.74.177:9257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/Session.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU3wAAAL4"]
[Tue Aug 18 13:01:46.498646 2026] [security2:error] [pid 139043:tid 139187] [client 20.163.43.14:8881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU6AAAAJM"]
[Tue Aug 18 13:01:46.508194 2026] [security2:error] [pid 123784:tid 124037] [client 158.23.17.4:38291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/14.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKTAAAAHc"]
[Tue Aug 18 13:01:46.518664 2026] [security2:error] [pid 123784:tid 123792] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/wn.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKTQAABwM"]
[Tue Aug 18 13:01:46.522406 2026] [security2:error] [pid 139043:tid 139262] [client 172.202.39.151:40354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/file.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU6QAAAN4"]
[Tue Aug 18 13:01:46.529542 2026] [security2:error] [pid 123784:tid 123987] [client 20.104.100.201:49117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-asudo.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKTgAAAEU"]
[Tue Aug 18 13:01:46.535599 2026] [security2:error] [pid 139043:tid 139284] [client 20.226.112.14:34191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/error1.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU6gAAAPQ"]
[Tue Aug 18 13:01:46.540408 2026] [security2:error] [pid 123784:tid 124018] [client 20.119.58.187:10122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/in.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKTwAAAGQ"]
[Tue Aug 18 13:01:46.563447 2026] [security2:error] [pid 139043:tid 139240] [client 20.29.77.16:16536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/phpcheck.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU6wAAAMg"]
[Tue Aug 18 13:01:46.594568 2026] [security2:error] [pid 123784:tid 124010] [client 20.48.236.86:14811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/ano.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKUQAAAFw"]
[Tue Aug 18 13:01:46.595336 2026] [security2:error] [pid 139043:tid 139237] [client 20.127.136.245:4820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU7QAAAMU"]
[Tue Aug 18 13:01:46.663430 2026] [security2:error] [pid 139043:tid 139229] [client 4.232.151.198:30704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wk/index.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU7gAAAL0"]
[Tue Aug 18 13:01:46.699918 2026] [security2:error] [pid 123784:tid 123894] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/app.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKVQAAYGk"]
[Tue Aug 18 13:01:46.704000 2026] [security2:error] [pid 139043:tid 139271] [client 20.79.204.6:11860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU7wAAAOc"]
[Tue Aug 18 13:01:46.707508 2026] [security2:error] [pid 123784:tid 123996] [client 172.213.243.2:34410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/Okxob.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKVgAAAE4"]
[Tue Aug 18 13:01:46.711587 2026] [security2:error] [pid 123784:tid 123921] [client 20.251.112.238:62484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/forbidals.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKVwAAAAM"]
[Tue Aug 18 13:01:46.720484 2026] [security2:error] [pid 139043:tid 139259] [client 213.202.253.4:62533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/wp-content/txets.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU8gAAANs"], referer: www.google.com
[Tue Aug 18 13:01:46.762269 2026] [security2:error] [pid 123784:tid 123929] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKWQAAAAs"]
[Tue Aug 18 13:01:46.782873 2026] [security2:error] [pid 139043:tid 139239] [client 20.116.17.175:54851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-css.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU9gAAAMc"]
[Tue Aug 18 13:01:46.792346 2026] [security2:error] [pid 123784:tid 123952] [client 20.226.56.190:17858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/del.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKWwAAACI"]
[Tue Aug 18 13:01:46.801385 2026] [security2:error] [pid 123784:tid 123928] [client 20.104.100.201:49119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/az.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKXAAAAAo"]
[Tue Aug 18 13:01:46.811767 2026] [security2:error] [pid 123784:tid 123989] [client 20.75.92.165:2023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/class.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKXQAAAEc"]
[Tue Aug 18 13:01:46.815152 2026] [security2:error] [pid 123784:tid 123968] [client 20.80.111.3:18454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wso.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKXgAAADI"]
[Tue Aug 18 13:01:46.818177 2026] [security2:error] [pid 123784:tid 123994] [client 213.35.127.232:59353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKXwAAAEw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:46.826222 2026] [security2:error] [pid 123784:tid 124043] [client 20.163.43.14:8855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKYAAAAH0"]
[Tue Aug 18 13:01:46.835374 2026] [security2:error] [pid 123784:tid 123970] [client 135.225.78.186:65450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/82.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKYQAAADQ"]
[Tue Aug 18 13:01:46.838667 2026] [security2:error] [pid 123784:tid 123964] [client 20.79.204.6:12256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKYgAAAC4"]
[Tue Aug 18 13:01:46.847078 2026] [security2:error] [pid 139043:tid 139272] [client 20.91.215.254:19396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/include/Lurd.class.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU-AAAAOg"]
[Tue Aug 18 13:01:46.865292 2026] [security2:error] [pid 139043:tid 139228] [client 52.139.47.57:16604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU-QAAALw"]
[Tue Aug 18 13:01:46.893924 2026] [security2:error] [pid 123784:tid 123997] [client 20.119.58.187:10490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/info.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKZAAAAE8"]
[Tue Aug 18 13:01:46.895865 2026] [security2:error] [pid 123784:tid 123946] [client 20.226.112.14:28772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/155.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKZgAAABw"]
[Tue Aug 18 13:01:46.902039 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:46.902310 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:46.914128 2026] [security2:error] [pid 123784:tid 123907] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/87.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKZwAADnY"]
[Tue Aug 18 13:01:46.918571 2026] [security2:error] [pid 123784:tid 123990] [client 20.151.109.219:39345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/un.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKaAAAAEg"]
[Tue Aug 18 13:01:46.950334 2026] [security2:error] [pid 123784:tid 124028] [client 20.250.13.23:7100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/asd.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKagAAAG4"]
[Tue Aug 18 13:01:46.962628 2026] [security2:error] [pid 123784:tid 123978] [client 138.185.145.78:39702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKbAAAADw"]
[Tue Aug 18 13:01:46.962709 2026] [security2:error] [pid 123784:tid 123978] [client 138.185.145.78:39702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKbAAAADw"]
[Tue Aug 18 13:01:46.966912 2026] [security2:error] [pid 139043:tid 139270] [client 223.185.37.47:10425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU_wAAAOY"]
[Tue Aug 18 13:01:46.967028 2026] [security2:error] [pid 139043:tid 139270] [client 223.185.37.47:10425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU_wAAAOY"]
[Tue Aug 18 13:01:46.993563 2026] [security2:error] [pid 123784:tid 123950] [client 20.29.77.16:13663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/mimes.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKbQAAACA"]
[Tue Aug 18 13:01:47.033544 2026] [security2:error] [pid 123784:tid 123988] [client 20.48.236.86:14799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/ai.php"] [unique_id "aoSB62wDnJBNj2tDbYYKbwAAAEY"]
[Tue Aug 18 13:01:47.038446 2026] [security2:error] [pid 123784:tid 123981] [client 20.203.183.135:64508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB62wDnJBNj2tDbYYKcAAAAD8"]
[Tue Aug 18 13:01:47.062206 2026] [security2:error] [pid 123784:tid 124044] [client 20.79.204.6:10409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/edit-tags.php"] [unique_id "aoSB62wDnJBNj2tDbYYKcQAAAH4"]
[Tue Aug 18 13:01:47.075903 2026] [security2:error] [pid 139043:tid 139236] [client 20.104.100.201:49670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/z43agz.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVAgAAAMQ"]
[Tue Aug 18 13:01:47.077388 2026] [security2:error] [pid 139043:tid 139251] [client 158.23.17.4:17545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/88.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVAwAAANM"]
[Tue Aug 18 13:01:47.085016 2026] [security2:error] [pid 139043:tid 139253] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVBAAAANU"]
[Tue Aug 18 13:01:47.090658 2026] [security2:error] [pid 139043:tid 139233] [client 158.158.74.177:18984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVBQAAAME"]
[Tue Aug 18 13:01:47.110806 2026] [security2:error] [pid 123784:tid 123868] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/zi.php"] [unique_id "aoSB62wDnJBNj2tDbYYKcgAAbE8"]
[Tue Aug 18 13:01:47.119610 2026] [security2:error] [pid 123784:tid 123938] [client 172.213.243.2:14370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/file59.php"] [unique_id "aoSB62wDnJBNj2tDbYYKdAAAABQ"]
[Tue Aug 18 13:01:47.135739 2026] [security2:error] [pid 139043:tid 139221] [client 172.202.39.151:53735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVBwAAALU"]
[Tue Aug 18 13:01:47.224895 2026] [security2:error] [pid 139043:tid 139205] [client 20.226.112.14:38945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/fasx.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVCAAAAKU"]
[Tue Aug 18 13:01:47.226981 2026] [security2:error] [pid 139043:tid 139269] [client 68.221.73.131:13514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/image2.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVCQAAAOU"]
[Tue Aug 18 13:01:47.242103 2026] [security2:error] [pid 123784:tid 124013] [client 20.75.92.165:4224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/flower.php"] [unique_id "aoSB62wDnJBNj2tDbYYKeAAAAF8"]
[Tue Aug 18 13:01:47.247878 2026] [security2:error] [pid 123784:tid 123976] [client 20.119.58.187:10453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/inputs.php"] [unique_id "aoSB62wDnJBNj2tDbYYKeQAAADo"]
[Tue Aug 18 13:01:47.248316 2026] [security2:error] [pid 139043:tid 139178] [client 20.226.56.190:23793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/moderator.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVCgAAAIo"]
[Tue Aug 18 13:01:47.252282 2026] [security2:error] [pid 123784:tid 124030] [client 20.80.111.3:2000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/www.php"] [unique_id "aoSB62wDnJBNj2tDbYYKegAAAHA"]
[Tue Aug 18 13:01:47.266553 2026] [security2:error] [pid 139043:tid 139191] [client 52.173.121.69:9790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVCwAAAJc"]
[Tue Aug 18 13:01:47.272301 2026] [security2:error] [pid 123784:tid 123880] [remote 57.141.22.25:20446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSB62wDnJBNj2tDbYYKewAAAls"]
[Tue Aug 18 13:01:47.279390 2026] [security2:error] [pid 139043:tid 139212] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/0x.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVDAAAAKw"]
[Tue Aug 18 13:01:47.288201 2026] [security2:error] [pid 139043:tid 139206] [client 20.251.112.238:20220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/edit.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVDQAAAKY"]
[Tue Aug 18 13:01:47.294706 2026] [security2:error] [pid 123784:tid 123958] [client 52.139.47.57:3831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/xx.php"] [unique_id "aoSB62wDnJBNj2tDbYYKfAAAACg"]
[Tue Aug 18 13:01:47.299679 2026] [security2:error] [pid 139043:tid 139200] [client 20.151.109.219:63995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/evil.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVDgAAAKA"]
[Tue Aug 18 13:01:47.305513 2026] [security2:error] [pid 139043:tid 139225] [client 216.73.161.208:49619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.161.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/edit.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVEAAAALk"], referer: https://ozzyfernandesoficial.com.br/wp-login.php
[Tue Aug 18 13:01:47.314225 2026] [security2:error] [pid 123784:tid 123904] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/92.php"] [unique_id "aoSB62wDnJBNj2tDbYYKfgAAQXM"]
[Tue Aug 18 13:01:47.327583 2026] [security2:error] [pid 123784:tid 124007] [client 20.163.43.14:8958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSB62wDnJBNj2tDbYYKgAAAAFk"]
[Tue Aug 18 13:01:47.351501 2026] [security2:error] [pid 123784:tid 123935] [client 20.104.100.201:49419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/3.php"] [unique_id "aoSB62wDnJBNj2tDbYYKgQAAABE"]
[Tue Aug 18 13:01:47.422060 2026] [security2:error] [pid 139043:tid 139282] [client 20.127.136.245:1230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVEwAAAPI"]
[Tue Aug 18 13:01:47.465074 2026] [security2:error] [pid 123784:tid 123945] [client 172.202.39.151:44496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/epinyins.php"] [unique_id "aoSB62wDnJBNj2tDbYYKgwAAABs"]
[Tue Aug 18 13:01:47.490960 2026] [security2:error] [pid 139043:tid 139276] [client 20.116.17.175:54250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/flox.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVFQAAAOw"]
[Tue Aug 18 13:01:47.495819 2026] [security2:error] [pid 139043:tid 139273] [client 20.51.153.15:13655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVFgAAAOk"]
[Tue Aug 18 13:01:47.514615 2026] [security2:error] [pid 123784:tid 124017] [client 114.119.131.112:44355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "schuenckimoveis.com.br"] [uri "/detalhes-do-imovel/niteroi/itacoatiara/497/cobertura/"] [unique_id "aoSB62wDnJBNj2tDbYYKhQAAAGM"], referer: https://schuenckimoveis.com.br/detalhes-do-imovel/niteroi/itacoatiara/497/cobertura/
[Tue Aug 18 13:01:47.516705 2026] [security2:error] [pid 139043:tid 139274] [client 20.116.17.175:55234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/txets.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVFwAAAOo"]
[Tue Aug 18 13:01:47.520356 2026] [security2:error] [pid 123784:tid 124003] [client 20.79.204.6:12233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSB62wDnJBNj2tDbYYKhwAAAFU"]
[Tue Aug 18 13:01:47.521597 2026] [security2:error] [pid 123784:tid 123930] [client 20.226.112.14:28738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-good.php"] [unique_id "aoSB62wDnJBNj2tDbYYKiAAAAAw"]
[Tue Aug 18 13:01:47.524304 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:47.524569 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:47.526331 2026] [security2:error] [pid 139043:tid 139298] [client 142.44.228.234:48604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "cstcoop.co.mz"] [uri "/"] [unique_id "aoSB6_2v-lWn9OzQT7UVGAAAAQI"]
[Tue Aug 18 13:01:47.526429 2026] [security2:error] [pid 139043:tid 139298] [client 142.44.228.234:48604] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cstcoop.co.mz"] [uri "/"] [unique_id "aoSB6_2v-lWn9OzQT7UVGAAAAQI"]
[Tue Aug 18 13:01:47.532036 2026] [security2:error] [pid 139043:tid 139264] [client 172.213.243.2:19875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/eauu.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVGQAAAOA"]
[Tue Aug 18 13:01:47.545574 2026] [security2:error] [pid 123784:tid 123821] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/jm.php"] [unique_id "aoSB62wDnJBNj2tDbYYKiQAAVCA"]
[Tue Aug 18 13:01:47.564951 2026] [security2:error] [pid 123784:tid 123954] [client 158.23.17.4:20380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/mz.php"] [unique_id "aoSB62wDnJBNj2tDbYYKigAAACQ"]
[Tue Aug 18 13:01:47.573873 2026] [security2:error] [pid 139043:tid 139255] [client 20.250.13.23:51230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/akc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVGgAAANc"]
[Tue Aug 18 13:01:47.592431 2026] [security2:error] [pid 123784:tid 123953] [client 20.91.215.254:11496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSB62wDnJBNj2tDbYYKjAAAACM"]
[Tue Aug 18 13:01:47.598631 2026] [security2:error] [pid 123784:tid 123975] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/222.php"] [unique_id "aoSB62wDnJBNj2tDbYYKjQAAADk"]
[Tue Aug 18 13:01:47.601016 2026] [security2:error] [pid 123784:tid 124040] [client 20.119.58.187:10464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/item.php"] [unique_id "aoSB62wDnJBNj2tDbYYKjgAAAHo"]
[Tue Aug 18 13:01:47.615209 2026] [security2:error] [pid 139043:tid 139258] [client 20.151.109.219:60399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/pw.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVGwAAANo"]
[Tue Aug 18 13:01:47.616538 2026] [security2:error] [pid 139043:tid 139210] [client 138.185.145.78:37618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVHAAAAKo"]
[Tue Aug 18 13:01:47.616616 2026] [security2:error] [pid 139043:tid 139210] [client 138.185.145.78:37618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVHAAAAKo"]
[Tue Aug 18 13:01:47.625046 2026] [security2:error] [pid 139043:tid 139267] [client 158.23.17.4:28375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/tk.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVHQAAAOM"]
[Tue Aug 18 13:01:47.627473 2026] [security2:error] [pid 123784:tid 123918] [client 20.104.100.201:49467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/log.php"] [unique_id "aoSB62wDnJBNj2tDbYYKjwAAAAA"]
[Tue Aug 18 13:01:47.641449 2026] [security2:error] [pid 139043:tid 139300] [client 20.75.92.165:2015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/motu.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVHgAAAQQ"]
[Tue Aug 18 13:01:47.651696 2026] [security2:error] [pid 123784:tid 124033] [client 138.36.100.162:42462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB62wDnJBNj2tDbYYKkAAAAHM"]
[Tue Aug 18 13:01:47.651812 2026] [security2:error] [pid 123784:tid 124033] [client 138.36.100.162:42462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB62wDnJBNj2tDbYYKkAAAAHM"]
[Tue Aug 18 13:01:47.656473 2026] [security2:error] [pid 139043:tid 139224] [client 20.163.43.14:8953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/an.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVHwAAALg"]
[Tue Aug 18 13:01:47.658907 2026] [security2:error] [pid 139043:tid 139248] [client 20.79.204.6:11521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-admin/js/index.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVIAAAANA"]
[Tue Aug 18 13:01:47.662026 2026] [security2:error] [pid 139043:tid 139241] [client 20.29.77.16:13639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVIQAAAMk"]
[Tue Aug 18 13:01:47.688283 2026] [security2:error] [pid 139043:tid 139252] [client 20.80.111.3:27126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/x.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVIgAAANQ"]
[Tue Aug 18 13:01:47.708946 2026] [security2:error] [pid 139043:tid 139179] [client 20.226.112.14:32534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/zxin.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVJQAAAIs"]
[Tue Aug 18 13:01:47.711795 2026] [security2:error] [pid 139043:tid 139187] [client 20.102.65.165:8570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/ajax.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVJgAAAJM"]
[Tue Aug 18 13:01:47.716107 2026] [security2:error] [pid 139043:tid 139247] [client 138.185.145.78:40168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/blog/xmlrpc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVJwAAAM8"]
[Tue Aug 18 13:01:47.716182 2026] [security2:error] [pid 139043:tid 139247] [client 138.185.145.78:40168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/blog/xmlrpc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVJwAAAM8"]
[Tue Aug 18 13:01:47.723754 2026] [security2:error] [pid 123784:tid 123840] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/wj.php"] [unique_id "aoSB62wDnJBNj2tDbYYKkgAAODM"]
[Tue Aug 18 13:01:47.772693 2026] [security2:error] [pid 139043:tid 139190] [client 20.51.153.15:13582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVKAAAAJY"]
[Tue Aug 18 13:01:47.798392 2026] [security2:error] [pid 123784:tid 123969] [client 52.139.47.57:17574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/zwso.php"] [unique_id "aoSB62wDnJBNj2tDbYYKlAAAADM"]
[Tue Aug 18 13:01:47.806717 2026] [authz_core:error] [pid 123784:tid 123813] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:47.806989 2026] [authz_core:error] [pid 123784:tid 123813] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:47.814947 2026] [security2:error] [pid 139043:tid 139240] [client 138.185.145.78:40230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/wp/xmlrpc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVKQAAAMg"]
[Tue Aug 18 13:01:47.815028 2026] [security2:error] [pid 139043:tid 139240] [client 138.185.145.78:40230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/wp/xmlrpc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVKQAAAMg"]
[Tue Aug 18 13:01:47.822384 2026] [security2:error] [pid 139043:tid 139184] [client 4.232.94.69:14423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/randkeyword.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVKgAAAJA"]
[Tue Aug 18 13:01:47.828221 2026] [security2:error] [pid 123784:tid 123919] [client 213.35.127.232:59568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSB62wDnJBNj2tDbYYKlgAAAAE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:47.841677 2026] [security2:error] [pid 139043:tid 139279] [client 158.158.74.177:22859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/abcd.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVLAAAAO8"]
[Tue Aug 18 13:01:47.842550 2026] [security2:error] [pid 139043:tid 139188] [client 20.48.236.86:14788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/w1px.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVLQAAAJQ"]
[Tue Aug 18 13:01:47.859007 2026] [security2:error] [pid 139043:tid 139220] [client 158.23.17.4:60741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/hj.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVLgAAALQ"]
[Tue Aug 18 13:01:47.903333 2026] [security2:error] [pid 123784:tid 123845] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/74.php"] [unique_id "aoSB62wDnJBNj2tDbYYKmQAATjg"]
[Tue Aug 18 13:01:47.905404 2026] [security2:error] [pid 139043:tid 139182] [client 20.104.100.201:49444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/ohct.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVLwAAAI4"]
[Tue Aug 18 13:01:47.912775 2026] [security2:error] [pid 139043:tid 139275] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/aa.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVMAAAAOs"]
[Tue Aug 18 13:01:47.916502 2026] [security2:error] [pid 139043:tid 139242] [client 138.185.145.78:40284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/wordpress/xmlrpc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVMQAAAMo"]
[Tue Aug 18 13:01:47.916575 2026] [security2:error] [pid 139043:tid 139242] [client 138.185.145.78:40284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/wordpress/xmlrpc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVMQAAAMo"]
[Tue Aug 18 13:01:47.947082 2026] [security2:error] [pid 123784:tid 124035] [client 172.213.243.2:18483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/dsd.php"] [unique_id "aoSB62wDnJBNj2tDbYYKnAAAAHU"]
[Tue Aug 18 13:01:47.954958 2026] [security2:error] [pid 139043:tid 139260] [client 20.119.58.187:10457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/k.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVMwAAANw"]
[Tue Aug 18 13:01:47.976679 2026] [security2:error] [pid 139043:tid 139278] [client 20.38.3.247:4515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/puc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVNAAAAO4"]
[Tue Aug 18 13:01:48.014475 2026] [security2:error] [pid 139043:tid 139228] [client 138.185.145.78:40352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/news/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVNwAAALw"]
[Tue Aug 18 13:01:48.014556 2026] [security2:error] [pid 139043:tid 139228] [client 138.185.145.78:40352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/news/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVNwAAALw"]
[Tue Aug 18 13:01:48.027887 2026] [security2:error] [pid 139043:tid 139209] [client 20.51.153.15:13685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/dirs.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVOAAAAKk"]
[Tue Aug 18 13:01:48.053677 2026] [security2:error] [pid 139043:tid 139235] [client 20.151.109.219:60922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/fn.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVOQAAAMM"]
[Tue Aug 18 13:01:48.065179 2026] [security2:error] [pid 139043:tid 139233] [client 168.62.48.100:5505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVOwAAAME"]
[Tue Aug 18 13:01:48.106865 2026] [authz_core:error] [pid 123784:tid 123877] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:48.107130 2026] [authz_core:error] [pid 123784:tid 123877] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:48.113764 2026] [security2:error] [pid 139043:tid 139254] [client 138.185.145.78:40422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/web/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVPAAAANY"]
[Tue Aug 18 13:01:48.113844 2026] [security2:error] [pid 139043:tid 139254] [client 138.185.145.78:40422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/web/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVPAAAANY"]
[Tue Aug 18 13:01:48.121479 2026] [security2:error] [pid 139043:tid 139291] [client 20.226.112.14:28585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/pass4.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVPQAAAPs"]
[Tue Aug 18 13:01:48.124244 2026] [security2:error] [pid 139043:tid 139174] [client 20.80.111.3:18446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVPgAAAIY"]
[Tue Aug 18 13:01:48.126750 2026] [security2:error] [pid 139043:tid 139261] [client 4.232.151.198:42100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/about.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVPwAAAN0"]
[Tue Aug 18 13:01:48.134587 2026] [security2:error] [pid 139043:tid 139178] [client 20.127.136.245:22951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVQAAAAIo"]
[Tue Aug 18 13:01:48.149283 2026] [security2:error] [pid 139043:tid 139212] [client 20.251.112.238:59522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/kj.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVQQAAAKw"]
[Tue Aug 18 13:01:48.154495 2026] [security2:error] [pid 139043:tid 139206] [client 172.202.39.151:40937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/cgi-bin/index.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVQgAAAKY"]
[Tue Aug 18 13:01:48.158200 2026] [security2:error] [pid 139043:tid 139200] [client 20.163.43.14:8900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/404.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVQwAAAKA"]
[Tue Aug 18 13:01:48.182680 2026] [security2:error] [pid 139043:tid 139186] [client 20.104.100.201:49112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/ot.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVRgAAAJI"]
[Tue Aug 18 13:01:48.213385 2026] [security2:error] [pid 139043:tid 139289] [client 138.185.145.78:40466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/cms/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVSAAAAPk"]
[Tue Aug 18 13:01:48.213477 2026] [security2:error] [pid 139043:tid 139289] [client 138.185.145.78:40466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/cms/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVSAAAAPk"]
[Tue Aug 18 13:01:48.220149 2026] [security2:error] [pid 123784:tid 123989] [client 216.244.66.232:51610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKogAAAEc"]
[Tue Aug 18 13:01:48.220242 2026] [security2:error] [pid 123784:tid 123989] [client 216.244.66.232:51610] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKogAAAEc"]
[Tue Aug 18 13:01:48.263466 2026] [security2:error] [pid 139043:tid 139297] [client 20.250.13.23:6794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/maintenance.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVSgAAAQE"]
[Tue Aug 18 13:01:48.273223 2026] [security2:error] [pid 139043:tid 139276] [client 20.51.153.15:13570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/fresh.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVTQAAAOw"]
[Tue Aug 18 13:01:48.289818 2026] [security2:error] [pid 139043:tid 139249] [client 20.91.215.254:27080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/lite.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVTgAAANE"]
[Tue Aug 18 13:01:48.307522 2026] [security2:error] [pid 139043:tid 139232] [client 20.203.183.135:50259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVUAAAAMA"]
[Tue Aug 18 13:01:48.309480 2026] [security2:error] [pid 139043:tid 139222] [client 20.48.236.86:14490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/zi-936.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVUQAAALY"]
[Tue Aug 18 13:01:48.311664 2026] [security2:error] [pid 139043:tid 139274] [client 138.185.145.78:40532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/wp-site/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVUgAAAOo"]
[Tue Aug 18 13:01:48.311751 2026] [security2:error] [pid 139043:tid 139274] [client 138.185.145.78:40532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/wp-site/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVUgAAAOo"]
[Tue Aug 18 13:01:48.312522 2026] [security2:error] [pid 139043:tid 139298] [client 68.221.73.131:43280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/fb.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVUwAAAQI"]
[Tue Aug 18 13:01:48.314406 2026] [security2:error] [pid 123784:tid 123970] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/abcd.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKpQAAADQ"]
[Tue Aug 18 13:01:48.319002 2026] [security2:error] [pid 139043:tid 139234] [client 20.119.58.187:9748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/license.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVVAAAAMI"]
[Tue Aug 18 13:01:48.335588 2026] [security2:error] [pid 139043:tid 139295] [client 20.226.112.14:38939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-conflg.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVVgAAAP8"]
[Tue Aug 18 13:01:48.360056 2026] [security2:error] [pid 139043:tid 139210] [client 172.213.243.2:19569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/c4.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVWAAAAKo"]
[Tue Aug 18 13:01:48.365971 2026] [security2:error] [pid 123784:tid 123924] [client 20.79.204.6:11861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKpgAAAAY"]
[Tue Aug 18 13:01:48.375705 2026] [security2:error] [pid 139043:tid 139285] [client 20.151.109.219:24439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/kf.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVWwAAAPU"]
[Tue Aug 18 13:01:48.380267 2026] [security2:error] [pid 139043:tid 139268] [client 52.139.47.57:17330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/x.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVXAAAAOQ"]
[Tue Aug 18 13:01:48.403620 2026] [security2:error] [pid 139043:tid 139283] [client 20.226.112.14:32554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/z.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVXQAAAPM"]
[Tue Aug 18 13:01:48.410233 2026] [authz_core:error] [pid 123784:tid 123835] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:48.410385 2026] [security2:error] [pid 139043:tid 139211] [client 20.29.77.16:27072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/pqr.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVXgAAAKs"]
[Tue Aug 18 13:01:48.410672 2026] [authz_core:error] [pid 123784:tid 123835] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:48.412163 2026] [security2:error] [pid 139043:tid 139248] [client 138.185.145.78:40582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/wpsite/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVXwAAANA"]
[Tue Aug 18 13:01:48.412228 2026] [security2:error] [pid 139043:tid 139248] [client 138.185.145.78:40582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/wpsite/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVXwAAANA"]
[Tue Aug 18 13:01:48.443813 2026] [security2:error] [pid 139043:tid 139266] [client 52.173.121.69:14999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVYgAAAOI"]
[Tue Aug 18 13:01:48.459036 2026] [security2:error] [pid 139043:tid 139187] [client 20.104.100.201:49148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/v5.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVYwAAAJM"]
[Tue Aug 18 13:01:48.465770 2026] [security2:error] [pid 139043:tid 139218] [client 20.116.17.175:22968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/img.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVZQAAALI"]
[Tue Aug 18 13:01:48.470587 2026] [security2:error] [pid 123784:tid 123946] [client 20.116.17.175:53122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/op.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKqgAAABw"]
[Tue Aug 18 13:01:48.473287 2026] [security2:error] [pid 139043:tid 139246] [client 20.79.204.6:11673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/about.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVZgAAAM4"]
[Tue Aug 18 13:01:48.475195 2026] [security2:error] [pid 139043:tid 139230] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVYAAAvhI"]
[Tue Aug 18 13:01:48.492637 2026] [security2:error] [pid 123784:tid 123876] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/av.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKrAAAFVc"]
[Tue Aug 18 13:01:48.495051 2026] [security2:error] [pid 139043:tid 139205] [client 20.79.204.6:10716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/u.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVaAAAAKU"]
[Tue Aug 18 13:01:48.503315 2026] [security2:error] [pid 139043:tid 139237] [client 135.225.78.186:58077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/dex.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVaQAAAMU"]
[Tue Aug 18 13:01:48.509358 2026] [security2:error] [pid 123784:tid 123968] [client 158.158.74.177:18983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/kj.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKrQAAADI"]
[Tue Aug 18 13:01:48.511742 2026] [security2:error] [pid 139043:tid 139194] [client 138.185.145.78:40638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/new/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVagAAAJo"]
[Tue Aug 18 13:01:48.511809 2026] [security2:error] [pid 139043:tid 139194] [client 138.185.145.78:40638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/new/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVagAAAJo"]
[Tue Aug 18 13:01:48.527361 2026] [security2:error] [pid 139043:tid 139279] [client 20.118.133.132:13987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/packed.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVawAAAO8"]
[Tue Aug 18 13:01:48.558427 2026] [security2:error] [pid 139043:tid 139241] [client 20.80.111.3:33421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/aaa.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVbAAAAMk"]
[Tue Aug 18 13:01:48.582046 2026] [security2:error] [pid 139043:tid 139292] [client 158.23.17.4:15134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ij.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVbgAAAPw"]
[Tue Aug 18 13:01:48.584490 2026] [security2:error] [pid 139043:tid 139259] [client 20.51.153.15:13688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/admin404.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVbwAAANs"]
[Tue Aug 18 13:01:48.594753 2026] [security2:error] [pid 139043:tid 139183] [client 20.226.112.14:38913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/222.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVcAAAAI8"]
[Tue Aug 18 13:01:48.601028 2026] [security2:error] [pid 139043:tid 139239] [client 20.75.92.165:4332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/404.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVcQAAAMc"]
[Tue Aug 18 13:01:48.613514 2026] [security2:error] [pid 139043:tid 139196] [client 138.185.145.78:40694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVcgAAAJw"]
[Tue Aug 18 13:01:48.613583 2026] [security2:error] [pid 139043:tid 139196] [client 138.185.145.78:40694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVcgAAAJw"]
[Tue Aug 18 13:01:48.663450 2026] [security2:error] [pid 139043:tid 139284] [client 20.163.43.14:8868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-login.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVZwAAAPQ"]
[Tue Aug 18 13:01:48.673130 2026] [security2:error] [pid 139043:tid 139214] [client 20.119.58.187:10138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/load.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVdQAAAK4"]
[Tue Aug 18 13:01:48.684363 2026] [security2:error] [pid 139043:tid 139231] [client 20.151.109.219:14116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/su.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVdgAAAL8"]
[Tue Aug 18 13:01:48.701451 2026] [security2:error] [pid 123784:tid 123814] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ag.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKsAAAWxk"]
[Tue Aug 18 13:01:48.702290 2026] [security2:error] [pid 139043:tid 139253] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/admin.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVdwAAANU"]
[Tue Aug 18 13:01:48.708819 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:48.709161 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:48.712298 2026] [security2:error] [pid 123784:tid 123991] [client 20.48.236.86:14536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/dcsgumnm.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKsgAAAEk"]
[Tue Aug 18 13:01:48.715777 2026] [security2:error] [pid 123784:tid 124028] [client 138.185.145.78:40758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKswAAAG4"]
[Tue Aug 18 13:01:48.715854 2026] [security2:error] [pid 123784:tid 124028] [client 138.185.145.78:40758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKswAAAG4"]
[Tue Aug 18 13:01:48.736787 2026] [security2:error] [pid 139043:tid 139221] [client 20.104.100.201:49460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/replace.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVegAAALU"]
[Tue Aug 18 13:01:48.769129 2026] [security2:error] [pid 123784:tid 123978] [client 172.213.243.2:16872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/an7.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKtQAAADw"]
[Tue Aug 18 13:01:48.815186 2026] [security2:error] [pid 123784:tid 123982] [client 138.185.145.78:40830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/site/xmlrpc.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKtgAAAEA"]
[Tue Aug 18 13:01:48.815317 2026] [security2:error] [pid 123784:tid 123982] [client 138.185.145.78:40830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/site/xmlrpc.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKtgAAAEA"]
[Tue Aug 18 13:01:48.815987 2026] [security2:error] [pid 139043:tid 139206] [client 20.251.112.238:59537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/bes.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVfwAAAKY"]
[Tue Aug 18 13:01:48.820077 2026] [security2:error] [pid 139043:tid 139200] [client 20.51.153.15:13571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/loading.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVgAAAAKA"]
[Tue Aug 18 13:01:48.840670 2026] [security2:error] [pid 123784:tid 123941] [client 213.35.127.232:59787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKtwAAABc"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:48.872763 2026] [security2:error] [pid 123784:tid 123852] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ig.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKuQAAbz8"]
[Tue Aug 18 13:01:48.873955 2026] [security2:error] [pid 123784:tid 123990] [client 52.139.47.57:36847] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.compratec.com.br"] [uri "/1.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKugAAAEg"]
[Tue Aug 18 13:01:48.874077 2026] [security2:error] [pid 123784:tid 123990] [client 52.139.47.57:36847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/1.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKugAAAEg"]
[Tue Aug 18 13:01:48.883762 2026] [security2:error] [pid 139043:tid 139213] [client 20.250.13.23:59909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/options-writing.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVgQAAAK0"]
[Tue Aug 18 13:01:48.907817 2026] [security2:error] [pid 123784:tid 124031] [client 20.127.136.245:22953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKuwAAAHE"]
[Tue Aug 18 13:01:48.907817 2026] [security2:error] [pid 139043:tid 139203] [client 20.226.112.14:39455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/G-in.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVhAAAAKM"]
[Tue Aug 18 13:01:48.908697 2026] [security2:error] [pid 123784:tid 123956] [client 20.29.77.16:33566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/lmfi2.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKvAAAACY"]
[Tue Aug 18 13:01:48.917983 2026] [security2:error] [pid 123784:tid 123962] [client 138.185.145.78:40876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/news/xmlrpc.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKvQAAACw"]
[Tue Aug 18 13:01:48.918055 2026] [security2:error] [pid 123784:tid 123962] [client 138.185.145.78:40876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/news/xmlrpc.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKvQAAACw"]
[Tue Aug 18 13:01:48.924919 2026] [security2:error] [pid 123784:tid 123934] [client 20.91.215.254:19433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSB7GwDnJBNj2tDbYYKvgAAABA"]
[Tue Aug 18 13:01:48.970641 2026] [security2:error] [pid 139043:tid 139254] [client 20.79.204.6:12260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVhgAAANY"]
[Tue Aug 18 13:01:48.987616 2026] [security2:error] [pid 123784:tid 123949] [client 20.163.43.14:8907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKwAAAAB8"]
[Tue Aug 18 13:01:48.999006 2026] [security2:error] [pid 139043:tid 139289] [client 20.80.111.3:31240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/fpwch.php"] [unique_id "aoSB7P2v-lWn9OzQT7UViAAAAPk"]
[Tue Aug 18 13:01:49.008420 2026] [security2:error] [pid 123784:tid 124044] [client 20.104.100.201:49665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/fw/faiyy.php"] [unique_id "aoSB7WwDnJBNj2tDbYYKwgAAAH4"]
[Tue Aug 18 13:01:49.011831 2026] [authz_core:error] [pid 123784:tid 123874] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:49.012236 2026] [authz_core:error] [pid 123784:tid 123874] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:49.018858 2026] [security2:error] [pid 139043:tid 139277] [client 138.185.145.78:40938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/main/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UViQAAAO0"]
[Tue Aug 18 13:01:49.018955 2026] [security2:error] [pid 139043:tid 139277] [client 138.185.145.78:40938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/main/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UViQAAAO0"]
[Tue Aug 18 13:01:49.026674 2026] [security2:error] [pid 123784:tid 123988] [client 20.119.58.187:10481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/manager.php"] [unique_id "aoSB7WwDnJBNj2tDbYYKxAAAAEY"]
[Tue Aug 18 13:01:49.060152 2026] [security2:error] [pid 139043:tid 139224] [client 196.12.128.158:56553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UViwAAALg"]
[Tue Aug 18 13:01:49.060257 2026] [security2:error] [pid 139043:tid 139224] [client 196.12.128.158:56553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UViwAAALg"]
[Tue Aug 18 13:01:49.062987 2026] [security2:error] [pid 123784:tid 123942] [client 20.51.153.15:13694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/conn-test.php"] [unique_id "aoSB7WwDnJBNj2tDbYYKxgAAABg"]
[Tue Aug 18 13:01:49.085142 2026] [security2:error] [pid 123784:tid 123817] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ta.php"] [unique_id "aoSB7WwDnJBNj2tDbYYKyAAAahw"]
[Tue Aug 18 13:01:49.095745 2026] [security2:error] [pid 123784:tid 123926] [client 20.116.17.175:23027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSB7WwDnJBNj2tDbYYKyQAAAAg"]
[Tue Aug 18 13:01:49.096867 2026] [security2:error] [pid 139043:tid 139297] [client 20.79.204.6:11711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/admin-header.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVjgAAAQE"]
[Tue Aug 18 13:01:49.115340 2026] [security2:error] [pid 139043:tid 139290] [client 4.232.151.198:40778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/term.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVjwAAAPo"]
[Tue Aug 18 13:01:49.127052 2026] [autoindex:error] [pid 123784:tid 123940] [client 20.48.236.86:14827] AH01276: Cannot serve directory /home2/treinolab/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:49.127204 2026] [security2:error] [pid 139043:tid 139255] [client 138.185.145.78:40996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVkAAAANc"]
[Tue Aug 18 13:01:49.127278 2026] [security2:error] [pid 139043:tid 139255] [client 138.185.145.78:40996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVkAAAANc"]
[Tue Aug 18 13:01:49.128755 2026] [security2:error] [pid 139043:tid 139295] [client 20.151.109.219:20101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/wp-key.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVkQAAAP8"]
[Tue Aug 18 13:01:49.133440 2026] [security2:error] [pid 123784:tid 123976] [client 172.202.39.151:12737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSB7WwDnJBNj2tDbYYKzAAAADo"]
[Tue Aug 18 13:01:49.151638 2026] [security2:error] [pid 123784:tid 123947] [client 20.226.112.14:60122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/xxx.php"] [unique_id "aoSB7WwDnJBNj2tDbYYKzgAAAB0"]
[Tue Aug 18 13:01:49.178829 2026] [security2:error] [pid 139043:tid 139252] [client 197.184.64.235:41965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVkgAAANQ"]
[Tue Aug 18 13:01:49.183594 2026] [security2:error] [pid 139043:tid 139252] [client 197.184.64.235:41965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVkgAAANQ"]
[Tue Aug 18 13:01:49.184393 2026] [security2:error] [pid 123784:tid 123935] [client 158.23.17.4:60754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ud.php"] [unique_id "aoSB7WwDnJBNj2tDbYYKzwAAABE"]
[Tue Aug 18 13:01:49.215839 2026] [security2:error] [pid 139043:tid 139268] [client 172.213.243.2:34411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/bsg-management/php.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVlQAAAOQ"]
[Tue Aug 18 13:01:49.221586 2026] [security2:error] [pid 139043:tid 139300] [client 20.29.77.16:16540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/info2.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVlgAAAQQ"]
[Tue Aug 18 13:01:49.224703 2026] [security2:error] [pid 139043:tid 139195] [client 138.185.145.78:41048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVlwAAAJs"]
[Tue Aug 18 13:01:49.224783 2026] [security2:error] [pid 139043:tid 139195] [client 138.185.145.78:41048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVlwAAAJs"]
[Tue Aug 18 13:01:49.236915 2026] [security2:error] [pid 139043:tid 139283] [client 68.221.73.131:13339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/gi.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVmAAAAPM"]
[Tue Aug 18 13:01:49.246054 2026] [security2:error] [pid 139043:tid 139232] [client 158.158.74.177:9249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/languages.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVmgAAAMA"]
[Tue Aug 18 13:01:49.251421 2026] [security2:error] [pid 139043:tid 139281] [client 20.75.92.165:4337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/lite.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVmwAAAPE"]
[Tue Aug 18 13:01:49.280203 2026] [security2:error] [pid 123784:tid 123967] [client 20.104.100.201:49469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/dk.php"] [unique_id "aoSB7WwDnJBNj2tDbYYK0gAAADE"]
[Tue Aug 18 13:01:49.295683 2026] [security2:error] [pid 123784:tid 123818] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/34.php"] [unique_id "aoSB7WwDnJBNj2tDbYYK0wAAXh0"]
[Tue Aug 18 13:01:49.303641 2026] [security2:error] [pid 139043:tid 139262] [client 20.226.112.14:34210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/un.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVnAAAAN4"]
[Tue Aug 18 13:01:49.311833 2026] [authz_core:error] [pid 123784:tid 123903] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:49.312198 2026] [authz_core:error] [pid 123784:tid 123903] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:49.324090 2026] [security2:error] [pid 139043:tid 139257] [client 138.185.145.78:41104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/old/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVngAAANk"]
[Tue Aug 18 13:01:49.324182 2026] [security2:error] [pid 139043:tid 139257] [client 138.185.145.78:41104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/old/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVngAAANk"]
[Tue Aug 18 13:01:49.329277 2026] [security2:error] [pid 139043:tid 139208] [client 52.139.47.57:12637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/z.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVnwAAAKg"]
[Tue Aug 18 13:01:49.354973 2026] [security2:error] [pid 139043:tid 139230] [client 20.51.153.15:13590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/evil.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVoAAAAL4"]
[Tue Aug 18 13:01:49.380667 2026] [security2:error] [pid 139043:tid 139266] [client 20.119.58.187:10460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/media.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVowAAAOI"]
[Tue Aug 18 13:01:49.401935 2026] [security2:error] [pid 123784:tid 123945] [client 20.48.236.86:14827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/php.php"] [unique_id "aoSB7WwDnJBNj2tDbYYK1wAAABs"]
[Tue Aug 18 13:01:49.448792 2026] [security2:error] [pid 139043:tid 139242] [client 20.151.109.219:14277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/gg.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVpQAAAMo"]
[Tue Aug 18 13:01:49.451204 2026] [security2:error] [pid 139043:tid 139190] [client 20.226.112.14:22890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/autogooey.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVpgAAAJY"]
[Tue Aug 18 13:01:49.468667 2026] [security2:error] [pid 139043:tid 139259] [client 20.251.112.238:7112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ws60.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVpwAAANs"]
[Tue Aug 18 13:01:49.470367 2026] [security2:error] [pid 123784:tid 123854] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/he.php"] [unique_id "aoSB7WwDnJBNj2tDbYYK2QAAY0E"]
[Tue Aug 18 13:01:49.509973 2026] [security2:error] [pid 139043:tid 139198] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVqQAAAJ4"]
[Tue Aug 18 13:01:49.559403 2026] [security2:error] [pid 139043:tid 139223] [client 20.104.100.201:49139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/bal.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVqgAAALc"]
[Tue Aug 18 13:01:49.572584 2026] [security2:error] [pid 139043:tid 139250] [client 20.91.215.254:11460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/alfa-rex1.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVqwAAANI"]
[Tue Aug 18 13:01:49.573450 2026] [security2:error] [pid 139043:tid 139194] [client 20.79.204.6:11557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVrAAAAJo"]
[Tue Aug 18 13:01:49.577686 2026] [security2:error] [pid 139043:tid 139246] [client 20.250.13.23:59906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVrQAAAM4"]
[Tue Aug 18 13:01:49.614424 2026] [authz_core:error] [pid 123784:tid 123869] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:49.614674 2026] [authz_core:error] [pid 123784:tid 123869] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:49.620659 2026] [security2:error] [pid 139043:tid 139235] [client 20.75.92.165:4321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/lock360.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVrwAAAMM"]
[Tue Aug 18 13:01:49.628371 2026] [security2:error] [pid 139043:tid 139233] [client 172.213.243.2:14569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/byp8.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVsAAAAME"]
[Tue Aug 18 13:01:49.666701 2026] [security2:error] [pid 139043:tid 139291] [client 20.163.43.14:8899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wso.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVswAAAPs"]
[Tue Aug 18 13:01:49.680646 2026] [security2:error] [pid 139043:tid 139182] [client 20.51.153.15:13653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/wp-key.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVtAAAAI4"]
[Tue Aug 18 13:01:49.704794 2026] [security2:error] [pid 123784:tid 123931] [client 20.79.204.6:12230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/admin.php"] [unique_id "aoSB7WwDnJBNj2tDbYYK3wAAAA0"]
[Tue Aug 18 13:01:49.707361 2026] [security2:error] [pid 123784:tid 123802] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/gz.php"] [unique_id "aoSB7WwDnJBNj2tDbYYK4AAAIw0"]
[Tue Aug 18 13:01:49.712909 2026] [security2:error] [pid 139043:tid 139179] [client 20.79.204.6:10707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVvwAAAIs"]
[Tue Aug 18 13:01:49.714656 2026] [security2:error] [pid 139043:tid 139212] [client 20.206.73.37:35304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/ws13.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVwAAAAKw"]
[Tue Aug 18 13:01:49.734774 2026] [security2:error] [pid 139043:tid 139263] [client 20.119.58.187:10113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/mar.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVwQAAAN8"]
[Tue Aug 18 13:01:49.738296 2026] [security2:error] [pid 139043:tid 139206] [client 20.151.109.219:39359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/gi.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVwgAAAKY"]
[Tue Aug 18 13:01:49.752367 2026] [security2:error] [pid 139043:tid 139231] [client 52.139.47.57:36817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/ee.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVwwAAAL8"]
[Tue Aug 18 13:01:49.758632 2026] [security2:error] [pid 139043:tid 139225] [client 138.185.145.78:41354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/wp-login.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVxAAAALk"]
[Tue Aug 18 13:01:49.793190 2026] [security2:error] [pid 139043:tid 139288] [client 158.23.17.4:6371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/hp.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVxQAAAPg"]
[Tue Aug 18 13:01:49.800926 2026] [security2:error] [pid 139043:tid 139269] [client 20.226.112.14:28786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/sty.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVxgAAAOU"]
[Tue Aug 18 13:01:49.801752 2026] [security2:error] [pid 139043:tid 139213] [client 172.202.39.151:44116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/an.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVxwAAAK0"]
[Tue Aug 18 13:01:49.814754 2026] [security2:error] [pid 139043:tid 139177] [client 20.48.236.86:14467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/sf.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVyAAAAIk"]
[Tue Aug 18 13:01:49.839187 2026] [security2:error] [pid 139043:tid 139289] [client 20.104.100.201:49461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/yawa.php"] [unique_id "aoSB7f2v-lWn9OzQT7UV5wAAAPk"]
[Tue Aug 18 13:01:49.842575 2026] [security2:error] [pid 123784:tid 124040] [client 20.116.17.175:22929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSB7WwDnJBNj2tDbYYK4gAAAHo"]
[Tue Aug 18 13:01:49.857756 2026] [security2:error] [pid 139043:tid 139278] [client 213.35.127.232:59992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSB7f2v-lWn9OzQT7UV6AAAAO4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:49.876051 2026] [security2:error] [pid 123784:tid 123906] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/nf.php"] [unique_id "aoSB7WwDnJBNj2tDbYYK5AAAN3U"]
[Tue Aug 18 13:01:49.908075 2026] [security2:error] [pid 139043:tid 139298] [client 20.29.77.16:33563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/test_info.php"] [unique_id "aoSB7f2v-lWn9OzQT7UV6gAAAQI"]
[Tue Aug 18 13:01:49.909036 2026] [security2:error] [pid 139043:tid 139297] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/akc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UV6wAAAQE"]
[Tue Aug 18 13:01:49.913716 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:49.913994 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:49.945580 2026] [security2:error] [pid 139043:tid 139295] [client 20.51.153.15:13676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/phpcheck.php"] [unique_id "aoSB7f2v-lWn9OzQT7UV7QAAAP8"]
[Tue Aug 18 13:01:49.959256 2026] [security2:error] [pid 139043:tid 139201] [client 68.221.73.131:21888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/video.php"] [unique_id "aoSB7f2v-lWn9OzQT7UV7wAAAKE"]
[Tue Aug 18 13:01:49.994211 2026] [security2:error] [pid 139043:tid 139300] [client 20.163.43.14:8862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/sf.php"] [unique_id "aoSB7f2v-lWn9OzQT7UV8QAAAQQ"]
[Tue Aug 18 13:01:50.032412 2026] [security2:error] [pid 123784:tid 124001] [client 20.151.109.219:39311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/pz.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK7QAAAFM"]
[Tue Aug 18 13:01:50.036434 2026] [security2:error] [pid 123784:tid 124041] [client 172.213.243.2:16848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/plugins.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK7gAAAHs"]
[Tue Aug 18 13:01:50.084103 2026] [security2:error] [pid 123784:tid 124037] [client 135.225.78.186:58109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/puc.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK7wAAAHc"]
[Tue Aug 18 13:01:50.085011 2026] [security2:error] [pid 139043:tid 139187] [client 20.75.92.165:4315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSB7v2v-lWn9OzQT7UV9AAAAJM"]
[Tue Aug 18 13:01:50.086431 2026] [security2:error] [pid 139043:tid 139191] [client 20.119.58.187:10550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/my1.php"] [unique_id "aoSB7v2v-lWn9OzQT7UV9QAAAJc"]
[Tue Aug 18 13:01:50.089029 2026] [security2:error] [pid 123784:tid 123890] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/xv.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK8AAAOGU"]
[Tue Aug 18 13:01:50.101450 2026] [security2:error] [pid 139043:tid 139257] [client 66.249.77.96:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "buscacep.linkasites.com.br"] [uri "/robots.txt"] [unique_id "aoSB7v2v-lWn9OzQT7UV9wAAANk"]
[Tue Aug 18 13:01:50.115147 2026] [security2:error] [pid 139043:tid 139208] [client 20.104.100.201:49431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSB7v2v-lWn9OzQT7UV-AAAAKg"]
[Tue Aug 18 13:01:50.117284 2026] [security2:error] [pid 139043:tid 139218] [client 158.158.74.177:22899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/nw.php"] [unique_id "aoSB7v2v-lWn9OzQT7UV-QAAALI"]
[Tue Aug 18 13:01:50.122466 2026] [security2:error] [pid 139043:tid 139247] [client 20.203.183.135:13034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/media.php"] [unique_id "aoSB7v2v-lWn9OzQT7UV-gAAAM8"]
[Tue Aug 18 13:01:50.157051 2026] [security2:error] [pid 139043:tid 139205] [client 20.251.112.238:26163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/olfclass.php"] [unique_id "aoSB7v2v-lWn9OzQT7UV_AAAAKU"]
[Tue Aug 18 13:01:50.164688 2026] [security2:error] [pid 139043:tid 139184] [client 158.23.17.4:15155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ip.php"] [unique_id "aoSB7v2v-lWn9OzQT7UV_gAAAJA"]
[Tue Aug 18 13:01:50.171291 2026] [security2:error] [pid 123784:tid 123925] [client 66.249.77.96:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "buscacep.linkasites.com.br"] [uri "/livrocep/ms/campo-grande/santa-fe/img/rua-abrao-julio-rahe-de-2116-2117-ao-fim-santa-fe-campo-grande-ms.webp"] [unique_id "aoSB7mwDnJBNj2tDbYYK8gAAAAc"]
[Tue Aug 18 13:01:50.180103 2026] [security2:error] [pid 139043:tid 139268] [client 20.79.204.6:11554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSB7v2v-lWn9OzQT7UV_wAAAOQ"]
[Tue Aug 18 13:01:50.197998 2026] [security2:error] [pid 123784:tid 123969] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/buy.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK8wAAADM"]
[Tue Aug 18 13:01:50.210044 2026] [security2:error] [pid 139043:tid 139281] [client 52.139.47.57:3843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/we.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWAAAAAPE"]
[Tue Aug 18 13:01:50.214706 2026] [security2:error] [pid 139043:tid 139248] [client 20.226.112.14:13675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wio.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWAQAAANA"]
[Tue Aug 18 13:01:50.215894 2026] [security2:error] [pid 139043:tid 139283] [client 20.250.13.23:6473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/maint.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWAgAAAPM"]
[Tue Aug 18 13:01:50.255211 2026] [security2:error] [pid 139043:tid 139299] [client 20.51.153.15:13641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/mimes.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWAwAAAQM"]
[Tue Aug 18 13:01:50.259643 2026] [security2:error] [pid 123784:tid 123824] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/mx.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK9QAAZiM"]
[Tue Aug 18 13:01:50.290252 2026] [security2:error] [pid 123784:tid 124014] [client 20.65.98.162:21892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/xx.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK9gAAAGA"]
[Tue Aug 18 13:01:50.295741 2026] [security2:error] [pid 139043:tid 139190] [client 20.48.236.86:14786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/xx.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWEgAAAJY"]
[Tue Aug 18 13:01:50.310383 2026] [security2:error] [pid 139043:tid 139219] [client 20.79.204.6:11699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/content.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWFQAAALM"]
[Tue Aug 18 13:01:50.322579 2026] [security2:error] [pid 139043:tid 139211] [client 20.91.215.254:19442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWFwAAAKs"]
[Tue Aug 18 13:01:50.333091 2026] [security2:error] [pid 139043:tid 139294] [client 102.213.179.104:51529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWGAAAAP4"]
[Tue Aug 18 13:01:50.333234 2026] [security2:error] [pid 139043:tid 139294] [client 102.213.179.104:51529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWGAAAAP4"]
[Tue Aug 18 13:01:50.361947 2026] [security2:error] [pid 139043:tid 139183] [client 20.226.112.14:32557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/1061.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWGQAAAI8"]
[Tue Aug 18 13:01:50.373959 2026] [security2:error] [pid 139043:tid 139198] [client 20.151.109.219:39301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/kk.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWGgAAAJ4"]
[Tue Aug 18 13:01:50.380448 2026] [security2:error] [pid 139043:tid 139272] [client 20.163.43.14:8956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/index/function.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWGwAAAOg"]
[Tue Aug 18 13:01:50.389334 2026] [security2:error] [pid 139043:tid 139128] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWHAAA91Q"]
[Tue Aug 18 13:01:50.389490 2026] [security2:error] [pid 139043:tid 139287] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWHAAA91Q"]
[Tue Aug 18 13:01:50.391640 2026] [security2:error] [pid 139043:tid 139223] [client 20.104.100.201:49664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/7.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWHQAAALc"]
[Tue Aug 18 13:01:50.439533 2026] [security2:error] [pid 123784:tid 123921] [client 20.119.58.187:10163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/mm.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK-gAAAAM"]
[Tue Aug 18 13:01:50.448382 2026] [security2:error] [pid 139043:tid 139270] [client 172.213.243.2:14342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/100.kb.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWJQAAAOY"]
[Tue Aug 18 13:01:50.482599 2026] [security2:error] [pid 123784:tid 123929] [client 20.116.17.175:22926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK-wAAAAs"]
[Tue Aug 18 13:01:50.511478 2026] [security2:error] [pid 139043:tid 139221] [client 20.51.153.15:13586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWKQAAALU"]
[Tue Aug 18 13:01:50.579534 2026] [security2:error] [pid 139043:tid 139225] [client 172.202.39.151:40351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWLgAAALk"]
[Tue Aug 18 13:01:50.592075 2026] [security2:error] [pid 139043:tid 139175] [client 20.226.112.14:22961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/gec.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWMwAAAIc"]
[Tue Aug 18 13:01:50.599367 2026] [security2:error] [pid 139043:tid 139186] [client 20.29.77.16:16530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/xynz1.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWNAAAAJI"]
[Tue Aug 18 13:01:50.658031 2026] [security2:error] [pid 123784:tid 123997] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/cong.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK_wAAAE8"]
[Tue Aug 18 13:01:50.669703 2026] [security2:error] [pid 139043:tid 139254] [client 20.104.100.201:49097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/ws77.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWNgAAANY"]
[Tue Aug 18 13:01:50.712278 2026] [security2:error] [pid 139043:tid 139274] [client 20.163.43.14:8878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/edit.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWOAAAAOo"]
[Tue Aug 18 13:01:50.713416 2026] [security2:error] [pid 139043:tid 139200] [client 52.139.47.57:17286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/to.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWOQAAAKA"]
[Tue Aug 18 13:01:50.741004 2026] [security2:error] [pid 139043:tid 139220] [client 78.47.98.55:61510] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dadicamotors.com.br"] [uri "/index.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWOgAAALQ"], referer: https://dadicamotors.com.br/
[Tue Aug 18 13:01:50.767575 2026] [security2:error] [pid 123784:tid 123978] [client 20.51.153.15:13649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/pqr.php"] [unique_id "aoSB7mwDnJBNj2tDbYYLBgAAADw"]
[Tue Aug 18 13:01:50.790850 2026] [security2:error] [pid 123784:tid 123959] [client 20.119.58.187:10470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/network.php"] [unique_id "aoSB7mwDnJBNj2tDbYYLCQAAACk"]
[Tue Aug 18 13:01:50.792398 2026] [security2:error] [pid 123784:tid 124025] [client 66.187.6.102:55102] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/site/js/splitting.js"] [unique_id "aoSB7mwDnJBNj2tDbYYLCwAAAGs"]
[Tue Aug 18 13:01:50.809783 2026] [security2:error] [pid 123784:tid 123955] [client 158.158.74.177:10130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSB7mwDnJBNj2tDbYYLDQAAACU"]
[Tue Aug 18 13:01:50.809886 2026] [security2:error] [pid 139043:tid 139255] [client 20.75.92.165:2002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWQQAAANc"]
[Tue Aug 18 13:01:50.810031 2026] [security2:error] [pid 139043:tid 139295] [client 20.127.136.245:18424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/xmr.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWQgAAAP8"]
[Tue Aug 18 13:01:50.814073 2026] [security2:error] [pid 123784:tid 123939] [client 66.187.6.102:55024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/content/categories/thumbs/a9781358edccedce831bca15a7f77824.svg"] [unique_id "aoSB7mwDnJBNj2tDbYYLDwAAABU"]
[Tue Aug 18 13:01:50.814182 2026] [security2:error] [pid 123784:tid 123939] [client 66.187.6.102:55024] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/content/categories/thumbs/a9781358edccedce831bca15a7f77824.svg"] [unique_id "aoSB7mwDnJBNj2tDbYYLDwAAABU"]
[Tue Aug 18 13:01:50.817710 2026] [security2:error] [pid 123784:tid 123980] [client 66.187.6.102:55010] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/produtos/plasticos"] [unique_id "aoSB7mwDnJBNj2tDbYYLEgAAAD4"]
[Tue Aug 18 13:01:50.818840 2026] [security2:error] [pid 123784:tid 123927] [client 66.187.6.102:55064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/content/display/6351ef1a0d96cf5bfb60bda2109f0bdc.png"] [unique_id "aoSB7mwDnJBNj2tDbYYLFgAAAAk"]
[Tue Aug 18 13:01:50.818955 2026] [security2:error] [pid 123784:tid 123927] [client 66.187.6.102:55064] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/content/display/6351ef1a0d96cf5bfb60bda2109f0bdc.png"] [unique_id "aoSB7mwDnJBNj2tDbYYLFgAAAAk"]
[Tue Aug 18 13:01:50.819765 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:50.820070 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:50.826982 2026] [security2:error] [pid 139043:tid 139201] [client 158.23.17.4:44840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/wx.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWSAAAAKE"]
[Tue Aug 18 13:01:50.835934 2026] [security2:error] [pid 139043:tid 139252] [client 20.48.236.86:14795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/uwu.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWSQAAANQ"]
[Tue Aug 18 13:01:50.836068 2026] [security2:error] [pid 123784:tid 123898] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/45.php"] [unique_id "aoSB7mwDnJBNj2tDbYYLGQAAEm0"]
[Tue Aug 18 13:01:50.841523 2026] [security2:error] [pid 139043:tid 139285] [client 20.203.183.135:20626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/admin.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWSgAAAPU"]
[Tue Aug 18 13:01:50.851449 2026] [security2:error] [pid 139043:tid 139232] [client 216.244.66.232:51626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWSwAAAMA"]
[Tue Aug 18 13:01:50.851576 2026] [security2:error] [pid 139043:tid 139232] [client 216.244.66.232:51626] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWSwAAAMA"]
[Tue Aug 18 13:01:50.854852 2026] [security2:error] [pid 139043:tid 139293] [client 66.187.6.102:55144] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/site/js/scrolltrigger.js"] [unique_id "aoSB7v2v-lWn9OzQT7UWTAAAAP0"]
[Tue Aug 18 13:01:50.859324 2026] [security2:error] [pid 123784:tid 123970] [client 20.250.13.23:6468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/phpMailer.php"] [unique_id "aoSB7mwDnJBNj2tDbYYLHQAAADQ"]
[Tue Aug 18 13:01:50.862872 2026] [security2:error] [pid 139043:tid 139251] [client 66.187.6.102:55124] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/produtos/limpeza"] [unique_id "aoSB7v2v-lWn9OzQT7UWTwAAANM"]
[Tue Aug 18 13:01:50.870675 2026] [security2:error] [pid 139043:tid 139182] [client 213.35.127.232:60200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWUAAAAI4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:50.878061 2026] [security2:error] [pid 139043:tid 139187] [client 172.213.243.2:36107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/mamzi.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWUQAAAJM"]
[Tue Aug 18 13:01:50.885320 2026] [security2:error] [pid 139043:tid 139191] [client 20.251.112.238:18228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wpver.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWUgAAAJc"]
[Tue Aug 18 13:01:50.941751 2026] [security2:error] [pid 139043:tid 139247] [client 20.104.100.201:49133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/read.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWUwAAAM8"]
[Tue Aug 18 13:01:50.970839 2026] [security2:error] [pid 123784:tid 123988] [client 20.116.17.175:53821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/1xmomo.php"] [unique_id "aoSB7mwDnJBNj2tDbYYLIAAAAEY"]
[Tue Aug 18 13:01:51.011869 2026] [security2:error] [pid 139043:tid 139245] [client 158.23.17.4:15109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/99.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWVQAAAM0"]
[Tue Aug 18 13:01:51.017495 2026] [security2:error] [pid 139043:tid 139248] [client 20.51.153.15:13599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/lmfi2.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWVgAAANA"]
[Tue Aug 18 13:01:51.035220 2026] [security2:error] [pid 139043:tid 139290] [client 20.91.215.254:19425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/xmrlpc.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWVwAAAPo"]
[Tue Aug 18 13:01:51.036074 2026] [security2:error] [pid 139043:tid 139176] [client 20.226.112.14:22968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/scx.php7"] [unique_id "aoSB7_2v-lWn9OzQT7UWWAAAAIg"]
[Tue Aug 18 13:01:51.079700 2026] [security2:error] [pid 123784:tid 123836] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/wy.php"] [unique_id "aoSB72wDnJBNj2tDbYYLIwAAXS8"]
[Tue Aug 18 13:01:51.101428 2026] [security2:error] [pid 139043:tid 139294] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWXAAAAP4"]
[Tue Aug 18 13:01:51.110653 2026] [security2:error] [pid 139043:tid 139189] [client 20.151.109.219:63964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/phpcheck.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWZQAAAJU"]
[Tue Aug 18 13:01:51.110916 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.112.14:22949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-admin/sc.php"] [unique_id "aoSB72wDnJBNj2tDbYYLJgAAAFI"]
[Tue Aug 18 13:01:51.115999 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:51.116256 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:51.136879 2026] [security2:error] [pid 123784:tid 123958] [client 20.48.236.86:14807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/signon.php"] [unique_id "aoSB72wDnJBNj2tDbYYLKAAAACg"]
[Tue Aug 18 13:01:51.138329 2026] [security2:error] [pid 123784:tid 123983] [client 20.226.112.14:39431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp5.php"] [unique_id "aoSB72wDnJBNj2tDbYYLKQAAAEE"]
[Tue Aug 18 13:01:51.145121 2026] [security2:error] [pid 123784:tid 123942] [client 20.119.58.187:10450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/new.php"] [unique_id "aoSB72wDnJBNj2tDbYYLKgAAABg"]
[Tue Aug 18 13:01:51.152422 2026] [security2:error] [pid 139043:tid 139183] [client 20.29.77.16:62863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/album.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWegAAAI8"]
[Tue Aug 18 13:01:51.173337 2026] [security2:error] [pid 123784:tid 124007] [client 172.202.39.151:4677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/tes.php"] [unique_id "aoSB72wDnJBNj2tDbYYLKwAAAFk"]
[Tue Aug 18 13:01:51.179983 2026] [security2:error] [pid 139043:tid 139229] [client 52.139.47.57:3819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/ty.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWfAAAAL0"]
[Tue Aug 18 13:01:51.213028 2026] [security2:error] [pid 139043:tid 139202] [client 20.104.100.201:49468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/albin.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWfQAAAKI"]
[Tue Aug 18 13:01:51.216549 2026] [security2:error] [pid 139043:tid 139185] [client 20.163.43.14:8838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWfgAAAJE"]
[Tue Aug 18 13:01:51.251960 2026] [security2:error] [pid 139043:tid 139246] [client 20.226.112.14:32520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/a2.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWgAAAAM4"]
[Tue Aug 18 13:01:51.252328 2026] [security2:error] [pid 139043:tid 139209] [client 20.51.153.15:13645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/info2.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWgQAAAKk"]
[Tue Aug 18 13:01:51.293909 2026] [security2:error] [pid 139043:tid 139241] [client 20.79.204.6:11657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/index.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWkAAAAMk"]
[Tue Aug 18 13:01:51.295704 2026] [security2:error] [pid 139043:tid 139265] [client 86.120.159.145:14589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWkQAAAOE"]
[Tue Aug 18 13:01:51.296085 2026] [security2:error] [pid 139043:tid 139265] [client 86.120.159.145:14589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWkQAAAOE"]
[Tue Aug 18 13:01:51.296630 2026] [security2:error] [pid 139043:tid 139296] [client 172.213.243.2:19534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ms.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWkgAAAQA"]
[Tue Aug 18 13:01:51.308363 2026] [security2:error] [pid 139043:tid 139192] [client 20.79.204.6:11859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWkwAAAJg"]
[Tue Aug 18 13:01:51.340731 2026] [security2:error] [pid 123784:tid 123967] [client 20.226.112.14:39956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/app.php"] [unique_id "aoSB72wDnJBNj2tDbYYLLgAAADE"]
[Tue Aug 18 13:01:51.418279 2026] [authz_core:error] [pid 123784:tid 123791] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:51.418559 2026] [authz_core:error] [pid 123784:tid 123791] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:51.429752 2026] [security2:error] [pid 123784:tid 123945] [client 66.187.6.102:54974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/content/display/1d40fb9ad67c3ac6459bc693cadb7c0c.png"] [unique_id "aoSB72wDnJBNj2tDbYYLMgAAABs"]
[Tue Aug 18 13:01:51.429889 2026] [security2:error] [pid 123784:tid 123945] [client 66.187.6.102:54974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/content/display/1d40fb9ad67c3ac6459bc693cadb7c0c.png"] [unique_id "aoSB72wDnJBNj2tDbYYLMgAAABs"]
[Tue Aug 18 13:01:51.447476 2026] [security2:error] [pid 139043:tid 139236] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/db.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWmAAAAMQ"]
[Tue Aug 18 13:01:51.461710 2026] [security2:error] [pid 139043:tid 139199] [client 20.79.204.6:10719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/h.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWnwAAAJ8"]
[Tue Aug 18 13:01:51.466334 2026] [security2:error] [pid 139043:tid 139274] [client 20.75.92.165:2035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/.alf.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWoAAAAOo"]
[Tue Aug 18 13:01:51.469189 2026] [autoindex:error] [pid 139043:tid 139238] [client 158.158.74.177:25544] AH01276: Cannot serve directory /home2/guscarautomoveis/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:51.472970 2026] [security2:error] [pid 123784:tid 124032] [client 20.151.109.219:60905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/dg.php"] [unique_id "aoSB72wDnJBNj2tDbYYLPQAAAHI"]
[Tue Aug 18 13:01:51.485228 2026] [security2:error] [pid 139043:tid 139174] [client 158.23.17.4:57028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/er.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWowAAAIY"]
[Tue Aug 18 13:01:51.486025 2026] [security2:error] [pid 139043:tid 139220] [client 20.104.100.201:49666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/fw/34.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWpAAAALQ"]
[Tue Aug 18 13:01:51.488637 2026] [security2:error] [pid 139043:tid 139288] [client 20.51.153.15:13657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/test_info.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWpQAAAPg"]
[Tue Aug 18 13:01:51.491421 2026] [security2:error] [pid 139043:tid 139197] [client 20.250.13.23:6526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWpgAAAJ0"]
[Tue Aug 18 13:01:51.497864 2026] [security2:error] [pid 139043:tid 139225] [client 20.119.58.187:10143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/0x.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWpwAAALk"]
[Tue Aug 18 13:01:51.511294 2026] [security2:error] [pid 139043:tid 139276] [client 20.116.17.175:22928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWqAAAAOw"]
[Tue Aug 18 13:01:51.581752 2026] [security2:error] [pid 139043:tid 139213] [client 20.48.236.86:14818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/file61.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWrAAAAK0"]
[Tue Aug 18 13:01:51.602527 2026] [security2:error] [pid 139043:tid 139252] [client 20.163.43.14:8768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-good.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWrQAAANQ"]
[Tue Aug 18 13:01:51.610281 2026] [security2:error] [pid 139043:tid 139195] [client 20.226.112.14:28773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-content/admin.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWrgAAAJs"]
[Tue Aug 18 13:01:51.610395 2026] [security2:error] [pid 123784:tid 123790] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/f.php"] [unique_id "aoSB72wDnJBNj2tDbYYLQAAANwE"]
[Tue Aug 18 13:01:51.620291 2026] [security2:error] [pid 123784:tid 123930] [client 52.139.47.57:60545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/ak.php"] [unique_id "aoSB72wDnJBNj2tDbYYLQQAAAAw"]
[Tue Aug 18 13:01:51.649916 2026] [security2:error] [pid 139043:tid 139216] [client 68.221.73.131:64662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/hel.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWsgAAALA"]
[Tue Aug 18 13:01:51.674933 2026] [security2:error] [pid 139043:tid 139247] [client 158.158.74.177:25544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWswAAAM8"]
[Tue Aug 18 13:01:51.692407 2026] [security2:error] [pid 139043:tid 139237] [client 20.29.77.16:61115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/creds.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWtAAAAMU"]
[Tue Aug 18 13:01:51.712707 2026] [security2:error] [pid 123784:tid 124005] [client 20.91.215.254:19449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/user/12.php"] [unique_id "aoSB72wDnJBNj2tDbYYLSAAAAFc"]
[Tue Aug 18 13:01:51.718216 2026] [security2:error] [pid 123784:tid 124042] [client 172.213.243.2:45921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/gfile.php"] [unique_id "aoSB72wDnJBNj2tDbYYLSQAAAHw"]
[Tue Aug 18 13:01:51.744031 2026] [security2:error] [pid 123784:tid 123996] [client 20.51.153.15:13585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/xynz1.php"] [unique_id "aoSB72wDnJBNj2tDbYYLTwAAAE4"]
[Tue Aug 18 13:01:51.759294 2026] [security2:error] [pid 139043:tid 139279] [client 20.104.100.201:49441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp9.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWuQAAAO8"]
[Tue Aug 18 13:01:51.769874 2026] [security2:error] [pid 139043:tid 139190] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/dropdown.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWugAAAJY"]
[Tue Aug 18 13:01:51.796704 2026] [security2:error] [pid 139043:tid 139280] [client 20.226.112.14:22912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/cxc.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWuwAAAPA"]
[Tue Aug 18 13:01:51.807256 2026] [security2:error] [pid 139043:tid 139294] [client 66.187.6.102:54952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/pt/produtos"] [unique_id "aoSB7_2v-lWn9OzQT7UWvAAAAP4"]
[Tue Aug 18 13:01:51.807363 2026] [security2:error] [pid 139043:tid 139294] [client 66.187.6.102:54952] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/pt/produtos"] [unique_id "aoSB7_2v-lWn9OzQT7UWvAAAAP4"]
[Tue Aug 18 13:01:51.841617 2026] [security2:error] [pid 139043:tid 139215] [client 20.151.109.219:60362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/bm.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWvQAAAK8"]
[Tue Aug 18 13:01:51.848765 2026] [security2:error] [pid 139043:tid 139180] [client 52.173.121.69:15003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWvwAAAIw"]
[Tue Aug 18 13:01:51.851536 2026] [security2:error] [pid 139043:tid 139290] [client 20.119.58.187:10534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/0.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWwAAAAPo"]
[Tue Aug 18 13:01:51.890952 2026] [security2:error] [pid 139043:tid 139295] [client 213.35.127.232:60389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWwQAAAP8"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:51.896697 2026] [security2:error] [pid 123784:tid 123921] [client 20.75.92.165:4277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/.trash7206/index.php"] [unique_id "aoSB72wDnJBNj2tDbYYLVAAAAAM"]
[Tue Aug 18 13:01:51.909534 2026] [security2:error] [pid 139043:tid 139188] [client 20.79.204.6:11583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSB7_2v-lWn9OzQT7UWwgAAAJQ"]
[Tue Aug 18 13:01:51.910353 2026] [security2:error] [pid 139043:tid 139249] [client 20.79.204.6:11581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSB7_2v-lWn9OzQT7UWwwAAANE"]
[Tue Aug 18 13:01:51.922641 2026] [security2:error] [pid 123784:tid 123997] [client 20.116.17.175:22942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/term.php"] [unique_id "aoSB72wDnJBNj2tDbYYLVQAAAE8"]
[Tue Aug 18 13:01:51.952089 2026] [security2:error] [pid 139043:tid 139287] [client 158.23.17.4:54743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/qk.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWxQAAAPc"]
[Tue Aug 18 13:01:51.952122 2026] [security2:error] [pid 139043:tid 139260] [client 172.202.39.151:40335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWxAAAANw"]
[Tue Aug 18 13:01:52.000048 2026] [security2:error] [pid 139043:tid 139244] [client 20.206.96.72:15232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/inputs.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWxgAAAMw"]
[Tue Aug 18 13:01:52.019362 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:52.019617 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:52.031770 2026] [security2:error] [pid 139043:tid 139192] [client 20.104.100.201:49703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/save.php"] [unique_id "aoSB8P2v-lWn9OzQT7UWygAAAJg"]
[Tue Aug 18 13:01:52.032415 2026] [security2:error] [pid 139043:tid 139258] [client 20.206.96.72:15461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/admin.php"] [unique_id "aoSB8P2v-lWn9OzQT7UWywAAANo"]
[Tue Aug 18 13:01:52.051327 2026] [security2:error] [pid 123784:tid 123965] [client 20.51.153.15:13611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/album.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLWwAAAC8"]
[Tue Aug 18 13:01:52.057191 2026] [security2:error] [pid 139043:tid 139291] [client 20.206.96.72:15465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/goods.php"] [unique_id "aoSB8P2v-lWn9OzQT7UWzQAAAPs"]
[Tue Aug 18 13:01:52.073970 2026] [security2:error] [pid 139043:tid 139226] [client 20.251.112.238:33969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/thui.php"] [unique_id "aoSB8P2v-lWn9OzQT7UWzwAAALo"]
[Tue Aug 18 13:01:52.109673 2026] [security2:error] [pid 139043:tid 139231] [client 20.226.112.14:28563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/alfa-rex.php7"] [unique_id "aoSB8P2v-lWn9OzQT7UW0AAAAL8"]
[Tue Aug 18 13:01:52.110246 2026] [security2:error] [pid 123784:tid 123952] [client 52.139.47.57:18310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/fm.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLXAAAACI"]
[Tue Aug 18 13:01:52.113490 2026] [security2:error] [pid 139043:tid 139175] [client 20.48.236.86:14517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/copypaths.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW0QAAAIc"]
[Tue Aug 18 13:01:52.120893 2026] [security2:error] [pid 139043:tid 139178] [client 20.206.96.72:15459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/file.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW0wAAAIo"]
[Tue Aug 18 13:01:52.126550 2026] [security2:error] [pid 139043:tid 139212] [client 172.213.243.2:14358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/public/wp-blog.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW1QAAAKw"]
[Tue Aug 18 13:01:52.189905 2026] [security2:error] [pid 123784:tid 123936] [client 20.29.77.16:40563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/mandrill.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLYAAAABI"]
[Tue Aug 18 13:01:52.189905 2026] [security2:error] [pid 139043:tid 139220] [client 20.206.96.72:15278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/adminfuns.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW1gAAALQ"]
[Tue Aug 18 13:01:52.203411 2026] [security2:error] [pid 123784:tid 123941] [client 20.119.58.187:10519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/oxshell.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLYgAAABc"]
[Tue Aug 18 13:01:52.206433 2026] [security2:error] [pid 123784:tid 123905] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/30.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLYwAAHHQ"]
[Tue Aug 18 13:01:52.208334 2026] [security2:error] [pid 123784:tid 124018] [client 4.232.151.198:48049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLZAAAAGQ"]
[Tue Aug 18 13:01:52.218409 2026] [security2:error] [pid 123784:tid 123950] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/file.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLZQAAACA"]
[Tue Aug 18 13:01:52.243084 2026] [security2:error] [pid 123784:tid 123970] [client 20.206.96.72:15279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/404.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLZwAAADQ"]
[Tue Aug 18 13:01:52.255275 2026] [security2:error] [pid 123784:tid 124016] [client 20.151.109.219:39327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/vu.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLaAAAAGI"]
[Tue Aug 18 13:01:52.264196 2026] [security2:error] [pid 139043:tid 139265] [client 20.250.13.23:6508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/al.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW2AAAAOE"]
[Tue Aug 18 13:01:52.287839 2026] [security2:error] [pid 123784:tid 124031] [client 20.206.96.72:15282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wk/index.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLawAAAHE"]
[Tue Aug 18 13:01:52.298731 2026] [security2:error] [pid 123784:tid 123962] [client 20.163.43.14:8886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/tes.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLbAAAACw"]
[Tue Aug 18 13:01:52.302262 2026] [security2:error] [pid 139043:tid 139179] [client 158.158.74.177:22908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW2gAAAIs"]
[Tue Aug 18 13:01:52.306072 2026] [security2:error] [pid 139043:tid 139263] [client 20.104.100.201:49466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-rrtx.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW2wAAAN8"]
[Tue Aug 18 13:01:52.308539 2026] [security2:error] [pid 139043:tid 139276] [client 20.51.153.15:5082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/creds.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW3AAAAOw"]
[Tue Aug 18 13:01:52.321214 2026] [authz_core:error] [pid 123784:tid 123842] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:52.321527 2026] [authz_core:error] [pid 123784:tid 123842] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:52.355978 2026] [security2:error] [pid 139043:tid 139300] [client 20.203.183.135:12932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/mac.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW3gAAAQQ"]
[Tue Aug 18 13:01:52.393244 2026] [security2:error] [pid 139043:tid 139252] [client 158.23.17.4:58742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW3wAAANQ"]
[Tue Aug 18 13:01:52.404797 2026] [security2:error] [pid 139043:tid 139282] [client 20.206.96.72:15431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/about.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW4AAAAPI"]
[Tue Aug 18 13:01:52.415539 2026] [security2:error] [pid 139043:tid 139241] [client 20.79.204.6:10740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/ms-edit.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW4QAAAMk"]
[Tue Aug 18 13:01:52.448975 2026] [security2:error] [pid 123784:tid 123988] [client 20.75.92.165:1992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLdQAAAEY"]
[Tue Aug 18 13:01:52.464535 2026] [security2:error] [pid 139043:tid 139200] [client 20.206.96.72:15445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/term.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW4gAAAKA"]
[Tue Aug 18 13:01:52.492738 2026] [security2:error] [pid 139043:tid 139247] [client 20.206.96.72:15274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/ioxi-o.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW5QAAAM8"]
[Tue Aug 18 13:01:52.510778 2026] [security2:error] [pid 123784:tid 124011] [client 20.127.136.245:3546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/about.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLdwAAAF0"]
[Tue Aug 18 13:01:52.513512 2026] [security2:error] [pid 139043:tid 139264] [client 20.79.204.6:12258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW5gAAAOA"]
[Tue Aug 18 13:01:52.523685 2026] [security2:error] [pid 123784:tid 123977] [client 52.139.47.57:18363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/wp.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLeAAAADs"]
[Tue Aug 18 13:01:52.524179 2026] [security2:error] [pid 123784:tid 123949] [client 20.79.204.6:11848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLeQAAAB8"]
[Tue Aug 18 13:01:52.537090 2026] [security2:error] [pid 139043:tid 139248] [client 20.116.17.175:22931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/black.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW5wAAANA"]
[Tue Aug 18 13:01:52.538120 2026] [security2:error] [pid 139043:tid 139279] [client 172.213.243.2:19546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/cu.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW6AAAAO8"]
[Tue Aug 18 13:01:52.543569 2026] [security2:error] [pid 139043:tid 139299] [client 20.51.153.15:13607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/mandrill.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW6QAAAQM"]
[Tue Aug 18 13:01:52.566465 2026] [security2:error] [pid 139043:tid 139191] [client 20.119.58.187:10448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/php8.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW6gAAAJc"]
[Tue Aug 18 13:01:52.576955 2026] [security2:error] [pid 139043:tid 139259] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/goods.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW7AAAANs"]
[Tue Aug 18 13:01:52.584816 2026] [security2:error] [pid 139043:tid 139215] [client 20.91.215.254:11461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/ku.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW7QAAAK8"]
[Tue Aug 18 13:01:52.585733 2026] [security2:error] [pid 139043:tid 139180] [client 20.104.100.201:49442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/gecko-new.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW7gAAAIw"]
[Tue Aug 18 13:01:52.588558 2026] [security2:error] [pid 139043:tid 139290] [client 20.48.236.86:14537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/bless6.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW7wAAAPo"]
[Tue Aug 18 13:01:52.616521 2026] [security2:error] [pid 139043:tid 139262] [client 158.23.17.4:6340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/dj.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW8AAAAN4"]
[Tue Aug 18 13:01:52.618302 2026] [security2:error] [pid 139043:tid 139245] [client 20.206.96.72:15249] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/1.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW8QAAAM0"]
[Tue Aug 18 13:01:52.618402 2026] [security2:error] [pid 139043:tid 139245] [client 20.206.96.72:15249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/1.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW8QAAAM0"]
[Tue Aug 18 13:01:52.623007 2026] [authz_core:error] [pid 123784:tid 123896] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:52.623267 2026] [authz_core:error] [pid 123784:tid 123896] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:52.686316 2026] [security2:error] [pid 123784:tid 124030] [client 20.206.96.72:15427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/alfa.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLfQAAAHA"]
[Tue Aug 18 13:01:52.695229 2026] [security2:error] [pid 123784:tid 123983] [client 20.163.43.14:8844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/files/index.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLfgAAAEE"]
[Tue Aug 18 13:01:52.712062 2026] [security2:error] [pid 139043:tid 139223] [client 135.225.78.186:65346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/inso.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW8wAAALc"]
[Tue Aug 18 13:01:52.718345 2026] [security2:error] [pid 139043:tid 139260] [client 20.206.96.72:15436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/edit.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW9AAAANw"]
[Tue Aug 18 13:01:52.746861 2026] [security2:error] [pid 139043:tid 139283] [client 20.226.112.14:28777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/0.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW9gAAAPM"]
[Tue Aug 18 13:01:52.767419 2026] [security2:error] [pid 139043:tid 139219] [client 20.29.77.16:61067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/main.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW-AAAALM"]
[Tue Aug 18 13:01:52.796972 2026] [security2:error] [pid 139043:tid 139243] [client 20.206.96.72:15245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/elp.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW-gAAAMs"]
[Tue Aug 18 13:01:52.801684 2026] [security2:error] [pid 123784:tid 123859] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/pu.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLgAAAZ0Y"]
[Tue Aug 18 13:01:52.824064 2026] [security2:error] [pid 139043:tid 139186] [client 20.151.109.219:63978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ic.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW_QAAAJI"]
[Tue Aug 18 13:01:52.844037 2026] [security2:error] [pid 123784:tid 123935] [client 20.51.153.15:13650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/main.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLgQAAABE"]
[Tue Aug 18 13:01:52.850300 2026] [security2:error] [pid 139043:tid 139178] [client 20.75.92.165:2016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW_gAAAIo"]
[Tue Aug 18 13:01:52.860522 2026] [security2:error] [pid 123784:tid 123944] [client 20.104.100.201:49147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/df.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLggAAABo"]
[Tue Aug 18 13:01:52.861522 2026] [security2:error] [pid 139043:tid 139269] [client 20.206.96.72:15243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/classwithtostring.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW_wAAAOU"]
[Tue Aug 18 13:01:52.881136 2026] [security2:error] [pid 139043:tid 139067] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8P2v-lWn9OzQT7UXAAAAjRc"]
[Tue Aug 18 13:01:52.881312 2026] [security2:error] [pid 139043:tid 139181] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8P2v-lWn9OzQT7UXAAAAjRc"]
[Tue Aug 18 13:01:52.883995 2026] [security2:error] [pid 123784:tid 123958] [client 20.250.13.23:51241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLhAAAACg"]
[Tue Aug 18 13:01:52.900080 2026] [security2:error] [pid 139043:tid 139198] [client 4.232.94.69:19570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ewywe1dg.php"] [unique_id "aoSB8P2v-lWn9OzQT7UXAQAAAJ4"]
[Tue Aug 18 13:01:52.902866 2026] [security2:error] [pid 139043:tid 139190] [client 213.35.127.232:60582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSB8P2v-lWn9OzQT7UXAgAAAJY"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:52.913235 2026] [security2:error] [pid 123784:tid 123967] [client 20.206.96.72:15261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/666.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLhQAAADE"]
[Tue Aug 18 13:01:52.919331 2026] [security2:error] [pid 139043:tid 139256] [client 20.119.58.187:10148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/p.php"] [unique_id "aoSB8P2v-lWn9OzQT7UXBAAAANg"]
[Tue Aug 18 13:01:52.924332 2026] [authz_core:error] [pid 123784:tid 123797] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:52.924599 2026] [authz_core:error] [pid 123784:tid 123797] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:52.945186 2026] [security2:error] [pid 139043:tid 139197] [client 172.202.39.151:47693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/404.php"] [unique_id "aoSB8P2v-lWn9OzQT7UXBQAAAJ0"]
[Tue Aug 18 13:01:52.954840 2026] [security2:error] [pid 123784:tid 123982] [client 172.213.243.2:45938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/X57.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLhwAAAEA"]
[Tue Aug 18 13:01:52.959922 2026] [security2:error] [pid 123784:tid 124007] [client 52.139.47.57:12609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/33.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLiQAAAFk"]
[Tue Aug 18 13:01:52.963407 2026] [security2:error] [pid 139043:tid 139196] [client 20.226.112.14:34179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/dom.php"] [unique_id "aoSB8P2v-lWn9OzQT7UXBgAAAJw"]
[Tue Aug 18 13:01:52.970831 2026] [security2:error] [pid 139043:tid 139265] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/hplfuns.php"] [unique_id "aoSB8P2v-lWn9OzQT7UXBwAAAOE"]
[Tue Aug 18 13:01:53.012076 2026] [security2:error] [pid 139043:tid 139179] [client 20.116.17.175:23009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/as.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXCAAAAIs"]
[Tue Aug 18 13:01:53.014944 2026] [security2:error] [pid 139043:tid 139193] [client 158.158.74.177:18946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/f7.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXCQAAAJk"]
[Tue Aug 18 13:01:53.020392 2026] [security2:error] [pid 123784:tid 124017] [client 20.206.96.72:15288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/ws54.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLjAAAAGM"]
[Tue Aug 18 13:01:53.022095 2026] [security2:error] [pid 139043:tid 139263] [client 20.163.43.14:8788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXCgAAAN8"]
[Tue Aug 18 13:01:53.028408 2026] [security2:error] [pid 123784:tid 124003] [client 20.226.112.14:32525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/bb.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLjQAAAFU"]
[Tue Aug 18 13:01:53.080495 2026] [security2:error] [pid 139043:tid 139234] [client 20.51.153.15:13695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/payout.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXCwAAAMI"]
[Tue Aug 18 13:01:53.099616 2026] [security2:error] [pid 123784:tid 124002] [client 20.206.96.72:15280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/deepseek_d.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLjwAAAFQ"]
[Tue Aug 18 13:01:53.106946 2026] [security2:error] [pid 139043:tid 139274] [client 132.196.30.78:17682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXDAAAAOo"]
[Tue Aug 18 13:01:53.111120 2026] [security2:error] [pid 139043:tid 139288] [client 20.79.204.6:11536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXDQAAAPg"]
[Tue Aug 18 13:01:53.114952 2026] [security2:error] [pid 139043:tid 139252] [client 216.244.66.232:57764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXDwAAANQ"]
[Tue Aug 18 13:01:53.115039 2026] [security2:error] [pid 139043:tid 139252] [client 216.244.66.232:57764] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXDwAAANQ"]
[Tue Aug 18 13:01:53.116488 2026] [security2:error] [pid 139043:tid 139282] [client 20.29.77.16:62884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/payout.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXEAAAAPI"]
[Tue Aug 18 13:01:53.118446 2026] [security2:error] [pid 139043:tid 139285] [client 20.48.236.86:14498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/special.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXEQAAAPU"]
[Tue Aug 18 13:01:53.125954 2026] [security2:error] [pid 123784:tid 124019] [client 20.79.204.6:11562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLkAAAAGU"]
[Tue Aug 18 13:01:53.130334 2026] [security2:error] [pid 123784:tid 124008] [client 20.79.204.6:10709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/a7.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLkQAAAFo"]
[Tue Aug 18 13:01:53.137827 2026] [security2:error] [pid 123784:tid 123930] [client 20.104.100.201:49701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLkgAAAAw"]
[Tue Aug 18 13:01:53.142582 2026] [security2:error] [pid 139043:tid 139293] [client 20.226.112.14:22867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ok.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXEgAAAP0"]
[Tue Aug 18 13:01:53.153293 2026] [security2:error] [pid 139043:tid 139195] [client 20.206.96.72:15277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/function/function.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXEwAAAJs"]
[Tue Aug 18 13:01:53.177084 2026] [security2:error] [pid 139043:tid 139208] [client 20.151.109.219:37254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ue.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXFAAAAKg"]
[Tue Aug 18 13:01:53.230805 2026] [security2:error] [pid 123784:tid 124036] [client 20.206.96.72:15242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/nw.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLlQAAAHY"]
[Tue Aug 18 13:01:53.248717 2026] [security2:error] [pid 139043:tid 139281] [client 158.23.17.4:55202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/fs.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXFgAAAPE"]
[Tue Aug 18 13:01:53.259627 2026] [security2:error] [pid 123784:tid 124033] [client 20.226.112.14:38924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp9.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLlgAAAHM"]
[Tue Aug 18 13:01:53.273734 2026] [security2:error] [pid 139043:tid 139204] [client 20.119.58.187:10477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/php.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXFwAAAKQ"]
[Tue Aug 18 13:01:53.288407 2026] [security2:error] [pid 139043:tid 139211] [client 172.202.39.151:4442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/files/index.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXGAAAAKs"]
[Tue Aug 18 13:01:53.303009 2026] [security2:error] [pid 139043:tid 139296] [client 20.116.17.175:56071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/txets.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXGQAAAQA"]
[Tue Aug 18 13:01:53.317381 2026] [security2:error] [pid 139043:tid 139180] [client 20.51.153.15:13675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/Mailgun.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXGgAAAIw"]
[Tue Aug 18 13:01:53.321324 2026] [security2:error] [pid 139043:tid 139294] [client 20.206.96.72:15248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/xleet.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXGwAAAP4"]
[Tue Aug 18 13:01:53.352132 2026] [security2:error] [pid 139043:tid 139273] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/htaccess.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXHAAAAOk"]
[Tue Aug 18 13:01:53.360991 2026] [security2:error] [pid 123784:tid 124014] [client 20.163.43.14:8841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/images/images/about.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLmAAAAGA"]
[Tue Aug 18 13:01:53.367944 2026] [security2:error] [pid 139043:tid 139229] [client 172.213.243.2:16842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/forbidals.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXHgAAAL0"]
[Tue Aug 18 13:01:53.379821 2026] [security2:error] [pid 139043:tid 139298] [client 20.206.96.72:15468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXHwAAAQI"]
[Tue Aug 18 13:01:53.382402 2026] [security2:error] [pid 139043:tid 139207] [client 52.139.47.57:39477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/az.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXIAAAAKc"]
[Tue Aug 18 13:01:53.408928 2026] [security2:error] [pid 139043:tid 139249] [client 20.104.100.201:49710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/usr.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXIQAAANE"]
[Tue Aug 18 13:01:53.421771 2026] [security2:error] [pid 139043:tid 139228] [client 20.226.112.14:39484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ws59.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXIgAAALw"]
[Tue Aug 18 13:01:53.475483 2026] [security2:error] [pid 123784:tid 124041] [client 20.48.236.86:14815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/fz.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLmgAAAHs"]
[Tue Aug 18 13:01:53.481865 2026] [security2:error] [pid 123784:tid 123929] [client 172.202.39.151:49352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-login.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLmwAAAAs"]
[Tue Aug 18 13:01:53.493825 2026] [security2:error] [pid 123784:tid 123971] [client 20.206.96.72:15247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/155.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLnAAAADU"]
[Tue Aug 18 13:01:53.509266 2026] [security2:error] [pid 139043:tid 139191] [client 20.250.13.23:6527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-activat.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXJAAAAJc"]
[Tue Aug 18 13:01:53.518590 2026] [security2:error] [pid 139043:tid 139286] [client 20.151.109.219:14328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/lr.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXJQAAAPY"]
[Tue Aug 18 13:01:53.527170 2026] [authz_core:error] [pid 123784:tid 123904] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:53.527455 2026] [authz_core:error] [pid 123784:tid 123904] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:53.543974 2026] [security2:error] [pid 123784:tid 123994] [client 20.206.96.72:15256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/96i.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLnwAAAEw"]
[Tue Aug 18 13:01:53.547114 2026] [security2:error] [pid 139043:tid 139283] [client 158.23.17.4:7184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ft.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXJgAAAPM"]
[Tue Aug 18 13:01:53.559411 2026] [security2:error] [pid 139043:tid 139291] [client 20.51.153.15:13651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/oauth.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXJwAAAPs"]
[Tue Aug 18 13:01:53.574868 2026] [security2:error] [pid 123784:tid 123919] [client 20.38.3.247:4562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/inso.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLoAAAAAE"]
[Tue Aug 18 13:01:53.579962 2026] [security2:error] [pid 139043:tid 139226] [client 20.91.215.254:25798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/chosen.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXKAAAALo"]
[Tue Aug 18 13:01:53.590709 2026] [security2:error] [pid 139043:tid 139184] [client 213.202.253.4:64505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/filefuns.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXKQAAAJA"], referer: www.google.com
[Tue Aug 18 13:01:53.594325 2026] [security2:error] [pid 123784:tid 123937] [client 20.206.96.72:15259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/as.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLoQAAABM"]
[Tue Aug 18 13:01:53.622974 2026] [security2:error] [pid 123784:tid 123924] [client 20.29.77.16:16517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/Mailgun.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLowAAAAY"]
[Tue Aug 18 13:01:53.626557 2026] [security2:error] [pid 123784:tid 123928] [client 20.119.58.187:10151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/past.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLpAAAAAo"]
[Tue Aug 18 13:01:53.632505 2026] [security2:error] [pid 123784:tid 123991] [client 20.226.112.14:38925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/Ov-Simple1.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLpQAAAEk"]
[Tue Aug 18 13:01:53.650986 2026] [security2:error] [pid 139043:tid 139287] [client 158.158.74.177:18979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/photo.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXKgAAAPc"]
[Tue Aug 18 13:01:53.681504 2026] [security2:error] [pid 139043:tid 139206] [client 20.226.112.14:38973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXKwAAAKY"]
[Tue Aug 18 13:01:53.685041 2026] [security2:error] [pid 139043:tid 139243] [client 20.104.100.201:49122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXLAAAAMs"]
[Tue Aug 18 13:01:53.721820 2026] [security2:error] [pid 123784:tid 123941] [client 3.79.134.69:41980] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.stampi.ind.br"] [uri "/index.html"] [unique_id "aoSB8WwDnJBNj2tDbYYLqAAAABc"], referer: http://www.stampi.ind.br/
[Tue Aug 18 13:01:53.726759 2026] [security2:error] [pid 139043:tid 139258] [client 20.79.204.6:11544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXLgAAANo"]
[Tue Aug 18 13:01:53.732741 2026] [security2:error] [pid 139043:tid 139266] [client 20.206.96.72:15432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/min.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXLwAAAOI"]
[Tue Aug 18 13:01:53.742700 2026] [security2:error] [pid 139043:tid 139178] [client 158.23.17.4:47888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/rb.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXMAAAAIo"]
[Tue Aug 18 13:01:53.760235 2026] [security2:error] [pid 139043:tid 139209] [client 20.163.43.14:8843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/ms-edit.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXMQAAAKk"]
[Tue Aug 18 13:01:53.761815 2026] [security2:error] [pid 139043:tid 139199] [client 68.155.154.236:9166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/weozh.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXMgAAAJ8"]
[Tue Aug 18 13:01:53.771162 2026] [security2:error] [pid 139043:tid 139202] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/images/wso.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXNAAAAKI"]
[Tue Aug 18 13:01:53.776293 2026] [security2:error] [pid 139043:tid 139213] [client 20.79.204.6:11550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXNQAAAK0"]
[Tue Aug 18 13:01:53.781896 2026] [security2:error] [pid 139043:tid 139198] [client 20.206.96.72:15241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/php8.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXNgAAAJ4"]
[Tue Aug 18 13:01:53.786029 2026] [security2:error] [pid 123784:tid 124029] [client 172.213.243.2:14354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/edit.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLqwAAAG8"]
[Tue Aug 18 13:01:53.790437 2026] [security2:error] [pid 123784:tid 123968] [client 20.226.112.14:13635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/vx.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLrAAAADI"]
[Tue Aug 18 13:01:53.791120 2026] [security2:error] [pid 123784:tid 124016] [client 20.203.183.135:25996] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ww2.pan.com.br"] [uri "/1.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLrQAAAGI"]
[Tue Aug 18 13:01:53.791188 2026] [security2:error] [pid 123784:tid 124016] [client 20.203.183.135:25996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/1.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLrQAAAGI"]
[Tue Aug 18 13:01:53.813107 2026] [security2:error] [pid 139043:tid 139174] [client 20.51.153.15:13597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/timeclock.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXOAAAAIY"]
[Tue Aug 18 13:01:53.826889 2026] [security2:error] [pid 123784:tid 123934] [client 20.206.96.72:15254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-content/admin.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLsAAAABA"]
[Tue Aug 18 13:01:53.827416 2026] [security2:error] [pid 139043:tid 139271] [client 20.151.109.219:63990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ka.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXOQAAAOc"]
[Tue Aug 18 13:01:53.829923 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:53.830382 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:53.894344 2026] [security2:error] [pid 123784:tid 124044] [client 20.75.92.165:1997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLsgAAAH4"]
[Tue Aug 18 13:01:53.913675 2026] [security2:error] [pid 123784:tid 124025] [client 213.35.127.232:60800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLtAAAAGs"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:53.915666 2026] [security2:error] [pid 139043:tid 139212] [client 52.139.47.57:19751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/sx.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXPAAAAKw"]
[Tue Aug 18 13:01:53.945634 2026] [security2:error] [pid 123784:tid 124022] [client 20.226.56.190:17881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/infoinfo.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLtwAAAGg"]
[Tue Aug 18 13:01:53.951784 2026] [security2:error] [pid 123784:tid 124024] [client 132.196.30.78:19223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLuAAAAGo"]
[Tue Aug 18 13:01:53.961333 2026] [security2:error] [pid 139043:tid 139252] [client 20.104.100.201:49668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/css/database.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXPQAAANQ"]
[Tue Aug 18 13:01:53.968682 2026] [security2:error] [pid 123784:tid 124011] [client 20.206.96.72:15233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/222.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLugAAAF0"]
[Tue Aug 18 13:01:53.981128 2026] [security2:error] [pid 139043:tid 139225] [client 20.119.58.187:10157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/root.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXPwAAALk"]
[Tue Aug 18 13:01:54.012183 2026] [security2:error] [pid 123784:tid 123955] [client 172.202.39.151:44512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLvAAAACU"]
[Tue Aug 18 13:01:54.024276 2026] [security2:error] [pid 139043:tid 139195] [client 20.48.236.86:14560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/clque.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXQQAAAJs"]
[Tue Aug 18 13:01:54.026780 2026] [security2:error] [pid 123784:tid 123920] [client 20.206.96.72:15238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLvQAAAAI"]
[Tue Aug 18 13:01:54.030047 2026] [security2:error] [pid 139043:tid 139236] [client 20.79.204.6:10390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/manager.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXQgAAAMQ"]
[Tue Aug 18 13:01:54.037555 2026] [security2:error] [pid 123784:tid 123983] [client 172.202.39.151:63742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLvgAAAEE"]
[Tue Aug 18 13:01:54.046532 2026] [security2:error] [pid 139043:tid 139200] [client 20.251.112.238:33975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/tmpls.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXRAAAAKA"]
[Tue Aug 18 13:01:54.063460 2026] [security2:error] [pid 139043:tid 139208] [client 20.51.153.15:13593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/email.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXRQAAAKg"]
[Tue Aug 18 13:01:54.095954 2026] [security2:error] [pid 139043:tid 139227] [client 68.221.73.131:30311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/grok.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXRgAAALs"]
[Tue Aug 18 13:01:54.098792 2026] [security2:error] [pid 139043:tid 139237] [client 20.163.43.14:8848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/rip.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXRwAAAMU"]
[Tue Aug 18 13:01:54.101106 2026] [security2:error] [pid 139043:tid 139194] [client 20.206.96.72:15265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/info.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXSAAAAJo"]
[Tue Aug 18 13:01:54.105960 2026] [security2:error] [pid 139043:tid 139264] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/index/function.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXSQAAAOA"]
[Tue Aug 18 13:01:54.111672 2026] [security2:error] [pid 139043:tid 139281] [client 20.127.136.245:8043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/admin.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXSgAAAPE"]
[Tue Aug 18 13:01:54.118622 2026] [security2:error] [pid 123784:tid 123947] [client 20.29.77.16:62905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/oauth.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLwgAAAB0"]
[Tue Aug 18 13:01:54.123433 2026] [security2:error] [pid 123784:tid 124021] [client 172.202.39.151:4439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLxAAAAGc"]
[Tue Aug 18 13:01:54.127841 2026] [authz_core:error] [pid 123784:tid 123885] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:54.128103 2026] [authz_core:error] [pid 123784:tid 123885] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:54.129950 2026] [security2:error] [pid 123784:tid 123956] [client 20.250.13.23:6495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLxgAAACY"]
[Tue Aug 18 13:01:54.165795 2026] [security2:error] [pid 123784:tid 123981] [client 20.226.112.14:34212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ah25.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLyQAAAD8"]
[Tue Aug 18 13:01:54.170992 2026] [security2:error] [pid 123784:tid 123967] [client 20.151.109.219:60916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ot.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLygAAADE"]
[Tue Aug 18 13:01:54.183507 2026] [security2:error] [pid 139043:tid 139279] [client 20.206.96.72:15455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/a.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXSwAAAO8"]
[Tue Aug 18 13:01:54.199125 2026] [security2:error] [pid 123784:tid 123982] [client 172.213.243.2:5725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/kj.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLywAAAEA"]
[Tue Aug 18 13:01:54.227395 2026] [security2:error] [pid 139043:tid 139259] [client 20.206.96.72:15234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/chosen.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXTQAAANs"]
[Tue Aug 18 13:01:54.236300 2026] [security2:error] [pid 123784:tid 123954] [client 20.104.100.201:49433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/privdayz.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLzQAAACQ"]
[Tue Aug 18 13:01:54.253817 2026] [security2:error] [pid 123784:tid 124030] [client 20.91.215.254:11487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/asd.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLzgAAAHA"]
[Tue Aug 18 13:01:54.261832 2026] [security2:error] [pid 139043:tid 139229] [client 20.206.96.72:15253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-content/index.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXTgAAAL0"]
[Tue Aug 18 13:01:54.274479 2026] [security2:error] [pid 139043:tid 139207] [client 158.23.17.4:54724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/37.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXTwAAAKc"]
[Tue Aug 18 13:01:54.300116 2026] [security2:error] [pid 139043:tid 139188] [client 20.51.153.15:13672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/profile.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXUAAAAJQ"]
[Tue Aug 18 13:01:54.303553 2026] [security2:error] [pid 123784:tid 124017] [client 20.226.112.14:28551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/tt.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLzwAAAGM"]
[Tue Aug 18 13:01:54.331315 2026] [security2:error] [pid 123784:tid 123935] [client 20.79.204.6:11846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL0AAAABE"]
[Tue Aug 18 13:01:54.335262 2026] [security2:error] [pid 139043:tid 139180] [client 20.119.58.187:10180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/r.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXUQAAAIw"]
[Tue Aug 18 13:01:54.344194 2026] [security2:error] [pid 139043:tid 139296] [client 52.139.47.57:39613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/tfm.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXUgAAAQA"]
[Tue Aug 18 13:01:54.378905 2026] [security2:error] [pid 139043:tid 139228] [client 20.206.96.72:15449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/vx.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXVAAAALw"]
[Tue Aug 18 13:01:54.384343 2026] [security2:error] [pid 139043:tid 139275] [client 20.79.204.6:11538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXVQAAAOs"]
[Tue Aug 18 13:01:54.428239 2026] [security2:error] [pid 139043:tid 139244] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/info.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXVwAAAMw"]
[Tue Aug 18 13:01:54.431167 2026] [security2:error] [pid 139043:tid 139274] [client 149.34.210.141:59348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXWQAAAOo"]
[Tue Aug 18 13:01:54.445068 2026] [security2:error] [pid 139043:tid 139214] [client 20.206.96.72:15443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wap.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXWgAAAK4"]
[Tue Aug 18 13:01:54.473237 2026] [security2:error] [pid 139043:tid 139221] [client 20.226.112.14:28552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/xqq.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXWwAAALU"]
[Tue Aug 18 13:01:54.477096 2026] [security2:error] [pid 139043:tid 139215] [client 158.158.74.177:9265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-aa.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXXAAAAK8"]
[Tue Aug 18 13:01:54.477259 2026] [security2:error] [pid 123784:tid 123973] [client 20.116.17.175:22971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/pucci.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL1AAAADc"]
[Tue Aug 18 13:01:54.512651 2026] [security2:error] [pid 139043:tid 139291] [client 20.104.100.201:49707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wg459o.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXXgAAAPs"]
[Tue Aug 18 13:01:54.528875 2026] [security2:error] [pid 123784:tid 123927] [client 4.232.94.69:15697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/class-wp-cmd.php/fied.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL1wAAAAk"]
[Tue Aug 18 13:01:54.530141 2026] [security2:error] [pid 123784:tid 123918] [client 132.196.30.78:19215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/admin.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL2AAAAAA"]
[Tue Aug 18 13:01:54.537093 2026] [autoindex:error] [pid 123784:tid 123930] [client 172.202.39.151:53724] AH01276: Cannot serve directory /home2/sfca23/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:54.541466 2026] [security2:error] [pid 123784:tid 124036] [client 20.65.98.162:2288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/uwu.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL2QAAAHY"]
[Tue Aug 18 13:01:54.551513 2026] [security2:error] [pid 123784:tid 124005] [client 20.75.92.165:4283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL2gAAAFc"]
[Tue Aug 18 13:01:54.553222 2026] [security2:error] [pid 139043:tid 139226] [client 20.29.77.16:47343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/timeclock.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXXwAAALo"]
[Tue Aug 18 13:01:54.554202 2026] [security2:error] [pid 123784:tid 124019] [client 138.36.100.162:41793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL2wAAAGU"]
[Tue Aug 18 13:01:54.556847 2026] [security2:error] [pid 139043:tid 139184] [client 20.51.153.15:13598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/summary.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXYAAAAJA"]
[Tue Aug 18 13:01:54.567397 2026] [security2:error] [pid 139043:tid 139203] [client 20.206.96.72:15483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-admin/wp.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXYQAAAKM"]
[Tue Aug 18 13:01:54.578560 2026] [security2:error] [pid 139043:tid 139239] [client 20.203.183.135:26032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/coffee.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXYgAAAMc"]
[Tue Aug 18 13:01:54.600639 2026] [security2:error] [pid 139043:tid 139243] [client 20.163.43.14:8832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXYwAAAMs"]
[Tue Aug 18 13:01:54.609936 2026] [security2:error] [pid 139043:tid 139300] [client 103.120.71.157:53804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXZAAAAQQ"]
[Tue Aug 18 13:01:54.610032 2026] [security2:error] [pid 139043:tid 139300] [client 103.120.71.157:53804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXZAAAAQQ"]
[Tue Aug 18 13:01:54.610617 2026] [security2:error] [pid 139043:tid 139175] [client 172.213.243.2:45918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/bes.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXZQAAAIc"]
[Tue Aug 18 13:01:54.633373 2026] [security2:error] [pid 123784:tid 124020] [client 20.206.96.72:15430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/bgymj.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL3QAAAGY"]
[Tue Aug 18 13:01:54.652129 2026] [security2:error] [pid 139043:tid 139217] [client 20.151.109.219:39329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ih.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXZwAAALE"]
[Tue Aug 18 13:01:54.663832 2026] [security2:error] [pid 139043:tid 139266] [client 20.206.96.72:15474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/aa.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXaAAAAOI"]
[Tue Aug 18 13:01:54.680522 2026] [security2:error] [pid 123784:tid 123987] [client 172.202.39.151:53724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wso.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL3gAAAEU"]
[Tue Aug 18 13:01:54.688791 2026] [security2:error] [pid 139043:tid 139287] [client 20.119.58.187:10121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/sid3.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXaQAAAPc"]
[Tue Aug 18 13:01:54.698273 2026] [security2:error] [pid 139043:tid 139181] [client 20.206.96.72:15434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-mail.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXagAAAI0"]
[Tue Aug 18 13:01:54.699502 2026] [security2:error] [pid 139043:tid 139213] [client 20.226.112.14:38956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/06.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXawAAAK0"]
[Tue Aug 18 13:01:54.711436 2026] [security2:error] [pid 139043:tid 139274] [client 149.34.210.141:59348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXWQAAAOo"]
[Tue Aug 18 13:01:54.730025 2026] [authz_core:error] [pid 123784:tid 123796] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:54.730288 2026] [authz_core:error] [pid 123784:tid 123796] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:54.733132 2026] [security2:error] [pid 139043:tid 139238] [client 172.202.39.151:4674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/images/images/about.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXbAAAAMY"]
[Tue Aug 18 13:01:54.747365 2026] [security2:error] [pid 123784:tid 123929] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/profile.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL4QAAAAs"]
[Tue Aug 18 13:01:54.786622 2026] [security2:error] [pid 139043:tid 139297] [client 20.104.100.201:49688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/mifta.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXbgAAAQE"]
[Tue Aug 18 13:01:54.789421 2026] [security2:error] [pid 123784:tid 124014] [client 52.139.47.57:28870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/asd.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL4wAAAGA"]
[Tue Aug 18 13:01:54.791530 2026] [security2:error] [pid 139043:tid 139173] [client 20.51.153.15:13660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/conf.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXbwAAAIU"]
[Tue Aug 18 13:01:54.812108 2026] [security2:error] [pid 139043:tid 139271] [client 20.206.96.72:15433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/bolt.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXcAAAAOc"]
[Tue Aug 18 13:01:54.835424 2026] [security2:error] [pid 123784:tid 124043] [client 20.48.236.86:14797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/nano.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL6QAAAH0"]
[Tue Aug 18 13:01:54.845409 2026] [security2:error] [pid 139043:tid 139276] [client 20.206.96.72:16005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/bthil.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXcQAAAOw"]
[Tue Aug 18 13:01:54.876586 2026] [security2:error] [pid 139043:tid 139233] [client 20.250.13.23:51238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/past1.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXcwAAAME"]
[Tue Aug 18 13:01:54.886111 2026] [security2:error] [pid 123784:tid 123939] [client 68.155.154.236:41490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/rymmm.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL6wAAABU"]
[Tue Aug 18 13:01:54.887888 2026] [security2:error] [pid 139043:tid 139272] [client 178.153.171.161:41470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXdAAAAOg"]
[Tue Aug 18 13:01:54.888029 2026] [security2:error] [pid 139043:tid 139272] [client 178.153.171.161:41470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXdAAAAOg"]
[Tue Aug 18 13:01:54.914453 2026] [security2:error] [pid 123784:tid 123991] [client 20.206.96.72:15235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/x.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL7QAAAEk"]
[Tue Aug 18 13:01:54.920417 2026] [security2:error] [pid 123784:tid 123979] [client 20.91.215.254:19447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/akc.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL7gAAAD0"]
[Tue Aug 18 13:01:54.930604 2026] [security2:error] [pid 123784:tid 124018] [client 20.163.43.14:8856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/moon.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL7wAAAGQ"]
[Tue Aug 18 13:01:54.931405 2026] [security2:error] [pid 139043:tid 139190] [client 20.79.204.6:12264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXdQAAAJY"]
[Tue Aug 18 13:01:54.932392 2026] [security2:error] [pid 123784:tid 123969] [client 213.35.127.232:60981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL8AAAADM"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:54.957806 2026] [security2:error] [pid 123784:tid 124019] [client 138.36.100.162:41793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL2wAAAGU"]
[Tue Aug 18 13:01:54.960121 2026] [security2:error] [pid 123784:tid 123970] [client 20.151.109.219:60876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/k.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL8QAAADQ"]
[Tue Aug 18 13:01:54.974637 2026] [security2:error] [pid 123784:tid 123968] [client 20.29.77.16:40518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/email.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL8wAAADI"]
[Tue Aug 18 13:01:54.984257 2026] [security2:error] [pid 139043:tid 139257] [client 132.196.30.78:19196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/edit.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXdgAAANk"]
[Tue Aug 18 13:01:54.993561 2026] [security2:error] [pid 139043:tid 139265] [client 20.79.204.6:12254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/themes/about.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXeAAAAOE"]
[Tue Aug 18 13:01:55.013655 2026] [security2:error] [pid 139043:tid 139187] [client 172.202.39.151:44594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/function/function.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXeQAAAJM"]
[Tue Aug 18 13:01:55.024400 2026] [security2:error] [pid 139043:tid 139289] [client 172.213.243.2:14393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ws60.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXegAAAPk"]
[Tue Aug 18 13:01:55.033061 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:55.033328 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:55.036825 2026] [security2:error] [pid 139043:tid 139227] [client 20.51.153.15:13642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/bala.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXewAAALs"]
[Tue Aug 18 13:01:55.053636 2026] [security2:error] [pid 139043:tid 139195] [client 20.119.58.187:10468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/ss.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXfAAAAJs"]
[Tue Aug 18 13:01:55.056952 2026] [security2:error] [pid 139043:tid 139247] [client 158.23.17.4:32527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/fa.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXfQAAAM8"]
[Tue Aug 18 13:01:55.061964 2026] [security2:error] [pid 123784:tid 123962] [client 20.104.100.201:49685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSB82wDnJBNj2tDbYYL-AAAACw"]
[Tue Aug 18 13:01:55.062436 2026] [security2:error] [pid 139043:tid 139205] [client 20.226.112.14:28795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/166.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXfgAAAKU"]
[Tue Aug 18 13:01:55.064691 2026] [security2:error] [pid 123784:tid 123948] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/sx.php"] [unique_id "aoSB82wDnJBNj2tDbYYL-QAAAB4"]
[Tue Aug 18 13:01:55.064903 2026] [security2:error] [pid 139043:tid 139240] [client 216.244.66.232:57800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXfwAAAMg"]
[Tue Aug 18 13:01:55.065014 2026] [security2:error] [pid 139043:tid 139240] [client 216.244.66.232:57800] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXfwAAAMg"]
[Tue Aug 18 13:01:55.075026 2026] [security2:error] [pid 123784:tid 123992] [client 20.206.96.72:15944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/index/function.php"] [unique_id "aoSB82wDnJBNj2tDbYYL-gAAAEo"]
[Tue Aug 18 13:01:55.105258 2026] [security2:error] [pid 123784:tid 123928] [client 158.158.74.177:22863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/d.php"] [unique_id "aoSB82wDnJBNj2tDbYYL-wAAAAo"]
[Tue Aug 18 13:01:55.107172 2026] [security2:error] [pid 123784:tid 123946] [client 20.206.96.72:15263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/aaa.php"] [unique_id "aoSB82wDnJBNj2tDbYYL_AAAABw"]
[Tue Aug 18 13:01:55.116402 2026] [security2:error] [pid 123784:tid 123988] [client 158.23.17.4:11778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/md.php"] [unique_id "aoSB82wDnJBNj2tDbYYL_QAAAEY"]
[Tue Aug 18 13:01:55.145422 2026] [security2:error] [pid 139043:tid 139248] [client 20.206.96.72:15273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/abcd.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXgQAAANA"]
[Tue Aug 18 13:01:55.222836 2026] [security2:error] [pid 139043:tid 139228] [client 172.202.39.151:4684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/ms-edit.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXhQAAALw"]
[Tue Aug 18 13:01:55.223979 2026] [security2:error] [pid 139043:tid 139292] [client 20.251.112.238:33956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/nzv.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXhgAAAPw"]
[Tue Aug 18 13:01:55.233941 2026] [security2:error] [pid 139043:tid 139194] [client 52.139.47.57:16599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/nij.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXhwAAAJo"]
[Tue Aug 18 13:01:55.240816 2026] [security2:error] [pid 123784:tid 123955] [client 20.206.96.72:15281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-good.php"] [unique_id "aoSB82wDnJBNj2tDbYYMAQAAACU"]
[Tue Aug 18 13:01:55.243572 2026] [security2:error] [pid 123784:tid 123920] [client 20.127.136.245:3548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB82wDnJBNj2tDbYYMAgAAAAI"]
[Tue Aug 18 13:01:55.265257 2026] [security2:error] [pid 123784:tid 124028] [client 20.163.43.14:8869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/cache.php"] [unique_id "aoSB82wDnJBNj2tDbYYMAwAAAG4"]
[Tue Aug 18 13:01:55.280430 2026] [security2:error] [pid 123784:tid 123983] [client 20.206.96.72:15464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/simple.php"] [unique_id "aoSB82wDnJBNj2tDbYYMBAAAAEE"]
[Tue Aug 18 13:01:55.283200 2026] [security2:error] [pid 123784:tid 123923] [client 20.51.153.15:13574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/222.php"] [unique_id "aoSB82wDnJBNj2tDbYYMBQAAAAU"]
[Tue Aug 18 13:01:55.294853 2026] [security2:error] [pid 139043:tid 139284] [client 20.226.112.14:38957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/snq.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXiAAAAPQ"]
[Tue Aug 18 13:01:55.305769 2026] [security2:error] [pid 123784:tid 123956] [client 20.206.96.72:15255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/edit-tags.php"] [unique_id "aoSB82wDnJBNj2tDbYYMBgAAACY"]
[Tue Aug 18 13:01:55.334642 2026] [authz_core:error] [pid 123784:tid 123909] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:55.334905 2026] [authz_core:error] [pid 123784:tid 123909] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:55.336618 2026] [security2:error] [pid 123784:tid 123993] [client 20.104.100.201:49457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/index2.php"] [unique_id "aoSB82wDnJBNj2tDbYYMCQAAAEs"]
[Tue Aug 18 13:01:55.342669 2026] [security2:error] [pid 139043:tid 139286] [client 20.206.96.72:15239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/u.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXiQAAAPY"]
[Tue Aug 18 13:01:55.355553 2026] [security2:error] [pid 139043:tid 139283] [client 20.151.109.219:14134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/iu.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXigAAAPM"]
[Tue Aug 18 13:01:55.384121 2026] [security2:error] [pid 139043:tid 139226] [client 20.226.56.190:23784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/c99shell.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXiwAAALo"]
[Tue Aug 18 13:01:55.387963 2026] [security2:error] [pid 139043:tid 139184] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXjAAAAJA"]
[Tue Aug 18 13:01:55.393300 2026] [security2:error] [pid 139043:tid 139177] [client 172.202.39.151:53707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/sf.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXjQAAAIk"]
[Tue Aug 18 13:01:55.397537 2026] [security2:error] [pid 139043:tid 139239] [client 20.75.92.165:2004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/xmr.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXjgAAAMc"]
[Tue Aug 18 13:01:55.403650 2026] [security2:error] [pid 123784:tid 124021] [client 20.119.58.187:10479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/sts.php"] [unique_id "aoSB82wDnJBNj2tDbYYMCgAAAGc"]
[Tue Aug 18 13:01:55.405597 2026] [security2:error] [pid 123784:tid 124012] [client 158.23.17.4:15806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/h.php"] [unique_id "aoSB82wDnJBNj2tDbYYMCwAAAF4"]
[Tue Aug 18 13:01:55.408314 2026] [security2:error] [pid 139043:tid 139278] [client 157.20.138.62:64801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXjwAAAO4"]
[Tue Aug 18 13:01:55.408397 2026] [security2:error] [pid 139043:tid 139278] [client 157.20.138.62:64801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXjwAAAO4"]
[Tue Aug 18 13:01:55.427210 2026] [security2:error] [pid 139043:tid 139243] [client 20.29.77.16:61102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/profile.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXkAAAAMs"]
[Tue Aug 18 13:01:55.432047 2026] [security2:error] [pid 139043:tid 139291] [client 20.206.96.72:15484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXkQAAAPs"]
[Tue Aug 18 13:01:55.438648 2026] [security2:error] [pid 139043:tid 139280] [client 172.213.243.2:45361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/olfclass.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXlAAAAPA"]
[Tue Aug 18 13:01:55.486412 2026] [security2:error] [pid 139043:tid 139178] [client 20.226.112.14:32550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-access.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXlQAAAIo"]
[Tue Aug 18 13:01:55.493676 2026] [security2:error] [pid 139043:tid 139266] [client 20.206.96.72:15286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/h.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXlgAAAOI"]
[Tue Aug 18 13:01:55.520550 2026] [security2:error] [pid 139043:tid 139287] [client 20.51.153.15:13608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/routes.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXlwAAAPc"]
[Tue Aug 18 13:01:55.524394 2026] [security2:error] [pid 139043:tid 139202] [client 20.206.96.72:15271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/ms-edit.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXmAAAAKI"]
[Tue Aug 18 13:01:55.541966 2026] [security2:error] [pid 139043:tid 139221] [client 20.79.204.6:11528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXmQAAALU"]
[Tue Aug 18 13:01:55.545218 2026] [security2:error] [pid 123784:tid 123884] [remote 47.89.174.181:15648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.app.decision.foxalpha.com.br"] [uri "/.env"] [unique_id "aoSB82wDnJBNj2tDbYYMDwAAIF8"]
[Tue Aug 18 13:01:55.548492 2026] [security2:error] [pid 123784:tid 123944] [client 20.250.13.23:6464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/file61.php"] [unique_id "aoSB82wDnJBNj2tDbYYMEAAAABo"]
[Tue Aug 18 13:01:55.559863 2026] [security2:error] [pid 139043:tid 139238] [client 20.206.96.72:15480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/a7.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXmgAAAMY"]
[Tue Aug 18 13:01:55.568027 2026] [security2:error] [pid 123784:tid 123960] [client 158.23.17.4:51164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/iy.php"] [unique_id "aoSB82wDnJBNj2tDbYYMEQAAACo"]
[Tue Aug 18 13:01:55.569050 2026] [security2:error] [pid 123784:tid 123958] [client 20.91.215.254:27088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/maintenance.php"] [unique_id "aoSB82wDnJBNj2tDbYYMEgAAACg"]
[Tue Aug 18 13:01:55.598717 2026] [security2:error] [pid 139043:tid 139232] [client 20.79.204.6:12250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXnAAAAMA"]
[Tue Aug 18 13:01:55.608377 2026] [security2:error] [pid 139043:tid 139297] [client 20.104.100.201:49458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/8.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXnQAAAQE"]
[Tue Aug 18 13:01:55.631450 2026] [security2:error] [pid 139043:tid 139173] [client 20.226.112.14:22917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/nw.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXnwAAAIU"]
[Tue Aug 18 13:01:55.658868 2026] [security2:error] [pid 139043:tid 139179] [client 20.206.96.72:15441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/manager.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXoAAAAIs"]
[Tue Aug 18 13:01:55.682360 2026] [security2:error] [pid 139043:tid 139255] [client 20.65.98.162:29727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/signon.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXogAAANc"]
[Tue Aug 18 13:01:55.699813 2026] [security2:error] [pid 139043:tid 139276] [client 20.151.109.219:63986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/pk.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXowAAAOw"]
[Tue Aug 18 13:01:55.711984 2026] [security2:error] [pid 139043:tid 139233] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXpAAAAME"]
[Tue Aug 18 13:01:55.715245 2026] [security2:error] [pid 139043:tid 139282] [client 20.206.96.72:15283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/w1.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXpQAAAPI"]
[Tue Aug 18 13:01:55.758755 2026] [security2:error] [pid 139043:tid 139271] [client 20.119.58.187:10214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/shell.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXqAAAAOc"]
[Tue Aug 18 13:01:55.766345 2026] [security2:error] [pid 123784:tid 124017] [client 158.158.74.177:22852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSB82wDnJBNj2tDbYYMGAAAAGM"]
[Tue Aug 18 13:01:55.797125 2026] [security2:error] [pid 139043:tid 139220] [client 20.51.153.15:13691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/php5.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXqgAAALQ"]
[Tue Aug 18 13:01:55.805995 2026] [security2:error] [pid 123784:tid 124009] [client 103.184.169.37:43246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB82wDnJBNj2tDbYYMGwAAAFs"]
[Tue Aug 18 13:01:55.806435 2026] [security2:error] [pid 123784:tid 124009] [client 103.184.169.37:43246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB82wDnJBNj2tDbYYMGwAAAFs"]
[Tue Aug 18 13:01:55.829573 2026] [security2:error] [pid 139043:tid 139265] [client 20.226.112.14:34217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ws62.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXqwAAAOE"]
[Tue Aug 18 13:01:55.840696 2026] [security2:error] [pid 123784:tid 123975] [client 132.196.30.78:6170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/w.php"] [unique_id "aoSB82wDnJBNj2tDbYYMHAAAADk"]
[Tue Aug 18 13:01:55.847290 2026] [security2:error] [pid 139043:tid 139289] [client 172.213.243.2:14397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wpver.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXrAAAAPk"]
[Tue Aug 18 13:01:55.888829 2026] [security2:error] [pid 139043:tid 139240] [client 20.104.100.201:49465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/images.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXrgAAAMg"]
[Tue Aug 18 13:01:55.891727 2026] [security2:error] [pid 139043:tid 139237] [client 172.202.39.151:63692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/index/function.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXrwAAAMU"]
[Tue Aug 18 13:01:55.924427 2026] [security2:error] [pid 139043:tid 139299] [client 20.48.236.86:14796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "treinolab.com.br"] [uri "/.mopj.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXsAAAAQM"]
[Tue Aug 18 13:01:55.924613 2026] [security2:error] [pid 139043:tid 139190] [client 20.206.96.72:15270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-login.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXpwAAAJY"]
[Tue Aug 18 13:01:55.937446 2026] [authz_core:error] [pid 123784:tid 123793] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:55.937708 2026] [authz_core:error] [pid 123784:tid 123793] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:55.944543 2026] [security2:error] [pid 139043:tid 139279] [client 20.29.77.16:40520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/summary.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXsQAAAO8"]
[Tue Aug 18 13:01:55.947685 2026] [security2:error] [pid 123784:tid 124003] [client 213.35.127.232:61182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSB82wDnJBNj2tDbYYMHwAAAFU"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:55.950828 2026] [security2:error] [pid 123784:tid 124002] [client 52.139.47.57:36809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/404.php"] [unique_id "aoSB82wDnJBNj2tDbYYMIAAAAFQ"]
[Tue Aug 18 13:01:55.969138 2026] [security2:error] [pid 139043:tid 139211] [client 20.203.183.135:13009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXswAAAKs"]
[Tue Aug 18 13:01:55.975583 2026] [security2:error] [pid 139043:tid 139259] [client 20.127.136.245:22975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/as.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXtQAAANs"]
[Tue Aug 18 13:01:55.978873 2026] [security2:error] [pid 139043:tid 139262] [client 20.75.92.165:4264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/about.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXtgAAAN4"]
[Tue Aug 18 13:01:55.991497 2026] [security2:error] [pid 139043:tid 139273] [client 20.206.96.72:15451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/default.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXtwAAAOk"]
[Tue Aug 18 13:01:56.022016 2026] [security2:error] [pid 139043:tid 139250] [client 158.23.17.4:60769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/og.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXuAAAANI"]
[Tue Aug 18 13:01:56.039507 2026] [security2:error] [pid 123784:tid 124008] [client 20.206.96.72:15240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/i.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMIgAAAFo"]
[Tue Aug 18 13:01:56.052602 2026] [security2:error] [pid 139043:tid 139186] [client 20.51.153.15:13621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/Black.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXuQAAAJI"]
[Tue Aug 18 13:01:56.082462 2026] [security2:error] [pid 139043:tid 139246] [client 20.151.109.219:14334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ge.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXugAAAM4"]
[Tue Aug 18 13:01:56.091881 2026] [security2:error] [pid 123784:tid 123798] [remote 89.185.225.24:60772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.225.185.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ihostiweb.com"] [uri "/wp-login.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMIwAADgk"]
[Tue Aug 18 13:01:56.099539 2026] [security2:error] [pid 139043:tid 139295] [client 158.23.17.4:40393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/40.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXuwAAAP8"]
[Tue Aug 18 13:01:56.113204 2026] [security2:error] [pid 139043:tid 139284] [client 135.225.78.186:11359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/aa.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXvAAAAPQ"]
[Tue Aug 18 13:01:56.113650 2026] [security2:error] [pid 139043:tid 139251] [client 20.119.58.187:10202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/setup-config.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXvQAAANM"]
[Tue Aug 18 13:01:56.119418 2026] [security2:error] [pid 139043:tid 139214] [client 20.163.43.14:8842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXvgAAAK4"]
[Tue Aug 18 13:01:56.138408 2026] [security2:error] [pid 139043:tid 139191] [client 172.202.39.151:4479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/rip.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXvwAAAJc"]
[Tue Aug 18 13:01:56.168455 2026] [security2:error] [pid 123784:tid 124020] [client 20.226.112.14:38923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/public/vx.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMJAAAAGY"]
[Tue Aug 18 13:01:56.169749 2026] [security2:error] [pid 139043:tid 139215] [client 20.104.100.201:49691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/a.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXwQAAAK8"]
[Tue Aug 18 13:01:56.173677 2026] [security2:error] [pid 139043:tid 139294] [client 20.79.204.6:11694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXwgAAAP4"]
[Tue Aug 18 13:01:56.185738 2026] [security2:error] [pid 139043:tid 139203] [client 20.206.96.72:15809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXyAAAAKM"]
[Tue Aug 18 13:01:56.202681 2026] [security2:error] [pid 139043:tid 139298] [client 20.79.204.6:12273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXyQAAAQI"]
[Tue Aug 18 13:01:56.230300 2026] [security2:error] [pid 139043:tid 139206] [client 20.206.96.72:15267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXzQAAAKY"]
[Tue Aug 18 13:01:56.246337 2026] [security2:error] [pid 139043:tid 139217] [client 20.75.92.165:2047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/admin.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXzgAAALE"]
[Tue Aug 18 13:01:56.258155 2026] [security2:error] [pid 123784:tid 124035] [client 172.213.243.2:5731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/thui.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMJwAAAHU"]
[Tue Aug 18 13:01:56.259200 2026] [security2:error] [pid 123784:tid 123986] [client 20.29.77.16:13654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/conf.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMKAAAAEQ"]
[Tue Aug 18 13:01:56.271928 2026] [security2:error] [pid 139043:tid 139209] [client 20.38.3.247:32619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/aa.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX0AAAAKk"]
[Tue Aug 18 13:01:56.290476 2026] [security2:error] [pid 123784:tid 123930] [client 20.91.215.254:27094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/options-writing.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMKQAAAAw"]
[Tue Aug 18 13:01:56.318788 2026] [autoindex:error] [pid 139043:tid 139136] [remote 34.31.203.120:34304] AH01276: Cannot serve directory /home2/siderurgiabrasil/anuariodasiderurgia.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Aug 18 13:01:56.320962 2026] [security2:error] [pid 139043:tid 139223] [client 4.232.151.198:30703] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.mabelini.com.br"] [uri "/1.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX0wAAALc"]
[Tue Aug 18 13:01:56.321082 2026] [security2:error] [pid 139043:tid 139223] [client 4.232.151.198:30703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/1.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX0wAAALc"]
[Tue Aug 18 13:01:56.330011 2026] [security2:error] [pid 139043:tid 139199] [client 20.206.96.72:15285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/gecko-new.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX1AAAAJ8"]
[Tue Aug 18 13:01:56.336329 2026] [security2:error] [pid 123784:tid 123921] [client 68.155.154.236:53650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/lddxs.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMKgAAAAM"]
[Tue Aug 18 13:01:56.350041 2026] [security2:error] [pid 139043:tid 139221] [client 20.116.17.175:22964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wicked.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX1QAAALU"]
[Tue Aug 18 13:01:56.385409 2026] [security2:error] [pid 139043:tid 139197] [client 20.206.96.72:15454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/NewFile.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX1wAAAJ0"]
[Tue Aug 18 13:01:56.394767 2026] [security2:error] [pid 139043:tid 139212] [client 20.51.153.15:13600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/filesystems.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX2AAAAKw"]
[Tue Aug 18 13:01:56.413335 2026] [security2:error] [pid 139043:tid 139239] [client 158.158.74.177:18981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX2QAAAMc"]
[Tue Aug 18 13:01:56.415743 2026] [security2:error] [pid 139043:tid 139288] [client 5.31.227.224:30459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX2gAAAPg"]
[Tue Aug 18 13:01:56.415829 2026] [security2:error] [pid 139043:tid 139288] [client 5.31.227.224:30459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX2gAAAPg"]
[Tue Aug 18 13:01:56.418964 2026] [security2:error] [pid 139043:tid 139179] [client 20.206.96.72:16045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-Blogs.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX2wAAAIs"]
[Tue Aug 18 13:01:56.438346 2026] [security2:error] [pid 123784:tid 123965] [client 20.250.13.23:51215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/license.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMKwAAAC8"]
[Tue Aug 18 13:01:56.440629 2026] [security2:error] [pid 139043:tid 139196] [client 20.104.100.201:49698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX3AAAAJw"]
[Tue Aug 18 13:01:56.456481 2026] [security2:error] [pid 139043:tid 139233] [client 20.206.96.72:15444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX3gAAAME"]
[Tue Aug 18 13:01:56.459669 2026] [security2:error] [pid 123784:tid 123991] [client 158.23.17.4:47919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/lp.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMLQAAAEk"]
[Tue Aug 18 13:01:56.464274 2026] [security2:error] [pid 139043:tid 139198] [client 20.119.58.187:10489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/t.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX3wAAAJ4"]
[Tue Aug 18 13:01:56.482648 2026] [security2:error] [pid 123784:tid 124018] [client 20.151.109.219:60359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/kl.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMLgAAAGQ"]
[Tue Aug 18 13:01:56.488202 2026] [security2:error] [pid 139043:tid 139236] [client 20.206.96.72:15428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/themes.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX4AAAAMQ"]
[Tue Aug 18 13:01:56.502936 2026] [security2:error] [pid 123784:tid 123970] [client 172.202.39.151:52893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/edit.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMMAAAADQ"]
[Tue Aug 18 13:01:56.537043 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:56.537319 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:56.567797 2026] [security2:error] [pid 139043:tid 139174] [client 52.139.47.57:16597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/mah.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX4gAAAIY"]
[Tue Aug 18 13:01:56.590546 2026] [security2:error] [pid 123784:tid 123962] [client 20.75.92.165:4351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMNwAAACw"]
[Tue Aug 18 13:01:56.598291 2026] [security2:error] [pid 139043:tid 139240] [client 20.226.112.14:34219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/loxi-o.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX5AAAAMg"]
[Tue Aug 18 13:01:56.605204 2026] [security2:error] [pid 123784:tid 124032] [client 20.206.96.72:15272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/cv.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMOQAAAHI"]
[Tue Aug 18 13:01:56.609974 2026] [security2:error] [pid 139043:tid 139200] [client 74.7.175.137:45368] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "a3veiculossc.com.br"] [uri "/robots.txt"] [unique_id "aoSB9P2v-lWn9OzQT7UX5QAAoFg"]
[Tue Aug 18 13:01:56.618710 2026] [security2:error] [pid 139043:tid 139299] [client 132.196.30.78:1130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/file.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX5wAAAQM"]
[Tue Aug 18 13:01:56.632375 2026] [security2:error] [pid 139043:tid 139190] [client 20.163.43.14:8833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-mail.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX6AAAAJY"]
[Tue Aug 18 13:01:56.674535 2026] [security2:error] [pid 123784:tid 124025] [client 172.213.243.2:48368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/tmpls.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMOgAAAGs"]
[Tue Aug 18 13:01:56.674640 2026] [security2:error] [pid 139043:tid 139259] [client 20.206.96.72:15435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX6gAAANs"]
[Tue Aug 18 13:01:56.685641 2026] [security2:error] [pid 123784:tid 124022] [client 20.51.153.15:13579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/showphpinfo.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMOwAAAGg"]
[Tue Aug 18 13:01:56.710548 2026] [security2:error] [pid 139043:tid 139245] [client 20.206.96.72:15292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/ws83.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX7AAAAM0"]
[Tue Aug 18 13:01:56.720934 2026] [security2:error] [pid 123784:tid 124026] [client 20.104.100.201:49131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/99.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMPQAAAGw"]
[Tue Aug 18 13:01:56.769979 2026] [security2:error] [pid 139043:tid 139194] [client 20.127.136.245:22155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/bolt.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX7QAAAJo"]
[Tue Aug 18 13:01:56.773892 2026] [security2:error] [pid 139043:tid 139244] [client 216.244.66.232:57816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX7gAAAMw"]
[Tue Aug 18 13:01:56.774016 2026] [security2:error] [pid 139043:tid 139244] [client 216.244.66.232:57816] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX7gAAAMw"]
[Tue Aug 18 13:01:56.799986 2026] [security2:error] [pid 139043:tid 139270] [client 37.40.227.74:56883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX8QAAAOY"]
[Tue Aug 18 13:01:56.800154 2026] [security2:error] [pid 139043:tid 139270] [client 37.40.227.74:56883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX8QAAAOY"]
[Tue Aug 18 13:01:56.814357 2026] [security2:error] [pid 123784:tid 123949] [client 20.119.58.187:10178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/up.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMPwAAAB8"]
[Tue Aug 18 13:01:56.816706 2026] [security2:error] [pid 139043:tid 139286] [client 20.206.96.72:15470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/atex1.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX8gAAAPY"]
[Tue Aug 18 13:01:56.828577 2026] [security2:error] [pid 123784:tid 124006] [client 20.29.77.16:13669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/bala.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMQAAAAFg"]
[Tue Aug 18 13:01:56.842348 2026] [authz_core:error] [pid 123784:tid 123872] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:56.842790 2026] [authz_core:error] [pid 123784:tid 123872] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:56.866963 2026] [security2:error] [pid 139043:tid 139192] [client 20.206.96.72:15260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/class-t.api.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX9AAAAJg"]
[Tue Aug 18 13:01:56.907883 2026] [security2:error] [pid 123784:tid 123976] [client 20.206.96.72:16006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/w.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMRAAAADo"]
[Tue Aug 18 13:01:56.913147 2026] [security2:error] [pid 123784:tid 123982] [client 20.151.109.219:14106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/gs.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMRQAAAEA"]
[Tue Aug 18 13:01:56.919118 2026] [security2:error] [pid 123784:tid 124030] [client 158.23.17.4:20211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/fb.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMRgAAAHA"]
[Tue Aug 18 13:01:56.925077 2026] [security2:error] [pid 123784:tid 124000] [client 20.91.215.254:27077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMRwAAAFI"]
[Tue Aug 18 13:01:56.951254 2026] [security2:error] [pid 139043:tid 139287] [client 20.75.92.165:4262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/as.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX9gAAAPc"]
[Tue Aug 18 13:01:56.954648 2026] [security2:error] [pid 139043:tid 139260] [client 20.51.153.15:13683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/phpstatus.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX9wAAANw"]
[Tue Aug 18 13:01:56.961468 2026] [security2:error] [pid 123784:tid 123946] [client 213.35.127.232:61389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMSAAAABw"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:56.974702 2026] [security2:error] [pid 139043:tid 139181] [client 20.226.112.14:28789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/sdsa.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX-AAAAI0"]
[Tue Aug 18 13:01:56.982358 2026] [security2:error] [pid 123784:tid 123950] [client 158.23.17.4:56539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ee.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMSQAAACA"]
[Tue Aug 18 13:01:56.989365 2026] [security2:error] [pid 123784:tid 123947] [client 52.139.47.57:3838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/ws.php7"] [unique_id "aoSB9GwDnJBNj2tDbYYMSgAAAB0"]
[Tue Aug 18 13:01:56.990492 2026] [security2:error] [pid 123784:tid 123985] [client 20.206.96.72:15250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/archive.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMSwAAAEM"]
[Tue Aug 18 13:01:56.993223 2026] [security2:error] [pid 139043:tid 139269] [client 68.155.154.236:45830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/zjggu.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX-gAAAOU"]
[Tue Aug 18 13:01:57.000881 2026] [security2:error] [pid 123784:tid 123935] [client 20.104.100.201:49096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/yup.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMTgAAABE"]
[Tue Aug 18 13:01:57.007209 2026] [security2:error] [pid 123784:tid 123999] [client 4.232.94.69:29854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/manager.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMTwAAAFE"]
[Tue Aug 18 13:01:57.018730 2026] [security2:error] [pid 123784:tid 124013] [client 20.163.43.14:8861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/o.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMUQAAAF8"]
[Tue Aug 18 13:01:57.046152 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.112.14:32524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-freya.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMUwAAAH8"]
[Tue Aug 18 13:01:57.046848 2026] [security2:error] [pid 123784:tid 123989] [client 4.232.151.198:11597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/alfa.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMVAAAAEc"]
[Tue Aug 18 13:01:57.049122 2026] [security2:error] [pid 123784:tid 123975] [client 20.206.96.72:16025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/bless.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMVQAAADk"]
[Tue Aug 18 13:01:57.074268 2026] [security2:error] [pid 139043:tid 139232] [client 20.116.17.175:55238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/water.php"] [unique_id "aoSB9f2v-lWn9OzQT7UX_AAAAMA"]
[Tue Aug 18 13:01:57.094104 2026] [security2:error] [pid 139043:tid 139297] [client 20.206.96.72:15251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/sagax1.php"] [unique_id "aoSB9f2v-lWn9OzQT7UX_QAAAQE"]
[Tue Aug 18 13:01:57.124031 2026] [security2:error] [pid 139043:tid 139239] [client 172.213.243.2:14339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/nzv.php"] [unique_id "aoSB9f2v-lWn9OzQT7UX_gAAAMc"]
[Tue Aug 18 13:01:57.151733 2026] [security2:error] [pid 139043:tid 139235] [client 158.158.74.177:9242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSB9f2v-lWn9OzQT7UX_wAAAMM"]
[Tue Aug 18 13:01:57.160175 2026] [security2:error] [pid 139043:tid 139282] [client 20.48.236.86:14802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/bengi.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYAAAAAPI"]
[Tue Aug 18 13:01:57.168135 2026] [security2:error] [pid 123784:tid 123973] [client 20.119.58.187:10204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/ultra.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMWAAAADc"]
[Tue Aug 18 13:01:57.185576 2026] [security2:error] [pid 139043:tid 139285] [client 20.29.77.16:13682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/222.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYAQAAAPU"]
[Tue Aug 18 13:01:57.186192 2026] [security2:error] [pid 139043:tid 139225] [client 20.79.204.6:12265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYAgAAALk"]
[Tue Aug 18 13:01:57.190297 2026] [security2:error] [pid 139043:tid 139241] [client 20.226.112.14:13677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/fleen.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYAwAAAMk"]
[Tue Aug 18 13:01:57.212055 2026] [security2:error] [pid 139043:tid 139288] [client 20.206.96.72:15236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wpc.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYBQAAAPg"]
[Tue Aug 18 13:01:57.213461 2026] [security2:error] [pid 123784:tid 123983] [client 20.79.204.6:10708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/w1.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMWQAAAEE"]
[Tue Aug 18 13:01:57.221132 2026] [security2:error] [pid 123784:tid 124035] [client 20.79.204.6:11841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMWgAAAHU"]
[Tue Aug 18 13:01:57.238360 2026] [security2:error] [pid 123784:tid 123898] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ry.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMXAAANW0"]
[Tue Aug 18 13:01:57.238391 2026] [security2:error] [pid 123784:tid 123986] [client 20.51.153.15:13670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/del.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMWwAAAEQ"]
[Tue Aug 18 13:01:57.268548 2026] [security2:error] [pid 123784:tid 123930] [client 20.206.96.72:15471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/fone1.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMXQAAAAw"]
[Tue Aug 18 13:01:57.277440 2026] [security2:error] [pid 139043:tid 139289] [client 20.104.100.201:49679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/222.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYBwAAAPk"]
[Tue Aug 18 13:01:57.279952 2026] [security2:error] [pid 139043:tid 139227] [client 132.196.30.78:1498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYCAAAALs"]
[Tue Aug 18 13:01:57.294264 2026] [security2:error] [pid 139043:tid 139195] [client 20.75.92.165:2036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/bolt.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYCgAAAJs"]
[Tue Aug 18 13:01:57.311335 2026] [security2:error] [pid 139043:tid 139205] [client 20.206.96.72:15460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/ncx.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYCwAAAKU"]
[Tue Aug 18 13:01:57.339094 2026] [security2:error] [pid 123784:tid 123936] [client 20.203.183.135:63412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMXwAAABI"]
[Tue Aug 18 13:01:57.340559 2026] [security2:error] [pid 139043:tid 139299] [client 20.206.96.72:15262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYDQAAAQM"]
[Tue Aug 18 13:01:57.342083 2026] [security2:error] [pid 139043:tid 139264] [client 20.151.109.219:39338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/lw.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYDgAAAOA"]
[Tue Aug 18 13:01:57.346760 2026] [security2:error] [pid 139043:tid 139279] [client 20.163.43.14:8888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/bb.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYDwAAAO8"]
[Tue Aug 18 13:01:57.372471 2026] [security2:error] [pid 139043:tid 139211] [client 20.206.96.72:16002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wso.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYEQAAAKs"]
[Tue Aug 18 13:01:57.388752 2026] [security2:error] [pid 139043:tid 139290] [client 20.251.112.238:54520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/error1.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYEwAAAPo"]
[Tue Aug 18 13:01:57.388774 2026] [security2:error] [pid 139043:tid 139228] [client 158.23.17.4:56530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ak.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYEgAAALw"]
[Tue Aug 18 13:01:57.394647 2026] [security2:error] [pid 139043:tid 139245] [client 20.226.112.14:32527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/e.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYFAAAAM0"]
[Tue Aug 18 13:01:57.418109 2026] [security2:error] [pid 123784:tid 124014] [client 52.139.47.57:28871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/jga.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMYQAAAGA"]
[Tue Aug 18 13:01:57.439051 2026] [authz_core:error] [pid 123784:tid 123810] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:57.439317 2026] [authz_core:error] [pid 123784:tid 123810] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:57.442550 2026] [security2:error] [pid 139043:tid 139250] [client 20.127.136.245:22153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/class-t.api.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYFgAAANI"]
[Tue Aug 18 13:01:57.473062 2026] [security2:error] [pid 123784:tid 123970] [client 20.51.153.15:13632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/moderator.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMYwAAADQ"]
[Tue Aug 18 13:01:57.490267 2026] [security2:error] [pid 123784:tid 124029] [client 158.23.17.4:15137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ey.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMZAAAAG8"]
[Tue Aug 18 13:01:57.494564 2026] [security2:error] [pid 123784:tid 123851] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/pm.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMZQAAMj4"]
[Tue Aug 18 13:01:57.509084 2026] [security2:error] [pid 139043:tid 139296] [client 20.206.96.72:15440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/zup.php73"] [unique_id "aoSB9f2v-lWn9OzQT7UYFwAAAQA"]
[Tue Aug 18 13:01:57.520554 2026] [security2:error] [pid 123784:tid 123939] [client 20.119.58.187:10182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/vv.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMZwAAABU"]
[Tue Aug 18 13:01:57.536435 2026] [security2:error] [pid 139043:tid 139208] [client 20.206.96.72:16010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/k.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYGQAAAKg"]
[Tue Aug 18 13:01:57.541013 2026] [security2:error] [pid 139043:tid 139251] [client 172.213.243.2:19881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/error1.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYGgAAANM"]
[Tue Aug 18 13:01:57.555861 2026] [security2:error] [pid 139043:tid 139278] [client 20.104.100.201:49422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-temp.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYHAAAAO4"]
[Tue Aug 18 13:01:57.558214 2026] [security2:error] [pid 139043:tid 139191] [client 20.206.96.72:15293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-blink.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYHQAAAJc"]
[Tue Aug 18 13:01:57.633544 2026] [security2:error] [pid 139043:tid 139243] [client 20.151.109.219:34009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/vj.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYIQAAAMs"]
[Tue Aug 18 13:01:57.650283 2026] [security2:error] [pid 123784:tid 124004] [client 68.155.154.236:8343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/dlvqo.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMbAAAAFY"]
[Tue Aug 18 13:01:57.681146 2026] [security2:error] [pid 139043:tid 139209] [client 20.206.96.72:15294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/ww5.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYJAAAAKk"]
[Tue Aug 18 13:01:57.681980 2026] [security2:error] [pid 139043:tid 139287] [client 20.163.43.14:8906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYJQAAAPc"]
[Tue Aug 18 13:01:57.687950 2026] [security2:error] [pid 139043:tid 139260] [client 20.29.77.16:62876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/routes.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYJgAAANw"]
[Tue Aug 18 13:01:57.708253 2026] [authz_core:error] [pid 139043:tid 139104] [remote 57.141.22.124:60816] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:57.708390 2026] [security2:error] [pid 139043:tid 139199] [client 20.226.112.14:38975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/hello.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYKQAAAJ8"]
[Tue Aug 18 13:01:57.708537 2026] [authz_core:error] [pid 139043:tid 139104] [remote 57.141.22.124:60816] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:57.715681 2026] [security2:error] [pid 139043:tid 139221] [client 135.225.78.186:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/img.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYKgAAALU"]
[Tue Aug 18 13:01:57.715729 2026] [security2:error] [pid 123784:tid 123911] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/dr.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMbQAAa3o"]
[Tue Aug 18 13:01:57.720529 2026] [security2:error] [pid 139043:tid 139185] [client 20.65.98.162:21928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/file61.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYKwAAAJE"]
[Tue Aug 18 13:01:57.733389 2026] [security2:error] [pid 123784:tid 123969] [client 20.206.96.72:15811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/2.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMbgAAADM"]
[Tue Aug 18 13:01:57.741911 2026] [security2:error] [pid 139043:tid 139216] [client 20.51.153.15:13662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/infoinfo.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYLgAAALA"]
[Tue Aug 18 13:01:57.744893 2026] [security2:error] [pid 139043:tid 139295] [client 20.91.215.254:11473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/maint.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYLwAAAP8"]
[Tue Aug 18 13:01:57.777405 2026] [security2:error] [pid 139043:tid 139188] [client 20.116.17.175:22990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/fine.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYMAAAAJQ"]
[Tue Aug 18 13:01:57.781111 2026] [security2:error] [pid 139043:tid 139212] [client 20.206.96.72:16023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYMQAAAKw"]
[Tue Aug 18 13:01:57.783597 2026] [security2:error] [pid 139043:tid 139179] [client 20.75.92.165:4245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/class-t.api.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYMgAAAIs"]
[Tue Aug 18 13:01:57.784216 2026] [security2:error] [pid 139043:tid 139226] [client 20.79.204.6:11840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYMwAAALo"]
[Tue Aug 18 13:01:57.802538 2026] [security2:error] [pid 139043:tid 139283] [client 158.158.74.177:10146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYNgAAAPM"]
[Tue Aug 18 13:01:57.814223 2026] [security2:error] [pid 123784:tid 124024] [client 20.206.96.72:15475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/atomlib.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMcAAAAGo"]
[Tue Aug 18 13:01:57.829972 2026] [security2:error] [pid 139043:tid 139291] [client 20.79.204.6:12243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-fclass.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYOAAAAPs"]
[Tue Aug 18 13:01:57.832778 2026] [security2:error] [pid 139043:tid 139238] [client 20.104.100.201:49103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/spadex.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYOQAAAMY"]
[Tue Aug 18 13:01:57.873969 2026] [security2:error] [pid 139043:tid 139277] [client 20.119.58.187:10183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/V5.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYOwAAAO0"]
[Tue Aug 18 13:01:57.874275 2026] [security2:error] [pid 123784:tid 123955] [client 20.127.136.245:21544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/edit.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMcgAAACU"]
[Tue Aug 18 13:01:57.876798 2026] [security2:error] [pid 139043:tid 139236] [client 20.48.236.86:14525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/file2.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYPAAAAMQ"]
[Tue Aug 18 13:01:57.907268 2026] [security2:error] [pid 139043:tid 139269] [client 52.139.47.57:18305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/166.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYPQAAAOU"]
[Tue Aug 18 13:01:57.907381 2026] [security2:error] [pid 139043:tid 139231] [client 20.226.112.14:32564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/brc.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYPgAAAL8"]
[Tue Aug 18 13:01:57.950106 2026] [security2:error] [pid 139043:tid 139289] [client 20.206.96.72:15469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/rip.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYQAAAAPk"]
[Tue Aug 18 13:01:57.953667 2026] [authz_core:error] [pid 123784:tid 123829] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:57.953770 2026] [security2:error] [pid 139043:tid 139227] [client 172.213.243.2:19766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/155.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYQQAAALs"]
[Tue Aug 18 13:01:57.953927 2026] [authz_core:error] [pid 123784:tid 123829] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:57.978257 2026] [security2:error] [pid 139043:tid 139206] [client 213.35.127.232:61582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYRQAAAKY"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:57.988366 2026] [security2:error] [pid 139043:tid 139242] [client 20.226.56.190:28265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/profiler.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYSQAAAMo"]
[Tue Aug 18 13:01:57.989033 2026] [security2:error] [pid 139043:tid 139200] [client 20.206.96.72:16050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/p.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYSgAAAKA"]
[Tue Aug 18 13:01:58.003998 2026] [security2:error] [pid 139043:tid 139290] [client 172.202.39.151:61730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYSwAAAPo"]
[Tue Aug 18 13:01:58.024460 2026] [security2:error] [pid 123784:tid 123992] [client 20.151.109.219:63942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/mimes.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMdQAAAEo"]
[Tue Aug 18 13:01:58.031227 2026] [security2:error] [pid 139043:tid 139250] [client 20.206.96.72:15244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/php.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYUAAAANI"]
[Tue Aug 18 13:01:58.081712 2026] [security2:error] [pid 139043:tid 139220] [client 223.185.37.47:25959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYUgAAALQ"]
[Tue Aug 18 13:01:58.081824 2026] [security2:error] [pid 139043:tid 139220] [client 223.185.37.47:25959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYUgAAALQ"]
[Tue Aug 18 13:01:58.117635 2026] [security2:error] [pid 139043:tid 139251] [client 20.104.100.201:49709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYVQAAANM"]
[Tue Aug 18 13:01:58.144545 2026] [security2:error] [pid 139043:tid 139270] [client 20.29.77.16:62899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/php5.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYVgAAAOY"]
[Tue Aug 18 13:01:58.159029 2026] [security2:error] [pid 139043:tid 139214] [client 20.51.153.15:13668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/c99shell.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYVwAAAK4"]
[Tue Aug 18 13:01:58.184105 2026] [security2:error] [pid 139043:tid 139191] [client 20.163.43.14:8939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYWAAAAJc"]
[Tue Aug 18 13:01:58.184818 2026] [security2:error] [pid 123784:tid 123923] [client 158.23.17.4:17569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/lv.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMdgAAAAU"]
[Tue Aug 18 13:01:58.208146 2026] [security2:error] [pid 139043:tid 139233] [client 20.226.112.14:22950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/file52.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYWgAAAME"]
[Tue Aug 18 13:01:58.209635 2026] [security2:error] [pid 123784:tid 123998] [client 20.75.92.165:4266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/edit.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMdwAAAFA"]
[Tue Aug 18 13:01:58.228890 2026] [security2:error] [pid 139043:tid 139244] [client 20.119.58.187:10128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-user.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYWwAAAMw"]
[Tue Aug 18 13:01:58.250027 2026] [authz_core:error] [pid 123784:tid 123848] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:58.250302 2026] [authz_core:error] [pid 123784:tid 123848] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:58.268586 2026] [security2:error] [pid 139043:tid 139192] [client 216.244.66.232:57830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYXAAAAJg"]
[Tue Aug 18 13:01:58.268678 2026] [security2:error] [pid 139043:tid 139192] [client 216.244.66.232:57830] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYXAAAAJg"]
[Tue Aug 18 13:01:58.281089 2026] [security2:error] [pid 123784:tid 123812] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ts.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMeQAASxc"]
[Tue Aug 18 13:01:58.328444 2026] [security2:error] [pid 123784:tid 123942] [client 52.139.47.57:3754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/log.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMegAAABg"]
[Tue Aug 18 13:01:58.358507 2026] [security2:error] [pid 139043:tid 139258] [client 20.116.17.175:55247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/loader.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYXgAAANo"]
[Tue Aug 18 13:01:58.368185 2026] [security2:error] [pid 139043:tid 139298] [client 172.213.243.2:5713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/fasx.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYXwAAAQI"]
[Tue Aug 18 13:01:58.380528 2026] [security2:error] [pid 123784:tid 123976] [client 20.48.236.86:14497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/gm.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMewAAADo"]
[Tue Aug 18 13:01:58.392624 2026] [security2:error] [pid 139043:tid 139213] [client 20.104.100.201:49125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/srontol.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYYwAAAK0"]
[Tue Aug 18 13:01:58.400337 2026] [security2:error] [pid 139043:tid 139223] [client 20.226.112.14:28558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/sxdfrt.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYZAAAALc"]
[Tue Aug 18 13:01:58.404323 2026] [security2:error] [pid 139043:tid 139199] [client 20.151.109.219:14275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ni.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYZQAAAJ8"]
[Tue Aug 18 13:01:58.412019 2026] [security2:error] [pid 123784:tid 124038] [client 20.51.153.15:13605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/profiler.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMfQAAAHg"]
[Tue Aug 18 13:01:58.462979 2026] [security2:error] [pid 123784:tid 123889] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/53.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMfgAAJGQ"]
[Tue Aug 18 13:01:58.464216 2026] [security2:error] [pid 123784:tid 123938] [client 158.158.74.177:9266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMfwAAABQ"]
[Tue Aug 18 13:01:58.466414 2026] [security2:error] [pid 139043:tid 139173] [client 68.221.73.131:62855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/indes.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYaQAAAIU"]
[Tue Aug 18 13:01:58.483908 2026] [security2:error] [pid 139043:tid 139184] [client 20.91.215.254:19416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/phpMailer.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYagAAAJA"]
[Tue Aug 18 13:01:58.514704 2026] [security2:error] [pid 139043:tid 139239] [client 132.196.30.78:19232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/aa.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYawAAAMc"]
[Tue Aug 18 13:01:58.515512 2026] [security2:error] [pid 139043:tid 139226] [client 20.163.43.14:8857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYbAAAALo"]
[Tue Aug 18 13:01:58.527255 2026] [security2:error] [pid 139043:tid 139201] [client 20.226.112.14:32562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/path.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYbQAAAKE"]
[Tue Aug 18 13:01:58.530129 2026] [security2:error] [pid 139043:tid 139283] [client 68.155.154.236:64177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/pkmoj.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYbgAAAPM"]
[Tue Aug 18 13:01:58.537098 2026] [security2:error] [pid 139043:tid 139235] [client 20.75.92.165:4250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/ff1.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYcAAAAMM"]
[Tue Aug 18 13:01:58.561165 2026] [security2:error] [pid 139043:tid 139219] [client 4.232.94.69:29635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/csv.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYcwAAALM"]
[Tue Aug 18 13:01:58.565852 2026] [security2:error] [pid 123784:tid 123945] [client 20.127.136.245:22189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/ff1.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMgwAAABs"]
[Tue Aug 18 13:01:58.580717 2026] [security2:error] [pid 139043:tid 139295] [client 20.119.58.187:10152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-blog.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYdAAAAP8"]
[Tue Aug 18 13:01:58.594037 2026] [security2:error] [pid 139043:tid 139241] [client 20.226.112.14:34194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wpo.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYdQAAAMk"]
[Tue Aug 18 13:01:58.661665 2026] [security2:error] [pid 139043:tid 139277] [client 20.51.153.15:13613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/findes.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYeQAAAO0"]
[Tue Aug 18 13:01:58.686774 2026] [security2:error] [pid 139043:tid 139174] [client 20.104.100.201:49100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/file5.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYegAAAIY"]
[Tue Aug 18 13:01:58.710024 2026] [security2:error] [pid 139043:tid 139300] [client 158.23.17.4:56556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/test_info.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYfAAAAQQ"]
[Tue Aug 18 13:01:58.712205 2026] [security2:error] [pid 139043:tid 139237] [client 158.23.17.4:58750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/51.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYfQAAAMU"]
[Tue Aug 18 13:01:58.728417 2026] [security2:error] [pid 139043:tid 139299] [client 20.29.77.16:64938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/Black.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYfgAAAQM"]
[Tue Aug 18 13:01:58.747157 2026] [security2:error] [pid 139043:tid 139271] [client 52.139.47.57:3790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/file.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYgAAAAOc"]
[Tue Aug 18 13:01:58.779408 2026] [security2:error] [pid 123784:tid 123897] [remote 129.121.48.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.48.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "altostima.com.br"] [uri "/wp-login.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMhAAAKmw"]
[Tue Aug 18 13:01:58.784067 2026] [security2:error] [pid 139043:tid 139190] [client 172.213.243.2:34400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp-good.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYgQAAAJY"]
[Tue Aug 18 13:01:58.800915 2026] [security2:error] [pid 139043:tid 139242] [client 158.23.17.4:44846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/gw.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYgwAAAMo"]
[Tue Aug 18 13:01:58.808657 2026] [security2:error] [pid 139043:tid 139200] [client 20.79.204.6:11654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYhAAAAKA"]
[Tue Aug 18 13:01:58.837263 2026] [security2:error] [pid 139043:tid 139228] [client 20.116.17.175:55295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/zero.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYhgAAALw"]
[Tue Aug 18 13:01:58.841960 2026] [security2:error] [pid 139043:tid 139273] [client 20.163.43.14:8952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/file.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYhwAAAOk"]
[Tue Aug 18 13:01:58.847121 2026] [security2:error] [pid 139043:tid 139259] [client 20.48.236.86:14464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/ws55.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYiAAAANs"]
[Tue Aug 18 13:01:58.850335 2026] [security2:error] [pid 139043:tid 139229] [client 20.79.204.6:12267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYiQAAAL0"]
[Tue Aug 18 13:01:58.852362 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:58.852619 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:58.854791 2026] [security2:error] [pid 139043:tid 139180] [client 20.151.109.219:14254] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "varandasgp.com.br"] [uri "/1.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYigAAAIw"]
[Tue Aug 18 13:01:58.854884 2026] [security2:error] [pid 139043:tid 139180] [client 20.151.109.219:14254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/1.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYigAAAIw"]
[Tue Aug 18 13:01:58.898604 2026] [security2:error] [pid 123784:tid 123931] [client 20.51.153.15:13580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/fedora.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMhgAAAA0"]
[Tue Aug 18 13:01:58.901136 2026] [security2:error] [pid 139043:tid 139207] [client 20.226.56.190:17875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/findes.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYiwAAAKc"]
[Tue Aug 18 13:01:58.926807 2026] [security2:error] [pid 139043:tid 139275] [client 20.226.112.14:39450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/a1vx.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYjQAAAOs"]
[Tue Aug 18 13:01:58.931901 2026] [security2:error] [pid 139043:tid 139248] [client 20.119.58.187:10222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYjwAAANA"]
[Tue Aug 18 13:01:58.959765 2026] [security2:error] [pid 139043:tid 139270] [client 132.196.30.78:30701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYkQAAAOY"]
[Tue Aug 18 13:01:58.965341 2026] [security2:error] [pid 139043:tid 139284] [client 20.104.100.201:49127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/yup.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYkgAAAPQ"]
[Tue Aug 18 13:01:58.991900 2026] [security2:error] [pid 139043:tid 139272] [client 213.35.127.232:61803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYkwAAAOg"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:01:58.998476 2026] [security2:error] [pid 139043:tid 139278] [client 20.226.112.14:28762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ty.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYlAAAAO4"]
[Tue Aug 18 13:01:59.010697 2026] [security2:error] [pid 123784:tid 123999] [client 172.202.39.151:47683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-good.php"] [unique_id "aoSB92wDnJBNj2tDbYYMiQAAAFE"]
[Tue Aug 18 13:01:59.058537 2026] [security2:error] [pid 139043:tid 139280] [client 20.251.112.238:33939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/155.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYmQAAAPA"]
[Tue Aug 18 13:01:59.111303 2026] [security2:error] [pid 139043:tid 139081] [remote 203.99.146.53:35660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/wp-login.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYnAAAziU"]
[Tue Aug 18 13:01:59.114368 2026] [security2:error] [pid 139043:tid 139217] [client 20.203.183.135:51422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/yj09.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYnQAAALE"]
[Tue Aug 18 13:01:59.125108 2026] [security2:error] [pid 139043:tid 139196] [client 172.202.39.151:40346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYnwAAAJw"]
[Tue Aug 18 13:01:59.136022 2026] [security2:error] [pid 139043:tid 139296] [client 20.91.215.254:27076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYoAAAAQA"]
[Tue Aug 18 13:01:59.145291 2026] [security2:error] [pid 139043:tid 139181] [client 68.155.154.236:63588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/kopyw.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYoQAAAI0"]
[Tue Aug 18 13:01:59.147903 2026] [security2:error] [pid 123784:tid 124034] [client 20.51.153.15:13589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/path.php"] [unique_id "aoSB92wDnJBNj2tDbYYMjAAAAHQ"]
[Tue Aug 18 13:01:59.153923 2026] [authz_core:error] [pid 123784:tid 123905] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:59.154179 2026] [authz_core:error] [pid 123784:tid 123905] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:59.185667 2026] [security2:error] [pid 123784:tid 124002] [client 20.75.92.165:4249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/fff.php"] [unique_id "aoSB92wDnJBNj2tDbYYMjQAAAFQ"]
[Tue Aug 18 13:01:59.195363 2026] [security2:error] [pid 139043:tid 139215] [client 20.163.43.14:8877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/epinyins.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYpAAAAK8"]
[Tue Aug 18 13:01:59.195964 2026] [security2:error] [pid 139043:tid 139185] [client 20.226.112.14:28573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/vgtyu.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYpQAAAJE"]
[Tue Aug 18 13:01:59.201637 2026] [security2:error] [pid 139043:tid 139256] [client 172.213.243.2:48330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/zxin.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYpgAAANg"]
[Tue Aug 18 13:01:59.227126 2026] [security2:error] [pid 139043:tid 139173] [client 172.202.39.151:4240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/xmlrpc.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYpwAAAIU"]
[Tue Aug 18 13:01:59.232713 2026] [security2:error] [pid 139043:tid 139193] [client 20.29.77.16:16561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/filesystems.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYqAAAAJk"]
[Tue Aug 18 13:01:59.236917 2026] [security2:error] [pid 139043:tid 139184] [client 20.104.100.201:49130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/classwithtostring.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYqQAAAJA"]
[Tue Aug 18 13:01:59.254949 2026] [security2:error] [pid 123784:tid 124031] [client 52.139.47.57:17990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/bolt.php"] [unique_id "aoSB92wDnJBNj2tDbYYMjwAAAHE"]
[Tue Aug 18 13:01:59.255143 2026] [security2:error] [pid 139043:tid 139179] [client 20.79.204.6:10389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-login.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYqgAAAIs"]
[Tue Aug 18 13:01:59.276877 2026] [security2:error] [pid 123784:tid 124008] [client 20.151.109.219:63994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/88.php"] [unique_id "aoSB92wDnJBNj2tDbYYMkAAAAFo"]
[Tue Aug 18 13:01:59.283446 2026] [security2:error] [pid 139043:tid 139251] [client 158.158.74.177:10163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/abc.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYqwAAANM"]
[Tue Aug 18 13:01:59.284752 2026] [security2:error] [pid 139043:tid 139262] [client 20.119.58.187:10217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/worksec.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYrAAAAN4"]
[Tue Aug 18 13:01:59.331427 2026] [security2:error] [pid 139043:tid 139219] [client 158.23.17.4:48409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/14.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYrwAAALM"]
[Tue Aug 18 13:01:59.341229 2026] [security2:error] [pid 139043:tid 139295] [client 20.226.112.14:28741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/mans.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYsAAAAP8"]
[Tue Aug 18 13:01:59.367666 2026] [security2:error] [pid 139043:tid 139222] [client 20.127.136.245:3529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/fff.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYsQAAALY"]
[Tue Aug 18 13:01:59.375359 2026] [security2:error] [pid 139043:tid 139253] [client 20.116.17.175:23032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/002.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYswAAANU"]
[Tue Aug 18 13:01:59.405700 2026] [security2:error] [pid 139043:tid 139285] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYsgAA9QQ"]
[Tue Aug 18 13:01:59.416386 2026] [security2:error] [pid 139043:tid 139216] [client 20.79.204.6:12234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYtQAAALA"]
[Tue Aug 18 13:01:59.421525 2026] [security2:error] [pid 139043:tid 139182] [client 20.226.112.14:34214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/co.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYtgAAAI4"]
[Tue Aug 18 13:01:59.457993 2026] [security2:error] [pid 139043:tid 139239] [client 20.79.204.6:12281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYuAAAAMc"]
[Tue Aug 18 13:01:59.457994 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:01:59.458475 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:01:59.464652 2026] [security2:error] [pid 139043:tid 139299] [client 20.226.56.190:17870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/fedora.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYuQAAAQM"]
[Tue Aug 18 13:01:59.472117 2026] [security2:error] [pid 139043:tid 139271] [client 132.196.30.78:4579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/about.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYuwAAAOc"]
[Tue Aug 18 13:01:59.479434 2026] [security2:error] [pid 139043:tid 139206] [client 20.48.236.86:14820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/m.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYvAAAAKY"]
[Tue Aug 18 13:01:59.484035 2026] [security2:error] [pid 123784:tid 124042] [client 20.75.92.165:4226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/inputs.php"] [unique_id "aoSB92wDnJBNj2tDbYYMkgAAAHw"]
[Tue Aug 18 13:01:59.500198 2026] [security2:error] [pid 139043:tid 139242] [client 20.226.112.14:28545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/btx25.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYvQAAAMo"]
[Tue Aug 18 13:01:59.512045 2026] [security2:error] [pid 139043:tid 139279] [client 20.104.100.201:49110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-the.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYvgAAAO8"]
[Tue Aug 18 13:01:59.521650 2026] [security2:error] [pid 139043:tid 139273] [client 20.51.153.15:13656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/456.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYvwAAAOk"]
[Tue Aug 18 13:01:59.523931 2026] [security2:error] [pid 139043:tid 139229] [client 20.163.43.14:8782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYwAAAAL0"]
[Tue Aug 18 13:01:59.547666 2026] [security2:error] [pid 139043:tid 139180] [client 20.226.112.14:38965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/avim.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYwQAAAIw"]
[Tue Aug 18 13:01:59.569654 2026] [security2:error] [pid 139043:tid 139207] [client 68.155.154.236:45853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/zznmg.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYwwAAAKc"]
[Tue Aug 18 13:01:59.571464 2026] [security2:error] [pid 139043:tid 139197] [client 20.151.109.219:14306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/hj.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYxAAAAJ0"]
[Tue Aug 18 13:01:59.590504 2026] [security2:error] [pid 139043:tid 139208] [client 196.12.128.158:57314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYxQAAAKg"]
[Tue Aug 18 13:01:59.592753 2026] [security2:error] [pid 139043:tid 139208] [client 196.12.128.158:57314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYxQAAAKg"]
[Tue Aug 18 13:01:59.593879 2026] [security2:error] [pid 139043:tid 139248] [client 216.244.66.232:57838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYxwAAANA"]
[Tue Aug 18 13:01:59.593994 2026] [security2:error] [pid 139043:tid 139248] [client 216.244.66.232:57838] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYxwAAANA"]
[Tue Aug 18 13:01:59.618487 2026] [security2:error] [pid 139043:tid 139233] [client 172.213.243.2:14558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/pass4.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYyAAAAME"]
[Tue Aug 18 13:01:59.634851 2026] [security2:error] [pid 139043:tid 139228] [client 20.119.58.187:9750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-themes.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYygAAALw"]
[Tue Aug 18 13:01:59.668573 2026] [security2:error] [pid 139043:tid 139269] [client 213.202.253.4:56435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/filefuns.php"] [unique_id "aoSB9_2v-lWn9OzQT7UY2AAAAOU"], referer: www.google.com
[Tue Aug 18 13:01:59.683924 2026] [security2:error] [pid 123784:tid 123977] [client 197.184.64.235:41966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB92wDnJBNj2tDbYYMlAAAADs"]
[Tue Aug 18 13:01:59.684024 2026] [security2:error] [pid 123784:tid 123977] [client 197.184.64.235:41966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB92wDnJBNj2tDbYYMlAAAADs"]
[Tue Aug 18 13:01:59.689606 2026] [security2:error] [pid 139043:tid 139280] [client 20.226.112.14:38921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/myfile.php"] [unique_id "aoSB9_2v-lWn9OzQT7UY9wAAAPA"]
[Tue Aug 18 13:01:59.701115 2026] [security2:error] [pid 139043:tid 139245] [client 52.139.47.57:60573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/item.php"] [unique_id "aoSB9_2v-lWn9OzQT7UY-AAAAM0"]
[Tue Aug 18 13:01:59.754731 2026] [security2:error] [pid 139043:tid 139217] [client 20.226.112.14:39476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/xmy.php"] [unique_id "aoSB9_2v-lWn9OzQT7UY-gAAALE"]
[Tue Aug 18 13:01:59.770675 2026] [security2:error] [pid 123784:tid 123983] [client 20.38.3.247:5070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/img.php"] [unique_id "aoSB92wDnJBNj2tDbYYMlgAAAEE"]
[Tue Aug 18 13:01:59.778534 2026] [security2:error] [pid 123784:tid 124005] [client 20.51.153.15:13687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/SMTP.php"] [unique_id "aoSB92wDnJBNj2tDbYYMlwAAAFc"]
[Tue Aug 18 13:01:59.783456 2026] [security2:error] [pid 123784:tid 124041] [client 20.29.77.16:40515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/showphpinfo.php"] [unique_id "aoSB92wDnJBNj2tDbYYMmAAAAHs"]
[Tue Aug 18 13:01:59.789772 2026] [security2:error] [pid 123784:tid 124035] [client 20.104.100.201:49994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/cong.php"] [unique_id "aoSB92wDnJBNj2tDbYYMmQAAAHU"]
[Tue Aug 18 13:01:59.815629 2026] [security2:error] [pid 123784:tid 123986] [client 20.48.236.86:14507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/33.php"] [unique_id "aoSB92wDnJBNj2tDbYYMmgAAAEQ"]
[Tue Aug 18 13:01:59.867378 2026] [security2:error] [pid 139043:tid 139175] [client 158.23.17.4:11432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/tk.php"] [unique_id "aoSB9_2v-lWn9OzQT7UY_wAAAIc"]
[Tue Aug 18 13:01:59.870108 2026] [security2:error] [pid 139043:tid 139214] [client 20.91.215.254:19427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/al.php"] [unique_id "aoSB9_2v-lWn9OzQT7UZAAAAAK4"]
[Tue Aug 18 13:01:59.888954 2026] [security2:error] [pid 139043:tid 139266] [client 135.225.78.186:47380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/222.php"] [unique_id "aoSB9_2v-lWn9OzQT7UZAQAAAOI"]
[Tue Aug 18 13:01:59.899187 2026] [security2:error] [pid 139043:tid 139215] [client 20.75.92.165:4328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB9_2v-lWn9OzQT7UZAgAAAK8"]
[Tue Aug 18 13:01:59.912933 2026] [security2:error] [pid 123784:tid 123934] [client 158.158.74.177:18988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/sf.php"] [unique_id "aoSB92wDnJBNj2tDbYYMmwAAABA"]
[Tue Aug 18 13:01:59.934704 2026] [security2:error] [pid 123784:tid 124023] [client 132.196.30.78:35541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/goods.php"] [unique_id "aoSB92wDnJBNj2tDbYYMnAAAAGk"]
[Tue Aug 18 13:01:59.947846 2026] [security2:error] [pid 139043:tid 139078] [remote 162.214.205.212:51836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/wp-login.php"] [unique_id "aoSB9_2v-lWn9OzQT7UZBwABASI"]
[Tue Aug 18 13:01:59.952473 2026] [security2:error] [pid 123784:tid 123965] [client 20.151.109.219:14100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ij.php"] [unique_id "aoSB92wDnJBNj2tDbYYMnQAAAC8"]
[Tue Aug 18 13:01:59.969806 2026] [security2:error] [pid 139043:tid 139193] [client 20.116.17.175:22913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/zxz.php"] [unique_id "aoSB9_2v-lWn9OzQT7UZCAAAAJk"]
[Tue Aug 18 13:02:00.004897 2026] [security2:error] [pid 139043:tid 139221] [client 20.119.58.187:10154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-signin.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZJAAAALU"]
[Tue Aug 18 13:02:00.009892 2026] [security2:error] [pid 123784:tid 124020] [client 213.35.127.232:62005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMngAAAGY"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:02:00.020540 2026] [security2:error] [pid 139043:tid 139226] [client 20.226.112.14:22973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/xda.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZJgAAALo"]
[Tue Aug 18 13:02:00.032462 2026] [security2:error] [pid 123784:tid 123952] [client 172.213.243.2:16679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMoAAAACI"]
[Tue Aug 18 13:02:00.035075 2026] [security2:error] [pid 139043:tid 139255] [client 20.163.43.14:8859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZJwAAANc"]
[Tue Aug 18 13:02:00.035083 2026] [security2:error] [pid 123784:tid 123991] [client 20.51.153.15:13638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/vbseo.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMoQAAAEk"]
[Tue Aug 18 13:02:00.068166 2026] [security2:error] [pid 139043:tid 139199] [client 68.155.154.236:9180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/bhfnd.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZKQAAAJ8"]
[Tue Aug 18 13:02:00.073584 2026] [security2:error] [pid 139043:tid 139276] [client 20.104.100.201:49140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/xwpg.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZKgAAAOw"]
[Tue Aug 18 13:02:00.077795 2026] [security2:error] [pid 123784:tid 123941] [client 161.118.206.101:55082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.206.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-login.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMowAAABc"]
[Tue Aug 18 13:02:00.107454 2026] [security2:error] [pid 139043:tid 139241] [client 20.226.112.14:22928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/zz.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZLQAAAMk"]
[Tue Aug 18 13:02:00.108854 2026] [security2:error] [pid 139043:tid 139198] [client 68.155.154.236:8878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZLgAAAJ4"]
[Tue Aug 18 13:02:00.117047 2026] [security2:error] [pid 123784:tid 123800] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/lq.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMpAAANAs"]
[Tue Aug 18 13:02:00.131401 2026] [security2:error] [pid 139043:tid 139234] [client 20.226.112.14:28791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/xa.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZLwAAAMI"]
[Tue Aug 18 13:02:00.136885 2026] [security2:error] [pid 139043:tid 139231] [client 158.23.17.4:20220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/sw.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZMAAAAL8"]
[Tue Aug 18 13:02:00.191060 2026] [security2:error] [pid 139043:tid 139285] [client 20.75.92.165:2034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/lite.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZMQAAAPU"]
[Tue Aug 18 13:02:00.192516 2026] [security2:error] [pid 123784:tid 123962] [client 20.29.77.16:47349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/phpstatus.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMpQAAACw"]
[Tue Aug 18 13:02:00.215693 2026] [security2:error] [pid 123784:tid 123980] [client 20.226.112.14:34207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/f6.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMpgAAAD4"]
[Tue Aug 18 13:02:00.219255 2026] [security2:error] [pid 139043:tid 139254] [client 52.139.47.57:60549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/sid3.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZNQAAANY"]
[Tue Aug 18 13:02:00.222072 2026] [security2:error] [pid 123784:tid 123951] [client 20.79.204.6:11858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMpwAAACE"]
[Tue Aug 18 13:02:00.243175 2026] [security2:error] [pid 123784:tid 124004] [client 20.127.136.245:3863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/inputs.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMqAAAAFY"]
[Tue Aug 18 13:02:00.263164 2026] [security2:error] [pid 139043:tid 139271] [client 20.79.204.6:11852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZNwAAAOc"]
[Tue Aug 18 13:02:00.273377 2026] [security2:error] [pid 139043:tid 139190] [client 20.151.109.219:16262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ud.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZQAAAAJY"]
[Tue Aug 18 13:02:00.291033 2026] [security2:error] [pid 123784:tid 123969] [client 20.48.236.86:14841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/packed.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMqQAAADM"]
[Tue Aug 18 13:02:00.298739 2026] [security2:error] [pid 139043:tid 139250] [client 20.51.153.15:5075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/sysinfo.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZQgAAANI"]
[Tue Aug 18 13:02:00.302762 2026] [security2:error] [pid 123784:tid 124022] [client 20.226.112.14:29889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/mcs.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMqgAAAGg"]
[Tue Aug 18 13:02:00.312300 2026] [security2:error] [pid 123784:tid 123996] [client 4.232.94.69:37548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/404.php123123"] [unique_id "aoSB-GwDnJBNj2tDbYYMqwAAAE4"]
[Tue Aug 18 13:02:00.324180 2026] [security2:error] [pid 139043:tid 139259] [client 168.62.48.100:5510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZQwAAANs"]
[Tue Aug 18 13:02:00.327230 2026] [security2:error] [pid 139043:tid 139273] [client 20.226.112.14:38933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/xleet.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZRAAAAOk"]
[Tue Aug 18 13:02:00.357824 2026] [security2:error] [pid 139043:tid 139281] [client 20.119.58.187:10209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZSAAAAPE"]
[Tue Aug 18 13:02:00.359845 2026] [security2:error] [pid 123784:tid 123964] [client 20.104.100.201:49720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/dex.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMrQAAAC4"]
[Tue Aug 18 13:02:00.360841 2026] [security2:error] [pid 123784:tid 123891] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/you.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMrgAATWY"]
[Tue Aug 18 13:02:00.361920 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:02:00.362319 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:02:00.364235 2026] [security2:error] [pid 139043:tid 139275] [client 20.163.43.14:8858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZTAAAAOs"]
[Tue Aug 18 13:02:00.365502 2026] [security2:error] [pid 139043:tid 139208] [client 20.251.112.238:7170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/fasx.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZTQAAAKg"]
[Tue Aug 18 13:02:00.421789 2026] [security2:error] [pid 123784:tid 123924] [client 20.226.112.14:32552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/fr/ms.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMrwAAAAY"]
[Tue Aug 18 13:02:00.436480 2026] [security2:error] [pid 139043:tid 139278] [client 132.196.30.78:9383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/php8.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZUAAAAO4"]
[Tue Aug 18 13:02:00.453762 2026] [security2:error] [pid 139043:tid 139244] [client 172.213.243.2:16856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/z.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZUwAAAMw"]
[Tue Aug 18 13:02:00.453791 2026] [security2:error] [pid 139043:tid 139293] [client 68.155.154.236:64145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/qfvqu.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZVAAAAP0"]
[Tue Aug 18 13:02:00.522444 2026] [security2:error] [pid 123784:tid 123920] [client 158.23.17.4:47644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/hp.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMsAAAAAI"]
[Tue Aug 18 13:02:00.549386 2026] [security2:error] [pid 139043:tid 139200] [client 20.91.215.254:19408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZWAAAAKA"]
[Tue Aug 18 13:02:00.550323 2026] [security2:error] [pid 139043:tid 139288] [client 20.79.204.6:10749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/default.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZWQAAAPg"]
[Tue Aug 18 13:02:00.552108 2026] [security2:error] [pid 123784:tid 123894] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ez.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMsQAAWGk"]
[Tue Aug 18 13:02:00.552113 2026] [security2:error] [pid 139043:tid 139282] [client 158.158.74.177:18951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/chosen.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZWgAAAPI"]
[Tue Aug 18 13:02:00.557430 2026] [security2:error] [pid 123784:tid 123992] [client 20.75.92.165:4288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/ms-edit.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMsgAAAEo"]
[Tue Aug 18 13:02:00.563613 2026] [security2:error] [pid 123784:tid 124019] [client 20.151.109.219:37256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ip.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMswAAAGU"]
[Tue Aug 18 13:02:00.571560 2026] [security2:error] [pid 123784:tid 123923] [client 20.51.153.15:13601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/ppinfo.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMtAAAAAU"]
[Tue Aug 18 13:02:00.594203 2026] [security2:error] [pid 139043:tid 139258] [client 172.202.39.151:63720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/tes.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZXQAAANo"]
[Tue Aug 18 13:02:00.598780 2026] [security2:error] [pid 139043:tid 139245] [client 20.116.17.175:22966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/memberfuns.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZXgAAAM0"]
[Tue Aug 18 13:02:00.599216 2026] [security2:error] [pid 123784:tid 124043] [client 114.119.158.31:63353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "casacorba.com.br"] [uri "/blog"] [unique_id "aoSB-GwDnJBNj2tDbYYMtQAAAH0"], referer: https://casacorba.com.br/verificacao
[Tue Aug 18 13:02:00.600836 2026] [security2:error] [pid 123784:tid 123957] [client 68.155.154.236:53687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMtgAAACc"]
[Tue Aug 18 13:02:00.603429 2026] [security2:error] [pid 123784:tid 123956] [client 68.221.73.131:41608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/tTPcH.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMtwAAACY"]
[Tue Aug 18 13:02:00.628417 2026] [security2:error] [pid 123784:tid 123993] [client 20.226.112.14:28555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/gool.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMuAAAAEs"]
[Tue Aug 18 13:02:00.635456 2026] [security2:error] [pid 123784:tid 123981] [client 20.104.100.201:49689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/xyn.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMuQAAAD8"]
[Tue Aug 18 13:02:00.641507 2026] [security2:error] [pid 139043:tid 139246] [client 20.226.112.14:28742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/maxro.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZXwAAAM4"]
[Tue Aug 18 13:02:00.661081 2026] [authz_core:error] [pid 123784:tid 123873] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:02:00.661345 2026] [authz_core:error] [pid 123784:tid 123873] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:02:00.671803 2026] [security2:error] [pid 123784:tid 123976] [client 20.226.112.14:34233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wdf.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMuwAAADo"]
[Tue Aug 18 13:02:00.673550 2026] [security2:error] [pid 139043:tid 139287] [client 20.203.183.135:58149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/scxy.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZYQAAAPc"]
[Tue Aug 18 13:02:00.679912 2026] [security2:error] [pid 123784:tid 123997] [client 158.23.17.4:46575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ew.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMvAAAAE8"]
[Tue Aug 18 13:02:00.684762 2026] [security2:error] [pid 123784:tid 124038] [client 20.226.112.14:22849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ff1.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMvQAAAHg"]
[Tue Aug 18 13:02:00.692871 2026] [security2:error] [pid 123784:tid 123982] [client 20.163.43.14:8777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMvgAAAEA"]
[Tue Aug 18 13:02:00.701605 2026] [security2:error] [pid 123784:tid 124030] [client 20.65.98.162:25389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/copypaths.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMwAAAAHA"]
[Tue Aug 18 13:02:00.705912 2026] [security2:error] [pid 123784:tid 123946] [client 158.23.17.4:34125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/gc.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMwgAAABw"]
[Tue Aug 18 13:02:00.708470 2026] [security2:error] [pid 139043:tid 139296] [client 20.226.112.14:13043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/guk.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZYwAAAQA"]
[Tue Aug 18 13:02:00.780950 2026] [security2:error] [pid 139043:tid 139291] [client 52.139.47.57:18356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/size.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZZwAAAPs"]
[Tue Aug 18 13:02:00.799088 2026] [security2:error] [pid 123784:tid 123931] [client 216.244.66.232:57850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMwwAAAA0"]
[Tue Aug 18 13:02:00.799191 2026] [security2:error] [pid 123784:tid 123931] [client 216.244.66.232:57850] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMwwAAAA0"]
[Tue Aug 18 13:02:00.810519 2026] [security2:error] [pid 123784:tid 123935] [client 20.51.153.15:13669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/globals.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMxAAAABE"]
[Tue Aug 18 13:02:00.816702 2026] [security2:error] [pid 139043:tid 139185] [client 20.226.112.14:39433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-the.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZaAAAAJE"]
[Tue Aug 18 13:02:00.845907 2026] [security2:error] [pid 139043:tid 139173] [client 20.226.56.190:20384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/path.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZagAAAIU"]
[Tue Aug 18 13:02:00.866121 2026] [security2:error] [pid 139043:tid 139297] [client 172.213.243.2:19556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/222.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZawAAAQE"]
[Tue Aug 18 13:02:00.879541 2026] [security2:error] [pid 139043:tid 139193] [client 20.226.112.14:28553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/sbhu.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZcQAAAJk"]
[Tue Aug 18 13:02:00.912534 2026] [security2:error] [pid 139043:tid 139179] [client 20.104.100.201:49453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZcgAAAIs"]
[Tue Aug 18 13:02:00.931419 2026] [security2:error] [pid 123784:tid 124009] [client 20.151.109.219:14138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/99.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMxwAAAFs"]
[Tue Aug 18 13:02:00.931470 2026] [security2:error] [pid 123784:tid 124034] [client 20.226.112.14:29915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/zc-318.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMyAAAAHQ"]
[Tue Aug 18 13:02:00.952357 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.112.14:28607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ccou.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMyQAAAEc"]
[Tue Aug 18 13:02:00.956963 2026] [security2:error] [pid 139043:tid 139201] [client 20.116.17.175:55251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/aa.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZdgAAAKE"]
[Tue Aug 18 13:02:00.961875 2026] [authz_core:error] [pid 123784:tid 123792] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:02:00.962170 2026] [authz_core:error] [pid 123784:tid 123792] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:02:00.989902 2026] [security2:error] [pid 123784:tid 124001] [client 20.29.77.16:47350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/del.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMzAAAAFM"]
[Tue Aug 18 13:02:00.992412 2026] [security2:error] [pid 123784:tid 124008] [client 20.116.17.175:56076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/img.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMzQAAAFo"]
[Tue Aug 18 13:02:01.004580 2026] [security2:error] [pid 123784:tid 123953] [client 172.202.39.151:4699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/moon.php"] [unique_id "aoSB-WwDnJBNj2tDbYYMzgAAACM"]
[Tue Aug 18 13:02:01.014131 2026] [security2:error] [pid 123784:tid 124010] [client 20.226.112.14:39431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/txets.php"] [unique_id "aoSB-WwDnJBNj2tDbYYMzwAAAFw"]
[Tue Aug 18 13:02:01.024231 2026] [security2:error] [pid 123784:tid 124042] [client 20.163.43.14:8925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/function/function.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM0AAAAHw"]
[Tue Aug 18 13:02:01.028205 2026] [security2:error] [pid 123784:tid 123977] [client 20.79.204.6:12239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM0QAAADs"]
[Tue Aug 18 13:02:01.028376 2026] [security2:error] [pid 123784:tid 123938] [client 213.35.127.232:62201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM0gAAABQ"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:02:01.036838 2026] [security2:error] [pid 123784:tid 123983] [client 172.202.39.151:53701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/files/index.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM0wAAAEE"]
[Tue Aug 18 13:02:01.052190 2026] [security2:error] [pid 139043:tid 139283] [client 20.226.112.14:22916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/fun.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZeAAAAPM"]
[Tue Aug 18 13:02:01.069172 2026] [security2:error] [pid 123784:tid 124005] [client 20.75.92.165:4301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/rip.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM1AAAAFc"]
[Tue Aug 18 13:02:01.075831 2026] [security2:error] [pid 139043:tid 139241] [client 20.79.204.6:12242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZegAAAMk"]
[Tue Aug 18 13:02:01.088433 2026] [security2:error] [pid 123784:tid 124035] [client 20.251.112.238:59061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wp-good.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM1QAAAHU"]
[Tue Aug 18 13:02:01.090713 2026] [security2:error] [pid 123784:tid 123986] [client 158.23.17.4:48428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/wx.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM1gAAAEQ"]
[Tue Aug 18 13:02:01.096829 2026] [security2:error] [pid 139043:tid 139277] [client 68.155.154.236:65438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/weozh.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZewAAAO0"]
[Tue Aug 18 13:02:01.097917 2026] [security2:error] [pid 139043:tid 139253] [client 20.127.136.245:22945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZfAAAANU"]
[Tue Aug 18 13:02:01.099256 2026] [security2:error] [pid 139043:tid 139236] [client 20.51.153.15:5095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/yindu.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZfQAAAMQ"]
[Tue Aug 18 13:02:01.125244 2026] [security2:error] [pid 139043:tid 139187] [client 20.119.58.187:10471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/ws.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZfwAAAJM"]
[Tue Aug 18 13:02:01.140581 2026] [security2:error] [pid 123784:tid 123816] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/asus.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM1wAADBs"]
[Tue Aug 18 13:02:01.142408 2026] [security2:error] [pid 123784:tid 123934] [client 132.196.30.78:21259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/info.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM2AAAABA"]
[Tue Aug 18 13:02:01.180131 2026] [security2:error] [pid 123784:tid 124023] [client 20.226.112.14:38948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/jq.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM2QAAAGk"]
[Tue Aug 18 13:02:01.187018 2026] [security2:error] [pid 123784:tid 123936] [client 20.104.100.201:49121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-good.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM2gAAABI"]
[Tue Aug 18 13:02:01.222095 2026] [security2:error] [pid 139043:tid 139220] [client 68.155.154.236:9157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/oivcl.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZggAAALQ"]
[Tue Aug 18 13:02:01.222640 2026] [security2:error] [pid 139043:tid 139199] [client 20.91.215.254:11490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-activat.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZgwAAAJ8"]
[Tue Aug 18 13:02:01.230459 2026] [security2:error] [pid 123784:tid 123932] [client 158.158.74.177:18985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/u.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM2wAAAA4"]
[Tue Aug 18 13:02:01.242499 2026] [security2:error] [pid 139043:tid 139234] [client 52.139.47.57:39566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/tgrs.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZhAAAAMI"]
[Tue Aug 18 13:02:01.267486 2026] [security2:error] [pid 123784:tid 124018] [client 88.99.80.227:49728] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.melocorretordeimoveis.com.br"] [uri "/"] [unique_id "aoSB-WwDnJBNj2tDbYYM3QAAAGQ"], referer: http://www.melocorretordeimoveis.com.br
[Tue Aug 18 13:02:01.272565 2026] [security2:error] [pid 139043:tid 139300] [client 20.226.112.14:28784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/sys.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZhQAAAQQ"]
[Tue Aug 18 13:02:01.279120 2026] [security2:error] [pid 139043:tid 139254] [client 172.213.243.2:14544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/G-in.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZhgAAANY"]
[Tue Aug 18 13:02:01.316495 2026] [security2:error] [pid 123784:tid 123850] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/22.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM3gAAMj0"]
[Tue Aug 18 13:02:01.337422 2026] [security2:error] [pid 139043:tid 139239] [client 20.51.153.15:4995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/sxx.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZiQAAAMc"]
[Tue Aug 18 13:02:01.353687 2026] [security2:error] [pid 123784:tid 124032] [client 158.23.17.4:17576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/pqr.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM3wAAAHI"]
[Tue Aug 18 13:02:01.362166 2026] [security2:error] [pid 123784:tid 124025] [client 20.163.43.14:8933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM4AAAAGs"]
[Tue Aug 18 13:02:01.363334 2026] [security2:error] [pid 139043:tid 139271] [client 52.173.121.69:9485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZigAAAOc"]
[Tue Aug 18 13:02:01.372383 2026] [security2:error] [pid 123784:tid 123969] [client 20.75.92.165:4292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/update/da222.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM4QAAADM"]
[Tue Aug 18 13:02:01.391422 2026] [security2:error] [pid 139043:tid 139259] [client 20.226.112.14:22855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/pp.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZiwAAANs"]
[Tue Aug 18 13:02:01.399180 2026] [security2:error] [pid 123784:tid 124022] [client 20.151.109.219:24400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/er.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM4gAAAGg"]
[Tue Aug 18 13:02:01.458223 2026] [security2:error] [pid 139043:tid 139281] [client 20.116.17.175:22922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/echkm.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZjQAAAPE"]
[Tue Aug 18 13:02:01.463373 2026] [security2:error] [pid 139043:tid 139197] [client 20.226.112.14:28584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wqqs.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZjwAAAJ0"]
[Tue Aug 18 13:02:01.465794 2026] [security2:error] [pid 123784:tid 124011] [client 20.104.100.201:50003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wmore1.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM4wAAAF0"]
[Tue Aug 18 13:02:01.467681 2026] [authz_core:error] [pid 139043:tid 139299] [client 192.178.4.134:56975] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:02:01.467981 2026] [authz_core:error] [pid 139043:tid 139299] [client 192.178.4.134:56975] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:02:01.478598 2026] [security2:error] [pid 123784:tid 123951] [client 20.119.58.187:10173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wsa.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM5AAAACE"]
[Tue Aug 18 13:02:01.495673 2026] [security2:error] [pid 123784:tid 123926] [client 20.226.112.14:28761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/clasa99.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM5QAAAAg"]
[Tue Aug 18 13:02:01.525172 2026] [security2:error] [pid 123784:tid 123859] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/zs.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM5gAATUY"]
[Tue Aug 18 13:02:01.547684 2026] [security2:error] [pid 139043:tid 139203] [client 20.29.77.16:40547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/moderator.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZnQAAAKM"]
[Tue Aug 18 13:02:01.615014 2026] [security2:error] [pid 139043:tid 139228] [client 20.251.112.238:53142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/zxin.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZoQAAALw"]
[Tue Aug 18 13:02:01.624029 2026] [security2:error] [pid 139043:tid 139177] [client 132.196.30.78:19157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/chosen.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZogAAAIk"]
[Tue Aug 18 13:02:01.630559 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.112.14:38922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/666.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM5wAAAH8"]
[Tue Aug 18 13:02:01.634540 2026] [security2:error] [pid 139043:tid 139180] [client 20.79.204.6:11878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZpAAAAIw"]
[Tue Aug 18 13:02:01.635570 2026] [security2:error] [pid 123784:tid 123958] [client 4.232.94.69:29842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/log.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM6AAAACg"]
[Tue Aug 18 13:02:01.638662 2026] [security2:error] [pid 123784:tid 124028] [client 20.75.92.165:4270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/upload.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM6QAAAG4"]
[Tue Aug 18 13:02:01.655367 2026] [security2:error] [pid 139043:tid 139269] [client 158.23.17.4:34026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/uq.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZpQAAAOU"]
[Tue Aug 18 13:02:01.671358 2026] [security2:error] [pid 139043:tid 139272] [client 52.139.47.57:18307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/ws83.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZqAAAAOg"]
[Tue Aug 18 13:02:01.680768 2026] [security2:error] [pid 139043:tid 139208] [client 20.79.204.6:11561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZqQAAAKg"]
[Tue Aug 18 13:02:01.691792 2026] [security2:error] [pid 139043:tid 139263] [client 20.163.43.14:8796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZqgAAAN8"]
[Tue Aug 18 13:02:01.692864 2026] [security2:error] [pid 139043:tid 139288] [client 172.213.243.2:11820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/xxx.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZqwAAAPg"]
[Tue Aug 18 13:02:01.709276 2026] [security2:error] [pid 139043:tid 139280] [client 20.51.153.15:13568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/settings.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZrAAAAPA"]
[Tue Aug 18 13:02:01.727320 2026] [authz_core:error] [pid 139043:tid 139096] [remote 57.141.22.86:27498] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:02:01.727798 2026] [authz_core:error] [pid 139043:tid 139096] [remote 57.141.22.86:27498] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:02:01.738128 2026] [security2:error] [pid 139043:tid 139245] [client 20.151.109.219:60906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/qk.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZrgAAAM0"]
[Tue Aug 18 13:02:01.747841 2026] [security2:error] [pid 139043:tid 139190] [client 20.79.204.6:10704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/i.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZrwAAAJY"]
[Tue Aug 18 13:02:01.751779 2026] [security2:error] [pid 123784:tid 124043] [client 20.104.100.201:49687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/special.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM6gAAAH0"]
[Tue Aug 18 13:02:01.754325 2026] [security2:error] [pid 139043:tid 139246] [client 20.226.112.14:32573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/thui.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZsAAAAM4"]
[Tue Aug 18 13:02:01.779349 2026] [security2:error] [pid 123784:tid 124033] [client 102.213.179.104:52183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM6wAAAHM"]
[Tue Aug 18 13:02:01.779550 2026] [security2:error] [pid 123784:tid 124033] [client 102.213.179.104:52183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM6wAAAHM"]
[Tue Aug 18 13:02:01.793211 2026] [security2:error] [pid 123784:tid 123915] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/iz.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM7AAAJn4"]
[Tue Aug 18 13:02:01.797986 2026] [security2:error] [pid 139043:tid 139287] [client 20.226.112.14:22946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/agg.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZswAAAPc"]
[Tue Aug 18 13:02:01.829293 2026] [security2:error] [pid 139043:tid 139242] [client 86.120.159.145:14859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZtgAAAMo"]
[Tue Aug 18 13:02:01.829392 2026] [security2:error] [pid 139043:tid 139242] [client 86.120.159.145:14859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZtgAAAMo"]
[Tue Aug 18 13:02:01.836678 2026] [security2:error] [pid 139043:tid 139181] [client 20.226.56.190:31620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/456.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZtwAAAI0"]
[Tue Aug 18 13:02:01.841266 2026] [security2:error] [pid 139043:tid 139175] [client 68.221.73.131:41659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/bs1.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZuAAAAIc"]
[Tue Aug 18 13:02:01.844352 2026] [security2:error] [pid 139043:tid 139223] [client 20.226.112.14:32528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/erty.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZuQAAALc"]
[Tue Aug 18 13:02:01.861796 2026] [security2:error] [pid 139043:tid 139261] [client 20.119.58.187:10221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/w.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZuwAAAN0"]
[Tue Aug 18 13:02:01.867996 2026] [security2:error] [pid 123784:tid 123976] [client 20.203.183.135:46986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM8AAAADo"]
[Tue Aug 18 13:02:01.873007 2026] [security2:error] [pid 123784:tid 124012] [client 20.226.112.14:32542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/mini.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM8QAAAF4"]
[Tue Aug 18 13:02:01.882880 2026] [security2:error] [pid 139043:tid 139173] [client 20.226.112.14:38928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/sid3.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZvAAAAIU"]
[Tue Aug 18 13:02:01.890787 2026] [security2:error] [pid 139043:tid 139252] [client 20.75.92.165:4302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wk/index.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZvQAAANQ"]
[Tue Aug 18 13:02:01.896135 2026] [security2:error] [pid 123784:tid 124038] [client 20.226.112.14:22934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/moon.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM8gAAAHg"]
[Tue Aug 18 13:02:01.897797 2026] [security2:error] [pid 123784:tid 123954] [client 68.155.154.236:8345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/zugvi.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM8wAAACQ"]
[Tue Aug 18 13:02:01.902294 2026] [security2:error] [pid 139043:tid 139193] [client 216.244.66.232:57686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZvgAAAJk"]
[Tue Aug 18 13:02:01.902377 2026] [security2:error] [pid 139043:tid 139193] [client 216.244.66.232:57686] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZvgAAAJk"]
[Tue Aug 18 13:02:01.921574 2026] [security2:error] [pid 123784:tid 123982] [client 135.225.78.186:39556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/key.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM9AAAAEA"]
[Tue Aug 18 13:02:01.932848 2026] [security2:error] [pid 139043:tid 139072] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZwAAAixw"]
[Tue Aug 18 13:02:01.933002 2026] [security2:error] [pid 139043:tid 139179] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZwAAAixw"]
[Tue Aug 18 13:02:01.936036 2026] [security2:error] [pid 139043:tid 139226] [client 20.226.112.14:13046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ms.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZwQAAALo"]
[Tue Aug 18 13:02:01.959798 2026] [security2:error] [pid 139043:tid 139298] [client 20.91.215.254:11459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZwwAAAQI"]
[Tue Aug 18 13:02:01.960349 2026] [security2:error] [pid 123784:tid 124000] [client 132.196.30.78:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/simple.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM9gAAAFI"]
[Tue Aug 18 13:02:01.960745 2026] [security2:error] [pid 139043:tid 139201] [client 20.226.112.14:39446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wsws.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZxAAAAKE"]
[Tue Aug 18 13:02:01.961207 2026] [security2:error] [pid 139043:tid 139211] [client 20.51.153.15:5085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/spip.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZxQAAAKs"]
[Tue Aug 18 13:02:01.972320 2026] [fcgid:warn] [pid 123784:tid 123946] (70014)End of file found: [client 199.45.155.75:45442] mod_fcgid: can't get data from http client
[Tue Aug 18 13:02:02.000061 2026] [security2:error] [pid 139043:tid 139276] [client 20.127.136.245:11804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/lite.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZxgAAAOw"]
[Tue Aug 18 13:02:02.005914 2026] [security2:error] [pid 123784:tid 123902] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/se.php"] [unique_id "aoSB-mwDnJBNj2tDbYYM-AAAG3E"]
[Tue Aug 18 13:02:02.033037 2026] [security2:error] [pid 139043:tid 139198] [client 20.104.100.201:49123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZyQAAAJ4"]
[Tue Aug 18 13:02:02.038743 2026] [security2:error] [pid 139043:tid 139238] [client 20.163.43.14:8870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/ok.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZywAAAMY"]
[Tue Aug 18 13:02:02.045005 2026] [security2:error] [pid 139043:tid 139282] [client 213.35.127.232:62414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZzAAAAPI"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:02:02.059996 2026] [security2:error] [pid 139043:tid 139174] [client 20.226.112.14:22969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/motu.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZzQAAAIY"]
[Tue Aug 18 13:02:02.064549 2026] [security2:error] [pid 139043:tid 139220] [client 158.23.17.4:20459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/dj.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZzgAAALQ"]
[Tue Aug 18 13:02:02.085039 2026] [security2:error] [pid 139043:tid 139234] [client 20.29.77.16:27098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/infoinfo.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZzwAAAMI"]
[Tue Aug 18 13:02:02.092749 2026] [security2:error] [pid 139043:tid 139111] [remote 68.178.165.65:52678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "historiasparadormir.top"] [uri "/wp-login.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ0QAA0UM"]
[Tue Aug 18 13:02:02.116220 2026] [security2:error] [pid 139043:tid 139239] [client 172.213.243.2:14553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/un.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ1AAAAMc"]
[Tue Aug 18 13:02:02.130204 2026] [security2:error] [pid 123784:tid 123999] [client 158.23.17.4:58717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/an.php"] [unique_id "aoSB-mwDnJBNj2tDbYYM-gAAAFE"]
[Tue Aug 18 13:02:02.139054 2026] [security2:error] [pid 139043:tid 139271] [client 158.158.74.177:9223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/customize.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ1gAAAOc"]
[Tue Aug 18 13:02:02.150203 2026] [security2:error] [pid 139043:tid 139279] [client 20.75.92.165:4344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-act.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ1wAAAO8"]
[Tue Aug 18 13:02:02.152014 2026] [security2:error] [pid 139043:tid 139259] [client 20.116.17.175:23038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/domvf.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ2AAAANs"]
[Tue Aug 18 13:02:02.163672 2026] [security2:error] [pid 139043:tid 139229] [client 20.151.109.219:20127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ3AAAAL0"]
[Tue Aug 18 13:02:02.183776 2026] [security2:error] [pid 123784:tid 124017] [client 172.202.39.151:52407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSB-mwDnJBNj2tDbYYM_AAAAGM"]
[Tue Aug 18 13:02:02.193239 2026] [security2:error] [pid 139043:tid 139283] [client 52.139.47.57:18325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/style.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ3QAAAPM"]
[Tue Aug 18 13:02:02.197204 2026] [security2:error] [pid 123784:tid 123842] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/vp.php"] [unique_id "aoSB-mwDnJBNj2tDbYYM_QAAMTU"]
[Tue Aug 18 13:02:02.210749 2026] [security2:error] [pid 123784:tid 123928] [client 20.251.112.238:26648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/pass4.php"] [unique_id "aoSB-mwDnJBNj2tDbYYM_gAAAAo"]
[Tue Aug 18 13:02:02.211499 2026] [security2:error] [pid 123784:tid 123940] [client 20.51.153.15:13581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/search.php"] [unique_id "aoSB-mwDnJBNj2tDbYYM_wAAABY"]
[Tue Aug 18 13:02:02.215711 2026] [security2:error] [pid 139043:tid 139182] [client 20.119.58.187:10164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/x.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ3gAAAI4"]
[Tue Aug 18 13:02:02.262554 2026] [security2:error] [pid 139043:tid 139231] [client 20.79.204.6:12272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ4QAAAL8"]
[Tue Aug 18 13:02:02.297222 2026] [security2:error] [pid 139043:tid 139177] [client 20.38.3.247:25845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/222.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ4wAAAIk"]
[Tue Aug 18 13:02:02.307227 2026] [security2:error] [pid 139043:tid 139180] [client 68.155.154.236:64180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/rymmm.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ5AAAAIw"]
[Tue Aug 18 13:02:02.308482 2026] [security2:error] [pid 139043:tid 139216] [client 20.79.204.6:12282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ5gAAALA"]
[Tue Aug 18 13:02:02.312384 2026] [security2:error] [pid 139043:tid 139269] [client 20.104.100.201:49115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/thoms.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ5wAAAOU"]
[Tue Aug 18 13:02:02.323102 2026] [security2:error] [pid 139043:tid 139192] [client 158.23.17.4:6375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/32.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ6AAAAJg"]
[Tue Aug 18 13:02:02.341288 2026] [security2:error] [pid 139043:tid 139086] [remote 40.77.167.254:63355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siderurgiabrasil.com.br"] [uri "/wp-content/ajax-handler.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ6QAA-Co"], referer: https://siderurgiabrasil.com.br/2020/09/02/iabr-icia-indice-de-confianca-da-industria-do-aco/
[Tue Aug 18 13:02:02.350059 2026] [security2:error] [pid 123784:tid 124002] [client 68.155.154.236:55461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wsrer.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNAAAAAFQ"]
[Tue Aug 18 13:02:02.361797 2026] [security2:error] [pid 139043:tid 139188] [client 20.163.43.14:8885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/item.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ6gAAAJQ"]
[Tue Aug 18 13:02:02.402339 2026] [security2:error] [pid 123784:tid 123927] [client 20.226.112.14:34193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/fff.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNAQAAAAk"]
[Tue Aug 18 13:02:02.438991 2026] [security2:error] [pid 123784:tid 124008] [client 158.23.17.4:49208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/fa.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNAgAAAFo"]
[Tue Aug 18 13:02:02.468133 2026] [authz_core:error] [pid 123784:tid 123887] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:02:02.468418 2026] [authz_core:error] [pid 123784:tid 123887] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:02:02.469793 2026] [security2:error] [pid 123784:tid 124042] [client 20.75.92.165:4294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNBAAAAHw"]
[Tue Aug 18 13:02:02.470957 2026] [security2:error] [pid 139043:tid 139287] [client 20.51.153.15:13591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/build.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ7QAAAPc"]
[Tue Aug 18 13:02:02.483098 2026] [security2:error] [pid 123784:tid 123987] [client 20.226.112.14:38919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/66.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNBgAAAEU"]
[Tue Aug 18 13:02:02.491659 2026] [security2:error] [pid 139043:tid 139196] [client 20.29.77.16:33575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/c99shell.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ7wAAAJw"]
[Tue Aug 18 13:02:02.530006 2026] [security2:error] [pid 139043:tid 139265] [client 172.213.243.2:45360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/autogooey.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ8QAAAOE"]
[Tue Aug 18 13:02:02.548939 2026] [security2:error] [pid 139043:tid 139181] [client 20.127.136.245:3561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/ms-edit.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ8gAAAI0"]
[Tue Aug 18 13:02:02.553191 2026] [security2:error] [pid 123784:tid 124003] [client 20.151.109.219:39335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/fs.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNBwAAAFU"]
[Tue Aug 18 13:02:02.568677 2026] [security2:error] [pid 123784:tid 123953] [client 20.119.58.187:10175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/xx.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNCAAAACM"]
[Tue Aug 18 13:02:02.573212 2026] [security2:error] [pid 123784:tid 124005] [client 172.202.39.151:5113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/cache.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNCQAAAFc"]
[Tue Aug 18 13:02:02.584349 2026] [security2:error] [pid 139043:tid 139266] [client 20.104.100.201:49696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ9AAAAOI"]
[Tue Aug 18 13:02:02.614483 2026] [security2:error] [pid 139043:tid 139294] [client 52.139.47.57:60558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/wp-the.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ9QAAAP4"]
[Tue Aug 18 13:02:02.653904 2026] [security2:error] [pid 139043:tid 139230] [client 20.226.112.14:22897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/g.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ9wAAAL4"]
[Tue Aug 18 13:02:02.689553 2026] [security2:error] [pid 123784:tid 123975] [client 20.91.215.254:27075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/past1.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNDAAAADk"]
[Tue Aug 18 13:02:02.690430 2026] [security2:error] [pid 139043:tid 139178] [client 40.77.167.254:63303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siderurgiabrasil.com.br"] [uri "/wp-content/ajax-handler.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ-QAAAIo"], referer: http://siderurgiabrasil.com.br/2026/06/30/industria-de-maquinas-enfrenta-desaceleracao-persistente/
[Tue Aug 18 13:02:02.741528 2026] [security2:error] [pid 139043:tid 139195] [client 20.226.112.14:22973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/x7.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ-wAAAJs"]
[Tue Aug 18 13:02:02.765291 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:02:02.765596 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:02:02.768499 2026] [security2:error] [pid 139043:tid 139225] [client 20.51.153.15:5056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/defaul.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ_gAAALk"]
[Tue Aug 18 13:02:02.774995 2026] [security2:error] [pid 139043:tid 139268] [client 132.196.30.78:25625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB-v2v-lWn9OzQT7UaAAAAAOQ"]
[Tue Aug 18 13:02:02.799767 2026] [security2:error] [pid 139043:tid 139255] [client 20.251.112.238:61006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSB-v2v-lWn9OzQT7UaAQAAANc"]
[Tue Aug 18 13:02:02.859354 2026] [security2:error] [pid 139043:tid 139262] [client 20.104.100.201:49409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/root.php"] [unique_id "aoSB-v2v-lWn9OzQT7UaBAAAAN4"]
[Tue Aug 18 13:02:02.923682 2026] [security2:error] [pid 123784:tid 123979] [client 20.79.204.6:10772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNEwAAAD0"]
[Tue Aug 18 13:02:02.925957 2026] [security2:error] [pid 123784:tid 123937] [client 20.119.58.187:10233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNEgAAABM"]
[Tue Aug 18 13:02:02.935212 2026] [security2:error] [pid 139043:tid 139198] [client 20.226.112.14:34222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/god.php"] [unique_id "aoSB-v2v-lWn9OzQT7UaCAAAAJ4"]
[Tue Aug 18 13:02:02.940666 2026] [security2:error] [pid 123784:tid 123932] [client 172.213.243.2:11632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/sty.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNFAAAAA4"]
[Tue Aug 18 13:02:02.966793 2026] [security2:error] [pid 139043:tid 139238] [client 158.158.74.177:25551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/mah/function.php"] [unique_id "aoSB-v2v-lWn9OzQT7UaCwAAAMY"]
[Tue Aug 18 13:02:03.010352 2026] [security2:error] [pid 123784:tid 124029] [client 20.116.17.175:22933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/red.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNFQAAAG8"]
[Tue Aug 18 13:02:03.026510 2026] [security2:error] [pid 123784:tid 123970] [client 158.23.17.4:55206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/sy.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNFgAAADQ"]
[Tue Aug 18 13:02:03.029166 2026] [security2:error] [pid 139043:tid 139276] [client 52.139.47.57:39079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/plugin.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaDAAAAOw"]
[Tue Aug 18 13:02:03.033470 2026] [security2:error] [pid 139043:tid 139189] [client 20.151.109.219:60921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/rb.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaDQAAAJU"]
[Tue Aug 18 13:02:03.037627 2026] [security2:error] [pid 123784:tid 123968] [client 20.51.153.15:5110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/twin.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNFwAAADI"]
[Tue Aug 18 13:02:03.054224 2026] [security2:error] [pid 123784:tid 123962] [client 68.155.154.236:41531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/ucpfr.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNGAAAACw"]
[Tue Aug 18 13:02:03.061201 2026] [security2:error] [pid 139043:tid 139297] [client 213.35.127.232:62614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaDwAAAQE"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:02:03.067506 2026] [authz_core:error] [pid 123784:tid 123896] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:02:03.067804 2026] [authz_core:error] [pid 123784:tid 123896] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:02:03.104262 2026] [security2:error] [pid 123784:tid 123949] [client 88.99.80.227:18396] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.melocorretordeimoveis.com.br"] [uri "/index.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM7wAAAB8"], referer: http://www.melocorretordeimoveis.com.br
[Tue Aug 18 13:02:03.123247 2026] [security2:error] [pid 123784:tid 123799] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ph.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNJQAATgo"]
[Tue Aug 18 13:02:03.136637 2026] [security2:error] [pid 139043:tid 139254] [client 20.104.100.201:49448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/fpwch.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaFQAAANY"]
[Tue Aug 18 13:02:03.160751 2026] [security2:error] [pid 139043:tid 139206] [client 158.23.17.4:30986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/73.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaFgAAAKY"]
[Tue Aug 18 13:02:03.169734 2026] [security2:error] [pid 123784:tid 123867] [remote 57.141.22.2:34674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSB-2wDnJBNj2tDbYYNJwAAVk4"]
[Tue Aug 18 13:02:03.173013 2026] [security2:error] [pid 139043:tid 139279] [client 20.226.112.14:39428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ebahvhhh.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaFwAAAO8"]
[Tue Aug 18 13:02:03.185521 2026] [security2:error] [pid 139043:tid 139127] [remote 40.77.167.254:63355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siderurgiabrasil.com.br"] [uri "/wp-content/ajax-handler.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaGQAA_FM"], referer: https://siderurgiabrasil.com.br/2022/10/25/gerdau-e-seu-papel-social/
[Tue Aug 18 13:02:03.249804 2026] [security2:error] [pid 139043:tid 139187] [client 20.226.112.14:38968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/8.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaHAAAAJM"]
[Tue Aug 18 13:02:03.257253 2026] [security2:error] [pid 139043:tid 139247] [client 20.29.77.16:64903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/profiler.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaHQAAAM8"]
[Tue Aug 18 13:02:03.278558 2026] [security2:error] [pid 139043:tid 139239] [client 20.119.58.187:9732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/y.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaHgAAAMc"]
[Tue Aug 18 13:02:03.288716 2026] [security2:error] [pid 123784:tid 123955] [client 20.51.153.15:13579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/new2.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNKQAAACU"]
[Tue Aug 18 13:02:03.292868 2026] [security2:error] [pid 123784:tid 123883] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/s.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNKwAAbF4"]
[Tue Aug 18 13:02:03.294438 2026] [security2:error] [pid 139043:tid 139275] [client 20.79.204.6:12286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaHwAAAOs"]
[Tue Aug 18 13:02:03.303484 2026] [security2:error] [pid 123784:tid 123958] [client 20.127.136.245:22153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/rip.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNLAAAACg"]
[Tue Aug 18 13:02:03.308517 2026] [security2:error] [pid 139043:tid 139270] [client 20.251.112.238:22366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/z.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaIAAAAOY"]
[Tue Aug 18 13:02:03.330613 2026] [security2:error] [pid 139043:tid 139278] [client 20.226.112.14:38924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/koiy.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaIgAAAO4"]
[Tue Aug 18 13:02:03.331427 2026] [security2:error] [pid 139043:tid 139219] [client 20.79.204.6:12278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaIwAAALM"]
[Tue Aug 18 13:02:03.334919 2026] [security2:error] [pid 123784:tid 124006] [client 20.151.109.219:14098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/37.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNMQAAAFg"]
[Tue Aug 18 13:02:03.360610 2026] [security2:error] [pid 139043:tid 139237] [client 20.91.215.254:11517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/file61.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaJAAAAMU"]
[Tue Aug 18 13:02:03.386403 2026] [security2:error] [pid 139043:tid 139228] [client 172.213.243.2:45951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wio.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaJgAAALw"]
[Tue Aug 18 13:02:03.403370 2026] [security2:error] [pid 139043:tid 139216] [client 20.226.112.14:39468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/iko.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaJwAAALA"]
[Tue Aug 18 13:02:03.412477 2026] [security2:error] [pid 139043:tid 139208] [client 20.104.100.201:49705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/mg.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaKQAAAKg"]
[Tue Aug 18 13:02:03.454997 2026] [security2:error] [pid 139043:tid 139191] [client 52.139.47.57:1112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/readme.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaLQAAAJc"]
[Tue Aug 18 13:02:03.456925 2026] [security2:error] [pid 139043:tid 139188] [client 158.23.17.4:25392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/fb.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaLgAAAJQ"]
[Tue Aug 18 13:02:03.465175 2026] [security2:error] [pid 139043:tid 139258] [client 20.116.17.175:55240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/JawirGenk.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaLwAAANo"]
[Tue Aug 18 13:02:03.472077 2026] [security2:error] [pid 123784:tid 123957] [client 68.155.154.236:8858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/lddxs.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNNwAAACc"]
[Tue Aug 18 13:02:03.475342 2026] [security2:error] [pid 123784:tid 124033] [client 20.226.112.14:28774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/raw.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNOQAAAHM"]
[Tue Aug 18 13:02:03.518686 2026] [security2:error] [pid 123784:tid 123876] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/uo.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNOgAAQ1c"]
[Tue Aug 18 13:02:03.531161 2026] [security2:error] [pid 139043:tid 139204] [client 20.51.153.15:13684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/rex.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaMQAAAKQ"]
[Tue Aug 18 13:02:03.533029 2026] [security2:error] [pid 139043:tid 139217] [client 68.155.154.236:8861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/yxijx.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaMgAAALE"]
[Tue Aug 18 13:02:03.559829 2026] [security2:error] [pid 139043:tid 139196] [client 68.221.73.131:28000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/hp2.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaMwAAAJw"]
[Tue Aug 18 13:02:03.566797 2026] [security2:error] [pid 139043:tid 139265] [client 20.226.56.190:47114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/SMTP.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaNQAAAOE"]
[Tue Aug 18 13:02:03.586878 2026] [security2:error] [pid 139043:tid 139181] [client 20.203.183.135:20910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaNgAAAI0"]
[Tue Aug 18 13:02:03.594493 2026] [security2:error] [pid 139043:tid 139214] [client 20.226.112.14:39428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/05.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaOAAAAK4"]
[Tue Aug 18 13:02:03.620007 2026] [security2:error] [pid 139043:tid 139240] [client 20.151.109.219:14226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/md.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaOgAAAMg"]
[Tue Aug 18 13:02:03.620652 2026] [security2:error] [pid 139043:tid 139180] [client 158.158.74.177:22878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/filter.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaOwAAAIw"]
[Tue Aug 18 13:02:03.623041 2026] [security2:error] [pid 139043:tid 139230] [client 20.226.112.14:32546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/public/hi.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaPAAAAL4"]
[Tue Aug 18 13:02:03.653418 2026] [security2:error] [pid 139043:tid 139246] [client 20.226.112.14:22954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/get.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaPQAAAM4"]
[Tue Aug 18 13:02:03.685668 2026] [security2:error] [pid 139043:tid 139261] [client 20.104.100.201:49150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/reop3.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaQAAAAN0"]
[Tue Aug 18 13:02:03.698909 2026] [security2:error] [pid 123784:tid 123835] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/kx.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNPQAAOC4"]
[Tue Aug 18 13:02:03.712049 2026] [security2:error] [pid 123784:tid 123837] [remote 115.146.125.52:35324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/wp-login.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNPgAAPjA"]
[Tue Aug 18 13:02:03.737647 2026] [security2:error] [pid 123784:tid 123976] [client 20.75.92.165:4350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNPwAAADo"]
[Tue Aug 18 13:02:03.739238 2026] [security2:error] [pid 139043:tid 139221] [client 20.226.112.14:28594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/rpk.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaQgAAALU"]
[Tue Aug 18 13:02:03.743005 2026] [security2:error] [pid 123784:tid 123923] [client 20.79.204.6:10733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNQAAAAAU"]
[Tue Aug 18 13:02:03.766985 2026] [security2:error] [pid 139043:tid 139225] [client 132.196.30.78:25642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/av.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaQwAAALk"]
[Tue Aug 18 13:02:03.767508 2026] [security2:error] [pid 139043:tid 139268] [client 20.51.153.15:13587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/verification.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaRAAAAOQ"]
[Tue Aug 18 13:02:03.772633 2026] [security2:error] [pid 123784:tid 124012] [client 20.29.77.16:27105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/findes.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNQgAAAF4"]
[Tue Aug 18 13:02:03.778258 2026] [security2:error] [pid 123784:tid 123972] [client 158.23.17.4:17567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/57.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNQwAAADY"]
[Tue Aug 18 13:02:03.807819 2026] [security2:error] [pid 123784:tid 124007] [client 172.213.243.2:16852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/1061.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNRQAAAFk"]
[Tue Aug 18 13:02:03.834965 2026] [security2:error] [pid 139043:tid 139251] [client 20.251.112.238:40618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/222.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaSAAAANM"]
[Tue Aug 18 13:02:03.836179 2026] [security2:error] [pid 139043:tid 139108] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaRwAAq0A"]
[Tue Aug 18 13:02:03.836347 2026] [security2:error] [pid 139043:tid 139211] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaRwAAq0A"]
[Tue Aug 18 13:02:03.840843 2026] [security2:error] [pid 139043:tid 139262] [client 172.202.39.151:52878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/images/images/about.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaSQAAAN4"]
[Tue Aug 18 13:02:03.843995 2026] [security2:error] [pid 123784:tid 124044] [client 4.232.151.198:38792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/edit.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNRgAAAH4"]
[Tue Aug 18 13:02:03.886650 2026] [security2:error] [pid 139043:tid 139195] [client 52.139.47.57:18077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/chosen.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaSwAAAJs"]
[Tue Aug 18 13:02:03.920887 2026] [security2:error] [pid 123784:tid 123877] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/va.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNSAAAHFg"]
[Tue Aug 18 13:02:03.939429 2026] [security2:error] [pid 123784:tid 123945] [client 20.151.109.219:14288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/iy.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNSQAAABs"]
[Tue Aug 18 13:02:03.943215 2026] [security2:error] [pid 123784:tid 123950] [client 20.116.17.175:55192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/options.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNSgAAACA"]
[Tue Aug 18 13:02:03.951586 2026] [security2:error] [pid 123784:tid 123984] [client 20.226.112.14:39432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-blog.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNSwAAAEI"]
[Tue Aug 18 13:02:03.955862 2026] [security2:error] [pid 123784:tid 124040] [client 20.104.100.201:49134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/php5.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNTAAAAHo"]
[Tue Aug 18 13:02:03.970799 2026] [authz_core:error] [pid 123784:tid 123833] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:02:03.971054 2026] [authz_core:error] [pid 123784:tid 123833] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:02:04.011014 2026] [security2:error] [pid 123784:tid 124013] [client 20.127.136.245:11777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/update/da222.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNUAAAAF8"]
[Tue Aug 18 13:02:04.035101 2026] [security2:error] [pid 139043:tid 139198] [client 20.226.112.14:32539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/mga.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaUQAAAJ4"]
[Tue Aug 18 13:02:04.048874 2026] [security2:error] [pid 139043:tid 139277] [client 20.38.3.247:38933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/key.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaUwAAAO0"]
[Tue Aug 18 13:02:04.053351 2026] [security2:error] [pid 139043:tid 139282] [client 20.51.153.15:13682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/smtp.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaVAAAAPI"]
[Tue Aug 18 13:02:04.078381 2026] [security2:error] [pid 139043:tid 139193] [client 213.35.127.232:62850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaVQAAAJk"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:02:04.090239 2026] [security2:error] [pid 123784:tid 123856] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/fo.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNUwAAHUM"]
[Tue Aug 18 13:02:04.096096 2026] [security2:error] [pid 139043:tid 139236] [client 20.226.112.14:34178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/fs.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaVgAAAMQ"]
[Tue Aug 18 13:02:04.102647 2026] [security2:error] [pid 139043:tid 139174] [client 20.79.204.6:12280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaVwAAAIY"]
[Tue Aug 18 13:02:04.124298 2026] [security2:error] [pid 139043:tid 139220] [client 52.173.121.69:54161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaWAAAALQ"]
[Tue Aug 18 13:02:04.143350 2026] [security2:error] [pid 139043:tid 139297] [client 158.23.17.4:25391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/gw.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaWgAAAQE"]
[Tue Aug 18 13:02:04.145941 2026] [security2:error] [pid 139043:tid 139224] [client 20.79.204.6:11563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaWwAAALg"]
[Tue Aug 18 13:02:04.149106 2026] [security2:error] [pid 139043:tid 139285] [client 20.75.92.165:4251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaXAAAAPU"]
[Tue Aug 18 13:02:04.194978 2026] [security2:error] [pid 139043:tid 139259] [client 158.23.17.4:63977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ve.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaXwAAANs"]
[Tue Aug 18 13:02:04.203557 2026] [security2:error] [pid 123784:tid 124010] [client 172.202.39.151:44578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNVQAAAFw"]
[Tue Aug 18 13:02:04.221274 2026] [security2:error] [pid 123784:tid 123987] [client 20.91.215.254:11500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/license.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNVwAAAEU"]
[Tue Aug 18 13:02:04.228029 2026] [security2:error] [pid 139043:tid 139273] [client 172.213.243.2:11807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/gec.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaYAAAAOk"]
[Tue Aug 18 13:02:04.231031 2026] [security2:error] [pid 139043:tid 139283] [client 20.104.100.201:49996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/acp.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaYgAAAPM"]
[Tue Aug 18 13:02:04.243729 2026] [security2:error] [pid 123784:tid 124003] [client 68.155.154.236:65423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/zwlsv.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNWAAAAFU"]
[Tue Aug 18 13:02:04.274953 2026] [authz_core:error] [pid 123784:tid 123817] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:02:04.275234 2026] [authz_core:error] [pid 123784:tid 123817] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:02:04.287581 2026] [security2:error] [pid 123784:tid 123818] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/loading.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNXAAAcR0"]
[Tue Aug 18 13:02:04.287736 2026] [security2:error] [pid 123784:tid 124035] [client 20.51.153.15:13623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/teste.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNXQAAAHU"]
[Tue Aug 18 13:02:04.289054 2026] [security2:error] [pid 123784:tid 124017] [client 158.158.74.177:22911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/input.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNXgAAAGM"]
[Tue Aug 18 13:02:04.300026 2026] [security2:error] [pid 139043:tid 139249] [client 52.139.47.57:18352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/system.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaZAAAANE"]
[Tue Aug 18 13:02:04.304136 2026] [security2:error] [pid 139043:tid 139231] [client 20.151.109.219:39299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/og.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaZQAAAL8"]
[Tue Aug 18 13:02:04.359394 2026] [security2:error] [pid 123784:tid 123936] [client 158.23.17.4:20201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ib.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNZAAAABI"]
[Tue Aug 18 13:02:04.370938 2026] [security2:error] [pid 139043:tid 139208] [client 20.226.112.14:60107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-tem.php"] [unique_id "aoSB_P2v-lWn9OzQT7UabAAAAKg"]
[Tue Aug 18 13:02:04.378460 2026] [security2:error] [pid 139043:tid 139288] [client 20.127.136.245:11836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/upload.php"] [unique_id "aoSB_P2v-lWn9OzQT7UabQAAAPg"]
[Tue Aug 18 13:02:04.406087 2026] [security2:error] [pid 139043:tid 139279] [client 66.187.6.102:33492] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/produtos/trinchas/trincha-angular"] [unique_id "aoSB_P2v-lWn9OzQT7UabgAAAO8"]
[Tue Aug 18 13:02:04.406175 2026] [security2:error] [pid 139043:tid 139279] [client 66.187.6.102:33492] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/produtos/trinchas/trincha-angular"] [unique_id "aoSB_P2v-lWn9OzQT7UabgAAAO8"]
[Tue Aug 18 13:02:04.434588 2026] [security2:error] [pid 123784:tid 123932] [client 68.155.154.236:45864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/zjggu.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNawAAAA4"]
[Tue Aug 18 13:02:04.442150 2026] [security2:error] [pid 123784:tid 124014] [client 20.226.112.14:13013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/sadd.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNbAAAAGA"]
[Tue Aug 18 13:02:04.460015 2026] [security2:error] [pid 123784:tid 123802] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ke.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNbQAAZA0"]
[Tue Aug 18 13:02:04.481508 2026] [security2:error] [pid 123784:tid 123854] [remote 8.229.129.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.129.229.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.outlimit.com.br"] [uri "/.env.php.bak"] [unique_id "aoSB_GwDnJBNj2tDbYYNYgAAaUE"]
[Tue Aug 18 13:02:04.486883 2026] [security2:error] [pid 123784:tid 123884] [remote 8.229.129.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.129.229.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.outlimit.com.br"] [uri "/config/.env.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNYQAAaV8"]
[Tue Aug 18 13:02:04.498977 2026] [security2:error] [pid 123784:tid 123970] [client 20.251.112.238:56672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/G-in.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNbwAAADQ"]
[Tue Aug 18 13:02:04.514604 2026] [security2:error] [pid 139043:tid 139242] [client 20.104.100.201:50016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/yas.php"] [unique_id "aoSB_P2v-lWn9OzQT7UafgAAAMo"]
[Tue Aug 18 13:02:04.516811 2026] [security2:error] [pid 123784:tid 123962] [client 20.29.77.16:13683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/fedora.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNdQAAACw"]
[Tue Aug 18 13:02:04.526120 2026] [security2:error] [pid 123784:tid 123959] [client 20.51.153.15:5067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/local.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNdgAAACk"]
[Tue Aug 18 13:02:04.545682 2026] [security2:error] [pid 139043:tid 139216] [client 66.187.6.102:33510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/site/plugins/jquerymask/jquery.mask.min.js"] [unique_id "aoSB_P2v-lWn9OzQT7UagAAAALA"]
[Tue Aug 18 13:02:04.545775 2026] [security2:error] [pid 139043:tid 139216] [client 66.187.6.102:33510] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/site/plugins/jquerymask/jquery.mask.min.js"] [unique_id "aoSB_P2v-lWn9OzQT7UagAAAALA"]
[Tue Aug 18 13:02:04.571539 2026] [security2:error] [pid 123784:tid 123909] [remote 8.229.129.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.129.229.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.outlimit.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSB_GwDnJBNj2tDbYYNZwAAaXg"]
[Tue Aug 18 13:02:04.572864 2026] [authz_core:error] [pid 123784:tid 123811] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:02:04.573139 2026] [authz_core:error] [pid 123784:tid 123811] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:02:04.580359 2026] [security2:error] [pid 123784:tid 123843] [remote 8.229.129.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.129.229.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.outlimit.com.br"] [uri "/config.php.bak"] [unique_id "aoSB_GwDnJBNj2tDbYYNaQAAaTY"]
[Tue Aug 18 13:02:04.590148 2026] [security2:error] [pid 123784:tid 124011] [client 20.151.109.219:24441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/lp.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNewAAAF0"]
[Tue Aug 18 13:02:04.606474 2026] [security2:error] [pid 123784:tid 124024] [client 20.226.112.14:60155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ex.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNfwAAAGo"]
[Tue Aug 18 13:02:04.654430 2026] [security2:error] [pid 123784:tid 123995] [client 172.213.243.2:11823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/scx.php7"] [unique_id "aoSB_GwDnJBNj2tDbYYNhQAAAE0"]
[Tue Aug 18 13:02:04.680007 2026] [security2:error] [pid 123784:tid 123961] [client 20.116.17.175:22962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNhgAAACs"]
[Tue Aug 18 13:02:04.693083 2026] [security2:error] [pid 123784:tid 123824] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/nh.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNiAAAASM"]
[Tue Aug 18 13:02:04.711955 2026] [security2:error] [pid 123784:tid 124032] [client 20.79.204.6:12276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNiQAAAHI"]
[Tue Aug 18 13:02:04.722577 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.112.14:38915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/tax.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNjAAAAH8"]
[Tue Aug 18 13:02:04.725030 2026] [security2:error] [pid 139043:tid 139266] [client 52.139.47.57:18347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/wp-load.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaigAAAOI"]
[Tue Aug 18 13:02:04.733196 2026] [security2:error] [pid 139043:tid 139194] [client 20.75.92.165:1931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaiwAAAJo"]
[Tue Aug 18 13:02:04.754267 2026] [security2:error] [pid 123784:tid 123969] [client 20.79.204.6:11665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNjgAAADM"]
[Tue Aug 18 13:02:04.757048 2026] [security2:error] [pid 123784:tid 124006] [client 68.155.154.236:8857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/jrpga.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNjwAAAFg"]
[Tue Aug 18 13:02:04.776547 2026] [security2:error] [pid 139043:tid 139185] [client 20.127.136.245:14208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wk/index.php"] [unique_id "aoSB_P2v-lWn9OzQT7UajQAAAJE"]
[Tue Aug 18 13:02:04.789178 2026] [security2:error] [pid 139043:tid 139173] [client 20.104.100.201:49149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/ah25.php"] [unique_id "aoSB_P2v-lWn9OzQT7UajgAAAIU"]
[Tue Aug 18 13:02:04.803885 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:55231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ah.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNlAAAAH0"]
[Tue Aug 18 13:02:04.824550 2026] [security2:error] [pid 123784:tid 124033] [client 20.51.153.15:13636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/wp_sitting.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNlgAAAHM"]
[Tue Aug 18 13:02:04.866020 2026] [security2:error] [pid 139043:tid 139225] [client 20.226.112.14:13641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/X7x.php"] [unique_id "aoSB_P2v-lWn9OzQT7UakgAAALk"]
[Tue Aug 18 13:02:04.868099 2026] [security2:error] [pid 123784:tid 123866] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/oo.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNmgAAeU0"]
[Tue Aug 18 13:02:04.868758 2026] [security2:error] [pid 139043:tid 139268] [client 158.23.17.4:41969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ia.php"] [unique_id "aoSB_P2v-lWn9OzQT7UakwAAAOQ"]
[Tue Aug 18 13:02:04.871684 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:02:04.871951 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:02:04.916093 2026] [security2:error] [pid 139043:tid 139179] [client 20.226.112.14:34236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ocxla.php"] [unique_id "aoSB_P2v-lWn9OzQT7UamAAAAIs"]
[Tue Aug 18 13:02:04.960574 2026] [security2:error] [pid 139043:tid 139181] [client 4.232.151.198:30669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/elp.php"] [unique_id "aoSB_P2v-lWn9OzQT7UamwAAAI0"]
[Tue Aug 18 13:02:04.965336 2026] [security2:error] [pid 139043:tid 139257] [client 20.151.109.219:63735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ey.php"] [unique_id "aoSB_P2v-lWn9OzQT7UanAAAANk"]
[Tue Aug 18 13:02:04.966063 2026] [authz_core:error] [pid 139043:tid 139290] [client 192.178.4.134:56975] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:02:04.966324 2026] [authz_core:error] [pid 139043:tid 139290] [client 192.178.4.134:56975] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:02:05.021116 2026] [security2:error] [pid 139043:tid 139267] [client 158.158.74.177:9224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/jquery.php"] [unique_id "aoSB_f2v-lWn9OzQT7UaoAAAAOM"]
[Tue Aug 18 13:02:05.036091 2026] [security2:error] [pid 139043:tid 139198] [client 20.203.183.135:59982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/blurbs.php"] [unique_id "aoSB_f2v-lWn9OzQT7UaoQAAAJ4"]
[Tue Aug 18 13:02:05.054653 2026] [security2:error] [pid 139043:tid 139241] [client 20.116.17.175:55178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSB_f2v-lWn9OzQT7UaowAAAMk"]
[Tue Aug 18 13:02:05.055404 2026] [security2:error] [pid 123784:tid 123944] [client 149.34.210.141:60062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNnQAAABo"]
[Tue Aug 18 13:02:05.057483 2026] [security2:error] [pid 139043:tid 139222] [client 20.75.92.165:4237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB_f2v-lWn9OzQT7UapAAAALY"]
[Tue Aug 18 13:02:05.061293 2026] [security2:error] [pid 123784:tid 124007] [client 158.23.17.4:15792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/sw.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNnwAAAFk"]
[Tue Aug 18 13:02:05.065011 2026] [security2:error] [pid 139043:tid 139277] [client 20.104.100.201:49151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/ano.php"] [unique_id "aoSB_f2v-lWn9OzQT7UapQAAAO0"]
[Tue Aug 18 13:02:05.066026 2026] [security2:error] [pid 123784:tid 124044] [client 172.213.243.2:16857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp-admin/sc.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNoAAAAH4"]
[Tue Aug 18 13:02:05.070930 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.112.14:28794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/post.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNoQAAAFI"]
[Tue Aug 18 13:02:05.072793 2026] [security2:error] [pid 123784:tid 123879] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ja.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNogAAcFo"]
[Tue Aug 18 13:02:05.073250 2026] [security2:error] [pid 139043:tid 139193] [client 132.196.30.78:35576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp.php"] [unique_id "aoSB_f2v-lWn9OzQT7UapgAAAJk"]
[Tue Aug 18 13:02:05.090251 2026] [security2:error] [pid 139043:tid 139246] [client 213.35.127.232:63075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSB_f2v-lWn9OzQT7UapwAAAM4"], referer: https://wondermoving.com/wp-login.php
[Tue Aug 18 13:02:05.115402 2026] [security2:error] [pid 123784:tid 123945] [client 172.202.39.151:61703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/ms-edit.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNowAAABs"]
[Tue Aug 18 13:02:05.127752 2026] [security2:error] [pid 123784:tid 123950] [client 20.251.112.238:22355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/xxx.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNpAAAACA"]
[Tue Aug 18 13:02:05.142613 2026] [security2:error] [pid 123784:tid 123960] [client 20.51.153.15:13596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/ninja.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNpQAAACo"]
[Tue Aug 18 13:02:05.152691 2026] [security2:error] [pid 139043:tid 139235] [client 52.139.47.57:60607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/files/8.php"] [unique_id "aoSB_f2v-lWn9OzQT7UaqQAAAMM"]
[Tue Aug 18 13:02:05.155250 2026] [security2:error] [pid 139043:tid 139236] [client 68.155.154.236:45845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSB_f2v-lWn9OzQT7UaqgAAAMQ"]
[Tue Aug 18 13:02:05.170077 2026] [security2:error] [pid 139043:tid 139276] [client 20.226.112.14:39449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/nhr.php"] [unique_id "aoSB_f2v-lWn9OzQT7UaqwAAAOw"]
[Tue Aug 18 13:02:05.178692 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4
[Tue Aug 18 13:02:05.179191 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3
[Tue Aug 18 13:02:05.181207 2026] [security2:error] [pid 123784:tid 123984] [client 20.29.77.16:47298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/path.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNqAAAAEI"]
[Tue Aug 18 13:02:05.239237 2026] [security2:error] [pid 123784:tid 123935] [client 20.226.112.14:32528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ms-edit.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNqgAAABE"]
[Tue Aug 18 13:02:05.248253 2026] [security2:error] [pid 123784:tid 123794] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/xx.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNqwAAeAU"]
[Tue Aug 18 13:02:05.265535 2026] [security2:error] [pid 123784:tid 123951] [client 103.120.71.157:28059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNrAAAACE"]
[Tue Aug 18 13:02:05.265655 2026] [security2:error] [pid 123784:tid 123951] [client 103.120.71.157:28059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNrAAAACE"]
[Tue Aug 18 13:02:05.272257 2026] [security2:error] [pid 123784:tid 123933] [client 138.36.100.162:42190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNrQAAAA8"]
[Tue Aug 18 13:02:05.272368 2026] [security2:error] [pid 123784:tid 123933] [client 138.36.100.162:42190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNrQAAAA8"]
[Tue Aug 18 13:02:05.305302 2026] [security2:error] [pid 139043:tid 139213] [client 20.75.92.165:4230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/0x.php"] [unique_id "aoSB_f2v-lWn9OzQT7UargAAAK0"]
[Tue Aug 18 13:02:05.313978 2026] [security2:error] [pid 123784:tid 123981] [client 20.79.204.6:12269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNrwAAAD8"]
[Tue Aug 18 13:02:05.323258 2026] [security2:error] [pid 123784:tid 123944] [client 149.34.210.141:60062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNnQAAABo"]
[Tue Aug 18 13:02:05.333848 2026] [security2:error] [pid 139043:tid 139275] [client 20.226.56.190:47138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/vbseo.php"] [unique_id "aoSB_f2v-lWn9OzQT7UasAAAAOs"]
[Tue Aug 18 13:02:05.346785 2026] [security2:error] [pid 139043:tid 139249] [client 20.104.100.201:49137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/nwflm.php"] [unique_id "aoSB_f2v-lWn9OzQT7UasQAAANE"]
[Tue Aug 18 13:02:05.354536 2026] [security2:error] [pid 139043:tid 139274] [client 20.79.204.6:11868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSB_f2v-lWn9OzQT7UasgAAAOo"]
[Tue Aug 18 13:02:05.374641 2026] [security2:error] [pid 139043:tid 139212] [client 20.151.109.219:60377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL